EXERCISE PURPOSE
Test cyber incident reporting and public-private coordination during a major incident affecting a critical open-source project.
A critical open-source build-toolchain vulnerability exploited across downstream critical infrastructure
CISA.GOV CTEP · SOFTWARE & SUPPLY CHAIN
A remote-code-execution flaw deep in an open-source toolchain enables repeated intrusions. Patch complexity, ransomware, public proof-of-concept code, account takeovers, and a DDoS attack challenge maintainers and downstream consumers.
EXERCISE PURPOSE
A critical open-source build-toolchain vulnerability exploited across downstream critical infrastructure
DECISION PRESSURE
The facilitator releases facts in stages. Participants should identify the decision owner, the authority being used, the information still needed, the immediate action, and the next escalation point.
How is suspicious maintainer or contributor behavior escalated?
Can releases be reproduced and signatures, builders, and dependencies trusted?
Which products and customers contain the affected component?
Who coordinates disclosure across maintainers, repositories, vendors, and government?
How does the organization ship a corrective release without compounding harm?
INSIDE THE EXERCISE
The template is already populated with public injects, facilitator-only context, discussion prompts, private role messages, and a final hotwash.
A major critical-infrastructure entity reports intrusion and data exfiltration to CISA. The intruder repeatedly returns after the entity believes the issue is fixed.
Investigators identify a previously unknown remote-code-execution vulnerability deep in the community’s build toolchain. It affects a core language library used across the ecosystem. CISA notifies the project’s security point of contact.
CISA and the FBI release a joint threat alert about the compromise.
More critical-infrastructure organizations investigate and report anomalous activity to CISA.
Minor critical-infrastructure disruptions are reported globally, though the cause is not public. Public- and private-sector organizations begin helping open-source developers prioritize a patch.
Developers determine that developing, testing, and deploying the fix will take about a month because downstream dependencies must be rebuilt and repackaged.
A threat group claims responsibility, encrypts several critical-infrastructure entities, and demands payment to stop disruption and prevent release of stolen data.
PARTICIPANTS
Assign people to functions, not titles alone. If one person owns several functions, keep the roles distinct during discussion so conflicts and handoffs remain visible.
REAL-WORLD INCIDENTS
Use these cases during planning or the prebrief. They are factual anchors, not scripts. Adapt the scenario to the organization’s technology, industry, geography, contracts, regulators, and risk profile.
A sophisticated actor spent years building maintainer trust before inserting a backdoor into widely distributed compression-library releases.
Log4Shell↗A critical vulnerability in the widely embedded Log4j library forced organizations to discover hidden dependencies, patch quickly, and monitor ongoing exploitation.
LEGAL, REGULATORY & STANDARDS LENS
Applicability depends on the organization and facts. Use counsel and subject-matter owners to tailor deadlines, thresholds, privileges, preservation, reporting, and communications.
The source collection for CISA Tabletop Exercise Packages covering ransomware, insider threats, phishing, supply-chain compromise, and sector incidents.
CISA Secure by Design↗Use the principles to test product accountability, secure defaults, evidence, and customer communications.
NIST Secure Software Development Framework↗A reference for testing release, provenance, vulnerability, and supplier practices.
PRACTITIONER PERSPECTIVES
External perspectives help the design team challenge internal assumptions. They do not replace organization-specific legal or technical advice.
EXPECTED OUTPUT