SOFTWARE SUPPLY CHAIN UNDER CYBER ATTACK

No ratings

Presented at BSidesSydney 2019 by

Supply chain attacks have become a trend in the past few years. A number of major cyber attacks were delivered through attacking software supply chain. One example of this is the CCleaner incident in which the infection of a few software developer machines resulted in massive infection of end user systems; another more recent example is ShadowHammer story in which the customers of popular ASUS Live Update Utility were served backdoored packages which the attackers managed to get digitally-signed by legitimate ASUS signatures. This talk focuses on the long history of concerns and techniques around compromising software developer systems and the impact of it on the software industry.