Threat Intelligence
In-depth guides and analysis on threat intelligence from the Safeguard engineering team.
65 articles
UNC5221 Ivanti Exploitation Campaign Analysis
UNC5221 chained Ivanti Connect Secure zero-days through 2024 and 2025. The campaign reads like a masterclass in living off trusted edge appliances.
Storm-0558 Microsoft Cloud Identity Aftermath
Storm-0558 forged Microsoft cloud tokens with a stolen MSA key and read government email. Three years later the architectural lessons are still unevenly applied.
INC Ransom: Inside the Group Targeting Healthcare Infrastructure
INC Ransom has made healthcare a primary target, exploiting the sector's unique vulnerabilities and urgency. A deep dive into their operations and what healthcare security teams should prioritize.
Office Document Macro Security: The Attack Vector That Will Not Die
Microsoft disabled macros by default in 2022. Attackers adapted. The macro threat has evolved, not disappeared.
North Korean Threat Actors Flood npm with Malicious Packages
In 2024, DPRK-linked groups dramatically escalated their campaign to compromise developers through malicious npm packages, using fake job offers and typosquatting to deploy infostealers and backdoors.
Akira Ransomware VPN Appliance Exploitation
Akira has industrialized VPN appliance exploitation. Here is the tradecraft, the advisories that document it, and what defenders must do about edge software supply chain risk.
The Supply Chain Attack Kill Chain: A Framework for Defense
We propose a kill chain framework specific to software supply chain attacks, mapping attacker techniques to defensive controls at each stage.
VMware ESXi Under Siege: Ransomware Campaigns Targeting Hypervisors in 2024
Ransomware groups increasingly target VMware ESXi hypervisors to encrypt entire virtual environments at once. The 2024 campaigns exploited known and zero-day vulnerabilities for maximum impact.
Dependency Confusion: Attack Evolution from 2022 to 2026
Alex Birsan's 2021 disclosure named a class of attacks. Four years on, dependency confusion has evolved across registries, tooling, and victim profiles.
Volt Typhoon: Critical Infrastructure Supply Chain
Volt Typhoon is pre-positioning inside U.S. critical infrastructure using living-off-the-land tradecraft and third-party access. Here is what defenders should do about it.
OpenAI Internal Breach: What the 2023 Forum Hack Reveals About AI Company Security
Reports emerged that a hacker accessed OpenAI's internal messaging systems in early 2023, raising questions about AI company security practices and the risks of concentrated AI development.
Cozy Bear / Midnight Blizzard Supply Chain Tactics
Midnight Blizzard (APT29, Cozy Bear) has refined long-dwell supply chain access into an operational art. Here is what their 2023-2025 pattern looks like to defenders.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.