SIGNAL//DESK
cybersrc: NIST SP 800-161

supply chain attack

A supply chain attack is like a criminal sneaking a poisoned ingredient into a trusted food supplier's warehouse so that when you buy your regular groceries, you unknowingly bring the poison into your own home.

A supply chain attack occurs when an adversary compromises a trusted third-party component, software dependency, or update mechanism to gain unauthorized access to a downstream target, bypassing the target's direct perimeter defenses.

A supply chain attack is a vector-based compromise wherein an adversary subverts the integrity of a trusted upstream entity—such as a software dependency, build pipeline, or distribution channel—to inject malicious code or artifacts into a target environment, effectively leveraging the implicit trust established between the vendor and the consumer to facilitate unauthorized access or exfiltration.

evolution

  1. 1984 · history
    Ken Thompson's Trusting Trust

    Ken Thompson demonstrated how a compiler could be subverted to insert backdoors into software, establishing the theoretical basis for supply chain compromise.

  2. 2013 · history
    Target Corporation Breach

    Attackers gained access to Target's network by compromising the credentials of a third-party HVAC vendor, highlighting the risk of trusted partner access.

  3. 2020 · history
    SolarWinds Orion Compromise

    State-sponsored actors injected malicious code into the SolarWinds Orion software update mechanism, affecting thousands of downstream government and corporate customers.

  4. 2021 · history
    Kaseya VSA Ransomware Attack

    The REvil ransomware group exploited a vulnerability in Kaseya's remote management software to push malicious updates to hundreds of managed service providers simultaneously.

seen in events


← all terms