Supply chain attack
Compromising a vendor, tool, or software update in order to reach that vendor's customers.
Attacking one trusted supplier is more efficient than attacking a thousand businesses individually. The route might be a poisoned software update, a compromised managed service provider with remote access into client environments, or a library pulled into an application build.
It is difficult to defend against directly, which shifts the emphasis to vendor due diligence, limiting what any single integration can reach, and monitoring for unusual activity from trusted tooling.
Where this comes up
Supply chain attack sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.