Supply chain & software security
Trust is an undeniable, if undesirable, part of supply chains. Trust is second to verification, but the challenge of today is software development has become a complex set of dependencies. API integrations, cloud services, open-source libraries, machine-generated code, software-as-a-service connections, and automated software builds. Grasping it from start to finish is a struggle.
Many companies no longer develop software in a vacuum. A single software application can depend on dozens of third-party components developed by other people or entities in different countries. The consequence is that companies are losing control over how their software reaches the production environment, who has access to it, and the security risks involved in each iteration of the software update process.
One breach reaches thousands
Consider the SolarWinds incident, in which attackers planted backdoors in SolarWinds Orion software updates, resulting in malware being installed across 18,000 companies (give or take) that were unaware of the infection.
Then, ShinyHunters carried out a slew of CRM attacks, using voice phishing and malicious OAuth applications to hijack Salesforce environments and gain API access. Hundreds of companies were affected, including luxury brands, travel entities, and tech companies. Significant amounts of consumer information were leaked.
The trend of attacking software vendors, managed service providers, CI/CD systems, update processes, and developer tools is growing, as attacking just one trusted supplier enables bad actors to access thousands of customers at once. Often, the initial attack itself is not very advanced. What makes these attacks successful is the trust inherent in software development ecosystems.
Pressure proliferates problems
AI is adding more pressure. As development teams embrace AI-coding assistants and automation systems to speed up development, their tolerance (and time) for vulnerability checking is decreasing. AI-generated code can introduce vulnerabilities, like logic flaws and dependencies, that developers might not verify before deploying.
Meanwhile, the proliferation of machine identities related to automation pipelines, cloud workloads, and development environments is escalating.
Visibility becomes resilience
The defender’s challenge lies in understanding systemic exposure. There is a trend toward more attention on issues such as software provenance, dependency mapping, code-signing integrity, identity governance, and runtime visibility throughout the software development life cycle. An issue that once only affected developers is now a board-level concern.
This is impacting the idea of resilience, too. Companies realise prevention will not be enough in interconnected supply chains. Firms must be able to detect when their dependencies are compromised, isolate the systems, gauge the impact, and ensure operations continue despite supplier or software component failures.
Maintaining visibility into software ecosystems, understanding how trust flows between suppliers and systems, and allowing them to react swiftly when trust is compromised. This is the advantage.
Top trends
More code means a larger attack surface: When developers ship more code, they ship more endpoints, integrations, configuration paths, and dependencies. Each one is something a security team eventually has to account for, whether for a routine assessment, an audit, an incident response, or a board-level risk conversation.
Code generation via AI raises governance issues: Auditors only care about three things, regardless of how the code was written: can you prove a vulnerability existed, that it got fixed, and if the testing can be repeated. “An AI suggested it and the developer approved it” doesn’t answer any of that. Neither does “the CI build passed.” And neither does a raw scanner report.
Visibility during runtime is more important than ever: Enterprises are paying closer attention to which software components are running in production environments, rather than relying solely on pre-deployment security checks.
Regulatory watch: EU AI Act
The European Parliament agreed on amendments to the AI Act on 16 June 2026, which allow delaying the deadlines for compliance with certain requirements for high-risk AI applications and making some elements of the Act simpler.
The changes will see some deadlines being deferred to 2 December 2027 and 2 August 2028. The Council adopted the final version of the amendment on 29 June 2026, and the amended regulation is set to be published soon.
CISO voice
“Supply chain attacks against software are successful due to the complex nature of modern trust relationships.
Where once organisations worried about their perimeter; they now defend an ecosystem of vendors, platforms, identities, and dependencies that is in constant flux.”
Innovation spotlight
One business gaining traction is Socket, an innovative startup that works to secure software supply chains by detecting malicious or compromised open-source packages before they are introduced into development environments. Its approach mirrors a surging industry demand for better, deeper visibility and proactive package risk analysis.
Barcelona Cybersecurity Congress update
This year’s Barcelona Cybersecurity Congress will cover the difficult task of securing software supply chains and gaining visibility into digital ecosystems. Among the topics to be covered are software resilience, the risks of AI-driven development, software supply chain vulnerabilities, and the adaptation of security strategies to the highly connected world.
Barcelona Cybersecurity Congress 2026
Dates: 3–5 November
Location: Barcelona
Co-located with: Smart City Expo World Congress
CONNECTING EUROPE’S CYBERSECURITY ECOSYSTEM