• Advertise
  • Contact Us
  • About Us
  • Supplier Directory
  • SCB YouTube
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Express/Small Shipments
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Sourcing/Procurement/SRM
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Robotics
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • VIDEOS
  • WHITEPAPERS
Home » Blogs » Think Tank » The Next Supply Chain Attack Vector: Open-Source Software

Think Tank
Think Tank RSS FeedRSS

The Next Supply Chain Attack Vector: Open-Source Software

A GRAPHIC SHOWING A MAP OF THE WORLD AND CYBER SECURITY NETWORKS456.jpg

Photo: iStock.com/cemagraphics

April 7, 2023
Kevin Kirkwood, SCB Contributor

The U.S. government has made significant strides in reducing direct cyberattack risks through programs such as the Cybersecurity and Infrastructure Security Agency (CISA), as well as by issuing guidelines on enhancing responsibility and community-driven threat detection. Yet more needs to be done to prevent supply chain attacks.

An organization’s attack surface extends far beyond its own facilities. And while those territories might not be in their direct line of sight, they require the same level of cybersecurity attention. The expanding global marketplace exposes supply chains to ever-greater risk to a company's bottom line and brand.

According to one report, 97% of businesses have experienced a data security breach as a result of an inefficient supply chain. Supply chain attacks surged by 42% between 2021 and 2022, affecting approximately seven million people.

Missed Wake-Up Calls

Attacks on supply chains aren’t new. Target's infamous 2013 incident was a supply chain breach. The attackers gained access to the retailer by using credentials obtained from its HVAC vendor, Fazio Mechanical Services. Fazio had access to Target’s systems, which allowed it to remotely monitor and maintain the temperature of individual stores across the U.S. Hackers used a phishing campaign to breach Fazio’s credentials, which they then used to gain access to Target's network. Full names, phone numbers, e-mail addresses, payment card numbers and credit card verification codes were among the information stolen by the hackers.

Another major supply chain breach occurred in 2018, with Ticketmaster. Inbenta, a Ticketmaster software supplier, was compromised. A hacking group infiltrated Inbenta and introduced malicious JavaScript into the vendor’s code, which was used by the Ticketmaster website. The malicious script functioned similarly to a credit card skimmer or key logger; therefore, any data given to the website was also transferred to a drop server operated by the attacker, allowing the hacking group to steal credit card information.

Six years later, the SolarWinds hack offered another example of how a supply chain attack could affect thousands of businesses. The attacker gained access to the SolarWinds build system and uploaded a malicious DLL file, which was then distributed to SolarWinds customers. The malicious file granted remote access and went unnoticed for more than six months. And just last December, it was discovered that threat actors had been accessing GoDaddy's source code for several years, in which at least two other breaches had been linked to the same exposure. In March of 2020, 28,000 customers had their login credentials compromised by a threat actor, and in November 2021, one gained access to the company's managed WordPress code base by exploiting a compromised password. All of these incidents demand the question: why are supply chain attacks continuing to increase in 2023?

Security Issues Within the Supply Chain

Supply chain security is complicated; it requires safeguarding networks of endpoints with distinct functions. Traditionally, a supply chain network consists of hardware, software and managed services provided by third-party businesses.

The need for greater resilience, transparency and speed has transformed supply chain networks into more adaptable, digital and interconnected components. As a result, more data than ever before passes across these connections. 

The risk profile for systems managing supply chain activities is getting higher. In terms of the cybersecurity attack surface and movement of components across supply chains, attackers can exploit a security flaw in one link and compromise the functionality of the entire network.

The Supply Chain’s Weakest Link

Open-source software might be the chain's weakest link, which is especially alarming given that open-source components make up approximately 85% of applications. In 2022, there was a 742% year-over-year increase in open-source software supply chain attacks targeting vulnerabilities in upstream ecosystems such as JavaScript, Java.NET and Python.

Nevertheless, open source will continue to be used by software developers without hesitation, and this vector must be included as part of the strategy to secure a company and ensure that third-party suppliers perform their own proper security checks.

If vulnerabilities are discovered in unmaintained open-source components, the organization and its end users may be jeopardized. While difficult, many of these calamities can be avoided by implementing a vulnerability scanning methodology that employs technologies such as source code analysis (SCA), static application security testing (SAST), and dynamic application security testing (DAST). Finding and addressing known vulnerabilities is beneficial, but it doesn’t guarantee that a company is totally secure.

Overall, if an organization uses open-source software, it must be on high alert for supply chain attacks. Hackers have become more strategic in exploiting open-source software and code in recent years, and this year will be no exception. Bad actors will closely observe the code and its components to gain a comprehensive understanding of its weaknesses, and the most effective ways to exploit them.

Kevin Kirkwood is deputy chief information security officer at LogRhythm.

Supply Chain Security & Risk Mgmt Supply Chains in Crisis

RELATED CONTENT

RELATED VIDEOS

Subscribe to our Daily Newsletter!

Timely, incisive articles delivered directly to your inbox.

Popular Stories

  • A CONTAINER SHIP PLIES THE OCEAN, SILHOUETTED BY DRAMATIC CLOUDS

    Flurry of FMC Complaints Reveals Widespread Accusations of Ocean Carrier Profiteering

    Ocean Transportation
  • A CITY SCENE AT NIGHT, WITH MANY LINES OF LIGHT RISING FROM THE GROUND

    Welcome to the World of ‘Ambient’ IoT

    Data Management (Big Data/IoT/Blockchain)
  • A WOMAN'S HANDS ARE HOLDING A PILE OF SOIL ABOVE THE GROUND WITH A SMALL PLANT GROWING OUT OF IT.

    Three Developments in ESG That Will Impact Supply Chains 2023

    Regulation & Compliance
  • A LARGE WHITE WALMART TRACTOR TRAILER IS DRIVING ON A FREEWAY BEHIND A PICK-UP TRUCK ONE LANE OVER.

    Walmart Unveils New Sustainability and Waste Reduction Measures

    Supply Chain Planning & Optimization
  • A GRAPHIC SHOWING AN AERIAL VIEW OF A FOREST WITH THE SHAPE OF A TRUCK CUT OUT IN SPACES

    Seven Ways That Companies Can Make Real Progress Toward Sustainability

    Quality & Metrics

Digital Edition

Scb may 2023 lg

2023 Supply Chain ESG Guide

VIEW THE LATEST ISSUE

Case Studies

  • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

  • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

  • New Revenue for Cloud-Based TMS that Embeds Orderful’s Modern EDI Platform

  • Convenience Store Client Maximizes Profit and Improves Customer Service

  • A Digitally Native Footwear Brand Finds Rapid Fulfillment

Visit Our Sponsors

Antuit Zebra Anvyl Brother
Cleo Data Capture E2open
Eva Air Enveyo GAINSystems
Generix Geodis GEP
GreyOrange Here Holman Logistics
Infor Inmar Kinaxis
Locus Robotics Logility LogistiVIEW
Lucas Systems MCA Connect MPO
Old Dominion OneRail Overhaul
PartnerLinQ (Visionet) Port of Virginia Ryder E-commerce by Whiplash
Saddle Creek Logistics SAP Shyft
Sourcemap Tecsys TGW Systems
Verusen Workshop
  • More From SCB
    • Featured Content
    • Video Library
    • Think Tank Blog
    • SupplyChainBrain Podcast
    • Whitepapers
    • On-Demand Webinars
    • Upcoming Webinars
  • Digital Offerings
    • Digital Issue
    • Subscribe
    • Manage Your Subscription
    • Newsletters
  • Resources
    • Events Calendar
    • SCB's Great Supply Chain Partners
    • Supplier Directory
    • Case Study Showcase
    • Supply Chain Innovation Awards
    • 100 Great Partners Form
  • SCB Corporate
    • Advertise on SCB.COM
    • About Us
    • Privacy Policy
    • Contact Us
    • Data Sharing Opt-Out

All content copyright ©2023 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

Design, CMS, Hosting & Web Development :: ePublishing