eSecurity Solutions Articles/Blog
Search by Keyword
Blog Categories
A Comprehensive Guide to Supply Chain Security in 2024
Published On:September 25, 2024 By: Tom Ruffolo 

On July 19, 2024, CrowdStrike illustrated the weakness of digital systems. A bad software update for CrowdStrike’s Falcon endpoint protection platform froze up an estimated 8.5 million Microsoft Windows operating systems. This disrupted airlines, banks, hospitals and government agencies worldwide.
Those updates caused systems to crash or boot into a loop – mostly among organizations using Windows machines with CrowdStrike software. Personal Windows PCs, macOS and Linux systems were mostly unaffected. The losses came to about USD 10 billion and a class action lawsuit was brought against CrowdStrike over apparently inadequate software testing.
Although not a deliberate cyberattack, this incident highlighted supply chain risks that may trouble airlines, banks and media.
Real-World Supply Chain Attacks
Supply chain security requires understanding real-life attacks that exploited supply chain vulnerabilities. They serve to illustrate both attackers’ tactics and the results of successful breaches.
1. PyPI Malware Incident (March 2023)
In March 2023, the Python Package Index (PyPI) was targeted by typosquatting-based supply chain attacks. Attackers uploaded malicious packages with fake names to exploit developers’ typographical errors while searching for packages. These packages ran scripts that collected Windows credentials and cryptocurrency wallet information to remote servers controlled by the attackers.
2. MOVEit Transfer Attack (June 2023)
Around June 2023, a vulnerability was exploited in MOVEit transfer, a secure file transfer software, in a large-scale supply chain attack. They exploited a zero-day vulnerability to execute arbitrary code on affected systems and gain unauthorized access to data in more than 600 organizations worldwide. Exploiting this vulnerability, attackers extracted sensitive files and credentials by leveraging the trust placed in the secure file transfer service.
3. Gigabyte Firmware Backdoor (Mid-2023)
In the middle of 2023, a backdoor was found in Gigabyte motherboards that attackers could exploit during firmware update. The insecure update mechanism allowed unauthorized code execution allowing attackers to retain persistent access to the system & possibly to steal sensitive data. This vulnerability was particularly grave because firmware runs low on the system and is not easily detected once installed.
The Cybercriminal Underground
The complexity of supply chain security is heightened by cybercriminals who often trade access to these networks. They target supply chains because such attacks have a more significant impact.
Imagine you’re a cybercriminal deploying ransomware. With supply chain access, you can potentially deploy it across numerous assets, unlike compromising a single asset, which wouldn’t have the same effect.
These access points typically command higher prices than standard network access due to their potential impact on multiple assets and the vast amount of data at risk.

For example, on Russian cybercrime forums, cybercriminals have been observed selling initial Active Directory access to an Israeli supply chain network for $500. While this may seem inexpensive, it’s important to understand that this is merely for initial access, which could be used for more extensive attacks.

In another instance, a cybercriminal offered access to an AT&T employee’s email inbox without multi-factor authentication (MFA) or two-factor authentication (2FA). The seller suggested that this access point could be used to launch a supply chain attack, with the access being offered for a five-figure sum.
Mitigating Supply Chain Attacks
Supply chain attacks must be prevented proactively and with multiple layers. Although no organization can ever achieve full security, the following steps can improve your organization’s security posture:
1. Thorough Vendor Risk Assessments (VRM)
Check on security practices of all vendors/suppliers, especially those that have access to sensitive data/critical systems regularly. That means looking at their security policies, incident response plans, and data protection procedures. You can find a lot of questionnaires and templates online for conducting these types of audits, such as ISO 27036.
2. Principle of Least Privilege
Implement the principle of least privilege by ensuring users/applications/systems have only the access and permissions required for their role. This involves identifying necessary permissions, implementing role-based access control (RBAC), conducting regular audits, and setting up monitoring and alerts to detect deviations from normal access patterns. Minimizing access limits the damage a compromised application or supplier can cause.
3. Vulnerability Scanning
Conduct regular vulnerability scans to discover unknown vulnerabilities in applications, including third-party code. This involves selecting appropriate tools, scheduling regular scans, prioritizing and patching identified vulnerabilities, and using scan results to continuously improve security practices. Regular vulnerability scans allow an organization to identify and patch holes quickly.
Your Next Steps With eSecurity Solutions
The recent CrowdStrike incident and discussions on cybercriminal tactics point to an increase in supply chain attacks and central points of failure exploitation – so take this risk seriously and consider mitigation for such third-party dependencies.
We at eSecurity Solutions have a suite of services to help you manage this risk. Doing a third-party risk assessment and placing security in your roadmap will give you maximum protection with the lowest cost.
We can help you identify your security gaps, develop a security roadmap and acquire, implement and manage your security Solutions. Let us help you select the right security measures for your company – click here to get in touch with us today.