3 September 2021

Autodesk admits it was victim of the SolarWinds supply-chain attack


Autodesk admits it was victim of the SolarWinds supply-chain attack

Autodesk, a software company that makes CAD software for manufacturing, has confirmed it was targeted as part of the SolarWinds supply-chain attack last year.

In a SEC filing Autodesk said that it identified a compromised server and immediately took steps to contain and remediate the incidents.

"While we believe that no customer operations or Autodesk products were disrupted as a result of this attack, other, similar attacks could have a significant negative impact on our systems and operations," the company said.

An Autodesk spokesperson told BleepingComputer that the compromised SolarWinds server was discovered on December 13, 2020. Attackers planted a backdoor called Sunburst on the server, but besides this implant no other malware was discovered on the compromised server.

"Autodesk’s Security team has concluded their investigation and observed no malicious activity beyond the initial software installation," the Autodesk representative said.


Back to the list

Latest Posts

Dropbox says hackers breached its Sign eSignature platform and stole sensitive data

Dropbox says hackers breached its Sign eSignature platform and stole sensitive data

The attackers accessed authentication tokens, MFA keys, hashed passwords, and customer info.
2 May 2024
New Cuttlefish malware steals credentials from SOHO routers

New Cuttlefish malware steals credentials from SOHO routers

Cuttlefish implements the functionality that allows it to execute HTTP and DNS hijacking.
1 May 2024
ZLoader malware resurfaces with anti-analysis feature

ZLoader malware resurfaces with anti-analysis feature

The trojan made a comeback around September 2023 after lying dormant for almost two years.
1 May 2024