EEP || Cybersecurity Investing Trendjacking (7d)

Supply Chain Security: ShapedPlugin Backdoor, EY Breach, Risk Ledger Funding

Supply Chain Security: ShapedPlugin Backdoor, EY Breach, Risk Ledger Funding

Key Questions

How was the ShapedPlugin backdoor delivered to customers?

Attackers inserted malicious code through a commercial update channel targeting paying customers. This supply-chain compromise bypassed typical open-source review processes.

What data was exposed in the EY breach?

The EY breach exposed client tax data through an IT support platform. It highlights persistent third-party risk gaps in professional services environments.

How much funding did Risk Ledger secure and for what purpose?

Risk Ledger raised £24M in Series B funding to expand its network-based supply chain security platform. The investment targets improved visibility into third-party risk relationships.

Why is third-party risk considered a critical blind spot?

Third-party risk remains a persistent vulnerability because organizations often lack full visibility into vendor security practices. Recent incidents like ShapedPlugin and EY demonstrate how these gaps can be exploited.

What regulatory pressure is emerging around software supply chains?

New directives require defense contractors to map software components in their supply chains. This reflects growing government focus on software bill of materials and provenance.

ShapedPlugin backdoored paying customers via commercial update channel. EY data breach exposed client tax data via IT support platform. Risk Ledger raises £24M Series B for network-based supply chain security. Third-party risk remains critical blind spot.

Sources (3)
Updated Jul 21, 2026
How was the ShapedPlugin backdoor delivered to customers? - EEP || Cybersecurity Investing Trendjacking (7d) | NBot | nbot.ai