supply-chain
Safeguard articles tagged "supply-chain" — guides, analysis, and best practices for software supply chain and application security.
100 articles
CrowdStrike (2024): The Update Channel Failed With No Attacker Involved
A factual look at the July 2024 CrowdStrike Falcon content update that crashed millions of Windows hosts worldwide, and why an incident with no adversary belongs in any serious discussion of software supply chain risk.
ua-parser-js (2021): An npm Account Takeover With Millions of Weekly Downloads
A factual account of the October 2021 ua-parser-js compromise, in which an attacker hijacked the maintainer npm account and published versions containing cryptominer and credential-stealing malware.
Patch Lag Explains the Old Breaches. It Does Not Explain the New Ones.
Reviewing two decades of major incidents, the ones that defined early security were patch-adoption failures. A growing share of recent ones had no patch to apply, because the compromise was in the distribution chain itself. These need different defences.
polyfill.io (2024): What Happens When a CDN Domain Changes Hands
A factual account of the 2024 polyfill.io incident, in which a widely embedded JavaScript CDN domain was acquired and began serving malicious code to a large number of websites.
3CX (2023): The First Widely Documented Cascading Supply Chain Attack
A factual retrospective on the 2023 3CX desktop app compromise, notable because the attackers reached 3CX through a prior supply chain compromise of a different vendor, producing a chain of two linked attacks.
Codecov (2021): A Modified CI Script That Harvested Secrets for Two Months
A factual retrospective on the 2021 Codecov Bash Uploader compromise, where attackers modified a widely used CI script to exfiltrate environment variables, including credentials, from thousands of build pipelines.
event-stream (2018): When a Maintainer Handoff Became a Supply Chain Attack
A factual account of the 2018 event-stream npm compromise, in which a new maintainer added a malicious dependency targeting a specific cryptocurrency wallet, and what it revealed about maintainer-trust risk.
Dependency Confusion (2021): How Public Package Registries Enabled Internal-Name Hijacking
A factual account of Alex Birsan’s 2021 dependency confusion research, which used public npm/PyPI/RubyGems packages matching internal company package names to execute code inside Apple, Microsoft, PayPal, and other major organizations.
NotPetya (2017): A Supply Chain Wiper Disguised as Ransomware
A factual retrospective on the June 2017 NotPetya attack, distributed through a compromised update to Ukrainian accounting software M.E.Doc, which caused billions in damages worldwide.
Kaseya VSA (2021): A Supply Chain Ransomware Attack via MSP Tooling
A factual look at the July 2021 Kaseya VSA supply chain attack, in which REvil affiliates exploited a zero-day to deploy ransomware through managed service provider software to downstream customers.
The XZ Utils Backdoor (CVE-2024-3094): A Near-Miss Supply Chain Attack
A factual retrospective on the March 2024 discovery of a deliberately planted backdoor in XZ Utils, inserted over a multi-year social-engineering campaign against the open-source maintainer.
Log4Shell (CVE-2021-44228): The Log4j RCE and Its Supply Chain Lesson
A factual look at Log4Shell, the critical remote code execution vulnerability in Apache Log4j disclosed in December 2021, and why it became a defining supply chain security event.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.