In 2023, the cybersecurity landscape changed in three significant ways. The Securities and Exchange Commission cut the allowed reporting period following a security breach to just four days. Artificial intelligence began to be used in cyberattacks. And after retreating in 2022, ransomware came back stronger than ever.In response to these threats, cybersecurity buyers, vendors, influencers and decision makers worked to improve their practices around ransomware prevention, privacy and third-party risk, vulnerability management, cloud security, and identity and access management. Yet respondents in several CyberRisk Alliance Business Intelligence surveys reported more than a few challenges in meeting these goals.The following is the second of a five-part series about how security practitioners struggled or, in some cases, made significant headway throughout 2023. Here, we focus on the risks posed to privacy and security by third-party software and vendor relationships.
The SolarWinds supply-chain hack of 2020, which in October led the SEC to charge the company CISO with fraud, seems to have inspired North Korean state-sponsored hackers. Over the course of 2023, Pyongyang was tied to supply-chain hacks of 3CX VoIP software, of the JumpCloud cloud-directory-provider, of the Zoho ManageEngine ServiceDesk, of VMConnect, and of CyberLink media-playing software.Ironically, SolarWinds’ charges had nothing to do with reporting time, and the company would likely have met the new SEC four-day notification deadline had the attack taken place in 2024. (The SEC alleges that SolarWinds told investors its systems were secure even as it knew of many unresolved security issues.)Publicly traded companies, especially those in the healthcare industry, will need to keep the new SEC reporting rules, along with the more stringently enforced FTC regulations, in mind going forward.The North Korean supply-chain attack on CyberLink was made possible by malicious Python packages placed in the online repository PyPI. It was one of several such supply-chain attacks involving open-source software. In February, 15,000 phishing packages were found in the NPM repository, and so many spam packages were uploaded to NPM in April that the repository briefly went offline.Supply-chain attacks on GitHub involved "repojacking," or taking over abandoned usernames, along with old-fashioned typosquatting to lure users to deceptively named tools. Fake vulnerability exploits and fake proofs of concept on GitHub spread malware to security researchers and wannabe black-hats alike.The widespread availability of code-writing AI tools like Microsoft’s Copilot, already part of GitHub, raised the stakes of third-party software security. AI can “hallucinate” the existence of imaginary code libraries in public software repositories, creating blank slates into which attackers can sneak malicious code through “hallucination squatting.”
Misplaced trust
Fifty-seven percent of all respondents to a January 2023 CRA Business Intelligence survey of 209 IT and security professionals in the U.S. said their organizations had suffered a security incident or data breach related to a third-party partner in the previous 24 months. Fifty-two percent of those said that the attack stemmed from a software vendor.Third-party software vulnerabilities were seen as the gravest threat posed by third-party relationships, with 60% of respondents rating them between 5 and 7 on a 1-7 scale of potential risk."The third-party ecosystem has become complex, and the open-source software system has been attacked and is an easy target," said one survey respondent. "Without having clear visibility into the remediation process, it poses a big risk."
2024 to-do list:
If you're a for-profit healthcare provider, plan for tougher FTC enforcement of data-breach rules (non-profit providers are regulated at the state level).
Perform risk assessments of third-party software and third-party vendor relationships.
Consider using a software bill of materials (SBOM) to keep track of third-party components.
Paul Wagenseil is a custom content strategist for CyberRisk Alliance, leading creation of content developed from CRA research and aligned to the most critical topics of interest for the cybersecurity community. He previously held editor roles focused on the security market at Tom’s Guide, Laptop Magazine, TechNewsDaily.com and SecurityNewsDaily.com.
Research from Ipsos, commissioned by Optus, indicates that one in three Australian small businesses have experienced a cyber incident, yet many remain underprepared.
NCAF 2.0 is a refined maturity model designed to assess cybersecurity efforts across various development stages, evaluating both the process and outcomes of national strategies.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news