Narrowing the Software Supply Chain Attack Vectors: The SSDF Is Wonderful but not Enough
Laurie A. Williams · IEEE Security & Privacy · 2024
Recent years have shown increased cyberattacks targeting less secure elements in the software supply chain and causing fatal damage to businesses and organizations. Past well-known examples of software supply chain attacks are the SolarWinds or log4j incidents that have affected thousands of customers and businesses. In 2023, Sonatype1 reported the detection of 245,000 malicious packages, double the number of malicious packages discovered in 2019–2022 combined.