When AppSec Scanners Become a Supply Chain Attack Vector
Specialized application security scanning tools embedded in the development pipeline can do wonders to harden code and bolster software supply chain security. But if engineering teams aren't careful, these security scanners can also become a gateway for attacks deep in the supply chain.
The development and security worlds saw that scenario play out in March with broad supply chain attacks that compromised development environments for two different open source security projects, which served poisoned versions of Trivy and KICS to unsuspecting software engineering teams. The attacks were part of broader supply chain attacks by TeamPCP to commit widespread credential theft and fraud.
Next week at the Black Hat USA conference in Las Vegas, another security researcher will demonstrate a different way attackers can use security tools to their advantage. This attack takes less effort because it doesn't require full compromise of the vendor's development environment. All it requires is asking...
Copyright of this story solely belongs to darkreading.com. To see the full text click HERE