Threat Actors Quick to Target (Patched) SAP Vulnerabilities

Threat actors are constantly targeting new vulnerabilities in SAP applications within days after the availability of security patches, according to a joint report issued by SAP and Onapsis.

In some cases, exploitation attempts were observed shortly after the security bugs are made public: scanning for vulnerable systems started 48 hours after patches were released, with actual exploitation attempts following roughly 24 hours later, an analysis that SAP and Onapsis conducted since mid-2020 has revealed.

Used within more than 400,000 organizations (including 1,000 government and government-owned organizations) for resource planning, management of product lifecycle, human capital, and supply chain, and for various other purposes, SAP’s applications represent an attractive target for adversaries.

During their study, the two organizations observed as many as 300 successful exploitations of SAP-specific vulnerabilities. The attacks were aimed at modifying configurations and user accounts, to ultimately access and exfiltrate business information.

“New unprotected SAP applications provisioned in cloud (IaaS) environments were discovered and attacked in less than three hours, stressing the need to “shift left” and ensure new mission-critical applications are provisioned securely from day one,” according to the report.

Sophisticated threat actors, the two organizations say, are leveraging various attack vectors to compromise organizations through unprotected SAP applications, including chaining together multiple vulnerabilities specific to SAP deployments.

The study also reveals that threat actors are making numerous brute-force attempts targeting high-privilege SAP user accounts, showing once again that maintaining secure system configurations is as important as keeping software patched at all times.

Exploited vulnerabilities include CVE-2020-6287 (also known as RECON, this critical bug has a CVSS score of 10), CVE-2020-6207 (also CVSS score of 10), CVE-2018-2380, CVE-2016-9563, CVE-2016-3976, and CVE-2010-5326. Successful exploitation of unpatched SAP bugs could lead to theft of sensitive data, financial fraud, the disruption of mission-critical business processes, and ransomware attacks, and could even force organizations to completely suspend operations.

Despite known targeting of vulnerable SAP systems, however, some organizations fail to apply the available patches in due time. Thus, together with the U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and Germany’s Federal Cybersecurity Authority (BSI), SAP and Onapsis are advising organizations to immediately apply available patches.

“SAP systems running outdated or misconfigured software are exposed to increased risks of malicious attacks. SAP applications help organizations manage critical business processes—such as enterprise resource planning, product lifecycle management, customer relationship management, and supply chain management,” CISA notes.

Organizations using SAP software are advised to perform compromise assessment on those applications, especially for Internet-facing resources, assess all applications in the SAP environment, perform misconfiguration assessments, and immediately apply all of the available patches where necessary.

Related: Scanning Activity Detected for Critical SAP SolMan Flaw

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/u-KRIGHykMk/threat-actors-quick-target-patched-sap-vulnerabilities




APT Group Using Voice Changing Software in Spear-Phishing Campaign

A sub-group of the ‘Molerats’ threat-actor has been using voice-changing software to successfully trick targets into installing malware, according to a warning from Cado Security.

The Molerats hacking group, also tagged as Gaza Hackers Team, Gaza Cybergang,DustySky, Extreme Jackal, and Moonlight, has been active since at least 2012, mainly targeting entities in the Middle East, but also launching attacks against targets in Europe and the United States.

Cado Security says that APT-C-23, believed to be part of Molerats, typically uses social engineering to trick victims into installing malware, and was previously observed impersonating women in attacks that leveraged social media sites to target soldiers in the Israel Defence Forces.

In recent attacks targeting political opponents, APT-C-23 appears to have taken the spear-phishing to a new level, through the use of voice-changing software to pose as women (the group’s members that have been identified so far are all men).

“APT-C-23 has been observed impersonating women to engage victims in conversations. As the conversations continue, the group sends video laden with malware to infect the target’s system,” Cado Security said.

While analyzing a publicly exposed server pertaining to the hacking group, Cado Security researchers identified an archive containing photos from the Instagram account of a female model, along with the installation for the voice changing application Morph Vox Pro.

“Given the context of both previous APT-C-23 attacks and the other contents of the folder, we think the most likely explanation for MorphVox being part of their toolset is that it was used to produce audio messages in a female voice to encourage targets to install their malware,” the company said.

On the same server, the researchers identified various tools employed by the attacks, such as the application used to bulk-send phishing emails, another to hack Voice over IP systems, one with example commands to find vulnerable routers, and a folder containing a Microsoft credential phishing page.

Related: Backdoors Used by Hamas-Linked APT Abuse Facebook, Dropbox

Related: New Backdoor Attacks Leverage Political Turmoil in Middle East

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/ii-bL2yFQ2Q/apt-group-using-voice-changing-software-spear-phishing-campaign




US DoD Launches Vuln Disclosure Program for Contractor Networks

The United States Department of Defense (DoD) this week announced the launch of a new vulnerability disclosure program on HackerOne to identify vulnerabilities in Defense Industrial Base (DIB) contractor networks.

Running as a pilot, the Defense Industrial Base Vulnerability Disclosure Program (DIB-VDP) covers participating DoD contractor partner’s information systems and web properties, as well as other assets within scope, and is separate from the DoD vulnerability disclosure program that already runs on HackerOne.

As part of the DIB-VDP Pilot, DoD invites the HackerOne community to remotely test the participating DoD contractors’ assets and report on any identified vulnerabilities.

Interested researchers, however, are prohibited from doing any harm to the vulnerable systems, from accessing or exfiltrating data, from compromising the privacy or safety of DoD or the contractor, as well as from sharing any information with third parties.

“Any information submitted to the DIB-VDP under this program will be used for defensive purposes – to mitigate or remediate vulnerabilities in DoD contractor information systems, networks, or applications. This research is not contributing to offensive tools or capabilities,” the program’s policy reads.

Researchers looking to participate are encouraged to read the provided guidelines and glance over the assets that are within scope of the program, as well as over the rest of the terms and conditions of the DIB-VDP.

The DIB-VDP Pilot is a voluntary event that will run for 12 months.  

Related: U.S. Gov Announces ‘Hack the Army 3.0’ Bug Bounty Program

Related: HackerOne Paid Out Over $107 Million in Bug Bounties

Related: Hackers Earn $275,000 for Vulns in U.S. Army Systems

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/0nJopxIAayM/us-dod-launches-vuln-disclosure-program-contractor-networks




Feds say hackers are likely exploiting critical Fortinet VPN vulnerabilities

Feds say hackers are likely exploiting critical Fortinet VPN vulnerabilities

The FBI and the Cybersecurity and Infrastructure Security Agency said that advanced hackers are likely exploiting critical vulnerabilities in the Fortinet FortiOS VPN in an attempt to plant a beachhead to breach medium and large-sized businesses in later attacks.

“APT actors may use these vulnerabilities or other common exploitation techniques to gain initial access to multiple government, commercial, and technology services,” the agencies said Friday in a joint advisory. “Gaining initial access pre-positions the APT actors to conduct future attacks.” APT is short for advanced persistent threat, a term used to describe well-organized and well-funded hacking groups, many backed by nation states.

Breaching the mote

Fortinet FortiOS SSL VPNs are used mainly in border firewalls, which cordon off sensitive internal networks from the public Internet. Two of the three already-patched vulnerabilities listed in the advisory—CVE-2018-13379 and CVE-2020-12812—are particularly severe because they make it possible for unauthenticated hackers to steal credentials and connect to VPNs that have yet to be updated.

“If the VPN credentials are also shared with other internal services (e.g. if they’re Active Directory, LDAP, or similar single sign-on credentials) then the attacker immediately gains access to those services with the privileges of the user whose credentials were stolen,” said James Renken, a site reliability engineer at the Internet Security Research Group. Renken is one of two people credited with discovering a third FortiOS vulnerability—CVE-2019-5591—that Friday’s advisory said was also likely being exploited. “The attacker can then explore the network, pivot to trying to exploit various internal services, etc.”

One of the most severe security bugs — CVE-2018-13379—was found and disclosed by researchers Orange Tsai and Meh Chang of security firm Devcore. Slides from a talk the researchers gave at the Black Hat Security Conference in 2019 describe it as providing “pre-auth arbitrary file reading,” meaning it allows the exploiter to read password databases or other files of interest.

Security firm Tenable, meanwhile, said that CVE-2020-12812 can result in an exploiter bypassing two-factor authentication and logging in successfully.

In an emailed statement, Fortinet said:

The security of our customers is our first priority. CVE-2018-13379 is an old vulnerability resolved in May 2019. Fortinet immediately issued a PSIRT advisory and communicated directly with customers and via corporate blog posts on multiple occasions in August 2019 and July 2020 strongly recommending an upgrade. Upon resolution we have consistently communicated with customers as recently as late as 2020. CVE-2019-5591 was resolved in July 2019 and CVE-2020-12812 was resolved in July 2020. To get more information, please visit our blog and immediately refer to the May 2019 advisory. If customers have not done so, we urge them to immediately implement the upgrade and mitigations.

The FBI and CISA provided no details about the APT mentioned in the joint advisory. The advisory also hedges by saying that there is a “likelihood” the threat actors are actively exploiting the vulnerabilities.

Patching the vulnerabilities requires IT administrators to make configuration changes, and unless an organization is using a network with more than one VPN device, there will be downtime. While those barriers are often tough in environments that need VPNs to be available around the clock, the risk of being swept into a ransomware or espionage compromise is significantly greater.

https://arstechnica.com/?p=1754203




SecureDrop Workstation Gets Post-Audit Security Refresh

The open-source SecureDrop Workstation has undergone a security makeover after a third-party security audit flagged multiple problems, including a high-risk bug that could allow an attacker to plant files on target machines.

The SecureDrop Workstation audit, conducted by Trail of Bits and financed by the New York Times, warned that the high-risk directory traversal bug could be leveraged for code execution attacks.

“The high severity finding details case where a malicious SecureDrop server could create files in arbitrary paths in the sd-app VM, which may allow for a code execution,” according to the audit report [PDF].

“When the SecureDrop Workstation client downloads a file, it stores it in a location derived from the filename returned by the server. However, since this location is not sanitized properly in all cases, an attacker who controls responses from the server can make the client save files in arbitrary paths on the filesystem. An attacker can use this vulnerability to plant files that potentially enable further vulnerabilities.”

The Trail of Bits code auditors found two cases when a malicious SecureDrop server could plant files.

Overall, the security assessment gave SecureDrop workstation a positive security bill of health. 

“We were unable to achieve a direct compromise of the Workstation from the position of an Internet-based attacker during our engagement,” Trail of Bits said, but made it clear this doesn’t imply that such a compromise exists or that SecureDrop Workstation is free of bugs.

SecureDrop Workstation is currently managed by the Freedom of the Press Foundation. Based on Qubes OS, the platform enables secure and encrypted communications between news organizations, journalists, sources and whistleblowers. It is currently being used in a limited pilot.

The Foundation said the audit report confirmed some its  assumptions around the use of virtualization to segment sensitive workloads and was pleased with the finding that the system system “represents a complex but well researched product that has been thoughtfully designed.”

None of the issues identified were directly exploitable by an attacker, and require either compromise of the SecureDrop server, or code execution in certain key VMs within the SecureDrop Workstation, the Foundation said.

Over the course of their engagement (6 person-weeks with two pen-test/code audit engineers), Trail of Bits found and documented 1 high-risk, 6 medium-risk, 7 low and 12 informational disclosure problems.

The audit confirmed that the high-severity and six of the medium-severity issues have already been patched and released, with the fixes validated by the auditing team. 

The Foundation said it is also investigating potential architectural improvements, including the creation of a custom RPC service to handle opening of files.

“In addition to addressing the findings surfaced in this report, we are also implementing feedback from current pilot participants, and planning new features around export and integration to other communication tools. We are in the process of expanding the pilot to several other news organizations, and hope to provide general availability later this year,” the Foundation said.

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. Ryan is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends. He is a regular speaker at cybersecurity conferences around the world.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/160J-vA58qQ/securedrop-workstation-gets-post-audit-security-refresh




Nine Critical Flaws in FactoryTalk Product Pose Serious Risk to Industrial Firms

Industrial automation giant Rockwell Automation on Thursday informed customers that it has patched nine critical vulnerabilities in its FactoryTalk AssetCentre product.

The vulnerabilities were discovered by researchers at industrial cybersecurity firm Claroty and they were addressed by the vendor with the release of AssetCentre v11. Previous versions are impacted.

FactoryTalk AssetCentre is designed for securing, managing, tracking, versioning and reporting information related to automation assets across an entire facility. The product is used by many industrial organizations for backup and disaster recovery, which, Claroty points out, can be very useful in case of a targeted ransomware attack.FactoryTalk AssetCentre vulnerabilities expose industrial organizations to attacks

“FactoryTalk AssetCentre is a powerful, centralized tool where project files are stored for use on any Rockwell Automation platform. The AssetCentre architecture, from a high level, includes the main server, an MS-SQL server database, clients, and remote agents,” Claroty said, noting that the product can be a “powerful target for attackers.”

The company explained, “The software agents run on engineering workstations (generally, Windows-based machines); the agents communicate with the centralized server and can accept and send commands to automation devices, such as PLCs. Project files are then updated and sent back to the server, which stores the files centrally. Operators can perform backup and restore, and version control functions from AssetCentre for all PLCs running on a factory floor, for example.”

The nine critical vulnerabilities identified by Claroty researchers — all of them have a CVSS score of 10 — can be exploited by remote, unauthenticated attackers to execute arbitrary code (due to data deserialization issues), execute arbitrary commands, modify sensitive data in the application, or launch SQL injection attacks.

Learn more about vulnerabilities in industrial systems at SecurityWeek’s ICS Cyber Security Conference and SecurityWeek’s Security Summits virtual event series

“An attacker who is able to successfully exploit these vulnerabilities could do so without authentication and control the centralized FactoryTalk AssetCentre Server and Windows-based engineering stations communicating with the server,” Claroty warned. “In short order, an attacker could own a facility’s entire operational technology (OT) network and run commands on server agents and automation devices such as programmable logic controllers (PLCs).”

In addition to an advisory from Rockwell and a blog post from Claroty, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published an advisory to warn industrial organizations about the risks associated with these vulnerabilities.

Claroty said the security holes were reported to Rockwell in October. The vendor — in addition to patches — has also shared some general security recommendations for mitigating attacks that could exploit these types of vulnerabilities.

Related: Industrial Firms Informed About Serious Vulnerabilities in Matrikon OPC Product

Related: Flaws in Rockwell Automation Product Expose Engineering Workstations to Attacks

Related: Unprotected Private Key Allows Remote Hacking of Rockwell Controllers

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/HzUSi-V9K8Y/nine-critical-flaws-factorytalk-product-pose-serious-risk-industrial-firms




DHS Gives Federal Agencies 5 Days to Identify Vulnerable MS Exchange Servers

The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) has issued a supplemental directive requiring all federal agencies to identify vulnerable Microsoft Exchange servers in their environments within five days.

Providing additional direction on the implementation of CISA Emergency Directive 21-02, which on March 3 requested federal agencies to take the necessary steps to disconnect and update Exchange servers, the new directive demands agencies to accelerate the mitigation process.

The new requirements are meant to complement the initial directive and apply to all operational Exchange servers that are either hosted by or on behalf of federal agencies and which had been connected to the Internet “at any time since January 1, 2021.”

CISA says that federal agencies did respond to the Emergency Directive and triaged and updated Exchange servers hosted in the federal enterprise, but also notes that the new directions are meant to help identify possibly undetected compromise.

“Since the original issuance of ED 21-02, Microsoft has developed new tools and techniques to aid organizations in investigating whether their Microsoft Exchange servers have been compromised. CISA also identified Microsoft Exchange servers still in operation and hosted by (or on behalf of) federal agencies that require additional hardening,” CISA said in an advisory.

Per the new directive, federal agencies are required to download and scan their environments with the latest version of Microsoft Safety Scanner (MSERT) within the next five days (by 12:00 pm Eastern Daylight Time on Monday, April 5, 2021), and report to CISA the results of the scans.

Then, the agencies should repeat the process weekly for the following four weeks, but only report any possible indicators of compromise discovered.

“MSERT only scans when manually triggered and it is updated frequently. Agencies must download the latest version of this tool before each scan. Running MSERT in Full Scan mode may cause server resource utilization to peak. Accordingly, CISA recommends agencies run the tool during off-peak hours,” CISA warns.

By April 5, agencies are also required to download and run the Test-ProxyLogon.ps1 script, as administrator, which should help identify potential attacker activity by analyzing Exchange and IIS logs. All results should be reported back to CISA.

“This script checks targeted exchange servers for signs of the proxy logon compromise described in CVE-2021-26855, 26857, 26858, and 27065. This script is intended to be run via an elevated Exchange Management Shell,” CISA explains.

The supplemental direction also provides a series of hardening requirements that federal agencies should implement by 12:00 pm Eastern Daylight Time on Monday, June 28, 2021, and which include the use of firewalls, applying software updates, ensuring that all software is still supported by vendors, and applying the principle of least privilege to minimize impact of compromise.

Related: Ransomware Gangs Targeting Vulnerable Exchange Servers

Related: Microsoft Defender Protects Against Ongoing Exchange Attacks

Related: Microsoft Ships One-Click Mitigation for Exchange Attacks

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/f0E9Mp43OqY/dhs-gives-federal-agencies-5-days-identify-vulnerable-ms-exchange-servers




Unpatched RCE Flaws Affect Tens of Thousands of QNAP SOHO NAS Devices

A pair of unpatched vulnerabilities in QNAP small office/home office (SOHO) network attached storage (NAS) devices could allow attackers to execute code remotely, according to a warning from security researchers at SAM Seamless Network.

The bugs were found to affect QNAP TS-231 SOHO NAS devices running firmware version 4.3.6.1446, but potentially impact other QNAP devices as well, provided they use the same firmware release. The TS-231 NAS, QNAP says, has already reached end of life (EOL) and might not receive software updates.

In fact, no patch has been released for the vulnerable devices although one of the flaws was initially reported during the first half of October 2020, SAM reveals. The second bug was reported in late November 2020.

“These vulnerabilities are severe in nature as they allow for full takeover of devices from the network including access to the user’s stored data, without any prior knowledge,” according to an advisory from SAM.

The first bug resides in the NAS web server, which by default uses TCP port 8080 and exists because of the lack of proper input sanitization for some APIs.

With previous remote code execution (RCE) flaws in QNAP NAS devices abusing web pages that do not require authentication, but execute code server-side, SAM’s researchers started looking at cgi files (which are stored locally on the device) that implement such pages.

During their investigation, the researchers discovered that, by leveraging HTTP requests to different cgi pages, mostly those that do not require prior authentication, they could trigger remote code execution indirectly.

“The vendor can fix the vulnerability by adding input sanitization to some core processes and library APIs, but it has not been fixed as of this writing,” SAM notes.

The second vulnerability was identified in the DLNA server, which uses default TCP port 8200, and which handles UPNP requests on this port. The bug, SAM reveals, could be abused for the execution of code on a remote NAS as well.

The security researchers deem the two security holes as being of critical severity and have refrained from providing full details on them yet. According to them, the flaws potentially impact tens of thousands of QNAP devices that are exposed to the Internet.

Related: QNAP Urges Users to Protect Against Brute-Force Attacks

Related: QNAP Warns NAS Users of ‘dovecat’ Malware Attacks

Related: Hackers Target Three-Year Old Vuln in QNAP NAS Devices 

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/29nuv1Km0YQ/unpatched-rce-flaws-affect-tens-thousands-qnap-soho-nas-devices




Kansas Man Charged with Tampering with Public Water System

The United States Department of Justice this week announced official charges against a Kansas man, for accessing and tampering with a public water system.

The man, Wyatt A. Travnichek, 22, of Ellsworth County, Kansas, is accused of accessing the computer system of the Ellsworth County Rural Water District without authorization.

The intrusion took place on or about March 27, 2019, the Department of Justice says.

Once he gained accessed to the protected computer system, Travnichek allegedly performed specific actions that resulted in shutting down processes affecting the facilities cleaning and disinfecting procedures.

These actions, the indictment claims, were intended to harm the Ellsworth Rural Water District No. 1, which is also referred to as Post Rock Rural Water District.

Travnichek, who worked for the Ellsworth County Rural Water District for roughly one year, had been tasked to remotely access the Post Rock computer system, for monitoring the plant.

If found guilty, Travnichek faces a sentence of up to 20 years in federal prison for tampering with a public water system, and up to 5 years in federal prison for reckless damage to a protected computer during unauthorized access. He also faces fines of up to $500,000, in total.

“By illegally tampering with a public drinking water system, the defendant threatened the safety and health of an entire community,” said Lance Ehrig, Special Agent in Charge of EPA’s Criminal Investigation Division in Kansas.

Related: U.S. Charges North Korean Hackers Over $1.3 Billion Bank Heists

Related: Russian Indicted for Attempting to Recruit Tesla Employee to Install Malware

Related: Feds Unseal 2018 Indictment Charging Kazakh Man in Hacks

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/35YizGfmcok/kansas-man-charged-tampering-public-water-system




After Hack, Officials Draw Attention to Supply Chain Threats

The U.S. government is working to draw attention to supply chain vulnerabilities, an issue that received particular attention late last year after suspected Russian hackers gained access to federal agencies and private corporations by sneaking malicious code into widely used software.

The National Counterintelligence and Security Center warned Thursday that foreign hackers are increasingly targeting vendors and suppliers that work with the government to compromise their products in an effort to steal intellectual property and carry out espionage. The NCSC said it is working with other agencies, including the Cybersecurity and Infrastructure Security Agency, to raise awareness of the supply chain issue.

April marks what the government is describing as the fourth annual National Supply Chain Integrity Month. This year’s event comes as federal officials deal with the aftermath of the SolarWinds intrusion, in which hackers compromised the software supply chain through malware. At least nine federal agencies were hacked, along with dozens of private-sector companies.

The NCSC said it plans to issue guidance throughout the month about how specific sectors, like health care and energy, can protect themselves.

“If the Covid-19 pandemic and resulting product shortages were not a sufficient wake-up call, the recent software supply chain attacks on U.S. industry and government should serve as a resounding call to action,” NCSC acting director Michael Orlando said in a statement. “We must enhance the resilience, diversity, and security of our supply chains. The vitality of our nation depends on it.”

Orlando and officials from the United Kingdom, Canada and Australia are participating next week in a Harvard University discussion about protecting the international supply chain.

The sheer number of steps in a product’s supply chain process give a hacker looking to infiltrate businesses, agencies and infrastructure numerous points of entry and can mean no company or executive bears sole responsibility for protecting an entire industry supply chain.

Perhaps the best-known supply chain intrusion before SolarWinds is the NotPetya attack, in which malicious code found to have been planted by Russian military hackers was unleashed through an automatic update of Ukrainian tax preparation software, called MeDoc.

Watch Sessions from SecurityWeek’s Supply Chain Security Summit on Demand

view counter

Previous Columns by Associated Press:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/1bPT-wfa-Qw/after-hack-officials-draw-attention-supply-chain-threats