{"id":42118,"date":"2021-08-03T11:28:32","date_gmt":"2021-08-03T11:28:32","guid":{"rendered":"http:\/\/8a2a327d-49e1-442d-8822-0faf973323f0"},"modified":"2021-08-03T11:28:32","modified_gmt":"2021-08-03T11:28:32","slug":"supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/","title":{"rendered":"Supply chain attacks are getting worse, and you are not ready for them"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/hub\/i\/r\/2019\/10\/16\/1fad666d-0736-4d13-850c-c70117348203\/thumbnail\/770x578\/e0f8487a963eba7933886b5a1d76e891\/istock-6386480021.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>The European Union Agency for Cybersecurity (ENISA) has analyzed 24 recent software supply chain attacks and concluded that strong security protection is no longer enough.&nbsp;<\/p>\n<p>Recent supply chain attacks in its analysis include those through SolarWinds Orion software, <a href=\"https:\/\/www.zdnet.com\/article\/mimecast-reveals-source-code-theft-in-solarwinds-hack\/\" target=\"_blank\" rel=\"noopener\">CDN provider Mimecast<\/a>, <a href=\"https:\/\/www.zdnet.com\/article\/rapid7-source-code-alert-data-accessed-in-codecov-supply-chain-attack\/\" target=\"_blank\" rel=\"noopener\">developer tool Codecov<\/a>, and <a href=\"https:\/\/www.zdnet.com\/article\/kaseya-ransomware-attack-1500-companies-affected-company-confirms\/\" target=\"_blank\" rel=\"noopener\">enterprise IT management firm Kaseya<\/a>.&nbsp;<\/p>\n<p>ENISA focuses on Advanced Persistent Threat (APT) supply chain attacks and notes that while the code, exploits and malware was not considered &#8220;advanced&#8221;, the planning, staging, and execution were complex tasks. It notes 11 of the supply chain attacks were conducted by known APT groups.&nbsp;<\/p>\n<p>&#8220;These distinctions are crucial to understand that an organization could be vulnerable to a supply chain attack even when its own defences are quite good and therefore the attackers are trying to explore new potential highways to infiltrate them by moving to their suppliers and making a target out of them,&#8221; <a href=\"https:\/\/www.enisa.europa.eu\/publications\/threat-landscape-for-supply-chain-attacks\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">ENISA notes in the report<\/a>.&nbsp;<\/p>\n<p><strong>SEE: <\/strong><a href=\"https:\/\/www.techrepublic.com\/resource-library\/whitepapers\/network-security-policy\/?ftag=CMG-01-10aaa1b\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\"><strong>Network security policy<\/strong><\/a><strong> (TechRepublic Premium)<\/strong><\/p>\n<p>The agency expects supply chain attacks to get a lot worse: &#8220;This is why novel protective measures to prevent and respond to potential supply chain attacks in the future while mitigating their impact need to be introduced urgently,&#8221; it said.<\/p>\n<p>ENISA&#8217;s analysis found that attackers focused on the suppliers&#8217; code in about 66% of reported incidents. The same proportion of vendors were not aware of the attack before it was disclosed.&nbsp;<\/p>\n<section class=\"sharethrough-top placeholder\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\"> <\/section>\n<p>&#8220;This shows that organisations should focus their efforts on validating third-party code and software before using them to ensure these were not tampered with or manipulated,&#8221; ENISA said, although this is something easier said than done.<\/p>\n<p>As the Linux Foundation <a href=\"https:\/\/www.zdnet.com\/article\/solarwinds-defense-how-to-stop-similar-attacks\/\">highlighted in the wake of the SolarWinds disclosure<\/a>, even reviewing source code \u2013 for both open source and unaudited proprietary software \u2013 probably wouldn&#8217;t have prevented that attack.&nbsp;<\/p>\n<p>ENISA is calling for coordinated action at an EU level and has outlined nine recommendations that customers and vendors should take.&nbsp;<\/p>\n<p>Recommendations for customers include:<\/p>\n<ul>\n<li>identifying and documenting suppliers and service providers;<\/li>\n<li>defining risk criteria for different types of suppliers and services such as supplier and customer dependencies, critical software dependencies, single points of failure;<\/li>\n<li>monitoring of supply chain risks and threats;<\/li>\n<li>managing suppliers over the whole lifecycle of a product or service, including procedures to handle end-of-life products or components;<\/li>\n<li>classifying of assets and information shared with or accessible to suppliers, and defining relevant procedures for accessing and handling them.<\/li>\n<\/ul>\n<p>ENISA recommends suppliers:<\/p>\n<ul>\n<li>ensure that the infrastructure used to design, develop, manufacture, and deliver products, components and services follows cybersecurity practices;<\/li>\n<li>implement a product development, maintenance and support process that is consistent with commonly accepted product development processes;<\/li>\n<li>monitor security vulnerabilities reported by internal and external sources, including third-party components;<\/li>\n<li>maintain an inventory of assets that includes patch-relevant information.<\/li>\n<\/ul>\n<p>The SolarWinds attack for example rattled Microsoft whose president Brad Smith said it was the &#8220;largest and most sophisticated attack the world has ever seen&#8221; and that it&nbsp;<a href=\"https:\/\/www.zdnet.com\/article\/microsoft-solarwinds-attack-took-more-than-1000-engineers-to-create\/\">probably took 1,000 engineers to pull off<\/a>. Alleged Russian intelligence hackers compromised SolarWinds&#8217; software build system for Orion to plant a backdoor that was distributed as a software to several US cybersecurity firms and multiple federal agencies.&nbsp;<\/p>\n<p><strong>SEE: <a href=\"https:\/\/www.zdnet.com\/article\/the-cybersecurity-jobs-crisis-is-getting-worse-and-companies-are-making-basic-mistakes-with-hiring\/\" target=\"_blank\" rel=\"noopener\">The cybersecurity jobs crisis is getting worse, and companies are making basic mistakes with hiring<\/a><\/strong><\/p>\n<p>The US Department of Justice (DoJ) revealed last week that 27 districts&#8217; Microsoft Office 365 email systems were&nbsp;<a href=\"https:\/\/www.zdnet.com\/article\/solarwinds-attackers-breached-email-of-us-prosecutors-says-department-of-justice\/\">compromised for at least six months beginning in May 2020<\/a>.<\/p>\n<p>The rise of state-sponsored supply chain attacks and criminal ransomware attacks that combine supply chain attacks, such as the Kaseya incident, has shifted the focus of discussions between the US and Russia.&nbsp;<\/p>\n<p>US president Joe Biden&nbsp;<a href=\"https:\/\/www.zdnet.com\/article\/biden-major-cyber-attack-could-lead-to-a-real-shooting-war\/\">last week said<\/a>&nbsp;a major cyberattack would be the likely cause of the US entering a &#8220;real shooting war&#8221; with another superpower.&nbsp;<\/p>\n<p> READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>EU cybersecurity think tank looks at 24 recent supply chain attacks, and warns that defences against them are not good enough.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":42119,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-42118","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Supply chain attacks are getting worse, and you are not ready for them 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Supply chain attacks are getting worse, and you are not ready for them 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-08-03T11:28:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"770\" \/>\n\t<meta property=\"og:image:height\" content=\"578\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Supply chain attacks are getting worse, and you are not ready for them\",\"datePublished\":\"2021-08-03T11:28:32+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\\\/\"},\"wordCount\":646,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them.jpg\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\\\/\",\"name\":\"Supply chain attacks are getting worse, and you are not ready for them 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them.jpg\",\"datePublished\":\"2021-08-03T11:28:32+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them.jpg\",\"width\":770,\"height\":578},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Supply chain attacks are getting worse, and you are not ready for them\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Supply chain attacks are getting worse, and you are not ready for them 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/","og_locale":"en_US","og_type":"article","og_title":"Supply chain attacks are getting worse, and you are not ready for them 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-08-03T11:28:32+00:00","og_image":[{"width":770,"height":578,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Supply chain attacks are getting worse, and you are not ready for them","datePublished":"2021-08-03T11:28:32+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/"},"wordCount":646,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them.jpg","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/","url":"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/","name":"Supply chain attacks are getting worse, and you are not ready for them 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them.jpg","datePublished":"2021-08-03T11:28:32+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them.jpg","width":770,"height":578},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/supply-chain-attacks-are-getting-worse-and-you-are-not-ready-for-them\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Supply chain attacks are getting worse, and you are not ready for them"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/42118","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=42118"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/42118\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/42119"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=42118"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=42118"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=42118"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}