Safeguard
Tag

ransomware

Safeguard articles tagged "ransomware" — guides, analysis, and best practices for software supply chain and application security.

87 articles

Threat Intelligence

Lazarus Group: 3CX and Software Builds

Lazarus turned a developer's personal machine into a corporate build-system compromise. Here is how that cascade actually worked and what it teaches about build-system trust.

Feb 6, 20267 min read
Incident Analysis

MGM Resorts and Caesars Hit by Scattered Spider: Social Engineering at Scale

In September 2023, the Scattered Spider hacking group crippled MGM Resorts and extorted Caesars Entertainment through phone-based social engineering, exposing how human vulnerabilities can bypass even the most expensive security stacks.

Feb 3, 20268 min read
Threat Intelligence

RansomHub Ransomware and EDR Bypass (2024)

RansomHub absorbed affiliates displaced by BlackCat and ran one of the most prolific extortion operations of 2024. Here is what made its tradecraft effective and how to counter it.

Feb 2, 20267 min read
Threat Intelligence

Scattered Spider: Identity as Supply Chain 2024-25

Scattered Spider showed that help-desk processes, SaaS federation, and MSPs are the new software supply chain. Here is how to think about it and what to actually change.

Jan 30, 20267 min read
Threat Intelligence

Clop/Cl0p Supply Chain Exploitation Patterns

Clop has industrialized third-party file-transfer exploitation. Here is how the group operates, what it keeps repeating, and how defenders can stop repeating their own mistakes.

Jan 23, 20266 min read
Incident Analysis

GoAnywhere MFT Zero-Day (CVE-2023-0669): Clop Ransomware's File Transfer Rampage

The Clop ransomware gang exploited a pre-auth RCE in GoAnywhere MFT to breach over 130 organizations. The campaign foreshadowed their devastating MOVEit attack months later.

Jan 22, 20266 min read
Incident Analysis

Synnovis NHS Qilin Ransomware: Pathology Supply Chain Lessons

Eighteen months after Qilin encrypted Synnovis, the pathology provider finally finished notifying NHS trusts. We unpack how a single supplier paralysed London hospitals and how defenders can prepare.

Jan 9, 20267 min read
Ransomware

Costa Rica Conti Ransomware: The First Ransomware Attack to Trigger a National Emergency

The Conti ransomware group attacked Costa Rica's government systems so severely that the president declared a national emergency — the first time a country took such action in response to a cyberattack.

Jan 8, 20265 min read
Ransomware

Kronos Ransomware Attack: When Payroll Systems Go Dark Before the Holidays

A ransomware attack on Ultimate Kronos Group disrupted payroll and workforce management for millions of workers at hospitals, governments, and major employers right before the holiday season.

Jan 5, 20265 min read
Ransomware

Accenture LockBit Ransomware Attack: When a Security Consultant Gets Hacked

LockBit ransomware operators breached Accenture, a major global consulting firm, claiming to have stolen 6TB of data and demanding a $50 million ransom.

Jan 3, 20265 min read
Incident Analysis

Kaseya VSA Ransomware: A Supply Chain Analysis

REvil chained three zero-days in Kaseya VSA to push ransomware through 1,500 MSP customers on July 2, 2021. Here is the technical anatomy.

Jan 3, 20266 min read
Incident Response

Kaseya VSA Ransomware: Supply Chain Attack Hits 1,500 Businesses

REvil exploited Kaseya's VSA platform to push ransomware to managed service providers and their customers. Up to 1,500 businesses were hit in a single weekend.

Jan 2, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.