Almost all of the applications that we use on a daily basis are developed with building blocks, code libraries and similar. It makes sense to do it that way, because it saves time not having to reinvent the wheel for each application, and some of the functionality libraries provide can be fairly complex to code.
The flip side to that is attackers are now targeting reusable code in so-called supply chain attacks which, if successful, can compromise a large amount of systems.
Here's the audio from the RNZ Nine To Noon segment on April 11 this year, talking about supply chain attacks including the recent one on the XZ data compression utilities, and how artificial intelligence (AI) can complicate the incidents.
Just a day after, the United States Computer and Infrastructure Security Agency (CISA) issued an alert about a potentially huge supply chain attack at a popular data analytics firm called Sisense. How that breach will pan out remains to be seen, but our CERT NZ agency was involved in the work, and told us this:
"Last week the US Cyber Security & Infrastructure Security Agency (CISA) reported that Sisense, a company that provides data analytics services to businesses, had its customer data compromised. CERT NZ was made aware of this compromise through its international networks and is monitoring the situation."
"Currently the impact on New Zealand businesses is minimal and those directly affected have been contacted by CERT NZ," a spokesperson for the cybersecurity agency said.
We welcome your comments below. If you are not already registered, please register to comment
Remember we welcome robust, respectful and insightful debate. We don't welcome abusive or defamatory comments and will de-register those repeatedly making such comments. Our current comment policy is here.