5 commercial software attacks — and what you can learn from them
ID: e55b63ac-7a71-5c2d-b21c-93bbe2563caf
STIX ID: report--e55b63ac-7a71-5c2d-b21c-93bbe2563caf
Feed Name: ReversingLabs Blog
Date Published: 2024-10-09
Date Updated: 2026-04-29
Author: [email protected] (Jaikumar Vijayan)
This report reviews five major commercial software supply-chain incidents — Sisense (mass credential exposure via a hard-coded token), JetBrains TeamCity (multiple critical CVEs exploited by state-aligned actors), CrowdStrike (widespread outage from a faulty update), Okta (service-account credential compromise via malware on an employee laptop), and XZ Utils (maintainer-introduced backdoor) — drawing lessons on credential hygiene, CI/CD hardening, SBOMs, least-privilege/service account management, and the fragility of the open-source maintainer model.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
