Security News > 2021 > January > Russia’s SolarWinds Attack and Software Security
Obscure software packages can have hidden vulnerabilities that affect the security of these networks, and sometimes the entire Internet.
Any system for acquiring software needs to evaluate the security of the software and the security practices of the company, in detail, to ensure they are sufficient to meet the security needs of the network they're being installed in.
Procurement contracts need to include security controls of the software development process.
Some of the groundwork for an approach like this has already been laid by the federal government, which has sponsored the development of a "Software Bill of Materials" that would set out a process for software makers to identify the components used to assemble their software.
These security requirements need to be monitored throughout the software's life cycle, along with what software is being used in government networks.
The Biden administration should prioritize minimum security standards for all software sold in the United States, not just to the government but to everyone.
News URL
https://www.schneier.com/blog/archives/2021/01/russias-solarwinds-attack-and-software-security.html
Related news
- Evil Corp's deep ties with Russia and NATO member attacks exposed (source)
- DOJ, Microsoft seize 107 domains used in Russia's Star Blizzard phishing attacks (source)
- Google Adds New Pixel Security Features to Block 2G Exploits and Baseband Attacks (source)
- WordPress LiteSpeed Cache Plugin Security Flaw Exposes Sites to XSS Attacks (source)
- EDRSilencer red team tool used in attacks to bypass security (source)
- SolarWinds Web Help Desk flaw is now exploited in attacks (source)
- ISC2 Security Congress 2024: The Landscape of Nation-State Cyber Attacks (source)
- SEC Charges 4 Companies Over Misleading SolarWinds Cyber Attack Disclosures (source)
- Stop LUCR-3 Attacks: Learn Key Identity Security Tactics in This Expert Webinar (source)
- T-Mobile US 'monitoring' China's 'industry-wide attack' amid fresh security breach fears (source)