Skip to main content
Resources / Webinars / Three Attacks, Three Weeks: A Technical Autopsy of the AI Supply Chain Crisis

10 juni 2026

Three Attacks, Three Weeks: A Technical Autopsy of the AI Supply Chain Crisis

In a three-week span in the spring of 2026, the security landscape shifted. Three distinct threat actors, including a North Korean state-sponsored operator launched Tier-1 supply chain attacks against widely trusted software: LiteLLM (AI infrastructure), Axios (the most downloaded JavaScript HTTP client), and CPU-Z (a trusted system utility). No perimeter was breached. The attack arrived through trusted software organizations had already approved.

This is the attack vector boards need to understand: sophisticated adversaries are targeting dependencies, not defenses. Trusted software is now the weapon. 

 

The board-level question that follows is: what is our maximum probable loss if a dependency in our build pipeline is weaponized against us? Most organizations cannot answer that today.

Gerelateerde resources