Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Industry Leaders Reaction on China Hacks
News & Analysis

Industry Leaders Reaction on China Hacks

ISBuzz TeamBy ISBuzz TeamOctober 5, 2018Updated:October 5, 20186 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Bloomberg broke a story today about how Chinese spies reportedly inserted microchips into servers used by Apple, Amazon, and others. According to the article, Chinese spies have infiltrated the supply chain for servers used by nearly 30 US companies. The chips were “not much bigger than a grain of rice,” reports Bloomberg, but able to subvert the hardware they’re installed on, siphoning off data and letting in new code like a Trojan Horse. According to Bloomberg, Amazon and Apple discovered the hack through internal investigations and reported it to US authorities. The publication says there’s no direct evidence that the companies’ data — or that of users — was stolen or tampered with, but both firms worked quietly to remove the compromised servers from their infrastructure. IT security experts commented below.

Ross Rustici, Senior Director, Intelligence Services at Cybereason:

“This report highlights the fundamental vulnerability of the globally distributed supply chains that exist. Hardware interdiction as a means to enable spying or sabotage is a fairly old concept. The fundamental problem facing countries these days is that as globalisation has created economic efficiencies by offshoring labour intensive products, individual countries no longer provide single source construction for their national security components. This creates a massive vulnerability for anyone building a high tech weapon system today. While this particular supply chain infection happened at least three years ago, the state of supply chain vulnerability management has not improved substantially.

Fundamentally, supply chain security is a cost problem. It is almost always conducted by a complicit insider, whether it is at the factory, a transportation agent, or customs official. This makes creating a tamper proof product extremely costly, the number of safeguards and other mechanisms required would drive up the cost of the product beyond market viability.

This incident should force government to re-examine how they inspect and certify critical hardware, however in the history of the spy wars, this will likely be forgotten as just another example of how countries are leveraging the global, vulnerable, supply chain for their own national security purposes.”

Edgard Capdevielle, CEO at Nozomi Networks:

“With revelations from the Super Micro attack revealing possible undetectable vulnerabilities in the supply chain, it becomes even more important to detect the malicious network activity they enable.

This means making sure you can dynamically identify all devices in your environments and ensuring continuous monitoring of corporate networks and industrial networks, especially those that operate critical infrastructure.

By detecting anomalies in the data traffic and in operations, organizations have their own tools to fight against these types of attacks.”

Pravin Kothari, CEO at CipherCloud:

Pravin Kothari“The new and recent DHS alerts about the Chinese APT10 “RedLeaves” cyberattack on cloud providers highlight the impossible problem faced by both enterprise and municipal government. The impossible problem is that enterprise and government cannot face off against well-funded nation-state attackers or large scale organized crime. It is a ridiculous proposition to believe otherwise. The U.S. government needs to step in and defend our internet infrastructure so that normal commerce and communications can continue unhindered. We must do this within the rule of law, put all of the evidence out there in the view of the global community, and enlist the support of our allies to ensure we are successful.”

Andy Wright, Check Point’s Regional Director at Northern Europe:  

“This attack shows that the threat landscape is much broader than people realize, and it highlights the major security risks which inevitably result from growing use of digital platforms and cloud services.  Entities which lack the correct perimeter security mechanisms are not equipped to protect their critical data from these fifth generation attacks, and are jeopardizing the security of their stakeholders.

“These types of attacks can be prevented using a comprehensive real-time perimeter security solution with anti-bot and reputation services, and good cooperation between government agencies and the cyber-security industry.  These solutions can reduce the time it takes to respond to such attacks from years, as seen in this case, to hours, and provide effective prevention against even these stealthy exploits.”

Tom Kellermann, Chief Cybersecurity Officer at Security Company Carbon Black and The Former Commissioner at President Barack Obama’s Cybersecurity Council:

“I am not shocked by the report from Bloomberg that claims China were able to infiltrate 30 large companies, like Apple and Amazon, and many federal agencies, by compromising the U.S. technology supply chain. This is a small example of China’s larger efforts to spy on and disrupt U.S. businesses. We have known for some time that China is a threat.  Government agencies have grown increasingly wary about how vulnerable U.S. infrastructure may be to Chinese espionage. China’s activities in this area have only become ramped up in recent years, particularly as trade tensions between China and the U.S. have increased.

Carbon Black’s quarterly Incident Response Threat Report shows that IT leaders are unambiguously pointing the finger at China and Russia for originating the vast majority of cyberattacks. And cybercriminals are seeking more than just financial gain or IP theft – 35% of the IT heads that we surveyed say the attackers’ end goal is espionage – as evident in China’s spying campaign.”

Kurt Baumgartner, Principal Security Researcher at Kaspersky Lab:

“Any alleged compromise of the hardware supply chain is a worrying event.  Big companies such as Facebook and Amazon design their own hardware because they use so much of it, so it would make sense that they would be the ones to find anything, and it is important that such companies keep examining their platforms.  The incident reported in the media highlights how stealthy an attack using tiny, carefully crafted and hidden chips could be. They could potentially alter the operating system or reduce overall security, for example by weakening encryption schemes, or raising privileges and access. There is a lot at stake: personal and corporate communications, IP, customer data, and more.

“However, sooner or later, the chip would have to phone home, and it is when communicating with the attacker’s command and control system that undiscovered threats are often most vulnerable. A defender looking at network traffic suddenly spots the anomaly. This is a big problem for threat actors, but it helps the security industry. We and other security companies have warned about a rise in supply chain attacks for a while now, and it is an area organizations need to be very alert to. Even things such as USB sticks still need checking for irregular traffic as they continue to be actively used to spread infection.”

Matan Or-El, CEO at Panorays:

“It is critically important for cyber threat intelligence like this to be disseminated, as companies can take extra precautions to secure the supply chain. These steps include discovering assets that hackers can target, identifying vulnerabilities and remediating any cyber gaps. However, the sophistication of these attacks means that companies will have to continuously review their digital assets and that of their third-party vendors and business partners to ensure that all vulnerabilities are detected and patched.”

.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}