Software supply chain remains vulnerable

Post Reply
Shane1145
Posts: 1836
Joined: Wed Sep 25, 2024 2:31 pm

Software supply chain remains vulnerable

Post by Shane1145 »

The SolarWinds megahack underscores what security mavens have been warning about for years: The software supply chain is complex, vulnerable, somewhat invisible and insufficiently protected.

For example, on Dec. 2, 2020, eleven days before the government’s announcement that it had been hacked, we quoted sources warning that the software supply chain is extremely vulnerable to cyberattacks, primarily because of the many links in the chain that are potentially invisible or unknown to design engineers. Our sources said attacks are especially likely during and after firmware updates, which is precisely how the SolarWinds hack occurred: during updates of Orion software that was trojan-ized to deliver malware.

https://www.embedded.com/software-suppl ... ulnerable/
Post Reply