Supply-chain Security

Trusting third-party code and dependencies compounds blast radius.

Short answer: Supply-chain security addresses risks introduced through third-party code, dependencies, build pipelines and vendor access — one compromise can reach many downstream consumers.

Evidence: CISA · MITRE · Research · Human reviewed

Definition

Supply-chain security addresses risks introduced through third-party code, dependencies, build pipelines and vendor access — one compromise can reach many downstream consumers.

Current Landscape
Backdoored open-source packages
Recent Changes
2020: SolarWinds compromise reshapes software supply chains · 2021: Log4Shell breaks the dependency chain
Evidence
CISA · MITRE · Research
Sources
NVD · CISA KEV · MITRE ATT&CK · Vendor Advisories

Major Entities

Timeline

  1. — SolarWinds compromise reshapes software supply chains
  2. — Log4Shell breaks the dependency chain

Latest Intelligence

  • Backdoored open-source packages
  • Build pipeline poisoning

Evidence & Sources

CISA · MITRE · Research · NVD · CISA KEV · MITRE ATT&CK

Related Intelligence

  • Threat actor: Dependency Confusion abusers
  • Threat actor: Nation State supply Chain operators
  • Campaign: Trusted update compromise
  • Campaign: Registry typosquatting
  • Research: Dependency blast-radius modeling
  • Research: SBOM adoption studies

Next Actions

Part of the OpenTrojan Security Knowledge Hub 2.0: <a href="/security/ransomware/">Ransomware</a> · <a href="/security/malware/">Malware</a> · <a href="/security/threat-intelligence/">Threat Intelligence</a> · <a href="/security/vulnerability-management/">Vulnerability Management</a> · <a href="/security/cloud-security/">Cloud Security</a> · <a href="/security/identity-security/">Identity Security</a> · <a href="/security/incident-response/">Incident Response</a> · <a href="/security/zero-day/">Zero Day</a> · <a href="/security/nation-state-threats/">Nation State Threats</a>