The FBI has discovered that the National Finance Center (NFC), a federal service of the U.S. Department of Agriculture (USDA), was breached by hackers, who appear to have exploited a flaw in the SolarWinds Orion software.

NFC provides payroll resources and services to approximately 170 federal agencies (i.e., more than 650,000 employees).
The US Department of Agriculture admitted to the data breach
According to the evidence available so far, the vulnerability in the SolarWinds Orion software that hackers to compromise NFC systems is not the same as the one used in December to deploy the Sunburst backdoor on SolarWinds customer systems.
Neither the FBI nor the Department have provided further details, but the Department confirmed the breach data, saying it “notified all customers (including individuals and organizations) whose data was affected.” (Later, however, another Department spokesperson said there was no breach.)

According to Reuters sources, Chinese likely hackers, are behind the hack as infrastructure and tools that have been seen in previous attacks supported by the Chinese government have been used. In addition to the federal payroll service, other government agencies have also been affected, but their number has not yet been determined.
The Chinese Foreign Ministry denied the attacks.

This specific vulnerability has been used to develop the Supernova backdoor
No further details about the vulnerability have been released, but according to Reuters, the hackers exploited the same bug that has been used to deploy the Supernova backdoor on systems with vulnerable versions of the Orion platform.
“This vulnerability in the Orion platform has been fixed in the latest updates,” SolarWinds said.
Companies that cannot immediately update systems can use a script provided by SolarWinds to temporarily protect their systems from potential attacks.
The SuperNova backdoor was deployed as a DLL file, which allowed attackers to send and execute code remotely on vulnerable systems.
At this time, we do not know exactly what the hackers' purpose behind this hack was.
Source: Bleeping Computer
