Safeguard
Tag

ransomware

Safeguard articles tagged "ransomware" — guides, analysis, and best practices for software supply chain and application security.

87 articles

Vulnerability Analysis

Colonial Pipeline (2021): A Single Compromised VPN Password

A factual retrospective on the May 2021 Colonial Pipeline ransomware attack, traced to a single compromised VPN account password with no multi-factor authentication, and its effect on U.S. critical infrastructure fuel supply.

Sep 17, 20262 min read
Vulnerability Analysis

Kaseya VSA (2021): A Supply Chain Ransomware Attack via MSP Tooling

A factual look at the July 2021 Kaseya VSA supply chain attack, in which REvil affiliates exploited a zero-day to deploy ransomware through managed service provider software to downstream customers.

Sep 17, 20262 min read
Vulnerability Analysis

WannaCry (2017): How EternalBlue and MS17-010 Enabled a Global Ransomware Worm

A factual retrospective on the May 2017 WannaCry ransomware outbreak, which spread using the EternalBlue exploit for the SMBv1 vulnerability patched as MS17-010.

Sep 16, 20262 min read
Threat Intelligence

2026 Mid-Year Threat Landscape: Supply-Chain Worms, Agentic AI, and Edge Zero-Days

A defender's synthesis of the first half of 2026 — self-propagating package worms, the agentic-AI access-control problem, edge-appliance zero-days, and a healthcare ransomware surge — and what to prioritize next.

Sep 16, 20265 min read
Vulnerability Analysis

The Windows CLFS Driver Produced a Second Confirmed-Exploited CVE, Two Years Apart

CVE-2023-36424 and CVE-2021-43226 both hit the same Windows Common Log File System Driver, one carrying a confirmed ransomware association, plus a separate Desktop Window Manager information leak.

Sep 16, 20265 min read
Vulnerability Analysis

HPE OneView and Fortra GoAnywhere MFT: Two Perfect-10 Unauthenticated RCEs

Infrastructure management and managed file transfer software rarely share a vulnerability post, but both HPE OneView and Fortra GoAnywhere MFT scored a maximum CVSS 10.0 for unauthenticated RCE.

Sep 16, 20265 min read
Vulnerability Analysis

BeyondTrust Remote Support's Pre-Auth Command Injection Is a Ransomware Vector

CVE-2026-1731 lets an unauthenticated attacker run OS commands on BeyondTrust Remote Support and Privileged Remote Access, with CISA confirming active ransomware use.

Sep 16, 20265 min read
Vulnerability Analysis

JetBrains TeamCity's Path Traversal Bug Is Now Tied to Ransomware

CVE-2024-27199, a relative path traversal in TeamCity enabling limited admin actions, carries CISA's confirmed ransomware flag — a reminder that CI/CD servers are a supply-chain target.

Sep 16, 20265 min read
Vulnerability Analysis

WatchGuard Firebox's IKEv2 VPN Bug Hit Twice, and One Is Tied to Ransomware

Two nearly identical out-of-bounds write vulnerabilities in Firebox's iked process, both CVSS 9.8, both unauthenticated remote code execution, one confirmed for ransomware.

Sep 16, 20264 min read
Vulnerability Analysis

A Second PaperCut Authentication Bypass, This One Tied to Ransomware

CVE-2023-27351 in PaperCut's SecurityRequestFilter class bypasses authentication with no credentials at all, and CISA flags it with a confirmed ransomware association.

Sep 16, 20264 min read
Vulnerability Analysis

SimpleHelp's Two Confirmed-Exploited Bugs Form a Complete Ransomware Attack Chain

A missing authorization flaw and a path traversal RCE in SimpleHelp remote support software, both confirmed for Medusa and DragonForce ransomware operations.

Sep 16, 20264 min read
Vulnerability Analysis

Two PAN-OS Vulnerabilities Target Palo Alto's Front Doors: GlobalProtect and Captive Portal

A root-privilege buffer overflow in the User-ID Authentication Portal and a GlobalProtect authentication bypass confirmed for ransomware use, both hitting PAN-OS's remote-access surface within weeks of each other.

Sep 16, 20264 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.