Media reports are coming in about a second wave of exploding communications devices used by Iran-backed Hezbollah in Lebanon, walkie-talkies this time. The reports say there were extensive casualties, with 14 dead and 450 wounded.
Following the earlier pager explosions in Lebanon, the gruesome events underline that "supply chain warfare" can be devastatingly effective and very difficult to prevent.
Supply chain compromises are nothing new however, and they can take different forms which operators of critical infrastructure must pay attention to.
In New Zealand, a spokesperson for the Port of Auckland authority confirmed the operation of its new cranes was delayed because of malware found on them after delivery.
"Our crane and cyber experts did thorough inspections of the ZPMC cranes on their arrival in 2019. Some malware was found and subsequently eradicated which is why the three new cranes took longer to be commissioned than originally anticipated."
"Our cyber security team at the port, alongside some independent experts, continue to perform regular reviews to ensure port security," the spokesperson said.
Further details on the malware in question were not provided. The National Cyber Security Centre was contacted for comment on this and the story will be updated if and when a response is available.
The crane story has been brewing for months now. Most recently, the United States House of Representatives and Department of Homeland Security released a report on the cranes made by China's state owned Zhenhua Heavy Industry - ZPMC - saying cellular modems had been found installed on ones designated for American ports.
"Throughout the course of the investigation, the Committees uncovered that cellular modems— connected to Linux computers on port cranes — were found on some ZPMC cranes delivered from China to the United States," the report said.
Port operators believed that the modems were installed to collect usage data and for diagnostics purposes, but they were not part of existing crane contracts or needed for their operation.
This could well be the case, but as the report authors point out, the information "created an obscure method to collect information and bypass firewalls in a manner that could disrupt port operations."
Nobody wants to take responsibility for the modems, with both ZPMC and its partner, Switzerland's ABB, denying any knowledge of them. The report said it's an "open secret among ports and terminal operators that throughout the process of procuring a ZPMC crane, they will be pressured to provide remote access - under the auspices of monitoring and diagnostics."
Oddly enough, the report doesn't say which cellular telco network the modems would connect to, an important technical detail that would be relatively easy to ascertain.
Supply chain security concerns are everywhere.
On the software side, supply chain attacks have become increasingly common and troublesome with many variations on the same theme. The SolarWinds attack a few years back that saw thousands of IT systems at important organisations like the US Treasury compromised, and which cost over US$100 million in direct charges to fix, is a good example.
Furthermore, re-using code so as not to reinvent the wheel is the norm for programmers; what if you can't trust the code you reuse though?
That's really at the crux of the matter: trust, and the undermining thereof. Supply chain attacks and compromises create an erosion of trust that can and will be exploited politically, because security isn't something anyone can ignore, particularly at the national level.
It doesn't mean there are easy fixes for situations when national security demands action, as the United States experience with ripping out and replacing Chinese gear made by Huawei and ZTE in telco networks has shown. Long story short, that whole programme looks like it's been filed in the too-hard drawer.
For a country that's so dependent on overseas supply chains such as New Zealand, we really do need to continue to pay attention to the potential threat, and ensure that agencies share information with each other and coordinate whenever possible. It's an additional pain that nobody asked for, and will add to the cost of business and lengthen lead times, but that's humanity for you.
Update: NCSC sent the following comment:
"The National Cyber Security Centre (NCSC) works closely with hundreds of nationally significant organisations to improve their cyber resilience and reduce their vulnerability to attack.
One of the ways we do this is through Security Information Exchanges (SIEs). These exchanges are trust groups of the NCSC that are organised into some of New Zealand’s critical sectors, including transport and logistics. The purpose of these are to support organisational cyber resilience through industry information sharing and discussions of best practices.
Additionally, through our international partnerships, we become aware of cyber security issues affecting particular sectors or types of systems and when we do, we engage directly with the relevant organisations or sectors as appropriate."
We welcome your comments below. If you are not already registered, please register to comment
Remember we welcome robust, respectful and insightful debate. We don't welcome abusive or defamatory comments and will de-register those repeatedly making such comments. Our current comment policy is here.