Showing posts with label supply chain. Show all posts
Showing posts with label supply chain. Show all posts

Thursday, April 18, 2019

Wipro Supply Chain attack (Update-3) - This is similar to Cognizant (last year)

 Maritz Holdings Inc., sued Cognizant saying a forensic investigation determined that hackers used Cognizant’s resources in an attack on Maritz’s loyalty program that netted the attackers more than $11 million in fraudulent eGift cards.

https://krebsonsecurity.com/2019/04/wipro-intruders-targeted-other-major-it-firms/

Wednesday, April 17, 2019

Wipro Supply Chain attack (Update) - Wipro's response is NOT SATISFACTORY



Wipro’s public response so far:


  • Ignore reporter’s questions for days and then pick nits in his story during a public investor conference call.
  • Question the stated timing of breach, but refuse to provide an alternative timeline.
  • Downplay the severity of the incident and characterize it as handled, even when they’ve only just hired an outside forensics firm.
  • Say the intruders deployed a “zero-day attack,” and then refuse to discuss details of said zero-day.
  • Claim the IoCs you’re sharing with affected clients were discovered by you when they weren’t.


The source said a subsequent phishing campaign between March 16 and 19 netted 22 additional Wipro employees, and that the vendor investigating the incident has so far discovered more than 100 Wipro endpoints that were seeded with ScreenConnect, a legitimate remote access tool sold by Connectwise.com.

Additionally, investigators found at least one of the compromised endpoints was attacked with Mimikatz

The source also said the vendor is still discovering newly-hacked systems.

https://krebsonsecurity.com/2019/04/how-not-to-acknowledge-a-data-breach/

Tuesday, April 16, 2019

A chain is no stronger than its weakest link , What happens when the chain ,in this case the "supply chain" itself is weak? - "Supply Chain Attack"

Wipro Ltd. has confirmed that its network was hacked and used for mounting attacks on its customers.

“[Victims] traced malicious and suspicious network reconnaissance activity back to partner systems that were communicating directly with Wipro’s network,” according to the sources. 

The incident is emblematic of the new era of highly targeted supply-chain attacks that have begun to accelerate.

https://threatpost.com/wipro-confirms-hack/143826/

Thursday, March 14, 2019

Software Supply Chain Attack - When modern software applications, such as websites or mobile phone apps, are built using complex supply chains of third party libraries or open source components which are COMPROMISED.



No wonder, #9 in OWASP top 10 is "Using Components with Known Vulnerabilities".

In supply chain attacks, attackers leverage trusted third party vendors to deliver malware to unsuspecting customers by inserting malware into third-party code

Through the supply chain threat actors can reach a wide range of organizations due to third party code that is used by so many software engineers across all industries.

Furthermore, there is no good way to partition third party libraries or code from your organization’s in-house built code. As a result, it all runs within the same privilege.

https://blog.checkpoint.com/2019/03/13/mobile-supply-chain-attacks-are-more-than-just-an-annoyance/