A new Rubrik Zero Labs report evaluating more than 400 software supply chain security incidents between January and July of this year underscores a point many security leaders have been reluctant to wake up to: prevention alone is a losing strategy.
The alarming frequency, technical maturity, and number of available targets for software supply chain compromises mean cyber resilience must be integrated into the foundational architecture of enterprise defense planning. Threat actors increasingly view the compromise of source code and developer credentials as the key to cascading attacks that deliver big paydays across a wide range of targets.
AI agent marketplaces like Hugging Face and ClawHub are worsening the severity of the supply chain problem. Threat actors are increasingly targeting these platforms due to their relatively immature security operations. The study noted more than 575 compromised "skills" deployed across popular registries.
An organization’s own defenses are no longer sufficient for protecting against attacks targeting all of the open-source code, developer platforms, and infrastructure underpinning their IT estate.
Nevertheless, spending on prevention continues to outpace spending on recovery, a trend predicted to hold through 2030.
But four key findings from our latest report fatally undermine defensive strategies that disproportionately favor prevention.
1. Incident response and containment windows have essentially disappeared
A single industrialized, high-velocity campaign dubbed Megalodon was able to inject more than 5,700 malicious commits into 5,561 GitHub repositories within a single six-hour window. Following this mass compromise, the threat actors behind the campaign prioritized the exfiltration of cloud credentials, SSH keys, and CI/CD secrets, ensuring the group would be able to embed itself even more deeply into the software supply chain.
Speed now complements the scale of these attacks. Google M-Trends research indicates that the transition from initial vulnerability exploitation to active ransomware deployment can occur in as little as 22 seconds, making effective human intervention essentially impossible. Instead, security teams must prioritize automated detection and containment to keep pace with near-instantaneous breakout times.
2. Ransomware payments no longer guarantee recovery
TeamPCP, the most prolific threat actor targeting supply chains from our study, enlists a ransomware affiliate known as “Vect” that makes large files “mathematically irrecoverable” post-encryption. A structural flaw within the ransomware essentially acts as a wiper for compromised files. This ensures that even victims willing to pay threat actors are still subject to irrecoverable loss and emphasizes the importance of immutable backup capabilities.
Given that TeamPCP emerged as the dominant criminal supply chain operator during our study, linked to approximately 34.1% of all attributable incidents, this is no niche threat. The financially-motivated threat group's technical sophistication, opportunism, and specialization make it a threat to a broad range of target organizations.
3. The upstream blast radius is expansive–and expanding
During the period of our study, the compromise of a single WordPress plugin known as Smart Slider 3 Pro impacted more than 900,000 websites. Another campaign by the Southeast Asia-based financially-motivated Funnull group is estimated to affect millions of users daily, on an ongoing basis. The CDN/CMS poisoning campaign illustrates how the compromise of shared infrastructure can expand the blast radius of an attack exponentially.
Ultimately, these incidents do not unfold in isolation. They represent cascading failures spanning entire, interconnected technology ecosystems underpinning organizations' operations. Often unseen webs of complexity mean an organization’s risk exposure is only ever partially under its own control.
4. Bad actors hide out in backups
Backup telemetry acts as a record of cyber threats that have successfully skirted perimeter defenses. The presence of malware families including Atomic Stealer (AMOS), BeaverTail, and WAVESHAPER.V2 demonstrates that registry-based threats consistently go undetected by email, endpoint, and firewall defenses, only leaving their tell-tale signatures at the data layer.
Trojanized skills on AI marketplaces, "fake recruiter" scams, and maintainer-account hijacking are all supply chain strategies used to evade perimeter-based defenses, empirical evidence that front-line prevention alone is insufficient.
Because these vectors exploit trust relationships rather than technical vulnerabilities, they are largely undetectable by controls built to flag malware or anomalous behavior. This gap between what perimeter tools are designed to catch and what actually reaches production environments makes data-layer telemetry an essential area of visibility.
Resilience: The metric that matters
The latest Rubrik Zero Labs report confirms that prevention alone is not a viable strategy for software supply chain risk. Cyber resilience is the critical determinant of whether a supply chain compromise is detected and contained or escalates into a catastrophic failure.
Immutable, isolated backups, near real-time detection of anomalous identity and CI/CD behavior, and validated recovery processes are critical when roughly 37% of incidents originate from identity and credential exploitation. A combination of high-velocity breakouts and long dwell times among sophisticated threat campaigns necessitates an “assume breach” mentality.
Rather than focusing solely on preventing the inevitable breach, new threat actor tactics require resilience and recovery receive equal prioritization.
Read the full report: Software Supply Chain Threat Landscape 2026: The Identity Crisis in Code
LATEST BLOGS