Supply-chain Security
Trusting third-party code and dependencies compounds blast radius.
Short answer: Supply-chain security addresses risks introduced through third-party code, dependencies, build pipelines and vendor access — one compromise can reach many downstream consumers.
Evidence: CISA · MITRE · Research · Human reviewed
Definition
Supply-chain security addresses risks introduced through third-party code, dependencies, build pipelines and vendor access — one compromise can reach many downstream consumers.
Major Entities
- CVE — CVE-2024-3094 (xz backdoor)
- CVE CVE-2021-44228 — CVE-2021-44228 (Log4Shell)
Timeline
- — SolarWinds compromise reshapes software supply chains
- — Log4Shell breaks the dependency chain
Latest Intelligence
- Backdoored open-source packages
- Build pipeline poisoning
Evidence & Sources
CISA · MITRE · Research · NVD · CISA KEV · MITRE ATT&CK
Related Intelligence
- Threat actor: Dependency Confusion abusers
- Threat actor: Nation State supply Chain operators
- Campaign: Trusted update compromise
- Campaign: Registry typosquatting
- Research: Dependency blast-radius modeling
- Research: SBOM adoption studies
Next Actions
Part of the OpenTrojan Security Knowledge Hub 2.0: <a href="/security/ransomware/">Ransomware</a> · <a href="/security/malware/">Malware</a> · <a href="/security/threat-intelligence/">Threat Intelligence</a> · <a href="/security/vulnerability-management/">Vulnerability Management</a> · <a href="/security/cloud-security/">Cloud Security</a> · <a href="/security/identity-security/">Identity Security</a> · <a href="/security/incident-response/">Incident Response</a> · <a href="/security/zero-day/">Zero Day</a> · <a href="/security/nation-state-threats/">Nation State Threats</a>