THREAT OPS › Threat News › [Security Blog] Modern Software’s Hidden Cost: Managing Risk in the Open-Source Ecosystem
[Security Blog] Modern Software’s Hidden Cost: Managing Risk in the Open-Source Ecosystem
<p>Modern software development has shifted towards prioritising speed. Developers no longer write code from scratch; instead, they assemble applications from a vast ecosystem of open-source building blocks. However, this efficiency comes with a hidden cost: open-source security risk. A single application today may depend on thousands of indirect components, many of which are maintain
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
- Code RepositoriesT1593.003
- CredentialsT1589.001
- Code RepositoriesT1213.003
- Malicious LinkT1204.001
- CompressionT1027.015
- Malicious LinkAML.T0011.003
- Generative AIAML.T0016.002
- Code RepositoriesAML.T0095.000
Indicators of compromise
- 223949d5a074ebc3dce9ee78baad9e27md5
- CVE-2021-44228cve
- CVE-2024-3094cve
- https://owasp.org/www-project-open-source-software-top-10/&quoturl
- https://www.oracle.com/security-alerts/alert-cve-2021-44228.html&quoturl
- https://www.theregister.com/2021/12/21/belgium_defence_ministry_log4j_exploited/&quoturl
- https://arcticwolf.com/resources/blog/log4j-retrospective/&quoturl
- https://access.redhat.com/security/cve/cve-2024-3094/#cve-details-description&quoturl
- https://blog.checkpoint.com/research/shai-hulud-2-0-inside-the-second-coming-the-most-aggressive-npm-supply-chain-attack-of-2025/&quoturl
- oracle.orgdomain
- hkcert.orgdomain