CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Your vendor’s vendor might be the real breach risk

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2460

As cited

Copy frozen at (site build).

threat intel

Your vendor’s vendor might be the real breach risk

A Field CTO from Zero Networks explains how breaches at vendors' subcontractors can compromise your organization through credentials and access tokens you never directly vetted. Attackers now target third-party vendors' vendors as an entry point into downstream customers' systems, leveraging trust relationships and access permissions that extend beyond direct vendor relationships.

Why it matters: Security practitioners need to assess and monitor the full supply chain of vendors and subcontractors, as compromised credentials at unknown third parties can grant attackers direct access to your environment.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary