ransomware
Safeguard articles tagged "ransomware" — guides, analysis, and best practices for software supply chain and application security.
87 articles
Colonial Pipeline (2021): A Single Compromised VPN Password
A factual retrospective on the May 2021 Colonial Pipeline ransomware attack, traced to a single compromised VPN account password with no multi-factor authentication, and its effect on U.S. critical infrastructure fuel supply.
Kaseya VSA (2021): A Supply Chain Ransomware Attack via MSP Tooling
A factual look at the July 2021 Kaseya VSA supply chain attack, in which REvil affiliates exploited a zero-day to deploy ransomware through managed service provider software to downstream customers.
WannaCry (2017): How EternalBlue and MS17-010 Enabled a Global Ransomware Worm
A factual retrospective on the May 2017 WannaCry ransomware outbreak, which spread using the EternalBlue exploit for the SMBv1 vulnerability patched as MS17-010.
2026 Mid-Year Threat Landscape: Supply-Chain Worms, Agentic AI, and Edge Zero-Days
A defender's synthesis of the first half of 2026 — self-propagating package worms, the agentic-AI access-control problem, edge-appliance zero-days, and a healthcare ransomware surge — and what to prioritize next.
The Windows CLFS Driver Produced a Second Confirmed-Exploited CVE, Two Years Apart
CVE-2023-36424 and CVE-2021-43226 both hit the same Windows Common Log File System Driver, one carrying a confirmed ransomware association, plus a separate Desktop Window Manager information leak.
HPE OneView and Fortra GoAnywhere MFT: Two Perfect-10 Unauthenticated RCEs
Infrastructure management and managed file transfer software rarely share a vulnerability post, but both HPE OneView and Fortra GoAnywhere MFT scored a maximum CVSS 10.0 for unauthenticated RCE.
BeyondTrust Remote Support's Pre-Auth Command Injection Is a Ransomware Vector
CVE-2026-1731 lets an unauthenticated attacker run OS commands on BeyondTrust Remote Support and Privileged Remote Access, with CISA confirming active ransomware use.
JetBrains TeamCity's Path Traversal Bug Is Now Tied to Ransomware
CVE-2024-27199, a relative path traversal in TeamCity enabling limited admin actions, carries CISA's confirmed ransomware flag — a reminder that CI/CD servers are a supply-chain target.
WatchGuard Firebox's IKEv2 VPN Bug Hit Twice, and One Is Tied to Ransomware
Two nearly identical out-of-bounds write vulnerabilities in Firebox's iked process, both CVSS 9.8, both unauthenticated remote code execution, one confirmed for ransomware.
A Second PaperCut Authentication Bypass, This One Tied to Ransomware
CVE-2023-27351 in PaperCut's SecurityRequestFilter class bypasses authentication with no credentials at all, and CISA flags it with a confirmed ransomware association.
SimpleHelp's Two Confirmed-Exploited Bugs Form a Complete Ransomware Attack Chain
A missing authorization flaw and a path traversal RCE in SimpleHelp remote support software, both confirmed for Medusa and DragonForce ransomware operations.
Two PAN-OS Vulnerabilities Target Palo Alto's Front Doors: GlobalProtect and Captive Portal
A root-privilege buffer overflow in the User-ID Authentication Portal and a GlobalProtect authentication bypass confirmed for ransomware use, both hitting PAN-OS's remote-access surface within weeks of each other.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.