HomeSecurityAWS Security Hub Extended: New Supply Chain Security category with Chainguard and...

AWS Security Hub Extended: New Supply Chain Security Category with Chainguard and Socket

Amazon Web Services announced on August 4, 2026 the addition of a new, tenth category to the AWS Security Hub Extended: Supply Chain Security. The new category, with curated partners Chainguard and Socket, enables enterprises to detect and block malicious dependencies before they are integrated into their applications.

See also: AWS Continuum: Secure code across Claude Code, Codex, and Kiro with a unifying AI orchestrator

Security Hub Extended Supply Chain Security category
AWS Security Hub Extended: New Supply Chain Security Category with Chainguard and Socket

What is AWS Security Hub Extended?

AWS Security Hub Extended is AWS’s unified program that combines its own security services with curated solutions from partner companies, so an organization can manage the full threat detection and response cycle from a single location. Participating solutions emit findings in a unified Open Cybersecurity Schema Framework (OCSF), which are automatically aggregated into AWS Security Hub for unified analysis.

The program currently covers ten categories, with Supply Chain Security being the latest addition:

  • Endpoint (terminal devices)
  • Identity
  • E-mail
  • Network
  • Data
  • Browser
  • Cloud
  • AI
  • Security operations
  • Supply Chain — new addition

With the addition of Chainguard and Socket, the program now has 23 curated partners in total. All solutions are available on a single AWS pricing plan, with no long-term commitments — a particularly attractive feature for organizations that want flexibility in their security budget.

Why a separate category is needed for Supply Chain Security

Modern applications are built on dozens, hundreds, or thousands of open source libraries. The rapid adoption of these dependencies has created a serious security gap: how does an organization ensure that every new package entering its environment is truly trustworthy and free of malicious code?.

In recent years, dramatic incidents of supply chain attacks have been recorded, from compromised npm packages to backdoored PyPI libraries. An attacker no longer needs to compromise the target company, they just need to compromise an external code supplier and the malicious changes will be automatically distributed to thousands of organizations.

The new Security Hub Extended category addresses exactly this gap. It aims to integrate dependency scanning into the regular security flow, with the same core features that all other categories have:

  • Unified activation process, without complex manual configuration
  • Pay-as-you-go pricing model, no long-term commitments
  • Consolidated findings in OCSF format for comprehensive analysis
  • Direct integration into existing AWS Security Hub dashboard, no separate installation required

Chainguard's role in the new category

Chainguard of secure container images. Its philosophy is based on the idea that every container should start with zero exposure to known vulnerabilities. It produces clean, minimal container images for thousands of open source applications, which are automatically updated whenever a new vulnerability is identified.

Chainguard's integration into Security Hub Extended means that organizations already using or considering its solution can have unified management, billing, and reporting with their other AWS security services.

See also: iCloud Private Relay: A passkey request is enough to reveal the real IP

Chainguard clean container images
AWS Security Hub Extended: New Supply Chain Security Category with Chainguard and Socket

Socket's approach to malicious packets

Socket It uses a combination of static analysis, dynamic monitoring, and behavioral identification to detect suspicious behaviors such as typosquatting, secret extraction attempts, or packages containing obfuscated code.

Socket protection is triggered before the malicious package is integrated into the normal deployment flow, giving organizations the opportunity to prevent installation, not just detect it after the fact. This proactive approach is especially critical for companies with rapid development cycles, where setting up manual approvals for each new package is practically impossible.

Frequently asked questions

What is the difference between Security Hub and Security Hub Extended?
Classic Security Hub aggregates findings from AWS’s own security services. Extended extends coverage to curated partners covering areas such as endpoint, browser, supply chain, and more. Customers can select whichever categories interest them, without having to purchase an entire package.

How much does the new Supply Chain Security tier cost?
The tier follows the same pay-as-you-go pricing model as all other tiers in Security Hub Extended. Exact pricing is available on the AWS Security Hub pricing page. There are no long-term commitments required.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Do I need to replace my existing SBOM or SCA tools?
Not necessarily. Chainguard and Socket can complement existing Software Composition Analysis tools, unifying their findings in the common OCSF format. Many organizations choose a multi-layered approach for mission-critical workloads.

Is the service available in eu-central-1 (Frankfurt)?
Yes. Chainguard and Socket solutions are available in all commercial AWS regions where Security Hub is available, including Frankfurt, Ireland and Paris which are the most common choices for Greek organizations due to GDPR compliance.

How do I get started?
Interested parties can enable the new category through the AWS Security Hub console. Integration with curated partners is done through a unified process, without complex technical configuration.

Is it extensible to other providers?
Yes. AWS explicitly states that Security Hub Extended will continue to expand with new curated partners, based on customer feedback. OCSF's open approach makes it easy to integrate new vendors without changes to the core infrastructure.

Also useful: Strong Ransomware hit Sithonia Halkidiki and Port Fund

Supply-chain attack: how a third party can lead to an EY breach

The addition of Supply Chain Security as the tenth category in AWS Security Hub Extended is an important step in standardizing defense against software supply chain attacks. The Chainguard and Socket options offer mature, proven solutions that address different aspects of the problem — from secure container images to detection of malicious open source packages. For Greek businesses that already use AWS or are considering the transition, the new category significantly simplifies supply chain security management. The SecNews editorial team will monitor the expansion of the program with new curated partners and will update with any relevant developments.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS