Compromised Software Code Poses New Systemic Risk to U.S. Critical Infrastructure
ID: 656b69d2-ba9f-59e7-98bd-6b5d11bdc947
STIX ID: report--656b69d2-ba9f-59e7-98bd-6b5d11bdc947
Feed Name: Dark Reading
Fortress Information Security analyzed SBOMs for 2,233 products used in U.S. utilities and found over 9,000 unique vulnerabilities (including 855 highly exploitable issues) and 3,841 instances of Known Exploited Vulnerabilities; 25% of components and 90% of products contained code from Chinese developers, and 20 common components accounted for the majority of critical vulnerabilities—the report warns this represents systemic supply-chain risk to power, oil & gas, and communications infrastructure and calls for remediation of high-risk components and removal of risky code.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
