Supply Chain Exploitation
Complex and interconnected supply chains for software and other information technology and
services, combined with growing reliance on common third-party service providers, create
opportunities for sophisticated adversaries to access victims at scale and complicate the efforts of
defenders to identify and manage cybersecurity risks. Adversaries are increasingly taking
advantage of complex and interconnected relationships between organizations and their
suppliers, customers, vendors, and service providers, compromising single nodes that grant
surreptitious access to victims in the United States and around the world.
In 2023, several high-profile compromises of technology providers impacted thousands of
connected victims, including critical infrastructure owners and operators. In December, Russia’s
Foreign Intelligence Service (SVR) targeted servers used by computer programmers to compile
and test software, presumably intending to maliciously modify developers’ source code. Earlier
in the year, a compromise of a widely used identity and access management firm enabled
malicious actors to steal credentials and session tokens that could provide surreptitious access to
thousands of customers. And, at the beginning of the year, a popular enterprise communications
suite was compromised in an entirely separate supply chain attack, demonstrating how a single
initial compromise can quickly spread through interlinked technology supply chains and thirdparty relationships.
Commercial Spyware
There is a growing market for sophisticated and invasive end-to-end cyber-surveillance tools
sold by private vendors to access electronic devices remotely, monitor and extract their content,
and manipulate their components without the knowledge or consent of the devices’ users.
Commercial spyware providers now offer world-class capabilities to the highest bidder, who
often employ these capabilities in cyber operations that are not subject to oversight or regulatory
constraints. While the commercial spyware industry has a long history, the recent proliferation
and misuse of these tools allows malicious cyber actors to target journalists, activists, human
rights defenders, and government officials with greater frequency.
A growing number of authoritarian regimes and democratic governments have misused
commercial spyware to surveil targets; intimidate perceived opponents; suppress dissent; limit
freedoms of expression, peaceful assembly, or association; and otherwise abuse human rights.
Some foreign governments and persons have deployed commercial spyware against U.S.
government personnel, information, and computer systems, presenting significant
counterintelligence and security risks to the United States. The misuse of these tools also
threatens the security and privacy of individuals in the United States and around the world.
Artificial Intelligence
Artificial intelligence (AI) is one of the most powerful technologies of our time, and it continues
to receive substantial public attention and media coverage. Advances in large-language
models (LLMs) and other foundational algorithms, combined with more affordable computing
power and access to data, have given rise to a new generation of AI tools. These tools captured
2024 REPORT
6
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE