Verizon 2025 DBIR: Third-party software risk takes the spotlight
ID: 770f67e6-9da5-55d2-bf4d-7bb4418433c3
STIX ID: report--770f67e6-9da5-55d2-bf4d-7bb4418433c3
Feed Name: ReversingLabs Blog
Date Published: 2025-04-24
Date Updated: 2026-04-29
Author: [email protected] (Carolynn van Arsdale)
The Verizon 2025 DBIR shows a significant increase in breaches linked to third-party software and supply-chain attacks—30% of 12,195 analyzed breaches involved third parties—while public repository scans reveal extensive exposed secrets (JWTs, CI/CD tokens, cloud API keys) with a median remediation time of 94 days, highlighting urgent third-party cyber-risk management and supply-chain security needs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
