2. of Elevation of Privilege (2022 deck)
An attacker has compromised a key technology supplier.
Threat |
|
The company that writes your order processing system has been hacked and the attackers have written a backdoor into the latest version and you have configured automatic updates. So, they can now steal/exfiltrate all your customer data. |
|
CAPEC |
CAPEC-523 – Malicious software implanted CAPEC-511 – Infiltration of the software development environment CAPEC-657 – Malicious automated software update via spoofing |
ASVS |
10.2.1 – Check for application phoning home and harvesting of data 10.2.3 – Check source for backdoors and other malicious code 10.3.1 – Check that automatic updates are signed and performed... |