The Software Supply Chain's Dirty Secret The recent revelations about vulnerabilities in ATM security software revealed by researcher Matt Burch at the Black Hat and Defcon conferences in Las Vegas should not be surprising to anyone who has been paying attention to cybersecurity.
What is surprising, however, is how these weaknesses have persisted for so long – and what it says about our collective approach to software security.
Burch's findings highlight a key problem with the way we develop and deploy software: the software supply chain.