Software Security: Too Little Vendor Accountability, Experts Say
ID: f1a05bf0-eb0b-5eaa-a849-d1a2b11926d2
STIX ID: report--f1a05bf0-eb0b-5eaa-a849-d1a2b11926d2
Feed Name: Dark Reading
Date Published: 2024-05-02
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
The article discusses efforts to hold software vendors legally accountable for insecure products, using high-profile incidents—Progress Software's MOVEit breach (impacting 600+ organizations and exposing around 40 million records) and Okta-related attacks used as initial access vectors—to illustrate how licensing, contract language, and cyber insurance have limited vendor liability; it summarizes proposed standards of care and a developer safe-harbor approach while noting meaningful legislation is likely years away.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
