<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/supply-chain-attacks-in-2026-risks-and-defenses-8tw06r1sa" -->

---
title: Supply Chain Attacks In 2026: Risks And Defenses | daily.dev
description: Third-party involvement in breaches jumped to 48% in Verizon&#x27;s 2026 Data Breach Investigations Report, up from 30% the prior year, underscoring that supply...
canonical: https://daily.dev/posts/supply-chain-attacks-in-2026-risks-and-defenses-8tw06r1sa
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Supply Chain Attacks In 2026: Risks And Defenses | daily.dev
og:description: Third-party involvement in breaches jumped to 48% in Verizon&#x27;s 2026 Data Breach Investigations Report, up from 30% the prior year, underscoring that supply...
og:url: https://daily.dev/posts/supply-chain-attacks-in-2026-risks-and-defenses-8tw06r1sa
og:image: https://api.daily.dev/og/posts/8tW06r1Sa.png
og:image:alt: Supply Chain Attacks In 2026: Risks And Defenses
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Supply Chain Attacks In 2026: Risks And Defenses

**[Cyble](https://daily.dev/sources/cyble)** · 6 min read · 0 upvotes · 0 comments

## Summary

Third-party involvement in breaches jumped to 48% in Verizon's 2026 Data Breach Investigations Report, up from 30% the prior year, underscoring that supply chain attacks now bypass traditional perimeter defenses. The piece revisits the Cl0p ransomware group's exploitation of MOVEit Transfer (CVE-2023-34362) and GoAnywhere MFT (CVE-2023-0669), which cascaded into breaches at over 2,700 organizations affecting 93 million people. It covers the July 29, 2026 release of updated Minimum Elements for a Software Bill of Materials by CISA, NSA, FBI and international partners, replacing the 2021 NTIA standard, and argues organizations need continuous vendor monitoring rather than periodic questionnaires. Cyble promotes its Third-Party Risk Management platform as the solution.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://cyble.com/blog/supply-chain-attacks-in-2026-vendor-risk>

## Questions this post answers

### What CVE did the Cl0p ransomware group exploit in the MOVEit Transfer breach?

Cl0p exploited a SQL injection flaw, CVE-2023-34362, in Progress Software's MOVEit Transfer platform, with exploitation beginning May 27, 2023. Progress published its own advisory on May 31, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on June 2, six days after exploitation began.

_Teams tracking managed file transfer risk follow vulnerability disclosures like this one on daily.dev._

### How many organizations and people were affected by the MOVEit breach?

By January 2024, breaches or downstream exposures tied to the MOVEit Transfer vulnerability affected more than 2,700 organizations and compromised the personal data of more than 93 million people, according to tracking by Emsisoft and KonBriefing Research. Censys had counted more than 3,000 MOVEit environments exposed to the internet before the flaw was disclosed or patched.

_Anyone assessing vendor exposure after a widescale breach can follow supply chain incident details on daily.dev._

### What changed in the 2026 Minimum Elements for a Software Bill of Materials guidance?

CISA, the NSA, the FBI, and international partners released the 2026 Minimum Elements for a Software Bill of Materials on July 29, 2026, updating and replacing the minimum elements NTIA published in 2021. The revision draws on more than 90 public comments and applies to all software, including open-source components, AI systems, and software delivered as a service.

_Security teams updating SBOM practices can track guidance changes like this on daily.dev._

## Similar posts on daily.dev

- [Cyble Reports Record Surge In Software Supply Chain Attacks](https://daily.dev/posts/cyble-reports-record-surge-in-software-supply-chain-attacks-9bkvjwbuh) · Cyble · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber)

[View this post on daily.dev](https://daily.dev/posts/supply-chain-attacks-in-2026-risks-and-defenses-8tw06r1sa)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Supply Chain Attacks In 2026: Risks And Defenses","url":"https://daily.dev/posts/supply-chain-attacks-in-2026-risks-and-defenses-8tw06r1sa","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/supply-chain-attacks-in-2026-risks-and-defenses-8tw06r1sa"},"datePublished":"2026-09-03T08:27:21.878Z","dateModified":"2026-09-03T08:33:20.050Z","description":"Third-party involvement in breaches jumped to 48% in Verizon's 2026 Data Breach Investigations Report, up from 30% the prior year, underscoring that supply...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/29d1684059041df54fb35805ce97c34f?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/29d1684059041df54fb35805ce97c34f?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Cyble","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Cyble","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/345d6009096c4c2da164d9d8e6ccfbe6","url":"https://daily.dev/sources/cyble"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/supply-chain-attacks-in-2026-risks-and-defenses-8tw06r1sa","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Cyble","item":"https://daily.dev/sources/cyble"},{"@type":"ListItem","position":3,"name":"Supply Chain Attacks In 2026: Risks And Defenses"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/supply-chain-attacks-in-2026-risks-and-defenses-8tw06r1sa#faq","mainEntity":[{"@type":"Question","name":"What CVE did the Cl0p ransomware group exploit in the MOVEit Transfer breach?","acceptedAnswer":{"@type":"Answer","text":"Cl0p exploited a SQL injection flaw, CVE-2023-34362, in Progress Software's MOVEit Transfer platform, with exploitation beginning May 27, 2023. Progress published its own advisory on May 31, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on June 2, six days after exploitation began. Teams tracking managed file transfer risk follow vulnerability disclosures like this one on daily.dev."}},{"@type":"Question","name":"How many organizations and people were affected by the MOVEit breach?","acceptedAnswer":{"@type":"Answer","text":"By January 2024, breaches or downstream exposures tied to the MOVEit Transfer vulnerability affected more than 2,700 organizations and compromised the personal data of more than 93 million people, according to tracking by Emsisoft and KonBriefing Research. Censys had counted more than 3,000 MOVEit environments exposed to the internet before the flaw was disclosed or patched. Anyone assessing vendor exposure after a widescale breach can follow supply chain incident details on daily.dev."}},{"@type":"Question","name":"What changed in the 2026 Minimum Elements for a Software Bill of Materials guidance?","acceptedAnswer":{"@type":"Answer","text":"CISA, the NSA, the FBI, and international partners released the 2026 Minimum Elements for a Software Bill of Materials on July 29, 2026, updating and replacing the minimum elements NTIA published in 2021. The revision draws on more than 90 public comments and applies to all software, including open-source components, AI systems, and software delivered as a service. Security teams updating SBOM practices can track guidance changes like this on daily.dev."}}]}
```

