The 2025 Software Supply Chain Security Report
Attacks Grow in Sophistication - Targeting AI, Crypto, Open Source, and Commercial Software
Attacks Grow in Sophistication - Targeting AI, Crypto, Open Source, and Commercial Software
Software supply chain attacks are an increasingly popular tool for malicious actors — including cybercriminal groups and nation-state hackers. And the rapid embrace of AI and machine learning (ML) by both enterprises and software producers is introducing new supply chain risks to those organizations.
Download this report to learn more about:
Software supply chain is one of the biggest challenges that we face as an industry. We really need to be able to know how much we trust that piece of software.
Tim Brown | CISO
Software supply chain attacks are becoming more sophisticated. In 2024, malicious actors zeroed in on build pipelines and prominent open-source projects in an effort to gain access to sensitive organizations and IT environments.
Cybercriminals and nation states continue to target and exploit endemic weaknesses in black-box, commercial-software binaries. RL analyzed 30 widely used commercial-software binaries, with many receiving a failing grade because they contained flaws.
Supply chain attacks on cryptocurrency applications and infrastructure were frequent. RL notes 23 attacks where attackers sought (and got) access to sensitive IT assets and diverted funds from cryptocurrency wallets.
RL surveyed top packages across three major open-source repositories: npm, PyPI, and RubyGems.
2024 saw the Common Vulnerabilities and Exposures (CVE) system for tracking software flaws falter, missing critical information needed by security teams.
See how the three pillars of software supply chain security can address this critical risk in the new Gartner report.
Learn MoreUnderstand the why, the how — and what actions your organization should take — in the new era of software supply chain security.
Learn MoreReversingLabs detected a more than 1300% increase in threats circulating via open-source package repositories between 2020 and 2023.
Learn More