We're not saying this is how SolarWinds was backdoored, but its FTP password 'leaked on GitHub in plaintext'
'solarwinds123' won't inspire confidence, if true Share Copy Updated SolarWinds, the maker of the Orion network management software that was subverted to distribute backdoored updates that led to the compromise of multiple US government bodies, was apparently told last year that credentials for its software update server had been exposed in a public GitHub repo. Vinoth Kumar, a security researcher, claimed on Tuesday he had made such a report to SolarWinds last November, warning that it could be used to upload files to the server. The password he said he found, in plaintext for all to...