Verizon’s data breach report confirms what GitHub just found out the hard way: software vulnerabilities are now a bigger initial access vector than stolen credentials.
GitHub has confirmed that a compromise of an employee’s device, following the installation of a malicious VS Code extension, has led to 3,800 internal code repositories being breached. The hackers behind the security incident, TeamPCP, have put data – which they say includes GitHub source code – up for sale with a starting price of $50,000.
The extension involved was Nx Console version 18.95.0, which has also now been confirmed as malicious by the developer, Jeff Ceross, who said that “we currently believe the number of users who received the malicious package,” is “potentially over 6k installs”.
Anyone reading the newly published annual Version Data Breach Report is unlikely to be surprised: “Using software flaws has surpassed stolen credentials for the first time,” it warned. Adding that AI is accelerating these attacks from months to hours. If you read my article at TechFinitive last week, this would come as no surprise either.
This. Is. Important. Please do not think of it as being just another headline trend, one that will be replaced with another next week. The Verizon DBR analysis has found that 31% of all breaches start with vulnerability exploitation. “This is the first time in 19 years that it has surpassed stolen credentials as the biggest point of entry,” it stated.
The old security patch chestnut?
As Keeper Security‘s CEO, Darren Guccione, warned, this represents a “fundamental shift in how attacks are being operationalised, and every security and business leader needs to take that seriously”.
Aha, the old patch now chestnut? Well, yes, sort of.
While patching quickly is the ideal panacea for software vulnerabilities, it’s actually not that simple in the very real world of enterprise security.
“Organisations are facing a growing backlog of critical vulnerabilities,” said Scott Miserendino, VP of Engineering, Cyber at DataBee, “with only 26% fully remediated and a median remediation time stretching to 43 days.” So it’s not an awareness gap; it’s an operational one.
“Security teams don’t lack vulnerability data,” Miserendino continued, “they lack the ability to prioritise, coordinate, and act on it at scale across fragmented environments.”
But with third-party attacks accounting for 48% all reported breaches, according to the Verizon DBR, something has to change.
“The fix is not faster patching, it is patching by reachability and containing the rest,” said Collin Hogue-Spears, Senior Director of Solution Management at Black Duck.
Reachability analysis separates the flaws attackers can actually exploit, Hogue-Spears explained, from those that only look dangerous. “Security leaders must prioritise the CISA Known Exploited Vulnerabilities catalog before the CVSS severity queue,” advised Hogue-Spears before adding that “CVSS tells you how bad a flaw can be, KEV tells you which flaws attackers already use”.
More security articles