Software supply chain security is broader than SolarWinds and Log4J • TechCrunch

[ad_1]

SolarWinds and Log4j have made software supply chain security issues a topic of intense interest and scrutiny for businesses and governments alike.

SolarWinds was a terrifying example of what can go wrong with the integrity of software build systems: Russian intelligence services hijacked the software build system for SolarWinds software, surreptitiously adding a backdoor to a piece of software and hitching a ride into the computer networks of thousands of customers. Log4J epitomizes the garbage-in, garbage-out problem of open source software: If you’re grabbing no-warranties code from the internet, there are going to be bugs, and some of these bugs will be exploitable.

What’s less talked about, though, is that these attacks represent only a fraction of the different types of software supply chain compromises that are possible.

Let’s take a look at some of the lesser-known, but no less serious, types of software supply chain attacks.

Unauthorized commits

This class of attacks describes an unauthorized user compromising a developer laptop or a source code management system (e.g., GitHub) and then pushing code.

A particularly famous example occurred when an attacker compromised the server hosting the PHP programming language and inserted malicious code into the programming language itself. Although discovered quickly, the code, if not corrected, would have enabled widespread unauthorized access across large swaths of the internet.

The security vendor landscape is selling a pipedream that “scanners” and “software composition analysis” wares can detect all of the critical vulnerabilities at the software artifact level. They don’t.

Fortunately, recently developed tools like Sigstore and gitsign reduce the probability of this type of attack and the damage if such an attack does occur.

Publishing server compromise

Recently an attacker, potentially the Chinese intelligence services, hacked the servers that distribute the Chinese messaging app MiMi, replacing the normal chat app with a malicious version. The malware allowed the attackers to monitor and control the chat software remotely.

This attack stems from the fact that the software industry has failed to treat critical points in the software supply chain (like publishing servers or build systems) with the same care as production environments and network perimeters.

Open source package repository attacks

From the Python Package Index, which houses Python packages, to npm, the world’s software now literally depends on vast stores of software packages, the open source software programmer’s equivalent of the Apple App Store.

[ad_2]

Source link

We will be happy to hear your thoughts

Leave a reply

https://thesunnysides.com/wp-content/bonus-new-member/

https://www.fastagram.fr/wp-includes/pragmatic-play/

https://equipatex.com.br/wp-includes/slot88/

https://trendingfashionhub.com/wp-includes/slot-bet-100/

https://becfe.com/wp-includes/slot88/

https://teccord.com/wp-includes/slot777/

https://eshottairfield.com/wp-content/slot777/

https://nassaugolf.com/wp-includes/slot-resmi/

https://loanmart.co.in/wp-includes/slot777/

https://www.rishabhdeomicrominerals.in/wp-includes/slot88/

Slot

Slot777

Slot Bet Kecil

Slot88

slot777

slot88

https://simarj.org.br/wp-content/slot777/

https://www.hontrade.fi/slot-resmi/

https://psychprovider.com/wp-content/slot-bet100/

https://wznh.org/wp-content/slot88/

https://monika-boettcher.com/wp-content/slot-bet-100/

https://www.herbanaturalcolour.com/wp-content/slot88/

RTP

Slot Deposit

Slot Bet Kecil

Slot88

Slot Bet 100

Slot88

Slot88

Slot Bet 100

Slot88

Slot bet 100

Slot777

Slot

Slot PG Soft Bet 200

Pragmatic Play

Slot Bet 200

Situs Slot88

Slot Bet 200

Slot88 Gacor

https://fanboyscollectors.com/wp-includes/slot777/

https://flamencomv.com.ve/wp-includes/sbobet/

https://cafe-bazilio.ru/slot-bet-100/

https://irancar.co/wp-content/mahjong-ways/

https://mehravaraneshahr.com/wp-content/slot-bet-100/

https://webem.ru/wp-includes/slot88/

https://mesure-pro.com/wp-content/slot-resmi/

https://nhero.ru/wp-content/slot-deposit-pulsa/

https://cafe-bazilio.ru/slot-bet-100/

https://irancar.co/wp-content/mahjong-ways/

https://1goodstore.com/wp-content/slot88/

https://tribaltravellaos.com/wp-admin/slot777/

https://morganwantads.com/wp-includes/slot-server-platinum/

https://www.guuf.org/wp-includes/slot-gacor/

https://turkuazmobilya.net/wp-includes/slot-server-platinum/

https://passioncode.fr/wp-includes/slot88/

https://bistrotagines.se/wp-content/sbobet/

https://www.oligoflowersbeauty.it/wp-content/slot-resmi/

https://www.birkatshalom.org/wp-includes/slot-server-platinum/

Bonus New Member

akun pro platinum

Slot Server Platinum

Slot88

pragmatic

Slot88

bonus new member

https://plosefit.com/slot-kamboja/

https://www.socalimplants.com/

https://hernanbrito.online/

https://yourcbdsite.com/

https://www.esquimmo.com/olympus/

https://newsbell.website/wp-content/pragmatic-play/

https://ostalux.com/bonus-new-member/

https://sadirista.com/wp-content/rtp-slot/

https://burhanienterprise.net/wp-content/sbobet-euro/

https://apk.urbanciaga.com/wp-content/starlight-princess/

https://givebacktocommunity.org/wp-content/pragmatic-play/

https://www.vishwaarogyasena.com/wp-includes/slot-bonus/

https://psdwing.com/rtp-slot/

https://susanamendezjewelry.com/wp-content/sbobet-euro/

https://bidirdioglu.com/wp-includes/starlight-princess/

https://programacion.click/aztec-gems

https://successionquest.com/slot-bonanza

https://paggitech.com/starlight-princess/

https://rocmont.com/slot-qris

https://tonimarengo.es/slot-bonus/

Situs Judi Bola

Situs Judi Bola

Sbobet

Sbobet

Sbobet

judi bola online

judi bola online

daftar sbobet

Judi Bola

Judi Bola

Judi Bola

Judi Bola

Situs Judi Bola

sbobet88