Supply Chain Threats to Industrial Control: Third-Party Compromise
ID: 7e90be83-0ac1-5172-b03b-1af07512b048
STIX ID: report--7e90be83-0ac1-5172-b03b-1af07512b048
Feed Name: Dragos Blog
This report warns that adversaries increasingly exploit third-party trust relationships to breach enterprises, highlighting techniques such as network pivoting, spear phishing from compromised partners, weaponized software updates, and credential/certificate theft. It cites notable examples—including the M.E.Doc/NotPetya outbreak and backdoored NetSarang and CCleaner software that impacted firms like FedEx and Maersk—and emphasizes that ICS environments face heightened risk. The guidance urges limiting and monitoring third-party access, using DMZs, enhancing visibility, and rigorously vetting vendors with clear disclosure and incident reporting requirements.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
