Safeguard
Topic

Incident Analysis

In-depth guides and analysis on incident analysis from the Safeguard engineering team.

139 articles

Incident Analysis

ASUS Live Update and ShadowHammer: The Backdoor

Operation ShadowHammer pushed a signed backdoor to roughly half a million ASUS laptops, targeting a list of 600 specific MAC addresses.

Jan 1, 20267 min read
Incident Analysis

XcodeGhost: When the Compiler Was the Attacker

XcodeGhost in 2015 infected at least 128 million iOS users through a malicious Xcode download. It is still the cleanest compiler-trust case.

Jan 1, 20267 min read
Incident Analysis

CCleaner 2017: Anatomy of a Quiet Supply Chain Hit

The CCleaner backdoor of 2017 was among the first modern build-system compromises to achieve mass distribution through a trusted installer.

Jan 1, 20267 min read
Incident Analysis

Equifax: The Supply Chain Angle Few Talked About

The 2017 Equifax breach is a case study in Apache Struts, inherited dependencies, and a vulnerability management process that mistook lists for action.

Jan 1, 20267 min read
Incident Analysis

M.E.Doc and NotPetya: The Origin Story

The forensic detail of how M.E.Doc's update server became the delivery mechanism for NotPetya, and what it means for small-vendor risk.

Jan 1, 20268 min read
Incident Analysis

NotPetya's Origin: A Supply Chain Story From Ukraine

NotPetya is remembered as ransomware. It was not. It was a supply chain wiper that detonated through Ukrainian tax software in June 2017.

Jan 1, 20267 min read
Incident Analysis

WannaCry's Supply Chain Dimensions

WannaCry was not a supply chain attack in the usual sense. Its real supply chain story is EternalBlue, NSA leaks, and the patch cycle.

Jan 1, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

Incident Analysis (Page 12) — Supply Chain Security Blog | Safeguard