NPCC Security Bulletin


Published
December 14, 2020
Security Bulletin
NPCC is publishing this compliance bulletin to engage and inform NPCC entities on aspects of Bulk Power System security, reliability, and compliance
SolarWinds Security Advisory
On December 14, 2020 SolarWinds Issued a Security Advisory concerning some of their products. Entities that have deployed SolarWinds products in their environments should:
- Review DHS CISA Emergency Directive 21-01.
- Assess their SolarWinds systems to see if the vulnerability is applicable.
- Assess and deploy patches per the entity patching procedure.
- Review logs to see if the vulnerability was exploited and report if necessary.
Currently, known victims of this supply chain attack are the US Treasury, Commerce Department, US NTIA, and FireEye.
NPCC is dedicated to the continued reliability of the bulk power system in Northeastern North America
