Tag
credential-theft
Safeguard articles tagged "credential-theft" — guides, analysis, and best practices for software supply chain and application security.
26 articles
Incident Response
Heroku and GitHub OAuth Token Theft: The Early Warning Signs
Stolen OAuth tokens from Heroku's integration with GitHub gave attackers access to private repositories across dozens of organizations. The breach revealed systemic weaknesses in third-party OAuth integrations.
Jan 6, 20265 min read
Supply Chain Attacks
Codecov Bash Uploader Compromise: A Supply Chain Attack on CI/CD
Attackers modified Codecov's bash uploader script to steal environment variables from CI pipelines. Thousands of repositories were exposed for two months.
Jan 2, 20265 min read
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.