A good candidate for the Next Big Supply Chain Vector is OneTrust which seems to be a very popular service for managing cookie consent across web assets.

The integration requires loading multiple remote scripts, and the docs mention nothing about subresource integrity protection, except for this little mention in the section for an obscure feature πŸ₯΄

#OneTrust #Security #WebAppSec #CookiesOmNom