Contact Us
[contact-form-7 id="ceb4db8" title="Contact form 1"]

Most companies make use of a supply chain, which is a connection between a company and the suppliers it uses. There are plenty of things that can be in a supply chain and there can be many steps, but the main thing to know is that the product goes to the buyer in the last steps. These products can go through different countries, companies, software, and even people.
When it comes to cybersecurity and information security, it is important to recognize the vulnerabilities that can exist in the supply chain. Realistically, anything can be exploited, so it’s a good idea to take measures to circumvent these situations. There are many ways to do that, including due diligence, monitoring, and third-party audits.
With advancing technology, there are plenty of ways that bad actors can disrupt a supply chain. A hacker may try to get to the target through a trusted service provider or a program that provides a company with functionality. One of the most impactful ways that they can do this is to get into a trusted supplier’s legitimate software updates.
If a bad actor infiltrates something like a trusted update, malware can be pushed to a whole company, or worse, the world. There have been plenty of examples of this. One of these malicious groups was able to get into a big supplier’s database to push out a bad piece of code or programming to infect millions of computers worldwide. It is a scary thought, but proper cybersecurity defenses can stop such things.
Updates to software is only one way. There are also things that a user may install themselves, like a browser update or an add-on or extension. If a bad actor accesses an account that produces one of these extensions, it can cause a lot of problems, leading to secret back doors in the programs. One small code injection, a pushed update, and an update notification for its users can lead to thousands, of not hundreds of thousands of compromised accounts.
Over the past few decades, there have been plenty of scares and attacks that have alerted people to the possibility of bad actors in their businesses. While the company may have occasional IT audits, some may overlook the importance of their due diligence.
At the time, CCleaner was one of the most-used programs to clean out the Windows Registry of unused or unnecessary registry files. Bad actors didn’t target Piriform Software’s network directly. They targeted the system that made the software, getting access to the source code to inject code into it. With this code, the hacker group was able to push out a new update with the backdoor in it.
While smaller, everyday users were targeted in this attack, there were also bigger corporations that were hacked because of it. Until the time it was discovered, big companies like Samsung, ASUS, Sony, and even Intel. CCleaner was later updated to remove this malicious code, but a lot of damage had already been done. It is said to be safe to use today, but even then, they lost many customers’ trust.
One of the earliest and most well-known supply chain attacks happened to ASUS back in July of 2017. ASUS is a huge company, worth well over $15 billion dollars, and is a renowned and respected name in the technology sphere. However, they fell victim to a supply chain attack that affected millions of users across the globe. It was discovered only two years later back in 2019.
Bad actors were able to infiltrate ASUS’s older builds for laptop updates, managing to put their own malicious code in, and push it out through ASUS’s Live Update Utility. With these tools, they simply pushed out the update with the malicious code which appeared legitimate and official. Over a million users downloaded this malicious update, installing backdoors to all of the ASUS laptops that had it installed.
Back in 2023, a worldwide cyber attack was initiated by a Russian hacking group, leading to thousands of organizations being hacked, including British Airways and the BBC. The bad actors discovered a zero-day vulnerability in the software, using it to gain entry into many sensitive databases. With this access, they were able to distribute malware into thousands of devices across the world.
In 2024, websites using a popular bit of code call Polyfill.io were compromised, which led to hundreds of thousands of websites directing traffic to malicious and dangerous sites. Some of these websites included the Warner Bros. website, Hulu, and various others. Polyfill.io was used by millions of websites, so it’s somewhat surprising that only a fraction of that were compromised. Experts have told websites to remove this code, but there are still some lingering domains that are connected.
While these attacks may be worrying to many, there are plenty of things that you can do to defend against supply chain cyberattacks. While third-party cybersecurity firms can assist with these things, there are also things you can do for your organization.
One of the most important things a business can perform is their due diligence. This is the basics of many cybersecurity plans, ranging from verification to implementation. When it comes to risks and vulnerabilities, this is where firms will go over each and every asset of an entity that is being considered. Not only does this include things like governance and access, but supply chain as well.
With proper due diligence, a cybersecurity firm (or an entity who is looking to hire the cybersecurity firm) can make sure that all vulnerabilities are contained and taken care of. Each organization or service should be examined thoroughly and it should be done often, not only making sure they are they being safe when it comes to information security, but to keep your business safe as well.
While usually part of due diligence, making sure that deeper levels of a network cannot be accessed in the case of a breach. This can be done with an internal penetration test as well, where the cybersecurity firm will test how an entity, be it a hired organization or a bad actor, to see how they can move laterally through a system.
This means that when someone gets access to a part of the server, the test will see how far and how deep they can get with their current credentials. It’s always a good idea to keep a close eye on the status of access and authentication, considering this is how many bad actors are able to move through a system undetected for a while.
When it comes to supply chain attacks, there’s only so many things that you can do. One of the best ways to be prepared is to assume that you will be hacked at some point. With this mindset, the organization will take proactive steps and keep cybersecurity in mind more often than not. Security awareness training can help with this as well, but no business is impervious.
There is a concerning rise of supply chain attacks that have been happening across the globe. More and more people have fallen victim to these attacks through no fault of their own. It has become easier for bad actors to get into older authentication methods and less secure browser extensions and add-ons. Bad actors have also been able to take over apps and inject malicious code there.
Due diligence and constant surveillance are always beneficial for any cybersecurity posture, but it’s especially important for supply chain defenses. Going through entities like merchants, suppliers, and various other businesses is a crucial part to keep your network safe. Bad actors go for the weakest link in a chain supply, so make sure that all of your links are solid and protected.