Centreon Cyber Attack: More Supply-Chain Cyberattacks are in the Wind

France recently suffered a major "SolarWinds" style cyberattack.

According to ANSSI, a sophisticated group of hackers has successfully infiltrated Centreon, a French IT firm specialized in network and system monitoring that is used by many large organizations including Air France, Ecole Polytechnique, Orange, Euronews, Lacoste, Sephora and the French Department of Justice. 

The hacked organizations were using very outdated versions of Centreon's open-source IT monitoring software. The hackers breached companies running the software and installed malware to perform silent surveillance.

France's recent cyberattackwhich has several uncanny similarities to the SolarWinds exploitation that exposed thousands of U.S. government agencies, critical infrastructure organizations, and major businesses. 

Centreon confirmed that none of its primary commercial customers were hit in these cyber attacks. Only organizations that downloaded the open-source version of the Centreon app, which the company freely provides on its website, were impacted. 

These attacks have been active for years and will continue to increase in pace, scope, and boldness. 

According to the French cybersecurity agency Agence Nationale de la sécurité des systèmes d’information (ANSSI), this attack may have begun back in 2017.

Deloittes Test your Hacker IQ Proves Vulnerable to being Hacked

Every active nation-state offensive cyber team is working to establish footholds in adversaries by going through supply chain solutions. 

The success exemplified by the SolarWinds attacks has proven to nations that undermining technology supplier’s products and services is a tremendously powerful means of gaining access to many sensitive systems within a targeted nation. 

This will become a foundational element for digital spy craft in the future.

I have already posted several Cybersecurity Insights videos (YouTube channel) on the topic, will be speaking at the upcoming HMG CISO conference about the long-term ramifications, and will continue to post my thoughts on this growing threat that is not going away! 

This is the moment organizations either begin to adapt or eventually become prey. Know the risks.

Comments

Comments (5)

author
Robin A
Even the mighty Microsoft has fallen this year.
2021-02-18 20:00


author
David Cooke
Hackers aren't sleeping at night, this is unbelievable. France, USA, Germany, which country is next?
2021-02-18 20:06


author
Jason Wilbraham
During the same week, hackers penetrated French hospitals and asked for money. Theses are despicable human beings. How can you hack a hospital during a pandemic? Hackers have no morals at all.
2021-02-18 20:14


author
Richard Harvey
Centreon took ownership of the problem but can they prevent a similar attack?
2021-02-18 20:20


author
Guillaume M
Many companies run outdated XP servers with hardly any protection
2021-02-18 20:29

Trending

Loading…
Loading the web debug toolbar…
Attempt #