Security News > 2022 > June > Supply chain attacks will get worse: Microsoft Security Response Center boss
Major supply-chain attacks of recent years - we're talking about SolarWinds, Kaseya and Log4j to name a few - are "Just the tip of the iceberg at this point," according to Aanchal Gupta, who leads Microsoft's Security Response Center.
As the head of MSRC, Gupta has a unique vantage point.
Her view spans all of Microsoft's products and services, as well as visibility across industry partners' software and tools plus customers' environments including government agencies.
"The reason we will have a continuation of these supply chain attacks is our reliance on third party software and open source software is only growing," she said.
Gupta, who previously worked as a developer at Microsoft and Facebook, said she remembers when the news about the Log4j exploit broke.
"When we ship something, or when we consume something, what are the downstream dependencies? It's critical for us to be very well aware of that," and Microsoft maintains a software dependency index, which helped the MSRC respond quickly to Log4j, Gupta noted.
News URL
https://go.theregister.com/feed/www.theregister.com/2022/06/09/microsoft_supply_chain_attacks/
Related news
- Update your OpenWrt router! Security issue made supply chain attack possible (source)
- OpenWrt orders router firmware updates after supply chain attack scare (source)
- CERT-UA Warns of Phishing Attacks Targeting Ukraine’s Defense and Security Force (source)
- Microsoft enforces defenses preventing NTLM relay attacks (source)
- Ultralytics Supply-Chain Attack (source)
- 390,000 WordPress accounts stolen from hackers in supply chain attack (source)
- Hackers Use Microsoft MSC Files to Deploy Obfuscated Backdoor in Pakistan Attacks (source)
- Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain Attack (source)
- It's only a matter of time before LLMs jump start supply-chain attacks (source)
- Cross-Domain Attacks: A Growing Threat to Modern Security and How to Combat Them (source)