Software Supply Chain Vulnerabilities: What Every Enterprise Needs to Know | TSG Ep. 922
Software supply chains face significant vulnerabilities, especially from phishing attacks that target developers. These attacks can result in widespread malware and security breaches. Many cyber attacks are simpler than they seem, highlighting the need for better verification processes. The organized nature of cybercrime is discussed, with criminal gangs using sophisticated tactics. The conversation also reflects on the anniversary of 9/11, emphasizing the importance of remembering its significance and ongoing societal issues related to violence.
Transcript
Hey everyone. Big yawn yesterday from Apple. Huh?
You're watching Textron Gang. Hey folks, we're back. And we are talking about some weird stuff because, well, a software supply chain involving the cryptographic community or the folks that make all that lovely funny money kind of just went crazy and wild.
And, uh, there was a maintainer of a, what's known as the node package manager and they were fished and then, uh, they wound up putting code into all these different tools that these folks were using. And before you knew it, this malware was everywhere and it seemed to just happen accidentally and instantaneously. And fortunately, I think they got it back under control.
But, um, IRA is this kind of like a, a, a sign of things to come because all these interdependencies in our software supply chain, it just seems to take one mistake and it takes everything down. This is a sign of what has been going on for a long, long time because at the end of the day, this was a phishing attack. You know, what happened at a high level appears to be that, you know, somebody went ahead and phished a lot of developers and basically went ahead and all these developers, you know, like change your, reset your password, like all these phishing messages do.
And basically all these developers changed their passwords. There was a man in the middle compromise of multifactor authentication. But the reality of the situation is we've seen these attacks time and time again.
Ironically, in this case, the end result from what I read was that it was essentially an option to try to steal crypto, you know, crypto coins and everything like that, which we have seen many times before in supply chain attacks. I think one of the more notorious ones, I, I don't, I, I don't, not sure I think it's bit wallet or something. I am not positive about that, but there was an incident where a major crypto wallet, basically what happened was they were compromised, not because they were compromised, but because they took a library program in an open source library program and somebody basically hacked, or I don't even think they hacked the developer of this one piece of open source software that then got pulled into the application, whatever it happened to be.
And then the criminal had full control over the crypto wallets and stole lots of money. And this happened four or five years ago, I think right now. So what we're seeing now is essentially why do criminals do this?
That's where the money is. In this case we saw it for spec, very specifically a crypto theft. The reality though is we have seen these phishing attacks time and time again.
And to see these major developers, especially with software supply chains being able to be compromised so simply, you know, and so quickly without any verification of the software, this is where the problems become. And this has been going on for a while, and this will go on as long as people still want open source software, common tool sets, without verifying and doing the analysis of the software, it's probably much more efficient to keep allowing these things to happen than to invest in all the checking that would have to go on. But we need to have much more of a rapid response going forward.
We need to have more of a verification process. And I never ever want to hear anyone's talk about stupid users being phished when this is an example of some of the top software developers in the world being phished. I'll, I'll leave it there.
Yeah, The, yeah, the, the challenge is, is that you have, when we think about just security in general, when we hear about a lot of these breaches, it's always a very simple and common breach, right? We always think that, oh, it must be some sort of sophisticated hacker that created this devastating scheme that's going to, you know, extract, you know, millions and billions of dollars from these companies. And if you think about it just within corporate America, when they have every employee go through this, how you understand cybersecurity in your company, it's how you understand phishing scams.
It's easy because you end up ignoring that thinking, ah, it's never gonna happen to me. I can detect that. So just attack the, the smart guys and you see what happens, right?
Because like I said, this is, this was a very simple way of doing this. This wasn't anything super sophisticated and they're able to just, you know, um, basically reach, you know, transfer a lot of this, um, a lot of this money within the, within the crypto space. So I think what we're seeing is that simplicity with a lot of these issues when it comes to tech and cybersecurity and breaches, is always something very simple and less sophisticated than we think.
Well, Let me just say, oh, sorry, just one quick point though. The attack itself was pretty simple and straightforward, done a lot, but there is sophistication in the targeting that went in, the research that went in, and this is where criminals are putting effort in. But you're right, the fundamental technology is simple, but don't downplay the amount of research criminals will do.
So, um, sorry, Go ahead. No, I totally agree with that. A hundred percent.
A hundred percent. But I think, think what typically happens is we think about what type of attack this is what's going to happen. We don't think, oh, developer's gonna hit with a phishing attack.
The average, anyone in the software industry would say, I doubt that would actually ever happen to these top tier developers. But yeah, there definitely was a lot of planning and sophistication, right? Simply, like I said, the best plans are the simplest in terms of how you do it.
So the amount of research, like you said, um, that they put into this was very well calculated and very well planned. Well, I think Ira hit on like what I was gonna say. So they, these gangs, 'cause they like to call them gangs, whatever, it's not necessarily that A lot of times it's nation states and it's big business and they are run like big businesses.
And if, if you're a small business wanting to get into the ransomware gang, you can go and subscribe to a SaaS service and they will provide you with the codes you need, they'll provide you with, um, with the marketing that you need. Because literally phishing is marketing and it has to be done very well. So it will trick people like these top tier developers.
So it will look authentic and, and you have to figure out who your target is. You have to figure out how to reach them, what their email address is. So the people that are doing this and, and actually the attack was pretty sophisticated.
It was pretty interesting that, that the code was obfuscated. They figured that out right away, but then it did things like it, it changed what you typed in and what they actually decided to capture and, and the output looked, uh, normal when it came back. So they did a lot of pretty neat tricks that were very elegantly done.
But those, when it looks that simple, it's never that easy. So I think the thing we miss on a lot of times when we talk about ransomware is that this is big business because there's big money behind it and they have sophisticated, um, marketing, sophisticated coding. And by the way, generative AI is helping that much be much easier for them to do Absolutely stretch.
I mean it's, yeah, I mean fundamentally like I've seen these attacks again for decades. Is there sophisticated? The problem is, I don't necessarily think the coding sophisticated, I look at this as professional.
I wrote a book called Advanced Persistent Security, making fun of the concept of advanced persistent threat because the concept is, you know, whether these are criminals or nation state, frankly doesn't matter if there's money, they will put it like North Korea is very much on the money raising. Maybe I've ran to a little bit, but you know, generally the, there's a lot of well-resourced criminal people who know exactly what these software programs are supposed to do, and this is their profession. And frankly, yes, these people are good at what they do, but if I take off the street a bunch of good developers, I don't wanna say out of Apple 'cause all the Silicon Valley's cliche, but I'm in the DC area, I could go find a lot of good developers who could develop this quality of software with this sophistication if I just say, this is your job and they would be that good.
It's about, it is the persistence. They are persistent. It's the persistence and it's doing it with style, you know, it's like falling with style I guess if you wanna another movie reference, but we've gotta expect this.
But again, I don't, you know, phishing is phishing, but I still don't fundamentally say, oh, I was tricked into divulging my two-factor authentication and saying, these are people, and the fundamental part is these people should theoretically know better that they are not all of a sudden gonna be locked out of their accounts. So we give way too much credit to technology people, especially developers and companies like the people who maintain NPM are gonna start, have to be a lot more, expect their people to be as stupid as the stupid users. They keep blaming for misusing their software that they're developing.
Absolutely agree with that. All right, I gotta pull the plug on this one guys. We're about outta time.
Hey, before we go off today though, I, I, I feel compelled to just say a few things. First of all, we're recording this show on nine 11, right? It's the 24th anniversary of, um, nine 11.
And you know, I was in New York last week with my wife and we went to make a reservation 'cause my wife's up in the city today, and we asked a young girl, a hostess at a restaurant about a reservation, and we said, you know, it's nine 11, it might be different. She said, oh yeah, that's right. Nine 11, isn't that some kind of holiday like Veterans Day or something?
Well, we've done a terrible job, I guess, of keeping our young people aware of, of, you know, of what happened on nine 11. But what it really represents that we live in a very dangerous world. And if we needed any reminder of it yesterday, nine 10 was a great reminder where, you know, whether you agree or disagree, and I'm not gonna get into it, uh, someone was shocked for their beliefs for, for stating their beliefs the same day three people were killed in a high school with gun violence.
We have a serious problem in this country, right? We don't solve things with guns. It shouldn't be solving with guns.
And, and we and people, we should never have to resort to violence to silence someone. I, I don't care whether what side of this argument you are on, it's wrong. It's, it's not American.
It's wrong and it's not healthy. So, you know, on this Friday, take this weekend, remember the victims of nine 11. Remember how it brought us together as a country, as Americans.
And um, that's all I got to say. Have a great weekend everyone. Bye-bye.


