threat-intelligence
Safeguard articles tagged "threat-intelligence" — guides, analysis, and best practices for software supply chain and application security.
55 articles
Indirect Prompt Injection Stopped Being a Demo. Google Is Measuring It at Web Scale.
Malicious injected instructions are now tracked across billions of crawled pages a month, every AI browser tested at Black Hat proved vulnerable, and one framework bug turned a prompt into RCE.
Device Code Phishing Rose 15x. Checking the URL Does Not Help.
Device code phishing sends victims to a genuine Microsoft page to enter a genuine code. There is no fake domain and no credential to steal. Training built on spotting bad URLs has nothing to use.
A Year Inside the Installer: QuickFox, FDMTP, and Targeted Supply Chain Patience
The trojanized QuickFox installer ran for roughly a year, fingerprinting each victim before deploying a backdoor. Selective targeting bought the dwell time and broke conventional detection.
Five Numbers From the CrowdStrike 2026 Threat Hunting Report That Should Change Your Roadmap
87% of software registry threats were malicious npm packages. 88% of exploitation with a public PoC happened inside 48 hours. Device code phishing rose 15x. Five numbers, five pieces of work.
Bring Your Own Runtime: Why the keyv Payload Downloaded Bun
The August 2026 npm worm did not run its second stage in Node. It downloaded a standalone Bun binary first — a choice that defeats a surprising amount of build-pipeline monitoring.
Go binary malware distribution trends
Go binaries are now a preferred malware delivery format — statically linked, cross-platform, and hard to fingerprint. Here's what the trend data shows.
What Is Exploit-DB? Using the Exploit Database for Defense
Exploit-DB is a public archive of exploits and proof-of-concept code maintained by OffSec. Defenders can use it to understand exposure and prioritize patching.
Best open source vulnerability database and threat intell...
A practical buyer's guide to open source vulnerability database tools, CVE aggregation, and threat intel feeds for tracking OSS risk.
TeamPCP: Running a Software Supply Chain Attack Like a Production Pipeline
TeamPCP (UNC6780) is the most active actor in the 2026 supply chain corpus, weaponizing the tools developers trust most. Here is how the operation works, and why a zero-CVE campaign breaks the model most teams still rely on.
Ransomware vs. Hospitals: The 2026 Healthcare Surge and the Push to Call It Terrorism
Healthcare ransomware dipped in volume in May 2026 but kept climbing in impact, and a former FBI cyber chief is asking Congress to treat hospital ransomware as terrorism. We weigh the policy debate against what actually protects patients.
ShinyHunters Breaches Match Group: Hinge, Match, and OkCupid Data Exposed in a Vishing-Driven Extortion Hit
ShinyHunters claimed 10 million records from Match Group's dating apps in late January 2026. Here is what was actually taken (Hinge, Match, and OkCupid — notably not Tinder), how a single vishing call opened the door, and why dating-app data raises the extortion stakes.
Kairos Ransomware Hits Gregory Jewellers: 574 GB of Data Extortion at an Australian Luxury Retailer
The Kairos extortion group claims it stole roughly 574 GB from Australian luxury jeweller Gregory Jewellers. Here is what is verified, what the group's playbook tells us, and why pure data-extortion crews are the harder problem.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.