TMCnet News
Cyber Threat Alert: Compromised Software Code Poses New Systemic Risk to U.S. Critical InfrastructureNew Fortress Information Security Research Shows 90 Percent of Software Products Used by Critical Infrastructure Organizations Contain Code Developed in China ORLANDO, Fla., Dec. 4, 2024 /PRNewswire/ -- The code that makes up the software now powering U.S. utilities is rife with vulnerabilities, including hundreds that are "highly exploitable," a new research report released by Fortress Information Security today finds. Researchers studied thousands of products and found troubling risk patterns. The report, Beyond the Bill of Materials: The Silent Threat Lurking in Critical Infrastructure Software, also shows that 25 percent of software components and 90 percent of software products contained code from developers in China. Compromised software code can provide threat actors with a "backdoor" into power grids, oil and gas pipelines, and communication networks. In similar research last year, Fortress discovered that code developed in China was 1.4 times more likely to contain vulnerabilities than code developed elsewhere. "China is an existential threat to U.S. economic and physical security," said Alex Santos, CEO of Fortress. "Software products with Chinaborn code must be identified and weeded out from our nation's critical infrastructure. We developed and then examined the Software Bill of Materials (SBOM) for the most widely used products managing the U.S. electric power grid. The next step is to take action to eliminate these systemic risks, and we look forward to working with utilities to do just that." Using the North American Energy Software Assurance Database (NAESAD) to review Software Bills of Materials (SBOMs) for more than 2,000 software products, researchers found:
"Once again, we found that just a small number of common components, used across hundreds of products, were responsible for the bulk of critical vulnerabilities," said Bryan Cowan, lead researcher for Fortress. "These are vulnerabilities that can be detected and software flaws that can be corrected. Addressing those 20 components would make our power plants, oil and gas refineries, and chemical companies much more secure." Brief Methodology About Fortress
SOURCE Fortress Information Security
|
