Software supply chain attacks, explained
A single dependency can compromise thousands of companies at once. We explain how supply chain attacks work and how to limit dependency risk.
Attacks through dependencies, packages and software vendors, and practical ways to reduce supply chain risk.
A single dependency can compromise thousands of companies at once. We explain how supply chain attacks work and how to limit dependency risk.
Your security ends at your weakest supplier. How to assess contractor risk, what to put in contracts and how to monitor suppliers efficiently.
Pickle, SafeTensors, ONNX, and AI checkpoints explained: prevent code execution and build a controlled, verifiable model supply-chain pipeline.
In autumn 2025 the Shai-Hulud worm infected hundreds of npm packages, spreading itself. We analyse the supply chain attack and how to secure your pipeline.
In 2025, stolen OAuth tokens from Salesloft exposed hundreds of firms' Salesforce data — with no cracked passwords. A lesson on integration risk.
Book a free consultation. We'll talk about your infrastructure and real priorities.