ComputerWeekly.com 09月29日
印度供应商安全漏洞威胁全球供应链
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

根据SecurityScorecard的报告,印度超过一半的供应商去年遭受了安全漏洞,包括制造、航空航天、制药和IT服务公司。印度IT服务提供商虽然安全状况良好,但记录的漏洞数量最多,占所有第三方漏洞的62.5%。这些漏洞可能引发连锁反应,影响全球企业。印度是全球数字经济的支柱,但其供应商的安全弱点为网络攻击者提供了机会,可能导致生产中断、服务延迟或关键物流混乱。

🔒 印度供应商的安全漏洞比最初预期的更普遍、更严重,可能导致影响全球组织的连锁第三方漏洞。

🌐 全球范围内,IT供应商因其核心作用、庞大的攻击面和高价值而成为攻击者的热门目标,印度IT公司尤其面临大量错别名域名、凭证泄露和感染设备的问题。

📈 印度IT公司在全球IT市场中占据巨大份额,为大型跨国公司供货,其安全弱点可能引发全球供应链的严重问题。

🔄 第三方公司的安全弱点可能为网络攻击者打开大门,而供应商的合作伙伴(第四方)也可能创造新的供应链风险。

🚨 单个印度供应商遭受勒索软件攻击或破坏性网络攻击,可能导致多个国家的生产线停工、服务延迟或关键物流中断。

<p>Global supply chains could be vulnerable to attack through third-party suppliers in India, as a report reveals that over half suffered breaches in the country last year.</p><div class="ad-wrapper ad-embedded"> <div id="halfpage" class="ad ad-hp"> <script>GPT.display('halfpage')</script> </div> <div id="mu-1" class="ad ad-mu"> <script>GPT.display('mu-1')</script> </div> </div> <p>According to <a href="file:///C:/Users/FlindersK/AppData/Local/Microsoft/Windows/INetCache/Content.Outlook/0KAKWPF0/India%20Supply%20Chain-Report_2025.pdf">research by SecurityScorecard</a>, Indian companies across multiple sectors – including manufacturers supplying the aerospace and pharmaceuticals industries, as well as IT services firms – have security weaknesses.</p> <p>The risk management company’s study of India-based <a href="https://www.computerweekly.com/news/366624029/Strong-fintech-security-posture-at-risk-via-third-party-weak-links"&gt;third-party risks</a> to global supply chains revealed potential security vulnerabilities in the country.</p> <p>“[Our] latest research reveals that the security weaknesses present in Indian suppliers are both more widespread and more severe than our analysts initially anticipated, creating significant potential for cascading third-party breaches that can affect organisations worldwide,” said SecurityScorecard.</p> <p>It added that while Indian IT service providers have strong security postures, they suffered the highest number of recorded breaches in the study.</p> <p>This is not unique to India. IT suppliers across the world are attractive targets for attackers. “Globally, IT providers face elevated cyber risk because of their central role in enabling third-party access, their large and complex attack surfaces, and their attractiveness as high-value targets.”</p> <p>The report said that Indian IT companies experienced large volumes of <a href="https://www.techtarget.com/searchsecurity/news/366577455/Typosquatting-campaign-malicious-packages-slam-PyPi"&gt;typosquatting&lt;/a&gt; domains, credential compromises and infected devices.</p> <p>It said suppliers of outsourced IT operations and managed services were responsible for 62.5% of all third-party breaches in its Indian sample. “This is the highest proportion our researchers have ever documented and raises urgent questions about the resilience of global businesses that rely heavily on Indian IT vendors,” said SecurityScorecard.</p> <p>Indian IT suppliers have a huge share of the global IT market and supply the largest multinationals.</p> <p>“India is a cornerstone of the global digital economy,” said Ryan Sherstobitoff, field chief threat intelligence officer at SecurityScorecard. “Our findings highlight both strong performance and areas where resilience must improve. Supply chain security is now an operational requirement.”</p> <p>Weaknesses in the security posture of third-party companies in the supply chain can open the door to large businesses for cyber attackers. Suppliers to third parties can also create fourth-party weaknesses in the supply chain.</p> <p>“The threat does not stop at direct connections. Indian companies themselves rely on a web of suppliers, creating fourth-party risks that extend even further into the global supply chain,” said the SecurityScorecard report. “A single ransomware incident or disruptive cyber attack affecting one Indian vendor could halt production lines, delay service delivery, or disrupt critical logistics for companies in multiple countries.”</p> <p>Separately, in another report, SecurityScorecard found that almost all (96%) of Europe’s largest financial services organisations have been affected by a security breach at a third-party organisation.</p> <p>It also revealed that 97% had experienced a breach via a fourth party, the partners of their partners, up from 84% two years ago.</p> <div class="extra-info"> <div class="extra-info-inner"> <h3 class="splash-heading">Read more about third-party breaches</h3> <ul class="default-list"> <li>Almost all (96%) of Europe’s largest financial services organisations have been <a href="https://www.computerweekly.com/news/366625478/Third-party-security-weaknesses-threaten-Europes-big-banks"&gt;affected by a security breach</a> at a third-party organisation, research has found.</li> <li>Outgoing CISA chief Jen Easterly calls on buyers to <a href="https://www.computerweekly.com/opinion/Secure-software-Third-party-suppliers-your-first-party-risk"&gt;demand better security standards</a> from their software suppliers.&nbsp;</li> <li>Despite having a strong security posture, the financial technology sector could <a href="https://www.computerweekly.com/news/366624029/Strong-fintech-security-posture-at-risk-via-third-party-weak-links"&gt;be open to attack via third parties</a></li> </ul> </div></div>

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

全球供应链 印度供应商 安全漏洞 第三方风险 网络攻击
相关文章