Cybersecurity definition
What is Supply Chain Attack?
By Cyber Tool Stack Editorial TeamUpdated
Definition
An attack that compromises a trusted upstream component — a software dependency, a build pipeline, a vendor's update mechanism — so the malicious code rides along into every downstream organization that uses it.
Where Supply Chain Attack fits in the security landscape
These beginner lessons use this term while explaining the surrounding security control.
Related cybersecurity terms
TyposquattingPublishing a malicious package or domain with a name deliberately similar to a popular one — a common misspelling or swapped character — hoping a developer or user installs or visits the fake by mistake.SBOMSoftware Bill of MaterialsA formal, machine-readable inventory of every open-source and third-party component that makes up a piece of software, so an organization can quickly tell whether a newly disclosed vulnerability affects anything it runs.