Safeguard
Tag

hardcoded-credentials

Safeguard articles tagged "hardcoded-credentials" — guides, analysis, and best practices for software supply chain and application security.

8 articles

Vulnerability Analysis

Uber (2016): Hardcoded Credentials in a Private Repository

A factual retrospective on the 2016 Uber breach, where attackers used credentials found in a private GitHub repository to access an AWS account holding rider and driver data, and how it was later concealed.

Sep 17, 20262 min read
Vulnerability Analysis

Gladinet CentreStack and Triofox: A Hardcoded Key, an Exposed Setup Page, and an Unauthenticated LFI

Three confirmed-exploited Gladinet vulnerabilities that NVD itself says can be chained together into full system compromise across CentreStack and Triofox.

Sep 16, 20265 min read
Vulnerability Analysis

Dell RecoverPoint's Perfect-10 Bug Was a Zero-Day Before It Was a Patch

CVE-2026-22769's hardcoded credential in Dell RecoverPoint for VMs was already being exploited by a tracked threat group, UNC6201, before Dell shipped a fix.

Sep 16, 20264 min read
Vulnerability Analysis

A CVSS 5.3 That Cisco Rated High: Static Credentials in Firewall Management Center

CVE-2026-20316 scores 5.3. Cisco rated its security impact High anyway, and CISA added it to the KEV catalogue. On a firewall management appliance, the base score measures the wrong thing.

Aug 5, 20266 min read
Vulnerability Analysis

Hardcoded credentials vulnerabilities explained

Hardcoded credentials (CWE-798) have caused real breaches at Uber, Toyota, and Mercedes-Benz. Here's how they happen, how common they are, and how to fix them.

Jul 31, 20267 min read
Buyer's Guides

Best secrets detection tools for source code repositories

A practical, no-hype comparison of secrets detection tools for source code repos — evaluation criteria, five real vendors reviewed fairly, and how Safeguard fits in.

Jul 21, 20269 min read
Incident Analysis

SolarWinds Web Help Desk CVE-2024-28987: Hardcoded Credential in Federal Networks

SolarWinds shipped a hardcoded helpdeskIntegrationUser credential in Web Help Desk that CISA added to KEV on October 15, 2024 after federal agency intrusions.

Mar 26, 20265 min read
Vulnerability Analysis

What Are Hardcoded Credentials

Hardcoded credentials are secrets baked into code instead of a vault. Toyota, Uber, and Samsung breaches show why that risk never expires on its own.

Mar 23, 20268 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.