Evidence over alarm
← All explainers
THE EXPLAINER DESK /

Supply chain.

Attacking the things other people depend on.

PLAIN-LANGUAGE GUIDE · 2 MIN READ

What does it mean?

Modern software is assembled from shared parts. A supply-chain attack tampers with a part, an update, or a trusted service so the compromise can travel to the people who use it.

PICTURE THIS

Instead of breaking into every home, imagine tampering with a product before the store delivers it.

An illustration of the idea, not a literal account.

Why should I care?

One compromised building block can reach many organizations that never interacted with the original attacker.

A distinction worth keeping.

Publishing a harmful package is an action. Proving that people installed it, or that it caused damage, takes separate evidence.