TL;DR
Current advisories show attackers succeeding in the layer you do not control: government and industry sources report exploitation of network devices, unpatched Microsoft Exchange servers, and abused PaperCut zero-days. That makes supplier security a contract-evidence problem, not a questionnaire problem. The matrix below turns each fact into the vendor question to ask, the clause to negotiate, and the dated artifact to demand.
What changed
Three source-backed facts define the current third-party picture:
- The Australian Signals Directorate's Australian Cyber Security Centre joined a joint advisory on the exploitation of network devices by Russian state-sponsored cyber actors, describing a "persistent and enduring campaign" of malicious activity targeting that device class (ASD ACSC, https://www.cyber.gov.au/about-us/view-all-content/news/joint-advisory-on-the-exploitation-of-network-devices-by-russian-state-sponsored-cyber-actors). Edge and network devices are commonly installed, monitored, or patched by an MSP or supplier — the advisory is the trigger; who administers your devices is your interpretation to verify.
- BleepingComputer reports that nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass that lets attackers hijack all user mailboxes on a server (https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/). The source reports the number and the vulnerability; lilMONSTER's interpretation is that this is what an unmanaged patch tail looks like at population scale.
- BleepingComputer also reports that two vulnerabilities in PaperCut NG and MF print management software — patched only last week after being exploited as zero-days — are now being abused in data theft attacks (https://www.bleepingcomputer.com/news/security/recently-patched-papercut-zero-days-used-in-data-theft-attacks/). PaperCut is exactly the kind of shared, vendor-operated application that sits inside many supplier environments and rarely appears on a questionnaire.
lilMONSTER has not scanned, tested, or observed any of these environments. Every claim above belongs to the cited sources.
Why it matters for business trust
Insurers, customers running tenders, auditors, and boards increasingly ask not "do you have a vendor policy?" but "show me the evidence your suppliers patch." These facts change specific decisions:
- The ACSC advisory changes who you hold accountable for edge devices. If a supplier or MSP administers your firewalls and VPNs, the advisory moves patch accountability from implicit to contractual.
- The Exchange number changes how you read questionnaire answers. A supplier ticking "we patch promptly" is indistinguishable from the organisations behind those 22,000 servers; only dated patch evidence distinguishes you from the tail.
- The PaperCut case changes your application inventory scope. Data theft via print management software shows that low-visibility vendor applications — not just flagship platforms — carry breach-relevant risk that customers and insurers will ask about after an incident.
The common failure is a point-in-time assessment: a signed questionnaire captures intent on one day and proves nothing about the week a zero-day lands.
A useful first project
You can issue a targeted evidence request to your top ten suppliers in one afternoon using this matrix
We verify authority first, minimise access, define scope, and focus on evidence that supports a real business decision.
Tell us what should work better →Evidence to produce now
Third-Party Evidence Request Matrix — use one row per supplier per relevant trigger:
| Trigger (source) | Vendor question to ask | Contract control to write | Evidence to request (artifact) |
|---|---|---|---|
| Network-device exploitation advisory (ASD ACSC) | Who administers our internet-facing network devices, and what is your patch SLA for critical government advisories? | Named obligation: acknowledge and patch critical advisories within an agreed window; notify us of exposure | Asset list naming your edge devices; the admin of record; dated change tickets for the last critical advisory |
| Zero-day exploitation of vendor applications (PaperCut, BleepingComputer) | Which third-party applications in your environment hold or touch our data, and how will you notify us of vendor security updates? | Notification clause: advise affected customers of vendor security updates within an agreed number of business days | Application inventory with versions for your instances; a sample dated update notification; the patch ticket for the most recent vendor fix |
| Unpatched exposed systems (Exchange, BleepingComputer) | What proves our systems or your shared platforms are not part of the unpatched tail? | Periodic exposure attestation backed by patch completion reports against named advisories | Current version/build report for internet-facing and shared systems; patch completion report mapped to the specific advisory |
30-minute review procedure: (1) List your top ten suppliers and mark who administers edge devices or shared applications. (2) Send the matching matrix row as an evidence request, not a questionnaire. (3) Record who returned dated artifacts versus policy statements — that split is your real supplier risk register. This procedure is lilMONSTER's original contribution; it is a review exercise, not a test of any supplier system.
FAQ
Doesn't a SOC 2 report or certification cover this? No. Certifications attest to control design at a point in time. They do not evidence that a specific advisory — the ACSC device campaign or the PaperCut zero-day — was actioned on your instances within days.
What if a supplier refuses to provide patch evidence? Treat refusal as a data point, not a dead end: record it, apply risk acceptance at the right management level, and make evidence delivery a contract renewal condition.
We're mostly cloud-hosted — does this apply? Partly. Cloud shifts responsibility but does not remove it: SaaS suppliers still run applications that get zero-days (the PaperCut pattern), and someone still administers the edge devices your traffic crosses (the ACSC pattern). The matrix rows just point at different suppliers.
How fast should a contract patch SLA be? That is your negotiation, informed by how quickly exploitation follows disclosure — the PaperCut case shows abuse of zero-days before and after patching, per BleepingComputer. Set windows you can verify with dated tickets.
Conclusion
The strongest position this quarter is not a better questionnaire — it is three timed, evidence-backed obligations with your critical suppliers: named edge-device accountability with patch tickets, an application inventory with update notifications, and exposure attestations backed by version reports. Run the 30-minute review, send the matrix rows, and file the artifacts where your insurer, auditor, and next tender can reach them. If you want help drafting the evidence requests and contract clauses for your supplier list, book a consultation at https://consult.lil.business/ — scoping, access, and rules of engagement are agreed in writing before anything touches a live system.