Module 5 · CI/CD & Supply Chain
SolarWinds, 2020
27 / 38

Why attack a thousand customers, when you can attack one build system?

Everything so far secured the application. This module asks: what if the attacker targets the machinery that builds and deploys it instead?

The SolarWinds chain — December 2020

1
Build system compromisedNot any customer, directly.
2
Malicious code injected into a legitimate updateSigned with SolarWinds' own valid certificate.
3
~18,000 organizations installed itTrusting it completely — it looked 100% legitimate.
4
Government agencies & Fortune 500 impactedOne build-system compromise, massive downstream reach.
"The attackers never needed a bug in SolarWinds' product code — they compromised the process that builds and signs the product instead."

Compromising one vendor's build pipeline poisons software every downstream customer will voluntarily, trustingly install.