---
title: The rise of supply chain attacks - Codenotary
description: MONITOR & MANAGE THE RISK EXPOSURE OF YOUR APPLICATIONS WITH TRUESBOM®
image: https://codenotary.com/hubfs/Imported_Blog_Media/Blog-Default-Cloud-Feb-10-2023-08-07-19-1640-AM.jpg
---

**$ protect --distro linux --machines 25 --free**

[Start now](https://apps.codenotary.com/linux)

[![cn-logo-black-nobg](https://codenotary.com/hubfs/cn-logo-black-nobg.svg)](https://codenotary.com/)

- Product
  
  #### [![AgentMon Start](https://codenotary.com/hubfs/chub_backup/AgentMon%20Start.svg) **AgentMon Start** See what your AI agents are doing on your machine. TRY NOW →](https://codenotary.com/agentmon-start)
  
  #### [![AgentMon for Enterprise](https://codenotary.com/hubfs/AgentMon%20for%20Enterprise.svg) **AgentMon** Currently monitors more \> 7 million agent interactions/day. TRY NOW →](https://codenotary.com/agentmon)
  
  #### [![AgentX](https://codenotary.com/hubfs/AgentX.svg) **AgentX** Agentic network control middleware. TRY NOW →](https://codenotary.com/agent-network-control)
  
  #### [![Autonomous Security](https://codenotary.com/hubfs/Autonomous%20Security.svg) **Autonomous Security** AI Agents keep your servers secure. TRY NOW →](https://codenotary.com/trust)
- Use Cases
  
  #### [**AI Agent Risk Monitoring** Continuous oversight of autonomous agents across every environment.](https://codenotary.com/use-cases#risk)
  
  #### [**Autonomous Security Operations** Self-healing defenses that detect, contain, and remediate threats.](https://codenotary.com/use-cases#agentops)
  
  #### [**AI Coding Governance & Performance Monitoring** AI-generated code reviewed, tracked, and held to quality standards.](https://codenotary.com/use-cases#performance)
  
  #### [**AI Tool Cost & Usage Optimization** Spend and consumption optimized across every AI service in use.](https://codenotary.com/use-cases#cost)
  
  #### [**AI Tool Security & Policy Enforcement** Approved AI usage enforced with guardrails and policy controls.](https://codenotary.com/use-cases#security#security)
  
  #### [**Shadow AI Governance** Unsanctioned AI tools discovered, surfaced, and brought under control.](https://codenotary.com/use-cases#shadowit)
- [Blog](https://codenotary.com/blog)
- [Press](https://codenotary.com/press)
- Resources
  
  #### [**Integrations** Connect with your favorite tools and platforms. LEARN MORE →](https://codenotary.com/integrations)
  
  #### [**Support** Get help from our dedicated support team. GET HELP →](https://support.codenotary.com)
  
  #### [**Success Stories** Read how customers achieve their goals. READ MORE →](https://codenotary.com/success)
  
  #### [**Learn** Access documentation and learning resources. EXPLORE →](https://codenotary.com/learn)

[Login](https://apps.codenotary.com/auth/login)

[All posts](https://codenotary.com/blog/all)

 Apr 05, 2022

# The rise of supply chain attacks

 By  [Sebastian Wind](https://codenotary.com/blog/author/sebastian-wind)  ·   2 minute read

Supply chain attacks are on the [rise](https://newsroom.ibm.com/2022-02-23-IBM-Report-Manufacturing-Felt-Brunt-of-Cyberattacks-in-2021-as-Supply-Chain-Woes-Grew). Why are they so attractive to cybercriminals? The reason is simple. Most of the industry is not yet ready to efficiently defend against them and once successfully deployed the chances of having a big impact are high. Tampering with the [software supply chain of SolarWinds](https://Codenotary.com/blog/the-trusted-cicd-pipeline/) affected 18,000 customers. Even more widespread was the log4j exploit with a huge number of servers affected and a [targeting rate of 50%](https://www.zdnet.com/article/log4j-flaw-nearly-half-of-corporate-networks-have-been-targeted-by-attackers-trying-to-use-this-vulnerability/). Political activism also discovered the huge impact of supply chain attacks as seen in a famous `npm` package that was modified by its own developers to [spread their message and delete files.](https://www.bleepingcomputer.com/news/security/big-sabotage-famous-npm-package-deletes-files-to-protest-ukraine-war/) The biggest challenges of securing the software supply chain come from:

1. Open-Source Software
2. Vendor supplied Software
3. Insider Threats

For open-source software, it’s become really clear that we have to know what’s inside. Therefore the concept of SBOMs (Software Bill of Materials) will be [mandatory in the near future](https://www.zdnet.com/article/securing-the-open-source-ecosystem-sboms-are-no-longer-optional/). Operations of every IT company have to be enabled to quickly answer the following questions: what is running on my systems and where does it come from? Those question don’t sound very complicated but in reality, it is a nightmare to identify software in a complex environment and trace it. Code signing is an important concept to simplify that process. The idea is to sign every software artifact that comes from you therefore making it possible to instantly identify what is yours and what isn’t (also known as provenance checks). Codenotary offers code signing using a zero-trust architecture. It can also create SBOMs in any language and container.

Vendor supplied software remains difficult to handle. Vendors should supply SBOMs in the future to comply with [the cybersecurity act](https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/) of president Biden. Vendors will also benefit from that, given they don’t have to worry about panicked customers asking them if they are affected by a vulnerability. With Codenotary it is possible to attach the SBOMs to the signed software without having to worry about the SBOMs being lost or tampered.

One mostly overlooked threat is the insider attack. Large IT organizations have thousands of contractors and employees who represent a cross-section of society. They can make mistakes or even act outright maliciously. The example of the node developer from above who changed his code to spread a political message is just one possible scenario. Codenotary is built on a zero-trust architecture. It uses [immudb, an open source tamper-evident database](https://github.com/Codenotary/immudb). Attackers are not able to cover up their tracks.

**Conclusion**

![](https://codenotary.com/hubfs/Imported_Blog_Media/codenotarycloudimg-1024x457-1.png)

Supply chain attacks and vulnerabilities are already there. Most of the businesses in the industry have been already affected. Exploits like log4j will pop up again and again. Therefore it is important to quickly identify and remove unwanted software to not get targeted by cyber attacks. [Codenotary Cloud is offers an all-in-one solution for a secure software supply chain.](https://Codenotary.com/products/ci-cd/) It complies with the cyber security executive order and feature a zero-trust model by the use of Codenotary’s immudb. Codenotary Cloud can be integrated easily not only in Cloud environments but also in legacy platforms.

[![Share on twitter](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/twitter-color.png?width=35&height=35&name=twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://codenotary.com/blog/the-rise-of-supply-chain-attacks&utm_medium=social&utm_source=twitter&url=https://codenotary.com/blog/the-rise-of-supply-chain-attacks&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on facebook](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/facebook-color.png?width=35&height=35&name=facebook-color.png)](http://www.facebook.com/share.php?u=https://codenotary.com/blog/the-rise-of-supply-chain-attacks&utm_medium=social&utm_source=facebook) [![Share on linkedin](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/01-marketplace/linkedin-color.png?width=35&height=35&name=linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://codenotary.com/blog/the-rise-of-supply-chain-attacks&utm_medium=social&utm_source=linkedin) [![Share on pinterest](https://4059529.fs1.hubspotusercontent-na1.net/hub/4059529/hubfs/pinterest.jpg?width=35&height=35&name=pinterest.jpg)](http://pinterest.com/pin/create/button/?url=https://codenotary.com/blog/the-rise-of-supply-chain-attacks&utm_medium=social&utm_source=pinterest&media=)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Sebastian Wind",
    "url" : "https://codenotary.com/blog/author/sebastian-wind"
  },
  "dateModified" : "2023-02-14T21:19:09.558Z",
  "datePublished" : "2022-04-05T18:57:34.000Z",
  "headline" : "The rise of supply chain attacks - Codenotary",
  "image" : [ "https://codenotary.com/hubfs/Imported_Blog_Media/Blog-Default-Cloud-Feb-10-2023-08-07-19-1640-AM.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://codenotary.com/blog/the-rise-of-supply-chain-attacks",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://codenotary.com/hubfs/logo-light.svg"
    },
    "name" : "Codenotary, Inc."
  }
}
```

```json
{
  "@context" : "http://schema.org",
  "@type" : "Article",
  "author" : {
    "@type" : "Person",
    "name" : [ "Sebastian Wind" ],
    "url" : "https://codenotary.com/blog/author/sebastian-wind"
  },
  "datePublished" : "2022-04-05T18:57:34+0000",
  "description" : "MONITOR & MANAGE THE RISK EXPOSURE OF YOUR APPLICATIONS WITH TRUESBOM®",
  "headline" : "The rise of supply chain attacks",
  "image" : "https://23873599.fs1.hubspotusercontent-na1.net/hubfs/23873599/Imported_Blog_Media/Blog-Default-Cloud-Feb-10-2023-08-07-19-1640-AM.jpg",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://cdn2.hubspot.net/hubfs/23873599/logo-light.svg"
    },
    "name" : ""
  },
  "url" : "https://codenotary.com/blog/the-rise-of-supply-chain-attacks"
}
```