Safeguard
Tag

supply-chain

Safeguard articles tagged "supply-chain" — guides, analysis, and best practices for software supply chain and application security.

850 articles

Network Security

DNS Hijacking and Its Supply Chain Implications

DNS hijacking can redirect software updates, package downloads, and API calls to attacker-controlled servers. Here's how this underrated attack vector threatens your entire software supply chain.

Aug 5, 20216 min read
Open Source Security

Open Source Security: State of the Union 2021

Open source powers the modern internet, but its security model is under strain. Here's the 2021 landscape of open source risk, from funding to maintainer burnout to malicious packages.

Aug 1, 20216 min read
DevSecOps

Why Software Bill of Materials Matter

SBOMs are the foundation of software supply chain security. Without knowing what's in your software, you can't secure it. Here's why SBOMs matter and how to get started.

Jul 25, 20216 min read
Risk Management

Disaster Recovery Planning for Software Supply Chain Incidents

When a supply chain attack hits, your DR plan needs to cover more than just infrastructure failover. Here is how to prepare for the worst.

Jun 22, 20217 min read
Ransomware

JBS Foods Ransomware Attack: When Hackers Targeted the World's Meat Supply

REvil ransomware shut down the world's largest meat processor, disrupting supply chains across the US, Australia, and Canada — and resulted in an $11 million ransom payment.

Jun 5, 20216 min read
Incident Analysis

Codecov Bash Uploader Compromise: A Retrospective

A single altered line in Codecov's Bash Uploader leaked CI secrets for 69 days across thousands of repos. Here is what actually happened and why.

Apr 15, 20216 min read
Incident Analysis

SunBurst: A Supply Chain Attack Evolution Study

The SolarWinds SunBurst campaign rewrote the supply chain threat model. Five years of research reveal what changed and what defenders still miss.

Dec 18, 20206 min read
Incident Analysis

CCleaner 2017: Anatomy of a Quiet Supply Chain Hit

The CCleaner backdoor of 2017 was among the first modern build-system compromises to achieve mass distribution through a trusted installer.

Sep 19, 20177 min read
Incident Analysis

M.E.Doc and NotPetya: The Origin Story

The forensic detail of how M.E.Doc's update server became the delivery mechanism for NotPetya, and what it means for small-vendor risk.

Sep 4, 20178 min read
Incident Analysis

NotPetya's Origin: A Supply Chain Story From Ukraine

NotPetya is remembered as ransomware. It was not. It was a supply chain wiper that detonated through Ukrainian tax software in June 2017.

Jul 5, 20177 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

supply-chain (Page 71) — Safeguard Blog