
THREAT‑WATCH
Glossary
Supply Chain Attack
An attack that compromises a trusted third-party vendor or software component to reach that vendor's customers.
Instead of attacking a well-defended target directly, attackers compromise a supplier, software update mechanism, or managed service provider that the target trusts, then use that trusted relationship to reach many downstream victims at once. This is why vetting vendor security and monitoring third-party access has become as important as securing an organization's own systems.