📦 Supply Chain Security theater
Tracks software and hardware supply-chain compromise: poisoned build systems, backdoored dependencies, vendor breaches, and trusted-update abuse. A single upstream implant can silently reach thousands of downstream victims, making early detection of injected code and malicious infrastructure critical.
Live indicators
3.7K
in this theater
High severity
0
score ≥ 0.75 (top 60)
Actors tracked
5
documented
Mapped sources
0
in catalog
🏹 Threat Actors
🦠 Malware & Tools
🛡 Exploited Vulnerabilities
| CVE | Vendor / Product | Ransomware | Malware |
|---|---|---|---|
| CVE-2025-26399 | SolarWinds Web Help Desk | KNOWN | ransomware (KEV-flagged) |
| CVE-2021-35211 | SolarWinds Serv-U | KNOWN | ransomware (KEV-flagged) |
| CVE-2026-28318 | SolarWinds Serv-U | — | |
| CVE-2025-40536 | SolarWinds Web Help Desk | — | |
| CVE-2025-40551 | SolarWinds Web Help Desk | — | |
| CVE-2024-28987 | SolarWinds Web Help Desk | — | |
| CVE-2024-28986 | SolarWinds Web Help Desk | — | |
| CVE-2024-38107 | Microsoft Windows | — | |
| CVE-2024-28995 | SolarWinds Serv-U | — | |
| CVE-2021-35247 | SolarWinds Serv-U | — | |
| CVE-2021-21315 | Npm package System Information Library | — | |
| CVE-2016-3643 | SolarWinds Virtualization Manager | — |
📚 Priority sources & datasets
📜 Supply Chain Security Playbook
- Collect build artifacts, package manifests, signed binaries, and SBOMs from monitored vendors and open-source registries.
- Normalize and hash suspect components, then diff against known-good releases and reproducible builds to isolate injected code.
- Detonate suspicious packages and updaters in a sandbox to extract C2 domains, loader chains, and persistence mechanisms.
- Map observed TTPs to ATT&CK and attribute to known intrusion sets (e.g., APT29 SolarWinds tradecraft) via code and infrastructure overlap.
- Publish vendor advisories and curated IOC feeds to downstream consumers and CISA.
- Trigger dependency quarantine, credential rotation, and rebuild-from-source across all impacted pipelines.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
🔗 Cross-domain pivots
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron