Skip to content

Topic

Software supply chain attacks

Attacks that reach many victims at once by compromising a shared vendor, dependency or distribution channel rather than each target individually.

Current clusters

product1 publisher

Polymarket's signup flow treated a stolen SSN as a password

According to the Wall Street Journal, nearly 500 Polymarket US accounts were entered by people who typed in someone else's Social Security number. The flow's duplicate-identity check opened the account it matched instead of blocking the attempt.

Publishers:gizmodo.com

Reality

Evidence55
Adoption72
Hype gap−15
Incentives70
Confidence55
security3 publishers

Attackers rewrote Brevo's embedded scripts at Cloudflare's edge with a hardcoded full-permission key

Brevo says a long-lived Cloudflare key with full account permissions sat in its application source code, and the Worker built with it stripped Content-Security-Policy headers from scripts that Sansec estimates reach 100,000 sites.

Perspective Coverage

3 publishers
Builder
Builder 34%
Operator
Operator 48%
Investor
Investor 18%

Reality

Evidence78
Adoption60
Hype gap+20
Incentives58
Confidence72