Supply Chain and Third-Party Risk Management
Originally reported viaCISA Software Supply Chain Security / Sonatype State of the Software Supply ChainSoftware supply chain attacks tripled in 2025. The pattern is well understood: rather than targeting a hardened enterprise directly, adversaries compromise a trusted vendor and ride that trust relationship into hundreds of downstream victims simultaneously. SolarWinds, Log4j, the XZ Utils backdoor — each demonstrated that the supply chain is the most force-multiplied attack vector available.
How supply chain attacks are evolving in 2026
Three patterns dominate: software build pipeline compromise (injecting malicious code into signed release artifacts), open-source package hijacking via typosquatting and maintainer account takeovers, and SaaS-to-SaaS attack chains where one compromised platform pivots through legitimate API integrations into connected services.
Managing open-source dependency risk
An SBOM (Software Bill of Materials) for every application you build or buy is now essential infrastructure — it enables rapid response when a new CVE affects a dependency and is increasingly required by regulators. Tools like Syft, SPDX, and CycloneDX make SBOM generation tractable; the challenge is operationalising SBOM data into your vulnerability management workflow.
- Tier vendors by access level and data sensitivity. Apply heightened controls to Tier 1 vendors with privileged access.
- Require vendors to notify you of security incidents within 24–48 hours contractually.
- Generate SBOMs for all in-house software and require them from software vendors.
- Run dependency confusion and typosquatting checks against your package registries.
- Continuously monitor critical vendors' external attack surfaces.
Stay ahead of the threat curve
Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.