ransomware
Safeguard articles tagged "ransomware" — guides, analysis, and best practices for software supply chain and application security.
87 articles
The ConnectWise ScreenConnect Path Traversal Bug Behind Storm-1175's Medusa Ransomware Runs
CVE-2024-1708 carries CISA's known-ransomware-use designation, tied directly to Storm-1175's high-tempo Medusa ransomware operations against unpatched, internet-facing RMM instances.
SmarterMail's Triple Threat: Three Unauthenticated Roads to Full Compromise
In eleven days, SmarterMail picked up three confirmed-exploited CVEs, all unauthenticated, all tied to known ransomware use — file upload, password-reset bypass, and an API missing authentication.
SolarWinds Web Help Desk's Deserialization Problem, Confirmed for Ransomware
Two separate deserialization RCEs and a security-control bypass in Web Help Desk, one confirmed for ransomware use, plus a denial-of-service bug in Serv-U.
Three of Oracle's Five Confirmed-Exploited CVEs Are Tied to Ransomware
PeopleSoft and E-Business Suite together account for three ransomware-associated Oracle vulnerabilities in a single year — an unusually high concentration for one vendor.
A Second Cisco Firewall Management Center Bug, This One Confirmed for Ransomware
CVE-2026-20131 in Cisco FMC carries CISA's confirmed ransomware flag — the second FMC vulnerability covered in this series, alongside new findings in Email Gateway, ASA/FTD, and Unified CM.
PTC Windchill and FlexPLM's Deserialization RCE Is Confirmed Tied to Ransomware
CVE-2026-12569, a deserialization RCE in PTC's product lifecycle management platforms, carries CISA's confirmed ransomware campaign flag — a notable finding in specialised industrial software.
VMware vCenter's Syslog Server Had a Path Traversal Bug CISA Ties to Ransomware
CVE-2026-59310, a directory traversal vulnerability in vCenter's Syslog server leading to code execution, carries CISA's confirmed ransomware campaign flag.
Five SharePoint CVEs in Five Weeks: The Deserialization Habit Continues
Microsoft SharePoint had five vulnerabilities confirmed exploited between July and August 2026, three of them the same root cause: deserialization of untrusted data. One carries CISA's confirmed ransomware flag.
Four SonicWall SMA1000 CVEs, Two Confirmed for Ransomware, Ten Weeks Apart
SonicWall's SMA1000 VPN appliance had four vulnerabilities confirmed exploited in 2026, two of them flagged by CISA for confirmed ransomware use. The same two bug classes, in the same two interfaces, twice.
ConnectWise ScreenConnect, SimpleHelp and N-able N-central: Remote Access Tools Keep Entering KEV
Four vulnerabilities across three remote monitoring and management platforms confirmed as exploited between June and September 2026. RMM software's structural appeal to ransomware operators, explained through the actual mechanisms.
Ransomware defense strategy for engineering teams
Ransomware hit 44% of breaches in Verizon's 2025 DBIR, up from 32% a year prior. Here's the backup, access, and detection playbook that actually stops it.
PaperCut CVE-2023-27350 Explained: Auth Bypass to Unauthenticated RCE
CVE-2023-27350 is an authentication bypass in PaperCut MF and NG that hands an attacker admin access and remote code execution, rated CVSS 9.8. Here is the timeline, root cause, and how to remediate.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.