The National Cyber Security Centre (NCSC, a part of GCHQ) has warned UK organisations and consumers to consider the risk of using Russian technologies amid the ongoing war in Ukraine, and the change in attitude of the Russian Leadership toward the West. The NCSC went on to add comment that Russian firms may be compelled by law to comply with the country’s Federal Security Service (FSB) – although there is no evidence that this has occurred yet – however, it is yet another tool in the toolbox of Russian Hybrid Warfare, so take note.
In several articles which have been published on the Internet, focus has been placed on the Russian Anti Malware Provider Kaspersky.
So where does the concern arise from when it comes to any Digital Assets in the West being serviced out of Russian software solution?
Consider an actual Anti-Malware solution running on the average server, workstation, laptop or even cell phone. In this technological implementation we have an application which is most likely running with high system privileges, and one which loads at boot-time into the kernel before many other software objects are allowed entry. This means, as I have always said, if you can compromise such an application as an Anti-Malware solution with a corrupt and malicious update, potentially you own that asset, or even network, which may then be manipulated or comprised to the end objective of the attacking, adverse actor – I will leave it to your imagination to work out the real-world implications of what such an onboard compromise could be!
In fact, no matter the software application involved, whilst it may safe and secure at time of install, there is nothing to say that sometime in the future, one of those urgent updates may be the one that punches a hole right through your firewall – you have been warned, so take note.
The opinions expressed in this post belongs to the individual contributors and do not necessarily reflect the views of Information Security Buzz.