The “Delivery and Installation” section covers this. It’s a very short section, the subtext of which is that there’s basically no defense for malware delivered with a valid signature from a trusted vendor.
It’ll be pretty interesting to find out what happened at SolarWinds in the coming days: whether this malware was smuggled into the update via employee collusion with attackers or a hack of SolarWinds itself.
Was someone being blackmailed? Or a malicious actor managed to gain employment?
That Jenkins plugin you haven't updated in years. Or that maven package no one knows about.
Third party risk management is unfortunately not well funded cyber security vertical.
You think you are supplying software to all the armed forces branches and "forgot" to update a Jenkins plugin?
As a security professional, getting people to upgrade simple software is difficult enough, upgrading critical infrastructure used 24/7 by the development team... forget about it.
yeah. Just now I am reading that their FTP servers had such a weak password that it allowed the pentester to upload/replace any binary back in 2019
If you think about it for even a moment you'll see that for code signing to be meaningful requires a completely locked down software supply chain, including controls that trace through developer laptops and third party open source code that's pulled in to your application. The typical app developer combines components from a huge number of sources of unknown reputability and security strength, which are then all executed on laptops that have permission to push arbitrary jobs to CI clusters.