logo

Compromised Software Code Poses New Systemic Risk to U.S. Critical Infrastructure

ID: 656b69d2-ba9f-59e7-98bd-6b5d11bdc947

STIX ID: report--656b69d2-ba9f-59e7-98bd-6b5d11bdc947

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-12-05

Date Updated: 2026-04-21

...
...

Fortress Information Security analyzed SBOMs for 2,233 products used in U.S. utilities and found over 9,000 unique vulnerabilities (including 855 highly exploitable issues) and 3,841 instances of Known Exploited Vulnerabilities; 25% of components and 90% of products contained code from Chinese developers, and 20 common components accounted for the majority of critical vulnerabilities—the report warns this represents systemic supply-chain risk to power, oil & gas, and communications infrastructure and calls for remediation of high-risk components and removal of risky code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.