Supply chain attack
Attack via the software supply chain — backdoor in a library, compromised build server, fake update — instead of directly against the target. SolarWinds (2020) and xz-utils (2024) are the big examples.
SolarWinds: backdoor was smuggled into an Orion build, 18,000 organizations got the update, Russian SVR actors got access to US federal agencies. xz-utils 2024: "Jia Tan" inserted a stealthy backdoor in an SSH-related lib after a 2-year social engineering of the maintainer — discovered by a Microsoft engineer who happened to benchmark. Mitigation: SBOM, reproducible builds, sigstore signing, lockfile pinning, dependency review before upgrade. No total defense — supply chain will be the next decade's biggest attack vector.