logo

5 commercial software attacks — and what you can learn from them

ID: e55b63ac-7a71-5c2d-b21c-93bbe2563caf

STIX ID: report--e55b63ac-7a71-5c2d-b21c-93bbe2563caf

Feed Name: ReversingLabs Blog

Threat Score
88/100

Date Published: 2024-10-09

Date Updated: 2026-04-29

Author: [email protected] (Jaikumar Vijayan)

...
...

This report reviews five major commercial software supply-chain incidents — Sisense (mass credential exposure via a hard-coded token), JetBrains TeamCity (multiple critical CVEs exploited by state-aligned actors), CrowdStrike (widespread outage from a faulty update), Okta (service-account credential compromise via malware on an employee laptop), and XZ Utils (maintainer-introduced backdoor) — drawing lessons on credential hygiene, CI/CD hardening, SBOMs, least-privilege/service account management, and the fragility of the open-source maintainer model.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.