Saturday, March 25, 2023
manilastandard.net
ADVERTISEMENT
  • About
  • News
    • Top Stories
    • National
    • World News
    • Pinoy Abroad
    • Features
  • Opinion
    • Editorial
    • Columns
    • Soundbytes
  • LGUs
    • NCR
    • Luzon
    • Visayas
    • Mindanao
  • Business
    • Corporate
    • Economy & Trade
    • Stocks
    • Money
    • Agri & Mining
    • Power & Tech
    • IT & Telecom
  • Sports
    • Basketball
    • Volleyball
    • Fightsports
    • Active
    • Sports Plus
    • One Championship
    • Columns
  • Entertainment
    • TV & Movies
    • Celebrity Profiles
    • Music & Concerts
    • Digital Media
    • Columns
  • Lifestyle
    • Food
    • Culture & Media
    • Fashion
    • Health and Home
    • Leisure
    • Shopping
    • Columns
  • Others
    • Pets
    • Pop.Life
      • Newsmakers
      • Hangouts
      • A-Pop
      • Post Its
      • Performances
      • Malls & Bazaars
      • Hobbies & Collections
    • Technology
      • Gadgets
      • Computers
      • Business
      • Tech Plus
    • MS ON THE ROAD
      • Sedan
      • SUV
      • Truck
      • Bike
      • Accessories
      • Motoring Plus
      • Commuter’s Corner
    • Home & Design
      • Residential
      • Commercial
      • Construction
      • Interior
    • Spotlight
    • Gallery
      • Photos
      • Videos
    • Events
      • Seminars
      • Exhibits
      • Community
    • Biyahero
      • Travel Features
      • Travel Reels
      • Travel Logs
  • Advertise with Us
No Result
View All Result
  • About
  • News
    • Top Stories
    • National
    • World News
    • Pinoy Abroad
    • Features
  • Opinion
    • Editorial
    • Columns
    • Soundbytes
  • LGUs
    • NCR
    • Luzon
    • Visayas
    • Mindanao
  • Business
    • Corporate
    • Economy & Trade
    • Stocks
    • Money
    • Agri & Mining
    • Power & Tech
    • IT & Telecom
  • Sports
    • Basketball
    • Volleyball
    • Fightsports
    • Active
    • Sports Plus
    • One Championship
    • Columns
  • Entertainment
    • TV & Movies
    • Celebrity Profiles
    • Music & Concerts
    • Digital Media
    • Columns
  • Lifestyle
    • Food
    • Culture & Media
    • Fashion
    • Health and Home
    • Leisure
    • Shopping
    • Columns
  • Others
    • Pets
    • Pop.Life
      • Newsmakers
      • Hangouts
      • A-Pop
      • Post Its
      • Performances
      • Malls & Bazaars
      • Hobbies & Collections
    • Technology
      • Gadgets
      • Computers
      • Business
      • Tech Plus
    • MS ON THE ROAD
      • Sedan
      • SUV
      • Truck
      • Bike
      • Accessories
      • Motoring Plus
      • Commuter’s Corner
    • Home & Design
      • Residential
      • Commercial
      • Construction
      • Interior
    • Spotlight
    • Gallery
      • Photos
      • Videos
    • Events
      • Seminars
      • Exhibits
      • Community
    • Biyahero
      • Travel Features
      • Travel Reels
      • Travel Logs
  • Advertise with Us
No Result
View All Result
manilastandard.net
No Result
View All Result
Home Technology Tech Plus

Palo Alto Nerworks Research: Poor software supply chain impacts cloud infrastructure

Manila StandardbyManila Standard
November 19, 2021, 6:20 pm
in Tech Plus
Reading Time: 3 mins read
A A
Share on FacebookShare on TwitterShare on Email

High-profile software supply chain attacks such as SolarWinds and Kaseya have shed a glaring light on the disparity between organizations’ perceptions of security within their cloud infrastructure, and the reality of threats in their supply chains that can impact business catastrophically. 

Palo Alto Nerworks Research: Poor software supply chain impacts cloud infrastructure
As an example of the prevalence of misconfigurations, Unit 42 researchers analyzed public Terraform modules by number of misconfigurations (left) and types of misconfigurations and their percentages (right). Source: Unit 42 Cloud Threat Report, 2H 2021.

In the latest Palo Alto Networks’ Unit 42 Cloud Threat Report, 2H 2021, Unit 42 researchers dive deep into the full scope of supply chain attacks in the cloud and explain often misunderstood details about how they occur. They also provide actionable recommendations any organization can adopt immediately to begin protecting their software supply chains in the cloud. 

The Unit 42 team analyzed data from a variety of public data sources around the world in order to draw conclusions about the growing threats organizations face today in their software supply chains. 

Their findings indicate that many organizations may have a false sense of security in the cloud and in reality, are vastly unprepared for the threats they face. 

In addition to analyzing data, Unit 42 researchers were commissioned by a large SaaS provider (a customer of Palo Alto Networks) to run a red team exercise against their software development environment. In just three days, a single Unit 42 researcher discovered critical software development flaws that left the customer vulnerable to an attack similar to that of SolarWinds and Kaseya.

ADVERTISEMENT

Key Findings

Poor Supply Chain Hygiene Impacts Cloud Infrastructure

The large SaaS provider detailed in the red team exercise has what many would consider a mature cloud security posture. However, during the exercise, Unit 42 researchers were able to leverage misconfigurations in the organization’s software development environment, such as the presence of hardcoded IAM key pairs, that would have allowed them to control all development processes and thus conduct a successful supply chain attack.

Further, Unit 42 researchers found that 21% of the security scans they ran against the customer’s development environment resulted in misconfigurations or vulnerabilities, highlighting how process gaps and critical security flaws leave an organization exposed and susceptible to a business-halting attack.

Third-Party Code Is Rarely Trustworthy

In their research, Unit 42 researchers discovered that 63% of third-party code templates used in building cloud infrastructure contained insecure configurations, and 96% of third-party container applications deployed in cloud infrastructure contain known vulnerabilities. With this level of risk, an attacker could easily gain access to sensitive data in the cloud and even take control of an organization’s software development environment. 

Based on the Unit 42 team’s findings, it’s evident that unvetted code can quickly snowball into a security breach, especially as infrastructure flaws can directly impact thousands of cloud workloads. For that reason, it is critical that organizations understand where their code is coming from since third-party code can come from anyone, including an Advanced Persistent Threat (APT).

Conclusion: Organizations Need to Shift Security Left

Teams continue to neglect DevOps security, due in part to lack of attention to supply chain threats. Cloud native applications have a long chain of dependencies, and those links have relationships of their own. DevOps and Security teams need to gain visibility into the bill of materials in every cloud workload in order to evaluate risk at every stage of the dependency chain and establish guardrails.

Tags: KaseyaPalo Alto NetworksSolarWindsUnit 42 Cloud Threat Report
ADVERTISEMENT
Manila Standard

Manila Standard

Related Posts

Home Credit’s #SIMguradoAko campaign aims to support government’s push for SIM Registration

byMST Tech
March 24, 2023, 4:59 pm
0
8
Home Credit’s #SIMguradoAko campaign aims to support  government’s push for SIM Registration

Manila, Philippines | March 24, 2023 – Since the announcement of mandatory SIM registration last year, many have been confused about...

Read more

Shopee, PLDT, Smart upskill local sellers in partnership with Talavera, Nueva Ecija LGU

byMST Tech
March 24, 2023, 4:56 pm
0
8
Shopee, PLDT, Smart upskill local sellers in partnership with  Talavera, Nueva Ecija LGU

Shopee recently partnered with leading digital services provider PLDT and its wireless unit Smart Communications, Inc. (Smart), to educate local...

Read more

New Cisco study: Only 27% of companies surveyed in PH ready to defend vs cybersecurity threats 

byMST Tech
March 22, 2023, 4:05 pm
0
8
New Cisco study: Only 27% of companies surveyed in PH ready to defend vs cybersecurity threats 

Only 27% of organizations in the Philippines have the ‘Mature’ level of readiness needed to be resilient against today’s modern...

Read more

Transforming healthcare with latest innovations

byMST Tech
March 22, 2023, 4:00 pm
0
8
Transforming healthcare with latest innovations

Workforce shortages, mounting workloads and economic pressures are challenging healthcare providers worldwide to improve operational efficiencies and innovate care delivery...

Read more

Woman-led SME Superapp Enstack brings together female start-up leaders to discuss future of women in tech

byMST Tech
March 21, 2023, 2:43 pm
0
8
Woman-led SME Superapp Enstack brings together female start-up leaders to discuss future of women in tech

In celebration of Women’s Month, Enstack, Southeast Asia’s first SME Superapp, hosted EmpowHER, its first ever forum specifically designed for...

Read more

Kaspersky blocks close to 1M financial phishing attacks eyeing SEA businesses last year

byMST Tech
March 20, 2023, 9:31 pm
0
8
Kaspersky blocks close to 1M financial phishing attacks eyeing SEA businesses last year

Phishing is one of the most prevalent forms of cybercrime due to the minimal effort required and the fact that...

Read more

Print Edition

View More

Recent Posts

  • Rodents as Pets
  • Women power on spotlight at Zampen Open Water swim
  • PRURide is back: Gear up for PH’s biggest cycling festival
  • Ramos, Bravo top Ironkids in Davao
  • FEU brushes off UP in UAAP women’s volley
  • Fajardo, Brownlee lead 28-man natl pool for SEA Games
  • Solar company heats up the power game in PH
  • Bank executive named one of the Young Global Leaders class of 2023

Advertisement

Latest News

Fajardo, Brownlee lead 28-man natl pool for SEA Games

byManila Standard
March 25, 2023, 7:40 pm
0
8
PBA to hold special draft for Gilas  Pilipinas

A year after the Philippines conceded the gold medal in men’s basketball to Indonesia during the rescheduled 31st Southeast Asian...

Read more

Solar company heats up the power game in PH

byOthel V. Campos
March 25, 2023, 7:30 pm
0
8
Food services company links with LP4Y to empower young women

Former Energy secretary Vince Perez and Solar Pacific Energy Corp. chief executive Mike Lichtenfeld quickly bonded when they first met...

Read more

Bank executive named one of the Young Global Leaders class of 2023

byManila Standard
March 25, 2023, 7:20 pm
0
8
Food services company links with LP4Y to empower young women

EastWest Banking Corporation executive director and vice president Isabelle Gotianun Yap is part of the new crop of Young Global...

Read more

Avon honors the diversity of Filipina beauty

byManila Standard
March 25, 2023, 7:10 pm
0
8
Food services company links with LP4Y to empower young women

Driven by the desire to support women and the causes that matter most to them, globally renowned beauty brand Avon...

Read more

Food services company links with LP4Y to empower young women

byManila Standard
March 25, 2023, 7:00 pm
0
8
Food services company links with LP4Y to empower young women

Sodexo On-site Services Philippines Inc, a leading integrated facilities management and food services company has donated a P5.5 million grant...

Read more

Advertisement

ADVERTISEMENT
Facebook Twitter Instagram Youtube

ABOUT US

Manila Standard

Manila Standard website (manilastandard.net), launched in August 2002, extends the newspaper’s reach beyond its traditional readers and makes its brand of Philippine news and opinion available to a much wider and geographically diverse readership here and overseas.

Digital Edition

In tone and content, the online edition mirrors the editorial thrust of the newspaper. While hewing to the traditional precepts of fairness and objectivity, MS believes the news of the day need not be staid, overly long or dry. Stories are succinct, readable and written in a lively style that has become a hallmark of the newspaper.

Download – Today’s Paper

Search

No Result
View All Result

6th Floor Universal Re Bldg., 106 Paseo De Roxas cor. Perea Street, Legaspi Village, 1226 Makati City Philippines

Trunklines: 832-5554, 832-5556, 832-5558

© 2021 Manila Standard - Designed and Developed by Neitiviti Studios.

No Result
View All Result
  • About
  • News
    • Top Stories
    • National
    • World News
    • Pinoy Abroad
    • Features
  • Opinion
    • Editorial
    • Columns
    • Soundbytes
  • LGUs
    • NCR
    • Luzon
    • Visayas
    • Mindanao
  • Business
    • Corporate
    • Economy & Trade
    • Stocks
    • Money
    • Agri & Mining
    • Power & Tech
    • IT & Telecom
  • Sports
    • Basketball
    • Volleyball
    • Fightsports
    • Active
    • Sports Plus
    • One Championship
    • Columns
  • Entertainment
    • TV & Movies
    • Celebrity Profiles
    • Music & Concerts
    • Digital Media
    • Columns
  • Lifestyle
    • Food
    • Culture & Media
    • Fashion
    • Health and Home
    • Leisure
    • Shopping
    • Columns
  • Pop.Life
    • Newsmakers
    • Hangouts
    • A-Pop
    • Post Its
    • Performances
    • Malls & Bazaars
    • Hobbies & Collections
  • Technology
    • Gadgets
    • Computers
    • Business
    • Tech Plus
  • MS ON THE ROAD
    • Sedan
    • SUV
    • Truck
    • Bike
    • Accessories
    • Motoring Plus
    • Commuter’s Corner
  • Home & Design
    • Residential
    • Commercial
    • Construction
    • Interior
  • Spotlight
  • Gallery
    • Photos
    • Videos
  • Events
    • Seminars
    • Exhibits
    • Community
  • Biyahero
    • Travel Features
    • Travel Reels
    • Travel Logs
  • Pets
  • Advertise with Us

© 2021 Manila Standard - Designed and Developed by Neitiviti Studios.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Install Manila Standard Web App

Install App