• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Blogs » Think Tank » The Next Supply Chain Attack Vector: Open-Source Software

Think Tank
Think Tank RSS FeedRSS

The Next Supply Chain Attack Vector: Open-Source Software

A GRAPHIC SHOWING A MAP OF THE WORLD AND CYBER SECURITY NETWORKS456.jpg

Photo: iStock.com/cemagraphics

April 7, 2023
Kevin Kirkwood, SCB Contributor

The U.S. government has made significant strides in reducing direct cyberattack risks through programs such as the Cybersecurity and Infrastructure Security Agency (CISA), as well as by issuing guidelines on enhancing responsibility and community-driven threat detection. Yet more needs to be done to prevent supply chain attacks.

An organization’s attack surface extends far beyond its own facilities. And while those territories might not be in their direct line of sight, they require the same level of cybersecurity attention. The expanding global marketplace exposes supply chains to ever-greater risk to a company's bottom line and brand.

According to one report, 97% of businesses have experienced a data security breach as a result of an inefficient supply chain. Supply chain attacks surged by 42% between 2021 and 2022, affecting approximately seven million people.

Missed Wake-Up Calls

Attacks on supply chains aren’t new. Target's infamous 2013 incident was a supply chain breach. The attackers gained access to the retailer by using credentials obtained from its HVAC vendor, Fazio Mechanical Services. Fazio had access to Target’s systems, which allowed it to remotely monitor and maintain the temperature of individual stores across the U.S. Hackers used a phishing campaign to breach Fazio’s credentials, which they then used to gain access to Target's network. Full names, phone numbers, e-mail addresses, payment card numbers and credit card verification codes were among the information stolen by the hackers.

Another major supply chain breach occurred in 2018, with Ticketmaster. Inbenta, a Ticketmaster software supplier, was compromised. A hacking group infiltrated Inbenta and introduced malicious JavaScript into the vendor’s code, which was used by the Ticketmaster website. The malicious script functioned similarly to a credit card skimmer or key logger; therefore, any data given to the website was also transferred to a drop server operated by the attacker, allowing the hacking group to steal credit card information.

Six years later, the SolarWinds hack offered another example of how a supply chain attack could affect thousands of businesses. The attacker gained access to the SolarWinds build system and uploaded a malicious DLL file, which was then distributed to SolarWinds customers. The malicious file granted remote access and went unnoticed for more than six months. And just last December, it was discovered that threat actors had been accessing GoDaddy's source code for several years, in which at least two other breaches had been linked to the same exposure. In March of 2020, 28,000 customers had their login credentials compromised by a threat actor, and in November 2021, one gained access to the company's managed WordPress code base by exploiting a compromised password. All of these incidents demand the question: why are supply chain attacks continuing to increase in 2023?

Security Issues Within the Supply Chain

Supply chain security is complicated; it requires safeguarding networks of endpoints with distinct functions. Traditionally, a supply chain network consists of hardware, software and managed services provided by third-party businesses.

The need for greater resilience, transparency and speed has transformed supply chain networks into more adaptable, digital and interconnected components. As a result, more data than ever before passes across these connections. 

The risk profile for systems managing supply chain activities is getting higher. In terms of the cybersecurity attack surface and movement of components across supply chains, attackers can exploit a security flaw in one link and compromise the functionality of the entire network.

The Supply Chain’s Weakest Link

Open-source software might be the chain's weakest link, which is especially alarming given that open-source components make up approximately 85% of applications. In 2022, there was a 742% year-over-year increase in open-source software supply chain attacks targeting vulnerabilities in upstream ecosystems such as JavaScript, Java.NET and Python.

Nevertheless, open source will continue to be used by software developers without hesitation, and this vector must be included as part of the strategy to secure a company and ensure that third-party suppliers perform their own proper security checks.

If vulnerabilities are discovered in unmaintained open-source components, the organization and its end users may be jeopardized. While difficult, many of these calamities can be avoided by implementing a vulnerability scanning methodology that employs technologies such as source code analysis (SCA), static application security testing (SAST), and dynamic application security testing (DAST). Finding and addressing known vulnerabilities is beneficial, but it doesn’t guarantee that a company is totally secure.

Overall, if an organization uses open-source software, it must be on high alert for supply chain attacks. Hackers have become more strategic in exploiting open-source software and code in recent years, and this year will be no exception. Bad actors will closely observe the code and its components to gain a comprehensive understanding of its weaknesses, and the most effective ways to exploit them.

Kevin Kirkwood is deputy chief information security officer at LogRhythm.

Supply Chain Security & Risk Mgmt Supply Chains in Crisis

RELATED CONTENT

RELATED VIDEOS

Subscribe to our Daily Newsletter!

Timely, incisive articles delivered directly to your inbox.

Featured Product

Popular Stories

  • Businessman using AI agent system on laptop computer.

    AI in Supply Chain Can’t Succeed Without Foundational Systems

    Artificial Intelligence
  • A LARGE CYLINDRICAL OBJECT SHRINK-WRAPPED IN WHITE PLASTIC IS LOWERED BY CRANE ONTO A FLAT BED TRUCK ON A DOCK

    AI Boom Has European Buyers Paying Extra to Secure Gas Turbines

    Technology
  • Close-up hands of unrecognizable man holding and using smartphone standing on city street.

    Five Supply Chain Security Risks Hiding Inside Your Mobile Apps

    Supply Chain Visibility
  • 016_ai_and_data_transformation_in_distribution_v1-(540p).png

    Watch: AI and Data Transformation in Distribution

    Artificial Intelligence
  • DARKENED RACKS IN A WAREHOUSE CLUSTER AROUND A GLOWING ORB

    How to Know If Your Facility Is Ready to Automate

    Supply Chain Finance & Revenue Management

Digital Edition

2026 esg cover main scb q2 2026 cover

SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

VIEW THE LATEST ISSUE

Case Studies

  • Recycled Tagging Fasteners: Small Changes Make a Big Impact

  • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

    Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

  • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

    Moving Robots Site-to-Site

  • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

  • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

Visit Our Sponsors

4flow Arkieva Blue Yonder
Carton Cloud CoEnterprise Dassault
Duravant E2Open General Logistics Systems
Hy-Tek iGPS Korber
Lyngsoe Procurability Quinyx
SAP Sikick Systech
S&P Global Mobility TADA TransImpact
US Bank Werner Enterprises WSI
  • More From SCB
    • Featured Content
    • Video Library
    • Think Tank Blog
    • SupplyChainBrain Podcast
    • Whitepapers
    • On-Demand Webinars
    • Upcoming Webinars
  • Digital Offerings
    • Digital Issue
    • Subscribe
    • Manage Email Preferences
    • Newsletters
  • Resources
    • Events Calendar
    • 2026 Event Coverage
    • SCB's Great Supply Chain Partners
    • Supplier Directory
    • Case Study Showcase
    • Supply Chain Innovation Awards
    • 100 Great Partners Form
  • SCB Corporate
    • Advertise on SCB.COM
    • About Us
    • Privacy Policy
    • Contact Us
    • Data Sharing Opt-Out

All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

Design, CMS, Hosting & Web Development :: ePublishing