• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Software Supply Chain Attacks Are A Growing Threat

    October 3, 2022 Alex Woodie

    There’s a lot going on in the world right now, so you probably don’t need something more to worry about. But the cat-and-mouse world of cybersecurity never sleeps, and one of the threats keeping the good guys up at night right now is the growing risk of software supply chain attacks. Unfortunately, security through obscurity won’t provide as much protection for the IBM i server this time around.

    Just what is a software supply chain attack? According to the U.S. government’s Cybersecurity and Infrastructure Security Agency (CISA), a software supply chain attack occurs when “a cyber threat actor infiltrates a software vendor’s network and employs malicious code to compromise the software before the vendor sends it to their customers.”

    Software supply chain attacks can involve proprietary software as well as software that’s distributed via open source. It can take the form of malicious files surreptitiously added to vendor software update websites or open source repositories, or it can even involve the actual insertion of malicious code directly into otherwise innocent software products.

    Long anticipated by cybersecurity professionals as other avenues of attack were squeezed out, the first documented supply chain security attack occurred in 2014. That’s when Russian cybercriminals exploited vulnerabilities in the Web servers used by industrial control and SCADA system vendors to update customers systems.

    According to a 2014 Security Week story, the hackers used the vulnerabilities to install a remote access Trojan (RAT) named Havex in the updates for at least three ICS and SCADA vendors’ products. (SCADA systems, including those running on IBM i servers, apparently are prime targets for malevolent souls.)

    Software supply chain attacks provide a new vector for malware to infiltrate the enterprise. (Image source: NIST)

    After a few early successes, supply chain security attacks proliferated, with at least seven documented cases targeting various products in 2017, including the infamous notPetya attack, which originated with a Russian compromise of a popular tax product in Ukraine but quickly spread around the world. Other targets include Android and iOS operating systems and Python and JavaScript libraries, according to 2017 NIST paper titled Software Supply Chain Attacks. The Kaspersky antivirus software has also been implicated in supply chain attacks, according to the feds.

    Cybercriminals began using this novel method of corrupting victims’ systems because they “are an efficient way to bypass traditional defenses and compromise a large number of computers,” the NIST says in its paper. When they target well-known brands in enterprise software, like SolarWinds, which was the victim of a supply chain software attack in early 2021, they can use the trust that customers have in these vendors and their products against them.

    That’s a powerful force, the NIST says in its paper.

    “Software supply chain attacks are particularly bothersome and insidious because they violate the basic and assumed trust between software provider and consumer,” NIST says. “Customers have been correctly conditioned to buy and install software only from trusted sources and to download and use patches or updates only from authorized vendor sites. Now, customers must be wary of performing those basic, proper and prudent cybersecurity tasks when purchasing software and maintaining systems, since even authorized resources may be compromised.”

    The Log4j vulnerability that surfaced at the end of 2021 adds another twist to the software supply chain security saga. By itself, the Log4j flaw was bad enough–it landed a perfect 10 on the 10-point CVSS v3 rating scale. Exploiting the zero-day flaw in Log4j versions 2.0 and 2.14.1 is relatively easy for the moderately skilled cybercriminal.

    But because the open source logging framework is used so widely by other Java-based software, the flaw created a domino effect of security vulnerabilities in other products. Prominent IBM i products, like the heritage version of IBM i Navigator, contained the vulnerable version of Log4j and would not be updated, according to IBM.

    The damage didn’t stop there, as various other of IBM’s Java-based products for IBM i contained the vulnerable version of Log4j, including WebSphere Application Server, Integrated Web Services Server (IWS), Integrated Application Server (IAS). IBM i ACS, and OmniFind Text Search Server.

    The Log4j vulnerability is so pervasive that IBM maintains a list of products not impacted by it. That list contains more than 500 products not impacted by Log4j, and more than 230 that are impacted by it. Java is also widely used in the IBM i, including by many software vendors. However, it’s unknown how many of these vendor products were impacted by Log4.

    The fact that security vulnerabilities are emerging in otherwise trustworthy products is a cause for concern. But flaws in open source software may have a chilling effect in some emerging markets.

    In its April 2021 paper Defending Against Software Supply Chain Attacks, CISA described an attack that took place with PyPI, the popular Python Package Index. Researchers discovered 12 malicious libraries loaded into the PyPI distribution that used so-called “typosquatting” tactics. The attack led users who were thinking they were installing a popular Python library called django to instead download malicious clones with names like “djago” and “dajngo.”

    “The malicious libraries contained the same code and functionality of those they impersonated,” CISA wrote. “But they also contained additional functionality, including the ability to obtain boot persistence and open a reverse shell on remote workstations.”

    Not surprisingly, this has had a chilling effect on Python users. According to Python data science tool provider Anaconda, 40 percent of organizations it recently surveyed say they’re pulling back on their use of open source data science software due to security concerns.

    Python-based data science programs aren’t a huge driver of workloads on the IBM i, at least not yet. However, open source software is a growing driver of workloads on IBM i. The anything-goes nature of supply chain security attacks shows that nobody is safe, not even back-office systems like IBM i with a growing appetite for open source.

    RELATED STORIES

    IBM Accelerates New Nav Development Following Log4j Issue

    Critical Log4j Vulnerability Hits Everything, Including the IBM i Server

    SolarWinds Hack Raises Concern for IBM i Shops

    Is Information Overload Hurting IBM i Security?

    IBM i Data Vulnerable, Security Report Says

    Verizon Outlines Disturbing AS/400 Breach At Water District

    Share this:

    • Share on Reddit (Opens in new window) Reddit
    • Share on Facebook (Opens in new window) Facebook
    • Share on LinkedIn (Opens in new window) LinkedIn
    • Share on X (Opens in new window) X
    • Email a link to a friend (Opens in new window) Email

    Tags: Tags: cybersecurity, IAS, IBM i, IBM i ACS, Integrated Application Server, Integrated Web Services Server, IWS, Java, Log4j, OmniFind Text Search Server, Python

    Sponsored by
    FalconStor

    Simplify Secure Offsite Data Protection for IBM Power with FalconStor Habanero™

    IBM i teams are under growing pressure to ensure data is protected, recoverable, and compliant—without adding complexity or disrupting stable environments.

    FalconStor Habanero™ provides secure, fully managed offsite data protection purpose-built for IBM Power. It integrates directly with existing IBM i backup tools and processes, enabling reliable offsite copies without new infrastructure, workflow changes, or added operational overhead.

    By delivering and managing the service end-to-end, FalconStor helps organizations strengthen cyber resilience, improve disaster recovery readiness, and meet compliance requirements with confidence. Offsite copies are securely maintained and available when needed, supporting recovery, audits, and business continuity.

    FalconStor Habanero offers a straightforward way to modernize offsite data protection for IBM i: focused on simplicity, reliability, and resilience.

    Learn More

    Share this:

    • Share on Reddit (Opens in new window) Reddit
    • Share on Facebook (Opens in new window) Facebook
    • Share on LinkedIn (Opens in new window) LinkedIn
    • Share on X (Opens in new window) X
    • Email a link to a friend (Opens in new window) Email

    Guru: Aliases — Underused and Unappreciated IBM i 7.3 Loses Standard Support On September 30, 2023

    Leave a ReplyCancel reply

TFH Volume: 32 Issue: 65

This Issue Sponsored By

  • ProData
  • WorksRight Software
  • ARCAD Software
  • New Generation Software
  • Manta Technologies

Table of Contents

  • IBM i 7.3 Loses Standard Support On September 30, 2023
  • Software Supply Chain Attacks Are A Growing Threat
  • Guru: Aliases — Underused and Unappreciated
  • We Need Some Insight From You
  • IBM i PTF Guide, Volume 24, Number 40

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Inside The Encryption Key Management Changes In IBM i 7.6
  • FalconStor Moved To The Blue Lagoon, And Is Poised For Growth Because Of It
  • Guru: Claude’s SQL Tip
  • Astera Makes Extracting Legacy Report Data an AI Specialty
  • IBM i PTF Guide, Volume 28, Number 27
  • Welcoming The New IBM i Chief Architect And Other New Top Brass
  • A Deep Dive Into That Power S1112 Entry Power11 Server
  • Guru: Beyond Three-Part Naming – Running SQL Across Remote IBM i Systems
  • How IBM Bolstered IBM i Resilience In The Summer Tech Refreshes
  • IBM i PTF Guide, Volume 28, Number 26

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle