A cybersecurity company disclosed unauthorised access to part of its source code repository. The firm serves more than 50,000 corporate and government customers.
A security vendor's source code leaking carries different severity from a customer data leak. Whoever holds the code can hunt for flaws far more efficiently than someone testing the product from outside, and the product in question is installed inside the perimeter of tens of thousands of organisations.
There's a structural aggravator. Security tools usually run with elevated privilege, because they need to see what other programs do. A flaw in that kind of component doesn't stay contained within the component.
The case repeats the pattern that ran through the year: attacking what many use pays better than attacking each one. The difference is that here the target was precisely the company selling protection.
For buyers, the practical question isn't whether the vendor has been attacked, because everyone will be. It's how they notify, how quickly, and what changes in the product afterwards. A notification deadline in the contract is worth more than a promise of invulnerability.
