Security News > 2021 > July > Top 5 things to know about supply chain attacks

Worried about supply chain attacks? Tom Merritt can help you understand your risk.
Whether its Stuxnet, SolarWinds or Microsoft Exchange, chances are you've read about supply chain attacks.
Hey, you follow all the security procedures right? You're not going to get targeted, right? Hmm. Here are five things to know about supply chain attacks.
At its base, a supply chain attack looks for a weak link in the companies that deliver you services and attempts to get into your network through them.
Although technically if you contract to a warehouse to guard your goods, and that warehouse gets robbed, it's a supply chain attack.
Supply chain attacks are not new but they also aren't going away.
News URL
Related news
- GitHub supply chain attack spills secrets from 23,000 projects (source)
- Supply chain attack on popular GitHub Action exposes CI/CD secrets (source)
- Google acquisition target Wiz links fresh supply chain attack to 23K pwned GitHub repos (source)
- GitHub Action hack likely led to another in cascading supply chain attack (source)
- GitHub Action supply chain attack exposed secrets in 218 repos (source)
- Coinbase Initially Targeted in GitHub Actions Supply Chain Attack; 218 Repositories' CI/CD Secrets Exposed (source)
- ⚡ THN Weekly Recap: GitHub Supply Chain Attack, AI Malware, BYOVD Tactics, and More (source)
- Recent GitHub supply chain attack traced to leaked SpotBugs token (source)
- SpotBugs Access Token Theft Identified as Root Cause of GitHub Supply Chain Attack (source)
- That massive GitHub supply chain attack? It all started with a stolen SpotBugs token (source)