VOOZH about

URL: https://thenewstack.io/lessons-learned-from-2021-software-supply-chain-attacks/

⇱ Lessons Learned from 2021 Software Supply Chain Attacks - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2022-02-24 06:31:13
Lessons Learned from 2021 Software Supply Chain Attacks
contributed,sponsor-aqua-security,sponsored,sponsored-post-contributed,
Security

Lessons Learned from 2021 Software Supply Chain Attacks

The number and impact of last year's attacks highlight the fact that application security teams face a new challenge that will require innovative thinking.
Feb 24th, 2022 6:31am by Eran Orzel
👁 Featued image for: Lessons Learned from 2021 Software Supply Chain Attacks
Feature image via Pixabay.
Aqua Security sponsored this post. Insight Partners is an investor in Aqua Security and TNS.

In 2021, the world woke up to a surge in an attack vector that had been a security risk for many years, one that the security community could no longer neglect: software supply chain attacks. Following the SolarWinds attack in late 2020, software companies of all sizes, across all industries, began facing an increased number of targeted and organized supply chain attacks. This enhanced threat resulted in significant system downtime, monetary loss and reputational damage to businesses worldwide.

When Did Random Attacks Become a Pattern?

Eran Orzel
Eran is chief customer and revenue officer and founding member of Argon Security, the leader in software supply chain security acquired by Aqua Security. Prior to joining Argon, he held several roles at Check Point Software Technologies, most recently as the global head of strategic sales and partnerships, where he led and played a significant role in the rapid growth of Check Point’s major business growth engines. Eran is an experienced and innovative business leader with over 20 years of experience in sales leadership and go-to-market operational roles in cybersecurity and enterprise software.

Throughout 2021, supply chain attacks were rapidly increasing in number and sophistication.

This represents a notable shift in attackers’ approach, now focusing their efforts on breaching software suppliers. This allows them to leverage paths that are implicitly trusted, yet less secure, and to establish a way to breach many victims with one attack, by proxy.

The high risk of software supply chains is, in part, attributed to the fact that a successful attack may affect a large number of companies that use the breached supplier’s software.

The SolarWinds attack is a good example of the potential damage of supply chain attacks. In this nation-state attack against the networking tools vendor SolarWinds, about 18,000 of its customers were exposed as a consequence of using SolarWinds’ breached software.

As many as 250 of these exposed organizations suffered targeted attacks, including governmental agencies, such as the U.S. Pentagon, and top enterprises, such as Microsoft and FireEye.

A Turning Point for Software Supply Chain Security

The SolarWinds attack is considered one of the largest and most sophisticated supply chain attacks to date and exemplifies the devastating potential of supply chain attacks. It directed attackers’ attention to the software supply chain’s comparatively low security status among organizations and was the trigger for a wave of supply chain attacks that followed. The SolarWinds attack received a lot of media coverage and inspired a global wave of security awareness and improvement initiatives focused on reducing the risk of supply chain attacks.

In February that year, Alex Birsan, an information security consultant and bug-bounty hacker, tested the exposure of enterprises to a supply chain attack technique that uses automated DevOps practices to compromise pipelines. This tactic, known as dependency confusion, results in malicious public libraries being incorporated into projects instead of the trusted private libraries of the same name. Birsan was able to hack into Apple, Microsoft and dozens of other top companies during this experiment, illustrating that even companies that highly prioritize security can fall victim to implicit shortcomings in the software supply chain.

SolarWinds was followed by a similar build-time code-manipulation attack in which attackers penetrated the Codecov product’s software supply chain, manipulating the build process to inject malicious code into its software and using the software update mechanism to distribute the malware to Codecov customers.

Not long after, on May 12, 2021, President Biden’s Executive Order on Improving the Nation’s Cybersecurity was released, emphasizing, for the first time, the need to enhance software supply chain security.

In July, the attack on Kaseya raised awareness of the immediate and downstream effects of supply chain attacks. In this attack, a managed service provider software was used to distribute the REvil ransomware to the managed service provider’s customers, causing significant downtime and revenue loss.

👁 Image

Visualizing where the biggest attacks compromise the software supply chain

Unfortunately, these examples are not isolated cases, and the number of supply chain attacks has since steadily increased with the most popular approach being software dependency poisoning. In November alone, we saw three attacks against popular npm packages (UA-Parser-JS, COA, and RC), each with millions of downloads per month. This malicious tactic has proven quite effective and further stresses the need for the security community to shift their attention to and address this highly damaging potential attack vector.

The past year’s final incident would come on December 9, when the Log4Shell vulnerability was discovered and forced software vendors into a patching frenzy. Shortly after the discovery, attackers started to exploit this popular package and take advantage of this vulnerability to launch their attacks.

Aqua Security is the largest pure-play cloud native security company, providing the freedom to innovate and accelerate digital transformations. Aqua enables customers to capture the benefits of cloud native without sacrificing the security of their supply chains and production environments. Aqua Security and TNS are under common control.
Learn More
The latest from Aqua Security

Main Lesson Learned from 2021 Attacks Analysis

Examining the success rate and consequent damage of the many attacks in 2021, one of the most evident details is that current security tools and practices are not adequate for preventing supply chain attacks. Traditional application security testing cannot detect supply chain attacks, which often exploit trusted software artifacts rather than the vulnerabilities targeted by such tools.

Additionally, established Cl/CD and DevOps pipelines rely on implicit permissions to enable rapid commits and deployment, implementing security controls at the end of this process — far too late to preclude malicious activity.

For organizations to stay secure, there is an increasing need for new protective methods and solutions that are built to address the unique characteristics of supply chain attacks.

Supply Chain Attack Vectors Still Waiting for a Solution

The number and impact of the past year’s attacks highlight the fact that application security teams face a new challenge that will require innovative thinking. Most AppSec teams lack the resources, budget and knowledge to sufficiently address the risk of supply chain attacks. This is further complicated by the need for cooperation from development and DevOps teams.

For more insights into software supply chain security trends, explore the full 2021 Software Supply Chain Security Report.

Aqua Security is the largest pure-play cloud native security company, providing the freedom to innovate and accelerate digital transformations. Aqua enables customers to capture the benefits of cloud native without sacrificing the security of their supply chains and production environments. Aqua Security and TNS are under common control.
Learn More
The latest from Aqua Security
TRENDING STORIES
Eran is chief customer and revenue officer and founding member of Argon Security, the leader in software supply chain security acquired by Aqua Security. Prior to joining Argon, he held several roles at Check Point Software Technologies, most recently as...
Read more from Eran Orzel
Aqua Security sponsored this post. Insight Partners is an investor in Aqua Security and TNS.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Aqua Security, Pragma, Kaseya, SolarWinds.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.