RL Blog

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
Why RL Built Spectra Assure Community

Why RL Built Spectra Assure Community

We set out to help dev and AppSec teams secure the village: OSS dependencies, malware, more. Learn how our free tier works.

Read More about Why RL Built Spectra Assure Community
Why RL Built Spectra Assure Community

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsBlack Hat 2026
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
AppSec & Supply Chain SecurityMarch 12, 2025

Hidden threats lurk in commercial software: How to manage risk

While open-source risks are not going away, attack trends show third-party commercial software presents the greatest risk to the enterprise.

paul roberts headshot black and white
Paul Roberts, Director of Content and Editorial at RLPaul Roberts
FacebookFacebookXX / TwitterLinkedInLinkedInblueskyBlueskyEmail Us
faceless man in hooded jacket standing in the rain

Your IT department just received notice that your network switches received a signed OS update that included feature improvements and fixes for security vulnerabilities. That’s good news, right?

Wrong. Within weeks of the update being installed, you find that your company -and those switches- have been hacked. A China-backed advanced persistent threat (APT) actor gained access to your network through a compromised employee account and took remote control of the switches: executing code to surveil network communications; move laterally within your environment; and take control of high value IT assets and data.

How did that happen? Well, what you didn’t know is that a remotely exploitable flaw related to a third party software module lurked in the signed switch OS update from the vendor that you readily deployed. A patch for that flaw was available for months, so you assumed your large, reputable networking equipment vendor had applied it to secure their products. But you were wrong. That was a sad truth revealed to you first by the Chinese APT group and, after the fact, by the vendor in the release notes for their emergency OS update.

This scenario isn’t hypothetical. Security flaws that lurk in the proprietary, third-party software are the thread that ties together successful hacks of organizations large and small in recent years. Without a way to check the software updates for known risks, organizations big and small are easy prey for malicious actors that actively target flaws hiding in commercial software binaries.

Download: 2025 Software Supply Chain Security ReportSee the SSCS Report Webinar

The exposed state of commercial software

To shed light on this not-so-silent epidemic of insecure commercial software, RL security researchers analyzed 30 widely used third party binaries using Spectra Assure™, RL’s software supply chain security platform. The applications the team scanned included recent versions of widely used commercial and open-source operating systems, web browsers, video conferencing software and virtual private network (VPN) software, among others. Client executables were scanned, as well as installer and setup files for dozens of applications.

What did we find? Many of the scanned packages received a grade of “fail” from Spectra Assure. That was due to chronic issues such as the presence of known vulnerabilities in the software. For example, RL’s scans included 20 distinct versions of VPN clients from six prominent vendors and found that seven of the VPN packages contained one or more software vulnerabilities that are considered “patch-mandated,” meaning that they are being actively exploited by malware and cybercriminal groups.

RL also found a lack of “application hardening.” For example, the commercial applications we scanned often failed to properly employ technologies like Address Space Layout Randomization (ASLR), which protects software from code-injection attacks, or Data Execution Prevention (DEP), a type of vulnerability mitigation that limits the ability of attackers to use stack and heap overflow attacks to plant malicious code.

And then there are development secrets such as access credentials, API keys, and other sensitive information that can power sophisticated attacks against organizations using the vulnerable software. These secrets are often left within commercial software by accident, or they are hard-coded into code to facilitate access to external systems. RL’s scans of commercial software binaries turned up multiple instances of exposed credentials, including the presence of embedded private keys in the Windows installer for a leading commercial video conferencing application.

Commercial software: The fuel for major attacks

The prevalence of severe software security issues — and the lack of attention they receive — fuels our current epidemic of devastating cybercriminal and nation state hacks that have crippled everything from hospital chains to critical infrastructure and local governments.

Microsoft recently disclosed efforts by the Chinese hacking and espionage group known as “Silk Typhoon” to compromise sensitive, targeted organizations in the defense, government, legal, and higher education sectors. Their campaign includes discovering and targeting vulnerable third-party services and software providers, including IT providers, identity management, privileged access management, and RMM solutions, Microsoft said. The group also leverages leaked or stolen secrets like API keys to access downstream customers of the compromised vendors where “they can then abuse a variety of deployed applications, including Microsoft services and others, to achieve their espionage objectives.”

This isn’t a new problem. In fact, a lack of transparency about software quality and risk is as old as the software industry itself. What’s changed is the risk landscape: the presence, willingness, and ability of malicious state- and criminal-actors to leverage software flaws to further their mission – whether that be financial or geopolitical.

Wanted: Commercial software transparency and accountability

As long as these software supply chain risks remain unaddressed, they set the stage for bigger and more disruptive cyberattacks in 2025 and beyond. As it stands, our status quo lacks incentives for software producers to secure their software and services. It also greatly complicates efforts by end-user organizations to assess the risks lurking in the software and services delivered to them by their trusted suppliers.

To help give shape to the software supply chain risks percolating in both the public and private sectors, as well as on critical infrastructure, RL’s "2025 Software Supply Chain Security Report" exposes these issues by digging into supply chain attack vectors such as the exploitation of proprietary software flaws that are increasingly the favored tools of both cybercriminal and nation-state actors. The report also provides valuable insights into the evolving cyber-risk landscape, a useful preview of the kinds of threats and attacks that organizations will be asked to defend against in the months and years ahead.

Get RL's new report to learn more about commercial software risks — and what to do about them. Plus: Join RL chief software architect Tomislav Peričin and editorial director Paul Roberts, as well as Chris Hughes, CEO of Aquia, for this webinar, where they will unpack the key findings of the annual report.

Keep learning

  • Take a deep dive into ClickFix with RL's new report, and join the webinar to learn more about the attack technique. Plus: Get RL's open-source YARA rule.
  • Learn how Gartner® named RL a supply chain security 'Visionary.' Download: Gartner® Magic Quadrant™ for Software Supply Chain Security.
  • Get up to speed on the Agentic Development Security tools landscape in this webinar with Forrester Sr. Analyst Janet Worthington.
  • Understand the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the the webinar discussing the findings.

Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

Plus: Join the free Spectra Assure Community today to get hands-on with RL's binary analysis-based software supply chain security platform.

Tags:AppSec & Supply Chain Security

More Blog Posts

Open Source Hardening

Akrites marshals the open source community to counter AI threats

Industry heavyweights bring new focus to vulnerabilities in the age of AI. Here’s how it might help improve security.

Learn More about Akrites marshals the open source community to counter AI threats
Akrites marshals the open source community to counter AI threats
AI threat advisor robot

New OWASP tool structures AI threat modeling

Threat Advisor could help teams with AI-specific risks. But a broader AppSec strategy rethink is needed in the AI era.

Learn More about New OWASP tool structures AI threat modeling
New OWASP tool structures AI threat modeling
AI-BOM minimum requirements

AI-BOM push borrows from the SBOM playbook

The Institute for Security and Technology's 'Driving AI Transparency' policy paper makes the case for AI-BOM minimum requirements.

Learn More about AI-BOM push borrows from the SBOM playbook
AI-BOM push borrows from the SBOM playbook
5 takeaways

2026 Gartner® Magic Quadrant™ for Software Supply Chain Security: 5 takeaways

The Magic Quadrant™ for Software Supply Chain Security is a 45-minute read. Here's what we feel security leaders need to pull from it.

Learn More about 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security: 5 takeaways
2026 Gartner® Magic Quadrant™ for Software Supply Chain Security: 5 takeaways

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top