The president ordered a board to investigate a massive Russian cyberattack. It didn't.
By not investigating how the SolarWinds hack exploited Microsoft software, the Cyber Safety Review Board missed an opportunity to prevent attacks, experts say.
CRAIG SILVERMAN,PROPUBLICA | JULY 8, 2024 06:22 PM ET
RUSSIA INDUSTRY WHITE HOUSE CYBER
After Russian intelligence launched one of the most devastating cyber espionage attacks in history against U.S. government agencies, the Biden administration set up a new board and tasked it to figure out what happened — and tell the public.
State hackers had infiltrated SolarWinds, an American software company that serves the U.S. government and thousands of American companies. The intruders used malicious code and a flaw in a Microsoft product to steal intelligence from the National Nuclear Security Administration, National Institutes of Health and the Treasury Department in what Microsoft President Brad Smith called “the largest and most sophisticated attack the world has ever seen.”
The president issued an executive order establishing the Cyber Safety Review Board in May 2021 and ordered it to start work by reviewing the SolarWinds attack.
But for reasons that experts say remain unclear, that never happened.
https://www.defenseone.com/threats/2024/07/biden-ordered-investigation-massive-russian-cyberattack-it-didn/397890/