Vendor flaws, vendor settlements, and the oversight gaps behind both. Here's what happened this month in third-party risk management news.
Recently Added Articles as of October 1
CISA warns banks to act on actively exploited NetScaler flaws. Industry groups are urging banks to act immediately on critical Citrix NetScaler flaws that attackers are exploiting now. The flaws let attackers run commands without a valid username or password and without any user action. Banks should identify affected systems, apply Citrix's updates, and investigate whether attackers got in first, since patching doesn't remove an attacker who already has access. Banks should also contact managed IT providers, core processors, hosted application providers, and other vendors that hold bank data to find out whether they use affected products, even if the bank doesn't use NetScaler itself.
$387.5 million stolen after zero-days hit a crypto exchange's security tools. Crypto exchange Bitget said attackers exploited zero-day flaws in two third-party security products to reach its wallet environment, then planted malware on a production wallet server and a custom withdrawal tool. The theft ran for nearly three hours across multiple blockchains. Logs show the earliest malicious activity on August 31, more than three weeks before the funds moved. Outside security appliances gave attackers the foothold.
FBI jobs portal breach leaves the third-party question open. The FBI is investigating a claimed compromise of its jobs portal and said it hasn’t determined whether the breach point was a third-party provider or its own enterprise. Attackers claim they stole data on nearly all FBI agents and applicants, and a sample reviewed by 404 Media contained sensitive personal information. The group says it exploited a flaw in Oracle's PeopleSoft HR platform. The portal is offline.
Mortgage lender hack puts vendor data in play. Attackers claim to have taken data from a mortgage lender, going beyond customer data to also steal vendor data and trade secrets. The lender acknowledged a cybersecurity incident, brought in a third-party forensics team, and already faces a consumer class action.
Labcorp pays $2.3 million over its debt collector's breach. A coalition of 44 state attorneys general settled with Labcorp over a 2019 breach at its debt collection vendor that exposed data on 27.5 million people, including 10.2 million Labcorp patients. Labcorp agreed to build an incident response plan for vendor security failures, limit how much data it shares with vendors, and stand up a risk management team that tracks vendor compliance with security practices. The attorneys general said Labcorp should have done more to police the vendor.
AI creep breaks the assumptions behind periodic vendor reviews. Vendors are adding AI features without customers fully understanding the change, which undermines three assumptions behind point-in-time reviews. Those assumptions are that capabilities change slowly, that contracts will flag significant changes, and that attestations reflect the product. Risk teams need ongoing oversight and operational evidence beyond SOC reports and questionnaires. Contracts should define what counts as a material change, since incremental updates can add up to one.