[](https://www.paloaltonetworks.com/?ts=markdown) * [](https://www.paloaltonetworks.com/?ts=markdown) * Products Products AI Security [![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/prisma-AIRS-logo-nav.svg)](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) [AI Security Platform](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) * [AI Gateway](https://www.paloaltonetworks.com/ai-security/ai-gateway?ts=markdown) * [AI Model Security](https://www.paloaltonetworks.com/ai-security/ai-model-security?ts=markdown) * [AI Red Teaming](https://www.paloaltonetworks.com/ai-security/ai-red-teaming?ts=markdown) * [AI Runtime Security](https://www.paloaltonetworks.com/ai-security/ai-runtime-security?ts=markdown) * [Agent Security](https://www.paloaltonetworks.com/ai-security/agent-security?ts=markdown) * [AI Posture Management](https://www.paloaltonetworks.com/prisma/cloud/ai-spm?ts=markdown) Secure GenAI Tools * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) Network Security [![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/strata-logo-nav.svg)](https://www.paloaltonetworks.com/network-security?ts=markdown) [Secure the Network](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [Quantum Safe Security](https://www.paloaltonetworks.com/network-security/quantum-safe-security?ts=markdown) * [Next-Gen Trust Security](https://www.paloaltonetworks.com/network-security/next-gen-trust-security?ts=markdown) * [OT / Industrial Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown) * [Device \& IoT Security](https://www.paloaltonetworks.com/network-security/device-security?ts=markdown) * [5G Security](https://www.paloaltonetworks.com/network-security/5g-security?ts=markdown) * [Managed Firewalls - Azure](https://www.paloaltonetworks.com/network-security/cloud-ngfw-for-azure?ts=markdown) * [Managed Firewalls - AWS](https://www.paloaltonetworks.com/network-security/cloud-ngfw?ts=markdown) [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Advanced IP Defense](https://www.paloaltonetworks.com/network-security/advanced-ip-defense?ts=markdown) SASE [![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/prisma-sase-logo-nav.svg)](https://www.paloaltonetworks.com/sase?ts=markdown) [Secure Access (SASE)](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma Access (ZTNA)](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) Security Operations [![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/cortex-logo-nav.svg)](https://www.paloaltonetworks.com/cortex?ts=markdown) [Security Operations](https://www.paloaltonetworks.com/cortex?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Extended Detection \& Response](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Security Orchestration \& Automation](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Attack Surface Management](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Exposure Management](https://www.paloaltonetworks.com/cortex/exposure-management?ts=markdown) * [Email Security](https://www.paloaltonetworks.com/cortex/advanced-email-security?ts=markdown) * [Threat Intelligence Management](https://www.paloaltonetworks.com/cortex/threat-intel-management?ts=markdown) * [Agentic-first Automation](https://www.paloaltonetworks.com/cortex/agentix?ts=markdown) * [Identity Threat Detection and Response](https://www.paloaltonetworks.com/cortex/itdr?ts=markdown) [Endpoint Security](https://www.paloaltonetworks.com/cortex/endpoint-protection?ts=markdown) * [Endpoint Protection](https://www.paloaltonetworks.com/cortex/endpoint-protection?ts=markdown) * [Agentic Endpoint Security](https://www.paloaltonetworks.com/cortex/agentic-endpoint-security?ts=markdown) * [Ransomware Protection](https://www.paloaltonetworks.com/cortex/ransomware-protection?ts=markdown) * [Digital Forensics](https://www.paloaltonetworks.com/cortex/digital-forensics?ts=markdown) [Data Security](https://www.paloaltonetworks.com/cortex/data-security?ts=markdown) Cloud Security [![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/cortex-cloud-logo-nav.svg)](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) [Application Security Overview](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Application Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/application-security-posture-management?ts=markdown) * [Software Supply Chain Security](https://www.paloaltonetworks.com/cortex/cloud/software-supply-chain-security?ts=markdown) * [Infrasture-as-Code (IaC) Security](https://www.paloaltonetworks.com/cortex/cloud/infrastructure-as-code-security?ts=markdown) * [Software Composition Analysis](https://www.paloaltonetworks.com/cortex/cloud/software-composition-analysis?ts=markdown) * [Secrets Security](https://www.paloaltonetworks.com/cortex/cloud/secrets-security?ts=markdown) * [Open Partner Ecosystem](https://www.paloaltonetworks.com/cortex/cloud/appsec-partner-ecosystem?ts=markdown) [Cloud Posture Security Overview](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/cloud-security-posture-management?ts=markdown) * [Cloud Infrastructure Entitlement Management](https://www.paloaltonetworks.com/cortex/cloud/cloud-infrastructure-entitlement-management?ts=markdown) * [Data Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/data-security-posture-management?ts=markdown) * [AI Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/ai-security-posture-management?ts=markdown) * [Vulnerability Management](https://www.paloaltonetworks.com/cortex/cloud/vulnerability-management?ts=markdown) * [Cloud Attack Surface Management](https://www.paloaltonetworks.com/cortex/cloud/attack-surface-management?ts=markdown) [Cloud Runtime Security Overview](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Cloud Detection and Response](https://www.paloaltonetworks.com/cortex/cloud-detection-and-response?ts=markdown) * [Container \& Kubernetes Security](https://www.paloaltonetworks.com/cortex/cloud/kubernetes-and-container-security?ts=markdown) * [Cloud Workload Protection](https://www.paloaltonetworks.com/cortex/cloud/cloud-workload-protection?ts=markdown) * [API Security](https://www.paloaltonetworks.com/cortex/cloud/api-security?ts=markdown) * [Serverless Security](https://www.paloaltonetworks.com/cortex/cloud/serverless-security?ts=markdown) Identity Security [![](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/idira-logo-nav.svg)](https://www.paloaltonetworks.com/idira?ts=markdown) [Human Identities](https://www.paloaltonetworks.com/idira/human?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) [Machine Identities](https://www.paloaltonetworks.com/idira/machine?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) [See All Products](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [![Overview icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/logo-default-orange.svg) Overview](#products-panel-0) * [![AI Security icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-prisma-blue.svg) AI Security](#products-panel-1) * [![Network Security icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-strata.svg) Network Security](#products-panel-2) * [![SASE icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-prisma-blue.svg) SASE](#products-panel-3) * [![Security Operations icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-cortex.svg) Security Operations](#products-panel-4) * [![Cloud Security icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-cortex.svg) Cloud Security](#products-panel-5) * [![Identity Security icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-idira.svg) Identity Security](#products-panel-6) [See All Products](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) [![AI Security icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/prisma-AIRS-logo-nav.svg) AI Security Discover, assess and protect AI apps, agents and employee use of GenAI tools](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) [![Network Security icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/strata-logo-nav.svg) Network Security AI-powered NetSec with next-gen firewalls, inline defense and unified management](https://www.paloaltonetworks.com/network-security?ts=markdown) [![Security Operations icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/cortex-logo-nav.svg) Security Operations Stop cyberattackers with the industry's premier platform for autonomous security operations](https://www.paloaltonetworks.com/cortex?ts=markdown) [![SASE icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/prisma-sase-logo-nav.svg) SASE Protect with AI, secure AI use and operate with AI using agentic Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) [![Identity Security icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/idira-logo-nav.svg) Identity Security Identity security platform to secure every identity: human, machine and agentic](https://www.paloaltonetworks.com/idira?ts=markdown) [![Cloud Security icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/cortex-cloud-logo-nav.svg) Cloud Security Prevent risks from code to cloud with the leading agentic cloud security platform](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) [![AI Security logo](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/prisma-AIRS-logo-nav.svg)](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) [AI Security Platform](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) * [AI Gateway](https://www.paloaltonetworks.com/ai-security/ai-gateway?ts=markdown) * [AI Model Security](https://www.paloaltonetworks.com/ai-security/ai-model-security?ts=markdown) * [AI Red Teaming](https://www.paloaltonetworks.com/ai-security/ai-red-teaming?ts=markdown) * [AI Runtime Security](https://www.paloaltonetworks.com/ai-security/ai-runtime-security?ts=markdown) * [Agent Security](https://www.paloaltonetworks.com/ai-security/agent-security?ts=markdown) * [AI Posture Management](https://www.paloaltonetworks.com/prisma/cloud/ai-spm?ts=markdown) Secure GenAI Tools * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) [![Network Security logo](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/strata-logo-nav.svg)](https://www.paloaltonetworks.com/network-security?ts=markdown) [Secure the Network](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [Quantum Safe Security](https://www.paloaltonetworks.com/network-security/quantum-safe-security?ts=markdown) * [Next-Gen Trust Security](https://www.paloaltonetworks.com/network-security/next-gen-trust-security?ts=markdown) * [OT / Industrial Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown) * [Device \& IoT Security](https://www.paloaltonetworks.com/network-security/device-security?ts=markdown) * [5G Security](https://www.paloaltonetworks.com/network-security/5g-security?ts=markdown) * [Managed Firewalls - Azure](https://www.paloaltonetworks.com/network-security/cloud-ngfw-for-azure?ts=markdown) * [Managed Firewalls - AWS](https://www.paloaltonetworks.com/network-security/cloud-ngfw?ts=markdown) [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Advanced IP Defense](https://www.paloaltonetworks.com/network-security/advanced-ip-defense?ts=markdown) [![SASE logo](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/prisma-sase-logo-nav.svg)](https://www.paloaltonetworks.com/sase?ts=markdown) [Secure Access (SASE)](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma Access (ZTNA)](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) [![Security Operations logo](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/cortex-logo-nav.svg)](https://www.paloaltonetworks.com/cortex?ts=markdown) [Security Operations](https://www.paloaltonetworks.com/cortex?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Extended Detection \& Response](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Security Orchestration \& Automation](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Attack Surface Management](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Exposure Management](https://www.paloaltonetworks.com/cortex/exposure-management?ts=markdown) * [Email Security](https://www.paloaltonetworks.com/cortex/advanced-email-security?ts=markdown) * [Threat Intelligence Management](https://www.paloaltonetworks.com/cortex/threat-intel-management?ts=markdown) * [Agentic-first Automation](https://www.paloaltonetworks.com/cortex/agentix?ts=markdown) * [Identity Threat Detection and Response](https://www.paloaltonetworks.com/cortex/itdr?ts=markdown) [Endpoint Security](https://www.paloaltonetworks.com/cortex/endpoint-protection?ts=markdown) * [Endpoint Protection](https://www.paloaltonetworks.com/cortex/endpoint-protection?ts=markdown) * [Agentic Endpoint Security](https://www.paloaltonetworks.com/cortex/agentic-endpoint-security?ts=markdown) * [Ransomware Protection](https://www.paloaltonetworks.com/cortex/ransomware-protection?ts=markdown) * [Digital Forensics](https://www.paloaltonetworks.com/cortex/digital-forensics?ts=markdown) [Data Security](https://www.paloaltonetworks.com/cortex/data-security?ts=markdown) [![Cloud Security logo](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/cortex-cloud-logo-nav.svg)](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) [Application Security Overview](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Application Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/application-security-posture-management?ts=markdown) * [Software Supply Chain Security](https://www.paloaltonetworks.com/cortex/cloud/software-supply-chain-security?ts=markdown) * [Infrasture-as-Code (IaC) Security](https://www.paloaltonetworks.com/cortex/cloud/infrastructure-as-code-security?ts=markdown) * [Software Composition Analysis](https://www.paloaltonetworks.com/cortex/cloud/software-composition-analysis?ts=markdown) * [Secrets Security](https://www.paloaltonetworks.com/cortex/cloud/secrets-security?ts=markdown) * [Open Partner Ecosystem](https://www.paloaltonetworks.com/cortex/cloud/appsec-partner-ecosystem?ts=markdown) [Cloud Posture Security Overview](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/cloud-security-posture-management?ts=markdown) * [Cloud Infrastructure Entitlement Management](https://www.paloaltonetworks.com/cortex/cloud/cloud-infrastructure-entitlement-management?ts=markdown) * [Data Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/data-security-posture-management?ts=markdown) * [AI Security Posture Management](https://www.paloaltonetworks.com/cortex/cloud/ai-security-posture-management?ts=markdown) * [Vulnerability Management](https://www.paloaltonetworks.com/cortex/cloud/vulnerability-management?ts=markdown) * [Cloud Attack Surface Management](https://www.paloaltonetworks.com/cortex/cloud/attack-surface-management?ts=markdown) [Cloud Runtime Security Overview](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Cloud Detection and Response](https://www.paloaltonetworks.com/cortex/cloud-detection-and-response?ts=markdown) * [Container \& Kubernetes Security](https://www.paloaltonetworks.com/cortex/cloud/kubernetes-and-container-security?ts=markdown) * [Cloud Workload Protection](https://www.paloaltonetworks.com/cortex/cloud/cloud-workload-protection?ts=markdown) * [API Security](https://www.paloaltonetworks.com/cortex/cloud/api-security?ts=markdown) * [Serverless Security](https://www.paloaltonetworks.com/cortex/cloud/serverless-security?ts=markdown) [![Identity Security logo](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/idira-logo-nav.svg)](https://www.paloaltonetworks.com/idira?ts=markdown) [Human Identities](https://www.paloaltonetworks.com/idira/human?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) [Machine Identities](https://www.paloaltonetworks.com/idira/machine?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * Solutions Solutions By Use Case [![Drive AI Transformation icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/ai-page/teaser-block/teaser-icon-2.svg) Drive AI Transformation Scale enterprise AI adoption across employees, applications and agents with confidence and control](https://www.paloaltonetworks.com/ai-security?ts=markdown) [![Secure the Hybrid Network icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-strata.svg) Secure the Hybrid Network Stay ahead of AI-driven attacks with unified network security across hybrid environments](https://www.paloaltonetworks.com/network-security?ts=markdown) [![Accelerate Cloud Transformation icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-cortex.svg) Accelerate Cloud Transformation Build fast and innovate fearlessly with AI-driven protection from code to cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) [![Secure AI Coding icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/logo-default-orange.svg) Secure AI Coding Let AI coding do more, with you in control. Protect data, govern agents and control AI costs.](https://www.paloaltonetworks.com/secure-ai-coding?ts=markdown) [![Secure Every Identity icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-idira.svg) Secure Every Identity Stop identity-led breaches: Secure human, machine, and agentic identities with zero trust](https://www.paloaltonetworks.com/idira?ts=markdown) [![Enable Autonomous SOC icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-cortex.svg) Enable Autonomous SOC Fight AI with AI to stop threats at machine speed with the power of analytics and automation](https://www.paloaltonetworks.com/cortex/fight-ai-with-ai?ts=markdown) [![Achieve Cyber Resilience icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/icon-Unit42.svg) Achieve Cyber Resilience Partner with world-class experts to proactively reduce risk, recover rapidly, and outsmart emerging threats](https://www.paloaltonetworks.com/unit42/ai-advantage?ts=markdown) * Services Services Security Services [![](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/unit-logo-dark.svg)](https://www.paloaltonetworks.com/unit42?ts=markdown) Prepare for Emerging Risks * [AI Security](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/ai-security-assessment?ts=markdown) * [Frontier AI](https://www.paloaltonetworks.com/unit42/ai-advantage?ts=markdown) * [Respond to Cyber Attacks](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond/incident-response?ts=markdown) * [Digital Forensics](https://www.paloaltonetworks.com/unit42/respond/digital-forensics?ts=markdown) * [Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed Threat Hunting](https://www.paloaltonetworks.com/cortex/managed-threat-hunting?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown) * [Attack Surface Assessment](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/attack-surface-assessment?ts=markdown) * [Breach Readiness](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/breach-readiness-review?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/cloud-security-assessment?ts=markdown) * [Compromise Assessment](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/compromise-assessment?ts=markdown) * [Ransomware Readiness](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/ransomware-readiness-assessment?ts=markdown) * [Supply Chain](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/supply-chain-risk-assessment?ts=markdown) * [Tabletop Exercises](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/tabletop-exercises?ts=markdown) * [Unit 42 Retainer](https://www.paloaltonetworks.com/unit42/retainer?ts=markdown) [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown) * [Cyber Risk](https://www.paloaltonetworks.com/unit42/build-your-security-strategy/cyber-risk-assessment?ts=markdown) * [IR Plan Development](https://www.paloaltonetworks.com/unit42/build-your-security-strategy/IR-plan-and-development-review?ts=markdown) * [Security Program Design](https://www.paloaltonetworks.com/unit42/build-your-security-strategy/security-program-design?ts=markdown) * [SOC Assessment](https://www.paloaltonetworks.com/unit42/build-your-security-strategy/soc-assessment?ts=markdown) * [Virtual CISO](https://www.paloaltonetworks.com/unit42/build-your-security-strategy/virtual-ciso?ts=markdown) * [Zero Trust](https://www.paloaltonetworks.com/unit42/build-your-security-strategy/zero-trust-advisory?ts=markdown) Understand the Adversary * [Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown) * [Offensive Security](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/offensive-security-services?ts=markdown) Managed Firewalls Managed Firewalls * [Managed Firewalls - AWS](https://www.paloaltonetworks.com/network-security/cloud-ngfw?ts=markdown) * [Managed Firewalls - Azure](https://www.paloaltonetworks.com/network-security/cloud-ngfw-for-azure?ts=markdown) Customer Services [Global Customer Services](https://www.paloaltonetworks.com/services?ts=markdown) * [Education \& Training](https://www.paloaltonetworks.com/services/education?ts=markdown) * [Professional Services](https://www.paloaltonetworks.com/services/consulting?ts=markdown) * [Success Tools](https://www.paloaltonetworks.com/services/customer-success-tools?ts=markdown) * [Support Services](https://www.paloaltonetworks.com/services/solution-assurance?ts=markdown) * [Customer Success](https://www.paloaltonetworks.com/services/customer-success?ts=markdown) [Under Attack?](https://www.paloaltonetworks.com/unit42/contact-unit42?ts=markdown) * [Services Overview](#services-panel-0) * [Security Services](#services-panel-1) * [Managed Firewalls](#services-panel-2) * [Customer Services](#services-panel-3) [Under Attack?](https://www.paloaltonetworks.com/unit42/contact-unit42?ts=markdown) [![Security Services logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/unit-logo-dark.svg)](https://www.paloaltonetworks.com/unit42?ts=markdown) Prepare for Emerging Risks * [AI Security](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/ai-security-assessment?ts=markdown) * [Frontier AI](https://www.paloaltonetworks.com/unit42/ai-advantage?ts=markdown) * [Respond to Cyber Attacks](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond/incident-response?ts=markdown) * [Digital Forensics](https://www.paloaltonetworks.com/unit42/respond/digital-forensics?ts=markdown) * [Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed Threat Hunting](https://www.paloaltonetworks.com/cortex/managed-threat-hunting?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown) * [Attack Surface Assessment](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/attack-surface-assessment?ts=markdown) * [Breach Readiness](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/breach-readiness-review?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/cloud-security-assessment?ts=markdown) * [Compromise Assessment](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/compromise-assessment?ts=markdown) * [Ransomware Readiness](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/ransomware-readiness-assessment?ts=markdown) * [Supply Chain](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/supply-chain-risk-assessment?ts=markdown) * [Tabletop Exercises](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/tabletop-exercises?ts=markdown) * [Unit 42 Retainer](https://www.paloaltonetworks.com/unit42/retainer?ts=markdown) [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown) * [Cyber Risk](https://www.paloaltonetworks.com/unit42/build-your-security-strategy/cyber-risk-assessment?ts=markdown) * [IR Plan Development](https://www.paloaltonetworks.com/unit42/build-your-security-strategy/IR-plan-and-development-review?ts=markdown) * [Security Program Design](https://www.paloaltonetworks.com/unit42/build-your-security-strategy/security-program-design?ts=markdown) * [SOC Assessment](https://www.paloaltonetworks.com/unit42/build-your-security-strategy/soc-assessment?ts=markdown) * [Virtual CISO](https://www.paloaltonetworks.com/unit42/build-your-security-strategy/virtual-ciso?ts=markdown) * [Zero Trust](https://www.paloaltonetworks.com/unit42/build-your-security-strategy/zero-trust-advisory?ts=markdown) Understand the Adversary * [Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown) * [Offensive Security](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses/offensive-security-services?ts=markdown) Managed Firewalls * [Managed Firewalls - AWS](https://www.paloaltonetworks.com/network-security/cloud-ngfw?ts=markdown) * [Managed Firewalls - Azure](https://www.paloaltonetworks.com/network-security/cloud-ngfw-for-azure?ts=markdown) [Global Customer Services](https://www.paloaltonetworks.com/services?ts=markdown) * [Education \& Training](https://www.paloaltonetworks.com/services/education?ts=markdown) * [Professional Services](https://www.paloaltonetworks.com/services/consulting?ts=markdown) * [Success Tools](https://www.paloaltonetworks.com/services/customer-success-tools?ts=markdown) * [Support Services](https://www.paloaltonetworks.com/services/solution-assurance?ts=markdown) * [Customer Success](https://www.paloaltonetworks.com/services/customer-success?ts=markdown) * Industries Industries [![Financial Services icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/financial-icon-2.svg) Financial Services Secure with AI cybersecurity, fraud and ransomware prevention, compliance, and customer data protection](https://www.paloaltonetworks.com/industry/financial-services?ts=markdown) [![Manufacturing icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/manufacturing-icon-2.svg) Manufacturing Secure with OT security, ransomware defense, industrial cybersecurity, supply chain resilience, and continuity](https://www.paloaltonetworks.com/industry/manufacturing?ts=markdown) [![Retail and Hospitality icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/retail-icon-2.svg) Retail and Hospitality Secure with payment security, PCI compliance, ransomware and fraud prevention, and data protection](https://www.paloaltonetworks.com/industry/retail?ts=markdown) [![Healthcare and Life Sciences icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/healthcare-icon-2.svg) Healthcare and Life Sciences Secure patient and clinical data, medical device security, ransomware defense, and HIPAA compliance](https://www.paloaltonetworks.com/industry/healthcare?ts=markdown) [![Public Sector icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/public-sector-icon-2.svg) Public Sector Secure with Zero Trust, cyber defense, compliance, infrastructure protection, and citizen data security](https://www.paloaltonetworks.com/industry/public-sector?ts=markdown) [![Utilities icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/utilities-icon-2.svg) Utilities Secure with power grid protection, OT network security, ransomware defense, and critical infrastructure security](https://www.paloaltonetworks.com/industry/electric-utilities?ts=markdown) [![Transportation icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/transportation-icon-2.svg) Transportation Secure OT and connected infrastructure protection, ransomware defense, supply chain security, compliance](https://www.paloaltonetworks.com/industry/transportation-security?ts=markdown) [![Small and Medium Business icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/smb-icon-2.svg) Small and Medium Business Secure against cyber threats using AI-powered endpoint, network, browser, cloud, and MDR](https://www.paloaltonetworks.com/industry/small-medium-business-portfolio?ts=markdown) * Partners Partners NextWave * [Partner Program](https://www.paloaltonetworks.com/partners/nextwave-partner-portal?ts=markdown) * [Become a Partner](https://paloaltonetworks.my.site.com/NextWavePartnerProgram/s/partnerregistration?type=becomepartner) * [Request Partner Portal Access](https://paloaltonetworks.my.site.com/NextWavePartnerProgram/s/partnerregistration?type=requestaccess) * [Partner Portal Login](https://www.paloaltonetworks.com/partners/nextwave-partner-portal?ts=markdown) * [Find a Partner](https://paloaltonetworks.my.site.com/NextWavePartnerProgram/s/partnerlocator) Partner Ecosystem [Explore All Partners Find the right partner network tailored to your business needs, cloud environments, and security requirements](https://www.paloaltonetworks.com/partners?ts=markdown) [Cloud Service Partners Bring cloud native security and compliance to the entire development lifecycle](https://www.paloaltonetworks.com/partners/nextwave-for-csp?ts=markdown) [Frontier AI Alliance Outpace today's cyberattacks through a global ecosystem of leaders orchestrating unified defenses](https://www.paloaltonetworks.com/frontier?ts=markdown) [Global System Integrators Speed and secure digital transformation with the industry's best technology, people and intelligence](https://www.paloaltonetworks.com/partners/nextwave-for-gsi?ts=markdown) [Managed Security Service Providers Gain valuable resource oversight to help your businesses administer security strategies](https://www.paloaltonetworks.com/partners/managed-security-service-providers?ts=markdown) [Resellers Deliver the most comprehensive cybersecurity portfolio while expanding opportunities and profitability](https://www.paloaltonetworks.com/partners/resellers?ts=markdown) [Service Providers Protect mobile users, devices and applications with effective, flexible and easy to deploy cybersecurity](https://www.paloaltonetworks.com/partners/service-providers?ts=markdown) [Technology Partners Advance security and transformation with innovative technology partner integrations](https://www.paloaltonetworks.com/partners/technology-partners?ts=markdown) * Resources Resources ![Learn icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/resource-library-icon.svg) Learn * [Resource Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Analyst Reports](https://www.paloaltonetworks.com/resources/research?ts=markdown) * [Customer Stories](https://www.paloaltonetworks.com/customers?ts=markdown) * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Threat Vector Podcast](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [Unit 42 Threat Research](https://unit42.paloaltonetworks.com/) * [Knowledgebase](https://knowledgebase.paloaltonetworks.com/) * [Technical Documentation](https://docs.paloaltonetworks.com/) ![Engage icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/engage-icon-2.svg) Engage * [Webinars](https://www.paloaltonetworks.com/resources/webinars?ts=markdown) * [Demos](https://www.paloaltonetworks.com/demos?ts=markdown) * [Test Drive](https://www.paloaltonetworks.com/resources/test-drives?ts=markdown) ![Connect icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/connect-icon-2.svg) Connect * [Executive Briefings](https://www.paloaltonetworks.com/about-us/executive-briefing-program?ts=markdown) * [Events](https://events.paloaltonetworks.com/) * [Live Community](https://live.paloaltonetworks.com/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) ![Discover icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/logos/nav/discover-icon-2.svg) Discover * [Why Palo Alto Networks?](https://www.paloaltonetworks.com/why-paloaltonetworks?ts=markdown) * [Platform Approach](https://www.paloaltonetworks.com/why-paloaltonetworks/platformization?ts=markdown) * [Awards \& Recognition](https://www.paloaltonetworks.com/about-us/awards?ts=markdown) * [Global Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown) * [Cloud Locations](https://www.paloaltonetworks.com/products/regional-cloud-locations?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Trust 360 Program](https://www.paloaltonetworks.com/resources/whitepapers/trust-360?ts=markdown) ![Company icon](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/logo-default-orange.svg) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Management Team](https://www.paloaltonetworks.com/about-us/management?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en) * [Culture \& Benefits](https://jobs.paloaltonetworks.com/en/culture/) * [Ethics \& Compliance](https://www.paloaltonetworks.com/company/ethics-and-compliance?ts=markdown) * [Office Locations](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * ![search magnifying glass](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/search-black.svg) * us Language * USA (ENGLISH) * [AUSTRALIA (ENGLISH)](https://www.paloaltonetworks.com.au/cyberpedia/what-is-supply-chain-attack) * [BRAZIL (PORTUGUÉS)](https://www.paloaltonetworks.com.br/cyberpedia/what-is-supply-chain-attack) * [CANADA (ENGLISH)](https://www.paloaltonetworks.ca/cyberpedia/what-is-supply-chain-attack) * [CHINA (简体中文)](https://www.paloaltonetworks.cn/cyberpedia/what-is-supply-chain-attack) * [FRANCE (FRANÇAIS)](https://www.paloaltonetworks.fr/cyberpedia/what-is-supply-chain-attack) * [GERMANY (DEUTSCH)](https://www.paloaltonetworks.de/cyberpedia/what-is-supply-chain-attack) * [INDIA (ENGLISH)](https://www.paloaltonetworks.in/cyberpedia/what-is-supply-chain-attack) * [ITALY (ITALIANO)](https://www.paloaltonetworks.it/cyberpedia/what-is-supply-chain-attack) * [JAPAN (日本語)](https://www.paloaltonetworks.jp/cyberpedia/what-is-supply-chain-attack) * [KOREA (한국어)](https://www.paloaltonetworks.co.kr/cyberpedia/what-is-supply-chain-attack) * [LATIN AMERICA (ESPAÑOL)](https://www.paloaltonetworks.lat/cyberpedia/what-is-supply-chain-attack) * [MEXICO (ESPAÑOL)](https://www.paloaltonetworks.com.mx/cyberpedia/what-is-supply-chain-attack) * [SINGAPORE (ENGLISH)](https://www.paloaltonetworks.sg/cyberpedia/what-is-supply-chain-attack) * [SPAIN (ESPAÑOL)](https://www.paloaltonetworks.es/cyberpedia/what-is-supply-chain-attack) * [TAIWAN (繁體中文)](https://www.paloaltonetworks.tw/cyberpedia/what-is-supply-chain-attack) * [UK (ENGLISH)](https://www.paloaltonetworks.co.uk/cyberpedia/what-is-supply-chain-attack) * Accounts \& Support Accounts \& Support * Accounts * Customer * Partner * Employee * [Login to Download](https://www.paloaltonetworks.com/login?ts=markdown) * [Become a Member](https://www.paloaltonetworks.com/login?screenToRender=traditionalRegistration&ts=markdown) * Support * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [What's New](https://www.paloaltonetworks.com/resources?ts=markdown) * [Get Support](https://support.paloaltonetworks.com/SupportAccount/MyAccount) [Under Attack?](https://www.paloaltonetworks.com/unit42/contact-unit42?ts=markdown) * [Demos and Trials](https://www.paloaltonetworks.com/get-started?ts=markdown) [Discover how prevention starts before the attack at InterSECt 2026. Watch Now](https://www.paloaltonetworks.com/intersect?ts=markdown) [Prisma AIRS AI Gateway is now generally available](https://www.paloaltonetworks.com/ai-security/ai-gateway?ts=markdown) [](https://www.paloaltonetworks.com/?ts=markdown) Search All * [Tech Docs](https://docs.paloaltonetworks.com/search) Close search modal 1. [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) 2. [Cloud Security](https://www.paloaltonetworks.com/cyberpedia/cloud-security?ts=markdown) 3. [AppSec](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security?ts=markdown) 4. [What Is Agentic Endpoint Security?](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack?ts=markdown) Table of Contents * [What Is AppSec?](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security?ts=markdown) * [AppSec Explained](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security#appsec?ts=markdown) * [The Fundamentals of AppSec](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security#fundamentals?ts=markdown) * [Building Security into the Development Lifecycle](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security#building?ts=markdown) * [Implementing Secure Coding Practices](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security#implementing?ts=markdown) * [Application Security Testing](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security#testing?ts=markdown) * [Implementing Security in CI/CD Pipelines](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security#pipelines?ts=markdown) * [Securing Application Architecture](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security#architecture?ts=markdown) * [Access Control and Authentication](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security#access?ts=markdown) * [Monitoring and Incident Response](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security#monitoring?ts=markdown) * [Managing AppSec in Production](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security#managing?ts=markdown) * [Training and Building a Security-First Culture](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security#training?ts=markdown) * [AppSec Trends](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security#trends?ts=markdown) * [AppSec FAQs](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security#faqs?ts=markdown) * What Is a Supply Chain Attack? * [Software Supply Chain Attack Explained](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#software?ts=markdown) * [How Do Software Supply Chain Attacks Work?](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#how?ts=markdown) * [Common Software Supply Chain Attack Types and Vectors](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#common?ts=markdown) * [Real-World Software Supply Chain Attacks](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#attacks?ts=markdown) * [What Are the Best Practices to Detect and Prevent Software Supply Chain Attacks?](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#what?ts=markdown) * [How Palo Alto Networks Approaches Supply Chain Attack](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#approaches?ts=markdown) * [Related FAQs](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#faqs?ts=markdown) * [What Is Vibe Coding?](https://www.paloaltonetworks.com/cyberpedia/what-is-vibe-coding?ts=markdown) * [Vibe Coding Explained](https://www.paloaltonetworks.com/cyberpedia/what-is-vibe-coding#vibe?ts=markdown) * [How the Vibe Coding Process Works](https://www.paloaltonetworks.com/cyberpedia/what-is-vibe-coding#how?ts=markdown) * [Vibe Coding Versus Traditional Programming](https://www.paloaltonetworks.com/cyberpedia/what-is-vibe-coding#vs?ts=markdown) * [Why Vibe Coding Matters for Developers](https://www.paloaltonetworks.com/cyberpedia/what-is-vibe-coding#why?ts=markdown) * [Vibe Coding Limitations](https://www.paloaltonetworks.com/cyberpedia/what-is-vibe-coding#limitations?ts=markdown) * [Vibe Coding and Security](https://www.paloaltonetworks.com/cyberpedia/what-is-vibe-coding#security?ts=markdown) * [Vibe Coding FAQs](https://www.paloaltonetworks.com/cyberpedia/what-is-vibe-coding#faqs?ts=markdown) * [Cloud Security Service, Cloud Storage and Cloud Technology](https://www.paloaltonetworks.com/cyberpedia/cloud-security-service-cloud-storage-and-cloud-technology?ts=markdown) * [Cloud and Platform as a Service](https://www.paloaltonetworks.com/cyberpedia/cloud-security-service-cloud-storage-and-cloud-technology#cloud-and-pass?ts=markdown) * [Infrastructure as a Service -- The Public Cloud](https://www.paloaltonetworks.com/cyberpedia/cloud-security-service-cloud-storage-and-cloud-technology#information-as-a-service?ts=markdown) * [Comprehensive, Scalable Cloud Security with Flexible Licensing Options](https://www.paloaltonetworks.com/cyberpedia/cloud-security-service-cloud-storage-and-cloud-technology#scalable-cloud-security?ts=markdown) * [Cloud Security Service, Storage and Technology FAQs](https://www.paloaltonetworks.com/cyberpedia/cloud-security-service-cloud-storage-and-cloud-technology#faq?ts=markdown) * [What Is Sandboxing?](https://www.paloaltonetworks.com/cyberpedia/sandboxing?ts=markdown) * [Sandboxing Explained](https://www.paloaltonetworks.com/cyberpedia/sandboxing#sandboxing?ts=markdown) * [Sandboxing in Email Security](https://www.paloaltonetworks.com/cyberpedia/sandboxing#security?ts=markdown) * [Endpoint Sandboxing and EDR](https://www.paloaltonetworks.com/cyberpedia/sandboxing#endpoint?ts=markdown) * [Browser Isolation and Web Sandboxing](https://www.paloaltonetworks.com/cyberpedia/sandboxing#browser?ts=markdown) * [Sandboxing in Cloud-Native Workflows](https://www.paloaltonetworks.com/cyberpedia/sandboxing#workflows?ts=markdown) * [Sandbox Evasion and Threat Actor Tradecraft](https://www.paloaltonetworks.com/cyberpedia/sandboxing#tradecraft?ts=markdown) * [Real-World Case Studies in Sandboxing Effectiveness](https://www.paloaltonetworks.com/cyberpedia/sandboxing#effectiveness?ts=markdown) * [Feeding Sandboxed Intelligence into XDR and SOC Pipelines](https://www.paloaltonetworks.com/cyberpedia/sandboxing#feeding?ts=markdown) * [Sandboxing FAQs](https://www.paloaltonetworks.com/cyberpedia/sandboxing#faqs?ts=markdown) * [What Is SDLC Security?](https://www.paloaltonetworks.com/cyberpedia/what-is-secure-software-development-lifecycle?ts=markdown) * [SDLC Security Overview](https://www.paloaltonetworks.com/cyberpedia/what-is-secure-software-development-lifecycle#sdlc?ts=markdown) * [Security Across the Classic SDLC Phases](https://www.paloaltonetworks.com/cyberpedia/what-is-secure-software-development-lifecycle#security?ts=markdown) * [Common Vulnerabilities and Attack Vectors in the SDLC](https://www.paloaltonetworks.com/cyberpedia/what-is-secure-software-development-lifecycle#common?ts=markdown) * [Foundational Secure-SDLC Practices](https://www.paloaltonetworks.com/cyberpedia/what-is-secure-software-development-lifecycle#practices?ts=markdown) * [Tooling and Automation Layers](https://www.paloaltonetworks.com/cyberpedia/what-is-secure-software-development-lifecycle#tooling?ts=markdown) * [Frameworks and Standards for Secure SDLC](https://www.paloaltonetworks.com/cyberpedia/what-is-secure-software-development-lifecycle#frameworks?ts=markdown) * [DevSecOps Integration](https://www.paloaltonetworks.com/cyberpedia/what-is-secure-software-development-lifecycle#devsecops?ts=markdown) * [Metrics and Continuous Improvement](https://www.paloaltonetworks.com/cyberpedia/what-is-secure-software-development-lifecycle#metrics?ts=markdown) * [Advancements in Software Supply Chain Defense](https://www.paloaltonetworks.com/cyberpedia/what-is-secure-software-development-lifecycle#advancements?ts=markdown) * [Roadmap to Secure-SDLC Maturity](https://www.paloaltonetworks.com/cyberpedia/what-is-secure-software-development-lifecycle#roadmap?ts=markdown) * [SDLC Security FAQs](https://www.paloaltonetworks.com/cyberpedia/what-is-secure-software-development-lifecycle#faqs?ts=markdown) * [Application Security: A Practitioner's Guide](https://www.paloaltonetworks.com/cyberpedia/application-security?ts=markdown) * [Application Security Explained](https://www.paloaltonetworks.com/cyberpedia/application-security#application?ts=markdown) * [Types of Applications Organizations Need to Secure](https://www.paloaltonetworks.com/cyberpedia/application-security#types?ts=markdown) * [Whose Job Is It -- Developers or Security?](https://www.paloaltonetworks.com/cyberpedia/application-security#security?ts=markdown) * [A Pragmatic Guide for Security-Minded Developers](https://www.paloaltonetworks.com/cyberpedia/application-security#developers?ts=markdown) * [Types of Application Security Testing](https://www.paloaltonetworks.com/cyberpedia/application-security#testing?ts=markdown) * [Application Security Tools and Solutions](https://www.paloaltonetworks.com/cyberpedia/application-security#solutions?ts=markdown) * [Compliance Is Not Security, But It's Not Optional Either](https://www.paloaltonetworks.com/cyberpedia/application-security#compliance?ts=markdown) * [Application Security FAQs](https://www.paloaltonetworks.com/cyberpedia/application-security#faqs?ts=markdown) * [What Is Cloud Detection and Response (CDR)?](https://www.paloaltonetworks.com/cyberpedia/what-is-cloud-detection-and-response-cdr?ts=markdown) * [Cloud Detection and Response (CDR) Explained](https://www.paloaltonetworks.com/cyberpedia/what-is-cloud-detection-and-response-cdr#explained?ts=markdown) * [How CDR Works](https://www.paloaltonetworks.com/cyberpedia/what-is-cloud-detection-and-response-cdr#how?ts=markdown) * [Key Features of CDR](https://www.paloaltonetworks.com/cyberpedia/what-is-cloud-detection-and-response-cdr#key?ts=markdown) * [CDR and Other Detection and Response Approaches](https://www.paloaltonetworks.com/cyberpedia/what-is-cloud-detection-and-response-cdr#vs?ts=markdown) * [How CDR and XSIAM Work Together](https://www.paloaltonetworks.com/cyberpedia/what-is-cloud-detection-and-response-cdr#work?ts=markdown) * [How CDR Addresses Unique Challenges in Cloud Security](https://www.paloaltonetworks.com/cyberpedia/what-is-cloud-detection-and-response-cdr#addressing?ts=markdown) * [Key Capabilities of CDR](https://www.paloaltonetworks.com/cyberpedia/what-is-cloud-detection-and-response-cdr#capabilities?ts=markdown) * [How CDR Bridges SOC and Cloud Security](https://www.paloaltonetworks.com/cyberpedia/what-is-cloud-detection-and-response-cdr#bridging?ts=markdown) * [Challenges of Implementing CDR](https://www.paloaltonetworks.com/cyberpedia/what-is-cloud-detection-and-response-cdr#potential?ts=markdown) * [CDR Best Practices](https://www.paloaltonetworks.com/cyberpedia/what-is-cloud-detection-and-response-cdr#practices?ts=markdown) * [Cloud Detection and Response FAQs](https://www.paloaltonetworks.com/cyberpedia/what-is-cloud-detection-and-response-cdr#faqs?ts=markdown) * [How to Transition from DevOps to DevSecOps](https://www.paloaltonetworks.com/cyberpedia/devops-to-devsecops?ts=markdown) * [Initiate a Security-First Culture](https://www.paloaltonetworks.com/cyberpedia/devops-to-devsecops#initiate-a-security-first-culture?ts=markdown) * [Incorporate Secure DevOps Practices](https://www.paloaltonetworks.com/cyberpedia/devops-to-devsecops#devops-practices?ts=markdown) * [Automate and Monitor Security](https://www.paloaltonetworks.com/cyberpedia/devops-to-devsecops#automate-and-monitor-security?ts=markdown) * [Evaluate and Maintain Security Posture](https://www.paloaltonetworks.com/cyberpedia/devops-to-devsecops#maintain-security-posture?ts=markdown) * [Ensure Compliance and Effective Incident Response](https://www.paloaltonetworks.com/cyberpedia/devops-to-devsecops#effective-incident-response?ts=markdown) * [Continuous Improvement in Security](https://www.paloaltonetworks.com/cyberpedia/devops-to-devsecops#improvement-in-security?ts=markdown) * [DevOps to DevSecOps FAQs](https://www.paloaltonetworks.com/cyberpedia/devops-to-devsecops#faq?ts=markdown) * [How Does VMware NSX Security Work](https://www.paloaltonetworks.com/cyberpedia/how-does-vmware-nsx-security-work?ts=markdown) * [What Is the Software Development Lifecycle (SDLC)?](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle?ts=markdown) * [Software Development Lifecycle Explained](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#software?ts=markdown) * [Why the SDLC Matters](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#why?ts=markdown) * [Foundational Phases](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#phases?ts=markdown) * [Common SDLC Models](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#common?ts=markdown) * [Security and Compliance Integration](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#security?ts=markdown) * [SDLC in Context](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#context?ts=markdown) * [SDLC Challenges](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#challenges?ts=markdown) * [Choosing or Tailoring an SDLC Model](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#choosing?ts=markdown) * [SDLC Tooling and Automation](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#automation?ts=markdown) * [Version Control and CI/CD Pipelines](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#version?ts=markdown) * [Value-Stream Metrics and Visibility](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#visibility?ts=markdown) * [Cloud, On-Premises, and Hybrid Considerations](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#cloud?ts=markdown) * [Best-Practice Guidelines for High-Velocity Delivery](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#best?ts=markdown) * [Next Steps Toward Lifecycle Maturity](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#next?ts=markdown) * [Software Development Lifecycle FAQs](https://www.paloaltonetworks.com/cyberpedia/sdlc-software-development-lifecycle#faqs?ts=markdown) # What Is a Supply Chain Attack? 4 min. read Table of Contents * * [Software Supply Chain Attack Explained](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#software?ts=markdown) * [How Do Software Supply Chain Attacks Work?](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#how?ts=markdown) * [Common Software Supply Chain Attack Types and Vectors](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#common?ts=markdown) * [Real-World Software Supply Chain Attacks](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#attacks?ts=markdown) * [What Are the Best Practices to Detect and Prevent Software Supply Chain Attacks?](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#what?ts=markdown) * [How Palo Alto Networks Approaches Supply Chain Attack](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#approaches?ts=markdown) * [Related FAQs](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#faqs?ts=markdown) 1. Software Supply Chain Attack Explained * * [Software Supply Chain Attack Explained](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#software?ts=markdown) * [How Do Software Supply Chain Attacks Work?](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#how?ts=markdown) * [Common Software Supply Chain Attack Types and Vectors](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#common?ts=markdown) * [Real-World Software Supply Chain Attacks](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#attacks?ts=markdown) * [What Are the Best Practices to Detect and Prevent Software Supply Chain Attacks?](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#what?ts=markdown) * [How Palo Alto Networks Approaches Supply Chain Attack](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#approaches?ts=markdown) * [Related FAQs](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack#faqs?ts=markdown) Supply chain attacks compromise an organization by targeting the trusted components it relies on rather than the organization itself. Attackers infiltrate open-source packages, build systems, code repositories, or vendor software, then ride that trust straight into thousands of downstream victims. A single poisoned dependency can compromise an entire industry. ## Software Supply Chain Attack Explained A supply chain attack can target physical components, logistics, or software, but software has become the dominant battleground. The guide below focuses on software supply chain attacks: compromises that target the development and delivery pipeline of an application rather than the finished product a victim runs. Attackers insert malicious code upstream, in an open-source library, a build server, or a vendor's update mechanism, so every downstream consumer inherits the compromise without warning. Modern software isn't built from scratch. A typical application pulls in hundreds of open-source packages and relies on shared [CI/CD pipelines](https://www.paloaltonetworks.com/cyberpedia/what-is-the-ci-cd-pipeline-and-ci-cd-security?ts=markdown), registries, and vendor integrations, each a trust relationship an attacker can exploit once instead of breaching every victim directly. Because the malicious code arrives through a signed update or trusted registry, it carries an implicit stamp of legitimacy that bypasses normal vetting, making supply chain compromise one of the most consequential attack patterns security leaders face today. Key Points * **Upstream targeting**: Attackers compromise a shared component instead of breaching each victim directly. \* **Inherited trust**: Malicious code arrives through signed updates, trusted registries, or established vendor relationships. \* **Amplified blast radius**: One compromised dependency can reach every downstream consumer simultaneously. \* **Detection challenges**: Traditional perimeter and endpoint controls rarely flag trusted software as suspicious. ## How Do Software Supply Chain Attacks Work? Software supply chain attacks follow a predictable lifecycle, even though the specific technique varies by target. Understanding that lifecycle helps security leaders decide where to place controls. ### Gaining a Foothold Upstream Attackers target a high-leverage upstream point, such as a popular package, a [CI/CD platform](https://www.paloaltonetworks.com/cyberpedia/what-is-the-ci-cd-pipeline-and-ci-cd-security?ts=markdown), or a vendor with a broad customer base, using stolen credentials, a phished maintainer, or a direct build compromise. The XZ Utils backdoor took root after an attacker spent nearly two years building credibility as a trusted contributor before gaining release access. ### Inserting and Concealing the Payload The attacker modifies source code, build scripts, or the compiled artifact, often timing activation to a delay or a specific condition. Obfuscated strings and staged payloads help the code evade review and automated scanning. ### Distribution Through Legitimate Channels The compromised component moves through the normal distribution path, whether a package registry, an auto-update, or a container image. Valid signatures and a trusted channel mean most organizations install it without extra scrutiny. ### Activation and Lateral Movement Once deployed, the payload harvests credentials, opens [command-and-control](https://www.paloaltonetworks.com/cyberpedia/command-and-control-explained?ts=markdown) channels, or, in wormable campaigns, searches for more packages to infect, propagating on its own. Precisely that pattern turned a single credential theft into a cascade across hundreds of npm packages during the 2025 and 2026 Shai-Hulud campaigns. ![The attack lifecycle, from initial upstream compromise to downstream activation.](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/cyberpedia/what-is-supply-chain-attack/the-software-supply-chain-attack-lifecycle.webp "The attack lifecycle, from initial upstream compromise to downstream activation.") ***Figure 1**: The attack lifecycle, from initial upstream compromise to downstream activation.* ## Common Software Supply Chain Attack Types and Vectors Supply chain attacks take several distinct forms, each exploiting a different link in the development and delivery chain. Most large-scale campaigns combine more than one vector, but the table below breaks out each on its own, showing how it works and a representative real-world case. | Vector | How It Works | Representative Example | | **Malicious/Compromised OSS Packages** | Attackers publish malicious packages under innocuous names or hijack poorly secured maintainer accounts, and dependency resolution pulls the code in automatically. | Shai-Hulud npm worm (2025--2026) | | **Dependency Confusion \& Typosquatting** | A public package mimics an internal package's name or a popular library's name, so misconfigured tooling or a typo installs the malicious version instead. | Internal package names hijacked on public registries | | **Source Code/Repository Compromise** | Stolen credentials or an exposed access token let an attacker commit malicious code directly into version control, often passing through normal review. | Direct malicious commits to production repositories | | **CI/CD \& Build System Compromise** | A compromised build server, plugin, or reusable component such as a GitHub Action injects malicious steps into every build that pipeline touches. | tj-actions/changed-files GitHub Action (2025) | | **Artifact \& Registry Compromise** | Attackers overwrite a published package version or poison a container base image after the build, bypassing source-level code review entirely. | Poisoned base images and overwritten package versions | | **Software Update Compromise** | A compromised vendor build pipeline pushes malicious code through a signed auto-update channel that users trust by default. | SolarWinds Orion (2020), 3CX DesktopApp (2023) | | **Third-Party Vendor Compromise** | A vendor or MSP with privileged customer access is compromised once, giving an attacker entry into every environment it touches. | MOVEit Transfer / Cl0p campaign (2023) | |-------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------| ## Real-World Software Supply Chain Attacks The past several years have produced a run of incidents that reshaped how security leaders think about upstream risk. Each case below illustrates a different vector from the taxonomy above. ### SolarWinds Orion (2020) Attackers linked to Russian intelligence compromised SolarWinds' build environment and inserted a backdoor, called Sunburst, into signed updates of the Orion platform. Roughly 18,000 organizations downloaded it, though attackers hand-selected a small set of high-value targets, including US federal agencies, for follow-on exploitation. ### 3CX DesktopApp (2023) North Korea-linked actors compromised a trading software package a 3CX employee had installed, then used that foothold to poison the build pipeline for 3CX's own desktop app, which was signed and distributed to millions of users. It remains a rare, documented double supply chain attack. ### XZ Utils Backdoor (2024) An attacker using the identity Jia Tan spent nearly two years contributing legitimate code to XZ Utils before gaining maintainer and release access, then embedded an obfuscated backdoor enabling remote code execution over SSH. A Microsoft engineer discovered it by chance, days before it reached major Linux distributions. ### tj-actions/changed-files GitHub Action (2025) Attackers compromised a personal access token belonging to a bot maintaining the tj-actions/changed-files GitHub Action, then rewrote its version tags to point to a malicious commit. The payload dumped [CI/CD](https://www.paloaltonetworks.com/cyberpedia/what-is-the-ci-cd-pipeline-and-ci-cd-security?ts=markdown) runner memory into build logs, exposing credentials across more than 23,000 repositories. ### Shai-Hulud npm Worm (2025--2026) Beginning in September 2025, a self-propagating worm called Shai-Hulud compromised npm maintainer accounts, harvested credentials, and automatically republished trojanized versions of every package it controlled. Successive waves, including a 2026 campaign spanning npm and PyPI, compromised well over a thousand packages and exposed thousands of secrets. **Omdia, Securing the Software Supply Chain**: Strategic Approaches to Support Scaling Development with AI Adoption, April 2026: * 77% of organizations experienced a software supply chain incident in the 12 months before the survey. * 38% of those incidents involved exploits of known vulnerabilities in third-party software, the single most common attack path. ## What Are the Best Practices to Detect and Prevent Software Supply Chain Attacks? No single control stops software supply chain attacks. Durable programs combine detection, prevention, and [incident response](https://www.paloaltonetworks.com/cyberpedia/what-is-incident-response?ts=markdown) into one continuous discipline that spans code, pipelines, and runtime. ### Detection Detection in the software supply chain depends on visibility into components an organization didn't write and infrastructure it doesn't fully control. Effective programs correlate signals across source code, build systems, and runtime behavior rather than relying on any single scanning tool. | Practice | How to Implement It | Why It Matters | | **[Software bill of materials](https://www.paloaltonetworks.com/cyberpedia/what-is-software-bill-materials-sbom?ts=markdown)** | Generate [SBOMs](https://www.paloaltonetworks.com/cyberpedia/what-is-software-bill-materials-sbom?ts=markdown) in SPDX or CycloneDX format on every build, and diff them release over release to catch new dependencies automatically. | Confirms what's running the moment a new package or vulnerability surfaces. | | **Anomalous build behavior** | Baseline expected outbound connections, process trees, and file writes per pipeline, then alert on deviations such as an unexpected curl call or an unscheduled publish step. | Catches tampering before a build reaches production. | | **Package and registry monitoring** | Subscribe to registry webhooks or a feed such as OSV or the GitHub Advisory Database, and flag maintainer changes, new publishes, or tag rewrites on packages already in the [SBOM](https://www.paloaltonetworks.com/cyberpedia/what-is-software-bill-materials-sbom?ts=markdown). | Flags a compromise in a dependency the moment it appears upstream. | | **Runtime and endpoint telemetry** | Correlate [EDR](https://www.paloaltonetworks.com/cyberpedia/what-is-endpoint-detection-and-response-edr?ts=markdown) and cloud workload telemetry against a known-good behavioral baseline to catch payloads that activate only after deployment, such as a delayed beacon. | Surfaces payloads that activate only once in production. | | **[Threat intelligence](https://www.paloaltonetworks.com/cyberpedia/cyber-threat-intelligence?ts=markdown) integration** | Ingest indicators, such as compromised package names, malicious commit hashes, or [C2](https://www.paloaltonetworks.com/cyberpedia/command-and-control-explained?ts=markdown) domains, directly into SCA and | Shortens the gap between public disclosure and internal detection. | |--------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------| ### Prevention Prevention shifts security earlier into the development lifecycle, reducing the number of vulnerable components and trust decisions that reach production in the first place. | Practice | How to Implement It | Why It Matters | | **Dependency pinning and hash verification** | Pin exact versions through lockfiles, such as package-lock.json or requirements.txt with --hash, and verify checksums in CI before the build proceeds. | Removes mutable tags and "latest" releases as an attack vector. | | **[Least-privilege](https://www.paloaltonetworks.com/cyberpedia/what-is-the-principle-of-least-privilege?ts=markdown) pipeline access** | Scope [CI/CD](https://www.paloaltonetworks.com/cyberpedia/what-is-the-ci-cd-pipeline-and-ci-cd-security?ts=markdown) tokens to a single repository and workflow, prefer short-lived OIDC credentials over long-lived secrets, and rotate anything static on a fixed schedule. | Limits what a stolen credential can reach. | | **[Code signing](https://www.paloaltonetworks.com/cyberpedia/what-is-code-signing?ts=markdown) and artifact provenance** | Require signed commits through GPG or Sigstore, signed build artifacts, and SLSA or in-toto attestations that record which pipeline produced a given binary. | Lets downstream consumers verify an artifact's origin before deployment. | | **Vendor and open-source risk assessment** | Score maintenance activity, contributor count, release cadence, and known CVEs before adoption, and apply the same rigor to vendor security questionnaires. | Keeps unvetted components out of the build in the first place. | | **[Segmentation](https://www.paloaltonetworks.com/cyberpedia/what-is-network-segmentation?ts=markdown) of build environments** | Run build agents in isolated, ephemeral environments with no direct route to corporate identity systems or production credentials. | Limits [lateral movement](https://www.paloaltonetworks.com/cyberpedia/what-is-lateral-movement?ts=markdown) from an unrelated compromise. | |-----------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------| ### Incident Response When a supply chain compromise is confirmed, response speed and scope determine how much damage propagates downstream before containment. | Practice | How to Implement It | Why It Matters | | **Rapid dependency mapping** | Query the [SBOM](https://www.paloaltonetworks.com/cyberpedia/what-is-software-bill-materials-sbom?ts=markdown) inventory and [CI/CD](https://www.paloaltonetworks.com/cyberpedia/what-is-the-ci-cd-pipeline-and-ci-cd-security?ts=markdown) logs to list every application, environment, and pipeline that pulled the compromised version. | Defines the true blast radius before it's fully known. | | **Credential rotation** | Rotate every token, key, and secret the compromised pipeline or package could reach, not only the one believed to be exposed. | Cuts off attacker access even before the entry point is fully understood. | | **Coordinated disclosure** | Notify registry operators, downstream consumers, and the relevant CERT or ISAC within the window your [incident response](https://www.paloaltonetworks.com/cyberpedia/what-is-incident-response?ts=markdown) plan defines, typically 24 to 72 hours. | Limits further spread beyond the organization's own environment. | | **Forensic preservation** | Snapshot build logs, commit history, and package metadata to immutable storage before running any remediation script that could overwrite them. | Preserves evidence that remediation actions would otherwise overwrite. | | **Post-incident hardening** | Convert the specific gap that enabled the compromise into a policy, such as mandatory hash pinning or a new approval gate, and track it to closure like any other finding. | Prevents the same class of compromise from recurring. | |------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------| ## How Palo Alto Networks Approaches Supply Chain Attack Palo Alto Networks treats software supply chain security as a continuous discipline spanning the endpoint, code, pipelines, and runtime rather than a single scanning checkpoint. ### Protecting the Coder Modern supply chain attacks intentionally target developer work environments, distribution registries, and open-source ecosystems before compiled code reaches production machines. With [Cortex Agentic Endpoint Security](https://www.paloaltonetworks.com/cortex/agentic-endpoint-security?ts=markdown), the inline security gateway intercepts installation attempts at the network layer before raw artifacts land on host disk storage. Sitting between local environments and public repositories like PyPI, npm, Hugging Face, and the Chrome Web Store, the gateway blocks risky dependencies using real-time policy checks. ### Protecting the Code Cortex Cloud's Software Supply Chain Security module gives teams a consolidated inventory of the tools, identities, artifacts, and dependencies behind the modern software factory, including package managers, [CI/CD platforms](https://www.paloaltonetworks.com/cyberpedia/what-is-the-ci-cd-pipeline-and-ci-cd-security?ts=markdown), and the AI models and MCP servers now embedded in development workflows. [Software Composition Analysis](https://www.paloaltonetworks.com/cyberpedia/what-is-sca?ts=markdown) maps dependency trees to their furthest transitive layer and generates [SBOMs](https://www.paloaltonetworks.com/cyberpedia/what-is-software-bill-materials-sbom?ts=markdown), while the Supply Chain Graph visualizes pipeline relationships to reveal hidden breach pathways and secrets detection flags exposed credentials before an attacker can use them. Software Supply Chain Trust Scores condense that posture into one measure of build integrity, and the Supply Chain Attack Threat Center connects active campaign intelligence from Unit 42, including tracking of the Shai-Hulud npm campaigns, directly to an organization's own exposure. ## Related FAQs ### What is the difference between a supply chain attack and a data breach? A [data breach](https://www.paloaltonetworks.com/cyberpedia/data-breach?ts=markdown) targets an organization's own systems or data directly. A supply chain attack targets a shared upstream component, such as a library, vendor, or build system, so the compromise reaches every downstream organization that relies on it. ### How common are software supply chain attacks? Software supply chain attacks have grown sharply in both frequency and scale in recent years, with self-propagating campaigns across open-source registries such as npm compromising thousands of packages within a matter of hours during 2025 and 2026. ### Can traditional antivirus or endpoint tools stop supply chain attacks? Traditional tools struggle because the malicious code arrives through a trusted, signed, or previously benign channel. Effective defense requires dependency-level visibility, build pipeline monitoring, and behavioral detection rather than signature matching alone. ### What is an SBOM, and why does it matter? A [software bill of materials](https://www.paloaltonetworks.com/cyberpedia/what-is-software-bill-materials-sbom?ts=markdown) is a complete inventory of every component, direct and transitive, that makes up an application. It lets an organization quickly determine whether it's exposed when a new vulnerability or compromised package comes to light. ### Who is responsible for securing the software supply chain? Responsibility spans development teams, security teams, and vendors alike. Developers control which dependencies enter a codebase, security teams provide visibility and guardrails across the pipeline, and vendors bear responsibility for the integrity of the software and updates they distribute. ![Share page on facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/resources/facebook-circular-icon.svg) ![Share page on linkedin](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/resources/linkedin-circular-icon.svg) [![Share page by an email](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/resources/email-circular-icon.svg)](mailto:?subject=What%20Is%20a%20Supply%20Chain%20Attack%3F&body=Supply%20chain%20attacks%20hijack%20trusted%20software%20components%20to%20breach%20thousands%20of%20organizations.%20Learn%20how%20to%20detect%2C%20prevent%2C%20and%20respond.%20at%20https%3A//www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack) Back to Top [Previous](https://www.paloaltonetworks.com/cyberpedia/appsec-application-security?ts=markdown) What Is AppSec? [Next](https://www.paloaltonetworks.com/cyberpedia/what-is-vibe-coding?ts=markdown) What Is Vibe Coding? {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense?ts=markdown) * [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown) * [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown) * [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown) * [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language