I wish the NYT would clarify or retract this piece/headline https://www.nytimes.com/2021/01/06/us/politics/russia-cyber-... > Widely Used Software Company May Be Entry Point for Huge U.S. Hacking > Russian hackers may have piggybacked on a tool developed by JetBrains, which is based in the Czech Republic, to gain access to federal government and private sector systems in the United States. My company has banned Jetbr…
Out of curiosity, what would you want to see clarified? They said that it “may” be an entry point for the SW hack and, according to some National Security folks, it is being investigated. Is there reason to believe this is incorrect in some way? It may be premature and amount to nothing if Team City had nothing to do with the breach, but it doesn’t appear to be misleading or false. If it was, I’d imagine JetBrains wo…
But it wasn't -- the attackers had reconfigured the build servers to add malicious code to product builds, but their malware was targeting MSBUILD.EXE processes on startup, and would have worked just the same if SolarWinds wasn't using JetBrains at all, and those processes were started instead by Jenkins, CircleCI, or a human typing at a command line. Here's a technical writeup:
https://www.crowdstrike.com/blog/sunspot-malware-technical-a...
As to the lawsuit: JetBrains is not based in the US; a lawsuit would probably take years to reach resolution, and be a massive, expensive distraction.