Security

CSO

Judge mostly drags SEC's lawsuit against SolarWinds into the recycling bin

Russia-invaded software biz 'grateful for the support we have received'


A judge has mostly thrown out a lawsuit brought by America's financial watchdog that accused SolarWinds and its chief infosec officer of misleading investors about its computer security practices and the backdooring of its Orion product.

In a Thursday ruling [PDF], US federal district Judge Paul Engelmayer dismissed all of the so-called "post-SUNBURST" claims the SEC levied against SolarWinds. That is to say, all the claims against SolarWinds for what followed the 2019-2020 SUNBURST attack.

SUNBURST is the code-name for some technologically top-notch backdoor malware Russian spies planted in the IT network monitoring software suite Orion after the snoops gained access to SolarWinds' internal infrastructure.

Orion is used by some 18,000 orgs including Microsoft and US government departments of State, Treasury, Homeland Security, and Commerce, making this a classic supply-chain attack. Infect a product a lot of valuable targets use so that when they come to deploy that compromised code in their networks, now you have remote-control access to those systems.

In its lawsuit, the SEC alleged SolarWinds and CISO Timothy Brown underhandedly played down the scope and severity of the cyberattack to the world, which included investors. Following a motion by SolarWinds to have those allegations binned, Judge Engelmayer rejected those particular claims in his 107-page opinion. 

"These do not plausibly plead actionable deficiencies in the company's reporting of the cybersecurity hack," Engelmayer wrote. "They impermissibly rely on hindsight and speculation."

The judge also tossed out the SEC's claims relating to SolarWinds' internal accounting and disclosure controls and procedures. 

Engelmayer did, however, sustain the regulator's claims of securities fraud based on SolarWinds' pre-SUNBURST statement about the security of its Orion product. Those allegations being:

The SEC contends SolarWinds hid the fact that its products and practices had porous cybersecurity. The SEC contends that the company's hype misled the investing public to believe that SolarWinds' central software product had minimal vulnerability to cyberattacks. 

Other statements and filings made by SolarWinds supported the SEC's claims regarding the developer's "porous" security, the judge noted. These charges will proceed, and there's no word on whether the SEC will appeal the ruling.

A SEC spokesperson declined to comment on the judge's opinion. SolarWinds, however, applauded the decision.

"We are pleased that Judge Engelmeyer has largely granted our motion to dismiss the SEC's claims," a SolarWinds spokesperson told The Register. "We look forward to the next stage, where we will have the opportunity for the first time to present our own evidence and to demonstrate why the remaining claim is factually inaccurate."

The spokesperson also said the company is "grateful for the support we have received thus far across the industry, from our customers, from cybersecurity professionals, and from veteran government officials who echoed our concerns, with which the court agreed." ®

Send us news
3 Comments

Tech firms to pay millions in SEC penalties for misleading SolarWinds disclosures

Unisys, Avaya, Check Point, and Mimecast settled with the agency without admitting or denying wrongdoing

Critical hardcoded SolarWinds credential now exploited in the wild

Another blow for IT software house and its customers

Wanted. Top infosec pros willing to defend Britain on shabby salaries

GCHQ job ads seek top talent with bottom-end pay packets

Just how private is Apple's Private Cloud Compute? You can test it to find out

Also updates bug bounty program with $1M payout

Five Eyes nations tell tech startups to take infosec seriously. Again

Only took 'em a year to dish up some scary travel advice, and a Secure Innovation … Placemat?

Windows Themes zero-day bug exposes users to NTLM credential theft

Plus a free micropatch until Redmond fixes the flaw

Sophos to snatch Secureworks in $859M buyout: Why fight when you can just buy?

Private equity giant Thoma Bravo adds another trophy to its growing collection

The billionaire behind Trump's 'unhackable' phone is on a mission to fight Tesla's FSD

Dan O'Dowd tells El Reg about the OS secrets and ongoing clash with Musk

Millions of Android and iOS users at risk from hardcoded creds in popular apps

Azure Blob Storage, AWS, and Twilio keys all up for grabs

Beijing claims it's found 'underwater lighthouses' that its foes use for espionage

Release the Kraken!

Perfctl malware strikes again as crypto-crooks target Docker Remote API servers

Attacks on unprotected servers reach 'critical level'

Merde! Macron's bodyguards reveal his location by sharing Strava data

It's not just the French president, Biden and Putin also reportedly trackable