Software Supply Chain Security Crisis Deepens
48% of breaches now originate in the supply chain, signaling that current TPRM approaches have failed. New defenses: GitHub and PyPI added time-based cooldowns to slow supply chain attacks (Dependabot 3-day wait, PyPI 14-day block). New funding: Risk Ledger secured £24m Series B for network-based TPRM. Notable attacks: RubyGems SleeperGem hijacked dormant maintainer accounts, TeamPCP attack on VS Code extensions exfiltrated 3,800 repos, Polymarket lost $3M via front-end supply chain attack. Deloitte launched an AI-driven software supply chain security platform powered by Claude. The signed, attested, and malicious problem challenges provenance assumptions. For CISOs, this reinforces the need for shared operational platforms and collective defense models.