All resources

13 July 2026 · Threat Spotlight · CyberSec360 Australia

Threat Spotlight: Supply-Chain Attacks — When the Update Is the Intruder

The most unsettling class of modern attack doesn’t sneak past your defences — it arrives through the front door wearing a trusted badge. In a software supply-chain attack, criminals compromise a product or update channel you already rely on, and every customer who installs the update installs the intrusion. SolarWinds (2020) put the technique on front pages; the MOVEit file-transfer exploitation (2023) showed a single supplier flaw rippling into thousands of organisations; and a steady stream of poisoned open-source packages keeps the theme current.

Why attackers love the supply chain

  • Leverage: one compromise, thousands of victims — the economics beat attacking targets one by one.
  • Trust inheritance: updates from a known vendor bypass the suspicion (and often the controls) applied to strangers.
  • Visibility gap: few businesses can list every third-party component inside the software they run.

The SMB version of the problem

You likely run dozens of third-party tools — accounting, remote access, website plugins, browser extensions. An SMB can’t audit vendors’ codebases, and shouldn’t try. What it can do is manage blast radius: know what you run, restrict what each tool can touch, and watch behaviour so a trusted program acting strangely gets caught anyway.

Practical defences

  • Inventory: a simple list of the software and plugins you depend on — you can’t defend the unknown.
  • Least privilege for tools, not just people: does that plugin really need admin?
  • Keep patching — supply-chain risk is not an argument against updates; unpatched known flaws remain the bigger danger.
  • Behavioural EDR: the defence that doesn’t care whether malicious code arrived via a stranger or a trusted update.
  • Prefer vendors who publish security practices and disclose incidents quickly — how a supplier handles a flaw tells you everything.

You outsource software, but you can’t outsource accountability for what it can reach. Blast-radius thinking is the honest response to a risk you can’t fully see.

Want help with this in your business?

Book a free security check with our Sydney team — plain-English advice, no obligation.

Get a Free Security Check