Supply-chain attacks

Compromising one supplier reaches all their customers at once, which is why it is worth an attacker's effort.

The economics are compelling: months of work against a single software vendor yields access to thousands of organisations through an update they will install willingly. It is also why these incidents are so hard to detect, since the delivery mechanism is the legitimate one.

Checked against the primary source.

More on Supply chain & third parties