Safeguard
Tag

supply-chain

Safeguard articles tagged "supply-chain" — guides, analysis, and best practices for software supply chain and application security.

100 articles

Vulnerability Analysis

CrowdStrike (2024): The Update Channel Failed With No Attacker Involved

A factual look at the July 2024 CrowdStrike Falcon content update that crashed millions of Windows hosts worldwide, and why an incident with no adversary belongs in any serious discussion of software supply chain risk.

Sep 17, 20263 min read
Vulnerability Analysis

ua-parser-js (2021): An npm Account Takeover With Millions of Weekly Downloads

A factual account of the October 2021 ua-parser-js compromise, in which an attacker hijacked the maintainer npm account and published versions containing cryptominer and credential-stealing malware.

Sep 17, 20262 min read
Vulnerability Analysis

Patch Lag Explains the Old Breaches. It Does Not Explain the New Ones.

Reviewing two decades of major incidents, the ones that defined early security were patch-adoption failures. A growing share of recent ones had no patch to apply, because the compromise was in the distribution chain itself. These need different defences.

Sep 17, 20264 min read
Vulnerability Analysis

polyfill.io (2024): What Happens When a CDN Domain Changes Hands

A factual account of the 2024 polyfill.io incident, in which a widely embedded JavaScript CDN domain was acquired and began serving malicious code to a large number of websites.

Sep 17, 20262 min read
Vulnerability Analysis

3CX (2023): The First Widely Documented Cascading Supply Chain Attack

A factual retrospective on the 2023 3CX desktop app compromise, notable because the attackers reached 3CX through a prior supply chain compromise of a different vendor, producing a chain of two linked attacks.

Sep 17, 20262 min read
Vulnerability Analysis

Codecov (2021): A Modified CI Script That Harvested Secrets for Two Months

A factual retrospective on the 2021 Codecov Bash Uploader compromise, where attackers modified a widely used CI script to exfiltrate environment variables, including credentials, from thousands of build pipelines.

Sep 17, 20262 min read
Vulnerability Analysis

event-stream (2018): When a Maintainer Handoff Became a Supply Chain Attack

A factual account of the 2018 event-stream npm compromise, in which a new maintainer added a malicious dependency targeting a specific cryptocurrency wallet, and what it revealed about maintainer-trust risk.

Sep 17, 20262 min read
Vulnerability Analysis

Dependency Confusion (2021): How Public Package Registries Enabled Internal-Name Hijacking

A factual account of Alex Birsan’s 2021 dependency confusion research, which used public npm/PyPI/RubyGems packages matching internal company package names to execute code inside Apple, Microsoft, PayPal, and other major organizations.

Sep 17, 20262 min read
Vulnerability Analysis

NotPetya (2017): A Supply Chain Wiper Disguised as Ransomware

A factual retrospective on the June 2017 NotPetya attack, distributed through a compromised update to Ukrainian accounting software M.E.Doc, which caused billions in damages worldwide.

Sep 17, 20262 min read
Vulnerability Analysis

Kaseya VSA (2021): A Supply Chain Ransomware Attack via MSP Tooling

A factual look at the July 2021 Kaseya VSA supply chain attack, in which REvil affiliates exploited a zero-day to deploy ransomware through managed service provider software to downstream customers.

Sep 17, 20262 min read
Vulnerability Analysis

The XZ Utils Backdoor (CVE-2024-3094): A Near-Miss Supply Chain Attack

A factual retrospective on the March 2024 discovery of a deliberately planted backdoor in XZ Utils, inserted over a multi-year social-engineering campaign against the open-source maintainer.

Sep 16, 20262 min read
Vulnerability Analysis

Log4Shell (CVE-2021-44228): The Log4j RCE and Its Supply Chain Lesson

A factual look at Log4Shell, the critical remote code execution vulnerability in Apache Log4j disclosed in December 2021, and why it became a defining supply chain security event.

Sep 16, 20262 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.