# Cybersecurity Venture's 2023 Software Supply Chain Attack Report

DevFeed: [Cybersecurity Venture's 2023 Software Supply Chain Attack Report](<https://devfeed.tech/articles/cybersecurity-venture-s-2023-software-supply-chain-attack-report-7881.md>)

Original publisher: [Read original article](<https://snyk.io/blog/cybersecurity-ventures-2023-software-supply-chain-attack-report/>)

Author: Sydney Milligan

Published: 2023-10-10T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [software supply-chain attack](<https://devfeed.tech/topics/software-supply-chain-attack.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data-breaches](<https://devfeed.tech/tags/data-breaches.md>), [developer](<https://devfeed.tech/tags/developer.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [report](<https://devfeed.tech/tags/report.md>), [saas](<https://devfeed.tech/tags/saas.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [security-attacks](<https://devfeed.tech/tags/security-attacks.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-attack](<https://devfeed.tech/tags/software-supply-chain-attack.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

The article summarizes findings from Cybersecurity Ventures' 2023 Software Supply Chain Attack Report. It predicts that the global cost of software supply chain attacks could reach nearly $138 billion by 2031 and explains how software complexity, cloud applications, and operational pipelines increase supply chain risk. It describes common attack methods, including social engineering, phishing, stolen credentials, CI/CD pipeline compromise, vulnerability exploitation, open-source component targeting, typosquatting, insider threats, and cloud hijacking. The article also examines the 2020 SolarWinds attack, in which a backdoor inserted into an Orion update affected approximately 18,000 customers and put critical infrastructure operations at risk.

## Source excerpt

Cybersecurity Ventures predicts the global cost of software supply chain attacks will reach nearly $138 billion by 2031. Learn more by reading the 2023 Software Supply Chain Attack Report.