Software supply chain attacks will continue to be successful as long as the chasm between software development teams and info security teams persists. Until these two departments agree on common goals, attacks targeting software vulnerabilities will continue to cause havoc.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Recent SEC filing disclosed that 18,000 customers installed the SolarWinds backdoor while Microsoft said that it alerted 40 customers targeted by the Russian state-sponsored hackers.
CISA says that SolarWinds hack possibly affected federal, state, and local government agencies and critical infrastructure entities dealing with gas, electricity, and manufacturing.
SolarWinds hackers suspected to have breached email security provider Mimecast compromising its Microsoft 365 Exchange connection certificate, and affecting 10% of its customers.
The SolarWinds hackers are back again, this time leveraging the stolen email account of a United States federal agency to run a phishing campaign against 150 government entities in 24 countries.
Armed forces would prefer to keep the exact locations of their assets secret as they come within striking range of hostile forces. Just one soldier using a fitness app or tracking device can out this location if their fitness results are automatically posted to a public profile.
A more precise allocation of power, policy-based management, activity tracking and automated procedures can add a layer of security to a category that is inherently risky while maintaining administrators should do their tasks quickly and successfully.
Sony Interactive Entertainment has confirmed a MOVEit data breach that leaked the personal information of current and former employees and their family members.
The software supply chain is becoming the new battleground. Trust, once a cornerstone of open-source, is now under scrutiny. Developers need to exercise caution, vetting each package, no matter how reputable the source might seem.
Ensuring data protection is an uphill battle as attacker tools and strategies grow more sophisticated over time, and turning to immutable ransomware protection is critical as it offers organizations secure storage that will ensure data protection and quick recovery following an attack.










