The deep work behind
the wire.
Research-led explainers, breach postmortems, regulatory briefs, and playbooks. Long-form work from the Supplier Shield desk and Abilene Advisors partners.
Matches titles, excerpts, categories, and author bylines.
Every long read.
Long readJscrambler's own npm package was hijacked: a trusted supplier became a supply-chain vector
An attacker hijacked Jscrambler's npm package with a stolen publishing credential and shipped an infostealer to developers between 11 and 13 July 2026. The malware harvested cloud tokens, wallets and AI-assistant credentials from any machine that installed it. For third-party risk teams, the lesson is that a trusted dependency is a supplier, and its release channel can become the attack path.
Long readLidl online shop data breach started at an IT service provider, not the retailer's own systems
Lidl has told online shop customers in Germany, Belgium and the Netherlands that their data was stolen in a breach at an IT service provider, not in its own systems. Names, phone numbers, email addresses, dates of birth and customer numbers were taken; payment data is not yet ruled out. Under GDPR the controller stays accountable for a processor's breach.
Long readAdaptHealth breach reached patient data through a third-party contractor's stolen credentials
AdaptHealth told the SEC that attackers reached patient data through a third-party contractor's stolen credentials, obtained by social engineering. The number of affected individuals is not yet confirmed. For third-party risk teams, contractor and vendor accounts are part of the attack surface.
Long readHemmersbach ransomware claim: why a breach at an IT services supplier reaches toward its clients
A ransomware group has claimed a breach of Hemmersbach, a German IT services provider that works inside its clients' technology estates. Researchers say the exposed data includes credentials to the firm's own identity systems. Hemmersbach has not confirmed the attack and the scope is unverified. For third-party risk teams, the lesson is about vendor access: a supplier's stolen login can become a route toward the clients it serves.
Long readFake Paysafe, Skrill and Neteller SDKs on npm and PyPI turned payment developers into a supply-chain target
Researchers found 17 fake Paysafe, Skrill and Neteller packages on npm and PyPI that steal API keys and CI tokens from developer and build machines. Nothing was breached at the payment firms. The exposure came through a poisoned dependency, which shows why the package registry is a supplier.
Long readAccenture breach: source code and cloud keys claimed stolen from a supplier many firms rely on
Accenture confirmed a security incident on 8 July 2026 after a threat actor listed about 35 GB of source code and cloud access keys for sale. The company called it isolated and remediated, but did not confirm scope or client-data impact. For third-party risk teams, the exposure is the client pipelines and cloud tenants a services provider touches.
Long readKDDI email breach: how one shared email platform exposed up to 14.2 million logins across six ISPs
One email platform run by KDDI exposed the logins of up to 14.2 million customers across six Japanese internet providers. The lesson for third-party risk teams is concentration and fourth-party risk: many brands on one shared supplier system, breached through a third-party software flaw.
Long readAmazon employee data breach exposes hidden dangers in the digital supply chain
Amazon’s recent data breach reveals hidden risks in third-party vendors. Learn how proactive supply chain security can help prevent such vulnerabilities.
Long readBrowsers: The new AI battleground and 2025�s biggest security test
Browsers are the new AI security battleground. Anthropic�s Claude for Chrome shows how browser agents can boost productivity but expose enterprises to prompt injection, data leaks, and governance risks. Learn why AI browser security, agentic workflows, and third-party risk management must be built i...
Long readCould scrapping IP laws supercharge AI—or leave your business exposed?
As Dorsey and Musk push to scrap IP laws, learn how this AI shift could expose your business to third-party risks—and how to stay protected.
Long readCyber supply chain risk management: From visibility gaps to resilience at scale
Build a resilient cyber supply chain risk management program. Learn the latest market trends, key challenges, future predictions, and real-world case studies. Get a 90-day plan to reduce vendor risk and meet regulations like NIS2 and DORA.
Long readDeepSeek vs ChatGPT: What they mean for supplier risk management
DeepSeek AI vs. ChatGPT: A look at features, risks, and data privacy concerns. Learn how supply risk management can help businesses stay secure.
Long readDetailed analysis: Why EU and Swiss companies must rely on European-rooted cybersecurity partners
In a shifting geopolitical world, discover why European-rooted cybersecurity partners are critical for EU and Swiss organizations. Explore the growing supply chain threats, legal risks with U.S. tech providers, and the importance of digital sovereignty in third-party risk management (TPRM).
Long readFrom vendor breach to boardroom liability: How the EU AI act changes accountability for suppliers
The EU AI Act makes both vendors and buyers liable for supplier AI failures, fines can reach €35M or 7% of turnover. Supplier Shield helps you track and mitigate that risk.
Long readHow 4.2 Million Internet Hosts Were Hijacked: What You Need to Know
Discover how vulnerabilities in tunneling protocols expose 4.2M internet hosts to attacks. Learn about the risks, affected regions, and essential steps to protect your network and supply chain.
Long readHow can financial risks in a supply chain be managed?
Learn how to manage financial risks in supply chains effectively. Discover strategies to mitigate supplier instability, credit risks, and market volatility for resilient operations.
Long readHow Supplier Shield protects against data breach risks from third-party vulnerabilities
Discover how Supplier Shield helps mitigate risks from third-party and supplier vulnerabilities, protecting businesses from different risks.
Long readMastering supplier risk management: Your ultimate guide to building resilient and transparent supply chains
Learn how to effectively manage supplier risks by identifying, assessing, and mitigating potential disruptions to ensure smooth operations and compliance.
Long readNIS2 compliance in manufacturing: how to secure your supply chain and meet EU requirements
Discover how manufacturers can achieve NIS2 compliance, secure their supply chains, and reduce third-party risk. Learn practical steps and see how Supplier Shield simplifies compliance.
Long readStarbucks faces cyber attack fallout: Could your coffee routine be at risk?
Ransomware hits Starbucks supply chain—barista pay and schedules disrupted. Could your daily coffee fix be next? Here's what you need to know!
Long readSupplier risk management best practices to protect your supply chain in 2025
Explore supplier risk management best practices to mitigate disruptions, build resilient supply chains, and embrace future trends like blockchain and IoT.
Long readThe hidden risks of AI: What businesses can learn from AI cheating in chess
AI isn't perfect�learn from chess AI cheating incidents and find out how to safeguard your business against emerging cyber threats
Long readThe ultimate guide to building a risk-aware culture: strategies top companies use
Learn how top companies build a risk-aware culture to navigate emerging risks, improve decision-making, and boost resilience through training, technology, and certifications.
Long readWhat Is the EU AI Act? Complete Guide (2025)
EU AI Act is the world's first AI regulation with penalties up to €35M. Learn risk categories, compliance deadlines (2025-2027), and high-risk AI requirements.
Long readWhat Is TPRM? Third-Party Risk Management Explained (2025)
TPRM manages risks from vendors, suppliers, and partners. Learn why 30% of breaches involve third parties and how to implement TPRM for NIS2 and DORA compliance.
