Two SC Media Perspectives columns argue that third-party and software supply-chain exposure is increasingly driving enterprise risk, citing examples such as Broadcom’s disclosure of exploited-in-the-wild VMware zero-days and the XZ Utils backdoor as reminders that upstream compromise or latent vulnerabilities can create broad downstream impact. The commentary frames this as an operational asymmetry: patching and validation cycles lag attacker exploitation timelines, making vendor and dependency risk harder to manage than credential- and phishing-driven intrusions.
Separately, Dark Reading reports that threat actors—particularly ransomware groups—are expanding use of bring-your-own-vulnerable-driver (BYOVD) techniques on Windows to gain kernel-level privileges and terminate security tooling (e.g., EDR processes) prior to deploying ransomware, infostealers, or backdoors. The article highlights that attackers have even abused a legitimate driver whose certificate was revoked years ago, underscoring persistent gaps in Windows driver trust and enforcement. Another SC Media commentary adds that mobile apps represent a structural supply-chain risk because they are publicly distributed and easily reverse engineered, and it flags 2026-era mobile threats such as AI introduced via third-party SDKs and growing urgency around post-quantum cryptography planning due to “harvest now, decrypt later” collection of encrypted data.

Get the actors, campaigns, and ATT&CK mapping behind it.
9 events from the most recent confirmed update back to the earliest known activity.
An SC Media article argued that AI will accelerate both exploitation and defense, and recommended stronger third-party due diligence, zero-trust controls, and real-time exposure visibility to reduce supply-chain risk. The piece framed these measures as necessary responses to increasingly efficient exploit-driven attacks.
Dark Reading reported growing concern that ransomware groups and other threat actors are abusing bring-your-own-vulnerable-driver techniques to gain kernel access and disable security tools on Windows. Researchers and vendors called for stronger Microsoft defenses, including more frequent blocklist updates and tighter driver trust controls.
Recent VMware zero-day vulnerabilities were cited as examples of attackers increasingly using third-party software flaws to breach enterprises. The article notes that exploit code often appears quickly after disclosure, giving attackers an advantage over defenders.
An SC Media analysis identified five mobile security threats expected to shape 2026: unintended AI adoption through SDKs, post-quantum cryptography planning, scalable supply-chain compromise, privacy failures, and mobile apps as reconnaissance sources. It urged organizations to use mobile apps as early warning signals for broader enterprise risk.
The 2025 Verizon Data Breach Investigations Report documented broader trends showing third-party and supply-chain vulnerabilities, especially zero-days, playing a growing role in enterprise intrusions. The report was used to support claims that exploit-based compromise is becoming more common.
The XZ Utils backdoor incident emerged in late 2024, demonstrating how a widely reused open-source component could become a supply-chain compromise vector. The case was cited as a major example of software dependency risk.
Threat actors exploited zero-days in managed file transfer products including Fortra GoAnywhere and Cleo to steal data from organizations at scale. The incidents were cited as examples of how third-party software flaws can drive widespread enterprise compromise.
Microsoft enabled its Vulnerable Driver Blocklist by default starting with the Windows 11 2022 update, a defensive measure intended to prevent known exploitable drivers from loading. Later reporting criticized the blocklist for being updated too infrequently to keep pace with BYOVD abuse.
A legitimate EnCase driver from Guardian Software had a code-signing certificate that expired in 2010. Researchers later highlighted the driver as an example of how old signed drivers could still be abused in BYOVD attacks.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcedarkreading.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.