Safeguard
Tag

ransomware

Safeguard articles tagged "ransomware" — guides, analysis, and best practices for software supply chain and application security.

87 articles

Vulnerability Analysis

The ConnectWise ScreenConnect Path Traversal Bug Behind Storm-1175's Medusa Ransomware Runs

CVE-2024-1708 carries CISA's known-ransomware-use designation, tied directly to Storm-1175's high-tempo Medusa ransomware operations against unpatched, internet-facing RMM instances.

Sep 16, 20265 min read
Vulnerability Analysis

SmarterMail's Triple Threat: Three Unauthenticated Roads to Full Compromise

In eleven days, SmarterMail picked up three confirmed-exploited CVEs, all unauthenticated, all tied to known ransomware use — file upload, password-reset bypass, and an API missing authentication.

Sep 16, 20265 min read
Vulnerability Analysis

SolarWinds Web Help Desk's Deserialization Problem, Confirmed for Ransomware

Two separate deserialization RCEs and a security-control bypass in Web Help Desk, one confirmed for ransomware use, plus a denial-of-service bug in Serv-U.

Sep 16, 20264 min read
Vulnerability Analysis

Three of Oracle's Five Confirmed-Exploited CVEs Are Tied to Ransomware

PeopleSoft and E-Business Suite together account for three ransomware-associated Oracle vulnerabilities in a single year — an unusually high concentration for one vendor.

Sep 16, 20264 min read
Vulnerability Analysis

A Second Cisco Firewall Management Center Bug, This One Confirmed for Ransomware

CVE-2026-20131 in Cisco FMC carries CISA's confirmed ransomware flag — the second FMC vulnerability covered in this series, alongside new findings in Email Gateway, ASA/FTD, and Unified CM.

Sep 16, 20264 min read
Vulnerability Analysis

PTC Windchill and FlexPLM's Deserialization RCE Is Confirmed Tied to Ransomware

CVE-2026-12569, a deserialization RCE in PTC's product lifecycle management platforms, carries CISA's confirmed ransomware campaign flag — a notable finding in specialised industrial software.

Sep 16, 20264 min read
Vulnerability Analysis

VMware vCenter's Syslog Server Had a Path Traversal Bug CISA Ties to Ransomware

CVE-2026-59310, a directory traversal vulnerability in vCenter's Syslog server leading to code execution, carries CISA's confirmed ransomware campaign flag.

Sep 16, 20264 min read
Vulnerability Analysis

Five SharePoint CVEs in Five Weeks: The Deserialization Habit Continues

Microsoft SharePoint had five vulnerabilities confirmed exploited between July and August 2026, three of them the same root cause: deserialization of untrusted data. One carries CISA's confirmed ransomware flag.

Sep 16, 20264 min read
Vulnerability Analysis

Four SonicWall SMA1000 CVEs, Two Confirmed for Ransomware, Ten Weeks Apart

SonicWall's SMA1000 VPN appliance had four vulnerabilities confirmed exploited in 2026, two of them flagged by CISA for confirmed ransomware use. The same two bug classes, in the same two interfaces, twice.

Sep 16, 20265 min read
Vulnerability Analysis

ConnectWise ScreenConnect, SimpleHelp and N-able N-central: Remote Access Tools Keep Entering KEV

Four vulnerabilities across three remote monitoring and management platforms confirmed as exploited between June and September 2026. RMM software's structural appeal to ransomware operators, explained through the actual mechanisms.

Sep 16, 20264 min read
Best Practices

Ransomware defense strategy for engineering teams

Ransomware hit 44% of breaches in Verizon's 2025 DBIR, up from 32% a year prior. Here's the backup, access, and detection playbook that actually stops it.

Jul 15, 20266 min read
Vulnerability Analysis

PaperCut CVE-2023-27350 Explained: Auth Bypass to Unauthenticated RCE

CVE-2023-27350 is an authentication bypass in PaperCut MF and NG that hands an attacker admin access and remote code execution, rated CVSS 9.8. Here is the timeline, root cause, and how to remediate.

Jul 2, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.