Warning on SolarWinds-like supply-chain attacks: 'They're just getting bigger'
- Reference: 1677843193
- News link: https://www.theregister.co.uk/2023/03/03/solarwinds_supplychain_security/
- Source link:
"It was similar to a fraternity rush - the best experience I never want to do again," Scales, head of incident response at Mandiant, told The Register . "It was quite intense. Little did we know we were going to be in the middle of the supply-chain attack of the decade."
This, of course, was [1]SolarWinds attack, which has since been attributed to [2]Russia's Cozy Bear gang, and in addition to being the most high-profile supply-chain breach, it was also during the COVID-19 lockdown, so the IR team's war room was entirely virtual.
More than two years later, "I don't think we've improved much at all," he said. "It seems that supply chain attacks are just on the rise." And these days, criminals are especially keen on attacking open source software libraries, he noted.
[3]Feeling VEXed by software supply chain security? You're not alone
[4]Uncle Sam orders federal agencies to step up scans for govt IT security holes
[5]Supply chain attacks will get worse: Microsoft Security Response Center boss
[6]Germany advises citizens to uninstall Kaspersky antivirus
Still, there are valuable lessons to be learned from SolarWinds, and Scales has some good tips on how companies can protect themselves and what organizations should do if they find themselves in a similar situation.
As Scales told us: "This problem is not going away — it's just going to get bigger." ®
[7]
Get our [8]Tech Resources
[1] https://www.theregister.com/2020/12/14/solarwinds_fireeye_cozybear_us_government/
[2] https://www.theregister.com/2021/04/15/solarwinds_hack_russia_apt29_positive_technologies_sanctions/
[3] https://www.theregister.com/2023/02/28/supply_chain_security_chainguard/
[4] https://www.theregister.com/2022/10/04/cisa_software_vulnerability_directive/
[5] https://www.theregister.com/2022/06/09/microsoft_supply_chain_attacks/
[6] https://www.theregister.com/2022/03/15/kaspersky_germany_antivirus/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZAIntlUHml2c4XFEFnaaSwAAAE4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[8] https://whitepapers.theregister.com/
I was going to say citation needed but:
https://www.theregister.com/2020/12/16/solarwinds_github_password/
This FTP password may well have played a role in the initial access.
But the code to subvert the build process, if true, was really a state-of-the-art operation.
If those guys got hold of the sealed DOJ indictments trove, I do not expect the ones they have been waiting to "catch if traveling" will be caught anytime soon, if ever.
USA has such a huge footprint and outdate software platforms, that some more than 10-yeard-old code / exploits still function over there, in some industries.
Is it only me who doesn't want to watch a 12 minute video?
Say what?
When I can use handwaving and lipreading to get code into the computer faster I might switch from being text based. I definitely can read faster than y'all can drawl. Text is compressed data!
Not much improved and not much likely to
The approach to shoring up secutiy is quite often to throw money at some consultants/security software/hardware etc.
While often these can improve and aid in securing systems, the problem is, has been, and will be cultural. As long as you have devs/executives/managers/etc that see even basic secure practices as bothersome or annoying (or even an affront to their ego) the attacks will continue to succeed. As long as you have sysadmins/IT managers/engineers unwilling to put their foot down and say no because that would be bad customer service, bad 'teamwork', or just not good soft skills, the attacks will continue to succeed.
No amount of money can protect you from being attacked if you store the ftp password in plain text on a public github repo. Sure, people like to make these attacks out to be super sophistcated spy v. spy level activitie. Writing the sophisticated tools, or listening in on the sophisticated communications, or injecting the sophisticated code is really just normal dev work in many cases. Gaining the access is often simple and about as unsophisticated as you can get while being the single most important part of the attack.
Honestly, until we start doling out consequences for leaving the door open instead of giving companies a pass beacuse "the attack was so expertly sophistacted" is how it is reported, people will continue to "prop the back door open with a rock" if you will.
The spin, each line quoted from the article:
>nation-state hack
>the supply-chain attack of the decade
>attributed to Russia's Cozy Bear gang
>most high-profile supply-chain breach
The reality:
The password for the update server was stored in a public github repo
The password was solarwinds123