HomeProcurement Risk Briefing › Issue #2
Procurement Risk Briefing · #2

Your software vendors are a supply chain too — and the freight market just got redrawn

Week of June 14, 2026 · 3 items · 4-minute read

1. The software you buy now carries its vendors’ dependency risk

A wave of self-replicating attacks is spreading through the open-source packages that software vendors build on. In the last few weeks the “IronWorm” campaign trojanized 37 NPM packages from one compromised account — its payload hunts for AWS, OpenAI, and Anthropic credentials — and a second worm, “Miasma,” now executes through a 157-byte binding.gyp file to slip past the install-script scanners most security tools watch, across 57 packages with 647,000 monthly downloads. The point for a buyer: a SaaS or software vendor can be breached without writing a single bad line of their own code — the compromise rides in through a dependency they pulled in, and that vendor’s exposure is your exposure.

So what: add one question to your software and SaaS vendor due-diligence: “How do you vet and monitor your third-party and open-source dependencies?” A vendor that can answer concretely — lockfiles, dependency scanning, signed builds — is managing the risk; one that goes quiet is carrying it on your behalf. Software vendors are a supply chain now; vet them like one.

2. FMCSA’s MOTUS rollout is a mess — and that’s negotiation leverage right now

FMCSA’s new MOTUS registration system launched May 14, 2026, and the legacy systems carriers relied on for years — the Unified Registration System, the L&I public filing system, and the FMCSA Portal’s registration functions — were switched off the same day. It has not gone well: of the 2.2 million launch letters FMCSA mailed, more than 400,000 came back undeliverable, one industry commentator called it “one of the worst software releases” he’d witnessed, and FMCSA has publicly said it is prioritizing fixes to insurance filings and operating-authority status. Net effect: a temporary window where a carrier’s authority and registration status can be genuinely stale or wrong.

So what: during a registration-system meltdown, “the system was down” is the carrier’s problem, not your defense if you book an unauthorized one. Re-verify authority and safety status on your key carriers this month and keep the dated record. (You can check any carrier free in 10 seconds with our carrier risk check.) Verify current MOTUS status against FMCSA directly — it is moving weekly.

3. The LTL market just fragmented — your freight benchmarks are stale

Three things landed in the same few weeks: FedEx completed the spin-off of FedEx Freight on June 1, 2026, making it an independent, publicly traded LTL carrier (NYSE: FDXF); Amazon expanded its LTL freight offering for shippers; and carriers are now deploying tools that score shipper performance — they’re grading you back. And the market itself has run hot: per the BLS Producer Price Index, the less-than-truckload market is up roughly 21% year-over-year (truckload is up about the same) as of the latest reading. The pricing and capacity landscape mid-market teams benchmarked against a year ago is being redrawn.

So what: if your LTL rate benchmarks predate the FedEx spin-off, they describe a market that no longer exists — and with carriers now instrumenting shipper behavior, being a “hard to load” account quietly costs you on rate. Refresh your LTL carrier mix and rate benchmarks this quarter, and treat your own dock and tender behavior as a negotiable variable, not a fixed cost.