CISA noted evidence of initial access vectors beyond SolarWindsâ Orion platform, and abuse of SAML authentication tokens that mirror behaviors of the actor behind the compromise. ("Peter @ Solarwinds office" by ecooper99 is licensed under CC BY 2.0) Largely lost in the fallout from yesterdayâs Capitol riots was an update on a mandatory order to federal agencies responding the SolarWinds hack. An alert from the Cybersecurity and Infrastructure Security Agency at the Department of Homeland Security pointed to evidence of initial access vectors beyond SolarWindsâ Orion platform, and abuse of SAML authentication tokens that mirror behaviors of the actor behind the compromise. An attacker gaining access to these tokens could be catastrophic for identity validation and likely requires a full rebuild of the network. The agency referenced guidance from Microsoft for further instructions.