
Defence & government
Nation-state actors target the dependency you trust the most.
Mission software, secure communications, and government services are built from a mix of custom and open-source code, and they are a standing target for nation-state actors who subvert the software and equipment supply chain rather than attack it head-on. Provenance and a verifiable bill of materials are becoming procurement requirements.
The software underneath
- Mission and command software
- Secure communications and network equipment
- Intelligence, surveillance, and logistics systems
- Vendor firmware across the hardware estate
State actors in the package registries
2025 to 2026The axios npm compromise was attributed to North Korea's Sapphire Sleet, while China's Salt Typhoon campaign compromised telecom and critical-infrastructure targets across more than 80 countries by exploiting known vulnerabilities in widely deployed equipment. Both show nation-states reaching their targets through trusted software and hardware dependencies.
Adversaries no longer need a zero-day when a trusted dependency or an unpatched known CVE gets them in.
US EO 14028 and NIST SSDF
Federal software-security direction that followed SolarWinds pushed SBOMs and secure-development attestation aligned with the NIST Secure Software Development Framework (SP 800-218). Even as specific orders are revised, SBOM and secure-development expectations continue to shape procurement.
Evidence-bound findings
Every finding cites concrete evidence: a matched advisory, an observed behaviour, a file and line. No unsourced verdicts.
Provenance and SBOM
Produce the bill of materials and provenance signals that secure-development attestation now expects.
Known and novel
Match against public advisories for known threats, and flag novel malicious behaviour before any advisory exists.
Have you used Verifi in defence & government?
We are building our library of real-world results. Tell us how your team runs Verifi and we will help you write it up, or request a case study for your sector.