{"id":11212,"date":"2022-01-24T07:00:00","date_gmt":"2022-01-24T15:00:00","guid":{"rendered":"https:\/\/formtek.com\/blog\/?p=11212"},"modified":"2021-07-22T08:04:11","modified_gmt":"2021-07-22T16:04:11","slug":"security-supply-chain-software-attacks-crack-trust-in-vendor-software","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/security-supply-chain-software-attacks-crack-trust-in-vendor-software\/","title":{"rendered":"Security: Supply Chain Software Attacks Crack Trust in Vendor Software"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.cips.org\/supply-management\/news\/2021\/april\/troubling-rise-in-supply-chain-cyber-attacks\/\" data-type=\"URL\" data-id=\"https:\/\/www.cips.org\/supply-management\/news\/2021\/april\/troubling-rise-in-supply-chain-cyber-attacks\/\">The number of cyberattacks via software supply chains<\/a> experienced double-digit percentage jumps in 2021, <a href=\"https:\/\/techhq.com\/2021\/06\/fortifying-supply-chain-security-by-tackling-endpoint-exposure\/\" data-type=\"URL\" data-id=\"https:\/\/techhq.com\/2021\/06\/fortifying-supply-chain-security-by-tackling-endpoint-exposure\/\">according to a study by the Identity Theft Resource Center (ITRC)<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.idtheftcenter.org\/key-staff\/\" data-type=\"URL\" data-id=\"https:\/\/www.idtheftcenter.org\/key-staff\/\">Eva Velasquez<\/a>, CEO of the ITRC, <a href=\"https:\/\/www.cips.org\/supply-management\/news\/2021\/april\/troubling-rise-in-supply-chain-cyber-attacks\/\" data-type=\"URL\" data-id=\"https:\/\/www.cips.org\/supply-management\/news\/2021\/april\/troubling-rise-in-supply-chain-cyber-attacks\/\">said that<\/a> \u201cwhile the number of data compromises is only up slightly, the rise in supply chain attacks is troubling. Supply chain, phishing, and ransomware attacks reflect a broader trend that cyber criminals want to exploit multiple organizations through a single point-of-attack.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A supply chain attack occurs via third-party infiltration, usually when a partner or provider inadvertently infects a network or computer system via a virus or malware.  The<a href=\"https:\/\/www.nytimes.com\/2021\/01\/02\/us\/politics\/russian-hacking-government.html\" data-type=\"URL\" data-id=\"https:\/\/www.nytimes.com\/2021\/01\/02\/us\/politics\/russian-hacking-government.html\"> SolarWinds attack in 2021<\/a> was an example of how malware embedded into a vendor&#8217;s software product can penetrate the networks using the product.  In that incident, as many as 18,000 customers were affected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/dwhitenyc\/\" data-type=\"URL\" data-id=\"https:\/\/www.linkedin.com\/in\/dwhitenyc\/\">David White<\/a>, president of the cybersecurity firm Axio, <a href=\"https:\/\/qz.com\/2030053\/what-is-a-supply-chain-cyber-attack\/\" data-type=\"URL\" data-id=\"https:\/\/qz.com\/2030053\/what-is-a-supply-chain-cyber-attack\/\">said that<\/a> \u201cwe\u2019re more and more reliant on internet-connected management tools. These tools have tremendous power and rights inside our network. Are we sure they\u2019re sufficiently protected themselves?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Historically, malware and security have played a cat and mouse game.  Every time hackers find an hole in the software that gave them access, vendors quickly follow up by patching their software to fix the problem.  But now even the security of patches is being called into question.  <a href=\"https:\/\/www.topionetworks.com\/people\/j-dale-gonzalez-5bf1594c105eb55c4e56ddde\" data-type=\"URL\" data-id=\"https:\/\/www.topionetworks.com\/people\/j-dale-gonzalez-5bf1594c105eb55c4e56ddde\">Dale Gonzalez<\/a>, chief product officer at Axio, <a href=\"https:\/\/qz.com\/2030053\/what-is-a-supply-chain-cyber-attack\/\" data-type=\"URL\" data-id=\"https:\/\/qz.com\/2030053\/what-is-a-supply-chain-cyber-attack\/\">said that<\/a> \u201cthe advice has always been patch, patch, patch, patch, patch. Do it automatically, do it as fast as you can, because we wanted a vehicle for resolving known security vulnerabilities as fast as we could.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www2.eecs.berkeley.edu\/Faculty\/Homepages\/nweaver.html\" data-type=\"URL\" data-id=\"https:\/\/www2.eecs.berkeley.edu\/Faculty\/Homepages\/nweaver.html\">Nick Weaver<\/a>, a security researcher at UC Berkeley&#8217;s International Computer Science Institute, <a href=\"https:\/\/www.wired.com\/story\/hacker-lexicon-what-is-a-supply-chain-attack\/\" data-type=\"URL\" data-id=\"https:\/\/www.wired.com\/story\/hacker-lexicon-what-is-a-supply-chain-attack\/\">said that<\/a> &#8220;supply chain attacks are scary because they&#8217;re really hard to deal with, and because they make it clear you&#8217;re trusting a whole ecology. You&#8217;re trusting every vendor whose code is on your machine, and you&#8217;re trusting every vendor&#8217;s vendor.&#8221;<\/p>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-supply-chain-software-attacks-crack-trust-in-vendor-software%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-supply-chain-software-attacks-crack-trust-in-vendor-software%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-supply-chain-software-attacks-crack-trust-in-vendor-software%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-supply-chain-software-attacks-crack-trust-in-vendor-software%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-supply-chain-software-attacks-crack-trust-in-vendor-software%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-supply-chain-software-attacks-crack-trust-in-vendor-software%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-supply-chain-software-attacks-crack-trust-in-vendor-software%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-supply-chain-software-attacks-crack-trust-in-vendor-software%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-supply-chain-software-attacks-crack-trust-in-vendor-software%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-supply-chain-software-attacks-crack-trust-in-vendor-software%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-supply-chain-software-attacks-crack-trust-in-vendor-software%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-supply-chain-software-attacks-crack-trust-in-vendor-software%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-supply-chain-software-attacks-crack-trust-in-vendor-software%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>The number of cyberattacks via software supply chains experienced double-digit percentage jumps in 2021, according to a study by the Identity Theft Resource Center (ITRC). Eva Velasquez, CEO of the ITRC, said that \u201cwhile the number of data compromises is<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/security-supply-chain-software-attacks-crack-trust-in-vendor-software\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-11212","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/11212","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=11212"}],"version-history":[{"count":4,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/11212\/revisions"}],"predecessor-version":[{"id":11217,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/11212\/revisions\/11217"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=11212"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=11212"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=11212"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}