Skip to content

Podcasts/Best episodes

Best podcast episodes on the SolarWinds hack

Beginning in at least March 2020, attackers used a compromised component of SolarWinds' Orion network management software to break into US government agencies, critical infrastructure operators, and private companies. CISA also flagged abuse of SAML authentication tokens in the campaign, and in April 2021 the US government formally named Russia's foreign intelligence service, the SVR, as responsible.

Sources: cisa.gov, bidenwhitehouse.archives.gov

8 episodes from 7 shows. Dates and lengths are from each show's own feed.

  1. 01

    Malicious Life

    Special: The Solarwinds Hack

    · 35 min · Beginner

    A special recorded two weeks after disclosure: the clearest plain-language walk through what happened and why it mattered.

  2. 02

    Talkin' Bout [Infosec] News

    Webcast: Discussing Implications of the SolarWinds Breach(es)

    · 76 min · Practitioner

    John Strand, Jonathan Ham, and Jake Williams on SUNBURST and SUPERNOVA, explicitly without the hype.

  3. 03

    Identity at the Center

    #84 - Solorigate Recap with Robb Reck

    · 45 min · Practitioner

    Ping Identity's CISO reads the campaign through an identity and Zero Trust lens three months in.

  4. 04

    Behind the Binary by Google Cloud Security

    EP04 Stephen Eckels - A Journey From Game Modding to SolarWinds: How One Gamer Became a Renowned Reverse Engineer

    · 66 min · Expert

    A Mandiant FLARE reverse engineer who worked on the SUNBURST backdoor explains how it was found.

  5. 05

    CyberWire Daily

    SolarWinds, SUNBURST, and supply chain security. [CyberWire-X]

    · 35 min · Practitioner

    How affected organizations worked out what was breached and for how long, beyond ejecting the intruders.

  6. 06

    The Lawfare Podcast

    Dmitri Alperovitch on SolarWinds and Microsoft Exchange

    · 38 min · Practitioner

    Dmitri Alperovitch on how the US should respond to SolarWinds and the Exchange hacks.

  7. 07

    CISO Tradecraft

    #246 - Tim Brown on SolarWinds: What Every CISO Should Know

    · 44 min · Practitioner

    SolarWinds' own CISO walks through the timeline and what other security leaders should take from it.

  8. 08

    The Lawfare Podcast

    Lawfare Daily: Shoba Pillay and Jennifer Lee on the Dismissal of Charges Against the SolarWinds Corporation and Timothy Brown

    · 36 min · Expert

    The legal aftermath: why most of the SEC's case against SolarWinds and its CISO was dismissed.