OSS solutions hold a privileged place in the operations of communications service providers around the world. They collect logs and events from network devices, security devices, shared services (like Active Directory) and other support systems. With increased automation and orchestration, they also have the power to quickly push controls back into all of those devices and systems.
“With great power comes great responsibility”
Wired has shared, The Untold Story of the Boldest Supply-Chain Hack Ever, describing how SolarWinds Orion, effectively an OSS, was compromised. In being compromised, attackers were able to access thousands of corporate and government networks that used Orion for monitoring.
The link above provides a detailed account about how SolarWinds’ network was breached and then how Orion was subsequently compromised.
It’s a must-read story for any OSS or BSS company.