Multi-CloudCIO BriefingsRetrospectives

CIO Brief: Open-Source Dependencies Are Third-Party Risk

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2024, written in 2026 with the benefit of hindsight.

The short version: In 2024, a hidden backdoor was discovered in XZ Utils, a small but widely used piece of free software in Linux systems. Someone had spent two years earning the trust of the volunteer maintainer to insert it. It was caught by chance, weeks before reaching most enterprise systems.

Why open-source dependencies are third-party risk

Most modern software is built from open-source components maintained by small teams or single volunteers. You depend on them as much as on any vendor — usually with no contract, no support and no visibility.

The business impact

  • Hidden backdoors in systems you trust.
  • Slow response if you don't know which components you use.
  • Supply-chain risk for software you sell to customers.

Questions to ask your team

  • Do we know which open-source components are in our applications and servers?
  • Can we find a specific component across all systems within hours?
  • Do we automatically pull the latest versions, or test and approve updates?
  • Do we contribute to or fund critical open-source projects we depend on?

What good looks like

An inventory of open-source components (SBOMs), scanning in build pipelines, controlled updates, and — for larger organizations — support for critical open-source projects.

The decision

Treat critical open-source components as suppliers. Ask your engineering leaders which ten components your products depend on most, and what you'd do if one were compromised.

xz utils backdoor impactXZ Utils backdoor2024

More on this story