Download this article in PDF format.
Supply chains have become a prime target for cyberattackers that are infiltrating these global networks and using them to defraud and disrupt organizations, and the number of breaches goes up every year. According to Cyble, supply chain attacks nearly doubled last year. Its researchers recorded 297 supply chain attacks during that 12-month period, up 93% from 154 the prior year.
That number may climb higher this year, with several high-profile incidents making news headlines recently. The latest one involves customer engagement platform Brevo, which fell victim to a supply chain attack where malicious code was injected into more than 100,000 websites, according to SecurityWeek.
It started when a threat actor exploited a vulnerability in Brevo’s handling of single sign-on to access 138 accounts, including one belonging to cryptocurrency storage provider Trezor. The attackers sent phishing emails from six of the accounts and exported the contacts of 43 accounts, the publication reports.
The attackers then came back and injected malicious scripts into the company’s websites and JavaScript files. “According to cybersecurity firm Sansec, the malware was served for roughly four hours, and more than 100,000 websites were likely impacted,” SecurityWeek says.
Cyber Security News says the Brevo attack shows how one trusted web component can multiply an intrusion quickly. This is a big problem for supply chain networks, which operate with a lot of different interconnected vendors, platforms, service providers and customers. “Instead of breaking into each website separately,” the publication says, “attackers can compromise a shared service and use its existing reach to place dangerous content in front of large audiences.”
Spreading Quickly
This year’s uptick in cybersecurity incidents has supply chain operators on high alert, and for good reason. “Cyberattacks are typically thought of as a direct breach of a company’s immediate security perimeters,” Megan Snaith writes in Cyber attacks expose supply chains as ‘weakest link.’ “But supply chain breaches, where hackers infiltrate a company via a trusted third party, have become an increasingly common attack route and cause for concern among cyber security professionals.”
The attacks themselves vary in sophistication, but in most cases they involve a hacker who places malicious code into a piece of software or hardware used by a company. Through that open portal, the bad actors gain access to more networks, with potentially hundreds of other customers and companies becoming targets downstream. “If you pop one, you get access to a thousand,” Darktrace’s Nathaniel Jones told Financial Times.
It Starts With Your Vendors
There are things companies can do to protect their networks and avoid becoming the next cyberattack headline. In “The new rules of software supply chain security: visibility, vigilance, validation,” Jon France tells companies to take a close look at any artificial intelligence (AI) integrations across the supply chain. This is important because cyberattackers are increasingly using AI to get the job done faster and more efficiently.
“Even a small amount of poisoned data can change the model’s behavior, in turn resulting in misclassifications, degraded accuracy or malicious outcomes,” he writes. “So suddenly that seemingly helpful ChatBot that is embedded in your CRM, CMS or other purpose-driven enterprise software may not be so friendly after all.”
He also tells companies to review and evaluate vendor agreements, and to focus on identifying and addressing potential weaknesses and changing needs. “A good contract with clear deliverables and expectations is part of a cybersecurity defensive strategy,” France adds, “alongside your people and your defense technologies and ongoing monitoring of systems and services.”
Take Stock Now
In “5 steps to strengthen supply chain security and improve cyber resilience,” CSO warns that cybersecurity can’t be an “isolated risk management exercise,” and it has to be baked into the organization’s broader threat assessments and risk avoidance strategies. It offers these tips to companies that want to do a better job in this area:
- Build a full inventory of your supply chain, including all software vendors, SaaS platforms, API integrations and anything else that’s hooked into your system.
- Next, classify each supplier by the impact it would have if compromised. Then, allocate the time, resources and extra scrutiny to the most vulnerable areas.
- Continuously evaluate and monitor supplier security, focusing on areas like frequency and transparency of security updates; secure development practices; and patch and vulnerability remediation programs.
- Finally, treat every supplier as an external, untrusted entity. “Even when a vendor is integrated deeply into your environment,” CSO says, “apply Zero Trust principles by validating activity continuously and limiting access to only what is necessary.”