RL Blog

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top
The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabs
ReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseVerify AI Supply ChainIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
Events
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
AppSec & Supply Chain SecurityMarch 12, 2025

Hidden threats lurk in commercial software: How to manage risk

While open-source risks are not going away, attack trends show third-party commercial software presents the greatest risk to the enterprise.

Paul Roberts, Director of Content and Editorial at RLPaul Roberts
FacebookFacebookXX / TwitterLinkedIn
LinkedIn
blueskyBluesky
Email Us

Main Story

IntroThe exposed state of commercial softwareCommercial software: The fuel for major attacksWanted: Commercial software transparency and accountability

Your IT department just received notice that your network switches received a signed OS update that included feature improvements and fixes for security vulnerabilities. That’s good news, right?

Wrong. Within weeks of the update being installed, you find that your company -and those switches- have been hacked. A China-backed advanced persistent threat (APT) actor gained access to your network through a compromised employee account and took remote control of the switches: executing code to surveil network communications; move laterally within your environment; and take control of high value IT assets and data.

How did that happen? Well, what you didn’t know is that a remotely exploitable flaw related to a third party software module lurked in the signed switch OS update from the vendor that you readily deployed. A patch for that flaw was available for months, so you assumed your large, reputable networking equipment vendor had applied it to secure their products. But you were wrong. That was a sad truth revealed to you first by the Chinese APT group and, after the fact, by the vendor in the release notes for their emergency OS update.

This scenario isn’t hypothetical. Security flaws that lurk in the proprietary, third-party software are the thread that ties together successful hacks of organizations large and small in recent years. Without a way to check the software updates for known risks, organizations big and small are easy prey for malicious actors that actively target flaws hiding in commercial software binaries.

Download: 2025 Software Supply Chain Security ReportSee the SSCS Report Webinar

The exposed state of commercial software

To shed light on this not-so-silent epidemic of insecure commercial software, RL security researchers analyzed 30 widely used third party binaries using Spectra Assure™, RL’s software supply chain security platform. The applications the team scanned included recent versions of widely used commercial and open-source operating systems, web browsers, video conferencing software and virtual private network (VPN) software, among others. Client executables were scanned, as well as installer and setup files for dozens of applications.

What did we find? Many of the scanned packages received a grade of “fail” from Spectra Assure. That was due to chronic issues such as the presence of known vulnerabilities in the software. For example, RL’s scans included 20 distinct versions of VPN clients from six prominent vendors and found that seven of the VPN packages contained one or more software vulnerabilities that are considered “patch-mandated,” meaning that they are being actively exploited by malware and cybercriminal groups.

RL also found a lack of “application hardening.” For example, the commercial applications we scanned often failed to properly employ technologies like Address Space Layout Randomization (ASLR), which protects software from code-injection attacks, or Data Execution Prevention (DEP), a type of vulnerability mitigation that limits the ability of attackers to use stack and heap overflow attacks to plant malicious code.

And then there are development secrets such as access credentials, API keys, and other sensitive information that can power sophisticated attacks against organizations using the vulnerable software. These secrets are often left within commercial software by accident, or they are hard-coded into code to facilitate access to external systems. RL’s scans of commercial software binaries turned up multiple instances of exposed credentials, including the presence of embedded private keys in the Windows installer for a leading commercial video conferencing application.

Commercial software: The fuel for major attacks

The prevalence of severe software security issues — and the lack of attention they receive — fuels our current epidemic of devastating cybercriminal and nation state hacks that have crippled everything from hospital chains to critical infrastructure and local governments.

Microsoft recently disclosed efforts by the Chinese hacking and espionage group known as “Silk Typhoon” to compromise sensitive, targeted organizations in the defense, government, legal, and higher education sectors. Their campaign includes discovering and targeting vulnerable third-party services and software providers, including IT providers, identity management, privileged access management, and RMM solutions, Microsoft said. The group also leverages leaked or stolen secrets like API keys to access downstream customers of the compromised vendors where “they can then abuse a variety of deployed applications, including Microsoft services and others, to achieve their espionage objectives.”

This isn’t a new problem. In fact, a lack of transparency about software quality and risk is as old as the software industry itself. What’s changed is the risk landscape: the presence, willingness, and ability of malicious state- and criminal-actors to leverage software flaws to further their mission – whether that be financial or geopolitical.

Wanted: Commercial software transparency and accountability

As long as these software supply chain risks remain unaddressed, they set the stage for bigger and more disruptive cyberattacks in 2025 and beyond. As it stands, our status quo lacks incentives for software producers to secure their software and services. It also greatly complicates efforts by end-user organizations to assess the risks lurking in the software and services delivered to them by their trusted suppliers.

To help give shape to the software supply chain risks percolating in both the public and private sectors, as well as on critical infrastructure, RL’s "2025 Software Supply Chain Security Report" exposes these issues by digging into supply chain attack vectors such as the exploitation of proprietary software flaws that are increasingly the favored tools of both cybercriminal and nation-state actors. The report also provides valuable insights into the evolving cyber-risk landscape, a useful preview of the kinds of threats and attacks that organizations will be asked to defend against in the months and years ahead.

Get RL's new report to learn more about commercial software risks — and what to do about them. Plus: Join RL chief software architect Tomislav Peričin and editorial director Paul Roberts, as well as Chris Hughes, CEO of Aquia, for this webinar, where they will unpack the key findings of the annual report.

Tags:AppSec & Supply Chain Security

More Blog Posts

Main Story

IntroThe exposed state of commercial softwareCommercial software: The fuel for major attacksWanted: Commercial software transparency and accountability

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagram
paul roberts headshot black and white
faceless man in hooded jacket standing in the rain

Join the free Spectra Assure Community today to get hands-on with RL's binary analysis-based software supply chain security platform.

Keep learning

  • Get up to speed on the agentic SOC in this webinar: Autonomy, Not Autopilot: Talking Agentic SOC. Plus: Learn about the new Agentic SOC Alliance.
  • Learn how Gartner® named RL a supply chain security 'visionary.' Download: Gartner® Magic Quadrant™ for Software Supply Chain Security.
  • Get key insights into why Gartner® said binary analysis is a must-have control in its recent CISO Playbook for Commercial Software Supply Chain Security.
  • Update your understanding of the Agentic Development Security tools landscape in this webinar with Forrester Sr. Analyst Janet Worthington.
  • Take a deep dive on the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the the webinar discussing the findings.

Explore RL's Spectra suite: Spectra Assure for software supply chain security,

Instagram
YouTubeYouTube
blueskyBluesky
Spectra Detect
for scalable file analysis,
Spectra Analyze
for malware analysis and threat hunting, and
Spectra Intelligence
for reputation data and intelligence.

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

Related

OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the riseFrontier AI agents: Only as safe as their containmentAI domain takeover takeaway: Focus on the harness not the model

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research

OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise

While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.

Learn More about OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise
OWASP Top 10 for LLM Apps 2026: Excessive agency risk on the rise

Frontier AI agents: Only as safe as their containment

The post-mortems of two compromises by rogue AI agents show that security teams need to focus on guardrails, not the AI model.

Learn More about Frontier AI agents: Only as safe as their containment
Frontier AI agents: Only as safe as their containment

AI domain takeover takeaway: Focus on the harness not the model

Research into an Active Directory takeover with a single AI prompt highlights why organizations need to focus on agentic SOCs.

Learn More about AI domain takeover takeaway: Focus on the harness not the model
AI domain takeover takeaway: Focus on the harness not the model
Robot agent
AI guardrails
Frontier AI controls