Nobody verifies itAugust 2026NSA and JFAC Hardware Assurance labs
NSA: when trust doesn’t cover the whole chip lifecycle, verify the rest
NSA and the Defense Department’s hardware assurance labs released a threat catalog and best practices for custom chips, covering attacks from design tools and third-party IP through fabrication, packaging and delivery. Unless every step runs through accredited trusted suppliers, programs are told to add their own validation for the steps that don’t.
Why it matters: The government’s own guidance now says trusted suppliers aren’t enough on their own. The gaps have to be checked.
Read at NSAAnalysis at Rambus
Supply interruptionFebruary 2026The New York Times
U.S. officials warned chip buyers about a Taiwan blockade
Senior U.S. intelligence officials privately briefed top tech CEOs that China could be ready to move on Taiwan as soon as 2027. Taiwan makes about 90% of the world’s most advanced chips, and a blockade could cut that supply off. Even chips made in Arizona are still sent back to Taiwan for packaging.
Why it matters: A single point of failure doesn’t need an invasion to fail. A blockade is enough.
Read at The New York Times
Compromised partsMay 2025Reuters
Undocumented radios found inside grid equipment
U.S. experts tearing down Chinese-made solar power inverters found communication devices that weren’t listed in the product documents, and undocumented cellular radios turned up in some batteries from several Chinese suppliers. Those extra channels could let the equipment be reached around a utility’s firewalls.
Why it matters: The documents said one thing and the board said another. Only a teardown showed the difference.
Read at Reuters
Supplier riskSeptember 2024House Homeland Security Committee
Port cranes arrived with cellular modems nobody ordered
A joint congressional investigation found that ZPMC, the Chinese state-owned company behind nearly 80% of the ship-to-shore cranes at U.S. ports, installed cellular modems on cranes beyond what the contracts called for, and repeatedly asked for remote access to cranes at U.S. ports.
Why it matters: When one foreign supplier dominates critical equipment, the buyer rarely controls what ships inside it.
Read at House Homeland Security Committee
Compromised partsSeptember 2024CBC News
Rigged pagers moved through the supply chain undetected
Thousands of pagers and other devices used by Hezbollah exploded across Lebanon. Security experts said the attack likely required infiltrating the manufacturing supply chain, with explosives hidden in devices that looked normal to their users for months.
Why it matters: Tampering at the factory or in transit can sit unnoticed until the moment it’s used.
Read at CBC News
Nobody verifies itSeptember 2022The Aviationist
F-35 deliveries paused over a Chinese alloy five tiers down
The Pentagon halted F-35 deliveries after learning that a magnet in the jet’s turbomachine pump used an alloy made in China. It came from a fifth-tier subcontractor and was in every F-35 delivered up to that point. Deliveries later resumed under a national security waiver.
Why it matters: Programs often learn what’s deep in their supply chain only after it’s built in.
Read at The Aviationist
Nobody verifies itMay 2012Senate Armed Services Committee
Over a million suspect counterfeit parts in U.S. defense systems
A Senate investigation found about 1,800 cases of suspect counterfeit electronic parts in the defense supply chain, totaling more than a million parts, including in the Air Force’s largest cargo plane, assemblies for special operations helicopters and a Navy surveillance plane. Most traced back to China, and in the cases studied in depth, the Pentagon didn’t know the parts were installed.
Why it matters: Counterfeits get in when nobody checks the parts themselves.
Read at Senate Armed Services Committee