Third-party attacks: A growing threat
Third-party attacks have emerged as one of the most critical threats in the modern cyber landscape. Adversaries increasingly exploit vulnerabilities within external vendors, suppliers, contractors, and service providers to gain indirect access to target organizations, often with severe consequences. These breaches can lead to significant data loss, operational disruption, regulatory penalties, and reputational damage. As a result, third-party risk management (TPRM) is no longer just an IT concern, it’s a board-level imperative essential to protecting sensitive data and maintaining customer trust.
In our 2025 State of the Underground report, we observed a 43% year-over-year increase in data breaches shared on underground forums, with US organizations representing nearly 20% of all identified victims.
Moreover, we uncovered 2.9 billion unique sets of compromised credentials leaked throughout 2024, marking a sharp rise from the 2.2 billion recorded in 2023. I don’t mean to be dramatic, but that is a HUGE increase. These findings underscore the escalating urgency for organizations to implement robust TPRM frameworks that extend visibility and control far beyond their own digital perimeters.
Why your GRC team needs access to CTI, too
Security Operations Centers (SOCs) are stretched thin. Their mandate is to defend the company’s own assets: patching, monitoring, and responding to threats targeting the enterprise directly. But today’s risks don’t stop at the perimeter. Increasingly, attackers are exploiting vulnerabilities in the extended ecosystem, vendors, partners, and service providers, where visibility is often weaker.
This is where Governance, Risk, and Compliance (GRC) teams come in. GRC is already responsible for monitoring vendor risk and the company’s broader attack surface. With access to Cyber Threat Intelligence (CTI), and powered by AI, GRC teams can move from passive oversight to active defense. They can identify where vulnerabilities in the supply chain might become backdoor entry points and flag them before they escalate into full-blown incidents.
A real-world example: CVE-2025-10035
Recently, a critical vulnerability (CVE-2025-10035) was identified in GoAnywhere MFT, a widely used file transfer solution for moving sensitive data such as financial records, HR files, legal documents, and PII.
- Severity: CVSS score 10.0 (critical) and 9.23 on Bitsight’s Dynamic Vulnerability Exploit (DVE) scale.
- Impact: Similar to the MOVEit breach, it shows how one flaw can trigger a chain reaction of exposures across countless organizations.
Even if your enterprise has patched systems and strong defenses, the real risk lies in your third- and fourth-party vendors. One unpatched vendor instance could compromise your sensitive data and ripple across your entire ecosystem.
Why this matters for TPRM
CVE-2025-10035 underscores the role of Third-Party Risk Management (TPRM) as a frontline defense. Vulnerabilities like this don’t just affect internal systems—they put the entire supply chain at risk.
For GRC teams, this is both a challenge and an opportunity:
- Vendor Assessments: Move beyond check-the-box questionnaires to real-time intelligence on vendor vulnerabilities.
- Prioritization: Use CTI and risk analytics to separate the signal from the noise—focusing on the vulnerabilities most likely to be exploited.
- Proactive Defense: Work hand-in-hand with SOCs, flagging risks in the extended ecosystem before attackers can exploit them.
SOCs can’t fight this battle alone. By integrating CTI into GRC workflows, organizations gain a powerful new layer of defense, one that keeps the backdoor to the enterprise closed, even when vendor ecosystems are under fire.