A supply chain attack compromises a company through a trusted vendor, for example by infecting a software update, a code library or a managed service provider's remote access. It works because the victim trusts what comes from that vendor, which is why third-party risk must be assessed.
How TecnetOne handles it: TecnetGRC
software supply chain attack, third-party risk, vendor compromise