Cyber resilience: supply chain, storage, cloud, and OT attack surface expansion
Key Questions
What supply chain security incidents were highlighted recently?
ShapedPlugin backdoored paying customers through a commercial update channel, while EY suffered a data breach exposing client tax data via an IT support platform.
Which company raised funding for supply chain security and how much?
Risk Ledger secured £24M in Series B funding to advance its network-based supply chain security platform.
Why are non-human identities becoming a governance priority?
Non-human identities for AI agents are emerging as a key focus area amid expanding attack surfaces in supply chain, storage, and cloud environments.
Supply chain security emerges as critical front: ShapedPlugin backdoored paying customers via commercial update channel. EY suffers data breach on IT support ticket platform, exposing client tax data. Risk Ledger secures £24M Series B for network-based supply chain security. Non-human identities for AI agents become governance priority; NHI access management market growing at 11.7% CAGR (healthcare 24.9%). Attackers targeting storage infrastructure directly (One Medical, Mount Royal) challenge backup-as-resilience assumptions. Cloud ransomware recovery article maps four attack pathways debunking cloud safety. OT remote access governance gap: 57% manage 6+ vendors but only 23% review credentials monthly, signaling shift from VPNs to centralized governance platforms. Both trends signal investment opportunity in continuous hardening and cloud/OT security solutions.