criticalUSAMultiAPT29 (Cozy Bear)
Impact
~18.000 organisasi terinfeksi; 9 agensi federal AS & 100+ perusahaan kena spionase.
Initial vector
Supply chain (Orion build server)
Malware / tooling
SUNBURST
Lessons learned
- Verifikasi integritas build pipeline
- SBOM & code signing kuat
- Threat hunting LotL pasca-update