Safeguard
Tag

threat-intelligence

Safeguard articles tagged "threat-intelligence" — guides, analysis, and best practices for software supply chain and application security.

55 articles

AI Security

Indirect Prompt Injection Stopped Being a Demo. Google Is Measuring It at Web Scale.

Malicious injected instructions are now tracked across billions of crawled pages a month, every AI browser tested at Black Hat proved vulnerable, and one framework bug turned a prompt into RCE.

Aug 12, 20266 min read
Security

Device Code Phishing Rose 15x. Checking the URL Does Not Help.

Device code phishing sends victims to a genuine Microsoft page to enter a genuine code. There is no fake domain and no credential to steal. Training built on spotting bad URLs has nothing to use.

Aug 9, 20266 min read
Supply Chain Attacks

A Year Inside the Installer: QuickFox, FDMTP, and Targeted Supply Chain Patience

The trojanized QuickFox installer ran for roughly a year, fingerprinting each victim before deploying a backdoor. Selective targeting bought the dwell time and broke conventional detection.

Aug 8, 20266 min read
Industry Analysis

Five Numbers From the CrowdStrike 2026 Threat Hunting Report That Should Change Your Roadmap

87% of software registry threats were malicious npm packages. 88% of exploitation with a public PoC happened inside 48 hours. Device code phishing rose 15x. Five numbers, five pieces of work.

Aug 6, 20266 min read
Threat Intelligence

Bring Your Own Runtime: Why the keyv Payload Downloaded Bun

The August 2026 npm worm did not run its second stage in Node. It downloaded a standalone Bun binary first — a choice that defeats a surprising amount of build-pipeline monitoring.

Aug 6, 20266 min read
Open Source Security

Go binary malware distribution trends

Go binaries are now a preferred malware delivery format — statically linked, cross-platform, and hard to fingerprint. Here's what the trend data shows.

Jul 22, 20266 min read
Security

What Is Exploit-DB? Using the Exploit Database for Defense

Exploit-DB is a public archive of exploits and proof-of-concept code maintained by OffSec. Defenders can use it to understand exposure and prioritize patching.

Jul 16, 20264 min read
Buyer's Guides

Best open source vulnerability database and threat intell...

A practical buyer's guide to open source vulnerability database tools, CVE aggregation, and threat intel feeds for tracking OSS risk.

Jul 8, 20267 min read
Threat Intelligence

TeamPCP: Running a Software Supply Chain Attack Like a Production Pipeline

TeamPCP (UNC6780) is the most active actor in the 2026 supply chain corpus, weaponizing the tools developers trust most. Here is how the operation works, and why a zero-CVE campaign breaks the model most teams still rely on.

Jun 23, 20267 min read
Threat Intelligence

Ransomware vs. Hospitals: The 2026 Healthcare Surge and the Push to Call It Terrorism

Healthcare ransomware dipped in volume in May 2026 but kept climbing in impact, and a former FBI cyber chief is asking Congress to treat hospital ransomware as terrorism. We weigh the policy debate against what actually protects patients.

Jun 20, 20267 min read
Threat Intelligence

ShinyHunters Breaches Match Group: Hinge, Match, and OkCupid Data Exposed in a Vishing-Driven Extortion Hit

ShinyHunters claimed 10 million records from Match Group's dating apps in late January 2026. Here is what was actually taken (Hinge, Match, and OkCupid — notably not Tinder), how a single vishing call opened the door, and why dating-app data raises the extortion stakes.

Jun 20, 20267 min read
Threat Intelligence

Kairos Ransomware Hits Gregory Jewellers: 574 GB of Data Extortion at an Australian Luxury Retailer

The Kairos extortion group claims it stole roughly 574 GB from Australian luxury jeweller Gregory Jewellers. Here is what is verified, what the group's playbook tells us, and why pure data-extortion crews are the harder problem.

Jun 19, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

threat-intelligence — Safeguard Blog