THE article discusses recent research into how embedded application security scanners can become a target for supply chain attacks. It highlights vulnerabilities found in these scanners that could allow attackers to exploit them, emphasizing the risks posed to downstream software engineering teams. The findings involve notable incidents where poisoned versions of security tools, such as Trivy and KICS, were disseminated, leading to credential theft and fraud.
The research was conducted by ZeroPath, which identified sensitive data exposure across multiple security vendors. They created a tool named Build Canaries to test the security of scanner environments, revealing significant vulnerabilities that could impact major organizations. The article previews a presentation by ZeroPath at the Black Hat USA conference, where they will introduce this tool and share their findings.