{"id":3440,"date":"2024-05-06T18:49:30","date_gmt":"2024-05-06T23:49:30","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/supply-chain-breaches-up-68-yoy-according-to-dbir"},"modified":"2024-05-06T18:49:30","modified_gmt":"2024-05-06T23:49:30","slug":"supply-chain-breaches-up-68-year-over-year-according-to-dbir","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/06\/supply-chain-breaches-up-68-year-over-year-according-to-dbir\/","title":{"rendered":"Supply Chain Breaches Up 68% Year Over Year, According to DBIR"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltfdc3a5f418402ff0\/64f152a58e08dfbd5f942760\/Supply-Chain_Kheng_Ho_Toh_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/supply-chain-breaches-up-68-year-over-year-according-to-dbir.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/supply-chain-breaches-up-68-year-over-year-according-to-dbir.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Breaches resulting from a third party were up 68% last year, primarily due to software vulnerabilities exploited in ransomware and extortion attacks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Supply chain breaches have been <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/supply-chain-attacks-increase-78-\" rel=\"noopener\">on the rise for some time now<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. According to Verizon&#8217;s latest <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/verizon-dbir-basic-security-gaffes-underpin-bumper-crop-of-breaches\" rel=\"noopener\">Data Breach Investigations Report (DBIR)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, that rise has been extra steep in recent months. Some 15% of all breaches in 2023 involved a third party, a marked increase from 9% in 2022. Those figures have as much to do with accounting as attacking, though.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In this year&#8217;s DBIR, Verizon Business expanded its definition of &#8220;supply chain breach&#8221; to include not just compromises through vendors (e.g., Target in 2013), data custodians (MOVEit), and software updates (SolarWinds), but also vulnerabilities in third-party software.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Exploited vulnerabilities were, in fact, the most common Vocabulary for Event Recording and Incident Sharing (VERIS) action tracked as part of DBIR&#8217;s supply chain metric, followed by backdoors\/command-and-control (C2) and extortions. &#8220;Last year in the ransomware space, we saw \u2014 whether they&#8217;re researching them themselves, or buying them \u2014 [threat actors] got their hands on so many zero-day vulnerabilities,&#8221; says Alex Pinto, associate director of threat intelligence at Verizon Business and co-author of the DBIR.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But should attacks like these be considered a supply chain issue? Could organizations benefit from conflating all of these different vectors of attack together?<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Treating CVEs as a Supply Chain Issue\">Treating CVEs as a Supply Chain Issue<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Of third-party bugs, Pinto recalls, &#8220;As we looked into it, we thought this looked like it might be not just a vulnerability management problem, but a vendor management problem in some ways. That&#8217;s when we decided: &#8216;How about we try to look at this holistically?'&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To the DBIR team, addressing bugs is bigger than just patching whenever they might arise. It&#8217;s about how organizations choose and engage with their vendors. No organization can prevent every potential vulnerability in the software they use, but vendors do &#8220;leak&#8221; certain kinds of signals that might indicate their worthiness.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For example, Pinto says, &#8220;We&#8217;ve been getting more external signals recently when you think about the work that the SEC is doing. Now, when something really bad happens, [vendors] have to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/make-changes-to-be-ready-for-the-new-sec-cybersecurity-disclosure-rule\" rel=\"noopener\">tell the SEC<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. So that gives us more signals about: Are they doing a good job or not?&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In its report, Verizon Business recommended that organizations start looking at ways of making better choices &#8220;so as to not reward the weakest links in the chain.&#8221; The <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/ivanti-poor-marks-cyber-incident-response\" rel=\"noopener\">consequences of making the wrong choices<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> will inevitably be more vulnerabilities to deal with down the line.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;There are things we can control and things we cannot control in the vendor management process. So we have to take into account those kinds of external signals, and how we can use that to improve our posture and encourage our vendors to have better posture,&#8221; Pinto says.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/supply-chain-breaches-up-68-yoy-according-to-dbir\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Breaches resulting from a third party were up 68% last<\/p>\n","protected":false},"author":12,"featured_media":3441,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3440","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/supply-chain-breaches-up-68-year-over-year-according-to-dbir.jpg?fit=1278%2C677&ssl=1",1278,677,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/supply-chain-breaches-up-68-year-over-year-according-to-dbir.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/supply-chain-breaches-up-68-year-over-year-according-to-dbir.jpg?fit=300%2C159&ssl=1",300,159,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/supply-chain-breaches-up-68-year-over-year-according-to-dbir.jpg?fit=640%2C339&ssl=1",640,339,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/supply-chain-breaches-up-68-year-over-year-according-to-dbir.jpg?fit=640%2C339&ssl=1",640,339,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/supply-chain-breaches-up-68-year-over-year-according-to-dbir.jpg?fit=1278%2C677&ssl=1",1278,677,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/supply-chain-breaches-up-68-year-over-year-according-to-dbir.jpg?fit=1278%2C677&ssl=1",1278,677,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/supply-chain-breaches-up-68-year-over-year-according-to-dbir.jpg?fit=1024%2C542&ssl=1",1024,542,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/supply-chain-breaches-up-68-year-over-year-according-to-dbir.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/supply-chain-breaches-up-68-year-over-year-according-to-dbir.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/supply-chain-breaches-up-68-year-over-year-according-to-dbir.jpg?fit=1278%2C677&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3440","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3440"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3440\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3441"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3440"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3440"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3440"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}