[Heads Up] Was SolarWinds Really A Daisy Supply Chain Attack?

JetBrains-LogoThe NYT just reported the next revelation regarding the SolarWinds hack.  The Russian FSB may have piggybacked on a tool developed by JetBrains, which is based in the Czech Republic.

The NYT said: "Officials are investigating whether the company, founded by three Russian engineers in the Czech Republic with research labs in Russia, was breached and used as a pathway for hackers to insert back doors into the software of an untold number of technology companies."

The exact software that investigators are examining is a JetBrains product called TeamCity, used by SolarWinds, which allows developers to test and exchange software code before its release. JetBrains is considered a predominant tool for developing software. Google, Hewlett-Packard and Citibank are among its customers, and the company is widely used by developers of Android mobile software. JetBrains themselves blogged about this and said they have not been notified and not aware of this investigation. 

KnowBe4 is not using the TeamCity product, but this whole affair does bring to light the enormous third party vendor risk. Remember how antivirus company Kaspersky was penetrated and "owned" by Russian state-sponsored hackers? Trusting your source code to three Russians seems to be an unacceptable risk in these days. 

You need to truly start managing that risk.  KnowBe4's KCM’s Vendor Risk Management module helps you manage your third-party vendor risk requirements. KCM enables you to centralize your third-party risk management processes and helps you prequalify risk, assess your vendors, and conduct remediation efforts in your KCM platform. You can even set a frequency for how often your vendors are assessed, to continually monitor the associated risk. Get your live demo now.

Request a Demo of KCM GRC

The new KCM GRC platform helps you get your audits done in half the time, is easy to use, and is surprisingly affordable. No more: "UGH, is it that time again!" 

products-KCM2-2With KCM GRC you can:

  • Reduce the amount of time and money required to easily manage your compliance, risk, and audit requirements
  • Automate reminders so you can quickly see what tasks have been completed, not met, and are past due
  • Simplify risk management with an intuitive interface simple workflow based on NIST 800-30.
  • Efficiently manage your third-party vendor risk requirements
  • Quickly implement compliance and risk assessment processes using KnowBe4's pre-built requirements and assessment templates

Request Your Demo

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:


Subscribe To Our Blog

Ransomware Hostage Rescue Manual

Get the latest about social engineering

Subscribe to CyberheistNews