2021
Safeguard articles tagged "2021" — guides, analysis, and best practices for software supply chain and application security.
4 articles
Codecov (2021): A Modified CI Script That Harvested Secrets for Two Months
A factual retrospective on the 2021 Codecov Bash Uploader compromise, where attackers modified a widely used CI script to exfiltrate environment variables, including credentials, from thousands of build pipelines.
ProxyLogon (2021): The Exchange Server Vulnerabilities Behind the HAFNIUM Campaign
A factual retrospective on ProxyLogon (CVE-2021-26855 and related CVEs), a chain of Microsoft Exchange Server vulnerabilities exploited at scale in early 2021, compromising tens of thousands of organizations.
Colonial Pipeline (2021): A Single Compromised VPN Password
A factual retrospective on the May 2021 Colonial Pipeline ransomware attack, traced to a single compromised VPN account password with no multi-factor authentication, and its effect on U.S. critical infrastructure fuel supply.
Dependency Confusion (2021): How Public Package Registries Enabled Internal-Name Hijacking
A factual account of Alex Birsan’s 2021 dependency confusion research, which used public npm/PyPI/RubyGems packages matching internal company package names to execute code inside Apple, Microsoft, PayPal, and other major organizations.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.