SolarWinds supply chain attackers manipulated OAuth app certificates to maintain persistence and access privileged resources including email, researchers at Proofpoint say. OAuth is an open standard for authorization that allows a third-party application to obtain access to a cloud service. U.S. authorities say supply chain attack was part of a Russian cyberespionage operation. Swiss cybersecurity firm Prodaft said Monday it had accessed several servers used by the solarWinds attackers. Researchers say that manipulated X.509 OAuth certificates played a crucial role in the solar winds attack.”]
Source: https://www.govinfosecurity.com/solarwinds-attackers-manipulated-oauth-app-certificates-a-16253