No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Wednesday, July 22, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Market Analysis

How F5 And SonicWall Revealed The Fragility Of The Software Supply Chain

by TheAdviserMagazine
9 months ago
in Market Analysis
Reading Time: 4 mins read
A A
How F5 And SonicWall Revealed The Fragility Of The Software Supply Chain
Share on FacebookShare on TwitterShare on LInkedIn


Adoption of cloud-native technologies such as SASE, SDWAN, and centralized firewall management have enabled operational agility and scalability. They have also, however, introduced new vectors and opportunities for exploitation. Enterprise risk management (ERM) programs are increasingly dominated by concerns around supply chain resilience, as highlighted in Forrester’s recent blog discussing supply chain, AI, and operational resilience.

The recent breaches at security vendors F5 and SonicWall illustrate how attackers are targeting the very infrastructure that enterprises rely on to secure and deliver digital services. According to Forrester data, software supply chain breaches were used in 30% of external attacks in 2025. It represents the broader fragility in software supply chain and assumptions made about trust, control, and visibility.

Source Code Theft And The Specter Of Zero-Day Exploits

The proverbial gut punch to supply chain security comes from F5 suffering a breach in its development environment. In this case, confirmed nation-state actors exfiltrated BIG-IP source code including details of undisclosed vulnerabilities last August. While no critical flaws have been confirmed yet, the theft of proprietary code is nothing to balk at since the product line sits in front of most enterprise applications inside the data center and in the cloud.

The F5 breach introduces a high probability of future zero-day exploitation. In fact, CISA’s emergency directives to federal agencies reflect the gravity of this supply chain compromise. Attackers are increasingly targeting the weakest links in software development and distribution pipelines, continuously testing your security. As highlighted in Forrester blog regarding the future of software supply chain security, organizations must realize that:

Software supply chain breaches will continue to be a top external attack vector
All 3rd party software, including open-source software, can introduce risk
Software supply chain security is a cross-discipline endeavor

The Trade-Offs of Centralized Cloud Management

The SonicWall breach is a reminder about the risk of centralized cloud management, particularly the involvement of sensitive infrastructure configurations. A key feature of its enterprise firewall platform is the MySonicWall cloud backup service, designed to streamline firewall management and disaster recovery. Its compromise resulted in the exposure of encrypted credentials, VPN settings and access rules which collectively give an attacker the operational blueprint necessary to enable precise and devastating intrusion attack campaigns.

To be fair, centralized cloud platforms do offer undeniable benefits, as echoed in Forrester’s report on the cybersecurity platform push, such as:

Simplified administration
Ease of integrations
Scalability
Tool consolidation

Lean IT and security teams find solace with such platforms, however the convenience often masks the dangerous assumption that centralized cloud-based management platforms are inherently secure and resilient. As our research has shown, that resilience must be built on the foundation of distributed risk. A centralized, single-cloud- repository introduces a high-value target for attackers with cascading effects.

The Common Thread: Supply Chain Fragility Creates Blind Spots

Both breaches reveal a shared vulnerability: the exposure of critical infrastructure through trusted third-party platforms. Whether it’s cloud-based configuration storage or proprietary development environments, attackers are exploiting the trust enterprises place in their vendors.

Traditional third-party risk management (TPRM) programs focus solely on assessing the security and risk of the entity (the vendor) but lack the directive to also assess security at the product level. This creates significant blind spots to flaws or vulnerabilities in the software supply chain.

These incidents reinforce the need for security leaders to treat vendors as extensions of their attack surface. As such, Forrester recommends that security and risk leaders:

Audit and harden: Immediately audit F5 and SonicWall deployments. Rotate credentials, patch systems, and harden public-facing interfaces.
Decentralize critical assets: Consider shifting sensitive configurations to local-only storage for high-value infrastructure.
Step up third-party risk management: Expand TPRM efforts to assess both entity AND product. Prioritize software supply chain security in vendor assessments. Don’t assume that security vendors get excused from detailed assessment and continuous monitoring. In fact, considering how critical they are to your organization’s security, they should be evaluated even more rigorously and continuously.
Make SBOMs mandatory. Require SBOMs (Software Bills of Materials), secure software development lifecycle (SDLC) practices, SLAs for patch updates, and incident response transparency from the vendor and continuously monitor SBOMs for newly disclosed vulnerabilities.
Encrypt backups with customer-controlled keys: Where possible, require client-side encryption or BYOK (Bring Your Own Key) for any vendor-managed backup service so that even if the vendor is breached, the attacker cannot decrypt sensitive configs.
Enable operational resilience: Integrate supply chain risk into ERM programs, aligning with Forrester’s guidance on resilience planning in 2025.
Carry out detection and threat hunting: To identify potential attacker activity from the F5 breach, hunt for anomalous management-plane logins, config changes, and code-signing anomalies. The vendor provided guidance for tracking login attempts. For SonicWall, track SSL VPN logs for credential-stuffing or mass logins and flag any config restores from cloud backups. Make sure you validate image integrity against vendor hashes.

Connect With Us

Forrester clients with questions related to this blog, supply chain risk, or enterprise risk management can connect with us through an inquiry or guidance session.

You can also meet our analysts in person at Forrester’s Security & Risk Summit, November 5–7, 2025.



Source link

Tags: ChainFragilityrevealedSoftwareSonicWallSupply
ShareTweetShare
Previous Post

12 Things That Disappear From Your Life After Divorce

Next Post

Highlights from ClioCon 2025 | Clio

Related Posts

edit post
Five Key Findings From The Forrester Wave™: Workday Services, Q2 2026

Five Key Findings From The Forrester Wave™: Workday Services, Q2 2026

by TheAdviserMagazine
July 22, 2026
0

The Workday services market has entered a new phase. Buyers are no longer looking solely for implementation partners that can...

edit post
trade promotion process

trade promotion process

by TheAdviserMagazine
July 22, 2026
0

Trade promotions help manufacturers increase product visibility, strengthen distributor relationships, and drive incremental sales. However, without a well-defined trade promotion...

edit post
Technology Leadership Networking In Austin: Forrester’s Tech Forum

Technology Leadership Networking In Austin: Forrester’s Tech Forum

by TheAdviserMagazine
July 22, 2026
0

In technology leadership, progress rarely comes from strategy alone. It comes from conversation — comparing approaches with peers, sharing lessons...

edit post
Co-op Advertising Program Management: The 2026 Strategy Guide

Co-op Advertising Program Management: The 2026 Strategy Guide

by TheAdviserMagazine
July 21, 2026
0

Your current spreadsheet-based tracking system isn’t just a nuisance; it’s a primary obstacle to your channel growth. When manual data...

edit post
CIOs: Use Rate Variance Analysis To Get To The Bottom Of Runaway Token Spend

CIOs: Use Rate Variance Analysis To Get To The Bottom Of Runaway Token Spend

by TheAdviserMagazine
July 21, 2026
0

So you’ve blown through your AI budget. Join the club. Blaming token consumption may have worked once. But as the...

edit post
Europe Intelligent Transportation Systems Market: Emerging Trends and Outlook

Europe Intelligent Transportation Systems Market: Emerging Trends and Outlook

by TheAdviserMagazine
July 21, 2026
0

The Europe Intelligent Transportation Systems Market is evolving rapidly as governments and transportation authorities invest in smarter, safer, and more...

Next Post
edit post
Florida’s Crypto Bill Gets A Second Life—But Will It Work This Time?

Florida’s Crypto Bill Gets A Second Life—But Will It Work This Time?

edit post
Chicago Woman Indicted Despite Claims She Was Shot by a Federal Agent

Chicago Woman Indicted Despite Claims She Was Shot by a Federal Agent

  • Trending
  • Comments
  • Latest
edit post
Mass Fraud in Massachusetts Committed by Illegal Immigrants Discovered

Mass Fraud in Massachusetts Committed by Illegal Immigrants Discovered

June 22, 2026
edit post
New Jersey Tax-Relief Events: Three July Dates Near Seniors

New Jersey Tax-Relief Events: Three July Dates Near Seniors

July 13, 2026
edit post
Bristlecone pines growing in the White Mountains of California germinated before the Great Pyramid was built, and the oldest one alive today, nicknamed Methuselah, has been quietly adding rings for 4,855 years in soil so poor almost nothing else survives beside it

Bristlecone pines growing in the White Mountains of California germinated before the Great Pyramid was built, and the oldest one alive today, nicknamed Methuselah, has been quietly adding rings for 4,855 years in soil so poor almost nothing else survives beside it

July 8, 2026
edit post
Retail giant exits U.S. fashion after multi-million-dollar scandal

Retail giant exits U.S. fashion after multi-million-dollar scandal

July 1, 2026
edit post
Same Portfolio. Same Retirement. A 10-Mile Move Costs One Couple ,000 A Year

Same Portfolio. Same Retirement. A 10-Mile Move Costs One Couple $10,000 A Year

June 27, 2026
edit post
Top Democrats Are Trapped in a Catch 22

Top Democrats Are Trapped in a Catch 22

July 6, 2026
edit post
Proof Noncitizens in NJ Are Being Registered to Vote

Proof Noncitizens in NJ Are Being Registered to Vote

0
edit post
Israeli plant-based protein co Plantopia raises m

Israeli plant-based protein co Plantopia raises $9m

0
edit post
Crown Castle Releases Q2 2026 Financial Results

Crown Castle Releases Q2 2026 Financial Results

0
edit post
Kevin Warsh has homed in on three key phrases. How Fed watchers interpret them

Kevin Warsh has homed in on three key phrases. How Fed watchers interpret them

0
edit post
S&P Unveils Digital Asset Index Tracking Blockchain Fundamentals

S&P Unveils Digital Asset Index Tracking Blockchain Fundamentals

0
edit post
Popular crypto firm files for Chapter 11 after token collapse

Popular crypto firm files for Chapter 11 after token collapse

0
edit post
How SEC’s e-delivery rule could cut paperwork, costs for advisors

How SEC’s e-delivery rule could cut paperwork, costs for advisors

July 22, 2026
edit post
6 Extra Help Prescription Costs Seniors Can Lower

6 Extra Help Prescription Costs Seniors Can Lower

July 22, 2026
edit post
Crown Castle Releases Q2 2026 Financial Results

Crown Castle Releases Q2 2026 Financial Results

July 22, 2026
edit post
Five Key Findings From The Forrester Wave™: Workday Services, Q2 2026

Five Key Findings From The Forrester Wave™: Workday Services, Q2 2026

July 22, 2026
edit post
S&P Unveils Digital Asset Index Tracking Blockchain Fundamentals

S&P Unveils Digital Asset Index Tracking Blockchain Fundamentals

July 22, 2026
edit post
John Paulson says we are in early stages of a long-term bull market for gold

John Paulson says we are in early stages of a long-term bull market for gold

July 22, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • How SEC’s e-delivery rule could cut paperwork, costs for advisors
  • 6 Extra Help Prescription Costs Seniors Can Lower
  • Crown Castle Releases Q2 2026 Financial Results
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.