logo

Software Security: Too Little Vendor Accountability, Experts Say

ID: f1a05bf0-eb0b-5eaa-a849-d1a2b11926d2

STIX ID: report--f1a05bf0-eb0b-5eaa-a849-d1a2b11926d2

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-05-02

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

The article discusses efforts to hold software vendors legally accountable for insecure products, using high-profile incidents—Progress Software's MOVEit breach (impacting 600+ organizations and exposing around 40 million records) and Okta-related attacks used as initial access vectors—to illustrate how licensing, contract language, and cyber insurance have limited vendor liability; it summarizes proposed standards of care and a developer safe-harbor approach while noting meaningful legislation is likely years away.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.