HomeSecuritySupply chain attacks are getting worse

Supply chain attacks are getting worse

The European Union Agency for Cybersecurity (ENISA) analyzed 24 recent supply chain software attacks and concluded that existing security is no longer sufficient.

supply chain

See also: Vaccine registration system in Italy hit by ransomware attack

Recent supply chain attacks in their analysis include those via SolarWinds Orion software, CDN provider Mimecast, Codecov, and Kaseya.

ENISA focuses on Advanced Persistent Threat (APT) supply chain attacks and notes that while the code, exploits and malware were not considered “advanced”, the planning, staging and execution were complex tasks. It notes that 11 of the supply chain attacks were carried out by known APT groups.

The organization expects supply chain attacks to get much worse: “This is why new protective measures must be urgently introduced to prevent and respond to potential supply chain attacks in the future.”.

See also: Microsoft on BazarCall: Initial attacks can lead to ransomware within 48 hours

ENISA’s analysis found that attackers targeted vendor code in about 66% of reported incidents. The same percentage of vendors were unaware of the attack before it was revealed.

ENISA is calling for coordinated action at EU and has presented nine recommendations for customers and suppliers.

Recommendations for customers include:

  • identification and documentation of suppliers and service providers
  • defining risk criteria for different types of suppliers and services, such as supplier and customer dependencies, critical software dependencies, single points of failure
  • monitoring supply chain risks and threats
  • supplier management throughout the life cycle of a product or service, including procedures for handling products or components at the end of their life cycle
  • Classification of assets and information shared or accessible to suppliers and establishes relevant procedures for their access and handling.

See also: Ransomware: Common ways hackers break into a network

ENISA recommends the following to suppliers:

  • ensuring that the infrastructure used to design, develop, manufacture and deliver products, components and services follows cybersecurity practices
  • implementing a product development, maintenance and support process that is consistent with commonly accepted product development processes
  • monitoring security vulnerabilities reported by internal and external sources, including third-party data
  • maintains a list of assets that includes patch-related information.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS