CSIST told to fix system after hack | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


NO RETROSPECTIVE REVIEW:
The institute said that the developer of its procurement system had hidden an interface, which was discovered and exploited

  • By Wu Liang-yi,Lo Tien-pin
    and Jake Chung / Staff reporters, with staff writer

Minister of National Defense Wellington Koo (顧立雄) yesterday said he had ordered a review of a hacking incident at the military-affiliated Chungshan Institute of Science and Technology (CSIST), which said it would establish appropriate response standard operating procedures for its procurement system.

On Aug. 28, the CSIST procurement system began sending hundreds of old procurement notices to suppliers.

CSIST initially attributed the incident to an artificial intelligence (AI) security-testing tool exceeding its permissions.

Photo: Wu Liang-yi, Taipei Times

However, CSIST yesterday said that the developer of its procurement system had hidden the system’s task-management interface, which was breached via an overseas IP address.

The hackers triggered scheduled commands, prompting the system to resend procurement notices to contractors, it said.

CSIST did not conduct a retrospective review of the system — which was built on March 29, 2019 — following the spirit of the software bill of materials (SBOM) policy in its Software Development Management Manual, which draws on the US software supply-chain security framework established under Executive Order 14028 issued by then-US president Joe Biden.

The manual requires outside developers of newly procured systems to provide a SBOM identifying the system’s software components and their sources to improve transparency in software risk management.

CSIST said the failure to conduct a retrospective review created a management gap, which needs addressing.

CSIST said it has been training an AI agent in a test area on the procurement Web site and initially attributed the incident to the test, but later determined that a concealed scheduling-management interface created by the system vendor had been breached by someone using an overseas IP address.

The institute said it has asked the vendor to provide a complete SBOM and reviewed its incident-response procedures.

It is also planning an alert system to detect abnormal outbound notifications or controls, and automatically restrict or block network traffic and suspend services when specified conditions are met, it said.

The measures would provide earlier warnings and enable a faster response, the CSIST said.

It would determine responsibility for management failures based on the full investigation and monitor implementation of corrective measures, it added.



Click Here For The Original Source.

——————————————————–

..........

.

.