* [Blog](https://www.paloaltonetworks.com.au/blog) * [Cloud Security](https://www.paloaltonetworks.com.au/blog/cloud-security/) * [AppSec](https://www.paloaltonetworks.com.au/blog/cloud-security/category/appsec/) * Build Trust into the SDLC... # Build Trust into the SDLC with Cortex Cloud's Software Supply Chain Security [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.paloaltonetworks.com.au%2Fblog%2Fcloud-security%2Fsoftware-supply-chain-security-module-new%2F) [](https://twitter.com/share?text=Build+Trust+into+the+SDLC+with+Cortex+Cloud%E2%80%99s+Software+Supply+Chain+Security&url=https%3A%2F%2Fwww.paloaltonetworks.com.au%2Fblog%2Fcloud-security%2Fsoftware-supply-chain-security-module-new%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.paloaltonetworks.com.au%2Fblog%2Fcloud-security%2Fsoftware-supply-chain-security-module-new%2F&title=Build+Trust+into+the+SDLC+with+Cortex+Cloud%E2%80%99s+Software+Supply+Chain+Security&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www.paloaltonetworks.com.au/blog/cloud-security/software-supply-chain-security-module-new/&ts=markdown) \[\](mailto:?subject=Build Trust into the SDLC with Cortex Cloud’s Software Supply Chain Security) Link copied By [Cameron Hyde](https://www.paloaltonetworks.com/blog/author/cameron-hyde/?ts=markdown "Posts by Cameron Hyde") and [Asaf Henig](https://www.paloaltonetworks.com/blog/author/asaf-henig/?ts=markdown "Posts by Asaf Henig") Aug 05, 2026 5 minutes [AppSec](https://www.paloaltonetworks.com/blog/cloud-security/category/appsec/?ts=markdown) [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown) [Software Supply Chain Security](https://www.paloaltonetworks.com/blog/cloud-security/category/software-supply-chain-security/?ts=markdown) ## Extend security across the AI-powered development ecosystem---from developer tools and identities to code artifacts and production. AI is transforming software development. Today's software supply chain extends beyond source code and open-source dependencies to include the tools, identities and processes that support software delivery across the entire SDLC. As organizations adopt coding assistants, AI models, MCP servers, skills and agents, they introduce new components that expand the attack surface. As development accelerates, threat actors target software supply chains at an unprecedented rate. In 2025, malicious open-source packages increased by [75%](https://www.sonatype.com/state-of-the-software-supply-chain/introduction), while the involvement of a third-party environment in breaches doubled from [15% to 30%](https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf). Responding to these attacks remains a challenge. Software supply chain compromises take an average of [267 days to identify and contain](https://www.ibm.com/reports/data-breach). When a compromise results in a data breach, the average [costs reach approximately $4.91 million](https://www.ibm.com/reports/data-breach). Organizations need a new approach to supply chain security that builds trust into every stage of software development. We're excited to introduce Software Supply Chain Security as a dedicated module within Cortex Cloud, along with two new capabilities: Software Supply Chain Trust Scores and the Supply Chain Attack Threat Center. Together, they help organizations prevent risk and respond faster to threats across the AI-powered software development lifecycle. ## What Modern Software Supply Chain Security Requires Modern software supply chain security requires more than dependency scanning. It must provide visibility into everything that enters or modifies the software supply chain, prevent risk throughout development and give teams the context to respond quickly when new threats emerge. ### Complete Visibility Across the Development Ecosystem Security teams need a continuous inventory spanning agentic tools, AI models, MCP servers and skills, IDEs, version control systems, pipelines, code artifacts, identities and developer endpoints. That visibility must reveal what is being built, who or what can modify it and what ultimately runs in production. ### Prevention Throughout the Development Lifecycle Effective prevention stops vulnerable dependencies, exposed secrets, insecure code and untrusted artifacts before they reach production. Automated guardrails must operate throughout the development lifecycle without impeding developer velocity. ### Automated Environment Mapping for Rapid Response When new software supply chain threats emerge, teams need to determine whether their organization is affected, identify impacted assets across endpoints, development environments and production, and prioritize remediation according to exposure. ## Build Trust into the AI-Powered Software Supply Chain with Cortex Cloud As software supply chains have evolved, so has Cortex Cloud. Software Supply Chain Security extends Cortex Cloud across the development ecosystem, connecting the tools, identities, code artifacts and production assets that determine whether builds should be trusted. By connecting development context with production exposure, Cortex Cloud gives security and development teams a complete view of the risks affecting each software release. ### Measure Software Integrity with Trust Scores Understanding supply chain risk shouldn't require reviewing hundreds of individual findings. New Software Supply Chain Trust Scores provide an intuitive measure of software integrity across the development lifecycle. Trust Scores evaluate the security posture of the dependencies in a software bill of materials (SBOM) and the development environment that produced the code artifact, helping teams determine which applications meet their security standards. Trust Scores express software integrity on a 0--100 scale, with 100 indicating the highest level of trust. If a malicious package is detected in the SBOM, the Trust Score automatically drops to 0. Rather than chasing individual alerts, teams can focus on improving the trustworthiness of code artifacts and prioritize remediation where it will have the greatest impact. ### Respond Faster with the New Supply Chain Attack Threat Center Newly disclosed CVEs, compromised developer tools and malicious packages can expose organizations to software supply chain attacks with little warning. Each new threat raises three urgent questions: * What happened? * Am I affected? * What should I do next? Answering those questions often requires security teams to understand the threat, search their environments for affected tools and dependencies and determine whether production applications are exposed. The Supply Chain Attack Threat Center continuously tracks emerging software supply chain threats---including newly disclosed CVEs, compromised developer tools, malicious packages and dependency attacks---and automatically maps them to your environment. Teams can immediately identify affected assets, confirm where exposure exists and prioritize the actions required to reduce it. ![Mapping emerging threats to compromised packages, impacted assets and immediate response actions](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/08/word-image-364764-1.png) Figure 1: Mapping emerging threats to compromised packages, impacted assets and immediate response actions Instead of spending hours investigating each new software supply chain attack, teams can move directly from threat discovery to targeted remediation. ## Secure Every Release from Development to Production Software Supply Chain Trust Scores give teams a continuous measure of software integrity, while the Supply Chain Attack Threat Center shows whether emerging threats affect their environment. Together with prevention across the development lifecycle, these capabilities help organizations stop compromised software before production and move faster when the software supply chain comes under attack. ## Learn More Learn more about Software Supply Chain Security in Cortex Cloud, [explore the latest capabilities](https://www.paloaltonetworks.com/cortex/cloud/software-supply-chain-security), and [request a demo](https://www.paloaltonetworks.com/cortex/cloud/demo) to see how Cortex Cloud helps you build trust into your software supply chain. *** ** * ** *** ## Related Blogs ### [AppSec](https://www.paloaltonetworks.com/blog/cloud-security/category/appsec/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [Points of View](https://www.paloaltonetworks.com/blog/category/points-of-view/?ts=markdown), [Software Supply Chain Security](https://www.paloaltonetworks.com/blog/cloud-security/category/software-supply-chain-security/?ts=markdown) [#### Shift Left Has Never Made Sense](https://www.paloaltonetworks.com.au/blog/cloud-security/shift-left-vs-unifying-appsec-cloudsec-runtime/) ### [AI-SPM](https://www.paloaltonetworks.com/blog/cloud-security/category/ai-spm/?ts=markdown), [Application Security](https://www.paloaltonetworks.com/blog/cloud-security/category/application-security/?ts=markdown), [AppSec](https://www.paloaltonetworks.com/blog/cloud-security/category/appsec/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [Software Supply Chain Security](https://www.paloaltonetworks.com/blog/cloud-security/category/software-supply-chain-security/?ts=markdown) [#### Why Are Software Supply Chains Under Constant Siege?](https://www.paloaltonetworks.com.au/blog/cloud-security/software-supply-chain-security-ai-risks-attacks-defense/) ### [AI Security](https://www.paloaltonetworks.com/blog/cloud-security/category/ai-security/?ts=markdown), [Application Security](https://www.paloaltonetworks.com/blog/cloud-security/category/application-security/?ts=markdown), [AppSec](https://www.paloaltonetworks.com/blog/cloud-security/category/appsec/?ts=markdown), [CIEM](https://www.paloaltonetworks.com/blog/cloud-security/category/ciem-2/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [Identity Security](https://www.paloaltonetworks.com/blog/cloud-security/category/identity-security/?ts=markdown), [Supply Chain Security](https://www.paloaltonetworks.com/blog/cloud-security/category/supply-chain-security/?ts=markdown) [#### Introducing Cortex Cloud 2.1](https://www.paloaltonetworks.com.au/blog/cloud-security/visibility-governance-automation/) ### [Application Security](https://www.paloaltonetworks.com/blog/cloud-security/category/application-security/?ts=markdown), [AppSec](https://www.paloaltonetworks.com/blog/cloud-security/category/appsec/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [Supply Chain Security](https://www.paloaltonetworks.com/blog/cloud-security/category/supply-chain-security/?ts=markdown) [#### Bitwarden CLI Impersonation Attack Steals Cloud Credentials and Spreads Across npm Supply Chains](https://www.paloaltonetworks.com.au/blog/cloud-security/bitwardencli-supply-chain-attack/) ### [Application Security](https://www.paloaltonetworks.com/blog/cloud-security/category/application-security/?ts=markdown), [AppSec](https://www.paloaltonetworks.com/blog/cloud-security/category/appsec/?ts=markdown), [ASPM](https://www.paloaltonetworks.com/blog/cloud-security/category/aspm/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [DevSecOps](https://www.paloaltonetworks.com/blog/cloud-security/category/devsecops/?ts=markdown) [#### Level Up Your AppSec Team with an Agentic Workforce](https://www.paloaltonetworks.com.au/blog/cloud-security/cloud-security-appsec-agent-aspm/) ### [AppSec](https://www.paloaltonetworks.com/blog/cloud-security/category/appsec/?ts=markdown), [ASPM](https://www.paloaltonetworks.com/blog/cloud-security/category/aspm/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [Code Security](https://www.paloaltonetworks.com/blog/cloud-security/category/code-security/?ts=markdown), [DevSecOps](https://www.paloaltonetworks.com/blog/cloud-security/category/devsecops/?ts=markdown), [Research](https://www.paloaltonetworks.com/blog/cloud-security/category/research/?ts=markdown) [#### An Inside Look into ASPM: Five Findings from New Industry Research](https://www.paloaltonetworks.com.au/blog/cloud-security/aspm-research-omdia/) ### Subscribe to Cloud Security Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www.paloaltonetworks.com.au/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language