Extending the requirement for vulnerability disclosure policies from federal agencies to their suppliers is not a quick fix for supply chain security issues.
The attackers behind the SolarWinds breach also gained access to and downloaded some Mimecast source code repositories.
Confidential threat intelligence sharing could help prevent the next large-scale intrusions, tech executives say.
Microsoft said the SolarWinds hackers were able to view and download some source code components for Azure, Exchange, and Intune.
SolarWinds has fixed two newly discovered bug in Orion, one of which can lead to remote code execution.