[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4snxHsQLqdVx11FiQE6E8npd_S6YOLEfWeLA4MKfMIg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"a3be5292-0b41-46e4-9552-2b0454faabc7","zero-day-in-third-party-security-tools-costs-bitget-3875m","e9ae049b-a5c4-456d-a1a6-4019c2841aab","Zero-Day in Third-Party Security Tools Costs Bitget $387.5M","Attackers exploited zero-day vulnerabilities in third-party security appliances to gain an initial foothold, then deployed web shells and malware to pivot into Bitget's wallet environment — resulting in a $387.5 million theft. This attack highlights a deeply ironic and dangerous reality: the security products organizations trust to protect them can themselves become the attack surface. Third-party tools often receive implicit trust and broad network access, making them high-value targets for sophisticated threat actors like North Korean state-sponsored groups. Organizations cannot assume that vendor-supplied security products are immune to exploitation, and must apply the same rigorous controls to those products as to any other critical asset.","**Immediate actions:**\n- Audit and patch all third-party security appliances immediately, prioritizing internet-facing and network-adjacent devices.\n- Scan for indicators of compromise (web shells, unusual outbound connections) on all security appliances connected to critical financial systems.\n- Enforce strict network access controls to isolate wallet infrastructure from security appliance management interfaces.\n\n**Long-term improvements:**\n- Apply the principle of least privilege to all third-party security products, limiting their access only to what is operationally required.\n- Establish a formal third-party risk management program that includes continuous vulnerability monitoring for all vendor-supplied tools.\n- Implement hardware security modules (HSMs) and multi-party computation (MPC) for cryptographic key management to limit blast radius during a compromise.\n\n**Detection measures:**\n- Deploy independent endpoint detection on security appliances to catch post-exploitation activity such as web shell deployment.\n- Monitor all outbound traffic from security appliances for anomalous behavior using a separate, out-of-band logging system.\n- Conduct regular red team exercises specifically targeting third-party security tooling to identify trust-abuse attack paths before adversaries do.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 13: Network Monitoring and Defense","NIST CSF ID.SC-4: Supply Chain Risk Management","NIST SP 800-161: Cybersecurity Supply Chain Risk Management","NIST AC-6: Least Privilege","NIST SI-3: Malicious Code Protection","NIST IR-4: Incident Handling","ISO 27001 A.15.1: Information Security in Supplier Relationships","ITIL: Supplier Management Practice","published","2026-09-30T12:21:28.187463+00:00","2026-09-30T12:21:28.059+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fbitget-hacked-via-zero-day-in-third-party-security-products\u002F","bitget-hacked-via-zero-day-in-third-party-security-products-52ffe6","Bitget hacked via zero-day in third-party security products",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"77c85905-73fa-480e-a442-763d0198abd9","2026-09-30","afternoon","ThreatNoir Afternoon Brief — September 30","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-30\u002Fthreatnoir-afternoon-brief-2026-09-30.mp3"]