How was SolarWinds compromised?
How did the SolarWinds hack happen? The hackers used a method known as a supply chain attack to insert malicious code into the Orion system. A supply chain attack works by targeting a third party with access to an organization’s systems rather than trying to hack the networks directly.
What percentage of an application is typically built with open source code?
One study found that 96 percent of all scanned applications contain some open source components and that the use of open source code increased from 36 percent to 57 percent over a one-year period ending in 2017. What’s more, a typical software application now contains an average of 257 open source components.
What is software supply chain attacks?
A software supply chain attack occurs when a cyber threat actor infiltrates a software vendor’s network and employs malicious code to compromise the software before the vendor sends it to their customers. The compromised software then compromises the customer’s data or system.
Who was behind SolarWinds hack?
The United States and Britain have blamed Russia’s Foreign Intelligence Service (SVR), successor to the foreign spying operations of the KGB, for the hack which compromised nine U.S. federal agencies and hundreds of private sector companies.
What companies were affected by SolarWinds hack?
Companies including Intel, Nvidia, Cisco, Belkin, and VMWare have all reportedly seen computers on their networks infected, as well as the US Treasury, Commerce, State, Energy, and Homeland Security departments. The scale of the attack means that it may be many months before the government completes its investigation.
Are open source libraries secure?
Yet, there are security risks associated with utilizing open source libraries. Over the last three years, open source security vulnerabilities have grown by about 2.5x. These vulnerabilities can present a lucrative opportunity for hackers.
How much of the Internet runs on open source?
It’s an open-source world: 78 percent of companies run open-source software. Black Duck Software and North Bridge’s survey found open-source software in businesses everywhere, but few are managing it worth a darn. The good news is that open-source software is used in the vast majority, 78 percent, of businesses.