Executive Summary
- On July 19th 2022, Bitsight announced it had discovered critical vulnerabilities in a popular vehicle GPS tracker (MiCODUS MV720) potentially allowing hackers to remotely disable entire fleets of corporate supply vehicles, thereby inducing supply chain disruptions.
- The discovered vulnerabilities could present significant threats to an organization’s supply chain. Organizations relying on third parties using this device could experience business disruption, significant financial loss, and reputational damage if a hacker successfully disables a supply chain partner’s vehicles.
- Billions of Internet of things (IoT) devices worldwide present a new cybersecurity era, creating unorthodox supply chain threats that are difficult to identify and manage. Given the opacity of IoT security, Bitsight suspects many other IoT devices to be vulnerable to exploitation.
- Organizations must rethink supply chain risk, prioritizing the formation of a modern cyber supply chain risk management program. Those with existing programs should promptly reassess the program’s priorities to better align with today’s expanding attack surface.
The modern attack surface is expanding, presenting new challenges to the status quo of cyber supply chain risk management. Let’s analyze the evolving landscape, and highlight key shifts important to your organization.
Organizations must rethink supply chain risk
Third parties can present risk to your organization in a multitude of ways. Whether that risk originates from a third party’s poor patching cadence, botnet infections, or via other areas of concern, the cybersecurity performance of your supply chain partners can significantly impact your organization.
Recent events suggest supply chain risk may be more complicated than once thought. Bitsight recently discovered critical vulnerabilities in a popular vehicle GPS tracker (MiCODUS MV720) potentially allowing hackers to remotely disable entire fleets of corporate supply vehicles, among other things. This means organizations relying on a third party using the MV720 could see deliveries abruptly come to a halt, presenting threats of financial loss, reputational damage, and of course supply chain disruption.
The news was yet another indication that Internet of things (IoT) devices are rapidly disrupting the status quo of supply chain risk management. IoT devices are proliferating worldwide, predicted to reach 31 billion units by 2025, up from 14 billion in 2021. This rapid growth coupled with subpar security standards across the IoT spectrum means it is likely that many more devices have vulnerabilities yet to be discovered. In this climate, organizations could be unknowingly exposed to one or more critical supply chain risks.
The risks do not stop at IoT devices – enterprise software solutions continue to be found vulnerable. Bitsight found that nearly 200,000 organizations were potentially vulnerable to the recent Atlassian zero-day vulnerability. SaaS products offered by your supply chain partners will continue to be found vulnerable, threatening the confidentiality, integrity, and availability of your sensitive data.
Security leaders must rethink cyber supply chain risk, forming a strategy appropriately considering the modern attack surface.