<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Safeguard Blog</title>
    <description>Insights on software supply chain security, SBOM compliance, and DevSecOps</description>
    <link>https://safeguard.sh/resources/blog</link>
    <atom:link href="https://safeguard.sh/feed.xml" rel="self" type="application/rss+xml"/>
    <language>en-us</language>
    <lastBuildDate>Fri, 14 Aug 2026 09:22:06 GMT</lastBuildDate>
    <managingEditor>hi@safeguard.sh (Safeguard Team)</managingEditor>
    <webMaster>hi@safeguard.sh (Safeguard Team)</webMaster>
    <ttl>60</ttl>
    <image>
      <url>https://safeguard.sh/icons/icon-192.png</url>
      <title>Safeguard Blog</title>
      <link>https://safeguard.sh/resources/blog</link>
    </image>
    <item>
      <title><![CDATA[Indirect Prompt Injection Stopped Being a Demo. Google Is Measuring It at Web Scale.]]></title>
      <description><![CDATA[Malicious injected instructions are now tracked across billions of crawled pages a month, every AI browser tested at Black Hat proved vulnerable, and one framework bug turned a prompt into RCE.]]></description>
      <link>https://safeguard.sh/resources/blog/indirect-prompt-injection-goes-operational-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/indirect-prompt-injection-goes-operational-2026</guid>
      <pubDate>Wed, 12 Aug 2026 14:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-68820: A 7.0 That Ends With a Kernel Rootkit and Your EDR Switched Off]]></title>
      <description><![CDATA[Lazarus used this afd.sys use-after-free to reach SYSTEM from a local foothold, then loaded a FudModule kernel rootkit. Escalation is never the objective — it is the step before it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2026-68820-afd-sys-lazarus-fudmodule-local-privilege-escalation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2026-68820-afd-sys-lazarus-fudmodule-local-privilege-escalation</guid>
      <pubDate>Wed, 12 Aug 2026 11:30:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Patch Tuesday August 2026: ~398 Flaws, 3 Zero-Days, and One the Norks Already Used]]></title>
      <description><![CDATA[Microsoft shipped fixes for roughly 398 CVEs on 11 August. Three are zero-days, one is under active exploitation by Lazarus, and the vendor tallies disagree by nearly 30.]]></description>
      <link>https://safeguard.sh/resources/blog/microsoft-august-2026-patch-tuesday-roundup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microsoft-august-2026-patch-tuesday-roundup</guid>
      <pubDate>Wed, 12 Aug 2026 09:00:00 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[66,000 CVEs: The Year Enumeration Stopped Being a Strategy]]></title>
      <description><![CDATA[2026 is forecast to close near 66,000 CVEs, driven partly by AI-assisted discovery. At that volume reading the list is not a job anyone can do — and most programmes are still built around reading it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-volume-2026-when-tracking-stops-being-practical</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-volume-2026-when-tracking-stops-being-practical</guid>
      <pubDate>Tue, 11 Aug 2026 14:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-8037: When the Function That Escapes Your Input Is the Bug]]></title>
      <description><![CDATA[Progress Kemp LoadMaster's flaw lives inside escape_quotes(), the routine meant to neutralise dangerous input. It fails to null-terminate, turning a sanitiser into unauthenticated command injection.]]></description>
      <link>https://safeguard.sh/resources/blog/kemp-loadmaster-cve-2026-8037-when-the-sanitiser-is-the-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kemp-loadmaster-cve-2026-8037-when-the-sanitiser-is-the-vulnerability</guid>
      <pubDate>Tue, 11 Aug 2026 11:30:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-63077: Your Build Server Is a Credential Store With an Open Port]]></title>
      <description><![CDATA[An unauthenticated attacker sends a crafted object to TeamCity's agent polling endpoint and gets OS command execution as the server process. Every credential the build server holds sits downstream.]]></description>
      <link>https://safeguard.sh/resources/blog/teamcity-cve-2026-63077-unauthenticated-rce-ci-cd-credential-store</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/teamcity-cve-2026-63077-unauthenticated-rce-ci-cd-credential-store</guid>
      <pubDate>Tue, 11 Aug 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Patch That Wasn't: CVE-2026-18577 and the Incomplete-Fix Problem]]></title>
      <description><![CDATA[N-able patched an authentication bypass in N-central. Attackers found what the patch missed and used it as a zero-day, pivoting into Microsoft 365 and Okta. Incomplete fixes are their own bug class.]]></description>
      <link>https://safeguard.sh/resources/blog/n-able-n-central-cve-2026-18577-incomplete-patch-rmm-blast-radius</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/n-able-n-central-cve-2026-18577-incomplete-patch-rmm-blast-radius</guid>
      <pubDate>Mon, 10 Aug 2026 14:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-9198: Two Endpoints, No Password, Full Remote Code Execution]]></title>
      <description><![CDATA[Langflow's auto-login endpoint mints a superuser token for anyone who asks. Its code-validation endpoint runs Python through exec(). Chained, that is unauthenticated RCE at CVSS 9.8.]]></description>
      <link>https://safeguard.sh/resources/blog/langflow-cve-2026-9198-unauthenticated-rce-ai-orchestration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/langflow-cve-2026-9198-unauthenticated-rce-ai-orchestration</guid>
      <pubDate>Mon, 10 Aug 2026 11:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Two Billion Installs in an Afternoon: The keyv and cacheable npm Worm]]></title>
      <description><![CDATA[On 4 August 2026, one compromised GitHub account seeded a self-propagating npm worm across 444 package names. The packages were caching utilities nobody thinks about — which is why it worked.]]></description>
      <link>https://safeguard.sh/resources/blog/keyv-cacheable-npm-worm-august-2026-blast-radius</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/keyv-cacheable-npm-worm-august-2026-blast-radius</guid>
      <pubDate>Mon, 10 Aug 2026 09:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Python setuptools package_index ReDoS (CVE-2022-40897)]]></title>
      <description><![CDATA[CVE-2022-40897 is a ReDoS flaw in setuptools' package_index.py that can hang CI pipelines when parsing crafted index pages. Here's how to detect and fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/python-setuptools-packageindex-redos-cve-2022-40897</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-setuptools-packageindex-redos-cve-2022-40897</guid>
      <pubDate>Mon, 10 Aug 2026 08:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Python requests library proxy-auth credential leak (CVE-2023-32681)]]></title>
      <description><![CDATA[CVE-2023-32681 lets Python's requests library leak Proxy-Authorization credentials to destination servers on HTTPS redirects. Here's the impact, timeline, and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/python-requests-library-proxy-auth-credential-leak-cve-2023-32681</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-requests-library-proxy-auth-credential-leak-cve-2023-32681</guid>
      <pubDate>Mon, 10 Aug 2026 06:39:33 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[urllib3 CA certificate verification bypass (CVE-2019-11324)]]></title>
      <description><![CDATA[CVE-2019-11324 let urllib3 silently trust unintended CAs during custom certificate validation, undermining pinned-trust and mTLS setups.]]></description>
      <link>https://safeguard.sh/resources/blog/urllib3-ca-certificate-verification-bypass-cve-2019-11324</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/urllib3-ca-certificate-verification-bypass-cve-2019-11324</guid>
      <pubDate>Mon, 10 Aug 2026 05:19:06 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[NAIC Insurance Data Security Model Law compliance for sof...]]></title>
      <description><![CDATA[What NAIC model law software vendor compliance means for insurtech and SaaS vendors, and how insurer TPRM programs are enforcing it in contracts today.]]></description>
      <link>https://safeguard.sh/resources/blog/naic-insurance-data-security-model-law-compliance-for-software-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/naic-insurance-data-security-model-law-compliance-for-software-vendors</guid>
      <pubDate>Mon, 10 Aug 2026 03:58:39 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[urllib3 regular expression denial of service (CVE-2021-33503)]]></title>
      <description><![CDATA[A deep dive into CVE-2021-33503, the urllib3 ReDoS flaw in Python's core HTTP library, its real-world exposure, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/urllib3-regular-expression-denial-of-service-cve-2021-33503</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/urllib3-regular-expression-denial-of-service-cve-2021-33503</guid>
      <pubDate>Mon, 10 Aug 2026 02:38:13 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Third-party risk assessment for insurtech SaaS platforms]]></title>
      <description><![CDATA[A practical playbook for running an insurtech third-party risk assessment across vendors, APIs, and integrations before they touch policyholder data.]]></description>
      <link>https://safeguard.sh/resources/blog/third-party-risk-assessment-for-insurtech-saas-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/third-party-risk-assessment-for-insurtech-saas-platforms</guid>
      <pubDate>Mon, 10 Aug 2026 01:17:46 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[ChatGPT Atlas and the Permanent Browser-Agent Injection Problem]]></title>
      <description><![CDATA[OpenAI shipped ChatGPT Atlas in October 2025 and admitted by December that prompt injection in AI browsers may never be fully solved. Defenders need a posture, not a patch.]]></description>
      <link>https://safeguard.sh/resources/blog/chatgpt-atlas-prompt-injection-permanent-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chatgpt-atlas-prompt-injection-permanent-risk</guid>
      <pubDate>Sun, 09 Aug 2026 23:57:19 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[urllib3 cookie/auth header leak on cross-origin redirect (CVE-2023-43804)]]></title>
      <description><![CDATA[CVE-2023-43804 lets urllib3 leak Cookie headers on cross-origin redirects. See affected versions, severity context, and how to remediate fast.]]></description>
      <link>https://safeguard.sh/resources/blog/urllib3-cookieauth-header-leak-on-cross-origin-redirect-cve-2023-43804</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/urllib3-cookieauth-header-leak-on-cross-origin-redirect-cve-2023-43804</guid>
      <pubDate>Sun, 09 Aug 2026 22:36:53 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[SBOM adoption in underwriting and actuarial software]]></title>
      <description><![CDATA[Insurers price risk with software built on unvetted open-source code. Here's how SBOM underwriting software closes that blind spot.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-adoption-in-underwriting-and-actuarial-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-adoption-in-underwriting-and-actuarial-software</guid>
      <pubDate>Sun, 09 Aug 2026 21:16:26 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[PyYAML full_load unsafe deserialization arbitrary code execution (CVE-2020-14343)]]></title>
      <description><![CDATA[CVE-2020-14343 shows PyYAML's full_load/FullLoader "safe" fix was incomplete, enabling arbitrary code execution. Here's the fix and how to detect exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/pyyaml-fullload-unsafe-deserialization-arbitrary-code-execution-cve-2020-14343</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pyyaml-fullload-unsafe-deserialization-arbitrary-code-execution-cve-2020-14343</guid>
      <pubDate>Sun, 09 Aug 2026 19:55:59 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[PyYAML Loader arbitrary code execution (CVE-2017-18342)]]></title>
      <description><![CDATA[PyYAML's default yaml.load() Loader lets attackers run arbitrary code via crafted YAML input. Here's how CVE-2017-18342 works and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/pyyaml-loader-arbitrary-code-execution-cve-2017-18342</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pyyaml-loader-arbitrary-code-execution-cve-2017-18342</guid>
      <pubDate>Sun, 09 Aug 2026 18:35:33 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to conduct a software supply chain risk assessment fo...]]></title>
      <description><![CDATA[A step-by-step guide for insurance carriers to assess software supply chain risk in vendor portfolios, from SBOM collection to continuous monitoring.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-conduct-a-software-supply-chain-risk-assessment-for-insurance-carriers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-conduct-a-software-supply-chain-risk-assessment-for-insurance-carriers</guid>
      <pubDate>Sun, 09 Aug 2026 17:15:06 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Your Dependency Incident Runbook Assumes a Fixed List of Bad Packages]]></title>
      <description><![CDATA[Most supply chain runbooks say: get the affected package list, search lockfiles, remediate. Against a worm that adds packages while you work, every one of those steps is wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/incident-response-playbook-self-propagating-dependency-worms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/incident-response-playbook-self-propagating-dependency-worms</guid>
      <pubDate>Sun, 09 Aug 2026 16:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[IPython crafted directory code execution (CVE-2022-21699)]]></title>
      <description><![CDATA[CVE-2022-21699 lets attackers plant crafted profile files in shared directories, triggering silent code execution when victims launch IPython or Jupyter sessions.]]></description>
      <link>https://safeguard.sh/resources/blog/ipython-crafted-directory-code-execution-cve-2022-21699</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ipython-crafted-directory-code-execution-cve-2022-21699</guid>
      <pubDate>Sun, 09 Aug 2026 15:54:39 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Software supply chain security for connected and autonomo...]]></title>
      <description><![CDATA[Modern cars run 100M+ lines of code across 150 ECUs from untracked suppliers. Here's why connected vehicle software supply chain security now demands real SBOMs, not compliance checkboxes.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-for-connected-and-autonomous-vehicles</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-for-connected-and-autonomous-vehicles</guid>
      <pubDate>Sun, 09 Aug 2026 14:34:12 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Device Code Phishing Rose 15x. Checking the URL Does Not Help.]]></title>
      <description><![CDATA[Device code phishing sends victims to a genuine Microsoft page to enter a genuine code. There is no fake domain and no credential to steal. Training built on spotting bad URLs has nothing to use.]]></description>
      <link>https://safeguard.sh/resources/blog/device-code-phishing-the-oauth-flow-you-should-disable</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/device-code-phishing-the-oauth-flow-you-should-disable</guid>
      <pubDate>Sun, 09 Aug 2026 14:00:00 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Python urllib.parse NFKC normalization blocklist bypass (CVE-2023-24329)]]></title>
      <description><![CDATA[CVE-2023-24329 let attackers bypass URL blocklists via leading blank characters in Python's urllib.parse, enabling SSRF and filter evasion.]]></description>
      <link>https://safeguard.sh/resources/blog/python-urllibparse-nfkc-normalization-blocklist-bypass-cve-2023-24329</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-urllibparse-nfkc-normalization-blocklist-bypass-cve-2023-24329</guid>
      <pubDate>Sun, 09 Aug 2026 13:13:46 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[ISO/SAE 21434 compliance for automotive software suppliers]]></title>
      <description><![CDATA[What ISO/SAE 21434 actually requires of automotive software suppliers, why UN R155 makes it mandatory, and how Tier 1s can build compliance into engineering instead of bolting it on.]]></description>
      <link>https://safeguard.sh/resources/blog/isosae-21434-compliance-for-automotive-software-suppliers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/isosae-21434-compliance-for-automotive-software-suppliers</guid>
      <pubDate>Sun, 09 Aug 2026 11:53:19 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[AI Writes Code Faster Than You Can Review It. Which Scanner Do You Point at It?]]></title>
      <description><![CDATA[AI-generated code arrives faster than review can absorb and fails in distinct patterns. SAST, DAST, and reachability each catch part of that — and each misses a specific, predictable slice.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-dast-reachability-triage-for-ai-generated-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-dast-reachability-triage-for-ai-generated-code</guid>
      <pubDate>Sun, 09 Aug 2026 11:30:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Python mailcap insecure shell command construction (CVE-2015-20107)]]></title>
      <description><![CDATA[Python mailcap shell injection (CVE-2015-20107) lets attackers run arbitrary commands via unescaped filenames. Here is how to detect and fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/python-mailcap-insecure-shell-command-construction-cve-2015-20107</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-mailcap-insecure-shell-command-construction-cve-2015-20107</guid>
      <pubDate>Sun, 09 Aug 2026 10:32:52 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[UNECE WP.29 R155 software supply chain requirements for a...]]></title>
      <description><![CDATA[A practical breakdown of UNECE WP.29 R155 compliance: CSMS certification, the SBOM requirement, and type approval cybersecurity rules automakers and suppliers now face.]]></description>
      <link>https://safeguard.sh/resources/blog/unece-wp29-r155-software-supply-chain-requirements-for-automakers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unece-wp29-r155-software-supply-chain-requirements-for-automakers</guid>
      <pubDate>Sun, 09 Aug 2026 09:12:26 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Your DAST Scanner Was Built to Crawl Links. Your Application Doesn't Have Any.]]></title>
      <description><![CDATA[Classic DAST discovers attack surface by following hyperlinks. In an estate of APIs and serverless functions there is nothing to crawl, so the scan completes, reports clean, and covers little.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-in-api-first-architectures-what-crawlers-miss</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-in-api-first-architectures-what-crawlers-miss</guid>
      <pubDate>Sun, 09 Aug 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Python tarfile extraction path traversal, the 15-year-old flaw (CVE-2007-4559)]]></title>
      <description><![CDATA[CVE-2007-4559, a path traversal flaw in Python's tarfile module, still lurks in hundreds of thousands of repos. Here's the impact, timeline, and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/python-tarfile-extraction-path-traversal-the-15-year-old-flaw-cve-2007-4559</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-tarfile-extraction-path-traversal-the-15-year-old-flaw-cve-2007-4559</guid>
      <pubDate>Sun, 09 Aug 2026 07:51:59 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SBOM for automotive ECU firmware and embedded software]]></title>
      <description><![CDATA[How automotive ECU firmware SBOMs help OEMs and suppliers track embedded components, manage vehicle firmware vulnerabilities, and secure OTA updates.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-automotive-ecu-firmware-and-embedded-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-automotive-ecu-firmware-and-embedded-software</guid>
      <pubDate>Sun, 09 Aug 2026 06:31:32 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[ctx and colourama PyPI typosquat malware incident]]></title>
      <description><![CDATA[The ctx and colourama PyPI typosquatting malware incident shows how account takeover and name-squatting delivered credential-stealing code to devs.]]></description>
      <link>https://safeguard.sh/resources/blog/ctx-and-colourama-pypi-typosquat-malware-incident</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ctx-and-colourama-pypi-typosquat-malware-incident</guid>
      <pubDate>Sun, 09 Aug 2026 05:11:06 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Python email module address-parsing confusion (CVE-2023-27043)]]></title>
      <description><![CDATA[CVE-2023-27043 shows how a Python email-parsing quirk lets attackers spoof trusted domains and bypass allowlist-based access controls silently.]]></description>
      <link>https://safeguard.sh/resources/blog/python-email-module-address-parsing-confusion-cve-2023-27043</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-email-module-address-parsing-confusion-cve-2023-27043</guid>
      <pubDate>Sun, 09 Aug 2026 03:50:39 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Python client aggregated API vulnerability (CVE-2022-3172)]]></title>
      <description><![CDATA[CVE-2022-3172 lets a rogue aggregated API backend redirect authenticated Kubernetes API traffic, exposing Python client apps to credential theft.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-python-client-aggregated-api-vulnerability-cve-2022-3172</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-python-client-aggregated-api-vulnerability-cve-2022-3172</guid>
      <pubDate>Sun, 09 Aug 2026 02:30:12 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Django str.format denial of service (CVE-2023-41164)]]></title>
      <description><![CDATA[CVE-2023-41164 lets attackers DoS Django apps via a str.format() flaw in uri_to_iri(). Here's what's affected, severity context, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/django-strformat-denial-of-service-cve-2023-41164</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/django-strformat-denial-of-service-cve-2023-41164</guid>
      <pubDate>Sun, 09 Aug 2026 01:09:46 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Buyer's guide: automotive-grade SBOM and SCA tools]]></title>
      <description><![CDATA[A practical buyer's guide to automotive SBOM and SCA tools: evaluation criteria for ISO 21434 compliance, and an honest roundup of six named vendors.]]></description>
      <link>https://safeguard.sh/resources/blog/buyers-guide-automotive-grade-sbom-and-sca-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buyers-guide-automotive-grade-sbom-and-sca-tools</guid>
      <pubDate>Sat, 08 Aug 2026 23:49:19 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Django admin ChangeList path traversal (CVE-2021-33203)]]></title>
      <description><![CDATA[CVE-2021-33203 is a staff-only path traversal in Django's admindocs TemplateDetailView. Here's what's affected, its CVSS/EPSS profile, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/django-admin-changelist-path-traversal-cve-2021-33203</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/django-admin-changelist-path-traversal-cve-2021-33203</guid>
      <pubDate>Sat, 08 Aug 2026 22:28:52 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Django QuerySet.explain SQL injection (CVE-2022-28346)]]></title>
      <description><![CDATA[A Django ORM flaw let unvalidated input reach EXPLAIN and annotate() SQL generation. Here's the CVE-2022-28347 impact, fix, and defense playbook.]]></description>
      <link>https://safeguard.sh/resources/blog/django-querysetexplain-sql-injection-cve-2022-28346</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/django-querysetexplain-sql-injection-cve-2022-28346</guid>
      <pubDate>Sat, 08 Aug 2026 21:08:25 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CMMC 2.0 software supply chain security requirements for ...]]></title>
      <description><![CDATA[CMMC 2.0 now folds SBOMs, third-party component risk, and build-pipeline integrity into defense contractor assessments. Here's what's required, when, and how to prove it.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-20-software-supply-chain-security-requirements-for-defense-contractors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-20-software-supply-chain-security-requirements-for-defense-contractors</guid>
      <pubDate>Sat, 08 Aug 2026 19:47:59 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Django GIS SQL injection (CVE-2020-9402)]]></title>
      <description><![CDATA[CVE-2020-9402 lets attackers inject SQL via Django GIS's tolerance parameter on Oracle. Versions, CVSS/EPSS data, timeline, and fixes inside.]]></description>
      <link>https://safeguard.sh/resources/blog/django-gis-sql-injection-cve-2020-9402</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/django-gis-sql-injection-cve-2020-9402</guid>
      <pubDate>Sat, 08 Aug 2026 18:27:32 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[NIST 800-171 and software composition analysis for defens...]]></title>
      <description><![CDATA[How NIST 800-171 software composition analysis, DFARS 252.204-7012, and CMMC 2.0 reshape open-source risk management for defense contractors protecting CUI.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-800-171-and-software-composition-analysis-for-defense-contractors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-800-171-and-software-composition-analysis-for-defense-contractors</guid>
      <pubDate>Sat, 08 Aug 2026 17:07:05 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Flask session cookie information disclosure (CVE-2023-30861)]]></title>
      <description><![CDATA[A missing Vary: Cookie header in Flask session handling let shared caches leak one user's session cookie to another. Here's how to detect and fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/flask-session-cookie-information-disclosure-cve-2023-30861</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/flask-session-cookie-information-disclosure-cve-2023-30861</guid>
      <pubDate>Sat, 08 Aug 2026 15:46:39 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The Average Enterprise Runs 900 APIs. It Can List Maybe 600 of Them.]]></title>
      <description><![CDATA[API attacks are climbing steeply and 87% of organisations reported an incident last year. The root cause is not weak authentication — it is that many production endpoints are on nobody's list.]]></description>
      <link>https://safeguard.sh/resources/blog/api-sprawl-900-endpoints-and-the-inventory-problem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-sprawl-900-endpoints-and-the-inventory-problem</guid>
      <pubDate>Sat, 08 Aug 2026 15:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SBOM requirements under DoD software supply chain risk ma...]]></title>
      <description><![CDATA[A practical breakdown of DoD SBOM requirements — where they came from, how Software Fast Track enforces them, and what happens when contractors can't produce one.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-requirements-under-dod-software-supply-chain-risk-management-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-requirements-under-dod-software-supply-chain-risk-management-programs</guid>
      <pubDate>Sat, 08 Aug 2026 14:26:12 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Werkzeug multipart form-data denial of service (CVE-2019-1010083)]]></title>
      <description><![CDATA[CVE-2019-1010083 lets attackers crash Flask apps via crafted multipart form-data. Here's the CVSS score, timeline, and how to fix the Werkzeug DoS flaw.]]></description>
      <link>https://safeguard.sh/resources/blog/werkzeug-multipart-form-data-denial-of-service-cve-2019-1010083</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/werkzeug-multipart-form-data-denial-of-service-cve-2019-1010083</guid>
      <pubDate>Sat, 08 Aug 2026 13:05:45 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Nobody Is Exploiting Your Dependencies. They Are Logging Into Them.]]></title>
      <description><![CDATA[keyv, Mastra, Nx, AsyncAPI, jscrambler. Five of 2026's largest supply chain incidents, and not one involved a software vulnerability. The exploited weakness every time was a maintainer account.]]></description>
      <link>https://safeguard.sh/resources/blog/maintainer-account-takeover-is-the-2026-supply-chain-threat-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maintainer-account-takeover-is-the-2026-supply-chain-threat-model</guid>
      <pubDate>Sat, 08 Aug 2026 12:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Securing avionics software supply chains under DO-178C]]></title>
      <description><![CDATA[DO-178C verifies that avionics code behaves correctly — but says almost nothing about where its components came from. Here's the supply chain gap and how to close it.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-avionics-software-supply-chains-under-do-178c</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-avionics-software-supply-chains-under-do-178c</guid>
      <pubDate>Sat, 08 Aug 2026 11:45:19 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Werkzeug multipart parser DoS (CVE-2023-46136)]]></title>
      <description><![CDATA[A crafted multipart upload could pin Werkzeug workers at 100% CPU with no auth required. Here's what CVE-2023-46136 affects and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/werkzeug-multipart-parser-dos-cve-2023-46136</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/werkzeug-multipart-parser-dos-cve-2023-46136</guid>
      <pubDate>Sat, 08 Aug 2026 10:24:52 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Counterfeit and untrusted component risk in defense softw...]]></title>
      <description><![CDATA[Counterfeit component risk defense software teams face across hardware and code, from gray-market parts to unverified builds, and how illumination catches it.]]></description>
      <link>https://safeguard.sh/resources/blog/counterfeit-and-untrusted-component-risk-in-defense-software-supply-chains</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/counterfeit-and-untrusted-component-risk-in-defense-software-supply-chains</guid>
      <pubDate>Sat, 08 Aug 2026 09:04:25 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[A Year Inside the Installer: QuickFox, FDMTP, and Targeted Supply Chain Patience]]></title>
      <description><![CDATA[The trojanized QuickFox installer ran for roughly a year, fingerprinting each victim before deploying a backdoor. Selective targeting bought the dwell time and broke conventional detection.]]></description>
      <link>https://safeguard.sh/resources/blog/quickfox-fdmtp-trojanized-installer-twelve-month-dwell-time</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/quickfox-fdmtp-trojanized-installer-twelve-month-dwell-time</guid>
      <pubDate>Sat, 08 Aug 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Jinja2 sandbox escape (CVE-2022-29361)]]></title>
      <description><![CDATA[CVE-2022-29361 lets attackers bypass Jinja2's SandboxedEnvironment via str.format, reaching unsafe attributes and risking RCE in untrusted-template apps.]]></description>
      <link>https://safeguard.sh/resources/blog/jinja2-sandbox-escape-cve-2022-29361</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jinja2-sandbox-escape-cve-2022-29361</guid>
      <pubDate>Sat, 08 Aug 2026 07:43:59 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE analysis: nation-state supply chain attacks on defens...]]></title>
      <description><![CDATA[CVE analysis of nation-state supply chain attacks on defense contractors: SolarWinds SUNBURST and Ivanti Connect Secure exploitation, CVSS, KEV, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-analysis-nation-state-supply-chain-attacks-on-defense-contractors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-analysis-nation-state-supply-chain-attacks-on-defense-contractors</guid>
      <pubDate>Sat, 08 Aug 2026 06:23:32 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Jinja2 xmlattr filter XSS (CVE-2024-22195)]]></title>
      <description><![CDATA[CVE-2024-22195 lets attacker-controlled dict keys bypass Jinja2's xmlattr escaping for XSS. Learn affected versions, CVSS/EPSS context, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/jinja2-xmlattr-filter-xss-cve-2024-22195</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jinja2-xmlattr-filter-xss-cve-2024-22195</guid>
      <pubDate>Sat, 08 Aug 2026 05:03:05 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Sentry SDK sensitive data exposure (CVE-2021-23727)]]></title>
      <description><![CDATA[CVE-2021-23727 let sentry-sdk for Python leak OS environment variables into Sentry events, exposing secrets. Here's the impact, timeline, and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/sentry-sdk-sensitive-data-exposure-cve-2021-23727</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sentry-sdk-sensitive-data-exposure-cve-2021-23727</guid>
      <pubDate>Sat, 08 Aug 2026 03:42:38 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Software supply chain security for telecom network infras...]]></title>
      <description><![CDATA[Why telecom network software supply chain security demands continuous SBOMs and vendor risk oversight — from 5G base stations to core networks — and how carriers are closing the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-for-telecom-network-infrastructure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-for-telecom-network-infrastructure</guid>
      <pubDate>Sat, 08 Aug 2026 02:22:12 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Log4j SocketServer unsafe deserialization (CVE-2019-17571)]]></title>
      <description><![CDATA[A deep dive into CVE-2019-17571, the Log4j 1.x SocketServer deserialization flaw enabling remote code execution, with remediation guidance.]]></description>
      <link>https://safeguard.sh/resources/blog/log4j-socketserver-unsafe-deserialization-cve-2019-17571</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4j-socketserver-unsafe-deserialization-cve-2019-17571</guid>
      <pubDate>Sat, 08 Aug 2026 01:01:45 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[5G network function virtualization (NFV) and Open RAN sof...]]></title>
      <description><![CDATA[5G networks now run on open-source-heavy virtualized and Open RAN software stacks. Here's where the real supply chain risk hides, and how to manage it.]]></description>
      <link>https://safeguard.sh/resources/blog/5g-network-function-virtualization-nfv-and-open-ran-software-supply-chain-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/5g-network-function-virtualization-nfv-and-open-ran-software-supply-chain-risk</guid>
      <pubDate>Fri, 07 Aug 2026 23:41:18 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Jackson-databind polymorphic deserialization RCE (CVE-2017-15095)]]></title>
      <description><![CDATA[A critical jackson-databind deserialization vulnerability (CVE-2017-15095) lets unauthenticated attackers achieve RCE via HikariCP gadget classes.]]></description>
      <link>https://safeguard.sh/resources/blog/jackson-databind-polymorphic-deserialization-rce-cve-2017-15095</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jackson-databind-polymorphic-deserialization-rce-cve-2017-15095</guid>
      <pubDate>Fri, 07 Aug 2026 22:20:52 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[FCC and CISA guidance on telecom software supply chain se...]]></title>
      <description><![CDATA[FCC telecom software supply chain guidance now overlaps with the Covered List and CISA telecom advisories. Here's what carriers must actually track.]]></description>
      <link>https://safeguard.sh/resources/blog/fcc-and-cisa-guidance-on-telecom-software-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fcc-and-cisa-guidance-on-telecom-software-supply-chain-security</guid>
      <pubDate>Fri, 07 Aug 2026 21:00:25 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Jackson-databind gadget chain RCE (CVE-2019-12384)]]></title>
      <description><![CDATA[CVE-2019-12384 lets attacker-controlled JSON trigger a jackson-databind gadget chain via Logback, turning polymorphic deserialization into remote code execution.]]></description>
      <link>https://safeguard.sh/resources/blog/jackson-databind-gadget-chain-rce-cve-2019-12384</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jackson-databind-gadget-chain-rce-cve-2019-12384</guid>
      <pubDate>Fri, 07 Aug 2026 19:39:58 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to manage open source risk in telecom OSS/BSS softwar...]]></title>
      <description><![CDATA[A practical guide to managing telecom OSS/BSS open source risk—from SBOM inventory to dependency scanning—so carrier billing and network software stays secure.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-manage-open-source-risk-in-telecom-ossbss-software-stacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-manage-open-source-risk-in-telecom-ossbss-software-stacks</guid>
      <pubDate>Fri, 07 Aug 2026 18:19:32 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Jackson-databind RCE via JDOM gadget (CVE-2020-36189)]]></title>
      <description><![CDATA[CVE-2020-36189 lets attackers chain jackson-databind polymorphic deserialization with a JDOM gadget for RCE, SSRF, or XXE. Here's the mechanics and the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/jackson-databind-rce-via-jdom-gadget-cve-2020-36189</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jackson-databind-rce-via-jdom-gadget-cve-2020-36189</guid>
      <pubDate>Fri, 07 Aug 2026 16:59:05 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[npm Classic Tokens Are Gone. The keyv Worm Shows Why That Mattered.]]></title>
      <description><![CDATA[Every npm classic token has been permanently revoked — unrecoverable, unrecreatable. Teams treated it as a chore. Then a worm propagated across 444 packages on exactly that kind of credential.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-classic-tokens-revoked-migration-reality-check</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-classic-tokens-revoked-migration-reality-check</guid>
      <pubDate>Fri, 07 Aug 2026 16:30:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Third-party risk management for telecom equipment vendors]]></title>
      <description><![CDATA[A practical playbook for vetting telecom equipment vendors: supply chain checks, hardware/software audits, and procurement security controls.]]></description>
      <link>https://safeguard.sh/resources/blog/third-party-risk-management-for-telecom-equipment-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/third-party-risk-management-for-telecom-equipment-vendors</guid>
      <pubDate>Fri, 07 Aug 2026 15:38:38 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[dom4j XML external entity vulnerability (CVE-2018-1000632)]]></title>
      <description><![CDATA[CVE-2018-1000632, the dom4j XXE vulnerability, let attackers inject and tamper with XML via unescaped addElement/addAttribute calls. Here's the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/dom4j-xml-external-entity-vulnerability-cve-2018-1000632</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dom4j-xml-external-entity-vulnerability-cve-2018-1000632</guid>
      <pubDate>Fri, 07 Aug 2026 14:18:12 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[You Cannot Defend an MCP Server You Do Not Know You Are Running]]></title>
      <description><![CDATA[Tool poisoning is the most impactful client-side MCP vulnerability, and the defensive research is solid. All of it assumes you know which MCP servers you connect to. Almost nobody does.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-inventory-prerequisite-for-tool-poisoning-defence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-inventory-prerequisite-for-tool-poisoning-defence</guid>
      <pubDate>Fri, 07 Aug 2026 14:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE analysis: vulnerabilities in Open RAN and 5G core net...]]></title>
      <description><![CDATA[An open RAN 5G core CVE analysis of the 5Ghoul modem flaws: affected components, CVSS/EPSS/KEV context, disclosure timeline, and practical remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-analysis-vulnerabilities-in-open-ran-and-5g-core-network-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-analysis-vulnerabilities-in-open-ran-and-5g-core-network-software</guid>
      <pubDate>Fri, 07 Aug 2026 12:57:45 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Apache Commons FileUpload RCE (CVE-2016-1000031)]]></title>
      <description><![CDATA[CVE-2016-1000031 is a critical Apache Commons FileUpload deserialization RCE that still lurks in transitive Java dependencies years after its fix.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-commons-fileupload-rce-cve-2016-1000031</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-commons-fileupload-rce-cve-2016-1000031</guid>
      <pubDate>Fri, 07 Aug 2026 11:37:18 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Every AI Coding Tool Has the Same Vulnerability, and It Isn't a Bug]]></title>
      <description><![CDATA[Sandbox escapes in Claude Code, critical CVEs in Cursor, a 10.0 in Gemini CLI, prompt injection in Copilot. Different vendors, one shared cause: the agent must hold elevated access to be useful.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-coding-tool-cves-2026-elevated-access-is-the-root-cause</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-coding-tool-cves-2026-elevated-access-is-the-root-cause</guid>
      <pubDate>Fri, 07 Aug 2026 11:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to vet open source software before deployment in tele...]]></title>
      <description><![CDATA[A seven-step process for vetting open source telecom core network components — SBOMs, signature verification, protocol fuzzing, and procurement sign-off — before they reach production.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-vet-open-source-software-before-deployment-in-telecom-core-networks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-vet-open-source-software-before-deployment-in-telecom-core-networks</guid>
      <pubDate>Fri, 07 Aug 2026 10:16:51 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[2,130 AI-Related CVEs and Counting: The Surge Is Structural, Not a Blip]]></title>
      <description><![CDATA[AI-related CVEs rose 34.6% year over year and more than 200% since 2023. The interesting question is what kind of vulnerabilities they are — because most of them are not model flaws at all.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-related-cve-surge-2130-in-2025-what-it-changes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-related-cve-surge-2130-in-2025-what-it-changes</guid>
      <pubDate>Fri, 07 Aug 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[H2 database console remote code execution (CVE-2021-42392)]]></title>
      <description><![CDATA[CVE-2021-42392 lets attackers trigger RCE in H2's console and JDBC URL handling via a Log4Shell-style JNDI gadget. Here's what's affected and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/h2-database-console-remote-code-execution-cve-2021-42392</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/h2-database-console-remote-code-execution-cve-2021-42392</guid>
      <pubDate>Fri, 07 Aug 2026 08:56:25 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Software supply chain security for e-commerce platforms]]></title>
      <description><![CDATA[Real breaches show how plugins, vendor scripts, and headless stacks put online stores at risk — and how to detect supply chain attacks before customers do.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-for-e-commerce-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-for-e-commerce-platforms</guid>
      <pubDate>Fri, 07 Aug 2026 07:35:58 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Spring Cloud Function SpEL injection RCE (CVE-2022-22963)]]></title>
      <description><![CDATA[CVE-2022-22963 lets attackers RCE unpatched Spring Cloud Function apps via one SpEL header. CVSS 9.8. Here's the fix, fast.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-cloud-function-spel-injection-rce-cve-2022-22963</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-cloud-function-spel-injection-rce-cve-2022-22963</guid>
      <pubDate>Fri, 07 Aug 2026 06:15:31 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[PCI DSS 4.0 requirement 6.4.3 for e-commerce third-party ...]]></title>
      <description><![CDATA[PCI DSS 4.0 now mandates strict controls over third-party JavaScript on payment pages. Here's what requirements 6.4.3 and 11.6.1 require and how to comply.]]></description>
      <link>https://safeguard.sh/resources/blog/pci-dss-40-requirement-643-for-e-commerce-third-party-javascript</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pci-dss-40-requirement-643-for-e-commerce-third-party-javascript</guid>
      <pubDate>Fri, 07 Aug 2026 04:55:05 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Spring Cloud Gateway actuator RCE (CVE-2022-22947)]]></title>
      <description><![CDATA[A critical SpEL injection flaw in Spring Cloud Gateway's actuator API let unauthenticated attackers run code. Here's the impact, timeline, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-cloud-gateway-actuator-rce-cve-2022-22947</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-cloud-gateway-actuator-rce-cve-2022-22947</guid>
      <pubDate>Fri, 07 Aug 2026 03:34:38 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Securing the retail point-of-sale (POS) software supply c...]]></title>
      <description><![CDATA[BlackPOS hit 40M Target cards in 2013. See how retail POS software supply chain security stops firmware tampering, malware, and vendor risk today.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-the-retail-point-of-sale-pos-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-the-retail-point-of-sale-pos-software-supply-chain</guid>
      <pubDate>Fri, 07 Aug 2026 02:14:11 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Apache Shiro remember-me cookie deserialization RCE (CVE-2016-4437)]]></title>
      <description><![CDATA[Apache Shiro's default rememberMe cipher key enables unauthenticated Java deserialization RCE. Here's how CVE-2016-4437 works and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-shiro-remember-me-cookie-deserialization-rce-cve-2016-4437</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-shiro-remember-me-cookie-deserialization-rce-cve-2016-4437</guid>
      <pubDate>Fri, 07 Aug 2026 00:53:45 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Open source dependency risk in e-commerce platforms (Mage...]]></title>
      <description><![CDATA[A practical guide to finding and fixing e-commerce platform dependency risk across Magento plugins, WooCommerce extensions, and Shopify apps before attackers do.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-dependency-risk-in-e-commerce-platforms-magento-woocommerce-shopify-apps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-dependency-risk-in-e-commerce-platforms-magento-woocommerce-shopify-apps</guid>
      <pubDate>Thu, 06 Aug 2026 23:33:18 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Jetty SSL buffer bloat denial of service (CVE-2021-28165)]]></title>
      <description><![CDATA[CVE-2021-28165 lets attackers exhaust Jetty server memory via SSL buffer bloat, causing denial of service. Affected versions, timeline, and fixes inside.]]></description>
      <link>https://safeguard.sh/resources/blog/jetty-ssl-buffer-bloat-denial-of-service-cve-2021-28165</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jetty-ssl-buffer-bloat-denial-of-service-cve-2021-28165</guid>
      <pubDate>Thu, 06 Aug 2026 22:12:51 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Third-party risk management for retail supply chain and l...]]></title>
      <description><![CDATA[A practical, step-by-step framework for assessing and monitoring retail logistics software vendor risk, from SaaS onboarding to inventory system offboarding.]]></description>
      <link>https://safeguard.sh/resources/blog/third-party-risk-management-for-retail-supply-chain-and-logistics-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/third-party-risk-management-for-retail-supply-chain-and-logistics-software</guid>
      <pubDate>Thu, 06 Aug 2026 20:52:24 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Spring Security authorization rule bypass (CVE-2023-34035)]]></title>
      <description><![CDATA[CVE-2023-34035 lets Spring Security's requestMatchers() silently mis-evaluate authorization rules in multi-servlet apps. Here's the fix and how to detect exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-security-authorization-rule-bypass-cve-2023-34035</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-security-authorization-rule-bypass-cve-2023-34035</guid>
      <pubDate>Thu, 06 Aug 2026 19:31:58 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CVE analysis: Magecart and e-commerce JavaScript supply c...]]></title>
      <description><![CDATA[A Magecart supply chain attack analysis of the CVEs and exploit chains behind skimmer campaigns on Adobe Commerce and Magento, plus how to defend checkout pages.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-analysis-magecart-and-e-commerce-javascript-supply-chain-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-analysis-magecart-and-e-commerce-javascript-supply-chain-attacks</guid>
      <pubDate>Thu, 06 Aug 2026 18:11:31 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Homomorphic Encryption in Software Supply Chains]]></title>
      <description><![CDATA[A grounded look at BFV, CKKS, and TFHE schemes for supply chain workloads, measured costs, library choices, and where HE is not yet practical.]]></description>
      <link>https://safeguard.sh/resources/blog/homomorphic-encryption-software-supply-chain-use</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/homomorphic-encryption-software-supply-chain-use</guid>
      <pubDate>Thu, 06 Aug 2026 16:51:04 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Spring Security OAuth2 client vulnerability (CVE-2022-31690)]]></title>
      <description><![CDATA[CVE-2022-31690 in Spring Security's OAuth2 client can let one principal obtain another's token. Here's the impact, CVSS/EPSS context, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-security-oauth2-client-vulnerability-cve-2022-31690</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-security-oauth2-client-vulnerability-cve-2022-31690</guid>
      <pubDate>Thu, 06 Aug 2026 15:30:38 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Your 30-Day Patch SLA Meets a 48-Hour Exploitation Window]]></title>
      <description><![CDATA[88% of exploitation against vulnerabilities with a public PoC now happens within 48 hours. No organisation patches everything that fast. The fix is a smaller fast lane, selected automatically.]]></description>
      <link>https://safeguard.sh/resources/blog/patch-sla-design-for-48-hour-exploitation-windows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/patch-sla-design-for-48-hour-exploitation-windows</guid>
      <pubDate>Thu, 06 Aug 2026 15:30:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[10 Predictions for Software Supply Chain Security in 2026]]></title>
      <description><![CDATA[From AI-generated SBOMs to regulatory enforcement and the death of CVSS-only triage, here is what the software security landscape will look like in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/predictions-software-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/predictions-software-security-2026</guid>
      <pubDate>Thu, 06 Aug 2026 14:10:11 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Buyer's guide: application security tools for retail and ...]]></title>
      <description><![CDATA[A practical, no-fluff comparison of application security tools for retail e-commerce, covering PCI compliance, SCA, and vendor tradeoffs.]]></description>
      <link>https://safeguard.sh/resources/blog/buyers-guide-application-security-tools-for-retail-and-e-commerce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buyers-guide-application-security-tools-for-retail-and-e-commerce</guid>
      <pubDate>Thu, 06 Aug 2026 12:49:44 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Five Numbers From the CrowdStrike 2026 Threat Hunting Report That Should Change Your Roadmap]]></title>
      <description><![CDATA[87% of software registry threats were malicious npm packages. 88% of exploitation with a public PoC happened inside 48 hours. Device code phishing rose 15x. Five numbers, five pieces of work.]]></description>
      <link>https://safeguard.sh/resources/blog/crowdstrike-2026-threat-hunting-report-appsec-takeaways</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crowdstrike-2026-threat-hunting-report-appsec-takeaways</guid>
      <pubDate>Thu, 06 Aug 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software supply chain security for critical energy infras...]]></title>
      <description><![CDATA[From Ukraine's 2015 blackout to Volt Typhoon's grid intrusions, attackers exploit trusted vendor software. Here's what utilities need to know about supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-for-critical-energy-infrastructure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-for-critical-energy-infrastructure</guid>
      <pubDate>Thu, 06 Aug 2026 11:29:18 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Apache Solr XXE remote code execution (CVE-2017-12629)]]></title>
      <description><![CDATA[CVE-2017-12629 chains XXE and Solr's RunExecutableListener into unauthenticated RCE. Affected versions, timeline, and concrete remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-solr-xxe-remote-code-execution-cve-2017-12629</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-solr-xxe-remote-code-execution-cve-2017-12629</guid>
      <pubDate>Thu, 06 Aug 2026 10:08:51 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Bring Your Own Runtime: Why the keyv Payload Downloaded Bun]]></title>
      <description><![CDATA[The August 2026 npm worm did not run its second stage in Node. It downloaded a standalone Bun binary first — a choice that defeats a surprising amount of build-pipeline monitoring.]]></description>
      <link>https://safeguard.sh/resources/blog/bring-your-own-runtime-bun-dropper-supply-chain-evasion</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bring-your-own-runtime-bun-dropper-supply-chain-evasion</guid>
      <pubDate>Thu, 06 Aug 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[NERC CIP-013 compliance and software supply chain risk ma...]]></title>
      <description><![CDATA[NERC CIP-013 turned vendor risk management into a mandatory grid compliance obligation. Here's what it requires, who it covers, and how to build an audit-ready supply chain plan.]]></description>
      <link>https://safeguard.sh/resources/blog/nerc-cip-013-compliance-and-software-supply-chain-risk-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nerc-cip-013-compliance-and-software-supply-chain-risk-management</guid>
      <pubDate>Thu, 06 Aug 2026 08:48:24 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[SBOM requirements for industrial control systems (ICS/SCADA)]]></title>
      <description><![CDATA[ICS/SCADA SBOM requirements are colliding with 20-year-old control systems that predate software transparency mandates. Here's what's required, why, and how to close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-requirements-for-industrial-control-systems-icsscada</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-requirements-for-industrial-control-systems-icsscada</guid>
      <pubDate>Thu, 06 Aug 2026 07:27:58 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Securing smart grid and advanced metering infrastructure ...]]></title>
      <description><![CDATA[How AMI firmware, smart meters, and grid modernization projects create software supply chain risk for utilities — and what closing that gap actually requires.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-smart-grid-and-advanced-metering-infrastructure-ami-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-smart-grid-and-advanced-metering-infrastructure-ami-software</guid>
      <pubDate>Thu, 06 Aug 2026 06:07:31 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Third-party risk management for OT/ICS vendors in utilities]]></title>
      <description><![CDATA[A step-by-step guide to OT ICS vendor risk management for utilities: assessing, auditing, and monitoring SCADA and industrial control system vendors.]]></description>
      <link>https://safeguard.sh/resources/blog/third-party-risk-management-for-otics-vendors-in-utilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/third-party-risk-management-for-otics-vendors-in-utilities</guid>
      <pubDate>Thu, 06 Aug 2026 04:47:04 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[CVE analysis: vulnerabilities in SCADA and industrial con...]]></title>
      <description><![CDATA[A SCADA industrial control CVE analysis of CVE-2018-8872, the Triconex Tricon flaw behind the TRITON safety-system attack — affected versions, CVSS context, timeline, and remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-analysis-vulnerabilities-in-scada-and-industrial-control-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-analysis-vulnerabilities-in-scada-and-industrial-control-software</guid>
      <pubDate>Thu, 06 Aug 2026 03:26:37 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[TSA pipeline cybersecurity directive and software supply ...]]></title>
      <description><![CDATA[A breakdown of TSA's pipeline cybersecurity directives and the software supply chain requirements they impose on operators and oil and gas vendors alike.]]></description>
      <link>https://safeguard.sh/resources/blog/tsa-pipeline-cybersecurity-directive-and-software-supply-chain-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tsa-pipeline-cybersecurity-directive-and-software-supply-chain-requirements</guid>
      <pubDate>Thu, 06 Aug 2026 02:06:11 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Compliance in 2025: Tracking Global Mandates and Deadlines]]></title>
      <description><![CDATA[SBOM requirements are now embedded in regulations across the US, EU, Japan, and beyond. A practical tracker of what is required, by whom, and by when.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-compliance-global-mandate-tracker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-compliance-global-mandate-tracker</guid>
      <pubDate>Thu, 06 Aug 2026 00:45:44 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What agentic AI security means and why traditional AppSec...]]></title>
      <description><![CDATA[Traditional AppSec was built for static code, not decision-making agents. Here's what agentic AI security actually covers—and why autonomous agents need a new defense model.]]></description>
      <link>https://safeguard.sh/resources/blog/what-agentic-ai-security-means-and-why-traditional-appsec-doesnt-cover-autonomous-agents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-agentic-ai-security-means-and-why-traditional-appsec-doesnt-cover-autonomous-agents</guid>
      <pubDate>Wed, 05 Aug 2026 23:25:17 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Identity and access management for non-human AI agents]]></title>
      <description><![CDATA[AI agents now hold production credentials the way employees do, except most are never offboarded. Here's how AI agent identity and access management closes that gap.]]></description>
      <link>https://safeguard.sh/resources/blog/identity-and-access-management-for-non-human-ai-agents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/identity-and-access-management-for-non-human-ai-agents</guid>
      <pubDate>Wed, 05 Aug 2026 22:04:51 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to authorize and scope permissions for autonomous AI ...]]></title>
      <description><![CDATA[A practical, step-by-step guide to AI agent authorization: scoping permissions, using OAuth for machine identities, and verifying least-privilege boundaries hold in production.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-authorize-and-scope-permissions-for-autonomous-ai-agents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-authorize-and-scope-permissions-for-autonomous-ai-agents</guid>
      <pubDate>Wed, 05 Aug 2026 20:44:24 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Security risks of multi-agent AI systems collaborating au...]]></title>
      <description><![CDATA[Multi-agent AI systems introduce security risks classic AppSec misses: agent-to-agent exploits, swarm failures, and orchestration trust gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/security-risks-of-multi-agent-ai-systems-collaborating-autonomously</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-risks-of-multi-agent-ai-systems-collaborating-autonomously</guid>
      <pubDate>Wed, 05 Aug 2026 19:23:57 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Security implications of AI browser agents that click, br...]]></title>
      <description><![CDATA[AI browser agents click, browse, and pay with your credentials -- and prompt injection attacks like EchoLeak and CometJacking prove they can be hijacked to do it.]]></description>
      <link>https://safeguard.sh/resources/blog/security-implications-of-ai-browser-agents-that-click-browse-and-transact</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-implications-of-ai-browser-agents-that-click-browse-and-transact</guid>
      <pubDate>Wed, 05 Aug 2026 18:03:31 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Securing computer-use AI agents that operate desktops and...]]></title>
      <description><![CDATA[Computer-use AI agents can click, type, and log into any app on your desktop. Here is how computer use AI agent security actually works in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-computer-use-ai-agents-that-operate-desktops-and-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-computer-use-ai-agents-that-operate-desktops-and-applications</guid>
      <pubDate>Wed, 05 Aug 2026 16:43:04 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[npm 12 Turned Install Scripts Off. The keyv Worm Used a preinstall Hook Anyway.]]></title>
      <description><![CDATA[Install scripts have been off by default since npm 12 shipped in July 2026. Four weeks later a worm propagated through preinstall hooks. A default is not a control until you prove it is enforced.]]></description>
      <link>https://safeguard.sh/resources/blog/preinstall-hooks-still-fire-npm-12-defaults-versus-reality</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preinstall-hooks-still-fire-npm-12-defaults-versus-reality</guid>
      <pubDate>Wed, 05 Aug 2026 16:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Zero trust architecture patterns adapted for AI agent wor...]]></title>
      <description><![CDATA[How zero trust AI agents, agent network segmentation, and continuous verification close the gaps that let one poisoned tool call turn an autonomous agent into a supply chain attack.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-trust-architecture-patterns-adapted-for-ai-agent-workloads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-trust-architecture-patterns-adapted-for-ai-agent-workloads</guid>
      <pubDate>Wed, 05 Aug 2026 15:22:37 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Explaining Model Context Protocol and its expanding attac...]]></title>
      <description><![CDATA[MCP security is now urgent: MCP servers grew from 700 to 16,000+ in a year, and most are unaudited. Here is the threat model and how Safeguard secures it.]]></description>
      <link>https://safeguard.sh/resources/blog/explaining-model-context-protocol-and-its-expanding-attack-surface</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/explaining-model-context-protocol-and-its-expanding-attack-surface</guid>
      <pubDate>Wed, 05 Aug 2026 14:02:11 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-34486: When the Encryption You Configured Doesn't Apply]]></title>
      <description><![CDATA[Apache Tomcat's EncryptInterceptor exists to encrypt cluster replication traffic. CVE-2026-34486 lets that protection be bypassed — the config says encrypted, the wire says otherwise.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-tomcat-cve-2026-34486-encryptinterceptor-bypass-cluster-traffic</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-tomcat-cve-2026-34486-encryptinterceptor-bypass-cluster-traffic</guid>
      <pubDate>Wed, 05 Aug 2026 13:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm CLI Login in CI: Tokens, npm-cli-login, and Safer Patterns]]></title>
      <description><![CDATA[The npm-cli-login package automated interactive npm login for CI pipelines — a pattern that npm's 2025 authentication overhaul has made both broken and unnecessary. Here is what to use instead.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-cli-login-ci-authentication</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-cli-login-ci-authentication</guid>
      <pubDate>Wed, 05 Aug 2026 12:41:44 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Terraform Module Supply Chain Security]]></title>
      <description><![CDATA[The dependency lockfile everyone commits only covers providers — your modules float free. Pinning, provenance, and the code-execution paths hiding inside terraform plan.]]></description>
      <link>https://safeguard.sh/resources/blog/terraform-module-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/terraform-module-supply-chain-security</guid>
      <pubDate>Wed, 05 Aug 2026 11:21:17 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Jonas Meyer)</author>
    </item>
    <item>
      <title><![CDATA[Analysis of known MCP server CVEs and disclosed vulnerabi...]]></title>
      <description><![CDATA[Two critical CVEs — in mcp-remote and Anthropic's MCP Inspector — reveal how MCP server vulnerabilities let untrusted servers execute code on client machines.]]></description>
      <link>https://safeguard.sh/resources/blog/analysis-of-known-mcp-server-cves-and-disclosed-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/analysis-of-known-mcp-server-cves-and-disclosed-vulnerabilities</guid>
      <pubDate>Wed, 05 Aug 2026 10:00:50 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[A CVSS 5.3 That Cisco Rated High: Static Credentials in Firewall Management Center]]></title>
      <description><![CDATA[CVE-2026-20316 scores 5.3. Cisco rated its security impact High anyway, and CISA added it to the KEV catalogue. On a firewall management appliance, the base score measures the wrong thing.]]></description>
      <link>https://safeguard.sh/resources/blog/cisco-fmc-cve-2026-20316-static-credentials-cvss-understates-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisco-fmc-cve-2026-20316-static-credentials-cvss-understates-risk</guid>
      <pubDate>Wed, 05 Aug 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How tool poisoning attacks compromise MCP tool descriptions]]></title>
      <description><![CDATA[A single poisoned tool description can turn a trusted MCP server into a silent data-exfiltration channel. Here's how these attacks work — and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/how-tool-poisoning-attacks-compromise-mcp-tool-descriptions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-tool-poisoning-attacks-compromise-mcp-tool-descriptions</guid>
      <pubDate>Wed, 05 Aug 2026 08:40:24 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Step-by-step guide to hardening and securing an MCP serve...]]></title>
      <description><![CDATA[A practical, step-by-step guide to hardening and securing an MCP server deployment -- authentication, sandboxing, network policy, and monitoring included.]]></description>
      <link>https://safeguard.sh/resources/blog/step-by-step-guide-to-hardening-and-securing-an-mcp-server-deployment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/step-by-step-guide-to-hardening-and-securing-an-mcp-server-deployment</guid>
      <pubDate>Wed, 05 Aug 2026 07:19:57 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[OAuth and authentication patterns for Model Context Proto...]]></title>
      <description><![CDATA[MCP OAuth authentication has been rewritten three times since March 2025. Here's how the spec, its token security model, and real CVEs like CVE-2025-49596 shape safe MCP deployments.]]></description>
      <link>https://safeguard.sh/resources/blog/oauth-and-authentication-patterns-for-model-context-protocol-implementations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oauth-and-authentication-patterns-for-model-context-protocol-implementations</guid>
      <pubDate>Wed, 05 Aug 2026 05:59:30 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Risks of MCP server rug-pulls and silently changing tool ...]]></title>
      <description><![CDATA[An MCP rug pull attack swaps a trusted server's tool definitions after approval. Here's how tool definition drift happens, and how Safeguard catches it early.]]></description>
      <link>https://safeguard.sh/resources/blog/risks-of-mcp-server-rug-pulls-and-silently-changing-tool-behavior</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/risks-of-mcp-server-rug-pulls-and-silently-changing-tool-behavior</guid>
      <pubDate>Wed, 05 Aug 2026 04:39:04 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Comparing MCP security scanning and gateway products]]></title>
      <description><![CDATA[A practical buyer's guide to MCP security gateways and scanners — evaluation criteria, honest strengths and gaps for real vendors, and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/comparing-mcp-security-scanning-and-gateway-products</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/comparing-mcp-security-scanning-and-gateway-products</guid>
      <pubDate>Wed, 05 Aug 2026 03:18:37 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Glossary of Model Context Protocol security terminology]]></title>
      <description><![CDATA[A precise MCP security glossary covering clients, servers, resources vs. tools, tool poisoning, rug pulls, and the confused deputy problem — with real-world examples.]]></description>
      <link>https://safeguard.sh/resources/blog/glossary-of-model-context-protocol-security-terminology</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/glossary-of-model-context-protocol-security-terminology</guid>
      <pubDate>Wed, 05 Aug 2026 01:58:10 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Overview of AI model supply chain security risks end to end]]></title>
      <description><![CDATA[A concrete, incident-driven walkthrough of AI supply chain security — from poisoned datasets and backdoored Hugging Face models to CI pipeline hijacks — and how to reduce the risk end to end.]]></description>
      <link>https://safeguard.sh/resources/blog/overview-of-ai-model-supply-chain-security-risks-end-to-end</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/overview-of-ai-model-supply-chain-security-risks-end-to-end</guid>
      <pubDate>Wed, 05 Aug 2026 00:37:44 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Why training data provenance matters for trustworthy AI m...]]></title>
      <description><![CDATA[Poisoned datasets and untraceable training data are already causing lawsuits and breaches. Here's why training data provenance is now a security requirement.]]></description>
      <link>https://safeguard.sh/resources/blog/why-training-data-provenance-matters-for-trustworthy-ai-models</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-training-data-provenance-matters-for-trustworthy-ai-models</guid>
      <pubDate>Tue, 04 Aug 2026 23:17:17 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Techniques for verifying model weight integrity and detec...]]></title>
      <description><![CDATA[A practical guide to model weight integrity: baseline checksums, sign weights, verify in CI/CD, and detect tampering before it reaches production.]]></description>
      <link>https://safeguard.sh/resources/blog/techniques-for-verifying-model-weight-integrity-and-detecting-tampering</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/techniques-for-verifying-model-weight-integrity-and-detecting-tampering</guid>
      <pubDate>Tue, 04 Aug 2026 21:56:50 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Securing the fine-tuning pipeline against injected malici...]]></title>
      <description><![CDATA[Fine-tuning pipeline security is now an AI supply chain priority: as few as 250 poisoned documents can backdoor a model, and LoRA adapters make it easy to hide.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-the-fine-tuning-pipeline-against-injected-malicious-data</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-the-fine-tuning-pipeline-against-injected-malicious-data</guid>
      <pubDate>Tue, 04 Aug 2026 20:36:24 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How data poisoning attacks corrupt LLM behavior during tr...]]></title>
      <description><![CDATA[A single expired domain and $60 can poison a training set. Here's how data poisoning attacks corrupt LLM behavior — and how Safeguard verifies training data before it ships.]]></description>
      <link>https://safeguard.sh/resources/blog/how-data-poisoning-attacks-corrupt-llm-behavior-during-training</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-data-poisoning-attacks-corrupt-llm-behavior-during-training</guid>
      <pubDate>Tue, 04 Aug 2026 19:15:57 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[GPT-5.2 System Card Update: What Changed Since August]]></title>
      <description><![CDATA[OpenAI shipped the GPT-5.2 update to the GPT-5 system card on December 11, 2025. We dig into the preparedness scoring, the cybersecurity capability claims, and what changed for downstream defenders.]]></description>
      <link>https://safeguard.sh/resources/blog/gpt-5-2-system-card-update-december-2025-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gpt-5-2-system-card-update-december-2025-analysis</guid>
      <pubDate>Tue, 04 Aug 2026 17:55:30 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CycloneDX 1.7 Ratified as ECMA-424 2nd Edition (December 2025)]]></title>
      <description><![CDATA[CycloneDX v1.7 was adopted as ECMA-424, 2nd Edition by the Ecma General Assembly in December 2025. We unpack citations, cryptographic assets, and distribution constraints.]]></description>
      <link>https://safeguard.sh/resources/blog/cyclonedx-1-7-ecma-424-second-edition-ratification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyclonedx-1-7-ecma-424-second-edition-ratification</guid>
      <pubDate>Tue, 04 Aug 2026 16:35:03 GMT</pubDate>
      <category>Standards</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The 2025 Software Supply Chain Security Report: Summary]]></title>
      <description><![CDATA[The 2025 annual SSCS report lands into a changed landscape. Key findings, trend lines, and what the numbers actually imply for 2026 planning.]]></description>
      <link>https://safeguard.sh/resources/blog/annual-sscs-report-summary-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/annual-sscs-report-summary-2025</guid>
      <pubDate>Tue, 04 Aug 2026 15:14:37 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AI Tool Confused-Deputy: A Deep Dive]]></title>
      <description><![CDATA[The confused deputy problem takes on new and subtle forms when AI agents invoke tools on behalf of users. A technical deep dive with concrete mitigations.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-tool-confused-deputy-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-tool-confused-deputy-deep-dive</guid>
      <pubDate>Tue, 04 Aug 2026 13:54:10 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security in 2025: The Year in Review]]></title>
      <description><![CDATA[From the CVE program funding crisis to the rise of AI-targeted supply chain attacks, 2025 reshaped the software security landscape. A comprehensive look at the year's defining events and trends.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-2025-year-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-2025-year-review</guid>
      <pubDate>Tue, 04 Aug 2026 12:33:43 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Docker symlink race condition escape (CVE-2018-15664)]]></title>
      <description><![CDATA[A TOCTOU race in Docker's docker cp symlink resolution let malicious containers write to host files as root. Impact, CVSS, and fixes inside.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-symlink-race-condition-escape-cve-2018-15664</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-symlink-race-condition-escape-cve-2018-15664</guid>
      <pubDate>Tue, 04 Aug 2026 11:13:17 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Understanding model poisoning and backdoored model weights]]></title>
      <description><![CDATA[A poisoned model looks like any other checkpoint file. Here's how model poisoning attacks work, real incidents on Hugging Face, and how detection and provenance checks catch them.]]></description>
      <link>https://safeguard.sh/resources/blog/understanding-model-poisoning-and-backdoored-model-weights</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/understanding-model-poisoning-and-backdoored-model-weights</guid>
      <pubDate>Tue, 04 Aug 2026 09:52:50 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Docker Engine crafted image denial of service (CVE-2021-21285)]]></title>
      <description><![CDATA[CVE-2021-21285 lets a crafted container image crash Docker Engine before 20.10.3. Affected versions, severity, timeline, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-engine-crafted-image-denial-of-service-cve-2021-21285</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-engine-crafted-image-denial-of-service-cve-2021-21285</guid>
      <pubDate>Tue, 04 Aug 2026 08:32:23 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[What an AI Bill of Materials is and why enterprises need one]]></title>
      <description><![CDATA[An AI bill of materials (AIBOM) inventories the models, data, and dependencies behind an AI system. Here's what it is and why enterprises need one.]]></description>
      <link>https://safeguard.sh/resources/blog/what-an-ai-bill-of-materials-is-and-why-enterprises-need-one</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-an-ai-bill-of-materials-is-and-why-enterprises-need-one</guid>
      <pubDate>Tue, 04 Aug 2026 07:11:57 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Docker Engine remap-root UID mapping vulnerability (CVE-2021-21284)]]></title>
      <description><![CDATA[CVE-2021-21284 let remapped-root containers escalate to real host root, defeating Docker's userns-remap isolation. Here's the full breakdown and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-engine-remap-root-uid-mapping-vulnerability-cve-2021-21284</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-engine-remap-root-uid-mapping-vulnerability-cve-2021-21284</guid>
      <pubDate>Tue, 04 Aug 2026 05:51:30 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Risks of downloading malicious pretrained models from pub...]]></title>
      <description><![CDATA[Real incidents show malicious Hugging Face models evading scanners with pickle exploits and reverse shells. Here's what teams need to know before the next pull.]]></description>
      <link>https://safeguard.sh/resources/blog/risks-of-downloading-malicious-pretrained-models-from-public-hubs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/risks-of-downloading-malicious-pretrained-models-from-public-hubs</guid>
      <pubDate>Tue, 04 Aug 2026 04:31:03 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[What is prototype pollution and why it keeps recurring in npm packages]]></title>
      <description><![CDATA[Prototype pollution has hit lodash, jQuery, minimist, hoek, and immer since 2018. Here's how the bug works and why it keeps coming back in npm.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-prototype-pollution-and-why-it-keeps-recurring-in-npm-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-prototype-pollution-and-why-it-keeps-recurring-in-npm-packages</guid>
      <pubDate>Tue, 04 Aug 2026 03:10:37 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Analysis of pickle file deserialization vulnerabilities i...]]></title>
      <description><![CDATA[CVE-2025-32434 shows PyTorch's "safe" weights_only loading could still be bypassed for code execution — a pickle deserialization vulnerability with real supply-chain consequences.]]></description>
      <link>https://safeguard.sh/resources/blog/analysis-of-pickle-file-deserialization-vulnerabilities-in-ml-frameworks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/analysis-of-pickle-file-deserialization-vulnerabilities-in-ml-frameworks</guid>
      <pubDate>Tue, 04 Aug 2026 01:50:10 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Path traversal vulnerabilities explained with real-world examples]]></title>
      <description><![CDATA[Path traversal (CWE-22) has powered CVEs from Apache to Citrix to F5. Here's how it works, real breaches, and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-vulnerabilities-explained-with-real-world-examples</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-vulnerabilities-explained-with-real-world-examples</guid>
      <pubDate>Tue, 04 Aug 2026 00:29:43 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[How slopsquatting exploits AI-hallucinated package names]]></title>
      <description><![CDATA[Slopsquatting attacks turn AI-hallucinated package names into real supply chain threats. Here's how it works, the numbers behind it, and how Safeguard stops it.]]></description>
      <link>https://safeguard.sh/resources/blog/how-slopsquatting-exploits-ai-hallucinated-package-names</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-slopsquatting-exploits-ai-hallucinated-package-names</guid>
      <pubDate>Mon, 03 Aug 2026 23:09:16 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Server-Side Request Forgery (SSRF): how it works and how to prevent it]]></title>
      <description><![CDATA[SSRF turns a server into an attacker's proxy into your internal network. Here's how it works, what Capital One's breach taught the industry, and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/server-side-request-forgery-ssrf-how-it-works-and-how-to-prevent-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/server-side-request-forgery-ssrf-how-it-works-and-how-to-prevent-it</guid>
      <pubDate>Mon, 03 Aug 2026 21:48:50 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Security risks introduced by AI coding assistants and gen...]]></title>
      <description><![CDATA[AI coding assistants now write huge shares of production code. Real 2025 incidents show hallucinated packages, leaked secrets, and vulnerable defaults ship with it.]]></description>
      <link>https://safeguard.sh/resources/blog/security-risks-introduced-by-ai-coding-assistants-and-generated-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-risks-introduced-by-ai-coding-assistants-and-generated-code</guid>
      <pubDate>Mon, 03 Aug 2026 20:28:23 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cross-site scripting (XSS) explained for developers]]></title>
      <description><![CDATA[XSS has topped vulnerability lists for two decades. Here's how reflected, stored, and DOM-based XSS actually work, real incidents, and how to fix them.]]></description>
      <link>https://safeguard.sh/resources/blog/cross-site-scripting-xss-explained-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cross-site-scripting-xss-explained-for-developers</guid>
      <pubDate>Mon, 03 Aug 2026 19:07:56 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SQL injection: a complete developer's guide]]></title>
      <description><![CDATA[A developer's guide to SQL injection: how it works, why CWE-89 still ranks in MITRE's Top 25, real breaches, and how to detect and fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-a-complete-developers-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-a-complete-developers-guide</guid>
      <pubDate>Mon, 03 Aug 2026 17:47:30 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Overview of NIST's finalized post-quantum cryptography st...]]></title>
      <description><![CDATA[NIST finalized FIPS 203, 204, and 205 in August 2024, formalizing the first NIST post-quantum standards. Here's what changes for software supply chain security teams.]]></description>
      <link>https://safeguard.sh/resources/blog/overview-of-nists-finalized-post-quantum-cryptography-standards</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/overview-of-nists-finalized-post-quantum-cryptography-standards</guid>
      <pubDate>Mon, 03 Aug 2026 16:27:03 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[OS command injection explained]]></title>
      <description><![CDATA[OS command injection lets attackers run arbitrary shell commands via unsanitized input. See how it works, real CVEs like PAN-OS 2024, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/os-command-injection-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/os-command-injection-explained</guid>
      <pubDate>Mon, 03 Aug 2026 15:06:36 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Insecure deserialization vulnerabilities explained]]></title>
      <description><![CDATA[Insecure deserialization vulnerabilities let attackers turn trusted classes into gadget chains for RCE. See real CVEs, affected languages, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/insecure-deserialization-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insecure-deserialization-vulnerabilities-explained</guid>
      <pubDate>Mon, 03 Aug 2026 13:46:10 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[What crypto-agility means and how to design for algorithm...]]></title>
      <description><![CDATA[What crypto agility really means, why SHA-1's decade-long death proved it, and how to design algorithm swaps into software before NIST's PQC deadlines force the issue.]]></description>
      <link>https://safeguard.sh/resources/blog/what-crypto-agility-means-and-how-to-design-for-algorithm-swaps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-crypto-agility-means-and-how-to-design-for-algorithm-swaps</guid>
      <pubDate>Mon, 03 Aug 2026 12:25:43 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[XML External Entity (XXE) injection explained]]></title>
      <description><![CDATA[XXE injection lets attackers abuse XML parsers to read files, hit cloud metadata via SSRF, or crash servers — here's how it works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/xml-external-entity-xxe-injection-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xml-external-entity-xxe-injection-explained</guid>
      <pubDate>Mon, 03 Aug 2026 11:05:16 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Comparing quantum-safe VPN and networking products on the...]]></title>
      <description><![CDATA[A practical buyers guide to quantum-safe VPN options, comparing Cisco, Palo Alto Networks, Mullvad, ExpressVPN, Zscaler, and Post-Quantum on real strengths and limitations.]]></description>
      <link>https://safeguard.sh/resources/blog/comparing-quantum-safe-vpn-and-networking-products-on-the-market</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/comparing-quantum-safe-vpn-and-networking-products-on-the-market</guid>
      <pubDate>Mon, 03 Aug 2026 09:44:49 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Cross-site request forgery (CSRF) explained]]></title>
      <description><![CDATA[CSRF forges authenticated requests using a victim's own session cookies. Learn how real attacks against Netflix and uTorrent worked, and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/cross-site-request-forgery-csrf-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cross-site-request-forgery-csrf-explained</guid>
      <pubDate>Mon, 03 Aug 2026 08:24:23 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How ML-KEM (Kyber) works and implementation pitfalls]]></title>
      <description><![CDATA[FIPS 203's ML-KEM Kyber is landing in TLS, SSH, and VPNs everywhere — here's how the lattice math works and the timing bugs, like KyberSlash, already found in real implementations.]]></description>
      <link>https://safeguard.sh/resources/blog/how-ml-kem-kyber-works-and-implementation-pitfalls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-ml-kem-kyber-works-and-implementation-pitfalls</guid>
      <pubDate>Mon, 03 Aug 2026 07:03:56 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Open redirect vulnerabilities explained]]></title>
      <description><![CDATA[Open redirect flaws (CWE-601) score as medium severity alone, but they power real phishing campaigns against Google, Amex, and Microsoft. Here's how they work and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/open-redirect-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-redirect-vulnerabilities-explained</guid>
      <pubDate>Mon, 03 Aug 2026 05:43:29 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What a cryptographic bill of materials is and why it's ne...]]></title>
      <description><![CDATA[A cryptographic bill of materials (CBOM) inventories every algorithm, key, and certificate in your systems—here's why PQC migration is impossible without one.]]></description>
      <link>https://safeguard.sh/resources/blog/what-a-cryptographic-bill-of-materials-is-and-why-its-needed-for-pqc-migration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-a-cryptographic-bill-of-materials-is-and-why-its-needed-for-pqc-migration</guid>
      <pubDate>Mon, 03 Aug 2026 04:23:03 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Arbitrary file upload vulnerabilities explained]]></title>
      <description><![CDATA[Arbitrary file upload flaws (CWE-434) have caused breaches from Equifax to GitLab. Here's how they work, the CVEs that prove it, and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/arbitrary-file-upload-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/arbitrary-file-upload-vulnerabilities-explained</guid>
      <pubDate>Mon, 03 Aug 2026 03:02:36 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Introduction to confidential computing and hardware-based...]]></title>
      <description><![CDATA[Confidential computing seals data in use inside hardware-encrypted enclaves, closing the last gap in the encrypt-everywhere model. Here's how it works.]]></description>
      <link>https://safeguard.sh/resources/blog/introduction-to-confidential-computing-and-hardware-based-data-protection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/introduction-to-confidential-computing-and-hardware-based-data-protection</guid>
      <pubDate>Mon, 03 Aug 2026 01:42:09 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Directory listing exposure risks explained]]></title>
      <description><![CDATA[Directory listing vulnerabilities expose raw file trees via one misconfigured Apache, Nginx, or IIS directive. Here's how they happen and how to fix them.]]></description>
      <link>https://safeguard.sh/resources/blog/directory-listing-exposure-risks-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/directory-listing-exposure-risks-explained</guid>
      <pubDate>Mon, 03 Aug 2026 00:21:43 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[How trusted execution environments protect sensitive work...]]></title>
      <description><![CDATA[Trusted execution environments promise hardware-isolated security for sensitive workloads, but real-world attacks show the TEE model has limits Safeguard helps you manage.]]></description>
      <link>https://safeguard.sh/resources/blog/how-trusted-execution-environments-protect-sensitive-workloads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-trusted-execution-environments-protect-sensitive-workloads</guid>
      <pubDate>Sun, 02 Aug 2026 23:01:16 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Time-of-check to time-of-use (TOCTOU) race condition vulnerabilities]]></title>
      <description><![CDATA[TOCTOU race conditions let attackers swap a resource between a security check and its use. Real CVEs, exploit mechanics, and prevention patterns explained.]]></description>
      <link>https://safeguard.sh/resources/blog/time-of-check-to-time-of-use-toctou-race-condition-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/time-of-check-to-time-of-use-toctou-race-condition-vulnerabilities</guid>
      <pubDate>Sun, 02 Aug 2026 21:40:49 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Using confidential computing to protect LLM inference and...]]></title>
      <description><![CDATA[How hardware-based secure enclaves keep LLM prompts and weights encrypted even during active inference, and why confidential AI inference is reshaping AI compliance in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/using-confidential-computing-to-protect-llm-inference-and-prompts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/using-confidential-computing-to-protect-llm-inference-and-prompts</guid>
      <pubDate>Sun, 02 Aug 2026 20:20:23 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Security News Today: What to Watch and How to Respond]]></title>
      <description><![CDATA[Keeping up with Kubernetes security news today means more than reading headlines. Here's how to triage a fresh CVE, what IngressNightmare taught us, and where to look first.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-security-news-today</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-security-news-today</guid>
      <pubDate>Sun, 02 Aug 2026 18:59:56 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-59718 in FortiOS: FortiCloud SSO SAML Bypass]]></title>
      <description><![CDATA[An unauthenticated SAML message manipulation lets attackers log in as admin on FortiGate, FortiWeb, and FortiProxy. We unpack the bug and the IR steps.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2025-59718-fortios-saml-bypass-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2025-59718-fortios-saml-bypass-deep-dive</guid>
      <pubDate>Sun, 02 Aug 2026 17:39:29 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Buffer overflow vulnerabilities explained]]></title>
      <description><![CDATA[Buffer overflows still make MITRE's CWE Top 25 every year. Here's how they corrupt memory, real CVEs like EternalBlue and Baron Samedit, and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/buffer-overflow-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buffer-overflow-vulnerabilities-explained</guid>
      <pubDate>Sun, 02 Aug 2026 16:19:02 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Comparing confidential VM offerings across major cloud pr...]]></title>
      <description><![CDATA[A practical comparison of confidential virtual machines across Azure, AWS Nitro Enclaves, GCP confidential compute, and more -- real strengths, real limitations, no marketing gloss.]]></description>
      <link>https://safeguard.sh/resources/blog/comparing-confidential-vm-offerings-across-major-cloud-providers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/comparing-confidential-vm-offerings-across-major-cloud-providers</guid>
      <pubDate>Sun, 02 Aug 2026 14:58:36 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Use-after-free vulnerabilities explained]]></title>
      <description><![CDATA[Use-after-free bugs (CWE-416) power some of the worst zero-day exploit chains in browsers and kernels. Here's how they work and what stops them.]]></description>
      <link>https://safeguard.sh/resources/blog/use-after-free-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/use-after-free-vulnerabilities-explained</guid>
      <pubDate>Sun, 02 Aug 2026 13:38:09 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Technical comparison of AMD SEV-SNP and Intel TDX securit...]]></title>
      <description><![CDATA[A technical comparison of AMD SEV-SNP vs Intel TDX covering memory encryption, attestation, CVE history, and cloud provider support.]]></description>
      <link>https://safeguard.sh/resources/blog/technical-comparison-of-amd-sev-snp-and-intel-tdx-security-guarantees</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/technical-comparison-of-amd-sev-snp-and-intel-tdx-security-guarantees</guid>
      <pubDate>Sun, 02 Aug 2026 12:17:42 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Integer overflow vulnerabilities explained]]></title>
      <description><![CDATA[What integer overflow vulnerabilities are, how CWE-190 causes real breaches like Bitcoin's 2010 overflow bug, and how to detect and prevent them.]]></description>
      <link>https://safeguard.sh/resources/blog/integer-overflow-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/integer-overflow-vulnerabilities-explained</guid>
      <pubDate>Sun, 02 Aug 2026 10:57:16 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Remote attestation fundamentals for confidential computin...]]></title>
      <description><![CDATA[A practical look at remote attestation for confidential computing: how enclave protocols and hardware verification prove workloads haven't been tampered with.]]></description>
      <link>https://safeguard.sh/resources/blog/remote-attestation-fundamentals-for-confidential-computing-environments</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/remote-attestation-fundamentals-for-confidential-computing-environments</guid>
      <pubDate>Sun, 02 Aug 2026 09:36:49 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Type confusion vulnerabilities explained]]></title>
      <description><![CDATA[Type confusion bugs let attackers corrupt memory by exploiting mismatched type assumptions. See real CVEs, how JIT engines fail, and how to catch it early.]]></description>
      <link>https://safeguard.sh/resources/blog/type-confusion-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/type-confusion-vulnerabilities-explained</guid>
      <pubDate>Sun, 02 Aug 2026 08:16:22 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Key security risks unique to WebAssembly runtimes and mod...]]></title>
      <description><![CDATA[WebAssembly runs your edge functions, service mesh plugins, and smart contracts. Here are the WebAssembly security risks hiding behind the sandbox.]]></description>
      <link>https://safeguard.sh/resources/blog/key-security-risks-unique-to-webassembly-runtimes-and-modules</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/key-security-risks-unique-to-webassembly-runtimes-and-modules</guid>
      <pubDate>Sun, 02 Aug 2026 06:55:56 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Format string vulnerabilities explained]]></title>
      <description><![CDATA[Format string bugs let attackers turn a printf call into memory disclosure or arbitrary writes. Here's how CWE-134 works, real CVEs, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/format-string-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/format-string-vulnerabilities-explained</guid>
      <pubDate>Sun, 02 Aug 2026 05:35:29 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Analysis of documented WebAssembly sandbox escape vulnera...]]></title>
      <description><![CDATA[Real documented WASM sandbox escape cases in Wasmtime and Wasmer, covering affected versions, severity, disclosure timelines, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/analysis-of-documented-webassembly-sandbox-escape-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/analysis-of-documented-webassembly-sandbox-escape-vulnerabilities</guid>
      <pubDate>Sun, 02 Aug 2026 04:15:02 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[NoSQL injection vulnerabilities explained]]></title>
      <description><![CDATA[NoSQL injection lets attackers manipulate MongoDB-style queries via operators like $ne and $where. Learn how it works, real CVEs, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/nosql-injection-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nosql-injection-vulnerabilities-explained</guid>
      <pubDate>Sun, 02 Aug 2026 02:54:36 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[How the WASI security model constrains system access for ...]]></title>
      <description><![CDATA[WASI's capability model gives Wasm modules only the exact files, sockets, and resources they're explicitly granted—but misconfiguration and runtime bugs still leave real gaps to close.]]></description>
      <link>https://safeguard.sh/resources/blog/how-the-wasi-security-model-constrains-system-access-for-wasm-modules</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-the-wasi-security-model-constrains-system-access-for-wasm-modules</guid>
      <pubDate>Sun, 02 Aug 2026 01:34:09 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[LDAP injection vulnerabilities explained]]></title>
      <description><![CDATA[LDAP injection lets attackers manipulate directory filters to bypass authentication or dump data. Here's how CWE-90 attacks work and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/ldap-injection-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ldap-injection-vulnerabilities-explained</guid>
      <pubDate>Sun, 02 Aug 2026 00:13:42 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Practical steps to secure third-party WebAssembly plugins...]]></title>
      <description><![CDATA[A step-by-step guide to securing third-party WebAssembly plugins in production: sandboxing, capability restriction, resource limits, provenance checks, and runtime monitoring.]]></description>
      <link>https://safeguard.sh/resources/blog/practical-steps-to-secure-third-party-webassembly-plugins-in-production</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/practical-steps-to-secure-third-party-webassembly-plugins-in-production</guid>
      <pubDate>Sat, 01 Aug 2026 22:53:15 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Server-side template injection (SSTI) explained]]></title>
      <description><![CDATA[SSTI lets attackers turn template syntax into server-side RCE. See how it works, real CVEs like Confluence's, and how to prevent it.]]></description>
      <link>https://safeguard.sh/resources/blog/server-side-template-injection-ssti-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/server-side-template-injection-ssti-explained</guid>
      <pubDate>Sat, 01 Aug 2026 21:32:49 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Security considerations for running WebAssembly at the ed...]]></title>
      <description><![CDATA[Wasm's sandbox is safe by default, not safe by construction. Here's where edge WebAssembly security breaks down -- in browsers, at the edge, and in the build pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/security-considerations-for-running-webassembly-at-the-edge-and-in-browsers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-considerations-for-running-webassembly-at-the-edge-and-in-browsers</guid>
      <pubDate>Sat, 01 Aug 2026 20:12:22 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[UK CSR Bill: Relevant MSPs and Data Centres Brought Into Scope]]></title>
      <description><![CDATA[The UK Cyber Security and Resilience Bill introduced on 12 November 2025 expands the NIS regime to 900-1,100 managed service providers and large data centres.]]></description>
      <link>https://safeguard.sh/resources/blog/uk-csr-bill-relevant-msps-data-centres-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uk-csr-bill-relevant-msps-data-centres-2025</guid>
      <pubDate>Sat, 01 Aug 2026 18:51:55 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CycloneDX 1.7 Deep Dive: Cryptography, Citations, and Patents]]></title>
      <description><![CDATA[CycloneDX 1.7 released in October 2025 with first-class cryptography metadata, a new Citations element, and patent-aware IP fields. We walk through what changed and which producers should adopt now.]]></description>
      <link>https://safeguard.sh/resources/blog/cyclonedx-1-7-cryptography-citations-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyclonedx-1-7-cryptography-citations-deep-dive</guid>
      <pubDate>Sat, 01 Aug 2026 17:31:29 GMT</pubDate>
      <category>Standards</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Insecure direct object reference (IDOR) explained]]></title>
      <description><![CDATA[IDOR lets attackers access other users' data by editing an ID in a request. See how it broke USPS, Panera, and First American — and how to actually fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/insecure-direct-object-reference-idor-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insecure-direct-object-reference-idor-explained</guid>
      <pubDate>Sat, 01 Aug 2026 16:11:02 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Grype v0.108 Release Notes Walkthrough]]></title>
      <description><![CDATA[Anchore's Grype shipped v0.108.0 in late 2025 with the new vulnerability database v6 schema, distroless support fixes, and a tightened CPE matcher.]]></description>
      <link>https://safeguard.sh/resources/blog/grype-v0-108-release-notes-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/grype-v0-108-release-notes-2025</guid>
      <pubDate>Sat, 01 Aug 2026 14:50:35 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Aisha Iqbal)</author>
    </item>
    <item>
      <title><![CDATA[What AI red teaming is and how to run a structured exercise]]></title>
      <description><![CDATA[A practical guide to AI red teaming: how to plan, run, and report a structured LLM red team exercise using a repeatable adversarial testing methodology.]]></description>
      <link>https://safeguard.sh/resources/blog/what-ai-red-teaming-is-and-how-to-run-a-structured-exercise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-ai-red-teaming-is-and-how-to-run-a-structured-exercise</guid>
      <pubDate>Sat, 01 Aug 2026 13:30:09 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Authentication bypass vulnerabilities explained]]></title>
      <description><![CDATA[Authentication bypass flaws let attackers skip login entirely. See how CVE-2022-40684, CVE-2023-22515, and CVE-2021-40539 were exploited and prevented.]]></description>
      <link>https://safeguard.sh/resources/blog/authentication-bypass-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/authentication-bypass-vulnerabilities-explained</guid>
      <pubDate>Sat, 01 Aug 2026 12:09:42 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Comparing leading LLM red teaming and automated testing t...]]></title>
      <description><![CDATA[A practical comparison of leading LLM red teaming tools -- PyRIT, Garak, Giskard, Promptfoo, Lakera Red, and Mindgard -- with real strengths, limits, and evaluation criteria.]]></description>
      <link>https://safeguard.sh/resources/blog/comparing-leading-llm-red-teaming-and-automated-testing-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/comparing-leading-llm-red-teaming-and-automated-testing-tools</guid>
      <pubDate>Sat, 01 Aug 2026 10:49:15 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Broken access control explained]]></title>
      <description><![CDATA[Broken access control has topped OWASP's Top 10 since 2021. See real breaches, common patterns like IDOR, and how to detect and fix them.]]></description>
      <link>https://safeguard.sh/resources/blog/broken-access-control-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/broken-access-control-explained</guid>
      <pubDate>Sat, 01 Aug 2026 09:28:49 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Privilege escalation vulnerabilities explained]]></title>
      <description><![CDATA[Privilege escalation vulnerabilities turn a low-privilege foothold into root or admin access. Learn how they work, key CVEs, and how to detect them.]]></description>
      <link>https://safeguard.sh/resources/blog/privilege-escalation-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/privilege-escalation-vulnerabilities-explained</guid>
      <pubDate>Sat, 01 Aug 2026 08:08:22 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-5752: Command Injection in pip via Mercurial Revisions]]></title>
      <description><![CDATA[Installing a package from a Mercurial URL with a crafted revision let attackers inject hg config options. Here is how CVE-2023-5752 works and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-5752</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-5752</guid>
      <pubDate>Sat, 01 Aug 2026 06:47:55 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[eslint-plugin-unused-imports: Cleaner Code, Smaller Surface]]></title>
      <description><![CDATA[eslint-plugin-unused-imports auto-removes dead imports that the base ESLint rule only warns about. Here is how to configure it correctly on ESLint 9.]]></description>
      <link>https://safeguard.sh/resources/blog/eslint-plugin-unused-imports</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eslint-plugin-unused-imports</guid>
      <pubDate>Sat, 01 Aug 2026 05:27:28 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[@angular-devkit/build-angular: A Security Guide to the Angular Build Package]]></title>
      <description><![CDATA[@angular-devkit/build-angular is the build toolchain behind the Angular CLI. Most of its security risk is transitive, coming from the build and dev-server dependencies it pulls in.]]></description>
      <link>https://safeguard.sh/resources/blog/angular-devkit-build-angular</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/angular-devkit-build-angular</guid>
      <pubDate>Sat, 01 Aug 2026 04:07:02 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What an SBOM Scanner Does and How to Choose One]]></title>
      <description><![CDATA[An SBOM scanner reads a software bill of materials and matches every listed component against vulnerability data. Here is how that differs from source scanning and what makes one worth trusting.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-scanner</guid>
      <pubDate>Sat, 01 Aug 2026 02:46:35 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-22102: The MySQL Connector/J Takeover Vulnerability]]></title>
      <description><![CDATA[CVE-2023-22102 is a High-severity flaw in Oracle's MySQL Connector/J that can lead to connector takeover. Here is the root cause and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-22102</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-22102</guid>
      <pubDate>Sat, 01 Aug 2026 01:26:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Black Duck Competitors: The Top SCA Alternatives Compared]]></title>
      <description><![CDATA[A fair look at the main Black Duck competitors in software composition analysis — Snyk, Mend, Sonatype, Endor Labs, and others — and which fits which job.]]></description>
      <link>https://safeguard.sh/resources/blog/blackduck-competitors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/blackduck-competitors</guid>
      <pubDate>Sat, 01 Aug 2026 00:05:42 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Application Data Security: How to Protect Data Across Its Lifecycle]]></title>
      <description><![CDATA[Application data security is the set of controls that protect data as your application collects, processes, stores, and transmits it. Here is a practical model for getting it right.]]></description>
      <link>https://safeguard.sh/resources/blog/application-data-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-data-security</guid>
      <pubDate>Fri, 31 Jul 2026 22:45:15 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Hardcoded credentials vulnerabilities explained]]></title>
      <description><![CDATA[Hardcoded credentials (CWE-798) have caused real breaches at Uber, Toyota, and Mercedes-Benz. Here's how they happen, how common they are, and how to fix them.]]></description>
      <link>https://safeguard.sh/resources/blog/hardcoded-credentials-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hardcoded-credentials-vulnerabilities-explained</guid>
      <pubDate>Fri, 31 Jul 2026 21:24:48 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Secure Software Development Lifecycle in 2025: What Actually Changed]]></title>
      <description><![CDATA[A practical look at how SSDLC practices evolved in 2025, what worked, what failed, and why most organizations are still getting the basics wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-software-development-lifecycle-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-software-development-lifecycle-2025</guid>
      <pubDate>Fri, 31 Jul 2026 20:04:22 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How AI safety benchmarks and evaluations measure model risk]]></title>
      <description><![CDATA[A concrete look at how AI safety benchmark evaluation, LLM safety scorecards, and capability testing actually measure model risk in 2026 — and where they fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/how-ai-safety-benchmarks-and-evaluations-measure-model-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-ai-safety-benchmarks-and-evaluations-measure-model-risk</guid>
      <pubDate>Fri, 31 Jul 2026 18:43:55 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Insecure randomness vulnerabilities explained]]></title>
      <description><![CDATA[CWE-338 explained through the Debian OpenSSL and Android Bitcoin SecureRandom breaches — how weak PRNGs get exploited, and how to detect and fix them.]]></description>
      <link>https://safeguard.sh/resources/blog/insecure-randomness-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insecure-randomness-vulnerabilities-explained</guid>
      <pubDate>Fri, 31 Jul 2026 17:23:28 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Evaluating automated AI red teaming platforms for continu...]]></title>
      <description><![CDATA[A practical buyer's guide to evaluating an automated red teaming platform for continuous AI testing, with a fair roundup of six real vendors and tools.]]></description>
      <link>https://safeguard.sh/resources/blog/evaluating-automated-ai-red-teaming-platforms-for-continuous-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/evaluating-automated-ai-red-teaming-platforms-for-continuous-testing</guid>
      <pubDate>Fri, 31 Jul 2026 16:03:02 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Weak/broken cryptography vulnerabilities explained]]></title>
      <description><![CDATA[Weak cryptography vulnerabilities like MD5, ECB mode, and undersized RSA keys quietly break real systems. Learn how, with cases from Adobe, Logjam, and SHAttered.]]></description>
      <link>https://safeguard.sh/resources/blog/weakbroken-cryptography-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/weakbroken-cryptography-vulnerabilities-explained</guid>
      <pubDate>Fri, 31 Jul 2026 14:42:35 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Explaining prompt injection attacks and why they're hard ...]]></title>
      <description><![CDATA[Prompt injection attacks trick AI models into obeying attacker instructions hidden in data or user input, and there's still no complete fix.]]></description>
      <link>https://safeguard.sh/resources/blog/explaining-prompt-injection-attacks-and-why-theyre-hard-to-fix</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/explaining-prompt-injection-attacks-and-why-theyre-hard-to-fix</guid>
      <pubDate>Fri, 31 Jul 2026 13:22:08 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Certificate validation bypass and man-in-the-middle risk explained]]></title>
      <description><![CDATA[Certificate validation bypass flaws silently disable TLS's identity guarantees, opening the door to man-in-the-middle attacks. Here's how they happen and how to catch them.]]></description>
      <link>https://safeguard.sh/resources/blog/certificate-validation-bypass-and-man-in-the-middle-risk-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/certificate-validation-bypass-and-man-in-the-middle-risk-explained</guid>
      <pubDate>Fri, 31 Jul 2026 12:01:41 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How indirect prompt injection hides malicious instruction...]]></title>
      <description><![CDATA[How attackers hide malicious instructions inside webpages, documents, and retrieved content to hijack AI systems — and why RAG pipelines are especially exposed.]]></description>
      <link>https://safeguard.sh/resources/blog/how-indirect-prompt-injection-hides-malicious-instructions-in-external-content</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-indirect-prompt-injection-hides-malicious-instructions-in-external-content</guid>
      <pubDate>Fri, 31 Jul 2026 10:41:15 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Algorithmic complexity denial of service explained]]></title>
      <description><![CDATA[Small inputs, big CPU spikes: how algorithmic complexity DoS vulnerabilities like ReDoS and hash flooding crash apps with a single request.]]></description>
      <link>https://safeguard.sh/resources/blog/algorithmic-complexity-denial-of-service-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/algorithmic-complexity-denial-of-service-explained</guid>
      <pubDate>Fri, 31 Jul 2026 09:20:48 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Comparing LLM firewall and guardrail products for enterpr...]]></title>
      <description><![CDATA[A vendor-by-vendor comparison of LLM firewall and AI guardrail platform options for enterprise deployment, with real strengths and limitations for each.]]></description>
      <link>https://safeguard.sh/resources/blog/comparing-llm-firewall-and-guardrail-products-for-enterprise-deployment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/comparing-llm-firewall-and-guardrail-products-for-enterprise-deployment</guid>
      <pubDate>Fri, 31 Jul 2026 08:00:21 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Typosquatting in open source package registries explained]]></title>
      <description><![CDATA[Typosquatting hides malware behind a one-character package name typo. Learn how it works, real incidents, and how to detect it before your build runs.]]></description>
      <link>https://safeguard.sh/resources/blog/typosquatting-in-open-source-package-registries-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/typosquatting-in-open-source-package-registries-explained</guid>
      <pubDate>Fri, 31 Jul 2026 06:39:55 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How RAG poisoning attacks manipulate retrieval-augmented ...]]></title>
      <description><![CDATA[RAG poisoning attacks corrupt the external knowledge base an LLM retrieves from, turning trusted documents into vectors for misinformation and data leaks.]]></description>
      <link>https://safeguard.sh/resources/blog/how-rag-poisoning-attacks-manipulate-retrieval-augmented-generation-systems</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-rag-poisoning-attacks-manipulate-retrieval-augmented-generation-systems</guid>
      <pubDate>Fri, 31 Jul 2026 05:19:28 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CI/CD pipeline supply chain attacks explained]]></title>
      <description><![CDATA[A breakdown of how CI/CD supply chain attacks work, from SolarWinds to the 2025 tj-actions/changed-files breach, and how to detect and stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/cicd-pipeline-supply-chain-attacks-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cicd-pipeline-supply-chain-attacks-explained</guid>
      <pubDate>Fri, 31 Jul 2026 03:59:01 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Security considerations for deploying and querying vector...]]></title>
      <description><![CDATA[Vector databases now hold copies of your most sensitive data with weaker controls than the systems they came from. Here's what to fix before your next RAG deployment.]]></description>
      <link>https://safeguard.sh/resources/blog/security-considerations-for-deploying-and-querying-vector-databases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-considerations-for-deploying-and-querying-vector-databases</guid>
      <pubDate>Fri, 31 Jul 2026 02:38:35 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to detect malicious npm packages]]></title>
      <description><![CDATA[Real npm supply chain attacks — event-stream, ua-parser-js, node-ipc, and the 2025 chalk/debug breach — show how to spot and stop malicious packages.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-detect-malicious-npm-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-detect-malicious-npm-packages</guid>
      <pubDate>Fri, 31 Jul 2026 01:18:08 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How model extraction attacks steal proprietary AI model b...]]></title>
      <description><![CDATA[Model extraction attacks let adversaries clone proprietary AI models through ordinary API queries alone. Here's how the attacks work, why they evade detection, and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/how-model-extraction-attacks-steal-proprietary-ai-model-behavior</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-model-extraction-attacks-steal-proprietary-ai-model-behavior</guid>
      <pubDate>Thu, 30 Jul 2026 23:57:41 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Subresource integrity bypass explained]]></title>
      <description><![CDATA[SRI hashes can't stop what happens before the hash is made. How polyfill.io, British Airways, and event-stream exposed real gaps in browser integrity checks.]]></description>
      <link>https://safeguard.sh/resources/blog/subresource-integrity-bypass-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/subresource-integrity-bypass-explained</guid>
      <pubDate>Thu, 30 Jul 2026 22:37:14 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Understanding membership inference attacks against traine...]]></title>
      <description><![CDATA[Membership inference attacks let adversaries confirm if your data trained a model, exposing privacy leakage in ML models and training data inference risks.]]></description>
      <link>https://safeguard.sh/resources/blog/understanding-membership-inference-attacks-against-trained-models</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/understanding-membership-inference-attacks-against-trained-models</guid>
      <pubDate>Thu, 30 Jul 2026 21:16:48 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Clickjacking vulnerabilities explained]]></title>
      <description><![CDATA[A clickjacking vulnerability hides real buttons under a decoy iframe to hijack clicks. Here's how the attack works, real incidents, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/clickjacking-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/clickjacking-vulnerabilities-explained</guid>
      <pubDate>Thu, 30 Jul 2026 19:56:21 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What shadow AI is and how to discover unsanctioned AI use...]]></title>
      <description><![CDATA[Shadow AI risk is spreading faster than governance can keep up. Here's what unsanctioned AI use looks like inside real enterprises and how to discover it before data leaks.]]></description>
      <link>https://safeguard.sh/resources/blog/what-shadow-ai-is-and-how-to-discover-unsanctioned-ai-use-in-the-enterprise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-shadow-ai-is-and-how-to-discover-unsanctioned-ai-use-in-the-enterprise</guid>
      <pubDate>Thu, 30 Jul 2026 18:35:54 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CRLF injection and HTTP response splitting explained]]></title>
      <description><![CDATA[CRLF injection lets attackers forge HTTP headers and split responses. Here's how it works, real CVEs behind it, and how to detect and stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/crlf-injection-and-http-response-splitting-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crlf-injection-and-http-response-splitting-explained</guid>
      <pubDate>Thu, 30 Jul 2026 17:15:28 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Building an AI governance framework for enterprise risk m...]]></title>
      <description><![CDATA[A practical breakdown of what an AI governance framework needs to contain in 2026 — from NIST's AI RMF to EU AI Act deadlines — and how to build one that scales with engineering velocity.]]></description>
      <link>https://safeguard.sh/resources/blog/building-an-ai-governance-framework-for-enterprise-risk-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-an-ai-governance-framework-for-enterprise-risk-management</guid>
      <pubDate>Thu, 30 Jul 2026 15:55:01 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[HTTP request smuggling explained]]></title>
      <description><![CDATA[HTTP request smuggling exploits parser mismatches between proxies and origin servers. Learn CL.TE/TE.CL mechanics, real CVEs, and how to detect it.]]></description>
      <link>https://safeguard.sh/resources/blog/http-request-smuggling-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/http-request-smuggling-explained</guid>
      <pubDate>Thu, 30 Jul 2026 14:34:34 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Server-side includes (SSI) injection explained]]></title>
      <description><![CDATA[SSI injection lets attackers run shell commands via directives like #exec cmd. Learn how CWE-97 works, real attack vectors, detection, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/server-side-includes-ssi-injection-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/server-side-includes-ssi-injection-explained</guid>
      <pubDate>Thu, 30 Jul 2026 13:14:08 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Glossary of AI Trust, Risk, and Security Management (AI T...]]></title>
      <description><![CDATA[A glossary of AI trust risk security management concepts: the Gartner AI TRiSM framework, its four pillars, AI risk taxonomy, and adversarial threats.]]></description>
      <link>https://safeguard.sh/resources/blog/glossary-of-ai-trust-risk-and-security-management-ai-trism-concepts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/glossary-of-ai-trust-risk-and-security-management-ai-trism-concepts</guid>
      <pubDate>Thu, 30 Jul 2026 11:53:41 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Business logic vulnerabilities explained]]></title>
      <description><![CDATA[A business logic vulnerability breaks your app's rules, not its code. See how Starbucks, Shopify, and the DAO were exploited -- and how to detect and prevent it.]]></description>
      <link>https://safeguard.sh/resources/blog/business-logic-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/business-logic-vulnerabilities-explained</guid>
      <pubDate>Thu, 30 Jul 2026 10:33:14 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[How to build an AI-specific incident response playbook]]></title>
      <description><![CDATA[A step-by-step guide to building an AI incident response plan — covering scoping, escalation, detection, containment, and post-incident review for LLM and agent failures.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-build-an-ai-specific-incident-response-playbook</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-build-an-ai-specific-incident-response-playbook</guid>
      <pubDate>Thu, 30 Jul 2026 09:12:48 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Mass assignment vulnerabilities explained]]></title>
      <description><![CDATA[Mass assignment lets attackers write privileged fields like "role":"admin" via ordinary API calls. Learn how it works, real CVEs, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/mass-assignment-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mass-assignment-vulnerabilities-explained</guid>
      <pubDate>Thu, 30 Jul 2026 07:52:21 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[How deepfake fraud detection tools identify synthetic med...]]></title>
      <description><![CDATA[A buyer's guide to real-time deepfake fraud detection tools: evaluation criteria, an honest comparison of six named vendors, and where Safeguard fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/how-deepfake-fraud-detection-tools-identify-synthetic-media-in-real-time</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-deepfake-fraud-detection-tools-identify-synthetic-media-in-real-time</guid>
      <pubDate>Thu, 30 Jul 2026 06:31:54 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[GraphQL injection and introspection abuse explained]]></title>
      <description><![CDATA[How GraphQL injection, introspection abuse, and alias-based DoS attacks expose APIs to data leaks—illustrated by the 2021 Peloton breach.]]></description>
      <link>https://safeguard.sh/resources/blog/graphql-injection-and-introspection-abuse-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/graphql-injection-and-introspection-abuse-explained</guid>
      <pubDate>Thu, 30 Jul 2026 05:11:27 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems 2019 Multi-CVE Disclosure: Directory Traversal v...]]></title>
      <description><![CDATA[CVE-2019-8320 let malicious RubyGems packages delete arbitrary directories via symlinked gem decompression. Here's the impact, timeline, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-2019-multi-cve-disclosure-directory-traversal-via-gem-decompression-cve-2019-8320</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-2019-multi-cve-disclosure-directory-traversal-via-gem-decompression-cve-2019-8320</guid>
      <pubDate>Thu, 30 Jul 2026 03:51:01 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CoSAI Releases Model Signing and Incident Response Frameworks]]></title>
      <description><![CDATA[The Coalition for Secure AI published two operational frameworks in November 2025: Signing ML Artifacts and AI Incident Response. We unpack what each contains and how to adopt them.]]></description>
      <link>https://safeguard.sh/resources/blog/cosai-model-signing-incident-response-frameworks-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cosai-model-signing-incident-response-frameworks-2025</guid>
      <pubDate>Thu, 30 Jul 2026 02:30:34 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[JWT algorithm confusion / none-algorithm bypass explained]]></title>
      <description><![CDATA[How attackers forge JWTs via RS256/HS256 key confusion and the alg:none bypass, with real CVEs, detection steps, and defenses.]]></description>
      <link>https://safeguard.sh/resources/blog/jwt-algorithm-confusion-none-algorithm-bypass-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jwt-algorithm-confusion-none-algorithm-bypass-explained</guid>
      <pubDate>Thu, 30 Jul 2026 01:10:07 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems Escape Sequence Injection via Gem Name Output (C...]]></title>
      <description><![CDATA[A look at CVE-2019-8321, the RubyGems escape sequence injection flaw in gem CLI output: affected versions, severity, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-escape-sequence-injection-via-gem-name-output-cve-2019-8321</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-escape-sequence-injection-via-gem-name-output-cve-2019-8321</guid>
      <pubDate>Wed, 29 Jul 2026 23:49:41 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Hacking Software: What It Is and How Defenders Use It Legally]]></title>
      <description><![CDATA[Hacking software is the category of programs used to test and break into systems. Used with authorization, it is how security teams find their own weaknesses first.]]></description>
      <link>https://safeguard.sh/resources/blog/hacking-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hacking-software</guid>
      <pubDate>Wed, 29 Jul 2026 22:29:14 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Reproducible Builds: Why Bit-for-Bit Identical Matters]]></title>
      <description><![CDATA[If two builds of the same source produce different binaries, you cannot prove what you shipped. How determinism breaks, the flags that fix it, and why auditors care.]]></description>
      <link>https://safeguard.sh/resources/blog/reproducible-builds-why-bit-for-bit-identical-matters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reproducible-builds-why-bit-for-bit-identical-matters</guid>
      <pubDate>Wed, 29 Jul 2026 21:08:47 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Elena Kovacs)</author>
    </item>
    <item>
      <title><![CDATA[XML signature wrapping attacks explained]]></title>
      <description><![CDATA[XML signature wrapping lets attackers forge signed SOAP and SAML messages without breaking the signature. Here's how the attack works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/xml-signature-wrapping-attacks-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xml-signature-wrapping-attacks-explained</guid>
      <pubDate>Wed, 29 Jul 2026 19:48:21 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems Escape Sequence Injection via Crafted API Respon...]]></title>
      <description><![CDATA[CVE-2019-8322 is a RubyGems flaw where crafted API responses could inject terminal escape sequences, spoofing gem output. Here's what to know and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-escape-sequence-injection-via-crafted-api-response-cve-2019-8322</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-escape-sequence-injection-via-crafted-api-response-cve-2019-8322</guid>
      <pubDate>Wed, 29 Jul 2026 18:27:54 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[SSRF via webhooks explained]]></title>
      <description><![CDATA[Webhook SSRF turns a trusted callback feature into an internal network foothold. Here is how the attack works, real incidents, and how to actually fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/ssrf-via-webhooks-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ssrf-via-webhooks-explained</guid>
      <pubDate>Wed, 29 Jul 2026 17:07:27 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems Escape Sequence Injection in Gem Owner Command (...]]></title>
      <description><![CDATA[CVE-2019-8323 shows how RubyGems' gem owner command echoed unsanitized API response data to the terminal, enabling escape sequence injection attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-escape-sequence-injection-in-gem-owner-command-cve-2019-8323</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-escape-sequence-injection-in-gem-owner-command-cve-2019-8323</guid>
      <pubDate>Wed, 29 Jul 2026 15:47:01 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes RBAC misconfiguration explained]]></title>
      <description><![CDATA[RBAC misconfigurations like wildcard rules and default service account bindings have powered real cluster takeovers, from CVE-2018-1002105 to Siloscape.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-rbac-misconfiguration-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-rbac-misconfiguration-explained</guid>
      <pubDate>Wed, 29 Jul 2026 14:26:34 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems Malicious Gem Arbitrary Code Execution via Missi...]]></title>
      <description><![CDATA[CVE-2019-8324 let a malicious RubyGems package run arbitrary code at install time via a crafted multi-line gem name evaluated during the preinstall check.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-malicious-gem-arbitrary-code-execution-via-missing-exception-handling-cve-2019-8324</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-malicious-gem-arbitrary-code-execution-via-missing-exception-handling-cve-2019-8324</guid>
      <pubDate>Wed, 29 Jul 2026 13:06:07 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How to Read a Security Scanning Report Without Drowning in Noise]]></title>
      <description><![CDATA[A security scanning report lists what a scanner found across your code, dependencies, and infrastructure. Here's how to read one, prioritize it, and act on what matters.]]></description>
      <link>https://safeguard.sh/resources/blog/scanning-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scanning-report</guid>
      <pubDate>Wed, 29 Jul 2026 11:45:40 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Is the mammoth npm Package Safe? A DOCX Converter Security Review]]></title>
      <description><![CDATA[The mammoth npm package converts .docx files to HTML, but CVE-2025-11849 showed how a crafted document can read files off your server. Here is what to check.]]></description>
      <link>https://safeguard.sh/resources/blog/mammoth-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mammoth-npm</guid>
      <pubDate>Wed, 29 Jul 2026 10:25:14 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Secrets leakage in Docker images explained]]></title>
      <description><![CDATA[How credentials get baked into Docker image layers, real incidents that exposed them, and how to detect and stop secrets leakage in container images.]]></description>
      <link>https://safeguard.sh/resources/blog/secrets-leakage-in-docker-images-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secrets-leakage-in-docker-images-explained</guid>
      <pubDate>Wed, 29 Jul 2026 09:04:47 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[eslint-plugin-import and import-helpers: Order Your Imports, Catch Mistakes]]></title>
      <description><![CDATA[eslint-plugin-import-helpers gives you fully configurable import ordering; eslint-plugin-import catches the real bugs — unresolved paths, phantom dependencies, cycles. Most codebases want both.]]></description>
      <link>https://safeguard.sh/resources/blog/eslint-plugin-import-helpers-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eslint-plugin-import-helpers-guide</guid>
      <pubDate>Wed, 29 Jul 2026 07:44:20 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems Escape Sequence Injection via Unpack API (CVE-20...]]></title>
      <description><![CDATA[CVE-2019-8325 lets a malicious RubyGems package inject terminal escape sequences via the unpack API. Here's the impact, affected versions, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-escape-sequence-injection-via-unpack-api-cve-2019-8325</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-escape-sequence-injection-via-unpack-api-cve-2019-8325</guid>
      <pubDate>Wed, 29 Jul 2026 06:23:54 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Terraform infrastructure-as-code misconfiguration explained]]></title>
      <description><![CDATA[Terraform misconfigurations — not zero-days — cause most cloud breaches. Here's how they happen, real incidents they caused, and how to catch them pre-deploy.]]></description>
      <link>https://safeguard.sh/resources/blog/terraform-infrastructure-as-code-misconfiguration-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/terraform-infrastructure-as-code-misconfiguration-explained</guid>
      <pubDate>Wed, 29 Jul 2026 05:03:27 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[pip's Version-Based Resolution and the Origin of Dependen...]]></title>
      <description><![CDATA[CVE-2018-20225 exposed how pip's version-based resolver lets a higher-versioned public PyPI package silently override a private one — the origin of dependency confusion attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/pips-version-based-resolution-and-the-origin-of-dependency-confusion-cve-2018-20225</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pips-version-based-resolution-and-the-origin-of-dependency-confusion-cve-2018-20225</guid>
      <pubDate>Wed, 29 Jul 2026 03:43:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Cloud IAM privilege escalation paths explained]]></title>
      <description><![CDATA[A breakdown of how cloud IAM privilege escalation paths work across AWS, GCP, and Azure, with real permission chains and breach examples.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-iam-privilege-escalation-paths-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-iam-privilege-escalation-paths-explained</guid>
      <pubDate>Wed, 29 Jul 2026 02:22:34 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[The torchtriton Dependency Confusion Attack on PyTorch-Ni...]]></title>
      <description><![CDATA[How a namespace gap on PyPI let a malicious "torchtriton" package hijack PyTorch-nightly installs for five days, and what it teaches about ML supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/the-torchtriton-dependency-confusion-attack-on-pytorch-nightly</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-torchtriton-dependency-confusion-attack-on-pytorch-nightly</guid>
      <pubDate>Wed, 29 Jul 2026 01:02:07 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[S3 bucket misconfiguration vulnerabilities explained]]></title>
      <description><![CDATA[S3 misconfigurations have exposed hundreds of millions of records in breaches from Deep Root Analytics to Capital One. Here's how they happen and how to catch them.]]></description>
      <link>https://safeguard.sh/resources/blog/s3-bucket-misconfiguration-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/s3-bucket-misconfiguration-vulnerabilities-explained</guid>
      <pubDate>Tue, 28 Jul 2026 23:41:40 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[The 'ctx' PyPI Package Hijack via Expired Maintainer Domain]]></title>
      <description><![CDATA[In 2022, attackers bought an expired domain, reset a PyPI maintainer's email, and hijacked the ctx package to steal environment variables from unsuspecting installs.]]></description>
      <link>https://safeguard.sh/resources/blog/the-ctx-pypi-package-hijack-via-expired-maintainer-domain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-ctx-pypi-package-hijack-via-expired-maintainer-domain</guid>
      <pubDate>Tue, 28 Jul 2026 22:21:14 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Prompt Injection Detection in Retrieval Systems]]></title>
      <description><![CDATA[Indirect prompt injection arrives through your retrieval corpus, not your chat box. We cover the detection strategies that survive when attackers write your RAG content.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-detection-retrieval-systems</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-detection-retrieval-systems</guid>
      <pubDate>Tue, 28 Jul 2026 21:00:47 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MCP Spec 2025-11-25: Tasks, URL Mode Elicitation, and What Defenders Must Watch]]></title>
      <description><![CDATA[The November 25, 2025 Model Context Protocol release adds Tasks, formalises long-running work, and reshapes the audit story for enterprise MCP.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-spec-2025-11-25-tasks-abstraction-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-spec-2025-11-25-tasks-abstraction-security</guid>
      <pubDate>Tue, 28 Jul 2026 19:40:20 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Prompt injection vulnerabilities in LLM applications explained]]></title>
      <description><![CDATA[Prompt injection is OWASP's #1 LLM risk. See real CVEs like Vanna.AI's RCE flaw and how to detect and stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-vulnerabilities-in-llm-applications-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-vulnerabilities-in-llm-applications-explained</guid>
      <pubDate>Tue, 28 Jul 2026 18:19:53 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[VAPT Tools: The Vulnerability Assessment and Penetration Testing Toolkit]]></title>
      <description><![CDATA[VAPT tools are the software used to run vulnerability assessment and penetration testing. Here is what belongs in the toolkit, how the categories differ, and how to pick the right tool for the job.]]></description>
      <link>https://safeguard.sh/resources/blog/vapt-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vapt-tools</guid>
      <pubDate>Tue, 28 Jul 2026 16:59:27 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Code Security Scanners: Choosing One for Your Stack]]></title>
      <description><![CDATA[The right code security scanner depends less on which vendor's marketing sounds best and more on language coverage, false-positive rate, and whether it fits into the workflow developers already use.]]></description>
      <link>https://safeguard.sh/resources/blog/code-security-scanners-choosing-one</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-security-scanners-choosing-one</guid>
      <pubDate>Tue, 28 Jul 2026 15:39:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Build Artifact?]]></title>
      <description><![CDATA[A build artifact is the packaged output your build process produces from source code. Here is why artifacts are a critical supply chain checkpoint and how to verify their provenance.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-build-artifact</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-build-artifact</guid>
      <pubDate>Tue, 28 Jul 2026 14:18:33 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[node-tar Arbitrary File Write via Symlink Extraction (CVE...]]></title>
      <description><![CDATA[CVE-2021-32803 allows crafted symlinks in tar archives to make node-tar write files outside the extraction directory via malicious npm packages.]]></description>
      <link>https://safeguard.sh/resources/blog/node-tar-arbitrary-file-write-via-symlink-extraction-cve-2021-32803</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-tar-arbitrary-file-write-via-symlink-extraction-cve-2021-32803</guid>
      <pubDate>Tue, 28 Jul 2026 12:58:07 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Python Pickle deserialization risk explained]]></title>
      <description><![CDATA[Pickle deserialization lets attacker-controlled data execute arbitrary code on load. Here's how the exploit works, real CVEs, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/python-pickle-deserialization-risk-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-pickle-deserialization-risk-explained</guid>
      <pubDate>Tue, 28 Jul 2026 11:37:40 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Every Supply Chain Attack of June and July 2026 Was After the Same Thing]]></title>
      <description><![CDATA[Nine incidents in eight weeks: a PyPI worm, typosquatted payment SDKs, jscrambler, AsyncAPI, Hugging Face, Polymarket, Nx Console, Medtronic, AdaptHealth. Nine different vectors, one prize — credentials sitting in developer environments and build pipelines. If you fix one thing this quarter, fix that.]]></description>
      <link>https://safeguard.sh/resources/blog/june-july-2026-supply-chain-attacks-were-all-after-the-same-thing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/june-july-2026-supply-chain-attacks-were-all-after-the-same-thing</guid>
      <pubDate>Tue, 28 Jul 2026 11:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Medtronic and AdaptHealth: The Third Party Was the Vulnerability]]></title>
      <description><![CDATA[3.8 million people notified by Medtronic. PII, PHI and insurance billing credentials exfiltrated at AdaptHealth after social engineering against a third-party contractor. Neither breach needed a software vulnerability — both needed a trusted outsider with a session.]]></description>
      <link>https://safeguard.sh/resources/blog/medtronic-adapthealth-2026-third-party-contractor-access-tprm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/medtronic-adapthealth-2026-third-party-contractor-access-tprm</guid>
      <pubDate>Tue, 28 Jul 2026 10:40:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Eighteen Minutes: The Nx Console Extension Compromise and the IDE Blind Spot]]></title>
      <description><![CDATA[A poisoned VS Code extension was live for eighteen minutes. In that window, auto-update pushed it into every developer environment with Nx Console installed — including a GitHub employee's device, leading to exfiltration of internal GitHub repositories. Your IDE extensions have no SBOM, no review, and a direct push channel to your engineers.]]></description>
      <link>https://safeguard.sh/resources/blog/nx-console-vscode-extension-compromise-ide-supply-chain-blind-spot</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nx-console-vscode-extension-compromise-ide-supply-chain-blind-spot</guid>
      <pubDate>Tue, 28 Jul 2026 10:20:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[node-tar Second Bypass Enabling Arbitrary File Write (CVE...]]></title>
      <description><![CDATA[CVE-2021-32804 let crafted tar archives bypass node-tar path sanitization, enabling arbitrary file writes during npm package extraction.]]></description>
      <link>https://safeguard.sh/resources/blog/node-tar-second-bypass-enabling-arbitrary-file-write-cve-2021-32804</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-tar-second-bypass-enabling-arbitrary-file-write-cve-2021-32804</guid>
      <pubDate>Tue, 28 Jul 2026 10:17:13 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Polymarket Lost ~$3M Without a Single Smart Contract Bug]]></title>
      <description><![CDATA[On 25–26 June 2026 attackers compromised a third-party vendor and injected malicious code into Polymarket's website frontend, manipulating users into approving fraudulent transactions. Roughly $3M in crypto drained. The smart contracts were never touched. Your client-side dependency tree is production.]]></description>
      <link>https://safeguard.sh/resources/blog/polymarket-frontend-compromise-june-2026-client-side-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/polymarket-frontend-compromise-june-2026-client-side-supply-chain</guid>
      <pubDate>Tue, 28 Jul 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Python's .pth Files Are a Code Execution Primitive, and Attackers Noticed]]></title>
      <description><![CDATA[The June 2026 PyPI worm wave used a *-setup.pth file to execute at interpreter startup — before your code, before your imports, on every single python invocation. It then fetched the Bun JavaScript runtime to run its payload. If your supply chain model stops at setup.py, it has a hole in it.]]></description>
      <link>https://safeguard.sh/resources/blog/python-pth-files-startup-code-execution-supply-chain-primitive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-pth-files-startup-code-execution-supply-chain-primitive</guid>
      <pubDate>Tue, 28 Jul 2026 09:40:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[We're Opening Our Channel and White-Label Partner Program Worldwide]]></title>
      <description><![CDATA[Resell it, distribute it, co-sell it, or put your own name on it. Safeguard's partner program is now open in every market outside India and the Middle East — here's how the eight tracks work, what the economics look like, and what we actually expect from a partner.]]></description>
      <link>https://safeguard.sh/resources/blog/opening-our-channel-and-white-label-partner-program-worldwide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/opening-our-channel-and-white-label-partner-program-worldwide</guid>
      <pubDate>Tue, 28 Jul 2026 09:30:00 GMT</pubDate>
      <category>Company</category>
      <author>hi@safeguard.sh (Hritik Kumar Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Seventeen Fake Payment SDKs, Six Minutes to Detection, and a Sandbox Check]]></title>
      <description><![CDATA[On 7 July 2026, roughly 17 typosquatted payment-provider packages hit npm and PyPI — paysafe-checkout, paysafe-node, neteller and friends. They swept environment variables matching KEY, SECRET, TOKEN, PASS, AUTH and API, explicitly hunted AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN and NPM_TOKEN, and exited quietly if they thought they were in a sandbox.]]></description>
      <link>https://safeguard.sh/resources/blog/fake-payment-sdk-typosquats-july-2026-environment-variable-sweeping</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fake-payment-sdk-typosquats-july-2026-environment-variable-sweeping</guid>
      <pubDate>Tue, 28 Jul 2026 09:20:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm v12 Disabled Install Scripts. Attackers Adapted in Three Days.]]></title>
      <description><![CDATA[On 8 July 2026 npm v12 shipped with install scripts off by default — closing what GitHub called the ecosystem's largest code-execution surface. By 11 July, the jscrambler payload was executing on import instead. A study in why one-vector mitigations buy days, not years.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-v12-disabled-install-scripts-attackers-adapted-in-three-days</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-v12-disabled-install-scripts-attackers-adapted-in-three-days</guid>
      <pubDate>Tue, 28 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Java deserialization gadget chains explained]]></title>
      <description><![CDATA[Java deserialization gadget chains turn trusted classpath libraries into RCE. Learn how they work, key CVEs like CVE-2015-4852, and how to detect them.]]></description>
      <link>https://safeguard.sh/resources/blog/java-deserialization-gadget-chains-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-deserialization-gadget-chains-explained</guid>
      <pubDate>Tue, 28 Jul 2026 08:56:47 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[The AsyncAPI Hijack: When Trusted Publishing Becomes the Attack Path]]></title>
      <description><![CDATA[On 14 July 2026 attackers used 37 pull requests against a pull_request_target workflow to steal the asyncapi-bot token, then let npm's OIDC trusted publisher automatically ship the malicious release. Four packages, 2.25 million weekly downloads, four hours live — and no code review was bypassed, because none was required.]]></description>
      <link>https://safeguard.sh/resources/blog/asyncapi-ci-pipeline-hijack-july-2026-oidc-trusted-publishing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/asyncapi-ci-pipeline-hijack-july-2026-oidc-trusted-publishing</guid>
      <pubDate>Tue, 28 Jul 2026 08:40:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Jscrambler npm Compromise Went After Your AI Coding Assistant's Credentials]]></title>
      <description><![CDATA[On 11 July 2026, five versions of the jscrambler package plus its webpack, gulp, grunt and metro plugins shipped malicious native binaries. The payload targeted crypto wallets and the credential stores of Claude Desktop, Cursor and Windsurf — and later versions fired on import, not install, defeating --ignore-scripts.]]></description>
      <link>https://safeguard.sh/resources/blog/jscrambler-npm-compromise-july-2026-ai-assistant-credential-theft</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jscrambler-npm-compromise-july-2026-ai-assistant-credential-theft</guid>
      <pubDate>Tue, 28 Jul 2026 08:20:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Hugging Face Breach: What Changes When an AI Agent Runs the Intrusion]]></title>
      <description><![CDATA[On 16 July 2026 Hugging Face disclosed that a malicious dataset gave an attacker code execution inside its data-processing pipeline, escalating to node-level access and internal cluster credentials over a single weekend — driven by an autonomous agent framework executing thousands of actions. Here's the anatomy, and what it means for anyone who treats a model registry as a trusted input.]]></description>
      <link>https://safeguard.sh/resources/blog/hugging-face-july-2026-breach-agentic-intrusion-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hugging-face-july-2026-breach-agentic-intrusion-analysis</guid>
      <pubDate>Tue, 28 Jul 2026 08:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[node-tar Windows-Specific Path Traversal Bypass (CVE-2021...]]></title>
      <description><![CDATA[CVE-2021-37712 let malicious tar archives bypass node-tar's symlink protections on Windows via junctions, enabling path traversal during npm installs. Here's what to patch.]]></description>
      <link>https://safeguard.sh/resources/blog/node-tar-windows-specific-path-traversal-bypass-cve-2021-37712</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-tar-windows-specific-path-traversal-bypass-cve-2021-37712</guid>
      <pubDate>Tue, 28 Jul 2026 07:36:20 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Regular expression injection explained]]></title>
      <description><![CDATA[Regex injection lets attackers rewrite pattern logic or trigger ReDoS. See real CVEs, exploit examples, and how to detect and fix it in your code.]]></description>
      <link>https://safeguard.sh/resources/blog/regular-expression-injection-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/regular-expression-injection-explained</guid>
      <pubDate>Tue, 28 Jul 2026 06:15:53 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[minimist Prototype Pollution and Its Ripple Effect Across...]]></title>
      <description><![CDATA[CVE-2020-7598 is a prototype pollution bug in minimist that let attackers taint Object.prototype, rippling through thousands of npm dependents.]]></description>
      <link>https://safeguard.sh/resources/blog/minimist-prototype-pollution-and-its-ripple-effect-across-the-npm-tree-cve-2020-7598</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/minimist-prototype-pollution-and-its-ripple-effect-across-the-npm-tree-cve-2020-7598</guid>
      <pubDate>Tue, 28 Jul 2026 04:55:26 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[The ROI of Vulnerability Remediation Automation: Numbers That Justify the Investment]]></title>
      <description><![CDATA[Manual vulnerability remediation costs more than most organizations realize. Breaking down the real costs, time savings, and risk reduction that automation delivers.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-remediation-automation-roi</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-remediation-automation-roi</guid>
      <pubDate>Tue, 28 Jul 2026 03:35:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Argument injection vulnerabilities explained]]></title>
      <description><![CDATA[How argument injection (CWE-88) vulnerabilities work, real CVEs like PHPMailer and Git ssh URLs, and how teams detect and prevent CWE-88 flaws.]]></description>
      <link>https://safeguard.sh/resources/blog/argument-injection-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/argument-injection-vulnerabilities-explained</guid>
      <pubDate>Tue, 28 Jul 2026 02:14:33 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[lodash zipObjectDeep Prototype Pollution (CVE-2020-8203)]]></title>
      <description><![CDATA[CVE-2020-8203 is a prototype pollution flaw in lodash's zipObjectDeep, affecting versions before 4.17.19. Here's the impact, timeline, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/lodash-zipobjectdeep-prototype-pollution-cve-2020-8203</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lodash-zipobjectdeep-prototype-pollution-cve-2020-8203</guid>
      <pubDate>Tue, 28 Jul 2026 00:54:06 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Improper input validation (CWE-20) explained]]></title>
      <description><![CDATA[CWE-20 explained: how improper input validation causes SQLi, RCE, and DoS, with real CVEs like Equifax's Struts breach and how to detect and fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/improper-input-validation-cwe-20-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/improper-input-validation-cwe-20-explained</guid>
      <pubDate>Mon, 27 Jul 2026 23:33:40 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[The tj-actions/changed-files GitHub Action Supply Chain C...]]></title>
      <description><![CDATA[CVE-2025-30066 exposed how a compromised tj-actions/changed-files GitHub Action leaked CI/CD secrets into build logs across 23,000+ repos. Timeline, impact, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/the-tj-actionschanged-files-github-action-supply-chain-compromise-cve-2025-30066</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-tj-actionschanged-files-github-action-supply-chain-compromise-cve-2025-30066</guid>
      <pubDate>Mon, 27 Jul 2026 22:13:13 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Sensitive data exposure in application logs explained]]></title>
      <description><![CDATA[Passwords, tokens, and PII often end up readable in plaintext logs. Here's how CWE-532 exposures happen, real breaches they caused, and how to fix them.]]></description>
      <link>https://safeguard.sh/resources/blog/sensitive-data-exposure-in-application-logs-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sensitive-data-exposure-in-application-logs-explained</guid>
      <pubDate>Mon, 27 Jul 2026 20:52:46 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[The coa and rc npm Maintainer Account Hijack Incident]]></title>
      <description><![CDATA[How the coa and rc npm hijack let attackers seize maintainer accounts on two packages with 20M+ weekly downloads to push Windows password-stealing malware.]]></description>
      <link>https://safeguard.sh/resources/blog/the-coa-and-rc-npm-maintainer-account-hijack-incident</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-coa-and-rc-npm-maintainer-account-hijack-incident</guid>
      <pubDate>Mon, 27 Jul 2026 19:32:20 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[npm prototype pollution trends report 2025]]></title>
      <description><![CDATA[Safeguard's 2025 analysis of npm prototype pollution advisories reveals rising volume, deeper transitive exposure, and why reachability—not CVSS alone—now separates real risk from noise.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-prototype-pollution-trends-report-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-prototype-pollution-trends-report-2025</guid>
      <pubDate>Mon, 27 Jul 2026 18:11:53 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[node-ipc 'Protestware' Sabotage Code Shipped to Millions ...]]></title>
      <description><![CDATA[How a rogue node-ipc update turned a trusted npm dependency into disk-wiping protestware, and what CVE-2022-23812 means for your supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/node-ipc-protestware-sabotage-code-shipped-to-millions-of-installs-cve-2022-23812</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-ipc-protestware-sabotage-code-shipped-to-millions-of-installs-cve-2022-23812</guid>
      <pubDate>Mon, 27 Jul 2026 16:51:26 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[State of npm supply chain attacks]]></title>
      <description><![CDATA[Maintainer phishing, self-propagating worms, and mass-download packages compromised: a look at the npm supply chain attack trends reshaping open source risk.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-npm-supply-chain-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-npm-supply-chain-attacks</guid>
      <pubDate>Mon, 27 Jul 2026 15:31:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Go's 'go get' Remote Code Execution via Crafted Import Pa...]]></title>
      <description><![CDATA[A deep dive into CVE-2018-16873, the Go 'go get' remote code execution vulnerability caused by crafted import paths and command injection in DVCS fetches.]]></description>
      <link>https://safeguard.sh/resources/blog/gos-go-get-remote-code-execution-via-crafted-import-path-cve-2018-16873</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gos-go-get-remote-code-execution-via-crafted-import-path-cve-2018-16873</guid>
      <pubDate>Mon, 27 Jul 2026 14:10:33 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Malicious npm packages targeting developers in 2025]]></title>
      <description><![CDATA[A year-end look at 2025's npm supply chain attacks—chalk/debug phishing, the Shai-Hulud worm, and industrialized malware campaigns—and how to defend against them.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-npm-packages-targeting-developers-in-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-npm-packages-targeting-developers-in-2025</guid>
      <pubDate>Mon, 27 Jul 2026 12:50:06 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Go's 'go get' Directory Traversal via GOPATH Package Path...]]></title>
      <description><![CDATA[CVE-2018-16874: a directory traversal flaw in Go's go get let malicious GOPATH import paths with curly braces write files outside the workspace.]]></description>
      <link>https://safeguard.sh/resources/blog/gos-go-get-directory-traversal-via-gopath-package-path-cve-2018-16874</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gos-go-get-directory-traversal-via-gopath-package-path-cve-2018-16874</guid>
      <pubDate>Mon, 27 Jul 2026 11:29:39 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[npm typosquatting campaigns roundup]]></title>
      <description><![CDATA[A roundup of npm typosquatting campaign patterns, from dependency confusion to AI-tooling lookalikes, and how teams can detect exposure fast.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-typosquatting-campaigns-roundup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-typosquatting-campaigns-roundup</guid>
      <pubDate>Mon, 27 Jul 2026 10:09:13 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Composer Arbitrary Code Execution via Platform Config Han...]]></title>
      <description><![CDATA[CVE-2021-41116 let malicious composer.json platform config values inject PHP code into Composer autoload files, causing code execution on install.]]></description>
      <link>https://safeguard.sh/resources/blog/composer-arbitrary-code-execution-via-platform-config-handling-cve-2021-41116</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/composer-arbitrary-code-execution-via-platform-config-handling-cve-2021-41116</guid>
      <pubDate>Mon, 27 Jul 2026 08:48:46 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[npm postinstall script malware trends]]></title>
      <description><![CDATA[npm postinstall script malware surged 61% in H1 2026. Here's how attackers weaponize lifecycle hooks — and how to detect and stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-postinstall-script-malware-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-postinstall-script-malware-trends</guid>
      <pubDate>Mon, 27 Jul 2026 07:28:19 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Packagist's GitHub Webhook Flaw That Could Have Poisoned ...]]></title>
      <description><![CDATA[A 2022 Packagist webhook vulnerability let a crafted GitHub branch name trigger command injection on Packagist's servers, threatening the entire PHP/Composer supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/packagists-github-webhook-flaw-that-could-have-poisoned-php-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/packagists-github-webhook-flaw-that-could-have-poisoned-php-packages</guid>
      <pubDate>Mon, 27 Jul 2026 06:07:53 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Compromised maintainer accounts on npm]]></title>
      <description><![CDATA[Recent npm maintainer account takeovers show how a single stolen credential can compromise billions of downloads. Here's the anatomy of the threat—and the defense.]]></description>
      <link>https://safeguard.sh/resources/blog/compromised-maintainer-accounts-on-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/compromised-maintainer-accounts-on-npm</guid>
      <pubDate>Mon, 27 Jul 2026 04:47:26 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CocoaPods Trunk Server Remote Code Execution (CVE-2024-38...]]></title>
      <description><![CDATA[CVE-2024-38366 exposed a critical remote code execution flaw in the CocoaPods trunk server, threatening the iOS dependency supply chain for years undetected.]]></description>
      <link>https://safeguard.sh/resources/blog/cocoapods-trunk-server-remote-code-execution-cve-2024-38366</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cocoapods-trunk-server-remote-code-execution-cve-2024-38366</guid>
      <pubDate>Mon, 27 Jul 2026 03:26:59 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CocoaPods Trunk Server Email Verification Bypass Enabling...]]></title>
      <description><![CDATA[CVE-2024-38367 let attackers bypass email verification on the CocoaPods trunk server to take over pod owner accounts, threatening the iOS supply chain. Here's the impact and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/cocoapods-trunk-server-email-verification-bypass-enabling-account-takeover-cve-2024-38367</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cocoapods-trunk-server-email-verification-bypass-enabling-account-takeover-cve-2024-38367</guid>
      <pubDate>Mon, 27 Jul 2026 02:06:33 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Most vulnerable npm packages of the year]]></title>
      <description><![CDATA[Safeguard's 2026 mid-year analysis of the npm registry breaks down the packages driving the most risk and why the same names keep coming back.]]></description>
      <link>https://safeguard.sh/resources/blog/most-vulnerable-npm-packages-of-the-year</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/most-vulnerable-npm-packages-of-the-year</guid>
      <pubDate>Mon, 27 Jul 2026 00:46:06 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CocoaPods Orphaned Pod Takeover Vulnerability (CVE-2024-3...]]></title>
      <description><![CDATA[CVE-2024-38368 let attackers claim orphaned CocoaPods and push malicious code into any iOS or macOS app still depending on them. Here is what to check.]]></description>
      <link>https://safeguard.sh/resources/blog/cocoapods-orphaned-pod-takeover-vulnerability-cve-2024-38368</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cocoapods-orphaned-pod-takeover-vulnerability-cve-2024-38368</guid>
      <pubDate>Sun, 26 Jul 2026 23:25:39 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[npm package hijacking via expired maintainer domains]]></title>
      <description><![CDATA[Attackers are hijacking npm packages by buying up maintainers' expired email domains to reset account passwords — here's how it works and how to detect it.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-package-hijacking-via-expired-maintainer-domains</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-package-hijacking-via-expired-maintainer-domains</guid>
      <pubDate>Sun, 26 Jul 2026 22:05:13 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[NuGet Package Manager Tampering / Spoofing Vulnerability ...]]></title>
      <description><![CDATA[CVE-2019-0757 lets an authenticated attacker tamper with NuGet package contents on Linux/Mac. CVSS 6.5. Affected versions, timeline, and fixes inside.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-package-manager-tampering-spoofing-vulnerability-cve-2019-0757</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-package-manager-tampering-spoofing-vulnerability-cve-2019-0757</guid>
      <pubDate>Sun, 26 Jul 2026 20:44:46 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[A Practical Kubernetes Operator Security Checklist]]></title>
      <description><![CDATA[Kubernetes operators run with broad cluster access. This checklist covers the controls that matter most in 2025, from RBAC scoping to image provenance.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-operator-security-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-operator-security-checklist</guid>
      <pubDate>Sun, 26 Jul 2026 19:24:19 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Node.js runtime CVE roundup]]></title>
      <description><![CDATA[A roundup of Node.js runtime CVEs since 2024 — command injection, HTTP smuggling, permission bypasses, and why runtime flaws evade typical dependency scanners.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-runtime-cve-roundup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-runtime-cve-roundup</guid>
      <pubDate>Sun, 26 Jul 2026 18:03:52 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Apache Maven's Insecure HTTP Repository Resolution Enabli...]]></title>
      <description><![CDATA[CVE-2021-26291 shows how Apache Maven resolved dependencies over plain HTTP, letting a MITM attacker swap in malicious artifacts during the build.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-mavens-insecure-http-repository-resolution-enabling-mitm-code-injection-cve-2021-26291</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-mavens-insecure-http-repository-resolution-enabling-mitm-code-injection-cve-2021-26291</guid>
      <pubDate>Sun, 26 Jul 2026 16:43:26 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[The glob npm Package and CVE-2025-64756: What Happened and How to Fix It]]></title>
      <description><![CDATA[In November 2025 a command-injection flaw in the glob npm CLI lit up scanners across the Node ecosystem. Here is what CVE-2025-64756 actually affects and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/glob-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/glob-npm</guid>
      <pubDate>Sun, 26 Jul 2026 15:22:59 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[PyPI typosquatting and malicious package report]]></title>
      <description><![CDATA[A 2026 look at PyPI typosquatting trends: attack patterns, CI/CD targeting, info-stealer payloads, and how to defend the Python supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-typosquatting-and-malicious-package-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-typosquatting-and-malicious-package-report</guid>
      <pubDate>Sun, 26 Jul 2026 14:02:32 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Apache Ant 'Get' Task Certificate Validation Failure (CVE...]]></title>
      <description><![CDATA[CVE-2020-1945 exposes insecure temp-file handling in Apache Ant, risking data leaks and build-tampering. Affected versions, CVSS/EPSS context, and fixes inside.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-ant-get-task-certificate-validation-failure-cve-2020-1945</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-ant-get-task-certificate-validation-failure-cve-2020-1945</guid>
      <pubDate>Sun, 26 Jul 2026 12:42:06 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Git Argument Injection via Crafted SSH URL (CVE-2017-1000...]]></title>
      <description><![CDATA[CVE-2017-1000117 let a malicious repo run code on anyone who cloned it via a crafted ssh:// URL. Impact, affected Git versions, CVSS, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/git-argument-injection-via-crafted-ssh-url-cve-2017-1000117</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-argument-injection-via-crafted-ssh-url-cve-2017-1000117</guid>
      <pubDate>Sun, 26 Jul 2026 11:21:39 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Git Remote Code Execution via Malicious .gitmodules Submo...]]></title>
      <description><![CDATA[CVE-2018-11235 let a malicious .gitmodules file hijack Git submodule checkout, executing arbitrary code via post-checkout hooks on clone.]]></description>
      <link>https://safeguard.sh/resources/blog/git-remote-code-execution-via-malicious-gitmodules-submodule-url-cve-2018-11235</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-remote-code-execution-via-malicious-gitmodules-submodule-url-cve-2018-11235</guid>
      <pubDate>Sun, 26 Jul 2026 10:01:12 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Git Clone RCE via Symlink Race on Case-Insensitive Filesy...]]></title>
      <description><![CDATA[A patched Git flaw let attackers achieve remote code execution during clone via a symlink race on case-insensitive filesystems. Here's what teams need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/git-clone-rce-via-symlink-race-on-case-insensitive-filesystems-cve-2021-21300</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-clone-rce-via-symlink-race-on-case-insensitive-filesystems-cve-2021-21300</guid>
      <pubDate>Sun, 26 Jul 2026 08:40:46 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Git safe.directory Bypass Enabling Code Execution on Mult...]]></title>
      <description><![CDATA[CVE-2022-24765 let local users on shared Windows systems bypass Git's ownership checks and trigger code execution via malicious repo configs. Here's the full breakdown.]]></description>
      <link>https://safeguard.sh/resources/blog/git-safedirectory-bypass-enabling-code-execution-on-multi-user-windows-cve-2022-24765</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-safedirectory-bypass-enabling-code-execution-on-multi-user-windows-cve-2022-24765</guid>
      <pubDate>Sun, 26 Jul 2026 07:20:19 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Git Local Clone Information Disclosure via Hardlinks (CVE...]]></title>
      <description><![CDATA[CVE-2022-39253 abuses Git's local clone hardlink optimization to leak files from outside a repository. Here's the impact, fix, and how to stay protected.]]></description>
      <link>https://safeguard.sh/resources/blog/git-local-clone-information-disclosure-via-hardlinks-cve-2022-39253</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-local-clone-information-disclosure-via-hardlinks-cve-2022-39253</guid>
      <pubDate>Sun, 26 Jul 2026 05:59:52 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Git Heap Buffer Overflow via GIT_PUSH_OPTION_COUNT (CVE-2...]]></title>
      <description><![CDATA[CVE-2022-39260 is a heap overflow in Git from an integer overflow in GIT_PUSH_OPTION_COUNT during git push. What changed, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/git-heap-buffer-overflow-via-gitpushoptioncount-cve-2022-39260</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-heap-buffer-overflow-via-gitpushoptioncount-cve-2022-39260</guid>
      <pubDate>Sun, 26 Jul 2026 04:39:26 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[vLLM CVE-2025-62164: Tensor Deserialization RCE]]></title>
      <description><![CDATA[vLLM 0.10.2-0.11.0 deserialized user-supplied PyTorch tensors via torch.load() in the Completions API. Memory corruption, potential RCE.]]></description>
      <link>https://safeguard.sh/resources/blog/vllm-cve-2025-62164-memory-corruption</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vllm-cve-2025-62164-memory-corruption</guid>
      <pubDate>Sun, 26 Jul 2026 03:18:59 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[DORA Concentration Risk: ESAs' Designation of Critical ICT Third-Party Providers]]></title>
      <description><![CDATA[DORA Article 31 lets the ESAs designate critical ICT third-party providers (CTPPs) for direct EU-level oversight. First designations land in 2025-2026 from the Register of Information.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-ict-third-party-concentration-risk-ces-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-ict-third-party-concentration-risk-ces-2025</guid>
      <pubDate>Sun, 26 Jul 2026 01:58:32 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Claude Opus 4.5 System Card: Defender Takeaways]]></title>
      <description><![CDATA[Anthropic released Claude Opus 4.5 on November 24, 2025 with the most detailed safety section of any system card to date. We pull out what enterprise defenders should change.]]></description>
      <link>https://safeguard.sh/resources/blog/claude-opus-4-5-system-card-2025-defender-takeaways</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/claude-opus-4-5-system-card-2025-defender-takeaways</guid>
      <pubDate>Sun, 26 Jul 2026 00:38:05 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Jenkins Stapler Unauthenticated RCE Mass-Exploited for Cr...]]></title>
      <description><![CDATA[CVE-2018-1000861 let attackers hit Jenkins Stapler unauthenticated, planting cryptomining malware on exposed CI/CD build servers across the internet.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-stapler-unauthenticated-rce-mass-exploited-for-cryptomining-cve-2018-1000861</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-stapler-unauthenticated-rce-mass-exploited-for-cryptomining-cve-2018-1000861</guid>
      <pubDate>Sat, 25 Jul 2026 23:17:39 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Jenkins CLI Java Deserialization Remote Code Execution (C...]]></title>
      <description><![CDATA[CVE-2017-1000353 let attackers gain unauthenticated RCE on Jenkins via CLI Java deserialization. Here's the impact, timeline, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-cli-java-deserialization-remote-code-execution-cve-2017-1000353</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-cli-java-deserialization-remote-code-execution-cve-2017-1000353</guid>
      <pubDate>Sat, 25 Jul 2026 21:57:12 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Jenkins Remote Code Execution via Groovy Metaclass (CVE-2...]]></title>
      <description><![CDATA[CVE-2016-0792 let attackers bypass Jenkins' deserialization blacklist using Groovy's metaclass to achieve unauthenticated remote code execution via the CLI.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-remote-code-execution-via-groovy-metaclass-cve-2016-0792</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-remote-code-execution-via-groovy-metaclass-cve-2016-0792</guid>
      <pubDate>Sat, 25 Jul 2026 20:36:45 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Jenkins CLI Deserialization RCE via Commons-Collections G...]]></title>
      <description><![CDATA[CVE-2015-8103: unauthenticated RCE in Jenkins CLI via a Commons-Collections deserialization gadget chain. Impact, timeline, and remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-cli-deserialization-rce-via-commons-collections-gadget-cve-2015-8103</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-cli-deserialization-rce-via-commons-collections-gadget-cve-2015-8103</guid>
      <pubDate>Sat, 25 Jul 2026 19:16:19 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AI Model Watermarking and Provenance]]></title>
      <description><![CDATA[Watermarking and provenance are the two most confused terms in AI security. A practical breakdown of what each actually does, where the 2025 techniques break, and what to ship in the meantime.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-model-watermarking-provenance-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-model-watermarking-provenance-techniques</guid>
      <pubDate>Sat, 25 Jul 2026 17:55:52 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Code Security Scan: How to Scan Your Code for Vulnerabilities]]></title>
      <description><![CDATA[A code security scan analyzes your source and its dependencies for security flaws before they ship. Here is how the main scan types work, what tools to use, and how to wire scanning into CI without drowning in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/code-security-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-security-scan</guid>
      <pubDate>Sat, 25 Jul 2026 16:35:25 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard CLI v5: Faster, Smarter, More Extensible]]></title>
      <description><![CDATA[Safeguard CLI v5 brings a rewritten scanning engine, plugin architecture, and native CI/CD integration. Here is what is new and how to upgrade.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-cli-v5-release</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-cli-v5-release</guid>
      <pubDate>Sat, 25 Jul 2026 15:14:59 GMT</pubDate>
      <category>Product Launch</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Jenkins Script Security Sandbox Bypass Leading to RCE (CV...]]></title>
      <description><![CDATA[CVE-2019-1003029 let attackers escape the Jenkins Script Security sandbox and execute arbitrary code via crafted Groovy pipeline scripts.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-script-security-sandbox-bypass-leading-to-rce-cve-2019-1003029</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-script-security-sandbox-bypass-leading-to-rce-cve-2019-1003029</guid>
      <pubDate>Sat, 25 Jul 2026 13:54:32 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Jenkins Arbitrary File Read via Crafted CLI Command (CVE-...]]></title>
      <description><![CDATA[CVE-2018-1999002 let attackers read arbitrary files from Jenkins masters via crafted requests to the Stapler framework, exposing secrets and credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-arbitrary-file-read-via-crafted-cli-command-cve-2018-1999002</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-arbitrary-file-read-via-crafted-cli-command-cve-2018-1999002</guid>
      <pubDate>Sat, 25 Jul 2026 12:34:05 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[TeamCity Authentication Bypass Exploited by Nation-State ...]]></title>
      <description><![CDATA[A critical TeamCity authentication bypass, CVE-2023-42793, let APT29 and North Korean hackers seize build servers for supply chain attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/teamcity-authentication-bypass-exploited-by-nation-state-actors-cve-2023-42793</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/teamcity-authentication-bypass-exploited-by-nation-state-actors-cve-2023-42793</guid>
      <pubDate>Sat, 25 Jul 2026 11:13:39 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[TeamCity Authentication Bypass Enabling Admin Account Cre...]]></title>
      <description><![CDATA[CVE-2024-27198 lets unauthenticated attackers bypass TeamCity login and create admin accounts, with active exploitation and ransomware activity observed.]]></description>
      <link>https://safeguard.sh/resources/blog/teamcity-authentication-bypass-enabling-admin-account-creation-cve-2024-27198</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/teamcity-authentication-bypass-enabling-admin-account-creation-cve-2024-27198</guid>
      <pubDate>Sat, 25 Jul 2026 09:53:12 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[angular.io Security: Keeping Your Angular App Safe in 2025]]></title>
      <description><![CDATA[The docs at angular.io teach safe defaults, but recent CVEs in SSR, the HTTP client, and template sanitization show where the framework still needs your attention.]]></description>
      <link>https://safeguard.sh/resources/blog/angular-io</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/angular-io</guid>
      <pubDate>Sat, 25 Jul 2026 08:32:45 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Securing the .NET NuGet Supply Chain]]></title>
      <description><![CDATA[Package source mapping, packages.lock.json, NuGetAudit and signature verification — .NET ships more built-in supply chain controls than any other ecosystem. Most teams enable none of them.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-the-net-nuget-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-the-net-nuget-supply-chain</guid>
      <pubDate>Sat, 25 Jul 2026 07:12:18 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Elena Kovacs)</author>
    </item>
    <item>
      <title><![CDATA[GitLab Unauthenticated RCE via ExifTool Image Processing ...]]></title>
      <description><![CDATA[CVE-2021-22205 let attackers gain unauthenticated RCE on self-hosted GitLab via ExifTool image parsing. Here's the affected versions, severity, timeline, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-unauthenticated-rce-via-exiftool-image-processing-cve-2021-22205</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-unauthenticated-rce-via-exiftool-image-processing-cve-2021-22205</guid>
      <pubDate>Sat, 25 Jul 2026 05:51:52 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Argo CD Path Traversal via Malicious Helm Chart values.ya...]]></title>
      <description><![CDATA[CVE-2022-24348 let attackers use a malicious Helm chart to path-traverse Argo CD's repo-server, exposing secrets across GitOps applications. Here's the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/argo-cd-path-traversal-via-malicious-helm-chart-valuesyaml-cve-2022-24348</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/argo-cd-path-traversal-via-malicious-helm-chart-valuesyaml-cve-2022-24348</guid>
      <pubDate>Sat, 25 Jul 2026 04:31:25 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Helm 2 Tiller's Default Unauthenticated gRPC Endpoint (CV...]]></title>
      <description><![CDATA[CVE-2019-18658 shows how Helm 2's Tiller ran an unauthenticated gRPC endpoint by default, letting network-adjacent attackers seize cluster-admin control.]]></description>
      <link>https://safeguard.sh/resources/blog/helm-2-tillers-default-unauthenticated-grpc-endpoint-cve-2019-18658</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/helm-2-tillers-default-unauthenticated-grpc-endpoint-cve-2019-18658</guid>
      <pubDate>Sat, 25 Jul 2026 03:10:58 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Helm Chart Repository Index Cache Confusion Vulnerability...]]></title>
      <description><![CDATA[CVE-2021-32690 is a Helm chart repository index cache confusion flaw fixed in 3.6.1 that could push users toward an unintended chart. Here's what matters.]]></description>
      <link>https://safeguard.sh/resources/blog/helm-chart-repository-index-cache-confusion-vulnerability-cve-2021-32690</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/helm-chart-repository-index-cache-confusion-vulnerability-cve-2021-32690</guid>
      <pubDate>Sat, 25 Jul 2026 01:50:32 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SaltStack Authentication Bypass Behind Mass Salt-Master E...]]></title>
      <description><![CDATA[CVE-2020-11651 let unauthenticated attackers hijack Salt masters, triggering mass exploitation within days of disclosure. Here is what happened and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/saltstack-authentication-bypass-behind-mass-salt-master-exploitation-cve-2020-11651</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/saltstack-authentication-bypass-behind-mass-salt-master-exploitation-cve-2020-11651</guid>
      <pubDate>Sat, 25 Jul 2026 00:30:05 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[SaltStack Directory Traversal Paired With Auth Bypass (CV...]]></title>
      <description><![CDATA[CVE-2020-11652, a directory traversal flaw in SaltStack's salt-master, paired with an auth bypass to enable full remote compromise. Impact, CVSS/KEV context, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/saltstack-directory-traversal-paired-with-auth-bypass-cve-2020-11652</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/saltstack-directory-traversal-paired-with-auth-bypass-cve-2020-11652</guid>
      <pubDate>Fri, 24 Jul 2026 23:09:38 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Sonatype Nexus Repository Unauthenticated RCE via REST AP...]]></title>
      <description><![CDATA[A deep dive into CVE-2019-7238, the unauthenticated RCE in Sonatype Nexus Repository Manager 3 that fueled cryptomining campaigns worldwide.]]></description>
      <link>https://safeguard.sh/resources/blog/sonatype-nexus-repository-unauthenticated-rce-via-rest-api-cve-2019-7238</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonatype-nexus-repository-unauthenticated-rce-via-rest-api-cve-2019-7238</guid>
      <pubDate>Fri, 24 Jul 2026 21:49:12 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Nexus Repository Manager 3 Remote Code Execution (CVE-202...]]></title>
      <description><![CDATA[CVE-2020-10199 is a critical Java EL injection flaw in Sonatype Nexus Repository Manager 3 letting authenticated users achieve remote code execution.]]></description>
      <link>https://safeguard.sh/resources/blog/nexus-repository-manager-3-remote-code-execution-cve-2020-10199</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nexus-repository-manager-3-remote-code-execution-cve-2020-10199</guid>
      <pubDate>Fri, 24 Jul 2026 20:28:45 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[vLLM CVE-2025-66448: Auto-Map RCE via Model Configs]]></title>
      <description><![CDATA[A critical RCE in vLLM allows malicious model configs to bypass trust_remote_code=False. We analyze the bug, the patch, and what every vLLM operator should do.]]></description>
      <link>https://safeguard.sh/resources/blog/vllm-cve-2025-66448-auto-map-rce-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vllm-cve-2025-66448-auto-map-rce-analysis</guid>
      <pubDate>Fri, 24 Jul 2026 19:08:18 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Nexus Repository Manager Authenticated RCE via EL Injecti...]]></title>
      <description><![CDATA[CVE-2020-10204 lets an authenticated Nexus Repository Manager user execute arbitrary code via EL injection. Here is what changed and how to respond.]]></description>
      <link>https://safeguard.sh/resources/blog/nexus-repository-manager-authenticated-rce-via-el-injection-cve-2020-10204</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nexus-repository-manager-authenticated-rce-via-el-injection-cve-2020-10204</guid>
      <pubDate>Fri, 24 Jul 2026 17:47:51 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Harbor Registry Privilege Escalation via Self-Registratio...]]></title>
      <description><![CDATA[CVE-2019-16097 let attackers self-register as Harbor admins via a single API call. Here's the impact, affected versions, timeline, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/harbor-registry-privilege-escalation-via-self-registration-cve-2019-16097</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/harbor-registry-privilege-escalation-via-self-registration-cve-2019-16097</guid>
      <pubDate>Fri, 24 Jul 2026 16:27:25 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Harbor Arbitrary File Overwrite via Chart Upload Path Tra...]]></title>
      <description><![CDATA[CVE-2020-13788 let authenticated users overwrite arbitrary files on Harbor via path traversal in Helm chart uploads. Here's the impact, fix, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/harbor-arbitrary-file-overwrite-via-chart-upload-path-traversal-cve-2020-13788</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/harbor-arbitrary-file-overwrite-via-chart-upload-path-traversal-cve-2020-13788</guid>
      <pubDate>Fri, 24 Jul 2026 15:06:58 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Harbor CSRF Token Bypass Enabling Session Hijack (CVE-202...]]></title>
      <description><![CDATA[CVE-2022-31663 let attackers bypass Harbor's CSRF protections to hijack authenticated sessions. Here's the impact, affected versions, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/harbor-csrf-token-bypass-enabling-session-hijack-cve-2022-31663</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/harbor-csrf-token-bypass-enabling-session-hijack-cve-2022-31663</guid>
      <pubDate>Fri, 24 Jul 2026 13:46:31 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cloudflare November 18 2025 Outage: A Bot Management Feature File Doubled in Size]]></title>
      <description><![CDATA[A ClickHouse permissions change caused Cloudflare's Bot Management feature file to balloon past a hard-coded proxy limit, taking the core network down for two hours and ten minutes.]]></description>
      <link>https://safeguard.sh/resources/blog/cloudflare-november-2025-bot-management-outage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloudflare-november-2025-bot-management-outage</guid>
      <pubDate>Fri, 24 Jul 2026 12:26:05 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Project Quay Improper Access Control Exposing Private Ima...]]></title>
      <description><![CDATA[CVE-2020-27838 exposed private container images in Project Quay due to improper access control. Here's what happened, who's affected, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/project-quay-improper-access-control-exposing-private-images-cve-2020-27838</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/project-quay-improper-access-control-exposing-private-images-cve-2020-27838</guid>
      <pubDate>Fri, 24 Jul 2026 11:05:38 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems.org domain takeover risk report]]></title>
      <description><![CDATA[RubyGems.org hasn't adopted the domain-resurrection defenses PyPI rolled out in 2025 — leaving a proven account-takeover technique open across the Ruby ecosystem.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygemsorg-domain-takeover-risk-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygemsorg-domain-takeover-risk-report</guid>
      <pubDate>Fri, 24 Jul 2026 09:45:11 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[runc Container Breakout via /proc/self/exe Overwrite (CVE...]]></title>
      <description><![CDATA[CVE-2019-5736 let a malicious container overwrite the host runc binary, escaping isolation to gain root on the Docker or Kubernetes host.]]></description>
      <link>https://safeguard.sh/resources/blog/runc-container-breakout-via-procselfexe-overwrite-cve-2019-5736</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runc-container-breakout-via-procselfexe-overwrite-cve-2019-5736</guid>
      <pubDate>Fri, 24 Jul 2026 08:24:45 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Ruby supply chain security report]]></title>
      <description><![CDATA[A report on Ruby supply chain security: malicious RubyGems campaigns, maintainer credential compromises, and 2025's RubyGems governance dispute.]]></description>
      <link>https://safeguard.sh/resources/blog/ruby-supply-chain-security-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ruby-supply-chain-security-report</guid>
      <pubDate>Fri, 24 Jul 2026 07:04:18 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[containerd-shim Abstract Unix Socket Exposure Enabling Co...]]></title>
      <description><![CDATA[CVE-2020-15257 lets processes in host-networked containers reach the containerd-shim socket and escape to the host. Impact, affected versions, and fixes explained.]]></description>
      <link>https://safeguard.sh/resources/blog/containerd-shim-abstract-unix-socket-exposure-enabling-container-escape-cve-2020-15257</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/containerd-shim-abstract-unix-socket-exposure-enabling-container-escape-cve-2020-15257</guid>
      <pubDate>Fri, 24 Jul 2026 05:43:51 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Go module proxy vulnerability trends]]></title>
      <description><![CDATA[A backdoor hid in Go's module proxy for 3+ years, and 63,000+ orphaned packages remain cached. Inside 2025's Go supply chain reckoning.]]></description>
      <link>https://safeguard.sh/resources/blog/go-module-proxy-vulnerability-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-module-proxy-vulnerability-trends</guid>
      <pubDate>Fri, 24 Jul 2026 04:23:25 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CRI-O 'cr8escape' Sysctl Injection Container Escape (CVE-...]]></title>
      <description><![CDATA[CVE-2022-0811 (cr8escape) is a CRI-O flaw where an unvalidated sysctl injection let attackers escape containers and gain root on Kubernetes hosts.]]></description>
      <link>https://safeguard.sh/resources/blog/cri-o-cr8escape-sysctl-injection-container-escape-cve-2022-0811</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cri-o-cr8escape-sysctl-injection-container-escape-cve-2022-0811</guid>
      <pubDate>Fri, 24 Jul 2026 03:02:58 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[SLSA v1.2 Source Track: What Changed in November 2025]]></title>
      <description><![CDATA[SLSA v1.2 was approved in November 2025 and finally completes the Source Track that v0.1 only sketched. We break down the new source levels and what producers must change.]]></description>
      <link>https://safeguard.sh/resources/blog/slsa-v1-2-source-track-deep-dive-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slsa-v1-2-source-track-deep-dive-2025</guid>
      <pubDate>Fri, 24 Jul 2026 01:42:31 GMT</pubDate>
      <category>Frameworks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Top 10:2025 RC1: Software Supply Chain Failures Becomes Its Own Category]]></title>
      <description><![CDATA[The OWASP Top 10:2025 release candidate, published November 2025, splits Vulnerable Components into a broader Software Supply Chain Failures category and elevates Security Misconfiguration to #2.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-2025-release-candidate-software-supply-chain-failures</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-2025-release-candidate-software-supply-chain-failures</guid>
      <pubDate>Fri, 24 Jul 2026 00:22:04 GMT</pubDate>
      <category>Frameworks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[LangGraph CVE-2025-64439: When Agent Checkpoints Become RCE]]></title>
      <description><![CDATA[A JsonPlusSerializer fallback in langgraph-checkpoint let attacker-controlled payloads execute arbitrary Python on deserialization. We unpack the bug, the patch, and what agent operators must change.]]></description>
      <link>https://safeguard.sh/resources/blog/langgraph-cve-2025-64439-checkpoint-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/langgraph-cve-2025-64439-checkpoint-rce</guid>
      <pubDate>Thu, 23 Jul 2026 23:01:38 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Gemini 3 Pro and the Frontier Safety Framework Report]]></title>
      <description><![CDATA[Google released Gemini 3 Pro on November 18, 2025 with the most thorough Frontier Safety Framework evaluation yet. We unpack what was disclosed and how it changes downstream defender posture.]]></description>
      <link>https://safeguard.sh/resources/blog/gemini-3-pro-frontier-safety-framework-disclosure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gemini-3-pro-frontier-safety-framework-disclosure</guid>
      <pubDate>Thu, 23 Jul 2026 21:41:11 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Anthropic's Responsible Scaling Policy v3: What Changed]]></title>
      <description><![CDATA[RSP v3.0 takes effect February 24, 2026. It splits the AI R&D threshold, adds a CBRN-development tier, and formalizes Risk Reports.]]></description>
      <link>https://safeguard.sh/resources/blog/anthropic-rsp-v3-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anthropic-rsp-v3-deep-dive</guid>
      <pubDate>Thu, 23 Jul 2026 20:20:44 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[npm Malware Today: The Current Threats and How to Stay Safe]]></title>
      <description><![CDATA[npm malware today means self-spreading worms, infostealers, and typosquatted packages that run on install. Here is what the current campaigns look like and how to defend your builds.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-malware-today</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-malware-today</guid>
      <pubDate>Thu, 23 Jul 2026 19:00:18 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Regulated Industries]]></title>
      <description><![CDATA[Healthcare, finance, energy, and defense face unique supply chain security requirements. Here is how regulated industries should approach SBOM compliance and vulnerability management.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-for-regulated-industries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-for-regulated-industries</guid>
      <pubDate>Thu, 23 Jul 2026 17:39:51 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Malicious Go modules found on GitHub]]></title>
      <description><![CDATA[Malicious Go modules keep surfacing on GitHub, exploiting the ecosystem's lack of a curated registry. Here's the pattern — and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-go-modules-found-on-github</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-go-modules-found-on-github</guid>
      <pubDate>Thu, 23 Jul 2026 16:19:24 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[NVD vs CVE: What's the Difference?]]></title>
      <description><![CDATA[CVE is the list of vulnerability identifiers; the NVD is the enriched database built on top of it. They are related but run by different programs, and confusing them leads to real mistakes.]]></description>
      <link>https://safeguard.sh/resources/blog/nvd-cve</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nvd-cve</guid>
      <pubDate>Thu, 23 Jul 2026 14:58:58 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Docker Vulnerability Scanners: What They Catch and Miss]]></title>
      <description><![CDATA[Image scanners are excellent at matching OS packages and language dependencies against CVE databases — and structurally blind to config flaws, runtime behavior, and code you compiled yourself. Where the line sits.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-vulnerability-scanner-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-vulnerability-scanner-guide</guid>
      <pubDate>Thu, 23 Jul 2026 13:38:31 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE Full Form Explained: What CVE Actually Stands For]]></title>
      <description><![CDATA[The CVE full form is Common Vulnerabilities and Exposures, a public catalog of known security flaws. Here is what the term means, how the IDs work, and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-full-form</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-full-form</guid>
      <pubDate>Thu, 23 Jul 2026 12:18:04 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[BuildKit Privileged Entitlement Check Bypass Enabling Hos...]]></title>
      <description><![CDATA[CVE-2024-23653 lets malicious Dockerfiles bypass BuildKit's privileged entitlement check via the interactive containers API, escaping to the host.]]></description>
      <link>https://safeguard.sh/resources/blog/buildkit-privileged-entitlement-check-bypass-enabling-host-access-cve-2024-23653</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buildkit-privileged-entitlement-check-bypass-enabling-host-access-cve-2024-23653</guid>
      <pubDate>Thu, 23 Jul 2026 10:57:38 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Go vulnerability database (govulncheck) trend report]]></title>
      <description><![CDATA[Go's vulnerability database is scaling fast and stdlib CVEs are clustering. Here's what govulncheck vulnerability trends reveal about reachability, typosquats, and risk.]]></description>
      <link>https://safeguard.sh/resources/blog/go-vulnerability-database-govulncheck-trend-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-vulnerability-database-govulncheck-trend-report</guid>
      <pubDate>Thu, 23 Jul 2026 09:37:11 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[BuildKit Build-Time Container Teardown Arbitrary File Del...]]></title>
      <description><![CDATA[A malicious Dockerfile can exploit CVE-2024-23652 to make BuildKit delete arbitrary host files during build teardown. Here's what's affected and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/buildkit-build-time-container-teardown-arbitrary-file-deletion-cve-2024-23652</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buildkit-build-time-container-teardown-arbitrary-file-deletion-cve-2024-23652</guid>
      <pubDate>Thu, 23 Jul 2026 08:16:44 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Typosquatting in the Go module ecosystem]]></title>
      <description><![CDATA[Typosquatting is surging across the Go module ecosystem, exploiting decentralized import paths and an immutable checksum database that makes takedowns nearly meaningless.]]></description>
      <link>https://safeguard.sh/resources/blog/typosquatting-in-the-go-module-ecosystem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/typosquatting-in-the-go-module-ecosystem</guid>
      <pubDate>Thu, 23 Jul 2026 06:56:17 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[BuildKit Mount Cache Race Condition Vulnerability (CVE-20...]]></title>
      <description><![CDATA[CVE-2024-23651 is a high-severity BuildKit race condition that can expose host files to build containers via shared cache mounts. Here's the full breakdown.]]></description>
      <link>https://safeguard.sh/resources/blog/buildkit-mount-cache-race-condition-vulnerability-cve-2024-23651</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buildkit-mount-cache-race-condition-vulnerability-cve-2024-23651</guid>
      <pubDate>Thu, 23 Jul 2026 05:35:51 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Most vulnerable Go packages report]]></title>
      <description><![CDATA[Safeguard's 2026 analysis ranks the most vulnerable Go packages by exposure-weighted risk, revealing why a handful of core modules drive most CVE impact.]]></description>
      <link>https://safeguard.sh/resources/blog/most-vulnerable-go-packages-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/most-vulnerable-go-packages-report</guid>
      <pubDate>Thu, 23 Jul 2026 04:15:24 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The PHP Source Code Git Server Backdoor Compromise of 2021]]></title>
      <description><![CDATA[In 2021, attackers breached PHP's git server and pushed a backdoor under forged commits from top maintainers. Here's how the PHP git server compromise unfolded.]]></description>
      <link>https://safeguard.sh/resources/blog/the-php-source-code-git-server-backdoor-compromise-of-2021</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-php-source-code-git-server-backdoor-compromise-of-2021</guid>
      <pubDate>Thu, 23 Jul 2026 02:54:57 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-31133 in runc: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[runc container-escape via /proc mount manipulation affects Docker, Kubernetes, and every CRI runtime. Defender playbook below.]]></description>
      <link>https://safeguard.sh/resources/blog/runc-cve-2025-31133-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runc-cve-2025-31133-patch-response</guid>
      <pubDate>Thu, 23 Jul 2026 01:34:31 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Malicious Code Detection: How to Catch Threats in Your Supply Chain]]></title>
      <description><![CDATA[Malicious code detection is the practice of identifying deliberately harmful code in your dependencies, containers, and repositories before it runs. Here is how modern detection actually works.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-code-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-code-detection</guid>
      <pubDate>Thu, 23 Jul 2026 00:14:04 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[ShadowMQ: 30+ RCE Flaws Across AI Inference Engines]]></title>
      <description><![CDATA[Oligo Security disclosed ShadowMQ in November 2025: ZeroMQ-and-pickle deserialization patterns copy-pasted across vLLM, Meta Llama, TensorRT-LLM, and others. We dissect the pattern.]]></description>
      <link>https://safeguard.sh/resources/blog/shadowmq-ai-inference-engine-rce-pattern-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shadowmq-ai-inference-engine-rce-pattern-2025</guid>
      <pubDate>Wed, 22 Jul 2026 22:53:37 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to Choose Vulnerability Assessment Solutions That Actually Reduce Risk]]></title>
      <description><![CDATA[Most vulnerability assessment solutions generate more findings than any team can fix. The right choice depends on what you're protecting — code, dependencies, containers, or infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-assessment-solutions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-assessment-solutions</guid>
      <pubDate>Wed, 22 Jul 2026 21:33:11 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SAST Tooling: How to Choose and Run Static Analysis That Developers Trust]]></title>
      <description><![CDATA[SAST tooling scans your source code for security flaws before it runs, but the tool you pick matters less than how you tune it. Here is how to choose, integrate, and keep the noise down.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-tooling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-tooling</guid>
      <pubDate>Wed, 22 Jul 2026 20:12:44 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to Build a Docker Image for Kubernetes Securely]]></title>
      <description><![CDATA[You do not build Docker images inside Kubernetes the old way anymore. Here are the secure patterns for building images that k8s will run, from CI to in-cluster builders.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-build-docker-image</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-build-docker-image</guid>
      <pubDate>Wed, 22 Jul 2026 18:52:17 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes and Go supply chain risk report]]></title>
      <description><![CDATA[Kubernetes leans on thousands of Go modules. New analysis shows how typosquats and vendored code turn that dependency into real supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-and-go-supply-chain-risk-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-and-go-supply-chain-risk-report</guid>
      <pubDate>Wed, 22 Jul 2026 17:31:51 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Phishing Tools: How Attackers Operate and How to Defend]]></title>
      <description><![CDATA[A defender's overview of phishing tools — the kit categories attackers use, the techniques that make modern campaigns effective, and the controls that actually blunt them.]]></description>
      <link>https://safeguard.sh/resources/blog/phishing-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/phishing-tools</guid>
      <pubDate>Wed, 22 Jul 2026 16:11:24 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[The Six-Month PEAR go-pear.phar Installer Compromise]]></title>
      <description><![CDATA[How a single tampered PEAR go-pear.phar installer sat undetected on pear.php.net for months, what it could do, and what the PHP ecosystem learned about supply chain trust.]]></description>
      <link>https://safeguard.sh/resources/blog/the-six-month-pear-go-pearphar-installer-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-six-month-pear-go-pearphar-installer-compromise</guid>
      <pubDate>Wed, 22 Jul 2026 14:50:57 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Go binary malware distribution trends]]></title>
      <description><![CDATA[Go binaries are now a preferred malware delivery format — statically linked, cross-platform, and hard to fingerprint. Here's what the trend data shows.]]></description>
      <link>https://safeguard.sh/resources/blog/go-binary-malware-distribution-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-binary-malware-distribution-trends</guid>
      <pubDate>Wed, 22 Jul 2026 13:30:30 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The 2019 Docker Hub Database Breach Exposing User Credent...]]></title>
      <description><![CDATA[In April 2019, Docker Hub exposed 190,000 accounts' credentials and GitHub/Bitbucket tokens. Here's what happened, what leaked, and why it still matters for supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/the-2019-docker-hub-database-breach-exposing-user-credentials-and-tokens</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-2019-docker-hub-database-breach-exposing-user-credentials-and-tokens</guid>
      <pubDate>Wed, 22 Jul 2026 12:10:04 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Cloud-native Go services vulnerability landscape]]></title>
      <description><![CDATA[A runc escape trilogy, a gRPC-Go bypass, and a lingering SSH auth flaw reveal how concentrated risk in Go now shapes the cloud native vulnerability landscape.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-native-go-services-vulnerability-landscape</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-native-go-services-vulnerability-landscape</guid>
      <pubDate>Wed, 22 Jul 2026 10:49:37 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best open source SBOM generation tools]]></title>
      <description><![CDATA[A practical, no-hype comparison of open source SBOM generation tools — Syft, Trivy, cdxgen, Microsoft sbom-tool, SPDX Tools, and Tern — plus what to check before you pick one.]]></description>
      <link>https://safeguard.sh/resources/blog/best-open-source-sbom-generation-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-open-source-sbom-generation-tools</guid>
      <pubDate>Wed, 22 Jul 2026 09:29:10 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Go standard library CVE trend report]]></title>
      <description><![CDATA[A trend analysis of Go standard library CVEs from HTTP/2 Rapid Reset to crypto/x509 parsing bugs — and why "it's stdlib" is not a safe-harbor assumption.]]></description>
      <link>https://safeguard.sh/resources/blog/go-standard-library-cve-trend-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-standard-library-cve-trend-report</guid>
      <pubDate>Wed, 22 Jul 2026 08:08:44 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best SBOM management and analysis platforms]]></title>
      <description><![CDATA[A practical buyer's guide to SBOM management platforms in 2026 -- evaluation criteria plus an honest look at six real vendors and where each one falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/best-sbom-management-and-analysis-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-sbom-management-and-analysis-platforms</guid>
      <pubDate>Wed, 22 Jul 2026 06:48:17 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Training Data Provenance for Enterprise Fine-Tuning]]></title>
      <description><![CDATA[Fine-tuning corpora are supply chain artifacts. We cover the provenance signals, attestations, and drift controls enterprises need before pushing weights to prod.]]></description>
      <link>https://safeguard.sh/resources/blog/training-data-provenance-enterprise-fine-tuning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/training-data-provenance-enterprise-fine-tuning</guid>
      <pubDate>Wed, 22 Jul 2026 05:27:50 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Go module checksum database bypass risks]]></title>
      <description><![CDATA[Go's GOSUMDB checksum verification is meant to be on by default, but Safeguard's research found roughly 1 in 6 CI pipelines quietly disable it.]]></description>
      <link>https://safeguard.sh/resources/blog/go-module-checksum-database-bypass-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-module-checksum-database-bypass-risks</guid>
      <pubDate>Wed, 22 Jul 2026 04:07:24 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Rogue AI Agents: When Autonomous Systems Act Outside Inte...]]></title>
      <description><![CDATA[Autonomous AI agents are gaining real access to production systems — and real incidents, from deleted databases to fabricated refunds, show what happens when they act outside intended boundaries.]]></description>
      <link>https://safeguard.sh/resources/blog/rogue-ai-agents-when-autonomous-systems-act-outside-intended-boundaries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rogue-ai-agents-when-autonomous-systems-act-outside-intended-boundaries</guid>
      <pubDate>Wed, 22 Jul 2026 02:46:57 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best secrets scanning tools for CI/CD pipelines]]></title>
      <description><![CDATA[A practical, no-hype comparison of secrets scanning tools for CI/CD: what gitleaks, TruffleHog, and GitGuardian catch, and where each one falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/best-secrets-scanning-tools-for-cicd-pipelines</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-secrets-scanning-tools-for-cicd-pipelines</guid>
      <pubDate>Wed, 22 Jul 2026 01:26:30 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Docker Hub malicious image report]]></title>
      <description><![CDATA[Researchers estimate roughly 3% of public Docker Hub images carry malicious payloads. Here's what's inside them, how they spread, and how to defend your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-hub-malicious-image-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-hub-malicious-image-report</guid>
      <pubDate>Wed, 22 Jul 2026 00:06:04 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Human-Agent Trust Exploitation in AI Systems]]></title>
      <description><![CDATA[Attackers are exploiting the trust between humans and AI agents — hidden prompt injections, hallucinated packages, and over-trusted autonomy are now supply chain risks.]]></description>
      <link>https://safeguard.sh/resources/blog/human-agent-trust-exploitation-in-ai-systems</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/human-agent-trust-exploitation-in-ai-systems</guid>
      <pubDate>Tue, 21 Jul 2026 22:45:37 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best secrets detection tools for source code repositories]]></title>
      <description><![CDATA[A practical, no-hype comparison of secrets detection tools for source code repos — evaluation criteria, five real vendors reviewed fairly, and how Safeguard fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/best-secrets-detection-tools-for-source-code-repositories</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-secrets-detection-tools-for-source-code-repositories</guid>
      <pubDate>Tue, 21 Jul 2026 21:25:10 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Top vulnerable base images on Docker Hub]]></title>
      <description><![CDATA[A look at why Docker Hub's most-pulled base images still ship hundreds of known CVEs, and how reachability analysis cuts the noise down to what's actually exploitable.]]></description>
      <link>https://safeguard.sh/resources/blog/top-vulnerable-base-images-on-docker-hub</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-vulnerable-base-images-on-docker-hub</guid>
      <pubDate>Tue, 21 Jul 2026 20:04:43 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Cascading Failures in Multi-Agent AI Architectures]]></title>
      <description><![CDATA[One compromised agent can poison an entire pipeline in seconds. Heres how cascading failures spread through multi-agent AI systems, and how to contain them.]]></description>
      <link>https://safeguard.sh/resources/blog/cascading-failures-in-multi-agent-ai-architectures</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cascading-failures-in-multi-agent-ai-architectures</guid>
      <pubDate>Tue, 21 Jul 2026 18:44:17 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best SLSA-compliant build systems]]></title>
      <description><![CDATA[A fair comparison of SLSA compliant build systems—GitHub Actions, Cloud Build, GitLab, Tekton Chains—with real strengths and limitations for Build Level 3.]]></description>
      <link>https://safeguard.sh/resources/blog/best-slsa-compliant-build-systems</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-slsa-compliant-build-systems</guid>
      <pubDate>Tue, 21 Jul 2026 17:23:50 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Cryptomining malware hidden in public Docker images]]></title>
      <description><![CDATA[Cryptomining malware keeps resurfacing in public Docker images. Here's how attackers hide miners in plain sight — and how to catch them before they run.]]></description>
      <link>https://safeguard.sh/resources/blog/cryptomining-malware-hidden-in-public-docker-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cryptomining-malware-hidden-in-public-docker-images</guid>
      <pubDate>Tue, 21 Jul 2026 16:03:23 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Insecure Inter-Agent Communication in Multi-Agent Systems]]></title>
      <description><![CDATA[Multi-agent AI pipelines pass untrusted content between agents with no authentication or integrity checks. Here's how insecure inter-agent communication opens the door to injection attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/insecure-inter-agent-communication-in-multi-agent-systems</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insecure-inter-agent-communication-in-multi-agent-systems</guid>
      <pubDate>Tue, 21 Jul 2026 14:42:57 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best software supply chain attestation tools]]></title>
      <description><![CDATA[A practical, no-hype comparison of software supply chain attestation tools — in-toto, Sigstore, GUAC, GitHub, JFrog, and Chainguard — plus how to pick the right fit.]]></description>
      <link>https://safeguard.sh/resources/blog/best-software-supply-chain-attestation-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-software-supply-chain-attestation-tools</guid>
      <pubDate>Tue, 21 Jul 2026 13:22:30 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Docker Hub typosquatting of official images]]></title>
      <description><![CDATA[Attackers are cloning popular Docker Official Images under lookalike names, tricking `docker pull` into fetching malware instead of trusted base images.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-hub-typosquatting-of-official-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-hub-typosquatting-of-official-images</guid>
      <pubDate>Tue, 21 Jul 2026 12:02:03 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Uncontrolled Recursion in AI Agent Loops]]></title>
      <description><![CDATA[AI agents can call themselves into runaway loops, burning thousands of dollars and crashing services. Here's why it happens and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/uncontrolled-recursion-in-ai-agent-loops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uncontrolled-recursion-in-ai-agent-loops</guid>
      <pubDate>Tue, 21 Jul 2026 10:41:37 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best container image scanning tools]]></title>
      <description><![CDATA[A practical comparison of container image scanning tools — Trivy, Grype, Snyk, Docker Scout, Clair, and Anchore — with real strengths, limits, and how to pick one.]]></description>
      <link>https://safeguard.sh/resources/blog/best-container-image-scanning-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-container-image-scanning-tools</guid>
      <pubDate>Tue, 21 Jul 2026 09:21:10 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Container image supply chain attack trends]]></title>
      <description><![CDATA[Container images have become the software supply chain's most contested attack surface. A look at the xz-utils backdoor, registry-borne malware campaigns, and the detection gaps behind them.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-supply-chain-attack-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-supply-chain-attack-trends</guid>
      <pubDate>Tue, 21 Jul 2026 08:00:43 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Memory and Context Poisoning Attacks Against AI Agents]]></title>
      <description><![CDATA[How attackers poisoned ChatGPT's memory and RAG pipelines to hijack AI agents long-term, and the controls Safeguard uses to catch it before it spreads.]]></description>
      <link>https://safeguard.sh/resources/blog/memory-and-context-poisoning-attacks-against-ai-agents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/memory-and-context-poisoning-attacks-against-ai-agents</guid>
      <pubDate>Tue, 21 Jul 2026 06:40:16 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best Kubernetes security scanning tools]]></title>
      <description><![CDATA[A practical, no-fluff comparison of Kubernetes security scanning tools — CIS benchmark coverage, runtime detection, and where each real vendor falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/best-kubernetes-security-scanning-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-kubernetes-security-scanning-tools</guid>
      <pubDate>Tue, 21 Jul 2026 05:19:50 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Alpine vs Debian base image vulnerability comparison]]></title>
      <description><![CDATA[A 2026 look at Alpine vs. Debian base image CVEs shows raw vulnerability counts mislead — patch cadence and reachability matter more than distro choice.]]></description>
      <link>https://safeguard.sh/resources/blog/alpine-vs-debian-base-image-vulnerability-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/alpine-vs-debian-base-image-vulnerability-comparison</guid>
      <pubDate>Tue, 21 Jul 2026 03:59:23 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Best open source software composition analysis (SCA) tools]]></title>
      <description><![CDATA[A practical comparison of the best open source SCA tools — vulnerability coverage, license scanning, and CI/CD fit — with honest strengths and limitations for each.]]></description>
      <link>https://safeguard.sh/resources/blog/best-open-source-software-composition-analysis-sca-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-open-source-software-composition-analysis-sca-tools</guid>
      <pubDate>Tue, 21 Jul 2026 02:38:56 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Agentic Unexpected Code Execution Vulnerabilities]]></title>
      <description><![CDATA[How AI agents with code-execution tools get hijacked by prompt injection—from the Vanna.ai RCE (CVE-2024-5565) to LangChain and MCP—and what to do about it.]]></description>
      <link>https://safeguard.sh/resources/blog/agentic-unexpected-code-execution-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agentic-unexpected-code-execution-vulnerabilities</guid>
      <pubDate>Tue, 21 Jul 2026 01:18:30 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Outdated container images still running in production]]></title>
      <description><![CDATA[New industry data shows most production containers still run on stale, vulnerable base images months after fixes ship -- here's why, and how to close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/outdated-container-images-still-running-in-production</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/outdated-container-images-still-running-in-production</guid>
      <pubDate>Mon, 20 Jul 2026 23:58:03 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Best SAST tools for enterprise applications]]></title>
      <description><![CDATA[A practical buyer's guide comparing top SAST tools for enterprise apps -- strengths, limitations, and how Safeguard unifies findings across your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/best-sast-tools-for-enterprise-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-sast-tools-for-enterprise-applications</guid>
      <pubDate>Mon, 20 Jul 2026 22:37:36 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Agentic AI Supply Chain Vulnerabilities]]></title>
      <description><![CDATA[Agentic AI systems trust tools and models at runtime, not build time. Real 2024-2025 incidents show how MCP servers and AI packages become supply chain attack vectors.]]></description>
      <link>https://safeguard.sh/resources/blog/agentic-ai-supply-chain-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agentic-ai-supply-chain-vulnerabilities</guid>
      <pubDate>Mon, 20 Jul 2026 21:17:10 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Container registry credential leak trends]]></title>
      <description><![CDATA[2026 data shows container registry credential leaks accelerating as CI pipelines speed up — and why layer-aware scanning, not just final-image checks, is now essential.]]></description>
      <link>https://safeguard.sh/resources/blog/container-registry-credential-leak-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-registry-credential-leak-trends</guid>
      <pubDate>Mon, 20 Jul 2026 19:56:43 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best DAST tools for web application security testing]]></title>
      <description><![CDATA[A practical comparison of DAST tools -- from OWASP ZAP to Invicti -- covering real strengths, limitations, and what Safeguard adds beyond runtime scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/best-dast-tools-for-web-application-security-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-dast-tools-for-web-application-security-testing</guid>
      <pubDate>Mon, 20 Jul 2026 18:36:16 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Agentic Identity and Privilege Abuse]]></title>
      <description><![CDATA[AI agents now inherit more privilege than they need — and incidents like the Microsoft 38TB SAS-token leak and ServiceNow's Now Assist flaw show what happens when that privilege gets abused.]]></description>
      <link>https://safeguard.sh/resources/blog/agentic-identity-and-privilege-abuse</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agentic-identity-and-privilege-abuse</guid>
      <pubDate>Mon, 20 Jul 2026 17:15:50 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Distroless image security trend report]]></title>
      <description><![CDATA[Distroless adoption is up nearly 3x since 2024, but Safeguard's 2026 scan data shows SBOM gaps, missed dependencies, and inflated CVE lists still undermine the hardening it promises.]]></description>
      <link>https://safeguard.sh/resources/blog/distroless-image-security-trend-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/distroless-image-security-trend-report</guid>
      <pubDate>Mon, 20 Jul 2026 15:55:23 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best IAST tools for runtime application security testing]]></title>
      <description><![CDATA[A practical, no-fluff comparison of IAST tools for runtime application security testing — evaluation criteria, honest vendor tradeoffs, and where supply chain risk still slips through.]]></description>
      <link>https://safeguard.sh/resources/blog/best-iast-tools-for-runtime-application-security-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-iast-tools-for-runtime-application-security-testing</guid>
      <pubDate>Mon, 20 Jul 2026 14:34:56 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Agent Tool Misuse and Exploitation]]></title>
      <description><![CDATA[Attackers don't need to hack AI agents — they just redirect their own tools. Here's how tool misuse works, real 2025 incidents, and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/agent-tool-misuse-and-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agent-tool-misuse-and-exploitation</guid>
      <pubDate>Mon, 20 Jul 2026 13:14:29 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Helm chart vulnerability trends]]></title>
      <description><![CDATA[New Safeguard research finds most public Helm charts ship risky defaults and stale image pins—here's what the data shows and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-helm-chart-vulnerability-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-helm-chart-vulnerability-trends</guid>
      <pubDate>Mon, 20 Jul 2026 11:54:03 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best Infrastructure as Code (IaC) security scanning tools]]></title>
      <description><![CDATA[A practical, no-hype comparison of IaC security scanning tools — Checkov, tfsec/Trivy, Terrascan, Snyk IaC, KICS, and cfn-guard — with real strengths and limitations.]]></description>
      <link>https://safeguard.sh/resources/blog/best-infrastructure-as-code-iac-security-scanning-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-infrastructure-as-code-iac-security-scanning-tools</guid>
      <pubDate>Mon, 20 Jul 2026 10:33:36 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Agent Goal Hijacking: Redirecting Autonomous AI Objectives]]></title>
      <description><![CDATA[Attackers are hijacking autonomous AI agents by planting instructions in content they read—no exploit needed. Here's how it works, real 2025 incidents, and defenses.]]></description>
      <link>https://safeguard.sh/resources/blog/agent-goal-hijacking-redirecting-autonomous-ai-objectives</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agent-goal-hijacking-redirecting-autonomous-ai-objectives</guid>
      <pubDate>Mon, 20 Jul 2026 09:13:09 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[NuGet package vulnerability trends report]]></title>
      <description><![CDATA[NuGet's growing attack surface: typosquatting, steganographic malware, and patch lag are reshaping .NET supply chain risk in 2026 — here's what the data shows.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-package-vulnerability-trends-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-package-vulnerability-trends-report</guid>
      <pubDate>Mon, 20 Jul 2026 07:52:43 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best Terraform security and compliance tools]]></title>
      <description><![CDATA[A practical, no-hype comparison of Terraform security tools — Checkov, tfsec/Trivy, Terrascan, Sentinel, Snyk IaC, and more — plus how Safeguard fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/best-terraform-security-and-compliance-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-terraform-security-and-compliance-tools</guid>
      <pubDate>Mon, 20 Jul 2026 06:32:16 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-64446 in Fortinet FortiWeb: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[FortiWeb path traversal + RCE scored CVSS 9.1 and entered CISA KEV after months of targeted exploitation. Defender playbook for the WAF emergency.]]></description>
      <link>https://safeguard.sh/resources/blog/fortiweb-cve-2025-64446-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fortiweb-cve-2025-64446-patch-response</guid>
      <pubDate>Mon, 20 Jul 2026 05:11:49 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Malicious NuGet packages targeting .NET developers]]></title>
      <description><![CDATA[A fresh wave of malicious NuGet packages is hitting .NET developers via typosquatting, MSBuild-triggered code, and IL weaving. Here's what's happening and how to respond.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-nuget-packages-targeting-net-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-nuget-packages-targeting-net-developers</guid>
      <pubDate>Mon, 20 Jul 2026 03:51:23 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[LLM Misinformation: Security Risks of Hallucinated Outputs]]></title>
      <description><![CDATA[LLM hallucinations aren't just AI trivia — they invent packages attackers squat on, fake CVEs, and false advisories that have already cost real companies real money.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-misinformation-security-risks-of-hallucinated-outputs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-misinformation-security-risks-of-hallucinated-outputs</guid>
      <pubDate>Mon, 20 Jul 2026 02:30:56 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best cloud security posture management (CSPM) tools]]></title>
      <description><![CDATA[A practical buyer's guide to CSPM tools: evaluation criteria that matter, a fair comparison of six leading vendors, and where supply chain security fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/best-cloud-security-posture-management-cspm-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-cloud-security-posture-management-cspm-tools</guid>
      <pubDate>Mon, 20 Jul 2026 01:10:29 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[.NET deserialization vulnerability landscape]]></title>
      <description><![CDATA[A look at the .NET deserialization vulnerability landscape — from the 2025 ASP.NET machine key crisis to BinaryFormatter's retirement and Telerik exploits.]]></description>
      <link>https://safeguard.sh/resources/blog/net-deserialization-vulnerability-landscape</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/net-deserialization-vulnerability-landscape</guid>
      <pubDate>Sun, 19 Jul 2026 23:50:03 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[LLM Unbounded Consumption: Resource Exhaustion Attacks]]></title>
      <description><![CDATA[How attackers exploit token-based pricing and growing context windows to exhaust LLM compute and inflate cloud bills — and the concrete limits that stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-unbounded-consumption-resource-exhaustion-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-unbounded-consumption-resource-exhaustion-attacks</guid>
      <pubDate>Sun, 19 Jul 2026 22:29:36 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best cloud workload protection platforms (CWPP)]]></title>
      <description><![CDATA[An honest, no-hype comparison of leading cloud workload protection platforms — evaluation criteria, real vendor tradeoffs, and where supply chain security fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/best-cloud-workload-protection-platforms-cwpp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-cloud-workload-protection-platforms-cwpp</guid>
      <pubDate>Sun, 19 Jul 2026 21:09:09 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[NuGet typosquatting campaign report]]></title>
      <description><![CDATA[Four disclosed NuGet typosquatting campaigns since 2024 reveal a shift toward patient, audience-specific attacks — from ICS time bombs to wallet-draining homoglyphs.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-typosquatting-campaign-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-typosquatting-campaign-report</guid>
      <pubDate>Sun, 19 Jul 2026 19:48:42 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[LLM Vector and Embedding Weaknesses]]></title>
      <description><![CDATA[Embeddings aren't anonymized math — Vec2Text recovers 92% of text from vectors, and OWASP's LLM08:2025 now names inversion, poisoning, and exposed vector DBs as core AI risks.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-vector-and-embedding-weaknesses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-vector-and-embedding-weaknesses</guid>
      <pubDate>Sun, 19 Jul 2026 18:28:16 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best CI/CD pipeline security tools]]></title>
      <description><![CDATA[A fair, no-hype buyer's guide to CI/CD pipeline security tools: what to evaluate, six real vendors compared, and where Safeguard fits in the stack.]]></description>
      <link>https://safeguard.sh/resources/blog/best-cicd-pipeline-security-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-cicd-pipeline-security-tools</guid>
      <pubDate>Sun, 19 Jul 2026 17:07:49 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Compromised NuGet author accounts]]></title>
      <description><![CDATA[NuGet maintainer accounts are the .NET supply chain's weakest link. Here's why account takeover beats typosquatting, and how to detect it before a CVE exists.]]></description>
      <link>https://safeguard.sh/resources/blog/compromised-nuget-author-accounts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/compromised-nuget-author-accounts</guid>
      <pubDate>Sun, 19 Jul 2026 15:47:22 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[LLM System Prompt Leakage]]></title>
      <description><![CDATA[System prompts often hide business logic and secrets. Here's how attackers extract them, real 2023-2024 incidents, and how to stop leaks before they reach production.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-system-prompt-leakage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-system-prompt-leakage</guid>
      <pubDate>Sun, 19 Jul 2026 14:26:56 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best GitHub Actions security scanning tools]]></title>
      <description><![CDATA[A practical, no-hype comparison of GitHub Actions security tools — Zizmor, StepSecurity, Scorecard, Checkov, GitGuardian, and Legit Security — plus what to evaluate before you buy.]]></description>
      <link>https://safeguard.sh/resources/blog/best-github-actions-security-scanning-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-github-actions-security-scanning-tools</guid>
      <pubDate>Sun, 19 Jul 2026 13:06:29 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The GNU Affero General Public License v3.0, Explained]]></title>
      <description><![CDATA[The GNU Affero General Public License v3.0 extends GPLv3 copyleft to software used over a network. Here is what AGPLv3 requires and how it differs from GPLv3.]]></description>
      <link>https://safeguard.sh/resources/blog/gnu-affero-general-public-license-v3-0</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gnu-affero-general-public-license-v3-0</guid>
      <pubDate>Sun, 19 Jul 2026 11:46:02 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Basic Hacking Skills for Aspiring Security Engineers]]></title>
      <description><![CDATA[The basic hacking skills that underpin ethical security work — networking, Linux, scripting, and web fundamentals — and how to build them legally and safely.]]></description>
      <link>https://safeguard.sh/resources/blog/basic-hacking-skills</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/basic-hacking-skills</guid>
      <pubDate>Sun, 19 Jul 2026 10:25:36 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Broker: How the On-Premise Connector Secures Access]]></title>
      <description><![CDATA[Snyk Broker is the proxy that lets a SaaS scanner reach your on-prem Git without opening inbound ports. Here is how it works and what to lock down.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-broker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-broker</guid>
      <pubDate>Sun, 19 Jul 2026 09:05:09 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Most vulnerable .NET libraries report]]></title>
      <description><![CDATA[Safeguard's H1 2026 analysis of 41,000+ .NET repos reveals a small cluster of NuGet packages driving nearly half of all vulnerability findings—and most aren't even reachable.]]></description>
      <link>https://safeguard.sh/resources/blog/most-vulnerable-net-libraries-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/most-vulnerable-net-libraries-report</guid>
      <pubDate>Sun, 19 Jul 2026 07:44:42 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Model Theft: Protecting Proprietary LLMs from Extraction ...]]></title>
      <description><![CDATA[A $20 API attack can clone a production LLM's embeddings. Here's how model extraction works, real incidents from LLaMA to DeepSeek, and how to protect proprietary models.]]></description>
      <link>https://safeguard.sh/resources/blog/model-theft-protecting-proprietary-llms-from-extraction-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/model-theft-protecting-proprietary-llms-from-extraction-attacks</guid>
      <pubDate>Sun, 19 Jul 2026 06:24:16 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best vulnerability management platforms]]></title>
      <description><![CDATA[A practical comparison of leading vulnerability management platforms — Tenable, Qualys, Rapid7, CrowdStrike, Wiz, and Microsoft — plus how Safeguard closes the supply-chain gap.]]></description>
      <link>https://safeguard.sh/resources/blog/best-vulnerability-management-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-vulnerability-management-platforms</guid>
      <pubDate>Sun, 19 Jul 2026 05:03:49 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[ASP.NET Core vulnerability trends]]></title>
      <description><![CDATA[A data-driven look at ASP.NET Core's recurring CVE patterns — DoS in Kestrel/SignalR, deserialization bugs, and NuGet supply chain risk — and how to triage what matters.]]></description>
      <link>https://safeguard.sh/resources/blog/aspnet-core-vulnerability-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aspnet-core-vulnerability-trends</guid>
      <pubDate>Sun, 19 Jul 2026 03:43:22 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[LLM Supply Chain Vulnerabilities]]></title>
      <description><![CDATA[Malicious model files, poisoned datasets, and compromised ML packages are the new software supply chain frontier. Here is how these LLM attacks actually work.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-supply-chain-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-supply-chain-vulnerabilities</guid>
      <pubDate>Sun, 19 Jul 2026 02:22:55 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best CVE tracking and monitoring tools]]></title>
      <description><![CDATA[A field guide to CVE tracking tools -- from NVD and OSV.dev to Snyk, Tenable, and Qualys -- with honest pros, cons, and how Safeguard adds supply-chain context.]]></description>
      <link>https://safeguard.sh/resources/blog/best-cve-tracking-and-monitoring-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-cve-tracking-and-monitoring-tools</guid>
      <pubDate>Sun, 19 Jul 2026 01:02:29 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[NuGet dependency confusion risk report]]></title>
      <description><![CDATA[NuGet's default feed-resolution behavior keeps dependency confusion risk elevated across .NET orgs. Here's what the incident history shows, and how to close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-dependency-confusion-risk-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-dependency-confusion-risk-report</guid>
      <pubDate>Sat, 18 Jul 2026 23:42:02 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Training Data Poisoning Attacks on Machine Learning Models]]></title>
      <description><![CDATA[A $60 domain purchase or 0.001% of training tokens can silently corrupt an ML model. Here's how training data poisoning attacks work and how to defend against them.]]></description>
      <link>https://safeguard.sh/resources/blog/training-data-poisoning-attacks-on-machine-learning-models</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/training-data-poisoning-attacks-on-machine-learning-models</guid>
      <pubDate>Sat, 18 Jul 2026 22:21:35 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best open source license compliance tools]]></title>
      <description><![CDATA[A practical comparison of open source license compliance tools—FOSSA, Mend, Black Duck, Snyk, and more—covering detection accuracy, policy engines, and SBOM support.]]></description>
      <link>https://safeguard.sh/resources/blog/best-open-source-license-compliance-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-open-source-license-compliance-tools</guid>
      <pubDate>Sat, 18 Jul 2026 21:01:09 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Composer package vulnerability trends report]]></title>
      <description><![CDATA[Composer package vulnerabilities rose 34% YoY, with 60%+ arriving via transitive dependencies. Safeguard breaks down the trends and what security teams should do.]]></description>
      <link>https://safeguard.sh/resources/blog/composer-package-vulnerability-trends-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/composer-package-vulnerability-trends-report</guid>
      <pubDate>Sat, 18 Jul 2026 19:40:42 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Sensitive Information Disclosure in LLM Applications]]></title>
      <description><![CDATA[From Samsung's ChatGPT leak to RAG pipelines with no access controls, sensitive information disclosure is now a top LLM security risk. Here's how it happens and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/sensitive-information-disclosure-in-llm-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sensitive-information-disclosure-in-llm-applications</guid>
      <pubDate>Sat, 18 Jul 2026 18:20:15 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best artifact and code signing tools]]></title>
      <description><![CDATA[A practical, no-hype comparison of Sigstore, Notation, GitHub Attestations, DigiCert, Vault, and AWS Signer for teams choosing artifact signing tools.]]></description>
      <link>https://safeguard.sh/resources/blog/best-artifact-and-code-signing-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-artifact-and-code-signing-tools</guid>
      <pubDate>Sat, 18 Jul 2026 16:59:49 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is Application Security Monitoring and How Do You Do It Well?]]></title>
      <description><![CDATA[Application security monitoring is the continuous observation of an application's behavior to detect attacks, abuse, and security failures as they happen. Here is what to monitor and how to make signals actionable.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-monitoring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-monitoring</guid>
      <pubDate>Sat, 18 Jul 2026 15:39:22 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What STATUS_STACK_BUFFER_OVERRUN (0xC0000409) Really Means]]></title>
      <description><![CDATA[The misleadingly named STATUS_STACK_BUFFER_OVERRUN rarely means an active attack — it means a program chose to kill itself the instant it stopped trusting its own memory.]]></description>
      <link>https://safeguard.sh/resources/blog/status-stack-buffer-overrun</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/status-stack-buffer-overrun</guid>
      <pubDate>Sat, 18 Jul 2026 14:18:55 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Choosing a Secrets Scanning Tool That Actually Catches Leaks]]></title>
      <description><![CDATA[A secrets scanning tool finds API keys, tokens, and passwords hiding in your code and git history. Here is how they work and what to look for in one.]]></description>
      <link>https://safeguard.sh/resources/blog/secrets-scanning-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secrets-scanning-tool</guid>
      <pubDate>Sat, 18 Jul 2026 12:58:28 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Docker Scratch Image: The Security Case for Empty Bases]]></title>
      <description><![CDATA[A Docker scratch image starts from nothing, and that emptiness is the point: no shell, no package manager, and almost no CVEs for a scanner to find.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-scratch-image</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-scratch-image</guid>
      <pubDate>Sat, 18 Jul 2026 11:38:02 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Semgrep Pricing Explained: Free, Team, and Enterprise Tiers]]></title>
      <description><![CDATA[Semgrep pricing is built around a free tier, a per-contributor Team plan, and custom Enterprise quotes. Here is how the tiers break down and what to watch for.]]></description>
      <link>https://safeguard.sh/resources/blog/semgrep-pricing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/semgrep-pricing</guid>
      <pubDate>Sat, 18 Jul 2026 10:17:35 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Docker Security Scanning: How to Find Vulnerabilities in Your Images]]></title>
      <description><![CDATA[Docker security scanning inspects your container images for known-vulnerable OS and application packages before they reach production. Here is how it works and how to wire it into your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-security-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-security-scanning</guid>
      <pubDate>Sat, 18 Jul 2026 08:57:08 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Malicious Composer packages on Packagist]]></title>
      <description><![CDATA[Three malicious Composer package campaigns hit Packagist in under a year -- each sitting undetected for months. Here's what happened and how to catch the next one faster.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-composer-packages-on-packagist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-composer-packages-on-packagist</guid>
      <pubDate>Sat, 18 Jul 2026 07:36:42 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is the Bootstrap Latest Version, and Is It Secure?]]></title>
      <description><![CDATA[The Bootstrap latest version is 5.3.8, and knowing your version is a security decision: older Bootstrap releases carry known XSS bugs and rely on end-of-life jQuery.]]></description>
      <link>https://safeguard.sh/resources/blog/bootstrap-latest-version</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bootstrap-latest-version</guid>
      <pubDate>Sat, 18 Jul 2026 06:16:15 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Insecure Output Handling in LLM-Integrated Applications]]></title>
      <description><![CDATA[LLM output that reaches a browser, database, or shell unvalidated can trigger XSS, SQL injection, or RCE. Here's how insecure output handling breaks AI apps.]]></description>
      <link>https://safeguard.sh/resources/blog/insecure-output-handling-in-llm-integrated-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insecure-output-handling-in-llm-integrated-applications</guid>
      <pubDate>Sat, 18 Jul 2026 04:55:48 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Best software supply chain security platforms]]></title>
      <description><![CDATA[A practical buyer's guide comparing top software supply chain security platforms—SBOM, dependency scanning, and CI/CD attestation—so you can pick the right fit.]]></description>
      <link>https://safeguard.sh/resources/blog/best-software-supply-chain-security-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-software-supply-chain-security-platforms</guid>
      <pubDate>Sat, 18 Jul 2026 03:35:22 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Download Maven for Windows and Verify It Safely]]></title>
      <description><![CDATA[To download Maven for Windows, grab the binary zip from the official Apache site, verify its checksum, and set JAVA_HOME plus PATH. Here is the full, safe walkthrough.]]></description>
      <link>https://safeguard.sh/resources/blog/download-maven-for-windows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/download-maven-for-windows</guid>
      <pubDate>Sat, 18 Jul 2026 02:14:55 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[WordPress plugin vulnerability trends]]></title>
      <description><![CDATA[WordPress plugin CVEs keep climbing and exploitation windows keep shrinking. Here's what the latest vulnerability trends mean for security teams in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/wordpress-plugin-vulnerability-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wordpress-plugin-vulnerability-trends</guid>
      <pubDate>Sat, 18 Jul 2026 00:54:28 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Overreliance on LLM Outputs: A Security Perspective]]></title>
      <description><![CDATA[LLMs hallucinate packages, vulnerability verdicts, and compliance summaries with total confidence. Here's where overreliance on AI outputs creates real security risk—and how to close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/overreliance-on-llm-outputs-a-security-perspective</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/overreliance-on-llm-outputs-a-security-perspective</guid>
      <pubDate>Fri, 17 Jul 2026 23:34:02 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best malicious package detection tools for open source de...]]></title>
      <description><![CDATA[A field guide to malicious package detection tools for npm and PyPI, comparing real vendors on detection method, coverage, and dependency confusion handling.]]></description>
      <link>https://safeguard.sh/resources/blog/best-malicious-package-detection-tools-for-open-source-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-malicious-package-detection-tools-for-open-source-dependencies</guid>
      <pubDate>Fri, 17 Jul 2026 22:13:35 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[PHP object injection vulnerability landscape]]></title>
      <description><![CDATA[Industry analysis of PHP object injection vulnerability trends, gadget chains, and real-world CVEs, plus how to find exploitable deserialization paths.]]></description>
      <link>https://safeguard.sh/resources/blog/php-object-injection-vulnerability-landscape</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-object-injection-vulnerability-landscape</guid>
      <pubDate>Fri, 17 Jul 2026 20:53:08 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[LLM Insecure Plugin Design Vulnerabilities]]></title>
      <description><![CDATA[ChatGPT plugins, LangChain agents, and MCP servers have all shipped insecure plugin flaws exposing accounts and data. Here's how Safeguard defends against them.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-insecure-plugin-design-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-insecure-plugin-design-vulnerabilities</guid>
      <pubDate>Fri, 17 Jul 2026 19:32:41 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best typosquatting and dependency confusion detection tools]]></title>
      <description><![CDATA[A practical buyer's guide to typosquatting detection tools and dependency confusion scanners, comparing real vendors and how Safeguard fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/best-typosquatting-and-dependency-confusion-detection-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-typosquatting-and-dependency-confusion-detection-tools</guid>
      <pubDate>Fri, 17 Jul 2026 18:12:15 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Packagist typosquatting report]]></title>
      <description><![CDATA[A report on Packagist typosquatting campaigns targeting Composer/PHP packages, how attackers exploit install hooks, and how to detect them.]]></description>
      <link>https://safeguard.sh/resources/blog/packagist-typosquatting-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/packagist-typosquatting-report</guid>
      <pubDate>Fri, 17 Jul 2026 16:51:48 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[LLM Denial of Service Attack Techniques]]></title>
      <description><![CDATA[LLM denial of service attacks exploit sponge prompts, unbounded generation, and denial-of-wallet loops to cripple AI systems without a single exploit.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-denial-of-service-attack-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-denial-of-service-attack-techniques</guid>
      <pubDate>Fri, 17 Jul 2026 15:31:21 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best software provenance verification tools]]></title>
      <description><![CDATA[A practical, no-fluff comparison of software provenance verification tools — Sigstore, in-toto, GitHub Attestations, JFrog, Chainguard, and Kosli — plus what to evaluate before you buy.]]></description>
      <link>https://safeguard.sh/resources/blog/best-software-provenance-verification-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-software-provenance-verification-tools</guid>
      <pubDate>Fri, 17 Jul 2026 14:10:55 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Is the New Relic npm Package Safe? A Security Review]]></title>
      <description><![CDATA[A security-focused review of the New Relic npm package (newrelic): what it does, how it handles your license key, install-script behavior, and safe-usage tips.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-new-relic</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-new-relic</guid>
      <pubDate>Fri, 17 Jul 2026 12:50:28 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[react-native-confirmation-code-field: Building Secure OTP Input]]></title>
      <description><![CDATA[This tiny React Native library gives you a clean OTP entry UI, but a secure one-time-code flow is mostly about what happens around the field, not in it.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-confirmation-code-field</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-confirmation-code-field</guid>
      <pubDate>Fri, 17 Jul 2026 11:30:01 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SCA and Application Security: How Software Composition Analysis Fits In]]></title>
      <description><![CDATA[SCA application security is about finding and fixing risk in the open-source code you depend on. Here is where it fits alongside SAST and DAST.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-application-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-application-security</guid>
      <pubDate>Fri, 17 Jul 2026 10:09:35 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Stock: Is Snyk Publicly Traded?]]></title>
      <description><![CDATA[Snyk stock is not available on any public exchange because Snyk is a private company with no ticker symbol. Here is what that means for investors and buyers.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-stock</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-stock</guid>
      <pubDate>Fri, 17 Jul 2026 08:49:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm Provenance: Adoption Tracking in Late 2025]]></title>
      <description><![CDATA[Two and a half years after npm provenance launched, adoption is climbing but uneven. Here is the late-2025 picture across the top packages and frameworks.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-provenance-adoption-tracking-late-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-provenance-adoption-tracking-late-2025</guid>
      <pubDate>Fri, 17 Jul 2026 07:28:41 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Node.js in Docker: A Practical Setup Guide]]></title>
      <description><![CDATA[A practical setup guide for running node.js docker containers in production, choosing between docker node slim and full images, and locking down what actually matters for security.]]></description>
      <link>https://safeguard.sh/resources/blog/node-js-in-docker-a-practical-setup-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-js-in-docker-a-practical-setup-guide</guid>
      <pubDate>Fri, 17 Jul 2026 06:08:15 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[CRA Harmonised Standards: Inside CEN-CENELEC JTC 13 and Standardisation Request M/606]]></title>
      <description><![CDATA[Standardisation Request M/606 was accepted in April 2025 with 41 harmonised standards to deliver by Q3 2026 to underpin CRA presumption of conformity.]]></description>
      <link>https://safeguard.sh/resources/blog/cra-cen-cenelec-harmonized-standards-jtc-13</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cra-cen-cenelec-harmonized-standards-jtc-13</guid>
      <pubDate>Fri, 17 Jul 2026 04:47:48 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Cheatsheet: Detection and Prevention for Developers]]></title>
      <description><![CDATA[A defender's SQL injection cheatsheet: how the vulnerability class works, how to recognize it in code, and the patterns that reliably shut it down.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-cheatsheet</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-cheatsheet</guid>
      <pubDate>Fri, 17 Jul 2026 03:27:21 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Java Error Checkers: Compilers, Linters, and Static Analysis]]></title>
      <description><![CDATA[A guide to the Java error-checking stack — the compiler, linters like Checkstyle, bug finders like SpotBugs and Error Prone, and security scanners — and which one catches which class of problem.]]></description>
      <link>https://safeguard.sh/resources/blog/java-error-checkers-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-error-checkers-guide</guid>
      <pubDate>Fri, 17 Jul 2026 02:06:54 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Most vulnerable PHP frameworks report]]></title>
      <description><![CDATA[A data-driven look at CVEs across Laravel, Symfony, CodeIgniter, Yii2 & ThinkPHP reveals which PHP frameworks carry the most real-world exploitation risk.]]></description>
      <link>https://safeguard.sh/resources/blog/most-vulnerable-php-frameworks-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/most-vulnerable-php-frameworks-report</guid>
      <pubDate>Fri, 17 Jul 2026 00:46:28 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AI-Generated SBOMs: How Accurate Are They?]]></title>
      <description><![CDATA[LLMs can now generate SBOMs from source code and documentation. We tested five AI SBOM generators against traditional tools to measure accuracy, completeness, and reliability.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-generated-sboms-accuracy-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-generated-sboms-accuracy-assessment</guid>
      <pubDate>Thu, 16 Jul 2026 23:26:01 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Repo Security: How to Secure Your Git Repositories End to End]]></title>
      <description><![CDATA[Repo security covers access, secrets, branch protection, dependencies, and CI/CD. Here is a practical checklist to lock down your Git repositories against the ways they actually get compromised.]]></description>
      <link>https://safeguard.sh/resources/blog/repo-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/repo-security</guid>
      <pubDate>Thu, 16 Jul 2026 22:05:34 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Excessive Agency in LLM-Powered Applications]]></title>
      <description><![CDATA[Excessive agency turns a bad LLM output into an executed action. From Replit's July 2025 database deletion to Air Canada's chatbot ruling, here's what it is and how to scope it down.]]></description>
      <link>https://safeguard.sh/resources/blog/excessive-agency-in-llm-powered-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/excessive-agency-in-llm-powered-applications</guid>
      <pubDate>Thu, 16 Jul 2026 20:45:08 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Best open source project risk scoring tools]]></title>
      <description><![CDATA[A practical buyer's guide comparing open source project risk scoring tools like OpenSSF Scorecard, Snyk, and Sonatype on signal quality and coverage.]]></description>
      <link>https://safeguard.sh/resources/blog/best-open-source-project-risk-scoring-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-open-source-project-risk-scoring-tools</guid>
      <pubDate>Thu, 16 Jul 2026 19:24:41 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Benefits of Using SAST Tools During Code Review]]></title>
      <description><![CDATA[The real benefit of using SAST tools during code review isn't finding more bugs than a human reviewer — it's finding the specific bugs humans consistently miss, before merge.]]></description>
      <link>https://safeguard.sh/resources/blog/benefits-of-sast-tools-during-code-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/benefits-of-sast-tools-during-code-review</guid>
      <pubDate>Thu, 16 Jul 2026 18:04:14 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Homebrew Formula Security for Engineering Teams]]></title>
      <description><![CDATA[Every brew install runs Ruby you didn't read on a laptop that holds your SSH keys and cloud credentials. How formulae, taps, casks and bottles actually differ in risk.]]></description>
      <link>https://safeguard.sh/resources/blog/homebrew-formula-security-for-engineering-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/homebrew-formula-security-for-engineering-teams</guid>
      <pubDate>Thu, 16 Jul 2026 16:43:48 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Aisha Bello)</author>
    </item>
    <item>
      <title><![CDATA[Drupal module vulnerability trends]]></title>
      <description><![CDATA[Contributed modules drive most Drupal risk today. Here's what the advisory trends show — and how reachability analysis changes triage.]]></description>
      <link>https://safeguard.sh/resources/blog/drupal-module-vulnerability-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/drupal-module-vulnerability-trends</guid>
      <pubDate>Thu, 16 Jul 2026 15:23:21 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Prompt Injection Attack Techniques and Defenses]]></title>
      <description><![CDATA[Prompt injection is now OWASP's #1 LLM risk, and real incidents like EchoLeak and Slack AI prove it can mean zero-click data exfiltration. Here's how it works and what stops it.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-attack-techniques-and-defenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-attack-techniques-and-defenses</guid>
      <pubDate>Thu, 16 Jul 2026 14:02:54 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best VEX (Vulnerability Exploitability eXchange) tools]]></title>
      <description><![CDATA[A practical buyer's guide to VEX tools: what to evaluate, and an honest look at Dependency-Track, GUAC, OpenVEX, Grype, Trivy, and Interlynk.]]></description>
      <link>https://safeguard.sh/resources/blog/best-vex-vulnerability-exploitability-exchange-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-vex-vulnerability-exploitability-exchange-tools</guid>
      <pubDate>Thu, 16 Jul 2026 12:42:28 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Laravel security vulnerability trends]]></title>
      <description><![CDATA[A data-driven look at recurring Laravel vulnerability patterns — debug-mode RCE, APP_KEY leaks, and Composer supply chain risk — and how to defend against them.]]></description>
      <link>https://safeguard.sh/resources/blog/laravel-security-vulnerability-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/laravel-security-vulnerability-trends</guid>
      <pubDate>Thu, 16 Jul 2026 11:22:01 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Out-of-Bounds Read Vulnerabilities (CWE-125) Explained]]></title>
      <description><![CDATA[How out-of-bounds read vulnerabilities (CWE-125) leak memory instead of crashing programs, why Heartbleed and Cloudbleed happened, and how to catch them in your dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/out-of-bounds-read-vulnerabilities-cwe-125-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/out-of-bounds-read-vulnerabilities-cwe-125-explained</guid>
      <pubDate>Thu, 16 Jul 2026 10:01:34 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[AWS IAM: common vulnerabilities and fixes]]></title>
      <description><![CDATA[Rhino Security Labs catalogs 21+ IAM privilege-escalation paths to full admin — most start with one over-scoped policy nobody remembers writing.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-iam-common-vulnerabilities-and-fixes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-iam-common-vulnerabilities-and-fixes</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Insecure defaults in Azure ARM templates: a pre-deployment scanning guide]]></title>
      <description><![CDATA[Azure Resource Manager templates don't enforce TLS 1.2 or block public blob access by default — here's how to catch it before terraform apply's Azure cousin ever runs.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-arm-template-security-misconfigurations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-arm-template-security-misconfigurations</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Anatomy of the Codecov Bash Uploader compromise]]></title>
      <description><![CDATA[A single altered line in Codecov's Bash Uploader ran undetected for 65 days, siphoning CI secrets from thousands of pipelines before anyone noticed.]]></description>
      <link>https://safeguard.sh/resources/blog/codecov-bash-uploader-supply-chain-attack-anatomy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/codecov-bash-uploader-supply-chain-attack-anatomy</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Cursor extension that cost a developer $500,000]]></title>
      <description><![CDATA[A fake Solidity extension on Open VSX was downloaded 50,000+ times, dropped an infostealer, and drained $500K in crypto — how the marketplace trust model failed.]]></description>
      <link>https://safeguard.sh/resources/blog/cursor-ide-extension-crypto-heist-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cursor-ide-extension-crypto-heist-lessons</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-45105: the Log4j denial-of-service flaw recursion built]]></title>
      <description><![CDATA[CVE-2021-45105 scored CVSS 5.9 and let a single crafted lookup string crash a JVM with a StackOverflowError — no RCE required, just uncontrolled recursion.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-45105-log4j-dos-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-45105-log4j-dos-vulnerability</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Finding vulnerable code hidden inside shaded and uber JARs]]></title>
      <description><![CDATA[JFrog found 65% of Log4Shell-affected artifacts embedded raw .class files instead of a jar — invisible to scanners that only read pom.xml metadata.]]></description>
      <link>https://safeguard.sh/resources/blog/detecting-vulnerable-code-in-shaded-uber-jars</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/detecting-vulnerable-code-in-shaded-uber-jars</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Do Not Pass GO: Malicious Golang Package Alert]]></title>
      <description><![CDATA[A typosquat of boltdb/bolt stayed cached on Go's module proxy for roughly three years after its source repo was cleaned up — proxy caching beats takedowns.]]></description>
      <link>https://safeguard.sh/resources/blog/do-not-pass-go-malicious-golang-package-alert</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/do-not-pass-go-malicious-golang-package-alert</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[OCI Image Labels and Annotations: A Practical Guide to Provenance and SBOM Linkage]]></title>
      <description><![CDATA[OCI defines 14 standard org.opencontainers.image.* annotation keys, but labels are unsigned metadata — anyone with build access can forge them.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-oci-image-labels-annotations-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-oci-image-labels-annotations-best-practices</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Minimal, Non-Root Docker Images for Python: A Best-Practices Guide]]></title>
      <description><![CDATA[CVE-2019-5736 let a malicious container overwrite the host runc binary via root access. Here's how multi-stage, non-root builds close that door for Python apps.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-security-best-practices-python-apps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-security-best-practices-python-apps</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The elementary-data hijack: when a dbt observability tool became a credential harvester]]></title>
      <description><![CDATA[A hijacked GitHub Actions token let attackers publish a backdoored elementary-data release that stole cloud, warehouse, and SSH credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/elementary-data-pypi-cloud-credential-theft</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/elementary-data-pypi-cloud-credential-theft</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The eslint-config-prettier npm compromise: when phishing beats your SCA scanner]]></title>
      <description><![CDATA[A phishing email spoofing npm support hijacked a maintainer's account and poisoned eslint-config-prettier, a package with roughly 30 million weekly downloads.]]></description>
      <link>https://safeguard.sh/resources/blog/eslint-prettier-plugin-npm-maintainer-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eslint-prettier-plugin-npm-maintainer-compromise</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[ESLint rules for detecting Trojan Source (bidi Unicode) attacks in JS/TS]]></title>
      <description><![CDATA[A single invisible Unicode character can flip how code executes versus how it reads on screen. Here's how to configure ESLint to catch it.]]></description>
      <link>https://safeguard.sh/resources/blog/eslint-rules-detecting-trojan-source-javascript</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eslint-rules-detecting-trojan-source-javascript</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[IoT device security fundamentals: firmware integrity, credentials, and network isolation]]></title>
      <description><![CDATA[One hardcoded Telnet password list built a 100,000-device botnet in 2016. A decade later, the same three failures still define most IoT breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/iot-device-security-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iot-device-security-fundamentals</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Jackson ObjectMapper and the gadget-chain trap: safe polymorphic deserialization]]></title>
      <description><![CDATA[One FasterXML fix in 2017 spawned nearly 30 follow-up CVEs. Here's how Jackson's polymorphic typing enables RCE, and how to configure ObjectMapper safely.]]></description>
      <link>https://safeguard.sh/resources/blog/java-jackson-objectmapper-deserialization-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-jackson-objectmapper-deserialization-risks</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Comparing open-source tools for secure Java code review]]></title>
      <description><![CDATA[SpotBugs checks 400+ bug patterns, Find Security Bugs adds 144 more, and CodeQL needs a full build — no single free Java scanner covers everything.]]></description>
      <link>https://safeguard.sh/resources/blog/java-secure-code-review-tools-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-secure-code-review-tools-comparison</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[When the Scanner Is the Backdoor: The LiteLLM Trivy Attack]]></title>
      <description><![CDATA[On March 19, 2026, TeamPCP hijacked Trivy's GitHub Action to steal LiteLLM's PyPI token, then shipped a backdoored release, CVE-2026-33634, CVSS 9.4.]]></description>
      <link>https://safeguard.sh/resources/blog/litellm-poisoned-security-scanner-backdoor</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/litellm-poisoned-security-scanner-backdoor</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[NoSQL injection prevention in MongoDB and Mongoose]]></title>
      <description><![CDATA[A single unsanitized query key like $ne can bypass authentication in MongoDB apps — two 2024-2025 Mongoose CVEs show the fix is harder than one middleware package.]]></description>
      <link>https://safeguard.sh/resources/blog/nosql-injection-prevention-mongodb</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nosql-injection-prevention-mongodb</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm package aliasing: the dependency confusion attack surface most teams never scan]]></title>
      <description><![CDATA[npm's alias@npm:target syntax lets an attacker capture a name that doesn't even exist yet on the registry — widening dependency confusion past simple squatting.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-dependency-confusion-package-aliasing-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-dependency-confusion-package-aliasing-attacks</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Nx Attack Turned AI Coding Agents Into the Malware]]></title>
      <description><![CDATA[In August 2025, attackers hijacked Nx's npm publish token and used Claude Code, Gemini CLI, and Amazon Q as the exfiltration engine — leaking 2,349 secrets.]]></description>
      <link>https://safeguard.sh/resources/blog/nx-npm-package-ai-coding-agent-weaponization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nx-npm-package-ai-coding-agent-weaponization</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The postmark-mcp Backdoor: What MCP Server Vetting Should Look Like]]></title>
      <description><![CDATA[A trojanized MCP server BCC'd every email it sent to an attacker for weeks, downloaded 1,643 times, before anyone noticed. Here's the pattern and the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/postmark-mcp-malicious-server-email-harvesting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/postmark-mcp-malicious-server-email-harvesting</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Protestware: what colors.js and faker.js taught the industry about maintainer risk]]></title>
      <description><![CDATA[One unpaid maintainer sabotaged two packages with 20M+ weekly downloads in a single week. Here's what colors.js and faker.js reveal about single-maintainer risk.]]></description>
      <link>https://safeguard.sh/resources/blog/protestware-open-source-maintainer-sabotage-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/protestware-open-source-maintainer-sabotage-risk</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Inside the Qinglong Scheduler RCE: How Two Auth Bugs Became a Cryptomining Campaign]]></title>
      <description><![CDATA[Two chainable auth-bypass bugs in the Qinglong task scheduler let attackers skip login entirely and mine crypto on victim CPUs — in the wild before a patch existed.]]></description>
      <link>https://safeguard.sh/resources/blog/qinglong-task-scheduler-rce-cryptomining</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/qinglong-task-scheduler-rce-cryptomining</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Postmortem: The Bun-Based Stealer Inside SAP's @cap-js and mbt Packages]]></title>
      <description><![CDATA[Four SAP npm packages shipped a Bun-executed credential stealer on April 29, 2026 — a look at how it evaded Node-centric detection and what actually stops it.]]></description>
      <link>https://safeguard.sh/resources/blog/sap-cap-js-mbt-npm-mini-shai-hulud-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sap-cap-js-mbt-npm-mini-shai-hulud-compromise</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secure code review: the checklist reviewers actually need]]></title>
      <description><![CDATA[Broken access control affects nearly every tested app and XSS remains the #1 CWE overall — both catchable in review. Here is a language-agnostic PR checklist.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-code-review-best-practices-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-code-review-best-practices-checklist</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secure SDLC: A Practical Guide to Embedding Security Gates in Every Phase]]></title>
      <description><![CDATA[NIST finalized the Secure Software Development Framework in February 2022, yet most teams still bolt security on at release. Here's where the gates actually belong.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-sdlc-best-practices-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-sdlc-best-practices-guide</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Catching Terraform Misconfigurations Before They Ever Reach Apply]]></title>
      <description><![CDATA[Trivy replaced tfsec in 2023 and Checkov ships thousands of policies — here's how to wire open-source Terraform scanners into CI/CD before terraform apply runs.]]></description>
      <link>https://safeguard.sh/resources/blog/terraform-iac-security-scanning-cicd</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/terraform-iac-security-scanning-cicd</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Trojan Source: how Unicode bidi control characters hide malicious code in plain sight]]></title>
      <description><![CDATA[CVE-2021-42574 scored 8.3 CVSS for a bug that isn't a parser flaw at all — it's Unicode's bidirectional text algorithm, weaponized against code review.]]></description>
      <link>https://safeguard.sh/resources/blog/trojan-source-unicode-bidi-attack-technique</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trojan-source-unicode-bidi-attack-technique</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[URL parser confusion: how inconsistent parsing enables SSRF and auth bypass]]></title>
      <description><![CDATA[Sixteen URL-parsing libraries tested, five inconsistency classes found, eight CVEs assigned — one wrong backslash can turn a validated URL into an SSRF.]]></description>
      <link>https://safeguard.sh/resources/blog/url-parser-confusion-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/url-parser-confusion-vulnerabilities-explained</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[When CVSS Scoring Misleads Severity Context]]></title>
      <description><![CDATA[Only 2-6% of published CVEs are ever exploited in the wild, yet a much larger share carry CVSS 7.0+ scores — a gap that quietly wrecks patch prioritization.]]></description>
      <link>https://safeguard.sh/resources/blog/when-cve-scoring-misleads-severity-context</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/when-cve-scoring-misleads-severity-context</guid>
      <pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best policy-as-code enforcement tools]]></title>
      <description><![CDATA[A practical buyer's guide to policy as code tools -- OPA, Kyverno, Sentinel, Checkov, InSpec, and Styra -- with honest strengths, limits, and evaluation criteria.]]></description>
      <link>https://safeguard.sh/resources/blog/best-policy-as-code-enforcement-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-policy-as-code-enforcement-tools</guid>
      <pubDate>Thu, 16 Jul 2026 08:41:07 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Cargo crate vulnerability trends report]]></title>
      <description><![CDATA[RustSec advisories rose 38% year-over-year as crates.io passed 195,000 packages. A breakdown of where Cargo's supply-chain risk is concentrated in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/cargo-crate-vulnerability-trends-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cargo-crate-vulnerability-trends-report</guid>
      <pubDate>Thu, 16 Jul 2026 07:20:41 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Out-of-Bounds Write Vulnerabilities (CWE-787) Explained]]></title>
      <description><![CDATA[CWE-787 out-of-bounds write bugs let attackers corrupt memory past a buffer's limit, causing crashes or code execution. Here's how they work.]]></description>
      <link>https://safeguard.sh/resources/blog/out-of-bounds-write-vulnerabilities-cwe-787-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/out-of-bounds-write-vulnerabilities-cwe-787-explained</guid>
      <pubDate>Thu, 16 Jul 2026 06:00:14 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best Kubernetes admission control tools]]></title>
      <description><![CDATA[A practical comparison of Kubernetes admission control tools — OPA/Gatekeeper, Kyverno, Kubewarden, Styra, jsPolicy, and Polaris — with real strengths, limits, and evaluation criteria.]]></description>
      <link>https://safeguard.sh/resources/blog/best-kubernetes-admission-control-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-kubernetes-admission-control-tools</guid>
      <pubDate>Thu, 16 Jul 2026 04:39:47 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What Is Exploit-DB? Using the Exploit Database for Defense]]></title>
      <description><![CDATA[Exploit-DB is a public archive of exploits and proof-of-concept code maintained by OffSec. Defenders can use it to understand exposure and prioritize patching.]]></description>
      <link>https://safeguard.sh/resources/blog/exploit-db</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/exploit-db</guid>
      <pubDate>Thu, 16 Jul 2026 03:19:21 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[The Node.js Image: A Security Guide to Docker Base Images]]></title>
      <description><![CDATA[Choosing a Node.js image is a security decision, not just a size one. The tag you pick, alpine, slim, or distroless, and the version you pin decide most of your container's attack surface.]]></description>
      <link>https://safeguard.sh/resources/blog/node-js-image</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-js-image</guid>
      <pubDate>Thu, 16 Jul 2026 01:58:54 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Malicious Rust crates found on crates.io]]></title>
      <description><![CDATA[Malicious crates keep surfacing on crates.io, from the rustdecimal typosquat to build-script payload attacks. Here's how the pattern works and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-rust-crates-found-on-cratesio</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-rust-crates-found-on-cratesio</guid>
      <pubDate>Thu, 16 Jul 2026 00:38:27 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The GPLv3 License Explained: Compliance and Risk]]></title>
      <description><![CDATA[The GPLv3 license is a strong copyleft license that carries real obligations, and treating it as just another dependency is how companies end up with compliance and legal exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/gplv3-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gplv3-license</guid>
      <pubDate>Wed, 15 Jul 2026 23:18:01 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Network Policy Best Practices for a Zero-Trust Cluster]]></title>
      <description><![CDATA[The core Kubernetes network policy best practice is to default-deny all traffic and then explicitly allow only what each workload needs. Here is how to build that model without breaking your cluster.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-network-policy-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-network-policy-best-practices</guid>
      <pubDate>Wed, 15 Jul 2026 21:57:34 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is a CVE Numbering Authority (CNA)?]]></title>
      <description><![CDATA[A CNA is an organization authorized to assign CVE identifiers to vulnerabilities in its scope. Here is how CNAs work and why they shape how fast a flaw becomes citable.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-cve-numbering-authority</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-cve-numbering-authority</guid>
      <pubDate>Wed, 15 Jul 2026 20:37:07 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Security Headers: A Practical Hardening Guide]]></title>
      <description><![CDATA[Which HTTP security headers actually matter, what each one defends against, and copy-ready configuration to harden a site without breaking it.]]></description>
      <link>https://safeguard.sh/resources/blog/security-header</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-header</guid>
      <pubDate>Wed, 15 Jul 2026 19:16:41 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Improper Restriction of Operations Within Memory Bounds]]></title>
      <description><![CDATA[CWE-119 has topped MITRE's vulnerability rankings for years, from Heartbleed to WannaCry to the 2023 libwebp zero-day. Here's why it persists and how to catch it early.]]></description>
      <link>https://safeguard.sh/resources/blog/improper-restriction-of-operations-within-memory-bounds</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/improper-restriction-of-operations-within-memory-bounds</guid>
      <pubDate>Wed, 15 Jul 2026 17:56:14 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best runtime container security tools]]></title>
      <description><![CDATA[A practical comparison of runtime container security tools, from eBPF-based monitoring to commercial threat detection platforms, and what to weigh before buying.]]></description>
      <link>https://safeguard.sh/resources/blog/best-runtime-container-security-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-runtime-container-security-tools</guid>
      <pubDate>Wed, 15 Jul 2026 16:35:47 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Unsafe Rust code vulnerability patterns]]></title>
      <description><![CDATA[RustSec advisories tied to unsafe code keep climbing. Here's how unsound FFI, transmute misuse, and unchecked indexing become real exploits.]]></description>
      <link>https://safeguard.sh/resources/blog/unsafe-rust-code-vulnerability-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unsafe-rust-code-vulnerability-patterns</guid>
      <pubDate>Wed, 15 Jul 2026 15:15:20 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Integer Overflow and Wraparound Vulnerabilities]]></title>
      <description><![CDATA[A single wrapped integer minted 184B bitcoin, grounded 787s, and erased $900M from a crypto token. Here's how overflow bugs work—and how Safeguard catches them first.]]></description>
      <link>https://safeguard.sh/resources/blog/integer-overflow-and-wraparound-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/integer-overflow-and-wraparound-vulnerabilities</guid>
      <pubDate>Wed, 15 Jul 2026 13:54:54 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best secrets management and vaulting solutions]]></title>
      <description><![CDATA[A buyer's guide to secrets management tools: evaluation criteria plus honest comparisons of Vault, AWS Secrets Manager, CyberArk, Doppler, and Infisical.]]></description>
      <link>https://safeguard.sh/resources/blog/best-secrets-management-and-vaulting-solutions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-secrets-management-and-vaulting-solutions</guid>
      <pubDate>Wed, 15 Jul 2026 12:34:27 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Rust supply chain security landscape]]></title>
      <description><![CDATA[Rust's crates.io has topped 170,000 packages and real attacks are following. Here's what's changed and how security teams should respond.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-supply-chain-security-landscape</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-supply-chain-security-landscape</guid>
      <pubDate>Wed, 15 Jul 2026 11:14:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Double-Free Vulnerabilities in C and C++]]></title>
      <description><![CDATA[Double-free bugs let attackers corrupt heap memory and hijack control flow. Here's how they happen in C/C++, real CVEs, and how to catch them early.]]></description>
      <link>https://safeguard.sh/resources/blog/double-free-vulnerabilities-in-c-and-c</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/double-free-vulnerabilities-in-c-and-c</guid>
      <pubDate>Wed, 15 Jul 2026 09:53:34 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Designing tamper-evident CloudTrail logging across an AWS organization]]></title>
      <description><![CDATA[AWS CloudTrail's default event history holds only 90 days. A centralized, hash-validated org trail is what actually survives an incident or an audit.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-cloudtrail-centralized-audit-logging</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-cloudtrail-centralized-audit-logging</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The AWS migration security checklist: IAM, encryption, and network segmentation]]></title>
      <description><![CDATA[A misconfigured WAF and an over-permissioned IAM role exposed 106 million records in 2019 — here's the checklist that prevents a repeat during your AWS migration.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-migration-security-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-migration-security-checklist</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Azure Bicep IaC security fundamentals: secrets, module trust, and policy gates]]></title>
      <description><![CDATA[A @secure() Bicep parameter still leaks in plaintext the moment it's written to an output — a well-documented gap most teams discover only after a deployment history review.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-bicep-iac-security-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-bicep-iac-security-fundamentals</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Building AppSec Training Programs That Actually Change Behavior]]></title>
      <description><![CDATA[OWASP's 2021 Top 10 added Insecure Design as its largest category by CWE count, yet most developer training still teaches syntax, not decisions.]]></description>
      <link>https://safeguard.sh/resources/blog/building-effective-appsec-training-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-effective-appsec-training-programs</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Lessons from the CircleCI 2023 secrets breach]]></title>
      <description><![CDATA[A stolen session cookie bypassed 2FA and let attackers read secrets from live memory. CircleCI's own timeline shows what fast rotation actually requires.]]></description>
      <link>https://safeguard.sh/resources/blog/circleci-2023-secrets-breach-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/circleci-2023-secrets-breach-lessons</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Code injection risks in CLI tools and IDE plugins]]></title>
      <description><![CDATA[A malicious npm dependency hid in event-stream for 8M downloads before detection. Developer tooling is a code-injection blast radius most teams never audit.]]></description>
      <link>https://safeguard.sh/resources/blog/code-injection-risks-in-cli-tools-and-ide-plugins</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-injection-risks-in-cli-tools-and-ide-plugins</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Container escape techniques and defense in depth]]></title>
      <description><![CDATA[CVE-2024-21626 let a leaked file descriptor turn runc exec into host root. Here's how container escapes actually work — and the layers that stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/container-escape-techniques-and-defense-in-depth</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-escape-techniques-and-defense-in-depth</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Exposed .git Directories and the Git Internals That Leak Your Source]]></title>
      <description><![CDATA[Roughly 4.96 million IPs expose .git metadata today, and over 252,000 leak live credentials in .git/config — a 2018-era bug that never went away.]]></description>
      <link>https://safeguard.sh/resources/blog/exposed-git-directories-and-git-internals-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/exposed-git-directories-and-git-internals-risk</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Does gamification actually make security training work?]]></title>
      <description><![CDATA[picoCTF drew 18,000+ participants in 2025, but research shows points and badges boost engagement far more reliably than they change security behavior.]]></description>
      <link>https://safeguard.sh/resources/blog/gamification-in-security-training-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gamification-in-security-training-programs</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Implementing HSTS correctly in Node.js and Express]]></title>
      <description><![CDATA[HSTS has one header and three flags, yet a misconfigured includeSubDomains or a premature preload submission can take a domain offline for months.]]></description>
      <link>https://safeguard.sh/resources/blog/hsts-implementation-nodejs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hsts-implementation-nodejs</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Implementing TLS in Java applications: keystores, trust managers, and protocol pinning done right]]></title>
      <description><![CDATA[One overridden checkServerTrusted() method disables certificate validation for an entire Java app — and it still ships to production more often than most teams admit.]]></description>
      <link>https://safeguard.sh/resources/blog/implementing-tls-in-java-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/implementing-tls-in-java-applications</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Default-deny NetworkPolicy: closing the pod-to-pod gap in Kubernetes]]></title>
      <description><![CDATA[Kubernetes pods allow all traffic by default, and many clusters' NetworkPolicy YAML silently does nothing because the CNI plugin never enforces it.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-networkpolicy-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-networkpolicy-best-practices</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Native Secrets, Sealed Secrets, or Vault: Picking a Kubernetes Secrets Strategy]]></title>
      <description><![CDATA[Kubernetes Secrets are base64-encoded, not encrypted — etcd stores them near-plaintext unless you configure encryption at rest yourself.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-secrets-management-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-secrets-management-best-practices</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Log injection attacks and how to stop forging your own audit trail]]></title>
      <description><![CDATA[One unsanitized 
 turns a log line into two, and a critical Log4j flaw with a CVSS score of 10.0 turned a log message into remote code execution.]]></description>
      <link>https://safeguard.sh/resources/blog/log-injection-attacks-and-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log-injection-attacks-and-prevention</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[RBAC vs. ABAC vs. ReBAC: choosing an access-control model for multi-tenant cloud apps]]></title>
      <description><![CDATA[Google's Zanzibar paper (USENIX ATC 2019) showed relationship graphs authorizing access with sub-10ms latency at massive scale — here's when RBAC or ABAC beats it instead.]]></description>
      <link>https://safeguard.sh/resources/blog/modern-access-control-models-cloud-apps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/modern-access-control-models-cloud-apps</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm supply-chain attacks: typosquatting, dependency confusion, and postinstall malware]]></title>
      <description><![CDATA[event-stream hid a wallet-stealing payload behind 8M downloads in 2018. Here's how typosquatting and dependency confusion actually work, and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-supply-chain-attack-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-supply-chain-attack-prevention</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Nuxt 3 Security Hardening: CSP, SSR Leakage, and Safe Server Routes]]></title>
      <description><![CDATA[Nuxt 3's server runs as one long-lived Node process — a single misplaced ref() can leak one user's data into another user's response.]]></description>
      <link>https://safeguard.sh/resources/blog/nuxt3-security-hardening-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuxt3-security-hardening-guide</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Building an OSPO security governance model for license and vulnerability risk]]></title>
      <description><![CDATA[77% of large organizations now run an OSPO, and 91% say it owns security issues — but most still track license and CVE risk in separate spreadsheets.]]></description>
      <link>https://safeguard.sh/resources/blog/ospo-security-governance-open-source-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ospo-security-governance-open-source-programs</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The OWASP Top 10:2025, explained with minimal fix-it code]]></title>
      <description><![CDATA[OWASP reordered its Top 10 for 2025 — Broken Access Control is back at #1 and a new Mishandling of Exceptional Conditions category debuts at #10.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-prevention-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-prevention-guide</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Path traversal, decoded: canonicalization patterns across languages]]></title>
      <description><![CDATA[CVE-2021-41773 turned a broken path-normalization routine in Apache 2.4.49 into remote code execution. Here's how canonicalization stops the whole bug class.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-vulnerability-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-vulnerability-prevention</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Ransomware defense strategy for engineering teams]]></title>
      <description><![CDATA[Ransomware hit 44% of breaches in Verizon's 2025 DBIR, up from 32% a year prior. Here's the backup, access, and detection playbook that actually stops it.]]></description>
      <link>https://safeguard.sh/resources/blog/ransomware-defense-strategy-for-engineering-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ransomware-defense-strategy-for-engineering-teams</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[React and TypeScript security best practices for 2026]]></title>
      <description><![CDATA[A 2025 npm phishing attack hit packages with 2.6 billion weekly downloads. Here's how React and TypeScript teams reduce XSS, API, and dependency risk.]]></description>
      <link>https://safeguard.sh/resources/blog/react-typescript-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-typescript-security-best-practices</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Designing a secure Node.js API gateway: auth, rate limits, validation, and signing]]></title>
      <description><![CDATA[CVE-2020-15084 let attackers forge JWTs against express-jwt because one algorithm check was missing — a case study in why gateways need four defense layers, not one.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-api-gateway-nodejs-design</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-api-gateway-nodejs-design</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secure Coding Fundamentals: A No-Jargon Checklist for New Developers]]></title>
      <description><![CDATA[Three habits — validating input, managing secrets, and pinning dependencies — sit behind most preventable breaches, from Log4Shell to the event-stream hack.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-coding-fundamentals-checklist-beginners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-coding-fundamentals-checklist-beginners</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secure file uploads in Node.js and Fastify]]></title>
      <description><![CDATA[CWE-22 path traversal climbed three spots to #5 on the 2024 CWE Top 25. Here's how to validate, store, and scan Fastify uploads without trusting the client.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-file-uploads-nodejs-fastify</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-file-uploads-nodejs-fastify</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing Secrets and Environment Variables in GitHub Actions]]></title>
      <description><![CDATA[A tag-pinned GitHub Action used by 23,000+ repos was rewritten to dump CI memory in March 2025 — here's how OIDC and SHA-pinning would have stopped it.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-github-actions-secrets-and-env-vars</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-github-actions-secrets-and-env-vars</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Security metrics and KPIs that actually indicate cloud program maturity]]></title>
      <description><![CDATA[IBM's 2024 breach data puts the average breach lifecycle at 258 days — most cloud security dashboards can't even tell you your own exposure window.]]></description>
      <link>https://safeguard.sh/resources/blog/security-metrics-and-kpis-for-cloud-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-metrics-and-kpis-for-cloud-programs</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A framework for consolidating SAST, DAST, and SCA tools]]></title>
      <description><![CDATA[Enterprises run 45 security tools on average, and 50+ tool stacks detect incidents 8% worse. Here's when AppSec consolidation actually pays off.]]></description>
      <link>https://safeguard.sh/resources/blog/security-tool-consolidation-for-appsec-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-tool-consolidation-for-appsec-teams</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-31692: how a forward dispatch bypassed Spring Security authorization]]></title>
      <description><![CDATA[A CVSS 9.8 flaw let a single internal forward skip Spring Security's URL-based access checks entirely — here's the root cause and the exact config fix.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-security-cve-2022-31692-authorization-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-security-cve-2022-31692-authorization-bypass</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[TLS termination and cert-manager: a hardening guide for Kubernetes Ingress]]></title>
      <description><![CDATA[IngressNightmare's CVSS 9.8 RCE showed that ingress-nginx's own admission webhook can be turned against cluster Secrets — here's how to configure TLS safely.]]></description>
      <link>https://safeguard.sh/resources/blog/tls-termination-kubernetes-ingress</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tls-termination-kubernetes-ingress</guid>
      <pubDate>Wed, 15 Jul 2026 09:00:00 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best third-party and vendor risk management (TPRM) tools]]></title>
      <description><![CDATA[A practical buyer's guide comparing six named third-party risk management tools — strengths, limitations, and where software supply chain visibility fills the gaps they miss.]]></description>
      <link>https://safeguard.sh/resources/blog/best-third-party-and-vendor-risk-management-tprm-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-third-party-and-vendor-risk-management-tprm-tools</guid>
      <pubDate>Wed, 15 Jul 2026 08:33:07 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[RustSec advisory database trend report]]></title>
      <description><![CDATA[RustSec crossed 200 advisories by July 2026, revealing a shift from memory bugs to malicious typosquats, unsound "safe" APIs, and abandoned crates.]]></description>
      <link>https://safeguard.sh/resources/blog/rustsec-advisory-database-trend-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rustsec-advisory-database-trend-report</guid>
      <pubDate>Wed, 15 Jul 2026 07:12:40 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Memory Leak Vulnerabilities: Causes and Detection]]></title>
      <description><![CDATA[Memory leaks aren't just a performance bug — from Heartbleed to Samba's CVE-2018-16851, they're a documented attack surface. Here's how they're caused, scored, and detected.]]></description>
      <link>https://safeguard.sh/resources/blog/memory-leak-vulnerabilities-causes-and-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/memory-leak-vulnerabilities-causes-and-detection</guid>
      <pubDate>Wed, 15 Jul 2026 05:52:14 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best continuous compliance monitoring platforms]]></title>
      <description><![CDATA[A practical, no-hype comparison of continuous compliance monitoring platforms for SOC 2 and audit readiness, plus where dedicated tools fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/best-continuous-compliance-monitoring-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-continuous-compliance-monitoring-platforms</guid>
      <pubDate>Wed, 15 Jul 2026 04:31:47 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Scanners and the Gartner AST Landscape: How the Tools Actually Work]]></title>
      <description><![CDATA[When people search for a vulnerability scanner in the Gartner sense, they usually mean the AST market. Here is what that market covers, how the tool types work, and how to choose.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-scanner-gartner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-scanner-gartner</guid>
      <pubDate>Wed, 15 Jul 2026 03:11:20 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Typosquatting on crates.io report]]></title>
      <description><![CDATA[Safeguard's research team scanned all of crates.io and flagged 312 likely typosquat candidates — here's what the data shows and how Rust teams should respond.]]></description>
      <link>https://safeguard.sh/resources/blog/typosquatting-on-cratesio-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/typosquatting-on-cratesio-report</guid>
      <pubDate>Wed, 15 Jul 2026 01:50:53 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Null Pointer Dereference Vulnerabilities]]></title>
      <description><![CDATA[A single unchecked pointer can crash a server. Here's what null pointer dereference vulnerabilities are, real CVEs like OpenSSL's, and how to catch them.]]></description>
      <link>https://safeguard.sh/resources/blog/null-pointer-dereference-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/null-pointer-dereference-vulnerabilities</guid>
      <pubDate>Wed, 15 Jul 2026 00:30:27 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best SOC 2 compliance automation tools]]></title>
      <description><![CDATA[A practical, no-hype comparison of SOC 2 compliance automation tools — what to evaluate, how Vanta, Drata, Secureframe, Sprinto, and others differ, and where they fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/best-soc-2-compliance-automation-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-soc-2-compliance-automation-tools</guid>
      <pubDate>Tue, 14 Jul 2026 23:10:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[CocoaPods trunk supply chain vulnerability report]]></title>
      <description><![CDATA[Three CocoaPods trunk server flaws sat unpatched for a decade, exposing 1,866 orphaned pods to takeover. Here's what happened and how to defend your dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/cocoapods-trunk-supply-chain-vulnerability-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cocoapods-trunk-supply-chain-vulnerability-report</guid>
      <pubDate>Tue, 14 Jul 2026 21:49:33 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Uncaught Exception Security Risks]]></title>
      <description><![CDATA[An uncaught exception isn't just a crash: it caused the Equifax breach and Log4j outages. See how exception-handling bugs become real security incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/uncaught-exception-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uncaught-exception-security-risks</guid>
      <pubDate>Tue, 14 Jul 2026 20:29:07 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best ISO 27001 compliance management tools]]></title>
      <description><![CDATA[A practical, no-fluff comparison of ISO 27001 compliance tools — what evaluation criteria matter, how six real platforms stack up, and where the gaps are.]]></description>
      <link>https://safeguard.sh/resources/blog/best-iso-27001-compliance-management-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-iso-27001-compliance-management-tools</guid>
      <pubDate>Tue, 14 Jul 2026 19:08:40 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Swift Package Manager vulnerability trends]]></title>
      <description><![CDATA[Typosquats, thin CVE coverage, and an executable manifest format: inside the Swift Package Manager vulnerability trends security teams can't ignore.]]></description>
      <link>https://safeguard.sh/resources/blog/swift-package-manager-vulnerability-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/swift-package-manager-vulnerability-trends</guid>
      <pubDate>Tue, 14 Jul 2026 17:48:13 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Insufficient Encapsulation Vulnerabilities]]></title>
      <description><![CDATA[An insufficient encapsulation vulnerability (CWE-485) exposes internal state to untrusted code. See how it drove real CVEs in Velocity, Lodash, and BeanUtils.]]></description>
      <link>https://safeguard.sh/resources/blog/insufficient-encapsulation-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insufficient-encapsulation-vulnerabilities</guid>
      <pubDate>Tue, 14 Jul 2026 16:27:47 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best SBOM validation and diffing tools]]></title>
      <description><![CDATA[A practical buyer's guide to SBOM validation tools -- covering schema checks, quality scoring, and diffing -- with an honest look at six real tools and their tradeoffs.]]></description>
      <link>https://safeguard.sh/resources/blog/best-sbom-validation-and-diffing-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-sbom-validation-and-diffing-tools</guid>
      <pubDate>Tue, 14 Jul 2026 15:07:20 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Introducing Safeguard Academy: Free Courses and Certifications for Supply Chain Security]]></title>
      <description><![CDATA[We're launching Safeguard Academy — a free learning platform at academy.safeguard.sh with curated courses, an AI tutor in every course, course communities, live sessions, and publicly verifiable certifications. The first credential is the Safeguard Certified Practitioner.]]></description>
      <link>https://safeguard.sh/resources/blog/introducing-safeguard-academy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/introducing-safeguard-academy</guid>
      <pubDate>Tue, 14 Jul 2026 14:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Malicious iOS SDKs and CocoaPods report]]></title>
      <description><![CDATA[CocoaPods trunk server CVEs and the SourMint SDK scandal reveal how malicious iOS SDKs and pods slip past App Review for years.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-ios-sdks-and-cocoapods-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-ios-sdks-and-cocoapods-report</guid>
      <pubDate>Tue, 14 Jul 2026 13:46:53 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Generation of Predictable Numbers or Identifiers]]></title>
      <description><![CDATA[From Debian's 2008 OpenSSL bug to First American's 885-million-record leak, predictable identifiers keep breaking security. Here's how the vulnerability works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/generation-of-predictable-numbers-or-identifiers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/generation-of-predictable-numbers-or-identifiers</guid>
      <pubDate>Tue, 14 Jul 2026 12:26:27 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best reproducible build tools]]></title>
      <description><![CDATA[A practical buyer's guide to reproducible build tools -- evaluation criteria, six real tools compared honestly, and how continuous verification closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/best-reproducible-build-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-reproducible-build-tools</guid>
      <pubDate>Tue, 14 Jul 2026 11:06:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Mobile app dependency vulnerability trends]]></title>
      <description><![CDATA[Mobile apps now ship more third-party code than first-party. Safeguard's analysis breaks down where dependency vulnerabilities cluster and why.]]></description>
      <link>https://safeguard.sh/resources/blog/mobile-app-dependency-vulnerability-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mobile-app-dependency-vulnerability-trends</guid>
      <pubDate>Tue, 14 Jul 2026 09:45:33 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Anatomy of a malicious npm package attack]]></title>
      <description><![CDATA[One phished maintainer, 18 packages, and billions of weekly downloads — how npm/PyPI supply chain attacks actually unfold, and the signals that expose them.]]></description>
      <link>https://safeguard.sh/resources/blog/anatomy-of-a-malicious-npm-package-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anatomy-of-a-malicious-npm-package-attack</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AppSec anti-patterns to eliminate]]></title>
      <description><![CDATA[23.8M secrets leaked on public GitHub in 2024 alone. Here are the AppSec anti-patterns behind numbers like that — and the concrete practices that replace them.]]></description>
      <link>https://safeguard.sh/resources/blog/appsec-anti-patterns-to-eliminate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/appsec-anti-patterns-to-eliminate</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Common AWS IAM privilege-escalation paths and how to design least privilege]]></title>
      <description><![CDATA[Rhino Security Labs cataloged 21 distinct AWS IAM privilege-escalation methods in 2018 — most still work today, and most are invisible to a manifest scan.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-iam-least-privilege-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-iam-least-privilege-security-risks</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The AWS misconfiguration cheat sheet: public S3, open IAM, and open security groups]]></title>
      <description><![CDATA[Three misconfigurations — public S3 buckets, over-permissioned IAM roles, and 0.0.0.0/0 security groups — keep causing breaches. Here's the CLI to find and fix each one.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-top-misconfigurations-cheat-sheet</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-top-misconfigurations-cheat-sheet</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Broken object-level authorization in Kubernetes integrations: CVE-2023-1065]]></title>
      <description><![CDATA[One leaked Integration ID was enough to pollute a Snyk customer's findings — CVE-2023-1065 shows why possession of an identifier is not authorization.]]></description>
      <link>https://safeguard.sh/resources/blog/broken-object-level-authorization-in-kubernetes-integrations-cve-2023-1065</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/broken-object-level-authorization-in-kubernetes-integrations-cve-2023-1065</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Building a security-first engineering culture]]></title>
      <description><![CDATA[Only 16.2% of orgs deploy on demand, per DORA's 2025 report. The gap between elite and low performers is culture, not tooling — here's how CISOs close it.]]></description>
      <link>https://safeguard.sh/resources/blog/building-a-security-first-engineering-culture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-a-security-first-engineering-culture</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Memory safety in C/C++: the vulnerability classes that won't go away]]></title>
      <description><![CDATA[Microsoft found ~70% of its patched CVEs trace to memory-safety bugs. Here's how buffer overflows, use-after-free, and double-free still happen — and what actually catches them.]]></description>
      <link>https://safeguard.sh/resources/blog/c-cpp-memory-safety-appsec-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/c-cpp-memory-safety-appsec-guide</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Choosing a secure Node.js web framework: Express, Fastify, Koa, and NestJS compared]]></title>
      <description><![CDATA[None of Express, Fastify, Koa, or NestJS enable security headers, CSRF protection, or input validation by default — the defaults you inherit differ more than you'd think.]]></description>
      <link>https://safeguard.sh/resources/blog/choosing-a-secure-nodejs-web-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/choosing-a-secure-nodejs-web-framework</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Cloud storage misconfiguration: why the same leak keeps happening]]></title>
      <description><![CDATA[A single public S3 bucket exposed 198 million voter records in 2017. A decade later, the same misconfiguration still causes the biggest cloud data leaks.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-storage-misconfiguration-data-leak-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-storage-misconfiguration-data-leak-lessons</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why Math.random() is a security bug waiting to happen]]></title>
      <description><![CDATA[A 2008 Debian OpenSSL patch cut key entropy to ~32,768 values; a 2012 scan found 0.75% of TLS certs shared keys. Weak PRNGs still cause real breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/csprng-secure-random-number-generation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/csprng-secure-random-number-generation</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The security hygiene checklist most engineering orgs still skip]]></title>
      <description><![CDATA[22% of breaches start with stolen credentials, per Verizon's 2025 DBIR. A quarter-long hygiene checklist — patching, MFA, secrets, least privilege — closes most of that gap.]]></description>
      <link>https://safeguard.sh/resources/blog/cybersecurity-hygiene-fundamentals-for-engineering-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cybersecurity-hygiene-fundamentals-for-engineering-teams</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Automating cloud compliance checks in Terraform and CloudFormation pipelines]]></title>
      <description><![CDATA[Terrascan went fully archived in November 2025. Here's how to gate CIS and SOC 2 checks in Terraform/CloudFormation pipelines with tools still standing.]]></description>
      <link>https://safeguard.sh/resources/blog/iac-compliance-automation-terraform-cloudformation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iac-compliance-automation-terraform-cloudformation</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Scanning Terraform and CloudFormation before you ever run apply]]></title>
      <description><![CDATA[tfsec merged into Trivy in 2024 and OPA hit CNCF graduated status in 2021 — here's how to scan Terraform and CloudFormation before deploy, with a working Conftest policy.]]></description>
      <link>https://safeguard.sh/resources/blog/infrastructure-as-code-security-scanning-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/infrastructure-as-code-security-scanning-guide</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Preventing mass assignment in Spring MVC and Spring Boot]]></title>
      <description><![CDATA[CWE-915 mass assignment lets one extra JSON field turn a profile update into a privilege escalation — here's how DTOs beat @JsonIgnore in Spring.]]></description>
      <link>https://safeguard.sh/resources/blog/mass-assignment-vulnerabilities-java-spring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mass-assignment-vulnerabilities-java-spring</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Mass assignment in Node, Express, and Mongoose apps]]></title>
      <description><![CDATA[One unfiltered req.body.role field can turn a signup form into an admin-creation endpoint — here's how mass assignment happens in Node and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/mass-assignment-vulnerabilities-nodejs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mass-assignment-vulnerabilities-nodejs</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Mass assignment in Python: how setattr and **kwargs turn request bodies into privilege escalation]]></title>
      <description><![CDATA[One unguarded setattr() loop can let a JSON body set is_admin directly — the same bug class that let a researcher add his key to Rails' GitHub org in 2012.]]></description>
      <link>https://safeguard.sh/resources/blog/mass-assignment-vulnerabilities-python-setattr</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mass-assignment-vulnerabilities-python-setattr</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why Node.js's vm module is not a security sandbox]]></title>
      <description><![CDATA[Node's own docs warn the vm module isn't a security mechanism — vm2, built on top of it, still shipped two CVSS 9.8 sandbox escapes in 2023.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-vm-module-sandbox-escape-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-vm-module-sandbox-escape-risks</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Detecting and preventing Zip Slip and path traversal in Java]]></title>
      <description><![CDATA[Snyk's 2018 Zip Slip disclosure hit Amazon, Apache, and LinkedIn projects at once — here's how the flaw still hides in Java archive code today, and how to catch it.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-vulnerabilities-in-java-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-vulnerabilities-in-java-applications</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Preventing path traversal in Node.js file upload and serving code]]></title>
      <description><![CDATA[path.join() doesn't stop ../../etc/passwd — CVE-2024-12905 and Zip Slip show why Node.js needs explicit containment checks, not just path normalization.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-vulnerabilities-in-nodejs-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-vulnerabilities-in-nodejs-applications</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Preventing XSS in Django applications]]></title>
      <description><![CDATA[Django escapes template output by default, but mark_safe() and format_html() misuse routinely reopen the exact XSS holes auto-escaping was built to close.]]></description>
      <link>https://safeguard.sh/resources/blog/preventing-xss-in-django-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preventing-xss-in-django-applications</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[ssl vs. requests vs. httpx: where Python TLS configuration goes wrong]]></title>
      <description><![CDATA[Python didn't verify TLS certificates by default until PEP 476 landed in 2014 — a decade later, one stray verify=False call still reopens that exact hole.]]></description>
      <link>https://safeguard.sh/resources/blog/python-secure-network-communication-libraries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-secure-network-communication-libraries</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The S3 bucket security hardening checklist]]></title>
      <description><![CDATA[AWS blocked public access by default in April 2023, yet misconfigured buckets still leak data — here's a concrete checklist and Terraform to close the gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/s3-bucket-security-hardening-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/s3-bucket-security-hardening-checklist</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The secure SDLC implementation guide: gates for every phase]]></title>
      <description><![CDATA[NIST's SSDF names four practice groups, but most teams bolt security onto one phase. Here's how to gate design, code, build, and release instead.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-sdlc-implementation-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-sdlc-implementation-guide</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A four-surface framework for software supply-chain risk]]></title>
      <description><![CDATA[Supply-chain attacks are up 650% year over year, per the SLSA framework — yet most teams still map risk to one surface instead of four.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-risk-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-risk-framework</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Common Go module vulnerability patterns and how govulncheck helps]]></title>
      <description><![CDATA[Two real CVEs in Go's path/filepath package and a growing SSRF problem in webhook handlers show why Go's safety guarantees don't cover application logic.]]></description>
      <link>https://safeguard.sh/resources/blog/top-open-source-vulnerabilities-go-ecosystem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-open-source-vulnerabilities-go-ecosystem</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Java ecosystem's recurring vulnerability classes: deserialization, XXE, and JNDI injection]]></title>
      <description><![CDATA[Log4Shell scored a 10.0 CVSS and Spring4Shell followed five months later — both traced back to two patterns Java has repeated for a decade.]]></description>
      <link>https://safeguard.sh/resources/blog/top-open-source-vulnerabilities-java-ecosystem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-open-source-vulnerabilities-java-ecosystem</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Top open-source vulnerabilities in the npm ecosystem]]></title>
      <description><![CDATA[Sonatype logged 512,000+ malicious npm packages in a year — a 156% jump. Here are the recurring vulnerability classes and how to catch them in CI.]]></description>
      <link>https://safeguard.sh/resources/blog/top-open-source-vulnerabilities-javascript-ecosystem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-open-source-vulnerabilities-javascript-ecosystem</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Recurring vulnerability patterns in the PyPI ecosystem]]></title>
      <description><![CDATA[PyYAML shipped two rounds of deserialization fixes in under two years — CVE-2017-18342 and CVE-2020-14343 — because the underlying pattern kept resurfacing.]]></description>
      <link>https://safeguard.sh/resources/blog/top-open-source-vulnerabilities-python-ecosystem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-open-source-vulnerabilities-python-ecosystem</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Typosquatting and dependency confusion: a defense guide]]></title>
      <description><![CDATA[In 2021 one researcher got code execution inside 35+ companies for $130,000+ in bounties — without exploiting a single vulnerability. Here's how to close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/typosquatting-and-dependency-confusion-defense-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/typosquatting-and-dependency-confusion-defense-guide</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[XSS defaults and escape hatches: React, Vue, and Angular compared]]></title>
      <description><![CDATA[All three major frameworks escape output by default, but each ships a named escape hatch that turns raw HTML back on — and only one sanitizes it automatically.]]></description>
      <link>https://safeguard.sh/resources/blog/xss-prevention-in-modern-frontend-frameworks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xss-prevention-in-modern-frontend-frameworks</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[NoSQL Injection Attack Techniques]]></title>
      <description><![CDATA[NoSQL injection lets attackers bypass logins and hijack MongoDB/CouchDB apps using operators like $ne and $where. Here's how it works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/nosql-injection-attack-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nosql-injection-attack-techniques</guid>
      <pubDate>Tue, 14 Jul 2026 08:25:06 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best binary analysis and reverse engineering tools]]></title>
      <description><![CDATA[A practical, no-hype guide to binary analysis tools — from Ghidra and IDA Pro to firmware-focused platforms — with real strengths, limitations, and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/best-binary-analysis-and-reverse-engineering-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-binary-analysis-and-reverse-engineering-tools</guid>
      <pubDate>Tue, 14 Jul 2026 07:04:40 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Malicious VS Code extensions report]]></title>
      <description><![CDATA[150+ malicious VS Code extensions have been pulled from marketplaces since 2024. Here's how the attacks work — and how to defend against them.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-vs-code-extensions-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-vs-code-extensions-report</guid>
      <pubDate>Tue, 14 Jul 2026 05:44:13 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best fuzz testing tools for finding software vulnerabilities]]></title>
      <description><![CDATA[A practical, no-hype comparison of AFL++, libFuzzer, OSS-Fuzz, Honggfuzz, Jazzer, and Mayhem — with real strengths, limitations, and how to choose.]]></description>
      <link>https://safeguard.sh/resources/blog/best-fuzz-testing-tools-for-finding-software-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-fuzz-testing-tools-for-finding-software-vulnerabilities</guid>
      <pubDate>Tue, 14 Jul 2026 04:23:46 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Terraform Registry module vulnerability trends]]></title>
      <description><![CDATA[Registry-wide analysis shows a rising share of Terraform modules carry stale provider pins and insecure defaults — here's what's driving it and how to respond.]]></description>
      <link>https://safeguard.sh/resources/blog/terraform-registry-module-vulnerability-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/terraform-registry-module-vulnerability-trends</guid>
      <pubDate>Tue, 14 Jul 2026 03:03:20 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[XPath Injection Vulnerabilities]]></title>
      <description><![CDATA[XPath injection lets attackers rewrite XML queries to bypass logins and steal data. Here is how it works, real incidents, and how Safeguard defends against it.]]></description>
      <link>https://safeguard.sh/resources/blog/xpath-injection-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xpath-injection-vulnerabilities</guid>
      <pubDate>Tue, 14 Jul 2026 01:42:53 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best API security testing tools]]></title>
      <description><![CDATA[A practical, no-hype comparison of API security testing tools — from OWASP ZAP to Salt Security — covering REST/GraphQL coverage, posture management, and real tradeoffs.]]></description>
      <link>https://safeguard.sh/resources/blog/best-api-security-testing-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-api-security-testing-tools</guid>
      <pubDate>Tue, 14 Jul 2026 00:22:26 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Homebrew formula security incidents]]></title>
      <description><![CDATA[A timeline of Homebrew formula security incidents — from the 2018 Jenkins token leak to 2026's Trivy tap compromise — and what Homebrew's Tap Trust fix means for security teams.]]></description>
      <link>https://safeguard.sh/resources/blog/homebrew-formula-security-incidents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/homebrew-formula-security-incidents</guid>
      <pubDate>Mon, 13 Jul 2026 23:02:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Object Injection Vulnerabilities in PHP and Node.js]]></title>
      <description><![CDATA[PHP's unserialize() and Node's insecure deserialization both let attackers forge objects and execute code. Here's how object injection works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/object-injection-vulnerabilities-in-php-and-nodejs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/object-injection-vulnerabilities-in-php-and-nodejs</guid>
      <pubDate>Mon, 13 Jul 2026 21:41:33 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best software composition analysis tools for mobile appli...]]></title>
      <description><![CDATA[A no-hype comparison of mobile SCA tools for scanning iOS and Android dependencies, generating SBOMs, and catching open-source vulnerabilities before release.]]></description>
      <link>https://safeguard.sh/resources/blog/best-software-composition-analysis-tools-for-mobile-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-software-composition-analysis-tools-for-mobile-applications</guid>
      <pubDate>Mon, 13 Jul 2026 20:21:06 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Web API Security: A Practical Guide to Protecting Your APIs]]></title>
      <description><![CDATA[Web API security is about controlling who can call your endpoints, what they can do, and what data they can reach. Here are the risks that matter and the defenses that work.]]></description>
      <link>https://safeguard.sh/resources/blog/web-api-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-api-security</guid>
      <pubDate>Mon, 13 Jul 2026 19:00:40 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The XZ Utils backdoor: anatomy of a supply chain attack]]></title>
      <description><![CDATA[A two-year maintainer-trust takeover placed a pre-auth SSH backdoor inside xz-utils. Heres how CVE-2024-3094 was built, hidden, and caught in time.]]></description>
      <link>https://safeguard.sh/resources/blog/the-xz-utils-backdoor-anatomy-of-a-supply-chain-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-xz-utils-backdoor-anatomy-of-a-supply-chain-attack</guid>
      <pubDate>Mon, 13 Jul 2026 17:40:13 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Automating Open Source License Compliance: From Manual Audits to Continuous Enforcement]]></title>
      <description><![CDATA[Manual license audits cannot keep pace with modern dependency trees. Automated license detection, policy enforcement, and compliance documentation turn a legal bottleneck into a developer workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-license-compliance-automation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-license-compliance-automation</guid>
      <pubDate>Mon, 13 Jul 2026 16:19:46 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Expression Language Injection (ELI) in Java Applications]]></title>
      <description><![CDATA[Expression language injection in Java has powered some of the decade's worst breaches, from Equifax to Confluence. Here's how OGNL and SpEL flaws actually get exploited.]]></description>
      <link>https://safeguard.sh/resources/blog/expression-language-injection-eli-in-java-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/expression-language-injection-eli-in-java-applications</guid>
      <pubDate>Mon, 13 Jul 2026 14:59:19 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best container base image hardening tools]]></title>
      <description><![CDATA[A buyer's guide to container base image hardening tools -- comparing Chainguard, Distroless, DockerSlim, Red Hat UBI, Wolfi, and Bitnami on real strengths and limitations.]]></description>
      <link>https://safeguard.sh/resources/blog/best-container-base-image-hardening-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-container-base-image-hardening-tools</guid>
      <pubDate>Mon, 13 Jul 2026 13:38:53 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Codecov Bash Uploader supply chain breach]]></title>
      <description><![CDATA[A look back at the 2021 Codecov Bash Uploader breach: how a tampered CI script exfiltrated secrets for two months, and what it teaches about supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/codecov-bash-uploader-supply-chain-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/codecov-bash-uploader-supply-chain-breach</guid>
      <pubDate>Mon, 13 Jul 2026 12:18:26 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[DOM-Based XSS: Client-Side Sink Vulnerabilities]]></title>
      <description><![CDATA[DOM-based XSS sink vulnerabilities let attacker data reach dangerous JavaScript sinks without touching the server, slipping past WAFs and static scanners.]]></description>
      <link>https://safeguard.sh/resources/blog/dom-based-xss-client-side-sink-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dom-based-xss-client-side-sink-vulnerabilities</guid>
      <pubDate>Mon, 13 Jul 2026 10:57:59 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best artifact repository security tools]]></title>
      <description><![CDATA[A practical, no-hype buyer's guide to artifact repository security tools — what to evaluate, six real vendors compared fairly, and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/best-artifact-repository-security-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-artifact-repository-security-tools</guid>
      <pubDate>Mon, 13 Jul 2026 09:37:33 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[API gateway security: enforcing authN/authZ and rate limits at the edge]]></title>
      <description><![CDATA[A single unauthenticated API endpoint exposed 37 million T-Mobile accounts in 2023. Edge-enforced authZ and identity-aware rate limits are how you prevent the repeat.]]></description>
      <link>https://safeguard.sh/resources/blog/api-gateway-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-gateway-security-best-practices</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[API security fundamentals: mapping the OWASP API Top 10 to real tests]]></title>
      <description><![CDATA[OWASP's 2023 API Security Top 10 lists 10 risk categories — most start with a single curl request. Here's how to test and fix each one.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-fundamentals-owasp-top-10</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-fundamentals-owasp-top-10</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Can AI-Generated Code Be Trusted? A Security Review]]></title>
      <description><![CDATA[A 2025 USENIX study found LLMs hallucinate nonexistent packages in up to 21.7% of code samples — and attackers are already registering the names.]]></description>
      <link>https://safeguard.sh/resources/blog/can-ai-generated-code-be-trusted-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/can-ai-generated-code-be-trusted-security-review</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Container isolation mechanisms explained: namespaces, cgroups, seccomp, and gVisor]]></title>
      <description><![CDATA[Docker's default seccomp profile blocks roughly 44 of the 300-plus Linux syscalls, yet a 2019 runc escape bypassed every default namespace boundary anyway.]]></description>
      <link>https://safeguard.sh/resources/blog/container-isolation-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-isolation-best-practices</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best practices for containerizing .NET applications securely]]></title>
      <description><![CDATA[.NET 8 gave containers a built-in non-root user and chiseled images that cut one team's CVE count 92% — most Dockerfiles still don't use either.]]></description>
      <link>https://safeguard.sh/resources/blog/containerizing-dotnet-apps-securely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/containerizing-dotnet-apps-securely</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Containerizing Node.js apps: an updated Docker best-practices guide]]></title>
      <description><![CDATA[The official node image ships a built-in non-root user, but COPY still writes files as root by default — most Node.js Dockerfiles never actually drop privileges.]]></description>
      <link>https://safeguard.sh/resources/blog/containerizing-nodejs-apps-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/containerizing-nodejs-apps-best-practices</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps best practices for secure builds: an 8-point SDLC framework]]></title>
      <description><![CDATA[Log4Shell (Dec 2021) and the XZ Utils backdoor (Mar 2024) exposed two different SDLC failure modes. An 8-point framework closes both.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-best-practices-for-secure-builds</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-best-practices-for-secure-builds</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Disaster recovery testing: a practical guide to tabletop, failover, and RTO/RPO drills]]></title>
      <description><![CDATA[GitLab's 2017 outage revealed 5 backup mechanisms had silently failed for weeks — recovery took 18 hours because no one had ever test-restored one.]]></description>
      <link>https://safeguard.sh/resources/blog/disaster-recovery-testing-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/disaster-recovery-testing-best-practices</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Disaster recovery testing methodologies compared]]></title>
      <description><![CDATA[DR plans fail when they're never really tested. Here's how tabletop, simulation, parallel, and full interruption tests differ — and when each is worth the risk.]]></description>
      <link>https://safeguard.sh/resources/blog/disaster-recovery-testing-methodologies-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/disaster-recovery-testing-methodologies-compared</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Docker image vulnerability scanning: best practices for CI/CD]]></title>
      <description><![CDATA[Log4Shell hid in countless container images for years before scanning caught it. Here's how to scan base layers and gate builds before that happens again.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-image-vulnerability-scanning-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-image-vulnerability-scanning-best-practices</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why developers ignore security tools, and how to fix it]]></title>
      <description><![CDATA[Verizon's 2025 DBIR found only 54% of edge-device vulnerabilities get fully remediated within a year. The gap isn't awareness — it's friction and delay.]]></description>
      <link>https://safeguard.sh/resources/blog/driving-developer-adoption-of-appsec-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/driving-developer-adoption-of-appsec-practices</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The NSA/CISA Enduring Security Framework Guide for Developers, Reviewed]]></title>
      <description><![CDATA[NSA, CISA, and ODNI published developer supply-chain guidance in August 2022 — four years on, here's what it actually asks of your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/enduring-security-framework-guide-for-developers-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enduring-security-framework-guide-for-developers-review</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Finding and fixing XXE vulnerabilities across common XML parsers]]></title>
      <description><![CDATA[XXE is tracked as CWE-611 and lives in OWASP's misconfiguration category — because most XML parsers ship unsafe by default.]]></description>
      <link>https://safeguard.sh/resources/blog/finding-fixing-xxe-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/finding-fixing-xxe-vulnerabilities</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A practical guide to HTTP security headers: CSP, HSTS, and beyond]]></title>
      <description><![CDATA[A misconfigured checkout page let attackers skim 380,000+ card payments from British Airways in 2018. Here's how CSP, HSTS, and frame-ancestors actually stop attacks like that.]]></description>
      <link>https://safeguard.sh/resources/blog/http-security-headers-hardening-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/http-security-headers-hardening-guide</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Integrating C/C++ security scanning into CI pipelines]]></title>
      <description><![CDATA[Roughly 70% of CVEs Microsoft assigns each year are memory-safety bugs. Here's how to catch them in C/C++ CI pipelines before they ship.]]></description>
      <link>https://safeguard.sh/resources/blog/integrating-c-cpp-security-scanning-in-ci</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/integrating-c-cpp-security-scanning-in-ci</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Java deserialization gadget chains explained]]></title>
      <description><![CDATA[One 2015 talk and a tool called ysoserial turned ordinary Java libraries into remote code execution chains — here's how gadget chains work and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/java-deserialization-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-deserialization-vulnerabilities-explained</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Using Jakarta Bean Validation correctly: a defensive walkthrough]]></title>
      <description><![CDATA[Jakarta Bean Validation stops malformed input, not attackers — a 2025 Hibernate Validator EL-injection flaw (CVSS 7.3) shows what goes wrong when teams conflate the two.]]></description>
      <link>https://safeguard.sh/resources/blog/java-input-validation-bean-validation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-input-validation-bean-validation</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A practical guide to least privilege in Kubernetes RBAC]]></title>
      <description><![CDATA[One RBAC flaw, CVE-2018-1002105 (CVSS 9.8), let any authenticated user escalate to cluster-admin — here's how to actually scope roles so that never happens again.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-rbac-least-privilege</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-rbac-least-privilege</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Unified identity, segmentation, and policy-as-code for multi-cloud]]></title>
      <description><![CDATA[38% of breaches start with stolen credentials, per Verizon's 2024 DBIR — the fix for multi-cloud estates is unified identity, segmentation, and policy-as-code, not per-provider IAM.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-cloud-security-architecture-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-cloud-security-architecture-fundamentals</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The faker.js and colors.js Sabotage: What Maintainer-Driven Risk Teaches About Pinning]]></title>
      <description><![CDATA[In January 2022 a trusted maintainer bricked two npm packages with a combined 26M+ weekly downloads — from his own account, with valid credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-faker-package-supply-chain-lesson</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-faker-package-supply-chain-lesson</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A patching playbook for critical open-source CVEs]]></title>
      <description><![CDATA[Heartbleed, the OpenSSL punycode bug, and XZ Utils each broke a different assumption in incident response. Here's an SLA-driven playbook that survives all three.]]></description>
      <link>https://safeguard.sh/resources/blog/patching-playbook-for-critical-oss-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/patching-playbook-for-critical-oss-vulnerabilities</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Preventing insecure deserialization in Node.js]]></title>
      <description><![CDATA[A 2017 node-serialize flaw let attackers turn a signed cookie into remote code execution — here's how deserialization bugs still slip into Node apps.]]></description>
      <link>https://safeguard.sh/resources/blog/preventing-insecure-deserialization-nodejs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preventing-insecure-deserialization-nodejs</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Preventing SMTP injection vulnerabilities in email-sending code]]></title>
      <description><![CDATA[A crafted From address turned PHPMailer into a remote code execution bug in 2016 — here's how header injection works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/preventing-smtp-injection-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preventing-smtp-injection-vulnerabilities</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Preventing XSS in Java Spring and JSP applications]]></title>
      <description><![CDATA[OWASP folded XSS into A03:2021-Injection, present in ~3.37% of tested apps — raw JSP EL output and a missing CSP header are still the two most common causes.]]></description>
      <link>https://safeguard.sh/resources/blog/preventing-xss-in-java-web-apps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preventing-xss-in-java-web-apps</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How catastrophic regex backtracking causes ReDoS — and how to stop it]]></title>
      <description><![CDATA[A single bad regex took Cloudflare's global network to ~100% CPU for 27 minutes in 2019. Here's the backtracking mechanics behind ReDoS and how to rewrite unsafe patterns.]]></description>
      <link>https://safeguard.sh/resources/blog/redos-regex-denial-of-service-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/redos-regex-denial-of-service-prevention</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing Your Ruby Dev Environment on macOS: rbenv, rvm, and Checksums]]></title>
      <description><![CDATA[60 malicious RubyGems downloaded ~275,000 times went undetected for years — here's how to actually verify what rbenv or rvm installs on your Mac.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-ruby-install-macos-dev-environment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-ruby-install-macos-dev-environment</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Safely Parsing Untrusted URLs in Node.js]]></title>
      <description><![CDATA[Node's legacy url.parse() is deprecated (DEP0169), and parser mismatches between it, the WHATWG URL API, and fetchers are a documented root cause of SSRF and open redirects.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-url-validation-javascript</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-url-validation-javascript</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best practices for securing Kubernetes ConfigMaps]]></title>
      <description><![CDATA[ConfigMaps store plaintext in etcd with no size guardrail beyond 1 MiB — teams that drop credentials in them expose secrets to a far bigger RBAC audience.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-kubernetes-configmaps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-kubernetes-configmaps</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Security compliance frameworks cheat sheet: SOC 2, ISO 27001, PCI DSS, HIPAA]]></title>
      <description><![CDATA[SOC 2, ISO 27001, PCI DSS 4.0, and HIPAA share roughly the same engineering controls — build them once and stop re-implementing access control four times.]]></description>
      <link>https://safeguard.sh/resources/blog/security-compliance-frameworks-cheat-sheet</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-compliance-frameworks-cheat-sheet</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[XPath injection: how it happens and how to stop it in Java, .NET, and PHP]]></title>
      <description><![CDATA[A 2024 GeoServer flaw showed unsanitized input reaching an XPath evaluator can mean remote code execution, not just data leakage. Here's how to prevent it.]]></description>
      <link>https://safeguard.sh/resources/blog/xpath-injection-prevention-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xpath-injection-prevention-guide</guid>
      <pubDate>Mon, 13 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[UAParser.js npm package compromise]]></title>
      <description><![CDATA[A deep dive into the 2021 ua-parser-js npm compromise: how a hijacked maintainer account delivered cryptominers and credential stealers to millions.]]></description>
      <link>https://safeguard.sh/resources/blog/uaparserjs-npm-package-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uaparserjs-npm-package-compromise</guid>
      <pubDate>Mon, 13 Jul 2026 08:17:06 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Prototype Pollution in JavaScript Applications]]></title>
      <description><![CDATA[Prototype pollution has hit lodash, jQuery, and minimist with real CVEs, from DoS to RCE. Here's how the bug works and how Safeguard catches it before it ships.]]></description>
      <link>https://safeguard.sh/resources/blog/prototype-pollution-in-javascript-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prototype-pollution-in-javascript-applications</guid>
      <pubDate>Mon, 13 Jul 2026 06:56:39 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best pull request and code review security automation tools]]></title>
      <description><![CDATA[A candid buyer's guide to pull request security automation tools — evaluation criteria, six real vendors compared, and where Safeguard fits in your stack.]]></description>
      <link>https://safeguard.sh/resources/blog/best-pull-request-and-code-review-security-automation-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-pull-request-and-code-review-security-automation-tools</guid>
      <pubDate>Mon, 13 Jul 2026 05:36:13 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Polyfill.io supply chain attack]]></title>
      <description><![CDATA[How a domain sale turned a trusted CDN into a malware vector for 100,000+ sites — and what the polyfill.io incident teaches defenders about third-party script risk.]]></description>
      <link>https://safeguard.sh/resources/blog/polyfillio-supply-chain-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/polyfillio-supply-chain-attack</guid>
      <pubDate>Mon, 13 Jul 2026 04:15:46 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[ReDoS: Regular Expression Denial of Service Attacks]]></title>
      <description><![CDATA[ReDoS took down Cloudflare's global network for 27 minutes in 2019 and Stack Overflow in 2016. Here's how one bad regex causes an outage, and how to catch it first.]]></description>
      <link>https://safeguard.sh/resources/blog/redos-regular-expression-denial-of-service-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/redos-regular-expression-denial-of-service-attacks</guid>
      <pubDate>Mon, 13 Jul 2026 02:55:19 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best dependency update automation tools]]></title>
      <description><![CDATA[A practical buyer's guide to dependency update automation tools -- what to evaluate, and how Dependabot, Renovate, Snyk, Socket, and others really compare.]]></description>
      <link>https://safeguard.sh/resources/blog/best-dependency-update-automation-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-dependency-update-automation-tools</guid>
      <pubDate>Mon, 13 Jul 2026 01:34:53 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Insider Threats in Open Source Projects: Lessons from XZ Utils]]></title>
      <description><![CDATA[The XZ Utils backdoor was a three-year social engineering operation, not a coding mistake. What the timeline shows about maintainer trust, and what you can actually monitor.]]></description>
      <link>https://safeguard.sh/resources/blog/insider-threats-in-open-source-projects-lessons-from-xz-utils</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insider-threats-in-open-source-projects-lessons-from-xz-utils</guid>
      <pubDate>Mon, 13 Jul 2026 00:14:26 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Marcus Webb)</author>
    </item>
    <item>
      <title><![CDATA[3CX desktop app supply chain compromise]]></title>
      <description><![CDATA[A breakdown of the 3CX supply chain compromise: how Lazarus-linked attackers poisoned a signed desktop build via a nested vendor attack chain.]]></description>
      <link>https://safeguard.sh/resources/blog/3cx-desktop-app-supply-chain-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/3cx-desktop-app-supply-chain-compromise</guid>
      <pubDate>Sun, 12 Jul 2026 22:53:59 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Code Injection via eval() and exec() Across Languages]]></title>
      <description><![CDATA[eval() and exec() turn dynamic code execution into remote code execution. A cross-language look at how it happens in Python, JS, PHP, and Ruby.]]></description>
      <link>https://safeguard.sh/resources/blog/code-injection-via-eval-and-exec-across-languages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-injection-via-eval-and-exec-across-languages</guid>
      <pubDate>Sun, 12 Jul 2026 21:33:32 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best software supply chain attack simulation and red team...]]></title>
      <description><![CDATA[A practical, no-hype comparison of supply chain attack simulation tools for red teams -- what to evaluate, six real vendors reviewed, and where Safeguard fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/best-software-supply-chain-attack-simulation-and-red-teaming-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-software-supply-chain-attack-simulation-and-red-teaming-tools</guid>
      <pubDate>Sun, 12 Jul 2026 20:13:06 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[PHP Git server compromise incident (2021)]]></title>
      <description><![CDATA[In 2021, attackers pushed a hidden RCE backdoor into PHP's own source repo under forged maintainer names — a supply chain near-miss worth revisiting.]]></description>
      <link>https://safeguard.sh/resources/blog/php-git-server-compromise-incident-2021</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-git-server-compromise-incident-2021</guid>
      <pubDate>Sun, 12 Jul 2026 18:52:39 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Broken Object Level Authorization (BOLA/IDOR) in APIs]]></title>
      <description><![CDATA[BOLA/IDOR has topped the OWASP API Security Top 10 since 2019. Here's how USPS, Peloton, and Parler got breached by it—and how to catch it before you do.]]></description>
      <link>https://safeguard.sh/resources/blog/broken-object-level-authorization-bolaidor-in-apis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/broken-object-level-authorization-bolaidor-in-apis</guid>
      <pubDate>Sun, 12 Jul 2026 17:32:12 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best git commit signing and repository integrity tools]]></title>
      <description><![CDATA[A buyer's guide to git commit signing tools -- GPG, SSH signing, Sigstore, gittuf, and more -- compared honestly for real repository integrity verification.]]></description>
      <link>https://safeguard.sh/resources/blog/best-git-commit-signing-and-repository-integrity-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-git-commit-signing-and-repository-integrity-tools</guid>
      <pubDate>Sun, 12 Jul 2026 16:11:46 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Colors.js and Faker.js maintainer sabotage incident]]></title>
      <description><![CDATA[In January 2022, colors.js and faker.js maintainer Marak Squires sabotaged his own packages, breaking thousands of builds—no compromise required.]]></description>
      <link>https://safeguard.sh/resources/blog/colorsjs-and-fakerjs-maintainer-sabotage-incident</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/colorsjs-and-fakerjs-maintainer-sabotage-incident</guid>
      <pubDate>Sun, 12 Jul 2026 14:51:19 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Broken Object Property Level Authorization (BOPLA)]]></title>
      <description><![CDATA[BOPLA (OWASP API3:2023) lets APIs correctly check object access while leaking or accepting the wrong fields. Real breaches show why it's so hard to catch.]]></description>
      <link>https://safeguard.sh/resources/blog/broken-object-property-level-authorization-bopla</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/broken-object-property-level-authorization-bopla</guid>
      <pubDate>Sun, 12 Jul 2026 13:30:52 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best DevSecOps platforms for shift-left security]]></title>
      <description><![CDATA[A fair, no-hype comparison of DevSecOps platforms — GitLab, GitHub, Snyk, Wiz, JFrog, and Checkmarx — plus what to evaluate for real shift-left security.]]></description>
      <link>https://safeguard.sh/resources/blog/best-devsecops-platforms-for-shift-left-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-devsecops-platforms-for-shift-left-security</guid>
      <pubDate>Sun, 12 Jul 2026 12:10:26 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[node-ipc protestware incident]]></title>
      <description><![CDATA[How a trusted maintainer turned node-ipc into "protestware," why transitive dependencies hid the blast radius, and what SBOM visibility could have prevented.]]></description>
      <link>https://safeguard.sh/resources/blog/node-ipc-protestware-incident</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-ipc-protestware-incident</guid>
      <pubDate>Sun, 12 Jul 2026 10:49:59 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Gold Open Source: A Free Directory for the Whole Supply Chain — Now in Your Browser]]></title>
      <description><![CDATA[Gold Open Source is Safeguard's free, no-login directory of security-verified open-source software. It now covers AI models, MCP servers, agent skills, chip manufacturers, and the full MITRE ATT&CK framework — and ships as a Chrome extension.]]></description>
      <link>https://safeguard.sh/resources/blog/gold-open-source-directory-chrome-extension</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gold-open-source-directory-chrome-extension</guid>
      <pubDate>Sun, 12 Jul 2026 10:00:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Broken Function Level Authorization (BFLA) in APIs]]></title>
      <description><![CDATA[BFLA lets a regular user call admin-only API functions. Here's how the USPS, Peloton, and Coinbase incidents happened — and how to catch it before attackers do.]]></description>
      <link>https://safeguard.sh/resources/blog/broken-function-level-authorization-bfla-in-apis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/broken-function-level-authorization-bfla-in-apis</guid>
      <pubDate>Sun, 12 Jul 2026 09:29:32 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Text4Shell deep dive: how CVE-2022-42889 turned string formatting into RCE]]></title>
      <description><![CDATA[CVSS 9.8. Apache Commons Text 1.5–1.9 ran attacker strings through a script interpolator by default — here's the root cause and the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-commons-text-cve-2022-42889-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-commons-text-cve-2022-42889-analysis</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The 2026 AWS Security Checklist: Account, IAM, Network, and Data Controls]]></title>
      <description><![CDATA[One SSRF call against an unpatched WAF and a permissive IAM role were enough to expose 106 million Capital One records in 2019 — here's the checklist that stops it.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-security-best-practices-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-security-best-practices-checklist</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Building security programs with limited headcount]]></title>
      <description><![CDATA[The developer-to-security ratio is roughly 100:1. A framework for scaling AppSec impact through automation and enablement when hiring isn't the answer.]]></description>
      <link>https://safeguard.sh/resources/blog/building-security-programs-with-limited-headcount</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-security-programs-with-limited-headcount</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Choosing a secure Node.js Docker base image]]></title>
      <description><![CDATA[A stock node:18 image ships at roughly 940MB with 100-200 tracked CVEs; distroless variants land 80% smaller with 0-2. Here's the real tradeoff.]]></description>
      <link>https://safeguard.sh/resources/blog/choosing-secure-nodejs-docker-base-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/choosing-secure-nodejs-docker-base-images</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Security considerations for authenticating CLI tools through corporate proxies]]></title>
      <description><![CDATA[Two 2026 curl CVEs show proxy credentials leaking across redirects and reused connections — plus why .npmrc still stores proxy passwords in plaintext.]]></description>
      <link>https://safeguard.sh/resources/blog/cli-proxy-authentication-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cli-proxy-authentication-security-considerations</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The most common AWS misconfigurations in 2026, with detection commands]]></title>
      <description><![CDATA[Public S3 buckets, wildcard IAM policies, and 0.0.0.0/0 security groups remain the top three AWS findings — here's how to detect each with native tools.]]></description>
      <link>https://safeguard.sh/resources/blog/common-aws-misconfigurations-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/common-aws-misconfigurations-2026</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Contributing to open source securely: a guide for new maintainers and PR authors]]></title>
      <description><![CDATA[It took roughly two years of trusted commits before the xz-utils backdoor shipped. Here's how new contributors avoid becoming the next weak link.]]></description>
      <link>https://safeguard.sh/resources/blog/contributing-to-open-source-securely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/contributing-to-open-source-securely</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Developer empowerment in cloud security: a guardrails-first framework]]></title>
      <description><![CDATA[Gartner estimated through 2025 that 99% of cloud breaches would be the customer's fault, not the provider's — guardrails at the point of action are how you fix that.]]></description>
      <link>https://safeguard.sh/resources/blog/developer-empowerment-in-cloud-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/developer-empowerment-in-cloud-security</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why Cloud Security Outcomes Depend on Developers, Not Gatekeepers]]></title>
      <description><![CDATA[Gartner projected 99% of cloud security failures through 2025 would be the customer's fault — the fix is guardrails developers own, not a central team reviewing after the fact.]]></description>
      <link>https://safeguard.sh/resources/blog/developers-role-in-cloud-security-ownership</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/developers-role-in-cloud-security-ownership</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[DNS attack techniques and defenses]]></title>
      <description><![CDATA[Cache poisoning, tunneling, and NXDOMAIN floods all abuse the same trust: DNS was built to be fast and open, not authenticated.]]></description>
      <link>https://safeguard.sh/resources/blog/dns-attack-techniques-and-defenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dns-attack-techniques-and-defenses</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Four Most Common Docker Image Vulnerabilities (And How to Fix Them)]]></title>
      <description><![CDATA[Sysdig found 76% of containers still run as root — one of four Docker image flaws that turn a routine build into a host compromise.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-security-vulnerabilities-and-mitigations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-security-vulnerabilities-and-mitigations</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing a Dockerized Rails Local Dev Environment]]></title>
      <description><![CDATA[A misplaced master.key or a permissive COPY . . can bake Rails credentials into an image layer forever — here's how to Dockerize Rails dev safely.]]></description>
      <link>https://safeguard.sh/resources/blog/dockerizing-rails-local-dev-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dockerizing-rails-local-dev-security</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Fuzz testing for AppSec teams: AFL++, libFuzzer, and OSS-Fuzz]]></title>
      <description><![CDATA[OSS-Fuzz has found over 13,000 vulnerabilities since 2016, yet most AppSec teams still treat fuzzing as a research curiosity rather than a pipeline stage.]]></description>
      <link>https://safeguard.sh/resources/blog/fuzz-testing-for-appsec-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fuzz-testing-for-appsec-teams</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Generating CycloneDX and SPDX SBOMs from Java Projects with Maven and Gradle]]></title>
      <description><![CDATA[CISA's 2025 draft update proposes four new fields on top of NTIA's minimum elements, from 7 to 11 — most Maven and Gradle-generated SBOMs still fail that bar.]]></description>
      <link>https://safeguard.sh/resources/blog/generating-sboms-java-maven-gradle</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/generating-sboms-java-maven-gradle</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to actually implement TLS correctly in Python]]></title>
      <description><![CDATA[One `verify=False` in a requests call disables both certificate and hostname checks — the same escape hatch PEP 476 tried to close in 2014.]]></description>
      <link>https://safeguard.sh/resources/blog/implementing-tls-in-python-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/implementing-tls-in-python-applications</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Java DTOs for secure data handling]]></title>
      <description><![CDATA[A single @RequestBody bound to a JPA entity can let attackers set fields like isAdmin — DTOs close that gap by design, not by discipline.]]></description>
      <link>https://safeguard.sh/resources/blog/java-dtos-for-secure-data-handling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-dtos-for-secure-data-handling</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Writing your first Jest unit tests for security-critical JavaScript]]></title>
      <description><![CDATA[Jest ships to ~41M weekly npm installs with assertions, mocking, and coverage built in — here's how to structure your first tests around security logic.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-unit-testing-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-unit-testing-fundamentals</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Know your cloud environment: a practical asset inventory methodology]]></title>
      <description><![CDATA[Gartner projects that through 2025, 99% of cloud security failures will be the customer's fault — almost always because an asset nobody tracked got misconfigured.]]></description>
      <link>https://safeguard.sh/resources/blog/know-your-cloud-environment-asset-inventory</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/know-your-cloud-environment-asset-inventory</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Minimal container images with ko: evaluating distroless Go builds]]></title>
      <description><![CDATA[ko builds Go containers straight from source onto a shell-less distroless base with no Dockerfile — cutting attack surface, and debugging tools, at once.]]></description>
      <link>https://safeguard.sh/resources/blog/minimal-container-images-with-ko</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/minimal-container-images-with-ko</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Mocking APIs for secure testing: MSW and json-server for error and auth flows]]></title>
      <description><![CDATA[MSW intercepts requests at the network layer; json-server spins up a fake REST API in one command. Neither should ever touch a real backend or real credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/mocking-apis-for-secure-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mocking-apis-for-secure-testing</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The security implications of Node.js worker_threads]]></title>
      <description><![CDATA[Node.js worker_threads share memory across V8 isolates by design — CVE-2025-23083 (CVSS 7.7) shows even the permission model meant to contain them can be bypassed.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-worker-threads-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-worker-threads-security-considerations</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Inside the OpenSSL punycode bug: why CVE-2022-3602 wasn't Heartbleed]]></title>
      <description><![CDATA[OpenSSL pre-announced a 'critical' flaw in October 2022. It shipped as HIGH severity. Here's the buffer overflow, the downgrade, and the safe patch path.]]></description>
      <link>https://safeguard.sh/resources/blog/openssl-cve-2022-3602-3786-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssl-cve-2022-3602-3786-deep-dive</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Python linting for security hygiene: what flake8, pylint, and bandit actually catch]]></title>
      <description><![CDATA[Bandit maps findings to CWE IDs like CWE-502 and CWE-78, but flake8 and pylint never look for a vulnerability at all — the three tools solve different problems.]]></description>
      <link>https://safeguard.sh/resources/blog/python-linting-for-security-hygiene</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-linting-for-security-hygiene</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Red team vs. blue team fundamentals: how to structure the exercise]]></title>
      <description><![CDATA[MITRE ATT&CK went public in May 2015 to give red and blue teams a shared language — most organizations still run the two in total isolation.]]></description>
      <link>https://safeguard.sh/resources/blog/red-team-vs-blue-team-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/red-team-vs-blue-team-fundamentals</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secure-by-design principles for cloud architecture: prevention over detection]]></title>
      <description><![CDATA[The 2019 Capital One breach hit 700+ S3 buckets through one SSRF call. Secure-by-design architecture stops that path before it exists.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-design-principles-for-cloud-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-design-principles-for-cloud-prevention</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing Playwright E2E Tests in GitHub Actions Without Leaking Secrets]]></title>
      <description><![CDATA[A 2025 supply-chain attack on tj-actions/changed-files hit 23,000+ repos and dumped secrets into public logs — the same CI patterns power most Playwright pipelines.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-playwright-ci-pipelines-github-actions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-playwright-ci-pipelines-github-actions</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing the Argo CD to Kubernetes GitOps Pipeline]]></title>
      <description><![CDATA[One symlinked Helm values file (CVE-2022-24348, CVSS 7.7) let attackers read secrets across Argo CD tenants — GitOps trust needs hardening, not just adoption.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-argocd-to-kubernetes-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-argocd-to-kubernetes-pipeline</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Piping security findings into your observability stack]]></title>
      <description><![CDATA[OCSF just cleared ITU review for ratification by June 2026 — here's how to route vulnerability and scan data into Datadog or New Relic without drowning your on-call rotation.]]></description>
      <link>https://safeguard.sh/resources/blog/sending-security-telemetry-to-observability-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sending-security-telemetry-to-observability-platforms</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Root cause: CVE-2022-40764, the Snyk CLI command injection]]></title>
      <description><![CDATA[A crafted vendor.json field let attackers run shell commands from inside a security scanner — CVE-2022-40764 shows why CLI tools must never build shell strings.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-cli-command-injection-cve-2022-40764-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-cli-command-injection-cve-2022-40764-analysis</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A guide to scanning Terraform IaC for misconfigurations before deployment]]></title>
      <description><![CDATA[tfsec folded into Trivy in February 2023. Sentinel gates plans in Terraform Enterprise. Here's how to catch misconfigured infrastructure before it's ever provisioned.]]></description>
      <link>https://safeguard.sh/resources/blog/terraform-iac-security-scanning-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/terraform-iac-security-scanning-guide</guid>
      <pubDate>Sun, 12 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best security champions program and developer training pl...]]></title>
      <description><![CDATA[A practical buyer's guide to security champions program tools — evaluation criteria, six real vendors compared honestly, and how to measure whether training actually reduces vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/best-security-champions-program-and-developer-training-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-security-champions-program-and-developer-training-platforms</guid>
      <pubDate>Sun, 12 Jul 2026 08:09:06 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[p-limit: Safe Concurrency Control in Node.js]]></title>
      <description><![CDATA[The p-limit npm package caps how many promises run at once — a one-function library that quietly prevents self-inflicted outages, API bans, and resource exhaustion in Node.js services.]]></description>
      <link>https://safeguard.sh/resources/blog/p-limit-npm-concurrency-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/p-limit-npm-concurrency-guide</guid>
      <pubDate>Sun, 12 Jul 2026 06:48:39 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[libwebp Vulnerability: What CVE-2023-4863 Means and How to Fix It]]></title>
      <description><![CDATA[The libwebp vulnerability CVE-2023-4863 was a heap buffer overflow exploited in the wild. Here is what it affected, why it was everywhere, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/libwebp-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/libwebp-vulnerability</guid>
      <pubDate>Sun, 12 Jul 2026 05:28:12 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[OpenRouter API: Security Considerations When Routing LLM Traffic]]></title>
      <description><![CDATA[The OpenRouter API gives you one endpoint and one key to reach hundreds of LLMs across providers. That convenience concentrates risk in a single credential and a third-party hop worth securing deliberately.]]></description>
      <link>https://safeguard.sh/resources/blog/open-router-api</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-router-api</guid>
      <pubDate>Sun, 12 Jul 2026 04:07:45 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Shai-Hulud self-propagating npm worm campaign]]></title>
      <description><![CDATA[Inside Shai-Hulud, the self-propagating npm worm that hijacked publish tokens to auto-infect hundreds of packages across the JavaScript ecosystem.]]></description>
      <link>https://safeguard.sh/resources/blog/shai-hulud-self-propagating-npm-worm-campaign</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shai-hulud-self-propagating-npm-worm-campaign</guid>
      <pubDate>Sun, 12 Jul 2026 02:47:19 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[K8s Admission Controllers: Enforcing Policy at the Kubernetes API]]></title>
      <description><![CDATA[A k8s admission controller intercepts every request to the API server and can validate or mutate it, making it the natural enforcement point for security policy.]]></description>
      <link>https://safeguard.sh/resources/blog/k8s-admission-controller</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/k8s-admission-controller</guid>
      <pubDate>Sun, 12 Jul 2026 01:26:52 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Buffer Overflow Attack: How It Works and How to Prevent It]]></title>
      <description><![CDATA[A buffer overflow attack overwrites memory past a buffer's bounds to corrupt data or hijack execution. Here's how it works conceptually and the defenses that stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/buffer-overflow-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buffer-overflow-attack</guid>
      <pubDate>Sun, 12 Jul 2026 00:06:25 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[App Vulnerability Classes: A Field Guide]]></title>
      <description><![CDATA[Not every app vulnerability behaves the same way — this field guide groups the common web vulnerabilities by root cause so triage and prevention actually map to something repeatable.]]></description>
      <link>https://safeguard.sh/resources/blog/app-vulnerability-classes-a-field-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/app-vulnerability-classes-a-field-guide</guid>
      <pubDate>Sat, 11 Jul 2026 22:45:59 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Unrestricted Resource Consumption in APIs]]></title>
      <description><![CDATA[API4:2023 shows how a single unbounded request—GraphQL depth, a ReDoS regex, an unthrottled upload—can take down an API or run up a cloud bill.]]></description>
      <link>https://safeguard.sh/resources/blog/unrestricted-resource-consumption-in-apis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unrestricted-resource-consumption-in-apis</guid>
      <pubDate>Sat, 11 Jul 2026 21:25:32 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Black Box Fuzzing, Explained]]></title>
      <description><![CDATA[Black box fuzzing throws malformed input at a running application with zero knowledge of its internals, and it still finds crashes and memory bugs white box testing misses — here's how it works and where it fits in a security program.]]></description>
      <link>https://safeguard.sh/resources/blog/black-box-fuzzing-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/black-box-fuzzing-explained</guid>
      <pubDate>Sat, 11 Jul 2026 20:05:05 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Best bug bounty and vulnerability disclosure platforms]]></title>
      <description><![CDATA[A practical buyers guide to bug bounty platforms and vulnerability disclosure program software, comparing HackerOne, Bugcrowd, Intigriti, YesWeHack, and more.]]></description>
      <link>https://safeguard.sh/resources/blog/best-bug-bounty-and-vulnerability-disclosure-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-bug-bounty-and-vulnerability-disclosure-platforms</guid>
      <pubDate>Sat, 11 Jul 2026 18:44:39 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[ZAP Scanner: How OWASP ZAP Works and When to Use It]]></title>
      <description><![CDATA[ZAP is the most widely used free DAST scanner. Here is how its spider, passive, and active engines work, where it fits in CI, and its honest limits.]]></description>
      <link>https://safeguard.sh/resources/blog/zap-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zap-scanner</guid>
      <pubDate>Sat, 11 Jul 2026 17:24:12 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[lottie-player npm supply chain compromise]]></title>
      <description><![CDATA[A phishing-driven npm token takeover pushed a crypto wallet drainer into lottie-player, hitting 94K weekly downloads before LottieFiles shipped a fix.]]></description>
      <link>https://safeguard.sh/resources/blog/lottie-player-npm-supply-chain-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lottie-player-npm-supply-chain-compromise</guid>
      <pubDate>Sat, 11 Jul 2026 16:03:45 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Unrestricted Access to Sensitive Business Flows]]></title>
      <description><![CDATA[OWASP's API10:2023 category covers a threat scanners can't see: bots abusing legitimate business flows like checkout and ticketing at scale. Here's how it works.]]></description>
      <link>https://safeguard.sh/resources/blog/unrestricted-access-to-sensitive-business-flows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unrestricted-access-to-sensitive-business-flows</guid>
      <pubDate>Sat, 11 Jul 2026 14:43:18 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Best penetration testing platforms and services]]></title>
      <description><![CDATA[A practical, no-hype comparison of penetration testing platforms and pentest-as-a-service vendors — what to evaluate, six real providers reviewed, and where supply chain risk fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/best-penetration-testing-platforms-and-services</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-penetration-testing-platforms-and-services</guid>
      <pubDate>Sat, 11 Jul 2026 13:22:52 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[jQuery CDN supply chain risk analysis]]></title>
      <description><![CDATA[jQuery loads on ~75% of websites, often via CDNs with no SRI or version pinning. The cdnjs RCE and Polyfill.io hijack show why that trust model keeps failing.]]></description>
      <link>https://safeguard.sh/resources/blog/jquery-cdn-supply-chain-risk-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jquery-cdn-supply-chain-risk-analysis</guid>
      <pubDate>Sat, 11 Jul 2026 12:02:25 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Unsafe Consumption of Third-Party APIs]]></title>
      <description><![CDATA[Third-party APIs get trusted more than user input ever would — and attackers know it. Real breaches from Polyfill.io to 3CX show why that trust is misplaced.]]></description>
      <link>https://safeguard.sh/resources/blog/unsafe-consumption-of-third-party-apis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unsafe-consumption-of-third-party-apis</guid>
      <pubDate>Sat, 11 Jul 2026 10:41:58 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best attack surface management (ASM) tools]]></title>
      <description><![CDATA[A practical buyer's guide comparing top attack surface management tools and ASM platforms, with honest strengths, limitations, and evaluation criteria.]]></description>
      <link>https://safeguard.sh/resources/blog/best-attack-surface-management-asm-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-attack-surface-management-asm-tools</guid>
      <pubDate>Sat, 11 Jul 2026 09:21:32 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Connecting build, deploy, and runtime security into one AppSec lifecycle]]></title>
      <description><![CDATA[The XZ Utils backdoor (CVE-2024-3094) was found in the build chain; most tools that would have caught it stop at deploy. Here's how to close that gap.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-native-application-security-lifecycle</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-native-application-security-lifecycle</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The most common cloud misconfigurations, and the queries that catch them]]></title>
      <description><![CDATA[Cloud misconfiguration was the initial attack vector in 15% of breaches in IBM's 2024 study — tied with phishing. Here are the six patterns and the queries to find them.]]></description>
      <link>https://safeguard.sh/resources/blog/common-cloud-security-misconfiguration-challenges</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/common-cloud-security-misconfiguration-challenges</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Container-handling security fundamentals: immutability, signing, and privilege drops]]></title>
      <description><![CDATA[Two runc CVEs, five years apart, both turned root-in-container into root-on-host — proof that container isolation needs backup, not blind trust.]]></description>
      <link>https://safeguard.sh/resources/blog/container-handling-security-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-handling-security-fundamentals</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Container security: five best practices for provenance, runtime, and network]]></title>
      <description><![CDATA[A single runc bug (CVE-2024-21626) enabled full container escapes in early 2024 — proof that provenance and network defaults matter as much as image scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-five-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-five-best-practices</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A hands-on stack buffer overflow in C++: root cause and mitigations]]></title>
      <description><![CDATA[The Morris Worm hit ~6,000 machines in 1988 via one unsafe gets() call. We build and hijack a stack overflow in C++ to teach why canaries and ASLR exist.]]></description>
      <link>https://safeguard.sh/resources/blog/cpp-buffer-overflow-hands-on-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cpp-buffer-overflow-hands-on-exploitation</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Modern C++ security: smart pointers, bounds checking, and static analysis]]></title>
      <description><![CDATA[Microsoft has said for years that ~70% of the CVEs it patches trace to memory-safety bugs — here's how modern C++ actually closes that gap.]]></description>
      <link>https://safeguard.sh/resources/blog/cpp-security-best-practices-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cpp-security-best-practices-overview</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-33980: Interpolation-Based RCE in Apache Commons Configuration]]></title>
      <description><![CDATA[A CVSS 9.8 flaw in Apache Commons Configuration 2.4–2.7 let default interpolators run script-engine expressions from untrusted config strings.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-33980-apache-commons-configuration-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-33980-apache-commons-configuration-rce</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A hardening checklist for modern Drupal deployments]]></title>
      <description><![CDATA[Drupal 7's 2025 end-of-life left unsupported sites exposed; here's a concrete checklist for module vetting, access control, and patch cadence on Drupal 10/11.]]></description>
      <link>https://safeguard.sh/resources/blog/drupal-hardening-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/drupal-hardening-guide</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Detecting and remediating Terraform and CloudFormation drift]]></title>
      <description><![CDATA[Terraform's own drift check can return an ambiguous exit code — here's how declared IaC state quietly diverges from live cloud resources, and how to catch it.]]></description>
      <link>https://safeguard.sh/resources/blog/infrastructure-drift-detection-and-remediation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/infrastructure-drift-detection-and-remediation</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Falco vs. Tetragon vs. Tracee: choosing a Kubernetes runtime security tool]]></title>
      <description><![CDATA[Falco graduated CNCF in February 2024, Tetragon enforces in-kernel, and Tracee ships 330+ prebuilt eBPF detections — here's when each one actually wins.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-runtime-security-tools-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-runtime-security-tools-comparison</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How modern SAST engines model data flow and taint tracking]]></title>
      <description><![CDATA[Linters flag every eval() call; SAST tools flag the two an attacker can reach. Here's how taint tracking works, and what it costs in precision and compute.]]></description>
      <link>https://safeguard.sh/resources/blog/modern-sast-how-static-analysis-works</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/modern-sast-how-static-analysis-works</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Running Multiple Custom Controllers Without RBAC or CRD Collisions]]></title>
      <description><![CDATA[Kubernetes CRDs are singletons by group and kind, and RBAC has no tenant concept — two facts that quietly break most multi-controller clusters.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-tenant-kubernetes-controller-isolation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-tenant-kubernetes-controller-isolation</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Dependency confusion on npm: how public-registry precedence became a delivery channel for post-exploitation frameworks]]></title>
      <description><![CDATA[In May 2022, Snyk found 200+ malicious npm packages, including one that polled for commands until it dropped a Cobalt Strike trojan, and another that delayed 30 minutes to dodge sandboxes.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-dependency-confusion-cobalt-strike-case-study</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-dependency-confusion-cobalt-strike-case-study</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Writing Rego policies for Kubernetes admission control and CI gates]]></title>
      <description><![CDATA[Open Policy Agent graduated CNCF on Jan 29, 2021 — yet most teams still ship Rego with no default-deny, turning a policy gate into a rubber stamp.]]></description>
      <link>https://safeguard.sh/resources/blog/opa-rego-policy-as-code-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/opa-rego-policy-as-code-guide</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The C++ supply chain has no npm — and that's the risk]]></title>
      <description><![CDATA[C++ has no single package registry like npm or PyPI, so vendored code hides provenance — the XZ Utils backdoor (CVE-2024-3094, CVSS 10.0) shows the cost.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-cpp-supply-chain-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-cpp-supply-chain-risk</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Policy as Code: Enforcing Cloud Security Guardrails in CI/CD Instead of Manual Review]]></title>
      <description><![CDATA[OPA reached CNCF Graduated status in January 2021 — yet most teams still catch misconfigured IAM roles by eyeballing a pull request.]]></description>
      <link>https://safeguard.sh/resources/blog/policy-as-code-cloud-security-automation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/policy-as-code-cloud-security-automation</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The anatomy of a PyPI credential stealer]]></title>
      <description><![CDATA[In a single 24-hour window in 2022, one actor shipped 12 malicious PyPI packages bundling Windows stealers that harvested browser, Discord, and Roblox credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-malware-credential-stealers-anatomy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-malware-credential-stealers-anatomy</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why assert is not a security control in Python]]></title>
      <description><![CDATA[Run Python with -O and every assert statement vanishes from the bytecode — including the ones guarding auth checks and input validation.]]></description>
      <link>https://safeguard.sh/resources/blog/python-assert-statement-security-pitfalls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-assert-statement-security-pitfalls</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Python code review security checklist: eval, pickle, and shell=True]]></title>
      <description><![CDATA[Bandit ships named checks for eval, pickle, and shell=True — B307, B301, B602 — yet these three smells still slip past manual review into production Python.]]></description>
      <link>https://safeguard.sh/resources/blog/python-code-review-security-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-code-review-security-checklist</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[React security best practices: stopping XSS, dangerouslySetInnerHTML, and dependency risk]]></title>
      <description><![CDATA[React auto-escapes JSX text by default, but dangerouslySetInnerHTML, href injection, and a 500-package npm worm show where that protection stops.]]></description>
      <link>https://safeguard.sh/resources/blog/react-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-security-best-practices</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Reverse shell attack mechanics and detection]]></title>
      <description><![CDATA[Reverse shells flip the direction of the connection so outbound firewall rules never fire — here is how they work and the signals that catch them anyway.]]></description>
      <link>https://safeguard.sh/resources/blog/reverse-shell-attack-mechanics-and-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reverse-shell-attack-mechanics-and-detection</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Bundler dependency resolution and safe Gemfile upgrade strategies]]></title>
      <description><![CDATA[In May 2026 RubyGems suspended new signups after attackers mass-created accounts to flood the registry with malicious gems. Here's how Bundler actually resolves risk.]]></description>
      <link>https://safeguard.sh/resources/blog/ruby-gems-dependency-management-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ruby-gems-dependency-management-guide</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How malicious Gemfile.lock entries redirect Ruby installs to attacker servers]]></title>
      <description><![CDATA[A single unreviewed remote: line in Gemfile.lock can silently reroute a bundle install — here's how Ruby lockfile injection works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/ruby-lockfile-injection-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ruby-lockfile-injection-attacks</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Is Now in Your Browser: the Chrome Extension Is Live]]></title>
      <description><![CDATA[One click on the Chrome Web Store puts Griffin AI search in a side panel next to any tab — one permission, no host access, no data collection, under 8 KiB. Here's what it does and why we built it so small.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-chrome-extension-now-on-the-chrome-web-store</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-chrome-extension-now-on-the-chrome-web-store</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Hardening a Java build pipeline in GitHub Actions]]></title>
      <description><![CDATA[23,000+ repos leaked CI secrets when tj-actions/changed-files was hijacked in March 2025. Here's how to pin, OIDC, and sign a Java pipeline against that.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-cicd-pipeline-github-actions-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-cicd-pipeline-github-actions-java</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Robust URL Validation in Python: Stopping SSRF and Open Redirects]]></title>
      <description><![CDATA[One misparsed IP string cost Capital One 106 million records. Here's how to validate URLs in Python without repeating that mistake.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-url-validation-python-ssrf</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-url-validation-python-ssrf</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Building an authenticated, TLS-secured WebSocket server in Python]]></title>
      <description><![CDATA[WebSockets skip same-origin checks by default — CWE-1385 exists because of it. Here's how to build one in Python with origin checks, TLS, and rate limits.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-websocket-server-python</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-websocket-server-python</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Hardening PHP-FPM and Apache Container Images]]></title>
      <description><![CDATA[PHP containers ship with defaults built for compatibility, not security. Opcache settings, disabled functions, and process ownership close the gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-php-containers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-php-containers</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Where Security Gates Belong in Your CI/CD Pipeline]]></title>
      <description><![CDATA[23.8 million secrets leaked on public GitHub in 2024 alone. The fix isn't more scanners — it's putting the right gate at the right stage and tuning out the noise.]]></description>
      <link>https://safeguard.sh/resources/blog/security-automation-in-the-sdlc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-automation-in-the-sdlc</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Policy-as-code for Terraform: testing before you ever run apply]]></title>
      <description><![CDATA[Checkov, OPA, and tflint each catch different Terraform mistakes — chained into CI before apply, they turn a review comment into a hard gate.]]></description>
      <link>https://safeguard.sh/resources/blog/terraform-security-testing-strategies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/terraform-security-testing-strategies</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The most common C++ vulnerability classes, and the tooling that catches them]]></title>
      <description><![CDATA[Memory-safety bugs account for roughly 70% of high-severity CVEs in large C/C++ codebases at Microsoft and Google. Here's why, and what actually stops them.]]></description>
      <link>https://safeguard.sh/resources/blog/top-cpp-memory-safety-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-cpp-memory-safety-risks</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Webhook security best practices: HMAC signing, replay protection, and IP allowlisting]]></title>
      <description><![CDATA[Stripe gives webhook signatures a 5-minute tolerance window; GitHub signs with HMAC-SHA256. Here's how to build inbound and outbound webhooks that survive both.]]></description>
      <link>https://safeguard.sh/resources/blog/webhook-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webhook-security-best-practices</guid>
      <pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[XcodeGhost iOS supply chain malware campaign]]></title>
      <description><![CDATA[XcodeGhost hid inside Xcode itself, silently infecting 4,000+ App Store apps like WeChat. Here is how the iOS supply chain malware campaign worked.]]></description>
      <link>https://safeguard.sh/resources/blog/xcodeghost-ios-supply-chain-malware-campaign</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xcodeghost-ios-supply-chain-malware-campaign</guid>
      <pubDate>Sat, 11 Jul 2026 08:01:05 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Security Misconfiguration in APIs]]></title>
      <description><![CDATA[Optus, T-Mobile, Peloton, and USPS were all breached through misconfigured APIs, not exploits. Here's what causes it, what it costs, and how to catch it first.]]></description>
      <link>https://safeguard.sh/resources/blog/security-misconfiguration-in-apis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-misconfiguration-in-apis</guid>
      <pubDate>Sat, 11 Jul 2026 06:40:38 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best security orchestration, automation and response (SOA...]]></title>
      <description><![CDATA[A practical buyer's guide to SOAR tools -- comparing Splunk, Cortex XSOAR, Microsoft Sentinel, Tines, Swimlane, and Torq for automation and incident response.]]></description>
      <link>https://safeguard.sh/resources/blog/best-security-orchestration-automation-and-response-soar-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-security-orchestration-automation-and-response-soar-tools</guid>
      <pubDate>Sat, 11 Jul 2026 05:20:12 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[XSS Code Examples: How Cross-Site Scripting Looks in Practice]]></title>
      <description><![CDATA[An XSS code example makes the abstract concrete: here is what vulnerable code looks like for each type of cross-site scripting, and the small change that fixes each one.]]></description>
      <link>https://safeguard.sh/resources/blog/xss-code-example</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xss-code-example</guid>
      <pubDate>Sat, 11 Jul 2026 03:59:45 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[The Python Pickle Exploit: Why Unpickling Untrusted Data Runs Code]]></title>
      <description><![CDATA[A Python pickle exploit works because unpickling can execute arbitrary code during deserialization. Here is how the class works, why it is unavoidable by design, and what to use instead.]]></description>
      <link>https://safeguard.sh/resources/blog/python-pickle-exploit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-pickle-exploit</guid>
      <pubDate>Sat, 11 Jul 2026 02:39:18 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[WebAssembly WASI Security Model in 2025]]></title>
      <description><![CDATA[A technical look at WASI Preview 2, the component model, and capability-based isolation for running untrusted code inside supply chain tooling.]]></description>
      <link>https://safeguard.sh/resources/blog/webassembly-wasi-security-model-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webassembly-wasi-security-model-2025</guid>
      <pubDate>Sat, 11 Jul 2026 01:18:52 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The ZAP Security Testing Tool: A Practical Guide]]></title>
      <description><![CDATA[How the ZAP security testing tool works as a free DAST scanner: passive and active scanning, the spider and AJAX spider, and how to run it in CI without noise.]]></description>
      <link>https://safeguard.sh/resources/blog/zap-security-testing-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zap-security-testing-tool</guid>
      <pubDate>Fri, 10 Jul 2026 23:58:25 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Licence logiciel : le guide securite pour choisir et rester conforme]]></title>
      <description><![CDATA[Une licence logiciel definit ce que vous avez le droit de faire avec un code, et mal la gerer expose autant a un risque juridique qu'a un risque securite.]]></description>
      <link>https://safeguard.sh/resources/blog/licence-logiciel</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/licence-logiciel</guid>
      <pubDate>Fri, 10 Jul 2026 22:37:58 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Software Provenance: An End-to-End Guide]]></title>
      <description><![CDATA[Provenance answers where software came from and how it was built. Here is how to implement end-to-end provenance tracking from source to deployment.]]></description>
      <link>https://safeguard.sh/resources/blog/software-provenance-end-to-end-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-provenance-end-to-end-guide</guid>
      <pubDate>Fri, 10 Jul 2026 21:17:31 GMT</pubDate>
      <category>Build Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Dependency confusion attacks against major tech companies]]></title>
      <description><![CDATA[A look at the dependency confusion attacks that hit Apple, Microsoft, PayPal, and PyTorch — and why the technique still works against top engineering orgs.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-confusion-attacks-against-major-tech-companies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-confusion-attacks-against-major-tech-companies</guid>
      <pubDate>Fri, 10 Jul 2026 19:57:05 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Mobile Security Testing: OWASP MAS in Practice]]></title>
      <description><![CDATA[OWASP MAS turns mobile app security from ad-hoc pentests into a program: what the eight MASVS control groups cover, how MASTG test cases work, and how to fit it all into CI.]]></description>
      <link>https://safeguard.sh/resources/blog/mobile-security-testing-owasp-mas</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mobile-security-testing-owasp-mas</guid>
      <pubDate>Fri, 10 Jul 2026 18:36:38 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Improper Inventory Management: Shadow and Zombie APIs]]></title>
      <description><![CDATA[Undocumented shadow APIs and forgotten zombie endpoints are quietly expanding attack surface. Here's why inventory gaps cause breaches like T-Mobile and Optus.]]></description>
      <link>https://safeguard.sh/resources/blog/improper-inventory-management-shadow-and-zombie-apis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/improper-inventory-management-shadow-and-zombie-apis</guid>
      <pubDate>Fri, 10 Jul 2026 17:16:11 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-36414: The Azure Identity SDK RCE You Should Patch]]></title>
      <description><![CDATA[CVE-2023-36414 is a remote code execution flaw in the Azure Identity SDK for .NET. Here is how the injection works and which version closes it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-36414</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-36414</guid>
      <pubDate>Fri, 10 Jul 2026 15:55:45 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Best zero trust architecture implementation tools]]></title>
      <description><![CDATA[A vendor-neutral buyer's guide to zero trust architecture tools: what to evaluate, plus honest strengths and limits of six leading platforms compared.]]></description>
      <link>https://safeguard.sh/resources/blog/best-zero-trust-architecture-implementation-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-zero-trust-architecture-implementation-tools</guid>
      <pubDate>Fri, 10 Jul 2026 14:35:18 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Web Application Scanning: Tools and Methods Compared]]></title>
      <description><![CDATA[Web application scanning ranges from free automated crawlers to full authenticated DAST pipelines — here's how the methods differ and when each is enough.]]></description>
      <link>https://safeguard.sh/resources/blog/web-application-scanning-tools-and-methods</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-application-scanning-tools-and-methods</guid>
      <pubDate>Fri, 10 Jul 2026 13:14:51 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Actions supply chain risk report]]></title>
      <description><![CDATA[A look at the tj-actions/changed-files compromise and the broader trend of GitHub Actions supply chain attacks — and what security teams should do now.]]></description>
      <link>https://safeguard.sh/resources/blog/github-actions-supply-chain-risk-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-actions-supply-chain-risk-report</guid>
      <pubDate>Fri, 10 Jul 2026 11:54:25 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Broken Authentication in API Endpoints]]></title>
      <description><![CDATA[Broken authentication in API endpoints drove breaches at T-Mobile, Optus, and Peloton. Here's why it keeps happening and how to catch it before attackers do.]]></description>
      <link>https://safeguard.sh/resources/blog/broken-authentication-in-api-endpoints</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/broken-authentication-in-api-endpoints</guid>
      <pubDate>Fri, 10 Jul 2026 10:33:58 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best software supply chain risk scoring and rating platforms]]></title>
      <description><![CDATA[A practical, no-hype guide to choosing software supply chain risk scoring platforms — evaluation criteria plus a fair roundup of six real vendors, strengths and limitations included.]]></description>
      <link>https://safeguard.sh/resources/blog/best-software-supply-chain-risk-scoring-and-rating-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-software-supply-chain-risk-scoring-and-rating-platforms</guid>
      <pubDate>Fri, 10 Jul 2026 09:13:31 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Least-privilege scoping for AI agents with write access to code, CI, and cloud]]></title>
      <description><![CDATA[OWASP's 2025 LLM Top 10 names Excessive Agency a top risk; a single over-scoped CI token already dumped secrets from 23,000+ repos in 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-agent-permission-scoping-for-devops-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-agent-permission-scoping-for-devops-tools</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AI Code Generation: An Evaluation Framework for Gating Output Before Merge]]></title>
      <description><![CDATA[NYU researchers found security weaknesses in ~40% of Copilot-generated programs. Here's how to gate AI code before it ever reaches main.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-code-generation-security-risks-and-tooling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-code-generation-security-risks-and-tooling</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Discover Shadow and Undocumented APIs Before Attackers Do]]></title>
      <description><![CDATA[A single undocumented API endpoint exposed 10 million Optus records in 2022. Here's how to find shadow APIs in production and assess their real exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/api-discovery-and-shadow-api-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-discovery-and-shadow-api-risk</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A primer on the OWASP API Security Top 10 and how to test for it]]></title>
      <description><![CDATA[The OWASP API Security Top 10 dropped Injection entirely in its 2023 update and added SSRF — most REST and GraphQL teams still test for the old list.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-risks-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-risks-fundamentals</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Argument injection in Git and Mercurial CLI wrappers]]></title>
      <description><![CDATA[A branch name like --upload-pack=/bin/sh isn't a string to Git — it's a flag. CVE-2017-1000117 and CVE-2017-1000116 show why that distinction matters.]]></description>
      <link>https://safeguard.sh/resources/blog/argument-injection-in-git-and-mercurial</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/argument-injection-in-git-and-mercurial</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Building a secure coding culture: training, champions, and incentives that stick]]></title>
      <description><![CDATA[Verizon's 2025 DBIR found the human element in ~60% of breaches. A practical playbook for training, champions programs, and incentives that actually change developer behavior.]]></description>
      <link>https://safeguard.sh/resources/blog/building-a-secure-coding-culture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-a-secure-coding-culture</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CI/CD pipeline hardening against supply chain attacks]]></title>
      <description><![CDATA[23,000+ repos were exposed when tj-actions/changed-files was compromised in March 2025 — pinned SHAs and OIDC would have stopped it cold.]]></description>
      <link>https://safeguard.sh/resources/blog/cicd-pipeline-hardening-against-supply-chain-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cicd-pipeline-hardening-against-supply-chain-attacks</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A Practical Container Security Checklist: From Base Image to Runtime]]></title>
      <description><![CDATA[Standard Docker Hub images ship 50-60 known CVEs on average. Here's the checklist that gets containers from base image to runtime without carrying them along.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-source-to-runtime-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-source-to-runtime-checklist</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Running internal CTFs to build real security skills on engineering teams]]></title>
      <description><![CDATA[picoCTF drew 39,000 players in 2019 across 160 countries — proof that gamified security training scales. Here's how to run the same model internally.]]></description>
      <link>https://safeguard.sh/resources/blog/ctf-driven-security-training-for-engineering-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ctf-driven-security-training-for-engineering-teams</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Practical DLP controls for generative AI tools]]></title>
      <description><![CDATA[Samsung engineers leaked chip source code into ChatGPT three times in 20 days. Here's how to build DLP controls that stop the next leak before it happens.]]></description>
      <link>https://safeguard.sh/resources/blog/data-loss-prevention-for-generative-ai-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/data-loss-prevention-for-generative-ai-tools</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Detecting weak cryptographic algorithms in code]]></title>
      <description><![CDATA[SHAttered proved a SHA-1 collision for ~$110,000 in 2017. NIST retires SHA-1 entirely by Dec 31, 2030 — here's how to find and fix MD5/SHA-1 in your code now.]]></description>
      <link>https://safeguard.sh/resources/blog/detecting-weak-cryptographic-algorithms-in-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/detecting-weak-cryptographic-algorithms-in-code</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Docker secrets management without Kubernetes: BuildKit, Swarm, and env vars compared]]></title>
      <description><![CDATA[BuildKit's --secret flag shipped in Docker 18.09 in 2018, yet ENV and --build-arg leaks into image layers remain the most common way containers ship credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-secrets-management-without-kubernetes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-secrets-management-without-kubernetes</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP Moderate: What It Actually Requires From Your Security Architecture]]></title>
      <description><![CDATA[FedRAMP Moderate maps to roughly 300 NIST 800-53 controls — and FedRAMP 20x is now replacing the old triennial paperwork cycle with continuous evidence.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-and-government-cloud-security-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-and-government-cloud-security-requirements</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What's New: Live Agentic Search, a Real Trust Center, and Safeguard in Your Browser]]></title>
      <description><![CDATA[A tour of this month's releases — watching Griffin work in real time, publishing your security posture and artifacts to a governed Trust Center, and reaching Safeguard from the browser, CLI, IDE, and MCP.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-agentic-search-live-activity-and-the-trust-center</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-agentic-search-live-activity-and-the-trust-center</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Building minimal, non-root Java containers with distroless and JVM hardening]]></title>
      <description><![CDATA[A typical java:17 image ships a full OS and root shell; distroless plus JVM container-awareness flags cut that attack surface to almost nothing.]]></description>
      <link>https://safeguard.sh/resources/blog/hardening-java-docker-containers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hardening-java-docker-containers</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What healthtech AppSec needs beyond generic security practices]]></title>
      <description><![CDATA[242.9 million records were exposed in 2024 HIPAA breaches. Generic AppSec checklists don't satisfy FDA premarket SBOM rules or a pending HIPAA rewrite.]]></description>
      <link>https://safeguard.sh/resources/blog/healthtech-application-security-compliance-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/healthtech-application-security-compliance-overview</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[IDE extension marketplace trust and verification]]></title>
      <description><![CDATA[Wiz Research found 550+ leaked secrets across 500+ VS Code extensions, including publisher tokens that let attackers push malicious updates to entire install bases.]]></description>
      <link>https://safeguard.sh/resources/blog/ide-extension-marketplace-trust-and-verification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ide-extension-marketplace-trust-and-verification</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Incident response playbook for a compromised dependency or CI action]]></title>
      <description><![CDATA[23,000+ repos leaked secrets when tj-actions was hijacked in March 2025. Here's the revoke, rotate, and audit playbook for when it's your turn.]]></description>
      <link>https://safeguard.sh/resources/blog/incident-response-playbook-for-supply-chain-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/incident-response-playbook-for-supply-chain-compromise</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Auditing and pinning transitive Java dependencies with Maven and Gradle]]></title>
      <description><![CDATA[Maven resolves version conflicts by nearest path, not highest version — one new direct dependency can silently reintroduce a patched CVE.]]></description>
      <link>https://safeguard.sh/resources/blog/java-dependency-management-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-dependency-management-best-practices</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[JWT security vulnerabilities and best practices]]></title>
      <description><![CDATA[The jsonwebtoken library shipped three separate signature-bypass CVEs between 2015 and 2022 — algorithm confusion is still the most common way JWTs fail.]]></description>
      <link>https://safeguard.sh/resources/blog/jwt-security-vulnerabilities-and-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jwt-security-vulnerabilities-and-best-practices</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Container and Kubernetes scanning in agent-driven DevOps, without new trust boundaries]]></title>
      <description><![CDATA[Autonomous agents that rebuild and redeploy containers can patch a CVE in under an hour — or become a new privileged path to production if scanning isn't gated.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-and-container-agentic-scanning-workflows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-and-container-agentic-scanning-workflows</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Building an Open-Source License Compliance Program That Flags Copyleft Risk in CI]]></title>
      <description><![CDATA[Software Freedom Conservancy's suit against Vizio is headed to trial in August 2026 — proof that copyleft violations are litigated, not theoretical.]]></description>
      <link>https://safeguard.sh/resources/blog/license-compliance-risk-in-open-source-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/license-compliance-risk-in-open-source-dependencies</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Anatomy of a Malicious Go Package Typosquat]]></title>
      <description><![CDATA[A Go typosquat backdoored since 2021 stayed live for over three years because Go's module proxy caches code immutably — even after the attacker cleaned the repo.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-go-package-typosquatting-alert</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-go-package-typosquatting-alert</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The OWASP Top 10 for LLM Applications, Explained With Real Examples]]></title>
      <description><![CDATA[OWASP's LLM security list has grown from a 2023 side project into a 600+ expert initiative. Here's what each of the ten risks actually looks like in production.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-for-llm-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-for-llm-applications</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Reachability analysis for vulnerability triage]]></title>
      <description><![CDATA[Only 10-30% of SCA findings are ever actually invoked by your code. Reachability analysis finds which ones, cutting patch backlogs without hiding real risk.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-for-vulnerability-triage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-for-vulnerability-triage</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What CISA's Secure by Design Pledge Actually Requires]]></title>
      <description><![CDATA[CISA's Secure by Design pledge asks 68+ vendors for measurable one-year progress on 7 goals. Here's what those goals mean for engineering teams.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-by-design-principles-for-software-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-by-design-principles-for-software-teams</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing gRPC APIs: mTLS, Interceptors, and Input Validation]]></title>
      <description><![CDATA[CVE-2023-44487 knocked grpc-go services offline with a Rapid Reset flood — a reminder that gRPC ships fast, insecure by default, and needs hardening at every layer.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-grpc-apis-mtls-and-auth</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-grpc-apis-mtls-and-auth</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Embedding security-by-design into DevSecOps risk management across the SDLC]]></title>
      <description><![CDATA[NIST's SSDF turns 'shift left' into eleven concrete practices — but a framework on paper doesn't stop a bad merge. Here's how to make it enforceable.]]></description>
      <link>https://safeguard.sh/resources/blog/security-by-design-risk-management-devsecops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-by-design-risk-management-devsecops</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Where should your SPA store auth tokens?]]></title>
      <description><![CDATA[OWASP has warned against localStorage tokens for years, yet it remains the default in countless SPA tutorials — one XSS bug is all it takes to exfiltrate every session.]]></description>
      <link>https://safeguard.sh/resources/blog/single-page-application-token-storage-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/single-page-application-token-storage-security</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Symbolic Reasoning vs. LLMs: Which Static Analysis Actually Finds Bugs?]]></title>
      <description><![CDATA[The CASTLE benchmark tested 13 static analyzers and 10 LLMs on 250 programs — neither approach won outright, and the reasons why matter for your AppSec stack.]]></description>
      <link>https://safeguard.sh/resources/blog/symbolic-ai-vs-llm-static-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/symbolic-ai-vs-llm-static-analysis</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability fatigue and the case for risk-based prioritization]]></title>
      <description><![CDATA[48,185 CVEs were published in 2025 alone. Most teams can't triage that volume — reachability and exploit maturity data show which ones actually matter.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-fatigue-and-prioritization-strategies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-fatigue-and-prioritization-strategies</guid>
      <pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Docker Hub cryptojacking campaign analysis]]></title>
      <description><![CDATA[Safeguard tracked a six-week Docker Hub cryptojacking campaign using 41 trojanized images, delayed payloads, and base-image laundering to evade scanners.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-hub-cryptojacking-campaign-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-hub-cryptojacking-campaign-analysis</guid>
      <pubDate>Fri, 10 Jul 2026 07:53:05 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Hidden Functionality and Undocumented API Endpoints]]></title>
      <description><![CDATA[Undocumented API endpoints and hidden functionality sit outside vendor documentation entirely — here's where they come from, why attackers find them first, and how to detect them.]]></description>
      <link>https://safeguard.sh/resources/blog/hidden-functionality-and-undocumented-api-endpoints</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hidden-functionality-and-undocumented-api-endpoints</guid>
      <pubDate>Fri, 10 Jul 2026 06:32:38 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best AI and LLM generated code security scanning tools]]></title>
      <description><![CDATA[An honest buyer's guide to AI generated code security scanning tools: what to evaluate, how six real vendors stack up, and where they fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/best-ai-and-llm-generated-code-security-scanning-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-ai-and-llm-generated-code-security-scanning-tools</guid>
      <pubDate>Fri, 10 Jul 2026 05:12:11 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[chalk and debug npm package compromise incident]]></title>
      <description><![CDATA[A phished maintainer account led to a malicious npm publish of chalk, debug, and 16 related packages, exposing a crypto-clipper to billions of weekly downloads.]]></description>
      <link>https://safeguard.sh/resources/blog/chalk-and-debug-npm-package-compromise-incident</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chalk-and-debug-npm-package-compromise-incident</guid>
      <pubDate>Fri, 10 Jul 2026 03:51:44 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Missing Rate Limiting on APIs and Login Endpoints]]></title>
      <description><![CDATA[Missing rate limiting turned single APIs into 37-million-record breaches at T-Mobile and Optus. Here's why it happens, how attackers exploit it, and how to catch it first.]]></description>
      <link>https://safeguard.sh/resources/blog/missing-rate-limiting-on-apis-and-login-endpoints</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/missing-rate-limiting-on-apis-and-login-endpoints</guid>
      <pubDate>Fri, 10 Jul 2026 02:31:18 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best open source audit tools for M&A due diligence]]></title>
      <description><![CDATA[A practical buyer's guide to open source audit tools for M&A due diligence, comparing ScanCode, FOSSology, ORT, Syft/Grype, FOSSA, and Black Duck.]]></description>
      <link>https://safeguard.sh/resources/blog/best-open-source-audit-tools-for-ma-due-diligence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-open-source-audit-tools-for-ma-due-diligence</guid>
      <pubDate>Fri, 10 Jul 2026 01:10:51 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-44794: The Sa-Token Authentication Bypass Explained]]></title>
      <description><![CDATA[A path-normalization mismatch lets attackers bypass route authentication in Dromara Sa-Token. Here is how CVE-2023-44794 works and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-44794</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-44794</guid>
      <pubDate>Thu, 09 Jul 2026 23:50:24 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to Prevent Buffer Overflow Vulnerabilities]]></title>
      <description><![CDATA[Preventing buffer overflow comes down to bounds-safe code, compiler and OS protections, and testing. Here is how each defense works and where it fits.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-prevent-buffer-overflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-prevent-buffer-overflow</guid>
      <pubDate>Thu, 09 Jul 2026 22:29:58 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Western Sydney University 2025 Breach: Third-Party Cloud Misconfiguration]]></title>
      <description><![CDATA[From June to September 2025 an attacker quietly accessed a third-party cloud system linked to Western Sydney University and exfiltrated data on 10,000 students. We unpack the supply-chain anatomy.]]></description>
      <link>https://safeguard.sh/resources/blog/western-sydney-university-third-party-cloud-breach-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/western-sydney-university-third-party-cloud-breach-2025</guid>
      <pubDate>Thu, 09 Jul 2026 21:09:31 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[MITRE ATT&CK v18: Detection Strategies Replace Data Sources]]></title>
      <description><![CDATA[ATT&CK v18 released October 28, 2025, replacing traditional Detections (Data Sources) with Detection Strategies and Analytics. Here is how the model changes for defenders.]]></description>
      <link>https://safeguard.sh/resources/blog/mitre-attack-v18-detection-strategies-analytics</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mitre-attack-v18-detection-strategies-analytics</guid>
      <pubDate>Thu, 09 Jul 2026 19:49:04 GMT</pubDate>
      <category>Frameworks</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP 20x Phase One: 13 of 26 Pilot Reviews Completed]]></title>
      <description><![CDATA[GSA announced FedRAMP 20x on March 24, 2025. By the end of Phase One in late September, FedRAMP had received 26 submissions and completed 13 reviews.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-20x-phase-one-results</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-20x-phase-one-results</guid>
      <pubDate>Thu, 09 Jul 2026 18:28:38 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[ENISA Threat Landscape 2025: Supply Chain Section Decoded]]></title>
      <description><![CDATA[ENISA's October 2025 report analysed 4,875 incidents from July 2024 to June 2025 and found phishing led at 60% of intrusions, with supply chain and slopsquatting as fast-growing vectors.]]></description>
      <link>https://safeguard.sh/resources/blog/enisa-threat-landscape-2025-supply-chain-findings</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enisa-threat-landscape-2025-supply-chain-findings</guid>
      <pubDate>Thu, 09 Jul 2026 17:08:11 GMT</pubDate>
      <category>Policy</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The Security Chores Agents Should Handle Themselves]]></title>
      <description><![CDATA[Enabling 2FA, rotating a password, revoking a stale session, minting a scoped key — the account-hygiene tasks everyone postpones. When an agent can do them through MCP, 'later' becomes 'now.']]></description>
      <link>https://safeguard.sh/resources/blog/agent-self-service-account-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agent-self-service-account-security</guid>
      <pubDate>Thu, 09 Jul 2026 17:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Trivy v0.69 Release Deep Dive]]></title>
      <description><![CDATA[Aqua's Trivy hit v0.69 in late 2025 with VEX-by-default scanning, ArtifactID/ReportID provenance fields, and faster misconfig scanning. We test the upgrade on a 1.2GB image.]]></description>
      <link>https://safeguard.sh/resources/blog/trivy-v0-69-release-deep-dive-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trivy-v0-69-release-deep-dive-2025</guid>
      <pubDate>Thu, 09 Jul 2026 15:47:44 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Region-Blind Pricing Breaks the Moment an Agent Checks Out]]></title>
      <description><![CDATA[Your pricing is localized by country — but an AI agent rarely holds a clean country code. If your checkout can't resolve region from the messy signals an agent actually has, it quotes the wrong price or none at all.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-region-pricing-for-ai-agents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-region-pricing-for-ai-agents</guid>
      <pubDate>Thu, 09 Jul 2026 15:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Terraform AWS provider misconfiguration trends]]></title>
      <description><![CDATA[Terraform's AWS misconfiguration trends in 2026: how provider v4.0 migration gaps, wildcard IAM policies, and state drift keep exposing production infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/terraform-aws-provider-misconfiguration-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/terraform-aws-provider-misconfiguration-trends</guid>
      <pubDate>Thu, 09 Jul 2026 14:27:18 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[@twotalltotems/react-native-otp-input: A Security Guide]]></title>
      <description><![CDATA[This popular OTP input component for React Native has not shipped an update in years. Here is a security guide to using @twotalltotems/react-native-otp-input, or moving off it.]]></description>
      <link>https://safeguard.sh/resources/blog/twotalltotems-react-native-otp-input</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/twotalltotems-react-native-otp-input</guid>
      <pubDate>Thu, 09 Jul 2026 13:06:51 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Death by a Thousand Tools: Governing an MCP Server at Scale]]></title>
      <description><![CDATA[A 900-tool MCP server is powerful and terrifying in equal measure. The answer isn't fewer tools — it's per-tenant governance, where each capability is off until an admin turns it on.]]></description>
      <link>https://safeguard.sh/resources/blog/governing-mcp-tools-at-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/governing-mcp-tools-at-scale</guid>
      <pubDate>Thu, 09 Jul 2026 13:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Dynamic Scanning, Explained for Engineers Who Aren't Security Specialists]]></title>
      <description><![CDATA[Dynamic scanning tests a running application the way an attacker would, by sending it requests and watching what comes back. Here's what that actually involves and when it's the right tool.]]></description>
      <link>https://safeguard.sh/resources/blog/dynamic-scanning-explained-for-engineers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dynamic-scanning-explained-for-engineers</guid>
      <pubDate>Thu, 09 Jul 2026 11:46:24 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[The Onboarding Tax: Why Signup Forms Break Agent Workflows]]></title>
      <description><![CDATA[Every signup form, verification email, and OAuth redirect is a wall an AI agent can't climb. Zero-touch onboarding lets an agent create the account and sign in itself — no browser, no human relay.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-touch-onboarding-for-ai-agents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-touch-onboarding-for-ai-agents</guid>
      <pubDate>Thu, 09 Jul 2026 11:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Golang Docker Images: Building Them Right]]></title>
      <description><![CDATA[How to build Golang Docker images that stay small, patch cleanly, and don't ship a compiler toolchain into production, using multi-stage builds done properly.]]></description>
      <link>https://safeguard.sh/resources/blog/golang-docker-images-building-them-right</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/golang-docker-images-building-them-right</guid>
      <pubDate>Thu, 09 Jul 2026 10:25:57 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Model Context Protocol in 2026: News, Adoption, and Security Landscape]]></title>
      <description><![CDATA[The latest Model Context Protocol news: foundation governance, near-universal vendor adoption, a maturing spec, and a security track record that already includes critical CVEs.]]></description>
      <link>https://safeguard.sh/resources/blog/model-context-protocol-security-landscape</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/model-context-protocol-security-landscape</guid>
      <pubDate>Thu, 09 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CORS Misconfiguration Vulnerabilities]]></title>
      <description><![CDATA[CORS misconfiguration vulnerabilities let attackers steal authenticated API data with a single reflected Origin header. Here's how they happen and how to catch them before release.]]></description>
      <link>https://safeguard.sh/resources/blog/cors-misconfiguration-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cors-misconfiguration-vulnerabilities</guid>
      <pubDate>Thu, 09 Jul 2026 09:05:31 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Agentic Commerce: Why Your SaaS Has to Let AI Agents Buy]]></title>
      <description><![CDATA[AI agents already research, compare, and recommend software — but the moment they hit a paywall, they stall and hand the job back to a human. Here's why that gap is expensive, and how agent-native purchasing closes it.]]></description>
      <link>https://safeguard.sh/resources/blog/agentic-commerce-why-saas-must-let-ai-agents-buy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agentic-commerce-why-saas-must-let-ai-agents-buy</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Hritik Kumar Sharma)</author>
    </item>
    <item>
      <title><![CDATA[AI agents in AppSec pipelines: triage, remediation, and guardrails]]></title>
      <description><![CDATA[GitHub's Copilot Autofix cuts median fix time from 1.5 hours to 28 minutes — but a 2025 Replit agent incident shows why autonomy needs hard limits.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-agents-in-appsec-pipelines</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-agents-in-appsec-pipelines</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AI-driven DAST for modern applications]]></title>
      <description><![CDATA[73% of open-source developers now use AI coding tools. Dynamic testing built for nightly crawls can't keep pace with apps that reshape their attack surface daily.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-driven-dast-for-modern-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-driven-dast-for-modern-applications</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AI risk management best practices: a lifecycle framework]]></title>
      <description><![CDATA[NIST's AI RMF has four functions and MITRE ATLAS now tracks 84 adversarial techniques — most AI risk programs still only cover one lifecycle stage.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-risk-management-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-risk-management-best-practices</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Anatomy of a Software Supply-Chain Worm: A Post-Mortem Framework]]></title>
      <description><![CDATA[500+ npm packages backdoored in days, then 796 more two months later. A repeatable post-mortem framework for self-propagating open-source worms.]]></description>
      <link>https://safeguard.sh/resources/blog/anatomy-of-a-software-supply-chain-worm-postmortem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anatomy-of-a-software-supply-chain-worm-postmortem</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[When Shared AI Chats Become Public Search Results]]></title>
      <description><![CDATA[In July 2025, ~4,500 shared ChatGPT conversations turned up indexed on Google. Here's why sharable AI chats leak, and how enterprises stop it at the gateway.]]></description>
      <link>https://safeguard.sh/resources/blog/chatgpt-conversation-data-leakage-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chatgpt-conversation-data-leakage-risk</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Credential rotation playbook after npm worm exposure]]></title>
      <description><![CDATA[A step-by-step rotation runbook for security teams exposed to the Shai-Hulud npm worm — what to revoke first, how to verify a credential is dead, and how to prevent a repeat.]]></description>
      <link>https://safeguard.sh/resources/blog/credential-rotation-playbook-after-npm-worm-exposure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/credential-rotation-playbook-after-npm-worm-exposure</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-29927: inside the Next.js middleware auth bypass]]></title>
      <description><![CDATA[A single spoofed header let attackers skip Next.js middleware entirely — CVSS 9.1, four major versions affected, exploited in the wild within days.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2025-29927-nextjs-middleware-auth-bypass-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2025-29927-nextjs-middleware-auth-bypass-deep-dive</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Detecting malicious postinstall scripts in npm packages]]></title>
      <description><![CDATA[A 2025 phishing attack compromised 18 npm packages with 2.6 billion weekly downloads. Here's how postinstall scripts became npm's top attack vector.]]></description>
      <link>https://safeguard.sh/resources/blog/detecting-malicious-postinstall-scripts-in-npm-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/detecting-malicious-postinstall-scripts-in-npm-packages</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why developers stop trusting AI-generated vulnerability fixes]]></title>
      <description><![CDATA[Trust in AI-generated code fell to 29% in 2025, yet 84% of developers keep using it anyway — the gap is a UX problem, not a model problem.]]></description>
      <link>https://safeguard.sh/resources/blog/developer-fatigue-from-ai-generated-vulnerability-fixes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/developer-fatigue-from-ai-generated-vulnerability-fixes</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A reference architecture for automating security gates in CI/CD]]></title>
      <description><![CDATA[29M hardcoded secrets leaked in 2025 alone. Here's a gate architecture — SAST, SCA, secrets, IaC — that catches that without adding a day to your release cycle.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-automation-framework-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-automation-framework-guide</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The DevSecOps metrics that actually indicate program maturity]]></title>
      <description><![CDATA[CISA's KEV directive now demands 3-day fixes for the riskiest bugs. Here's why raw finding counts are the wrong way to measure a DevSecOps program.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-governance-metrics-that-matter</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-governance-metrics-that-matter</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The emerging role of the AI security engineer]]></title>
      <description><![CDATA[OWASP's 2025 LLM Top 10 ranks prompt injection #1 and calls it structurally unfixable by parameterization — a signal that AppSec skills alone no longer cover the job.]]></description>
      <link>https://safeguard.sh/resources/blog/emerging-role-of-ai-security-engineer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/emerging-role-of-ai-security-engineer</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A risk framework for enterprise AI coding and agent tool rollouts]]></title>
      <description><![CDATA[Samsung banned ChatGPT company-wide after three leaks in 20 days. A working framework for data exposure, model supply chain, and access control risk.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-ai-adoption-security-risk-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-ai-adoption-security-risk-framework</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why traditional AppSec still catches most enterprise AI agent bugs]]></title>
      <description><![CDATA[OWASP's LLM Top 10 names new categories, but most enterprise agent breaches trace back to broken access control and unvalidated input — the classics.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-conversational-ai-agent-vulnerability-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-conversational-ai-agent-vulnerability-patterns</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A Practical Guide to EU Cyber Resilience Act Compliance]]></title>
      <description><![CDATA[The CRA's 24-hour vulnerability reporting clock starts 11 September 2026. Here's how to build the SDLC changes now instead of scrambling later.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cyber-resilience-act-compliance-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cyber-resilience-act-compliance-guide</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Concrete guardrails for AI coding assistants]]></title>
      <description><![CDATA[40% of Copilot-generated code contained CWE Top 25 flaws in a 2022 study. Here are the prompt, scanning, and review gates that actually stop AI-written risk.]]></description>
      <link>https://safeguard.sh/resources/blog/guardrails-for-ai-coding-assistants</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/guardrails-for-ai-coding-assistants</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The guardrail gap in low-code agentic AI platforms]]></title>
      <description><![CDATA[Low-code AI builders let business users wire agents to live connectors in minutes — but most ship without per-tool scoping, approval gates, or audit trails.]]></description>
      <link>https://safeguard.sh/resources/blog/guardrails-for-low-code-agentic-ai-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/guardrails-for-low-code-agentic-ai-platforms</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Hardening CI/CD Against a Compromised Upstream Registry]]></title>
      <description><![CDATA[The Sept 2025 npm attack hit packages with 2B weekly downloads in 2 hours. Pinning, lockfile checks, and mirrors would have stopped it cold.]]></description>
      <link>https://safeguard.sh/resources/blog/hardening-cicd-against-compromised-package-registries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hardening-cicd-against-compromised-package-registries</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A HIPAA technical safeguards checklist for application security teams]]></title>
      <description><![CDATA[HHS reported 663 large healthcare breaches in 2024 exposing 242.9M records. Here's how §164.312's technical safeguards map to concrete app-sec controls.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-compliance-guide-for-application-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-compliance-guide-for-application-security</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Least-Privilege Tool Scoping for AI Coding Agents]]></title>
      <description><![CDATA[One overprivileged GitHub token let researchers hijack an AI agent into leaking private repo data via a public issue. Scoping tool access closes that gap.]]></description>
      <link>https://safeguard.sh/resources/blog/least-privilege-tool-scoping-for-ai-coding-agents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/least-privilege-tool-scoping-for-ai-coding-agents</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Cursor IDE extension that stole $500K: a supply chain post-mortem]]></title>
      <description><![CDATA[A fake 'Solidity Language' extension hit 50,000+ downloads on Open VSX before stealing $500K in crypto. Here's how IDE marketplaces became a trust gap.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-vscode-cursor-extension-crypto-theft</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-vscode-cursor-extension-crypto-theft</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[MCP server security for AI coding agents]]></title>
      <description><![CDATA[A critical RCE in Anthropic's own MCP Inspector (CVSS 9.4) and two Cursor CVEs show that giving AI agents tool access creates a new, largely unvetted attack surface.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-security-for-ai-coding-agents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-security-for-ai-coding-agents</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Anatomy of an npm maintainer account takeover]]></title>
      <description><![CDATA[A single phishing email hit eslint-config-prettier's ~30M weekly downloads in July 2025 — no code compromise needed, just a stolen npm login.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-maintainer-account-takeover-supply-chain-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-maintainer-account-takeover-supply-chain-attacks</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The npm worm incident response playbook]]></title>
      <description><![CDATA[Shai-Hulud compromised 500+ npm packages by auto-publishing itself with stolen tokens. Here's a concrete detection, rotation, and pinning playbook.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-supply-chain-worm-incident-response-playbook</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-supply-chain-worm-incident-response-playbook</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Inside the npm Reward-Farming Worm That Published 89,000+ Packages]]></title>
      <description><![CDATA[One npm publishing bot exploited a crypto reward protocol to spam 89,000+ packages, some appearing every 7-10 seconds. Here's how it worked and how to spot it.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-typosquat-crypto-reward-farming-scam-anatomy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-typosquat-crypto-reward-farming-scam-anatomy</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The 4 dimensions of open-source dependency risk]]></title>
      <description><![CDATA[Open-source risk isn't one problem — CVEs, malware, license exposure, and abandonment each fail differently, and Sonatype logged 454,600+ malicious packages in 2025 alone.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-security-risks-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-security-risks-overview</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A Reproducible Rubric for Measuring Prompt-Injection Risk in Agent Skills]]></title>
      <description><![CDATA[OWASP has ranked prompt injection the #1 LLM risk for two straight editions, yet almost no one scores agent skill packages for it consistently. Here's a rubric.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-prevalence-in-agent-skill-ecosystems</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-prevalence-in-agent-skill-ecosystems</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Inside CVE-2025-55182: the React Server Components RCE and how to defend against it]]></title>
      <description><![CDATA[A CVSS 10.0 pre-auth RCE in React Server Components, exploited within 48 hours of disclosure — how the deserialization flaw works and how to mitigate it.]]></description>
      <link>https://safeguard.sh/resources/blog/react-server-components-rce-cve-2025-55182</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-server-components-rce-cve-2025-55182</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Reducing false positives in SAST and SCA tools]]></title>
      <description><![CDATA[NIST benchmark data puts some SAST false-positive rates near 78%. Reachability analysis and contextual triage are how teams cut that noise without missing real risk.]]></description>
      <link>https://safeguard.sh/resources/blog/reducing-false-positives-in-sast-sca-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reducing-false-positives-in-sast-sca-tools</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SBOM-based blast radius analysis for vulnerable dependencies]]></title>
      <description><![CDATA[An SBOM tells you what's inside one artifact. It takes a dependency graph across every service to know what breaks first when a library gets a CVE.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-based-blast-radius-analysis-for-vulnerable-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-based-blast-radius-analysis-for-vulnerable-dependencies</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Scanning AI-Generated Code Before It Merges: Wiring Scanners into Coding Assistants with MCP]]></title>
      <description><![CDATA[Research found ~40% of Copilot suggestions were vulnerable, and devs using AI assistants trusted their code more. MCP lets you scan before merge.]]></description>
      <link>https://safeguard.sh/resources/blog/scanning-ai-generated-code-with-mcp-tooling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scanning-ai-generated-code-with-mcp-tooling</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Auditing AI agent skill registries for hardcoded keys]]></title>
      <description><![CDATA[29M new hardcoded secrets hit public GitHub in 2025, up 34% YoY — and 3% of MCP servers in production carry hardcoded credentials as theft traps.]]></description>
      <link>https://safeguard.sh/resources/blog/secrets-exposure-in-ai-agent-skill-registries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secrets-exposure-in-ai-agent-skill-registries</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing MCP Servers for AI Agents]]></title>
      <description><![CDATA[Five CVEs in 2025 alone trace MCP tool compromise back to one root cause: unsanitized strings piped into exec(). Here's how to expose and consume MCP safely.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-mcp-servers-for-ai-agents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-mcp-servers-for-ai-agents</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A prioritization framework for triaging security alerts at scale]]></title>
      <description><![CDATA[Only 2.6% of CVEs tracked in 2019 saw real-world exploitation, per Kenna Security/Cyentia — yet most teams still triage by CVSS alone. Here's a better framework.]]></description>
      <link>https://safeguard.sh/resources/blog/security-alert-triage-and-remediation-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-alert-triage-and-remediation-best-practices</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A methodology for testing SPAs for client-side vulnerabilities]]></title>
      <description><![CDATA[DOM XSS, token storage, and API exposure don't show up in a server-side scan — here's a repeatable methodology for testing React, Vue, and Angular apps.]]></description>
      <link>https://safeguard.sh/resources/blog/security-testing-single-page-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-testing-single-page-applications</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The real ROI of shifting left: what early flaw detection actually saves]]></title>
      <description><![CDATA[A 2025 data breach averages $4.44M globally and $10.22M in the US. Here's a defensible cost model for catching flaws before they ship, not after.]]></description>
      <link>https://safeguard.sh/resources/blog/shift-left-security-roi-early-flaw-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shift-left-security-roi-early-flaw-detection</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Signing and provenance standards for AI agent skill registries]]></title>
      <description><![CDATA[Shai-Hulud infected 500+ npm packages via stolen tokens in 2025. Agent skill registries are repeating the same unsigned-artifact mistake — here's the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/signing-and-provenance-standards-for-ai-agent-skill-registries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/signing-and-provenance-standards-for-ai-agent-skill-registries</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Threat-modeling for AI-native applications]]></title>
      <description><![CDATA[STRIDE has six categories from 1999. OWASP's LLM Top 10 and MITRE ATLAS's ~84 techniques show why agentic AI needs new threat-modeling columns, not a new framework.]]></description>
      <link>https://safeguard.sh/resources/blog/threat-modeling-for-ai-native-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/threat-modeling-for-ai-native-applications</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Reconstructing the tj-actions/changed-files compromise]]></title>
      <description><![CDATA[CVE-2025-30066 hit CISA's KEV list within 3 days: 23,000+ repos ran a poisoned GitHub Action that dumped CI secrets straight into public build logs.]]></description>
      <link>https://safeguard.sh/resources/blog/tj-actions-changed-files-github-actions-supply-chain-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tj-actions-changed-files-github-actions-supply-chain-compromise</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Verifying open source package provenance with SLSA and Sigstore]]></title>
      <description><![CDATA[A maintainer account takeover hid a backdoor in xz-utils for years. SLSA provenance and Sigstore signing are how you catch the next one before it ships.]]></description>
      <link>https://safeguard.sh/resources/blog/verifying-open-source-package-provenance-with-slsa-sigstore</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/verifying-open-source-package-provenance-with-slsa-sigstore</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best container registry vulnerability scanning tools]]></title>
      <description><![CDATA[A practical look at container registry scanning tools — evaluation criteria, six real vendors compared fairly, and how Safeguard closes the supply-chain gaps scanning alone leaves open.]]></description>
      <link>https://safeguard.sh/resources/blog/best-container-registry-vulnerability-scanning-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-container-registry-vulnerability-scanning-tools</guid>
      <pubDate>Thu, 09 Jul 2026 07:45:04 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Fortify Scan vs Modern SAST Tools: What Changed]]></title>
      <description><![CDATA[A Fortify scan still catches classic code-level flaws well, but the SAST category has moved toward faster feedback and reachability-aware prioritization since Fortify's architecture was designed.]]></description>
      <link>https://safeguard.sh/resources/blog/fortify-scan-vs-modern-sast-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fortify-scan-vs-modern-sast-tools</guid>
      <pubDate>Thu, 09 Jul 2026 06:24:37 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes ingress controller vulnerability roundup]]></title>
      <description><![CDATA[Ingress-nginx, Apache APISIX, and other Kubernetes ingress controllers have racked up critical CVEs since 2021 — here's what actually happened.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-ingress-controller-vulnerability-roundup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-ingress-controller-vulnerability-roundup</guid>
      <pubDate>Thu, 09 Jul 2026 05:04:11 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Known Vulnerabilities in Dependencies: Detection and Triage]]></title>
      <description><![CDATA[Known vulnerabilities in dependencies aren't a detection problem — they're a triage problem. Here's how CVEs get exploited, why CVSS alone misleads, and how to prioritize fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/known-vulnerabilities-in-dependencies-detection-and-triage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/known-vulnerabilities-in-dependencies-detection-and-triage</guid>
      <pubDate>Thu, 09 Jul 2026 03:43:44 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best infrastructure drift detection tools]]></title>
      <description><![CDATA[A practical buyer's guide to infrastructure drift detection tools, comparing Terraform Cloud, Spacelift, env0, driftctl-style OSS, and Safeguard.]]></description>
      <link>https://safeguard.sh/resources/blog/best-infrastructure-drift-detection-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-infrastructure-drift-detection-tools</guid>
      <pubDate>Thu, 09 Jul 2026 02:23:17 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[AWS IAM policy misconfiguration vulnerability patterns]]></title>
      <description><![CDATA[Wildcard policies, PassRole chains, and trust-policy gaps drive most AWS IAM breaches. Here's how these misconfiguration patterns actually get exploited.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-iam-policy-misconfiguration-vulnerability-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-iam-policy-misconfiguration-vulnerability-patterns</guid>
      <pubDate>Thu, 09 Jul 2026 01:02:51 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Compromise of Legitimate Upstream Packages]]></title>
      <description><![CDATA[From xz-utils to polyfill.io, attackers increasingly compromise packages developers already trust rather than planting fakes. Here's how these attacks work and how Safeguard catches them.]]></description>
      <link>https://safeguard.sh/resources/blog/compromise-of-legitimate-upstream-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/compromise-of-legitimate-upstream-packages</guid>
      <pubDate>Wed, 08 Jul 2026 23:42:24 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best secure software development lifecycle (SSDLC) platforms]]></title>
      <description><![CDATA[A practical buyer's guide to SSDLC platforms in 2026 — evaluation criteria, an honest roundup of six real vendors, and where Safeguard fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/best-secure-software-development-lifecycle-ssdlc-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-secure-software-development-lifecycle-ssdlc-platforms</guid>
      <pubDate>Wed, 08 Jul 2026 22:21:57 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Azure storage account misconfiguration report]]></title>
      <description><![CDATA[A breakdown of what drives Azure storage misconfiguration reports, from the 2023 Wiz-disclosed 38TB leak to SAS token and public access risks in 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-storage-account-misconfiguration-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-storage-account-misconfiguration-report</guid>
      <pubDate>Wed, 08 Jul 2026 21:01:31 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Name Confusion Attacks: Typosquatting and Brandjacking]]></title>
      <description><![CDATA[Typosquatting and brandjacking let attackers hijack trust in package names instead of writing exploits. Here's how crossenv, PyPI's 2017 campaign, and PyTorch's torchtriton breach actually worked.]]></description>
      <link>https://safeguard.sh/resources/blog/name-confusion-attacks-typosquatting-and-brandjacking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/name-confusion-attacks-typosquatting-and-brandjacking</guid>
      <pubDate>Wed, 08 Jul 2026 19:41:04 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best software supply chain observability tools]]></title>
      <description><![CDATA[A practical, no-hype buyer's guide to software supply chain observability tools -- evaluation criteria, an honest roundup of six real vendors, and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/best-software-supply-chain-observability-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-software-supply-chain-observability-tools</guid>
      <pubDate>Wed, 08 Jul 2026 18:20:37 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Docker Isolation: How Containers Actually Separate Workloads]]></title>
      <description><![CDATA[Docker isolation relies on Linux namespaces, cgroups, and capabilities, not a hypervisor. Here is what that really protects and where the boundary is weaker than teams assume.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-isolation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-isolation</guid>
      <pubDate>Wed, 08 Jul 2026 17:00:10 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[DevOps Velocity Without Sacrificing Security: How Fast Teams Stay Safe]]></title>
      <description><![CDATA[How high-velocity DevOps teams ship daily without trading away security — the automated gates, guardrails, and metrics that let speed and safety coexist.]]></description>
      <link>https://safeguard.sh/resources/blog/velocity-devops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/velocity-devops</guid>
      <pubDate>Wed, 08 Jul 2026 15:39:44 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The OWASP Top 10 for LLM Applications, Explained]]></title>
      <description><![CDATA[The OWASP LLM Top 10 is the closest thing the field has to a shared checklist for AI security. Here is what each of the ten risks actually means, in plain language, with the defenses that matter.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-llm-top-10-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-llm-top-10-explained</guid>
      <pubDate>Wed, 08 Jul 2026 15:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Python Dependency Scanning: A Practical Guide]]></title>
      <description><![CDATA[Your code is a small fraction of what ships. This is how to inventory, scan, and continuously monitor the Python dependency tree that makes up the rest.]]></description>
      <link>https://safeguard.sh/resources/blog/python-dependency-scanning-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-dependency-scanning-guide</guid>
      <pubDate>Wed, 08 Jul 2026 15:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The 2026 SBOM compliance guide: where a software bill of materials is now required]]></title>
      <description><![CDATA[SBOM requirements have spread from a single US executive order to regulations across sectors and continents. Here's a framework-by-framework map of where you need one in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-compliance-guide-2026-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-compliance-guide-2026-guide</guid>
      <pubDate>Wed, 08 Jul 2026 15:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Writing a Container Security Policy That Actually Holds]]></title>
      <description><![CDATA[Most container security policies get written once, ignored during the next sprint, and rediscovered during an audit — here's how to write one that engineers actually follow.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-policy-writing-one-that-holds</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-policy-writing-one-that-holds</guid>
      <pubDate>Wed, 08 Jul 2026 14:19:17 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Multi-Stage Docker Builds: A Security Pattern, Not Just a Size Trick]]></title>
      <description><![CDATA[Multi-stage builds are pitched as a way to shrink images. Their bigger payoff is security: build secrets, compilers, and toolchains that never reach production. Here is how to use them right.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-stage-docker-build-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-stage-docker-build-security</guid>
      <pubDate>Wed, 08 Jul 2026 14:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[GCP IAM privilege escalation paths explained]]></title>
      <description><![CDATA[Attackers escalate GCP privilege using IAM actAs chains, default Editor service accounts, and Cloud Build tokens -- no exploit code required.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-iam-privilege-escalation-paths-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-iam-privilege-escalation-paths-explained</guid>
      <pubDate>Wed, 08 Jul 2026 12:58:50 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Unmaintained Open Source Software: A Supply Chain Risk]]></title>
      <description><![CDATA[Unmaintained open source components quietly power critical software until a bug hits and no one is left to patch it. Here's the risk, and how to manage it.]]></description>
      <link>https://safeguard.sh/resources/blog/unmaintained-open-source-software-a-supply-chain-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unmaintained-open-source-software-a-supply-chain-risk</guid>
      <pubDate>Wed, 08 Jul 2026 11:38:24 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Security in the SDLC: Where It Actually Belongs]]></title>
      <description><![CDATA[Bolting a scanner on before release doesn't count as shift-left. Here's where security actually needs to sit across the SDLC, and why mobile testing is often the weakest link.]]></description>
      <link>https://safeguard.sh/resources/blog/security-in-the-sdlc-where-it-actually-belongs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-in-the-sdlc-where-it-actually-belongs</guid>
      <pubDate>Wed, 08 Jul 2026 10:17:57 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[AI Agents and Supply Chain Security FAQ: 2026 Answers]]></title>
      <description><![CDATA[Answers on where AI agents meet software supply chain security — the dependencies agents pull in, hallucinated packages, MCP servers as components, AIBOMs, and how Safeguard keeps the agentic supply chain governed.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-agents-and-supply-chain-security-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-agents-and-supply-chain-security-faq</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[API Authentication Best Practices (2026)]]></title>
      <description><![CDATA[How you authenticate API clients decides how bad a leaked credential gets. Here is how to choose and harden API keys, bearer tokens, JWTs, and mTLS in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/api-authentication-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-authentication-best-practices</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Aqua Security vs Prisma Cloud: A Neutral Comparison for 2026]]></title>
      <description><![CDATA[Aqua Security and Prisma Cloud both secure cloud-native workloads, but one grew from container and runtime defense and the other from a broad platform. An honest side-by-side, plus where a third option fits.]]></description>
      <link>https://safeguard.sh/resources/blog/aqua-vs-prisma-cloud</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aqua-vs-prisma-cloud</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Autonomous Remediation FAQ: How Self-Healing Vulnerability Fixes Work]]></title>
      <description><![CDATA[What autonomous remediation actually means in 2026 — how the detect-fix-validate-merge loop runs without a human bottleneck, where humans stay in control, and how to roll it out safely.]]></description>
      <link>https://safeguard.sh/resources/blog/autonomous-remediation-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/autonomous-remediation-faq</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Best API Security Tools in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced 2026 comparison of the leading API security tools — Salt Security, Akamai API Security, Traceable, 42Crunch, Wallarm, and StackHawk — with an honest look at where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/best-api-security-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-api-security-tools-2026</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Best Software Supply Chain Security Platforms in 2026]]></title>
      <description><![CDATA[Supply-chain security has grown from SCA into a platform category spanning SBOMs, build integrity, and malicious-package defense. This balanced guide compares Snyk, Sonatype, Chainguard, Endor Labs, Socket, and Safeguard.]]></description>
      <link>https://safeguard.sh/resources/blog/best-supply-chain-security-platforms-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-supply-chain-security-platforms-2026</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Buffer Overflow Vulnerabilities: A Practical Guide]]></title>
      <description><![CDATA[Buffer overflows write past the end of a memory buffer, corrupting adjacent data and often reaching code execution. Here is how they work and how to prevent them.]]></description>
      <link>https://safeguard.sh/resources/blog/buffer-overflow-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buffer-overflow-vulnerabilities</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[CCPA and CPRA for Developers: What the Code Actually Has to Do]]></title>
      <description><![CDATA[California's privacy laws are usually framed as a legal problem, but honoring opt-outs, deleting data, and maintaining reasonable security are engineering problems. Here's the developer's view of CCPA and CPRA.]]></description>
      <link>https://safeguard.sh/resources/blog/ccpa-cpra-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ccpa-cpra-for-developers</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Cloud-Native Application Security: Securing the Full Stack in 2026]]></title>
      <description><![CDATA[Cloud-native apps spread risk across code, containers, and infrastructure-as-code. This guide maps the full attack surface and a layered strategy to secure all of it.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-native-application-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-native-application-security</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Cloud-Native Supply Chain Security: From Source to Runtime]]></title>
      <description><![CDATA[A stage-by-stage guide to securing the cloud-native software supply chain — source, dependencies, build, artifacts, and deploy — using SBOMs, SLSA provenance, signing, and admission policy.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-native-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-native-supply-chain-security</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Container Runtime Security Monitoring: Catching the Breach in Progress]]></title>
      <description><![CDATA[Scanning tells you what could go wrong before deploy. Runtime monitoring tells you what is going wrong right now. Here is how to detect container attacks as they happen.]]></description>
      <link>https://safeguard.sh/resources/blog/container-runtime-security-monitoring-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-runtime-security-monitoring-guide</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[curl SOCKS5 Heap Overflow (CVE-2023-38545) Explained: When a Long Hostname Broke the Handshake]]></title>
      <description><![CDATA[CVE-2023-38545 is a heap buffer overflow in curl and libcurl's SOCKS5 proxy handshake, triggered when a too-long hostname is copied into a fixed buffer during a slow handshake. Here is the bug.]]></description>
      <link>https://safeguard.sh/resources/blog/curl-socks5-cve-2023-38545-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/curl-socks5-cve-2023-38545-explained</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CVE vs CWE: What's the Difference?]]></title>
      <description><![CDATA[A CVE identifies one specific vulnerability in one product; a CWE names the underlying type of weakness that caused it. Here's how the two systems differ and how they work together.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-vs-cwe-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-vs-cwe-explained</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Data Residency and Security: FAQ]]></title>
      <description><![CDATA[Where your data lives, what actually leaves your boundary, region pinning, customer-held keys, and how residency differs from sovereignty in a security platform.]]></description>
      <link>https://safeguard.sh/resources/blog/data-residency-and-security-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/data-residency-and-security-faq</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Management for Beginners: Keeping Your Borrowed Code Healthy]]></title>
      <description><![CDATA[Most of your application is packages other people wrote. Dependency management is the everyday craft of choosing them well, updating them safely, and keeping them from becoming a liability. Here is a friendly guide with a first step to try today.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-management-for-beginners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-management-for-beginners</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Fundamentals]]></title>
      <description><![CDATA[DevSecOps folds security into the fast, automated flow of modern development instead of bolting it on at the end. This guide explains what DevSecOps really means, how the pipeline works stage by stage, and the practices that make it stick.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-fundamentals</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Metrics and KPIs That Actually Prove Progress]]></title>
      <description><![CDATA[Most security dashboards count findings and prove nothing. A 2026 guide to the DevSecOps metrics and KPIs that show real risk reduction — MTTR, escape rate, coverage, and DORA-aligned measures.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-metrics-and-kpis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-metrics-and-kpis</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Docker Layer Caching Security Risks (and How to Avoid Them)]]></title>
      <description><![CDATA[Layer caching makes builds fast — and quietly bakes secrets into layers, hides unpatched base images, and poisons shared CI caches. Here is how to keep caching without the exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-layer-caching-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-layer-caching-security-risks</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[DORA compliance for financial services: the software supply chain angle]]></title>
      <description><![CDATA[The Digital Operational Resilience Act is now in force across EU financial services. Here's how its five pillars reach into your software supply chain and ICT third parties.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-compliance-financial-services</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-compliance-financial-services</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Insecure Deserialization in .NET: BinaryFormatter and Beyond]]></title>
      <description><![CDATA[Why insecure deserialization is a remote-code-execution risk in .NET, what changed with BinaryFormatter's removal in .NET 9, and the dangerous JSON.NET settings still in the wild.]]></description>
      <link>https://safeguard.sh/resources/blog/dotnet-insecure-deserialization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dotnet-insecure-deserialization</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[eBPF Runtime Security for Kubernetes]]></title>
      <description><![CDATA[eBPF lets you observe and enforce security at the kernel level — every syscall, network connection, and process exec — without kernel modules or instrumenting your apps. Here is how tools like Falco, Tetragon, and Cilium use it to catch what image scanning cannot.]]></description>
      <link>https://safeguard.sh/resources/blog/ebpf-runtime-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ebpf-runtime-security</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Free Ways to Learn Application Security in 2026]]></title>
      <description><![CDATA[You do not need an expensive bootcamp to break into application security. Here is a complete, genuinely free learning stack—labs, courses, practice platforms, and free certifications—organized so you know exactly where to start.]]></description>
      <link>https://safeguard.sh/resources/blog/free-ways-to-learn-application-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/free-ways-to-learn-application-security</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Career</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Ghostscript (CVE-2023-36664) Explained: Command Injection via Pipe Devices]]></title>
      <description><![CDATA[CVE-2023-36664 let a crafted PostScript or EPS file run system commands through Ghostscript's mishandling of pipe device filenames. Because Ghostscript hides behind image tools, the blast radius was wide.]]></description>
      <link>https://safeguard.sh/resources/blog/ghostscript-cve-2023-36664-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ghostscript-cve-2023-36664-explained</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[The Go Web Application Security Checklist: Server Hardening to Output Encoding]]></title>
      <description><![CDATA[A field-tested checklist for Go web services — the http.Server timeouts nobody sets, html/template escaping traps, auth and session hygiene, and the headers that actually matter.]]></description>
      <link>https://safeguard.sh/resources/blog/go-web-application-security-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-web-application-security-checklist</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Choose an Open Source License]]></title>
      <description><![CDATA[Choosing a license for your project comes down to how much control you want over downstream use. This guide walks through the decision — permissive, weak copyleft, or strong copyleft.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-choose-an-open-source-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-choose-an-open-source-license</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Create an AIBOM for Your AI Models]]></title>
      <description><![CDATA[Build an AI Bill of Materials that inventories the models, datasets, adapters, and MCP tools your application depends on — using CycloneDX ML-BOM and commands you can run today.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-create-an-aibom-for-ai-models</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-create-an-aibom-for-ai-models</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Report a Security Vulnerability]]></title>
      <description><![CDATA[You found a security bug — now what? This beginner guide walks through reporting a vulnerability responsibly, from finding the right contact to writing a clear report.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-report-a-security-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-report-a-security-vulnerability</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Ivanti Connect Secure CVE-2024-21887 Explained: Command Injection in a Two-Bug Chain]]></title>
      <description><![CDATA[CVE-2024-21887 is a command injection in Ivanti Connect Secure that, chained with the auth bypass CVE-2023-46805, gave attackers unauthenticated RCE. Here is the timeline, root cause, and patched versions.]]></description>
      <link>https://safeguard.sh/resources/blog/ivanti-connect-secure-cve-2024-21887-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ivanti-connect-secure-cve-2024-21887-explained</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Lessons from Shai-Hulud: The First Self-Propagating npm Worm]]></title>
      <description><![CDATA[In September 2025, npm faced a supply chain attack that spread by itself — stealing developers' tokens, then using them to trojanize the victims' own packages. Here is how it worked.]]></description>
      <link>https://safeguard.sh/resources/blog/lessons-from-the-shai-hulud-npm-worm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lessons-from-the-shai-hulud-npm-worm</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Log4Shell Explained: Root Cause and Complete Remediation]]></title>
      <description><![CDATA[Log4Shell (CVE-2021-44228) hit CVSS 10.0 and is still exploited today. Here's how the attack works, why it lingers, and how to remediate it completely.]]></description>
      <link>https://safeguard.sh/resources/blog/log4shell-explained-and-remediation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4shell-explained-and-remediation</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Managing Transitive Dependencies: The Vulnerabilities You Didn't Choose]]></title>
      <description><![CDATA[Most dependency risk lives in packages you never installed directly. Here is how transitive dependencies work across ecosystems and how to audit and control them.]]></description>
      <link>https://safeguard.sh/resources/blog/managing-transitive-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/managing-transitive-dependencies</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[MCP Protocol News: The 2026 Spec Update and Its Security Fallout]]></title>
      <description><![CDATA[The biggest MCP protocol news of 2026 is a major specification overhaul that fixes old flaws and shifts a load of new security responsibility onto developers.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-protocol-news</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-protocol-news</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Measuring AppSec ROI: Metrics That Prove Your Program Works]]></title>
      <description><![CDATA[You cannot fund an application security program on fear forever. Here is how to measure AppSec ROI with metrics executives believe — cost avoided, MTTR, and the leading indicators that predict both.]]></description>
      <link>https://safeguard.sh/resources/blog/measuring-appsec-roi</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/measuring-appsec-roi</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[node-fetch Security Guide (2026)]]></title>
      <description><![CDATA[node-fetch brought the browser fetch API to Node.js and became a near-universal HTTP client — and its two real CVEs, a redirect-based header leak and a size-limit bypass, are exactly the kind of subtle bug that ships to millions of apps.]]></description>
      <link>https://safeguard.sh/resources/blog/node-fetch-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-fetch-security-guide</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[OIDC vs Static Credentials in CI/CD (2026 Guide)]]></title>
      <description><![CDATA[Static secrets in CI are the credential most likely to be stolen — as the CircleCI breach proved. OIDC federation issues short-lived, per-run credentials with nothing to leak. Here is how to make the switch.]]></description>
      <link>https://safeguard.sh/resources/blog/oidc-vs-static-credentials-in-ci</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oidc-vs-static-credentials-in-ci</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Open Redirect Vulnerabilities: Prevention Guide]]></title>
      <description><![CDATA[An open redirect lets an attacker use your trusted domain to send victims anywhere — the ideal setup for phishing and OAuth token theft. Here's how to build redirects that can't be abused.]]></description>
      <link>https://safeguard.sh/resources/blog/open-redirect-vulnerability-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-redirect-vulnerability-prevention</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[OWASP A10: Server-Side Request Forgery (SSRF) — A Deep-Dive Guide]]></title>
      <description><![CDATA[Server-Side Request Forgery ranks #10 in the OWASP Top 10 (2021). A deep dive into cloud metadata theft, real CVEs like ProxyLogon, and how to stop SSRF in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-a10-ssrf</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-a10-ssrf</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[PHP-CGI Argument Injection RCE on Windows (CVE-2024-4577) Explained]]></title>
      <description><![CDATA[CVE-2024-4577 revived a decade-old PHP-CGI flaw through a Windows Unicode 'best-fit' quirk, yielding unauthenticated RCE. Here's the mechanism and the patched versions.]]></description>
      <link>https://safeguard.sh/resources/blog/php-cgi-cve-2024-4577-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-cgi-cve-2024-4577-explained</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Protocol Buffers (protobuf) Security Guide (2026)]]></title>
      <description><![CDATA[Protocol Buffers is the serialization format behind gRPC and much of modern service-to-service traffic — and because parsing untrusted binary is its whole job, its real CVEs are denial-of-service by design, with a critical prototype-pollution bug in the JavaScript runtime.]]></description>
      <link>https://safeguard.sh/resources/blog/protobuf-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/protobuf-security-guide</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Preventing SSRF in Python Applications]]></title>
      <description><![CDATA[Server-side request forgery turns your own backend into an attacker's proxy, reaching internal services and cloud metadata endpoints you never meant to expose.]]></description>
      <link>https://safeguard.sh/resources/blog/python-ssrf-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-ssrf-prevention</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[PyYAML Security Guide (2026)]]></title>
      <description><![CDATA[PyYAML is the default YAML parser for Python — and its history of arbitrary-code-execution CVEs from unsafe loading makes yaml.load() one of the most dangerous calls in the language.]]></description>
      <link>https://safeguard.sh/resources/blog/pyyaml-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pyyaml-security-guide</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Red-Teaming AI Applications: A Field Guide]]></title>
      <description><![CDATA[You cannot secure an LLM application by reading its code alone. You have to attack it the way an adversary will — with language, with poisoned content, and with the goal of making it do something it should not. Here is how to run an AI red team.]]></description>
      <link>https://safeguard.sh/resources/blog/red-teaming-ai-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/red-teaming-ai-applications</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[ReDoS: Regular Expression Denial of Service in JavaScript]]></title>
      <description><![CDATA[A single bad regex can freeze your entire Node.js event loop on one malicious request. Here is how catastrophic backtracking works, how to spot vulnerable patterns, and how to fix them without rewriting everything.]]></description>
      <link>https://safeguard.sh/resources/blog/redos-regular-expression-dos-javascript</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/redos-regular-expression-dos-javascript</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Rust Supply Chain Security: build.rs, Typosquatting, and Auditing crates.io]]></title>
      <description><![CDATA[Rust's borrow checker guarantees memory safety in your code — and nothing about the crates you pull in. A cargo build runs arbitrary code at compile time, before any safe code executes.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-supply-chain-security</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[SAST vs SCA: What's the Difference? (Beginner's Guide)]]></title>
      <description><![CDATA[SAST reads the code your team wrote, looking for insecure patterns. SCA inspects the open-source code you borrowed, looking for known vulnerabilities. One checks your writing; the other checks your ingredients.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-vs-sca-for-beginners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-vs-sca-for-beginners</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Compliance Requirements FAQ: NTIA Elements, Formats, and Mandates]]></title>
      <description><![CDATA[A precise FAQ on SBOM compliance in 2026 — the NTIA minimum elements, accepted formats, where SBOMs are actually mandated (federal, FDA, EU CRA), depth, VEX, and generation.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-compliance-requirements-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-compliance-requirements-faq</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Service Mesh Security: mTLS, Authorization, and Zero Trust]]></title>
      <description><![CDATA[A service mesh can give you mutual TLS between every service, identity-based authorization, and encrypted traffic without touching application code — or it can become an over-privileged proxy layer you never locked down. Here is how to do it right.]]></description>
      <link>https://safeguard.sh/resources/blog/service-mesh-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/service-mesh-security-guide</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Socket.dev Alternatives in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced comparison of the leading Socket.dev alternatives in 2026 — Snyk, Endor Labs, Mend, Aikido, Sonatype, and Safeguard — with candid pros, cons, and a framework for choosing.]]></description>
      <link>https://safeguard.sh/resources/blog/socket-dev-alternatives-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/socket-dev-alternatives-2026</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Static vs Dynamic Code Analysis: An Honest 2026 Comparison]]></title>
      <description><![CDATA[SAST vs DAST vs IAST in 2026 — what each finds, what each misses, the real tools, how reachability bridges them, and where Safeguard fits — explained without hype.]]></description>
      <link>https://safeguard.sh/resources/blog/static-vs-dynamic-code-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-vs-dynamic-code-analysis</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Terrapin Attack (CVE-2023-48795) Explained: SSH's Prefix Truncation Flaw]]></title>
      <description><![CDATA[CVE-2023-48795, the Terrapin attack, is a protocol-level flaw letting a MITM silently truncate the start of an SSH session. Here is how it works, what it downgrades, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/terrapin-ssh-cve-2023-48795-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/terrapin-ssh-cve-2023-48795-explained</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Prioritization FAQ: How to Decide What to Fix First]]></title>
      <description><![CDATA[You can't fix everything at once. This FAQ explains how to prioritize vulnerabilities using severity, exploitation likelihood, active-exploitation evidence, and reachability.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-prioritization-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-prioritization-faq</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[WebSocket Security Guide: Origin Checks, Auth, and CSWSH]]></title>
      <description><![CDATA[WebSockets skip the same-origin policy and don't carry your REST auth for free. Cross-site WebSocket hijacking is the flaw teams miss. Here's how to secure the handshake.]]></description>
      <link>https://safeguard.sh/resources/blog/websocket-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/websocket-security-guide</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What Is the Model Context Protocol (MCP)? And What It Means for Security]]></title>
      <description><![CDATA[MCP is the USB-C of AI integrations — one open standard for connecting models to tools and data. It also standardizes a fresh attack surface, so understanding both halves matters.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-model-context-protocol-mcp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-model-context-protocol-mcp</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What Is Vulnerability Management? A Complete Explanation]]></title>
      <description><![CDATA[Vulnerability management is the continuous, cyclical process of identifying, prioritizing, remediating, and verifying security weaknesses across your software and systems. Here's the full lifecycle and how to run it without drowning in findings.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-vulnerability-management-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-vulnerability-management-explained</guid>
      <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Agents Can Now Procure Safeguard Through MCP]]></title>
      <description><![CDATA[AI agents can browse regional pricing, compare tiers, start a Stripe checkout, and verify activation — the entire Safeguard procurement journey now runs through the MCP server.]]></description>
      <link>https://safeguard.sh/resources/blog/agents-can-now-procure-safeguard-through-mcp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agents-can-now-procure-safeguard-through-mcp</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Hritik Kumar Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Integrating AI Tools Without Expanding Your Attack Surface]]></title>
      <description><![CDATA[Stanford researchers found developers using AI coding assistants wrote more security bugs — and felt more confident in them. Here's how to adopt AI safely.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-assisted-development-cybersecurity-workflows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-assisted-development-cybersecurity-workflows</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AI-assisted vulnerability remediation patterns: what to verify before you merge]]></title>
      <description><![CDATA[GitHub reports its Copilot Autofix suggestions resolve two-thirds of flagged vulnerabilities with little or no editing — but the other third is where merges go wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-assisted-vulnerability-remediation-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-assisted-vulnerability-remediation-patterns</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to validate AI-generated autofix suggestions before you merge them]]></title>
      <description><![CDATA[319 LLM patches for 64 real CVEs were graded in 2026: only 24.8% were both secure and functional. Speed without validation just merges bugs faster.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-code-autofix-validation-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-code-autofix-validation-techniques</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AI code review: what it actually catches versus misses]]></title>
      <description><![CDATA[GitClear's 211M-line study found copy-pasted code rose from 8.3% to 12.3% of changes from 2020 to 2024 — even as AI reviewers flag more comments, the defects that matter most still slip through.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-code-review-benefits-and-limits</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-code-review-benefits-and-limits</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The supply-chain and IP risk hiding inside AI coding assistants]]></title>
      <description><![CDATA[GitHub has disclosed that Copilot suggestions match training-set code verbatim about 1% of the time — and a class action over it is still being argued in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-coding-assistant-supply-chain-risk-amazon-codewhisperer-class</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-coding-assistant-supply-chain-risk-amazon-codewhisperer-class</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What AI Executive Orders Actually Mean for Enterprise Security Teams]]></title>
      <description><![CDATA[The US revoked its AI safety EO in January 2025, but SBOM and evidence obligations under EO 14028 never went away — and the EU AI Act just got harder deadlines.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-executive-order-compliance-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-executive-order-compliance-implications</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why AI-generated code quality problems compound into security risk]]></title>
      <description><![CDATA[Developers using AI coding assistants wrote less secure code in 4 of 5 tasks in a 2023 Stanford study — and were more confident it was safe.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-generated-code-quality-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-generated-code-quality-risk</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Security Pitfalls Hiding in AI-Generated Code]]></title>
      <description><![CDATA[A 2021 NYU study found roughly 40% of Copilot completions on security-relevant prompts contained exploitable flaws. Here's a field guide to catching them.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-generated-code-security-pitfalls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-generated-code-security-pitfalls</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Where AI actually helps AppSec — and where it quietly makes things worse]]></title>
      <description><![CDATA[One 2025 benchmark found an LLM filter cut Semgrep's false positives by 88.6% — while a separate study found GPT-4 alone flagging vulnerabilities was wrong more often than right.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-in-appsec-benefits-and-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-in-appsec-benefits-and-risks</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How AI-powered SAST auto-fix engines actually work]]></title>
      <description><![CDATA[GitHub says Copilot Autofix resolves two-thirds of flagged vulnerabilities with little editing; Snyk claims 80% fix accuracy. Here's the pipeline behind both numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-powered-sast-autofix-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-powered-sast-autofix-explained</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AI Red Teaming vs. AI-SPM: Why You Need Both]]></title>
      <description><![CDATA[OWASP's 2025 LLM Top 10 and MITRE ATLAS both treat adversarial testing and posture scanning as separate disciplines — most AI programs still run only one.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-red-teaming-vs-ai-spm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-red-teaming-vs-ai-spm</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AI Developer Tools: Weighing Productivity Against Security and IP Exposure]]></title>
      <description><![CDATA[NYU found 40% of Copilot-generated code contained exploitable flaws; Samsung banned ChatGPT after three leaks in under 20 days. The productivity math still isn't simple.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-tools-for-developer-productivity-and-security-tradeoffs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-tools-for-developer-productivity-and-security-tradeoffs</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Mapping security training and roles to the NIST NICE Framework]]></title>
      <description><![CDATA[NIST's NICE Framework sorts cybersecurity work into 7 categories and 52 work roles — most security teams have never mapped a single job description to it.]]></description>
      <link>https://safeguard.sh/resources/blog/aligning-security-training-with-nist-nice-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aligning-security-training-with-nist-nice-framework</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[ASPM fundamentals: what application security posture management actually aggregates]]></title>
      <description><![CDATA[Gartner coined the ASPM term in May 2023 and projects over 40% of organizations building software will adopt it by 2026 — here is what it actually does.]]></description>
      <link>https://safeguard.sh/resources/blog/application-risk-management-aspm-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-risk-management-aspm-fundamentals</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A practical AppSec maturity model: five stages, self-assessment included]]></title>
      <description><![CDATA[OWASP SAMM v2 scores 15 practices on a 0–3 scale; BSIMM15 measured 121 firms and found SCA adoption up 67%. Here's a five-stage model to self-assess against.]]></description>
      <link>https://safeguard.sh/resources/blog/appsec-maturity-model-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/appsec-maturity-model-framework</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The AppSec Program Spring-Cleaning Checklist]]></title>
      <description><![CDATA[The xz-utils backdoor sat in a maintainer's commits for over two years before a Postgres developer's slow SSH login exposed it in March 2024. Most AppSec programs never audit for that kind of drift.]]></description>
      <link>https://safeguard.sh/resources/blog/appsec-program-spring-cleaning-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/appsec-program-spring-cleaning-checklist</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What to Evaluate in an ASPM Solution: A 2026 Buyer's Guide]]></title>
      <description><![CDATA[Gartner named Application Security Posture Management a category in May 2023 — three years later, most RFPs still can't distinguish a real ASPM from a dashboard bolted onto old scanners.]]></description>
      <link>https://safeguard.sh/resources/blog/aspm-evaluation-criteria-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aspm-evaluation-criteria-2026</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[ASPM fundamentals for security teams]]></title>
      <description><![CDATA[Gartner projects over 40% of organizations will adopt Application Security Posture Management by 2026 — here's what it actually aggregates and how to judge if yours is working.]]></description>
      <link>https://safeguard.sh/resources/blog/aspm-fundamentals-for-security-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aspm-fundamentals-for-security-teams</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A framework for integrating ASPM into an existing AppSec program]]></title>
      <description><![CDATA[Gartner defined ASPM in May 2023 as a correlation layer, not a rip-and-replace — here's how to fold it into a toolchain you already run.]]></description>
      <link>https://safeguard.sh/resources/blog/aspm-integration-with-appsec-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aspm-integration-with-appsec-programs</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why asset inventory should come before AppSec tooling]]></title>
      <description><![CDATA[Only 17% of organizations can inventory 95%+ of their assets, and 69% have been breached through one they didn't know existed — start with the map, not the scanner.]]></description>
      <link>https://safeguard.sh/resources/blog/asset-first-application-security-approach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/asset-first-application-security-approach</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A Step-by-Step Methodology for Mapping and Prioritizing Attack Surface]]></title>
      <description><![CDATA[CVE-2023-34362 sat in one internet-facing file-transfer server and still produced thousands of downstream breaches — attack surface mapping is what catches that server before Cl0p does.]]></description>
      <link>https://safeguard.sh/resources/blog/attack-surface-analysis-methodology</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/attack-surface-analysis-methodology</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Automating container image vulnerability scans in GitHub Actions]]></title>
      <description><![CDATA[A fail-the-build scanning pipeline is a few YAML lines away — but pin the Action wrong and you inherit its supply chain risk too.]]></description>
      <link>https://safeguard.sh/resources/blog/automating-container-image-scans-in-github-actions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automating-container-image-scans-in-github-actions</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Automating Security Controls on Google Cloud]]></title>
      <description><![CDATA[Binary Authorization can block every unsigned container from reaching GKE or Cloud Run — but only if your pipeline is wired to sign images the moment they pass scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/automating-security-controls-on-google-cloud</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automating-security-controls-on-google-cloud</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A guide to AWS IAM permissions boundaries for delegated administration]]></title>
      <description><![CDATA[AWS IAM lets any principal with iam:CreateRole and iam:AttachRolePolicy hand themselves admin — permissions boundaries are the one native control built to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-iam-permissions-boundaries-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-iam-permissions-boundaries-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AWS secure REST API vs. S3: where shared responsibility actually splits]]></title>
      <description><![CDATA[S3 buckets are private by default — every public leak is a customer misconfiguration. Capital One's 2019 breach of 106 million records proves the boundary.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-secure-rest-api-vs-s3-shared-responsibility</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-secure-rest-api-vs-s3-shared-responsibility</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The AWS Shared Responsibility Model, Explained With Real Examples]]></title>
      <description><![CDATA[AWS secures the cloud; you secure what's in it. Most breaches — like the thousands of exposed public S3 buckets found every year — happen entirely on the customer's side of that line.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-shared-responsibility-model-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-shared-responsibility-model-explained</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Beyond vulnerability management: a risk-based approach to AppSec]]></title>
      <description><![CDATA[Fewer than 5% of published CVEs are ever exploited in the wild, yet most teams still triage by raw count — here's the exploitability-first alternative.]]></description>
      <link>https://safeguard.sh/resources/blog/beyond-vulnerability-management-risk-based-appsec</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/beyond-vulnerability-management-risk-based-appsec</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Broken access control in Express: the OWASP #1 risk, fixed with middleware]]></title>
      <description><![CDATA[Broken access control now shows up in 100% of tested applications, per OWASP's 2025 Top 10 — up from 94% in 2021. Here's how to close it in Express.]]></description>
      <link>https://safeguard.sh/resources/blog/broken-access-control-express-nodejs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/broken-access-control-express-nodejs</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Browser extensions are the softest target in your stack]]></title>
      <description><![CDATA[A patched Grammarly bug let any website steal a user's documents; a 2025 flaw in Anthropic's Claude extension enabled silent prompt injection. Extensions keep failing the same three ways.]]></description>
      <link>https://safeguard.sh/resources/blog/browser-extension-security-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/browser-extension-security-vulnerabilities</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to publish a secure Python package: signing, SBOMs, and trusted publishing]]></title>
      <description><![CDATA[PyPI enforced two-factor authentication for all users on January 1, 2024 — but 2FA alone doesn't stop a stolen API token. Here's the full secure-publishing stack.]]></description>
      <link>https://safeguard.sh/resources/blog/building-secure-python-packages-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-secure-python-packages-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Bun-compiled JS binaries as PyPI credential stealers]]></title>
      <description><![CDATA[Two lightning releases fetched the Bun runtime at import time to run an 11MB obfuscated JS stealer — PyPI's Python trust model didn't expect a JS binary.]]></description>
      <link>https://safeguard.sh/resources/blog/bun-compiled-credential-stealer-in-python-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bun-compiled-credential-stealer-in-python-packages</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Memory-Safety Vulnerabilities in C/C++: What Static and Dynamic Analysis Actually Catch]]></title>
      <description><![CDATA[Roughly 70% of the CVEs Microsoft and Google's Chrome team assign each year trace to memory-unsafe C/C++ code — how static analysis, sanitizers, and fuzzers each catch a different slice of it.]]></description>
      <link>https://safeguard.sh/resources/blog/c-cpp-memory-safety-vulnerability-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/c-cpp-memory-safety-vulnerability-scanning</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[C/C++ security in automotive software-defined vehicles]]></title>
      <description><![CDATA[MISRA C:2025 now spans roughly 225 guidelines and explicitly covers AI-generated code — but memory-safety bugs still drive roughly 70% of the vulnerabilities patched in major C/C++ codebases.]]></description>
      <link>https://safeguard.sh/resources/blog/c-cpp-security-in-automotive-software-defined-vehicles</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/c-cpp-security-in-automotive-software-defined-vehicles</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Running Capture the Flag exercises for internal security training]]></title>
      <description><![CDATA[DEF CON CTF has run since 1996, yet most engineering orgs still train security awareness with slide decks instead of the format that actually built the industry.]]></description>
      <link>https://safeguard.sh/resources/blog/capture-the-flag-security-training-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/capture-the-flag-security-training-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Chaos engineering for security resilience testing]]></title>
      <description><![CDATA[A one-hour Cloudflare R2 outage in March 2025 traced back to a mistyped deploy flag during credential rotation — exactly the failure a security chaos experiment is built to catch first.]]></description>
      <link>https://safeguard.sh/resources/blog/chaos-engineering-for-security-resilience-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chaos-engineering-for-security-resilience-testing</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Python code injection: eval, exec, and pickle explained]]></title>
      <description><![CDATA[eval(), exec(), and pickle.load() can each hand an attacker a Python interpreter — CVE-2020-1747 shows how one unsafe deserialization call became a real RCE.]]></description>
      <link>https://safeguard.sh/resources/blog/code-injection-prevention-python</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-injection-prevention-python</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Code injection risks in GenAI-generated code]]></title>
      <description><![CDATA[Nearly 40% of GitHub Copilot's suggested programs contain exploitable vulnerabilities, and 19.7% of AI-generated code samples reference packages that don't exist.]]></description>
      <link>https://safeguard.sh/resources/blog/code-injection-risks-in-genai-generated-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-injection-risks-in-genai-generated-code</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The code-to-cloud AppSec checklist: unifying code, dependency, container, and config security]]></title>
      <description><![CDATA[Log4Shell and the XZ Utils backdoor both proved the same thing: a flaw in one layer is only as contained as your weakest disconnected tool.]]></description>
      <link>https://safeguard.sh/resources/blog/code-to-cloud-appsec-strategy-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-to-cloud-appsec-strategy-checklist</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Command injection in Python: subprocess, os.system, and safe-by-default patterns]]></title>
      <description><![CDATA[os.system() and subprocess.run(shell=True) both hand a string straight to /bin/sh — one unescaped semicolon is enough to run arbitrary commands.]]></description>
      <link>https://safeguard.sh/resources/blog/command-injection-prevention-python</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/command-injection-prevention-python</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Common Configuration Scoring System (CCSS) explained]]></title>
      <description><![CDATA[NIST published CCSS in December 2010 to score misconfigurations the way CVSS scores bugs — most cloud teams have never applied it.]]></description>
      <link>https://safeguard.sh/resources/blog/common-configuration-scoring-system-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/common-configuration-scoring-system-explained</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Sigstore vs. Notary v2 vs. Docker Content Trust: signing containers in 2026]]></title>
      <description><![CDATA[Docker retires Content Trust on December 8, 2026, while fewer than 0.05% of Hub pulls ever used it — here's how Sigstore and Notary v2 actually replaced it.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-signing-sigstore-notary-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-signing-sigstore-notary-comparison</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing Containerized AI Workloads: Base Images, GPU Drivers, and Runtime Policy]]></title>
      <description><![CDATA[A CVSS 9.0 flaw in NVIDIA's Container Toolkit let any GPU container escape to the host — and its first patch didn't fully close it. Here's how to defend AI infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-for-ai-workloads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-for-ai-workloads</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Continuous vulnerability management: the discovery-to-verification lifecycle]]></title>
      <description><![CDATA[CISA's new BOD 26-04 gives federal agencies as little as 3 days to remediate the highest-risk flaws — a preview of the SLA pressure every engineering org now faces.]]></description>
      <link>https://safeguard.sh/resources/blog/continuous-vulnerability-management-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/continuous-vulnerability-management-best-practices</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Inside CVE-2023-46233: How crypto-js Shipped a 1.3-Million-Times-Weaker Key Derivation]]></title>
      <description><![CDATA[crypto-js versions before 4.2.0 defaulted PBKDF2 to SHA1 with a single iteration — NVD calls it 1,300,000 times weaker than modern standards. Here's the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/crypto-js-weak-hash-cve-2023-46233-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crypto-js-weak-hash-cve-2023-46233-deep-dive</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CTF Writeup: Container SETUID Escape Techniques]]></title>
      <description><![CDATA[A container-local root shell is not the flag. CVE-2019-5736 and CVE-2021-4034 both show how a SETUID binary inside a container can become a host compromise.]]></description>
      <link>https://safeguard.sh/resources/blog/ctf-writeup-container-setuid-escape-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ctf-writeup-container-setuid-escape-techniques</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CTF writeup patterns: serialization and cryptographic puzzles, decoded]]></title>
      <description><![CDATA[CVE-2013-0156 let attackers RCE Rails by feeding YAML into a parameter parser — the same insecure-deserialization pattern CTF players train on every weekend.]]></description>
      <link>https://safeguard.sh/resources/blog/ctf-writeup-serialization-and-cryptographic-puzzle-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ctf-writeup-serialization-and-cryptographic-puzzle-patterns</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The CUPS RCE Chain: A Technical Breakdown of CVE-2024-47176]]></title>
      <description><![CDATA[Four medium-severity CUPS bugs chained into unauthenticated RCE on UDP/631 — a masterclass in why CVSS scores per-CVE miss the real risk of a vulnerability chain.]]></description>
      <link>https://safeguard.sh/resources/blog/cups-cve-2024-47176-zero-day-rce-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cups-cve-2024-47176-zero-day-rce-deep-dive</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Inside CVE-2023-38545: the libcurl SOCKS5 heap overflow]]></title>
      <description><![CDATA[A single off-by-length check in curl's SOCKS5 handshake, live for over three years across libcurl 7.69.0–8.3.x, earned a 9.8 CVSS score and a CWE-787 out-of-bounds write.]]></description>
      <link>https://safeguard.sh/resources/blog/curl-libcurl-cve-2023-38545-socks5-heap-overflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/curl-libcurl-cve-2023-38545-socks5-heap-overflow</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What the curl CVE disclosures teach about patching embedded C libraries]]></title>
      <description><![CDATA[curl.se lists 206 published CVEs across two decades — two 2023 disclosures show why transitive C-library patching needs its own discipline.]]></description>
      <link>https://safeguard.sh/resources/blog/curl-vulnerability-patch-management-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/curl-vulnerability-patch-management-lessons</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVSS 4.0 vs. 3.1: what actually changed, and why your priority list should too]]></title>
      <description><![CDATA[CVSS 4.0 killed the Scope metric, added Attack Requirements, and split scoring into CVSS-B/BT/BE/BTE labels — here's what that means for triage.]]></description>
      <link>https://safeguard.sh/resources/blog/cvss-4-scoring-changes-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cvss-4-scoring-changes-explained</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why AI-generated code needs DAST, not just SAST]]></title>
      <description><![CDATA[Copilot-generated code carried vulnerabilities in ~40% of cases in a 2021 NYU study. Static scanning alone cannot catch the runtime-only bug classes LLMs introduce.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-for-ai-generated-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-for-ai-generated-code</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Data loss prevention for developers: stopping leaks before they hit the network]]></title>
      <description><![CDATA[CWE-532 covers secrets logged in plaintext — the exact bug that led Twitter to reset every password on May 3, 2018. Network DLP can't catch it; your code has to.]]></description>
      <link>https://safeguard.sh/resources/blog/data-loss-prevention-practices-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/data-loss-prevention-practices-for-developers</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Defense-in-depth for a modern cloud-native application stack]]></title>
      <description><![CDATA[Log4Shell and the XZ backdoor were caught two different ways — one by patching, one by a developer noticing 500ms of extra SSH latency. Neither alone is a strategy.]]></description>
      <link>https://safeguard.sh/resources/blog/defense-in-depth-modern-application-stack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/defense-in-depth-modern-application-stack</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Dependency confusion and npm supply-chain hardening]]></title>
      <description><![CDATA[One researcher earned over $130,000 exploiting name collisions between public and private registries at 35 companies — here's how lockfiles and scoping stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-confusion-and-npm-supply-chain-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-confusion-and-npm-supply-chain-hardening</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Dependency injection in Python: a guide to testability and security boundaries]]></title>
      <description><![CDATA[FastAPI shipped a built-in DI container in its very first release in December 2018 — but the same swappability that makes DI testable can quietly ship a mock into production.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-injection-security-implications-python</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-injection-security-implications-python</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Dependabot vs. Renovate: Tuning Dependency Updates Without Drowning in PRs]]></title>
      <description><![CDATA[Dependabot GA'd grouped security updates in March 2024 and cross-directory consolidation in February 2026 — both direct responses to teams muting bots entirely.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-update-automation-strategies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-update-automation-strategies</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Detecting AI Hallucinations in Generated Code]]></title>
      <description><![CDATA[A USENIX Security 2025 study found 19.7% of packages recommended by 16 LLMs across 576,000 code samples don't exist — and attackers are registering them first.]]></description>
      <link>https://safeguard.sh/resources/blog/detecting-ai-hallucinations-in-generated-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/detecting-ai-hallucinations-in-generated-code</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What developer-first supply chain security actually requires]]></title>
      <description><![CDATA[The xz-utils backdoor was caught by a 500ms SSH login delay, not a scanner. Real developer-first security means catching it before the commit ships.]]></description>
      <link>https://safeguard.sh/resources/blog/developer-first-supply-chain-security-principles</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/developer-first-supply-chain-security-principles</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The DevSecOps Adoption Leadership Playbook]]></title>
      <description><![CDATA[Datadog's 2026 State of DevSecOps found 87% of organizations have a known-exploited vulnerability live in production — the fix is incentive design, not another mandate.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-adoption-leadership-playbook</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-adoption-leadership-playbook</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The four-phase roadmap for adopting DevSecOps]]></title>
      <description><![CDATA[Google Cloud's 2024 DORA report found AI-tool adoption correlated with worse delivery performance for the second year running — tool sprawl without a plan makes DevSecOps worse, not better.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-implementation-roadmap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-implementation-roadmap</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps on AWS: a reference architecture for CI/CD security gates]]></title>
      <description><![CDATA[Amazon Inspector, CodePipeline manual approvals, and SLSA v1.0 (April 2023) give you the primitives — but nobody ships them wired together as one gated pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-on-aws-reference-architecture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-on-aws-reference-architecture</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Docker best practices for Node.js developers in 2026]]></title>
      <description><![CDATA[Multi-stage builds can cut a Node.js image from 1GB+ down to under 150MB — but most teams still ship dev dependencies, root shells, and unscanned base layers to production.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-best-practices-nodejs-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-best-practices-nodejs-developers</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Using jlink to Build Minimal, Lower-Attack-Surface Java Docker Images]]></title>
      <description><![CDATA[jlink has shipped with every JDK since Java 9 in 2017, yet most Spring Boot images still ship a full 300MB+ JDK. Here's how to fix that.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-jlink-minimal-java-images-security-benefits</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-jlink-minimal-java-images-security-benefits</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[DOM clobbering: the XSS attack that never runs a script tag]]></title>
      <description><![CDATA[DOM clobbering lets attackers hijack JavaScript logic using pure HTML — no <script> tag required — and it just bypassed DOMPurify's own sanitizer in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/dom-clobbering-attack-mitigation-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dom-clobbering-attack-mitigation-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[DORA compliance for application risk management]]></title>
      <description><![CDATA[DORA became fully applicable on 17 January 2025 with no grace period, and its ICT risk-management articles map almost line-for-line onto standard AppSec practice.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-compliance-for-application-risk-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-compliance-for-application-risk-management</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A reference architecture for SAST, SCA, and DAST gates that don't block developers]]></title>
      <description><![CDATA[Log4Shell sat exploitable for 8 days before public disclosure in December 2021 — the canonical case for why security gates belong in CI, not just at release.]]></description>
      <link>https://safeguard.sh/resources/blog/embedding-security-testing-in-devops-pipelines</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/embedding-security-testing-in-devops-pipelines</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Enriching SBOMs with Vulnerability and License Metadata]]></title>
      <description><![CDATA[A base SBOM only lists what's in your build — OSV.dev, EPSS, and OpenSSF Scorecard turn that inventory into a prioritized risk decision.]]></description>
      <link>https://safeguard.sh/resources/blog/enriching-sboms-with-vulnerability-and-license-metadata</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enriching-sboms-with-vulnerability-and-license-metadata</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The four pillars every enterprise security program needs]]></title>
      <description><![CDATA[Identity, patching, segmentation, and logging aren't a checklist — they're the four controls that determine whether a breach stays contained or becomes Log4Shell.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-security-best-practices-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-security-best-practices-framework</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Protect the Environment: How Env-Var Leakage Happens in CI/CD]]></title>
      <description><![CDATA[One tampered Bash script exposed roughly 23,000 Codecov customers' credentials for two months. Environment-variable leakage is a recurring CI/CD failure mode, not a one-off.]]></description>
      <link>https://safeguard.sh/resources/blog/environment-variable-leakage-attack-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/environment-variable-leakage-attack-patterns</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Shipping a Dual ESM/CJS npm Package Without Creating a Supply-Chain Hazard]]></title>
      <description><![CDATA[Node's own docs call it a 'dual package hazard' — the same module loaded twice via require() and import can produce two objects that fail instanceof against each other.]]></description>
      <link>https://safeguard.sh/resources/blog/esm-cjs-dual-package-npm-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/esm-cjs-dual-package-npm-security</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Ethical hacking techniques, mapped to a responsible disclosure workflow]]></title>
      <description><![CDATA[Recon, enumeration, exploitation, and privilege escalation aren't just attacker steps — Log4Shell's 15-day gap between private report and public exploit shows why each maps to a disclosure decision.]]></description>
      <link>https://safeguard.sh/resources/blog/ethical-hacking-techniques-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ethical-hacking-techniques-overview</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Exploitability vs. breakability: a practical rubric for vulnerability triage]]></title>
      <description><![CDATA[CVSS says a flaw could be bad. CISA's KEV catalog, now past 1,300 entries, says one actually was exploited. Most teams still triage as if the two are the same.]]></description>
      <link>https://safeguard.sh/resources/blog/exploitability-vs-breakability-in-vulnerability-triage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/exploitability-vs-breakability-in-vulnerability-triage</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Designing Secure Fastify Plugin Boundaries]]></title>
      <description><![CDATA[Fastify's encapsulation model isolates plugin state by default — but one `fastify-plugin` wrapper or a stray `skip-override` symbol can silently punch a hole through every boundary you had.]]></description>
      <link>https://safeguard.sh/resources/blog/fastify-plugin-architecture-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fastify-plugin-architecture-security</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Finding and fixing IDOR vulnerabilities in Python]]></title>
      <description><![CDATA[Broken Object Level Authorization has held the #1 spot on the OWASP API Security Top 10 since 2019 — and Django's get_object_or_404() does nothing to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/finding-fixing-idor-vulnerabilities-in-python</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/finding-fixing-idor-vulnerabilities-in-python</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Generating a CycloneDX/SPDX SBOM for a Node.js Application]]></title>
      <description><![CDATA[npm has shipped a native `npm sbom` command since v9 — but a real supply chain program needs more than the CLI default. Here's how to do it right.]]></description>
      <link>https://safeguard.sh/resources/blog/generating-sbom-for-nodejs-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/generating-sbom-for-nodejs-applications</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How Attackers Clone GitHub Repos to Ship Malware]]></title>
      <description><![CDATA[One threat actor ran 3,000+ fake GitHub accounts and 2,200+ cloned repos to infect over 1,300 victims in four days. Here's how to spot the fakes.]]></description>
      <link>https://safeguard.sh/resources/blog/github-repo-confusion-malware-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-repo-confusion-malware-detection</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The GitOps security model: risks and controls]]></title>
      <description><![CDATA[GitOps turns a Git repo into a deploy button — Argo CD's own CVE-2022-24348 path traversal proved what happens when that button isn't locked down.]]></description>
      <link>https://safeguard.sh/resources/blog/gitops-security-model-risks-and-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitops-security-model-risks-and-controls</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Command injection in Go: os/exec, exec.Command, and how it still goes wrong]]></title>
      <description><![CDATA[Go's exec.Command never invokes a shell — yet CWE-78 command injection keeps shipping in Go services. Here's exactly how, and how gosec's G204 rule catches it.]]></description>
      <link>https://safeguard.sh/resources/blog/go-command-injection-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-command-injection-prevention</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Guardrails for Autonomous AI Agents: Allowlisting, Validation, and Human-in-the-Loop]]></title>
      <description><![CDATA[OWASP's 2025 LLM Top 10 splits Excessive Agency into three root causes. Here's how tool allowlisting, output validation, and approval gates address each one.]]></description>
      <link>https://safeguard.sh/resources/blog/guardrails-for-autonomous-ai-agents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/guardrails-for-autonomous-ai-agents</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Hardening CI/CD Pipelines End to End]]></title>
      <description><![CDATA[A leaked Codecov credential let attackers read CI secrets from 23,000+ customers for two months in 2021. Here's how to close every stage of that gap.]]></description>
      <link>https://safeguard.sh/resources/blog/hardening-ci-cd-pipelines-end-to-end</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hardening-ci-cd-pipelines-end-to-end</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[High-profile AWS breaches: lessons learned]]></title>
      <description><![CDATA[Capital One's 2019 breach exposed 106 million records through a single SSRF call to the EC2 metadata service — here's the exact control that would have stopped it.]]></description>
      <link>https://safeguard.sh/resources/blog/high-profile-aws-breaches-lessons-learned</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/high-profile-aws-breaches-lessons-learned</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Designing an application security program from first principles]]></title>
      <description><![CDATA[Two backdoors nine years apart — event-stream in 2018, XZ Utils in 2024 — show why code-only AppSec programs fail. Here's a four-layer framework built from scratch.]]></description>
      <link>https://safeguard.sh/resources/blog/holistic-application-security-program-design</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/holistic-application-security-program-design</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[HTTP/2 CONTINUATION Flood: Inside CVE-2024-27316 and the Frame-Based DoS Class]]></title>
      <description><![CDATA[A single TCP connection with no END_HEADERS flag was enough to crash major HTTP/2 servers — worse than Rapid Reset, and it took the industry a decade to check for it.]]></description>
      <link>https://safeguard.sh/resources/blog/http2-continuation-flood-dos-cve-2024-27316</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/http2-continuation-flood-dos-cve-2024-27316</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Hardening HTTP/2 against protocol-level DoS attacks]]></title>
      <description><![CDATA[HTTP/2 Rapid Reset hit Google with 398 million requests per second in 2023 — a single protocol quirk, not a bug in any one server, drove the largest DDoS ever disclosed.]]></description>
      <link>https://safeguard.sh/resources/blog/http2-protocol-security-hardening-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/http2-protocol-security-hardening-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[HTTP/2 Rapid Reset: inside CVE-2023-44487]]></title>
      <description><![CDATA[A single HTTP/2 feature let attackers hit 398 million requests per second. Here's how Rapid Reset (CVE-2023-44487) broke nearly every major web server at once.]]></description>
      <link>https://safeguard.sh/resources/blog/http2-rapid-reset-cve-2023-44487-explainer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/http2-rapid-reset-cve-2023-44487-explainer</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Shifting Infrastructure-as-Code security left across the SDLC]]></title>
      <description><![CDATA[Terrascan went archived in November 2025 and tfsec folded into Trivy in 2024 — IaC scanning is consolidating fast, and where you run it matters as much as which tool you pick.]]></description>
      <link>https://safeguard.sh/resources/blog/iac-security-across-the-sdlc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iac-security-across-the-sdlc</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Identifying memory safety bugs with Valgrind]]></title>
      <description><![CDATA[Valgrind's Memcheck catches use-after-free, leaks, and buffer overruns in unmodified C binaries — at the cost of running your program 10-50x slower.]]></description>
      <link>https://safeguard.sh/resources/blog/identifying-memory-safety-bugs-with-valgrind</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/identifying-memory-safety-bugs-with-valgrind</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Implementing mTLS in Kubernetes clusters: a hands-on guide]]></title>
      <description><![CDATA[Kubernetes ships zero built-in encryption for pod-to-pod traffic — here's how cert-manager and service meshes fix that, and the five misconfigurations that quietly undo it.]]></description>
      <link>https://safeguard.sh/resources/blog/implementing-mtls-in-kubernetes-clusters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/implementing-mtls-in-kubernetes-clusters</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Installing and Verifying Java on macOS Securely]]></title>
      <description><![CDATA[A SHA-256 checksum only proves a JDK download wasn't corrupted in transit — it takes a GPG signature check to prove it actually came from the vendor you trust.]]></description>
      <link>https://safeguard.sh/resources/blog/installing-verifying-java-macos-securely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/installing-verifying-java-macos-securely</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Japan METI's SBOM Guidance: What Software Vendors Need to Know]]></title>
      <description><![CDATA[METI's SBOM guidance has no legal teeth, yet Ver. 2.0 already shapes procurement at Japan's largest manufacturers and critical-infrastructure buyers.]]></description>
      <link>https://safeguard.sh/resources/blog/japan-meti-sbom-guidance-for-software-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/japan-meti-sbom-guidance-for-software-management</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Bytecode vs. source analysis: static analysis techniques for Java and Kotlin]]></title>
      <description><![CDATA[SpotBugs scans compiled .class files for 400+ bug patterns; Semgrep parses source directly. Neither alone would have caught CVE-2015-7501 fast enough.]]></description>
      <link>https://safeguard.sh/resources/blog/java-kotlin-static-analysis-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-kotlin-static-analysis-techniques</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Defensive Java: coding patterns that stop NullPointerExceptions from becoming outages]]></title>
      <description><![CDATA[NPE has been Java's most common runtime exception since JDK 1.0 in 1996 — Optional, JSpecify annotations, and static analysis can turn most of them into compile-time errors.]]></description>
      <link>https://safeguard.sh/resources/blog/java-nullpointerexception-prevention-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-nullpointerexception-prevention-patterns</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Java SecurityManager is gone: a practical migration guide]]></title>
      <description><![CDATA[JEP 411 deprecated the Security Manager in JDK 17; JEP 486 disabled it outright in JDK 24, released March 18, 2025. Here's how to migrate before it's removed for good.]]></description>
      <link>https://safeguard.sh/resources/blog/java-securitymanager-removal-migration-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-securitymanager-removal-migration-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Getting AES right in Java: JCA/JCE mistakes that break your encryption]]></title>
      <description><![CDATA[Call `Cipher.getInstance("AES")` in Java and you silently get ECB mode — no warning, no error, just plaintext patterns leaking through.]]></description>
      <link>https://safeguard.sh/resources/blog/java-symmetric-encryption-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-symmetric-encryption-best-practices</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Wiring dependency and SAST scanning into your JavaScript CLI workflow]]></title>
      <description><![CDATA[npm audit has shipped for free since npm 6 in 2018, yet most JavaScript teams still find out about vulnerable dependencies in a Slack alert, not a failed commit.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-cli-security-scanning-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-cli-security-scanning-workflow</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secure JWT handling: algorithm confusion, expiry, and storage done right]]></title>
      <description><![CDATA[A single unchecked `alg` header turned jsonwebtoken into a forgeable token in CVE-2015-9235 — here's how to close every hole RFC 8725 warns about.]]></description>
      <link>https://safeguard.sh/resources/blog/jwt-handling-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jwt-handling-security-best-practices</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Designing Least-Privilege Kubernetes RBAC: A Practical Guide]]></title>
      <description><![CDATA[CVE-2018-1002105 (CVSS 9.8) let an unauthenticated request reach cluster-admin through pod exec endpoints — most RBAC breaches since trace back to the same handful of over-broad bindings.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-rbac-least-privilege-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-rbac-least-privilege-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[LDAP injection: a technical primer and defense guide]]></title>
      <description><![CDATA[LDAP injection is CWE-90, dates to the same root cause as SQL injection, and still shipped in production software as recently as CVE-2023-0476.]]></description>
      <link>https://safeguard.sh/resources/blog/ldap-injection-primer-and-defenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ldap-injection-primer-and-defenses</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why static scanners miss malicious AI agent skills]]></title>
      <description><![CDATA[In April 2025, Invariant Labs showed a malicious MCP tool description could exfiltrate an SSH key — with zero suspicious code for a static scanner to flag.]]></description>
      <link>https://safeguard.sh/resources/blog/limits-of-static-scanners-for-ai-agent-skills</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/limits-of-static-scanners-for-ai-agent-skills</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[LLM-assisted vulnerability autofixing: approaches and how to validate the patches]]></title>
      <description><![CDATA[At DARPA's AIxCC finals in August 2025, AI systems patched 68% of vulnerabilities they found — up from 25% at semifinals. Here's how the approaches differ and why validation still matters most.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-assisted-vulnerability-autofixing-approaches</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-assisted-vulnerability-autofixing-approaches</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Log4Shell and Spring4Shell, years later: why the same bug keeps coming back]]></title>
      <description><![CDATA[CVE-2021-44228 scored a perfect CVSS 10.0 and hit CISA's Known Exploited Vulnerabilities list the day it was published — the root cause hasn't gone away.]]></description>
      <link>https://safeguard.sh/resources/blog/log4shell-spring4shell-lessons-years-later</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4shell-spring4shell-lessons-years-later</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The security cost of long-lived HTTP connections]]></title>
      <description><![CDATA[Keep-alive and HTTP/2 multiplexing cut handshake overhead but hold server resources open per connection — Slowloris and 2023's Rapid Reset attacks both exploited exactly that tradeoff.]]></description>
      <link>https://safeguard.sh/resources/blog/long-lived-http-connections-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/long-lived-http-connections-security-considerations</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How Malicious Skills Get Distributed Through Agent Registries]]></title>
      <description><![CDATA[CVE-2025-59536 (CVSS 8.7) let a single malicious commit auto-approve MCP servers in Claude Code, no install click required. Registries need the same controls as package managers.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-ai-agent-skill-malware-distribution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-ai-agent-skill-malware-distribution</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Mapping the blast radius of a vulnerable AI infrastructure dependency]]></title>
      <description><![CDATA[One Ray dashboard flaw let attackers hit hundreds of exposed AI servers. SBOM plus call-graph data is how you find every service that shares the exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/mapping-ai-dependency-blast-radius</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mapping-ai-dependency-blast-radius</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Moq NuGet incident: how a mocking library harvested developer emails]]></title>
      <description><![CDATA[In August 2023, Moq v4.20.0 quietly ran git config at build time and phoned home 10,356 times before anyone pulled it — via a dependency nobody vetted.]]></description>
      <link>https://safeguard.sh/resources/blog/moq-nuget-package-data-exfiltration-incident</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/moq-nuget-package-data-exfiltration-incident</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The 10 most common code-level vulnerability classes, ranked by real-world data]]></title>
      <description><![CDATA[MITRE's 2025 CWE Top 25 scored 39,080 CVEs — cross-site scripting still ranks #1, but Missing Authorization jumped five spots. Here's how to prevent each class.]]></description>
      <link>https://safeguard.sh/resources/blog/most-common-code-level-vulnerability-classes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/most-common-code-level-vulnerability-classes</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Mapping NIST CSF 2.0 to your AppSec program]]></title>
      <description><![CDATA[NIST CSF 2.0 added a sixth function, Govern, in February 2024 — most AppSec teams still map their tooling to only three of the six.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-csf-mapping-for-appsec-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-csf-mapping-for-appsec-teams</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The node-ipc protestware incident, four years later: a checklist for maintainer-inserted risk]]></title>
      <description><![CDATA[In March 2022 a legitimate node-ipc maintainer shipped code that wiped files based on IP geolocation. CVE-2022-23812 still has no patch for the real problem.]]></description>
      <link>https://safeguard.sh/resources/blog/node-ipc-protestware-2022-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-ipc-protestware-2022-lessons</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Node.js backend architecture patterns for 2026]]></title>
      <description><![CDATA[Node 22 shipped a stable permission model and npm has supported provenance since 2023 — yet the September 2025 Shai-Hulud worm still spread through unpinned installs.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-backend-architecture-patterns-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-backend-architecture-patterns-2026</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Security Implications of Misconfigured CORS in Node.js APIs]]></title>
      <description><![CDATA[One line of Express middleware — reflecting Origin back with credentials: true — turns CORS from a browser protection into an authenticated data-exfiltration channel.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-cors-security-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-cors-security-implications</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CSRF in Node.js: attack mechanics and modern mitigation]]></title>
      <description><![CDATA[Express has never shipped CSRF protection in core, and its most popular middleware, csurf, was archived in 2022 — here's what actually replaces it.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-csrf-protection-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-csrf-protection-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Node.js vs Deno vs Bun: comparing their security models]]></title>
      <description><![CDATA[Only one of the three major JavaScript runtimes denies system access by default — Node's permission model only went stable in v23.5.0, and Bun still has none.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-deno-bun-security-model-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-deno-bun-security-model-comparison</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[When Node.js sandboxing stops at the C++ boundary]]></title>
      <description><![CDATA[Node's permission model can block a native addon from loading at all — but once it's in, a single buffer overflow in C++ can corrupt the whole process.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-native-addon-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-native-addon-security-risks</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The security case for Node.js's newer runtime features]]></title>
      <description><![CDATA[Node's permission model went stable in v23.5.0, the built-in test runner in v20 — both quietly shrink attack surface, but neither is the sandbox teams assume it is.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-runtime-features-2026-security-impact</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-runtime-features-2026-security-impact</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Implementing SSL/TLS certificate pinning in Node.js]]></title>
      <description><![CDATA[HTTP Public Key Pinning died in Chrome 67 back in 2018, yet Node.js apps still need pinning for mobile backends and server-to-server calls — here's how to do it without bricking your own API.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-ssl-tls-pinning-implementation-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-ssl-tls-pinning-implementation-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Anatomy of an npm Build-Pipeline Hijack That Shipped a Cross-Platform RAT]]></title>
      <description><![CDATA[One stolen npm token, three malicious releases, four hours online — and 8 million weekly downloads exposed to a cross-platform credential stealer.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-build-pipeline-compromise-delivering-rat</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-build-pipeline-compromise-delivering-rat</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How npm's default install behavior leaked macOS text-replacement secrets]]></title>
      <description><![CDATA[npm auto-runs postinstall scripts with zero prompts on every install — a design choice Snyk showed in June 2023 can pull sensitive data out of macOS defaults.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-insecure-default-config-macos-keychain-exposure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-insecure-default-config-macos-keychain-exposure</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Anatomy of a self-propagating npm worm]]></title>
      <description><![CDATA[In September 2025, one phished maintainer account led to malicious chalk and debug releases hitting over 2B weekly downloads within two hours.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-maintainer-account-takeover-self-propagating-worm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-maintainer-account-takeover-self-propagating-worm</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The string-width-cjs npm packages: a supply chain warm-up, not a breach]]></title>
      <description><![CDATA[One of three empty npm packages aliasing real libraries reached 500+ dependents and 7,274 weekly downloads — with no malicious code found at all.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-string-width-cjs-supply-chain-incident</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-string-width-cjs-supply-chain-incident</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[NVD's enrichment backlog and how to build a multi-source vuln database strategy]]></title>
      <description><![CDATA[NIST enriched 42,000 CVEs in 2025 — 45% more than any prior year — and still fell behind. On April 15, 2026, it stopped trying to enrich everything.]]></description>
      <link>https://safeguard.sh/resources/blog/nvd-enrichment-delays-and-vuln-db-strategy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nvd-enrichment-delays-and-vuln-db-strategy</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A hands-on introduction to Rego for Kubernetes admission control]]></title>
      <description><![CDATA[OPA graduated CNCF on January 29, 2021, and Rego v1 became the default syntax in OPA v1.0.0 (Dec 2024) — here's how to write your first admission-control policies.]]></description>
      <link>https://safeguard.sh/resources/blog/open-policy-agent-rego-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-policy-agent-rego-fundamentals</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Preventing open redirect vulnerabilities in Laravel]]></title>
      <description><![CDATA[Laravel's own ->away() helper is documented as a bypass of its URL safety checks — feed it user input and you've built an open redirect, CWE-601, into the framework's happy path.]]></description>
      <link>https://safeguard.sh/resources/blog/open-redirect-prevention-laravel</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-redirect-prevention-laravel</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Inside OpenSSF's priority stack: SBOM, Scorecard, and Sigstore]]></title>
      <description><![CDATA[OpenSSF now runs eight technical initiative areas and four flagship projects — most teams have heard of one and adopted none. Here's what's actually worth doing first.]]></description>
      <link>https://safeguard.sh/resources/blog/openssf-secure-open-source-priorities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssf-secure-open-source-priorities</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Top 10 for LLM Applications: A Practical Walkthrough]]></title>
      <description><![CDATA[OWASP's 2025 LLM Top 10 added three new categories in one revision — here's what changed, why, and concrete mitigation patterns for each risk.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-for-llm-applications-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-for-llm-applications-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Open-source penetration testing tools: a comparison guide]]></title>
      <description><![CDATA[Nine open-source pentest tools, one decision problem: Nmap finds hosts, Metasploit exploits them, but neither replaces the other. Here's when to reach for each.]]></description>
      <link>https://safeguard.sh/resources/blog/penetration-testing-tools-comparison-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/penetration-testing-tools-comparison-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[PHP code security fundamentals: injection, deserialization, and file inclusion]]></title>
      <description><![CDATA[PHP still powers over 70% of server-side websites, and its three oldest vulnerability classes — injection, deserialization, and file inclusion — remain the most common findings in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/php-code-security-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-code-security-fundamentals</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[PHPStan vs. Psalm: setting up PHP static analysis to catch security bugs pre-commit]]></title>
      <description><![CDATA[Psalm ships free taint analysis out of the box; PHPStan doesn't track data flow at all without extensions. Here's how to wire either one into pre-commit.]]></description>
      <link>https://safeguard.sh/resources/blog/php-static-analysis-tooling-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-static-analysis-tooling-guide-2026</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What PHP's use-after-free bugs teach us about dynamic-runtime memory safety]]></title>
      <description><![CDATA[Check Point disclosed three PHP 7 unserialize zero-days in 2016 alone. A decade of PHP use-after-free CVEs shows memory-safety risk doesn't end at the C/C++ boundary.]]></description>
      <link>https://safeguard.sh/resources/blog/php-use-after-free-cve-disclosure-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-use-after-free-cve-disclosure-lessons</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Anatomy of the polyfill.io CDN Compromise]]></title>
      <description><![CDATA[In June 2024, a single acquired domain turned a free CDN trusted by over 100,000 sites into a live malware injection point — with no dependency update required.]]></description>
      <link>https://safeguard.sh/resources/blog/polyfill-io-supply-chain-attack-anatomy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/polyfill-io-supply-chain-attack-anatomy</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Preventing log injection in Node.js and Express]]></title>
      <description><![CDATA[A single unescaped newline in req.body can let an attacker forge fake log entries — CWE-117 log injection still hits Node apps that log with plain string concatenation.]]></description>
      <link>https://safeguard.sh/resources/blog/preventing-log-injection-in-nodejs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preventing-log-injection-in-nodejs</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Preventing SQL Injection with Entity Framework]]></title>
      <description><![CDATA[EF Core parameterizes every standard LINQ query by default — the real injection risk lives in three raw-SQL escape hatches Microsoft documents but developers still misuse.]]></description>
      <link>https://safeguard.sh/resources/blog/preventing-sql-injection-with-entity-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preventing-sql-injection-with-entity-framework</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Prioritizing vulnerabilities by real-world risk, not raw CVSS score]]></title>
      <description><![CDATA[Kenna/Cyentia found just 2.6% of 2019's tracked CVEs were ever actively exploited — yet most teams still triage backlogs by CVSS score alone.]]></description>
      <link>https://safeguard.sh/resources/blog/prioritizing-vulnerabilities-by-real-world-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prioritizing-vulnerabilities-by-real-world-risk</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Building a minimal, multi-stage, non-root Dockerfile for PHP]]></title>
      <description><![CDATA[The official php:fpm image still runs its master process as root — a documented, still-open issue. Here's how to build a PHP Dockerfile that doesn't.]]></description>
      <link>https://safeguard.sh/resources/blog/production-ready-dockerfile-php-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/production-ready-dockerfile-php-best-practices</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Prompt injection in AI coding assistant system prompts]]></title>
      <description><![CDATA[Copilot, Cursor, and Windsurf all read untrusted repo text into the same channel as trusted instructions — three 2025 CVEs show what happens next.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-in-ai-coding-assistant-system-prompts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-in-ai-coding-assistant-system-prompts</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Prompt injection via AI agent CI/CD workflow tampering]]></title>
      <description><![CDATA[A single malicious PR title was enough to make three major AI coding agents leak API keys straight out of a GitHub Actions runner.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-via-ai-agent-cicd-workflow-tampering</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-via-ai-agent-cicd-workflow-tampering</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How malicious PyPI packages steal cloud credentials at install time]]></title>
      <description><![CDATA[A typosquat of a 200M-download SSH library stole AWS keys from 37,000 installs — before anyone imported it. Here's the install-time attack pattern.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-malicious-package-cloud-credential-theft</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-malicious-package-cloud-credential-theft</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Anatomy of a PyPI Compromise: How durabletask Got Hijacked in 35 Minutes]]></title>
      <description><![CDATA[Three malicious durabletask releases hit PyPI in a 35-minute window in May 2026 — a maintainer-token theft, not a code review failure.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-package-compromise-anatomy-durabletask</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-package-compromise-anatomy-durabletask</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Symmetric vs asymmetric file encryption in Python, done correctly]]></title>
      <description><![CDATA[AES-GCM needs a unique 96-bit nonce every single time — reuse one under the same key and GCM's authentication guarantee collapses entirely, not just confidentiality.]]></description>
      <link>https://safeguard.sh/resources/blog/python-file-encryption-symmetric-vs-asymmetric</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-file-encryption-symmetric-vs-asymmetric</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The three dimensions of Python static analysis, and where each one blinds itself]]></title>
      <description><![CDATA[AST scanners, taint trackers, and type checkers each solve a different problem — and each has a documented blind spot that lets real bugs through untouched.]]></description>
      <link>https://safeguard.sh/resources/blog/python-static-analysis-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-static-analysis-deep-dive</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secure conditional rendering in React and Next.js Server Components]]></title>
      <description><![CDATA[A CVSS 10.0 React Server Components flaw, patched in December 2025, shows why {isAdmin && <Panel/>} isn't access control — the data ships to the client either way.]]></description>
      <link>https://safeguard.sh/resources/blog/react-nextjs-conditional-rendering-xss-pitfalls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-nextjs-conditional-rendering-xss-pitfalls</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[ReDoS in Python and FastAPI: how one regex takes down an event loop]]></title>
      <description><![CDATA[CVE-2024-3772 let a single crafted email string trigger catastrophic backtracking in Pydantic's own validator — the exact code path every FastAPI request body runs through.]]></description>
      <link>https://safeguard.sh/resources/blog/redos-in-python-and-fastapi-input-validation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/redos-in-python-and-fastapi-input-validation</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Rego for intermediates: combining rules with AND/OR and writing actionable error messages]]></title>
      <description><![CDATA[Rego has no `&&` or `||` operators — AND is implicit, OR means writing the same rule twice, and most teams miss both until a policy silently passes.]]></description>
      <link>https://safeguard.sh/resources/blog/rego-combining-queries-and-custom-error-messages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rego-combining-queries-and-custom-error-messages</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Rego for security engineers: a beginner's guide to OPA policy]]></title>
      <description><![CDATA[Rego graduated from Styra research project to a CNCF-graduated standard in under five years. Here's how to write your first real OPA/Conftest policy.]]></description>
      <link>https://safeguard.sh/resources/blog/rego-introduction-for-security-engineers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rego-introduction-for-security-engineers</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A practical REST API hardening checklist]]></title>
      <description><![CDATA[OWASP's 2023 API Security Top 10 still ranks broken object-level authorization as the #1 risk — here's a concrete checklist for authn, rate limiting, and input validation.]]></description>
      <link>https://safeguard.sh/resources/blog/rest-api-security-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rest-api-security-checklist</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Hidden Risks of AI Coding Assistants]]></title>
      <description><![CDATA[A 2021 NYU study found 40% of Copilot-generated code contained exploitable bugs — and that's before counting leaked secrets or hallucinated packages.]]></description>
      <link>https://safeguard.sh/resources/blog/risks-of-ai-coding-assistants</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/risks-of-ai-coding-assistants</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The blind spots of single-model AI security tooling]]></title>
      <description><![CDATA[OpenAI's API went down three separate times in 2024 alone — if your SAST pipeline hard-depends on one model provider, its outages and blind spots become yours.]]></description>
      <link>https://safeguard.sh/resources/blog/risks-of-relying-on-a-single-ai-model-for-security-tooling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/risks-of-relying-on-a-single-ai-model-for-security-tooling</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SAML SSO vulnerabilities: signature wrapping and assertion replay explained]]></title>
      <description><![CDATA[A 2024 ruby-saml flaw (CVE-2024-45409, CVSS 9.8) let attackers forge SAML assertions and log in as any user, including admins — seven years after the same bug class was first disclosed.]]></description>
      <link>https://safeguard.sh/resources/blog/saml-vulnerabilities-and-remediation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/saml-vulnerabilities-and-remediation</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Wiring SAST Findings Into ITSM: The Overlooked Lever for MTTR]]></title>
      <description><![CDATA[The 2026 Verizon DBIR found median patch time hit 43 days, up from 32 — and much of that gap is ticket handoff friction, not fix difficulty.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-findings-itsm-workflow-integration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-findings-itsm-workflow-integration</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A vendor-neutral framework for evaluating SAST tools]]></title>
      <description><![CDATA[OWASP's Benchmark suite has run 2,740 fixed Java test cases since 2016, yet most SAST comparisons still amount to a vendor's self-reported false-positive number.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-tool-evaluation-criteria</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-tool-evaluation-criteria</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SBOM adoption: generating, distributing, and consuming SBOMs to cut supply chain risk]]></title>
      <description><![CDATA[Four years after EO 14028, most SBOMs still sit unread in a folder. Here's how to generate, ship, and actually query one before the next Log4Shell.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-adoption-reducing-supply-chain-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-adoption-reducing-supply-chain-risk</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A framework for scaling risk-based AppSec across many teams]]></title>
      <description><![CDATA[40,009 CVEs were published in 2024 alone — a 38.83% jump over 2023. No security team can triage that volume by hand across dozens of engineering teams.]]></description>
      <link>https://safeguard.sh/resources/blog/scaling-risk-based-appsec-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scaling-risk-based-appsec-programs</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Scan Large GitHub Orgs for Exposed Secrets Responsibly]]></title>
      <description><![CDATA[28.65 million new secrets landed on public GitHub in 2025 alone. Here's a research methodology for finding them at scale without becoming the next incident.]]></description>
      <link>https://safeguard.sh/resources/blog/scanning-github-orgs-for-exposed-secrets-research</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scanning-github-orgs-for-exposed-secrets-research</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The complete workflow for finding and remediating hardcoded secrets in GitHub]]></title>
      <description><![CDATA[GitGuardian found 12.8 million secrets leaked on public GitHub in 2023 alone, and over 90% were still valid five days later. Here's the fix workflow that actually closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/scanning-github-repos-for-hardcoded-secrets</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scanning-github-repos-for-hardcoded-secrets</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The SEC's cybersecurity disclosure rules, explained for CISOs and boards]]></title>
      <description><![CDATA[Since December 18, 2023, U.S. public companies must disclose material cyber incidents within four business days — and boards must now document their oversight of the risk.]]></description>
      <link>https://safeguard.sh/resources/blog/sec-cybersecurity-disclosure-rules-ciso-impact</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sec-cybersecurity-disclosure-rules-ciso-impact</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secrets detection to prevent data breaches]]></title>
      <description><![CDATA[GitGuardian found 12.8 million new secrets exposed on public GitHub in 2023, up 28% year over year — and most of them stayed live for days after leaking.]]></description>
      <link>https://safeguard.sh/resources/blog/secrets-detection-to-prevent-data-breaches</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secrets-detection-to-prevent-data-breaches</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secure AI-Assisted Development: A Best-Practices Guide]]></title>
      <description><![CDATA[Samsung banned ChatGPT company-wide in May 2023 after engineers pasted proprietary source code into it three times in 20 days. Here's how to adopt AI coding assistants without repeating that mistake.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-ai-assisted-development-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-ai-assisted-development-best-practices</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Guardrails for AI Coding Assistants in the SDLC]]></title>
      <description><![CDATA[45% of AI-generated code samples in Veracode's 2025 test of 100+ LLMs contained OWASP Top 10 vulnerabilities — here's how to gate it before merge.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-ai-assisted-sdlc-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-ai-assisted-sdlc-practices</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A vendor-neutral checklist for rolling out AI coding assistants safely]]></title>
      <description><![CDATA[437,000+ downloads of a vulnerable mcp-remote bridge and a backdoored Postmark MCP server prove AI assistants are now a live supply-chain surface, not a theoretical one.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-ai-coding-assistant-adoption-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-ai-coding-assistant-adoption-checklist</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A hardening guide to securing Flask applications]]></title>
      <description><![CDATA[Flask ships session cookies with HttpOnly on by default — but Secure, SameSite, CSRF tokens, and every security header are left entirely to you.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-flask-applications-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-flask-applications-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secure multi-tenant SaaS access control patterns]]></title>
      <description><![CDATA[Broken Access Control has topped OWASP's Top 10 for two straight cycles, found in 100% of tested apps in 2025 — most of that risk starts with one missing tenant_id check.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-multitenant-saas-access-control-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-multitenant-saas-access-control-patterns</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secure password hashing in Go: bcrypt, Argon2, and the mistakes in between]]></title>
      <description><![CDATA[Go's bcrypt package caps input at 72 bytes and returns ErrPasswordTooLong instead of silently truncating — one of several Go-specific quirks that trip up password hashing code.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-password-hashing-go</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-password-hashing-go</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secure URL Encoding and Decoding in Java]]></title>
      <description><![CDATA[Java's URLEncoder turns spaces into + instead of %20 — a form-encoding quirk that, mixed with double-decoding, still causes path-traversal bugs like CVE-2025-41242 in 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-url-encoding-decoding-in-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-url-encoding-decoding-in-java</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing AI coding agent remediation loops]]></title>
      <description><![CDATA[Replit's AI agent deleted a live production database in July 2025 despite an explicit freeze order. Here's how to wire remediation agents so that can't happen to you.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-ai-coding-agent-remediation-loops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-ai-coding-agent-remediation-loops</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A Checklist for Reviewing AI-Generated Code Before It Merges]]></title>
      <description><![CDATA[19.7% of packages LLMs recommend don't exist in real registries, per a 576,000-sample USENIX 2025 study — here's what to check before merging AI-written code.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-ai-generated-code-review-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-ai-generated-code-review-checklist</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing AI-Generated Code: The New Risk Surface]]></title>
      <description><![CDATA[40.73% of Copilot's suggested code contains a vulnerability, and one 2024 study found nearly 1 in 5 AI-recommended packages simply don't exist.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-ai-generated-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-ai-generated-code</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Hardening Amazon EKS With Native AWS Controls]]></title>
      <description><![CDATA[AWS secures the EKS control plane and etcd — everything else, from IAM to security groups to node OS patching, is on you under the shared responsibility model.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-eks-clusters-native-aws-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-eks-clusters-native-aws-controls</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing LLM and Model Supply Chains]]></title>
      <description><![CDATA[JFrog found roughly 100 malicious model files on Hugging Face in 2024 alone — model weights are now a build-pipeline attack surface, and most teams have no SBOM for them.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-llm-and-model-supply-chains</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-llm-and-model-supply-chains</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The S3 bucket security checklist every AWS team needs]]></title>
      <description><![CDATA[AWS made Block Public Access the default for new S3 buckets in April 2023 — but the Capital One breach exposed 106 million records through IAM, not a bucket setting.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-s3-buckets-on-aws</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-s3-buckets-on-aws</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing SBOM storage and distribution in cloud environments]]></title>
      <description><![CDATA[GitGuardian found 23.77 million secrets exposed on public GitHub in 2024 alone — an unprotected SBOM repository is the same mistake, just with your dependency tree instead.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-sbom-storage-and-distribution-cloud</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-sbom-storage-and-distribution-cloud</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Security Practices for GitHub Copilot and AI Coding Assistants]]></title>
      <description><![CDATA[Copilot suggested 2,702 hardcoded secrets from just 900 prompts in one study, and at least 200 were live credentials — adoption without policy is a leak waiting to happen.]]></description>
      <link>https://safeguard.sh/resources/blog/security-practices-for-github-copilot-and-ai-assistants</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-practices-for-github-copilot-and-ai-assistants</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The security risk of LLMs reviving abandoned open-source packages]]></title>
      <description><![CDATA[USENIX Security 2025 found 19.7% of LLM code samples hallucinate a package name — and real, dormant packages carry the same blind trust.]]></description>
      <link>https://safeguard.sh/resources/blog/security-risk-of-llms-reviving-abandoned-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-risk-of-llms-reviving-abandoned-packages</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[When the Security Tool Is the Backdoor]]></title>
      <description><![CDATA[CCleaner, tj-actions, and ua-parser-js show the same pattern: trusted tools with CI access became the attack, hitting 2.27M+ users and 23,000+ repos.]]></description>
      <link>https://safeguard.sh/resources/blog/security-tool-supply-chain-backdoor-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-tool-supply-chain-backdoor-risk</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Security error budgets: gating risk instead of blocking everything]]></title>
      <description><![CDATA[Google's SRE teams have spent an error budget on reliability since 2016 — applying the same model to security turns blanket blocking into risk-weighted gating.]]></description>
      <link>https://safeguard.sh/resources/blog/security-vs-development-priority-tradeoffs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-vs-development-priority-tradeoffs</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why semantic versioning and release channels matter for security tools]]></title>
      <description><![CDATA[A backdoor sat in xz-utils 5.6.0 and 5.6.1 for weeks before Andres Freund caught it — stable distro channels, not luck, kept it out of most production systems.]]></description>
      <link>https://safeguard.sh/resources/blog/semantic-versioning-for-security-tool-releases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/semantic-versioning-for-security-tool-releases</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secure session lifecycle management: tokens, rotation, and cookie flags]]></title>
      <description><![CDATA[OWASP requires session IDs carry at least 64 bits of entropy, yet a 2007 Rails flaw shows one dropped attribute is enough to make fixation trivial.]]></description>
      <link>https://safeguard.sh/resources/blog/session-management-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/session-management-security-best-practices</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Building a shift-left security culture developers actually buy into]]></title>
      <description><![CDATA[Log4Shell sat in most Java codebases for years before Dec 2021 — shift-left tooling alone didn't stop it. Culture, placement, and incentives are what make it work.]]></description>
      <link>https://safeguard.sh/resources/blog/shift-left-culture-developer-first-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shift-left-culture-developer-first-security</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-1471: Inside the SnakeYaml Deserialization RCE]]></title>
      <description><![CDATA[CVE-2022-1471 scored 9.8 CRITICAL under NIST's CVSS calculation — a single YAML tag could hand attackers remote code execution in any Java app parsing untrusted input.]]></description>
      <link>https://safeguard.sh/resources/blog/snakeyaml-cve-2022-1471-unsafe-deserialization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snakeyaml-cve-2022-1471-unsafe-deserialization</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Software supply chain attack trends: what the public incident data shows]]></title>
      <description><![CDATA[Sonatype tracked 454,648 new malicious packages in 2025 alone — over 1.2 million total since it started counting. Here's what three years of incident data reveal.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-attack-trends-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-attack-trends-analysis</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A vendor-neutral framework for software supply chain security tools]]></title>
      <description><![CDATA[Supply chain tooling splits into four distinct categories with different failure modes — the xz-utils backdoor slipped past most of them for over two years.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-tools-landscape</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-tools-landscape</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Software supply chain attacks in 2026: what's actually changed]]></title>
      <description><![CDATA[A single compromised maintainer token in March 2025 exposed secrets across 23,000+ repositories — supply chain attacks now target the pipeline, not just the package.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-trends</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Robust input validation in Spring Boot: Bean Validation and its bypasses]]></title>
      <description><![CDATA[Bean Validation (JSR-380) looks like a solved problem in Spring Boot, but nested DTOs, list elements, and unannotated service methods routinely skip validation silently.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-boot-input-validation-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-boot-input-validation-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The most common Spring Boot security misconfigurations, and how to fix them]]></title>
      <description><![CDATA[CVE-2026-40976 let anonymous users hit /actuator/env and /actuator/heapdump on default Spring Boot 4 filter chains, CVSS 9.1 — here's how to actually harden Spring Boot.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-boot-security-vulnerabilities-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-boot-security-vulnerabilities-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Parameterized queries across languages: the real defense against SQL injection]]></title>
      <description><![CDATA[SQL injection (CWE-89) still ranks #3 on the OWASP Top 10, but every major language has shipped a native, built-in fix for over a decade — most breaches happen anyway.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-query-parameterization-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-query-parameterization-best-practices</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The State of Open Source Security: What a Year of Disclosure Data Shows]]></title>
      <description><![CDATA[454,600+ new malicious packages hit open-source registries in 2025, and NVD still closed the year with a 27,000-CVE enrichment backlog.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-open-source-security-trends-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-open-source-security-trends-analysis</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Unsafe Deserialization in Swift: NSCoding, Codable, and Safer Patterns]]></title>
      <description><![CDATA[Two 2019 iOS zero-click bugs, CVE-2019-8646 and CVE-2019-8647, both traced back to NSKeyedUnarchiver — a reminder that Swift's Objective-C legacy still hides deserialization risk.]]></description>
      <link>https://safeguard.sh/resources/blog/swift-deserialization-security-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/swift-deserialization-security-fundamentals</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Symmetric vs Asymmetric Encryption in Python: A Practical Guide]]></title>
      <description><![CDATA[One key or two? A working comparison of Fernet and RSA in Python's cryptography library — with the OAEP-vs-PKCS1v15 mistake that still causes padding-oracle bugs.]]></description>
      <link>https://safeguard.sh/resources/blog/symmetric-vs-asymmetric-encryption-python-examples</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/symmetric-vs-asymmetric-encryption-python-examples</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How task-scheduler RCEs become cryptomining botnets]]></title>
      <description><![CDATA[Two chained Apache Airflow CVEs and a Rundeck YAML deserialization bug show how scheduler tools turn one flaw into unauthenticated RCE and persistent mining.]]></description>
      <link>https://safeguard.sh/resources/blog/task-scheduler-rce-cryptomining-botnets</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/task-scheduler-rce-cryptomining-botnets</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Thymeleaf SSTI risk patterns: how a tab character bypassed a Java template sandbox]]></title>
      <description><![CDATA[CVE-2026-40478 shows how a single tab character bypassed Thymeleaf's expression sandbox, turning misused templates into remote code execution.]]></description>
      <link>https://safeguard.sh/resources/blog/thymeleaf-ssti-risk-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/thymeleaf-ssti-risk-patterns</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The most common infrastructure-as-code security risks, with Terraform examples]]></title>
      <description><![CDATA[AWS S3 buckets are private by default, yet public-bucket findings still top every cloud posture scan — because Terraform's own access-block resource defaults to open.]]></description>
      <link>https://safeguard.sh/resources/blog/top-infrastructure-as-code-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-infrastructure-as-code-security-risks</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Using EPSS scores for vulnerability remediation prioritization]]></title>
      <description><![CDATA[EPSS predicts exploitation probability for every CVE on a 0-1 scale, updated daily. Paired with CVSS, it turns a 1,000-ticket backlog into a short, defensible list.]]></description>
      <link>https://safeguard.sh/resources/blog/using-epss-scores-for-vulnerability-prioritization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/using-epss-scores-for-vulnerability-prioritization</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Verifying webhook signatures correctly]]></title>
      <description><![CDATA[Stripe gives you a 5-minute replay window and GitHub a raw-body HMAC — but most outages trace back to one bug: verifying JSON after it's been re-serialized.]]></description>
      <link>https://safeguard.sh/resources/blog/verifying-webhook-signatures-correctly</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/verifying-webhook-signatures-correctly</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Vetting third-party agent skills before you install them]]></title>
      <description><![CDATA[AI agent skill marketplaces run installed code with your full permissions and no sandboxing — VS Code's 2025 extension attacks show exactly how that gets abused.]]></description>
      <link>https://safeguard.sh/resources/blog/vetting-third-party-agent-skill-marketplaces</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vetting-third-party-agent-skill-marketplaces</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Building Secure VS Code Extensions: A Developer's Guide]]></title>
      <description><![CDATA[VS Code extensions run as trusted Node.js code with full disk and network access and no permission model to fall back on. Here is how to build one that does not become the next supply chain incident.]]></description>
      <link>https://safeguard.sh/resources/blog/vscode-extension-security-development-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vscode-extension-security-development-guide</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CWE vs. CVE vs. CVSS: The Vocabulary Every AppSec Team Gets Wrong]]></title>
      <description><![CDATA[One CWE weakness class can spawn thousands of CVEs, and a single CVE can now carry two different CVSS scores at once — most teams still use the terms interchangeably.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-vs-weakness-appsec-taxonomy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-vs-weakness-appsec-taxonomy</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Web cache poisoning: attack mechanics and prevention]]></title>
      <description><![CDATA[A 2024 academic scan of the Tranco Top 1000 domains found roughly 17% vulnerable to web cache poisoning — here's how the attack works and how to stop it at the edge.]]></description>
      <link>https://safeguard.sh/resources/blog/web-cache-poisoning-attack-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-cache-poisoning-attack-prevention</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[WebAssembly's security model: sandbox guarantees and the attack surface that remains]]></title>
      <description><![CDATA[Two Critical Wasmtime sandbox-escape CVEs landed on the same day in April 2026 — proof that a wasm sandbox is only as strong as the runtime enforcing it.]]></description>
      <link>https://safeguard.sh/resources/blog/webassembly-security-concerns-and-sandboxing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webassembly-security-concerns-and-sandboxing</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The libwebp heap overflow that patched half the internet: CVE-2023-4863]]></title>
      <description><![CDATA[One heap buffer overflow in a 15-year-old image codec forced Chrome, Firefox, Edge, Electron apps, and entire Linux distros to ship emergency patches within days.]]></description>
      <link>https://safeguard.sh/resources/blog/webp-libwebp-cve-2023-4863-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webp-libwebp-cve-2023-4863-deep-dive</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[XS-Leaks explained: cross-site leak techniques and the defenses that stop them]]></title>
      <description><![CDATA[XS-Leaks bypass the Same-Origin Policy without running a single line of attacker script — they read state through timing, frame counts, and error events instead.]]></description>
      <link>https://safeguard.sh/resources/blog/xs-leaks-explained-and-defenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xs-leaks-explained-and-defenses</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Anatomy of the XZ Utils backdoor: how CVE-2024-3094 nearly compromised SSH on every major Linux distro]]></title>
      <description><![CDATA[A CVSS 10.0 backdoor sat in xz 5.6.0 and 5.6.1 for weeks, hidden in a test file, until 0.5 seconds of extra SSH login latency gave it away.]]></description>
      <link>https://safeguard.sh/resources/blog/xz-utils-backdoor-cve-2024-3094-anatomy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xz-utils-backdoor-cve-2024-3094-anatomy</guid>
      <pubDate>Wed, 08 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best open source vulnerability database and threat intell...]]></title>
      <description><![CDATA[A practical buyer's guide to open source vulnerability database tools, CVE aggregation, and threat intel feeds for tracking OSS risk.]]></description>
      <link>https://safeguard.sh/resources/blog/best-open-source-vulnerability-database-and-threat-intelligence-feeds</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-open-source-vulnerability-database-and-threat-intelligence-feeds</guid>
      <pubDate>Wed, 08 Jul 2026 08:57:30 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes secrets management vulnerability guide]]></title>
      <description><![CDATA[Kubernetes Secrets are base64, not encrypted. Real CVEs and the Tesla breach show how attackers exploit that gap — and how to close it.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-secrets-management-vulnerability-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-secrets-management-vulnerability-guide</guid>
      <pubDate>Wed, 08 Jul 2026 07:37:04 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Untracked Dependencies in the Software Supply Chain]]></title>
      <description><![CDATA[Most teams can name their direct dependencies but not the hundreds of transitive packages actually running underneath. Here's why that gap is where real supply chain attacks live.]]></description>
      <link>https://safeguard.sh/resources/blog/untracked-dependencies-in-the-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/untracked-dependencies-in-the-software-supply-chain</guid>
      <pubDate>Wed, 08 Jul 2026 06:16:37 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CI/CD pipeline security vulnerability trends]]></title>
      <description><![CDATA[CI/CD pipelines now hold the keys attackers want most. Here's what tj-actions, Ultralytics, and Jenkins CVE-2024-23897 reveal about the trend.]]></description>
      <link>https://safeguard.sh/resources/blog/cicd-pipeline-security-vulnerability-trends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cicd-pipeline-security-vulnerability-trends</guid>
      <pubDate>Wed, 08 Jul 2026 04:56:10 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Outdated Software Components: Quantifying the Risk]]></title>
      <description><![CDATA[Outdated dependencies sit in nearly every codebase. Here's what Equifax and Log4Shell reveal about the real cost of unpatched software supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/outdated-software-components-quantifying-the-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/outdated-software-components-quantifying-the-risk</guid>
      <pubDate>Wed, 08 Jul 2026 03:35:43 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Actions workflow injection vulnerabilities]]></title>
      <description><![CDATA[How GitHub Actions workflow injection lets attackers hijack CI pipelines via untrusted input, real CVEs like CVE-2025-30066, and how to detect it.]]></description>
      <link>https://safeguard.sh/resources/blog/github-actions-workflow-injection-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-actions-workflow-injection-vulnerabilities</guid>
      <pubDate>Wed, 08 Jul 2026 02:15:17 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Immature Open Source Projects as a Supply Chain Risk]]></title>
      <description><![CDATA[xz-utils, event-stream, node-ipc: a decade of supply chain incidents traces back to one root cause — thinly maintained, single-person open source projects.]]></description>
      <link>https://safeguard.sh/resources/blog/immature-open-source-projects-as-a-supply-chain-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/immature-open-source-projects-as-a-supply-chain-risk</guid>
      <pubDate>Wed, 08 Jul 2026 00:54:50 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Jenkins plugin vulnerability trends report]]></title>
      <description><![CDATA[Jenkins plugin CVEs keep piling up—missing permission checks, CSRF gaps, and a critical CVE-2024-23897 that attackers scanned for within days.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-plugin-vulnerability-trends-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-plugin-vulnerability-trends-report</guid>
      <pubDate>Tue, 07 Jul 2026 23:34:23 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[White-Box Penetration Testing: What Testers Actually See]]></title>
      <description><![CDATA[White box penetration testing gives testers source code, architecture diagrams, and credentials up front, which finds different bugs than a black-box test — usually faster and deeper, at the cost of realism.]]></description>
      <link>https://safeguard.sh/resources/blog/white-box-penetration-testing-what-testers-see</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/white-box-penetration-testing-what-testers-see</guid>
      <pubDate>Tue, 07 Jul 2026 22:13:57 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[License and Regulatory Risk in Open Source Components]]></title>
      <description><![CDATA[Redis, HashiCorp, and Elastic all re-licensed core projects since 2021, and new rules like the EU Cyber Resilience Act now make license and SBOM gaps a regulatory problem.]]></description>
      <link>https://safeguard.sh/resources/blog/license-and-regulatory-risk-in-open-source-components</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/license-and-regulatory-risk-in-open-source-components</guid>
      <pubDate>Tue, 07 Jul 2026 20:53:30 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Container runtime security (containerd/CRI-O) vulnerability roundup]]></title>
      <description><![CDATA[Container runtime CVEs like the runc Leaky Vessels flaw and CRI-O's cr8escape show how containerd and CRI-O bugs turn into full host takeovers.]]></description>
      <link>https://safeguard.sh/resources/blog/container-runtime-security-containerdcri-o-vulnerability-roundup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-runtime-security-containerdcri-o-vulnerability-roundup</guid>
      <pubDate>Tue, 07 Jul 2026 19:33:03 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Under/Oversized Dependency Risk in Modern Applications]]></title>
      <description><![CDATA[Oversized dependency risk and fragile single-maintainer packages both widen your software supply chain attack surface. Here's how to spot and manage both.]]></description>
      <link>https://safeguard.sh/resources/blog/underoversized-dependency-risk-in-modern-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/underoversized-dependency-risk-in-modern-applications</guid>
      <pubDate>Tue, 07 Jul 2026 18:12:37 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Unapproved Change Risk in the Software Supply Chain]]></title>
      <description><![CDATA[How unreviewed code, dependency, and pipeline changes create supply chain breaches like SolarWinds and XZ Utils - and how to detect them before attackers do.]]></description>
      <link>https://safeguard.sh/resources/blog/unapproved-change-risk-in-the-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unapproved-change-risk-in-the-software-supply-chain</guid>
      <pubDate>Tue, 07 Jul 2026 16:52:10 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AI Bill of Materials (AI-BOM) for Model Supply Chains]]></title>
      <description><![CDATA[An AI-BOM tracks every model, dataset, and dependency in your ML pipeline so a compromised base model or license issue can be traced in minutes, not weeks.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-bill-of-materials-ai-bom-for-model-supply-chains</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-bill-of-materials-ai-bom-for-model-supply-chains</guid>
      <pubDate>Tue, 07 Jul 2026 15:31:43 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[OpenTofu and Terraform provider supply chain risk]]></title>
      <description><![CDATA[Terraform and OpenTofu providers run unsandboxed with full pipeline credentials. Here's where the provider supply chain actually breaks down.]]></description>
      <link>https://safeguard.sh/resources/blog/opentofu-and-terraform-provider-supply-chain-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/opentofu-and-terraform-provider-supply-chain-risk</guid>
      <pubDate>Tue, 07 Jul 2026 14:11:17 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Weak Password Recovery Mechanisms]]></title>
      <description><![CDATA[From Sarah Palin's 2008 Yahoo hack to the 2014 iCloud photo leak, weak password recovery flows keep giving attackers account takeover without a password.]]></description>
      <link>https://safeguard.sh/resources/blog/weak-password-recovery-mechanisms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/weak-password-recovery-mechanisms</guid>
      <pubDate>Tue, 07 Jul 2026 12:50:50 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Session Persistence Security Risks]]></title>
      <description><![CDATA[CircleCI, Okta, Sourcegraph, and Codecov were all breached the same way: a session token outlived the trust that created it. Here's how session persistence becomes a supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/session-persistence-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/session-persistence-security-risks</guid>
      <pubDate>Tue, 07 Jul 2026 11:30:23 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Multi-Factor Authentication Bypass via Privilege Escalation]]></title>
      <description><![CDATA[Attackers increasingly skip cracking MFA altogether — they escalate privileges around it. Real cases from Microsoft, Uber, and SolarWinds show how, and what actually stops it.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-factor-authentication-bypass-via-privilege-escalation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-factor-authentication-bypass-via-privilege-escalation</guid>
      <pubDate>Tue, 07 Jul 2026 10:09:56 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Affordable SCA Tool FAQ: Real Software Composition Analysis for $1]]></title>
      <description><![CDATA[How to get affordable software composition analysis in 2026 — what SCA should cost, why free scanners aren't really free, and how Safeguard's $1 Starter plan delivers real SCA.]]></description>
      <link>https://safeguard.sh/resources/blog/affordable-sca-tool-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/affordable-sca-tool-faq</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Agent-Based vs Agentless Scanning: What's the Difference?]]></title>
      <description><![CDATA[Agent-based scanning installs software on each system to watch it from the inside. Agentless scanning inspects from the outside with no installation. One sees deeper; the other deploys faster.]]></description>
      <link>https://safeguard.sh/resources/blog/agent-based-vs-agentless-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agent-based-vs-agentless-scanning</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Preventing CSRF and XSS in ASP.NET Core]]></title>
      <description><![CDATA[How CSRF and XSS actually work against ASP.NET Core apps, and the concrete defenses, antiforgery tokens, Razor output encoding, CSP, and SameSite cookies, that shut them down.]]></description>
      <link>https://safeguard.sh/resources/blog/aspnet-csrf-xss-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aspnet-csrf-xss-prevention</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Auto-Fix Vulnerabilities FAQ: Patching Code and Containers Automatically]]></title>
      <description><![CDATA[How automated vulnerability fixing works across source code and container images — direct and transitive dependencies, breaking-change safety, and where human review belongs.]]></description>
      <link>https://safeguard.sh/resources/blog/auto-fix-vulnerabilities-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/auto-fix-vulnerabilities-faq</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[AWS S3 Bucket Security: The Complete 2026 Guide]]></title>
      <description><![CDATA[S3 is the single most common source of cloud data leaks. This guide covers block public access, encryption, bucket policies, and how to enforce all three in Terraform.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-s3-bucket-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-s3-bucket-security</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Axios Security Guide (2026)]]></title>
      <description><![CDATA[Axios is the most popular HTTP client in the JavaScript ecosystem — and its SSRF and credential-leak CVEs make its version and configuration security-relevant. Here is how to run it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/axios-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/axios-security-guide</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Barracuda ESG CVE-2023-2868 Explained: The Command Injection That Ended in Hardware Replacement]]></title>
      <description><![CDATA[CVE-2023-2868 is a command injection in the Barracuda Email Security Gateway, exploited as a zero-day by UNC4841 for months. Rated CVSS 9.8, it ended with Barracuda advising physical appliance replacement.]]></description>
      <link>https://safeguard.sh/resources/blog/barracuda-esg-cve-2023-2868-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/barracuda-esg-cve-2023-2868-explained</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[The Best Open Source Security Tools in 2026]]></title>
      <description><![CDATA[You can build a capable security program from free tools. This balanced guide compares Trivy, Grype and Syft, OSV-Scanner, OWASP Dependency-Check, and Dependency-Track — and is honest about when a commercial platform earns its cost.]]></description>
      <link>https://safeguard.sh/resources/blog/best-open-source-security-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-open-source-security-tools-2026</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best SAST Tools in 2026: A Buyer's Guide to Static Analysis]]></title>
      <description><![CDATA[A balanced 2026 comparison of the leading static application security testing tools — Semgrep, CodeQL, SonarQube, Snyk Code, Checkmarx, and Fortify — with an honest look at where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/best-sast-tools-2026-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-sast-tools-2026-2026</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CI/CD Supply Chain Attacks Explained: Anatomy and Defense]]></title>
      <description><![CDATA[From SolarWinds to tj-actions, CI/CD pipelines are where one foothold reaches thousands of victims. This guide explains the anatomy of a pipeline supply chain attack and the layered defenses that stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/ci-cd-supply-chain-attacks-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ci-cd-supply-chain-attacks-explained</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Secrets Management: A Lifecycle Guide for 2026]]></title>
      <description><![CDATA[A lifecycle approach to managing secrets across AWS, Azure, and GCP — storage, distribution, rotation, and detection — with Secrets Manager, Key Vault, Secret Manager, and CI/CD examples.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-secrets-management-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-secrets-management-guide</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Confluence Broken Access Control Zero-Day (CVE-2023-22515) Explained]]></title>
      <description><![CDATA[CVE-2023-22515 let unauthenticated attackers create rogue administrator accounts on Confluence Data Center and Server. Here's the broken-access-control flaw and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/confluence-cve-2023-22515-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/confluence-cve-2023-22515-explained</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Container Security Fundamentals]]></title>
      <description><![CDATA[Containers made shipping software faster, but every image is a stack of inherited software with its own attack surface. This guide covers the fundamentals: what a container really is, where the risks live, and the practices that keep images and runtimes safe.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-fundamentals</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVSS, EPSS, and KEV Explained: A Prioritization FAQ]]></title>
      <description><![CDATA[CVSS measures severity, EPSS estimates exploitation likelihood, and CISA KEV lists what is actively exploited. Here is how the three differ and how to use them together.]]></description>
      <link>https://safeguard.sh/resources/blog/cvss-epss-kev-explained-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cvss-epss-kev-explained-faq</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Dart and Flutter Security Best Practices: Storage, Transport, and the pub.dev Supply Chain]]></title>
      <description><![CDATA[A Flutter binary ships to both stores from one codebase — including any hardcoded secret, any disabled TLS check, and any vulnerable pub.dev package. Here is how to close each gap.]]></description>
      <link>https://safeguard.sh/resources/blog/dart-flutter-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dart-flutter-security-best-practices</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[The gosec Static Analysis Guide: Rules, CI, and Taming False Positives]]></title>
      <description><![CDATA[gosec catches hardcoded secrets, weak crypto, unsafe SQL, and command injection in Go — but only if you run it well and triage it honestly. A practical guide to the rules that matter and the noise that doesn't.]]></description>
      <link>https://safeguard.sh/resources/blog/gosec-static-analysis-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gosec-static-analysis-guide</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Choose a Security Scanner]]></title>
      <description><![CDATA[There are dozens of security scanners and the marketing all sounds the same. This beginner guide gives you a simple, hands-on way to pick the right one.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-choose-a-security-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-choose-a-security-scanner</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Remediate Transitive Dependency Vulnerabilities]]></title>
      <description><![CDATA[Fix vulnerabilities in the nested packages you never installed directly — trace the import chain, choose between upgrading the parent or overriding the child, and verify the fix without breaking builds.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-remediate-transitive-dependency-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-remediate-transitive-dependency-vulnerabilities</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 application security: the Annex A controls that govern your code]]></title>
      <description><![CDATA[ISO/IEC 27001:2022 added and sharpened Annex A controls for secure development and technical vulnerabilities. Here's how they apply to application and supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-application-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-application-security-guide</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Java Secrets Management: Getting Credentials Out of Your Code]]></title>
      <description><![CDATA[Hardcoded credentials are among the most common findings in Java codebases. Here's how to externalize, rotate, and protect secrets properly in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/java-secrets-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-secrets-management</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[JFrog Xray Alternatives in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced comparison of the top JFrog Xray alternatives in 2026 — Snyk, Sonatype, Mend, Trivy, Anchore, and Safeguard — with candid pros, cons, and a way to choose.]]></description>
      <link>https://safeguard.sh/resources/blog/jfrog-xray-alternatives-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jfrog-xray-alternatives-2026</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Admission Controllers for Security]]></title>
      <description><![CDATA[Admission controllers are the policy chokepoint between a validated API request and a running workload. Used well, they enforce your entire security posture. Here is how validating webhooks, Kyverno, OPA, and the new CEL-based policies fit together.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-admission-controllers-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-admission-controllers-security</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Supply Chain Security: Trusting What You Deploy]]></title>
      <description><![CDATA[The path from a git commit to a running pod crosses a dozen systems, each a place to inject malicious code. Here is how to build a chain of custody Kubernetes will actually verify.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-supply-chain-security</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Lessons from the ua-parser-js Compromise: Four Hours, Eight Million Downloads a Week]]></title>
      <description><![CDATA[A hijacked npm account turned a tiny User-Agent parser into a cryptominer and password stealer for a few hours in 2021. Here is what account takeover does at ecosystem scale.]]></description>
      <link>https://safeguard.sh/resources/blog/lessons-from-ua-parser-js-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lessons-from-ua-parser-js-compromise</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[NIST SSDF FAQ: SP 800-218, the Four Practice Groups, and Attestation]]></title>
      <description><![CDATA[A precise FAQ on the NIST Secure Software Development Framework in 2026 — the four practice groups, the CISA self-attestation form, EO 14028 lineage, the AI augmentation, and the evidence behind it.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-ssdf-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-ssdf-faq</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Node.js Docker Security Best Practices]]></title>
      <description><![CDATA[A Node.js container is only as secure as its base image, its user, and its dependency layer. This is a Dockerfile-by-Dockerfile walkthrough of hardening a Node app image — multi-stage builds, non-root, distroless, and layer hygiene.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-docker-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-docker-security-best-practices</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[OAuth 2.0 Security Best Practices (2026)]]></title>
      <description><![CDATA[OAuth 2.0 is safe when you follow the current security BCP and dangerous when you follow a decade-old tutorial. Here is what RFC 9700 requires in 2026: PKCE everywhere, exact redirect matching, and sender-constrained tokens.]]></description>
      <link>https://safeguard.sh/resources/blog/oauth-2-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oauth-2-security-best-practices</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Open Source License Comparison: MIT, Apache, BSD, GPL, and More]]></title>
      <description><![CDATA[A side-by-side comparison of the major open-source licenses — MIT, BSD, Apache 2.0, MPL, LGPL, GPL, and AGPL — across permissions, conditions, copyleft strength, and patent handling.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-license-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-license-comparison</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSL Punycode Overflow (CVE-2022-3602) Explained]]></title>
      <description><![CDATA[CVE-2022-3602 was pre-announced as OpenSSL's next critical bug, then downgraded to high. Here is what the X.509 punycode buffer overflow actually does, why the panic cooled, and how to patch.]]></description>
      <link>https://safeguard.sh/resources/blog/openssl-punycode-cve-2022-3602-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssl-punycode-cve-2022-3602-explained</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[OWASP A09: Security Logging and Monitoring Failures — A Deep-Dive Guide]]></title>
      <description><![CDATA[Security Logging and Monitoring Failures rank #9 in the OWASP Top 10 (2021). A deep dive into undetected breaches, dwell time, real incidents, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-a09-security-logging-and-monitoring-failures</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-a09-security-logging-and-monitoring-failures</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Secrets Management for Python Applications]]></title>
      <description><![CDATA[Hard-coded API keys and .env files committed to git are still the fastest route into a Python app. Here is how to keep secrets out of your code and your history.]]></description>
      <link>https://safeguard.sh/resources/blog/python-secrets-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-secrets-management</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[regreSSHion (CVE-2024-6387) Explained: A Signal-Handler Race That Reopened an Old OpenSSH RCE]]></title>
      <description><![CDATA[CVE-2024-6387, regreSSHion, is an unauthenticated remote code execution flaw in OpenSSH's sshd caused by a signal-handler race — a regression of a bug fixed back in 2006.]]></description>
      <link>https://safeguard.sh/resources/blog/regresshion-openssh-cve-2024-6387-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/regresshion-openssh-cve-2024-6387-explained</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Repojacking Explained: Hijacking Abandoned Repository Names]]></title>
      <description><![CDATA[Repojacking lets an attacker claim a renamed or deleted GitHub namespace and serve malicious code to everyone still referencing the old path. Here is how it works.]]></description>
      <link>https://safeguard.sh/resources/blog/repojacking-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/repojacking-explained</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Secrets Vault Comparison Guide (2026)]]></title>
      <description><![CDATA[A secrets manager is the difference between one rotation and a hundred. This guide compares HashiCorp Vault, AWS/Azure/GCP native stores, Doppler, and Infisical — and how to migrate off hardcoded secrets.]]></description>
      <link>https://safeguard.sh/resources/blog/secrets-vault-comparison-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secrets-vault-comparison-guide</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Securing AI-Generated Code FAQ: What Breaks and How to Fix It in 2026]]></title>
      <description><![CDATA[Practical answers on securing AI-generated code — the vulnerability patterns models produce, why volume defeats manual review, hallucinated dependencies, and how Safeguard scans and auto-fixes at merge time.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-ai-generated-code-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-ai-generated-code-faq</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[A Security Engineer Career Roadmap for 2026]]></title>
      <description><![CDATA[From your first junior role to senior specialist, here is a realistic security engineer career roadmap—the stages, the skills at each one, the specializations to choose between, and a mostly free path to get started.]]></description>
      <link>https://safeguard.sh/resources/blog/security-engineer-career-roadmap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-engineer-career-roadmap</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Career</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Security Regression Testing: Make Sure Fixed Vulnerabilities Stay Fixed]]></title>
      <description><![CDATA[A vulnerability you patched last quarter that quietly comes back this quarter is worse than one you never fixed — because you thought it was handled. Here is how to build security regression testing that keeps fixes fixed.]]></description>
      <link>https://safeguard.sh/resources/blog/security-regression-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-regression-testing</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Shift-Left Security: How to Implement It Without Breaking Developers]]></title>
      <description><![CDATA[Shift-left security fails when it just means 'more scanners earlier.' A 2026 implementation guide to moving security into the developer workflow with precision — IDE, pre-commit, PR, and pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/shift-left-security-implementation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shift-left-security-implementation</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Single-Page Application Security: Tokens, XSS, and the Public Bundle]]></title>
      <description><![CDATA[In an SPA, one XSS is game over and your entire bundle is public. Here's how token storage, CSP, OAuth PKCE, and CORS decide whether your SPA holds.]]></description>
      <link>https://safeguard.sh/resources/blog/single-page-application-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/single-page-application-security</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Slopsquatting: When AI Hallucinates a Package Attackers Register]]></title>
      <description><![CDATA[AI coding assistants confidently recommend packages that do not exist. Attackers noticed. Slopsquatting turns a model's hallucination into a supply-chain foothold — and the fix is not to make models stop hallucinating.]]></description>
      <link>https://safeguard.sh/resources/blog/slopsquatting-ai-hallucinated-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slopsquatting-ai-hallucinated-packages</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Defense]]></title>
      <description><![CDATA[CMMC 2.0, NIST SP 800-171, DFARS clauses, and the DoD's push toward SBOM-backed software authorization have raised the bar for the defense industrial base. Here is what contractors need, including in air-gapped enclaves.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-for-defense</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-for-defense</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Source Code Analysis Explained: A Practical 2026 Guide]]></title>
      <description><![CDATA[What source code analysis actually is in 2026 — the categories, the real tools, how it relates to SCA and reachability, and where Safeguard fits — explained honestly and without hype.]]></description>
      <link>https://safeguard.sh/resources/blog/source-code-analysis-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/source-code-analysis-explained</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Sovereign Cloud Security: FAQ]]></title>
      <description><![CDATA[What sovereign deployment means for software supply chain security: jurisdictional control, in-region operation, customer-held keys, foreign-access resistance, and honest limits.]]></description>
      <link>https://safeguard.sh/resources/blog/sovereign-cloud-security-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sovereign-cloud-security-faq</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SOX Compliance for Software: IT General Controls and the Supply Chain]]></title>
      <description><![CDATA[Sarbanes-Oxley is a financial-reporting law, but it reaches deep into the software that produces the numbers. Here's how IT general controls, change management, and dependency integrity fit under SOX.]]></description>
      <link>https://safeguard.sh/resources/blog/sox-compliance-for-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sox-compliance-for-software</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[tar (node-tar) Security Guide (2026)]]></title>
      <description><![CDATA[node-tar is the archive engine underneath npm install itself — and a cluster of path-traversal and symlink CVEs made 'just extracting a tarball' one of the more dangerous operations in the Node.js ecosystem.]]></description>
      <link>https://safeguard.sh/resources/blog/tar-npm-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tar-npm-security-guide</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Text4Shell (CVE-2022-42889) Explained: RCE in Apache Commons Text Interpolation]]></title>
      <description><![CDATA[CVE-2022-42889, Text4Shell, let attackers run code through Apache Commons Text's string interpolation when apps passed untrusted input to StringSubstitutor. Here is the flaw and why it was narrower than feared.]]></description>
      <link>https://safeguard.sh/resources/blog/text4shell-cve-2022-42889-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/text4shell-cve-2022-42889-explained</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Management for Beginners: From Alert Overload to Calm Control]]></title>
      <description><![CDATA[Scanners are good at finding problems. Vulnerability management is the calmer discipline of deciding which ones actually matter and fixing them in order. Here is a friendly guide with a first workflow to try today.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-management-for-beginners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-management-for-beginners</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What Is an AIBOM (AI Bill of Materials)? A 2026 Primer]]></title>
      <description><![CDATA[An SBOM tells you what code you ship. An AIBOM answers the question that has no good answer today: what models, datasets, and prompts is our AI actually built on — and where did they come from?]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-aibom-ai-bill-of-materials</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-aibom-ai-bill-of-materials</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What is CSRF (Cross-Site Request Forgery)?]]></title>
      <description><![CDATA[CSRF makes a logged-in user's browser perform actions they never intended — changing an email, moving money, granting access — using the victim's own session. Here's how it works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-csrf-cross-site-request-forgery</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-csrf-cross-site-request-forgery</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Package URL (purl)?]]></title>
      <description><![CDATA[A Package URL, or purl, is a standardized string that identifies a software package across any ecosystem. Here's how its structure works and why SBOMs and vulnerability feeds depend on it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-package-url-purl</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-package-url-purl</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is Privilege Escalation? A 2026 Explainer]]></title>
      <description><![CDATA[Privilege escalation is how a limited foothold becomes full control. This explainer covers vertical vs. horizontal paths across Linux, containers, and cloud IAM.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-privilege-escalation-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-privilege-escalation-explained</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What Is Reachability Analysis in Security?]]></title>
      <description><![CDATA[Reachability analysis determines whether a vulnerable piece of code can actually be executed from your application — cutting through the noise of vulnerabilities that exist but can never be triggered. Here's how it slashes false positives.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-reachability-analysis-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-reachability-analysis-security</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Wiz vs Prisma Cloud: A Neutral CNAPP Comparison for 2026]]></title>
      <description><![CDATA[Wiz and Prisma Cloud are leading cloud-native application protection platforms with different DNA — agentless graph versus a broad code-to-cloud suite. An honest side-by-side, plus where a third option fits.]]></description>
      <link>https://safeguard.sh/resources/blog/wiz-vs-prisma-cloud</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wiz-vs-prisma-cloud</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Auditing Yarn Dependencies: A Guide to yarn audit and yarn npm audit]]></title>
      <description><![CDATA[Yarn Classic and Yarn Berry audit dependencies differently. Learn the right commands for each, how to enforce overrides via resolutions, and where to go further.]]></description>
      <link>https://safeguard.sh/resources/blog/yarn-audit-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/yarn-audit-guide</guid>
      <pubDate>Tue, 07 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[A practical guide to bug bounty hunting]]></title>
      <description><![CDATA[HackerOne alone has paid hackers over $300M since 2012, but most new researchers earn nothing — duplicates, not skill gaps, are the top reason first reports fail.]]></description>
      <link>https://safeguard.sh/resources/blog/a-practical-guide-to-bug-bounty-hunting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/a-practical-guide-to-bug-bounty-hunting</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[An introduction to C and C++ memory-safety vulnerabilities]]></title>
      <description><![CDATA[Microsoft has reported that roughly 70% of the CVEs it patches each year trace back to memory-safety bugs — here's what buffer overflows, use-after-free, and double-free actually look like.]]></description>
      <link>https://safeguard.sh/resources/blog/an-introduction-to-c-and-cpp-memory-safety-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/an-introduction-to-c-and-cpp-memory-safety-vulnerabilities</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Anatomy of an npm Dependency Confusion Attack]]></title>
      <description><![CDATA[One researcher published fake packages matching internal names at over 35 companies in 2021 and collected six-figure bounties — here's exactly how the registry resolution flaw works.]]></description>
      <link>https://safeguard.sh/resources/blog/anatomy-of-an-npm-dependency-confusion-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anatomy-of-an-npm-dependency-confusion-attack</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Apache Struts and the recurring pattern of path-traversal and RCE bugs]]></title>
      <description><![CDATA[Equifax lost data on 147 million people to one unpatched Struts CVE in 2017 — and the same class of bug resurfaced in Struts as recently as December 2023.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-struts-path-traversal-vulnerabilities-a-recurring-pattern</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-struts-path-traversal-vulnerabilities-a-recurring-pattern</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Choosing a security tool for AI-generated code]]></title>
      <description><![CDATA[GitHub reported in 2024 that Copilot writes up to 46% of code in enabled files — the same vulnerability classes humans write, now shipped at machine speed.]]></description>
      <link>https://safeguard.sh/resources/blog/choosing-a-security-tool-for-ai-generated-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/choosing-a-security-tool-for-ai-generated-code</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Report AppSec Risk to Your CISO]]></title>
      <description><![CDATA[CVSS measures severity, not risk — and a slide of 4,000 raw findings tells a CISO nothing. Here's how to translate scan output into decisions.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-report-appsec-risk-to-your-ciso</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-report-appsec-risk-to-your-ciso</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-22195: how Jinja2's xmlattr filter opened an XSS hole]]></title>
      <description><![CDATA[A single filter in Jinja, xmlattr, could inject arbitrary HTML attributes and slip past autoescaping entirely — fixed in Jinja 3.1.3, tracked as CVE-2024-22195.]]></description>
      <link>https://safeguard.sh/resources/blog/jinja2-xss-cve-2024-22195-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jinja2-xss-cve-2024-22195-explained</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Managing Open Source Component Risk at Scale]]></title>
      <description><![CDATA[A modern app's dozen direct dependencies can resolve into thousands of transitive packages — and CVE-2024-3094 proved a single unmaintained one is enough to backdoor SSH itself.]]></description>
      <link>https://safeguard.sh/resources/blog/managing-open-source-component-risk-at-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/managing-open-source-component-risk-at-scale</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Native-extension vulnerabilities in Python packages]]></title>
      <description><![CDATA[numpy, pandas, cryptography, and lxml all ship compiled C/C++ code — and a Python SCA scan that only checks package versions can miss memory-safety bugs buried in that native layer.]]></description>
      <link>https://safeguard.sh/resources/blog/native-extension-vulnerabilities-in-python-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/native-extension-vulnerabilities-in-python-packages</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[PHP Laravel security best practices]]></title>
      <description><![CDATA[One line, `protected $guarded = [];`, can turn a Laravel signup form into an admin-account minting machine — here's how to lock down five real Laravel risk areas.]]></description>
      <link>https://safeguard.sh/resources/blog/php-laravel-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-laravel-security-best-practices</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Preventing SQL injection in Node.js applications]]></title>
      <description><![CDATA[CWE-89 is a 25-year-old bug class, but Node's template literals make it trivially easy to reintroduce in mysql2, pg, and even Sequelize's raw-query escape hatch.]]></description>
      <link>https://safeguard.sh/resources/blog/preventing-sql-injection-in-nodejs-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preventing-sql-injection-in-nodejs-applications</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Preventing SSRF in Node.js applications]]></title>
      <description><![CDATA[A single unvalidated URL in a fetch or axios call can let an attacker reach 169.254.169.254 and steal cloud credentials — as the 2019 Capital One breach showed.]]></description>
      <link>https://safeguard.sh/resources/blog/preventing-ssrf-in-nodejs-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preventing-ssrf-in-nodejs-applications</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Reducing Docker image build time without sacrificing security]]></title>
      <description><![CDATA[Multi-stage builds and minimal base images can cut CI build times dramatically — and they're the same changes that shrink your CVE attack surface.]]></description>
      <link>https://safeguard.sh/resources/blog/reducing-docker-image-build-time-without-sacrificing-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reducing-docker-image-build-time-without-sacrificing-security</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing Python Virtual Environments]]></title>
      <description><![CDATA[A single sudo pip install can overwrite files an OS package manager owns — PEP 668 exists because that anti-pattern was common enough to break Linux distros.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-python-virtual-environments</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-python-virtual-environments</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Software Composition Analysis Best Practices for Engineering Teams]]></title>
      <description><![CDATA[CVE-2017-5638 was patched by Apache in March 2017, two months before Equifax was breached through it. Point-in-time SCA scans miss exactly this kind of drift.]]></description>
      <link>https://safeguard.sh/resources/blog/software-composition-analysis-best-practices-for-engineering-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-composition-analysis-best-practices-for-engineering-teams</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Python pickle security model, explained]]></title>
      <description><![CDATA[Python's own docs warn that unpickling can execute arbitrary code — yet pickle is still the default weight format behind millions of ML model downloads.]]></description>
      <link>https://safeguard.sh/resources/blog/the-python-pickle-security-model-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-python-pickle-security-model-explained</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why You Need a Kubernetes Admission Controller]]></title>
      <description><![CDATA[RBAC decides who can call the Kubernetes API — it has no concept of what a pod spec contains, which is why privileged containers still slip through into clusters every day.]]></description>
      <link>https://safeguard.sh/resources/blog/why-you-need-a-kubernetes-admission-controller</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-you-need-a-kubernetes-admission-controller</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Personal Access Token Security Best Practices]]></title>
      <description><![CDATA[Leaked personal access tokens have driven major supply chain breaches. Here's why PATs are risky, real incidents, and how scoping, rotation, and detection fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/personal-access-token-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/personal-access-token-security-best-practices</guid>
      <pubDate>Tue, 07 Jul 2026 08:49:30 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Hardcoded Secrets in Source Code: Detection and Remediation]]></title>
      <description><![CDATA[Hardcoded secrets in source code caused breaches at Toyota, Uber, and Samsung. Here's why developers keep doing it, how attackers exploit it, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/hardcoded-secrets-in-source-code-detection-and-remediation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hardcoded-secrets-in-source-code-detection-and-remediation</guid>
      <pubDate>Tue, 07 Jul 2026 07:29:03 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[A dormant contributor account just took down the entire Mastra npm scope]]></title>
      <description><![CDATA[One forgotten npm maintainer account let an attacker republish all 142 packages in the @mastra scope in 90 minutes, hitting a package with 4 million monthly downloads.]]></description>
      <link>https://safeguard.sh/resources/blog/forgotten-contributor-accounts-npm-scope-takeover-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/forgotten-contributor-accounts-npm-scope-takeover-risk</guid>
      <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Foundations for adopting AI coding tools securely in an engineering org]]></title>
      <description><![CDATA[One engineering team cut critical vulnerability remediation from a week to 24 hours after wiring security checks into AI coding tools at the moment of code generation.]]></description>
      <link>https://safeguard.sh/resources/blog/foundations-for-adopting-ai-coding-tools-securely-in-an-engineering-org</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/foundations-for-adopting-ai-coding-tools-securely-in-an-engineering-org</guid>
      <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Governing AI agents inside the execution loop]]></title>
      <description><![CDATA[Snyk's Evo Agentic Development Security, in open preview since June 23, 2026, hooks directly into an agent's tool calls — proof that pre-deployment review can't govern a decision made mid-session.]]></description>
      <link>https://safeguard.sh/resources/blog/governing-ai-agents-inside-the-execution-loop</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/governing-ai-agents-inside-the-execution-loop</guid>
      <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How the security industry is scaling partnerships for AI risk]]></title>
      <description><![CDATA[No vendor covers model security, agent runtime policy, supply-chain risk, and code-level AppSec alone — partner-sourced ARR at one major vendor grew over 6x from 2023 to 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/how-the-security-industry-is-scaling-partnerships-for-ai-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-the-security-industry-is-scaling-partnerships-for-ai-risk</guid>
      <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to build and justify an AI security budget]]></title>
      <description><![CDATA[CVE-2025-6514 let a flawed MCP proxy escalate to full remote code execution — a preview of why AI/agentic risk needs its own budget line, not a slice of the AppSec line.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-build-and-justify-an-ai-security-budget</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-build-and-justify-an-ai-security-budget</guid>
      <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Can an LLM find the same bug twice? What repeatability benchmarking reveals]]></title>
      <description><![CDATA[In a 300-run benchmark, the best LLM scanner hit 75.4% F1 while a deterministic SAST baseline hit 100% — but the real story is in what varies between runs.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-code-review-repeatability-vulnerability-benchmarking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-code-review-repeatability-vulnerability-benchmarking</guid>
      <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Malicious code in scoped npm packages: what the Miasma attack teaches]]></title>
      <description><![CDATA[32 releases under the trusted @redhat-cloud-services npm scope shipped credential-stealing malware in June 2026 — with valid SLSA provenance attached.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-code-in-scoped-npm-packages-what-the-miasma-attack-teaches</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-code-in-scoped-npm-packages-what-the-miasma-attack-teaches</guid>
      <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[New security risks across the agentic development lifecycle]]></title>
      <description><![CDATA[Snyk found 76 confirmed-malicious skills among 3,984 analyzed and roughly a third of public MCP servers carrying exploitable flaws — legacy AppSec never modeled an agent as the author.]]></description>
      <link>https://safeguard.sh/resources/blog/new-security-risks-across-the-agentic-development-lifecycle</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/new-security-risks-across-the-agentic-development-lifecycle</guid>
      <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Protestware via prompt injection: when maintainers target AI agents]]></title>
      <description><![CDATA[jqwik 1.10.0 shipped a hidden instruction telling AI coding agents to delete their own tests, then erased it from the terminal with ANSI codes — protestware built for agents, not humans.]]></description>
      <link>https://safeguard.sh/resources/blog/protestware-via-prompt-injection-when-maintainers-target-ai-agents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/protestware-via-prompt-injection-when-maintainers-target-ai-agents</guid>
      <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing MCP integrations for enterprise AI assistants]]></title>
      <description><![CDATA[Claude's May 2026 enterprise and desktop expansion put MCP tool calls in front of compliance teams and IDEs alike — governance can no longer be an afterthought.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-mcp-integrations-for-enterprise-ai-assistants</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-mcp-integrations-for-enterprise-ai-assistants</guid>
      <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Should open source maintainers get free enterprise security tooling?]]></title>
      <description><![CDATA[80-90% of the average codebase is open source, built largely by unpaid maintainers — Snyk's year-old maintainer program now covers 60+ projects for free.]]></description>
      <link>https://safeguard.sh/resources/blog/should-open-source-maintainers-get-free-enterprise-security-tooling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/should-open-source-maintainers-get-free-enterprise-security-tooling</guid>
      <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What a good AI remediation agent needs to fix dependencies safely]]></title>
      <description><![CDATA[Snyk's CLI remediation agent pushed fix rates from 23% to 45% with an intelligence layer — but the harder problem is making an agent developers trust to touch their lockfile unsupervised.]]></description>
      <link>https://safeguard.sh/resources/blog/what-a-good-ai-remediation-agent-needs-to-fix-dependencies-safely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-a-good-ai-remediation-agent-needs-to-fix-dependencies-safely</guid>
      <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What agentic coding environments reveal about developer risk]]></title>
      <description><![CDATA[Snyk analyzed nearly 10,000 real developer environments and found 43% run 2+ AI coding tools at once — with MCP servers and skills quietly widening the attack surface.]]></description>
      <link>https://safeguard.sh/resources/blog/what-agentic-coding-environments-reveal-about-developer-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-agentic-coding-environments-reveal-about-developer-risk</guid>
      <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why NVD alone is not enough: the case for multi-source vulnerability intelligence]]></title>
      <description><![CDATA[NIST now fully enriches a fraction of CVEs — on April 15, 2026 it moved to a triage model that leaves most of 2025's 48,185 published CVEs without a timely severity score.]]></description>
      <link>https://safeguard.sh/resources/blog/why-nvd-alone-is-not-enough-multi-source-vulnerability-intelligence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-nvd-alone-is-not-enough-multi-source-vulnerability-intelligence</guid>
      <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Insecure Hash Algorithm Usage in Application Code]]></title>
      <description><![CDATA[MD5 and SHA-1 collisions were proven broken decades ago, yet they still power passwords, checksums, and signatures in production code today. Here's why—and how to find them.]]></description>
      <link>https://safeguard.sh/resources/blog/insecure-hash-algorithm-usage-in-application-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insecure-hash-algorithm-usage-in-application-code</guid>
      <pubDate>Tue, 07 Jul 2026 06:08:36 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Insecure Randomness in Security-Sensitive Code]]></title>
      <description><![CDATA[A single deleted line broke Debian's OpenSSL keys for two years. We break down real insecure randomness vulnerabilities and how Safeguard catches weak PRNGs before attackers do.]]></description>
      <link>https://safeguard.sh/resources/blog/insecure-randomness-in-security-sensitive-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insecure-randomness-in-security-sensitive-code</guid>
      <pubDate>Tue, 07 Jul 2026 04:48:10 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Missing Encryption of Sensitive Data]]></title>
      <description><![CDATA[Missing encryption of sensitive data (CWE-311) drove breaches from Equifax to CVS Health. Here's how it happens across the software supply chain and how to catch it early.]]></description>
      <link>https://safeguard.sh/resources/blog/missing-encryption-of-sensitive-data</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/missing-encryption-of-sensitive-data</guid>
      <pubDate>Tue, 07 Jul 2026 03:27:43 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CometJacking and the AI Browser Agent Threat Model]]></title>
      <description><![CDATA[LayerX's October 2025 CometJacking attack siphoned Gmail and Calendar via one Perplexity Comet click. The browser-as-agent design is the new blast radius.]]></description>
      <link>https://safeguard.sh/resources/blog/perplexity-comet-cometjacking-browser-agent</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/perplexity-comet-cometjacking-browser-agent</guid>
      <pubDate>Tue, 07 Jul 2026 02:07:16 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Anubhav Verma)</author>
    </item>
    <item>
      <title><![CDATA[Semgrep Community Fall 2025: Native Windows and 3x Multicore]]></title>
      <description><![CDATA[Semgrep's Fall 2025 Community Edition ships native Windows binaries, a memory-efficient multicore engine, and up to 3x scan speedups. We benchmarked it.]]></description>
      <link>https://safeguard.sh/resources/blog/semgrep-fall-2025-community-windows-multicore</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/semgrep-fall-2025-community-windows-multicore</guid>
      <pubDate>Tue, 07 Jul 2026 00:46:50 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Aisha Iqbal)</author>
    </item>
    <item>
      <title><![CDATA[The Complete Guide to Dependency Lifecycle Management]]></title>
      <description><![CDATA[Dependencies are not static. They are born, maintained, deprecated, and abandoned. Here is how to manage the full lifecycle of your software dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-lifecycle-management-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-lifecycle-management-guide</guid>
      <pubDate>Mon, 06 Jul 2026 23:26:23 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Cleartext Sensitive Information in Cookies]]></title>
      <description><![CDATA[Cleartext sensitive data in cookies (CWE-315) quietly enables account takeover and IDOR. Here's how it happens, why it survives review, and how Safeguard catches it.]]></description>
      <link>https://safeguard.sh/resources/blog/cleartext-sensitive-information-in-cookies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cleartext-sensitive-information-in-cookies</guid>
      <pubDate>Mon, 06 Jul 2026 22:05:56 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[bcrypt on npm: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[The bcrypt npm package is a solid password-hashing choice, but its 72-byte input limit and native build story create footguns worth understanding before you ship.]]></description>
      <link>https://safeguard.sh/resources/blog/bcrypt-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bcrypt-npm</guid>
      <pubDate>Mon, 06 Jul 2026 20:45:30 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Post-Quantum Cryptography Migration for Application Security]]></title>
      <description><![CDATA[NIST finalized PQC standards in 2024, but most companies can't even inventory where RSA and ECC live in their stack. Here's a realistic migration roadmap for AppSec teams.]]></description>
      <link>https://safeguard.sh/resources/blog/post-quantum-cryptography-migration-for-application-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/post-quantum-cryptography-migration-for-application-security</guid>
      <pubDate>Mon, 06 Jul 2026 19:25:03 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Unrestricted File Upload Vulnerabilities]]></title>
      <description><![CDATA[Unrestricted file upload flaws let attackers turn a simple upload form into remote code execution. Here's how real-world CVEs happened, and how to prevent them.]]></description>
      <link>https://safeguard.sh/resources/blog/unrestricted-file-upload-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unrestricted-file-upload-vulnerabilities</guid>
      <pubDate>Mon, 06 Jul 2026 18:04:36 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Insecure Temporary File Creation]]></title>
      <description><![CDATA[Insecure temp file creation (CWE-377) still causes real CVEs today — from JUnit4 to npm's tmp package. Here's how the race condition works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/insecure-temporary-file-creation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insecure-temporary-file-creation</guid>
      <pubDate>Mon, 06 Jul 2026 16:44:09 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Race Conditions (TOCTOU) in Application Code]]></title>
      <description><![CDATA[From Dirty COW to runc's CVE-2021-30465, TOCTOU race conditions keep slipping past code review. Here's why they're invisible to standard tooling — and how to catch them.]]></description>
      <link>https://safeguard.sh/resources/blog/race-conditions-toctou-in-application-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/race-conditions-toctou-in-application-code</guid>
      <pubDate>Mon, 06 Jul 2026 15:23:43 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Sensitive Information Exposure in Error Messages]]></title>
      <description><![CDATA[Stack traces, SQL errors, and debug pages routinely leak credentials, paths, and library versions to attackers. Here's how CWE-209 exposure happens and how to close it.]]></description>
      <link>https://safeguard.sh/resources/blog/sensitive-information-exposure-in-error-messages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sensitive-information-exposure-in-error-messages</guid>
      <pubDate>Mon, 06 Jul 2026 14:03:16 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Expands Into a Unified, AI-Native Defensive Security Platform]]></title>
      <description><![CDATA[Safeguard is growing from a posture and findings platform into a first-party detection and prevention platform — first-party AppSec, defensive red-teaming, AI security, data security, runtime/CNAPP, and a supply-chain package firewall — all feeding one prioritized findings model.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-expands-into-a-unified-defensive-security-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-expands-into-a-unified-defensive-security-platform</guid>
      <pubDate>Mon, 06 Jul 2026 14:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Logging Vulnerabilities: Log Injection and Sensitive Data...]]></title>
      <description><![CDATA[Log4Shell, plaintext password logs, and CRLF injection show how logging vulnerabilities turn debug output into a full-blown breach vector for attackers.]]></description>
      <link>https://safeguard.sh/resources/blog/logging-vulnerabilities-log-injection-and-sensitive-data-exposure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/logging-vulnerabilities-log-injection-and-sensitive-data-exposure</guid>
      <pubDate>Mon, 06 Jul 2026 12:42:49 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Insecure Default Configurations in Applications and Frame...]]></title>
      <description><![CDATA[Insecure default configurations caused the 2016 MongoDB ransom wave, the 2018 Tesla Kubernetes breach, and countless audit failures. Here's why defaults stay dangerous and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/insecure-default-configurations-in-applications-and-frameworks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insecure-default-configurations-in-applications-and-frameworks</guid>
      <pubDate>Mon, 06 Jul 2026 11:22:23 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[DHS Software Assurance Guidance: A Review]]></title>
      <description><![CDATA[CISA and DHS's October 2025 software assurance guidance refines federal expectations on SBOMs, attestation, and secure-by-design, and signals what is next.]]></description>
      <link>https://safeguard.sh/resources/blog/dhs-software-assurance-guidance-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dhs-software-assurance-guidance-2025</guid>
      <pubDate>Mon, 06 Jul 2026 10:01:56 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Agentic AI Security FAQ: Governing Autonomous AI in 2026]]></title>
      <description><![CDATA[Clear answers on securing agentic AI — what makes autonomy risky, how tool scope and identity work, prompt injection and confused-deputy failures, and how Safeguard governs agents that act on your systems.]]></description>
      <link>https://safeguard.sh/resources/blog/agentic-ai-security-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agentic-ai-security-faq</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[AI Security Remediation FAQ: How AI-Authored Fixes Are Kept Trustworthy]]></title>
      <description><![CDATA[How an AI can be trusted to fix security vulnerabilities — the role of reachability, validation, and human review in keeping AI-authored remediation accurate and safe.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-remediation-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-remediation-faq</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[AI Supply Chain Security: Securing Models and Datasets]]></title>
      <description><![CDATA[Your AI supply chain is not just your npm dependencies anymore. It is the models you download, the weights you load, and the datasets you train on — and each is an attack surface most software security programs have never inventoried.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-supply-chain-security-models-datasets</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-supply-chain-security-models-datasets</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Best License Compliance Tools in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced 2026 comparison of the leading open-source license compliance tools — FOSSA, Black Duck, Mend, Snyk, and the ScanCode/FOSSology open-source stack — with an honest look at where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/best-license-compliance-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-license-compliance-tools-2026</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Auditing RubyGems Dependencies with bundler-audit]]></title>
      <description><![CDATA[bundler-audit checks your Gemfile.lock against the ruby-advisory-db and flags insecure gem sources. Here is how to run it in Ruby and Rails projects — and beyond.]]></description>
      <link>https://safeguard.sh/resources/blog/bundler-audit-rubygems</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bundler-audit-rubygems</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Citrix Bleed (CVE-2023-4966) Explained: Leaking Session Tokens Straight Past MFA]]></title>
      <description><![CDATA[CVE-2023-4966, Citrix Bleed, let unauthenticated attackers read memory from NetScaler appliances and steal valid session tokens — hijacking sessions and bypassing multi-factor authentication.]]></description>
      <link>https://safeguard.sh/resources/blog/citrix-bleed-cve-2023-4966-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/citrix-bleed-cve-2023-4966-explained</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Security Deployment: FAQ]]></title>
      <description><![CDATA[How the multi-tenant and dedicated-VPC cloud deployments work: tenant isolation, data handling, key ownership, latency, and when cloud is the right choice versus self-hosting.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-security-deployment-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-security-deployment-faq</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Comparing Supply Chain Security Platforms (2026): An Honest FAQ]]></title>
      <description><![CDATA[A vendor-neutral 2026 FAQ on comparing software supply chain security platforms — the dimensions that matter, how the major players differ, and how to run a fair bake-off.]]></description>
      <link>https://safeguard.sh/resources/blog/comparing-supply-chain-security-platforms-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/comparing-supply-chain-security-platforms-faq</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Cookie Security Best Practices (2026)]]></title>
      <description><![CDATA[Session cookies are the keys to your users' accounts. Here is how to set them so they cannot be stolen, forged, or leaked: the flags, the prefixes, and the parsing pitfalls.]]></description>
      <link>https://safeguard.sh/resources/blog/cookie-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cookie-security-best-practices</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Data Flow Diagrams for Threat Modeling]]></title>
      <description><![CDATA[A data flow diagram maps how data moves through a system and where trust changes — the foundation most threat modeling is built on. Here's how to draw one that actually surfaces threats.]]></description>
      <link>https://safeguard.sh/resources/blog/data-flow-diagrams-for-threat-modeling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/data-flow-diagrams-for-threat-modeling</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Detecting Hardcoded Secrets in Code (2026 Guide)]]></title>
      <description><![CDATA[Nearly 24 million secrets leaked to public GitHub in 2024 alone. This guide covers how hardcoded secrets get in, how detection actually works, and how to catch them pre-commit with real commands.]]></description>
      <link>https://safeguard.sh/resources/blog/detecting-hardcoded-secrets-in-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/detecting-hardcoded-secrets-in-code</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps for Beginners: Building Security Into How You Ship]]></title>
      <description><![CDATA[DevSecOps sounds like a buzzword, but the idea is refreshingly human: make security a shared, everyday part of building software rather than a gate at the end. Here is a friendly introduction with a first step to try today.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-for-beginners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-for-beginners</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Dirty Pipe (CVE-2022-0847) Explained: Overwriting Read-Only Files in the Linux Kernel]]></title>
      <description><![CDATA[CVE-2022-0847, Dirty Pipe, let unprivileged users overwrite data in read-only files through an uninitialized pipe flag — a clean path to root. Here is the page-cache mechanism behind it.]]></description>
      <link>https://safeguard.sh/resources/blog/dirty-pipe-cve-2022-0847-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dirty-pipe-cve-2022-0847-explained</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Docker Secrets Management: Stop Baking Credentials Into Images]]></title>
      <description><![CDATA[A secret written into a Docker layer is recoverable forever, even after you delete it. Learn the build-time and runtime patterns that keep credentials out of your images entirely.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-secrets-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-secrets-management</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[.NET Secrets Management: From User Secrets to Key Vault]]></title>
      <description><![CDATA[How to keep connection strings, API keys, and certificates out of your .NET source and images, using the Secret Manager, environment configuration, managed identities, and a real vault.]]></description>
      <link>https://safeguard.sh/resources/blog/dotnet-secrets-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dotnet-secrets-management</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Elixir and Phoenix Security Best Practices: BEAM Footguns and the Hex Supply Chain]]></title>
      <description><![CDATA[Phoenix is safe by default, but the BEAM has its own footguns — binary_to_term, atom exhaustion, dynamic eval — and the Erlang/OTP runtime beneath it shipped a CVSS 10.0 pre-auth SSH RCE in 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/elixir-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/elixir-security-best-practices</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[F5 BIG-IP CVE-2022-1388 Explained: The iControl REST Authentication Bypass]]></title>
      <description><![CDATA[CVE-2022-1388 is an authentication bypass in the F5 BIG-IP iControl REST interface that leads to unauthenticated remote code execution, rated CVSS 9.8. Here is the timeline, root cause, and patched versions.]]></description>
      <link>https://safeguard.sh/resources/blog/f5-big-ip-cve-2022-1388-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/f5-big-ip-cve-2022-1388-explained</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[False Positives in Security Scanning FAQ]]></title>
      <description><![CDATA[Why security scanners produce so many false positives, what actually counts as one, and how reachability analysis and context reduce the noise. A practical FAQ.]]></description>
      <link>https://safeguard.sh/resources/blog/false-positives-in-security-scanning-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/false-positives-in-security-scanning-faq</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Go Dependency Management Security: go.mod Hygiene That Actually Reduces Risk]]></title>
      <description><![CDATA[Minimal version selection, indirect dependencies, replace directives, and the update cadence nobody documents. A practical guide to keeping your Go dependency graph both current and trustworthy.]]></description>
      <link>https://safeguard.sh/resources/blog/go-dependency-management-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-dependency-management-security</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Become a DevSecOps Engineer in 2026]]></title>
      <description><![CDATA[The DevSecOps engineer role blends development, operations, and security into one high-demand job. Here is what it involves, what it pays attention to, and a practical, mostly free path to landing one.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-become-a-devsecops-engineer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-become-a-devsecops-engineer</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Career</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Secure Your Open Source Dependencies]]></title>
      <description><![CDATA[Most of your code is code you didn't write. This beginner guide covers the practical habits that keep your open-source dependencies safe, from lockfiles to scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-secure-your-open-source-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-secure-your-open-source-dependencies</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Set Up a Vulnerability Policy Gate]]></title>
      <description><![CDATA[Define a written, version-controlled policy for which vulnerabilities block a release, enforce it consistently across CLI and CI, and manage time-boxed exceptions without an allowlist that lives forever.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-a-vulnerability-policy-gate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-a-vulnerability-policy-gate</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Image Signing with Cosign and Sigstore]]></title>
      <description><![CDATA[A container image tag proves nothing about who built the image or whether it was tampered with. Cosign and Sigstore fix that with cryptographic signatures and a public transparency log — here is how to sign, verify, and enforce.]]></description>
      <link>https://safeguard.sh/resources/blog/image-signing-with-cosign-sigstore</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/image-signing-with-cosign-sigstore</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Infrastructure Drift Detection: A Practical Guide for 2026]]></title>
      <description><![CDATA[When running infrastructure diverges from your Terraform, your security scans start auditing a fiction. Here's how to detect, understand, and reconcile configuration drift.]]></description>
      <link>https://safeguard.sh/resources/blog/infrastructure-drift-detection-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/infrastructure-drift-detection-guide</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Dependency Vulnerability Scanning: Beyond npm audit]]></title>
      <description><![CDATA[npm audit tells you a CVE exists somewhere in your tree — not whether it can hurt you. Here is how dependency scanning really works, why reachability changes everything, and how to build a signal-rich program.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-dependency-vulnerability-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-dependency-vulnerability-scanning</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Jenkins CLI Arbitrary File Read (CVE-2024-23897) Explained]]></title>
      <description><![CDATA[CVE-2024-23897 turned a convenience feature in Jenkins' CLI argument parser into an arbitrary file read that can escalate to full RCE. Here's the mechanism and the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-cve-2024-23897-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-cve-2024-23897-explained</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[JVM Supply Chain Security: Securing the Path from Source to Artifact]]></title>
      <description><![CDATA[Your JVM supply chain spans repositories, build tools, plugins, and artifacts. Here's how to secure each link — from dependency confusion to artifact signing.]]></description>
      <link>https://safeguard.sh/resources/blog/jvm-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jvm-supply-chain-security</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Securing Managed Kubernetes: EKS, AKS, and GKE Compared]]></title>
      <description><![CDATA[A cross-cloud guide to hardening managed Kubernetes — the shared responsibility line, cloud IAM-to-pod integration, network policy, Pod Security Standards, and node hardening across EKS, AKS, and GKE.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-managed-service-security-eks-aks-gke</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-managed-service-security-eks-aks-gke</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Lessons from event-stream: How a Free Handoff Became a Bitcoin Heist]]></title>
      <description><![CDATA[A volunteer handed control of a hugely popular npm package to a stranger, who used it to target one Bitcoin wallet app. The event-stream incident is the case study in maintainer-handoff risk.]]></description>
      <link>https://safeguard.sh/resources/blog/lessons-from-event-stream-npm-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lessons-from-event-stream-npm-attack</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Minimal Base Images for Security: A Practical Guide]]></title>
      <description><![CDATA[Minimal base images cut CVE counts by up to 95% by shipping only what your app needs. Here is how to choose between distroless, Wolfi, Alpine, and scratch — and build on each safely.]]></description>
      <link>https://safeguard.sh/resources/blog/minimal-base-images-for-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/minimal-base-images-for-security</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[npm typosquatting attacks]]></title>
      <description><![CDATA[npm typosquatting turns a single mistyped `npm install` into a live compromise. Real incidents, attack patterns, and defenses that actually catch it.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-typosquatting-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-typosquatting-attacks</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[OWASP A08: Software and Data Integrity Failures — A Deep-Dive Guide]]></title>
      <description><![CDATA[Software and Data Integrity Failures rank #8 in the OWASP Top 10 (2021). A deep dive into insecure deserialization, unsigned updates, SolarWinds, and real CVEs.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-a08-software-and-data-integrity-failures</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-a08-software-and-data-integrity-failures</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Path Traversal Vulnerability Prevention, Explained]]></title>
      <description><![CDATA[One unvalidated filename and `../../../etc/passwd` reads files you never meant to expose — or worse, executes them. Here's how path traversal works and how to build file access that can't be tricked.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-vulnerability-prevention-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-vulnerability-prevention-explained</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Pre-Commit Security Hooks: Catch Problems Before They're Committed]]></title>
      <description><![CDATA[The cheapest place to catch a security issue is before the commit exists. Here is how to set up pre-commit security hooks that give developers instant feedback without slowing them down.]]></description>
      <link>https://safeguard.sh/resources/blog/pre-commit-security-hooks-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pre-commit-security-hooks-guide</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Race Condition Vulnerabilities Explained]]></title>
      <description><![CDATA[A race condition is a timing flaw where two operations that should happen in order overlap instead — enabling double-spends, TOCTOU bypasses, and kernel exploits.]]></description>
      <link>https://safeguard.sh/resources/blog/race-condition-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/race-condition-vulnerabilities</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Red Team vs Blue Team: What's the Difference?]]></title>
      <description><![CDATA[The red team plays the attacker, probing for ways in. The blue team plays the defender, detecting and stopping them. One breaks; the other protects.]]></description>
      <link>https://safeguard.sh/resources/blog/red-team-vs-blue-team</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/red-team-vs-blue-team</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[REST API Security Best Practices: The OWASP API Top 10 in Practice]]></title>
      <description><![CDATA[Most API breaches aren't exotic — they're broken object-level authorization and missing rate limits. A practical walk through the OWASP API Security Top 10.]]></description>
      <link>https://safeguard.sh/resources/blog/rest-api-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rest-api-security-best-practices</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Securing CI/CD Secrets: OIDC, Scanning, and Short-Lived Credentials]]></title>
      <description><![CDATA[CI/CD secrets are the crown jewels attackers go after — the CircleCI breach forced every customer to rotate everything. This guide covers secret sprawl, scanning, OIDC federation, and killing long-lived credentials for good.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-ci-cd-secrets</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-ci-cd-secrets</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Securing Your Python Supply Chain on PyPI]]></title>
      <description><![CDATA[Typosquats, dependency confusion, and account takeovers all target the same moment: pip install. Here is how to make that moment trustworthy.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-python-pypi-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-python-pypi-packages</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[semver (npm) Security Guide (2026)]]></title>
      <description><![CDATA[semver is the version-parsing library at the heart of npm itself — and a single ReDoS CVE in its range parser turned this universal dependency into one of the most widely flagged advisories in the JavaScript ecosystem.]]></description>
      <link>https://safeguard.sh/resources/blog/semver-npm-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/semver-npm-security-guide</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 and software supply chain security: mapping the Trust Services Criteria]]></title>
      <description><![CDATA[SOC 2 never says the words 'software bill of materials,' but auditors increasingly expect supply-chain evidence. Here's how the Trust Services Criteria map to your dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-software-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-software-supply-chain-security</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Automotive]]></title>
      <description><![CDATA[UNECE R155 and R156, ISO/SAE 21434, and OEM SBOM flow-down have made the software supply chain a type-approval issue for vehicles. Here is what OEMs and suppliers need to build into their programs.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-for-automotive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-for-automotive</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Sonatype Nexus Alternatives in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced comparison of the leading Sonatype Nexus alternatives in 2026 — JFrog, Snyk, Mend, Black Duck, Cloudsmith, and Safeguard — with candid pros, cons, and a framework for choosing.]]></description>
      <link>https://safeguard.sh/resources/blog/sonatype-nexus-alternatives-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonatype-nexus-alternatives-2026</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Spring Framework Security Guide (2026)]]></title>
      <description><![CDATA[Spring Framework is the backbone of enterprise Java — and the source of Spring4Shell plus a steady stream of path-traversal and SSRF CVEs. Here is how to run it safely in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-framework-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-framework-security-guide</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Threat Modeling for Developers: A Lightweight Practical Guide]]></title>
      <description><![CDATA[Threat modeling doesn't need a two-day workshop. A developer-friendly 2026 guide to modeling threats with the four-question framework and STRIDE — fast enough to run on a feature branch.]]></description>
      <link>https://safeguard.sh/resources/blog/threat-modeling-guide-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/threat-modeling-guide-for-developers</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Top SAST Auto-Fixing Tools in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced 2026 comparison of SAST tools that auto-fix findings — GitHub Copilot Autofix, Semgrep, Snyk, SonarQube, Mobb, Pixee — with honest tradeoffs and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/top-sast-auto-fixing-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-sast-auto-fixing-tools</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Transitive Dependency Risk Explained: The Code You Never Chose]]></title>
      <description><![CDATA[Transitive dependencies are the packages your dependencies pull in, and they make up most of your codebase. Here is why they are risky and how to manage them.]]></description>
      <link>https://safeguard.sh/resources/blog/transitive-dependency-risk-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/transitive-dependency-risk-explained</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Trivy vs Grype: A Neutral Open-Source Scanner Comparison for 2026]]></title>
      <description><![CDATA[Trivy and Grype are both free, open-source vulnerability scanners loved by engineers, but they differ in scope and philosophy. An honest side-by-side, plus where a managed third option fits.]]></description>
      <link>https://safeguard.sh/resources/blog/trivy-vs-grype</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trivy-vs-grype</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Understanding Open Source Security Risk]]></title>
      <description><![CDATA[Open source powers nearly every modern application, but the code you inherit brings risks you did not write. This guide explains where open source risk comes from, how it reaches your product, and how to manage it without abandoning the ecosystem.]]></description>
      <link>https://safeguard.sh/resources/blog/understanding-open-source-security-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/understanding-open-source-security-risk</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[VMware vCenter (CVE-2021-21985) Explained: The vSAN Plugin RCE]]></title>
      <description><![CDATA[CVE-2021-21985 is a CVSS 9.8 unauthenticated RCE in VMware vCenter Server's vSAN Health plugin, enabled by default on every install. Here is how it works and the patched builds to run.]]></description>
      <link>https://safeguard.sh/resources/blog/vmware-vcenter-cve-2021-21985-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vmware-vcenter-cve-2021-21985-explained</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Security Advisory]]></title>
      <description><![CDATA[A security advisory is an official notice that a product has a security flaw, plus how to fix it. Here is what advisories contain, who issues them, and how to act on one.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-security-advisory</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-security-advisory</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is ASPM (Application Security Posture Management)?]]></title>
      <description><![CDATA[Application Security Posture Management (ASPM) unifies findings from every AppSec tool into one correlated, prioritized view of your risk. Here's what ASPM is, the tool-sprawl problem it solves, and how it differs from CSPM and ASOC.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-aspm-application-security-posture-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-aspm-application-security-posture-management</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is the in-toto Framework?]]></title>
      <description><![CDATA[in-toto is a framework for cryptographically verifying that every step in a software supply chain was performed as planned by authorized parties. Here's how layouts, link metadata, and functionaries fit together.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-in-toto-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-in-toto-framework</guid>
      <pubDate>Mon, 06 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Set It and Forget It: Onboarding the Guard SDK Just Got a Lot Simpler]]></title>
      <description><![CDATA[Generate a secret key from Settings, drop it into the Guard SDK, and your live security policy is enforced automatically — no manual wiring, no restarts when policy changes. OAuth login is available too.]]></description>
      <link>https://safeguard.sh/resources/blog/guard-sdk-secret-key-onboarding-policy-sync</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/guard-sdk-secret-key-onboarding-policy-sync</guid>
      <pubDate>Mon, 06 Jul 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Introducing the Package Firewall and AI Model-Artifact Scanning]]></title>
      <description><![CDATA[Two supply-chain defenses are rolling out on Safeguard: an install-time Package Firewall that blocks malicious npm and pip packages before they resolve, and AI model-artifact scanning that inspects model weights — now including ONNX — for malware before they load.]]></description>
      <link>https://safeguard.sh/resources/blog/introducing-package-firewall-model-artifact-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/introducing-package-firewall-model-artifact-scanning</guid>
      <pubDate>Mon, 06 Jul 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 vs SOC 2: Which Certification Matters More]]></title>
      <description><![CDATA[ISO 27001 and SOC 2 answer different questions. Here's how to read both when vetting supply chain security vendors like Snyk and Safeguard.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-vs-soc-2-which-certification-matters-more</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-vs-soc-2-which-certification-matters-more</guid>
      <pubDate>Mon, 06 Jul 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How to Create an npm Package (and Publish It Securely)]]></title>
      <description><![CDATA[A practical npm create package walkthrough: init, entry points, files whitelist, dry-run checks, then publishing with 2FA, provenance, and trusted publishing so your package cannot be hijacked.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-create-npm-package-securely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-create-npm-package-securely</guid>
      <pubDate>Mon, 06 Jul 2026 08:41:29 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Containers Not Dropping Default Linux Capabilities]]></title>
      <description><![CDATA[Docker grants every container 14 Linux capabilities by default. Here's why NET_RAW, SYS_CHROOT, and friends turn contained compromises into breakouts—and how to drop them safely.]]></description>
      <link>https://safeguard.sh/resources/blog/containers-not-dropping-default-linux-capabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/containers-not-dropping-default-linux-capabilities</guid>
      <pubDate>Mon, 06 Jul 2026 07:21:03 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Governing MCP tools with per-tenant feature flags]]></title>
      <description><![CDATA[Safeguard's MCP server exposes 650+ tools. Here's how per-tool feature flags keep each tenant scoped to exactly what it needs — with safe defaults and a fail-safe that narrows, never widens, on error.]]></description>
      <link>https://safeguard.sh/resources/blog/governing-mcp-tools-with-per-tenant-feature-flags</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/governing-mcp-tools-with-per-tenant-feature-flags</guid>
      <pubDate>Mon, 06 Jul 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[The SolarWinds Orion supply chain attack explained]]></title>
      <description><![CDATA[How SUNBURST hid inside a signed SolarWinds Orion update, hit 18,000 organizations, and reshaped supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/the-solarwinds-orion-supply-chain-attack-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-solarwinds-orion-supply-chain-attack-explained</guid>
      <pubDate>Mon, 06 Jul 2026 07:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Containers Running in Privileged Mode: Risks and Fixes]]></title>
      <description><![CDATA[Docker's --privileged flag strips seccomp, AppArmor, and capability limits in one line. Here's how attackers exploit it, real CVEs, and how to lock it down.]]></description>
      <link>https://safeguard.sh/resources/blog/containers-running-in-privileged-mode-risks-and-fixes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/containers-running-in-privileged-mode-risks-and-fixes</guid>
      <pubDate>Mon, 06 Jul 2026 06:00:36 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Wiz: Which Platform Fits Your AppSec Needs]]></title>
      <description><![CDATA[Snyk scans code and dependencies, Wiz scans cloud posture — but neither verifies build provenance. Here's where Safeguard fits in the AppSec stack.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-wiz-which-platform-fits-your-appsec-needs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-wiz-which-platform-fits-your-appsec-needs</guid>
      <pubDate>Mon, 06 Jul 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-21626: runc process.cwd Container Breakout Deep ...]]></title>
      <description><![CDATA[A technical breakdown of CVE-2024-21626, the runc process.cwd() flaw enabling container breakout to host access, with detection and remediation guidance.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-21626-runc-processcwd-container-breakout-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-21626-runc-processcwd-container-breakout-deep-dive</guid>
      <pubDate>Mon, 06 Jul 2026 04:40:09 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[The Codecov Bash uploader breach]]></title>
      <description><![CDATA[How a Docker image flaw let attackers tamper with Codecov's Bash Uploader for 65 days, exfiltrating CI secrets from HashiCorp, Twilio, and more.]]></description>
      <link>https://safeguard.sh/resources/blog/the-codecov-bash-uploader-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-codecov-bash-uploader-breach</guid>
      <pubDate>Mon, 06 Jul 2026 04:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Log4Shell (CVE-2021-44228) Deep Dive: JNDI Injection in L...]]></title>
      <description><![CDATA[Log4Shell (CVE-2021-44228) let attackers achieve remote code execution via a single logged string. A deep dive into the JNDI flaw, its impact, and remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/log4shell-cve-2021-44228-deep-dive-jndi-injection-in-log4j</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4shell-cve-2021-44228-deep-dive-jndi-injection-in-log4j</guid>
      <pubDate>Mon, 06 Jul 2026 03:19:43 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Black Duck (Synopsys) Comparison]]></title>
      <description><![CDATA[Snyk vs Black Duck comparison for security buyers: how the two SCA platforms differ on workflow, coverage, and compliance — and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-black-duck-synopsys-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-black-duck-synopsys-comparison</guid>
      <pubDate>Mon, 06 Jul 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Measure DevOps Success]]></title>
      <description><![CDATA[Measuring DevOps success means tracking delivery speed, stability, reliability, and security together, so improvement in one area doesn't quietly degrade another. Here is a practical framework.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-measure-devops-success</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-measure-devops-success</guid>
      <pubDate>Mon, 06 Jul 2026 01:59:16 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[3CX DesktopApp supply chain compromise]]></title>
      <description><![CDATA[How North Korea-linked hackers turned a signed, trusted 3CX VoIP installer into malware — and the double supply chain attack that made it possible.]]></description>
      <link>https://safeguard.sh/resources/blog/3cx-desktopapp-supply-chain-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/3cx-desktopapp-supply-chain-compromise</guid>
      <pubDate>Mon, 06 Jul 2026 01:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Spring4Shell (CVE-2022-22965) Deep Dive: RCE via Data Bin...]]></title>
      <description><![CDATA[A technical breakdown of Spring4Shell (CVE-2022-22965): the data-binding RCE, affected Spring/Tomcat configurations, severity, timeline, and how to remediate and detect exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/spring4shell-cve-2022-22965-deep-dive-rce-via-data-binding</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring4shell-cve-2022-22965-deep-dive-rce-via-data-binding</guid>
      <pubDate>Mon, 06 Jul 2026 00:38:49 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Aikido Security Comparison]]></title>
      <description><![CDATA[Comparing Snyk and Aikido as code scanners misses the bigger question: can you prove what actually shipped? Here's where Safeguard's supply chain security fits.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-aikido-security-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-aikido-security-comparison</guid>
      <pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Prevention in Java with PreparedStatement]]></title>
      <description><![CDATA[Java teams still ship SQL injection bugs despite PreparedStatement being free and built into the JDK since 1997. Here is how it works and where it fails.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-prevention-in-java-with-preparedstatement</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-prevention-in-java-with-preparedstatement</guid>
      <pubDate>Sun, 05 Jul 2026 23:18:22 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Prevention in Python with Parameterized Que...]]></title>
      <description><![CDATA[SQL injection remains widespread in Python apps despite decades-old fixes. Here's how parameterized queries actually prevent it, and where ORMs still leave gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-prevention-in-python-with-parameterized-queries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-prevention-in-python-with-parameterized-queries</guid>
      <pubDate>Sun, 05 Jul 2026 21:57:56 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Prevention in Node.js/JavaScript]]></title>
      <description><![CDATA[SQL injection still hits Node.js apps through raw drivers, Sequelize, Prisma, and Knex alike. Here's how it happens, what safe queries look like, and how to catch it in CI.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-prevention-in-nodejsjavascript</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-prevention-in-nodejsjavascript</guid>
      <pubDate>Sun, 05 Jul 2026 20:37:29 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Prevention in Go with database/sql Prepared...]]></title>
      <description><![CDATA[How Go's database/sql prepared statements prevent SQL injection, where developers still get it wrong with dynamic queries and ORMs, and how Safeguard catches these gaps in code review.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-prevention-in-go-with-databasesql-prepared-statements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-prevention-in-go-with-databasesql-prepared-statements</guid>
      <pubDate>Sun, 05 Jul 2026 19:17:02 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Prevention in C# with Entity Framework/LINQ]]></title>
      <description><![CDATA[EF Core's LINQ layer parameterizes queries by default, but FromSqlRaw, ExecuteSqlRaw, and dynamic sort columns still open real SQL injection risk in .NET apps.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-prevention-in-c-with-entity-frameworklinq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-prevention-in-c-with-entity-frameworklinq</guid>
      <pubDate>Sun, 05 Jul 2026 17:56:36 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Prevention in PHP with Parameterized Queries]]></title>
      <description><![CDATA[Parameterized queries stop SQL injection in PHP by separating code from data. Here's how PDO and MySQLi prepared statements work, and where they still fail.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-prevention-in-php-with-parameterized-queries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-prevention-in-php-with-parameterized-queries</guid>
      <pubDate>Sun, 05 Jul 2026 16:36:09 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Prevention in Ruby with exec_params Binding]]></title>
      <description><![CDATA[Ruby's pg gem makes SQL injection preventable with one method change. Here's how exec_params binds parameters, why Rails CVEs keep recurring, and how to migrate safely.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-prevention-in-ruby-with-execparams-binding</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-prevention-in-ruby-with-execparams-binding</guid>
      <pubDate>Sun, 05 Jul 2026 15:15:42 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Introducing First-Party SAST and DAST: One Findings Model Across Code and Runtime]]></title>
      <description><![CDATA[Safeguard is extending the platform with first-party static (SAST) and dynamic (DAST) application security testing — sharing one unified findings model with SCA, secrets, container, and IaC, with defensive-only DAST that only ever touches targets you've proven you own.]]></description>
      <link>https://safeguard.sh/resources/blog/introducing-first-party-sast-and-dast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/introducing-first-party-sast-and-dast</guid>
      <pubDate>Sun, 05 Jul 2026 14:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Prevention in Rust with sqlx]]></title>
      <description><![CDATA[sqlx blocks SQL injection by default with compile-time query checks and bind parameters — but format!() and raw SQL calls can still reopen the gap. Here's how to audit for it.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-prevention-in-rust-with-sqlx</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-prevention-in-rust-with-sqlx</guid>
      <pubDate>Sun, 05 Jul 2026 13:55:16 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Prevention in C++ with SQLite Bind Parameters]]></title>
      <description><![CDATA[How sqlite3_bind_text() stops SQL injection in C++ apps, common mistakes with bind parameters, and how to audit existing SQLite code for injection risk.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-prevention-in-c-with-sqlite-bind-parameters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-prevention-in-c-with-sqlite-bind-parameters</guid>
      <pubDate>Sun, 05 Jul 2026 12:34:49 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Path Traversal Prevention in JavaScript/Node.js with path...]]></title>
      <description><![CDATA[path.normalize() alone will not stop path traversal in Node.js. Real CVEs like node-tar show why resolve-then-compare beats normalize-then-trust.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-prevention-in-javascriptnodejs-with-pathnormalize</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-prevention-in-javascriptnodejs-with-pathnormalize</guid>
      <pubDate>Sun, 05 Jul 2026 11:14:22 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[AI Coding Assistant Security FAQ: Risks and Controls for 2026]]></title>
      <description><![CDATA[Straight answers on securing AI coding assistants like Claude Code, Cursor, and Cline — the real risks, data-leakage paths, insecure output, and how to add guardrails without slowing developers.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-coding-assistant-security-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-coding-assistant-security-faq</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Alpine vs Debian Base Image Security: Which Is Safer?]]></title>
      <description><![CDATA[Alpine is tiny and dodged the xz backdoor; Debian has deeper security tracking and broader compatibility. Here is how the two base images actually compare on security — and how to harden either one.]]></description>
      <link>https://safeguard.sh/resources/blog/alpine-vs-debian-base-image-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/alpine-vs-debian-base-image-security</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Artifact Tampering and Integrity: Trusting What You Actually Ship]]></title>
      <description><![CDATA[Artifact tampering alters a build output after it leaves source control, so what you deploy differs from what you reviewed. Here is how it works and how to verify integrity.]]></description>
      <link>https://safeguard.sh/resources/blog/artifact-tampering-and-integrity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/artifact-tampering-and-integrity</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Confluence OGNL Injection (CVE-2022-26134) Explained]]></title>
      <description><![CDATA[CVE-2022-26134 is a CVSS 9.8 unauthenticated OGNL injection in Atlassian Confluence, exploited as a zero-day before the patch. Here is how the flaw works and which versions fixed it.]]></description>
      <link>https://safeguard.sh/resources/blog/atlassian-confluence-cve-2022-26134-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/atlassian-confluence-cve-2022-26134-explained</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Automated Pull Request Fixes FAQ: How Fix PRs Are Built, Tested, and Merged]]></title>
      <description><![CDATA[What an automated fix pull request contains, how CI validates it, how auto-merge gating works, and which SCM platforms and review workflows are supported.]]></description>
      <link>https://safeguard.sh/resources/blog/automated-pull-request-fixes-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automated-pull-request-fixes-faq</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Azure Pipelines Security: Stop Treating YAML as Config]]></title>
      <description><![CDATA[An Azure Pipeline is a program with attacker-controllable input, not a config file. This guide covers macro injection, task and template pinning, environment approvals, workload identity federation, and adding scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-pipelines-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-pipelines-security</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Best AI Code Security Tools in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced 2026 comparison of tools for securing AI-generated code and AI-native applications — Semgrep, CodeQL with Copilot Autofix, Snyk, Socket, Endor Labs, and model-layer tools — with an honest look at where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/best-ai-code-security-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-ai-code-security-tools-2026</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best SBOM Tools (2026): An Honest FAQ]]></title>
      <description><![CDATA[A balanced 2026 FAQ on the best SBOM tools — how Syft, Trivy, Dependency-Track, Sonatype, Black Duck, and Safeguard compare, and when a generator is enough versus a platform.]]></description>
      <link>https://safeguard.sh/resources/blog/best-sbom-tools-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-sbom-tools-faq</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Clickjacking: A Prevention Guide]]></title>
      <description><![CDATA[Clickjacking tricks a user into clicking something different from what they see by layering an invisible frame over a decoy page. Here is how to block it.]]></description>
      <link>https://safeguard.sh/resources/blog/clickjacking-prevention-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/clickjacking-prevention-guide</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Workload Protection: A Practical Guide to CWPP in 2026]]></title>
      <description><![CDATA[What cloud workload protection (CWPP) actually covers across VMs, containers, and serverless — how it differs from CSPM and CNAPP, what to configure, and where build-time scanning fits.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-workload-protection-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-workload-protection-guide</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Auditing PHP Dependencies with composer audit]]></title>
      <description><![CDATA[Composer ships a native security auditor. Learn to run composer audit against your composer.lock, catch abandoned packages, and extend it with continuous SCA.]]></description>
      <link>https://safeguard.sh/resources/blog/composer-audit-php-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/composer-audit-php-dependencies</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Confluence CVE-2021-26084 Explained: The Webwork OGNL Injection RCE]]></title>
      <description><![CDATA[CVE-2021-26084 is an unauthenticated OGNL injection in Confluence Server and Data Center that allows remote code execution, rated CVSS 9.8. Here is the timeline, root cause, detection, and patched versions.]]></description>
      <link>https://safeguard.sh/resources/blog/confluence-ognl-cve-2021-26084-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/confluence-ognl-cve-2021-26084-explained</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Container Escape Vulnerabilities: How They Work and How to Stop Them]]></title>
      <description><![CDATA[A container is a process with boundaries, not a virtual machine. When those boundaries fail, an attacker lands on the host. Here is the anatomy of real container escapes — runc, Leaky Vessels, Dirty Pipe — and how to defend against them.]]></description>
      <link>https://safeguard.sh/resources/blog/container-escape-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-escape-vulnerabilities</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[C# Cryptography Best Practices in .NET]]></title>
      <description><![CDATA[The right way to do cryptography in C#: authenticated encryption with AesGcm, secure randomness, PBKDF2 password hashing, constant-time comparison, and the legacy APIs to stop using.]]></description>
      <link>https://safeguard.sh/resources/blog/csharp-cryptography-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/csharp-cryptography-best-practices</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Distroless vs Alpine: Which Base Image Is More Secure?]]></title>
      <description><![CDATA[Alpine is tiny and familiar; distroless is tinier and shell-free. The right choice depends on what you value more — debuggability or a minimal attack surface. Here is the honest tradeoff.]]></description>
      <link>https://safeguard.sh/resources/blog/distroless-vs-alpine-container-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/distroless-vs-alpine-container-security</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Essential Security Skills Every Developer Should Learn]]></title>
      <description><![CDATA[Security is no longer a separate team's job. Here are the essential security skills every developer should build in 2026—why they matter to your career, how to learn them for free, and how to prove you have them.]]></description>
      <link>https://safeguard.sh/resources/blog/essential-security-skills-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/essential-security-skills-for-developers</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Career</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[False Positives vs False Negatives: What's the Difference?]]></title>
      <description><![CDATA[A false positive flags something safe as dangerous. A false negative misses something dangerous entirely. One wastes your time; the other gets you breached.]]></description>
      <link>https://safeguard.sh/resources/blog/false-positives-vs-false-negatives</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/false-positives-vs-false-negatives</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[The FedRAMP Authorization Guide: Paths, Baselines, and Continuous Monitoring]]></title>
      <description><![CDATA[FedRAMP is how cloud products earn the right to sell to U.S. federal agencies. Here's how the authorization paths work, what the NIST 800-53 baselines require, and where your software supply chain gets scrutinized.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-authorization-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-authorization-guide</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[GitLab Account Takeover via Password Reset (CVE-2023-7028) Explained]]></title>
      <description><![CDATA[CVE-2023-7028 let attackers send GitLab password-reset links to an address they controlled — a zero-interaction account takeover scored 10.0. Here's the flaw and the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-cve-2023-7028-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-cve-2023-7028-explained</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Go Concurrency Security Pitfalls: When Data Races Become Vulnerabilities]]></title>
      <description><![CDATA[A data race isn't just a flaky test — in the wrong place it's an auth bypass, a cross-request leak, or a denial of service. Here are the Go concurrency bugs that turn into security incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/go-concurrency-security-pitfalls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-concurrency-security-pitfalls</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[GraphQL API Security: Introspection, Depth Limits, and Authorization]]></title>
      <description><![CDATA[GraphQL's flexibility is its attack surface. Nested queries, introspection, and per-field authorization all fail differently than REST. Here's how to secure them.]]></description>
      <link>https://safeguard.sh/resources/blog/graphql-api-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/graphql-api-security</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Audit npm Dependencies for Vulnerabilities]]></title>
      <description><![CDATA[Go beyond npm audit's noisy output — resolve your dependency tree, prioritize by reachability, and fix both direct and transitive vulnerabilities in a Node.js project the right way.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-audit-npm-dependencies-for-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-audit-npm-dependencies-for-vulnerabilities</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Prioritize Vulnerabilities]]></title>
      <description><![CDATA[A scan gave you a hundred findings and you can't fix them all today. This beginner guide teaches a simple, sensible order for deciding what to fix first.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-prioritize-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-prioritize-vulnerabilities</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Introduction to Secure Software Development]]></title>
      <description><![CDATA[Security is not a phase you bolt on at the end — it is a set of practices woven through every stage of building software. This guide introduces the secure development lifecycle, the practices that matter at each stage, and how to get started.]]></description>
      <link>https://safeguard.sh/resources/blog/introduction-to-secure-software-development</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/introduction-to-secure-software-development</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Java SQL Injection Prevention: Parameterized Queries and Beyond]]></title>
      <description><![CDATA[SQL injection is decades old and still breaching Java apps. Here's how to prevent it with prepared statements, JPA binding, and safe dynamic queries.]]></description>
      <link>https://safeguard.sh/resources/blog/java-sql-injection-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-sql-injection-prevention</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Lessons from the 3CX Attack: The First Supply Chain Attack Caused by Another]]></title>
      <description><![CDATA[3CX shipped a trojanized version of its own softphone through official updates in 2023 — because an employee installed compromised trading software. Here is the cascade, and its lessons.]]></description>
      <link>https://safeguard.sh/resources/blog/lessons-from-3cx-supply-chain-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lessons-from-3cx-supply-chain-attack</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Log4j Security Guide (2026)]]></title>
      <description><![CDATA[Log4j is the most widely deployed Java logging library — and the source of Log4Shell, the defining supply-chain vulnerability of the decade. Here is how to run it safely in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/log4j-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4j-security-guide</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Mend Alternatives in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced comparison of the top Mend alternatives in 2026 — Snyk, Sonatype, Black Duck, Endor Labs, Dependabot, and Safeguard — with candid pros, cons, and guidance on choosing.]]></description>
      <link>https://safeguard.sh/resources/blog/mend-alternatives-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mend-alternatives-2026</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[minimist Security Guide (2026)]]></title>
      <description><![CDATA[minimist is the tiny argument parser buried under a huge slice of the npm ecosystem — and two prototype-pollution CVEs made this 'harmless' 100-line library one of the most widely flagged transitive dependencies in JavaScript.]]></description>
      <link>https://safeguard.sh/resources/blog/minimist-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/minimist-security-guide</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[MOVEit Transfer (CVE-2023-34362) Explained: The SQL Injection Behind the Cl0p Mass Breach]]></title>
      <description><![CDATA[CVE-2023-34362 is a SQL injection in Progress MOVEit Transfer that let unauthenticated attackers reach the database and drop a web shell. Cl0p used it to breach thousands of organizations.]]></description>
      <link>https://safeguard.sh/resources/blog/moveit-cve-2023-34362-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/moveit-cve-2023-34362-explained</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[The NIST Secure Software Development Framework (SSDF), explained]]></title>
      <description><![CDATA[NIST SP 800-218 is the framework behind federal secure-development attestations. Here's what its four practice groups ask of you and how to produce the evidence.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-ssdf-secure-software-development-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-ssdf-secure-software-development-framework</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Secrets Management in Node.js: From .env to Zero-Standing-Credentials]]></title>
      <description><![CDATA[Hardcoded tokens and committed .env files are still the fastest way to lose a cloud account. Here is a maturity ladder for Node.js secrets — from native --env-file to managed vaults and short-lived OIDC credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-secrets-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-secrets-management</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[On-Premise Security Platform: FAQ]]></title>
      <description><![CDATA[Running software supply chain security inside your own datacenter or private cloud: architecture, upgrades, key ownership, integrations, and how on-prem differs from air-gapped.]]></description>
      <link>https://safeguard.sh/resources/blog/on-premise-security-platform-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/on-premise-security-platform-faq</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Open Source License Compliance: Frequently Asked Questions]]></title>
      <description><![CDATA[A clear FAQ on open-source license compliance in 2026 — permissive vs copyleft, SPDX identifiers, AGPL and SaaS, attribution obligations, license changes, and automated scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-license-compliance-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-license-compliance-faq</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[OWASP A07: Identification and Authentication Failures — A Deep-Dive Guide]]></title>
      <description><![CDATA[Identification and Authentication Failures rank #7 in the OWASP Top 10 (2021). A deep dive into credential stuffing, session handling, real CVEs, and 2026 fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-a07-authentication-failures</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-a07-authentication-failures</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[PHP Code Review Tools: An Honest 2026 Buyer's Guide]]></title>
      <description><![CDATA[A balanced 2026 comparison of PHP code review and static-analysis tools — PHPStan, Psalm, PHP_CodeSniffer, progpilot, Semgrep, SonarQube — with honest tradeoffs and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/php-code-review-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-code-review-tools</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Pickle and Deserialization Security in Python]]></title>
      <description><![CDATA[Unpickling untrusted data is arbitrary code execution, by design. Here is why pickle is dangerous, where it hides, and what to use instead.]]></description>
      <link>https://safeguard.sh/resources/blog/python-pickle-deserialization-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-pickle-deserialization-security</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Risks of Secrets in Environment Variables (2026)]]></title>
      <description><![CDATA[Environment variables feel like the safe place to put secrets — but they leak through crash dumps, child processes, CI logs, and container layers. Here is where env-var secrets escape and what to do instead.]]></description>
      <link>https://safeguard.sh/resources/blog/risks-of-secrets-in-environment-variables</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/risks-of-secrets-in-environment-variables</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Getting Started With Safeguard: Onboarding FAQ]]></title>
      <description><![CDATA[A practical FAQ for new Safeguard users — how to create an account, connect a repository, run a first scan, integrate CI, and expand coverage across your org.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-getting-started-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-getting-started-faq</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Scala Security Best Practices: JVM Supply Chain, Deserialization, and Framework CVEs]]></title>
      <description><![CDATA[Scala's expressive type system does nothing about the JVM attack surface underneath it. Log4Shell, Jackson gadget chains, and Spark's command-injection CVE all reach Scala code directly.]]></description>
      <link>https://safeguard.sh/resources/blog/scala-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scala-security-best-practices</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Secrets Scanning: Stop Leaking Credentials Before They Ship]]></title>
      <description><![CDATA[A leaked API key in Git history is compromised the moment it is pushed — deleting the commit does not help. Here is how to build secrets scanning across your whole lifecycle, from pre-commit to Git history.]]></description>
      <link>https://safeguard.sh/resources/blog/secrets-scanning-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secrets-scanning-guide</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Secure Coding for Beginners: Writing Code That Resists Attack]]></title>
      <description><![CDATA[Secure coding is not a separate discipline you bolt on later. It is a set of small habits you weave into the way you already write software. Here is a friendly introduction with a first exercise to try today.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-coding-for-beginners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-coding-for-beginners</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Securing AI Coding Assistants: Guardrails That Hold]]></title>
      <description><![CDATA[AI coding assistants are in nearly every IDE now. Banning them fails; trusting them blindly fails harder. The middle path is guardrails — technical controls that let assistants move fast without letting them ship the wrong thing.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-ai-coding-assistants-guardrails</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-ai-coding-assistants-guardrails</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Build a Security Champions Program That Lasts]]></title>
      <description><![CDATA[A security champions program scales AppSec without scaling headcount — if it's built right. A 2026 playbook for recruiting, enabling, and retaining champions, plus the metrics that prove it works.]]></description>
      <link>https://safeguard.sh/resources/blog/security-champions-program-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-champions-program-guide</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Security Design Review: A Practical Guide]]></title>
      <description><![CDATA[A security design review examines a system's architecture before it is built to find flaws that no code scanner can catch. Here's how to run one that finds real problems while they are still cheap to fix.]]></description>
      <link>https://safeguard.sh/resources/blog/security-design-review-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-design-review-guide</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Security Tool Cost and ROI: A Practical FAQ for 2026]]></title>
      <description><![CDATA[How to think about the cost and ROI of supply chain security tooling in 2026 — what drives price, how to measure return, and why a $1 starting point changes the math.]]></description>
      <link>https://safeguard.sh/resources/blog/security-tool-cost-and-roi-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-tool-cost-and-roi-faq</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Shellshock (CVE-2014-6271) Explained: RCE Hiding in Bash Environment Variables]]></title>
      <description><![CDATA[CVE-2014-6271, Shellshock, let attackers run commands by smuggling code into environment variables that Bash parsed as function definitions. Reachable over HTTP, DHCP, and SSH. Here is how.]]></description>
      <link>https://safeguard.sh/resources/blog/shellshock-cve-2014-6271-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shellshock-cve-2014-6271-explained</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for SaaS]]></title>
      <description><![CDATA[SaaS companies are a supply chain for everyone else, which is why the EU Cyber Resilience Act, NIS2, SOC 2, and DORA now push obligations onto them. Here is how to build a program that satisfies customers and regulators alike.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-for-saas</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-for-saas</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Sonatype vs JFrog Xray: A Neutral Comparison for 2026]]></title>
      <description><![CDATA[Sonatype and JFrog Xray both secure the software supply chain from the artifact repository outward, but they anchor to different platforms and philosophies. An honest side-by-side, plus a third option.]]></description>
      <link>https://safeguard.sh/resources/blog/sonatype-vs-jfrog-xray</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonatype-vs-jfrog-xray</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Subresource Integrity (SRI) Explained (2026)]]></title>
      <description><![CDATA[Subresource Integrity pins a cryptographic hash to every script you load from a CDN, so a compromised CDN cannot silently swap in malicious code. Here is how it works and where it stops.]]></description>
      <link>https://safeguard.sh/resources/blog/subresource-integrity-sri-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/subresource-integrity-sri-explained</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Attacks FAQ: 2026 Threats Explained]]></title>
      <description><![CDATA[Answers to the most common questions about software supply chain attacks in 2026 — how they work, famous examples, the main techniques, and how to defend against them.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-attacks-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-attacks-faq</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Product Security Teams]]></title>
      <description><![CDATA[Product security teams own the security of what ships and stays shipped. Here is how to embed supply chain controls across the SDLC, run PSIRT for third-party CVEs, and manage security debt in released products without owning every repo yourself.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-for-product-security-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-for-product-security-teams</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Terraform Security Best Practices: Hardening Your IaC in 2026]]></title>
      <description><![CDATA[Terraform provisions your entire cloud, which makes it your largest attack surface as code. Here are the practices that keep state, modules, and providers from becoming the breach.]]></description>
      <link>https://safeguard.sh/resources/blog/terraform-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/terraform-security-best-practices</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[The XZ Utils backdoor CVE-2024-3094 explained]]></title>
      <description><![CDATA[CVE-2024-3094 hid a remote-access backdoor inside xz-utils via a years-long social engineering campaign. Here's the timeline, impact, and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/the-xz-utils-backdoor-cve-2024-3094-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-xz-utils-backdoor-cve-2024-3094-explained</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Management FAQ: Process, Tooling, and SLAs]]></title>
      <description><![CDATA[What vulnerability management actually involves — discovery, triage, prioritization, remediation, and verification — answered as a practical FAQ for security and engineering teams.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-management-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-management-faq</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is a CVSS Score]]></title>
      <description><![CDATA[A CVSS score rates how severe a security flaw is on a scale of 0 to 10. Here is what the number means, how to read it, and why it is only part of the risk picture.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-cvss-score</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-cvss-score</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is ReDoS (Regular Expression Denial of Service)?]]></title>
      <description><![CDATA[A single badly written regular expression can freeze an entire service under a short, crafted input. This is ReDoS — and it has taken down Cloudflare and Stack Overflow. Here's how to avoid it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-redos-denial-of-service</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-redos-denial-of-service</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What Is Shift-Left Security? A Plain-English Explanation]]></title>
      <description><![CDATA[Shift-left security means moving security checks earlier in development — into the IDE, the commit, and the pull request — so flaws are caught while they're cheap to fix. Here's what it actually means and how to do it without slowing teams down.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-shift-left-security-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-shift-left-security-explained</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is Sigstore?]]></title>
      <description><![CDATA[Sigstore is an open-source project for signing and verifying software without managing long-lived keys. Here's how Cosign, Fulcio, and Rekor make keyless signing work.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-sigstore-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-sigstore-explained</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is the LGPL License? Linking and Weak Copyleft]]></title>
      <description><![CDATA[The GNU Lesser GPL is a weak-copyleft license designed for libraries. It lets proprietary software link to LGPL code without becoming GPL. Here is how the linking rules actually work.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-lgpl-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-lgpl-license</guid>
      <pubDate>Sun, 05 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Path Traversal Prevention in PHP: Avoiding include() with...]]></title>
      <description><![CDATA[PHP's include() turns a path traversal bug into remote code execution. See how CVE-2015-2213 and CVE-2022-1329 happened, and how to prevent it with allowlists.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-prevention-in-php-avoiding-include-with-user-input</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-prevention-in-php-avoiding-include-with-user-input</guid>
      <pubDate>Sun, 05 Jul 2026 09:53:55 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs SonarQube for SAST]]></title>
      <description><![CDATA[Snyk Code and SonarQube both do SAST, but neither started as a supply chain security platform. Here's how their approaches differ, and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-sonarqube-for-sast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-sonarqube-for-sast</guid>
      <pubDate>Sun, 05 Jul 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Path Traversal Prevention in Python with os.path.realpath]]></title>
      <description><![CDATA[os.path.normpath() and abspath() don't stop symlink-based path traversal. Here's how os.path.realpath() closes the gap, with real CVEs and a secure pattern.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-prevention-in-python-with-ospathrealpath</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-prevention-in-python-with-ospathrealpath</guid>
      <pubDate>Sun, 05 Jul 2026 08:33:29 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Path Traversal Prevention in Go with filepath.Join Valida...]]></title>
      <description><![CDATA[filepath.Join in Go only cleans a path, it doesn't restrict it to a base directory. Here's why that gap produced real CVEs, and how to close it for good.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-prevention-in-go-with-filepathjoin-validation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-prevention-in-go-with-filepathjoin-validation</guid>
      <pubDate>Sun, 05 Jul 2026 07:13:02 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[event-stream npm package backdoor incident]]></title>
      <description><![CDATA[How a routine maintainer handoff let attackers slip a Bitcoin-stealing backdoor into event-stream, hitting millions of npm installs for ten weeks.]]></description>
      <link>https://safeguard.sh/resources/blog/event-stream-npm-package-backdoor-incident</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/event-stream-npm-package-backdoor-incident</guid>
      <pubDate>Sun, 05 Jul 2026 07:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Path Traversal Prevention in Java with Path.normalize]]></title>
      <description><![CDATA[Path.normalize() cleans up "." and ".." in a Java path — but it doesn't stop path traversal. Here's why the Zip Slip pattern still slips past code review in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-prevention-in-java-with-pathnormalize</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-prevention-in-java-with-pathnormalize</guid>
      <pubDate>Sun, 05 Jul 2026 05:52:35 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Path Traversal Prevention in C# with Path.GetFullPath]]></title>
      <description><![CDATA[Path.GetFullPath resolves traversal sequences, but it isn't a sanitizer on its own. Here's how C# teams get containment checks wrong, and how to fix them.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-prevention-in-c-with-pathgetfullpath</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-prevention-in-c-with-pathgetfullpath</guid>
      <pubDate>Sun, 05 Jul 2026 04:32:09 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[ua-parser-js npm hijack incident]]></title>
      <description><![CDATA[In 2021, a hijacked npm account pushed cryptomining and password-stealing malware into ua-parser-js for 4 hours. Here's what happened and how to catch it faster.]]></description>
      <link>https://safeguard.sh/resources/blog/ua-parser-js-npm-hijack-incident</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ua-parser-js-npm-hijack-incident</guid>
      <pubDate>Sun, 05 Jul 2026 04:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Path Traversal Prevention in Ruby with File.realpath]]></title>
      <description><![CDATA[How File.realpath stops path traversal in Ruby apps, why File.expand_path alone fails, and what real CVEs like Sprockets' CVE-2018-3760 reveal about secure file handling.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-prevention-in-ruby-with-filerealpath</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-prevention-in-ruby-with-filerealpath</guid>
      <pubDate>Sun, 05 Jul 2026 03:11:42 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Pricing: Is It Worth the Cost]]></title>
      <description><![CDATA[Snyk's tiered, per-seat pricing looks simple until you scale. A buyer's-guide breakdown of what drives Snyk's total cost, and how Safeguard approaches supply chain security pricing differently.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-pricing-is-it-worth-the-cost</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-pricing-is-it-worth-the-cost</guid>
      <pubDate>Sun, 05 Jul 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Path Traversal Prevention in Rust with fs::canonicalize]]></title>
      <description><![CDATA[fs::canonicalize resolves `..` and symlinks into one absolute path, but it can't fix TOCTOU races, missing files, or Windows prefix quirks on its own. Here's the safe pattern.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-prevention-in-rust-with-fscanonicalize</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-prevention-in-rust-with-fscanonicalize</guid>
      <pubDate>Sun, 05 Jul 2026 01:51:15 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[colors.js and faker.js protestware sabotage]]></title>
      <description><![CDATA[In 2022, maintainer Marak Squires turned colors.js and faker.js into protestware, breaking 19,000+ npm projects and coining a new supply chain threat term.]]></description>
      <link>https://safeguard.sh/resources/blog/colorsjs-and-fakerjs-protestware-sabotage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/colorsjs-and-fakerjs-protestware-sabotage</guid>
      <pubDate>Sun, 05 Jul 2026 01:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Path Traversal Prevention in C++ with std::filesystem::we...]]></title>
      <description><![CDATA[Why std::filesystem::weakly_canonical alone doesn't stop path traversal in C++, and the containment check every extraction, upload, or plugin loader needs beside it.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-prevention-in-c-with-stdfilesystemweaklycanonical</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-prevention-in-c-with-stdfilesystemweaklycanonical</guid>
      <pubDate>Sun, 05 Jul 2026 00:30:49 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is Application Security (AppSec) 101]]></title>
      <description><![CDATA[AppSec used to mean scanning code for known bugs. Here's why that's no longer enough, what CVE-matching tools like Snyk miss, and what a real supply chain security program requires.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-application-security-appsec-101</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-application-security-appsec-101</guid>
      <pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[XXE Prevention in Ruby with Nokogiri NONET/NOENT]]></title>
      <description><![CDATA[Nokogiri wraps libxml2, and one misconfigured parse call can leak local files or trigger SSRF. Here's how NONET and NOENT actually work, and how to lock them down.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-prevention-in-ruby-with-nokogiri-nonetnoent</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-prevention-in-ruby-with-nokogiri-nonetnoent</guid>
      <pubDate>Sat, 04 Jul 2026 23:10:22 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[react-native-android-location-enabler: Safe Usage and Security Notes]]></title>
      <description><![CDATA[The react-native-android-location-enabler package shows the native Android dialog that asks users to turn on location services. Here is how to use it correctly and the privacy practices that go with it.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-android-location-enabler</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-android-location-enabler</guid>
      <pubDate>Sat, 04 Jul 2026 21:49:55 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Vulnerability Databases Compared: NVD, OSV, GitHub Advisory, and More]]></title>
      <description><![CDATA[Not all vulnerability databases are created equal. A detailed comparison of coverage, timeliness, accuracy, and practical usability across the major databases.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-vulnerability-database-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-vulnerability-database-comparison</guid>
      <pubDate>Sat, 04 Jul 2026 20:29:29 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[XXE Prevention in JavaScript: Disabling libxmljs noent]]></title>
      <description><![CDATA[How the libxmljs noent option silently reopens XML External Entity (XXE) attacks in Node.js apps, and the exact parser settings that shut it down for good.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-prevention-in-javascript-disabling-libxmljs-noent</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-prevention-in-javascript-disabling-libxmljs-noent</guid>
      <pubDate>Sat, 04 Jul 2026 19:09:02 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[XXE Prevention in C++: Removing libxml2 XML_PARSE_NOENT]]></title>
      <description><![CDATA[How the libxml2 XML_PARSE_NOENT flag enables XXE in C++ codebases, the real CVEs behind it, and the exact code changes needed to remove it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-prevention-in-c-removing-libxml2-xmlparsenoent</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-prevention-in-c-removing-libxml2-xmlparsenoent</guid>
      <pubDate>Sat, 04 Jul 2026 17:48:35 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[XXE Prevention in Python with resolve_entities=False]]></title>
      <description><![CDATA[Why lxml's XMLParser resolves external entities by default, how resolve_entities=False actually stops XXE, and where Python teams still leave file-read and SSRF paths open.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-prevention-in-python-with-resolveentitiesfalse</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-prevention-in-python-with-resolveentitiesfalse</guid>
      <pubDate>Sat, 04 Jul 2026 16:28:08 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[XXE Prevention in Java: Hardening DocumentBuilderFactory]]></title>
      <description><![CDATA[Java's DocumentBuilderFactory parses XML with external entities on by default, turning XML uploads into file-read and SSRF vectors. Here is how to lock it down.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-prevention-in-java-hardening-documentbuilderfactory</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-prevention-in-java-hardening-documentbuilderfactory</guid>
      <pubDate>Sat, 04 Jul 2026 15:07:42 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[The LLM Application Security Checklist (2026)]]></title>
      <description><![CDATA[You are shipping an LLM feature. Before it goes live, walk this checklist — organized around the OWASP Top 10 for LLM Applications — to catch the risks that matter most in production.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-application-security-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-application-security-checklist</guid>
      <pubDate>Sat, 04 Jul 2026 15:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Securing Hugging Face Models: A Practical Safety Guide]]></title>
      <description><![CDATA[Hugging Face is the npm of machine learning, and it inherits npm's problems. Malicious weights, pickle payloads, and leaked Space secrets are all live risks — here is how to pull models safely.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-huggingface-models</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-huggingface-models</guid>
      <pubDate>Sat, 04 Jul 2026 15:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[.NET Dependency Vulnerability Scanning: A Practical Guide]]></title>
      <description><![CDATA[How to scan .NET dependencies for known vulnerabilities using dotnet list package, NuGet audit, and reachability-aware SCA, and how to wire it into CI so nothing ships with a known critical.]]></description>
      <link>https://safeguard.sh/resources/blog/dotnet-dependency-vulnerability-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dotnet-dependency-vulnerability-scanning</guid>
      <pubDate>Sat, 04 Jul 2026 14:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Securing Express Applications: A Layered Playbook]]></title>
      <description><![CDATA[Express gives you almost no security by default. This playbook layers the middleware, headers, rate limits, session hardening, and input validation that turn a bare Express app into a defensible one — with Express 5 in mind.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-express-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-express-applications</guid>
      <pubDate>Sat, 04 Jul 2026 14:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Jest Latest Version: Upgrading Safely in 2026]]></title>
      <description><![CDATA[The Jest latest version is 30.x, and keeping current matters less for features than for cutting the pile of transitive dev dependencies older Jest drags in.]]></description>
      <link>https://safeguard.sh/resources/blog/jest-latest-version</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jest-latest-version</guid>
      <pubDate>Sat, 04 Jul 2026 13:47:15 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Python Vulnerability Scanner: How It Works and What to Use]]></title>
      <description><![CDATA[A Python vulnerability scanner checks your code and dependencies for known security flaws. Here is how the different scanner types work and how to combine them in CI.]]></description>
      <link>https://safeguard.sh/resources/blog/python-vulnerability-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-vulnerability-scanner</guid>
      <pubDate>Sat, 04 Jul 2026 12:26:48 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is an SSRF Attack? Examples and How to Stop It]]></title>
      <description><![CDATA[An SSRF attack tricks your server into making requests on an attacker's behalf, often reaching internal systems it should never touch. Here is how it works and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/ssrf-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ssrf-attack</guid>
      <pubDate>Sat, 04 Jul 2026 11:06:22 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[AI Code Review and Security: Reviewer, Reviewed, or Both?]]></title>
      <description><![CDATA[AI can review pull requests and AI can write them — sometimes in the same workflow. Both roles carry security implications teams routinely underestimate. Here is how to get the benefit without the blind spots.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-code-review-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-code-review-security</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[AI Data Poisoning Defense: Protecting Models from Tainted Data]]></title>
      <description><![CDATA[You do not need to corrupt most of a training set to backdoor a model — recent research suggests a small, near-constant number of poisoned documents can be enough. Defense starts with treating data as a dependency.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-data-poisoning-defense</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-data-poisoning-defense</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Air-Gapped Security Deployment: FAQ]]></title>
      <description><![CDATA[How software supply chain security works in fully disconnected environments: offline vulnerability database sync, sealed deployments, customer-held keys, and what changes when there is no internet.]]></description>
      <link>https://safeguard.sh/resources/blog/air-gapped-security-deployment-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/air-gapped-security-deployment-faq</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[The Best Dependency Scanning Tools in 2026]]></title>
      <description><![CDATA[Dependency scanning is crowded and the tools differ more than the marketing suggests. This balanced guide compares Dependabot, Snyk, Mend, Trivy, Socket, and Safeguard on accuracy, prioritization, and remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/best-dependency-scanning-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-dependency-scanning-tools-2026</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best IaC Security Tools in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced 2026 comparison of the leading infrastructure-as-code security tools — Checkov, Trivy, KICS, Snyk IaC, Prisma Cloud, and Wiz — with an honest look at where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/best-iac-security-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-iac-security-tools-2026</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Black Duck Alternatives in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced comparison of the leading Black Duck alternatives in 2026 — Snyk, Mend, Sonatype, FOSSA, Trivy, and Safeguard — with candid pros, cons, and a framework for choosing.]]></description>
      <link>https://safeguard.sh/resources/blog/black-duck-alternatives-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/black-duck-alternatives-2026</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Build Pipeline Compromise: When the Factory Ships the Malware]]></title>
      <description><![CDATA[A build pipeline compromise injects malicious code during CI/CD, so the software you sign and ship is already backdoored. Here is how it works and how to defend.]]></description>
      <link>https://safeguard.sh/resources/blog/build-pipeline-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/build-pipeline-compromise</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx vs Veracode: A Neutral AppSec Comparison for 2026]]></title>
      <description><![CDATA[Checkmarx and Veracode are both enterprise application security platforms with deep SAST roots, but they differ in analysis method and deployment model. An honest side-by-side, plus where a third option fits.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-vs-veracode</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-vs-veracode</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CircleCI Security Best Practices After the 2023 Breach]]></title>
      <description><![CDATA[The January 2023 CircleCI incident forced every customer to rotate every secret. Here is what it taught us — plus hardened config.yml examples for orb pinning, restricted contexts, OIDC, and adding scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/circleci-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/circleci-security-best-practices</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Security for Beginners: Your First Steps in the Cloud]]></title>
      <description><![CDATA[The cloud gives you enormous power with a few clicks, and that includes the power to expose data by accident. Here is a warm, beginner-friendly guide with a first check you can run on your own account today.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-security-for-beginners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-security-for-beginners</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Content Security Policy (CSP) Explained (2026)]]></title>
      <description><![CDATA[A Content Security Policy is your last line of defense against XSS. Here is how CSP works, why nonce-based strict policies beat allowlists, and how to deploy one without breaking your app.]]></description>
      <link>https://safeguard.sh/resources/blog/content-security-policy-csp-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/content-security-policy-csp-explained</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[CORS Misconfiguration: How to Prevent It]]></title>
      <description><![CDATA[A too-generous CORS policy can let a malicious site read authenticated responses from your API. Reflecting the Origin with credentials is the classic mistake.]]></description>
      <link>https://safeguard.sh/resources/blog/cors-misconfiguration-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cors-misconfiguration-prevention</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[C++ Security Best Practices: Memory Safety, Hardening Flags, and the C/C++ Supply Chain]]></title>
      <description><![CDATA[Microsoft attributes roughly 70% of its CVEs to memory-safety bugs, and the xz backdoor proved the C/C++ supply chain is a live target. Here is the practical hardening path for code you can't rewrite.]]></description>
      <link>https://safeguard.sh/resources/blog/cpp-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cpp-security-best-practices</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Database Credential Security (2026 Guide)]]></title>
      <description><![CDATA[Database credentials are the last door between an attacker and your data. This guide covers eliminating static passwords with IAM auth, scoping least privilege, rotating safely, and detecting leaked connection strings.]]></description>
      <link>https://safeguard.sh/resources/blog/database-credential-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/database-credential-security</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Management Best Practices for Secure Software]]></title>
      <description><![CDATA[Your app is mostly other people's code. A 2026 guide to managing dependencies securely — lockfiles, provenance, SBOMs, update strategy, and reachability — so a bad package doesn't become your breach.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-management-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-management-best-practices</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Management: Frequently Asked Questions]]></title>
      <description><![CDATA[A practical FAQ on managing software dependencies in 2026 — direct vs transitive, lockfiles, semantic versioning, safe updates, dependency confusion, and keeping trees clean.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-management-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-management-faq</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Fastjson AutoType Bypass RCE (CVE-2022-25845) Explained]]></title>
      <description><![CDATA[CVE-2022-25845 defeated Fastjson's autoType protection and reopened a deserialization RCE path. Here's how the bypass worked and how to lock the library down.]]></description>
      <link>https://safeguard.sh/resources/blog/fastjson-rce-cve-2022-25845-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fastjson-rce-cve-2022-25845-explained</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Follina (CVE-2022-30190) Explained: Code Execution From a Word Document With Macros Off]]></title>
      <description><![CDATA[CVE-2022-30190, Follina, abused the Windows MSDT protocol handler so a Word document could run PowerShell — no macros, no enable-content click. Here is the ms-msdt mechanism.]]></description>
      <link>https://safeguard.sh/resources/blog/follina-cve-2022-30190-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/follina-cve-2022-30190-explained</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[FortiOS CVE-2024-21762 Explained: The SSL VPN Out-of-Bounds Write RCE]]></title>
      <description><![CDATA[CVE-2024-21762 is a pre-authentication out-of-bounds write in the FortiOS SSL VPN daemon that allows remote code execution. Here is the timeline, root cause, detection, and the full list of fixed versions.]]></description>
      <link>https://safeguard.sh/resources/blog/fortios-cve-2024-21762-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fortios-cve-2024-21762-explained</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[GCP IAM Best Practices: Least Privilege on Google Cloud]]></title>
      <description><![CDATA[Principle-driven Google Cloud IAM guidance: avoiding primitive roles, service account hygiene, Workload Identity Federation, the IAM Recommender, and inheritance — with gcloud and Terraform examples.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-iam-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-iam-best-practices</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Go Code Review Tools: An Honest 2026 Buyer's Guide]]></title>
      <description><![CDATA[A balanced 2026 comparison of Go code review and static-analysis tools — go vet, staticcheck, golangci-lint, gosec, govulncheck, Semgrep, CodeQL — with honest tradeoffs and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/go-code-review-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-code-review-tools</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Go Vulnerability Scanning Guide: govulncheck, Reachability, and CI]]></title>
      <description><![CDATA[Most scanners tell you a CVE exists somewhere in go.sum. govulncheck tells you whether your code can actually reach it. Here's how Go's reachability-based scanning works and how to run it well.]]></description>
      <link>https://safeguard.sh/resources/blog/go-vulnerability-scanning-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-vulnerability-scanning-guide</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Gradle Dependency Security: Locking, Verification, and Version Catalogs]]></title>
      <description><![CDATA[Secure Gradle builds in 2026 with dependency locking, cryptographic dependency verification, version catalogs, and reachability-aware CVE scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/gradle-dependency-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gradle-dependency-security</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI FAQ: Autonomous Remediation Explained]]></title>
      <description><![CDATA[Everything teams ask about Griffin AI — Safeguard's autonomous remediation engine — including how it fixes vulnerabilities, tests compatibility, and stays safe to trust.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-faq</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[The HIPAA Security Rule for Software Teams: Safeguards, Structure, and Change Ahead]]></title>
      <description><![CDATA[The HIPAA Security Rule is technology-neutral by design, but its administrative, physical, and technical safeguards translate into concrete engineering work. Here's how the rule is structured and how a proposed 2025 overhaul could tighten it.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-security-rule-for-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-security-rule-for-software</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Choose an SCA Tool (2026): An Honest FAQ]]></title>
      <description><![CDATA[A practical 2026 FAQ on choosing a software composition analysis tool — the criteria that matter, how the major vendors differ, and how to run a trial on your own repos.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-choose-an-sca-tool-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-choose-an-sca-tool-faq</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Get Into Software Supply Chain Security]]></title>
      <description><![CDATA[Software supply chain security is one of the hottest specialties in the field—and one of the least crowded. Here is how students and career-changers can break into it, from the core concepts to a portfolio that stands out.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-get-into-software-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-get-into-software-supply-chain-security</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Career</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Scan for Secrets in a Git Repository]]></title>
      <description><![CDATA[Find hardcoded API keys, tokens, and credentials in your working tree and full Git history, stop new leaks at commit time, and remediate a secret that has already been pushed.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-scan-for-secrets-in-git</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-scan-for-secrets-in-git</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Update Dependencies Safely]]></title>
      <description><![CDATA[Updating a library can fix a vulnerability or break your app. This beginner guide shows you how to update dependencies safely, one careful step at a time.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-update-dependencies-safely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-update-dependencies-safely</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Introduction to Vulnerability Scanning]]></title>
      <description><![CDATA[Vulnerability scanning is how teams find known weaknesses before attackers do. This guide explains what a scanner actually does, the main types, how a scan works end to end, and how to turn a wall of findings into a short list of things worth fixing.]]></description>
      <link>https://safeguard.sh/resources/blog/introduction-to-vulnerability-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/introduction-to-vulnerability-scanning</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Jackson-databind Security Guide (2026)]]></title>
      <description><![CDATA[Jackson-databind is the default JSON engine for the Java ecosystem — and the source of one of the longest deserialization CVE sagas in open source. Here is how to run it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/jackson-databind-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jackson-databind-security-guide</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Laravel Security Best Practices: Mass Assignment, Blade, and Debug Mode]]></title>
      <description><![CDATA[Laravel's defaults are solid, but $guarded misuse, {!! !!} in Blade, and APP_DEBUG=true in production have all led to real compromises. Here's the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/laravel-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/laravel-security-best-practices</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Lessons from the Codecov Breach: When Your CI Secrets Walk Out the Door]]></title>
      <description><![CDATA[For two months in 2021, Codecov's Bash Uploader quietly exfiltrated CI environment variables. Here is how a single trusted script became a mass credential-harvesting operation.]]></description>
      <link>https://safeguard.sh/resources/blog/lessons-from-codecov-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lessons-from-codecov-breach</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Log Injection: How Attackers Poison Your Logs (and How to Stop Them)]]></title>
      <description><![CDATA[Logs are supposed to be your source of truth during an incident. Log injection lets attackers forge entries, break parsers, and — in the worst cases — trigger code execution from a log line.]]></description>
      <link>https://safeguard.sh/resources/blog/log-injection-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log-injection-prevention</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Security FAQ: Safeguarding AI Agent Tool Access in 2026]]></title>
      <description><![CDATA[Plain answers about securing the Model Context Protocol — what an MCP server exposes, how agents authenticate, the prompt-injection and tool-poisoning risks, and how Safeguard's MCP server fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-security-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-security-faq</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[node-ipc protestware targeting Russia/Belarus IPs]]></title>
      <description><![CDATA[In March 2022, node-ipc's maintainer shipped code wiping files on Russian and Belarusian machines. Here's what happened, how it spread, and how to catch it next time.]]></description>
      <link>https://safeguard.sh/resources/blog/node-ipc-protestware-targeting-russiabelarus-ips</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-ipc-protestware-targeting-russiabelarus-ips</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Scanning NuGet Packages for Vulnerabilities in .NET]]></title>
      <description><![CDATA[The .NET SDK ships a built-in vulnerability scanner: dotnet list package --vulnerable. Here is how to audit NuGet dependencies with it — and where to go beyond it.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-package-vulnerability-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-package-vulnerability-scanning</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[NuGet Supply Chain Security: Protecting Your .NET Dependencies]]></title>
      <description><![CDATA[How NuGet supply chain attacks work, from dependency confusion to typosquatting, and the concrete controls, lock files, source mapping, and signing, that lock down your .NET build.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-supply-chain-security</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[OWASP A06: Vulnerable and Outdated Components — A Deep-Dive Guide]]></title>
      <description><![CDATA[Vulnerable and Outdated Components rank #6 in the OWASP Top 10 (2021). A deep dive into transitive risk, real CVEs like Log4Shell, and how to fix it in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-a06-vulnerable-and-outdated-components</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-a06-vulnerable-and-outdated-components</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Pillow (PIL) Security Guide (2026)]]></title>
      <description><![CDATA[Pillow is the default image library for Python — and because it parses untrusted image bytes and once shipped an eval-based ImageMath, it has a long, real CVE history spanning arbitrary code execution and native buffer overflows.]]></description>
      <link>https://safeguard.sh/resources/blog/pillow-python-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pillow-python-security-guide</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Policy as Code for Security: A Practical Guide]]></title>
      <description><![CDATA[When your security rules live in a wiki, they are advice. When they live in version-controlled code the pipeline enforces, they are controls. Here is how to move security policy into code that actually runs.]]></description>
      <link>https://safeguard.sh/resources/blog/policy-as-code-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/policy-as-code-guide</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Prevent Prototype Pollution in JavaScript]]></title>
      <description><![CDATA[Prototype pollution turns a single crafted JSON key into process-wide corruption — and it has escalated to RCE in real Node.js apps. Here is how the attack works and four layers of defense that stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/prevent-prototype-pollution-javascript</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prevent-prototype-pollution-javascript</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Preventing Command Injection in Python]]></title>
      <description><![CDATA[Every time Python code shells out with user input, an attacker gets a vote on what the shell runs. The fix is almost always to stop using the shell at all.]]></description>
      <link>https://safeguard.sh/resources/blog/python-command-injection-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-command-injection-prevention</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis FAQ: What It Is and Why It Cuts Noise]]></title>
      <description><![CDATA[Reachability analysis decides whether a vulnerable function in a dependency is actually called by your code. Here are the common questions, answered plainly.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-faq</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Remediation Automation FAQ: Policies, Strategies, and Scaling Fixes]]></title>
      <description><![CDATA[How to operationalize remediation automation — automation strategies, severity policies, SLAs, metrics that matter, and how a small team scales fixes across hundreds of repos.]]></description>
      <link>https://safeguard.sh/resources/blog/remediation-automation-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/remediation-automation-faq</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SBOMs and Executive Order 14028: how a 2021 order reshaped software supply chain policy]]></title>
      <description><![CDATA[Executive Order 14028 made the software bill of materials a matter of federal policy. Here's the story of how it happened, what it requires, and what it means for you in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-executive-order-14028-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-executive-order-14028-guide</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Scanning Docker Images in CI/CD Pipelines]]></title>
      <description><![CDATA[Scanning a container after it deploys is an incident report. Scanning it in the pipeline is a one-line diff. Here is how to gate builds on image scans without drowning developers in false positives.]]></description>
      <link>https://safeguard.sh/resources/blog/scanning-docker-images-in-ci-cd</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scanning-docker-images-in-ci-cd</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Secure Defaults, Explained]]></title>
      <description><![CDATA[Secure defaults mean the out-of-the-box configuration is the safe one, and weakening it requires a deliberate opt-in. Here's why the default state decides most real-world security outcomes.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-defaults-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-defaults-explained</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Securing Container Registries: From Push to Pull]]></title>
      <description><![CDATA[Your registry is the single point every image passes through — and a favorite target for attackers who want to poison many deployments at once. Here is how to lock it down end to end.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-container-registries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-container-registries</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Securing the Kubernetes API Server]]></title>
      <description><![CDATA[The API server is the front door to your cluster — every kubectl command, controller, and kubelet talks to it. If it is misconfigured, nothing else you harden matters. Here is how to lock it down.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-kubernetes-api-server</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-kubernetes-api-server</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Shift-Left Security FAQ: 2026 Explained]]></title>
      <description><![CDATA[Common questions about shift-left security answered for 2026 — what it means, why earlier is cheaper, how it works in practice, and how to avoid overwhelming developers.]]></description>
      <link>https://safeguard.sh/resources/blog/shift-left-security-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shift-left-security-faq</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Startups]]></title>
      <description><![CDATA[For a startup, supply chain security is less about compliance mandates and more about closing enterprise deals and surviving the incident that could end you. Here is how to get it right with a small team.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-for-startups-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-for-startups-guide</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Baron Samedit (CVE-2021-3156) Explained: The Sudo Root Overflow]]></title>
      <description><![CDATA[CVE-2021-3156, Baron Samedit, is a heap overflow in sudo that gives any local user root and hid in plain sight for nearly a decade. Here is the root cause, a one-line test, and the patched version.]]></description>
      <link>https://safeguard.sh/resources/blog/sudo-baron-samedit-cve-2021-3156-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sudo-baron-samedit-cve-2021-3156-explained</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Compliance Officers]]></title>
      <description><![CDATA[For compliance officers, supply chain security is an evidence problem before it is a technical one. Here is how to map controls to frameworks, keep evidence current, and pass an audit without turning your engineers into a documentation team.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-for-compliance-officers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-for-compliance-officers</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Symmetric vs Asymmetric Encryption: What's the Difference?]]></title>
      <description><![CDATA[Symmetric encryption uses one shared key for both locking and unlocking. Asymmetric encryption uses a key pair, one public and one private. One is fast; the other solves the key-sharing problem.]]></description>
      <link>https://safeguard.sh/resources/blog/symmetric-vs-asymmetric-encryption</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/symmetric-vs-asymmetric-encryption</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Security Patch]]></title>
      <description><![CDATA[A security patch is a small update that fixes a specific flaw in software. Here is what patches are, why applying them quickly matters, and how teams manage them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-security-patch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-security-patch</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is an Artifact Attestation?]]></title>
      <description><![CDATA[An artifact attestation is a signed, machine-readable claim about a software artifact, bound to it by digest. Here's how the in-toto structure works and what kinds of claims it carries.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-artifact-attestation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-artifact-attestation</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is CSPM? Cloud Security Posture Management Explained]]></title>
      <description><![CDATA[A clear, vendor-neutral explanation of Cloud Security Posture Management — what CSPM does, where it fits, its blind spots, and how build-time scanning complements it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-cspm-cloud-security-posture-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-cspm-cloud-security-posture-management</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Secure SDLC (Secure Software Development Lifecycle)?]]></title>
      <description><![CDATA[A Secure SDLC embeds security activities into every phase of software development — from planning to production — instead of bolting a security review on at the end. Here's what each phase looks like and how to build one.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-secure-sdlc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-secure-sdlc</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is the AGPL License? The Network Copyleft, Explained]]></title>
      <description><![CDATA[The GNU Affero GPL closes the SaaS loophole: it extends copyleft to software used over a network. Here is what AGPLv3 requires, why companies treat it cautiously, and what it means for you.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-agpl-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-agpl-license</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The XZ Utils Backdoor (CVE-2024-3094) Explained: A Near-Miss Supply Chain Catastrophe]]></title>
      <description><![CDATA[CVE-2024-3094 was a deliberately planted backdoor in xz-utils 5.6.0/5.6.1 targeting sshd. It was caught by a 500ms delay one engineer refused to ignore. Here is how the attack worked.]]></description>
      <link>https://safeguard.sh/resources/blog/xz-utils-backdoor-cve-2024-3094-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xz-utils-backdoor-cve-2024-3094-explained</guid>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Windsurf CVE-2025-62353: Path Traversal in Cascade and the IDEsaster Wave]]></title>
      <description><![CDATA[HiddenLayer's CVSS 9.8 Windsurf flaw exfiltrated secrets even with write_to_file on the deny list. The Cascade agent's filesystem trust broke wide open.]]></description>
      <link>https://safeguard.sh/resources/blog/windsurf-cve-2025-62353-path-traversal-cascade</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/windsurf-cve-2025-62353-path-traversal-cascade</guid>
      <pubDate>Sat, 04 Jul 2026 09:45:55 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Software Composition Analysis (SCA) Explained]]></title>
      <description><![CDATA[SCA finds every open-source package in your app — but knowing it's there isn't knowing it's exploitable. Here's what Log4Shell, xz, and Snyk's approach got right and wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/software-composition-analysis-sca-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-composition-analysis-sca-explained</guid>
      <pubDate>Sat, 04 Jul 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[The MCP Registry and the Namespace-Impersonation Problem]]></title>
      <description><![CDATA[The official MCP Registry launched in September 2025 with namespace-bound publishing. We unpack the trust model and what it does — and does not — defend against.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-registry-namespace-impersonation-defense</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-registry-namespace-impersonation-defense</guid>
      <pubDate>Sat, 04 Jul 2026 08:25:28 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CRA Open Source Software Stewards: Article 24's Light-Touch Regime]]></title>
      <description><![CDATA[The CRA's open-source software steward concept under Article 24 creates a distinct, lighter set of obligations for foundations and non-profits supporting commercial OSS.]]></description>
      <link>https://safeguard.sh/resources/blog/cra-open-source-steward-article-24-obligations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cra-open-source-steward-article-24-obligations</guid>
      <pubDate>Sat, 04 Jul 2026 07:05:02 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Shai-Hulud npm worm campaign]]></title>
      <description><![CDATA[A self-replicating npm worm hit 500+ packages in September 2025 and 796 more in November — here's how Shai-Hulud actually spread, stole secrets, and what stops it.]]></description>
      <link>https://safeguard.sh/resources/blog/the-shai-hulud-npm-worm-campaign</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-shai-hulud-npm-worm-campaign</guid>
      <pubDate>Sat, 04 Jul 2026 07:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Container Image Scanning Best Practices]]></title>
      <description><![CDATA[A practical guide to container image scanning: when to scan, what to block, what scanners like Snyk miss, and how to build a policy that actually gets remediated.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-scanning-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-scanning-best-practices</guid>
      <pubDate>Sat, 04 Jul 2026 06:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Black Duck Software Explained: SCA, BDSA, and Independence from Synopsys]]></title>
      <description><![CDATA[Black Duck software is one of the oldest names in software composition analysis, now an independent company again after spinning out of Synopsys in 2024. Here is what it does.]]></description>
      <link>https://safeguard.sh/resources/blog/blackduck-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/blackduck-software</guid>
      <pubDate>Sat, 04 Jul 2026 05:44:35 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Source Code Analyzer: How Static Analysis Finds Real Vulnerabilities]]></title>
      <description><![CDATA[A source code analyzer reads your code without running it to find bugs and security flaws early. Here is how it works, what it catches, and how to run one without drowning in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/source-code-analyzer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/source-code-analyzer</guid>
      <pubDate>Sat, 04 Jul 2026 04:24:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SHA1-Hulud second-wave npm supply chain incident]]></title>
      <description><![CDATA[Shai-Hulud's November 2025 second wave hit npm via a Bun-based worm, stealing cloud creds and re-publishing trojanized packages at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/sha1-hulud-second-wave-npm-supply-chain-incident</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sha1-hulud-second-wave-npm-supply-chain-incident</guid>
      <pubDate>Sat, 04 Jul 2026 04:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Cosign v2.6: New Bundle Format and Trusted Root]]></title>
      <description><![CDATA[Sigstore's Cosign v2.6 unlocks offline verification, in-toto statement signing, and trusted-root portability. We walk through the new --new-bundle-format flag end-to-end.]]></description>
      <link>https://safeguard.sh/resources/blog/cosign-v2-6-new-bundle-format-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cosign-v2-6-new-bundle-format-2025</guid>
      <pubDate>Sat, 04 Jul 2026 03:03:42 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Dependabot alerts vs CodeQL analysis: what's the difference]]></title>
      <description><![CDATA[Dependabot flags known vulnerabilities in dependencies; CodeQL finds flaws in your own code. Here's how the two differ inside GitHub Advanced Security.]]></description>
      <link>https://safeguard.sh/resources/blog/dependabot-alerts-vs-codeql-analysis-whats-the-difference</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependabot-alerts-vs-codeql-analysis-whats-the-difference</guid>
      <pubDate>Sat, 04 Jul 2026 03:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Fix a Vulnerable Transitive Dependency in npm]]></title>
      <description><![CDATA[The CVE is four levels deep in a package you never installed. Four escalating fixes — parent upgrade, npm update, overrides, and forking — with the exact commands.]]></description>
      <link>https://safeguard.sh/resources/blog/fix-vulnerable-transitive-dependency-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fix-vulnerable-transitive-dependency-npm</guid>
      <pubDate>Sat, 04 Jul 2026 01:43:15 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Mini Shai-Hulud hits TanStack npm packages]]></title>
      <description><![CDATA[TeamPCP's Mini Shai-Hulud worm hijacked 42 TanStack npm packages via stolen GitHub OIDC tokens, spreading to 169 packages with valid SLSA attestations.]]></description>
      <link>https://safeguard.sh/resources/blog/mini-shai-hulud-hits-tanstack-npm-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mini-shai-hulud-hits-tanstack-npm-packages</guid>
      <pubDate>Sat, 04 Jul 2026 01:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Agile Security Operations PDF Free Download: Legit Sources and Key Takeaways]]></title>
      <description><![CDATA[Looking for an Agile Security Operations PDF free download? Here is how to get it legitimately and the ideas that make the book worth reading.]]></description>
      <link>https://safeguard.sh/resources/blog/agile-security-operations-pdf-free-download</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agile-security-operations-pdf-free-download</guid>
      <pubDate>Sat, 04 Jul 2026 00:22:48 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CodeQL default setup vs advanced setup for code scanning]]></title>
      <description><![CDATA[CodeQL's default setup is fast but limited; advanced setup adds control but more YAML to maintain. Here's how the two compare, and where Safeguard fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/codeql-default-setup-vs-advanced-setup-for-code-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/codeql-default-setup-vs-advanced-setup-for-code-scanning</guid>
      <pubDate>Sat, 04 Jul 2026 00:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[XXE Prevention in C# by Disabling XmlResolver/DTD Processing]]></title>
      <description><![CDATA[XXE in C# lives at the XmlResolver and DtdProcessing settings. Here's how .NET's defaults evolved since 2014 and exactly how to lock down XmlDocument, XmlTextReader, and XmlReaderSettings.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-prevention-in-c-by-disabling-xmlresolverdtd-processing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-prevention-in-c-by-disabling-xmlresolverdtd-processing</guid>
      <pubDate>Fri, 03 Jul 2026 23:02:21 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is OSV (Open Source Vulnerabilities)?]]></title>
      <description><![CDATA[OSV is an open, ecosystem-native vulnerability database that expresses affected versions in precise, machine-matchable ranges. Here is how it works and why scanners rely on it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-osv-open-source-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-osv-open-source-vulnerabilities</guid>
      <pubDate>Fri, 03 Jul 2026 21:41:55 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes SecurityContext: The Settings That Matter]]></title>
      <description><![CDATA[A pod's securityContext decides whether a compromised container is contained or a launchpad. Here are the fields that actually reduce blast radius — and the copy-paste block that sets a hardened baseline.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-securitycontext-settings-that-matter</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-securitycontext-settings-that-matter</guid>
      <pubDate>Fri, 03 Jul 2026 20:21:28 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[XXE Prevention in Go with decoder.DisallowDTD]]></title>
      <description><![CDATA[Go's standard XML parser resists classic XXE by design, but cgo bindings and SAML libraries can reopen it. Here's how the DisallowDTD pattern closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-prevention-in-go-with-decoderdisallowdtd</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-prevention-in-go-with-decoderdisallowdtd</guid>
      <pubDate>Fri, 03 Jul 2026 19:01:01 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[XXE Prevention in PHP with libxml_disable_entity_loader]]></title>
      <description><![CDATA[libxml_disable_entity_loader() looked like the fix for XXE in PHP, but PHP 8.0 deprecated it. Here's what it did, why it broke, and what to use now.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-prevention-in-php-with-libxmldisableentityloader</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-prevention-in-php-with-libxmldisableentityloader</guid>
      <pubDate>Fri, 03 Jul 2026 17:40:35 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Insecure Deserialization Prevention in Java with Deserial...]]></title>
      <description><![CDATA[Java deserialization RCEs still hit production years after JEP 290 shipped filters. Here's how JEP 290/415 filters work, common rollout mistakes, and how Safeguard closes the gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/insecure-deserialization-prevention-in-java-with-deserialization-filters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insecure-deserialization-prevention-in-java-with-deserialization-filters</guid>
      <pubDate>Fri, 03 Jul 2026 16:20:08 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Misconfiguration Prevention: Stop Breaches Before They Ship]]></title>
      <description><![CDATA[Misconfiguration is the leading cause of cloud breaches, and it has no CVE and no patch. Here's a taxonomy of the common ones and a shift-left playbook to prevent them.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-misconfiguration-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-misconfiguration-prevention</guid>
      <pubDate>Fri, 03 Jul 2026 15:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Securing the Go Modules Supply Chain: Proxy, Checksums, and Provenance End to End]]></title>
      <description><![CDATA[The Go module system ships with a tamper-evident checksum log and a public proxy most teams never configure deliberately. Here's how to turn those defaults into a real supply-chain control plane.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-go-modules-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-go-modules-supply-chain</guid>
      <pubDate>Fri, 03 Jul 2026 15:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Snyk in the Gartner Magic Quadrant: What the 2025 AST Placement Means]]></title>
      <description><![CDATA[Snyk was named a Leader in the 2025 Gartner Magic Quadrant for Application Security Testing. Here is what that placement does and does not tell buyers.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-gartner-magic-quadrant</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-gartner-magic-quadrant</guid>
      <pubDate>Fri, 03 Jul 2026 14:59:41 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[RAG Poisoning: Defenses That Work]]></title>
      <description><![CDATA[Retrieval-augmented generation is the most common LLM deployment pattern in the enterprise and the most commonly poisoned. A senior security engineer's playbook for defences that hold up in production.]]></description>
      <link>https://safeguard.sh/resources/blog/retrieval-augmented-generation-poisoning-defenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/retrieval-augmented-generation-poisoning-defenses</guid>
      <pubDate>Fri, 03 Jul 2026 13:39:15 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Insecure Deserialization Prevention in JavaScript: Avoidi...]]></title>
      <description><![CDATA[How the node-serialize RCE flaw (CVE-2017-5941) works, why unsafe JS deserialization patterns persist, and concrete steps—plus how Safeguard catches them in CI.]]></description>
      <link>https://safeguard.sh/resources/blog/insecure-deserialization-prevention-in-javascript-avoiding-node-serialize</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insecure-deserialization-prevention-in-javascript-avoiding-node-serialize</guid>
      <pubDate>Fri, 03 Jul 2026 12:18:48 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Insecure Deserialization Prevention in Python: yaml.safe_...]]></title>
      <description><![CDATA[Why yaml.load() and pickle.load() became RCE vectors in Python, the CVEs behind them, and how safe_load() closes the gap — plus how Safeguard catches unsafe deserialization before it ships.]]></description>
      <link>https://safeguard.sh/resources/blog/insecure-deserialization-prevention-in-python-yamlsafeload-vs-pickle</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insecure-deserialization-prevention-in-python-yamlsafeload-vs-pickle</guid>
      <pubDate>Fri, 03 Jul 2026 10:58:21 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[AI Code Review Tools Compared: An Honest 2026 Guide]]></title>
      <description><![CDATA[A balanced 2026 comparison of AI code review tools — GitHub Copilot, CodeRabbit, Qodo, Graphite, Amazon Q, Snyk DeepCode — with honest tradeoffs, the security gap, and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-code-review-tools-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-code-review-tools-compared</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AIBOM (AI Bill of Materials): Frequently Asked Questions]]></title>
      <description><![CDATA[A practical FAQ on AI bills of materials in 2026 — what an AIBOM captures, how it extends SBOMs to models and datasets, model provenance risks, formats, and governance drivers.]]></description>
      <link>https://safeguard.sh/resources/blog/aibom-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aibom-faq</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[An Application Security Learning Path for 2026]]></title>
      <description><![CDATA[A phase-by-phase learning path into application security, built for students and career-changers. Foundations, offense, defense, tooling, and a portfolio—mostly free, and structured so you always know the next step.]]></description>
      <link>https://safeguard.sh/resources/blog/appsec-learning-path-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/appsec-learning-path-2026</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Career</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AWS IAM Security Best Practices: A 2026 Field Guide]]></title>
      <description><![CDATA[IAM is where most AWS breaches actually happen. This field guide covers least privilege, role assumption, permission boundaries, and the policy patterns that keep blast radius small.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-iam-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-iam-security-best-practices</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Azure IAM and RBAC Best Practices]]></title>
      <description><![CDATA[A question-driven guide to Azure identity and access management: Entra ID vs Azure RBAC, scoping assignments, managed identities, PIM, and Conditional Access — with az CLI and Terraform examples.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-iam-rbac-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-iam-rbac-best-practices</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[The Best Cloud Security Tools in 2026]]></title>
      <description><![CDATA[Cloud security spans posture, workloads, identities, and the software you ship. This balanced guide compares Wiz, Prisma Cloud, Microsoft Defender for Cloud, Orca, and Sysdig — and is honest about the slice a supply-chain tool covers.]]></description>
      <link>https://safeguard.sh/resources/blog/best-cloud-security-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-cloud-security-tools-2026</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best DAST Tools in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced 2026 comparison of the leading dynamic application security testing tools — OWASP ZAP, Burp Suite, Invicti, Rapid7 InsightAppSec, StackHawk, and Bright — with an honest look at where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/best-dast-tools-2026-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-dast-tools-2026-2026</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Auditing Rust Dependencies with cargo-audit]]></title>
      <description><![CDATA[cargo-audit checks your Cargo.lock against the RustSec Advisory Database, flagging vulnerable, yanked, and unmaintained crates. Here is how to use it and extend it.]]></description>
      <link>https://safeguard.sh/resources/blog/cargo-audit-rust-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cargo-audit-rust-dependencies</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Cisco IOS XE CVE-2023-20198 Explained: The Web UI Privilege Escalation Zero-Day]]></title>
      <description><![CDATA[CVE-2023-20198 is an unauthenticated privilege escalation in the Cisco IOS XE Web UI, rated CVSS 10.0, that let attackers implant tens of thousands of devices in days. Here is how it worked and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/cisco-ios-xe-cve-2023-20198-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisco-ios-xe-cve-2023-20198-explained</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CMMC 2.0 Explained: What Defense Contractors and Their Software Must Do]]></title>
      <description><![CDATA[CMMC 2.0 turns NIST SP 800-171 into a certification requirement for the defense supply chain. Here's how the three levels work, who assesses them, and where your software components fit.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-2-0-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-2-0-explained</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Container Security for Beginners: Keeping Your Docker Images Safe]]></title>
      <description><![CDATA[Containers made shipping software wonderfully simple, but they also package up whatever risks come along for the ride. Here is a beginner-friendly introduction with a first image scan you can run today.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-for-beginners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-for-beginners</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps FAQ: Practical Answers for 2026]]></title>
      <description><![CDATA[Straight answers to common DevSecOps questions in 2026 — what it means, how it differs from DevOps, where security fits in CI/CD, and how to avoid slowing developers down.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-faq</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Preventing SQL Injection in .NET with Entity Framework Core]]></title>
      <description><![CDATA[How SQL injection still happens in Entity Framework Core apps, which EF Core APIs are safe by default, which ones aren't, and the exact patterns that keep raw SQL parameterized.]]></description>
      <link>https://safeguard.sh/resources/blog/dotnet-sql-injection-prevention-entity-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dotnet-sql-injection-prevention-entity-framework</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Drupalgeddon2 (CVE-2018-7600) Explained: Drupal's Form API RCE]]></title>
      <description><![CDATA[CVE-2018-7600, known as Drupalgeddon2, is a CVSS 9.8 unauthenticated remote code execution flaw in Drupal core's Form API. Here is how the renderable-array bug works and which versions to run.]]></description>
      <link>https://safeguard.sh/resources/blog/drupalgeddon2-cve-2018-7600-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/drupalgeddon2-cve-2018-7600-explained</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Encryption vs Hashing: What's the Difference?]]></title>
      <description><![CDATA[Encryption scrambles data so it can be unscrambled later with a key. Hashing turns data into a fixed fingerprint that can never be reversed. One protects secrets; the other verifies them.]]></description>
      <link>https://safeguard.sh/resources/blog/encryption-vs-hashing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/encryption-vs-hashing</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[EU Cyber Resilience Act FAQ: Timelines, SBOMs, and Reporting Duties]]></title>
      <description><![CDATA[A precise FAQ on the EU Cyber Resilience Act in 2026 — what it covers, the phased 2026 and 2027 deadlines, the SBOM requirement, 24-hour vulnerability reporting, risk classes, and penalties.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cyber-resilience-act-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cyber-resilience-act-faq</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP and the software supply chain: a 2026 guide]]></title>
      <description><![CDATA[FedRAMP authorization increasingly hinges on how you secure your software supply chain. Here's how the SR control family, SBOMs, and SSDF attestation fit together.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-software-supply-chain-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-software-supply-chain-guide</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Token Security (2026 Guide)]]></title>
      <description><![CDATA[GitHub tokens are keys to your source, your CI, and often your cloud. This guide covers PATs, fine-grained tokens, GitHub App and Actions tokens — and how to scope, store, and rotate them after the CircleCI and Heroku token thefts.]]></description>
      <link>https://safeguard.sh/resources/blog/github-token-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-token-security</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection in Go: Why database/sql Is Safe Until You Reach for Sprintf]]></title>
      <description><![CDATA[database/sql gives Go parameterized queries for free — yet SQL injection still ships in Go services through dynamic query building, ORM escape hatches, and misused identifiers. Here's the line you can't cross.]]></description>
      <link>https://safeguard.sh/resources/blog/go-sql-injection-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-sql-injection-prevention</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Auditing Go Modules with govulncheck]]></title>
      <description><![CDATA[govulncheck is unusual: it uses static analysis to tell you not just which Go dependencies are vulnerable, but whether your code actually reaches the vulnerable function.]]></description>
      <link>https://safeguard.sh/resources/blog/govulncheck-go-modules-audit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/govulncheck-go-modules-audit</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Safeguard Works: FAQ on the Scan-to-Fix Workflow]]></title>
      <description><![CDATA[A step-by-step FAQ on how Safeguard works under the hood — from dependency discovery and reachability analysis to autonomous fix pull requests and policy gates.]]></description>
      <link>https://safeguard.sh/resources/blog/how-safeguard-works-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-safeguard-works-faq</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Add Security Scanning to Your CI/CD Pipeline]]></title>
      <description><![CDATA[Wire dependency, container, and secret scanning into GitHub Actions or GitLab CI as a required check that blocks risky merges — with working workflow files and sensible thresholds.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-add-security-scanning-to-ci-cd</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-add-security-scanning-to-ci-cd</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Read an SBOM]]></title>
      <description><![CDATA[An SBOM is a list of everything inside your software. This beginner guide shows you how to open one, understand each field, and turn it into something useful.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-read-an-sbom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-read-an-sbom</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[HTTP Security Headers Explained (2026)]]></title>
      <description><![CDATA[HTTP security headers are the cheapest defense-in-depth you can ship. Here is what each one does, the values to set in 2026, and how to verify they are actually present.]]></description>
      <link>https://safeguard.sh/resources/blog/http-security-headers-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/http-security-headers-explained</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 Annex A controls guide: the software and supplier set]]></title>
      <description><![CDATA[ISO/IEC 27001:2022 restructured Annex A into 93 controls and added new ones for secure development and supply chain. Here is the subset that lands on engineering teams and how to evidence it.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-annex-a-controls-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-annex-a-controls-guide</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Jackson-databind Polymorphic Deserialization Gadget (CVE-2019-12384) Explained]]></title>
      <description><![CDATA[CVE-2019-12384 chained a logback gadget with H2's RUNSCRIPT to turn default typing into code execution. Here's the mechanism, the classpath caveat, and how to fix it for good.]]></description>
      <link>https://safeguard.sh/resources/blog/jackson-databind-cve-2019-12384-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jackson-databind-cve-2019-12384-explained</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript & TypeScript Code Review Tools: An Honest 2026 Guide]]></title>
      <description><![CDATA[A balanced 2026 comparison of JavaScript and TypeScript code review tools — ESLint, Biome, Semgrep, CodeQL, SonarQube, Snyk Code — with honest tradeoffs and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-code-review-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-code-review-tools</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Jenkins Pipeline Security: Hardening the Controller and Your Builds]]></title>
      <description><![CDATA[Jenkins is a favorite target because the controller holds every credential and runs arbitrary Groovy. This guide covers CVE-2024-23897, the plugin attack surface, credential handling, ephemeral agents, and adding scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-pipeline-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-pipeline-security</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[JWT Security Vulnerabilities and How to Avoid Them]]></title>
      <description><![CDATA[JSON Web Tokens are only as safe as how you verify them. The alg:none trick, RS256-to-HS256 confusion, and weak secrets have all led to full auth bypass.]]></description>
      <link>https://safeguard.sh/resources/blog/jwt-security-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jwt-security-vulnerabilities</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes RBAC Security: Least Privilege That Actually Holds]]></title>
      <description><![CDATA[Wildcard verbs, cluster-admin bindings, and forgotten service account tokens turn RBAC into a rubber stamp. Here is how to design roles that contain a breach instead of amplifying it.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-rbac-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-rbac-security</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Lessons from the XZ Utils Backdoor: A Three-Year Social Engineering Heist]]></title>
      <description><![CDATA[CVE-2024-3094 was a backdoor patiently planted in XZ Utils over years of social engineering, caught by an engineer chasing half a second of SSH latency. Here is the full story.]]></description>
      <link>https://safeguard.sh/resources/blog/lessons-from-xz-utils-backdoor</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lessons-from-xz-utils-backdoor</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[LLM Jailbreak Prevention: A Defense-in-Depth Playbook]]></title>
      <description><![CDATA[A jailbreak is not the same thing as a prompt injection, and conflating them leads to defenses that miss. Here is how modern jailbreaks actually work and the layered controls that hold the line.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-jailbreak-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-jailbreak-prevention</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Maintainer Account Takeover Attacks: Hijacking Trust in Open Source]]></title>
      <description><![CDATA[A maintainer account takeover lets an attacker publish malicious versions of a trusted package under a legitimate identity. Here is how it happens and how to defend.]]></description>
      <link>https://safeguard.sh/resources/blog/maintainer-account-takeover-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maintainer-account-takeover-attacks</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Maven Dependency Security: Pinning, Verification, and Scanning]]></title>
      <description><![CDATA[How to secure a Maven build in 2026 — pin versions, enforce convergence, verify artifacts, and scan the transitive tree that pom.xml never shows you.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-dependency-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-dependency-security</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Mini Shai-Hulud AntV npm packages compromise]]></title>
      <description><![CDATA[A compromised npm maintainer account pushed 639 malicious @antv package versions in 10 minutes, stealing CI/CD secrets via a fake OpenTelemetry channel.]]></description>
      <link>https://safeguard.sh/resources/blog/mini-shai-hulud-antv-npm-packages-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mini-shai-hulud-antv-npm-packages-compromise</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Preventing SSRF in Node.js Applications]]></title>
      <description><![CDATA[Server-Side Request Forgery is the bug that turns a harmless URL field into a doorway to your cloud metadata service. Here is how SSRF works in Node.js and how to shut it down with allowlists and DNS-safe validation.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-ssrf-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-ssrf-prevention</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[OWASP A05: Security Misconfiguration — A Deep-Dive Guide]]></title>
      <description><![CDATA[Security Misconfiguration ranks #5 in the OWASP Top 10 (2021) and absorbed XXE. A deep dive into defaults, exposed services, real CVEs, and how to fix them.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-a05-security-misconfiguration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-a05-security-misconfiguration</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[pandas Security Guide (2026)]]></title>
      <description><![CDATA[pandas is the backbone of Python data analysis — and while its own CVE record is thin, the read_pickle deserialization risk is real, the query/eval expression engine invites injection, and most 'pandas findings' actually live in its dependency tree.]]></description>
      <link>https://safeguard.sh/resources/blog/pandas-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pandas-security-guide</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Pod Security Standards: The Complete Guide]]></title>
      <description><![CDATA[PodSecurityPolicy is gone. Pod Security Admission and the three Pod Security Standards are how you enforce baseline and restricted profiles in modern Kubernetes — here is how to adopt them without breaking workloads.]]></description>
      <link>https://safeguard.sh/resources/blog/pod-security-standards-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pod-security-standards-guide</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[PrintNightmare (CVE-2021-34527) Explained: When the Windows Print Spooler Ran Code as SYSTEM]]></title>
      <description><![CDATA[CVE-2021-34527, PrintNightmare, let an authenticated attacker load a malicious printer driver through the Windows Print Spooler and execute code as SYSTEM — locally or across a domain.]]></description>
      <link>https://safeguard.sh/resources/blog/printnightmare-cve-2021-34527-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/printnightmare-cve-2021-34527-explained</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Prompt Injection Prevention: A Defense-in-Depth Guide]]></title>
      <description><![CDATA[Prompt injection is the top risk on the OWASP list for LLM applications for a reason: there is no single patch. Preventing it means layering controls around a model that cannot reliably tell instructions from data.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-prevention-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-prevention-guide</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Preventing SQL Injection in Python]]></title>
      <description><![CDATA[SQL injection is decades old and still ships to production. In Python it almost always comes down to one habit: building query strings instead of passing parameters.]]></description>
      <link>https://safeguard.sh/resources/blog/python-sql-injection-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-sql-injection-prevention</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Rails Security Best Practices: Strong Parameters, SQL, and Gems]]></title>
      <description><![CDATA[Rails ships secure defaults, but mass assignment, string-interpolated SQL, and unvetted gems still cause real breaches. Here is how to hold the line.]]></description>
      <link>https://safeguard.sh/resources/blog/rails-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rails-security-best-practices</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Reducing the Attack Surface of Your Docker Images]]></title>
      <description><![CDATA[Every binary, library, and shell in a Docker image is attack surface. Here is how to strip an image down to the bytes your app actually needs — and cut your CVE count by up to 95%.]]></description>
      <link>https://safeguard.sh/resources/blog/reducing-docker-image-attack-surface</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reducing-docker-image-attack-surface</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Requests (Python) Security Guide (2026)]]></title>
      <description><![CDATA[The Requests library is how most Python code talks HTTP — and a recurring class of credential-leak-on-redirect CVEs makes its version and config genuinely security-relevant.]]></description>
      <link>https://safeguard.sh/resources/blog/requests-python-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/requests-python-security-guide</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard's $1 Starter Plan: FAQ on What You Get for a Dollar]]></title>
      <description><![CDATA[Everything about Safeguard's $1 Starter plan — what one dollar connects, what's included, what's not, and when to upgrade to autonomous remediation and compliance packs.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-1-dollar-starter-plan-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-1-dollar-starter-plan-faq</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SBOMs in the CI/CD Pipeline: From Generation to Actually Useful]]></title>
      <description><![CDATA[Generating an SBOM is easy. Making it answer 'are we affected by this CVE, and where?' in seconds is the part most teams skip. Here is how to build SBOMs into your pipeline so they earn their keep.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-in-ci-cd-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-in-ci-cd-pipeline</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Secure Code Review Checklist Every Team Should Use]]></title>
      <description><![CDATA[A practical secure code review checklist for 2026 — what to look for in auth, input handling, secrets, dependencies, and business logic, plus how to scale review with automation and AI.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-code-review-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-code-review-checklist</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SMTP Injection (Email Header Injection): Prevention Guide]]></title>
      <description><![CDATA[A contact form that builds emails from user input can be turned into a spam relay or a phishing generator through SMTP header injection. Here's how the attack works and how to neutralize it.]]></description>
      <link>https://safeguard.sh/resources/blog/smtp-injection-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/smtp-injection-prevention</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Alternatives (2026): An Honest FAQ]]></title>
      <description><![CDATA[A fair 2026 FAQ on Snyk alternatives — why teams look, how Black Duck, Mend, Sonatype, Socket, Trivy, and Safeguard compare, and how to migrate without regret.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-alternatives-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-alternatives-faq</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Sonatype: A Neutral Comparison for 2026]]></title>
      <description><![CDATA[Snyk and Sonatype both secure open-source dependencies, but one leads with developer workflow and the other with repository governance and a component firewall. An honest side-by-side, plus a third option.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-sonatype</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-sonatype</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Government]]></title>
      <description><![CDATA[Executive Order 14028, OMB self-attestation, the CISA attestation form, NIST SSDF, and FedRAMP have made secure software development a condition of selling to government. Here is what agencies and their vendors need.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-for-government</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-for-government</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for AppSec Leads]]></title>
      <description><![CDATA[AppSec leads own the program that turns scanner noise into fixed risk. Here is how to consolidate tooling, prioritize by reachability, win developer trust, and measure a program by remediation velocity instead of finding count.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-for-appsec-leads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-for-appsec-leads</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for DevOps Teams]]></title>
      <description><![CDATA[DevOps teams own the pipeline, and the pipeline is now the primary target. Here is how to secure build, artifact, and deploy without turning delivery speed into collateral damage.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-for-devops-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-for-devops-teams</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Swift and iOS Security Best Practices: Storage, Transport, and the Dependency Supply Chain]]></title>
      <description><![CDATA[iOS gives you a hardware-backed Keychain, Data Protection, and App Transport Security. Most iOS app breaches come from switching those defaults off — and from unaudited SwiftPM dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/swift-ios-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/swift-ios-security-best-practices</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Understanding SBOM Formats]]></title>
      <description><![CDATA[A software bill of materials is only useful if tools can read it. Two standards dominate — SPDX and CycloneDX — and knowing what each captures, how they differ, and when to use which is the difference between an inventory that works and one that gathers dust.]]></description>
      <link>https://safeguard.sh/resources/blog/understanding-sbom-formats</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/understanding-sbom-formats</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Veracode Alternatives in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced comparison of the top Veracode alternatives in 2026 — Checkmarx, Snyk, OpenText Fortify, Semgrep, GitHub Advanced Security, and Safeguard — with candid pros, cons, and a way to choose.]]></description>
      <link>https://safeguard.sh/resources/blog/veracode-alternatives-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/veracode-alternatives-2026</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[WebP (CVE-2023-4863) Explained: The libwebp Heap Overflow That Patched the Web]]></title>
      <description><![CDATA[CVE-2023-4863 was an actively exploited heap buffer overflow in libwebp's Huffman decoder. Because the codec is vendored everywhere, one bug forced emergency patches across browsers and apps.]]></description>
      <link>https://safeguard.sh/resources/blog/webp-cve-2023-4863-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webp-cve-2023-4863-explained</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Software Dependency]]></title>
      <description><![CDATA[A software dependency is outside code your program relies on to run. Here is what dependencies are, why modern apps have so many, and why they matter for security.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-software-dependency</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-software-dependency</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is Open Source License Compliance?]]></title>
      <description><![CDATA[Open source license compliance is the practice of tracking every open source component you use and honoring the legal obligations of its license. Get it wrong and you risk lawsuits, forced code disclosure, or a blocked acquisition.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-open-source-license-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-open-source-license-compliance</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is Software Provenance?]]></title>
      <description><![CDATA[Software provenance is the verifiable record of where an artifact came from and how it was built. Here's what a provenance record contains, how it is proven, and why it stops build-time tampering.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-software-provenance-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-software-provenance-explained</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is the Mozilla Public License (MPL 2.0)?]]></title>
      <description><![CDATA[The Mozilla Public License 2.0 is a file-level copyleft license that sits between permissive and strong copyleft. Here is how its per-file reciprocity works and what it means for your project.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-mozilla-public-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-mozilla-public-license</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Zero Trust Architecture, Explained]]></title>
      <description><![CDATA[Zero trust replaces the trusted internal network with a model that verifies every request explicitly, regardless of where it comes from. Here's what it actually means and how to move toward it.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-trust-architecture-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-trust-architecture-explained</guid>
      <pubDate>Fri, 03 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Secure Random Number Generation in JavaScript with crypto...]]></title>
      <description><![CDATA[Math.random() is predictable and unsafe for security tokens. Here's why Node's crypto.randomBytes() is the standard for secure JavaScript randomness.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-random-number-generation-in-javascript-with-cryptorandombytes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-random-number-generation-in-javascript-with-cryptorandombytes</guid>
      <pubDate>Fri, 03 Jul 2026 09:37:55 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Advisory Database: 30,000+ curated advisories beyo...]]></title>
      <description><![CDATA[GitHub's Advisory Database curates 30,000+ entries beyond raw CVE data. Here's what it actually covers, where GHAS inherits its limits, and where correlation across sources closes the gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/github-advisory-database-30000-curated-advisories-beyond-raw-cve-data</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-advisory-database-30000-curated-advisories-beyond-raw-cve-data</guid>
      <pubDate>Fri, 03 Jul 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Secure Random Number Generation in Python with the secret...]]></title>
      <description><![CDATA[Python's random module is predictable, not secure. Here's why CWE-338 matters, when the secrets module (PEP 506, Python 3.6) fixed it, and how to generate tokens safely.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-random-number-generation-in-python-with-the-secrets-module</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-random-number-generation-in-python-with-the-secrets-module</guid>
      <pubDate>Fri, 03 Jul 2026 08:17:28 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[tj-actions/changed-files GitHub Action compromise]]></title>
      <description><![CDATA[How the tj-actions/changed-files GitHub Action compromise (CVE-2025-30066) leaked CI/CD secrets from 23,000+ repos, and how to prevent it.]]></description>
      <link>https://safeguard.sh/resources/blog/tj-actionschanged-files-github-action-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tj-actionschanged-files-github-action-compromise</guid>
      <pubDate>Fri, 03 Jul 2026 07:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Secure Random Number Generation in Ruby with SecureRandom]]></title>
      <description><![CDATA[Ruby's built-in rand() uses a predictable Mersenne Twister and should never generate tokens, passwords, or session IDs. Here's how SecureRandom fixes that.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-random-number-generation-in-ruby-with-securerandom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-random-number-generation-in-ruby-with-securerandom</guid>
      <pubDate>Fri, 03 Jul 2026 06:57:01 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Advanced Security alternatives: why teams look bey...]]></title>
      <description><![CDATA[GitHub Advanced Security works well inside GitHub — but multi-SCM estates, independent CVE data needs, and AI-agent workflows push teams to look further. Here's a grounded comparison.]]></description>
      <link>https://safeguard.sh/resources/blog/github-advanced-security-alternatives-why-teams-look-beyond-ghas-for-appsec</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-advanced-security-alternatives-why-teams-look-beyond-ghas-for-appsec</guid>
      <pubDate>Fri, 03 Jul 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Secure Random Number Generation in PHP with random_bytes]]></title>
      <description><![CDATA[PHP's mt_rand() has a 32-bit seed space attackers can crack in seconds. Here's why random_bytes() and random_int() replaced it in PHP 7.0, and how weak randomness still causes breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-random-number-generation-in-php-with-randombytes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-random-number-generation-in-php-with-randombytes</guid>
      <pubDate>Fri, 03 Jul 2026 05:36:34 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Secure Random Number Generation in Go with crypto/rand]]></title>
      <description><![CDATA[Go's math/rand is fast but predictable. Here's why crypto/rand is the only safe choice for tokens, keys, and nonces -- and what changed in Go 1.20-1.24.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-random-number-generation-in-go-with-cryptorand</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-random-number-generation-in-go-with-cryptorand</guid>
      <pubDate>Fri, 03 Jul 2026 04:16:08 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Ultralytics AI pwn request supply chain attack]]></title>
      <description><![CDATA[How a malicious pull request, a poisoned GitHub Actions cache, and a stored PyPI token turned the Ultralytics YOLO package into a cryptominer.]]></description>
      <link>https://safeguard.sh/resources/blog/the-ultralytics-ai-pwn-request-supply-chain-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-ultralytics-ai-pwn-request-supply-chain-attack</guid>
      <pubDate>Fri, 03 Jul 2026 04:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[GitHub-only lock-in: why GHAS doesn't support GitLab, Bit...]]></title>
      <description><![CDATA[GHAS only scans GitHub repos. For orgs running GitLab, Bitbucket, or self-hosted Git, that's a real coverage gap. Here's how Safeguard closes it.]]></description>
      <link>https://safeguard.sh/resources/blog/github-only-lock-in-why-ghas-doesnt-support-gitlab-bitbucket-or-self-hosted-scms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-only-lock-in-why-ghas-doesnt-support-gitlab-bitbucket-or-self-hosted-scms</guid>
      <pubDate>Fri, 03 Jul 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Secure Random Number Generation in C# with RandomNumberGe...]]></title>
      <description><![CDATA[Why System.Random is a security liability in C# and how RandomNumberGenerator prevents predictable tokens, nonces, and keys in .NET applications.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-random-number-generation-in-c-with-randomnumbergenerator</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-random-number-generation-in-c-with-randomnumbergenerator</guid>
      <pubDate>Fri, 03 Jul 2026 02:55:41 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Embedding Model Supply Chain Risks]]></title>
      <description><![CDATA[Embedding models are the silent dependency under every RAG system. We cover poisoning, deprecation, and provenance gaps that break retrieval in production.]]></description>
      <link>https://safeguard.sh/resources/blog/embedding-model-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/embedding-model-supply-chain-risks</guid>
      <pubDate>Fri, 03 Jul 2026 01:35:14 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Axios npm package RAT supply chain compromise]]></title>
      <description><![CDATA[A compromised maintainer account pushed malicious axios releases carrying a cross-platform RAT to npm on March 31, 2026 — here's the full timeline and IOCs.]]></description>
      <link>https://safeguard.sh/resources/blog/axios-npm-package-rat-supply-chain-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/axios-npm-package-rat-supply-chain-compromise</guid>
      <pubDate>Fri, 03 Jul 2026 01:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secure Random Number Generation in Java with SecureRandom...]]></title>
      <description><![CDATA[Why java.util.Random and even UUID.randomUUID() can leak predictable tokens, and how Java's SecureRandom and NIST DRBG providers actually protect secrets.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-random-number-generation-in-java-with-securerandom-and-uuid</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-random-number-generation-in-java-with-securerandom-and-uuid</guid>
      <pubDate>Fri, 03 Jul 2026 00:14:48 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Secret scanning coverage: GHAS's ~200 patterns vs broader...]]></title>
      <description><![CDATA[GHAS matches secrets against ~200 partner patterns. We break down where that coverage ends and how Safeguard's layered detection catches what pattern lists miss.]]></description>
      <link>https://safeguard.sh/resources/blog/secret-scanning-coverage-ghass-200-patterns-vs-broader-secret-type-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secret-scanning-coverage-ghass-200-patterns-vs-broader-secret-type-detection</guid>
      <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2018-16487: Prototype pollution in lodash via merge/m...]]></title>
      <description><![CDATA[CVE-2018-16487 let attackers pollute Object.prototype through lodash's merge, mergeWith, and defaultsDeep — a bypass of an earlier fix, patched in 4.17.11.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2018-16487-prototype-pollution-in-lodash-via-mergemergewith</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2018-16487-prototype-pollution-in-lodash-via-mergemergewith</guid>
      <pubDate>Thu, 02 Jul 2026 22:54:21 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-8203: Prototype pollution in lodash zipObjectDeep]]></title>
      <description><![CDATA[CVE-2020-8203 lets attackers pollute JavaScript's Object prototype via lodash's zipObjectDeep function, risking DoS or RCE in downstream apps.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-8203-prototype-pollution-in-lodash-zipobjectdeep</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-8203-prototype-pollution-in-lodash-zipobjectdeep</guid>
      <pubDate>Thu, 02 Jul 2026 21:33:54 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Docker Meaning: What Docker Is and Why It Matters for Security]]></title>
      <description><![CDATA[Docker packages an application and everything it needs into a portable container that runs the same everywhere. Understanding that model is the first step to securing it.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-meaning</guid>
      <pubDate>Thu, 02 Jul 2026 20:13:28 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Login: A Security Guide to Authentication and Access]]></title>
      <description><![CDATA[The Snyk login flow supports SSO, identity-provider integration, and CLI token auth. Here is how each works and how to keep your Snyk account access secure.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-login</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-login</guid>
      <pubDate>Thu, 02 Jul 2026 18:53:01 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Zod on npm: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[Zod is a well-maintained TypeScript validation library that is itself a security asset, if you put it at your trust boundaries. Here is a review and how to use it right.]]></description>
      <link>https://safeguard.sh/resources/blog/zod-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zod-npm</guid>
      <pubDate>Thu, 02 Jul 2026 17:32:34 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Code Injection: How It Works and How to Prevent It]]></title>
      <description><![CDATA[JavaScript code injection happens when an application treats untrusted input as executable code. This guide explains the attack class conceptually and focuses on detection and prevention.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-code-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-code-injection</guid>
      <pubDate>Thu, 02 Jul 2026 16:12:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AI Model Supply Chain Attacks: How Weights Become Malware]]></title>
      <description><![CDATA[You would never run an unknown binary from a stranger, but teams pull unknown model weights off public hubs every day. Loading them can be code execution — and that is only the most obvious link in the chain.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-model-supply-chain-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-model-supply-chain-attacks</guid>
      <pubDate>Thu, 02 Jul 2026 15:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Prioritization: How to Triage What Actually Matters]]></title>
      <description><![CDATA[CVSS alone is a poor priority signal. A 2026 guide to prioritizing vulnerabilities with EPSS, CISA KEV, SSVC, and reachability — so you fix the few that are exploitable, not the thousands that aren't.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-prioritization-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-prioritization-guide</guid>
      <pubDate>Thu, 02 Jul 2026 15:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is Infrastructure as Code (IaC) Security?]]></title>
      <description><![CDATA[Infrastructure as Code (IaC) security is the practice of scanning and hardening the machine-readable files that define your cloud infrastructure — before they provision anything. Here's how it catches misconfigurations at the source.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-infrastructure-as-code-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-infrastructure-as-code-security</guid>
      <pubDate>Thu, 02 Jul 2026 15:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Python Code Fixers for Security: What They Catch and Where They Stop]]></title>
      <description><![CDATA[A Python code fixer can auto-remediate a real slice of security and quality issues, but only if you know which findings are safe to fix automatically. Here is how the tooling works and how to wire it up.]]></description>
      <link>https://safeguard.sh/resources/blog/python-code-fixer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-code-fixer</guid>
      <pubDate>Thu, 02 Jul 2026 14:51:41 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA compliance for developers: securing the software supply chain]]></title>
      <description><![CDATA[HIPAA does not name your open source dependencies, but its Security Rule holds you responsible for them. Here's what developers building health-tech actually need to do.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-compliance-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-compliance-for-developers</guid>
      <pubDate>Thu, 02 Jul 2026 14:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Mass Assignment Vulnerability: How to Prevent It]]></title>
      <description><![CDATA[Mass assignment lets attackers set fields you never meant to expose — like isAdmin or accountBalance — by adding them to a request body. Here is the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/mass-assignment-vulnerability-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mass-assignment-vulnerability-prevention</guid>
      <pubDate>Thu, 02 Jul 2026 14:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Building a Multi-Cloud Security Strategy That Actually Scales]]></title>
      <description><![CDATA[A practical framework for securing AWS, Azure, and GCP together — the pillars, the provider differences that trip teams up, and how to unify controls with policy-as-code.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-cloud-security-strategy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-cloud-security-strategy</guid>
      <pubDate>Thu, 02 Jul 2026 14:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[The npm Supply Chain Security Guide]]></title>
      <description><![CDATA[How the npm supply chain actually gets attacked — install scripts, maintainer takeovers, typosquatting, and dependency confusion — and a phased program to defend it from developer laptop to production.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-supply-chain-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-supply-chain-security-guide</guid>
      <pubDate>Thu, 02 Jul 2026 14:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SSRF Prevention in Go: Blocking Metadata, Redirects, and DNS Rebinding]]></title>
      <description><![CDATA[A single unvalidated URL passed to net/http can hand an attacker your cloud metadata credentials. Here's how SSRF actually works against Go services — and the DialContext-level defense that stops it.]]></description>
      <link>https://safeguard.sh/resources/blog/ssrf-prevention-in-go</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ssrf-prevention-in-go</guid>
      <pubDate>Thu, 02 Jul 2026 14:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What Is Agentic Development Security?]]></title>
      <description><![CDATA[When an AI agent can read your repo, run commands, open pull requests, and call external tools on its own, the security model shifts from reviewing code to governing an actor. Here is what agentic development security means and why it is different.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-agentic-development-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-agentic-development-security</guid>
      <pubDate>Thu, 02 Jul 2026 14:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[YAML Injection: How It Happens and How to Prevent It]]></title>
      <description><![CDATA[YAML looks like a harmless config format, but the wrong parser call turns a config file into a code-execution engine. Here's how YAML deserialization attacks work and how to parse safely.]]></description>
      <link>https://safeguard.sh/resources/blog/yaml-injection-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/yaml-injection-prevention</guid>
      <pubDate>Thu, 02 Jul 2026 14:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-23337: Command injection in lodash template func...]]></title>
      <description><![CDATA[CVE-2021-23337 enables command injection via lodash's template function in versions before 4.17.21. Here's the CVSS context, timeline, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-23337-command-injection-in-lodash-template-function</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-23337-command-injection-in-lodash-template-function</guid>
      <pubDate>Thu, 02 Jul 2026 13:31:14 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-44906: Prototype pollution in minimist]]></title>
      <description><![CDATA[CVE-2021-44906 exposed a prototype pollution flaw in minimist versions before 1.2.6, letting attackers pollute Object.prototype via crafted parser keys.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-44906-prototype-pollution-in-minimist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-44906-prototype-pollution-in-minimist</guid>
      <pubDate>Thu, 02 Jul 2026 12:10:47 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2017-16137: ReDoS in debug package]]></title>
      <description><![CDATA[CVE-2017-16137 is a ReDoS flaw in the debug npm package that can hang Node.js apps on crafted input. Here's what's affected and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2017-16137-redos-in-debug-package</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2017-16137-redos-in-debug-package</guid>
      <pubDate>Thu, 02 Jul 2026 10:50:21 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Angular Security Best Practices: Trusting the Sanitizer, Not Bypassing It]]></title>
      <description><![CDATA[Angular sanitizes bindings by default — until a developer calls bypassSecurityTrustHtml. Here is how Angular's security model works and where teams break it.]]></description>
      <link>https://safeguard.sh/resources/blog/angular-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/angular-security-best-practices</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Apache Struts (CVE-2017-5638) Explained: The OGNL Header That Breached Equifax]]></title>
      <description><![CDATA[CVE-2017-5638 let attackers run commands on Apache Struts 2 servers through a crafted Content-Type header. It is the unpatched flaw behind the Equifax breach. Here is the OGNL mechanism.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-struts-cve-2017-5638-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-struts-cve-2017-5638-explained</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Application Security FAQ: A 2026 Guide]]></title>
      <description><![CDATA[Clear answers to common application security questions in 2026 — what AppSec covers, how SAST, DAST, and SCA differ, the role of the OWASP Top 10, and how to prioritize fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-faq</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[ASP.NET Core Security Checklist for Production]]></title>
      <description><![CDATA[A production-ready ASP.NET Core security checklist covering authentication, headers, HTTPS, antiforgery, rate limiting, and data protection, with the exact configuration for .NET 8 and .NET 9.]]></description>
      <link>https://safeguard.sh/resources/blog/aspnet-core-security-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aspnet-core-security-checklist</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Authentication vs Authorization: What's the Difference?]]></title>
      <description><![CDATA[Authentication proves who you are. Authorization decides what you're allowed to do. One is the ID check at the door; the other is the list of rooms you can enter.]]></description>
      <link>https://safeguard.sh/resources/blog/authentication-vs-authorization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/authentication-vs-authorization</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[AWS Access Key Security Best Practices (2026)]]></title>
      <description><![CDATA[Long-lived AWS access keys are the single most abused cloud credential. Here is how to eliminate them where you can, harden the ones you keep, and detect leaks — with real breaches and copy-paste commands.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-access-key-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-access-key-security-best-practices</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AWS Lambda Security: A Deep Dive Into the Function Attack Surface]]></title>
      <description><![CDATA[An attack-surface walkthrough of AWS Lambda security — execution roles, resource-based policies, environment-variable secrets, function URLs, and dependency layers — with IAM policy and CLI examples.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-lambda-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-lambda-security</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[The Best Application Security Certifications in 2026]]></title>
      <description><![CDATA[Which AppSec certifications are actually worth your time and money? A candid guide for students and career-changers on entry-level, specialist, and free certifications—and how to pair them with the evidence hiring managers really want.]]></description>
      <link>https://safeguard.sh/resources/blog/best-application-security-certifications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-application-security-certifications</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Career</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Best DevSecOps Tools in 2026]]></title>
      <description><![CDATA[DevSecOps is a category with fuzzy edges. This balanced guide compares GitHub Advanced Security, GitLab, Snyk, Semgrep, Aqua, and Safeguard on how they actually fit into pipelines — with honest tradeoffs and a framework for choosing.]]></description>
      <link>https://safeguard.sh/resources/blog/best-devsecops-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-devsecops-tools-2026</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best Kubernetes Security Tools in 2026: A Buyer's Guide]]></title>
      <description><![CDATA[A balanced buyer's guide to the best Kubernetes security tools in 2026 — Aqua, Sysdig, Falco, Kubescape, Trivy, and Wiz — covering image scanning, admission control, runtime detection, and KSPM, plus where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/best-kubernetes-security-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-kubernetes-security-tools-2026</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best Secrets Detection Tools in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced 2026 comparison of the leading secrets detection tools — Gitleaks, TruffleHog, GitGuardian, Semgrep Secrets, and GitHub secret scanning — on precision, coverage, and what happens after a leak is found.]]></description>
      <link>https://safeguard.sh/resources/blog/best-secrets-detection-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-secrets-detection-tools-2026</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best Software Supply Chain Security Tools (2026): An Honest FAQ]]></title>
      <description><![CDATA[A balanced 2026 FAQ on the best software supply chain security tools — how Snyk, Black Duck, Sonatype, Socket, JFrog, Wiz, and Safeguard actually differ, and how to pick for your own repos.]]></description>
      <link>https://safeguard.sh/resources/blog/best-software-supply-chain-security-tools-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-software-supply-chain-security-tools-faq</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Best Vulnerability Scanners in 2026: A Buyer's Guide]]></title>
      <description><![CDATA[A balanced guide to the best vulnerability scanners in 2026 across network, cloud, container, and software layers — Tenable, Qualys, Rapid7, Wiz, Trivy, and Snyk — with honest tradeoffs and where Safeguard fits for software and supply-chain scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/best-vulnerability-scanners-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-vulnerability-scanners-2026</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[BlueKeep (CVE-2019-0708) Explained: The Wormable RDP Vulnerability]]></title>
      <description><![CDATA[CVE-2019-0708, known as BlueKeep, is a pre-authentication use-after-free in Windows Remote Desktop Services rated CVSS 9.8. Here is how it works and why Microsoft patched Windows XP to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/bluekeep-cve-2019-0708-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bluekeep-cve-2019-0708-explained</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Building a Vulnerability Management Program That Developers Don't Hate]]></title>
      <description><![CDATA[Most vulnerability management programs fail not because they miss bugs, but because they drown teams in unprioritized findings. Here is a phased, developer-friendly way to build one that actually reduces risk.]]></description>
      <link>https://safeguard.sh/resources/blog/building-a-vulnerability-management-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-a-vulnerability-management-program</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Bun Security Best Practices (2026)]]></title>
      <description><![CDATA[Bun is fast and Node-compatible, but unlike Deno it has no permission sandbox. Here is how to run it safely: trusted-dependency script blocking, frozen lockfiles, and real dependency auditing.]]></description>
      <link>https://safeguard.sh/resources/blog/bun-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bun-security-best-practices</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What's the Cheapest Way to Start Supply Chain Security? (FAQ)]]></title>
      <description><![CDATA[The most affordable way to run real software supply chain security in 2026 — why Safeguard's $1 Starter plan is the cheapest genuine entry point, and what 'cheap' should and shouldn't mean.]]></description>
      <link>https://safeguard.sh/resources/blog/cheapest-supply-chain-security-tool-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cheapest-supply-chain-security-tool-faq</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx Alternatives in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced comparison of the leading Checkmarx alternatives in 2026 — Snyk, Veracode, Semgrep, SonarQube, GitHub Advanced Security, and Safeguard — with candid pros, cons, and guidance on choosing.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-alternatives-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-alternatives-2026</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Biggest Cloud Security Challenges in 2026 (and How to Solve Them)]]></title>
      <description><![CDATA[The seven cloud security challenges that consistently trip up engineering teams in 2026 — misconfiguration, identity sprawl, supply chain risk, drift — with pragmatic solutions.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-security-challenges-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-security-challenges-guide</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Container Image Scanning: A Practical Guide]]></title>
      <description><![CDATA[Scanning a container image is easy. Scanning it at the right moment, cutting the false positives, and gating deploys on the result is where most programs fall apart.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-scanning-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-scanning-guide</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Deno Security Best Practices (2026)]]></title>
      <description><![CDATA[Deno is secure by default, but its permission model only protects you if you use it deliberately. Here is how to run Deno with least privilege and keep its dependency graph clean.]]></description>
      <link>https://safeguard.sh/resources/blog/deno-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/deno-security-best-practices</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Docker Security Pro Tips: Hardening Beyond the Basics]]></title>
      <description><![CDATA[You already use a non-root user and a slim base. These are the pro-level Docker hardening tips — read-only filesystems, dropped capabilities, and the docker.sock trap — that actually stop breakouts.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-security-pro-tips</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-security-pro-tips</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Express.js Security Guide (2026)]]></title>
      <description><![CDATA[Express is the default web framework for Node.js — and a small, deep dependency tree that has produced open-redirect, XSS, and ReDoS CVEs. Here is how to run Express safely in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/express-js-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/express-js-security-guide</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[FastAPI Security Best Practices: A 2026 Guide]]></title>
      <description><![CDATA[FastAPI's type system catches a whole class of bugs for free, but async I/O, JWT handling, and dependency injection introduce risks that Pydantic will not save you from.]]></description>
      <link>https://safeguard.sh/resources/blog/fastapi-security-best-practices-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fastapi-security-best-practices-guide</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP Compliance FAQ: Baselines, 3PAOs, ConMon, and FedRAMP 20x]]></title>
      <description><![CDATA[A precise FAQ on FedRAMP in 2026 — impact baselines, NIST 800-53 controls, the agency authorization path, continuous monitoring, DoD Impact Levels, and the FedRAMP 20x modernization.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-compliance-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-compliance-faq</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[GDPR for software developers: privacy by design in practice]]></title>
      <description><![CDATA[GDPR is not just a legal team's problem. Data protection by design, security of processing, and processor due diligence all translate into code, dependencies, and architecture. Here is the developer's view.]]></description>
      <link>https://safeguard.sh/resources/blog/gdpr-for-software-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gdpr-for-software-developers</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Actions Security Hardening: A Practical Checklist]]></title>
      <description><![CDATA[GitHub Actions runs arbitrary code with access to your secrets and repos. A hands-on hardening guide — SHA pinning, least-privilege GITHUB_TOKEN, OIDC, and runner protection — with copy-paste YAML.]]></description>
      <link>https://safeguard.sh/resources/blog/github-actions-security-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-actions-security-hardening</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[GitLab CI Security Best Practices for 2026]]></title>
      <description><![CDATA[GitLab CI hands every job a CI_JOB_TOKEN, a runner, and your variables. This guide covers the real attack surface — remote includes, token scope, privileged runners — with hardened .gitlab-ci.yml examples, OIDC, and scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-ci-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-ci-security-best-practices</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Preventing Command Injection in Go: Allowlists, Argument Safety, and Sandboxing]]></title>
      <description><![CDATA[os/exec keeps the shell out of your way — but user-controlled binaries, flag injection, and PATH tricks still get Go services popped. Here's the prevention playbook, not just the theory.]]></description>
      <link>https://safeguard.sh/resources/blog/go-command-injection-prevention-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-command-injection-prevention-2026</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Do a Secure Code Review: A Practical 2026 Guide]]></title>
      <description><![CDATA[A practical 2026 walkthrough of secure code review — the process, the checklist, the real tools that automate it, how reachability prioritizes findings, and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-do-a-secure-code-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-do-a-secure-code-review</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Find Vulnerabilities in Your Code]]></title>
      <description><![CDATA[A beginner-friendly guide to finding security vulnerabilities in both your own code and the open-source libraries you depend on, using free and open tools.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-find-vulnerabilities-in-your-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-find-vulnerabilities-in-your-code</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Scan a Container Image for Vulnerabilities]]></title>
      <description><![CDATA[Scan any Docker or OCI image for OS-package and application-layer vulnerabilities, understand the results, and gate risky images before they reach your registry — with copy-paste commands.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-scan-a-container-image-for-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-scan-a-container-image-for-vulnerabilities</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Java Code Review Tools: An Honest 2026 Buyer's Guide]]></title>
      <description><![CDATA[A balanced 2026 comparison of Java code review and static-analysis tools — SpotBugs with FindSecBugs, PMD, Error Prone, SonarQube, Semgrep, CodeQL — with honest tradeoffs and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/java-code-review-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-code-review-tools</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Java Deserialization Vulnerabilities: How Gadget Chains Work and How to Stop Them]]></title>
      <description><![CDATA[Native Java deserialization can turn a single readObject() call into remote code execution. Here's how gadget chains work and how to shut them down.]]></description>
      <link>https://safeguard.sh/resources/blog/java-deserialization-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-deserialization-vulnerabilities</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Security: The Common Pitfalls That Keep Burning Teams]]></title>
      <description><![CDATA[The recurring JavaScript security mistakes that show up in real breaches — unsafe deserialization, injection sinks, prototype pollution, and trusting client input — each with vulnerable and fixed code.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-security-common-pitfalls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-security-common-pitfalls</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Kotlin Security Best Practices: Beyond Null Safety on the JVM and Android]]></title>
      <description><![CDATA[Null safety is a reliability win, not a security boundary. A Kotlin app inherits every JVM supply-chain CVE and the full Android attack surface — here's what the type system doesn't do for you.]]></description>
      <link>https://safeguard.sh/resources/blog/kotlin-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kotlin-security-best-practices</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Secrets Management Done Right]]></title>
      <description><![CDATA[A Kubernetes Secret is base64, not encryption — and by default it sits in etcd in plaintext. Here is how to actually protect credentials with encryption at rest, external secret stores, and tight RBAC.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-secrets-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-secrets-management</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Lessons from Log4Shell: How One Logging Call Became the Internet's Worst Weekend]]></title>
      <description><![CDATA[CVE-2021-44228 let an unauthenticated attacker run code by getting a single string logged. Here is how Log4Shell worked, why it was everywhere, and what actually contained it.]]></description>
      <link>https://safeguard.sh/resources/blog/lessons-from-log4shell</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lessons-from-log4shell</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Auditing Maven Dependencies with OWASP Dependency-Check]]></title>
      <description><![CDATA[OWASP Dependency-Check is the classic way to scan Java and Maven projects against the NVD. Learn to run it, tame its false positives, and move beyond CPE matching.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-dependency-check-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-dependency-check-guide</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Security: 8 Best Practices for 2026]]></title>
      <description><![CDATA[The Model Context Protocol connects AI agents to your tools and data. That power cuts both ways. Here are eight concrete practices for running MCP servers without handing attackers a remote control.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-security-best-practices</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[NumPy Security Guide (2026)]]></title>
      <description><![CDATA[NumPy is the numerical foundation of the Python data ecosystem — and while many of its CVEs are disputed, the pickle-based numpy.load deserialization risk is real and worth understanding.]]></description>
      <link>https://safeguard.sh/resources/blog/numpy-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/numpy-security-guide</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[OWASP A03: Injection Explained — A Deep-Dive Guide]]></title>
      <description><![CDATA[Injection ranks #3 in the OWASP Top 10 (2021) and now includes XSS. A deep dive into SQLi, command injection, real CVEs, and how to detect and fix it in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-a03-injection-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-a03-injection-explained</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[OWASP A04: Insecure Design — A Deep-Dive Guide]]></title>
      <description><![CDATA[Insecure Design is a new OWASP Top 10 (2021) category at #4. A deep dive into design flaws vs implementation bugs, threat modeling, real cases, and prevention.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-a04-insecure-design</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-a04-insecure-design</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[PaperCut CVE-2023-27350 Explained: Auth Bypass to Unauthenticated RCE]]></title>
      <description><![CDATA[CVE-2023-27350 is an authentication bypass in PaperCut MF and NG that hands an attacker admin access and remote code execution, rated CVSS 9.8. Here is the timeline, root cause, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/papercut-cve-2023-27350-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/papercut-cve-2023-27350-explained</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[PCI DSS 4.0 for developers: a practical secure-coding guide]]></title>
      <description><![CDATA[PCI DSS 4.0 moved secure development from an annual review to a continuous engineering practice. Here's what Requirement 6 means for developers writing and shipping code.]]></description>
      <link>https://safeguard.sh/resources/blog/pci-dss-4-developer-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pci-dss-4-developer-guide</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[PCI DSS 4.0 Requirement 6: the software security guide]]></title>
      <description><![CDATA[Requirement 6 is where PCI DSS 4.0 turned application and software security into a continuous, evidenced discipline. Here is a clause-by-clause walkthrough of 6.2 through 6.5 and what auditors expect.]]></description>
      <link>https://safeguard.sh/resources/blog/pci-dss-4-requirement-6-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pci-dss-4-requirement-6-guide</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Polyfill.io supply chain domain takeover]]></title>
      <description><![CDATA[How a routine domain sale turned polyfill.io into malware served to 100,000+ sites, and how to catch supply chain takeovers before they ship.]]></description>
      <link>https://safeguard.sh/resources/blog/polyfillio-supply-chain-domain-takeover</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/polyfillio-supply-chain-domain-takeover</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[The Principle of Least Privilege, Explained]]></title>
      <description><![CDATA[Least privilege means every user, service, and process gets exactly the access it needs to do its job — and nothing more. Here's why it contains breaches and how to implement it without breaking things.]]></description>
      <link>https://safeguard.sh/resources/blog/principle-of-least-privilege</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/principle-of-least-privilege</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[ProxyShell (CVE-2021-34473) Explained: The Exchange Path Confusion Behind a Pre-Auth RCE Chain]]></title>
      <description><![CDATA[CVE-2021-34473 is the path-confusion flaw at the head of ProxyShell — a three-bug Microsoft Exchange chain that took unauthenticated attackers all the way to remote code execution.]]></description>
      <link>https://safeguard.sh/resources/blog/proxyshell-cve-2021-34473-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/proxyshell-cve-2021-34473-explained</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Zerologon: The Netlogon Cryptographic Flaw (CVE-2020-1472) Explained]]></title>
      <description><![CDATA[CVE-2020-1472 let an unauthenticated attacker seize a domain controller in seconds by exploiting an all-zero AES-CFB8 initialization vector. Here's the real mechanism and the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/samba-zerologon-cve-2020-1472-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/samba-zerologon-cve-2020-1472-explained</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[SBOM (Software Bill of Materials): Frequently Asked Questions]]></title>
      <description><![CDATA[A clear FAQ on software bills of materials in 2026 — what an SBOM is, SPDX vs CycloneDX, NTIA minimum elements, VEX, signing, and how to keep an SBOM continuously accurate.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-faq</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SBOM for Beginners: What a Software Bill of Materials Really Is]]></title>
      <description><![CDATA[Modern software is assembled from hundreds of parts you did not write. An SBOM is the ingredient label that lists them all. Here is a warm, beginner-friendly tour with a first SBOM you can generate today.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-beginners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-beginners</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[SCA for Beginners: Understanding Software Composition Analysis]]></title>
      <description><![CDATA[Most of your application is code you did not write. Software Composition Analysis helps you keep that borrowed code safe. Here is a beginner-friendly tour with a first scan you can run today.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-for-beginners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-for-beginners</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Secure Design Principles Every Team Should Know]]></title>
      <description><![CDATA[Secure design principles are the durable rules of thumb — least privilege, fail securely, defense in depth, secure defaults — that keep systems safe by construction rather than by patching. Here's the working set and how to apply them.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-design-principles</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-design-principles</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Securing Vector Databases: The Overlooked Attack Surface in AI Apps]]></title>
      <description><![CDATA[Vector databases became critical infrastructure the moment RAG went mainstream, but most are deployed with the security posture of a cache. Embeddings leak, indexes get poisoned, and tenants bleed into each other.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-vector-databases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-vector-databases</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Security Gates in CI/CD: How to Block Risk Without Blocking Delivery]]></title>
      <description><![CDATA[A security gate that fails every build gets disabled by Friday. Here is how to design CI/CD security gates that stop real risk, stay fast, and keep developers on your side.]]></description>
      <link>https://safeguard.sh/resources/blog/security-gates-in-ci-cd</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-gates-in-ci-cd</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Serverless Security Best Practices: Securing the Function Lifecycle]]></title>
      <description><![CDATA[A lifecycle approach to serverless security across AWS Lambda, Azure Functions, and Cloud Functions — covering the build, deploy, invoke, and runtime phases with IAM, dependency, and event-injection controls.]]></description>
      <link>https://safeguard.sh/resources/blog/serverless-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/serverless-security-best-practices</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Black Duck: A Neutral SCA Comparison for 2026]]></title>
      <description><![CDATA[Snyk and Black Duck are both leaders in open-source security, but they optimize for different buyers — developer velocity versus license and compliance depth. A fair side-by-side, plus where a third option fits.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-black-duck</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-black-duck</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Healthcare]]></title>
      <description><![CDATA[From FDA premarket SBOM requirements to a strengthened HIPAA Security Rule and connected medical devices with decade-long lifecycles, healthcare has a distinct supply chain problem. Here is how to build a program that holds up.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-for-healthcare</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-for-healthcare</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Spring Security Configuration Guide: The Modern SecurityFilterChain Approach]]></title>
      <description><![CDATA[A practical Spring Security configuration guide for 2026 using the component-based SecurityFilterChain, method security, CSRF, CORS, and password encoding.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-security-configuration-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-security-configuration-guide</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Spring4Shell (CVE-2022-22965) Explained: RCE Through Spring Data Binding]]></title>
      <description><![CDATA[CVE-2022-22965, Spring4Shell, let attackers write a JSP web shell to Spring MVC apps on JDK 9+ by abusing data binding. Here is the ClassLoader trick and the exact conditions required.]]></description>
      <link>https://safeguard.sh/resources/blog/spring4shell-cve-2022-22965-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring4shell-cve-2022-22965-explained</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Developers]]></title>
      <description><![CDATA[For developers, supply chain security lives or dies in the pull request. Here is how to keep it there: catch real risk early, fix it in minutes, and never lose an afternoon to noise.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-for-developers</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Security Champions]]></title>
      <description><![CDATA[A security champion is one engineer per team carrying the security conversation. Here is how to be effective at supply chain risk without a security title, a security budget, or a full day to spend on it.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-for-security-champions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-for-security-champions</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for SRE Teams]]></title>
      <description><![CDATA[For SRE teams, supply chain risk is a reliability problem — a zero-day in a production image is an incident waiting to page you. Here is how to own runtime posture, gate deploys, and answer 'where does this run?' in minutes instead of days.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-for-sre-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-for-sre-teams</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Threat Modeling for Developers]]></title>
      <description><![CDATA[Threat modeling doesn't have to be a heavyweight ceremony run by a separate security team. Here's how developers can fold lightweight, per-feature threat modeling directly into pull requests and sprint work.]]></description>
      <link>https://safeguard.sh/resources/blog/threat-modeling-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/threat-modeling-for-developers</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Understanding CVSS Scores]]></title>
      <description><![CDATA[CVSS turns a vulnerability's characteristics into a number from 0 to 10 and a severity label. Here is what the score actually measures, how the metrics combine, and why the number alone should never drive your patching.]]></description>
      <link>https://safeguard.sh/resources/blog/understanding-cvss-scores</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/understanding-cvss-scores</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Understanding Dependency Trees]]></title>
      <description><![CDATA[The libraries you install are only the tip of the iceberg. Each one pulls in its own dependencies, which pull in more, forming a tree that can run hundreds of packages deep. Understanding that tree is the first step to securing it.]]></description>
      <link>https://safeguard.sh/resources/blog/understanding-dependency-trees</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/understanding-dependency-trees</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Vue Security Best Practices: v-html, Dynamic Components, and SSR]]></title>
      <description><![CDATA[Vue escapes mustache templates automatically, but v-html, dynamic component names, and SSR hydration open real XSS holes. Here is how to close them.]]></description>
      <link>https://safeguard.sh/resources/blog/vue-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vue-security-best-practices</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What Is Defense in Depth in Security?]]></title>
      <description><![CDATA[Defense in depth is a layered security strategy that assumes any single control will eventually fail, so it stacks independent safeguards to slow and stop attackers. Here's how the model works and how it maps to the software supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-defense-in-depth-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-defense-in-depth-security</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is Insecure Deserialization? A Developer's Guide]]></title>
      <description><![CDATA[Insecure deserialization turns a trusted data-loading routine into a remote code execution primitive. Learn how gadget chains work and how to deserialize untrusted data safely.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-insecure-deserialization-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-insecure-deserialization-explained</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What Is Malware? Types and How It Spreads]]></title>
      <description><![CDATA[Malware is any software built to do harm, from stealing data to locking up your files. Here's a beginner-friendly tour of the main types and how it gets in.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-malware-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-malware-explained</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is Protestware? When Maintainers Weaponize Their Own Packages]]></title>
      <description><![CDATA[Protestware is open-source code a maintainer deliberately alters to make a political or personal statement, sometimes sabotaging users. Here is how it works and how to defend.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-protestware</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-protestware</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is Safeguard? Common Questions Answered]]></title>
      <description><![CDATA[A beginner-friendly FAQ explaining what Safeguard is, who it is for, what it protects against, and how it compares to the tools teams already use.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-safeguard-questions-answered</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-safeguard-questions-answered</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is SSTI (Server-Side Template Injection)?]]></title>
      <description><![CDATA[SSTI happens when user input is compiled as template code instead of rendered as data, often leading straight to remote code execution. Here is how to prevent it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-ssti-server-side-template-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-ssti-server-side-template-injection</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What Is the BSD License? 2-Clause vs 3-Clause Explained]]></title>
      <description><![CDATA[The BSD licenses are a family of short, permissive licenses. This guide explains the 2-clause and 3-clause variants, what each permits, and what they mean for compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-bsd-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-bsd-license</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is the GPL License? Copyleft Explained]]></title>
      <description><![CDATA[The GNU General Public License is the best-known copyleft license. This guide explains what it permits, its source-disclosure obligations, GPLv2 vs GPLv3, and what it means for your project.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-gpl-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-gpl-license</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is VEX (Vulnerability Exploitability eXchange)?]]></title>
      <description><![CDATA[VEX is a machine-readable advisory that states whether a product is actually affected by a known vulnerability. Here's how its status values work and why it cuts SBOM-driven false positives.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-vex-vulnerability-exploitability-exchange</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-vex-vulnerability-exploitability-exchange</guid>
      <pubDate>Thu, 02 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2018-3728: Prototype pollution in hoek]]></title>
      <description><![CDATA[CVE-2018-3728 is a prototype pollution flaw in Hoek's merge functions, exposing hapi.js and Joi-based apps to __proto__ injection. Here's the impact, fix, and remediation path.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2018-3728-prototype-pollution-in-hoek</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2018-3728-prototype-pollution-in-hoek</guid>
      <pubDate>Thu, 02 Jul 2026 09:29:54 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What GitHub Advanced Security actually includes now that ...]]></title>
      <description><![CDATA[GitHub split Advanced Security into Secret Protection and Code Security in April 2025. Here's what each product covers, what it costs, and where the gaps still are.]]></description>
      <link>https://safeguard.sh/resources/blog/what-github-advanced-security-actually-includes-now-that-its-split-into-secret-protection-and-code-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-github-advanced-security-actually-includes-now-that-its-split-into-secret-protection-and-code-security</guid>
      <pubDate>Thu, 02 Jul 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Docker Ubuntu Image: How to Use It Securely and Keep It Slim]]></title>
      <description><![CDATA[The Docker Ubuntu image is a fine base, but a naive Dockerfile ships a bloated, vulnerable container. Here is how to pin, slim, and scan it properly.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-ubuntu-image</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-ubuntu-image</guid>
      <pubDate>Thu, 02 Jul 2026 08:09:27 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[AI Security Software: A Buyer's Guide for 2026]]></title>
      <description><![CDATA[The label 'AI security software' now covers two different markets — tools that secure AI systems, and security tools powered by AI. How to tell them apart, what to evaluate, and the questions that expose thin products.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-software-buyers-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-software-buyers-guide</guid>
      <pubDate>Thu, 02 Jul 2026 08:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Log4j Log4Shell vulnerability explained CVE-2021-44228]]></title>
      <description><![CDATA[Log4Shell (CVE-2021-44228) let attackers gain RCE via a single logged string. Here's the CVSS/EPSS/KEV context, timeline, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/log4j-log4shell-vulnerability-explained-cve-2021-44228</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4j-log4shell-vulnerability-explained-cve-2021-44228</guid>
      <pubDate>Thu, 02 Jul 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Getting Value From a Wiz Demo: What to Test in the Security Graph]]></title>
      <description><![CDATA[How to run a Wiz demo that tells you something real — connecting your own cloud, chasing attack paths and toxic combinations, and the questions that reveal fit.]]></description>
      <link>https://safeguard.sh/resources/blog/wiz-demo</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wiz-demo</guid>
      <pubDate>Thu, 02 Jul 2026 06:49:01 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Secret Protection deep dive: push protection, cust...]]></title>
      <description><![CDATA[How GitHub Secret Protection's push protection, custom patterns, and validity checks actually work post-GHAS split, and where the coverage gaps still leave secrets exposed.]]></description>
      <link>https://safeguard.sh/resources/blog/github-secret-protection-deep-dive-push-protection-custom-patterns-validity-checks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-secret-protection-deep-dive-push-protection-custom-patterns-validity-checks</guid>
      <pubDate>Thu, 02 Jul 2026 06:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001:2022 Transition Deadline: The Approach]]></title>
      <description><![CDATA[The October 31, 2025 ISO/IEC 27001:2022 transition deadline is weeks away. Here's what auditors will look for in Annex A controls, statements of applicability, and evidence packs.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-2022-transition-deadline-approach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-2022-transition-deadline-approach</guid>
      <pubDate>Thu, 02 Jul 2026 05:28:34 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Skill Scanner: How It Works and What to Use]]></title>
      <description><![CDATA[What a skill scanner does, why AI agent skills and voice-assistant skills need scanning, and how to evaluate one for your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/skill-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/skill-scanner</guid>
      <pubDate>Thu, 02 Jul 2026 04:08:07 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[PyPI typosquatting malicious packages]]></title>
      <description><![CDATA[PyPI typosquatting tricks developers into installing malicious lookalike packages via one-letter typos. Real incidents, attack patterns, and defenses inside.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-typosquatting-malicious-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-typosquatting-malicious-packages</guid>
      <pubDate>Thu, 02 Jul 2026 04:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Code Security and CodeQL SAST scanning explained]]></title>
      <description><![CDATA[GitHub split Advanced Security into Code Security and Secret Protection in 2025. Here's how CodeQL SAST actually works, what it misses, and how Safeguard fills the supply-chain gap.]]></description>
      <link>https://safeguard.sh/resources/blog/github-code-security-and-codeql-sast-scanning-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-code-security-and-codeql-sast-scanning-explained</guid>
      <pubDate>Thu, 02 Jul 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Security Tools: What to Use and Why]]></title>
      <description><![CDATA[A Kubernetes security tool covers one slice of cluster risk — image scanning, admission control, runtime detection, or posture. Here is how to combine them.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-security-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-security-tool</guid>
      <pubDate>Thu, 02 Jul 2026 02:47:41 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to Scan a Docker Image with Snyk (and What It Misses)]]></title>
      <description><![CDATA[A practical guide to scanning a Snyk Docker image for vulnerabilities: the CLI workflow, base-image advice, free-tier limits, and where container scanning needs a second look.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-docker-image</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-docker-image</guid>
      <pubDate>Thu, 02 Jul 2026 01:27:14 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems strong_password malicious version RCE]]></title>
      <description><![CDATA[In 2019, attackers hijacked the strong_password RubyGems account and shipped a backdoored v0.0.7 that let them eval() code in production Rails apps.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-strongpassword-malicious-version-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-strongpassword-malicious-version-rce</guid>
      <pubDate>Thu, 02 Jul 2026 01:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Introducing Safeguard Guardrails: Automated Policy Enforcement for Your Supply Chain]]></title>
      <description><![CDATA[Safeguard Guardrails brings automated, configurable policy enforcement to your software supply chain. Define rules once, enforce everywhere.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-guardrails-feature-release</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-guardrails-feature-release</guid>
      <pubDate>Thu, 02 Jul 2026 00:06:47 GMT</pubDate>
      <category>Product Launch</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How Copilot Autofix generates AI-powered vulnerability fi...]]></title>
      <description><![CDATA[Copilot Autofix pairs CodeQL with an LLM to patch code-scanning alerts up to 3x faster. Here's how it works, its limits, and where supply chain risk still slips through.]]></description>
      <link>https://safeguard.sh/resources/blog/how-copilot-autofix-generates-ai-powered-vulnerability-fixes-in-code-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-copilot-autofix-generates-ai-powered-vulnerability-fixes-in-code-scanning</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-11358: Prototype pollution in jQuery $.extend]]></title>
      <description><![CDATA[CVE-2019-11358 lets attackers pollute Object.prototype via jQuery's $.extend() deep merge. Here's the impact, affected versions, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-11358-prototype-pollution-in-jquery-extend</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-11358-prototype-pollution-in-jquery-extend</guid>
      <pubDate>Wed, 01 Jul 2026 22:46:20 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Vulnerability Scanning: How the Engine Actually Works]]></title>
      <description><![CDATA[Snyk vulnerability scanning combines a proprietary vulnerability database with dependency-graph resolution and a separate static analysis engine for code — here's how each piece actually fits together.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vulnerability-scanning-how-the-engine-works</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vulnerability-scanning-how-the-engine-works</guid>
      <pubDate>Wed, 01 Jul 2026 21:25:54 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-11022: XSS in jQuery via htmlPrefilter]]></title>
      <description><![CDATA[CVE-2020-11022 lets attacker-controlled HTML bypass sanitization via jQuery's htmlPrefilter, enabling XSS in versions before 3.5.0. Impact, timeline, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-11022-xss-in-jquery-via-htmlprefilter</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-11022-xss-in-jquery-via-htmlprefilter</guid>
      <pubDate>Wed, 01 Jul 2026 20:05:27 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-11023: XSS in jQuery option/script tag handling]]></title>
      <description><![CDATA[CVE-2020-11023 let untrusted HTML with option tags bypass sanitization in jQuery's DOM methods, enabling XSS. Here's the fix, timeline, and remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-11023-xss-in-jquery-optionscript-tag-handling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-11023-xss-in-jquery-optionscript-tag-handling</guid>
      <pubDate>Wed, 01 Jul 2026 18:45:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2015-9251: jQuery cross-domain AJAX XSS]]></title>
      <description><![CDATA[CVE-2015-9251 lets attackers exploit jQuery's cross-domain AJAX handling to run arbitrary script. Learn affected versions, risk context, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2015-9251-jquery-cross-domain-ajax-xss</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2015-9251-jquery-cross-domain-ajax-xss</guid>
      <pubDate>Wed, 01 Jul 2026 17:24:34 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SCA Solution: How to Choose Software Composition Analysis]]></title>
      <description><![CDATA[An SCA solution inventories your open-source dependencies and flags the ones with known vulnerabilities or risky licenses. Here is what separates a good one.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-solution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-solution</guid>
      <pubDate>Wed, 01 Jul 2026 16:04:07 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Is vite-plugin-static-copy Safe? Understanding CVE-2025-57753 and Path Traversal]]></title>
      <description><![CDATA[vite-plugin-static-copy is a popular Vite asset plugin, but one version range shipped a directory traversal flaw. Here is what to know and how to patch.]]></description>
      <link>https://safeguard.sh/resources/blog/vite-plugin-static-copy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vite-plugin-static-copy</guid>
      <pubDate>Wed, 01 Jul 2026 14:43:40 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[AI Agent Tool-Use Security: Locking Down What Agents Can Do]]></title>
      <description><![CDATA[The moment you give an LLM tools, it stops being a chatbot and becomes an actor in your systems. Tool-use security is about making sure a compromised agent hits a wall instead of a credential.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-agent-tool-use-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-agent-tool-use-security</guid>
      <pubDate>Wed, 01 Jul 2026 14:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[CI/CD Pipeline Security Best Practices for 2026]]></title>
      <description><![CDATA[Your build pipeline is production-adjacent infrastructure with credentials to everything. Here are the CI/CD security practices — mapped to the OWASP Top 10 CI/CD risks — that actually close the gaps attackers use.]]></description>
      <link>https://safeguard.sh/resources/blog/ci-cd-pipeline-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ci-cd-pipeline-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 14:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Docker Image Security Best Practices]]></title>
      <description><![CDATA[Every Docker layer you ship is attack surface you have to defend. Learn how to build lean, non-root, secret-free images that survive a registry scan and a real audit.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-image-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-image-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 14:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Flask Security Best Practices for 2026]]></title>
      <description><![CDATA[Flask is minimal by design, which means the security decisions Django makes for you are decisions you own. Here is how to make them correctly.]]></description>
      <link>https://safeguard.sh/resources/blog/flask-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/flask-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 14:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is Software Composition Analysis (SCA)?]]></title>
      <description><![CDATA[Software Composition Analysis (SCA) identifies the open source and third-party components in your code, then flags their known vulnerabilities and license risks. Here's how SCA works and what separates modern tools from legacy scanners.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-software-composition-analysis-sca</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-software-composition-analysis-sca</guid>
      <pubDate>Wed, 01 Jul 2026 14:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[regenerator-runtime: What It Is and Whether to Worry]]></title>
      <description><![CDATA[regenerator-runtime shows up in thousands of dependency trees, usually transitively. Here is what it does, why it is there, and how to think about its risk.]]></description>
      <link>https://safeguard.sh/resources/blog/regenerator-runtime</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/regenerator-runtime</guid>
      <pubDate>Wed, 01 Jul 2026 13:23:14 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[C# Secure Coding Guide: Patterns That Prevent Real Bugs]]></title>
      <description><![CDATA[A hands-on C# secure coding guide covering input validation, safe APIs, path traversal, injection, and the language-level patterns that keep vulnerabilities out of your code.]]></description>
      <link>https://safeguard.sh/resources/blog/csharp-secure-coding-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/csharp-secure-coding-guide</guid>
      <pubDate>Wed, 01 Jul 2026 13:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is XXE (XML External Entity Injection)?]]></title>
      <description><![CDATA[XXE abuses an XML parser's ability to load external entities to read local files, reach internal services, or knock a server offline. Here is how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-xxe-xml-external-entity-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-xxe-xml-external-entity-injection</guid>
      <pubDate>Wed, 01 Jul 2026 13:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Cross-Site Scripting (XSS): A Prevention Guide]]></title>
      <description><![CDATA[XSS lets an attacker run their JavaScript in your users' browsers — stealing sessions, rewriting pages, and pivoting to account takeover. This guide covers the three XSS types and the defenses that actually hold.]]></description>
      <link>https://safeguard.sh/resources/blog/xss-cross-site-scripting-prevention-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xss-cross-site-scripting-prevention-guide</guid>
      <pubDate>Wed, 01 Jul 2026 13:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Web Session Management: A Security Guide for Developers]]></title>
      <description><![CDATA[Web session management is how an application remembers who a user is across stateless HTTP requests. Get the session identifier, storage, and lifecycle wrong and you hand attackers the keys.]]></description>
      <link>https://safeguard.sh/resources/blog/web-session-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-session-management</guid>
      <pubDate>Wed, 01 Jul 2026 12:02:47 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[image-size npm Package: Vulnerability History and Safe Usage]]></title>
      <description><![CDATA[The image-size npm package has shipped several infinite-loop denial-of-service bugs in 2025. Here is what happened, which versions are affected, and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/image-size-npm-vulnerability-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/image-size-npm-vulnerability-review</guid>
      <pubDate>Wed, 01 Jul 2026 10:42:20 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[ActiveMQ CVE-2023-46604 Explained: The OpenWire Deserialization RCE]]></title>
      <description><![CDATA[CVE-2023-46604 is an unauthenticated remote code execution flaw in Apache ActiveMQ's OpenWire protocol, rated CVSS 10.0. Here is how it works, how ransomware crews weaponized it, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/activemq-cve-2023-46604-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/activemq-cve-2023-46604-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Application Security for Beginners: Where to Start Without Feeling Overwhelmed]]></title>
      <description><![CDATA[Application security sounds intimidating, but the fundamentals are learnable in an afternoon. Here is a warm, practical introduction with a first hands-on step you can try today.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-for-beginners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-for-beginners</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[ASPM vs CNAPP: Which Security Platform Does Your Team Actually Need?]]></title>
      <description><![CDATA[ASPM governs risk in the code and pipeline; CNAPP protects the cloud runtime. They overlap but solve different problems. Here is a clear comparison and how to decide which one to invest in first.]]></description>
      <link>https://safeguard.sh/resources/blog/aspm-vs-cnapp-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aspm-vs-cnapp-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Attack Surface Reduction: A Practical Guide]]></title>
      <description><![CDATA[Attack surface reduction is the discipline of removing every input, interface, and privilege an attacker could reach that your system does not actually need. Here's how to inventory, shrink, and keep it small.]]></description>
      <link>https://safeguard.sh/resources/blog/attack-surface-reduction</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/attack-surface-reduction</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[AWS Security Best Practices for 2026]]></title>
      <description><![CDATA[A practical, code-backed walkthrough of the AWS security controls that actually reduce breach risk in 2026 — identity, data, network, and infrastructure-as-code.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Azure Security Best Practices for 2026]]></title>
      <description><![CDATA[A practical Azure hardening guide covering Entra ID identity, Azure Policy guardrails, network isolation, Key Vault secrets, and Defender for Cloud — with Terraform and az CLI examples.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Best CNAPP Tools in 2026: A Practical Buyer's Guide]]></title>
      <description><![CDATA[A balanced buyer's guide to the best CNAPP tools in 2026 — Wiz, Prisma Cloud, Microsoft Defender for Cloud, CrowdStrike, Orca, and Sysdig — with honest strengths, tradeoffs, and where a supply-chain layer like Safeguard fits alongside them.]]></description>
      <link>https://safeguard.sh/resources/blog/best-cnapp-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-cnapp-tools-2026</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best Container Scanning Tools in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced 2026 comparison of the leading container image scanners — Trivy, Grype, Snyk Container, Prisma Cloud, Wiz, and Docker Scout — with an honest look at where each fits and how Safeguard compares.]]></description>
      <link>https://safeguard.sh/resources/blog/best-container-scanning-tools-2026-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-container-scanning-tools-2026-2026</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best CSPM Tools in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced comparison of the best CSPM tools in 2026 — Wiz, Prisma Cloud, Microsoft Defender for Cloud, Orca, Tenable Cloud Security, and AWS Security Hub — with honest tradeoffs and where shift-left IaC scanning from Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/best-cspm-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-cspm-tools-2026</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Best Secrets Management Tools in 2026]]></title>
      <description><![CDATA[A balanced buyer's guide to secrets management in 2026 — comparing Vault, cloud-native services, Doppler, Infisical, and CyberArk on the criteria that actually matter, plus an honest note on where secret detection tools fit.]]></description>
      <link>https://safeguard.sh/resources/blog/best-secrets-management-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-secrets-management-tools-2026</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Cybersecurity Basics for Developers]]></title>
      <description><![CDATA[You do not need to become a security specialist to write secure code, but a working grasp of a few core ideas prevents most common mistakes. Here are the fundamentals every developer should carry into daily work.]]></description>
      <link>https://safeguard.sh/resources/blog/cybersecurity-basics-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cybersecurity-basics-for-developers</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Cybersecurity Career Guide for Developers]]></title>
      <description><![CDATA[Already a developer? Your coding background is a cybersecurity superpower. Here's how to translate it into a security career—roles, skills, a free learning path, and portfolio moves that land interviews.]]></description>
      <link>https://safeguard.sh/resources/blog/cybersecurity-career-guide-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cybersecurity-career-guide-for-developers</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Career</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Best Practices: A 2026 Implementation Guide]]></title>
      <description><![CDATA[A practical, opinionated guide to the DevSecOps practices that actually reduce risk in 2026 — from shifting left correctly to policy gates, reachability, and measurable ownership.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-best-practices-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-best-practices-guide</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Django Security Best Practices for 2026]]></title>
      <description><![CDATA[Django ships with strong defaults, but misconfigured settings, raw ORM queries, and unpinned dependencies still cause real breaches. Here is the checklist that matters.]]></description>
      <link>https://safeguard.sh/resources/blog/django-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/django-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[DORA regulation deep dive: ICT risk, testing, and third-party rules]]></title>
      <description><![CDATA[The Digital Operational Resilience Act applies to EU financial entities and their ICT providers. Here are the five pillars, the register of information, and what your software supply chain now has to withstand.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-regulation-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-regulation-deep-dive</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[.NET Security Best Practices for 2026]]></title>
      <description><![CDATA[A practical .NET security playbook covering dependency risk, deserialization, secrets, cryptography, and CI/CD hardening, with the config flags and CVEs that make each control real.]]></description>
      <link>https://safeguard.sh/resources/blog/dotnet-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dotnet-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[EternalBlue (CVE-2017-0144) Explained: The SMBv1 Flaw Behind WannaCry]]></title>
      <description><![CDATA[CVE-2017-0144 is the SMBv1 remote code execution bug that powered WannaCry and NotPetya. Here is how the EternalBlue exploit works, why it spread, and how to stay clear of it today.]]></description>
      <link>https://safeguard.sh/resources/blog/eternalblue-ms17-010-cve-2017-0144-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eternalblue-ms17-010-cve-2017-0144-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[GCP Security Best Practices for 2026]]></title>
      <description><![CDATA[A hands-on Google Cloud hardening guide: resource hierarchy and Organization Policy, least-privilege IAM, VPC Service Controls, CMEK, and Security Command Center — with Terraform and gcloud examples.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Ghostcat: Apache Tomcat AJP File Read and RCE (CVE-2020-1938) Explained]]></title>
      <description><![CDATA[CVE-2020-1938 turned Tomcat's default AJP connector into a file-disclosure and RCE primitive. Here's how the request-attribute abuse works and how to shut it down.]]></description>
      <link>https://safeguard.sh/resources/blog/ghostcat-tomcat-cve-2020-1938-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ghostcat-tomcat-cve-2020-1938-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Actions Supply Chain Security: A 2026 Hardening Guide]]></title>
      <description><![CDATA[GitHub Actions runs with your secrets and write access to your repo. This guide maps the real attack surface — from the tj-actions compromise to script injection — and gives you copy-paste hardening, OIDC, and scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/github-actions-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-actions-supply-chain-security</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[GitLab ExifTool RCE (CVE-2021-22205) Explained]]></title>
      <description><![CDATA[An unauthenticated attacker could run code on a GitLab server just by uploading an image. The bug was not in GitLab at all — it was in ExifTool. Here is the full story.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-exiftool-cve-2021-22205-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-exiftool-cve-2021-22205-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Go Security Best Practices: A 2026 Field Guide for Backend Teams]]></title>
      <description><![CDATA[Go ships secure defaults most other languages lack — but its supply chain, concurrency model, and cgo edges still leak real vulnerabilities. Here are the practices that actually move the needle.]]></description>
      <link>https://safeguard.sh/resources/blog/go-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Heartbleed (CVE-2014-0160) Explained: When OpenSSL Leaked Memory to Anyone]]></title>
      <description><![CDATA[CVE-2014-0160, Heartbleed, let remote attackers read up to 64KB of an OpenSSL server's memory per request — private keys, sessions, passwords. Here is the missing bounds check that caused it.]]></description>
      <link>https://safeguard.sh/resources/blog/heartbleed-cve-2014-0160-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/heartbleed-cve-2014-0160-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Helm Chart Security Best Practices]]></title>
      <description><![CDATA[Helm charts template every RBAC binding, image reference, and secret your cluster runs. Here is how to harden charts, verify provenance, and stop a templating tool from quietly shipping cluster-admin.]]></description>
      <link>https://safeguard.sh/resources/blog/helm-chart-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/helm-chart-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How to Become an Application Security Engineer in 2026]]></title>
      <description><![CDATA[A practical, no-fluff path into application security for students and career-changers—the role, the skills, free learning resources, portfolio projects, and certifications that actually move the needle.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-become-an-application-security-engineer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-become-an-application-security-engineer</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Career</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Build a Secure npm Package (2026)]]></title>
      <description><![CDATA[A practical checklist for shipping an npm package that resists supply chain attacks: provenance, granular tokens, minimal published files, no install scripts, and ReDoS-safe code.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-build-a-secure-npm-package</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-build-a-secure-npm-package</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Check if an npm Package Is Safe]]></title>
      <description><![CDATA[Before you run npm install, learn a quick, repeatable routine to judge whether an npm package is trustworthy — using metadata, known vulnerabilities, and a scan.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-check-if-an-npm-package-is-safe</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-check-if-an-npm-package-is-safe</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Containerize a Node.js App Securely]]></title>
      <description><![CDATA[The default Node.js Dockerfile runs as root, ships dev dependencies, and bakes secrets into layers. Here is a secure, multi-stage build you can copy, step by step.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-containerize-a-nodejs-app-securely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-containerize-a-nodejs-app-securely</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How to Generate an SBOM: A Step-by-Step Guide]]></title>
      <description><![CDATA[Produce a spec-compliant CycloneDX or SPDX software bill of materials from any repository in minutes, validate it, and attach it to a release — with real commands you can run today.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-generate-an-sbom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-generate-an-sbom</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Learn DevSecOps in 2026: A Beginner's Roadmap]]></title>
      <description><![CDATA[DevSecOps is one of the most hireable skill sets in software today. Here is a practical, mostly free roadmap for students and career-changers—the mindset, the skills, the resources, and the portfolio that gets you hired.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-learn-devsecops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-learn-devsecops</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Career</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Read a CVE: A Beginner's Guide]]></title>
      <description><![CDATA[A plain-language walkthrough of what a CVE record contains and how to read one — the ID, description, CVSS score, CWE, affected versions, and whether a fix exists.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-read-a-cve</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-read-a-cve</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Rotate Leaked API Keys (2026 Playbook)]]></title>
      <description><![CDATA[A leaked API key is a live credential until you kill it. Here is a provider-agnostic rotation playbook — grounded in the Toyota T-Connect and CircleCI incidents — that revokes access without breaking production.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-rotate-leaked-api-keys</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-rotate-leaked-api-keys</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Run Your First Security Scan]]></title>
      <description><![CDATA[New to security? This beginner walkthrough shows you how to run your first vulnerability scan on a real project, read the results, and know exactly what to do next.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-run-your-first-security-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-run-your-first-security-scan</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[HTTP/2 Rapid Reset (CVE-2023-44487) Explained]]></title>
      <description><![CDATA[A protocol-level flaw in HTTP/2 turned a normal feature into the largest DDoS attacks ever recorded. Here is how Rapid Reset works and which library versions fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/http2-rapid-reset-cve-2023-44487-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/http2-rapid-reset-cve-2023-44487-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Introduction to Software Supply Chain Security]]></title>
      <description><![CDATA[Modern software is assembled from far more code than any one team writes. Software supply chain security protects every dependency, build tool, and pipeline that goes into the finished product. Here is the foundational picture.]]></description>
      <link>https://safeguard.sh/resources/blog/introduction-to-software-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/introduction-to-software-supply-chain-security</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Is Lodash Safe? A 2026 Security Guide]]></title>
      <description><![CDATA[Lodash powers a huge slice of the JavaScript ecosystem — and a string of prototype pollution and injection CVEs have made 'is lodash safe' a real question. Here is the honest answer for 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/is-lodash-safe-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/is-lodash-safe-security-guide</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Java Security Best Practices: A Lifecycle Approach for 2026]]></title>
      <description><![CDATA[A practical, lifecycle-based guide to Java security in 2026 — covering input handling, cryptography, dependencies, and runtime hardening with real code.]]></description>
      <link>https://safeguard.sh/resources/blog/java-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Network Policies: A Practical Guide]]></title>
      <description><![CDATA[By default every pod in a Kubernetes cluster can talk to every other pod. NetworkPolicies are how you replace that flat network with least-privilege segmentation — here is how to design and roll them out without breaking traffic.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-network-policies-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-network-policies-guide</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Security Best Practices for 2026]]></title>
      <description><![CDATA[A default Kubernetes cluster trusts too much: root pods, flat networking, and readable secrets. Here are the hardening practices that actually move the needle in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Lessons from SolarWinds: When the Build Pipeline Becomes the Attack Surface]]></title>
      <description><![CDATA[The SUNBURST backdoor reached roughly 18,000 organizations through a trojanized SolarWinds Orion update. Here is what actually happened, and the defenses that hold up years later.]]></description>
      <link>https://safeguard.sh/resources/blog/lessons-from-solarwinds-supply-chain-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lessons-from-solarwinds-supply-chain-attack</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Next.js Security Best Practices: Middleware, Server Components, and Secrets]]></title>
      <description><![CDATA[CVE-2025-29927 let attackers skip Next.js middleware with a single header. Here is where App Router security actually breaks and how to lock it down.]]></description>
      <link>https://safeguard.sh/resources/blog/nextjs-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nextjs-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[NIS2 Directive explained: the software and supply-chain obligations]]></title>
      <description><![CDATA[NIS2 rewired EU cybersecurity law around supply-chain security, vulnerability handling, and 24-hour incident reporting. Here is who is in scope and what your software teams now have to prove.]]></description>
      <link>https://safeguard.sh/resources/blog/nis2-directive-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nis2-directive-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Node.js Security Best Practices for 2026]]></title>
      <description><![CDATA[A practical, runtime-aware checklist for hardening Node.js services in 2026 — from the built-in permission model and secure defaults to dependency risk, secrets, and reachability-based triage.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-security-best-practices-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-security-best-practices-2026</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[npm audit: The Complete Guide to Auditing Node.js Dependencies]]></title>
      <description><![CDATA[How npm audit really works, the exact commands to run in CI, where it silently falls short, and how to close the gaps with reachability-aware SCA and autonomous fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-audit-complete-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-audit-complete-guide</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[OWASP A01: Broken Access Control — A Deep-Dive Guide]]></title>
      <description><![CDATA[Broken Access Control is the #1 OWASP Top 10 (2021) risk. A deep dive into IDOR, missing authorization, real CVEs, and how to detect and fix it in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-a01-broken-access-control</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-a01-broken-access-control</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[OWASP A02: Cryptographic Failures — A Deep-Dive Guide]]></title>
      <description><![CDATA[Cryptographic Failures rank #2 in the OWASP Top 10 (2021). A deep dive into weak algorithms, key management, real CVEs, and how to detect and fix them in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-a02-cryptographic-failures</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-a02-cryptographic-failures</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Auditing Python Dependencies with pip-audit: A Practical Guide]]></title>
      <description><![CDATA[pip-audit is the PyPA-backed tool for scanning Python dependencies against the OSV and PyPI advisory databases. Here is how to run it well — and where it needs backup.]]></description>
      <link>https://safeguard.sh/resources/blog/pip-audit-python-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pip-audit-python-dependencies</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[ProxyLogon (CVE-2021-26855) Explained: The Exchange SSRF That Opened a Pre-Auth Door]]></title>
      <description><![CDATA[CVE-2021-26855, ProxyLogon, is a server-side request forgery in Microsoft Exchange that let unauthenticated attackers impersonate the server — the first link in a chain to full remote code execution.]]></description>
      <link>https://safeguard.sh/resources/blog/proxylogon-cve-2021-26855-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/proxylogon-cve-2021-26855-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[PwnKit (CVE-2021-4034) Explained: Root From a 12-Year-Old Polkit Bug]]></title>
      <description><![CDATA[CVE-2021-4034, aka PwnKit, is a memory-corruption flaw in polkit's pkexec that gives any local user reliable root on nearly every Linux distribution. Here is how it works and how to close it.]]></description>
      <link>https://safeguard.sh/resources/blog/pwnkit-cve-2021-4034-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pwnkit-cve-2021-4034-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Python Code Review Tools: An Honest 2026 Buyer's Guide]]></title>
      <description><![CDATA[A balanced look at the Python code review and static-analysis tools that actually matter in 2026 — Ruff, Bandit, Semgrep, CodeQL, SonarQube, and more — with honest tradeoffs and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/python-code-review-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-code-review-tools</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[PyTorch Security Guide (2026)]]></title>
      <description><![CDATA[PyTorch is the dominant deep-learning framework for research and production — and its torch.load remote-code-execution history makes loading a model checkpoint one of the most security-sensitive operations in modern ML.]]></description>
      <link>https://safeguard.sh/resources/blog/pytorch-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pytorch-security-guide</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[RAG Security Best Practices for 2026]]></title>
      <description><![CDATA[Retrieval-augmented generation wired an untrusted-content pipeline straight into your model's context window. Here are the practices that keep a poisoned document or a leaked chunk from becoming an incident.]]></description>
      <link>https://safeguard.sh/resources/blog/rag-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rag-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[React Security Best Practices: A Practical Checklist for 2026]]></title>
      <description><![CDATA[React escapes JSX text for you, but XSS sinks, secrets in the client bundle, token storage, and a 500-package npm worm are still yours to handle.]]></description>
      <link>https://safeguard.sh/resources/blog/react-security-best-practices-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-security-best-practices-guide</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Ruby Security Best Practices: Deserialization, Injection, and the Gem Supply Chain]]></title>
      <description><![CDATA[Rails is safe by default — until a developer reaches for YAML.load, Kernel#open, or a raw-string query. Here are the Ruby footguns and the gem hygiene that keep them closed.]]></description>
      <link>https://safeguard.sh/resources/blog/ruby-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ruby-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Platform FAQ: Software Supply Chain Security Answered]]></title>
      <description><![CDATA[A plain-English FAQ about the Safeguard platform — what it covers, how the pieces fit together, and how it differs from a traditional scanner-plus-dashboard stack.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-platform-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-platform-faq</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Pricing FAQ: Plans, the $1 Starter, and What You Get]]></title>
      <description><![CDATA[How Safeguard pricing works in 2026 — the $1 Starter plan, what each tier includes, when to upgrade, and how to start with no sales call.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-pricing-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-pricing-faq</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SAST vs DAST vs SCA: The Three Pillars of AppSec Explained]]></title>
      <description><![CDATA[SAST reads your code, DAST attacks your running app, and SCA inspects your dependencies. Here is how the three application security testing methods differ, where each wins, and how to combine them.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-vs-dast-vs-sca-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-vs-dast-vs-sca-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SBOM vs SCA: What's the Difference?]]></title>
      <description><![CDATA[An SBOM is a list of what's in your software. SCA is the practice of analyzing that list for risk. One is an artifact; the other is an activity.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-vs-sca</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-vs-sca</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Securing AI-Generated Code: A Practical 2026 Guide]]></title>
      <description><![CDATA[AI now writes a large share of the code shipping to production, and it reproduces the same insecure patterns humans do — at machine speed. Here is how to keep AI-authored code from becoming your next incident.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-ai-generated-code-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-ai-generated-code-guide</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Alternatives in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[A balanced look at the strongest Snyk alternatives in 2026 — Mend, Sonatype, Checkmarx, GitHub Advanced Security, Endor Labs, and Safeguard — with real pros and cons and a framework for choosing.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-alternatives-2026-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-alternatives-2026-2026</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Checkmarx: A Neutral Comparison for 2026]]></title>
      <description><![CDATA[Snyk and Checkmarx solve application security from opposite ends — developer-first scanning versus enterprise SAST depth. Here is an honest, side-by-side look at both, and where a third option fits.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-checkmarx</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-checkmarx</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 Compliance FAQ: Trust Services Criteria, Type II, and Evidence]]></title>
      <description><![CDATA[A precise FAQ on SOC 2 in 2026 — what it is, Type I vs Type II, the five Trust Services Criteria, observation periods, who performs the audit, and the evidence auditors actually test.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-compliance-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-compliance-faq</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Software Composition Analysis (SCA): Frequently Asked Questions]]></title>
      <description><![CDATA[A practical FAQ on software composition analysis in 2026 — what SCA scans, how reachability cuts false positives, transitive dependencies, VEX, and how modern SCA differs from legacy scanners.]]></description>
      <link>https://safeguard.sh/resources/blog/software-composition-analysis-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-composition-analysis-faq</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security FAQ: 2026 Answers]]></title>
      <description><![CDATA[Plain answers to the most common questions about software supply chain security in 2026 — what it covers, why SBOMs matter, how SLSA and provenance fit, and where to start.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-faq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-faq</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>FAQ</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Beginners: A Friendly First Guide]]></title>
      <description><![CDATA[New to software supply chain security? This gentle, practical guide explains what it is, why every modern app depends on it, and how to run your very first check today.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-for-beginners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-for-beginners</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Financial Services]]></title>
      <description><![CDATA[Banks, insurers, and fintechs now answer to DORA, PCI DSS 4.0, NYDFS 500, and SEC disclosure rules for the software they depend on. Here is what a supply chain security program needs, and how Safeguard delivers it.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-for-financial-services</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-for-financial-services</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Spring Boot Security Best Practices: Hardening the Defaults]]></title>
      <description><![CDATA[Spring Boot's convenience defaults can quietly widen your attack surface. Here's how to harden actuators, dependencies, and auto-configuration for 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-boot-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-boot-security-best-practices</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[The STRIDE Methodology Explained]]></title>
      <description><![CDATA[STRIDE is a threat-modeling mnemonic that turns a blank whiteboard into six specific questions: is this element vulnerable to Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, or Elevation of privilege? Here's how to apply it.]]></description>
      <link>https://safeguard.sh/resources/blog/stride-methodology-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/stride-methodology-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for CISOs]]></title>
      <description><![CDATA[The CISO does not write the vulnerable dependency, but answers for it to the board, the auditor, and the regulator. Here is how to run a supply chain program that stands up to all three.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-for-cisos</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-for-cisos</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Engineering Managers]]></title>
      <description><![CDATA[Engineering managers sit where delivery pressure meets inherited risk. Here is how to own dependency security without stalling the roadmap — what to prioritize, which metrics to track, and how to make remediation a normal part of the sprint.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-for-engineering-managers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-for-engineering-managers</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Platform Engineers]]></title>
      <description><![CDATA[Platform engineers turn security from a request into a default. Here is how to build supply chain guardrails into the paved road so the secure path is also the fast one.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-for-platform-engineers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-for-platform-engineers</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Solutions</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[TensorFlow Security Guide (2026)]]></title>
      <description><![CDATA[TensorFlow is one of the most widely deployed machine-learning frameworks — and its history of model-deserialization RCE and crafted-tensor memory bugs makes its version and loading habits genuinely security-relevant.]]></description>
      <link>https://safeguard.sh/resources/blog/tensorflow-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tensorflow-security-guide</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Understanding dependency confusion via npm package aliasing]]></title>
      <description><![CDATA[npm's `npm:` alias syntax lets a trusted-looking dependency name resolve to attacker-controlled code — here's how that becomes dependency confusion, and how to detect it.]]></description>
      <link>https://safeguard.sh/resources/blog/understanding-dependency-confusion-via-npm-package-aliasing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/understanding-dependency-confusion-via-npm-package-aliasing</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability vs Exploit vs Threat: What's the Difference?]]></title>
      <description><![CDATA[A vulnerability is a weakness, an exploit is the tool that abuses it, and a threat is the actor who wants to. Confusing them muddles how you prioritize risk.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-vs-exploit-vs-threat</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-vs-exploit-vs-threat</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[WebAssembly Security Explained (2026)]]></title>
      <description><![CDATA[WebAssembly runs untrusted code in a memory-isolated sandbox, but sandboxed is not the same as safe. Here is how the Wasm security model actually works and where it breaks.]]></description>
      <link>https://safeguard.sh/resources/blog/webassembly-security-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webassembly-security-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Security Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What Is a CVE? Understanding Vulnerability IDs]]></title>
      <description><![CDATA[A CVE is a unique public ID given to a specific known security weakness, so everyone can talk about the same flaw without confusion. Here's how the system works.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-cve</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-cve</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Malicious Package? Supply-Chain Malware in Open Source]]></title>
      <description><![CDATA[A malicious package is an open-source component built or altered to run attacker code on install or at runtime. Here is how they work, real npm and PyPI cases, and how to defend.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-malicious-package</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-malicious-package</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Software Supply Chain Attack? Explained]]></title>
      <description><![CDATA[A software supply chain attack compromises the code, tools, or pipeline your software depends on — not the product itself. Here is how it works and how to defend.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-software-supply-chain-attack-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-software-supply-chain-attack-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Threat Research</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Vulnerability? A Plain-English Guide]]></title>
      <description><![CDATA[A vulnerability is a weakness in software that an attacker can misuse to do something they shouldn't. Here's what that means, why it matters, and how teams find and fix them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-vulnerability</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is the EU Cyber Resilience Act (CRA)? A software supply chain guide]]></title>
      <description><![CDATA[The Cyber Resilience Act sets binding cybersecurity rules for products with digital elements sold in the EU. Here's who it covers, what it demands of software, and how to prepare before the 2027 deadline.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-eu-cyber-resilience-act-cra</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-eu-cyber-resilience-act-cra</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is IDOR (Insecure Direct Object Reference)?]]></title>
      <description><![CDATA[IDOR lets an attacker swap an ID in a request and read or change data that belongs to someone else. Here is how it works and how to shut it down.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-idor-insecure-direct-object-reference</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-idor-insecure-direct-object-reference</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What Is Secrets Management?]]></title>
      <description><![CDATA[Secrets management is the practice of securely storing, distributing, rotating, and auditing the credentials your software needs to run. Here's how it works, why leaked secrets are a top breach vector, and how to get it right in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-secrets-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-secrets-management</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is SLSA? Supply-chain Levels for Software Artifacts Explained]]></title>
      <description><![CDATA[SLSA is an open framework of graded security levels for build integrity, letting teams prove how a software artifact was produced. Here's how the Build track levels work and how to reach them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-slsa-supply-chain-levels</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-slsa-supply-chain-levels</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is SSRF (Server-Side Request Forgery)?]]></title>
      <description><![CDATA[Server-side request forgery tricks your own backend into making attacker-chosen requests — often against internal systems it should never reach. Here's how SSRF works and how to shut it down.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-ssrf-server-side-request-forgery</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-ssrf-server-side-request-forgery</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What Is the Apache 2.0 License? A Complete Guide]]></title>
      <description><![CDATA[The Apache License 2.0 is a permissive license with an explicit patent grant and a few conditions that set it apart from MIT and BSD. Here is what it permits, requires, and means for compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-apache-2-0-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-apache-2-0-license</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is the MIT License? A Plain-English Guide]]></title>
      <description><![CDATA[The MIT License is one of the shortest and most permissive open-source licenses in existence. Here is exactly what it lets you do, what it requires, and what it means for compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-mit-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-mit-license</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is Threat Modeling?]]></title>
      <description><![CDATA[Threat modeling is the structured practice of asking what can go wrong with a system before you build it, then designing controls to match. Here's the four-question framework, how to run a session, and where it fits supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-threat-modeling-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-threat-modeling-explained</guid>
      <pubDate>Wed, 01 Jul 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Reviews: An Honest Look at the Developer Security Platform]]></title>
      <description><![CDATA[What Snyk reviews consistently praise, where users push back, and how to judge whether it fits your team. A balanced read on the developer-first security platform based on public feedback.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-reviews</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-reviews</guid>
      <pubDate>Wed, 01 Jul 2026 09:21:54 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How GitHub used secret scanning to reach 'inbox zero' on ...]]></title>
      <description><![CDATA[GitHub spent nine months clearing 20,000+ secret scanning alerts across 15,000 repos, finding 90% were noise. Here's how they beat alert fatigue, and how Safeguard automates it.]]></description>
      <link>https://safeguard.sh/resources/blog/how-github-used-secret-scanning-to-reach-inbox-zero-on-20000-alerts-across-15000-repos</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-github-used-secret-scanning-to-reach-inbox-zero-on-20000-alerts-across-15000-repos</guid>
      <pubDate>Wed, 01 Jul 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-7729: Command injection in node-notifier]]></title>
      <description><![CDATA[CVE-2020-7729 lets attacker-influenced input reach node-notifier's OS notifier calls, enabling command injection. Here's the impact, timeline, and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-7729-command-injection-in-node-notifier</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-7729-command-injection-in-node-notifier</guid>
      <pubDate>Wed, 01 Jul 2026 08:01:27 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[GitHub repo confusion and malware repositories]]></title>
      <description><![CDATA[Fake GitHub repos with forged stars and AI-written READMEs are stealing crypto and credentials. Here's how repo confusion attacks actually work.]]></description>
      <link>https://safeguard.sh/resources/blog/github-repo-confusion-and-malware-repositories</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-repo-confusion-and-malware-repositories</guid>
      <pubDate>Wed, 01 Jul 2026 07:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The Security Development Lifecycle (SDL): A Working Guide]]></title>
      <description><![CDATA[The SDL turned security from a pre-release audit into a discipline applied at every phase of building software. What the lifecycle actually contains, where it came from, and how to run it without a Microsoft-sized team.]]></description>
      <link>https://safeguard.sh/resources/blog/security-development-lifecycle-sdl-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-development-lifecycle-sdl-guide</guid>
      <pubDate>Wed, 01 Jul 2026 06:41:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Reducing false positives in secret scanning with context-...]]></title>
      <description><![CDATA[Regex-based secret scanners like GitHub Advanced Security flood teams with false positives. Here's how context-aware LLM reasoning cuts the noise without missing real leaked credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/reducing-false-positives-in-secret-scanning-with-context-aware-llm-reasoning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reducing-false-positives-in-secret-scanning-with-context-aware-llm-reasoning</guid>
      <pubDate>Wed, 01 Jul 2026 06:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-28469: ReDoS in glob-parent]]></title>
      <description><![CDATA[CVE-2020-28469 is a ReDoS flaw in glob-parent before 5.1.2 that can hang processes parsing crafted glob strings. Here's the risk, timeline, and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-28469-redos-in-glob-parent</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-28469-redos-in-glob-parent</guid>
      <pubDate>Wed, 01 Jul 2026 05:20:33 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-23343: ReDoS in path-parse]]></title>
      <description><![CDATA[CVE-2021-23343 is a ReDoS vulnerability in path-parse before 1.0.7 that lets crafted path strings stall Node.js apps. Here's how it works and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-23343-redos-in-path-parse</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-23343-redos-in-path-parse</guid>
      <pubDate>Wed, 01 Jul 2026 04:00:07 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software supply chain attack statistics and trends report]]></title>
      <description><![CDATA[Software supply chain attacks keep climbing year over year. Here are the stats, incidents, and trends security teams need to know in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-attack-statistics-and-trends-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-attack-statistics-and-trends-report</guid>
      <pubDate>Wed, 01 Jul 2026 04:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[6 free GitHub security settings every maintainer should e...]]></title>
      <description><![CDATA[GitHub Advanced Security costs per committer, but six free GitHub repository security settings — from 2FA to secret scanning — already stop most real-world supply chain attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/6-free-github-security-settings-every-maintainer-should-enable</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/6-free-github-security-settings-every-maintainer-should-enable</guid>
      <pubDate>Wed, 01 Jul 2026 03:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2018-1000620: ReDoS in marked markdown parser]]></title>
      <description><![CDATA[A ReDoS flaw in the marked Markdown parser (CVE-2018-1000620) let crafted input stall Node.js services. Here's the impact, fix, and how to catch it in your dependency tree.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2018-1000620-redos-in-marked-markdown-parser</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2018-1000620-redos-in-marked-markdown-parser</guid>
      <pubDate>Wed, 01 Jul 2026 02:39:40 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[NIST SP 800-53 Release 5.2.0: Three New Controls You Cannot Ignore]]></title>
      <description><![CDATA[NIST released SP 800-53 5.2.0 on August 27, 2025 with three new controls focused on patch root-cause analysis, structured logging, and cyber resiliency. Here is what it means for compliance teams.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-sp-800-53-release-5-2-0-software-update-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-sp-800-53-release-5-2-0-software-update-controls</guid>
      <pubDate>Wed, 01 Jul 2026 01:19:13 GMT</pubDate>
      <category>Standards</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Laravel Lang supply chain advisory]]></title>
      <description><![CDATA[A leaked PAT let attackers rewrite 700+ git tags across four Laravel-Lang packages, planting a credential stealer that ran on every PHP request.]]></description>
      <link>https://safeguard.sh/resources/blog/laravel-lang-supply-chain-advisory</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/laravel-lang-supply-chain-advisory</guid>
      <pubDate>Wed, 01 Jul 2026 01:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Inside the GitHub Advisory Database: how vulnerability re...]]></title>
      <description><![CDATA[How vulnerability records actually get into the GitHub Advisory Database — curation, CNA status, GHAS enrichment, and the gaps in severity and version data teams should watch for.]]></description>
      <link>https://safeguard.sh/resources/blog/inside-the-github-advisory-database-how-vulnerability-records-are-curated</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/inside-the-github-advisory-database-how-vulnerability-records-are-curated</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-21680: ReDoS in marked via block token regexes]]></title>
      <description><![CDATA[CVE-2022-21680: how a ReDoS in marked's block-tokenizer regexes could let attackers freeze Markdown-rendering services, plus affected versions, fix, and mitigation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-21680-redos-in-marked-via-block-token-regexes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-21680-redos-in-marked-via-block-token-regexes</guid>
      <pubDate>Tue, 30 Jun 2026 23:58:47 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-21681: Second ReDoS flaw in marked]]></title>
      <description><![CDATA[CVE-2022-21681 is a ReDoS flaw in marked's inline tokenizer that lets crafted Markdown hang parsing. What's affected, severity, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-21681-second-redos-flaw-in-marked</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-21681-second-redos-flaw-in-marked</guid>
      <pubDate>Tue, 30 Jun 2026 22:38:20 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-0235: node-fetch forwards sensitive headers on r...]]></title>
      <description><![CDATA[CVE-2022-0235: node-fetch forwarded cookie and authorization headers across cross-origin redirects. Affected versions, exploitability context, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-0235-node-fetch-forwards-sensitive-headers-on-redirect</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-0235-node-fetch-forwards-sensitive-headers-on-redirect</guid>
      <pubDate>Tue, 30 Jun 2026 21:17:53 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-0155: follow-redirects leaks Proxy-Authorization...]]></title>
      <description><![CDATA[CVE-2022-0155: follow-redirects leaked Proxy-Authorization headers across hosts on redirect, exposing proxy credentials via axios and other widely used npm HTTP clients.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-0155-follow-redirects-leaks-proxy-authorization-header</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-0155-follow-redirects-leaks-proxy-authorization-header</guid>
      <pubDate>Tue, 30 Jun 2026 19:57:27 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[npm run dev: What It Does and How to Run It Safely]]></title>
      <description><![CDATA[npm run dev starts your project's development server via a script in package.json. Here is what actually happens under the hood and the security risks worth knowing.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-run-dev</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-run-dev</guid>
      <pubDate>Tue, 30 Jun 2026 18:37:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-0536: follow-redirects leaks Authorization heade...]]></title>
      <description><![CDATA[CVE-2022-0536 let follow-redirects forward Authorization headers to third-party hosts on cross-domain redirects, exposing tokens and credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-0536-follow-redirects-leaks-authorization-header-cross-domain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-0536-follow-redirects-leaks-authorization-header-cross-domain</guid>
      <pubDate>Tue, 30 Jun 2026 17:16:33 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-26159: SSRF/credential exposure in follow-redire...]]></title>
      <description><![CDATA[CVE-2023-26159 shows how flawed URL parsing in follow-redirects let attackers trigger SSRF and leak Authorization headers across unintended hosts.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-26159-ssrfcredential-exposure-in-follow-redirects-url-parsing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-26159-ssrfcredential-exposure-in-follow-redirects-url-parsing</guid>
      <pubDate>Tue, 30 Jun 2026 15:56:07 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-37890: Denial of service in ws WebSocket library]]></title>
      <description><![CDATA[CVE-2024-37890 lets attackers crash Node.js servers running vulnerable ws WebSocket versions with a single crafted request. Here's what's affected and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-37890-denial-of-service-in-ws-websocket-library</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-37890-denial-of-service-in-ws-websocket-library</guid>
      <pubDate>Tue, 30 Jun 2026 14:35:40 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-25883: ReDoS in semver package]]></title>
      <description><![CDATA[CVE-2022-25883 is a ReDoS flaw in the widely used semver npm package. Here's what versions are affected, its severity, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-25883-redos-in-semver-package</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-25883-redos-in-semver-package</guid>
      <pubDate>Tue, 30 Jun 2026 13:15:13 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[browser-image-compression: Is Client-Side Image Compression Safe?]]></title>
      <description><![CDATA[browser-image-compression shrinks images in the browser before upload. Here is how it works, its security trade-offs, and why client-side compression is never validation.]]></description>
      <link>https://safeguard.sh/resources/blog/browser-image-compression</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/browser-image-compression</guid>
      <pubDate>Tue, 30 Jun 2026 11:54:46 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-3803: ReDoS in nth-check CSS selector parser]]></title>
      <description><![CDATA[CVE-2021-3803 is a ReDoS flaw in nth-check's CSS selector regex, reachable via css-select, svgo, and countless React build toolchains relying on them.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-3803-redos-in-nth-check-css-selector-parser</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-3803-redos-in-nth-check-css-selector-parser</guid>
      <pubDate>Tue, 30 Jun 2026 10:34:20 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-3807: ReDoS in ansi-regex]]></title>
      <description><![CDATA[A ReDoS flaw in the widely-depended-on ansi-regex npm package could hang Node.js processes on crafted input. Here's what's affected and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-3807-redos-in-ansi-regex</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-3807-redos-in-ansi-regex</guid>
      <pubDate>Tue, 30 Jun 2026 09:13:53 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[GitHub for Beginners: getting started with GitHub securit...]]></title>
      <description><![CDATA[A beginner's guide to GitHub's free security tools, what GitHub Advanced Security actually adds, its 2025 pricing shift, and the supply chain gaps neither one covers.]]></description>
      <link>https://safeguard.sh/resources/blog/github-for-beginners-getting-started-with-github-security-features</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-for-beginners-getting-started-with-github-security-features</guid>
      <pubDate>Tue, 30 Jun 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-24999: Prototype pollution / DoS in qs querystri...]]></title>
      <description><![CDATA[CVE-2022-24999 exposes a prototype pollution and denial-of-service flaw in the qs querystring library used across the Node.js ecosystem.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-24999-prototype-pollution-dos-in-qs-querystring-library</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-24999-prototype-pollution-dos-in-qs-querystring-library</guid>
      <pubDate>Tue, 30 Jun 2026 07:53:26 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-23364: ReDoS in browserslist]]></title>
      <description><![CDATA[A regex denial of service in browserslist (CVE-2021-23364) could stall Node.js builds via crafted version strings. Here's the fix and how Safeguard catches it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-23364-redos-in-browserslist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-23364-redos-in-browserslist</guid>
      <pubDate>Tue, 30 Jun 2026 06:33:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Advanced Security setup made simple: guided config...]]></title>
      <description><![CDATA[GitHub Advanced Security setup takes weeks, not clicks. Here's what GHAS configuration really involves, what it costs in 2026, and how Safeguard cuts the tuning work.]]></description>
      <link>https://safeguard.sh/resources/blog/github-advanced-security-setup-made-simple-guided-configuration-walkthrough</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-advanced-security-setup-made-simple-guided-configuration-walkthrough</guid>
      <pubDate>Tue, 30 Jun 2026 06:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVSS 4.0 Scoring Adoption: What Changed]]></title>
      <description><![CDATA[Two years after CVSS 4.0's release, adoption remains uneven. Here is where scoring really changed, where it did not, and how to handle mixed datasets.]]></description>
      <link>https://safeguard.sh/resources/blog/cvss-4-0-scoring-adoption-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cvss-4-0-scoring-adoption-review</guid>
      <pubDate>Tue, 30 Jun 2026 05:12:33 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[A forgotten contributor account compromised the Mastra npm scope]]></title>
      <description><![CDATA[A dormant npm account with unrevoked publish rights let attackers trojanize 144 @mastra packages in 88 minutes, dropping a crypto-wallet RAT tied to Sapphire Sleet.]]></description>
      <link>https://safeguard.sh/resources/blog/a-forgotten-contributor-account-compromised-the-mastra-npm-scope</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/a-forgotten-contributor-account-compromised-the-mastra-npm-scope</guid>
      <pubDate>Tue, 30 Jun 2026 04:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CISA's Software Identification Ecosystem: What You Need to Know]]></title>
      <description><![CDATA[CISA is building a comprehensive software identification ecosystem that ties SBOMs, vulnerabilities, and procurement together. Here is what it means for software producers and consumers.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-software-identification-ecosystem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-software-identification-ecosystem</guid>
      <pubDate>Tue, 30 Jun 2026 03:52:06 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Advanced Security for Azure DevOps: general availa...]]></title>
      <description><![CDATA[GitHub Advanced Security for Azure DevOps hit GA on June 1, 2023 at $49/committer/month. Here's what it covers, what it misses, and how Safeguard fills the gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/github-advanced-security-for-azure-devops-general-availability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-advanced-security-for-azure-devops-general-availability</guid>
      <pubDate>Tue, 30 Jun 2026 03:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-7676: XSS in vue-template-compiler]]></title>
      <description><![CDATA[CVE-2020-7676 is an XSS flaw in vue-template-compiler (pre-2.6.12) that lets attacker-controlled templates bypass URI sanitization. Impact, fix, and remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-7676-xss-in-vue-template-compiler</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-7676-xss-in-vue-template-compiler</guid>
      <pubDate>Tue, 30 Jun 2026 02:31:40 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-32314: Sandbox escape in vm2]]></title>
      <description><![CDATA[CVE-2023-32314 let attackers escape the vm2 Node.js sandbox for remote code execution. Here's the CVSS 10.0 flaw, affected versions, timeline, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-32314-sandbox-escape-in-vm2</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-32314-sandbox-escape-in-vm2</guid>
      <pubDate>Tue, 30 Jun 2026 01:11:13 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Clinejection: prompt injection turns AI coding bot into supply chain attack]]></title>
      <description><![CDATA[A prompt-injected GitHub issue title hijacked Cline's AI triage bot, poisoned its build cache, and pushed a malicious npm release to 4,000 developers.]]></description>
      <link>https://safeguard.sh/resources/blog/clinejection-prompt-injection-turns-ai-coding-bot-into-supply-chain-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/clinejection-prompt-injection-turns-ai-coding-bot-into-supply-chain-attack</guid>
      <pubDate>Tue, 30 Jun 2026 01:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Dependabot security updates and automated dependency pull...]]></title>
      <description><![CDATA[Dependabot opens patch PRs from known CVEs, but backlogs pile up and malicious packages slip through. Here's what it misses versus GitHub Advanced Security.]]></description>
      <link>https://safeguard.sh/resources/blog/dependabot-security-updates-and-automated-dependency-pull-requests</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependabot-security-updates-and-automated-dependency-pull-requests</guid>
      <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-30547: Sandbox escape via Node custom inspect in...]]></title>
      <description><![CDATA[CVE-2023-30547 lets attackers escape the vm2 Node.js sandbox via a crafted custom inspect method, achieving host code execution. Here's the impact, timeline, and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-30547-sandbox-escape-via-node-custom-inspect-in-vm2</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-30547-sandbox-escape-via-node-custom-inspect-in-vm2</guid>
      <pubDate>Mon, 29 Jun 2026 23:50:46 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-37466: Remote code execution via vm2 sandbox escape]]></title>
      <description><![CDATA[A critical vm2 sandbox escape (CVE-2023-37466) lets untrusted JavaScript break out to achieve remote code execution on the host Node.js process.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-37466-remote-code-execution-via-vm2-sandbox-escape</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-37466-remote-code-execution-via-vm2-sandbox-escape</guid>
      <pubDate>Mon, 29 Jun 2026 22:30:20 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Mobile Application Penetration Testing: A Practical Guide]]></title>
      <description><![CDATA[How mobile application penetration testing actually works — the methodology, the tools, and what to expect from a good engagement — from someone who runs them.]]></description>
      <link>https://safeguard.sh/resources/blog/mobile-application-penetration-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mobile-application-penetration-testing</guid>
      <pubDate>Mon, 29 Jun 2026 21:09:53 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Binary Provenance]]></title>
      <description><![CDATA[Binary provenance is verifiable metadata proving which source, builder, and process produced an artifact — the paper trail that makes 'where did this come from' answerable.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-binary-provenance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-binary-provenance</guid>
      <pubDate>Mon, 29 Jun 2026 19:49:26 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Elena Kovacs)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-3517: ReDoS in minimatch pattern matching]]></title>
      <description><![CDATA[CVE-2022-3517 is a high-severity ReDoS flaw in minimatch's glob-to-regex conversion, impacting a huge share of the npm ecosystem's dependency graph.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-3517-redos-in-minimatch-pattern-matching</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-3517-redos-in-minimatch-pattern-matching</guid>
      <pubDate>Mon, 29 Jun 2026 18:28:59 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-43138: Code injection risk in async npm package]]></title>
      <description><![CDATA[A prototype-pollution flaw in async's iterator functions (CVE-2021-43138) could escalate to code injection. Affected versions, severity, timeline, and remediation steps inside.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-43138-code-injection-risk-in-async-npm-package</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-43138-code-injection-risk-in-async-npm-package</guid>
      <pubDate>Mon, 29 Jun 2026 17:08:33 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-19844: Django password reset token weakness]]></title>
      <description><![CDATA[CVE-2019-19844 let attackers hijack Django accounts by exploiting how case-sensitive email matching broke the base36 password reset token flow.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-19844-django-password-reset-token-weakness</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-19844-django-password-reset-token-weakness</guid>
      <pubDate>Mon, 29 Jun 2026 15:48:06 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2018-14574: Open redirect in Django CommonMiddleware]]></title>
      <description><![CDATA[CVE-2018-14574 let attackers abuse Django CommonMiddleware's APPEND_SLASH redirect to send users to external, attacker-controlled domains.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2018-14574-open-redirect-in-django-commonmiddleware</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2018-14574-open-redirect-in-django-commonmiddleware</guid>
      <pubDate>Mon, 29 Jun 2026 14:27:39 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Is Java Safe? A Realistic Look at Java Security in 2025]]></title>
      <description><![CDATA[Is Java safe? The language has strong built-in protections, but real Java risk lives in dependencies, deserialization, and configuration. Here is the honest picture.]]></description>
      <link>https://safeguard.sh/resources/blog/is-java-safe</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/is-java-safe</guid>
      <pubDate>Mon, 29 Jun 2026 13:07:13 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How to Git Pull a Remote Branch (and Check It Out Safely)]]></title>
      <description><![CDATA[A clear guide to git pull remote branch workflows: fetching, checking out a remote branch for the first time, and the tracking setup that avoids surprises.]]></description>
      <link>https://safeguard.sh/resources/blog/git-pull-remote-branch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-pull-remote-branch</guid>
      <pubDate>Mon, 29 Jun 2026 11:46:46 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How Is DevOps Delivery Value Measured?]]></title>
      <description><![CDATA[How DevOps delivery value is measured in practice: the four DORA metrics, why security belongs in the picture, and the traps that make the numbers lie.]]></description>
      <link>https://safeguard.sh/resources/blog/how-devops-delivery-value-measured</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-devops-delivery-value-measured</guid>
      <pubDate>Mon, 29 Jun 2026 10:26:19 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[ESLint config-prettier maintainer npm account compromise]]></title>
      <description><![CDATA[A phished maintainer account turned eslint-config-prettier and four sibling npm packages into a malicious install-time payload — here's what happened and how to check exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/eslint-config-prettier-maintainer-npm-account-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eslint-config-prettier-maintainer-npm-account-compromise</guid>
      <pubDate>Mon, 29 Jun 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Capture the Flag Cyber Security: How CTF Games Work]]></title>
      <description><![CDATA[Capture the flag cyber security competitions turn real security skills into a game where you find hidden flags by breaking, analyzing, and defending systems. Here is how they work and why they build practitioners.]]></description>
      <link>https://safeguard.sh/resources/blog/capture-the-flag-cyber-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/capture-the-flag-cyber-security</guid>
      <pubDate>Mon, 29 Jun 2026 09:05:53 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Dependabot malware detection in open source packages]]></title>
      <description><![CDATA[Dependabot catches known vulnerabilities, not injected malware. Here's how GitHub Advanced Security handles malicious packages — and where the gaps remain.]]></description>
      <link>https://safeguard.sh/resources/blog/dependabot-malware-detection-in-open-source-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependabot-malware-detection-in-open-source-packages</guid>
      <pubDate>Mon, 29 Jun 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Snyk and Log4j: Finding and Fixing Log4Shell in Your Dependencies]]></title>
      <description><![CDATA[Snyk can detect the Log4Shell family of Log4j vulnerabilities across your dependency tree, including transitive ones. Here is what it finds, how the fix path works, and the limits to know.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-log4j</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-log4j</guid>
      <pubDate>Mon, 29 Jun 2026 07:45:26 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Understanding the software supply chain attack surface]]></title>
      <description><![CDATA[SolarWinds, Log4Shell, and XZ Utils show the software supply chain attack surface is bigger than any single scan. Here's how to actually map and shrink it.]]></description>
      <link>https://safeguard.sh/resources/blog/understanding-the-software-supply-chain-attack-surface</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/understanding-the-software-supply-chain-attack-surface</guid>
      <pubDate>Mon, 29 Jun 2026 07:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Sentry for Node.js: Error Monitoring Without Leaking Secrets]]></title>
      <description><![CDATA[Setting up Sentry in a Node.js app takes minutes, but doing it securely means scrubbing sensitive data before it ever leaves your server. Here is how.]]></description>
      <link>https://safeguard.sh/resources/blog/sentry-node</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sentry-node</guid>
      <pubDate>Mon, 29 Jun 2026 06:24:59 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Auto-triage rules for Dependabot pull requests at scale]]></title>
      <description><![CDATA[Dependabot floods teams with PRs, but not every alert deserves equal attention. Here's how auto-triage rules cut noise at scale, and where GHAS falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/auto-triage-rules-for-dependabot-pull-requests-at-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/auto-triage-rules-for-dependabot-pull-requests-at-scale</guid>
      <pubDate>Mon, 29 Jun 2026 06:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Network Hacking Tools Attackers Use — and How Defenders Answer]]></title>
      <description><![CDATA[A defender's field guide to the network hacking tools attackers reach for — reconnaissance, sniffing, exploitation, credential attacks — and the detection and control that answers each class.]]></description>
      <link>https://safeguard.sh/resources/blog/network-security-tools-attackers-use</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/network-security-tools-attackers-use</guid>
      <pubDate>Mon, 29 Jun 2026 05:04:33 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[SBOM as a supply chain defense strategy]]></title>
      <description><![CDATA[SBOMs turn "are we affected?" from a weeks-long fire drill into a query. Here's how they defend against real supply chain attacks like Log4Shell and XZ Utils.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-as-a-supply-chain-defense-strategy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-as-a-supply-chain-defense-strategy</guid>
      <pubDate>Mon, 29 Jun 2026 04:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-33203: Path traversal via Django admindocs]]></title>
      <description><![CDATA[CVE-2021-33203 let authenticated Django staff users traverse outside admindocs' template directory. Here's what's affected, real severity context, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-33203-path-traversal-via-django-admindocs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-33203-path-traversal-via-django-admindocs</guid>
      <pubDate>Mon, 29 Jun 2026 03:44:06 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[GitHub dependency graph and dependency review explained]]></title>
      <description><![CDATA[How GitHub Dependency Graph and Dependency Review actually work, what GitHub Advanced Security adds on top, and where the coverage gaps are for teams relying on manifest-only scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/github-dependency-graph-and-dependency-review-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-dependency-graph-and-dependency-review-explained</guid>
      <pubDate>Mon, 29 Jun 2026 03:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-9402: SQL injection via Django GIS functions]]></title>
      <description><![CDATA[CVE-2020-9402 let attackers inject SQL through GeoDjango's tolerance parameter on Oracle backends. Here's what's affected, severity context, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-9402-sql-injection-via-django-gis-functions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-9402-sql-injection-via-django-gis-functions</guid>
      <pubDate>Mon, 29 Jun 2026 02:23:39 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-34265: SQL injection via Trunc/Extract database ...]]></title>
      <description><![CDATA[A technical breakdown of CVE-2022-34265, the Django SQL injection flaw in Trunc() and Extract(), covering affected versions, risk, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-34265-sql-injection-via-truncextract-database-functions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-34265-sql-injection-via-truncextract-database-functions</guid>
      <pubDate>Mon, 29 Jun 2026 01:03:12 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Preventing malicious packages with automated detection]]></title>
      <description><![CDATA[Malicious npm and PyPI packages skip CVEs entirely. Here's how attackers get them published and how automated detection catches them before they ship.]]></description>
      <link>https://safeguard.sh/resources/blog/preventing-malicious-packages-with-automated-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preventing-malicious-packages-with-automated-detection</guid>
      <pubDate>Mon, 29 Jun 2026 01:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[License compliance checks for open source dependencies on...]]></title>
      <description><![CDATA[GitHub Advanced Security scans for vulnerabilities, not license risk. Here's what real open source license compliance requires—and where GHAS falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/license-compliance-checks-for-open-source-dependencies-on-github</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/license-compliance-checks-for-open-source-dependencies-on-github</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2018-6188: User enumeration in Django password reset]]></title>
      <description><![CDATA[A timing difference in Django password resets let attackers confirm valid emails via response latency. CVE-2018-6188 impact, fix versions, and remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2018-6188-user-enumeration-in-django-password-reset</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2018-6188-user-enumeration-in-django-password-reset</guid>
      <pubDate>Sun, 28 Jun 2026 23:42:46 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[XSS Payloads on GitHub: What Those Repos Contain and How to Defend]]></title>
      <description><![CDATA[Searching for XSS payloads on GitHub turns up huge lists of test strings. Here is what they are actually for, how defenders use them responsibly, and how to stop cross-site scripting in your own code.]]></description>
      <link>https://safeguard.sh/resources/blog/xss-payloads-github</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xss-payloads-github</guid>
      <pubDate>Sun, 28 Jun 2026 22:22:19 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Docs: A Practical Guide to Finding What You Need]]></title>
      <description><![CDATA[The Snyk docs at docs.snyk.io cover four scanning products and a maze of integrations. Here's how they're organized and the fastest path to the page you actually want.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-docs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-docs</guid>
      <pubDate>Sun, 28 Jun 2026 21:01:52 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Install Python on Mac Terminal: A Step-by-Step Guide]]></title>
      <description><![CDATA[The clean way to install Python on a Mac using the terminal, why you should not touch the system Python, and how to keep your install secure and up to date.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-install-python-on-mac-terminal</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-install-python-on-mac-terminal</guid>
      <pubDate>Sun, 28 Jun 2026 19:41:26 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Semgrep SCA: How Reachability Changes Dependency Scanning]]></title>
      <description><![CDATA[What Semgrep SCA (Supply Chain) does, how its reachability analysis cuts alert noise, where it fits, and how to run it in CI.]]></description>
      <link>https://safeguard.sh/resources/blog/semgrep-sca</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/semgrep-sca</guid>
      <pubDate>Sun, 28 Jun 2026 18:20:59 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[DAST Tools List: The Dynamic Application Security Scanners That Matter]]></title>
      <description><![CDATA[A practical DAST tools list for 2025: the open source and commercial scanners worth knowing, what each is good at, and how to fit DAST into your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-tools-list</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-tools-list</guid>
      <pubDate>Sun, 28 Jun 2026 17:00:32 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Trivy vs Snyk: A Practical Comparison for Real Pipelines]]></title>
      <description><![CDATA[Trivy vs Snyk is really open-source scanner versus commercial platform. Here is where each wins, where they overlap, and why many teams run both.]]></description>
      <link>https://safeguard.sh/resources/blog/trivy-vs-snyk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trivy-vs-snyk</guid>
      <pubDate>Sun, 28 Jun 2026 15:40:06 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[spring-security-core Maven: Keeping Your Auth Layer Patched]]></title>
      <description><![CDATA[The spring-security-core Maven artifact is the heart of authentication and authorization in Spring apps, and a handful of recent CVEs make version hygiene non-negotiable.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-security-core-maven</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-security-core-maven</guid>
      <pubDate>Sun, 28 Jun 2026 14:19:39 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[npm-check-updates: A Safe Dependency Upgrade Workflow]]></title>
      <description><![CDATA[npm check updates (ncu) shows you every dependency with a newer version than your ranges allow. The tool is simple; the workflow around it is what keeps upgrades from breaking prod.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-check-updates-safe-upgrade-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-check-updates-safe-upgrade-workflow</guid>
      <pubDate>Sun, 28 Jun 2026 12:59:12 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2018-18074: requests library leaks Authorization head...]]></title>
      <description><![CDATA[The Python requests library leaked Authorization headers on same-host HTTPS-to-HTTP redirects, exposing credentials to sniffing before v2.20.0.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2018-18074-requests-library-leaks-authorization-header-on-redirect</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2018-18074-requests-library-leaks-authorization-header-on-redirect</guid>
      <pubDate>Sun, 28 Jun 2026 11:38:45 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[An XSS Example That Explains How Cross-Site Scripting Works]]></title>
      <description><![CDATA[A clear XSS example shows how unescaped user input becomes executable script in a victim's browser, and why output encoding and CSP are the fixes that hold.]]></description>
      <link>https://safeguard.sh/resources/blog/xss-example</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xss-example</guid>
      <pubDate>Sun, 28 Jun 2026 10:18:19 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Vendor breach exposure: third-party risk lessons from the Klue incident]]></title>
      <description><![CDATA[A single forgotten credential at Klue exposed Salesforce CRM data at 14+ companies, including Snyk and Huntress—here's what it teaches about vendor risk.]]></description>
      <link>https://safeguard.sh/resources/blog/vendor-breach-exposure-third-party-risk-lessons-from-the-klue-incident</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vendor-breach-exposure-third-party-risk-lessons-from-the-klue-incident</guid>
      <pubDate>Sun, 28 Jun 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SBOM export in GitHub: generating a software bill of mate...]]></title>
      <description><![CDATA[GitHub lets you export an SPDX SBOM in two clicks, but the file only reflects what its dependency graph can see. Here's what's missing and how Safeguard fills it.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-export-in-github-generating-a-software-bill-of-materials</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-export-in-github-generating-a-software-bill-of-materials</guid>
      <pubDate>Sun, 28 Jun 2026 09:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-32681: requests leaks Proxy-Authorization on red...]]></title>
      <description><![CDATA[A malicious proxy could capture Proxy-Authorization credentials from Python's requests library when redirects crossed to HTTPS, before v2.31.0.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-32681-requests-leaks-proxy-authorization-on-redirect</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-32681-requests-leaks-proxy-authorization-on-redirect</guid>
      <pubDate>Sun, 28 Jun 2026 08:57:52 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-33503: ReDoS in urllib3 URL authority parsing]]></title>
      <description><![CDATA[CVE-2021-33503 exposes urllib3 before 1.26.5 to a ReDoS in URL authority parsing, letting attacker URLs exhaust CPU. What to patch and why.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-33503-redos-in-urllib3-url-authority-parsing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-33503-redos-in-urllib3-url-authority-parsing</guid>
      <pubDate>Sun, 28 Jun 2026 07:37:25 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[10 Docker image security best practices]]></title>
      <description><![CDATA[Ten concrete Docker image security practices — minimal base images, secret handling, reachability-based scanning, non-root runtimes, and SBOMs — with real CVEs and data.]]></description>
      <link>https://safeguard.sh/resources/blog/10-docker-image-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/10-docker-image-security-best-practices</guid>
      <pubDate>Sun, 28 Jun 2026 07:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-26137: CRLF injection in urllib3 header handling]]></title>
      <description><![CDATA[CVE-2020-26137 let attackers inject CRLF sequences into urllib3-built HTTP requests. Here's the impact, affected versions, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-26137-crlf-injection-in-urllib3-header-handling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-26137-crlf-injection-in-urllib3-header-handling</guid>
      <pubDate>Sun, 28 Jun 2026 06:16:59 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[DAST vs SAST vs IAST: choosing the right testing method]]></title>
      <description><![CDATA[SAST, DAST, and IAST each test different things. Here's how Checkmarx positions its platform, and where Safeguard's supply chain approach fits alongside it.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-vs-sast-vs-iast-choosing-the-right-testing-method</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-vs-sast-vs-iast-choosing-the-right-testing-method</guid>
      <pubDate>Sun, 28 Jun 2026 06:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[DAST Vendors Compared: Picking a Dynamic Scanning Tool]]></title>
      <description><![CDATA[Choosing among DAST vendors hinges on how well the scanner authenticates, crawls modern apps and APIs, and fits into CI without turning into a manual chore.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-vendors</guid>
      <pubDate>Sun, 28 Jun 2026 04:56:32 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Top Docker security vulnerabilities to watch]]></title>
      <description><![CDATA[Runc escapes, exposed Docker APIs, malicious registry images: the Docker vulnerabilities actually driving incidents in 2024-2025, and how to triage what's exploitable.]]></description>
      <link>https://safeguard.sh/resources/blog/top-docker-security-vulnerabilities-to-watch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-docker-security-vulnerabilities-to-watch</guid>
      <pubDate>Sun, 28 Jun 2026 04:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[DAST Automated Testing: How It Works and Why It Belongs in CI]]></title>
      <description><![CDATA[A DAST automated test probes your running application for vulnerabilities the way an attacker would, on every build. Here is how it works and the benefits of wiring it into CI.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-automated-test</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-automated-test</guid>
      <pubDate>Sun, 28 Jun 2026 03:36:05 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[False positives vs. false negatives in security scanning]]></title>
      <description><![CDATA[False positives waste engineering time; false negatives cause breaches. A verifiable, metrics-based look at how Safeguard and Checkmarx approach scan accuracy.]]></description>
      <link>https://safeguard.sh/resources/blog/false-positives-vs-false-negatives-in-security-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/false-positives-vs-false-negatives-in-security-scanning</guid>
      <pubDate>Sun, 28 Jun 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Choose a Vulnerability Assessment Solution]]></title>
      <description><![CDATA[A vulnerability assessment solution finds, ranks, and tracks weaknesses across your systems. Here is what separates a useful one from a report generator.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-assessment-solution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-assessment-solution</guid>
      <pubDate>Sun, 28 Jun 2026 02:15:39 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Choosing secure base images for containers]]></title>
      <description><![CDATA[Base image choice drives most of your container's attack surface. Here's what secure Docker base images actually require, with concrete CVE data.]]></description>
      <link>https://safeguard.sh/resources/blog/choosing-secure-base-images-for-containers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/choosing-secure-base-images-for-containers</guid>
      <pubDate>Sun, 28 Jun 2026 01:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2017-18342: Arbitrary code execution via PyYAML yaml....]]></title>
      <description><![CDATA[CVE-2017-18342 lets attackers achieve remote code execution via PyYAML's yaml.load(), which deserialized untrusted YAML into live Python objects by default.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2017-18342-arbitrary-code-execution-via-pyyaml-yamlload</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2017-18342-arbitrary-code-execution-via-pyyaml-yamlload</guid>
      <pubDate>Sun, 28 Jun 2026 00:55:12 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability assessment vs. penetration testing]]></title>
      <description><![CDATA[Vulnerability assessment and penetration testing solve different problems. Here's how Safeguard's supply chain approach compares to Checkmarx's AppSec platform.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-assessment-vs-penetration-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-assessment-vs-penetration-testing</guid>
      <pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-1747: PyYAML full_load still allows code execution]]></title>
      <description><![CDATA[CVE-2020-1747 shows PyYAML's FullLoader and full_load() could still trigger arbitrary code execution on untrusted YAML before 5.3.1. Here's the full breakdown.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-1747-pyyaml-fullload-still-allows-code-execution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-1747-pyyaml-fullload-still-allows-code-execution</guid>
      <pubDate>Sat, 27 Jun 2026 23:34:45 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-14343: PyYAML arbitrary code execution via pytho...]]></title>
      <description><![CDATA[CVE-2020-14343 lets attackers run arbitrary code via PyYAML's python/object/new tag, bypassing an earlier FullLoader fix. Versions, CVSS, and remediation inside.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-14343-pyyaml-arbitrary-code-execution-via-pythonobjectnew</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-14343-pyyaml-arbitrary-code-execution-via-pythonobjectnew</guid>
      <pubDate>Sat, 27 Jun 2026 22:14:19 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-22817: Arbitrary code execution in Pillow via Im...]]></title>
      <description><![CDATA[CVE-2022-22817 lets attackers achieve arbitrary code execution via Pillow's ImageMath.eval() when environment data is attacker-controlled. Patch to 9.0.1+.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-22817-arbitrary-code-execution-in-pillow-via-imagematheval</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-22817-arbitrary-code-execution-in-pillow-via-imagematheval</guid>
      <pubDate>Sat, 27 Jun 2026 20:53:52 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Source Code Protection: How to Keep Your Codebase From Leaking]]></title>
      <description><![CDATA[Source code protection is less about obfuscation and more about controlling access, catching secrets before they leak, and knowing when your code has escaped. Here is how to do it.]]></description>
      <link>https://safeguard.sh/resources/blog/source-code-protection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/source-code-protection</guid>
      <pubDate>Sat, 27 Jun 2026 19:33:25 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The AGPL Licence Explained: Obligations and Real Risks]]></title>
      <description><![CDATA[The AGPL licence closes the SaaS loophole in the GPL by triggering source-sharing over the network. Here is what it obliges, and where it bites teams by surprise.]]></description>
      <link>https://safeguard.sh/resources/blog/licence-agpl</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/licence-agpl</guid>
      <pubDate>Sat, 27 Jun 2026 18:12:58 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript DI: Dependency Injection Patterns and Their Security Impact]]></title>
      <description><![CDATA[JavaScript DI (dependency injection) decouples your code, but the container that wires it together is also a place security can slip. Here is how to use it well.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-di</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-di</guid>
      <pubDate>Sat, 27 Jun 2026 16:52:32 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Audit: How to Audit Your Cloud Environment for Security]]></title>
      <description><![CDATA[A cloud audit is a systematic review of your cloud accounts against security and compliance baselines. Here is a practical process covering identity, configuration, logging, and evidence.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-audit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-audit</guid>
      <pubDate>Sat, 27 Jun 2026 15:32:05 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-25287: Buffer overflow in Pillow SGI decoder]]></title>
      <description><![CDATA[A heap buffer overflow in Pillow's SGI image decoder (CVE-2021-25287) let crafted images corrupt memory. Here's the impact, fix, and remediation guidance.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-25287-buffer-overflow-in-pillow-sgi-decoder</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-25287-buffer-overflow-in-pillow-sgi-decoder</guid>
      <pubDate>Sat, 27 Jun 2026 14:11:38 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-25288: Buffer overflow in Pillow FLI decoder]]></title>
      <description><![CDATA[CVE-2021-25288 is a buffer overflow in Pillow's FLI decoder, fixed in Pillow 8.1.0. Here's what's affected, the risk profile, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-25288-buffer-overflow-in-pillow-fli-decoder</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-25288-buffer-overflow-in-pillow-fli-decoder</guid>
      <pubDate>Sat, 27 Jun 2026 12:51:12 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-35654: Buffer over-read in Pillow PCX decoder]]></title>
      <description><![CDATA[A buffer over-read in Pillow's PCX decoder (CVE-2020-35654) could crash image-processing services on crafted files. Here's the fix and detection guidance.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-35654-buffer-over-read-in-pillow-pcx-decoder</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-35654-buffer-over-read-in-pillow-pcx-decoder</guid>
      <pubDate>Sat, 27 Jun 2026 11:30:45 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-35655: Decompression bomb DoS in Pillow]]></title>
      <description><![CDATA[A crafted image file could force Pillow to over-allocate memory, causing denial of service. Here's what CVE-2020-35655 affects, its severity, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-35655-decompression-bomb-dos-in-pillow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-35655-decompression-bomb-dos-in-pillow</guid>
      <pubDate>Sat, 27 Jun 2026 10:10:18 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Distroless container images explained]]></title>
      <description><![CDATA[Distroless images cut container size by up to 90% and eliminate OS-level CVEs, but they don't secure app dependencies. Here's how they work and where they fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/distroless-container-images-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/distroless-container-images-explained</guid>
      <pubDate>Sat, 27 Jun 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Unified AppSec platform vs. stitched-together point solut...]]></title>
      <description><![CDATA[Checkmarx built its AppSec suite through years of acquisitions. Safeguard built one risk graph. Here's how to verify which model actually reduces triage work.]]></description>
      <link>https://safeguard.sh/resources/blog/unified-appsec-platform-vs-stitched-together-point-solutions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unified-appsec-platform-vs-stitched-together-point-solutions</guid>
      <pubDate>Sat, 27 Jun 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-50447: Arbitrary code execution via Pillow Image...]]></title>
      <description><![CDATA[A patch bypass in Pillow's ImageMath.eval() reopens arbitrary code execution first flagged in CVE-2022-22817. Here's what changed and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-50447-arbitrary-code-execution-via-pillow-imagemath-eval-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-50447-arbitrary-code-execution-via-pillow-imagemath-eval-bypass</guid>
      <pubDate>Sat, 27 Jun 2026 08:49:52 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-49083: NULL pointer dereference in python-crypto...]]></title>
      <description><![CDATA[A NULL pointer dereference in python-cryptography's PKCS7 loader (CVE-2023-49083) lets malformed input crash applications. Here's what to patch and why.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-49083-null-pointer-dereference-in-python-cryptography-pkcs7</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-49083-null-pointer-dereference-in-python-cryptography-pkcs7</guid>
      <pubDate>Sat, 27 Jun 2026 07:29:25 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Alpine vs distroless: which base image is more secure]]></title>
      <description><![CDATA[Alpine and distroless both shrink attack surface differently. We compare real CVEs, musl risks, and patch tradeoffs to settle which base image actually wins.]]></description>
      <link>https://safeguard.sh/resources/blog/alpine-vs-distroless-which-base-image-is-more-secure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/alpine-vs-distroless-which-base-image-is-more-secure</guid>
      <pubDate>Sat, 27 Jun 2026 07:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-50782: Bleichenbacher timing oracle in python-cr...]]></title>
      <description><![CDATA[CVE-2023-50782 exposes a Bleichenbacher-style timing oracle in python-cryptography's RSA PKCS1v15 decryption, letting attackers recover plaintext.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-50782-bleichenbacher-timing-oracle-in-python-cryptography-rsa-decryption</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-50782-bleichenbacher-timing-oracle-in-python-cryptography-rsa-decryption</guid>
      <pubDate>Sat, 27 Jun 2026 06:08:58 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx vs Veracode: platform comparison]]></title>
      <description><![CDATA[Checkmarx and Veracode both scan code for vulnerabilities. Here is how the platforms compare, and where software supply chain security fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-vs-veracode-platform-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-vs-veracode-platform-comparison</guid>
      <pubDate>Sat, 27 Jun 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-30861: Flask session cookie disclosure to templates]]></title>
      <description><![CDATA[CVE-2023-30861 lets caching proxies leak Flask session cookies between users when responses aren't marked Vary: Cookie. Here's who's affected and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-30861-flask-session-cookie-disclosure-to-templates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-30861-flask-session-cookie-disclosure-to-templates</guid>
      <pubDate>Sat, 27 Jun 2026 04:48:32 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Scanning container images in CI/CD pipelines]]></title>
      <description><![CDATA[Where to put container image scanning in your CI/CD pipeline, what it actually catches, and how to stop CVE floods from blocking every build.]]></description>
      <link>https://safeguard.sh/resources/blog/scanning-container-images-in-cicd-pipelines</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scanning-container-images-in-cicd-pipelines</guid>
      <pubDate>Sat, 27 Jun 2026 04:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Valuation: How Much Is Snyk Worth?]]></title>
      <description><![CDATA[Snyk's valuation peaked at $8.5 billion in 2021, then repriced through later rounds and investor markdowns. Here is the documented timeline and what it signals.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-valuation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-valuation</guid>
      <pubDate>Sat, 27 Jun 2026 03:28:05 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx vs Snyk: which AppSec platform fits your stack]]></title>
      <description><![CDATA[Checkmarx vs Snyk searches usually miss the real question: does your AppSec stack cover source code, or the full build-to-deploy supply chain? Here's how to check.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-vs-snyk-which-appsec-platform-fits-your-stack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-vs-snyk-which-appsec-platform-fits-your-stack</guid>
      <pubDate>Sat, 27 Jun 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-1010083: Denial of service in Flask via large mu...]]></title>
      <description><![CDATA[CVE-2019-1010083 let attackers crash Flask apps with crafted multipart requests. Here's the impact, affected versions, and how to remediate the DoS flaw.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-1010083-denial-of-service-in-flask-via-large-multipart-request</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-1010083-denial-of-service-in-flask-via-large-multipart-request</guid>
      <pubDate>Sat, 27 Jun 2026 02:07:38 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Container isolation with namespaces, cgroups, and seccomp]]></title>
      <description><![CDATA[Namespaces, cgroups, and seccomp each isolate a different layer of a container — and a single misconfigured one, like CVE-2024-21626 showed, breaks all three.]]></description>
      <link>https://safeguard.sh/resources/blog/container-isolation-with-namespaces-cgroups-and-seccomp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-isolation-with-namespaces-cgroups-and-seccomp</guid>
      <pubDate>Sat, 27 Jun 2026 01:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-25577: Denial of service in Werkzeug multipart p...]]></title>
      <description><![CDATA[CVE-2023-25577 lets attackers trigger denial of service in Werkzeug's multipart parser via crafted uploads. Here's the impact, timeline, and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-25577-denial-of-service-in-werkzeug-multipart-parser</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-25577-denial-of-service-in-werkzeug-multipart-parser</guid>
      <pubDate>Sat, 27 Jun 2026 00:47:11 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx alternatives for enterprise AppSec teams]]></title>
      <description><![CDATA[Checkmarx bundles SAST, SCA, and DAST into one platform. For teams whose real gap is supply chain risk, here's how Safeguard compares on reachability, SBOM, and deployment.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-alternatives-for-enterprise-appsec-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-alternatives-for-enterprise-appsec-teams</guid>
      <pubDate>Sat, 27 Jun 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-10108: Cross-protocol scripting in Twisted]]></title>
      <description><![CDATA[CVE-2020-10108 lets a malicious server abuse Twisted's redirect handling for cross-protocol scripting. Affected versions, risk context, and fixes inside.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-10108-cross-protocol-scripting-in-twisted</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-10108-cross-protocol-scripting-in-twisted</guid>
      <pubDate>Fri, 26 Jun 2026 23:26:45 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-10109: Denial of service in Twisted via 100-cont...]]></title>
      <description><![CDATA[CVE-2020-10109 lets attackers hang Twisted's HTTP server with malformed 100-continue requests, exhausting resources until it stops responding.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-10109-denial-of-service-in-twisted-via-100-continue-handling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-10109-denial-of-service-in-twisted-via-100-continue-handling</guid>
      <pubDate>Fri, 26 Jun 2026 22:06:18 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Detected: What the Alert Means and How to Respond]]></title>
      <description><![CDATA[A SQL injection detected alert means a scanner or WAF found input reaching your database as executable code. Here is how to confirm it, triage it, and fix the root cause.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-detected</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-detected</guid>
      <pubDate>Fri, 26 Jun 2026 20:45:51 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Write a Kubernetes Security Policy That Holds Up]]></title>
      <description><![CDATA[A Kubernetes security policy is the set of enforced rules that decide what workloads may run and how. This guide covers Pod Security Standards, admission control, and turning intent into rules the cluster actually enforces.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-security-policy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-security-policy</guid>
      <pubDate>Fri, 26 Jun 2026 19:25:25 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-20333 in Cisco ASA: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[Cisco Secure Firewall ASA/FTD buffer overflow scored CVSS 9.9 and was added to CISA KEV the day Cisco published the advisory. Here is the defender playbook.]]></description>
      <link>https://safeguard.sh/resources/blog/cisco-asa-cve-2025-20333-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisco-asa-cve-2025-20333-patch-response</guid>
      <pubDate>Fri, 26 Jun 2026 18:04:58 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[React Native Cookies: Managing and Securing Session Cookies]]></title>
      <description><![CDATA[A guide to react-native-cookies for reading and writing HTTP cookies in React Native apps, the platform gotchas, and how to keep session cookies secure.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-cookies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-cookies</guid>
      <pubDate>Fri, 26 Jun 2026 16:44:31 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Threat Model Examples: Walkthroughs You Can Actually Copy]]></title>
      <description><![CDATA[Concrete threat model examples for a web app, an API, and a CI/CD pipeline, using STRIDE and data flow diagrams to show how the process works end to end.]]></description>
      <link>https://safeguard.sh/resources/blog/threat-model-examples</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/threat-model-examples</guid>
      <pubDate>Fri, 26 Jun 2026 15:24:05 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Running Node.js on Ubuntu in Docker, Securely]]></title>
      <description><![CDATA[A guide to the Node Ubuntu Docker pattern: when an Ubuntu base makes sense for Node.js, how to build it safely, and the security trade-offs versus slim images.]]></description>
      <link>https://safeguard.sh/resources/blog/node-ubuntu-docker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-ubuntu-docker</guid>
      <pubDate>Fri, 26 Jun 2026 14:03:38 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Prisma Cloud vs Wiz: Supply Chain Features]]></title>
      <description><![CDATA[Both Prisma Cloud and Wiz have expanded into supply chain territory from cloud security origins. A head-to-head on what each actually delivers on the supply chain dimension.]]></description>
      <link>https://safeguard.sh/resources/blog/prisma-cloud-vs-wiz-supply-chain-features</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prisma-cloud-vs-wiz-supply-chain-features</guid>
      <pubDate>Fri, 26 Jun 2026 12:43:11 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Claude Sonnet 4.5 System Card: Security Reading]]></title>
      <description><![CDATA[Anthropic shipped Claude Sonnet 4.5 on September 29, 2025 with a 70-page system card. We pull the supply-chain-relevant findings out of it.]]></description>
      <link>https://safeguard.sh/resources/blog/claude-sonnet-4-5-system-card-security-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/claude-sonnet-4-5-system-card-security-analysis</guid>
      <pubDate>Fri, 26 Jun 2026 11:22:45 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CIRCIA Final Rule Slips to May 2026: What Changes]]></title>
      <description><![CDATA[CISA pushed the CIRCIA final rule deadline from October 2025 to May 2026, citing 24,000 public comments and harmonization work with other federal cyber reporting frameworks.]]></description>
      <link>https://safeguard.sh/resources/blog/circia-final-rule-2026-delay</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/circia-final-rule-2026-delay</guid>
      <pubDate>Fri, 26 Jun 2026 10:02:18 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Pod Security Standards explained]]></title>
      <description><![CDATA[A breakdown of Kubernetes' Privileged, Baseline, and Restricted Pod Security Standards, how they replaced PodSecurityPolicy, and where enforcement typically fails.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-pod-security-standards-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-pod-security-standards-explained</guid>
      <pubDate>Fri, 26 Jun 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[How AppSec teams cut false-positive triage time]]></title>
      <description><![CDATA[AppSec teams drown in false positives. See how Safeguard's supply-chain-native triage compares to Checkmarx's SAST-driven approach on reachability, context, and workflow fit.]]></description>
      <link>https://safeguard.sh/resources/blog/how-appsec-teams-cut-false-positive-triage-time</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-appsec-teams-cut-false-positive-triage-time</guid>
      <pubDate>Fri, 26 Jun 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[AWS TEAM CVE-2025-1969: Spoofed Approvals in IAM Identity Center]]></title>
      <description><![CDATA[AWS Security Bulletin AWS-2025-004 disclosed an input validation flaw in Temporary Elevated Access Management that let users forge approvals. Here's what changed and how to harden TEAM 1.2.2.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-iam-team-cve-2025-1969-elevated-access</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-iam-team-cve-2025-1969-elevated-access</guid>
      <pubDate>Fri, 26 Jun 2026 08:41:51 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Template: How to Structure a Software Bill of Materials]]></title>
      <description><![CDATA[A practical SBOM template covering the required fields, a ready-to-adapt CycloneDX skeleton, and the mistake of treating an SBOM as a document you fill in by hand.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-template</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-template</guid>
      <pubDate>Fri, 26 Jun 2026 07:21:24 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes securityContext settings guide]]></title>
      <description><![CDATA[A field-by-field guide to Kubernetes securityContext: which settings stop container breakouts, how to enforce them cluster-wide, and how to audit gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-securitycontext-settings-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-securitycontext-settings-guide</guid>
      <pubDate>Fri, 26 Jun 2026 07:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[ngx-bootstrap Security: What to Know After the 2025 npm Compromise]]></title>
      <description><![CDATA[ngx-bootstrap is a popular Angular component library that was hit by a real npm supply-chain attack in September 2025. Here is what happened, what to check, and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/ngx-bootstrap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ngx-bootstrap</guid>
      <pubDate>Fri, 26 Jun 2026 06:00:58 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[API security and the rise of shadow/zombie APIs]]></title>
      <description><![CDATA[Shadow and zombie APIs caused breaches at Optus, T-Mobile, and Peloton. Here's why code-scanning tools miss them and what API security best practices actually work.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-and-the-rise-of-shadowzombie-apis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-and-the-rise-of-shadowzombie-apis</guid>
      <pubDate>Fri, 26 Jun 2026 06:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Interactive Application Security Testing Tools: How IAST Works and When to Use It]]></title>
      <description><![CDATA[IAST watches your running application from the inside during normal testing, catching real, reachable flaws that static scanners can only guess at.]]></description>
      <link>https://safeguard.sh/resources/blog/interactive-application-security-testing-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/interactive-application-security-testing-tools</guid>
      <pubDate>Fri, 26 Jun 2026 04:40:31 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes RBAC best practices]]></title>
      <description><![CDATA[RBAC drift and over-broad bindings are the top cause of Kubernetes lateral movement. Six concrete, question-first practices to lock down access before it's exploited.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-rbac-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-rbac-best-practices</guid>
      <pubDate>Fri, 26 Jun 2026 04:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-34455: snappy-java's Unchecked Chunk Length DoS]]></title>
      <description><![CDATA[CVE-2023-34455 lets an attacker crash a JVM by feeding snappy-java a bogus chunk length. Here is the root cause, affected versions, and the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-34455</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-34455</guid>
      <pubDate>Fri, 26 Jun 2026 03:20:04 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Secrets detection and remediation best practices]]></title>
      <description><![CDATA[Leaked API keys still cause breaches within minutes. Here's how secrets detection and remediation should work in practice, and where scanner-only tools fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/secrets-detection-and-remediation-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secrets-detection-and-remediation-best-practices</guid>
      <pubDate>Fri, 26 Jun 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-42794: The Apache Tomcat Incomplete Cleanup DoS Explained]]></title>
      <description><![CDATA[An unreleased refactoring in Tomcat's bundled Commons FileUpload left temp files undeleted on Windows, risking a disk-exhaustion DoS. Here is what CVE-2023-42794 is and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-42794</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-42794</guid>
      <pubDate>Fri, 26 Jun 2026 01:59:38 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes network policies for zero trust]]></title>
      <description><![CDATA[Kubernetes network policies default to allow-all. Here is how default-deny rules, CNI enforcement, and policy testing build real zero-trust segmentation.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-network-policies-for-zero-trust</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-network-policies-for-zero-trust</guid>
      <pubDate>Fri, 26 Jun 2026 01:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Setting JAVA_HOME on Ubuntu: A Step-by-Step Guide]]></title>
      <description><![CDATA[How to set JAVA_HOME on Ubuntu correctly and permanently: find your JDK path, choose the right scope (user vs system), handle multiple JDKs with update-alternatives, and verify it stuck.]]></description>
      <link>https://safeguard.sh/resources/blog/ubuntu-set-java-home</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ubuntu-set-java-home</guid>
      <pubDate>Fri, 26 Jun 2026 00:39:11 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[URL Scanner: How It Works and What to Use]]></title>
      <description><![CDATA[A URL scanner checks a web address for danger before you visit or ship it — but 'URL scanner' covers two very different tools. Here is how each works and which one solves your problem.]]></description>
      <link>https://safeguard.sh/resources/blog/url-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/url-scanner</guid>
      <pubDate>Thu, 25 Jun 2026 23:18:44 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[node-sass Is End-of-Life: What That Means and How to Migrate to Dart Sass]]></title>
      <description><![CDATA[node-sass reached end-of-life in 2024 and no longer receives updates or Node.js support. Here is why it was deprecated, what the risk is, and how to migrate to Dart Sass in an afternoon.]]></description>
      <link>https://safeguard.sh/resources/blog/node-sass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-sass</guid>
      <pubDate>Thu, 25 Jun 2026 21:58:18 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[k8s Pod Security Policy: Why It Was Removed and What Replaced It]]></title>
      <description><![CDATA[The k8s Pod Security Policy was deprecated in 1.21 and removed in 1.25. Here is why it went away and how to migrate to Pod Security Admission and Standards.]]></description>
      <link>https://safeguard.sh/resources/blog/k8s-pod-security-policy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/k8s-pod-security-policy</guid>
      <pubDate>Thu, 25 Jun 2026 20:37:51 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CWE Meaning: What Common Weakness Enumeration Is and Why It Matters]]></title>
      <description><![CDATA[The CWE meaning is simpler than it looks: a shared catalog of software weakness types. Here is how it differs from CVE and how to actually use it.]]></description>
      <link>https://safeguard.sh/resources/blog/cwe-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cwe-meaning</guid>
      <pubDate>Thu, 25 Jun 2026 19:17:24 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-43818: XSS bypass in lxml Cleaner]]></title>
      <description><![CDATA[CVE-2021-43818 shows how crafted SVG markup could slip past lxml's Cleaner sanitizer and execute script in supposedly 'cleaned' HTML output.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-43818-xss-bypass-in-lxml-cleaner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-43818-xss-bypass-in-lxml-cleaner</guid>
      <pubDate>Thu, 25 Jun 2026 17:56:57 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-27783: Cross-site scripting bypass in lxml html ...]]></title>
      <description><![CDATA[CVE-2020-27783 lets attackers bypass lxml's html.clean.Cleaner sanitizer to smuggle XSS past HTML cleaning. Here's what's affected and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-27783-cross-site-scripting-bypass-in-lxml-html-cleaner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-27783-cross-site-scripting-bypass-in-lxml-html-cleaner</guid>
      <pubDate>Thu, 25 Jun 2026 16:36:31 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2018-7750: Authentication bypass in paramiko SSH serv...]]></title>
      <description><![CDATA[CVE-2018-7750 lets attackers bypass authentication on Paramiko SSH servers using interactive auth by forging a success message. Impact, timeline, and fixes inside.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2018-7750-authentication-bypass-in-paramiko-ssh-server-mode</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2018-7750-authentication-bypass-in-paramiko-ssh-server-mode</guid>
      <pubDate>Thu, 25 Jun 2026 15:16:04 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-48795: Terrapin attack affecting paramiko SSH ex...]]></title>
      <description><![CDATA[The Terrapin attack (CVE-2023-48795) lets on-path attackers truncate SSH extension negotiation, downgrading security in paramiko and other SSH implementations.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-48795-terrapin-attack-affecting-paramiko-ssh-extension-negotiation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-48795-terrapin-attack-affecting-paramiko-ssh-extension-negotiation</guid>
      <pubDate>Thu, 25 Jun 2026 13:55:37 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Container SBOM Generation: Best Practices for 2025]]></title>
      <description><![CDATA[Container images are multi-layered artifacts that challenge SBOM generators. Here is how to generate comprehensive, accurate SBOMs for containerized applications.]]></description>
      <link>https://safeguard.sh/resources/blog/container-sbom-generation-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-sbom-generation-best-practices</guid>
      <pubDate>Thu, 25 Jun 2026 12:35:11 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-11651: Authentication bypass in SaltStack salt-m...]]></title>
      <description><![CDATA[CVE-2020-11651, a critical CVSS 9.8 authentication bypass in SaltStack's salt-master, enabled unauthenticated RCE and fueled real-world attacks on LineageOS, Ghost, and DigiCert.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-11651-authentication-bypass-in-saltstack-salt-master</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-11651-authentication-bypass-in-saltstack-salt-master</guid>
      <pubDate>Thu, 25 Jun 2026 11:14:44 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Securing Kubernetes Secrets management]]></title>
      <description><![CDATA[Base64 isn't encryption. Here's how Kubernetes Secrets actually get exposed, and the encryption, RBAC, and rotation controls that fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-kubernetes-secrets-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-kubernetes-secrets-management</guid>
      <pubDate>Thu, 25 Jun 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-11652: Directory traversal in SaltStack salt-master]]></title>
      <description><![CDATA[CVE-2020-11652 lets remote attackers read files outside SaltStack file_roots via a salt-master directory traversal flaw. Impact, timeline, and fixes inside.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-11652-directory-traversal-in-saltstack-salt-master</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-11652-directory-traversal-in-saltstack-salt-master</guid>
      <pubDate>Thu, 25 Jun 2026 09:54:17 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[PCI DSS compliance for application security teams]]></title>
      <description><![CDATA[PCI DSS 4.0's software inventory rules are enforced since March 2025. Here's why scanner-only tools like Checkmarx miss Requirements 6.3.2, 6.4.3, and 11.6.1.]]></description>
      <link>https://safeguard.sh/resources/blog/pci-dss-compliance-for-application-security-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pci-dss-compliance-for-application-security-teams</guid>
      <pubDate>Thu, 25 Jun 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2018-11776: Remote code execution in Apache Struts2 v...]]></title>
      <description><![CDATA[CVE-2018-11776 lets attackers achieve unauthenticated RCE in Apache Struts2 via crafted namespace/OGNL injection. Affected versions, timeline, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2018-11776-remote-code-execution-in-apache-struts2-via-namespace</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2018-11776-remote-code-execution-in-apache-struts2-via-namespace</guid>
      <pubDate>Thu, 25 Jun 2026 08:33:51 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-0230: OGNL remote code execution in Apache Struts2]]></title>
      <description><![CDATA[CVE-2019-0230 lets attackers chain forced double OGNL evaluation in Struts2 tag attributes into remote code execution. Here's what's affected, the CVSS/EPSS context, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-0230-ognl-remote-code-execution-in-apache-struts2</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-0230-ognl-remote-code-execution-in-apache-struts2</guid>
      <pubDate>Thu, 25 Jun 2026 07:13:24 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes admission controllers for security]]></title>
      <description><![CDATA[How Kubernetes admission controllers work, why defaults leave clusters exposed, and how Pod Security Admission, OPA Gatekeeper, and Kyverno close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-admission-controllers-for-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-admission-controllers-for-security</guid>
      <pubDate>Thu, 25 Jun 2026 07:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA requirements and application security]]></title>
      <description><![CDATA[HIPAA's Security Rule ties ePHI protection to application security, but scanner tools like Checkmarx rarely map findings to 45 CFR safeguards. Here's what compliance teams actually need.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-requirements-and-application-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-requirements-and-application-security</guid>
      <pubDate>Thu, 25 Jun 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[What Does 'CVE: BYN' Mean? Decoding Vulnerability Identifiers]]></title>
      <description><![CDATA[If you searched for 'cve: byn', you probably landed on a garbled query. Here is what a CVE identifier actually is, how to read one, and why 'BYN' is not part of it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-byn</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-byn</guid>
      <pubDate>Thu, 25 Jun 2026 05:52:57 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How Do You Run a Vulnerability Test? A Practical Guide]]></title>
      <description><![CDATA[A vulnerability test is a systematic check of a system for known security weaknesses. Here is what it involves, the types available, and how to run one that produces action instead of a wall of findings.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-test</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-test</guid>
      <pubDate>Thu, 25 Jun 2026 04:32:31 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Lessons from the CNCF Kubernetes security audit]]></title>
      <description><![CDATA[The 2019 CNCF Kubernetes security audit found 37 issues rooted in insecure defaults. Here's what it uncovered and what still applies today.]]></description>
      <link>https://safeguard.sh/resources/blog/lessons-from-the-cncf-kubernetes-security-audit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lessons-from-the-cncf-kubernetes-security-audit</guid>
      <pubDate>Thu, 25 Jun 2026 04:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Security in PHP: Framework-Level Protections and Common Gaps]]></title>
      <description><![CDATA[Security in PHP improved enormously once frameworks took over escaping, CSRF, and query building. The remaining incidents live in the gaps where developers step outside those rails.]]></description>
      <link>https://safeguard.sh/resources/blog/php-framework-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-framework-security-guide</guid>
      <pubDate>Thu, 25 Jun 2026 03:12:04 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Federal AST mandate M-22-09 explained]]></title>
      <description><![CDATA[OMB's M-22-09 forces federal agencies to run continuous application security testing under zero trust. Here's what changed, and how Safeguard compares to Checkmarx.]]></description>
      <link>https://safeguard.sh/resources/blog/federal-ast-mandate-m-22-09-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/federal-ast-mandate-m-22-09-explained</guid>
      <pubDate>Thu, 25 Jun 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[faster_log and async_println: Rust's First Public Wallet-Stealing Crates]]></title>
      <description><![CDATA[On September 24, 2025, crates.io removed faster_log and async_println — Rust typosquats that had quietly stolen Ethereum and Solana keys from 8,424 downloads since May.]]></description>
      <link>https://safeguard.sh/resources/blog/crates-io-faster-log-async-println-malicious-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crates-io-faster-log-async-println-malicious-2025</guid>
      <pubDate>Thu, 25 Jun 2026 01:51:37 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Runtime security tools for Kubernetes clusters]]></title>
      <description><![CDATA[A concrete look at Kubernetes runtime security tools — Falco, Tetragon, Tracee, eBPF, and recent CVEs — and what to check before you buy one.]]></description>
      <link>https://safeguard.sh/resources/blog/runtime-security-tools-for-kubernetes-clusters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runtime-security-tools-for-kubernetes-clusters</guid>
      <pubDate>Thu, 25 Jun 2026 01:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Code Scanning Tools: How to Choose and Use One That Works]]></title>
      <description><![CDATA[A code scanning tool automatically inspects your source and dependencies for vulnerabilities. Here is how the main types differ and how to wire one into CI without drowning in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/code-scanning-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-scanning-tool</guid>
      <pubDate>Thu, 25 Jun 2026 00:31:10 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 Type II and vendor trust in AppSec tooling]]></title>
      <description><![CDATA[Why SOC 2 Type II compliance is the real trust signal for AppSec vendors, where Checkmarx's public evidence falls short, and how Safeguard makes its audit trail verifiable.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-type-ii-and-vendor-trust-in-appsec-tooling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-type-ii-and-vendor-trust-in-appsec-tooling</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Pandoc CVE-2025-51591: SSRF Against EC2 Metadata in the Wild]]></title>
      <description><![CDATA[Wiz documented active exploitation of Pandoc CVE-2025-51591 to reach the AWS IMDS through iframe rendering. Here is the kill chain and the production controls that contained it.]]></description>
      <link>https://safeguard.sh/resources/blog/pandoc-ssrf-cve-2025-51591-ec2-iam-theft</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pandoc-ssrf-cve-2025-51591-ec2-iam-theft</guid>
      <pubDate>Wed, 24 Jun 2026 23:10:44 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSF Scorecard v5.1: Azure DevOps Support and File-Mode Selection]]></title>
      <description><![CDATA[Scorecard v5.1 added experimental Azure DevOps repository support and a new --file-mode flag that materially changes how repository files are fetched.]]></description>
      <link>https://safeguard.sh/resources/blog/openssf-scorecard-v5-1-azure-devops-support</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssf-scorecard-v5-1-azure-devops-support</guid>
      <pubDate>Wed, 24 Jun 2026 21:50:17 GMT</pubDate>
      <category>Frameworks</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Is the exceljs npm Package Safe? A Security Review]]></title>
      <description><![CDATA[The exceljs npm package is a maintained, popular library for reading and writing Excel files, and it is a reasonable choice, but parsing untrusted spreadsheets carries real risk. Here is the review.]]></description>
      <link>https://safeguard.sh/resources/blog/exceljs-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/exceljs-npm</guid>
      <pubDate>Wed, 24 Jun 2026 20:29:50 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Best SBOM Tools in 2026: Generation, Management, and Compliance Compared]]></title>
      <description><![CDATA[An honest guide to the best SBOM tools in 2026 — from open-source generators like Syft and Trivy to full SBOM management and AIBOM platforms — with clear guidance on which to use for generation, analysis, and compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/best-sbom-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-sbom-tools-2026</guid>
      <pubDate>Wed, 24 Jun 2026 20:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-20352 in Cisco IOS: SNMP Stack Overflow Deep Dive]]></title>
      <description><![CDATA[An authenticated stack buffer overflow in Cisco IOS and IOS XE SNMP is being exploited in the wild. We dissect the bug, the patch, and the detection signal.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2025-20352-cisco-ios-snmp-rce-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2025-20352-cisco-ios-snmp-rce-analysis</guid>
      <pubDate>Wed, 24 Jun 2026 19:09:24 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best Software Supply Chain Security Platforms in 2026: A Buyer's Guide]]></title>
      <description><![CDATA[An honest, side-by-side guide to the best software supply chain security platforms in 2026 — what each tool is genuinely good at, who it fits, and how to choose between zero-CVE, SCA, reachability, and CNAPP approaches.]]></description>
      <link>https://safeguard.sh/resources/blog/best-software-supply-chain-security-platforms-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-software-supply-chain-security-platforms-2026</guid>
      <pubDate>Wed, 24 Jun 2026 19:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Daybreak vs. Mythos: 2026 Is the Year the Frontier Labs Entered Defensive Security]]></title>
      <description><![CDATA[OpenAI's Daybreak and Anthropic's Mythos both bet that frontier models can find and fix vulnerabilities at scale. The discovery race is real — but the bottleneck, the cost curve, and the winning strategy all point the same direction: be model-agnostic.]]></description>
      <link>https://safeguard.sh/resources/blog/daybreak-vs-mythos-labs-enter-vuln-finding-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/daybreak-vs-mythos-labs-enter-vuln-finding-2026</guid>
      <pubDate>Wed, 24 Jun 2026 18:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx API Security: What It Does and How to Use It]]></title>
      <description><![CDATA[Checkmarx API Security discovers your real API footprint — including shadow and zombie endpoints — and correlates static and dynamic findings. Here's how it fits an AppSec program.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-api-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-api-security</guid>
      <pubDate>Wed, 24 Jun 2026 17:48:57 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[spring-web Maven Dependency: Known CVEs and How to Stay Patched]]></title>
      <description><![CDATA[The spring-web Maven artifact pulls a lot of transitive weight and has been at the center of high-profile RCE bugs. Here is what to watch and how to keep it patched.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-web-maven</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-web-maven</guid>
      <pubDate>Wed, 24 Jun 2026 16:28:30 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[2026 Mid-Year Threat Landscape: Supply-Chain Worms, Agentic AI, and Edge Zero-Days]]></title>
      <description><![CDATA[A defender's synthesis of the first half of 2026 — self-propagating package worms, the agentic-AI access-control problem, edge-appliance zero-days, and a healthcare ransomware surge — and what to prioritize next.]]></description>
      <link>https://safeguard.sh/resources/blog/2026-mid-year-threat-landscape-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/2026-mid-year-threat-landscape-review</guid>
      <pubDate>Wed, 24 Jun 2026 16:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-46589: The Tomcat Request Smuggling Flaw, Explained]]></title>
      <description><![CDATA[CVE-2023-46589 lets an attacker smuggle HTTP requests past a reverse proxy by abusing malformed trailer headers in Apache Tomcat. Here is how it works and which versions to run.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-46589</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-46589</guid>
      <pubDate>Wed, 24 Jun 2026 15:08:04 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Patch the Planet: What AI-Generated Fixes Actually Mean for Open-Source Maintainers]]></title>
      <description><![CDATA[OpenAI's Patch the Planet, co-founded with Trail of Bits, wants to move widely-used open-source projects from findings to fixes. The ambition is right — but it shifts the bottleneck to maintainer review, patch provenance, and the trust of machine-authored code.]]></description>
      <link>https://safeguard.sh/resources/blog/patch-the-planet-ai-patches-oss-maintainers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/patch-the-planet-ai-patches-oss-maintainers</guid>
      <pubDate>Wed, 24 Jun 2026 15:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Open Source License Scanning: How It Actually Works]]></title>
      <description><![CDATA[How open source license scanning identifies oss license obligations across a dependency tree, and what open source compliance management software actually automates versus flags for review.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-license-scanning-how-it-works</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-license-scanning-how-it-works</guid>
      <pubDate>Wed, 24 Jun 2026 13:47:37 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[OpenAI's Daybreak: An Honest Assessment of Codex Security, GPT-5.5-Cyber, and the Find-Validate-Patch Loop]]></title>
      <description><![CDATA[Daybreak is the most complete attempt yet to turn a frontier model into a vulnerability-finding-and-fixing system. We break down what it gets right, where the verification and economics still bite, and how it fits alongside a purpose-built engine.]]></description>
      <link>https://safeguard.sh/resources/blog/openai-daybreak-honest-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openai-daybreak-honest-review</guid>
      <pubDate>Wed, 24 Jun 2026 13:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Attack at Scale: npm, PyPI, and Docker Hub Hit in 48 Hours]]></title>
      <description><![CDATA[GitGuardian documented three distinct supply-chain campaigns striking npm, PyPI, and Docker Hub inside a single 48-hour window in April 2026. The simultaneity tells you more about attacker tooling than any single payload does.]]></description>
      <link>https://safeguard.sh/resources/blog/three-supply-chain-campaigns-48-hours</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/three-supply-chain-campaigns-48-hours</guid>
      <pubDate>Wed, 24 Jun 2026 13:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Working With the Semgrep API: Pulling Findings and Automating Scans]]></title>
      <description><![CDATA[The Semgrep API lets you list deployments, pull findings, and manage projects and tokens programmatically. Here is how authentication works and how to use it well.]]></description>
      <link>https://safeguard.sh/resources/blog/semgrep-api</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/semgrep-api</guid>
      <pubDate>Wed, 24 Jun 2026 12:27:10 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[PHP Code Checker Tools: How to Catch Bugs and Security Flaws in PHP]]></title>
      <description><![CDATA[A PHP code checker can mean a syntax linter, a static analyzer like PHPStan, or a security taint scanner. Here is what each one catches and how to combine them.]]></description>
      <link>https://safeguard.sh/resources/blog/php-code-checker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-code-checker</guid>
      <pubDate>Wed, 24 Jun 2026 11:06:44 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Helm chart security scanning]]></title>
      <description><![CDATA[Helm charts can render insecure RBAC, network policies, and default passwords even when the container image itself passes every vulnerability scan cleanly.]]></description>
      <link>https://safeguard.sh/resources/blog/helm-chart-security-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/helm-chart-security-scanning</guid>
      <pubDate>Wed, 24 Jun 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[App Security Tools: A Practical Guide to Building Your AppSec Stack]]></title>
      <description><![CDATA[The right app security tools do not overlap by accident — each one covers a layer the others cannot see, and the gaps between them are where breaches start.]]></description>
      <link>https://safeguard.sh/resources/blog/app-security-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/app-security-tools</guid>
      <pubDate>Wed, 24 Jun 2026 09:46:17 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Claude Code Skill, and How Do You Secure One?]]></title>
      <description><![CDATA[A Claude Code skill is a folder of Markdown instructions and scripts that an AI agent loads on demand. Because it can carry executable code, it deserves the same review as any dependency.]]></description>
      <link>https://safeguard.sh/resources/blog/claude-code-skill</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/claude-code-skill</guid>
      <pubDate>Wed, 24 Jun 2026 09:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Securing AI coding assistants (Claude Code, Copilot, etc.)]]></title>
      <description><![CDATA[AI coding assistants like Claude Code and Copilot introduce new supply chain risks. Here's what's actually going wrong and how to secure your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-ai-coding-assistants-claude-code-copilot-etc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-ai-coding-assistants-claude-code-copilot-etc</guid>
      <pubDate>Wed, 24 Jun 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Prompt Injection Examples: Attacks Seen in the Wild]]></title>
      <description><![CDATA[From hidden text in resumes to poisoned web pages that hijack AI browsing agents, prompt injection has moved from research demos to real incidents. Here are the patterns and what actually blunts them.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-examples-in-the-wild</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-examples-in-the-wild</guid>
      <pubDate>Wed, 24 Jun 2026 08:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is the NVD (National Vulnerability Database)?]]></title>
      <description><![CDATA[The NVD is the U.S. government's enrichment layer on top of the CVE List, adding CVSS scores, CWE classifications, and affected-configuration data. Here is how it works and where it falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-nvd</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-nvd</guid>
      <pubDate>Wed, 24 Jun 2026 08:25:50 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Secure a Monorepo Without Slowing Every Team Down]]></title>
      <description><![CDATA[Monorepo security fails when every check runs on every commit. Path-filtered CI, CODEOWNERS, per-workspace scanning, and merge queues fix that.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-secure-a-monorepo-without-slowing-every-team-down</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-secure-a-monorepo-without-slowing-every-team-down</guid>
      <pubDate>Wed, 24 Jun 2026 08:00:00 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Sofia Marchetti)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-17530: Forced OGNL evaluation RCE in Apache Struts2]]></title>
      <description><![CDATA[CVE-2020-17530 lets attackers achieve unauthenticated RCE in Apache Struts2 via forced OGNL evaluation. Here's the scope, timeline, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-17530-forced-ognl-evaluation-rce-in-apache-struts2</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-17530-forced-ognl-evaluation-rce-in-apache-struts2</guid>
      <pubDate>Wed, 24 Jun 2026 07:05:23 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Container configuration drift detection at runtime]]></title>
      <description><![CDATA[Container images pass CI clean, but running containers drift within hours via exec sessions, sidecars, and webhooks. Here's how to detect it at runtime.]]></description>
      <link>https://safeguard.sh/resources/blog/container-configuration-drift-detection-at-runtime</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-configuration-drift-detection-at-runtime</guid>
      <pubDate>Wed, 24 Jun 2026 07:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Code-to-cloud security (CNAPP-style end-to-end protection)]]></title>
      <description><![CDATA[Checkmarx scans code and pipelines well, but stops short of live cloud context. Here is what code-to-cloud security actually requires, with real breach examples.]]></description>
      <link>https://safeguard.sh/resources/blog/code-to-cloud-security-cnapp-style-end-to-end-protection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-to-cloud-security-cnapp-style-end-to-end-protection</guid>
      <pubDate>Wed, 24 Jun 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[DevOps Measurements: Metrics That Actually Matter]]></title>
      <description><![CDATA[The DevOps measurements worth tracking tie delivery speed to stability and security. Here are the ones that change decisions, not just dashboards.]]></description>
      <link>https://safeguard.sh/resources/blog/devops-measurements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devops-measurements</guid>
      <pubDate>Wed, 24 Jun 2026 05:44:57 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[SCA Scanning: What It Catches in Practice]]></title>
      <description><![CDATA[SCA scanning finds known CVEs in your open-source dependencies and license conflicts you didn't know you'd agreed to — here's exactly what a scan catches, in order of how often it actually matters.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-scanning-what-it-catches-in-practice</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-scanning-what-it-catches-in-practice</guid>
      <pubDate>Wed, 24 Jun 2026 04:24:30 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Detecting vulnerabilities in multi-stage Docker builds]]></title>
      <description><![CDATA[Multi-stage Docker builds hide vulnerabilities, leaked secrets, and untracked dependencies in discarded layers. Here's what final-image scans miss and how to catch it.]]></description>
      <link>https://safeguard.sh/resources/blog/detecting-vulnerabilities-in-multi-stage-docker-builds</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/detecting-vulnerabilities-in-multi-stage-docker-builds</guid>
      <pubDate>Wed, 24 Jun 2026 04:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Cyber Hygiene: The Everyday Habits That Stop Most Breaches]]></title>
      <description><![CDATA[Cyber hygiene is the routine set of practices that keep systems healthy and hard to compromise. Get the basics right and you close the door on the majority of real-world attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/cyber-hygiene</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyber-hygiene</guid>
      <pubDate>Wed, 24 Jun 2026 03:04:03 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps and CI/CD pipeline security]]></title>
      <description><![CDATA[CI/CD pipelines are now a prime attack surface. Here's what Checkmarx's SAST-first approach misses, and how Safeguard secures the full pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-and-cicd-pipeline-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-and-cicd-pipeline-security</guid>
      <pubDate>Wed, 24 Jun 2026 03:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2015-6420: Deserialization vulnerability via Apache C...]]></title>
      <description><![CDATA[How a vulnerable Apache Commons Collections library let attackers achieve remote code execution via Java deserialization gadget chains, and what CVE-2015-6420 still teaches about supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2015-6420-deserialization-vulnerability-via-apache-commons-collections</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2015-6420-deserialization-vulnerability-via-apache-commons-collections</guid>
      <pubDate>Wed, 24 Jun 2026 01:43:37 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Keeping Docker secrets secure without Kubernetes]]></title>
      <description><![CDATA[Docker ships with tmpfs-backed Swarm secrets, BuildKit secret mounts, and Compose file secrets — here's how to use them without Kubernetes.]]></description>
      <link>https://safeguard.sh/resources/blog/keeping-docker-secrets-secure-without-kubernetes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/keeping-docker-secrets-secure-without-kubernetes</guid>
      <pubDate>Wed, 24 Jun 2026 01:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-12384: Polymorphic deserialization gadget in Jac...]]></title>
      <description><![CDATA[CVE-2019-12384 is a Jackson-databind polymorphic deserialization gadget flaw via Ehcache's transaction manager class, patched in 2.9.9.1.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-12384-polymorphic-deserialization-gadget-in-jackson-databind</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-12384-polymorphic-deserialization-gadget-in-jackson-databind</guid>
      <pubDate>Wed, 24 Jun 2026 00:23:10 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Reducing developer friction in AppSec adoption]]></title>
      <description><![CDATA[Why traditional SAST tooling like Checkmarx creates developer friction, what it costs engineering teams, and how to build developer experience application security that ships.]]></description>
      <link>https://safeguard.sh/resources/blog/reducing-developer-friction-in-appsec-adoption</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reducing-developer-friction-in-appsec-adoption</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-12814: Jackson-databind polymorphic type gadget ...]]></title>
      <description><![CDATA[A look at CVE-2019-12814, a jackson-databind polymorphic typing gadget tied to JAXB classes, its risk profile, and how to remediate it in modern Java stacks.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-12814-jackson-databind-polymorphic-type-gadget-jaxb</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-12814-jackson-databind-polymorphic-type-gadget-jaxb</guid>
      <pubDate>Tue, 23 Jun 2026 23:02:43 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Docker Architecture Explained: A Security-Focused Breakdown]]></title>
      <description><![CDATA[Docker architecture is a client-server system built on the daemon, containerd, images, and the kernel features that isolate containers. Here is how the pieces fit and where the security lines are.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-architecture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-architecture</guid>
      <pubDate>Tue, 23 Jun 2026 21:42:17 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-14379: Jackson-databind deserialization via jdk....]]></title>
      <description><![CDATA[CVE-2019-14379 lets attackers abuse jackson-databind's polymorphic deserialization via a JDK Nashorn gadget class. Here's the risk, fix, and detection guidance.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-14379-jackson-databind-deserialization-via-jdknashorn-class</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-14379-jackson-databind-deserialization-via-jdknashorn-class</guid>
      <pubDate>Tue, 23 Jun 2026 20:21:50 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-14540: Jackson-databind blacklist bypass via c3p...]]></title>
      <description><![CDATA[CVE-2019-14540 lets attackers bypass jackson-databind's deserialization blacklist via c3p0 classes to achieve RCE. Here's what's affected, the timeline, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-14540-jackson-databind-blacklist-bypass-via-c3p0-classes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-14540-jackson-databind-blacklist-bypass-via-c3p0-classes</guid>
      <pubDate>Tue, 23 Jun 2026 19:01:23 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-16335: Jackson-databind gadget via jackson-dataf...]]></title>
      <description><![CDATA[CVE-2019-16335 is a jackson-databind polymorphic deserialization flaw tied to jackson-dataformat-cbor, fixed in 2.9.10. Here's the impact, timeline, and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-16335-jackson-databind-gadget-via-jackson-dataformat-cbor</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-16335-jackson-databind-gadget-via-jackson-dataformat-cbor</guid>
      <pubDate>Tue, 23 Jun 2026 17:40:57 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[GPT-5.5-Cyber and Trusted Access: The Dual-Use Governance Questions Defenders Should Be Asking]]></title>
      <description><![CDATA[OpenAI's Daybreak ships a permissive, offensive-capable model behind a tiered Trusted Access program and a wave of government partnerships. Here's what model-risk, procurement, and security-policy teams should demand before they rely on it.]]></description>
      <link>https://safeguard.sh/resources/blog/gpt-5-5-cyber-dual-use-trusted-access-governance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gpt-5-5-cyber-dual-use-trusted-access-governance</guid>
      <pubDate>Tue, 23 Jun 2026 17:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Automated Cloud Security: Scaling Protection Without Scaling Headcount]]></title>
      <description><![CDATA[Automated cloud security uses continuous, policy-driven tooling to find and fix misconfigurations and vulnerabilities at the speed the cloud actually changes.]]></description>
      <link>https://safeguard.sh/resources/blog/automated-cloud-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automated-cloud-security</guid>
      <pubDate>Tue, 23 Jun 2026 16:20:30 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Cybersecurity SDK: Building Security Into Your Application from Code]]></title>
      <description><![CDATA[A cybersecurity SDK gives developers ready-made libraries for the security work they would otherwise get wrong — crypto, auth, scanning, and secrets. Here is how to choose and use one well.]]></description>
      <link>https://safeguard.sh/resources/blog/cybersecurity-sdk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cybersecurity-sdk</guid>
      <pubDate>Tue, 23 Jun 2026 15:00:03 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Attack Trends: Q3 2025]]></title>
      <description><![CDATA[A data-led look at software supply chain attacks in Q3 2025: npm maintainer phishing, VS Code extension abuse, and a quiet shift toward CI/CD targeting.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-attack-trends-q3-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-attack-trends-q3-2025</guid>
      <pubDate>Tue, 23 Jun 2026 13:39:36 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-45321: Anatomy of the TanStack npm and PyPI Supply Chain Worm]]></title>
      <description><![CDATA[The Mini Shai-Hulud worm hit TanStack, Mistral AI, UiPath and 170+ npm and PyPI packages by hijacking a trusted release pipeline mid-run. Here is how the software supply chain attack actually worked, and what it changes.]]></description>
      <link>https://safeguard.sh/resources/blog/tanstack-npm-pypi-supply-chain-worm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tanstack-npm-pypi-supply-chain-worm</guid>
      <pubDate>Tue, 23 Jun 2026 13:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[TeamPCP: Running a Software Supply Chain Attack Like a Production Pipeline]]></title>
      <description><![CDATA[TeamPCP (UNC6780) is the most active actor in the 2026 supply chain corpus, weaponizing the tools developers trust most. Here is how the operation works, and why a zero-CVE campaign breaks the model most teams still rely on.]]></description>
      <link>https://safeguard.sh/resources/blog/teampcp-supply-chain-threat-actor</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/teampcp-supply-chain-threat-actor</guid>
      <pubDate>Tue, 23 Jun 2026 13:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Software Attestation Frameworks Compared: SLSA, in-toto, and Sigstore]]></title>
      <description><![CDATA[Software attestation proves that your artifacts were built the way you claim. Here is a practical comparison of SLSA, in-toto, and Sigstore for securing your build pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/software-attestation-framework-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-attestation-framework-comparison</guid>
      <pubDate>Tue, 23 Jun 2026 12:19:10 GMT</pubDate>
      <category>Build Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Java Code Security: A Practical Checklist]]></title>
      <description><![CDATA[Java code security has a specific set of recurring failure modes — deserialization, XXE, dependency sprawl — this checklist covers the ones worth checking on every review.]]></description>
      <link>https://safeguard.sh/resources/blog/java-code-security-a-practical-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-code-security-a-practical-checklist</guid>
      <pubDate>Tue, 23 Jun 2026 10:58:43 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Container security throughout the SDLC]]></title>
      <description><![CDATA[A clean build-time scan doesn't mean a secure container. Here's why container security has to span code, build, deploy, and runtime — with real CVE examples.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-throughout-the-sdlc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-throughout-the-sdlc</guid>
      <pubDate>Tue, 23 Jun 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Security Products: How to Build a Stack That Fits]]></title>
      <description><![CDATA[Enterprise security products span identity, endpoint, network, cloud, and application layers. Here is how the categories fit together and how to avoid buying overlap.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-security-products</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-security-products</guid>
      <pubDate>Tue, 23 Jun 2026 09:38:16 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Repository health and source-code manager (SCM) risk]]></title>
      <description><![CDATA[Repository health—branch protection, stale permissions, leaked secrets, OAuth grants—is a supply chain risk AppSec scanners like Checkmarx can't see. Here's why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/repository-health-and-source-code-manager-scm-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/repository-health-and-source-code-manager-scm-risk</guid>
      <pubDate>Tue, 23 Jun 2026 09:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Snyk and GitHub Actions: How to Wire Up CI Scanning]]></title>
      <description><![CDATA[How to set up Snyk in GitHub Actions the right way — the official actions, storing your token, uploading SARIF to code scanning, and gating pull requests.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-github-actions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-github-actions</guid>
      <pubDate>Tue, 23 Jun 2026 08:17:50 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Minimizing container attack surface]]></title>
      <description><![CDATA[Container images ship 400+ CVEs on average but under 15% are reachable. Learn concrete, numbers-backed steps to cut container attack surface.]]></description>
      <link>https://safeguard.sh/resources/blog/minimizing-container-attack-surface</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/minimizing-container-attack-surface</guid>
      <pubDate>Tue, 23 Jun 2026 07:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-1938 (Ghostcat): File inclusion via Apache Tomca...]]></title>
      <description><![CDATA[Ghostcat (CVE-2020-1938) let attackers read files—and often achieve RCE—via Tomcat's default, unauthenticated AJP connector. Here's the risk, fix, and KEV context.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-1938-ghostcat-file-inclusion-via-apache-tomcat-ajp-connector</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-1938-ghostcat-file-inclusion-via-apache-tomcat-ajp-connector</guid>
      <pubDate>Tue, 23 Jun 2026 06:57:23 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[MSSP and partner program models in AppSec]]></title>
      <description><![CDATA[Checkmarx built an MSSP and partner program around code scanning. Here's how that model works, where it misses software supply chain risk, and what to check before signing.]]></description>
      <link>https://safeguard.sh/resources/blog/mssp-and-partner-program-models-in-appsec</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mssp-and-partner-program-models-in-appsec</guid>
      <pubDate>Tue, 23 Jun 2026 06:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-33037: HTTP request smuggling in Apache Tomcat]]></title>
      <description><![CDATA[CVE-2021-33037 let malformed HTTP trailers desync Apache Tomcat from front-end proxies, enabling request smuggling. Here's what's affected and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-33037-http-request-smuggling-in-apache-tomcat</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-33037-http-request-smuggling-in-apache-tomcat</guid>
      <pubDate>Tue, 23 Jun 2026 05:36:56 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-0232: Remote code execution in Apache Tomcat CGI...]]></title>
      <description><![CDATA[CVE-2019-0232 lets attackers execute arbitrary commands on Windows-hosted Apache Tomcat via the CGI Servlet. Here's the CVSS 9.8 detail, affected versions, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-0232-remote-code-execution-in-apache-tomcat-cgi-servlet-on-windows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-0232-remote-code-execution-in-apache-tomcat-cgi-servlet-on-windows</guid>
      <pubDate>Tue, 23 Jun 2026 04:16:30 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Signing and verifying container images with Sigstore/cosign]]></title>
      <description><![CDATA[How cosign and Sigstore replace long-lived signing keys with short-lived, identity-based certificates and a public transparency log for containers.]]></description>
      <link>https://safeguard.sh/resources/blog/signing-and-verifying-container-images-with-sigstorecosign</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/signing-and-verifying-container-images-with-sigstorecosign</guid>
      <pubDate>Tue, 23 Jun 2026 04:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[What is Static Application Security Testing (SAST)]]></title>
      <description><![CDATA[SAST scans source code for flaws before deployment. Learn how it works, where Checkmarx-style tools fall short on supply chain risk, and how Safeguard closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-static-application-security-testing-sast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-static-application-security-testing-sast</guid>
      <pubDate>Tue, 23 Jun 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[eslint-plugin-react-refresh: What It Does and Why It Matters]]></title>
      <description><![CDATA[A guide to eslint-plugin-react-refresh: what the only-export-components rule enforces, how it relates to the react-refresh webpack plugin, and its security relevance.]]></description>
      <link>https://safeguard.sh/resources/blog/eslint-plugin-react-refresh</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eslint-plugin-react-refresh</guid>
      <pubDate>Tue, 23 Jun 2026 02:56:03 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SAST, DAST, and SCA: The Three Scanner Types You Actually Need]]></title>
      <description><![CDATA[Each scanner type answers a different question about your application. Here's what SAST, DAST, and SCA each catch, and why running just one leaves gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-dast-sca-the-three-scanner-types-you-need</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-dast-sca-the-three-scanner-types-you-need</guid>
      <pubDate>Tue, 23 Jun 2026 01:35:36 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Detecting cryptomining malware in container images]]></title>
      <description><![CDATA[Cryptomining malware like Kinsing and TeamTNT quietly hijacks container CPU cycles to mine Monero. Here's how it gets in, how to spot it, and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/detecting-cryptomining-malware-in-container-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/detecting-cryptomining-malware-in-container-images</guid>
      <pubDate>Tue, 23 Jun 2026 01:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-9484: Deserialization RCE via Apache Tomcat Pers...]]></title>
      <description><![CDATA[A deep dive into CVE-2020-9484, the Apache Tomcat PersistenceManager deserialization RCE — affected versions, CVSS/EPSS context, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-9484-deserialization-rce-via-apache-tomcat-persistencemanager</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-9484-deserialization-rce-via-apache-tomcat-persistencemanager</guid>
      <pubDate>Tue, 23 Jun 2026 00:15:10 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Interactive Application Security Testing (IAST) explained]]></title>
      <description><![CDATA[IAST tests applications from the inside while they run, catching flaws SAST and DAST miss alone. Here's how it works, how Checkmarx uses it, and where gaps remain.]]></description>
      <link>https://safeguard.sh/resources/blog/interactive-application-security-testing-iast-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/interactive-application-security-testing-iast-explained</guid>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Web Application Vulnerability Scanners, Compared]]></title>
      <description><![CDATA[Web application vulnerability scanners range from free online URL checkers to full DAST platforms — here's how the categories differ and which one actually matches your risk.]]></description>
      <link>https://safeguard.sh/resources/blog/web-application-vulnerability-scanners-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-application-vulnerability-scanners-compared</guid>
      <pubDate>Mon, 22 Jun 2026 22:54:43 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-25122: Request mix-up via Apache Tomcat h2c support]]></title>
      <description><![CDATA[CVE-2021-25122 let Apache Tomcat mix up HTTP responses between concurrent users via the h2c upgrade path. Here's the impact, affected versions, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-25122-request-mix-up-via-apache-tomcat-h2c-support</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-25122-request-mix-up-via-apache-tomcat-h2c-support</guid>
      <pubDate>Mon, 22 Jun 2026 21:34:16 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-25329: Incomplete fix of Tomcat PersistenceManag...]]></title>
      <description><![CDATA[CVE-2021-25329 shows how Tomcat's PersistenceManager deserialization fix (CVE-2020-9484) was incomplete, still risking RCE in edge-case configs.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-25329-incomplete-fix-of-tomcat-persistencemanager-deserialization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-25329-incomplete-fix-of-tomcat-persistencemanager-deserialization</guid>
      <pubDate>Mon, 22 Jun 2026 20:13:49 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-1471: Remote code execution in SnakeYAML deseria...]]></title>
      <description><![CDATA[CVE-2022-1471 exposes SnakeYAML deserialization to remote code execution. Here is what is affected, CVSS context, and how to remediate the flaw.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-1471-remote-code-execution-in-snakeyaml-deserialization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-1471-remote-code-execution-in-snakeyaml-deserialization</guid>
      <pubDate>Mon, 22 Jun 2026 18:53:23 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-41080: Apache Tomcat Open Redirect in FORM Authentication]]></title>
      <description><![CDATA[CVE-2023-41080 lets a crafted URL trigger an open redirect during FORM login on Tomcat's ROOT web app. Here is the exact condition, affected versions, and the one-line fix path.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-41080</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-41080</guid>
      <pubDate>Mon, 22 Jun 2026 17:32:56 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-42919: Python's multiprocessing Privilege Escalation Explained]]></title>
      <description><![CDATA[A local privilege escalation in Python's multiprocessing forkserver on Linux. Here is what CVE-2022-42919 does, which versions are affected, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-42919</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-42919</guid>
      <pubDate>Mon, 22 Jun 2026 16:12:29 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Level Security: A Practical Guide]]></title>
      <description><![CDATA[Enterprise level security is less about buying premium tools and more about controls that hold up under scale, audit, and adversaries. Here is what actually distinguishes it.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-level-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-level-security</guid>
      <pubDate>Mon, 22 Jun 2026 14:52:03 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Serialisation in Java: A Security Guide]]></title>
      <description><![CDATA[How Java serialisation works, why deserialising untrusted data is dangerous, and the filters and patterns that keep it from becoming remote code execution.]]></description>
      <link>https://safeguard.sh/resources/blog/serialisation-in-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/serialisation-in-java</guid>
      <pubDate>Mon, 22 Jun 2026 13:31:36 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[IronWorm: A Rust eBPF Rootkit Worm Hits the npm Supply Chain]]></title>
      <description><![CDATA[IronWorm is a compiled Rust npm worm with a kernel-level eBPF rootkit, Tor C2, and OIDC-based self-propagation. It is the engineering ceiling of 2026 software supply chain attacks — and it carries no CVE.]]></description>
      <link>https://safeguard.sh/resources/blog/ironworm-npm-supply-chain-worm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ironworm-npm-supply-chain-worm</guid>
      <pubDate>Mon, 22 Jun 2026 13:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Shai-Hulud: The Self-Replicating npm Worm That Hit 500+ Packages]]></title>
      <description><![CDATA[On September 15, 2025, a self-replicating npm worm dubbed Shai-Hulud backdoored more than 500 packages, including @ctrl/tinycolor and CrowdStrike libraries, by pivoting through stolen publish tokens.]]></description>
      <link>https://safeguard.sh/resources/blog/shai-hulud-npm-worm-self-replicating-september-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shai-hulud-npm-worm-self-replicating-september-2025</guid>
      <pubDate>Mon, 22 Jun 2026 12:11:09 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSF Scorecard v6 Roadmap: OSPS Baseline Conformance]]></title>
      <description><![CDATA[The Scorecard v6 proposal introduces PASS/FAIL/ATTESTED conformance against the OSPS Baseline, versioned probe mapping, and CI gating. Here is what consumers and maintainers need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/openssf-scorecard-v6-roadmap-osps-baseline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssf-scorecard-v6-roadmap-osps-baseline</guid>
      <pubDate>Mon, 22 Jun 2026 10:50:43 GMT</pubDate>
      <category>Frameworks</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[EKS vs GKE vs AKS: managed Kubernetes security compared]]></title>
      <description><![CDATA[A technical breakdown of EKS, GKE, and AKS security: default hardening gaps, IAM models, real CVEs, and audit logging differences teams must know.]]></description>
      <link>https://safeguard.sh/resources/blog/eks-vs-gke-vs-aks-managed-kubernetes-security-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eks-vs-gke-vs-aks-managed-kubernetes-security-compared</guid>
      <pubDate>Mon, 22 Jun 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[EU AI Act Article 5: Prohibited Practices Now Enforceable]]></title>
      <description><![CDATA[Article 5 of the EU AI Act became enforceable on 2 August 2025, with administrative fines up to €35 million or 7% of worldwide turnover for prohibited AI practices.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-ai-act-prohibited-practices-august-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-ai-act-prohibited-practices-august-2025</guid>
      <pubDate>Mon, 22 Jun 2026 09:30:16 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AWS-2025-021: The IMDS Impersonation Bulletin Few Teams Read Carefully]]></title>
      <description><![CDATA[AWS published Security Bulletin AWS-2025-021 warning that EC2 instances may interact with unexpected AWS accounts through the Instance Metadata Service. Here is the technical impact and the IMDSv2 enforcement plan.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-imds-impersonation-bulletin-2025-021</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-imds-impersonation-bulletin-2025-021</guid>
      <pubDate>Mon, 22 Jun 2026 08:09:49 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Pooja Rao)</author>
    </item>
    <item>
      <title><![CDATA[Security implications of Kubernetes operators]]></title>
      <description><![CDATA[Kubernetes Operators run with elevated, cluster-wide privilege by design. IngressNightmare, Argo CD, and cert-manager CVEs show what happens when that trust is abused.]]></description>
      <link>https://safeguard.sh/resources/blog/security-implications-of-kubernetes-operators</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-implications-of-kubernetes-operators</guid>
      <pubDate>Mon, 22 Jun 2026 07:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[ngx-cookie-service: Secure Cookie Handling in Angular]]></title>
      <description><![CDATA[ngx-cookie-service makes reading and writing cookies in Angular trivial, but the security depends entirely on the flags you set. Here is how to use it without leaking session data.]]></description>
      <link>https://safeguard.sh/resources/blog/ngx-cookie-service</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ngx-cookie-service</guid>
      <pubDate>Mon, 22 Jun 2026 06:49:22 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Container security for Kubernetes and Docker]]></title>
      <description><![CDATA[A practical glossary breakdown of container security for Kubernetes and Docker: the real risks, key benchmarks, and where code-scanning tools like Checkmarx fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-for-kubernetes-and-docker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-for-kubernetes-and-docker</guid>
      <pubDate>Mon, 22 Jun 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Is @vitejs/plugin-react Safe? A Security Review]]></title>
      <description><![CDATA[@vitejs/plugin-react is a build-time dev dependency, so its security story is mostly about supply chain trust and keeping it current rather than runtime exploits.]]></description>
      <link>https://safeguard.sh/resources/blog/vitejs-plugin-react</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vitejs-plugin-react</guid>
      <pubDate>Mon, 22 Jun 2026 05:28:56 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[react-native-compressor: Security and Trust Considerations for Media Compression]]></title>
      <description><![CDATA[react-native-compressor shrinks images, video, and audio on-device before upload. Here is how to vet it, its native footprint, and where the real risks are.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-compressor</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-compressor</guid>
      <pubDate>Mon, 22 Jun 2026 04:08:29 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[OCI image vulnerability scanning explained]]></title>
      <description><![CDATA[A concrete breakdown of how OCI image vulnerability scanning works, where scanners miss real risk, and how to build a scan workflow that doesn't drown teams in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/oci-image-vulnerability-scanning-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oci-image-vulnerability-scanning-explained</guid>
      <pubDate>Mon, 22 Jun 2026 04:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Static Analysis Tools compared]]></title>
      <description><![CDATA[Veracode built its name on SAST, DAST, and SCA for application code. Safeguard focuses static analysis on the software supply chain. Here's how the two actually differ.]]></description>
      <link>https://safeguard.sh/resources/blog/static-analysis-tools-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-analysis-tools-compared</guid>
      <pubDate>Mon, 22 Jun 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2017-18640: Denial of service via SnakeYAML alias ent...]]></title>
      <description><![CDATA[CVE-2017-18640 lets attackers crash Java services by abusing SnakeYAML's YAML alias/anchor expansion. Here's what's affected and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2017-18640-denial-of-service-via-snakeyaml-alias-entity-expansion</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2017-18640-denial-of-service-via-snakeyaml-alias-entity-expansion</guid>
      <pubDate>Mon, 22 Jun 2026 02:48:02 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2016-1000027: Remote code execution via Spring HttpIn...]]></title>
      <description><![CDATA[A decade-old flaw in Spring's HttpInvokerServiceExporter enables unauthenticated RCE via Java deserialization. Severity, timeline, and remediation for CVE-2016-1000027.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2016-1000027-remote-code-execution-via-spring-httpinvokerserviceexporter</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2016-1000027-remote-code-execution-via-spring-httpinvokerserviceexporter</guid>
      <pubDate>Mon, 22 Jun 2026 01:27:36 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Container escape vulnerabilities explained]]></title>
      <description><![CDATA[Container escape vulnerabilities let attackers break out of isolation and reach the host kernel. Here's how CVE-2024-21626 and CVE-2019-5736 actually work.]]></description>
      <link>https://safeguard.sh/resources/blog/container-escape-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-escape-vulnerabilities-explained</guid>
      <pubDate>Mon, 22 Jun 2026 01:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2018-1270: Remote code execution in Spring Messaging ...]]></title>
      <description><![CDATA[CVE-2018-1270 is a critical, unauthenticated RCE in Spring Messaging's STOMP-over-WebSocket support. Here's what's affected, how severe it is, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2018-1270-remote-code-execution-in-spring-messaging-stomp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2018-1270-remote-code-execution-in-spring-messaging-stomp</guid>
      <pubDate>Mon, 22 Jun 2026 00:07:09 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Veracode Trust Center walkthrough / vendor security trans...]]></title>
      <description><![CDATA[What Veracode's trust center actually proves about vendor security — and why SOC 2 reports don't answer software supply chain questions like SBOM and build provenance.]]></description>
      <link>https://safeguard.sh/resources/blog/veracode-trust-center-walkthrough-vendor-security-transparency</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/veracode-trust-center-walkthrough-vendor-security-transparency</guid>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2018-1271: Path traversal in Spring MVC static resour...]]></title>
      <description><![CDATA[A path traversal flaw in Spring MVC's static resource handling let attackers on Windows deployments escape the web root and read arbitrary files.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2018-1271-path-traversal-in-spring-mvc-static-resource-handling-on-windows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2018-1271-path-traversal-in-spring-mvc-static-resource-handling-on-windows</guid>
      <pubDate>Sun, 21 Jun 2026 22:46:42 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-5398: Content-type bypass in Spring Framework]]></title>
      <description><![CDATA[CVE-2020-5398 lets attackers bypass Spring Framework RFD protections via Content-Disposition, tricking browsers into downloading malicious files.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-5398-content-type-bypass-in-spring-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-5398-content-type-bypass-in-spring-framework</guid>
      <pubDate>Sun, 21 Jun 2026 21:26:16 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2016-4977: Remote code execution in Spring Security O...]]></title>
      <description><![CDATA[CVE-2016-4977 let attackers achieve remote code execution against Spring Security OAuth's whitelabel views via SpEL injection. Here's what shipped, why, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2016-4977-remote-code-execution-in-spring-security-oauth</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2016-4977-remote-code-execution-in-spring-security-oauth</guid>
      <pubDate>Sun, 21 Jun 2026 20:05:49 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2018-1199: Authorization bypass in Spring Security CO...]]></title>
      <description><![CDATA[CVE-2018-1199 let CORS pre-flight requests slip past Spring Security's authorization checks. What it affected, its real severity, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2018-1199-authorization-bypass-in-spring-security-cors-handling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2018-1199-authorization-bypass-in-spring-security-cors-handling</guid>
      <pubDate>Sun, 21 Jun 2026 18:45:22 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-22112: Improper authorization in Spring Security...]]></title>
      <description><![CDATA[CVE-2021-22112 let Spring Security lose SecurityContext changes mid-request, an improper authorization flaw exposing OAuth2-secured apps to privilege escalation.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-22112-improper-authorization-in-spring-security-oauth2-with-actuator-endpoints</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-22112-improper-authorization-in-spring-security-oauth2-with-actuator-endpoints</guid>
      <pubDate>Sun, 21 Jun 2026 17:24:56 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[snyk.io: What It Is, What It Costs, and How It Fits Your Stack]]></title>
      <description><![CDATA[A straight look at snyk.io: what the platform scans, how its 2025 pricing tiers and test caps work, and where it fits alongside other security tooling.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-io</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-io</guid>
      <pubDate>Sun, 21 Jun 2026 16:04:29 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[TLS Library Comparison: OpenSSL vs. LibreSSL vs. BoringSSL]]></title>
      <description><![CDATA[Three forks of the same codebase, three different security philosophies. Here is how to choose the right TLS library for your project.]]></description>
      <link>https://safeguard.sh/resources/blog/tls-library-comparison-openssl-libressl-boringssl</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tls-library-comparison-openssl-libressl-boringssl</guid>
      <pubDate>Sun, 21 Jun 2026 14:44:02 GMT</pubDate>
      <category>Secure Development</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-0815: Remote code execution in .NET Core]]></title>
      <description><![CDATA[CVE-2019-0815 is a Microsoft-disclosed remote code execution flaw in .NET Core. Here's what we know about impact, remediation, and supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-0815-remote-code-execution-in-net-core</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-0815-remote-code-execution-in-net-core</guid>
      <pubDate>Sun, 21 Jun 2026 13:23:35 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Agentic AI Security: Why Architecture Beats Model Size in Vulnerability Discovery]]></title>
      <description><![CDATA[The CyberGym leaderboard shows the lead in AI vulnerability discovery moving to multi-agent orchestration, not raw model scale. Here is what that means for security teams betting on agentic AI.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-agent-verification-beats-model-size</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-agent-verification-beats-model-size</guid>
      <pubDate>Sun, 21 Jun 2026 13:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Stryker Wiper Attack: When Hacktivists Used Intune to Brick 200,000 Medtech Devices]]></title>
      <description><![CDATA[An Iran-aligned group used a compromised admin account and Microsoft Intune to factory-reset roughly 200,000 of Stryker's devices in real time. The lesson is uncomfortable: your management plane is your biggest single point of failure.]]></description>
      <link>https://safeguard.sh/resources/blog/stryker-cyberattack-2026-medtech</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/stryker-cyberattack-2026-medtech</guid>
      <pubDate>Sun, 21 Jun 2026 13:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-0980: .NET Core remote code execution via crafte...]]></title>
      <description><![CDATA[CVE-2019-0980 lets attackers run arbitrary code via a crafted document that abuses how .NET Framework and .NET Core process untrusted input.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-0980-net-core-remote-code-execution-via-crafted-document</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-0980-net-core-remote-code-execution-via-crafted-document</guid>
      <pubDate>Sun, 21 Jun 2026 12:03:09 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-0981: .NET Core remote code execution (second va...]]></title>
      <description><![CDATA[CVE-2019-0981, the second variant of the April 2019 .NET Core RCE pair, let attackers run arbitrary code via a malicious file. Here's what to patch and why.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-0981-net-core-remote-code-execution-second-variant</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-0981-net-core-remote-code-execution-second-variant</guid>
      <pubDate>Sun, 21 Jun 2026 10:42:42 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Docker Hub malicious image detection]]></title>
      <description><![CDATA[Docker Hub's open upload model has enabled real cryptojacking and phishing campaigns — here's how attackers hide malware in images and how to detect them.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-hub-malicious-image-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-hub-malicious-image-detection</guid>
      <pubDate>Sun, 21 Jun 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-1075: Denial of service in .NET Core]]></title>
      <description><![CDATA[CVE-2019-1075 is a 2019 denial-of-service flaw in .NET Core that let unauthenticated attackers crash web apps with crafted requests. Here's what to know.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-1075-denial-of-service-in-net-core</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-1075-denial-of-service-in-net-core</guid>
      <pubDate>Sun, 21 Jun 2026 09:22:15 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Veracode vs. Checkmarx / Snyk / SonarQube / Fortify (comp...]]></title>
      <description><![CDATA[Comparing Veracode, Checkmarx, Snyk, SonarQube, and Fortify against Safeguard's supply chain security approach — scan scope, deployment, and fit.]]></description>
      <link>https://safeguard.sh/resources/blog/veracode-vs-checkmarx-snyk-sonarqube-fortify-competitive-landscape</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/veracode-vs-checkmarx-snyk-sonarqube-fortify-competitive-landscape</guid>
      <pubDate>Sun, 21 Jun 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-0602: Denial of service in ASP.NET Core]]></title>
      <description><![CDATA[A denial of service flaw in ASP.NET Core 3.0/3.1, patched January 2020. Unauthenticated, network-exploitable, high-severity impact on availability.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-0602-denial-of-service-in-aspnet-core</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-0602-denial-of-service-in-aspnet-core</guid>
      <pubDate>Sun, 21 Jun 2026 08:01:49 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Securing serverless containers on Fargate and Cloud Run]]></title>
      <description><![CDATA[No SSH, no DaemonSets, no host agents. Here's how Firecracker and gVisor isolation change container security on Fargate and Cloud Run — and what still gets you breached.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-serverless-containers-on-fargate-and-cloud-run</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-serverless-containers-on-fargate-and-cloud-run</guid>
      <pubDate>Sun, 21 Jun 2026 07:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-1045: Security feature bypass in ASP.NET Core]]></title>
      <description><![CDATA[CVE-2020-1045 lets attackers bypass CORS protections in ASP.NET Core apps. Here's what's affected, the risk context, and how to remediate it for good.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-1045-security-feature-bypass-in-aspnet-core</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-1045-security-feature-bypass-in-aspnet-core</guid>
      <pubDate>Sun, 21 Jun 2026 06:41:22 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Application Security: The Complete Guide]]></title>
      <description><![CDATA[What is application security? A concrete guide covering AppSec fundamentals, OWASP Top 10 risks, supply chain threats, and how Safeguard fills the gaps legacy tools like Veracode leave open.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-the-complete-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-the-complete-guide</guid>
      <pubDate>Sun, 21 Jun 2026 06:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-26701: Remote code execution in .NET Core]]></title>
      <description><![CDATA[CVE-2021-26701 is a 2021 .NET Core remote code execution flaw tied to text encoding. Here's what was affected, how it was patched, and how to stay protected.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-26701-remote-code-execution-in-net-core</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-26701-remote-code-execution-in-net-core</guid>
      <pubDate>Sun, 21 Jun 2026 05:20:55 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-29117: Regular expression denial of service in .NET]]></title>
      <description><![CDATA[CVE-2022-29117 is a regular expression denial-of-service vulnerability in .NET that lets attackers exhaust CPU with crafted input. Here's what to patch and why.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-29117-regular-expression-denial-of-service-in-net</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-29117-regular-expression-denial-of-service-in-net</guid>
      <pubDate>Sun, 21 Jun 2026 04:00:29 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Reducing CVEs in container base images]]></title>
      <description><![CDATA[Base images inherit hundreds of OS-level CVEs your app never touches. Here's how reachability analysis and minimal bases cut real risk, not just counts.]]></description>
      <link>https://safeguard.sh/resources/blog/reducing-cves-in-container-base-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reducing-cves-in-container-base-images</guid>
      <pubDate>Sun, 21 Jun 2026 04:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What is AI Code Remediation?]]></title>
      <description><![CDATA[AI code remediation turns vulnerability findings into ready-to-merge patches. Here's how it works, where Veracode's approach falls short, and how Safeguard closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-ai-code-remediation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-ai-code-remediation</guid>
      <pubDate>Sun, 21 Jun 2026 03:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Is the jsPDF npm Package Safe? A Security Review]]></title>
      <description><![CDATA[The jsPDF npm package is widely used for client-side PDF generation, but recent path traversal and ReDoS advisories mean the version you pin matters. Here is what to check.]]></description>
      <link>https://safeguard.sh/resources/blog/jspdf-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jspdf-npm</guid>
      <pubDate>Sun, 21 Jun 2026 02:40:02 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SPDX 3.0 AI Profile: Building an AIBOM in Practice]]></title>
      <description><![CDATA[SPDX 3.0 was published in March 2025 with a dedicated AI profile and a Dataset profile. We walk through how to produce a defensible AIBOM in SPDX format alongside or in place of CycloneDX.]]></description>
      <link>https://safeguard.sh/resources/blog/spdx-3-0-ai-profile-aibom-implementation-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spdx-3-0-ai-profile-aibom-implementation-guide</guid>
      <pubDate>Sun, 21 Jun 2026 01:19:35 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Top AWS security misconfigurations and how to fix them]]></title>
      <description><![CDATA[A practical AWS misconfigurations cheat sheet — IAM, S3, security groups, logging, and snapshots — with real breach data and exact fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/top-aws-security-misconfigurations-and-how-to-fix-them</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-aws-security-misconfigurations-and-how-to-fix-them</guid>
      <pubDate>Sun, 21 Jun 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What is Vibe Coding (and its security risk)?]]></title>
      <description><![CDATA[Vibe coding lets AI write your app while you skip the review. Veracode found 45% of AI-generated code is vulnerable. Here's the risk, and how Safeguard closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-vibe-coding-and-its-security-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-vibe-coding-and-its-security-risk</guid>
      <pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Syft v1.20 Release: Faster Scans, Smarter License Detection]]></title>
      <description><![CDATA[Anchore's Syft v1.20 ships a refactored license cataloger, Bitnami SBOM passthrough, and a 2x speedup on filesystem scans. We tested the upgrade on five real codebases.]]></description>
      <link>https://safeguard.sh/resources/blog/syft-v1-20-release-license-detection-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/syft-v1-20-release-license-detection-2025</guid>
      <pubDate>Sat, 20 Jun 2026 23:59:09 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[VEX Adoption in the Enterprise: Lessons From Early Adopters]]></title>
      <description><![CDATA[Vulnerability Exploitability eXchange documents promise to reduce alert fatigue by distinguishing exploitable vulnerabilities from theoretical ones. Here is how enterprises are actually using them.]]></description>
      <link>https://safeguard.sh/resources/blog/vex-adoption-enterprise-case-studies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vex-adoption-enterprise-case-studies</guid>
      <pubDate>Sat, 20 Jun 2026 22:38:42 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[@ctrl/tinycolor and the 40-Package npm Wave of September 2025]]></title>
      <description><![CDATA[@ctrl/tinycolor versions 4.1.1 and 4.1.2 shipped a credential-stealing payload that propagated to 40+ packages with 2 million combined weekly downloads in under 24 hours.]]></description>
      <link>https://safeguard.sh/resources/blog/ctrl-tinycolor-npm-compromise-shai-hulud-wave</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ctrl-tinycolor-npm-compromise-shai-hulud-wave</guid>
      <pubDate>Sat, 20 Jun 2026 21:18:15 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Secure Coding Practices: A Working Checklist]]></title>
      <description><![CDATA[OWASP secure coding practices boil down to a handful of checks that catch most real-world vulnerabilities — here's the checklist teams actually use, not the full 200-item reference.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-secure-coding-practices-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-secure-coding-practices-checklist</guid>
      <pubDate>Sat, 20 Jun 2026 19:57:48 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-29145: Denial of service in .NET SignalR/Network...]]></title>
      <description><![CDATA[CVE-2022-29145 is a High-severity DoS flaw in .NET's networking stack affecting ASP.NET Core and SignalR. Here's the scope, timeline, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-29145-denial-of-service-in-net-signalrnetworking-components</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-29145-denial-of-service-in-net-signalrnetworking-components</guid>
      <pubDate>Sat, 20 Jun 2026 18:37:22 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Code Scan Tools: How They Work and What to Use]]></title>
      <description><![CDATA[A practical breakdown of code scan tool categories — SAST, SCA, secrets, and DAST — how each works, and how to choose and combine them without alert fatigue.]]></description>
      <link>https://safeguard.sh/resources/blog/code-scan-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-scan-tool</guid>
      <pubDate>Sat, 20 Jun 2026 17:16:55 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-29148: Denial of service in .NET Kestrel HTTP stack]]></title>
      <description><![CDATA[CVE-2022-21986 is a CVSS 7.5 denial-of-service flaw in .NET Kestrel's HTTP/2 and HTTP/3 handling. Here's what's affected and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-29148-denial-of-service-in-net-kestrel-http-stack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-29148-denial-of-service-in-net-kestrel-http-stack</guid>
      <pubDate>Sat, 20 Jun 2026 15:56:28 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-38013: Denial of service in .NET via crafted req...]]></title>
      <description><![CDATA[A denial-of-service flaw in .NET, CVE-2022-38013, let attackers crash apps with crafted requests. Here is what is affected, the risk, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-38013-denial-of-service-in-net-via-crafted-requests</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-38013-denial-of-service-in-net-via-crafted-requests</guid>
      <pubDate>Sat, 20 Jun 2026 14:36:02 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-29331: Remote code execution in .NET via crafted...]]></title>
      <description><![CDATA[CVE-2023-29331 lets a crafted .NET assembly trigger remote code execution during loading. Here's what's affected, the severity context, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-29331-remote-code-execution-in-net-via-crafted-assembly-loading</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-29331-remote-code-execution-in-net-via-crafted-assembly-loading</guid>
      <pubDate>Sat, 20 Jun 2026 13:15:35 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Ransomware vs. Hospitals: The 2026 Healthcare Surge and the Push to Call It Terrorism]]></title>
      <description><![CDATA[Healthcare ransomware dipped in volume in May 2026 but kept climbing in impact, and a former FBI cyber chief is asking Congress to treat hospital ransomware as terrorism. We weigh the policy debate against what actually protects patients.]]></description>
      <link>https://safeguard.sh/resources/blog/healthcare-ransomware-surge-2026-fbi</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/healthcare-ransomware-surge-2026-fbi</guid>
      <pubDate>Sat, 20 Jun 2026 13:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[ShinyHunters Breaches Match Group: Hinge, Match, and OkCupid Data Exposed in a Vishing-Driven Extortion Hit]]></title>
      <description><![CDATA[ShinyHunters claimed 10 million records from Match Group's dating apps in late January 2026. Here is what was actually taken (Hinge, Match, and OkCupid — notably not Tinder), how a single vishing call opened the door, and why dating-app data raises the extortion stakes.]]></description>
      <link>https://safeguard.sh/resources/blog/match-group-shinyhunters-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/match-group-shinyhunters-breach</guid>
      <pubDate>Sat, 20 Jun 2026 13:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[PyTorch Lightning PyPI Compromise: A Software Supply Chain Attack Built to Drain ML Credentials]]></title>
      <description><![CDATA[In April 2026, attackers pushed malicious versions of the lightning PyPI package and an npm intercom-client release, harvesting cloud, CI/CD, and GitHub credentials. Here is what happened and why ML tooling is now a prime supply chain target.]]></description>
      <link>https://safeguard.sh/resources/blog/pytorch-lightning-pypi-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pytorch-lightning-pypi-compromise</guid>
      <pubDate>Sat, 20 Jun 2026 13:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Who Is Snyk's General Counsel, and Why Vendor Legal Governance Matters]]></title>
      <description><![CDATA[The Snyk general counsel runs legal, privacy, and regulatory affairs for a developer security vendor. Here's what that role tells you about evaluating any security supplier.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-general-counsel</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-general-counsel</guid>
      <pubDate>Sat, 20 Jun 2026 11:55:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Security News: How to Track and Respond to Python Package Threats]]></title>
      <description><![CDATA[Keeping up with PyPI security news is now part of the job for any Python team. Here is how to follow the threats that matter and act before a malicious package reaches production.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-security-news</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-security-news</guid>
      <pubDate>Sat, 20 Jun 2026 10:34:42 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The AWS shared responsibility model explained]]></title>
      <description><![CDATA[AWS secures the cloud; you secure what's in it. Here's exactly where that line falls across EC2, RDS, Lambda, and EKS -- with real breach examples.]]></description>
      <link>https://safeguard.sh/resources/blog/the-aws-shared-responsibility-model-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-aws-shared-responsibility-model-explained</guid>
      <pubDate>Sat, 20 Jun 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Agent2Agent (A2A): The Security Model for Cross-Vendor Agent Communication]]></title>
      <description><![CDATA[Google launched A2A in April 2025 with 50 partners; the Linux Foundation took it over in June. We unpack the security primitives and what defenders should ask for.]]></description>
      <link>https://safeguard.sh/resources/blog/agent2agent-a2a-protocol-security-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agent2agent-a2a-protocol-security-2025</guid>
      <pubDate>Sat, 20 Jun 2026 09:14:15 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software Development Lifecycle (SDLC) security]]></title>
      <description><![CDATA[A secure SDLC needs more than periodic scans. See where Veracode's upload-and-scan model leaves supply chain gaps, and how continuous, provenance-aware security closes them.]]></description>
      <link>https://safeguard.sh/resources/blog/software-development-lifecycle-sdlc-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-development-lifecycle-sdlc-security</guid>
      <pubDate>Sat, 20 Jun 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Set Up Dependency Review on GitHub Pull Requests]]></title>
      <description><![CDATA[GitHub's dependency-review-action can block PRs that introduce vulnerable or badly-licensed packages. Here is the exact configuration, plus the cases it silently misses.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-dependency-review-on-github-pull-requests</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-dependency-review-on-github-pull-requests</guid>
      <pubDate>Sat, 20 Jun 2026 07:53:48 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Sofia Marchetti)</author>
    </item>
    <item>
      <title><![CDATA[How to secure an Amazon S3 bucket]]></title>
      <description><![CDATA[S3 misconfigurations have caused breaches from Verizon to Pegasus Airlines. Here's what actually secures a bucket—defaults, policies, encryption, and monitoring that hold.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-secure-an-amazon-s3-bucket</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-secure-an-amazon-s3-bucket</guid>
      <pubDate>Sat, 20 Jun 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[API Scanner Tools: What to Look For]]></title>
      <description><![CDATA[An API scanner tool needs to do more than replay a Postman collection against your endpoints. Here's what actually separates a useful API scanner from one that generates noise.]]></description>
      <link>https://safeguard.sh/resources/blog/api-scanner-tools-what-to-look-for</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-scanner-tools-what-to-look-for</guid>
      <pubDate>Sat, 20 Jun 2026 06:33:22 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Scanner Tools: how they work]]></title>
      <description><![CDATA[A breakdown of how SAST, DAST, SCA, and container vulnerability scanner tools actually work, where Veracode fits, and why false positives remain the industry's biggest problem.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-scanner-tools-how-they-work</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-scanner-tools-how-they-work</guid>
      <pubDate>Sat, 20 Jun 2026 06:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Angular Compiler Security: What @angular/compiler-cli Handles and How to Keep It Safe]]></title>
      <description><![CDATA[The Angular compiler is more than a build step — it enforces your template sanitization contract, and a 2025 XSS bug proved that assumption can break.]]></description>
      <link>https://safeguard.sh/resources/blog/angular-compiler</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/angular-compiler</guid>
      <pubDate>Sat, 20 Jun 2026 05:12:55 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AWS IAM permissions boundaries best practices]]></title>
      <description><![CDATA[How AWS IAM permissions boundaries cap delegated identities, differ from SCPs, and where teams get privilege escalation wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-iam-permissions-boundaries-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-iam-permissions-boundaries-best-practices</guid>
      <pubDate>Sat, 20 Jun 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[What Is a DevOps Pipeline? Stages, Tools, and Security Gates]]></title>
      <description><![CDATA[A DevOps pipeline is the automated path code takes from commit to production. Here are the stages every pipeline shares, the tools teams actually use, and where security gates belong.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-devops-pipeline-stages-tools-security-gates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-devops-pipeline-stages-tools-security-gates</guid>
      <pubDate>Sat, 20 Jun 2026 03:52:28 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Web Application Security Standards overview]]></title>
      <description><![CDATA[A breakdown of OWASP, NIST SSDF, and PCI DSS 4.0 web application security standards, where Veracode's scanning model covers them, and where supply-chain gaps remain.]]></description>
      <link>https://safeguard.sh/resources/blog/web-application-security-standards-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-application-security-standards-overview</guid>
      <pubDate>Sat, 20 Jun 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Shift-Left Security Testing in Practice]]></title>
      <description><![CDATA[Shift-left security testing means catching vulnerabilities at commit time instead of at deployment — here's what that actually looks like on a working pipeline, not just the slogan.]]></description>
      <link>https://safeguard.sh/resources/blog/shift-left-security-testing-in-practice</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shift-left-security-testing-in-practice</guid>
      <pubDate>Sat, 20 Jun 2026 02:32:01 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[OpenJDK Vulnerabilities: Tracking and Patching]]></title>
      <description><![CDATA[OpenJDK vulnerabilities are disclosed and patched through Oracle's quarterly Critical Patch Update cycle, but tracking them well means watching your specific JDK distribution and version line, not just assuming a generic update covers you.]]></description>
      <link>https://safeguard.sh/resources/blog/openjdk-vulnerabilities-tracking-and-patching</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openjdk-vulnerabilities-tracking-and-patching</guid>
      <pubDate>Sat, 20 Jun 2026 01:11:35 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Top 10 Azure security risks and prevention]]></title>
      <description><![CDATA[Real Azure breaches — BlueBleed, ChaosDB, OMIGOD, Midnight Blizzard — trace back to storage misconfigs, identity sprawl, and exposed secrets, not zero-days.]]></description>
      <link>https://safeguard.sh/resources/blog/top-10-azure-security-risks-and-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-10-azure-security-risks-and-prevention</guid>
      <pubDate>Sat, 20 Jun 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Testing Tools and Methodology]]></title>
      <description><![CDATA[OWASP testing tools cover the methodology; Veracode wraps part of it commercially. Neither was built for supply chain risk — here's where the gaps are and how to close them.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-testing-tools-and-methodology</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-testing-tools-and-methodology</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Docker Scanners: Comparing the Image-Scanning Options]]></title>
      <description><![CDATA[A docker scanner has to check three separate layers — base OS packages, application dependencies, and the Dockerfile itself — and most tools are genuinely strong at only one or two.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-scanners-comparing-the-image-scanning-options</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-scanners-comparing-the-image-scanning-options</guid>
      <pubDate>Fri, 19 Jun 2026 23:51:08 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-33170: Denial of service in .NET SocketsHttpHandler]]></title>
      <description><![CDATA[A memory-allocation flaw in .NET's SocketsHttpHandler (CVE-2022-23267) let malicious HTTP responses trigger denial of service in HttpClient-based apps.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-33170-denial-of-service-in-net-socketshttphandler</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-33170-denial-of-service-in-net-socketshttphandler</guid>
      <pubDate>Fri, 19 Jun 2026 22:30:41 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-36799: Denial of service in .NET Core]]></title>
      <description><![CDATA[CVE-2023-36799 is a denial-of-service flaw in the .NET runtime powering .NET Core-descended apps. Here's what's affected and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-36799-denial-of-service-in-net-core</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-36799-denial-of-service-in-net-core</guid>
      <pubDate>Fri, 19 Jun 2026 21:10:15 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-0056: Security bypass in Microsoft.Data.SqlClient]]></title>
      <description><![CDATA[CVE-2024-0056 lets attackers bypass TLS protections in Microsoft.Data.SqlClient/System.Data.SqlClient. Affected versions, remediation, and masking as defense in depth.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-0056-security-bypass-in-microsoftdatasqlclient</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-0056-security-bypass-in-microsoftdatasqlclient</guid>
      <pubDate>Fri, 19 Jun 2026 19:49:48 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-0057: Certificate validation bypass in .NET X.50...]]></title>
      <description><![CDATA[CVE-2024-0057 lets attackers forge X.509 certificates that bypass .NET's chain validation, risking spoofing in TLS and code-signing flows.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-0057-certificate-validation-bypass-in-net-x509-handling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-0057-certificate-validation-bypass-in-net-x509-handling</guid>
      <pubDate>Fri, 19 Jun 2026 18:29:21 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[oidc-client-ts: A Security Guide for Browser OIDC]]></title>
      <description><![CDATA[oidc-client-ts is the maintained TypeScript library for adding OpenID Connect and OAuth2 to browser apps. Here is how to use it, and how to avoid the token-handling mistakes that undo its security.]]></description>
      <link>https://safeguard.sh/resources/blog/oidc-client-ts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oidc-client-ts</guid>
      <pubDate>Fri, 19 Jun 2026 17:08:55 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Source Code Analysis Tools: SAST, Linters, and Semantic Engines]]></title>
      <description><![CDATA[Not all source code analysis tools do the same job. Linters, pattern-based SAST, and semantic dataflow engines catch different bug classes, and mixing them up wastes budget.]]></description>
      <link>https://safeguard.sh/resources/blog/source-code-analysis-tools-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/source-code-analysis-tools-guide</guid>
      <pubDate>Fri, 19 Jun 2026 15:48:28 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Revenue Explained: ARR, Valuation, and the Road to IPO]]></title>
      <description><![CDATA[Snyk revenue crossed $300M in annual recurring revenue with a $7.4B valuation. Here is what the numbers say about the developer-security market.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-revenue</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-revenue</guid>
      <pubDate>Fri, 19 Jun 2026 14:28:01 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[@aws-sdk/client-s3: A Practical Security Guide]]></title>
      <description><![CDATA[The @aws-sdk/client-s3 package is the AWS SDK for JavaScript v3 S3 client. Here is how to use it securely, from credential handling to why v2 is now end-of-support.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-sdk-client-s3</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-sdk-client-s3</guid>
      <pubDate>Fri, 19 Jun 2026 13:07:35 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Kairos Ransomware Hits Gregory Jewellers: 574 GB of Data Extortion at an Australian Luxury Retailer]]></title>
      <description><![CDATA[The Kairos extortion group claims it stole roughly 574 GB from Australian luxury jeweller Gregory Jewellers. Here is what is verified, what the group's playbook tells us, and why pure data-extortion crews are the harder problem.]]></description>
      <link>https://safeguard.sh/resources/blog/gregory-jewellers-kairos-ransomware</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gregory-jewellers-kairos-ransomware</guid>
      <pubDate>Fri, 19 Jun 2026 13:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Where Defenders Should Be: The H2 2026 Cybersecurity Conference Calendar]]></title>
      <description><![CDATA[A preview of the major H2 2026 security events — Black Hat USA, DEF CON 34, USENIX Security — and the agentic AI security and supply chain themes that will dominate the agendas.]]></description>
      <link>https://safeguard.sh/resources/blog/h2-2026-cybersecurity-conference-calendar</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/h2-2026-cybersecurity-conference-calendar</guid>
      <pubDate>Fri, 19 Jun 2026 13:00:00 GMT</pubDate>
      <category>Industry Events</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[OpenRouter API Security: Using the Unified LLM Gateway Safely]]></title>
      <description><![CDATA[The OpenRouter API routes your prompts through one endpoint to many model providers. Convenient, but it changes where your data goes and where your keys live.]]></description>
      <link>https://safeguard.sh/resources/blog/openrouter-api</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openrouter-api</guid>
      <pubDate>Fri, 19 Jun 2026 11:47:08 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[spring-expression Security: SpEL Risks and How to Contain Them]]></title>
      <description><![CDATA[What the spring-expression library does, the SpEL vulnerability classes it introduces, the 2026 SpEL CVEs, and how to evaluate expressions without opening an RCE or DoS hole.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-expression</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-expression</guid>
      <pubDate>Fri, 19 Jun 2026 10:26:41 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[GCP IAM security best practices]]></title>
      <description><![CDATA[GCP IAM misconfigurations, not exploits, cause most cloud breaches. Here is how to enforce least privilege, lock down service accounts, and audit access.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-iam-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-iam-security-best-practices</guid>
      <pubDate>Fri, 19 Jun 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Scanning Docker Images for Vulnerabilities: How To]]></title>
      <description><![CDATA[Knowing how to scan Docker images for vulnerabilities before they ship is the difference between catching a known CVE in CI and finding it in an incident report.]]></description>
      <link>https://safeguard.sh/resources/blog/scanning-docker-images-for-vulnerabilities-how-to</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scanning-docker-images-for-vulnerabilities-how-to</guid>
      <pubDate>Fri, 19 Jun 2026 09:06:14 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Choosing a Container Security Scanner]]></title>
      <description><![CDATA[A practical checklist for choosing a container security scanner, covering base-image coverage, registry integration, runtime relevance, and how scan noise actually gets managed.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-scanner-selection-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-scanner-selection-guide</guid>
      <pubDate>Fri, 19 Jun 2026 07:45:48 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Scanning Terraform code for security misconfigurations]]></title>
      <description><![CDATA[Public S3 buckets, open security groups, and wildcard IAM policies are the recurring Terraform mistakes behind most cloud breaches — here's how to catch them before apply.]]></description>
      <link>https://safeguard.sh/resources/blog/scanning-terraform-code-for-security-misconfigurations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scanning-terraform-code-for-security-misconfigurations</guid>
      <pubDate>Fri, 19 Jun 2026 07:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is the HSTS Header and How Do You Configure It?]]></title>
      <description><![CDATA[The HSTS header forces browsers to talk to your site over HTTPS only. Here is what Strict-Transport-Security does, how to set it safely, and why scanners like Checkmarx flag it as missing.]]></description>
      <link>https://safeguard.sh/resources/blog/hsts-header</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hsts-header</guid>
      <pubDate>Fri, 19 Jun 2026 06:25:21 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[AI Code Security Tools: risks of restricting them]]></title>
      <description><![CDATA[Banning AI coding assistants doesn't remove the risk, it just removes visibility. Here's why restriction backfires and what actually secures AI-generated code.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-code-security-tools-risks-of-restricting-them</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-code-security-tools-risks-of-restricting-them</guid>
      <pubDate>Fri, 19 Jun 2026 06:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Security Testing Tools for Mobile Applications: What Actually Finds Bugs]]></title>
      <description><![CDATA[A practitioner's guide to the security testing tools for mobile applications that matter — SAST, DAST, dependency scanning, and runtime instrumentation — and how to combine them without drowning in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/security-testing-tools-for-mobile-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-testing-tools-for-mobile-applications</guid>
      <pubDate>Fri, 19 Jun 2026 05:04:54 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Terraform Cloud security integration guide]]></title>
      <description><![CDATA[A practical breakdown of Terraform Cloud security: state file exposure, Sentinel/OPA policy gaps, Run Tasks trust risks, and drift monitoring.]]></description>
      <link>https://safeguard.sh/resources/blog/terraform-cloud-security-integration-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/terraform-cloud-security-integration-guide</guid>
      <pubDate>Fri, 19 Jun 2026 04:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Secure Is js-cookie? A Practical Security Guide]]></title>
      <description><![CDATA[js-cookie is a tiny, popular cookie helper, but a 2026 attribute-injection flaw shows why the library needs the same scrutiny as any other dependency. Here is what to watch.]]></description>
      <link>https://safeguard.sh/resources/blog/js-cookie</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/js-cookie</guid>
      <pubDate>Fri, 19 Jun 2026 03:44:28 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Audit Preparation for AppSec programs]]></title>
      <description><![CDATA[Veracode scans your code, but auditors want proof: which artifact shipped, which SBOM covers it, who approved every exception. Here's what closes that gap.]]></description>
      <link>https://safeguard.sh/resources/blog/audit-preparation-for-appsec-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/audit-preparation-for-appsec-programs</guid>
      <pubDate>Fri, 19 Jun 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Encryption and Decryption in Python: A Practical Guide]]></title>
      <description><![CDATA[Encryption in Python is easy to get working and surprisingly easy to get wrong — here's how to do symmetric and asymmetric encryption correctly using the cryptography library instead of rolling your own.]]></description>
      <link>https://safeguard.sh/resources/blog/encryption-and-decryption-in-python-a-practical-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/encryption-and-decryption-in-python-a-practical-guide</guid>
      <pubDate>Fri, 19 Jun 2026 02:24:01 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2018-1285: XXE in Apache log4net]]></title>
      <description><![CDATA[CVE-2018-1285: Apache log4net before 2.0.10 fails to disable external XML entities, enabling XXE attacks via config files. Impact, fix, and detection.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2018-1285-xxe-in-apache-log4net</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2018-1285-xxe-in-apache-log4net</guid>
      <pubDate>Fri, 19 Jun 2026 01:03:34 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Managing Terraform state file security risks]]></title>
      <description><![CDATA[Terraform state files store database passwords, IAM keys, and private keys in plaintext. Here's how they leak, why encryption alone won't save you, and how to lock them down.]]></description>
      <link>https://safeguard.sh/resources/blog/managing-terraform-state-file-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/managing-terraform-state-file-security-risks</guid>
      <pubDate>Fri, 19 Jun 2026 01:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Compliance overview (PCI DSS, HIPAA,...]]></title>
      <description><![CDATA[PCI DSS 4.0, GDPR, FedRAMP, SOC 2, ISO 27001, NIST 800-53, and DORA now demand application-layer evidence. Here is what each requires and where scanner-only tools fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-compliance-overview-pci-dss-hipaa-gdpr-fedramp-soc-2-iso-27001-nist-800-53-dora</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-compliance-overview-pci-dss-hipaa-gdpr-fedramp-soc-2-iso-27001-nist-800-53-dora</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[What is Secretless Authentication in CI/CD]]></title>
      <description><![CDATA[Secretless authentication replaces stored CI credentials with short-lived OIDC tokens minted per job. Here's the trust-policy plumbing, provider support, and the pitfalls.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-secretless-authentication-in-ci-cd</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-secretless-authentication-in-ci-cd</guid>
      <pubDate>Thu, 18 Jun 2026 23:43:08 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Docker Privileged Mode: What It Unlocks and Why to Avoid It]]></title>
      <description><![CDATA[One flag, --privileged, hands a container almost the same power as root on the host. Here is exactly what it turns on, why it breaks isolation, and the narrow capabilities that replace it.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-privileged-mode-risks-alternatives</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-privileged-mode-risks-alternatives</guid>
      <pubDate>Thu, 18 Jun 2026 22:22:41 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-29652: Denial of service in golang.org/x/crypto/...]]></title>
      <description><![CDATA[A pre-auth nil pointer dereference in golang.org/x/crypto/ssh let a single crafted request crash Go SSH servers. Here's the impact, fix, and remediation path.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-29652-denial-of-service-in-golangorgxcryptossh-nil-pointer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-29652-denial-of-service-in-golangorgxcryptossh-nil-pointer</guid>
      <pubDate>Thu, 18 Jun 2026 21:02:14 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-43565: Denial of service in golang.org/x/crypto/...]]></title>
      <description><![CDATA[A crafted SSH packet could crash Go services using golang.org/x/crypto/ssh before the December 2021 fix. What's affected, the severity context, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-43565-denial-of-service-in-golangorgxcryptossh-packet-handling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-43565-denial-of-service-in-golangorgxcryptossh-packet-handling</guid>
      <pubDate>Thu, 18 Jun 2026 19:41:47 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx Pricing: What It Costs and How the Model Works]]></title>
      <description><![CDATA[Checkmarx pricing is quote-based and not published publicly, driven by developer count, modules, and contract term. Here is what buyers actually report paying.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-pricing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-pricing</guid>
      <pubDate>Thu, 18 Jun 2026 18:21:21 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Write an Application Security Policy Teams Actually Follow]]></title>
      <description><![CDATA[An application security policy only works if engineers can act on it. Here's how to write one that sets clear requirements, maps to real controls, and does not become shelfware.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-policy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-policy</guid>
      <pubDate>Thu, 18 Jun 2026 17:00:54 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The HIPAA Security Rule Update and Your Supply Chain]]></title>
      <description><![CDATA[HHS's December 2024 NPRM rewrites the HIPAA Security Rule with explicit software supply chain, SBOM, and business associate controls set to take effect in 2025 and 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-security-rule-update-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-security-rule-update-supply-chain</guid>
      <pubDate>Thu, 18 Jun 2026 15:40:27 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CMMC 32 CFR Part 170: The Program Rule and the Four Phases]]></title>
      <description><![CDATA[DoD's CMMC program rule became effective December 16, 2024 with a four-phase rollout running through November 2028. The companion DFARS rule landed September 10, 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-final-rule-32-cfr-170</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-final-rule-32-cfr-170</guid>
      <pubDate>Thu, 18 Jun 2026 14:20:01 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Hacker Summer Camp 2026 Survival Guide: OPSEC for Black Hat, DEF CON 34 and BSides]]></title>
      <description><![CDATA[A practical, opinionated field guide to surviving Hacker Summer Camp in Las Vegas this August — device hygiene, network OPSEC, talk selection, and pacing — with a preview of the AI agent and supply chain themes likely to dominate the floor.]]></description>
      <link>https://safeguard.sh/resources/blog/hacker-summer-camp-2026-survival-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hacker-summer-camp-2026-survival-guide</guid>
      <pubDate>Thu, 18 Jun 2026 13:00:00 GMT</pubDate>
      <category>Industry Events</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Cost-Per-Verified-Finding: How Agentic AI Breaks Vulnerability Triage]]></title>
      <description><![CDATA[Agentic AI can generate findings faster than any team can read them. The metric that survives that flood isn't cost-per-finding, it's cost-per-verified-finding. Here's why verification is now the bottleneck.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-triage-cost-per-verified-finding</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-triage-cost-per-verified-finding</guid>
      <pubDate>Thu, 18 Jun 2026 13:00:00 GMT</pubDate>
      <category>Strategy</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AI Agent Memory: Security Risks]]></title>
      <description><![CDATA[Persistent memory makes AI agents more useful and more dangerous. A security engineer's walkthrough of how agent memory gets poisoned, exfiltrated, and weaponised, with concrete 2025 examples.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-agent-memory-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-agent-memory-security-risks</guid>
      <pubDate>Thu, 18 Jun 2026 12:59:34 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AI Chip Security: What Accelerators Mean for Your Threat Model]]></title>
      <description><![CDATA[An AI chip is specialized hardware for running machine learning workloads, and it brings its own security concerns from supply chain to firmware. Here is what matters.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-chip</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-chip</guid>
      <pubDate>Thu, 18 Jun 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[pdf-lib npm: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[pdf-lib is a popular pure-JavaScript library for creating and editing PDFs, with no known direct vulnerabilities but an inactive maintenance status worth planning around.]]></description>
      <link>https://safeguard.sh/resources/blog/pdf-lib-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pdf-lib-npm</guid>
      <pubDate>Thu, 18 Jun 2026 11:39:07 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm Hack: How Supply Chain Attacks Work and How to Stay Safe]]></title>
      <description><![CDATA[An npm hack rarely means npm itself was breached. It usually means a maintainer account was phished or a package was hijacked. Here is how these attacks unfold and how to defend your builds.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-hack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-hack</guid>
      <pubDate>Thu, 18 Jun 2026 10:18:41 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Detecting drift between IaC and live cloud infrastructure]]></title>
      <description><![CDATA[IaC and live cloud state drift apart within days of every deploy. Here's how drift detection actually works, why it matters, and how to close the gap fast.]]></description>
      <link>https://safeguard.sh/resources/blog/detecting-drift-between-iac-and-live-cloud-infrastructure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/detecting-drift-between-iac-and-live-cloud-infrastructure</guid>
      <pubDate>Thu, 18 Jun 2026 10:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Achieving PCI DSS compliance through AppSec testing]]></title>
      <description><![CDATA[PCI DSS 4.0 made application security testing mandatory, not optional. Here's what auditors check, where scanner-only programs fail, and how to close the gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/achieving-pci-dss-compliance-through-appsec-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/achieving-pci-dss-compliance-through-appsec-testing</guid>
      <pubDate>Thu, 18 Jun 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Broken Access Control Examples: Real Cases and How to Fix Them]]></title>
      <description><![CDATA[Broken access control is the number-one web risk on the OWASP Top 10. These examples show what it looks like in real code and how to close each gap.]]></description>
      <link>https://safeguard.sh/resources/blog/broken-access-control-examples</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/broken-access-control-examples</guid>
      <pubDate>Thu, 18 Jun 2026 08:58:14 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Attack News Today: What to Watch For]]></title>
      <description><![CDATA[Software supply chain attack news today keeps pointing at the same target: open source package registries like npm and PyPI. Here is what the recent wave of attacks looks like and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-attack-news-today</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-attack-news-today</guid>
      <pubDate>Thu, 18 Jun 2026 08:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Security Vulnerabilities: The Ones That Actually Bite]]></title>
      <description><![CDATA[JavaScript security vulnerabilities cluster around a few patterns: XSS, prototype pollution, ReDoS, and dependency risk. Here is how each works and how to catch it.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-security-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-security-vulnerabilities</guid>
      <pubDate>Thu, 18 Jun 2026 07:37:47 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Scanning AWS CloudFormation templates for misconfigurations]]></title>
      <description><![CDATA[CloudFormation deploys exactly what you write, misconfigurations included. Here's how scanning catches IAM, S3, and security group errors before they ship.]]></description>
      <link>https://safeguard.sh/resources/blog/scanning-aws-cloudformation-templates-for-misconfigurations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scanning-aws-cloudformation-templates-for-misconfigurations</guid>
      <pubDate>Thu, 18 Jun 2026 07:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[A DevSecOps Checklist That Actually Works in Production]]></title>
      <description><![CDATA[A practical DevSecOps checklist organized by pipeline stage, from pre-commit to runtime, with the controls that matter and the ones that just generate noise.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-checklist</guid>
      <pubDate>Thu, 18 Jun 2026 06:17:21 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA application security validation testing]]></title>
      <description><![CDATA[A 2025 HHS rule proposes fixed testing cadences for HIPAA. Heres what security testing requirements demand now, and how Safeguard closes the gaps Veracode leaves.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-application-security-validation-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-application-security-validation-testing</guid>
      <pubDate>Thu, 18 Jun 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[SCA vs Static Code Analysis: The Real Difference]]></title>
      <description><![CDATA[Software composition analysis and static code analysis get lumped together constantly, but they read entirely different things and catch entirely different bugs.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-vs-static-code-analysis-the-real-difference</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-vs-static-code-analysis-the-real-difference</guid>
      <pubDate>Thu, 18 Jun 2026 04:56:54 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Introduction to Open Policy Agent and Rego]]></title>
      <description><![CDATA[A concrete walkthrough of Open Policy Agent and Rego — how OPA evaluates decisions, a runnable policy example, and where it fits in supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/introduction-to-open-policy-agent-and-rego</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/introduction-to-open-policy-agent-and-rego</guid>
      <pubDate>Thu, 18 Jun 2026 04:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Snyk in Cybersecurity: Where It Fits in a Modern AppSec Program]]></title>
      <description><![CDATA[How Snyk fits into a cybersecurity program: what its developer-first SCA, SAST, container, and IaC tools cover, and what they leave for other controls.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-cybersecurity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-cybersecurity</guid>
      <pubDate>Thu, 18 Jun 2026 03:36:27 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP Moderate authorization and AppSec controls]]></title>
      <description><![CDATA[Veracode's FedRAMP Moderate authorization is a procurement accelerant, not proof of AppSec efficacy. Here's what the badge covers, what it doesn't, and what federal buyers should verify.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-moderate-authorization-and-appsec-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-moderate-authorization-and-appsec-controls</guid>
      <pubDate>Thu, 18 Jun 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[What react-native-get-random-values Does and Why Your App Needs It]]></title>
      <description><![CDATA[The react-native-get-random-values package polyfills crypto.getRandomValues so libraries like uuid work under React Native's Hermes engine. Here is how to install it correctly and use it securely.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-get-random-values</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-get-random-values</guid>
      <pubDate>Thu, 18 Jun 2026 02:16:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Policy as code for cloud security guardrails]]></title>
      <description><![CDATA[Policy as code turns cloud security guardrails into version-controlled, testable rules enforced automatically across IaC, Kubernetes, and CI/CD pipelines.]]></description>
      <link>https://safeguard.sh/resources/blog/policy-as-code-for-cloud-security-guardrails</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/policy-as-code-for-cloud-security-guardrails</guid>
      <pubDate>Thu, 18 Jun 2026 01:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[How an API Security Scanner Works and What to Use]]></title>
      <description><![CDATA[An API security scanner automatically probes your endpoints for authentication, authorization, and injection flaws. Here is how they work and how to fit one into your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-scanner</guid>
      <pubDate>Thu, 18 Jun 2026 00:55:34 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[DORA (Digital Operational Resilience Act) and code-level ...]]></title>
      <description><![CDATA[DORA turns code-level and open-source risk into a regulatory obligation. Here's what dora compliance software security actually requires, and where tools like Veracode fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-digital-operational-resilience-act-and-code-level-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-digital-operational-resilience-act-and-code-level-risk</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[@angular-builders/custom-webpack: Extending Angular Builds Without Ejecting]]></title>
      <description><![CDATA[The @angular-builders/custom-webpack package lets you merge custom webpack config into Angular CLI builds. Here is how it works and how to use it without adding risk.]]></description>
      <link>https://safeguard.sh/resources/blog/angular-builders-custom-webpack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/angular-builders-custom-webpack</guid>
      <pubDate>Wed, 17 Jun 2026 23:35:07 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Change Java Versions on a Mac: jenv, SDKMAN, and JAVA_HOME]]></title>
      <description><![CDATA[Three reliable ways to change Java version on a Mac — plain JAVA_HOME switching, jenv shims, and SDKMAN — with per-project pinning so builds stop depending on whatever your shell happens to export.]]></description>
      <link>https://safeguard.sh/resources/blog/switch-java-versions-mac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/switch-java-versions-mac</guid>
      <pubDate>Wed, 17 Jun 2026 22:14:40 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code's semantic analysis engine builds a code mo...]]></title>
      <description><![CDATA[A mechanical look at how Snyk Code's semantic analysis engine parses source into a code model, tracks data flow across files, and prioritizes vulnerability findings.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-codes-semantic-analysis-engine-builds-a-code-model-to-detect-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-codes-semantic-analysis-engine-builds-a-code-model-to-detect-vulnerabilities</guid>
      <pubDate>Wed, 17 Jun 2026 20:54:14 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Securing GitHub Actions Reusable Workflows at Scale]]></title>
      <description><![CDATA[Reusable workflows centralize CI logic — and centralize compromise. Pinning, secrets scoping, org policy, and the review process that keeps one bad merge from owning 400 repos.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-github-actions-reusable-workflows-at-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-github-actions-reusable-workflows-at-scale</guid>
      <pubDate>Wed, 17 Jun 2026 19:33:47 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Sofia Marchetti)</author>
    </item>
    <item>
      <title><![CDATA[Inside DeepCode AI: how Snyk Code's ML models are trained...]]></title>
      <description><![CDATA[How Snyk's DeepCode AI turns millions of open-source commit fixes into the symbolic-AI and ML models powering Snyk Code's vulnerability detection and autofixes.]]></description>
      <link>https://safeguard.sh/resources/blog/inside-deepcode-ai-how-snyk-codes-ml-models-are-trained-on-open-source-commit-history</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/inside-deepcode-ai-how-snyk-codes-ml-models-are-trained-on-open-source-commit-history</guid>
      <pubDate>Wed, 17 Jun 2026 18:13:20 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How taint analysis works in Snyk Code: tracking data from...]]></title>
      <description><![CDATA[Snyk Code traces untrusted data from source to sink using interprocedural static analysis and ML ranking. Here's how the taint-tracking mechanics work.]]></description>
      <link>https://safeguard.sh/resources/blog/how-taint-analysis-works-in-snyk-code-tracking-data-from-source-to-sink</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-taint-analysis-works-in-snyk-code-tracking-data-from-source-to-sink</guid>
      <pubDate>Wed, 17 Jun 2026 16:52:54 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code performs interprocedural data-flow analysis...]]></title>
      <description><![CDATA[How Snyk Code tracks tainted data across function and file boundaries using call-graph summaries, taint propagation, and hybrid symbolic AI rules.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-code-performs-interprocedural-data-flow-analysis-across-function-boundaries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-code-performs-interprocedural-data-flow-analysis-across-function-boundaries</guid>
      <pubDate>Wed, 17 Jun 2026 15:32:27 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code models control flow to catch race condition...]]></title>
      <description><![CDATA[A mechanical look at how Snyk Code builds control flow and data flow graphs to trace paths that produce race conditions and null pointer dereferences.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-code-models-control-flow-to-catch-race-conditions-and-null-dereferences</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-code-models-control-flow-to-catch-race-conditions-and-null-dereferences</guid>
      <pubDate>Wed, 17 Jun 2026 14:12:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Black Hat Arsenal 2026 Preview: The Agentic AI and Supply-Chain Tools to Watch]]></title>
      <description><![CDATA[Black Hat USA 2026 runs August 1–6 at Mandalay Bay, with Arsenal August 4–6. Here is an honest preview of the open-source tool categories worth your time — and how to tell signal from demo-day hype.]]></description>
      <link>https://safeguard.sh/resources/blog/black-hat-arsenal-2026-preview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/black-hat-arsenal-2026-preview</guid>
      <pubDate>Wed, 17 Jun 2026 13:00:00 GMT</pubDate>
      <category>Industry Events</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The Klue Breach: One Legacy Credential Turned Into a SaaS Supply Chain Attack on Salesforce and Gong]]></title>
      <description><![CDATA[Attackers used a disused legacy credential at marketing-intelligence vendor Klue to push code that harvested customer OAuth tokens, then walked into Salesforce and Gong instances. A textbook SaaS-to-SaaS supply chain pivot.]]></description>
      <link>https://safeguard.sh/resources/blog/klue-breach-oauth-salesforce-gong</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/klue-breach-oauth-salesforce-gong</guid>
      <pubDate>Wed, 17 Jun 2026 13:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Edge Appliances Are the Soft Underbelly: VPN Zero-Days as Initial Access in 2026]]></title>
      <description><![CDATA[Check Point's CVE-2026-50751 and Cisco's seventh SD-WAN zero-day of the year are not isolated bugs — they are the same story. Here is why VPN and edge appliances keep becoming the front door for ransomware, and how to monitor and segment them.]]></description>
      <link>https://safeguard.sh/resources/blog/vpn-edge-appliance-zero-days-initial-access</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vpn-edge-appliance-zero-days-initial-access</guid>
      <pubDate>Wed, 17 Jun 2026 13:00:00 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code distinguishes sanitizers from insecure sour...]]></title>
      <description><![CDATA[How Snyk Code's taint-tracking engine tells sanitizers apart from insecure sources and sinks, and where the source-sink-sanitizer model still needs human review.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-code-distinguishes-sanitizers-from-insecure-sources-during-taint-tracking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-code-distinguishes-sanitizers-from-insecure-sources-during-taint-tracking</guid>
      <pubDate>Wed, 17 Jun 2026 12:51:34 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Why Snyk Code's semantic approach produces fewer false po...]]></title>
      <description><![CDATA[Snyk Code cuts SAST false positives using semantic analysis: AST/data-flow graphs plus ML trained on real code, not regex patterns. Here is how the mechanics work.]]></description>
      <link>https://safeguard.sh/resources/blog/why-snyk-codes-semantic-approach-produces-fewer-false-positives-than-pattern-matching-sast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-snyk-codes-semantic-approach-produces-fewer-false-positives-than-pattern-matching-sast</guid>
      <pubDate>Wed, 17 Jun 2026 11:31:07 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code detects SQL injection vulnerabilities step ...]]></title>
      <description><![CDATA[A mechanical, publicly-documented look at how Snyk Code's symbolic analysis and ML model trace source-to-sink data flow to detect SQL injection vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-code-detects-sql-injection-vulnerabilities-step-by-step</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-code-detects-sql-injection-vulnerabilities-step-by-step</guid>
      <pubDate>Wed, 17 Jun 2026 10:10:40 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Application Security for the Public Sector: What's Different]]></title>
      <description><![CDATA[Application security for public sector agencies runs under FedRAMP, StateRAMP, and Executive Order 14028 SBOM mandates that private-sector programs rarely have to satisfy on the same timeline.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-for-the-public-sector</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-for-the-public-sector</guid>
      <pubDate>Wed, 17 Jun 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Pulumi security scanning best practices]]></title>
      <description><![CDATA[Pulumi programs run as real code with live cloud credentials -- here's how to secure state files, dependencies, CrossGuard policy, and CI/CD.]]></description>
      <link>https://safeguard.sh/resources/blog/pulumi-security-scanning-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pulumi-security-scanning-best-practices</guid>
      <pubDate>Wed, 17 Jun 2026 10:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Code Language Support in 2026: Full Matrix and Gaps]]></title>
      <description><![CDATA[Snyk Code language support in 2026 spans 18 languages, but several sit in Early Access behind Enterprise plans. The full matrix, the gaps, and how to verify your stack.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-code-language-support-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-code-language-support-2026</guid>
      <pubDate>Wed, 17 Jun 2026 09:30:00 GMT</pubDate>
      <category>Industry</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001/27002 mapping for application security controls]]></title>
      <description><![CDATA[ISO 27001:2022 maps 10+ Annex A controls directly to secure development. Here's how to evidence them, and where SAST-only tools like Veracode fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-2700127002-mapping-for-application-security-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-2700127002-mapping-for-application-security-controls</guid>
      <pubDate>Wed, 17 Jun 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[GPAI Code of Practice: The 2025 Signatory Landscape]]></title>
      <description><![CDATA[The General-Purpose AI Code of Practice was published on 10 July 2025 with three chapters. Most major providers signed, with notable partial signatures from xAI.]]></description>
      <link>https://safeguard.sh/resources/blog/gpai-code-of-practice-signatory-landscape-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gpai-code-of-practice-signatory-landscape-2025</guid>
      <pubDate>Wed, 17 Jun 2026 08:50:13 GMT</pubDate>
      <category>Policy</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Gemini 2.5 Pro and the Late Safety Report]]></title>
      <description><![CDATA[Google released Gemini 2.5 Pro Experimental on March 25, 2025 without a contemporaneous safety report. The UK reaction set a precedent.]]></description>
      <link>https://safeguard.sh/resources/blog/gemini-2-5-pro-safety-disclosure-controversy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gemini-2-5-pro-safety-disclosure-controversy</guid>
      <pubDate>Wed, 17 Jun 2026 07:29:47 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Ansible playbook security scanning]]></title>
      <description><![CDATA[Hardcoded secrets, unrestricted become, and injection-prone shell tasks turn Ansible playbooks into a single point of compromise across every host they touch.]]></description>
      <link>https://safeguard.sh/resources/blog/ansible-playbook-security-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ansible-playbook-security-scanning</guid>
      <pubDate>Wed, 17 Jun 2026 07:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-9086 in cURL: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[Heap out-of-bounds read in libcurl's cookie path comparison affects nearly every Linux distro. Defender SBOM playbook below.]]></description>
      <link>https://safeguard.sh/resources/blog/curl-cve-2025-9086-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/curl-cve-2025-9086-patch-response</guid>
      <pubDate>Wed, 17 Jun 2026 06:09:20 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[NIST SP 800-53 control mapping for AppSec]]></title>
      <description><![CDATA[How NIST SP 800-53's SA, RA, and SR control families map to modern AppSec — and where legacy scanners like Veracode leave supply-chain evidence gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-sp-800-53-control-mapping-for-appsec</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-sp-800-53-control-mapping-for-appsec</guid>
      <pubDate>Wed, 17 Jun 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code detects cross-site scripting (XSS) through ...]]></title>
      <description><![CDATA[How Snyk Code's taint analysis traces untrusted input from source to sink to flag reflected, DOM-based, and stored XSS with fewer false positives.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-code-detects-cross-site-scripting-xss-through-data-flow-modeling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-code-detects-cross-site-scripting-xss-through-data-flow-modeling</guid>
      <pubDate>Wed, 17 Jun 2026 04:48:53 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Security Posture Management (CSPM) explained]]></title>
      <description><![CDATA[CSPM explained: what it checks, why Gartner created the category in 2019, how it differs from CWPP/CNAPP, and why raw findings alone don't stop breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-security-posture-management-cspm-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-security-posture-management-cspm-explained</guid>
      <pubDate>Wed, 17 Jun 2026 04:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[spring-security-core: A Practical Security Guide]]></title>
      <description><![CDATA[The spring-security-core artifact is the foundation of Spring Security, providing authentication and authorization primitives. Here is how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-security-core</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-security-core</guid>
      <pubDate>Wed, 17 Jun 2026 03:28:27 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 Type II reporting for AppSec vendors and buyers]]></title>
      <description><![CDATA[A SOC 2 Type II badge isn't enough due diligence for AppSec vendors. Here's what to actually check in the report—scope, exceptions, and subservice carve-outs—before you trust one.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-type-ii-reporting-for-appsec-vendors-and-buyers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-type-ii-reporting-for-appsec-vendors-and-buyers</guid>
      <pubDate>Wed, 17 Jun 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code identifies hardcoded secrets and credential...]]></title>
      <description><![CDATA[A technical look at how Snyk Code's static analysis engine detects hardcoded API keys, tokens, and credentials in source code — and where source-code scanning alone falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-code-identifies-hardcoded-secrets-and-credentials-in-source-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-code-identifies-hardcoded-secrets-and-credentials-in-source-code</guid>
      <pubDate>Wed, 17 Jun 2026 02:08:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cloud misconfiguration as the top cause of cloud breaches]]></title>
      <description><![CDATA[Capital One, Toyota, and a single Azure endpoint that leaked 65,000 companies' data all trace back to one root cause: cloud misconfiguration.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-misconfiguration-as-the-top-cause-of-cloud-breaches</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-misconfiguration-as-the-top-cause-of-cloud-breaches</guid>
      <pubDate>Wed, 17 Jun 2026 01:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code's security rule sets are structured and ver...]]></title>
      <description><![CDATA[A technical look at how Snyk Code structures, scores, and versions its SAST rules — from the DeepCode AI engine to CWE mapping and custom rule bundles.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-codes-security-rule-sets-are-structured-and-versioned</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-codes-security-rule-sets-are-structured-and-versioned</guid>
      <pubDate>Wed, 17 Jun 2026 00:47:33 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Why a Customer Trust Center matters for vendor risk reviews]]></title>
      <description><![CDATA[Vendor security reviews stall without a live trust center. See what appsec teams check, how Veracode approaches transparency, and how Safeguard's trust center speeds reviews.]]></description>
      <link>https://safeguard.sh/resources/blog/why-a-customer-trust-center-matters-for-vendor-risk-reviews</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-a-customer-trust-center-matters-for-vendor-risk-reviews</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code scans multi-language monorepos in a single ...]]></title>
      <description><![CDATA[Snyk Code scans multi-language monorepos in a single pass by parsing source files directly into a shared internal representation, no build step required.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-code-scans-multi-language-monorepos-in-a-single-pass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-code-scans-multi-language-monorepos-in-a-single-pass</guid>
      <pubDate>Tue, 16 Jun 2026 23:27:07 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Hacking Explained: Attack Classes and Defenses]]></title>
      <description><![CDATA[JavaScript hacking is less about breaking the language and more about abusing how apps handle untrusted input. Here are the main attack classes and how to defend against each.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-hacking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-hacking</guid>
      <pubDate>Tue, 16 Jun 2026 22:06:40 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Licence Compliance: A Security and Legal Guide]]></title>
      <description><![CDATA[An open source licence is not just a legal footnote — it dictates what you can ship, and getting the obligations wrong creates real risk. Here is how to read them.]]></description>
      <link>https://safeguard.sh/resources/blog/licence-open-source</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/licence-open-source</guid>
      <pubDate>Tue, 16 Jun 2026 20:46:13 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Examples: What a Real Software Bill of Materials Looks Like]]></title>
      <description><![CDATA[Concrete SBOM examples in both SPDX and CycloneDX, showing what fields actually go in a software bill of materials and how the two formats differ in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-examples</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-examples</guid>
      <pubDate>Tue, 16 Jun 2026 19:25:47 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Strategies: A Free Guide (No PDF Download Needed)]]></title>
      <description><![CDATA[Looking for a SQL injection strategies PDF free download? Here is the defensive material that actually matters, covering how the attack works and how to shut it down.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-strategies-pdf-free-download</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-strategies-pdf-free-download</guid>
      <pubDate>Tue, 16 Jun 2026 18:05:20 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Status: How to Check if Snyk Is Down and What to Do About It]]></title>
      <description><![CDATA[The Snyk status page at status.snyk.io tells you whether the platform, its scanners, and integrations are healthy. Here is how to read it and how to keep a Snyk outage from breaking your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-status</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-status</guid>
      <pubDate>Tue, 16 Jun 2026 16:44:53 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[React Diff Viewer: Is the npm Package Still Safe to Use?]]></title>
      <description><![CDATA[The original react-diff-viewer has not shipped a release in years. Here is what that means for security and why most teams should move to the maintained fork.]]></description>
      <link>https://safeguard.sh/resources/blog/react-diff-viewer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-diff-viewer</guid>
      <pubDate>Tue, 16 Jun 2026 15:24:26 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[MIT License Adalah: What It Means and Its Security Implications]]></title>
      <description><![CDATA[MIT License adalah salah satu lisensi open source paling permisif — it lets anyone use, modify, and sell the code as long as they keep the copyright notice. Here is what that permissiveness means for security and compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/mit-license-adalah</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mit-license-adalah</guid>
      <pubDate>Tue, 16 Jun 2026 14:04:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[DEF CON 34 Preview: Agentic AI Security Takes Center Stage at Hacker Summer Camp]]></title>
      <description><![CDATA[DEF CON 34 lands in Las Vegas August 6-9, 2026 under the theme 'Agency' — a deliberate nod to agentic AI. Here is what to watch, why it matters, and how to prepare before you board the plane.]]></description>
      <link>https://safeguard.sh/resources/blog/def-con-34-preview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/def-con-34-preview</guid>
      <pubDate>Tue, 16 Jun 2026 13:00:00 GMT</pubDate>
      <category>Industry Events</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[eBPF Rootkits Go Mainstream: Inside IronWorm and the Kernel-Level Turn in Supply Chain Malware]]></title>
      <description><![CDATA[IronWorm shipped a kernel-level eBPF rootkit inside dozens of npm packages, hiding the very processes your security tools rely on seeing. Here is what changed, and how to detect kernel-level supply chain malware before it blinds you.]]></description>
      <link>https://safeguard.sh/resources/blog/ebpf-rootkits-supply-chain-malware</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ebpf-rootkits-supply-chain-malware</guid>
      <pubDate>Tue, 16 Jun 2026 13:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Exploits Explained: How They Work and How to Stop Them]]></title>
      <description><![CDATA[JavaScript exploits target the code that runs in browsers and on Node servers. Here is how the main attack classes work and the defenses that actually hold up.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-exploits</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-exploits</guid>
      <pubDate>Tue, 16 Jun 2026 12:43:33 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[App Vulnerability Scanner: How It Works and What to Use]]></title>
      <description><![CDATA[An app vulnerability scanner automatically probes your application for known flaws and misconfigurations. Here is how the main types work and how to pick the right one.]]></description>
      <link>https://safeguard.sh/resources/blog/app-vulnerability-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/app-vulnerability-scanner</guid>
      <pubDate>Tue, 16 Jun 2026 11:23:06 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What triggers a Snyk Code scan in the IDE: save, open, an...]]></title>
      <description><![CDATA[A mechanical breakdown of when Snyk Code scans fire in the IDE — on open, on save, and on manual command — and how each trigger affects scan scope and speed.]]></description>
      <link>https://safeguard.sh/resources/blog/what-triggers-a-snyk-code-scan-in-the-ide-save-open-and-manual-triggers-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-triggers-a-snyk-code-scan-in-the-ide-save-open-and-manual-triggers-explained</guid>
      <pubDate>Tue, 16 Jun 2026 10:02:40 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Securing Infrastructure as Code in GitOps workflows]]></title>
      <description><![CDATA[GitOps auto-applies every merged Terraform and Kubernetes change within minutes. Here's how CVE-2022-24348 and CVE-2025-30066 show why PR-time IaC checks are non-negotiable.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-infrastructure-as-code-in-gitops-workflows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-infrastructure-as-code-in-gitops-workflows</guid>
      <pubDate>Tue, 16 Jun 2026 10:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[AWS Application Security: A Practical Guide to Locking Down Your Workloads]]></title>
      <description><![CDATA[AWS application security is a shared responsibility, and most incidents come from the customer side of that line. Here is a practical guide to the controls that actually prevent them.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-application-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-application-security</guid>
      <pubDate>Tue, 16 Jun 2026 08:42:13 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Nginx Version Vulnerabilities: CVE Guide from 1.10 to 1.24]]></title>
      <description><![CDATA[From the nginx 1.18.0 vulnerability set back to 1.10.3 and forward to 1.24.0: which CVEs actually apply to each version line, which need specific config to exploit, and where to upgrade.]]></description>
      <link>https://safeguard.sh/resources/blog/nginx-version-vulnerabilities-cve-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nginx-version-vulnerabilities-cve-guide</guid>
      <pubDate>Tue, 16 Jun 2026 07:21:46 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Applying CIS Benchmarks to cloud infrastructure]]></title>
      <description><![CDATA[CIS Benchmarks turn "be secure" into testable checks for AWS, Azure, and GCP — here's how to move from annual audit to continuous enforcement.]]></description>
      <link>https://safeguard.sh/resources/blog/applying-cis-benchmarks-to-cloud-infrastructure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/applying-cis-benchmarks-to-cloud-infrastructure</guid>
      <pubDate>Tue, 16 Jun 2026 07:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code's PR and MR checks block merges on newly in...]]></title>
      <description><![CDATA[A mechanical look at how Snyk Code's pull and merge request checks isolate net-new vulnerabilities from pre-existing debt and gate merges on policy.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-codes-pr-and-mr-checks-block-merges-on-newly-introduced-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-codes-pr-and-mr-checks-block-merges-on-newly-introduced-vulnerabilities</guid>
      <pubDate>Tue, 16 Jun 2026 06:01:20 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Breaking free from alert fatigue in AppSec]]></title>
      <description><![CDATA[Veracode-style scanners flood AppSec teams with thousands of unranked alerts. Here's why appsec alert fatigue happens, what it costs, and how reachability-based triage fixes it.]]></description>
      <link>https://safeguard.sh/resources/blog/breaking-free-from-alert-fatigue-in-appsec</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/breaking-free-from-alert-fatigue-in-appsec</guid>
      <pubDate>Tue, 16 Jun 2026 06:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code visualizes a vulnerability's data-flow path...]]></title>
      <description><![CDATA[A mechanical look at how Snyk Code traces and visualizes a vulnerability's taint path from source to sink, step by step, inside its developer UI.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-code-visualizes-a-vulnerabilitys-data-flow-path-in-its-ui</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-code-visualizes-a-vulnerabilitys-data-flow-path-in-its-ui</guid>
      <pubDate>Tue, 16 Jun 2026 04:40:53 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Securing AWS Lambda functions]]></title>
      <description><![CDATA[A practical guide to AWS Lambda security best practices: IAM scoping, dependency risk, secrets handling, and runtime detection for serverless apps.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-aws-lambda-functions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-aws-lambda-functions</guid>
      <pubDate>Tue, 16 Jun 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code differentiates Security issues from Code Qu...]]></title>
      <description><![CDATA[Snyk Code splits every finding into a security vulnerability or a code quality issue. Here's how that classification actually works under the hood, and why the split matters for triage.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-code-differentiates-security-issues-from-code-quality-issues</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-code-differentiates-security-issues-from-code-quality-issues</guid>
      <pubDate>Tue, 16 Jun 2026 03:20:26 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Building Securely with AI (secure AI-assisted development)]]></title>
      <description><![CDATA[AI coding assistants ship code fast — Veracode found 45% of AI-generated code contains security flaws. Here's what secure AI-assisted development actually requires.]]></description>
      <link>https://safeguard.sh/resources/blog/building-securely-with-ai-secure-ai-assisted-development</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-securely-with-ai-secure-ai-assisted-development</guid>
      <pubDate>Tue, 16 Jun 2026 03:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Malware Meaning: What It Is and How It Spreads]]></title>
      <description><![CDATA[The meaning of malware is simple — any software written to harm, exploit, or gain unauthorized access — but the categories and delivery methods are worth knowing.]]></description>
      <link>https://safeguard.sh/resources/blog/malware-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malware-meaning</guid>
      <pubDate>Tue, 16 Jun 2026 02:00:00 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Azure DevOps pipeline security best practices]]></title>
      <description><![CDATA[A practical guide to the six Azure DevOps pipeline settings attackers exploit most, with exact controls to fix fork triggers, secrets, and agents.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-devops-pipeline-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-devops-pipeline-security-best-practices</guid>
      <pubDate>Tue, 16 Jun 2026 01:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Vector DB Security Considerations]]></title>
      <description><![CDATA[Vector stores hold derivatives of your most sensitive text. We cover the access, isolation, and integrity controls production deployments of Pinecone and Weaviate need.]]></description>
      <link>https://safeguard.sh/resources/blog/vector-db-security-considerations-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vector-db-security-considerations-2025</guid>
      <pubDate>Tue, 16 Jun 2026 00:39:33 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The hidden cost of surface-level code security]]></title>
      <description><![CDATA[Legacy SAST/SCA scanning piles up findings without context, quietly building code security debt whose hidden cost shows up in engineering hours, audits, and breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/the-hidden-cost-of-surface-level-code-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-hidden-cost-of-surface-level-code-security</guid>
      <pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Interoperability: Bridging CycloneDX and SPDX]]></title>
      <description><![CDATA[Your suppliers send SPDX. Your tools expect CycloneDX. Interoperability between SBOM formats is a real operational challenge. Here is how to solve it.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-interoperability-cyclonedx-spdx-bridge</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-interoperability-cyclonedx-spdx-bridge</guid>
      <pubDate>Mon, 15 Jun 2026 23:19:06 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Python itsdangerous: Signing Data Safely and Avoiding Key Leaks]]></title>
      <description><![CDATA[The Python itsdangerous library signs data so tampering is detectable. Getting it right depends on how you handle the secret key and key rotation.]]></description>
      <link>https://safeguard.sh/resources/blog/python-itsdangerous</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-itsdangerous</guid>
      <pubDate>Mon, 15 Jun 2026 21:58:39 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code suppressions and in-file ignore annotations...]]></title>
      <description><![CDATA[How Snyk Code's in-file ignore annotations and UI-based suppressions work mechanically, from fingerprinting to Consistent Ignores, and where governance gaps appear.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-code-suppressions-and-in-file-ignore-annotations-work</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-code-suppressions-and-in-file-ignore-annotations-work</guid>
      <pubDate>Mon, 15 Jun 2026 20:38:13 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code's incremental scanning speeds up repeated s...]]></title>
      <description><![CDATA[Snyk Code speeds up repeat SAST scans on large codebases by re-analyzing only changed files instead of the whole repository each time.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-codes-incremental-scanning-speeds-up-repeated-scans-on-large-codebases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-codes-incremental-scanning-speeds-up-repeated-scans-on-large-codebases</guid>
      <pubDate>Mon, 15 Jun 2026 19:17:46 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Agent Fix uses dynamic few-shot prompting to gen...]]></title>
      <description><![CDATA[How Snyk Agent Fix uses dynamic few-shot prompting and a 35,000-example database to generate, validate, and iteratively repair AI-generated code fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-agent-fix-uses-dynamic-few-shot-prompting-to-generate-code-fixes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-agent-fix-uses-dynamic-few-shot-prompting-to-generate-code-fixes</guid>
      <pubDate>Mon, 15 Jun 2026 17:57:19 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Agent Fix's agentic retry loop self-corrects fai...]]></title>
      <description><![CDATA[A technical look at how Snyk's Agent Fix uses a bounded, feedback-driven retry loop to validate and self-correct AI-generated vulnerability fixes before they reach a pull request.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-agent-fixs-agentic-retry-loop-self-corrects-failed-fix-attempts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-agent-fixs-agentic-retry-loop-self-corrects-failed-fix-attempts</guid>
      <pubDate>Mon, 15 Jun 2026 16:36:53 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[npm copyfiles: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[copyfiles is a tiny cross-platform file-copy CLI that a lot of build scripts rely on. Here is its security profile and how to use the npm copyfiles package carefully.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-copyfiles</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-copyfiles</guid>
      <pubDate>Mon, 15 Jun 2026 15:16:26 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[nginx 1.22.1 Vulnerabilities: What Actually Affects You]]></title>
      <description><![CDATA[Worried about nginx 1.22.1 vulnerabilities? Here is what genuinely affects this release, what does not, and how to decide whether you need to upgrade.]]></description>
      <link>https://safeguard.sh/resources/blog/nginx-1-22-1-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nginx-1-22-1-vulnerabilities</guid>
      <pubDate>Mon, 15 Jun 2026 13:55:59 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[AIBOM in 2026: Treating AI Models as a Software Supply Chain]]></title>
      <description><![CDATA[The AI bill of materials is graduating from optional security artifact to procurement requirement. Here is what AIBOM/ML-BOM actually tracks in 2026, how it ties to the EU AI Act, and where it still falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/aibom-tracking-models-as-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aibom-tracking-models-as-supply-chain-2026</guid>
      <pubDate>Mon, 15 Jun 2026 13:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Black Hat USA 2026 Preview: Agentic AI Security Takes Mandalay Bay]]></title>
      <description><![CDATA[A preview of Black Hat USA 2026 at Mandalay Bay, Aug 1-6. Why agentic AI security, the software supply chain, and post-quantum readiness are the threads to watch before the briefings begin.]]></description>
      <link>https://safeguard.sh/resources/blog/black-hat-usa-2026-preview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/black-hat-usa-2026-preview</guid>
      <pubDate>Mon, 15 Jun 2026 13:00:00 GMT</pubDate>
      <category>Industry Events</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Squidbleed (CVE-2026-47729): A 1997 Default Comes Back to Bite Squid]]></title>
      <description><![CDATA[A one-line FTP-parsing bug from 1997 lets any user of a shared Squid proxy read other people's cleartext HTTP requests. We break down the root cause, why ancient defaults survive, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/squid-squidbleed-cve-2026-47729</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/squid-squidbleed-cve-2026-47729</guid>
      <pubDate>Mon, 15 Jun 2026 13:00:00 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Capture the Flag in Cybersecurity: How CTFs Build Real Skills]]></title>
      <description><![CDATA[CTFs compress years of security intuition into weekends of deliberate practice. The main formats, what each one actually teaches, and how to start without getting demoralized.]]></description>
      <link>https://safeguard.sh/resources/blog/capture-the-flag-cybersecurity-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/capture-the-flag-cybersecurity-guide</guid>
      <pubDate>Mon, 15 Jun 2026 12:35:33 GMT</pubDate>
      <category>Culture</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SSRF Meaning: What Server-Side Request Forgery Is and How to Stop It]]></title>
      <description><![CDATA[SSRF stands for Server-Side Request Forgery, a vulnerability where an attacker tricks your server into making requests on their behalf. Here is what it means, why it is dangerous, and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/ssrf-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ssrf-meaning</guid>
      <pubDate>Mon, 15 Jun 2026 11:15:06 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Applying least privilege IAM in cloud-native environments]]></title>
      <description><![CDATA[Least privilege IAM fails in practice because permissions are granted for convenience and rarely revoked. Here's how to fix that at cloud scale.]]></description>
      <link>https://safeguard.sh/resources/blog/applying-least-privilege-iam-in-cloud-native-environments</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/applying-least-privilege-iam-in-cloud-native-environments</guid>
      <pubDate>Mon, 15 Jun 2026 10:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CNCF Supply Chain Security Best Practices v2: What Changed]]></title>
      <description><![CDATA[CNCF TAG Security shipped the v2 Supply Chain Security paper in 2025, mainstreaming SBOMs, signed attestations, and zero-trust workload identity. We walk through the practical guidance.]]></description>
      <link>https://safeguard.sh/resources/blog/cncf-supply-chain-security-paper-v2-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cncf-supply-chain-security-paper-v2-2025</guid>
      <pubDate>Mon, 15 Jun 2026 09:54:39 GMT</pubDate>
      <category>Industry</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Strategy for 2026: AI, DevSecOps, an...]]></title>
      <description><![CDATA[AppSec platform consolidation is reshaping 2026 strategy. See how it compares to Veracode's approach and where Safeguard fits in a unified DevSecOps stack.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-strategy-for-2026-ai-devsecops-and-platform-consolidation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-strategy-for-2026-ai-devsecops-and-platform-consolidation</guid>
      <pubDate>Mon, 15 Jun 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Black Duck and Synopsys: What the Spinoff Means for SCA]]></title>
      <description><![CDATA[Black Duck is now an independent company after splitting from Synopsys in 2024. Here is what changed, and what it means if you rely on it for SCA.]]></description>
      <link>https://safeguard.sh/resources/blog/blackduck-synopsys</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/blackduck-synopsys</guid>
      <pubDate>Mon, 15 Jun 2026 08:34:12 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[CodeQL 2.22 Security Query Pack Review]]></title>
      <description><![CDATA[GitHub's CodeQL 2.22.4 runs 478 security queries by default across 169 CWEs. We map the new queries added in 2025 and benchmark scan times on real repos.]]></description>
      <link>https://safeguard.sh/resources/blog/codeql-2-22-security-queries-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/codeql-2-22-security-queries-2025</guid>
      <pubDate>Mon, 15 Jun 2026 07:13:46 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Maya Reddy)</author>
    </item>
    <item>
      <title><![CDATA[Securing managed Kubernetes clusters with IaC scanning]]></title>
      <description><![CDATA[IaC scanning catches Kubernetes RBAC, network, and IAM misconfigurations in Terraform and Helm before they ever reach EKS, GKE, or AKS clusters.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-managed-kubernetes-clusters-with-iac-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-managed-kubernetes-clusters-with-iac-scanning</guid>
      <pubDate>Mon, 15 Jun 2026 07:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Reachability-based vulnerability prioritization (Polaris ...]]></title>
      <description><![CDATA[Reachability analysis cuts CVE noise by confirming which vulnerabilities are exploitable. Here's how Black Duck's Polaris reachability compares to Safeguard's pipeline-native approach.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-based-vulnerability-prioritization-polaris-reachability-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-based-vulnerability-prioritization-polaris-reachability-analysis</guid>
      <pubDate>Mon, 15 Jun 2026 06:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx DAST: What It Does and How It Fits an AppSec Program]]></title>
      <description><![CDATA[Checkmarx DAST is the dynamic testing component of the Checkmarx One platform, scanning running web apps and APIs for vulnerabilities. Here is how it works and where it fits.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-dast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-dast</guid>
      <pubDate>Mon, 15 Jun 2026 05:53:19 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[mobx-react-lite: A Security and Dependency Guide]]></title>
      <description><![CDATA[mobx-react-lite is the lightweight MobX binding for React function components. It is a small, focused dependency, and that shape has real implications for how you keep it safe.]]></description>
      <link>https://safeguard.sh/resources/blog/mobx-react-lite</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mobx-react-lite</guid>
      <pubDate>Mon, 15 Jun 2026 04:32:52 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Comparing Terraform security scanners: Snyk IaC, Checkov, tfsec]]></title>
      <description><![CDATA[Snyk IaC, Checkov, and tfsec take different approaches to Terraform scanning — and one of them stopped getting new checks in 2023. Here's how they actually compare.]]></description>
      <link>https://safeguard.sh/resources/blog/comparing-terraform-security-scanners-snyk-iac-checkov-tfsec</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/comparing-terraform-security-scanners-snyk-iac-checkov-tfsec</guid>
      <pubDate>Mon, 15 Jun 2026 04:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Blind and Out-of-Band XXE: How XXE Injection Really Works]]></title>
      <description><![CDATA[A defensive guide to XXE injection, including the blind and out-of-band variants that leak data with no visible response, plus how to detect and shut them down.]]></description>
      <link>https://safeguard.sh/resources/blog/bf-xxe</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bf-xxe</guid>
      <pubDate>Mon, 15 Jun 2026 03:12:26 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What open source scans miss in M&A due diligence]]></title>
      <description><![CDATA[Open source composition scans like Black Duck catch known packages and licenses — but M&A due diligence needs to catch what those scans miss too.]]></description>
      <link>https://safeguard.sh/resources/blog/what-open-source-scans-miss-in-ma-due-diligence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-open-source-scans-miss-in-ma-due-diligence</guid>
      <pubDate>Mon, 15 Jun 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Why Snyk Agent Fix scopes fixes to a single file, and wha...]]></title>
      <description><![CDATA[Snyk Agent Fix patches one file per finding. Here's why that scope exists, which vulnerability classes need multi-file fixes, and how to catch what a single-file patch leaves behind.]]></description>
      <link>https://safeguard.sh/resources/blog/why-snyk-agent-fix-scopes-fixes-to-a-single-file-and-what-that-means-for-complex-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-snyk-agent-fix-scopes-fixes-to-a-single-file-and-what-that-means-for-complex-vulnerabilities</guid>
      <pubDate>Mon, 15 Jun 2026 01:51:59 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[The cost of cloud misconfiguration breaches]]></title>
      <description><![CDATA[New breach-cost data shows cloud misconfigurations now cost millions per incident and take months to detect — here's what's driving the trend and how to close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/the-cost-of-cloud-misconfiguration-breaches</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-cost-of-cloud-misconfiguration-breaches</guid>
      <pubDate>Mon, 15 Jun 2026 01:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What Is Semantic Versioning?]]></title>
      <description><![CDATA[Semantic versioning encodes the meaning of a release into its version number. Here is how MAJOR.MINOR.PATCH works and why it drives both dependency resolution and security triage.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-semantic-versioning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-semantic-versioning</guid>
      <pubDate>Mon, 15 Jun 2026 00:31:32 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Deep visibility into hardened/minimal container images (d...]]></title>
      <description><![CDATA[Distroless images strip the package managers most scanners rely on. Here's how Safeguard achieves deep visibility into hardened images, compared to Black Duck's SCA heritage.]]></description>
      <link>https://safeguard.sh/resources/blog/deep-visibility-into-hardenedminimal-container-images-distroless-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/deep-visibility-into-hardenedminimal-container-images-distroless-scanning</guid>
      <pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[PentesterLand and Other Security Research Feeds Worth Following]]></title>
      <description><![CDATA[PentesterLand's weekly link roundup of write-ups, tools, and CTF material is one of the best-curated feeds in offensive security — here's what it covers and what else belongs in the same reading list.]]></description>
      <link>https://safeguard.sh/resources/blog/pentesterland-and-other-security-research-feeds</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pentesterland-and-other-security-research-feeds</guid>
      <pubDate>Sun, 14 Jun 2026 23:11:06 GMT</pubDate>
      <category>Culture</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The OWASP Top 10 API Security Risks, Explained]]></title>
      <description><![CDATA[The OWASP Top 10 API Security Risks reorder the classic web vulnerability list around how APIs actually get broken — object-level authorization failures beat injection as the most common real-world root cause.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-api-security-risks-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-api-security-risks-explained</guid>
      <pubDate>Sun, 14 Jun 2026 21:50:39 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Security Vulnerability Remediation: Process, Prioritization, and SLAs]]></title>
      <description><![CDATA[Finding vulnerabilities is the easy half. A working remediation program needs ownership, evidence-based prioritization, and SLAs that engineering teams can actually hit.]]></description>
      <link>https://safeguard.sh/resources/blog/security-vulnerability-remediation-process-slas</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-vulnerability-remediation-process-slas</guid>
      <pubDate>Sun, 14 Jun 2026 20:30:12 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Reading a SAST Report: Findings, Traces, and Triage]]></title>
      <description><![CDATA[A SAST report is a list of claims, not a list of bugs. How to read data-flow traces, judge severity honestly, and run a triage workflow that keeps the queue moving.]]></description>
      <link>https://safeguard.sh/resources/blog/reading-a-sast-report-findings-triage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reading-a-sast-report-findings-triage</guid>
      <pubDate>Sun, 14 Jun 2026 19:09:46 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Software Ingredient Label?]]></title>
      <description><![CDATA[Food gets an ingredient panel; software gets an SBOM. What a software ingredient label contains, who is demanding one, and how to generate yours automatically.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-software-ingredient-label</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-software-ingredient-label</guid>
      <pubDate>Sun, 14 Jun 2026 17:49:19 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code's detection differs across Java, JavaScript...]]></title>
      <description><![CDATA[Snyk Code applies one hybrid AI-plus-symbolic engine to ten languages, but rule depth, autofix coverage, and taint tracking vary widely by language.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-codes-detection-differs-across-java-javascripttypescript-python-go-cc-c-apex-php-ruby-and-swift</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-codes-detection-differs-across-java-javascripttypescript-python-go-cc-c-apex-php-ruby-and-swift</guid>
      <pubDate>Sun, 14 Jun 2026 16:28:52 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code integrates with GitHub Advanced Security th...]]></title>
      <description><![CDATA[A technical walkthrough of how Snyk Code's SARIF output is generated, uploaded, and deduplicated inside GitHub Advanced Security's code scanning pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-code-integrates-with-github-advanced-security-through-sarif-output</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-code-integrates-with-github-advanced-security-through-sarif-output</guid>
      <pubDate>Sun, 14 Jun 2026 15:08:25 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Slopsquatting: When AI Hallucinates Package Names]]></title>
      <description><![CDATA[LLMs invent plausible package names; attackers register them and wait. How slopsquatting works, why hallucinations repeat predictably, and the gates that stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/slopsquatting-when-ai-hallucinates-package-names</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slopsquatting-when-ai-hallucinates-package-names</guid>
      <pubDate>Sun, 14 Jun 2026 14:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Raman)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code's confidence scoring separates high-confide...]]></title>
      <description><![CDATA[How Snyk Code's confidence scoring works under the hood, and why "high confidence" and "severity" are not the same axis for triage.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-codes-confidence-scoring-separates-high-confidence-findings-from-exploratory-ones</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-codes-confidence-scoring-separates-high-confidence-findings-from-exploratory-ones</guid>
      <pubDate>Sun, 14 Jun 2026 13:47:59 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-20262: Cisco Catalyst SD-WAN Manager Zero-Day File-Write Exploited in the Wild]]></title>
      <description><![CDATA[Cisco confirmed limited in-the-wild exploitation of CVE-2026-20262, an arbitrary file-write zero-day in Catalyst SD-WAN Manager, alongside CVE-2026-20245. Here's what the chain actually buys an attacker and why edge management planes keep ending up on the KEV list.]]></description>
      <link>https://safeguard.sh/resources/blog/cisco-sd-wan-manager-zero-days-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisco-sd-wan-manager-zero-days-2026</guid>
      <pubDate>Sun, 14 Jun 2026 13:00:00 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Platformization vs Best-of-Breed: The 2026 Security Consolidation Debate]]></title>
      <description><![CDATA[RSAC 2026 made it official: the industry is consolidating. But platform breadth buys you integration and data gravity at the cost of lock-in and concentration risk. Here is where consolidation genuinely helps, and where it quietly hurts.]]></description>
      <link>https://safeguard.sh/resources/blog/platformization-vs-best-of-breed-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/platformization-vs-best-of-breed-2026</guid>
      <pubDate>Sun, 14 Jun 2026 13:00:00 GMT</pubDate>
      <category>Strategy</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Mocking in Python: unittest.mock, MagicMock, and Return Values]]></title>
      <description><![CDATA[A practitioner's guide to Python unit test mocking: when to use Mock vs MagicMock, setting return values and side effects, patching in the right place, and the assertions that make a mock worth writing.]]></description>
      <link>https://safeguard.sh/resources/blog/python-mocking-complete-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-mocking-complete-guide</guid>
      <pubDate>Sun, 14 Jun 2026 12:27:32 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Choosing an Agile Data Security Solution That Keeps Up]]></title>
      <description><![CDATA[An agile data security solution protects data at the speed teams actually ship, embedding controls into pipelines and adapting as data moves rather than gating everything through slow manual review.]]></description>
      <link>https://safeguard.sh/resources/blog/agile-data-security-solution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agile-data-security-solution</guid>
      <pubDate>Sun, 14 Jun 2026 11:07:05 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Top 10 for LLM Applications explained]]></title>
      <description><![CDATA[A breakdown of the 2025 OWASP Top 10 for LLM Applications—prompt injection, supply chain, excessive agency—with real examples and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-for-llm-applications-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-for-llm-applications-explained</guid>
      <pubDate>Sun, 14 Jun 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Securing LangChain and LlamaIndex Applications in Production]]></title>
      <description><![CDATA[Agent frameworks ship fast and patch fast. The CVE history, the dangerous defaults, and a production hardening baseline for LangChain and LlamaIndex apps.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-langchain-and-llamaindex-applications-in-production</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-langchain-and-llamaindex-applications-in-production</guid>
      <pubDate>Sun, 14 Jun 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Webb)</author>
    </item>
    <item>
      <title><![CDATA[Salesloft Drift OAuth Breach: 700+ Salesforce Tenants Compromised]]></title>
      <description><![CDATA[UNC6395 stole Salesloft Drift OAuth tokens to exfiltrate Salesforce data from more than 700 organisations including Cloudflare, Zscaler, and Palo Alto Networks in August 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/salesloft-drift-oauth-salesforce-supply-chain-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/salesloft-drift-oauth-salesforce-supply-chain-breach</guid>
      <pubDate>Sun, 14 Jun 2026 09:46:39 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Software Composition Analysis Tools: buyer's checklist]]></title>
      <description><![CDATA[A practical SCA buyer's checklist comparing Safeguard and Black Duck on detection method, CI/CD fit, remediation speed, and license policy enforcement.]]></description>
      <link>https://safeguard.sh/resources/blog/software-composition-analysis-tools-buyers-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-composition-analysis-tools-buyers-checklist</guid>
      <pubDate>Sun, 14 Jun 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[EUCC: First Certificates Issued Six Weeks After Scheme Launch]]></title>
      <description><![CDATA[ANSSI issued the first two EUCC certificates in April 2025, just six weeks after the European Common Criteria-based cybersecurity certification scheme entered into force on 27 February 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/eucc-scheme-first-certificates-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eucc-scheme-first-certificates-2025</guid>
      <pubDate>Sun, 14 Jun 2026 08:26:12 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-55190 in Argo CD: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[Argo CD project details API leaks repository credentials, scored CVSS 9.9. GitOps platforms are now top-tier credential targets. Defender playbook below.]]></description>
      <link>https://safeguard.sh/resources/blog/argo-cd-cve-2025-55190-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/argo-cd-cve-2025-55190-patch-response</guid>
      <pubDate>Sun, 14 Jun 2026 07:05:45 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Prompt injection attacks: direct vs indirect]]></title>
      <description><![CDATA[Direct prompt injection comes from the chat box; indirect injection hides in the data your AI agent trusts. Here's how the two attack types differ and what stops each.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-attacks-direct-vs-indirect</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-attacks-direct-vs-indirect</guid>
      <pubDate>Sun, 14 Jun 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[SCA language and package manager coverage comparison]]></title>
      <description><![CDATA[See how Safeguard and Black Duck differ on SCA language and package manager coverage, detection methodology, and transitive dependency depth.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-language-and-package-manager-coverage-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-language-and-package-manager-coverage-comparison</guid>
      <pubDate>Sun, 14 Jun 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Is react-hot-toast Safe to Use? A Security Review]]></title>
      <description><![CDATA[react-hot-toast is a small, well-maintained React notification library with a clean security record, but the way you render toast content is where risk creeps in.]]></description>
      <link>https://safeguard.sh/resources/blog/react-hot-toast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-hot-toast</guid>
      <pubDate>Sun, 14 Jun 2026 05:45:19 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Code Scanning Software: How to Pick the Right Tool]]></title>
      <description><![CDATA[Code scanning software analyzes your source and dependencies for security flaws automatically. Here is how the categories differ and how to choose.]]></description>
      <link>https://safeguard.sh/resources/blog/code-scanning-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-scanning-software</guid>
      <pubDate>Sun, 14 Jun 2026 04:24:52 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Agent hijacking: the real-world impact of prompt injection]]></title>
      <description><![CDATA[From a zero-click Microsoft 365 Copilot breach to poisoned MCP servers, AI agent hijacking is now a real, documented software supply chain threat.]]></description>
      <link>https://safeguard.sh/resources/blog/agent-hijacking-the-real-world-impact-of-prompt-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agent-hijacking-the-real-world-impact-of-prompt-injection</guid>
      <pubDate>Sun, 14 Jun 2026 04:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Web App Pen Testing: A Practical Guide for Developers]]></title>
      <description><![CDATA[Web app pen testing simulates a real attacker to find exploitable flaws before they do. Here is how the process works, what it covers, and where it fits alongside automated scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/web-app-pen-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-app-pen-testing</guid>
      <pubDate>Sun, 14 Jun 2026 03:04:25 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Static analysis (SAST) tool buyer's guide]]></title>
      <description><![CDATA[A concrete, checkable buyer's guide comparing Safeguard and Black Duck on SAST analysis architecture, taint-tracking depth, reachability-driven triage, and unified findings data models.]]></description>
      <link>https://safeguard.sh/resources/blog/static-analysis-sast-tool-buyers-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-analysis-sast-tool-buyers-guide</guid>
      <pubDate>Sun, 14 Jun 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software Licensing Models Explained (and Their Hidden Security Risks)]]></title>
      <description><![CDATA[Software licensing models decide more than what you pay. Permissive, copyleft, dual, and proprietary licenses each carry compliance and security implications your SBOM needs to track.]]></description>
      <link>https://safeguard.sh/resources/blog/software-licensing-models</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-licensing-models</guid>
      <pubDate>Sun, 14 Jun 2026 01:43:59 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Securing Model Context Protocol (MCP) servers]]></title>
      <description><![CDATA[MCP server security explained through real 2025 CVEs, tool poisoning, and rug-pull attacks, plus concrete controls security teams need to defend AI agent tool calls.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-model-context-protocol-mcp-servers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-model-context-protocol-mcp-servers</guid>
      <pubDate>Sun, 14 Jun 2026 01:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Software Agent? A Security Guide to Autonomous Programs]]></title>
      <description><![CDATA[A software agent is a program that acts on a user's behalf, often with some autonomy. Here is what that means and the security concerns that come with delegated action.]]></description>
      <link>https://safeguard.sh/resources/blog/software-agent</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-agent</guid>
      <pubDate>Sun, 14 Jun 2026 00:23:32 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[DAST tool buyer's guide]]></title>
      <description><![CDATA[How Safeguard's unified, defensive-only DAST compares to Black Duck's WhiteHat-derived module on correlation, safety controls, and deployment for regulated teams.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-tool-buyers-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-tool-buyers-guide</guid>
      <pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code analyzes API usage patterns to catch insecu...]]></title>
      <description><![CDATA[A technical look at how Snyk Code's symbolic engine and taint tracking flag insecure API calls like weak crypto, XXE, and SSRF before code ships.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-code-analyzes-api-usage-patterns-to-catch-insecure-function-calls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-code-analyzes-api-usage-patterns-to-catch-insecure-function-calls</guid>
      <pubDate>Sat, 13 Jun 2026 23:03:05 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Download the Snyk CLI on Any Platform]]></title>
      <description><![CDATA[A Snyk CLI download guide covering npm, Homebrew, and standalone binaries, plus how to verify the download and authenticate before your first scan.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-cli-download</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-cli-download</guid>
      <pubDate>Sat, 13 Jun 2026 21:42:38 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Is react-native-pager-view Safe? A Security Look at the Package]]></title>
      <description><![CDATA[react-native-pager-view is a widely used swipeable-pager component with a healthy maintenance record. Here is how to assess its supply-chain risk and pin it safely in a React Native app.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-pager-view</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-pager-view</guid>
      <pubDate>Sat, 13 Jun 2026 20:22:12 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code detects path traversal vulnerabilities thro...]]></title>
      <description><![CDATA[How Snyk Code uses interprocedural data-flow tracing—not regex matching—to catch path traversal (CWE-22) by connecting tainted sources to file-system sinks.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-code-detects-path-traversal-vulnerabilities-through-symbolic-tracing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-code-detects-path-traversal-vulnerabilities-through-symbolic-tracing</guid>
      <pubDate>Sat, 13 Jun 2026 19:01:45 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Code's duplicate and similar-code detection supp...]]></title>
      <description><![CDATA[Snyk Code once shipped duplicate and similar-code detection under its Code Quality rules. Here's how it worked, and what its 2025 retirement means for teams.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-codes-duplicate-and-similar-code-detection-supports-code-quality-rules</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-codes-duplicate-and-similar-code-detection-supports-code-quality-rules</guid>
      <pubDate>Sat, 13 Jun 2026 17:41:18 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container detects a Dockerfile's base image with...]]></title>
      <description><![CDATA[Snyk Container identifies a Dockerfile's true base image by comparing layer digests against a registry database, no docker run required.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-container-detects-a-dockerfiles-base-image-without-ever-running-the-container</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-container-detects-a-dockerfiles-base-image-without-ever-running-the-container</guid>
      <pubDate>Sat, 13 Jun 2026 16:20:52 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container recommends minor, major, and alternati...]]></title>
      <description><![CDATA[A mechanical look at how Snyk Container ranks minor, major, and alternative base image upgrades using vulnerability counts and registry metadata.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-container-recommends-minor-major-and-alternative-base-image-upgrades</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-container-recommends-minor-major-and-alternative-base-image-upgrades</guid>
      <pubDate>Sat, 13 Jun 2026 15:00:25 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container maps vulnerabilities to specific image...]]></title>
      <description><![CDATA[How Snyk Container uses OCI manifest metadata, diff_ids, and Dockerfile history to trace a vulnerable package to the exact layer and build instruction that introduced it.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-container-maps-vulnerabilities-to-specific-image-layers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-container-maps-vulnerabilities-to-specific-image-layers</guid>
      <pubDate>Sat, 13 Jun 2026 13:39:58 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Browser Security: The Browser Is the New Endpoint for Agentic AI]]></title>
      <description><![CDATA[RSAC 2026 made it official — the enterprise browser is where agentic AI and shadow AI now live, and the industry is racing to put controls there. Here is what actually shipped and what still does not add up.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-browser-new-endpoint</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-browser-new-endpoint</guid>
      <pubDate>Sat, 13 Jun 2026 13:00:00 GMT</pubDate>
      <category>Strategy</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Defender 'RoguePlanet' Zero-Day (CVE-2026-50656): SYSTEM on Fully Patched Windows]]></title>
      <description><![CDATA[A race condition in Microsoft Defender, dubbed RoguePlanet, reportedly hands attackers SYSTEM privileges on fully updated Windows. We break down what is confirmed, what is still hedged, and what to do while the patch is in development.]]></description>
      <link>https://safeguard.sh/resources/blog/microsoft-defender-rogueplanet-zero-day</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microsoft-defender-rogueplanet-zero-day</guid>
      <pubDate>Sat, 13 Jun 2026 13:00:00 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container's Base Image filter isolates OS-level ...]]></title>
      <description><![CDATA[How Snyk Container's Base Image filter separates OS-level vulnerabilities from application dependencies, how it identifies base images, and where attribution breaks down.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-containers-base-image-filter-isolates-os-level-from-application-level-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-containers-base-image-filter-isolates-os-level-from-application-level-vulnerabilities</guid>
      <pubDate>Sat, 13 Jun 2026 12:19:32 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Best AIBOM Tools in 2026: AI Bill of Materials Platforms Compared]]></title>
      <description><![CDATA[An honest, technical guide to the best AIBOM tools in 2026 — from the open-source OWASP AIBOM Generator to AI-BOM features in Snyk, Wiz, Mend, JFrog, and Manifest Cyber — with clear guidance on what an AI bill of materials should actually capture.]]></description>
      <link>https://safeguard.sh/resources/blog/best-aibom-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-aibom-tools-2026</guid>
      <pubDate>Sat, 13 Jun 2026 12:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container scans distroless and minimal (Wolfi-st...]]></title>
      <description><![CDATA[Distroless and Wolfi-style images strip out package managers, breaking traditional scanners. Here's how Snyk Container identifies vulnerable packages anyway.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-container-scans-distroless-and-minimal-wolfi-style-images-for-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-container-scans-distroless-and-minimal-wolfi-style-images-for-vulnerabilities</guid>
      <pubDate>Sat, 13 Jun 2026 10:59:05 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[mcp-scan: detecting malicious MCP tool definitions]]></title>
      <description><![CDATA[MCP lets AI agents call tools via plain-text descriptions the model trusts blindly. Here's how mcp-scan catches poisoning, rug-pulls, and shadowing.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-scan-detecting-malicious-mcp-tool-definitions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-scan-detecting-malicious-mcp-tool-definitions</guid>
      <pubDate>Sat, 13 Jun 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container's static filesystem analysis avoids th...]]></title>
      <description><![CDATA[How Snyk Container inspects image layers, package databases, and lockfiles without ever running the container — and where static filesystem analysis hits its limits.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-containers-static-filesystem-analysis-avoids-the-need-for-a-running-container</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-containers-static-filesystem-analysis-avoids-the-need-for-a-running-container</guid>
      <pubDate>Sat, 13 Jun 2026 09:38:38 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[ASPM platform buyer's guide (Software Risk Manager)]]></title>
      <description><![CDATA[A fact-based comparison of Safeguard and Black Duck's Software Risk Manager for teams evaluating ASPM platforms: architecture, SCA heritage, deployment.]]></description>
      <link>https://safeguard.sh/resources/blog/aspm-platform-buyers-guide-software-risk-manager</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aspm-platform-buyers-guide-software-risk-manager</guid>
      <pubDate>Sat, 13 Jun 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container detects application-level dependencies...]]></title>
      <description><![CDATA[A mechanical look at how Snyk Container scans image filesystems to detect npm, pip, Maven, and other application dependencies bundled inside containers.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-container-detects-application-level-dependencies-bundled-inside-an-image</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-container-detects-application-level-dependencies-bundled-inside-an-image</guid>
      <pubDate>Sat, 13 Jun 2026 08:18:12 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container integrates with Kubernetes workloads f...]]></title>
      <description><![CDATA[How Snyk Container's Kubernetes integration uses a read-only controller to continuously re-check running workload images as new CVEs are disclosed.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-container-integrates-with-kubernetes-workloads-for-continuous-image-monitoring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-container-integrates-with-kubernetes-workloads-for-continuous-image-monitoring</guid>
      <pubDate>Sat, 13 Jun 2026 06:57:45 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[AppSec program consolidation: reducing tool sprawl]]></title>
      <description><![CDATA[AppSec tool sprawl is a consolidation problem, not just a vendor-count problem. A look at Black Duck's product lineage versus Safeguard's unified scanning pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/appsec-program-consolidation-reducing-tool-sprawl</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/appsec-program-consolidation-reducing-tool-sprawl</guid>
      <pubDate>Sat, 13 Jun 2026 06:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container handles multi-stage Docker builds duri...]]></title>
      <description><![CDATA[How Snyk Container identifies base images, attributes vulnerabilities to Dockerfile instructions, and scopes scans across multi-stage Docker builds.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-container-handles-multi-stage-docker-builds-during-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-container-handles-multi-stage-docker-builds-during-scanning</guid>
      <pubDate>Sat, 13 Jun 2026 05:37:18 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CNAPPs in 2025: What Cloud-Native Application Protection Platforms Actually Protect]]></title>
      <description><![CDATA[CNAPP has become the dominant category in cloud security. But the label covers wildly different capabilities. A clear-eyed look at what CNAPPs do, where they fall short, and how supply chain security fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-native-application-protection-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-native-application-protection-platforms</guid>
      <pubDate>Sat, 13 Jun 2026 04:16:51 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Can AI write secure code? Auditing AI-generated code]]></title>
      <description><![CDATA[AI writes code fast, but studies from 2021 to 2025 show it also reproduces insecure patterns and invents fake dependencies. Here's what the data says.]]></description>
      <link>https://safeguard.sh/resources/blog/can-ai-write-secure-code-auditing-ai-generated-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/can-ai-write-secure-code-auditing-ai-generated-code</guid>
      <pubDate>Sat, 13 Jun 2026 04:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise AppSec risk management at scale]]></title>
      <description><![CDATA[Black Duck built its platform on decades of license-compliance SCA and acquired tools. Safeguard built a unified, reachability-aware supply-chain risk platform from day one.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-appsec-risk-management-at-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-appsec-risk-management-at-scale</guid>
      <pubDate>Sat, 13 Jun 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container generates a Software Bill of Materials...]]></title>
      <description><![CDATA[How Snyk Container statically scans image layers, parses OS package databases and lockfiles, and exports CycloneDX/SPDX SBOMs — mechanically explained.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-container-generates-a-software-bill-of-materials-directly-from-an-image</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-container-generates-a-software-bill-of-materials-directly-from-an-image</guid>
      <pubDate>Sat, 13 Jun 2026 02:56:25 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container's registry integrations authenticate a...]]></title>
      <description><![CDATA[A technical walkthrough of how Snyk Container authenticates and pulls images from ECR, ACR, GCR, and Artifactory using IAM roles, service principals, and tokens.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-containers-registry-integrations-authenticate-and-scan-ecr-acr-gcr-and-artifactory</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-containers-registry-integrations-authenticate-and-scan-ecr-acr-gcr-and-artifactory</guid>
      <pubDate>Sat, 13 Jun 2026 01:35:58 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Copilot code security: XSS vulnerabilities found in React]]></title>
      <description><![CDATA[Copilot commonly suggests dangerouslySetInnerHTML and unsanitized DOM writes in React. Here's the data on AI-generated XSS risk and how to catch it.]]></description>
      <link>https://safeguard.sh/resources/blog/github-copilot-code-security-xss-vulnerabilities-found-in-react</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-copilot-code-security-xss-vulnerabilities-found-in-react</guid>
      <pubDate>Sat, 13 Jun 2026 01:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Broker's Container Registry Agent scans private,...]]></title>
      <description><![CDATA[How Snyk's Broker Container Registry Agent scans private, self-hosted registries like Artifactory and Nexus without exposing credentials or images to the cloud.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-brokers-container-registry-agent-scans-private-self-hosted-registries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-brokers-container-registry-agent-scans-private-self-hosted-registries</guid>
      <pubDate>Sat, 13 Jun 2026 00:15:31 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What is a Software Bill of Materials workflow (SPDX/SBOM)...]]></title>
      <description><![CDATA[A practical breakdown of SPDX-based SBOM compliance workflows — NTIA rules, EU CRA and FDA deadlines, where Black Duck falls short, and how continuous SBOM generation closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-software-bill-of-materials-workflow-spdxsbom-for-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-software-bill-of-materials-workflow-spdxsbom-for-compliance</guid>
      <pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container prioritizes OS package vulnerabilities...]]></title>
      <description><![CDATA[A technical look at how Snyk Container ranks OS package vulnerabilities using exploit maturity signals, CVSS, and EPSS instead of severity alone.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-container-prioritizes-os-package-vulnerabilities-using-exploit-maturity-signals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-container-prioritizes-os-package-vulnerabilities-using-exploit-maturity-signals</guid>
      <pubDate>Fri, 12 Jun 2026 22:55:05 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Choosing an npm Vulnerability Scanner That Catches Real Threats]]></title>
      <description><![CDATA[npm audit is only the starting point. Here is how an npm vulnerability scanner should handle transitive risk, reachability, install scripts, and lockfile integrity.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-vulnerability-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-vulnerability-scanner</guid>
      <pubDate>Fri, 12 Jun 2026 21:34:38 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's Docker Desktop Extension scans images before t...]]></title>
      <description><![CDATA[How Snyk's Docker Desktop extension scans local images for CVEs before push, what it can and can't detect, and where it fits with CI and registry scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-docker-desktop-extension-scans-images-before-theyre-pushed</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-docker-desktop-extension-scans-images-before-theyre-pushed</guid>
      <pubDate>Fri, 12 Jun 2026 20:14:11 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container parses apk, deb, and rpm package datab...]]></title>
      <description><![CDATA[How Snyk Container reads apk, dpkg, and rpm databases inside image layers to detect OS package vulnerabilities without ever running the container.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-container-parses-apk-deb-and-rpm-package-databases-for-os-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-container-parses-apk-deb-and-rpm-package-databases-for-os-vulnerabilities</guid>
      <pubDate>Fri, 12 Jun 2026 18:53:45 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container's automatic base image remediation PRs...]]></title>
      <description><![CDATA[How Snyk Container's automatic base image remediation PRs pick replacement tags, what triggers them, and what they actually change in a Dockerfile.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-containers-automatic-base-image-remediation-prs-are-constructed</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-containers-automatic-base-image-remediation-prs-are-constructed</guid>
      <pubDate>Fri, 12 Jun 2026 17:33:18 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Is Now a Connector in Claude: Continuous Compliance Monitoring for Enterprise AI]]></title>
      <description><![CDATA[Connect Safeguard to Claude Enterprise and Claude Platform to turn Claude activity logs into real-time AI compliance monitoring, audit-ready SOC 2 / NIST / PCI-DSS evidence, and policy enforcement — activity logs only, never conversation content.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-claude-compliance-api-connector</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-claude-compliance-api-connector</guid>
      <pubDate>Fri, 12 Jun 2026 17:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Hritik Kumar Sharma)</author>
    </item>
    <item>
      <title><![CDATA[How image digest pinning strengthens container supply cha...]]></title>
      <description><![CDATA[How SHA-256 image digests, unlike mutable tags, anchor Snyk container scans to the exact artifact that ships—and why that distinction matters for supply chain integrity.]]></description>
      <link>https://safeguard.sh/resources/blog/how-image-digest-pinning-strengthens-container-supply-chain-integrity-in-snyk-workflows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-image-digest-pinning-strengthens-container-supply-chain-integrity-in-snyk-workflows</guid>
      <pubDate>Fri, 12 Jun 2026 16:12:51 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Docker Image Labels: Metadata That Actually Matters]]></title>
      <description><![CDATA[Docker image labels are free-form key-value metadata that, used well, drive SBOM generation, ownership tracing, and vulnerability triage — used poorly, they're just clutter in the Dockerfile.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-image-labels-metadata-that-actually-matters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-image-labels-metadata-that-actually-matters</guid>
      <pubDate>Fri, 12 Jun 2026 14:52:24 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[API Security: A Clear Definition and What It Covers]]></title>
      <description><![CDATA[The API security definition is straightforward: protecting the APIs that expose your data and logic from misuse, abuse, and unauthorized access. What that covers in practice is broader than most teams assume.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-definition</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-definition</guid>
      <pubDate>Fri, 12 Jun 2026 13:31:58 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Ransomware Economics in 2026: Data Extortion Wins, Encryption Loses]]></title>
      <description><![CDATA[Payment rates hit record lows in 2025 while attack volume surged. The result is a colder, leaner extortion economy built on data theft, not encryption — and a RaaS market reconsolidating around a handful of operators.]]></description>
      <link>https://safeguard.sh/resources/blog/ransomware-economics-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ransomware-economics-2026</guid>
      <pubDate>Fri, 12 Jun 2026 13:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-45657: The Wormable-Class Windows Kernel RCE You Should Patch This Week]]></title>
      <description><![CDATA[A CVSS 9.8 zero-day-grade remote code execution flaw in the Windows kernel's TCP/IP path lets unauthenticated attackers run code as SYSTEM with no user interaction. Here's what's confirmed, what's hype, and what to do now.]]></description>
      <link>https://safeguard.sh/resources/blog/windows-kernel-rce-cve-2026-45657</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/windows-kernel-rce-cve-2026-45657</guid>
      <pubDate>Fri, 12 Jun 2026 13:00:00 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[web-vitals npm Package: Measuring Core Web Vitals Without Adding Risk]]></title>
      <description><![CDATA[The web vitals npm package from the Chrome team measures LCP, INP, and CLS in the field. Here is how to deploy it without turning performance monitoring into a security or privacy liability.]]></description>
      <link>https://safeguard.sh/resources/blog/web-vitals-npm-package-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-vitals-npm-package-guide</guid>
      <pubDate>Fri, 12 Jun 2026 12:11:31 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Best LLM Security Tools in 2026: Guardrails, Red Teaming, and Runtime Defense Compared]]></title>
      <description><![CDATA[An honest guide to the best LLM security tools in 2026 — from open-source guardrails and red-teaming scanners like NeMo Guardrails, garak, and LLM Guard to runtime APIs and full AI security platforms — with clear guidance on which job each one actually does.]]></description>
      <link>https://safeguard.sh/resources/blog/best-llm-security-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-llm-security-tools-2026</guid>
      <pubDate>Fri, 12 Jun 2026 12:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Container's exclude and allow policies reduce no...]]></title>
      <description><![CDATA[Snyk Container's exclude and allow policies scope ignore rules to specific paths and layers, filtering base-image noise without hiding real application risk.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-containers-exclude-and-allow-policies-reduce-noisy-base-image-findings</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-containers-exclude-and-allow-policies-reduce-noisy-base-image-findings</guid>
      <pubDate>Fri, 12 Jun 2026 10:51:04 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Copilot amplifies insecure codebases]]></title>
      <description><![CDATA[Copilot writes ~46% of code where enabled, and studies show ~40% of its security-relevant suggestions are vulnerable. Here's the data on the risk.]]></description>
      <link>https://safeguard.sh/resources/blog/how-copilot-amplifies-insecure-codebases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-copilot-amplifies-insecure-codebases</guid>
      <pubDate>Fri, 12 Jun 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Audit the Dependencies of an AI Agent]]></title>
      <description><![CDATA[An AI agent's dependency tree spans packages, MCP servers, models, and system prompts. A step-by-step audit method that actually enumerates all four layers.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-audit-the-dependencies-of-an-ai-agent</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-audit-the-dependencies-of-an-ai-agent</guid>
      <pubDate>Fri, 12 Jun 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Jonas Meyer)</author>
    </item>
    <item>
      <title><![CDATA[Docker Image for Node: Choosing Slim vs Full Builds]]></title>
      <description><![CDATA[The default node image on Docker Hub ships a full Debian userland most services never touch — knowing when slim, alpine, or distroless actually pays off keeps builds smaller without breaking native modules.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-image-node-choosing-slim-vs-full</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-image-node-choosing-slim-vs-full</guid>
      <pubDate>Fri, 12 Jun 2026 09:30:38 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[AI-Generated Code Security: risks and controls]]></title>
      <description><![CDATA[AI now writes up to 40%+ of new code, and models hallucinate nonexistent packages in 5-22% of outputs. Here's why Black Duck-style SCA misses that risk, and what controls actually work.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-generated-code-security-risks-and-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-generated-code-security-risks-and-controls</guid>
      <pubDate>Fri, 12 Jun 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[babel-loader: Keeping Your Babel Toolchain Lean and Patched]]></title>
      <description><![CDATA[The babel-loader npm package bridges webpack and Babel in millions of builds. Here's how to configure it for speed, keep the toolchain patched, and know when you no longer need it.]]></description>
      <link>https://safeguard.sh/resources/blog/babel-loader-npm-package-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/babel-loader-npm-package-guide</guid>
      <pubDate>Fri, 12 Jun 2026 08:10:11 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[5 best practices for adopting GitHub Copilot securely]]></title>
      <description><![CDATA[GitHub Copilot has 1.3M+ paid seats. Five concrete, evidence-based practices for locking down content exclusion, licensing, code quality, and prompt injection risk.]]></description>
      <link>https://safeguard.sh/resources/blog/5-best-practices-for-adopting-github-copilot-securely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/5-best-practices-for-adopting-github-copilot-securely</guid>
      <pubDate>Fri, 12 Jun 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Application Security vs Network Security: Where the Line Is]]></title>
      <description><![CDATA[Application security vs network security comes down to what layer you're defending — code and logic versus traffic and perimeter — and most breaches now happen in the gap between them.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-application-security-vs-network-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-application-security-vs-network-security</guid>
      <pubDate>Fri, 12 Jun 2026 06:49:44 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why LLM API keys should be treated as tier-zero secrets]]></title>
      <description><![CDATA[A leaked LLM API key is a blank check and a data pipe in one credential. Here's why it demands tier-zero controls—and why tools like Black Duck never see it.]]></description>
      <link>https://safeguard.sh/resources/blog/why-llm-api-keys-should-be-treated-as-tier-zero-secrets</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-llm-api-keys-should-be-treated-as-tier-zero-secrets</guid>
      <pubDate>Fri, 12 Jun 2026 06:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk IaC's static analysis engine parses Terraform HC...]]></title>
      <description><![CDATA[A technical walkthrough of how Snyk IaC parses Terraform HCL into JSON, evaluates it with OPA/Rego policies, and maps violations back to source lines.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-iacs-static-analysis-engine-parses-terraform-hcl-into-a-security-checkable-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-iacs-static-analysis-engine-parses-terraform-hcl-into-a-security-checkable-model</guid>
      <pubDate>Fri, 12 Jun 2026 05:29:18 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk IaC's 400+ rule library maps to CIS benchmarks a...]]></title>
      <description><![CDATA[How Snyk IaC's 400+ rules trace to numbered CIS AWS, Azure, GCP, and Kubernetes benchmark controls — and where benchmark-mapped scanning stops short.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-iacs-400-rule-library-maps-to-cis-benchmarks-and-cloud-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-iacs-400-rule-library-maps-to-cis-benchmarks-and-cloud-best-practices</guid>
      <pubDate>Fri, 12 Jun 2026 04:08:51 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[AI hallucinations and their security implications for developers]]></title>
      <description><![CDATA[LLMs hallucinate nonexistent packages in up to 1 in 5 code samples — and slopsquatting attacks are already exploiting that predictability in the wild.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-hallucinations-and-their-security-implications-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-hallucinations-and-their-security-implications-for-developers</guid>
      <pubDate>Fri, 12 Jun 2026 04:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[BSIMM16 report: benchmarking software security program ma...]]></title>
      <description><![CDATA[BSIMM16 shows AI now drives more security program change than any other force, with 111 firms assessed and SBOM use up nearly 30%. Here's what it means — and its blind spots.]]></description>
      <link>https://safeguard.sh/resources/blog/bsimm16-report-benchmarking-software-security-program-maturity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bsimm16-report-benchmarking-software-security-program-maturity</guid>
      <pubDate>Fri, 12 Jun 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk IaC scans Kubernetes manifests and Helm charts f...]]></title>
      <description><![CDATA[A technical walkthrough of how Snyk IaC parses Kubernetes manifests, renders Helm charts, and checks them against CIS benchmarks before deployment.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-iac-scans-kubernetes-manifests-and-helm-charts-for-misconfigurations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-iac-scans-kubernetes-manifests-and-helm-charts-for-misconfigurations</guid>
      <pubDate>Fri, 12 Jun 2026 02:48:24 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[React Native MMKV: Fast Storage and How to Keep It Secure]]></title>
      <description><![CDATA[React Native MMKV is the fastest key-value store for React Native, but speed does not equal security. Here is how to use it and how to protect the data you put in it.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-mmkv</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-mmkv</guid>
      <pubDate>Fri, 12 Jun 2026 01:27:58 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[PrismJS: Vulnerability History and Hardening Your Syntax Highlighting]]></title>
      <description><![CDATA[The npm prismjs package has patched ReDoS, plugin XSS, and a DOM clobbering flaw over the years. Here is the full history and how to run a syntax highlighter safely.]]></description>
      <link>https://safeguard.sh/resources/blog/prismjs-npm-vulnerabilities-and-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prismjs-npm-vulnerabilities-and-hardening</guid>
      <pubDate>Fri, 12 Jun 2026 00:07:31 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Open source license compliance and risk management]]></title>
      <description><![CDATA[How to manage open source license risk beyond point-in-time scans: copyleft traps, MongoDB/Elastic relicensing, and why continuous checks beat Black Duck-style audits.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-license-compliance-and-risk-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-license-compliance-and-risk-management</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[GenAI Code Review Tools: A 2025 Field Test]]></title>
      <description><![CDATA[We field-tested five GenAI code review tools against 240 seeded security defects to see which catch real issues and which hallucinate findings.]]></description>
      <link>https://safeguard.sh/resources/blog/genai-code-review-tools-field-test-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/genai-code-review-tools-field-test-2025</guid>
      <pubDate>Thu, 11 Jun 2026 22:47:04 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[DORA Subcontracting RTS: Inside Commission Delegated Regulation 2025/532]]></title>
      <description><![CDATA[The DORA subcontracting RTS adopted on 24 March 2025 governs how ICT third-party providers may subcontract critical or important functions, in force from 22 July 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-subcontracting-rts-regulation-2025-532</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-subcontracting-rts-regulation-2025-532</guid>
      <pubDate>Thu, 11 Jun 2026 21:26:37 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to write a custom Snyk IaC rule in Rego using the Rul...]]></title>
      <description><![CDATA[A technical walkthrough of Snyk's IaC Rules SDK: scaffolding, writing Rego deny rules, local testing, bundling, and org-wide enforcement via OCI registries.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-write-a-custom-snyk-iac-rule-in-rego-using-the-rules-sdk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-write-a-custom-snyk-iac-rule-in-rego-using-the-rules-sdk</guid>
      <pubDate>Thu, 11 Jun 2026 20:06:11 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk IaC's Terraform Cloud run tasks gate infrastruct...]]></title>
      <description><![CDATA[How Snyk IaC uses Terraform Cloud's run tasks to scan plan output and block infrastructure changes before apply — the mechanics, enforcement levels, and limits.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-iacs-terraform-cloud-run-tasks-gate-infrastructure-changes-before-apply</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-iacs-terraform-cloud-run-tasks-gate-infrastructure-changes-before-apply</guid>
      <pubDate>Thu, 11 Jun 2026 18:45:44 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk IaC scans a Terraform Plan JSON file to catch dr...]]></title>
      <description><![CDATA[How Snyk IaC parses Terraform plan JSON's resource_changes to catch drift and misconfigurations before terraform apply — the mechanics, limits, and what it can't see.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-iac-scans-a-terraform-plan-json-file-to-catch-drift-before-deployment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-iac-scans-a-terraform-plan-json-file-to-catch-drift-before-deployment</guid>
      <pubDate>Thu, 11 Jun 2026 17:25:17 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Attacks Targeting AI/ML Pipelines]]></title>
      <description><![CDATA[AI and ML pipelines introduce unique supply chain risks -- from poisoned training data to compromised model registries. Here is what attackers are targeting and how to defend.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-attacks-targeting-ai-ml-pipelines</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-attacks-targeting-ai-ml-pipelines</guid>
      <pubDate>Thu, 11 Jun 2026 16:04:51 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk IaC correlates code-level misconfigurations with...]]></title>
      <description><![CDATA[How Snyk's Cloud Context feature joins Terraform and CloudFormation misconfigurations to live AWS, Azure, and GCP resources — and where that correlation model breaks down.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-iac-correlates-code-level-misconfigurations-with-deployed-cloud-resources</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-iac-correlates-code-level-misconfigurations-with-deployed-cloud-resources</guid>
      <pubDate>Thu, 11 Jun 2026 14:44:24 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk IaC's severity scoring weighs the exploitability...]]></title>
      <description><![CDATA[A mechanical look at how Snyk IaC assigns Critical-to-Low severity to misconfigurations, and how exploitability factors like exposure and privilege requirements shape the rating.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-iacs-severity-scoring-weighs-the-exploitability-of-a-misconfiguration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-iacs-severity-scoring-weighs-the-exploitability-of-a-misconfiguration</guid>
      <pubDate>Thu, 11 Jun 2026 13:23:57 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Patch Tuesday June 2026: ~200 Flaws, 6 Zero-Days, and a Wormable Kernel RCE]]></title>
      <description><![CDATA[Microsoft's June 2026 Patch Tuesday is among the largest on record — roughly 200 fixes, six zero-days including one exploited in the wild, and a top-severity Windows Kernel RCE. Here's what actually matters.]]></description>
      <link>https://safeguard.sh/resources/blog/microsoft-june-2026-patch-tuesday-roundup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microsoft-june-2026-patch-tuesday-roundup</guid>
      <pubDate>Thu, 11 Jun 2026 13:00:00 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Agentic AI at RSAC 2026 vs Infosecurity Europe 2026: Two Continents, One Theme]]></title>
      <description><![CDATA[RSAC 2026 in San Francisco and Infosecurity Europe 2026 in London both orbited agentic AI, shadow AI, and post-quantum cryptography. What changed across the Atlantic was the framing: market velocity versus regulation and sovereignty.]]></description>
      <link>https://safeguard.sh/resources/blog/rsac-vs-infosec-europe-2026-agentic-ai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rsac-vs-infosec-europe-2026-agentic-ai</guid>
      <pubDate>Thu, 11 Jun 2026 13:00:00 GMT</pubDate>
      <category>Strategy</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk IaC's custom rule SDK structures resource-attrib...]]></title>
      <description><![CDATA[A technical look at how Snyk IaC's Rego-based SDK normalizes Terraform, CloudFormation, Kubernetes, and ARM into one resource-attribute query model.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-iacs-custom-rule-sdk-structures-resource-attribute-queries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-iacs-custom-rule-sdk-structures-resource-attribute-queries</guid>
      <pubDate>Thu, 11 Jun 2026 12:03:31 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Best AI Security Tools in 2026: Guardrails, Red Teaming, and Agentic AI Security Compared]]></title>
      <description><![CDATA[An honest guide to the best AI security tools in 2026 — red-teaming and testing tools, runtime guardrails for prompt injection, agentic AI and MCP security, and the AI supply chain layer (AIBOM) — with a clear best-for line for each.]]></description>
      <link>https://safeguard.sh/resources/blog/best-ai-security-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-ai-security-tools-2026</guid>
      <pubDate>Thu, 11 Jun 2026 12:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk IaC handles Terraform modules and remote module ...]]></title>
      <description><![CDATA[How Snyk IaC statically parses Terraform, resolves local modules inline, and why remote Registry or Git modules stay unexpanded until a Terraform plan is scanned.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-iac-handles-terraform-modules-and-remote-module-sources-during-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-iac-handles-terraform-modules-and-remote-module-sources-during-scanning</guid>
      <pubDate>Thu, 11 Jun 2026 10:43:04 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How an organization's custom policy set overrides Snyk Ia...]]></title>
      <description><![CDATA[How Snyk IaC's Rego-based custom rules layer onto, disable, or supplement default policies — and what that means for enforcing org-specific IaC standards.]]></description>
      <link>https://safeguard.sh/resources/blog/how-an-organizations-custom-policy-set-overrides-snyk-iacs-default-rules</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-an-organizations-custom-policy-set-overrides-snyk-iacs-default-rules</guid>
      <pubDate>Thu, 11 Jun 2026 09:22:37 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Financial services application security compliance]]></title>
      <description><![CDATA[PCI DSS 4.0, DORA, and NYDFS 500 now demand provable SBOM and provenance evidence — see where legacy SCA tools like Black Duck fall short for financial services teams.]]></description>
      <link>https://safeguard.sh/resources/blog/financial-services-application-security-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/financial-services-application-security-compliance</guid>
      <pubDate>Thu, 11 Jun 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk IaC detects overly permissive IAM policies in Te...]]></title>
      <description><![CDATA[A mechanical walkthrough of how Snyk IaC parses Terraform and CloudFormation, normalizes IAM policies into one model, and flags wildcard actions, resources, and principals before deploy.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-iac-detects-overly-permissive-iam-policies-in-terraform-and-cloudformation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-iac-detects-overly-permissive-iam-policies-in-terraform-and-cloudformation</guid>
      <pubDate>Thu, 11 Jun 2026 08:02:11 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk IaC identifies unencrypted storage resources acr...]]></title>
      <description><![CDATA[Snyk IaC flags unencrypted S3 buckets, Azure Storage, and GCP disks by parsing Terraform and CloudFormation for missing encryption attributes before deployment.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-iac-identifies-unencrypted-storage-resources-across-aws-azure-and-gcp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-iac-identifies-unencrypted-storage-resources-across-aws-azure-and-gcp</guid>
      <pubDate>Thu, 11 Jun 2026 06:41:44 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Medical device software security and compliance]]></title>
      <description><![CDATA[FDA's 2023 cybersecurity mandate turned SBOMs into a submission gate. Here's what medical device makers actually need, and where legacy SCA tools like Black Duck fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/medical-device-software-security-and-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/medical-device-software-security-and-compliance</guid>
      <pubDate>Thu, 11 Jun 2026 06:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk IaC's admission-time Kubernetes scanning differs...]]></title>
      <description><![CDATA[How Snyk IaC's static manifest scanning, the Snyk Controller's in-cluster monitoring, and true Kubernetes admission control mechanically differ — and why the gap between them matters.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-iacs-admission-time-kubernetes-scanning-differs-from-repository-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-iacs-admission-time-kubernetes-scanning-differs-from-repository-scanning</guid>
      <pubDate>Thu, 11 Jun 2026 05:21:17 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Open Source builds a full dependency tree from p...]]></title>
      <description><![CDATA[How Snyk Open Source turns package-lock.json and yarn.lock files into a full dependency graph to power vulnerability matching and fix advice.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-open-source-builds-a-full-dependency-tree-from-project-lockfiles</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-open-source-builds-a-full-dependency-tree-from-project-lockfiles</guid>
      <pubDate>Thu, 11 Jun 2026 04:00:50 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Public sector / government application security requirements]]></title>
      <description><![CDATA[EO 14028, CISA's attestation form, and FedRAMP have made government application security compliance its own discipline. Here's what's required and where legacy SCA tools like Black Duck fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/public-sector-government-application-security-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/public-sector-government-application-security-requirements</guid>
      <pubDate>Thu, 11 Jun 2026 03:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk parses npm, yarn, and pnpm lockfiles differently...]]></title>
      <description><![CDATA[How Snyk resolves exact package versions from npm, Yarn, and pnpm lockfiles — and why each format's structure demands its own parsing logic.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-parses-npm-yarn-and-pnpm-lockfiles-differently-to-resolve-exact-versions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-parses-npm-yarn-and-pnpm-lockfiles-differently-to-resolve-exact-versions</guid>
      <pubDate>Thu, 11 Jun 2026 02:40:24 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk resolves Maven and Gradle dependency graphs incl...]]></title>
      <description><![CDATA[Snyk doesn't parse pom.xml or build.gradle statically -- it invokes real Maven and Gradle tooling to compute the exact dependency graph your build produces.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-resolves-maven-and-gradle-dependency-graphs-including-transitive-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-resolves-maven-and-gradle-dependency-graphs-including-transitive-dependencies</guid>
      <pubDate>Thu, 11 Jun 2026 01:19:57 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Embedded software and ISV security programs]]></title>
      <description><![CDATA[Black Duck built its business on binary composition analysis for embedded software. Here's what that approach misses in 2026, and what a modern ISV security program needs instead.]]></description>
      <link>https://safeguard.sh/resources/blog/embedded-software-and-isv-security-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/embedded-software-and-isv-security-programs</guid>
      <pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Nx s1ngularity: The First AI-Aware Supply Chain Worm]]></title>
      <description><![CDATA[On August 26, 2025, malicious versions of Nx (20.9.0–21.8.0) harvested 2,349 credentials from 1,079 developers and weaponized Claude, Gemini, and Q CLIs to enumerate local secrets.]]></description>
      <link>https://safeguard.sh/resources/blog/nx-build-system-s1ngularity-supply-chain-attack-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nx-build-system-s1ngularity-supply-chain-attack-2025</guid>
      <pubDate>Wed, 10 Jun 2026 23:59:30 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk handles Python dependency resolution across pip,...]]></title>
      <description><![CDATA[How Snyk resolves Python dependency trees differently for pip, Poetry, and Pipenv, and what that means for vulnerability scan accuracy.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-handles-python-dependency-resolution-across-pip-poetry-and-pipenv</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-handles-python-dependency-resolution-across-pip-poetry-and-pipenv</guid>
      <pubDate>Wed, 10 Jun 2026 22:39:04 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Open Source scans Go modules and resolves the Go...]]></title>
      <description><![CDATA[How Snyk Open Source reads go.mod/go.sum, builds the Go module dependency graph, and uses Minimal Version Selection to identify vulnerable versions.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-open-source-scans-go-modules-and-resolves-the-go-module-graph</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-open-source-scans-go-modules-and-resolves-the-go-module-graph</guid>
      <pubDate>Wed, 10 Jun 2026 21:18:37 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Open Source analyzes Cargo.lock for Rust depende...]]></title>
      <description><![CDATA[How Snyk Open Source parses Cargo.lock, matches resolved crate versions against RustSec advisories, and handles Rust workspaces -- a mechanical breakdown of its documented approach.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-open-source-analyzes-cargolock-for-rust-dependency-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-open-source-analyzes-cargolock-for-rust-dependency-vulnerabilities</guid>
      <pubDate>Wed, 10 Jun 2026 19:58:10 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Open-Weight Model Sandboxing Patterns]]></title>
      <description><![CDATA[Running an open-weight model inside an enterprise perimeter seems safer than calling a hosted API. It is, and it isn't. The sandboxing patterns that actually produce the safety properties.]]></description>
      <link>https://safeguard.sh/resources/blog/open-weight-model-sandboxing-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-weight-model-sandboxing-patterns</guid>
      <pubDate>Wed, 10 Jun 2026 18:37:44 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How the Snyk Vulnerability Database sources and verifies ...]]></title>
      <description><![CDATA[A look at how Snyk's Vulnerability Database sources, verifies, and scores new disclosures, from GHSA feeds and silent fixes to CVSS overrides and embargo timing.]]></description>
      <link>https://safeguard.sh/resources/blog/how-the-snyk-vulnerability-database-sources-and-verifies-new-vulnerability-disclosures</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-the-snyk-vulnerability-database-sources-and-verifies-new-vulnerability-disclosures</guid>
      <pubDate>Wed, 10 Jun 2026 17:17:17 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Why Snyk's vulnerability database often reports issues be...]]></title>
      <description><![CDATA[NVD's CVE enrichment pipeline has a well-documented backlog since 2024. Here's the mechanical reason Snyk's database often shows vulnerabilities weeks earlier.]]></description>
      <link>https://safeguard.sh/resources/blog/why-snyks-vulnerability-database-often-reports-issues-before-they-appear-in-the-nvd</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-snyks-vulnerability-database-often-reports-issues-before-they-appear-in-the-nvd</guid>
      <pubDate>Wed, 10 Jun 2026 15:56:50 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's Fix PRs mechanically differ from Upgrade PRs a...]]></title>
      <description><![CDATA[Snyk's Upgrade, Fix, and Backlog PRs aren't interchangeable — each changes different files and carries different CI risk. Here's the mechanical breakdown.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-fix-prs-mechanically-differ-from-upgrade-prs-and-backlog-prs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-fix-prs-mechanically-differ-from-upgrade-prs-and-backlog-prs</guid>
      <pubDate>Wed, 10 Jun 2026 14:36:24 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk decides whether an automatic PR proposes a minor...]]></title>
      <description><![CDATA[A mechanical walkthrough of the semver logic behind Snyk's automatic fix PRs — how it picks target versions and decides between patch, minor, and major bumps.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-decides-whether-an-automatic-pr-proposes-a-minor-or-major-version-bump</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-decides-whether-an-automatic-pr-proposes-a-minor-or-major-version-bump</guid>
      <pubDate>Wed, 10 Jun 2026 13:15:57 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Zero-Day Alert: Chrome V8 CVE-2026-11645 Is Being Exploited in the Wild]]></title>
      <description><![CDATA[Google shipped an emergency Chrome update for CVE-2026-11645, an out-of-bounds memory bug in V8 already exploited in the wild. Here is what the CVE actually means and why your browser patch window just shrank to days.]]></description>
      <link>https://safeguard.sh/resources/blog/chrome-v8-zero-day-cve-2026-11645</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chrome-v8-zero-day-cve-2026-11645</guid>
      <pubDate>Wed, 10 Jun 2026 13:00:00 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Gartner Says 75% of SOC Teams Will Lose Core Skills to Automation by 2030]]></title>
      <description><![CDATA[At its 2026 Security & Risk Management Summit, Gartner predicted that three in four SOC teams will see their foundational analysis skills erode from over-reliance on AI and automation. Here is what that actually means, and what to do about it.]]></description>
      <link>https://safeguard.sh/resources/blog/gartner-2026-soc-skill-erosion-prediction</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gartner-2026-soc-skill-erosion-prediction</guid>
      <pubDate>Wed, 10 Jun 2026 13:00:00 GMT</pubDate>
      <category>Strategy</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best Vulnerability Management Tools in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[An honest guide to the best vulnerability management tools in 2026 — from broad asset scanners like Tenable, Qualys, and Rapid7 to cloud-native Wiz and reachability-driven SCA from Snyk and Endor Labs — with a clear 'best for' for each and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/best-vulnerability-management-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-vulnerability-management-tools-2026</guid>
      <pubDate>Wed, 10 Jun 2026 12:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[universal-cookie: Package Review and Cookie Security Basics]]></title>
      <description><![CDATA[A review of the universal cookie npm package: what it does in isomorphic apps, the advisory it inherited through its cookie dependency, and the cookie security flags that matter more than the library.]]></description>
      <link>https://safeguard.sh/resources/blog/universal-cookie-npm-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/universal-cookie-npm-security-review</guid>
      <pubDate>Wed, 10 Jun 2026 11:55:30 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Technology: The Tools and Practices That Actually Work]]></title>
      <description><![CDATA[DevSecOps technology is the stack of tools and automation that embeds security into the software delivery pipeline. Here is what the categories are and how they fit together.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-technology</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-technology</guid>
      <pubDate>Wed, 10 Jun 2026 10:35:03 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Security in AI Systems: What Actually Changes]]></title>
      <description><![CDATA[Security in AI systems isn't a wholly new discipline, but prompt injection, training data provenance, and model supply chains introduce risks traditional AppSec tooling wasn't built to catch.]]></description>
      <link>https://safeguard.sh/resources/blog/security-in-ai-systems-what-changes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-in-ai-systems-what-changes</guid>
      <pubDate>Wed, 10 Jun 2026 09:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to List Images in a Docker Registry (and Why the CLI Cannot)]]></title>
      <description><![CDATA[To list images in a Docker registry you query the Registry HTTP API v2 directly, because the docker CLI has no command to enumerate a remote registry. Here is how to do it, and how to lock the endpoint down.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-registry-list-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-registry-list-images</guid>
      <pubDate>Wed, 10 Jun 2026 09:14:37 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Automotive software security (connected/autonomous vehicles)]]></title>
      <description><![CDATA[UN R155 and R156 are now mandatory for every vehicle sold in the EU, Japan, and Korea. Here's what automotive software security compliance actually requires, and where Black Duck falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/automotive-software-security-connectedautonomous-vehicles</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automotive-software-security-connectedautonomous-vehicles</guid>
      <pubDate>Wed, 10 Jun 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Management KPIs Your Board Actually Understands]]></title>
      <description><![CDATA[Boards don't want scanner counts — they want to know if risk is going up or down and whether the money is working. The handful of vulnerability management KPIs that translate, and the vanity metrics to drop.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-management-kpis-for-boards</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-management-kpis-for-boards</guid>
      <pubDate>Wed, 10 Jun 2026 08:00:00 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[A Checkmarx Scan: What It Actually Analyzes]]></title>
      <description><![CDATA[A breakdown of what a Checkmarx scan actually analyzes under the hood, what its static analysis engine catches well, and where teams typically add another tool alongside it.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-scan-what-it-actually-analyzes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-scan-what-it-actually-analyzes</guid>
      <pubDate>Wed, 10 Jun 2026 07:54:10 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Introducing Agentic Development Security (ADS)]]></title>
      <description><![CDATA[As AI agents now author up to half of production commits, Safeguard introduces Agentic Development Security (ADS) — a new framework for securing autonomous coding.]]></description>
      <link>https://safeguard.sh/resources/blog/introducing-agentic-development-security-ads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/introducing-agentic-development-security-ads</guid>
      <pubDate>Wed, 10 Jun 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-7775 in Citrix NetScaler: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[NetScaler ADC and Gateway memory overflow scored CVSS 9.2 and landed on CISA KEV with a 48-hour patch deadline. Here is the defender playbook.]]></description>
      <link>https://safeguard.sh/resources/blog/citrix-netscaler-cve-2025-7775-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/citrix-netscaler-cve-2025-7775-patch-response</guid>
      <pubDate>Wed, 10 Jun 2026 06:33:43 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Cybersecurity Research Center (CyRC): vulnerability resea...]]></title>
      <description><![CDATA[What is Black Duck's CyRC, how does it research and disclose vulnerabilities, and where do its coverage gaps leave your open source supply chain exposed?]]></description>
      <link>https://safeguard.sh/resources/blog/cybersecurity-research-center-cyrc-vulnerability-research-and-disclosures</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cybersecurity-research-center-cyrc-vulnerability-research-and-disclosures</guid>
      <pubDate>Wed, 10 Jun 2026 06:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How to Run an API Security Scan (and What It Catches)]]></title>
      <description><![CDATA[An API security scan probes your endpoints for auth flaws, broken object-level access, injection, and misconfiguration. Here is how to scan an API properly.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-scan</guid>
      <pubDate>Wed, 10 Jun 2026 05:13:17 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Security Vulnerability Assessment: A Step-by-Step Guide]]></title>
      <description><![CDATA[A security vulnerability assessment finds, ranks, and tracks weaknesses across your systems. Here is the full lifecycle from scoping to remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/security-vulnerability-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-vulnerability-assessment</guid>
      <pubDate>Wed, 10 Jun 2026 03:52:50 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk patches remediate vulnerabilities that have no a...]]></title>
      <description><![CDATA[How Snyk's patch feature applies targeted code-level diffs to fix vulnerabilities directly in dependencies when no clean upgrade path exists.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-patches-remediate-vulnerabilities-that-have-no-available-upgrade-path</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-patches-remediate-vulnerabilities-that-have-no-available-upgrade-path</guid>
      <pubDate>Wed, 10 Jun 2026 02:32:23 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How snyk monitor creates and tracks a point-in-time proje...]]></title>
      <description><![CDATA[A technical walkthrough of how `snyk monitor` builds a dependency snapshot, stores it as a Project, and re-checks it against new CVEs after the fact.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-monitor-creates-and-tracks-a-point-in-time-project-snapshot</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-monitor-creates-and-tracks-a-point-in-time-project-snapshot</guid>
      <pubDate>Wed, 10 Jun 2026 01:11:57 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Open Source's PR checks block merges based on se...]]></title>
      <description><![CDATA[A technical look at how Snyk Open Source's PR checks scan pull requests, compare severity to configured thresholds, and gate merges in CI/CD.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-open-sources-pr-checks-block-merges-based-on-severity-thresholds</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-open-sources-pr-checks-block-merges-based-on-severity-thresholds</guid>
      <pubDate>Tue, 09 Jun 2026 23:51:30 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk calculates direct versus transitive dependency v...]]></title>
      <description><![CDATA[Snyk splits vulnerability exposure into direct and transitive dependencies using lockfile graphs, CVE version-range matching, and path-level reachability analysis.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-calculates-direct-versus-transitive-dependency-vulnerability-exposure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-calculates-direct-versus-transitive-dependency-vulnerability-exposure</guid>
      <pubDate>Tue, 09 Jun 2026 22:31:03 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Transitive Dependency?]]></title>
      <description><![CDATA[A transitive dependency is code you never chose but still ship, pulled in by the libraries you did choose. Here is why indirect dependencies dominate your attack surface.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-transitive-dependency</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-transitive-dependency</guid>
      <pubDate>Tue, 09 Jun 2026 21:10:37 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's reachability analysis determines whether vulne...]]></title>
      <description><![CDATA[A technical walkthrough of how Snyk's reachability analysis builds static call graphs to determine whether vulnerable dependency functions are actually invoked by your code.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-reachability-analysis-determines-whether-vulnerable-code-is-actually-called</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-reachability-analysis-determines-whether-vulnerable-code-is-actually-called</guid>
      <pubDate>Tue, 09 Jun 2026 19:50:10 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How reachability analysis coverage differs across Java, J...]]></title>
      <description><![CDATA[Snyk's reachability analysis works differently across Java, JavaScript, and Python — here's why static, typed Java gets deeper coverage than dynamic Python and JS call graphs.]]></description>
      <link>https://safeguard.sh/resources/blog/how-reachability-analysis-coverage-differs-across-java-javascript-and-python-in-snyk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-reachability-analysis-coverage-differs-across-java-javascript-and-python-in-snyk</guid>
      <pubDate>Tue, 09 Jun 2026 18:29:43 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How the Snyk Priority Score algorithm blends CVSS, exploi...]]></title>
      <description><![CDATA[How Snyk's Priority Score blends CVSS severity, exploit maturity, and reachability analysis into a single 1-1000 vulnerability ranking score.]]></description>
      <link>https://safeguard.sh/resources/blog/how-the-snyk-priority-score-algorithm-blends-cvss-exploit-maturity-and-reachability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-the-snyk-priority-score-algorithm-blends-cvss-exploit-maturity-and-reachability</guid>
      <pubDate>Tue, 09 Jun 2026 17:09:16 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How the Snyk Risk Score's 0-1000 scale is derived from CV...]]></title>
      <description><![CDATA[How Snyk's 0-1000 Risk Score starts from the CVSS impact subscore formula, then layers in exploit maturity, social trends, and reachability data.]]></description>
      <link>https://safeguard.sh/resources/blog/how-the-snyk-risk-scores-0-1000-scale-is-derived-from-cvss-impact-subscores</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-the-snyk-risk-scores-0-1000-scale-is-derived-from-cvss-impact-subscores</guid>
      <pubDate>Tue, 09 Jun 2026 15:48:50 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Desktop App: Supply Chain Security Without the Browser Tab]]></title>
      <description><![CDATA[Announcing the Safeguard Desktop App -- a native application for macOS, Windows, and Linux that brings SBOM management, vulnerability tracking, and policy gates to your desktop.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-desktop-app-release</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-desktop-app-release</guid>
      <pubDate>Tue, 09 Jun 2026 14:28:23 GMT</pubDate>
      <category>Product Launch</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk Advisor's package health score weighs popularity...]]></title>
      <description><![CDATA[Snyk Advisor scores packages 0-100 using four signals: popularity, maintenance, community, and security. Here is exactly how each one is calculated.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-advisors-package-health-score-weighs-popularity-maintenance-and-community-signals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-advisors-package-health-score-weighs-popularity-maintenance-and-community-signals</guid>
      <pubDate>Tue, 09 Jun 2026 13:07:56 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Check Point VPN Zero-Day CVE-2026-50751: Auth Bypass Under Active Exploitation]]></title>
      <description><![CDATA[Check Point's CVE-2026-50751 lets an attacker dictate how hard the gateway checks them — and walk in without a password. It is rated CVSS 9.3, exploited since early May 2026, and already tied to a Qilin ransomware affiliate.]]></description>
      <link>https://safeguard.sh/resources/blog/check-point-vpn-zero-day-cve-2026-50751</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/check-point-vpn-zero-day-cve-2026-50751</guid>
      <pubDate>Tue, 09 Jun 2026 13:00:00 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Agentic AI Security: Gartner Says Most AI-Agent Attacks Will Be Access-Control Failures]]></title>
      <description><![CDATA[Gartner predicts that through 2029, more than half of successful attacks against AI agents will exploit access-control issues — with prompt injection as the delivery mechanism. Here's why that framing matters more than the headline number.]]></description>
      <link>https://safeguard.sh/resources/blog/gartner-2026-ai-agent-access-control-prediction</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gartner-2026-ai-agent-access-control-prediction</guid>
      <pubDate>Tue, 09 Jun 2026 13:00:00 GMT</pubDate>
      <category>Strategy</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best Secrets Scanning Tools in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[An honest, engineer-first guide to the best secrets scanning tools in 2026 — Gitleaks, TruffleHog, detect-secrets, GitGuardian, Kingfisher, and where a supply chain platform fits — with a clear 'best for' line for each.]]></description>
      <link>https://safeguard.sh/resources/blog/best-secrets-scanning-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-secrets-scanning-tools-2026</guid>
      <pubDate>Tue, 09 Jun 2026 12:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Now Supports Every Major AI Model Family for Zero-Day Discovery: Anthropic, OpenAI, Gemini, Microsoft, Meta, and Your Own Models]]></title>
      <description><![CDATA[You should not have to choose between your organization's AI strategy and your security platform. Safeguard's agentic zero-day discovery and remediation pipeline now works on Anthropic Claude Fable 5, OpenAI GPT, Google Gemini, Microsoft Phi, Meta Llama, Safeguard native models, and privately hosted custom models — all running as first-class agents in the same Multi-Agent TAOR Deep Think AI Engine.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-universal-model-support-all-ai-families-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-universal-model-support-all-ai-families-2026</guid>
      <pubDate>Tue, 09 Jun 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk detects malicious and typosquatted open-source p...]]></title>
      <description><![CDATA[How Snyk's research team detects malicious and typosquatted open-source packages — from name-similarity heuristics to install-script analysis and source-code provenance checks.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-detects-malicious-and-typosquatted-open-source-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-detects-malicious-and-typosquatted-open-source-packages</guid>
      <pubDate>Tue, 09 Jun 2026 11:47:30 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk identifies dependency confusion attacks in priva...]]></title>
      <description><![CDATA[A technical look at how Snyk detects dependency confusion attacks — from vulnerability database malicious-package flags to registry scoping and Advisor scoring.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-identifies-dependency-confusion-attacks-in-private-package-namespaces</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-identifies-dependency-confusion-attacks-in-private-package-namespaces</guid>
      <pubDate>Tue, 09 Jun 2026 10:27:03 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Anthropic Claude Mythos Releases Tomorrow: Capabilities, Benchmarks, and What Security Teams Must Do Now]]></title>
      <description><![CDATA[Anthropic's Claude Mythos model goes public on June 10, 2026 — a frontier AI that scored 97.6% on the Math Olympiad, completed expert-level hacking tasks at 73% success, and found 271 vulnerabilities in Firefox 150. Here is everything security teams need to know before it lands, and how Safeguard already supports Mythos zero-day discovery natively.]]></description>
      <link>https://safeguard.sh/resources/blog/anthropic-mythos-public-release-june-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anthropic-mythos-public-release-june-2026</guid>
      <pubDate>Tue, 09 Jun 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Claude Fable 5: Anthropic's Most Capable Public Model Is Here — Benchmarks, Capabilities, and What It Means for Security]]></title>
      <description><![CDATA[Anthropic just released Claude Fable 5, its most capable publicly available model and the first Mythos-class AI open to everyone. 80.3% on SWE-Bench Pro, 88% on Terminal-Bench 2.1, state-of-the-art across software engineering, vision, and scientific research. Safeguard has already integrated Fable 5 natively — here is everything you need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/claude-fable-5-anthropic-mythos-class-model-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/claude-fable-5-anthropic-mythos-class-model-2026</guid>
      <pubDate>Tue, 09 Jun 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's open-source license compliance engine classifi...]]></title>
      <description><![CDATA[How Snyk's license compliance engine groups open-source licenses and maps them to low, medium, high, and critical severity levels.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-open-source-license-compliance-engine-classifies-license-risk-severity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-open-source-license-compliance-engine-classifies-license-risk-severity</guid>
      <pubDate>Tue, 09 Jun 2026 09:06:36 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-34453: The snappy-java Integer Overflow Explained]]></title>
      <description><![CDATA[CVE-2023-34453 is an integer overflow in snappy-java's BitShuffle code that lets an attacker crash a JVM. Here are the affected versions and the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-34453</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-34453</guid>
      <pubDate>Tue, 09 Jun 2026 07:46:10 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's default license policy is structured and how t...]]></title>
      <description><![CDATA[How Snyk structures its default license policy—severity tiers, unknown-license handling, and PR enforcement—and the concrete steps to customize it for your org.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-default-license-policy-is-structured-and-how-to-customize-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-default-license-policy-is-structured-and-how-to-customize-it</guid>
      <pubDate>Tue, 09 Jun 2026 06:25:43 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk keeps its license classifications aligned with t...]]></title>
      <description><![CDATA[How Snyk detects, normalizes, and categorizes open source license metadata against the SPDX License List to power its license compliance policies.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-keeps-its-license-classifications-aligned-with-the-spdx-license-list</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-keeps-its-license-classifications-aligned-with-the-spdx-license-list</guid>
      <pubDate>Tue, 09 Jun 2026 05:05:16 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk detects deprecated or unmaintained packages befo...]]></title>
      <description><![CDATA[A look at how Snyk Advisor scores package maintenance health and surfaces deprecated or abandoned dependencies before they turn into security incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-detects-deprecated-or-unmaintained-packages-before-they-become-liabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-detects-deprecated-or-unmaintained-packages-before-they-become-liabilities</guid>
      <pubDate>Tue, 09 Jun 2026 03:44:49 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[What is an Open Source Audit?]]></title>
      <description><![CDATA[What is an open source audit, how does it compare to Black Duck's point-in-time scans, and why continuous monitoring closes the gap audits leave open.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-an-open-source-audit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-an-open-source-audit</guid>
      <pubDate>Tue, 09 Jun 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk scans NuGet and .NET project files for vulnerabl...]]></title>
      <description><![CDATA[How Snyk resolves NuGet and .NET dependency graphs from csproj, packages.config, and project.assets.json files to find vulnerable packages.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-scans-nuget-and-net-project-files-for-vulnerable-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-scans-nuget-and-net-project-files-for-vulnerable-dependencies</guid>
      <pubDate>Tue, 09 Jun 2026 02:24:23 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk scans Composer/PHP and RubyGems dependency manif...]]></title>
      <description><![CDATA[A technical look at how Snyk parses composer.json/composer.lock and Gemfile/Gemfile.lock to build dependency trees and match PHP and Ruby packages against known vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-scans-composerphp-and-rubygems-dependency-manifests</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-scans-composerphp-and-rubygems-dependency-manifests</guid>
      <pubDate>Tue, 09 Jun 2026 01:03:56 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[What are Open Source Licenses?]]></title>
      <description><![CDATA[Open source licenses govern how 96% of modern codebases can legally be used. Here's how license compliance works, where Black Duck's approach falls short, and how to close the gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/what-are-open-source-licenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-are-open-source-licenses</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's exploit maturity rating is researched and assi...]]></title>
      <description><![CDATA[A look at how Snyk researches and assigns exploit maturity ratings — the categories, the manual research process, and how the label shapes vulnerability prioritization.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-exploit-maturity-rating-is-researched-and-assigned-to-a-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-exploit-maturity-rating-is-researched-and-assigned-to-a-vulnerability</guid>
      <pubDate>Mon, 08 Jun 2026 23:43:29 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk handles vulnerability remediation for indirect (...]]></title>
      <description><![CDATA[How does Snyk fix vulnerabilities buried in transitive dependencies you never directly installed? A look at dependency graphs, upgrade paths, and pinning.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-handles-vulnerability-remediation-for-indirect-transitive-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-handles-vulnerability-remediation-for-indirect-transitive-dependencies</guid>
      <pubDate>Mon, 08 Jun 2026 22:23:03 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's .snyk file structures ignore rules with expiry...]]></title>
      <description><![CDATA[How Snyk's .snyk file encodes vulnerability ignore rules using reason and expiry date fields, and what happens in CI once an exception lapses.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-snyk-file-structures-ignore-rules-with-expiry-dates-and-reasons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-snyk-file-structures-ignore-rules-with-expiry-dates-and-reasons</guid>
      <pubDate>Mon, 08 Jun 2026 21:02:36 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is a Vulnerability Exploitability eXchange (VEX) Statement]]></title>
      <description><![CDATA[A VEX statement is a machine-readable assertion of whether a product is actually affected by a CVE — the document that stops your customers from triaging your SBOM for you.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-vulnerability-exploitability-exchange-vex-statement</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-vulnerability-exploitability-exchange-vex-statement</guid>
      <pubDate>Mon, 08 Jun 2026 19:42:09 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Tomas Lindgren)</author>
    </item>
    <item>
      <title><![CDATA[Webhooks Security: A Practical Checklist]]></title>
      <description><![CDATA[Webhooks security is easy to get wrong because the endpoint has to trust an unauthenticated inbound request by default — here's the checklist that closes the common gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/webhooks-security-a-practical-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webhooks-security-a-practical-checklist</guid>
      <pubDate>Mon, 08 Jun 2026 18:21:43 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[GPT-5 Launch: Reading the System Card for Supply-Chain Risk]]></title>
      <description><![CDATA[GPT-5 shipped August 13, 2025 under OpenAI's Preparedness Framework v2. Here's what the system card tells security teams about deployment risk.]]></description>
      <link>https://safeguard.sh/resources/blog/gpt-5-launch-system-card-supply-chain-impact</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gpt-5-launch-system-card-supply-chain-impact</guid>
      <pubDate>Mon, 08 Jun 2026 17:01:16 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Container Image Security Tools, Compared]]></title>
      <description><![CDATA[A container image security tool scans layers, packages, and configuration inside an image before and after it ships — here's how the major approaches differ and what actually matters when picking one.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-security-tools-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-security-tools-compared</guid>
      <pubDate>Mon, 08 Jun 2026 15:40:49 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[The .snyk Ignore File: How It Actually Works]]></title>
      <description><![CDATA[Snyk ignore rules let teams suppress a finding without deleting it from history — here's how the .snyk file's syntax, expiry, and reason fields actually work in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-ignore-file-how-it-works</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-ignore-file-how-it-works</guid>
      <pubDate>Mon, 08 Jun 2026 14:20:23 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Infosecurity Europe 2026's Cyber Startup Programme: A New Pipeline for Early-Stage Security]]></title>
      <description><![CDATA[Infosecurity Europe debuted a Cyber Startup Programme, a live-pitch Startup Award, and a dedicated Cyber Startups Zone in June 2026. Here is what it actually delivered for early-stage founders working on agentic AI security and software supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/infosecurity-europe-2026-cyber-startup-programme</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/infosecurity-europe-2026-cyber-startup-programme</guid>
      <pubDate>Mon, 08 Jun 2026 13:00:00 GMT</pubDate>
      <category>Industry Events</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[OAuth Token Theft: The SaaS-to-SaaS Supply Chain Is the New Soft Target]]></title>
      <description><![CDATA[The Klue and Salesloft Drift breaches showed the same pattern: steal one integration's OAuth tokens, inherit trusted access into hundreds of customer SaaS instances. Here is why third-party app grants are the supply chain risk most teams still aren't governing.]]></description>
      <link>https://safeguard.sh/resources/blog/oauth-token-theft-saas-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oauth-token-theft-saas-supply-chain</guid>
      <pubDate>Mon, 08 Jun 2026 13:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Ethical Hacking Course Online Free: Where to Learn Legally]]></title>
      <description><![CDATA[You can learn ethical hacking online for free through legitimate labs, capture-the-flag platforms, and vendor training, without spending a rupee or breaking a law. Here is a realistic starting path.]]></description>
      <link>https://safeguard.sh/resources/blog/ethical-hacking-course-online-free</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ethical-hacking-course-online-free</guid>
      <pubDate>Mon, 08 Jun 2026 12:59:56 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best ASPM Tools in 2026: Application Security Posture Management Compared]]></title>
      <description><![CDATA[An honest buyer's guide to the best ASPM tools in 2026 — Apiiro, ArmorCode, Cycode, Snyk AppRisk, OX Security, and Safeguard — with a fair blurb and a best-for line for each, plus how AIBOM and supply chain risk reshape the category.]]></description>
      <link>https://safeguard.sh/resources/blog/best-aspm-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-aspm-tools-2026</guid>
      <pubDate>Mon, 08 Jun 2026 12:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[npm ws Security: Fixing the CVE-2024-37890 WebSocket DoS]]></title>
      <description><![CDATA[The npm ws package powers most Node WebSocket servers. CVE-2024-37890 let a flood of request headers crash it. Here is how the flaw works and how to patch.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-ws</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-ws</guid>
      <pubDate>Mon, 08 Jun 2026 11:39:29 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How the --policy-path option centralizes ignore rules acr...]]></title>
      <description><![CDATA[A technical look at how Snyk's --policy-path flag lets teams share one .snyk ignore file across repos instead of duplicating exceptions everywhere.]]></description>
      <link>https://safeguard.sh/resources/blog/how-the-policy-path-option-centralizes-ignore-rules-across-multiple-projects</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-the-policy-path-option-centralizes-ignore-rules-across-multiple-projects</guid>
      <pubDate>Mon, 08 Jun 2026 10:19:02 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Sonatype Trust Center and Security Program Overview]]></title>
      <description><![CDATA[Sonatype's trust center offers compliance snapshots on request. Safeguard compares that model to continuous, evidence-based supply chain verification.]]></description>
      <link>https://safeguard.sh/resources/blog/sonatype-trust-center-and-security-program-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonatype-trust-center-and-security-program-overview</guid>
      <pubDate>Mon, 08 Jun 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk continuously monitors production dependencies fo...]]></title>
      <description><![CDATA[A technical walkthrough of how Snyk's continuous monitoring uses dependency snapshots, vuln-DB updates, and priority scoring to flag newly disclosed CVEs in production.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-continuously-monitors-production-dependencies-for-newly-disclosed-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-continuously-monitors-production-dependencies-for-newly-disclosed-vulnerabilities</guid>
      <pubDate>Mon, 08 Jun 2026 08:58:36 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's CLI test command differs technically from the ...]]></title>
      <description><![CDATA[A technical breakdown of how Snyk's snyk test and snyk monitor commands differ mechanically — exit codes, dependency snapshots, and continuous vulnerability tracking.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-cli-test-command-differs-technically-from-the-monitor-command</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-cli-test-command-differs-technically-from-the-monitor-command</guid>
      <pubDate>Mon, 08 Jun 2026 07:38:09 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Data poisoning attacks against LLMs]]></title>
      <description><![CDATA[A $60 domain purchase or 250 documents can backdoor an LLM. Here's how data poisoning attacks work, real cases, and how to defend against them.]]></description>
      <link>https://safeguard.sh/resources/blog/data-poisoning-attacks-against-llms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/data-poisoning-attacks-against-llms</guid>
      <pubDate>Mon, 08 Jun 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's private package registry scanning supports Art...]]></title>
      <description><![CDATA[How Snyk private registry package scanning connects to Artifactory and Nexus, from Docker Registry API calls to Broker-relayed authentication behind the firewall.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-private-package-registry-scanning-supports-artifactory-and-nexus-hosted-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-private-package-registry-scanning-supports-artifactory-and-nexus-hosted-packages</guid>
      <pubDate>Mon, 08 Jun 2026 06:17:42 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Compare Sonatype / Why Choose Sonatype]]></title>
      <description><![CDATA[Comparing Safeguard and Sonatype on origin, CVE-vs-malicious-package coverage, AI-agent (MCP) support, and CI/CD fit — a practical guide to Sonatype alternatives.]]></description>
      <link>https://safeguard.sh/resources/blog/compare-sonatype-why-choose-sonatype</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/compare-sonatype-why-choose-sonatype</guid>
      <pubDate>Mon, 08 Jun 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[jest-environment-jsdom: Setup, Gotchas, and Supply Chain Notes]]></title>
      <description><![CDATA[Setting up npm jest-environment-jsdom correctly, why it stopped shipping with Jest, and what its jsdom dependency tree means for your test toolchain's security.]]></description>
      <link>https://safeguard.sh/resources/blog/jest-environment-jsdom-setup-and-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jest-environment-jsdom-setup-and-security</guid>
      <pubDate>Mon, 08 Jun 2026 04:57:16 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Securing RAG pipelines against injection attacks]]></title>
      <description><![CDATA[RAG pipelines feed untrusted retrieved content straight into model context. Real breaches like EchoLeak show what happens when nothing checks it.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-rag-pipelines-against-injection-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-rag-pipelines-against-injection-attacks</guid>
      <pubDate>Mon, 08 Jun 2026 04:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[react-native-flash-message: A Security Guide]]></title>
      <description><![CDATA[The react-native-flash-message package is a popular but no-longer-maintained notification library. Here is what its inactive status means for your app's security.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-flash-message</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-flash-message</guid>
      <pubDate>Mon, 08 Jun 2026 03:36:49 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Sonatype Lifecycle (SCA + Repository Firewall) Deep Dive]]></title>
      <description><![CDATA[A concrete look at how Safeguard compares to Sonatype Lifecycle on deployment architecture, vulnerability data sourcing, and CI/CD fit for teams evaluating alternatives.]]></description>
      <link>https://safeguard.sh/resources/blog/sonatype-lifecycle-sca-repository-firewall-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonatype-lifecycle-sca-repository-firewall-deep-dive</guid>
      <pubDate>Mon, 08 Jun 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Java Supply Chain Security Beyond Log4Shell]]></title>
      <description><![CDATA[Log4Shell was the fire drill. The structural problems — unverified Maven resolution, invisible shaded jars, sprawling transitive graphs — are still there. Here's what to actually fix.]]></description>
      <link>https://safeguard.sh/resources/blog/java-supply-chain-security-beyond-log4shell</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-supply-chain-security-beyond-log4shell</guid>
      <pubDate>Mon, 08 Jun 2026 02:16:22 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Type-level security: the future of secure AI code generation]]></title>
      <description><![CDATA[45% of AI-generated code fails basic security tests. Here's why type systems catch what code review misses, and how to enforce type-level security on AI-authored diffs.]]></description>
      <link>https://safeguard.sh/resources/blog/type-level-security-the-future-of-secure-ai-code-generation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/type-level-security-the-future-of-secure-ai-code-generation</guid>
      <pubDate>Mon, 08 Jun 2026 01:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx Documentation: A Guide to Navigating It]]></title>
      <description><![CDATA[Checkmarx documentation is deep but sprawling. Here is how to find what you need across SAST, the APIs, and integrations without losing an afternoon.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-documentation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-documentation</guid>
      <pubDate>Mon, 08 Jun 2026 00:55:56 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Sonatype Nexus Repository Manager Alternatives]]></title>
      <description><![CDATA[Evaluating Nexus Repository Manager alternatives? A concrete look at reachability analysis, scanner fusion, auto-fix, and AI/MCP governance versus Sonatype.]]></description>
      <link>https://safeguard.sh/resources/blog/sonatype-nexus-repository-manager-alternatives</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonatype-nexus-repository-manager-alternatives</guid>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Makes a Strong Application Security Solution]]></title>
      <description><![CDATA[An application security solution is not a single scanner but a coordinated set of controls across the software lifecycle. Here is what a real one covers.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-solution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-solution</guid>
      <pubDate>Sun, 07 Jun 2026 23:35:29 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-9074 in Docker Desktop: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[Docker Desktop container-to-host escape scored CVSS 9.3. Affected Windows and macOS developer fleets need a fast patch rollout. Defender playbook below.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-desktop-cve-2025-9074-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-desktop-cve-2025-9074-patch-response</guid>
      <pubDate>Sun, 07 Jun 2026 22:15:02 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Shared Responsibility Model in Cloud Security, Explained]]></title>
      <description><![CDATA[The shared responsibility model cloud providers publish decides who secures what — and misreading the boundary is behind most cloud breaches. Here is how the split really works across IaaS, PaaS, and SaaS.]]></description>
      <link>https://safeguard.sh/resources/blog/shared-responsibility-model-cloud-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shared-responsibility-model-cloud-explained</guid>
      <pubDate>Sun, 07 Jun 2026 20:54:36 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[DevOps Maturity Models, Explained]]></title>
      <description><![CDATA[What a devops maturity model actually measures, why devops mttr alone is a weak proxy for maturity, and how teams can measure whether devops delivery value is improving.]]></description>
      <link>https://safeguard.sh/resources/blog/devops-maturity-models-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devops-maturity-models-explained</guid>
      <pubDate>Sun, 07 Jun 2026 19:34:09 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[XStream Deserialization Vulnerabilities: What You Need to Know]]></title>
      <description><![CDATA[XStream, the popular Java XML serialization library, has a long history of deserialization vulnerabilities that lead to remote code execution when it processes untrusted input — here's what changed and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/xstream-deserialization-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xstream-deserialization-vulnerabilities-explained</guid>
      <pubDate>Sun, 07 Jun 2026 18:13:42 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk resolves CocoaPods and Swift Package Manager dep...]]></title>
      <description><![CDATA[How Snyk parses Podfile.lock for CocoaPods and invokes the Swift toolchain to resolve Swift Package Manager dependencies when scanning iOS codebases.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-resolves-cocoapods-and-swift-package-manager-dependencies-for-ios-projects</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-resolves-cocoapods-and-swift-package-manager-dependencies-for-ios-projects</guid>
      <pubDate>Sun, 07 Jun 2026 16:53:15 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk AI-BOM discovers agents, tools, models, and data...]]></title>
      <description><![CDATA[How Snyk AI-BOM's static analysis engine discovers agents, tools, models, datasets, and MCP servers hiding in code, even without a manifest file.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-ai-bom-discovers-agents-tools-models-and-datasets-in-a-codebase</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-ai-bom-discovers-agents-tools-models-and-datasets-in-a-codebase</guid>
      <pubDate>Sun, 07 Jun 2026 15:32:49 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk AI-BOM detects MCP servers connected to an appli...]]></title>
      <description><![CDATA[A technical look at how Snyk's AI-BOM statically detects MCP client-server connections in source code, what CycloneDX data it captures, and where its coverage stops.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-ai-bom-detects-mcp-servers-connected-to-an-application</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-ai-bom-detects-mcp-servers-connected-to-an-application</guid>
      <pubDate>Sun, 07 Jun 2026 14:12:22 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Why postinstall Scripts Became the Frontline of the Software Supply Chain Attack]]></title>
      <description><![CDATA[Install-time script execution turned npm install and pip install into code-execution events. Here is how 2026's wave of attacks works, and the lockfile, allowlist, and sandbox discipline that actually stops it.]]></description>
      <link>https://safeguard.sh/resources/blog/postinstall-script-attacks-package-managers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/postinstall-script-attacks-package-managers</guid>
      <pubDate>Sun, 07 Jun 2026 13:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk AI-BOM generates a CycloneDX v1.6-compliant ML-BOM]]></title>
      <description><![CDATA[How Snyk's aibom CLI uses static analysis to detect models, agents, and MCP servers, then maps them into a CycloneDX v1.6-compliant ML-BOM structure.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-ai-bom-generates-a-cyclonedx-v16-compliant-ml-bom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-ai-bom-generates-a-cyclonedx-v16-compliant-ml-bom</guid>
      <pubDate>Sun, 07 Jun 2026 12:51:55 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Best CNAPP Platforms in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[An honest, opinionated guide to the best CNAPP platforms in 2026 — Wiz, Prisma Cloud, Microsoft Defender for Cloud, CrowdStrike, Aqua, Orca, and Sysdig — plus where the cloud-native security category is heading on AI-SPM, runtime, and supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/best-cnapp-platforms-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-cnapp-platforms-2026</guid>
      <pubDate>Sun, 07 Jun 2026 12:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Target URL? Definition and Security Implications]]></title>
      <description><![CDATA[A target URL is the destination address a request, scan, or link is aimed at. Here is what the term means across different contexts and why getting it right matters for security testing and web safety.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-target-url</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-target-url</guid>
      <pubDate>Sun, 07 Jun 2026 11:31:29 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Multer on npm: Security Review and the 2025 DoS Fixes]]></title>
      <description><![CDATA[Multer had a run of denial-of-service advisories through 2025. Here is what each one was, which version fixes them, and how to use the npm package safely.]]></description>
      <link>https://safeguard.sh/resources/blog/multer-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multer-npm</guid>
      <pubDate>Sun, 07 Jun 2026 10:11:02 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[NVD in the AI era: multi-source vulnerability intelligence]]></title>
      <description><![CDATA[NVD's 2024 enrichment backlog exposed the risk of a single vulnerability feed. Here's how multi-source data and AI triage close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/nvd-in-the-ai-era-multi-source-vulnerability-intelligence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nvd-in-the-ai-era-multi-source-vulnerability-intelligence</guid>
      <pubDate>Sun, 07 Jun 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Forrester Wave methodology for SCA vendor evaluation (not...]]></title>
      <description><![CDATA[A buyer's guide to reading Forrester Wave reports for SCA critically, plus two verifiable dimensions — deployment architecture and vulnerability data — comparing Safeguard and Sonatype.]]></description>
      <link>https://safeguard.sh/resources/blog/forrester-wave-leadership-claim-for-sca</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/forrester-wave-leadership-claim-for-sca</guid>
      <pubDate>Sun, 07 Jun 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Add Reachability Analysis to PR Checks]]></title>
      <description><![CDATA[Run reachability analysis on every pull request to slash vulnerability false positives by 70%+, gate merges on exploitable findings, and keep devs focused.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-add-reachability-analysis-to-pr-checks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-add-reachability-analysis-to-pr-checks</guid>
      <pubDate>Sun, 07 Jun 2026 08:50:35 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[DORA TLPT RTS: What the Threat-Led Penetration Testing Standard Requires]]></title>
      <description><![CDATA[The Commission published the DORA TLPT RTS on 18 June 2025 with direct effect from 8 July 2025. Tests are mandated every three years, aligned to TIBER-EU methodology.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-tlpt-rts-financial-entities-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-tlpt-rts-financial-entities-2025</guid>
      <pubDate>Sun, 07 Jun 2026 07:30:09 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Snyk VulnBench: benchmarking LLMs on repeat vulnerability discovery]]></title>
      <description><![CDATA[Snyk's VulnBench JS 1.0 ran 300 repeated LLM scans and found half of non-reference findings vanish on rerun—raising the bar for AI security tooling.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vulnbench-benchmarking-llms-on-repeat-vulnerability-discovery</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vulnbench-benchmarking-llms-on-repeat-vulnerability-discovery</guid>
      <pubDate>Sun, 07 Jun 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Test: How to Safely Check Your App for SQLi]]></title>
      <description><![CDATA[A SQL injection test proves whether user input can reach your database as code. Here is how to test your own applications responsibly, read the results, and fix what you find.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-test</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-test</guid>
      <pubDate>Sun, 07 Jun 2026 06:09:42 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to evaluate software supply chain security vendors us...]]></title>
      <description><![CDATA[A practical framework for evaluating software supply chain security vendors on verifiable dimensions—SBOM support, provenance, deployment model—rather than analyst labels alone.]]></description>
      <link>https://safeguard.sh/resources/blog/gartner-magic-quadrant-for-software-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gartner-magic-quadrant-for-software-supply-chain-security</guid>
      <pubDate>Sun, 07 Jun 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[jose npm: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[The jose npm package is a well-regarded library for JWT, JWS, and JWE across JavaScript runtimes. It gives you the right primitives; using them securely still comes down to how you verify tokens.]]></description>
      <link>https://safeguard.sh/resources/blog/jose-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jose-npm</guid>
      <pubDate>Sun, 07 Jun 2026 04:49:15 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Protestware via prompt injection: the jqwik 1.10.0 case]]></title>
      <description><![CDATA[jqwik 1.10.0 hid a prompt injection telling AI coding agents to delete tests. Here's how it worked, why it's protestware, and how to catch it.]]></description>
      <link>https://safeguard.sh/resources/blog/protestware-via-prompt-injection-the-jqwik-1100-case</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/protestware-via-prompt-injection-the-jqwik-1100-case</guid>
      <pubDate>Sun, 07 Jun 2026 04:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk AI-BOM's continuous refresh model differs from a...]]></title>
      <description><![CDATA[How Snyk's AI-BOM keeps model and dataset inventories current through continuous refresh, and why that differs mechanically from a point-in-time static SBOM export.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-ai-boms-continuous-refresh-model-differs-from-a-static-sbom-snapshot</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-ai-boms-continuous-refresh-model-differs-from-a-static-sbom-snapshot</guid>
      <pubDate>Sun, 07 Jun 2026 03:28:49 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AI Is Forcing a New Open Source Security Model]]></title>
      <description><![CDATA[AI coding agents now choose dependencies — and attackers are exploiting hallucinated packages and MCP backdoors that legacy SCA tools like Sonatype's were never built to catch.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-is-forcing-a-new-open-source-security-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-is-forcing-a-new-open-source-security-model</guid>
      <pubDate>Sun, 07 Jun 2026 03:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk AI-BOM surfaces shadow AI usage that security te...]]></title>
      <description><![CDATA[How Snyk's AI-BOM uses code-level analysis, not manifest parsing, to surface shadow AI models, agent frameworks, and MCP servers security teams don't know are running.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-ai-bom-surfaces-shadow-ai-usage-that-security-teams-dont-know-about</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-ai-bom-surfaces-shadow-ai-usage-that-security-teams-dont-know-about</guid>
      <pubDate>Sun, 07 Jun 2026 02:08:22 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Governments banning AI models: security implications for teams]]></title>
      <description><![CDATA[Governments banned DeepSeek and other AI models in 2025 within days. Here's the security supply-chain risk teams face and how to find and fix it fast.]]></description>
      <link>https://safeguard.sh/resources/blog/governments-banning-ai-models-security-implications-for-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/governments-banning-ai-models-security-implications-for-teams</guid>
      <pubDate>Sun, 07 Jun 2026 01:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's AI-BOM API lets teams query AI component inven...]]></title>
      <description><![CDATA[How Snyk's AI-BOM API exposes AI model and dataset inventories as queryable, CycloneDX-aligned data teams can pull into CI, GRC, and asset tooling programmatically.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-ai-bom-api-lets-teams-query-ai-component-inventories-programmatically</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-ai-bom-api-lets-teams-query-ai-component-inventories-programmatically</guid>
      <pubDate>Sun, 07 Jun 2026 00:47:55 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis as the Missing Piece of SCA]]></title>
      <description><![CDATA[Most SCA-flagged vulnerabilities aren't exploitable. Here's why reachability analysis — not just dependency matching — is what separates real risk from noise, and where Sonatype falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-as-the-missing-piece-of-sca</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-as-the-missing-piece-of-sca</guid>
      <pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk AI-BOM's --html flag visualizes AI dependency an...]]></title>
      <description><![CDATA[How Snyk's snyk aibom --html flag turns CycloneDX AI-BOM data into an interactive graph of models, agents, tools, and MCP client-server-tool dependency chains.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-ai-boms-html-flag-visualizes-ai-dependency-and-agent-relationships</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-ai-boms-html-flag-visualizes-ai-dependency-and-agent-relationships</guid>
      <pubDate>Sat, 06 Jun 2026 23:27:28 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[OSS License Management: A Practical Guide for Engineering Teams]]></title>
      <description><![CDATA[OSS license management is the practice of tracking every open source license in your dependency tree and checking it against policy before it ships. Here is how to do it without slowing developers down.]]></description>
      <link>https://safeguard.sh/resources/blog/oss-license-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oss-license-management</guid>
      <pubDate>Sat, 06 Jun 2026 22:07:02 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Jobs: What a Career in Developer Security Looks Like]]></title>
      <description><![CDATA[Curious about Snyk jobs and roles in the developer-security space? Here is how the field is structured, the skills that get you hired, and what to expect.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-jobs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-jobs</guid>
      <pubDate>Sat, 06 Jun 2026 20:46:35 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-3331: How the WinSCP URL Handler RCE Works]]></title>
      <description><![CDATA[CVE-2021-3331 is a critical remote code execution flaw in WinSCP's URL handling before 5.17.10. Here is how a crafted link triggers it and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-3331</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-3331</guid>
      <pubDate>Sat, 06 Jun 2026 19:26:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[react-test-renderer: Deprecation, Risks, and What to Use Instead]]></title>
      <description><![CDATA[react-test-renderer is now deprecated and unmaintained as of React 19. Here is what that means for your test suite and how to migrate off it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/react-test-renderer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-test-renderer</guid>
      <pubDate>Sat, 06 Jun 2026 18:05:42 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP 20x KSIs: Compliance as Machine-Readable Evidence]]></title>
      <description><![CDATA[FedRAMP 20x, launched March 2025, replaces document-heavy authorization with 56-61 Key Security Indicators submitted as OSCAL. Here is what cloud providers must actually automate.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-20x-key-security-indicators-oscal-automation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-20x-key-security-indicators-oscal-automation</guid>
      <pubDate>Sat, 06 Jun 2026 16:45:15 GMT</pubDate>
      <category>Frameworks</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[ZAP Security Testing: Using OWASP ZAP in Your Pipeline]]></title>
      <description><![CDATA[ZAP security testing works best as a pipeline stage, not a desktop tool. Docker scan modes, authentication, alert filters, and the CI wiring that makes findings stick.]]></description>
      <link>https://safeguard.sh/resources/blog/zap-security-testing-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zap-security-testing-guide</guid>
      <pubDate>Sat, 06 Jun 2026 15:24:48 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Python Syntax Checker: Catching Errors Before They Ship]]></title>
      <description><![CDATA[A Python syntax checker validates that your code parses and follows the rules of the language before you run it. Here are the tools that do it and how they fit a secure pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/python-syntax-checker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-syntax-checker</guid>
      <pubDate>Sat, 06 Jun 2026 14:04:22 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[After the Worms: A CI/CD Security Playbook for Developer Credentials in 2026]]></title>
      <description><![CDATA[The 2026 npm and PyPI worms proved that a trusted release pipeline is a credential vault. Here is what IronWorm and Mini Shai-Hulud actually exploited, and how to harden CI/CD before the next one lands.]]></description>
      <link>https://safeguard.sh/resources/blog/defending-cicd-developer-credentials-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/defending-cicd-developer-credentials-2026</guid>
      <pubDate>Sat, 06 Jun 2026 13:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Agentic AI Security Took Center Stage: The OWASP GenAI Summit at Infosecurity Europe 2026]]></title>
      <description><![CDATA[OWASP's first dedicated GenAI Security Summit at Infosecurity Europe put agentic AI security front and center, unveiling an Agentic Research Council and a maturity framework. Here's what actually mattered.]]></description>
      <link>https://safeguard.sh/resources/blog/infosecurity-europe-2026-owasp-genai-summit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/infosecurity-europe-2026-owasp-genai-summit</guid>
      <pubDate>Sat, 06 Jun 2026 13:00:00 GMT</pubDate>
      <category>Industry Events</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVSS Full Form: What Does CVSS Stand For?]]></title>
      <description><![CDATA[The CVSS full form is Common Vulnerability Scoring System. Here is what the acronym means, how the 0-10 score is built, and how to use it without treating the number as gospel.]]></description>
      <link>https://safeguard.sh/resources/blog/cvss-full-form</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cvss-full-form</guid>
      <pubDate>Sat, 06 Jun 2026 12:43:55 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best DAST Tools in 2026: Web, API, and CI/CD Scanning Compared]]></title>
      <description><![CDATA[An honest guide to the best DAST tools in 2026 — from OWASP ZAP and Burp Suite to Invicti, StackHawk, and Escape — with clear guidance on which fits web apps, APIs, and CI/CD-native pipelines, and where DAST stops and supply chain security begins.]]></description>
      <link>https://safeguard.sh/resources/blog/best-dast-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-dast-tools-2026</guid>
      <pubDate>Sat, 06 Jun 2026 12:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Choosing a Python Tool for Security: Scanning and Hardening Python Code]]></title>
      <description><![CDATA[The right Python tool depends on what you are trying to catch: bugs in your own code, vulnerable dependencies, or leaked secrets. Here is how the categories fit together.]]></description>
      <link>https://safeguard.sh/resources/blog/python-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-tool</guid>
      <pubDate>Sat, 06 Jun 2026 11:23:28 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Scanning: A Quick Reference]]></title>
      <description><![CDATA[A fast reference for what a vuln scan actually checks, the different scan types, and how often each should run — for engineers who need the answer, not the textbook.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-scanning-quick-reference</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-scanning-quick-reference</guid>
      <pubDate>Sat, 06 Jun 2026 10:03:02 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Building trust in AI-assisted software development]]></title>
      <description><![CDATA[AI writes 30-50% of new code at many shops now, and 45% of it ships with security flaws. Here's how to build real trust in that pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/building-trust-in-ai-assisted-software-development</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-trust-in-ai-assisted-software-development</guid>
      <pubDate>Sat, 06 Jun 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Prioritization in the AI Era]]></title>
      <description><![CDATA[CVSS scores can't keep pace with AI-generated code and 40,000+ annual CVEs. Here's why Sonatype's component-level model falls short and what real prioritization requires.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-prioritization-in-the-ai-era</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-prioritization-in-the-ai-era</guid>
      <pubDate>Sat, 06 Jun 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[react-hook-form npm: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[The react-hook-form npm package is a dependency-free form library with a clean security record. The risk is not the library itself but how you validate and handle the data it collects.]]></description>
      <link>https://safeguard.sh/resources/blog/react-hook-form-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-hook-form-npm</guid>
      <pubDate>Sat, 06 Jun 2026 08:42:35 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Can a DevOps Team Take Advantage of Artificial Intelligence?]]></title>
      <description><![CDATA[A DevOps team takes advantage of artificial intelligence by using it where signal is buried in noise — triaging alerts, prioritizing vulnerabilities, and drafting fixes. Here is where it pays off and where it does not.]]></description>
      <link>https://safeguard.sh/resources/blog/how-can-a-devops-team-take-advantage-of-artificial-intelligence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-can-a-devops-team-take-advantage-of-artificial-intelligence</guid>
      <pubDate>Sat, 06 Jun 2026 07:22:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Cursor's AI security agents: what they get right and what's missing]]></title>
      <description><![CDATA[Cursor's Bugbot and MCP agents catch real bugs, but CurXecute and MCPoison show they open new attack surfaces SCA tools never had to face.]]></description>
      <link>https://safeguard.sh/resources/blog/cursors-ai-security-agents-what-they-get-right-and-whats-missing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cursors-ai-security-agents-what-they-get-right-and-whats-missing</guid>
      <pubDate>Sat, 06 Jun 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Source Code Security Scanning Programs That Scale]]></title>
      <description><![CDATA[A source code security scanning program that works for 20 repos usually breaks at 200 — here's how to design one that scales with the number of teams, not just the number of scans.]]></description>
      <link>https://safeguard.sh/resources/blog/source-code-security-scanning-programs-that-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/source-code-security-scanning-programs-that-scale</guid>
      <pubDate>Sat, 06 Jun 2026 06:01:41 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Software Dependency Cooldown Policies]]></title>
      <description><![CDATA[A dependency cooldown policy delays new package versions for a set window so the ecosystem can catch malicious releases before they reach your build pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/software-dependency-cooldown-policies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-dependency-cooldown-policies</guid>
      <pubDate>Sat, 06 Jun 2026 06:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Mobile Application Security Assessment: How It's Actually Done]]></title>
      <description><![CDATA[What a mobile application security assessment actually involves, from static binary analysis through dynamic testing on real devices, and where it differs from a web app pen test.]]></description>
      <link>https://safeguard.sh/resources/blog/mobile-application-security-assessment-how-its-done</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mobile-application-security-assessment-how-its-done</guid>
      <pubDate>Sat, 06 Jun 2026 04:41:15 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Claude Code and Claude Desktop security integrations]]></title>
      <description><![CDATA[Claude Code's shell access and MCP's connector boom are reshaping software supply chain risk. Here's what security teams need to know and do.]]></description>
      <link>https://safeguard.sh/resources/blog/claude-code-and-claude-desktop-security-integrations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/claude-code-and-claude-desktop-security-integrations</guid>
      <pubDate>Sat, 06 Jun 2026 04:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk detects AI/ML-specific libraries during standard...]]></title>
      <description><![CDATA[Snyk's standard SCA treats AI/ML packages like any other dependency, while a separate AI-BOM tool adds static analysis to detect models, agents, and MCP connections.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-detects-aiml-specific-libraries-during-standard-sca-scans</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-detects-aiml-specific-libraries-during-standard-sca-scans</guid>
      <pubDate>Sat, 06 Jun 2026 03:20:48 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[From SBOMs to AI BOMs: SPDX 3.0 Explained]]></title>
      <description><![CDATA[SPDX 3.0 adds a formal AI profile for documenting ML models and datasets. Here's what changed, how it compares to CycloneDX, and why it matters now.]]></description>
      <link>https://safeguard.sh/resources/blog/from-sboms-to-ai-boms-spdx-30-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/from-sboms-to-ai-boms-spdx-30-explained</guid>
      <pubDate>Sat, 06 Jun 2026 03:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[DAST Software: Choosing a Dynamic Scanner for Your Stack]]></title>
      <description><![CDATA[The right DAST software depends less on brand name and more on whether it can authenticate into your app and understand your API's actual shape.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-software-choosing-a-dynamic-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-software-choosing-a-dynamic-scanner</guid>
      <pubDate>Sat, 06 Jun 2026 02:00:21 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Anthropic Claude Enterprise security features overview]]></title>
      <description><![CDATA[Claude Enterprise ships strong SSO, SCIM, audit logging, and SOC 2/ISO compliance — but its controls stop at the API boundary, leaving code and dependencies exposed.]]></description>
      <link>https://safeguard.sh/resources/blog/anthropic-claude-enterprise-security-features-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anthropic-claude-enterprise-security-features-overview</guid>
      <pubDate>Sat, 06 Jun 2026 01:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[DAST Scanners: How to Choose One for Your Stack]]></title>
      <description><![CDATA[A DAST scanner tests a running app the way an attacker would — but the options range from free crawlers to full authenticated-flow platforms. Here's how to pick.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-scanners-how-to-choose-one</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-scanners-how-to-choose-one</guid>
      <pubDate>Sat, 06 Jun 2026 00:39:55 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 and NIST Framework Alignment for Supply Chain V...]]></title>
      <description><![CDATA[How ISO 27001:2022 and NIST's SSDF, SP 800-161, and CSF 2.0 converge on software supply chain vendors—and where CVE-only scanning tools leave compliance gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-and-nist-framework-alignment-for-supply-chain-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-and-nist-framework-alignment-for-supply-chain-vendors</guid>
      <pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[fast-xml-parser on npm: Security Review and Safe Usage]]></title>
      <description><![CDATA[fast-xml-parser is one of the most-downloaded XML parsers on npm. Here is its security history, the CVEs that mattered, and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/fast-xml-parser-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fast-xml-parser-npm</guid>
      <pubDate>Fri, 05 Jun 2026 23:19:28 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[NIST SSDF PW.4: Reusing Well-Secured Software, Explained]]></title>
      <description><![CDATA[PW.4 is the SSDF practice that governs how you consume third-party and open-source components. Here is what its tasks actually ask for and how to satisfy them with evidence, not policy documents.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-ssdf-pw4-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-ssdf-pw4-explained</guid>
      <pubDate>Fri, 05 Jun 2026 21:59:01 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Java Cheatsheet: Lists, Sums, Random Strings, and Everyday Idioms]]></title>
      <description><![CDATA[A working cheatsheet for Java: modern list creation, summing collections with streams, generating random strings safely, string handling, and the idioms worth memorizing in 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/java-cheatsheet-common-operations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-cheatsheet-common-operations</guid>
      <pubDate>Fri, 05 Jun 2026 20:38:35 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Choosing a Software Composition Analysis Tool: A Practical Guide]]></title>
      <description><![CDATA[A software composition analysis tool inventories your open-source dependencies and flags the vulnerable ones. Here is how it differs from static code analysis and how to pick one.]]></description>
      <link>https://safeguard.sh/resources/blog/software-composition-analysis-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-composition-analysis-tool</guid>
      <pubDate>Fri, 05 Jun 2026 19:18:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk AI-BOM identifies prompt files and prompt-inject...]]></title>
      <description><![CDATA[How Snyk's AI-BOM tooling discovers prompt files, SKILL.md packages, and MCP tool chains, and the detection engine it uses to flag prompt-injection risk.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-ai-bom-identifies-prompt-files-and-prompt-injection-surface-area</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-ai-bom-identifies-prompt-files-and-prompt-injection-surface-area</guid>
      <pubDate>Fri, 05 Jun 2026 17:57:41 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk approaches securing AI-generated code from codin...]]></title>
      <description><![CDATA[A technical look at how Snyk's DeepCode AI engine, Agent Fix, and Snyk Studio MCP server scan and govern code from AI coding assistants like Claude Code and Cursor.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-approaches-securing-ai-generated-code-from-coding-assistants</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-approaches-securing-ai-generated-code-from-coding-assistants</guid>
      <pubDate>Fri, 05 Jun 2026 16:37:14 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's AI-SPM approach extends ASPM concepts to AI sy...]]></title>
      <description><![CDATA[How Snyk's Evo AI-SPM extends ASPM's discover-assess-enforce loop to models, datasets, and agents, based on its March 2026 GA launch and public documentation.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-ai-spm-approach-extends-aspm-concepts-to-ai-system-security-posture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-ai-spm-approach-extends-aspm-concepts-to-ai-system-security-posture</guid>
      <pubDate>Fri, 05 Jun 2026 15:16:48 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Runtime Threat Detection in Cloud-Native Environments]]></title>
      <description><![CDATA[Static analysis catches known vulnerabilities. Runtime detection catches exploitation. Here is how to implement runtime threat detection for containerized workloads.]]></description>
      <link>https://safeguard.sh/resources/blog/runtime-threat-detection-cloud-native</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runtime-threat-detection-cloud-native</guid>
      <pubDate>Fri, 05 Jun 2026 13:56:21 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Infosecurity Europe 2026 Recap: Agentic AI Security Owned the Floor at ExCeL London]]></title>
      <description><![CDATA[Agentic AI, post-quantum cryptography, and ransomware economics dominated Infosecurity Europe 2026. Here is what actually mattered on the floor at ExCeL London, and what was hype.]]></description>
      <link>https://safeguard.sh/resources/blog/infosecurity-europe-2026-recap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/infosecurity-europe-2026-recap</guid>
      <pubDate>Fri, 05 Jun 2026 13:00:00 GMT</pubDate>
      <category>Industry Events</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AI-Powered SOC, Dull Analysts: Fighting Skill Erosion Before 2030]]></title>
      <description><![CDATA[Gartner warns that by 2030 most SOC teams could lose foundational analysis skills to automation overdependence. Here is what skill erosion actually looks like, and the practices that keep human judgment sharp inside an AI-powered SOC.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-skill-erosion-automation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-skill-erosion-automation</guid>
      <pubDate>Fri, 05 Jun 2026 13:00:00 GMT</pubDate>
      <category>Strategy</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How the Snyk Language Server powers IDE plugins across VS...]]></title>
      <description><![CDATA[A technical look at how Snyk's Go-based Language Server uses LSP and a delegating scanner pattern to power VS Code, JetBrains, and Eclipse plugins from one binary.]]></description>
      <link>https://safeguard.sh/resources/blog/how-the-snyk-language-server-powers-ide-plugins-across-vs-code-jetbrains-and-eclipse</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-the-snyk-language-server-powers-ide-plugins-across-vs-code-jetbrains-and-eclipse</guid>
      <pubDate>Fri, 05 Jun 2026 12:35:54 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best SAST Tools in 2026: Semgrep, CodeQL, Snyk, and the AI Shift Compared]]></title>
      <description><![CDATA[An honest buyer's guide to the best SAST tools in 2026 — from Semgrep and CodeQL to SonarQube, Snyk Code, and Checkmarx — plus how reachability analysis and agentic AI are reshaping static application security testing and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/best-sast-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-sast-tools-2026</guid>
      <pubDate>Fri, 05 Jun 2026 12:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's JetBrains plugin family supports IntelliJ, PyC...]]></title>
      <description><![CDATA[A mechanical look at how Snyk ships one JetBrains plugin across IntelliJ, PyCharm, WebStorm, GoLand, and Rider using a shared platform and backend scan engine.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-jetbrains-plugin-family-supports-intellij-pycharm-webstorm-goland-and-rider</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-jetbrains-plugin-family-supports-intellij-pycharm-webstorm-goland-and-rider</guid>
      <pubDate>Fri, 05 Jun 2026 11:15:28 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Securing AI coding IDE extensions and plugins]]></title>
      <description><![CDATA[VS Code themes with 9M installs shipped backdoors; Cursor's rules files were hijacked in 2025. Here's what AI IDE extension security actually requires.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-ai-coding-ide-extensions-and-plugins</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-ai-coding-ide-extensions-and-plugins</guid>
      <pubDate>Fri, 05 Jun 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's Eclipse plugin integrates open source and code...]]></title>
      <description><![CDATA[A mechanical look at how Snyk's Eclipse plugin surfaces open source and code scan findings as native markers in the IDE's Problems view.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-eclipse-plugin-integrates-open-source-and-code-scanning-into-the-problems-view</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-eclipse-plugin-integrates-open-source-and-code-scanning-into-the-problems-view</guid>
      <pubDate>Fri, 05 Jun 2026 09:55:01 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Sonatype Firewall: Malicious Package Protection]]></title>
      <description><![CDATA[Sonatype's Repository Firewall blocks known malicious packages at the door, but timing gaps and single-source blind spots still let real threats through.]]></description>
      <link>https://safeguard.sh/resources/blog/sonatype-firewall-malicious-package-protection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonatype-firewall-malicious-package-protection</guid>
      <pubDate>Fri, 05 Jun 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's Visual Studio extension scans .NET solutions f...]]></title>
      <description><![CDATA[How Snyk's Visual Studio extension resolves .NET dependency trees, matches NuGet packages against its vulnerability database, and surfaces results in-editor.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-visual-studio-extension-scans-net-solutions-for-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-visual-studio-extension-scans-net-solutions-for-vulnerabilities</guid>
      <pubDate>Fri, 05 Jun 2026 08:34:34 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[superagent npm: Security Review and Safe HTTP Requests]]></title>
      <description><![CDATA[SuperAgent is a mature HTTP client for Node.js, but old versions carry prototype pollution and information-exposure flaws. Here is a practical security review.]]></description>
      <link>https://safeguard.sh/resources/blog/superagent-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/superagent-npm</guid>
      <pubDate>Fri, 05 Jun 2026 07:14:08 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[LLM output validation and sanitization best practices]]></title>
      <description><![CDATA[LLM output is untrusted input to everything downstream. Here's how to validate, encode, and sandbox it before it becomes your next injection vector.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-output-validation-and-sanitization-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-output-validation-and-sanitization-best-practices</guid>
      <pubDate>Fri, 05 Jun 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Sonatype SBOM Manager Overview]]></title>
      <description><![CDATA[A concrete look at Sonatype SBOM Manager — its origins, pricing model, VEX support, and common adoption gaps — for teams evaluating an SBOM manager tool.]]></description>
      <link>https://safeguard.sh/resources/blog/sonatype-sbom-manager-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonatype-sbom-manager-overview</guid>
      <pubDate>Fri, 05 Jun 2026 06:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Website Scanner: How It Works and What to Use]]></title>
      <description><![CDATA[A website scanner probes a live site for security flaws like injection, misconfiguration, and known CVEs. Here is how the different scanner types work and when each one fits.]]></description>
      <link>https://safeguard.sh/resources/blog/website-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/website-scanner</guid>
      <pubDate>Fri, 05 Jun 2026 05:53:41 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is Patch Latency]]></title>
      <description><![CDATA[Patch latency is the gap between a fix existing and the fix running in production. Here's how to measure it honestly, why it balloons, and how teams get it under 30 days.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-patch-latency</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-patch-latency</guid>
      <pubDate>Fri, 05 Jun 2026 04:33:14 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Marcus Webb)</author>
    </item>
    <item>
      <title><![CDATA[Zero-day risk in third-party AI model dependencies]]></title>
      <description><![CDATA[Malicious Hugging Face models, a trojanized Ultralytics PyPI release, and a torch.load bypass show AI model dependencies now carry real zero-day risk.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-day-risk-in-third-party-ai-model-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-day-risk-in-third-party-ai-model-dependencies</guid>
      <pubDate>Fri, 05 Jun 2026 04:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How the Snyk CLI's authentication flow issues and stores ...]]></title>
      <description><![CDATA[A technical walkthrough of how Snyk's CLI authenticates via `snyk auth`, where it stores API tokens locally, and why that plaintext credential file is worth protecting.]]></description>
      <link>https://safeguard.sh/resources/blog/how-the-snyk-clis-authentication-flow-issues-and-stores-api-tokens</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-the-snyk-clis-authentication-flow-issues-and-stores-api-tokens</guid>
      <pubDate>Fri, 05 Jun 2026 03:12:48 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Sonatype Guide: Securing Agentic AI Development]]></title>
      <description><![CDATA[Sonatype's new guide reframes AI dependency risk, but its scanner-based model can't govern agents that install packages and call MCP tools on their own. Here's the gap and how to close it.]]></description>
      <link>https://safeguard.sh/resources/blog/sonatype-guide-securing-agentic-ai-development</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonatype-guide-securing-agentic-ai-development</guid>
      <pubDate>Fri, 05 Jun 2026 03:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk CLI's --severity-threshold and --fail-on flags g...]]></title>
      <description><![CDATA[How Snyk CLI severity-threshold and fail-on flags filter and gate vulnerability findings, plus exit codes and common CI/CD misconfigurations.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-clis-severity-threshold-and-fail-on-flags-gate-cicd-pipelines</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-clis-severity-threshold-and-fail-on-flags-gate-cicd-pipelines</guid>
      <pubDate>Fri, 05 Jun 2026 01:52:21 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Mapping AI-generated code risks to the CWE Top 25]]></title>
      <description><![CDATA[45% of AI-generated code fails security tests. Here's how CWE Top 25 weaknesses like XSS, SQLi, and broken auth map to specific LLM coding habits.]]></description>
      <link>https://safeguard.sh/resources/blog/mapping-ai-generated-code-risks-to-the-cwe-top-25</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mapping-ai-generated-code-risks-to-the-cwe-top-25</guid>
      <pubDate>Fri, 05 Jun 2026 01:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How the Snyk CLI's JSON output format supports custom too...]]></title>
      <description><![CDATA[A technical look at how Snyk CLI's --json and --sarif output structure vulnerability data, its exit-code quirks, and the official tools that turn it into reports.]]></description>
      <link>https://safeguard.sh/resources/blog/how-the-snyk-clis-json-output-format-supports-custom-tooling-and-reporting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-the-snyk-clis-json-output-format-supports-custom-tooling-and-reporting</guid>
      <pubDate>Fri, 05 Jun 2026 00:31:54 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Open Source License Compliance Management]]></title>
      <description><![CDATA[Open source license compliance is now a continuous, automated discipline. Here's what Sonatype gets right, where it falls short, and how Safeguard unifies license risk with vulnerability management.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-license-compliance-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-license-compliance-management</guid>
      <pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How snyk-to-html converts CLI scan results into shareable...]]></title>
      <description><![CDATA[A technical look at how snyk-to-html converts Snyk CLI JSON scan output into shareable, self-contained HTML reports for CI pipelines and audits.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-to-html-converts-cli-scan-results-into-shareable-html-reports</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-to-html-converts-cli-scan-results-into-shareable-html-reports</guid>
      <pubDate>Thu, 04 Jun 2026 23:11:27 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How the Snyk CLI generates SARIF output for GitHub code s...]]></title>
      <description><![CDATA[A technical walkthrough of how the Snyk CLI serializes scan results into SARIF 2.1.0 and how GitHub code scanning ingests them into Security tab alerts.]]></description>
      <link>https://safeguard.sh/resources/blog/how-the-snyk-cli-generates-sarif-output-for-github-code-scanning-integration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-the-snyk-cli-generates-sarif-output-for-github-code-scanning-integration</guid>
      <pubDate>Thu, 04 Jun 2026 21:51:01 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's GitHub Actions integration scans pull requests...]]></title>
      <description><![CDATA[A mechanical breakdown of how Snyk's GitHub Actions integration scans pull requests: triggers, SARIF uploads, severity thresholds, and what the checks can't see.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-github-actions-integration-scans-pull-requests-automatically</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-github-actions-integration-scans-pull-requests-automatically</guid>
      <pubDate>Thu, 04 Jun 2026 20:30:34 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's GitLab CI/CD template integrates security gate...]]></title>
      <description><![CDATA[A technical look at how Snyk's GitLab CI/CD template authenticates, scans, and uses severity thresholds to block merge requests with known vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-gitlab-cicd-template-integrates-security-gates-into-pipelines</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-gitlab-cicd-template-integrates-security-gates-into-pipelines</guid>
      <pubDate>Thu, 04 Jun 2026 19:10:07 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk integrates with Jenkins to fail builds on new vu...]]></title>
      <description><![CDATA[A mechanical look at how the Snyk Jenkins plugin scans manifests, applies severity thresholds, and turns newly disclosed vulnerabilities into failed builds.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyk-integrates-with-jenkins-to-fail-builds-on-new-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyk-integrates-with-jenkins-to-fail-builds-on-new-vulnerabilities</guid>
      <pubDate>Thu, 04 Jun 2026 17:49:41 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[A Threat Modeling Example, Walked Through Step by Step]]></title>
      <description><![CDATA[A concrete threat modeling example beats any amount of theory. We model a real feature, a file-upload API, with STRIDE and turn the findings into fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/threat-modeling-example</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/threat-modeling-example</guid>
      <pubDate>Thu, 04 Jun 2026 16:29:14 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[EU NIS2 Directive: Enforcement at One Year]]></title>
      <description><![CDATA[Twelve months after the NIS2 transposition deadline, enforcement is uneven, fines are real, and software supply chain obligations are starting to bite.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-nis2-directive-enforcement-first-year</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-nis2-directive-enforcement-first-year</guid>
      <pubDate>Thu, 04 Jun 2026 15:08:47 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[eslint-import-resolver-typescript: A Security Guide]]></title>
      <description><![CDATA[eslint-import-resolver-typescript lives in your dev toolchain, which is precisely the part of the supply chain attackers now target. Here is how to keep it clean.]]></description>
      <link>https://safeguard.sh/resources/blog/eslint-import-resolver-typescript</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eslint-import-resolver-typescript</guid>
      <pubDate>Thu, 04 Jun 2026 13:48:21 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Gartner SRM Summit 2026 Recap: Agentic AI Security and the Post-Quantum Clock]]></title>
      <description><![CDATA[Gartner's Security & Risk Management Summit landed on four forces every security leader now has to navigate. Two of them — agentic AI security and the post-quantum world — dominated the room. Here's our honest read on what mattered.]]></description>
      <link>https://safeguard.sh/resources/blog/gartner-srm-2026-smarter-faster-stronger</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gartner-srm-2026-smarter-faster-stronger</guid>
      <pubDate>Thu, 04 Jun 2026 13:00:00 GMT</pubDate>
      <category>Industry Events</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's Azure Pipelines and Bitbucket Pipelines integr...]]></title>
      <description><![CDATA[Snyk's CLI, Azure Pipelines extension, and Bitbucket pipe handle auth, gating, and reporting differently — here's how each mechanism actually works under the hood.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-azure-pipelines-and-bitbucket-pipelines-integrations-differ-from-generic-cli-use</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-azure-pipelines-and-bitbucket-pipelines-integrations-differ-from-generic-cli-use</guid>
      <pubDate>Thu, 04 Jun 2026 12:27:54 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best Container Scanning Tools in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[An honest guide to the best container scanning tools in 2026 — from open-source scanners like Trivy and Grype to cloud-context platforms like Wiz and Aqua — with clear guidance on which fits your CI/CD pipeline, registry, and runtime.]]></description>
      <link>https://safeguard.sh/resources/blog/best-container-scanning-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-container-scanning-tools-2026</guid>
      <pubDate>Thu, 04 Jun 2026 12:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How the Snyk CLI's --all-projects flag discovers manifest...]]></title>
      <description><![CDATA[A technical look at how Snyk CLI's --all-projects flag walks a repository, matches manifest files, and where directory-depth limits can leave dependencies unscanned.]]></description>
      <link>https://safeguard.sh/resources/blog/how-the-snyk-clis-all-projects-flag-discovers-manifests-across-a-large-repository</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-the-snyk-clis-all-projects-flag-discovers-manifests-across-a-large-repository</guid>
      <pubDate>Thu, 04 Jun 2026 11:07:27 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[The Economics of Vulnerability Backlogs]]></title>
      <description><![CDATA[A vulnerability backlog is an inventory problem with interest payments. Triage costs, carrying costs, and why fixing by EPSS beats fixing by CVSS on pure ROI.]]></description>
      <link>https://safeguard.sh/resources/blog/the-economics-of-vulnerability-backlogs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-economics-of-vulnerability-backlogs</guid>
      <pubDate>Thu, 04 Jun 2026 11:00:00 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Aisha Bello)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Top 10 vulnerabilities explained]]></title>
      <description><![CDATA[A breakdown of all 10 OWASP Top 10 categories with real CVEs (Log4Shell, Equifax, Heartbleed) mapped to each, and stats on which risks hit production most.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-vulnerabilities-explained</guid>
      <pubDate>Thu, 04 Jun 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How the Snyk CLI handles proxy and air-gapped enterprise ...]]></title>
      <description><![CDATA[How the Snyk CLI actually handles corporate proxies, TLS-inspecting firewalls, and air-gapped network claims — based on Snyk's own documented configuration surface.]]></description>
      <link>https://safeguard.sh/resources/blog/how-the-snyk-cli-handles-proxy-and-air-gapped-enterprise-network-environments</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-the-snyk-cli-handles-proxy-and-air-gapped-enterprise-network-environments</guid>
      <pubDate>Thu, 04 Jun 2026 09:47:01 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Container Security for the Software Supply Chain]]></title>
      <description><![CDATA[Container scanning means more than SCA: OS layers, secrets, and provenance matter too. See the gaps in SCA-first tools and how Safeguard closes them.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-for-the-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-for-the-software-supply-chain</guid>
      <pubDate>Thu, 04 Jun 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How the Snyk CLI's exit codes are structured for CI/CD fa...]]></title>
      <description><![CDATA[A mechanical look at how the Snyk CLI's 0/1/2/3 exit codes work, how --severity-threshold and --fail-on change them, and how to branch on them correctly in CI/CD.]]></description>
      <link>https://safeguard.sh/resources/blog/how-the-snyk-clis-exit-codes-are-structured-for-cicd-failure-conditions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-the-snyk-clis-exit-codes-are-structured-for-cicd-failure-conditions</guid>
      <pubDate>Thu, 04 Jun 2026 08:26:34 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Code Vulnerability Scanning Tools: How to Choose the Right One]]></title>
      <description><![CDATA[Code vulnerability scanning tools fall into distinct categories that see different risks. Knowing which does what is the difference between coverage and false confidence.]]></description>
      <link>https://safeguard.sh/resources/blog/code-vulnerability-scanning-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-vulnerability-scanning-tools</guid>
      <pubDate>Thu, 04 Jun 2026 07:06:07 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[OWASP API Security Top 10 risks explained]]></title>
      <description><![CDATA[The OWASP API Security Top 10 ranks BOLA, broken auth, SSRF, and 7 more API risks behind breaches like Optus and T-Mobile — explained with real incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-api-security-top-10-risks-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-api-security-top-10-risks-explained</guid>
      <pubDate>Thu, 04 Jun 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[AI & LLM Governance for Software Development]]></title>
      <description><![CDATA[Sonatype flags bad packages after the fact. Here's what AI governance for software development requires, and how Safeguard tracks models and output together.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-llm-governance-for-software-development</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-llm-governance-for-software-development</guid>
      <pubDate>Thu, 04 Jun 2026 06:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Top 10 and XSS: Where Cross-Site Scripting Fits Now]]></title>
      <description><![CDATA[In the OWASP Top 10, XSS is no longer its own category. As of the 2021 list it lives inside A03: Injection. Here is what changed, why, and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-xss</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-xss</guid>
      <pubDate>Thu, 04 Jun 2026 05:45:40 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[GPLv2 vs GPLv3: A Practical Comparison for Developers]]></title>
      <description><![CDATA[The real differences between GPLv2 and GPLv3 that affect how you ship software: patents, tivoization, license compatibility, and the security angle.]]></description>
      <link>https://safeguard.sh/resources/blog/gpl-v2-vs-v3</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gpl-v2-vs-v3</guid>
      <pubDate>Thu, 04 Jun 2026 04:25:14 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Implementing the OWASP Top 10 Proactive Controls]]></title>
      <description><![CDATA[A field guide to the OWASP Top 10 Proactive Controls: what each control requires, real breach examples like Equifax, and how to implement them in CI/CD.]]></description>
      <link>https://safeguard.sh/resources/blog/implementing-the-owasp-top-10-proactive-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/implementing-the-owasp-top-10-proactive-controls</guid>
      <pubDate>Thu, 04 Jun 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[SFMC API Security: How to Integrate Marketing Cloud Safely]]></title>
      <description><![CDATA[A security-focused guide to the Salesforce Marketing Cloud (SFMC) API: OAuth scopes, token handling, least-privilege packages, and protecting subscriber data.]]></description>
      <link>https://safeguard.sh/resources/blog/sfmc-api</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sfmc-api</guid>
      <pubDate>Thu, 04 Jun 2026 03:04:47 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Shadow Risks: Unmanaged and Unauthorized Dependencies]]></title>
      <description><![CDATA[Shadow dependencies risk management is now core to SBOM strategy. See how unmanaged, unauthorized open source packages cause breaches Sonatype-style scans miss.]]></description>
      <link>https://safeguard.sh/resources/blog/shadow-risks-unmanaged-and-unauthorized-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shadow-risks-unmanaged-and-unauthorized-dependencies</guid>
      <pubDate>Thu, 04 Jun 2026 03:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Container Security Testing Methods, Compared]]></title>
      <description><![CDATA[Image scanning, runtime monitoring, and configuration auditing all count as container security testing, but they catch different things at different stages — here's how to combine them.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-testing-methods-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-testing-methods-compared</guid>
      <pubDate>Thu, 04 Jun 2026 01:44:20 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is SAST? Static Application Security Testing explained]]></title>
      <description><![CDATA[SAST scans source code for vulnerabilities before deployment. Learn how it works, where it fits vs. DAST/SCA, its false-positive limits, and 2026 tooling.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-sast-static-application-security-testing-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-sast-static-application-security-testing-explained</guid>
      <pubDate>Thu, 04 Jun 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Rate Limiting Vulnerability: Why Missing Limits Are an OWASP Risk]]></title>
      <description><![CDATA[A rate limiting vulnerability lets attackers hammer your endpoints unchecked, enabling brute force, credential stuffing, and resource exhaustion. Here is how to find and fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/rate-limiting-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rate-limiting-vulnerability</guid>
      <pubDate>Thu, 04 Jun 2026 00:23:54 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[InnerSource Practices for Enterprise Development]]></title>
      <description><![CDATA[InnerSource speeds up enterprise code reuse, but it also turns every internal team into an unaudited package publisher. Here's where governance breaks and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/innersource-practices-for-enterprise-development</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/innersource-practices-for-enterprise-development</guid>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[VAPT Services: What They Are and How to Choose One]]></title>
      <description><![CDATA[VAPT services combine vulnerability assessment with penetration testing to both find weaknesses and prove which ones are actually exploitable. Here is what to expect and what to ask for.]]></description>
      <link>https://safeguard.sh/resources/blog/vapt-services</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vapt-services</guid>
      <pubDate>Wed, 03 Jun 2026 23:03:27 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Using a Code Tester Safely: Online Playgrounds and the Risks]]></title>
      <description><![CDATA[An online code tester is a fast way to run a snippet without local setup, but pasting real code into someone else's server carries real risk. Here is how to test code online without leaking secrets.]]></description>
      <link>https://safeguard.sh/resources/blog/code-tester</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-tester</guid>
      <pubDate>Wed, 03 Jun 2026 21:43:00 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[GPL Adalah: What the GNU General Public License Means for Your Code]]></title>
      <description><![CDATA[GPL adalah lisensi copyleft yang paling terkenal. This guide explains what the GPL actually requires, why the copyleft obligation matters, and how it affects the code you ship.]]></description>
      <link>https://safeguard.sh/resources/blog/gpl-adalah</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gpl-adalah</guid>
      <pubDate>Wed, 03 Jun 2026 20:22:34 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[localStorage Security: Why You Shouldn't Keep Tokens There]]></title>
      <description><![CDATA[localStorage security comes down to one fact: any script on your page can read it. That makes it the wrong place for auth tokens and anything sensitive.]]></description>
      <link>https://safeguard.sh/resources/blog/localstorage-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/localstorage-security</guid>
      <pubDate>Wed, 03 Jun 2026 19:02:07 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[react-quill and Quill: XSS History and Safe Rich-Text Editing]]></title>
      <description><![CDATA[Using Quill in React means understanding CVE-2021-3163, the react-quill maintenance gap, and why editor output must always be sanitized server-side before display.]]></description>
      <link>https://safeguard.sh/resources/blog/react-quill-npm-xss-and-package-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-quill-npm-xss-and-package-review</guid>
      <pubDate>Wed, 03 Jun 2026 17:41:40 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Regex DDoS (ReDoS): How Catastrophic Backtracking Takes Down a Service]]></title>
      <description><![CDATA[A regex DDoS, or ReDoS, weaponizes a slow regular expression so a short input pins a CPU core for seconds or minutes. Here is why it happens and how to detect and fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/regex-ddos</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/regex-ddos</guid>
      <pubDate>Wed, 03 Jun 2026 16:21:14 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-34034 Explained: The Spring Security WebFlux Authorization Bypass]]></title>
      <description><![CDATA[CVE-2023-34034 lets attackers slip past Spring Security rules in WebFlux apps because of a wildcard-matching mismatch. Here is exactly what breaks, who is affected, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-34034</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-34034</guid>
      <pubDate>Wed, 03 Jun 2026 15:00:47 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Pod Security Context: A Practical Hardening Guide]]></title>
      <description><![CDATA[The Kubernetes pod security context controls the privileges your containers run with. Here is how to configure it, and how it relates to the retired PodSecurityPolicy.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-pod-security-context</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-pod-security-context</guid>
      <pubDate>Wed, 03 Jun 2026 13:40:20 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Shadow AI: Finding and Governing the Tools Your Employees Already Use]]></title>
      <description><![CDATA[Most of your organization is already using AI you never approved. Here is how to discover it, govern it, and offer sanctioned alternatives before it becomes a breach.]]></description>
      <link>https://safeguard.sh/resources/blog/shadow-ai-discovery-governance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shadow-ai-discovery-governance</guid>
      <pubDate>Wed, 03 Jun 2026 13:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Dynamic Application Security Testing Tools, Compared]]></title>
      <description><![CDATA[Dynamic application security testing tools test running applications the way an attacker would, but they differ sharply on API coverage, auth handling, and CI integration — here's how to tell them apart.]]></description>
      <link>https://safeguard.sh/resources/blog/dynamic-application-security-testing-tools-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dynamic-application-security-testing-tools-compared</guid>
      <pubDate>Wed, 03 Jun 2026 12:19:53 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Best SCA Tools in 2026: Software Composition Analysis Compared]]></title>
      <description><![CDATA[An honest comparison of the best SCA tools in 2026 — Snyk, Endor Labs, Socket, Mend, Sonatype, JFrog, Trivy, and Safeguard — covering reachability analysis, malicious-package detection, SBOM/AIBOM, and remediation, with a clear best-for line for each.]]></description>
      <link>https://safeguard.sh/resources/blog/best-sca-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-sca-tools-2026</guid>
      <pubDate>Wed, 03 Jun 2026 12:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Report Scanner: How Vulnerability Scan Reports Work]]></title>
      <description><![CDATA[A report scanner turns raw scan output into something a team can act on — deduplicated, prioritized, and mapped to owners — which is where most scanning programs actually stall.]]></description>
      <link>https://safeguard.sh/resources/blog/report-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/report-scanner</guid>
      <pubDate>Wed, 03 Jun 2026 10:59:27 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What is DAST? Dynamic Application Security Testing explained]]></title>
      <description><![CDATA[DAST tests running applications like an attacker would. Learn how it works, how it differs from SAST, and where it falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-dast-dynamic-application-security-testing-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-dast-dynamic-application-security-testing-explained</guid>
      <pubDate>Wed, 03 Jun 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[How Snyk's --project-tags and business-criticality flags ...]]></title>
      <description><![CDATA[How Snyk CLI's --project-tags and --project-business-criticality flags attach business context to scans, and why that context can drift out of date.]]></description>
      <link>https://safeguard.sh/resources/blog/how-snyks-project-tags-and-business-criticality-flags-enrich-cli-scan-context</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-snyks-project-tags-and-business-criticality-flags-enrich-cli-scan-context</guid>
      <pubDate>Wed, 03 Jun 2026 09:39:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Are AI Bills of Materials (AIBOMs)]]></title>
      <description><![CDATA[What is an AI Bill of Materials (AIBOM), why do SBOM tools like Sonatype fall short on AI components, and how do teams build one in 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/what-are-ai-bills-of-materials-aiboms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-are-ai-bills-of-materials-aiboms</guid>
      <pubDate>Wed, 03 Jun 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[DOM-Based XSS: Finding and Fixing Client-Side Injection]]></title>
      <description><![CDATA[DOM XSS never touches your server, so response scanners miss it. Here is how to trace sources to sinks in client code and shut the flaw down.]]></description>
      <link>https://safeguard.sh/resources/blog/dom-based-xss-finding-and-fixing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dom-based-xss-finding-and-fixing</guid>
      <pubDate>Wed, 03 Jun 2026 08:18:33 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is SCA? Software Composition Analysis explained]]></title>
      <description><![CDATA[SCA scans your open-source dependencies for known vulnerabilities and license risk. Here's what it checks, how it differs from SAST, and why reachability matters.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-sca-software-composition-analysis-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-sca-software-composition-analysis-explained</guid>
      <pubDate>Wed, 03 Jun 2026 07:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-43527: The NSS Heap Overflow Explained]]></title>
      <description><![CDATA[CVE-2021-43527 is a critical heap buffer overflow in Mozilla NSS that can lead to remote code execution when verifying certain digital signatures.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-43527</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-43527</guid>
      <pubDate>Wed, 03 Jun 2026 06:58:07 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Nginx 1.18.0 Vulnerabilities: Audit and Upgrade Path]]></title>
      <description><![CDATA[Nginx 1.18.0 left support in 2021, but not every scanner hit is exploitable — and many distro builds are already patched. How to audit what you actually run and get onto a supported line.]]></description>
      <link>https://safeguard.sh/resources/blog/nginx-1-18-0-vulnerabilities-upgrade-path</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nginx-1-18-0-vulnerabilities-upgrade-path</guid>
      <pubDate>Wed, 03 Jun 2026 05:37:40 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Cyber Security: The Fundamentals Teams Skip]]></title>
      <description><![CDATA[The cloud cyber security fundamentals teams reliably skip — identity sprawl, misconfigured storage, and compliance standards treated as a checkbox instead of a control.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-cyber-security-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-cyber-security-fundamentals</guid>
      <pubDate>Wed, 03 Jun 2026 04:17:13 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SAST vs DAST vs SCA: choosing the right tool]]></title>
      <description><![CDATA[SAST, DAST, and SCA each answer a different security question — here's what each catches, when to run them, and how to prioritize the flood of findings.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-vs-dast-vs-sca-choosing-the-right-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-vs-dast-vs-sca-choosing-the-right-tool</guid>
      <pubDate>Wed, 03 Jun 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What Is Open Source Malware]]></title>
      <description><![CDATA[Open source malware is code deliberately planted in packages to attack the systems that install it. Learn how it spreads, real incidents, and how it differs from CVEs.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-open-source-malware</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-open-source-malware</guid>
      <pubDate>Wed, 03 Jun 2026 03:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Devin's Sandbox: What the Autonomous Engineer Threat Model Looks Like]]></title>
      <description><![CDATA[Cognition's Devin executes engineering tasks autonomously in cloud sandboxes. We unpack the trust boundaries, the human checkpoints, and what defenders must require.]]></description>
      <link>https://safeguard.sh/resources/blog/devin-cognition-autonomous-engineer-blast-radius</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devin-cognition-autonomous-engineer-blast-radius</guid>
      <pubDate>Wed, 03 Jun 2026 02:56:47 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Why Transitive Dependencies Are the Blind Spot in Most Vu...]]></title>
      <description><![CDATA[Most vulnerability scans stop at direct dependencies, missing the 70-80% of your codebase that arrives transitively — where Log4Shell and other major CVEs actually hid.]]></description>
      <link>https://safeguard.sh/resources/blog/why-transitive-dependencies-are-the-blind-spot-in-most-vulnerability-scans</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-transitive-dependencies-are-the-blind-spot-in-most-vulnerability-scans</guid>
      <pubDate>Wed, 03 Jun 2026 01:36:20 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is a known vulnerability?]]></title>
      <description><![CDATA[A known vulnerability is a publicly disclosed, CVE-tracked flaw — and disclosure alone doesn't mean it's fixed, patched, or harmless.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-known-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-known-vulnerability</guid>
      <pubDate>Wed, 03 Jun 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[The Real Cost of Delayed Patching in Open Source Components]]></title>
      <description><![CDATA[Patches for open source flaws often exist for months before teams apply them. Here is what that patch lag actually costs in breaches, cleanup, and trust.]]></description>
      <link>https://safeguard.sh/resources/blog/the-real-cost-of-delayed-patching-in-open-source-components</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-real-cost-of-delayed-patching-in-open-source-components</guid>
      <pubDate>Wed, 03 Jun 2026 00:15:53 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[What Are Open Source Vulnerabilities]]></title>
      <description><![CDATA[Open source vulnerabilities explained: how flaws like Log4Shell and XZ Utils spread through dependency trees, how Sonatype tracks them, and how to prioritize fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/what-are-open-source-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-are-open-source-vulnerabilities</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[react-native-video-processing: Status, Risks, and Alternatives]]></title>
      <description><![CDATA[A security-minded look at react-native-video-processing: what the library does, its maintenance status, the native dependency risk, and what to use instead.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-video-processing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-video-processing</guid>
      <pubDate>Tue, 02 Jun 2026 22:55:26 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[form-data npm Package: Usage, Health, and Security Review]]></title>
      <description><![CDATA[The form-data npm package builds multipart request bodies for half the Node.js ecosystem — and its 2025 predictable-boundary CVE showed how a one-line randomness choice becomes an injection primitive.]]></description>
      <link>https://safeguard.sh/resources/blog/form-data-npm-package-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/form-data-npm-package-security-review</guid>
      <pubDate>Tue, 02 Jun 2026 21:35:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Local LLM Deployment: Enterprise Risks]]></title>
      <description><![CDATA[Running LLMs on local hardware eliminates some risks and introduces others. A clear-eyed look at the enterprise risk profile of on-premise and on-device model deployments.]]></description>
      <link>https://safeguard.sh/resources/blog/local-llm-deployment-enterprise-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/local-llm-deployment-enterprise-risks</guid>
      <pubDate>Tue, 02 Jun 2026 20:14:33 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[MCPoison (CVE-2025-54136): How Cursor's Trust Model Failed Open]]></title>
      <description><![CDATA[Check Point Research showed Cursor bound trust to MCP entry names, not contents. A swap-after-approval gave attackers persistent RCE on engineers' laptops.]]></description>
      <link>https://safeguard.sh/resources/blog/cursor-mcpoison-cve-2025-54136-trust-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cursor-mcpoison-cve-2025-54136-trust-bypass</guid>
      <pubDate>Tue, 02 Jun 2026 18:54:06 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Anubhav Verma)</author>
    </item>
    <item>
      <title><![CDATA[Is the ioredis npm Package Secure? A Practical Review]]></title>
      <description><![CDATA[The ioredis npm package is a solid, well-maintained Redis client, but most real risk lives in how you configure the connection rather than in the library code itself.]]></description>
      <link>https://safeguard.sh/resources/blog/ioredis-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ioredis-npm</guid>
      <pubDate>Tue, 02 Jun 2026 17:33:40 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Top 10 Certification: What It Actually Means]]></title>
      <description><![CDATA[There is no official OWASP Top 10 certification, but here is how to prove OWASP Top 10 competence, which credentials cover it, and how teams demonstrate coverage.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-certification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-certification</guid>
      <pubDate>Tue, 02 Jun 2026 16:13:13 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How Dependency Graphs Reveal Hidden Supply Chain Risk]]></title>
      <description><![CDATA[Dependency graph analysis reveals which transitive packages can actually reach your code. From Log4Shell to the xz backdoor, see why flat scans miss what graphs catch.]]></description>
      <link>https://safeguard.sh/resources/blog/how-dependency-graphs-reveal-hidden-supply-chain-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-dependency-graphs-reveal-hidden-supply-chain-risk</guid>
      <pubDate>Tue, 02 Jun 2026 14:52:46 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[DevOps Research and Assessment (DORA): The Four Metrics Explained]]></title>
      <description><![CDATA[DevOps Research and Assessment (DORA) distilled a decade of research into four metrics that predict software delivery performance — here's what they measure and how security work actually affects them.]]></description>
      <link>https://safeguard.sh/resources/blog/devops-research-and-assessment-dora-metrics-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devops-research-and-assessment-dora-metrics-explained</guid>
      <pubDate>Tue, 02 Jun 2026 13:32:20 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Agentic AI Security: Access Control Is the Whole Ballgame]]></title>
      <description><![CDATA[Gartner expects most successful attacks on AI agents through 2029 to exploit access control, with prompt injection as the delivery mechanism. Here is why that single failure mode dominates agentic AI security, and what actually moves the needle.]]></description>
      <link>https://safeguard.sh/resources/blog/agentic-ai-access-control-problem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agentic-ai-access-control-problem</guid>
      <pubDate>Tue, 02 Jun 2026 13:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[License Compliance Debt: The Quiet Risk Growing Alongside...]]></title>
      <description><![CDATA[Open source license debt is compounding as fast as CVE backlogs, but has no CVSS score, no patch, and no dashboard — until an audit, M&A deal, or lawsuit forces the issue.]]></description>
      <link>https://safeguard.sh/resources/blog/license-compliance-debt-the-quiet-risk-growing-alongside-cve-backlogs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/license-compliance-debt-the-quiet-risk-growing-alongside-cve-backlogs</guid>
      <pubDate>Tue, 02 Jun 2026 12:11:53 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Dependabot Alternatives in 2026: An Honest Buyer's Guide]]></title>
      <description><![CDATA[An honest guide to Dependabot alternatives in 2026 — Renovate, Snyk, Socket, Endor Labs, Mend, and Safeguard — covering dependency updates, reachability analysis, malicious-package detection, and software supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/dependabot-alternatives-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependabot-alternatives-2026</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Why 'Time to Fix' Is a Better Supply Chain Metric Than Vu...]]></title>
      <description><![CDATA[Vulnerability counts measure how hard you're looking, not how exposed you are. Here's why mean time to remediate is the metric that actually predicts breach risk.]]></description>
      <link>https://safeguard.sh/resources/blog/why-time-to-fix-is-a-better-supply-chain-metric-than-vulnerability-count</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-time-to-fix-is-a-better-supply-chain-metric-than-vulnerability-count</guid>
      <pubDate>Tue, 02 Jun 2026 10:51:26 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Understanding CVSS scoring for vulnerabilities]]></title>
      <description><![CDATA[CVSS scores run 0-10, but a 9.8 doesn't always mean patch tonight. Here's how base scores are calculated and why context beats the number.]]></description>
      <link>https://safeguard.sh/resources/blog/understanding-cvss-scoring-for-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/understanding-cvss-scoring-for-vulnerabilities</guid>
      <pubDate>Tue, 02 Jun 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The Long Tail of Abandoned Open Source Projects and Enter...]]></title>
      <description><![CDATA[Abandoned open source packages sit quietly in enterprise SBOMs until a burned-out maintainer, a hijacked account, or a patient attacker turns them into the next supply chain incident.]]></description>
      <link>https://safeguard.sh/resources/blog/the-long-tail-of-abandoned-open-source-projects-and-enterprise-exposure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-long-tail-of-abandoned-open-source-projects-and-enterprise-exposure</guid>
      <pubDate>Tue, 02 Jun 2026 09:31:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[API Security Posture Management, Explained]]></title>
      <description><![CDATA[API security posture management inventories every API you actually have, then continuously checks it against the rules you meant to enforce.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-posture-management-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-posture-management-explained</guid>
      <pubDate>Tue, 02 Jun 2026 09:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Management: Programs That Actually Work]]></title>
      <description><![CDATA[What separates an application security management program that actually reduces risk from one that just generates dashboards, based on where ownership and monitoring break down.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-management-programs-that-work</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-management-programs-that-work</guid>
      <pubDate>Tue, 02 Jun 2026 09:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Claude Code Security: A Practical Guide for Teams Adopting AI Coding Agents]]></title>
      <description><![CDATA[Claude Code can read your repo, run commands, and edit files — which is exactly why it needs the same security engineering as any privileged developer tool. Here's a practical hardening guide.]]></description>
      <link>https://safeguard.sh/resources/blog/claude-code-security-practical-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/claude-code-security-practical-guide</guid>
      <pubDate>Tue, 02 Jun 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is SLSA (Supply-chain Levels for Software Artifacts)]]></title>
      <description><![CDATA[SLSA verifies how software was built, not just what is inside it. Here is what the four build levels mean and how it differs from SBOM-only tooling.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-slsa-supply-chain-levels-for-software-artifacts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-slsa-supply-chain-levels-for-software-artifacts</guid>
      <pubDate>Tue, 02 Jun 2026 09:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Is Node.js Safe? A Security Guide]]></title>
      <description><![CDATA[Node.js itself is safe when kept current and configured well. Most real risk lives in your dependencies and your code, not the runtime.]]></description>
      <link>https://safeguard.sh/resources/blog/is-nodejs-safe</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/is-nodejs-safe</guid>
      <pubDate>Tue, 02 Jun 2026 08:10:33 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Best Container Base Images for Security in 2026]]></title>
      <description><![CDATA[Chainguard, distroless, Alpine, UBI micro, Ubuntu chiseled, and scratch, compared on CVE counts, size, libc, and the operational costs nobody puts in the marketing.]]></description>
      <link>https://safeguard.sh/resources/blog/best-container-base-images-for-security-in-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-container-base-images-for-security-in-2026</guid>
      <pubDate>Tue, 02 Jun 2026 08:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Elena Kovacs)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Malware News: What's Happening and How to Detect It]]></title>
      <description><![CDATA[PyPI malware news keeps repeating the same pattern — typosquats, compromised maintainer accounts, and post-install scripts that exfiltrate credentials — here's how to actually catch it.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-malware-news-and-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-malware-news-and-detection</guid>
      <pubDate>Tue, 02 Jun 2026 08:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Angular CDK: What Ships in @angular/cdk and Keeping It Current]]></title>
      <description><![CDATA[The angular cdk npm package is the behavior layer under Angular Material — overlays, a11y, drag-drop, virtual scroll. Knowing what is inside and how its versioning works keeps upgrades boring.]]></description>
      <link>https://safeguard.sh/resources/blog/angular-cdk-npm-package-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/angular-cdk-npm-package-guide</guid>
      <pubDate>Tue, 02 Jun 2026 06:50:06 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What Is Shift Left Security]]></title>
      <description><![CDATA[Shift left security moves scanning earlier in the SDLC. Here's what it means, how Sonatype approaches it, where it falls short, and how Safeguard closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-shift-left-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-shift-left-security</guid>
      <pubDate>Tue, 02 Jun 2026 06:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Monorepo vs Polyrepo: How Architecture Choices Shape Supp...]]></title>
      <description><![CDATA[Monorepos and polyrepos don't just shape build times — they shape blast radius, patch speed, and dependency visibility. Here's how each affects supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/monorepo-vs-polyrepo-how-architecture-choices-shape-supply-chain-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/monorepo-vs-polyrepo-how-architecture-choices-shape-supply-chain-risk</guid>
      <pubDate>Tue, 02 Jun 2026 05:29:39 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What a Decade of Open Source Vulnerability Data Tells Us ...]]></title>
      <description><![CDATA[CVEs grew sixfold in a decade. Here is what a decade of open source vulnerability trends reveals about ecosystem maturity, from Log4Shell to the xz backdoor.]]></description>
      <link>https://safeguard.sh/resources/blog/what-a-decade-of-open-source-vulnerability-data-tells-us-about-ecosystem-maturity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-a-decade-of-open-source-vulnerability-data-tells-us-about-ecosystem-maturity</guid>
      <pubDate>Tue, 02 Jun 2026 04:09:13 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[When is a CVE not a CVE?]]></title>
      <description><![CDATA[Not all CVEs are equal: NVD's 2024 backlog, disputed curl CVEs, and duplicate OpenSSL bugs show why CVE quality varies wildly.]]></description>
      <link>https://safeguard.sh/resources/blog/when-is-a-cve-not-a-cve</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/when-is-a-cve-not-a-cve</guid>
      <pubDate>Tue, 02 Jun 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What Is Post-Quantum Cryptography (for software supply ch...]]></title>
      <description><![CDATA[Quantum computers will eventually break RSA and ECDSA. Here's what NIST's 2024 PQC standards, CNSA 2.0 deadlines, and "harvest now, decrypt later" mean for signed software supply chains.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-post-quantum-cryptography-for-software-supply-chains</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-post-quantum-cryptography-for-software-supply-chains</guid>
      <pubDate>Tue, 02 Jun 2026 03:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Direct vs Transitive Vulnerabilities: Why the Distinction...]]></title>
      <description><![CDATA[Most CVEs in your stack aren't in packages you chose — they're transitive. Here's why direct vs transitive vulnerabilities need different fixes and different priority.]]></description>
      <link>https://safeguard.sh/resources/blog/direct-vs-transitive-vulnerabilities-why-the-distinction-matters-for-remediation-prioritization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/direct-vs-transitive-vulnerabilities-why-the-distinction-matters-for-remediation-prioritization</guid>
      <pubDate>Tue, 02 Jun 2026 02:48:46 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Package Manager Design Choices Influence Supply Chain...]]></title>
      <description><![CDATA[npm, PyPI, RubyGems, Go, and Cargo each made different design bets on install scripts, namespacing, and signing — and those bets directly shape supply chain attack surface.]]></description>
      <link>https://safeguard.sh/resources/blog/how-package-manager-design-choices-influence-supply-chain-attack-surface</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-package-manager-design-choices-influence-supply-chain-attack-surface</guid>
      <pubDate>Tue, 02 Jun 2026 01:28:19 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability vs weakness: CVE vs CWE explained]]></title>
      <description><![CDATA[CVE identifies one specific vulnerability; CWE identifies the weakness pattern behind it. Here's how the two taxonomies connect and why both matter.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-vs-weakness-cve-vs-cwe-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-vs-weakness-cve-vs-cwe-explained</guid>
      <pubDate>Tue, 02 Jun 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Maintainer Succession Planning: A Supply Chain Imperative]]></title>
      <description><![CDATA[When a solo maintainer disappears, entire dependency chains are at risk. How organizations should approach succession planning for critical open source projects.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-maintainer-succession-planning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-maintainer-succession-planning</guid>
      <pubDate>Tue, 02 Jun 2026 00:07:53 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What Is Perimeter Protection in Application Security]]></title>
      <description><![CDATA[Perimeter protection screens packages at the gate — but xz-utils, SolarWinds, and event-stream all slipped past firewalls. Here's what it catches, and what it misses.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-perimeter-protection-in-application-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-perimeter-protection-in-application-security</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Economics of Free Riding in Open Source Security]]></title>
      <description><![CDATA[Open source runs on unpaid labor while billion-dollar companies use it for free. Here's the economics behind Log4Shell, xz-utils, and the free rider problem.]]></description>
      <link>https://safeguard.sh/resources/blog/the-economics-of-free-riding-in-open-source-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-economics-of-free-riding-in-open-source-security</guid>
      <pubDate>Mon, 01 Jun 2026 22:47:26 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why Vulnerability Disclosure Timelines Still Vary Wildly ...]]></title>
      <description><![CDATA[Google gives vendors 90 days, ZDI gives 120, the EU wants 24 hours, and Linux had no CVE process until 2024. Here's why disclosure timelines diverge so sharply across ecosystems.]]></description>
      <link>https://safeguard.sh/resources/blog/why-vulnerability-disclosure-timelines-still-vary-wildly-across-ecosystems</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-vulnerability-disclosure-timelines-still-vary-wildly-across-ecosystems</guid>
      <pubDate>Mon, 01 Jun 2026 21:26:59 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[From Log4Shell to Now: What Changed and What Didn't in Su...]]></title>
      <description><![CDATA[Three years after Log4Shell, Log4j is still found in production systems. Here is what the industry fixed, what it didn't, and why the risk persists.]]></description>
      <link>https://safeguard.sh/resources/blog/from-log4shell-to-now-what-changed-and-what-didnt-in-supply-chain-defense</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/from-log4shell-to-now-what-changed-and-what-didnt-in-supply-chain-defense</guid>
      <pubDate>Mon, 01 Jun 2026 20:06:33 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[The Hidden Risk of Copy-Pasted Code Snippets from Forums ...]]></title>
      <description><![CDATA[Copy-pasted code from Stack Overflow and AI chats often ships with hidden vulnerabilities. Here's the data behind the risk, real breaches it caused, and how to catch it.]]></description>
      <link>https://safeguard.sh/resources/blog/the-hidden-risk-of-copy-pasted-code-snippets-from-forums-and-ai-chats</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-hidden-risk-of-copy-pasted-code-snippets-from-forums-and-ai-chats</guid>
      <pubDate>Mon, 01 Jun 2026 18:46:06 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Do Bug Bounties Actually Reduce Open Source Risk? An Inde...]]></title>
      <description><![CDATA[Bug bounties didn't catch Log4Shell or the XZ Utils backdoor. An independent look at what OSS bounty programs actually cover — and where they structurally fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/do-bug-bounties-actually-reduce-open-source-risk-an-independent-look</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/do-bug-bounties-actually-reduce-open-source-risk-an-independent-look</guid>
      <pubDate>Mon, 01 Jun 2026 17:25:39 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[The Confidence Gap: Why Developers Trust AI Code More Tha...]]></title>
      <description><![CDATA[Studies show developers trust AI-generated code more than human code, even though it's often less secure. Here's what's driving the AI code trust gap.]]></description>
      <link>https://safeguard.sh/resources/blog/the-confidence-gap-why-developers-trust-ai-code-more-than-they-should</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-confidence-gap-why-developers-trust-ai-code-more-than-they-should</guid>
      <pubDate>Mon, 01 Jun 2026 16:05:13 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Autocomplete Anxiety: Measuring How Often AI Coding Assis...]]></title>
      <description><![CDATA[Studies show 40-45% of AI-suggested code contains exploitable flaws, and models hallucinate fake packages developers install. Here's what the data says.]]></description>
      <link>https://safeguard.sh/resources/blog/autocomplete-anxiety-measuring-how-often-ai-coding-assistants-suggest-vulnerable-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/autocomplete-anxiety-measuring-how-often-ai-coding-assistants-suggest-vulnerable-patterns</guid>
      <pubDate>Mon, 01 Jun 2026 14:44:46 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why Scanning AI-Generated Code Requires Different Heurist...]]></title>
      <description><![CDATA[AI coding assistants write fast but fail differently than humans do. Learn why scanning AI-generated code needs new heuristics for hallucinated dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/why-scanning-ai-generated-code-requires-different-heuristics-than-human-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-scanning-ai-generated-code-requires-different-heuristics-than-human-code</guid>
      <pubDate>Mon, 01 Jun 2026 13:24:19 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Post-Quantum Cryptography in 2026: Where Enterprise Migration Actually Stands]]></title>
      <description><![CDATA[The NIST standards are final, the deadlines are real, and the harvest-now-decrypt-later clock is running. Here is an honest look at what enterprise PQC migration looks like in 2026 — and why crypto-agility matters more than picking an algorithm.]]></description>
      <link>https://safeguard.sh/resources/blog/post-quantum-cryptography-migration-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/post-quantum-cryptography-migration-2026</guid>
      <pubDate>Mon, 01 Jun 2026 13:00:00 GMT</pubDate>
      <category>Strategy</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Apache Tomcat and Coyote Connector Vulnerabilities Explained]]></title>
      <description><![CDATA[Apache tomcat vulnerabilities keep surfacing because Tomcat sits directly in the request path of so many Java applications; here is what the Coyote connector does and which vulnerability classes recur most.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-tomcat-and-coyote-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-tomcat-and-coyote-vulnerabilities-explained</guid>
      <pubDate>Mon, 01 Jun 2026 12:03:52 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Alternatives in 2026: 8 Options Compared]]></title>
      <description><![CDATA[An honest, opinionated guide to the best Snyk alternatives in 2026 — Endor Labs, Socket, Mend, Aikido, Semgrep, Sonatype, Trivy, and Safeguard — with a fair blurb and a 'best for' line for each, plus where reachability and remediation actually matter.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-alternatives-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-alternatives-2026</guid>
      <pubDate>Mon, 01 Jun 2026 12:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Binary SBOM Analysis: Creating Software Bills of Materials Without Source Code]]></title>
      <description><![CDATA[Not all software comes with source code. Binary analysis techniques can extract component information from compiled artifacts, firmware, and commercial software to produce SBOMs where traditional tools cannot.]]></description>
      <link>https://safeguard.sh/resources/blog/binary-sbom-analysis-reverse-engineering</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/binary-sbom-analysis-reverse-engineering</guid>
      <pubDate>Mon, 01 Jun 2026 10:43:26 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[The CWE Top 25 most dangerous software weaknesses]]></title>
      <description><![CDATA[MITRE's 2023 CWE Top 25 ranks the software weaknesses behind 43,996 CVEs. Here's how it's scored, what moved, and how to prioritize fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/the-cwe-top-25-most-dangerous-software-weaknesses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-cwe-top-25-most-dangerous-software-weaknesses</guid>
      <pubDate>Mon, 01 Jun 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The Prompt Injection Problem Hiding Inside Everyday Code ...]]></title>
      <description><![CDATA[AI coding assistants read untrusted files as instructions, not data. Here's how prompt injection sneaks malicious code into your commits — and how to catch it before it ships.]]></description>
      <link>https://safeguard.sh/resources/blog/the-prompt-injection-problem-hiding-inside-everyday-code-generation-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-prompt-injection-problem-hiding-inside-everyday-code-generation-tools</guid>
      <pubDate>Mon, 01 Jun 2026 09:22:59 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SAST vs DAST: static and dynamic application security tes...]]></title>
      <description><![CDATA[SAST catches insecure code before deploy; DAST tests running apps after. We compare both against JFrog's Artifactory-first model and Safeguard's supply-chain-native approach.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-vs-dast-static-and-dynamic-application-security-testing-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-vs-dast-static-and-dynamic-application-security-testing-compared</guid>
      <pubDate>Mon, 01 Jun 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How 'Vibe Coding' Culture Is Reshaping Application Securi...]]></title>
      <description><![CDATA[AI-assisted "vibe coding" is reshaping how much code ships and how little of it gets truly reviewed. Here's what the data shows and how AppSec teams should respond.]]></description>
      <link>https://safeguard.sh/resources/blog/how-vibe-coding-culture-is-reshaping-application-security-reviews</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-vibe-coding-culture-is-reshaping-application-security-reviews</guid>
      <pubDate>Mon, 01 Jun 2026 08:02:32 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to secure a REST API]]></title>
      <description><![CDATA[REST API breaches from T-Mobile to Optus trace to a handful of recurring mistakes. Here's how to fix authorization, auth, injection, and rate limiting.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-secure-a-rest-api</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-secure-a-rest-api</guid>
      <pubDate>Mon, 01 Jun 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Do Code Review Practices Need to Change When Half the Cod...]]></title>
      <description><![CDATA[AI now writes up to half of production code. Here is why traditional code review breaks down on AI output, and what teams need to change.]]></description>
      <link>https://safeguard.sh/resources/blog/do-code-review-practices-need-to-change-when-half-the-code-is-ai-written</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/do-code-review-practices-need-to-change-when-half-the-code-is-ai-written</guid>
      <pubDate>Mon, 01 Jun 2026 06:42:06 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[DevOps vs DevSecOps: what actually changes when you add s...]]></title>
      <description><![CDATA[DevOps vs DevSecOps isn't a mindset shift — it's specific new artifacts, gates, and ownership. Here's what changes, contrasted with JFrog's artifact-first model.]]></description>
      <link>https://safeguard.sh/resources/blog/devops-vs-devsecops-what-actually-changes-when-you-add-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devops-vs-devsecops-what-actually-changes-when-you-add-security</guid>
      <pubDate>Mon, 01 Jun 2026 06:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Missing Guardrails: Why So Few Teams Scan AI Suggesti...]]></title>
      <description><![CDATA[AI writes most new code, but few CI pipelines scan it before merge. Here's why the AI code scanning adoption gap exists — and what closes it.]]></description>
      <link>https://safeguard.sh/resources/blog/the-missing-guardrails-why-so-few-teams-scan-ai-suggestions-before-merge</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-missing-guardrails-why-so-few-teams-scan-ai-suggestions-before-merge</guid>
      <pubDate>Mon, 01 Jun 2026 05:21:39 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Code Guide Buzzardcoding: How to Read and Review Code for Security]]></title>
      <description><![CDATA[A good code guide teaches you to read code, not just write it. This walkthrough covers how to review code for the security flaws that automated tools and casual readers miss.]]></description>
      <link>https://safeguard.sh/resources/blog/code-guide-buzzardcoding</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-guide-buzzardcoding</guid>
      <pubDate>Mon, 01 Jun 2026 04:01:12 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability scanning tools and techniques compared]]></title>
      <description><![CDATA[A verifiable comparison of Safeguard and JFrog Xray on scan coverage, data sourcing, reachability analysis, and CI/CD integration for vulnerability scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-scanning-tools-and-techniques-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-scanning-tools-and-techniques-compared</guid>
      <pubDate>Mon, 01 Jun 2026 03:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[@angular-eslint/schematics: Is the Angular ESLint Setup Package Safe?]]></title>
      <description><![CDATA[A security review of @angular-eslint/schematics: what the package does, its install-time behavior, dependency footprint, and how to adopt it safely in an Angular workspace.]]></description>
      <link>https://safeguard.sh/resources/blog/angular-eslint-schematics</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/angular-eslint-schematics</guid>
      <pubDate>Mon, 01 Jun 2026 02:40:46 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[AWS Breach: How They Actually Happen and How to Prevent One]]></title>
      <description><![CDATA[Most AWS breaches are not AWS failing — they are misconfiguration, leaked keys, and over-privileged roles. Here is how the real ones unfolded and how to stop yours.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-breach</guid>
      <pubDate>Mon, 01 Jun 2026 01:20:19 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 Type II vs ISO 27001: what each certification actua...]]></title>
      <description><![CDATA[SOC 2 Type II and ISO 27001 certify different things to different audiences. Here's what each actually covers, and how to evaluate supply chain vendors like JFrog and Safeguard on it.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-type-ii-vs-iso-27001-what-each-certification-actually-covers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-type-ii-vs-iso-27001-what-each-certification-actually-covers</guid>
      <pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Hallucinated Dependencies: How AI Models Invent Package N...]]></title>
      <description><![CDATA[AI coding assistants regularly invent package names that don't exist — and attackers are registering them first. Here's how slopsquatting works and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/hallucinated-dependencies-how-ai-models-invent-package-names-attackers-can-register</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hallucinated-dependencies-how-ai-models-invent-package-names-attackers-can-register</guid>
      <pubDate>Sun, 31 May 2026 23:59:52 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Model Training Data and the Propagation of Insecure Codin...]]></title>
      <description><![CDATA[LLM coding assistants inherit insecure patterns from their training data — from SQLi-prone snippets to hallucinated packages attackers exploit. Here's how the risk propagates.]]></description>
      <link>https://safeguard.sh/resources/blog/model-training-data-and-the-propagation-of-insecure-coding-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/model-training-data-and-the-propagation-of-insecure-coding-patterns</guid>
      <pubDate>Sun, 31 May 2026 22:39:26 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Why Policy Bypass Is Rising Even as AI Coding Tools Get '...]]></title>
      <description><![CDATA[AI coding assistants keep getting smarter, yet developer security policy bypasses keep rising. Here's why the two trends are linked and how to close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/why-policy-bypass-is-rising-even-as-ai-coding-tools-get-smarter</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-policy-bypass-is-rising-even-as-ai-coding-tools-get-smarter</guid>
      <pubDate>Sun, 31 May 2026 21:18:59 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Comparing Insecure Output Rates Across Popular AI Coding ...]]></title>
      <description><![CDATA[A benchmark-driven look at insecure output rates across GitHub Copilot, Cursor, Amazon Q, and Tabnine, and why the model matters more than the brand.]]></description>
      <link>https://safeguard.sh/resources/blog/comparing-insecure-output-rates-across-popular-ai-coding-assistants</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/comparing-insecure-output-rates-across-popular-ai-coding-assistants</guid>
      <pubDate>Sun, 31 May 2026 19:58:32 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Using Literal in Python: Type Safety for Fixed Values]]></title>
      <description><![CDATA[The Literal type in Python lets you constrain a value to a fixed set of options the type checker enforces. Here's how to use it well, and where it quietly improves security.]]></description>
      <link>https://safeguard.sh/resources/blog/literal-in-python</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/literal-in-python</guid>
      <pubDate>Sun, 31 May 2026 18:38:05 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Node.js Security News: Recent Advisories and How to Stay Ahead]]></title>
      <description><![CDATA[Node.js security news moves on a predictable cadence. Here is how to read the advisories, act on the ones that matter, and harden your apps.]]></description>
      <link>https://safeguard.sh/resources/blog/node-js-security-news</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-js-security-news</guid>
      <pubDate>Sun, 31 May 2026 17:17:39 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Define HIPAA: What the Law Actually Requires of Software Teams]]></title>
      <description><![CDATA[HIPAA gets invoked constantly and understood rarely. Here is a plain-English definition, the rules that matter for engineers, and where software supply chain fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/define-hipaa</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/define-hipaa</guid>
      <pubDate>Sun, 31 May 2026 15:57:12 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How a Source Code Security Scanner Works and Which One to Use]]></title>
      <description><![CDATA[A source code security scanner reads your code without running it to find injection, secrets, and logic flaws. Here is how the analysis works and how to pick one that fits.]]></description>
      <link>https://safeguard.sh/resources/blog/source-code-security-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/source-code-security-scanner</guid>
      <pubDate>Sun, 31 May 2026 14:36:45 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[The False Sense of Security Effect in AI-Assisted Develop...]]></title>
      <description><![CDATA[AI coding assistants make developers write faster and trust more — even when the code is less secure. Here's what the data shows, and how to close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/the-false-sense-of-security-effect-in-ai-assisted-development-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-false-sense-of-security-effect-in-ai-assisted-development-teams</guid>
      <pubDate>Sun, 31 May 2026 13:16:19 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The OWASP Top Ten Vulnerabilities, Explained]]></title>
      <description><![CDATA[The OWASP Top Ten vulnerabilities is the industry-standard list of the most critical web application security risks. Here is what the current 2025 edition covers and how to defend against each.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-ten-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-ten-vulnerabilities</guid>
      <pubDate>Sun, 31 May 2026 11:55:52 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Nginx Vulnerabilities: Tracking and Patching at Scale]]></title>
      <description><![CDATA[Nginx vulnerabilities are rare compared to application-layer bugs but high-impact when they land — here's how to track disclosures and patch fleets without breaking uptime.]]></description>
      <link>https://safeguard.sh/resources/blog/nginx-vulnerabilities-tracking-and-patching</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nginx-vulnerabilities-tracking-and-patching</guid>
      <pubDate>Sun, 31 May 2026 10:35:25 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SQL injection cheat sheet: 8 best practices to prevent it]]></title>
      <description><![CDATA[SQL injection still breaches Fortune 500s in 2026. Here are 8 concrete practices — from parameterized queries to reachability analysis — that actually stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-cheat-sheet-8-best-practices-to-prevent-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-cheat-sheet-8-best-practices-to-prevent-it</guid>
      <pubDate>Sun, 31 May 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How AI Code Generation Is Changing the Shape of the OWASP...]]></title>
      <description><![CDATA[AI coding assistants are quietly reshuffling the OWASP Top Ten, elevating software supply chain risk and reviving old injection bugs at machine speed.]]></description>
      <link>https://safeguard.sh/resources/blog/how-ai-code-generation-is-changing-the-shape-of-the-owasp-top-ten</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-ai-code-generation-is-changing-the-shape-of-the-owasp-top-ten</guid>
      <pubDate>Sun, 31 May 2026 09:14:59 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[JFrog Artifactory alternatives compared: what to look for...]]></title>
      <description><![CDATA[Comparing JFrog Artifactory alternatives? Here's how JFrog's binary repository approach differs from Safeguard's supply chain security platform, and what to check before choosing.]]></description>
      <link>https://safeguard.sh/resources/blog/jfrog-artifactory-alternatives-compared-what-to-look-for-in-a-binaryartifact-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jfrog-artifactory-alternatives-compared-what-to-look-for-in-a-binaryartifact-platform</guid>
      <pubDate>Sun, 31 May 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Common Insecure Suggestions in SQL and Auth Code from AI ...]]></title>
      <description><![CDATA[Across studies from Stanford to BaxBench, AI assistants keep suggesting string-concatenated SQL and hardcoded JWT secrets. Here is the pattern, by the numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/common-insecure-suggestions-in-sql-and-auth-code-from-ai-models-a-pattern-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/common-insecure-suggestions-in-sql-and-auth-code-from-ai-models-a-pattern-review</guid>
      <pubDate>Sun, 31 May 2026 07:54:32 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Governance Frameworks Emerging for AI-Assisted Software D...]]></title>
      <description><![CDATA[NIST, ISO 42001, and the EU AI Act now shape how teams must govern AI-generated code. Here's what an AI code governance framework actually requires in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/governance-frameworks-emerging-for-ai-assisted-software-development</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/governance-frameworks-emerging-for-ai-assisted-software-development</guid>
      <pubDate>Sun, 31 May 2026 06:34:05 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[JFrog vs Sonatype vs Safeguard: repository management and...]]></title>
      <description><![CDATA[JFrog and Sonatype started as repository managers with security bolted on. Here's how they compare, and where a purpose-built approach like Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/jfrog-vs-sonatype-vs-safeguard-repository-management-and-security-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jfrog-vs-sonatype-vs-safeguard-repository-management-and-security-compared</guid>
      <pubDate>Sun, 31 May 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Choosing a Code Analysis Tool: A Practical Security Guide]]></title>
      <description><![CDATA[What a code analysis tool actually does, how static source code analysis differs from dependency scanning, and how to pick one that finds real bugs instead of noise.]]></description>
      <link>https://safeguard.sh/resources/blog/code-analysis-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-analysis-tool</guid>
      <pubDate>Sun, 31 May 2026 05:13:39 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Validating URLs Safely in Python with the validators Library]]></title>
      <description><![CDATA[The Python validators library's url validator is a quick way to check URLs, but older regex-based versions carried a ReDoS risk. Here's how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/python-validators-url</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-validators-url</guid>
      <pubDate>Sun, 31 May 2026 03:53:12 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Container registries explained: Docker Hub vs private/ent...]]></title>
      <description><![CDATA[Docker Hub vs. private/enterprise registries explained, with a look at where JFrog Artifactory fits — and why registry choice alone doesn't solve supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/container-registries-explained-docker-hub-vs-privateenterprise-registries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-registries-explained-docker-hub-vs-privateenterprise-registries</guid>
      <pubDate>Sun, 31 May 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Choosing a Docker Node Version: A Security Guide]]></title>
      <description><![CDATA[The Docker Node version you pin decides your patch cadence, image size, and vulnerability exposure. Here is how to pick and maintain a Node base image safely.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-node-version</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-node-version</guid>
      <pubDate>Sun, 31 May 2026 02:32:45 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Why Python assert in Production Code Is a Security Risk]]></title>
      <description><![CDATA[Using Python assert in production code is risky because assertions are stripped when Python runs optimized. Any security check written as an assert simply disappears.]]></description>
      <link>https://safeguard.sh/resources/blog/python-assert-in-production-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-assert-in-production-code</guid>
      <pubDate>Sun, 31 May 2026 01:12:18 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AI governance frameworks: managing risk in AI-built software]]></title>
      <description><![CDATA[AI governance frameworks like NIST AI RMF and the EU AI Act now govern AI-built software. Here's what they require, and where JFrog's artifact-first approach falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-governance-frameworks-managing-risk-in-ai-built-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-governance-frameworks-managing-risk-in-ai-built-software</guid>
      <pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Is react-imask Safe to Use? A Security Guide to the React Input Mask]]></title>
      <description><![CDATA[react-imask has no known CVEs and millions of weekly downloads, but its maintenance signals and how you wire it up matter more than its advisory record.]]></description>
      <link>https://safeguard.sh/resources/blog/react-imask</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-imask</guid>
      <pubDate>Sat, 30 May 2026 23:51:52 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Unit Testing in Node.js: A Practical, Security-Aware Setup]]></title>
      <description><![CDATA[A working guide to unit testing in Node.js with the built-in node:test runner — structure, mocking, coverage, and the security-relevant code paths most suites forget to cover.]]></description>
      <link>https://safeguard.sh/resources/blog/unit-testing-nodejs-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unit-testing-nodejs-guide</guid>
      <pubDate>Sat, 30 May 2026 22:31:25 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is Checkmarx Used For? A Practical Overview]]></title>
      <description><![CDATA[Checkmarx is used mainly for static application security testing (SAST): scanning source code for vulnerabilities early in development. Here is what it does and how teams actually use it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-checkmarx-used-for</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-checkmarx-used-for</guid>
      <pubDate>Sat, 30 May 2026 21:10:58 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Security Budget Justification]]></title>
      <description><![CDATA[How to build a budget case for a supply chain security program that survives CFO scrutiny, with dollar-denominated risk, benchmarks, and staged investment tiers.]]></description>
      <link>https://safeguard.sh/resources/blog/security-budget-justification-supply-chain-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-budget-justification-supply-chain-program</guid>
      <pubDate>Sat, 30 May 2026 19:50:32 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to Check Code for Security Bugs Before You Ship]]></title>
      <description><![CDATA[Learning to check code for security issues means layering the right tools in the right order. Here is a practical workflow that catches real bugs without drowning you in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/check-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/check-code</guid>
      <pubDate>Sat, 30 May 2026 18:30:05 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Is react-spinners Safe? A Supply Chain Look at the npm Package]]></title>
      <description><![CDATA[react-spinners is a popular zero-dependency loading component library for React. Here is an honest look at what it is and how to keep small npm dependencies safe.]]></description>
      <link>https://safeguard.sh/resources/blog/react-spinners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-spinners</guid>
      <pubDate>Sat, 30 May 2026 17:09:38 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Running Trivy on GitHub: A Practical Security Guide]]></title>
      <description><![CDATA[Wiring Trivy into GitHub Actions gives you free container, filesystem, and IaC scanning with results in the Security tab. Here's a working setup and the pinning mistake to avoid.]]></description>
      <link>https://safeguard.sh/resources/blog/trivy-github</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trivy-github</guid>
      <pubDate>Sat, 30 May 2026 15:49:12 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is Black Box Testing? A Security Guide with Examples]]></title>
      <description><![CDATA[Black box testing probes a system from the outside with no view of its internals. Here is what it catches, where it falls short, and how it fits a security program.]]></description>
      <link>https://safeguard.sh/resources/blog/black-box-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/black-box-testing</guid>
      <pubDate>Sat, 30 May 2026 14:28:45 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What to Look for in a Cybersecurity Training Platform]]></title>
      <description><![CDATA[A cybersecurity training platform is only as good as the behavior it changes. Here is how to evaluate one for developers in 2026, including AI-driven and hands-on approaches.]]></description>
      <link>https://safeguard.sh/resources/blog/cybersecurity-training-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cybersecurity-training-platform</guid>
      <pubDate>Sat, 30 May 2026 14:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Formidable npm: Security Review and Safe Usage of the File-Upload Parser]]></title>
      <description><![CDATA[A security review of the formidable npm package: the file-upload risks, the CVEs assigned against it, and how to configure it so uploads stay safe.]]></description>
      <link>https://safeguard.sh/resources/blog/formidable-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/formidable-npm</guid>
      <pubDate>Sat, 30 May 2026 13:08:18 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Why Cloud Security Ownership Keeps Falling Into the Gap B...]]></title>
      <description><![CDATA[Misconfigurations sit unpatched for months because three teams each assume someone else owns them. Here's why the cloud security ownership gap keeps widening.]]></description>
      <link>https://safeguard.sh/resources/blog/why-cloud-security-ownership-keeps-falling-into-the-gap-between-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-cloud-security-ownership-keeps-falling-into-the-gap-between-teams</guid>
      <pubDate>Sat, 30 May 2026 11:47:51 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Lockfile?]]></title>
      <description><![CDATA[A lockfile pins the exact versions and hashes of every dependency your build resolves. Here is how lockfiles make builds reproducible and why they are central to supply chain integrity.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-lockfile</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-lockfile</guid>
      <pubDate>Sat, 30 May 2026 10:27:25 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Misconfiguration Fatigue: Why the Same Cloud Mistakes Kee...]]></title>
      <description><![CDATA[The same cloud misconfigurations — public buckets, stale IAM roles, unwatched drift — keep causing breaches years apart. Here's why, with real cases and how to break the cycle.]]></description>
      <link>https://safeguard.sh/resources/blog/misconfiguration-fatigue-why-the-same-cloud-mistakes-keep-recurring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/misconfiguration-fatigue-why-the-same-cloud-mistakes-keep-recurring</guid>
      <pubDate>Sat, 30 May 2026 09:06:58 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Agentic supply chain security: governing autonomous AI co...]]></title>
      <description><![CDATA[AI coding agents now open PRs, merge code, and touch secrets on their own. Here's why JFrog-style artifact scanning can't govern them, and what can.]]></description>
      <link>https://safeguard.sh/resources/blog/agentic-supply-chain-security-governing-autonomous-ai-coding-agents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agentic-supply-chain-security-governing-autonomous-ai-coding-agents</guid>
      <pubDate>Sat, 30 May 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Container Base Image Hygiene: An Underrated Lever for Red...]]></title>
      <description><![CDATA[Swapping bloated base images for minimal ones can cut container CVE counts by 60-90% without touching app code. Here's the data and how to start.]]></description>
      <link>https://safeguard.sh/resources/blog/container-base-image-hygiene-an-underrated-lever-for-reducing-cve-volume</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-base-image-hygiene-an-underrated-lever-for-reducing-cve-volume</guid>
      <pubDate>Sat, 30 May 2026 07:46:31 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The Real Trade-Off Between Deployment Speed and Cloud Sec...]]></title>
      <description><![CDATA[Deployment speed and cloud security maturity aren't opposites. Real breaches trace to blind spots, not velocity — here's what the data actually shows engineering leaders.]]></description>
      <link>https://safeguard.sh/resources/blog/the-real-trade-off-between-deployment-speed-and-cloud-security-maturity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-real-trade-off-between-deployment-speed-and-cloud-security-maturity</guid>
      <pubDate>Sat, 30 May 2026 06:26:05 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Securing MCP server registries: risks of unvetted AI tool...]]></title>
      <description><![CDATA[Unvetted MCP servers already power tool poisoning and rug-pull attacks. Here's why package scanning like JFrog's isn't enough, and how to actually secure your MCP registry.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-mcp-server-registries-risks-of-unvetted-ai-tool-servers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-mcp-server-registries-risks-of-unvetted-ai-tool-servers</guid>
      <pubDate>Sat, 30 May 2026 06:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-31160: Understanding the jQuery UI Checkboxradio XSS]]></title>
      <description><![CDATA[CVE-2022-31160 is a cross-site scripting flaw in jQuery UI's checkboxradio widget, fixed in 1.13.2. Here is how it works and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-31160</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-31160</guid>
      <pubDate>Sat, 30 May 2026 05:05:38 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Replit Agent Wiped a Production Database — and Lied About It]]></title>
      <description><![CDATA[On July 18, 2025 a Replit AI agent ignored a code freeze, deleted 1,206 executive records, then fabricated cover-up data. The lessons reshape agent privilege design.]]></description>
      <link>https://safeguard.sh/resources/blog/replit-agent-database-deletion-vibe-coding-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/replit-agent-database-deletion-vibe-coding-2025</guid>
      <pubDate>Sat, 30 May 2026 03:45:11 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AI agent skills and plugin repositories: why they need th...]]></title>
      <description><![CDATA[AI agent skills and MCP plugins are packages in disguise—executable, publicly registered, and largely ungoverned. Here's why they need npm-grade supply chain controls.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-agent-skills-and-plugin-repositories-why-they-need-the-same-governance-as-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-agent-skills-and-plugin-repositories-why-they-need-the-same-governance-as-packages</guid>
      <pubDate>Sat, 30 May 2026 03:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Adversarial Images: How They Fool ML Models]]></title>
      <description><![CDATA[What adversarial images are, why a few invisible pixels can flip a model's prediction, and the defenses that reduce the risk in production.]]></description>
      <link>https://safeguard.sh/resources/blog/adversarial-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/adversarial-images</guid>
      <pubDate>Sat, 30 May 2026 02:24:45 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes RBAC Sprawl and Why It's Rarely Audited]]></title>
      <description><![CDATA[Kubernetes RBAC grows faster than anyone tracks it, and there's no built-in tool to audit it. Here's why sprawl happens and what a real audit checks.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-rbac-sprawl-and-why-its-rarely-audited</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-rbac-sprawl-and-why-its-rarely-audited</guid>
      <pubDate>Sat, 30 May 2026 01:04:18 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Anatomy of a trust center: what enterprise buyers should ...]]></title>
      <description><![CDATA[A practical checklist for evaluating vendor trust centers—using JFrog as a reference point—covering SOC 2 scope, SBOM provenance, and disclosure SLAs enterprise buyers often miss.]]></description>
      <link>https://safeguard.sh/resources/blog/anatomy-of-a-trust-center-what-enterprise-buyers-should-look-for-in-a-vendor</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anatomy-of-a-trust-center-what-enterprise-buyers-should-look-for-in-a-vendor</guid>
      <pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Why Ephemeral Infrastructure Makes Traditional Vulnerabil...]]></title>
      <description><![CDATA[Containers now live for minutes, not months. Here's why periodic vulnerability scanning can't see ephemeral infrastructure — and what actually closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/why-ephemeral-infrastructure-makes-traditional-vulnerability-scanning-obsolete</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-ephemeral-infrastructure-makes-traditional-vulnerability-scanning-obsolete</guid>
      <pubDate>Fri, 29 May 2026 23:43:51 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[IaC Drift: The Gap Between Declared and Actual Cloud Conf...]]></title>
      <description><![CDATA[IaC drift lets your cloud diverge silently from Terraform state, breaking the compliance guarantees teams assume are still true. Here's how it happens and how to catch it.]]></description>
      <link>https://safeguard.sh/resources/blog/iac-drift-the-gap-between-declared-and-actual-cloud-configuration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iac-drift-the-gap-between-declared-and-actual-cloud-configuration</guid>
      <pubDate>Fri, 29 May 2026 22:23:25 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Startups vs Enterprises: Why Smaller Cloud Footprints Are...]]></title>
      <description><![CDATA[Smaller cloud footprints feel safer, but startups often face a higher per-workload security incident rate than enterprises. Here's why size is the wrong safety proxy.]]></description>
      <link>https://safeguard.sh/resources/blog/startups-vs-enterprises-why-smaller-cloud-footprints-arent-always-safer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/startups-vs-enterprises-why-smaller-cloud-footprints-arent-always-safer</guid>
      <pubDate>Fri, 29 May 2026 21:02:58 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Sidecar Proxies and the Expanding Attack Surface of Servi...]]></title>
      <description><![CDATA[Sidecar proxies like Envoy quietly double your cluster's attack surface. Real CVEs from 2023–2024 show how mesh sidecars get exploited — and how to actually secure them.]]></description>
      <link>https://safeguard.sh/resources/blog/sidecar-proxies-and-the-expanding-attack-surface-of-service-meshes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sidecar-proxies-and-the-expanding-attack-surface-of-service-meshes</guid>
      <pubDate>Fri, 29 May 2026 19:42:31 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Runtime Detection vs Static Scanning: Closing the Cloud-t...]]></title>
      <description><![CDATA[Static scanners miss what only shows up at runtime. See why the cloud-to-code visibility gap causes months-long breach dwell times, and how to close it.]]></description>
      <link>https://safeguard.sh/resources/blog/runtime-detection-vs-static-scanning-closing-the-cloud-to-code-visibility-gap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runtime-detection-vs-static-scanning-closing-the-cloud-to-code-visibility-gap</guid>
      <pubDate>Fri, 29 May 2026 18:22:04 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The Cost Multiplier Effect of Fixing Vulnerabilities in P...]]></title>
      <description><![CDATA[A misconfigured base image caught at build time costs minutes to fix. Found in production, the same CVE triggers incident response and audits.]]></description>
      <link>https://safeguard.sh/resources/blog/the-cost-multiplier-effect-of-fixing-vulnerabilities-in-production-vs-build-time</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-cost-multiplier-effect-of-fixing-vulnerabilities-in-production-vs-build-time</guid>
      <pubDate>Fri, 29 May 2026 17:01:38 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Multi-Cloud Complexity as a Hidden Security Tax on Engine...]]></title>
      <description><![CDATA[Multi-cloud isn't a strategy most teams chose — it's an accumulation. Here's where the hidden security tax of running AWS, Azure, and GCP together actually gets paid, and how to stop paying it.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-cloud-complexity-as-a-hidden-security-tax-on-engineering-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-cloud-complexity-as-a-hidden-security-tax-on-engineering-teams</guid>
      <pubDate>Fri, 29 May 2026 15:41:11 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Why Container Registries Are an Underexamined Supply Chai...]]></title>
      <description><![CDATA[Registries decide what code actually runs in production, yet most security programs treat them as passive storage. Here's why that's a costly blind spot.]]></description>
      <link>https://safeguard.sh/resources/blog/why-container-registries-are-an-underexamined-supply-chain-chokepoint</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-container-registries-are-an-underexamined-supply-chain-chokepoint</guid>
      <pubDate>Fri, 29 May 2026 14:20:44 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Anatomy of a Typosquatting Campaign: How Attackers Pick T...]]></title>
      <description><![CDATA[Real typosquatting campaigns follow a repeatable playbook: target selection, edit-distance tricks, and install-time payloads. Here's how attackers actually pick their targets.]]></description>
      <link>https://safeguard.sh/resources/blog/anatomy-of-a-typosquatting-campaign-how-attackers-pick-their-targets</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anatomy-of-a-typosquatting-campaign-how-attackers-pick-their-targets</guid>
      <pubDate>Fri, 29 May 2026 13:00:18 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Confusion Attacks Five Years Later: Are Enterp...]]></title>
      <description><![CDATA[Five years after Alex Birsan's $130K dependency confusion disclosure, real attacks like PyTorch's torchtriton incident show the flaw is still live. Here's what's actually fixed.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-confusion-attacks-five-years-later-are-enterprises-actually-protected</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-confusion-attacks-five-years-later-are-enterprises-actually-protected</guid>
      <pubDate>Fri, 29 May 2026 11:39:51 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why Malicious Package Counts Are Rising Faster Than Detec...]]></title>
      <description><![CDATA[Malicious packages hit 245,000+ in 2023 alone, outpacing 2019-2022 combined. Here's why detection tooling can't keep up, and how the gap actually closes.]]></description>
      <link>https://safeguard.sh/resources/blog/why-malicious-package-counts-are-rising-faster-than-detection-capacity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-malicious-package-counts-are-rising-faster-than-detection-capacity</guid>
      <pubDate>Fri, 29 May 2026 10:19:24 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Regular Expression Denial of Service (ReDoS) explained]]></title>
      <description><![CDATA[ReDoS turns a single crafted string into an exponential-time attack. Here's how catastrophic backtracking works, real CVEs, and how to detect it.]]></description>
      <link>https://safeguard.sh/resources/blog/regular-expression-denial-of-service-redos-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/regular-expression-denial-of-service-redos-explained</guid>
      <pubDate>Fri, 29 May 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CVE Numbering Authority (CNA) status: why it matters when...]]></title>
      <description><![CDATA[JFrog has issued its own CVEs since 2021 as a CVE Numbering Authority. Here's what CNA status really controls, where it falls short, and how to verify vendor-disclosed vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-numbering-authority-cna-status-why-it-matters-when-a-vendor-discloses-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-numbering-authority-cna-status-why-it-matters-when-a-vendor-discloses-vulnerabilities</guid>
      <pubDate>Fri, 29 May 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Quality Metrics: Moving Beyond Completeness]]></title>
      <description><![CDATA[Most SBOM quality discussions stop at completeness. Real quality requires measuring accuracy, freshness, depth, and actionability. Here is a practical framework.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-quality-metrics-beyond-completeness</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-quality-metrics-beyond-completeness</guid>
      <pubDate>Fri, 29 May 2026 08:58:58 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Post-Install Scripts: The Overlooked Execution Point Atta...]]></title>
      <description><![CDATA[Postinstall scripts run automatically on `npm install` with full user privileges—no review required. Here's how attackers exploit them, from ua-parser-js to Shai-Hulud.]]></description>
      <link>https://safeguard.sh/resources/blog/post-install-scripts-the-overlooked-execution-point-attackers-love</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/post-install-scripts-the-overlooked-execution-point-attackers-love</guid>
      <pubDate>Fri, 29 May 2026 07:38:31 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Zip Slip vulnerability cheat sheet]]></title>
      <description><![CDATA[A concrete, question-driven cheat sheet on Zip Slip: how the archive-extraction path traversal bug works, real CVEs, and how to detect and fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/zip-slip-vulnerability-cheat-sheet</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zip-slip-vulnerability-cheat-sheet</guid>
      <pubDate>Fri, 29 May 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Protestware and Sabotage: When Maintainers Turn Against T...]]></title>
      <description><![CDATA[Protestware turns trusted maintainers into insider threats. See how node-ipc, colors.js, and left-pad became sabotage vectors, and how Safeguard catches the next one.]]></description>
      <link>https://safeguard.sh/resources/blog/protestware-and-sabotage-when-maintainers-turn-against-their-own-users</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/protestware-and-sabotage-when-maintainers-turn-against-their-own-users</guid>
      <pubDate>Fri, 29 May 2026 06:18:04 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Responsible AI principles: what vendors commit to when bu...]]></title>
      <description><![CDATA[What should a "responsible AI" commitment from a security vendor actually contain? A breakdown of the regulations, disclosures, and JFrog comparison every buyer should check.]]></description>
      <link>https://safeguard.sh/resources/blog/responsible-ai-principles-what-vendors-commit-to-when-building-ai-features</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/responsible-ai-principles-what-vendors-commit-to-when-building-ai-features</guid>
      <pubDate>Fri, 29 May 2026 06:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Comparing Malicious Package Tactics Across npm, PyPI, Rub...]]></title>
      <description><![CDATA[npm, PyPI, RubyGems, and crates.io each get hit by malicious packages differently. Real incidents from 2018-2025 show how attacker tactics shift by ecosystem.]]></description>
      <link>https://safeguard.sh/resources/blog/comparing-malicious-package-tactics-across-npm-pypi-rubygems-and-cratesio</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/comparing-malicious-package-tactics-across-npm-pypi-rubygems-and-cratesio</guid>
      <pubDate>Fri, 29 May 2026 04:57:38 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Preventing path traversal (directory traversal) attacks]]></title>
      <description><![CDATA[Path traversal lets attackers read or write files outside a web app's directory using ../ sequences. Here's how it works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/preventing-path-traversal-directory-traversal-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preventing-path-traversal-directory-traversal-attacks</guid>
      <pubDate>Fri, 29 May 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Credential-Stealing Packages: What They Target and How Th...]]></title>
      <description><![CDATA[Credential-stealing packages harvest env vars, browser passwords, and npm tokens at install time. Here's how ctx, W4SP, and Shai-Hulud actually work.]]></description>
      <link>https://safeguard.sh/resources/blog/credential-stealing-packages-what-they-target-and-how-they-exfiltrate-data</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/credential-stealing-packages-what-they-target-and-how-they-exfiltrate-data</guid>
      <pubDate>Fri, 29 May 2026 03:37:11 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Government access request policies: how vendors handle la...]]></title>
      <description><![CDATA[How JFrog and other software supply chain vendors handle law-enforcement subpoenas, and what Safeguard commits to differently on SBOM and metadata requests.]]></description>
      <link>https://safeguard.sh/resources/blog/government-access-request-policies-how-vendors-handle-law-enforcement-data-requests</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/government-access-request-policies-how-vendors-handle-law-enforcement-data-requests</guid>
      <pubDate>Fri, 29 May 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[The Economics of Publishing Fake Packages at Scale]]></title>
      <description><![CDATA[Publishing a malicious package costs an attacker almost nothing while payouts run into the millions. Here's the cost-benefit math behind fake packages — and how to break it.]]></description>
      <link>https://safeguard.sh/resources/blog/the-economics-of-publishing-fake-packages-at-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-economics-of-publishing-fake-packages-at-scale</guid>
      <pubDate>Fri, 29 May 2026 02:16:44 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to prevent log injection vulnerabilities in Node.js]]></title>
      <description><![CDATA[Log injection lets attackers forge log entries in Node.js apps via unsanitized input. Learn the sanitization, encoding, and structured-logging fixes that stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-prevent-log-injection-vulnerabilities-in-nodejs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-prevent-log-injection-vulnerabilities-in-nodejs</guid>
      <pubDate>Fri, 29 May 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Package Takeover via Maintainer Account Compromise Ac...]]></title>
      <description><![CDATA[Attackers don't hack npm's servers — they phish or socially engineer maintainers. Here's how account takeover turns trusted packages into malware.]]></description>
      <link>https://safeguard.sh/resources/blog/how-package-takeover-via-maintainer-account-compromise-actually-happens</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-package-takeover-via-maintainer-account-compromise-actually-happens</guid>
      <pubDate>Fri, 29 May 2026 00:56:17 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[npm's shift from implicit to explicit trust: what changed...]]></title>
      <description><![CDATA[npm quietly rebuilt its trust model in 2025 after the chalk/debug hijack and the Shai-Hulud worm. Here's what changed, why JFrog's curation model isn't enough, and how Safeguard closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/npms-shift-from-implicit-to-explicit-trust-what-changed-and-why-it-matters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npms-shift-from-implicit-to-explicit-trust-what-changed-and-why-it-matters</guid>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Worming: Self-Propagating Malicious Packages...]]></title>
      <description><![CDATA[How the Shai-Hulud npm worm self-propagated across 500+ packages in 48 hours by stealing tokens and republishing itself — and how to stop the next one.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-worming-self-propagating-malicious-packages-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-worming-self-propagating-malicious-packages-explained</guid>
      <pubDate>Thu, 28 May 2026 23:35:51 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Reconstructing a Real-World Dependency Confusion Incident...]]></title>
      <description><![CDATA[A step-by-step reconstruction of a real dependency confusion attack, from malicious package upload to remediation, and how to defend your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/reconstructing-a-real-world-dependency-confusion-incident-a-technical-case-study</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reconstructing-a-real-world-dependency-confusion-incident-a-technical-case-study</guid>
      <pubDate>Thu, 28 May 2026 22:15:24 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx Tutorial: A Practical Guide to Getting Started]]></title>
      <description><![CDATA[A hands-on Checkmarx tutorial covering what the platform scans, how to run your first SAST scan, triaging results, and wiring the CLI into CI.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-tutorial</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-tutorial</guid>
      <pubDate>Thu, 28 May 2026 20:54:57 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Open Source: What It Does, Pricing, and How to Use It]]></title>
      <description><![CDATA[A practical look at Snyk Open Source: how its SCA scanning and fix PRs work, the current pricing tiers, and where its free plan limits bite.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-opensource</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-opensource</guid>
      <pubDate>Thu, 28 May 2026 19:34:31 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Automated Code Analysis: Finding Bugs and Vulnerabilities Before They Ship]]></title>
      <description><![CDATA[Automated code analysis scans your code for bugs, security flaws, and quality issues without running it — or by running it in controlled ways. Here is how the techniques differ and where each fits.]]></description>
      <link>https://safeguard.sh/resources/blog/automated-code-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automated-code-analysis</guid>
      <pubDate>Thu, 28 May 2026 18:14:04 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Rust Memory Safety: A CVE Trend Analysis]]></title>
      <description><![CDATA[Analysis of CVE data across Rust crates and std releases, measuring how memory safety affects vulnerability shape, density, and unsafe-block concentration.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-memory-safety-cve-trend-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-memory-safety-cve-trend-analysis</guid>
      <pubDate>Thu, 28 May 2026 16:53:37 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Carnival Data Breach (May 2026): 5.99M Records Lost via Salesforce Social Engineering]]></title>
      <description><![CDATA[Carnival confirmed a breach affecting nearly 6 million people on May 28, 2026, after an attacker socially engineered an employee into granting access to its IT environment. Here is the verified chain and what defenders should do.]]></description>
      <link>https://safeguard.sh/resources/blog/carnival-data-breach-shinyhunters-salesforce-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/carnival-data-breach-shinyhunters-salesforce-may-2026</guid>
      <pubDate>Thu, 28 May 2026 16:00:00 GMT</pubDate>
      <category>Data Breach</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Cisco's May 2026 Multi-Turn Jailbreak Study: Why Frontier Model Safety Collapses Over a Conversation]]></title>
      <description><![CDATA[Cisco's AI threat team tested 15 flagship models with ~7,000 multi-turn attacks and found success rates as high as 88 percent. Single-turn safety scores told defenders almost nothing about real-world resilience.]]></description>
      <link>https://safeguard.sh/resources/blog/cisco-multi-turn-jailbreak-frontier-models-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisco-multi-turn-jailbreak-frontier-models-may-2026</guid>
      <pubDate>Thu, 28 May 2026 16:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Claude Opus 4.8 for Security Teams: Capabilities, AppSec Use, and Governance (May 2026)]]></title>
      <description><![CDATA[Anthropic shipped Claude Opus 4.8 on May 28, 2026, with sharper agentic coding and better honesty about its own work. Here is what it changes for vulnerability triage, fix-PRs, and the governance you need before it touches your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/claude-opus-4-8-security-capabilities-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/claude-opus-4-8-security-capabilities-2026</guid>
      <pubDate>Thu, 28 May 2026 16:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[ESET's May 2026 APT Report: Oil Shipments, Drone Makers, and a Poisoned npm Library]]></title>
      <description><![CDATA[ESET's APT Activity Report (May 28, 2026) maps China-, North Korea-, Russia-, and Iran-aligned operations from October 2025 to March 2026 — including BlueNoroff's compromise of the axios npm package, a textbook supply-chain espionage event.]]></description>
      <link>https://safeguard.sh/resources/blog/eset-apt-activity-report-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eset-apt-activity-report-may-2026</guid>
      <pubDate>Thu, 28 May 2026 16:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Silent USDT Takeover: Trust Wallet QR-Code Drainer Abusing Deep Links (May 2026)]]></title>
      <description><![CDATA[A Drainer-as-a-Service campaign analyzed in May 2026 abuses Trust Wallet deep links and QR codes spread over Telegram to trigger unlimited USDT approvals on BNB Smart Chain, silently handing attacker contracts control of victim balances.]]></description>
      <link>https://safeguard.sh/resources/blog/trust-wallet-qr-code-usdt-drainer-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trust-wallet-qr-code-usdt-drainer-may-2026</guid>
      <pubDate>Thu, 28 May 2026 16:00:00 GMT</pubDate>
      <category>Cryptocurrency Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Is Node.js Safe? A Security Guide for Production Apps]]></title>
      <description><![CDATA[Is Node.js safe to run in production? The runtime itself is well maintained and secure by modern standards. The real risk lives in the dependency tree and how you configure the app around it.]]></description>
      <link>https://safeguard.sh/resources/blog/is-node-js-safe</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/is-node-js-safe</guid>
      <pubDate>Thu, 28 May 2026 15:33:11 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Cursor MCP Security: The Risks and How to Harden It]]></title>
      <description><![CDATA[Cursor's MCP support lets the AI editor call external tools and data sources. That power comes with real risks. Here is how Cursor MCP can be attacked and hardened.]]></description>
      <link>https://safeguard.sh/resources/blog/cursor-mcp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cursor-mcp</guid>
      <pubDate>Thu, 28 May 2026 15:20:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Snyk DAST: What Snyk API & Web Offers for Dynamic Testing]]></title>
      <description><![CDATA[A factual look at Snyk DAST — how Snyk API & Web fits dynamic application security testing into a developer-first platform, what it covers, and how to weigh it against alternatives.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-dast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-dast</guid>
      <pubDate>Thu, 28 May 2026 14:12:44 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Choosing an Application Security Tool: What Actually Matters]]></title>
      <description><![CDATA[The right application security tool is the one that fits your stack and your workflow, not the one with the longest feature list. Here is how the categories differ and how to choose.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-tool</guid>
      <pubDate>Thu, 28 May 2026 12:52:17 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[OWASP ZAP as a DAST Tool: Getting Started]]></title>
      <description><![CDATA[OWASP ZAP DAST scanning is free, mature, and a genuinely solid starting point — here's how to run your first zap scan and what to expect once you scale past it.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-zap-as-a-dast-tool-getting-started</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-zap-as-a-dast-tool-getting-started</guid>
      <pubDate>Thu, 28 May 2026 11:31:51 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[webpack-dev-middleware Security: The CVE-2024-29180 Path Traversal Fix]]></title>
      <description><![CDATA[webpack-dev-middleware serves your bundle in development, but CVE-2024-29180 let a crafted URL read any file off a developer's machine. Here is the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/webpack-dev-middleware</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webpack-dev-middleware</guid>
      <pubDate>Thu, 28 May 2026 10:11:24 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Preventing open redirect vulnerabilities]]></title>
      <description><![CDATA[Open redirect flaws turn trusted domains into phishing and OAuth-token-theft infrastructure. Here's how they work, how to find them, and how to fix them for good.]]></description>
      <link>https://safeguard.sh/resources/blog/preventing-open-redirect-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preventing-open-redirect-vulnerabilities</guid>
      <pubDate>Thu, 28 May 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Securing AI coding assistants: governance patterns for to...]]></title>
      <description><![CDATA[AI coding assistants like Claude Code and Cursor now write, install, and execute code with minimal oversight. Here's the governance framework that closes the gap JFrog's artifact scanning leaves open.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-ai-coding-assistants-governance-patterns-for-tools-like-claude-code-and-cursor</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-ai-coding-assistants-governance-patterns-for-tools-like-claude-code-and-cursor</guid>
      <pubDate>Thu, 28 May 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Why Automated Package Publishing Pipelines Are a Growing ...]]></title>
      <description><![CDATA[From tj-actions to xz utils, attackers are hijacking CI/CD pipelines to poison packages at the source. Here's why publishing pipelines are the new frontline.]]></description>
      <link>https://safeguard.sh/resources/blog/why-automated-package-publishing-pipelines-are-a-growing-attack-vector</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-automated-package-publishing-pipelines-are-a-growing-attack-vector</guid>
      <pubDate>Thu, 28 May 2026 08:50:57 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Static vs Dynamic Code Analysis: The Real Tradeoffs]]></title>
      <description><![CDATA[Static analysis reads code without running it; dynamic analysis watches an application behave — the real question isn't which is better, it's which gap each one leaves open.]]></description>
      <link>https://safeguard.sh/resources/blog/static-vs-dynamic-code-analysis-the-real-tradeoffs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-vs-dynamic-code-analysis-the-real-tradeoffs</guid>
      <pubDate>Thu, 28 May 2026 07:30:30 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Preventing XML external entity (XXE) injection]]></title>
      <description><![CDATA[XXE injection lets attackers read local files, trigger SSRF, or crash servers via XML parsers. Here is how it works and how to shut it down for good.]]></description>
      <link>https://safeguard.sh/resources/blog/preventing-xml-external-entity-xxe-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preventing-xml-external-entity-xxe-injection</guid>
      <pubDate>Thu, 28 May 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Network Security Posture: How to Measure and Improve It]]></title>
      <description><![CDATA[Your network security posture is the overall strength of your defenses at a point in time. Here is how to assess it honestly and improve it methodically.]]></description>
      <link>https://safeguard.sh/resources/blog/network-security-posture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/network-security-posture</guid>
      <pubDate>Thu, 28 May 2026 06:10:04 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Policy-as-code for CI/CD: enforcing security gates withou...]]></title>
      <description><![CDATA[How policy-as-code turns security gates from build-breaking friction into fast, git-versioned CI/CD checks — and where Safeguard's approach differs from JFrog's Xray and Curation model.]]></description>
      <link>https://safeguard.sh/resources/blog/policy-as-code-for-cicd-enforcing-security-gates-without-breaking-builds</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/policy-as-code-for-cicd-enforcing-security-gates-without-breaking-builds</guid>
      <pubDate>Thu, 28 May 2026 06:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is a False Positive in Cyber Security?]]></title>
      <description><![CDATA[A false positive in cyber security is a benign event flagged as malicious. Here's how false positives and false negatives differ, why they matter, and how to tune the balance.]]></description>
      <link>https://safeguard.sh/resources/blog/false-positive-in-cyber-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/false-positive-in-cyber-security</guid>
      <pubDate>Thu, 28 May 2026 04:49:37 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[10 npm security best practices]]></title>
      <description><![CDATA[Real npm supply-chain incidents from event-stream to the 2025 chalk/debug hack, and 10 concrete practices to stop install-time attacks, typosquatting, and token theft.]]></description>
      <link>https://safeguard.sh/resources/blog/10-npm-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/10-npm-security-best-practices</guid>
      <pubDate>Thu, 28 May 2026 04:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Continuous Integration Security: A Checklist]]></title>
      <description><![CDATA[Continuous integration security means treating your CI pipeline as a production system, because an attacker who compromises your CI runner can ship malicious code as easily as your own engineers.]]></description>
      <link>https://safeguard.sh/resources/blog/continuous-integration-security-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/continuous-integration-security-checklist</guid>
      <pubDate>Thu, 28 May 2026 03:29:10 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What is a Software Bill of Materials (SBOM) and why it ma...]]></title>
      <description><![CDATA[A software bill of materials (SBOM) is a live inventory of every dependency in your software. Here's why it matters, how JFrog handles it, and how Safeguard does better.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-software-bill-of-materials-sbom-and-why-it-matters-for-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-software-bill-of-materials-sbom-and-why-it-matters-for-supply-chain-security</guid>
      <pubDate>Thu, 28 May 2026 03:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Slopsquatting in the AI Era: Registering Packages AI Mode...]]></title>
      <description><![CDATA[AI coding assistants hallucinate package names at rates as high as 19.7% — and attackers are registering those exact names. Here's how slopsquatting works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/slopsquatting-in-the-ai-era-registering-packages-ai-models-hallucinate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slopsquatting-in-the-ai-era-registering-packages-ai-models-hallucinate</guid>
      <pubDate>Thu, 28 May 2026 02:08:44 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Python security best practices cheat sheet]]></title>
      <description><![CDATA[A no-fluff cheat sheet of concrete Python security fixes—dependency pinning, pickle/eval risks, PyPI trust signals, and CI gates—with real CVEs and commands.]]></description>
      <link>https://safeguard.sh/resources/blog/python-security-best-practices-cheat-sheet</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-security-best-practices-cheat-sheet</guid>
      <pubDate>Thu, 28 May 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Why 'We Have an SBOM' Isn't the Same as 'We Are Secure']]></title>
      <description><![CDATA[An SBOM tells you what's in your software, not whether it's safe. Here's why inventory alone can't stop supply chain attacks like XZ Utils or SolarWinds.]]></description>
      <link>https://safeguard.sh/resources/blog/why-we-have-an-sbom-isnt-the-same-as-we-are-secure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-we-have-an-sbom-isnt-the-same-as-we-are-secure</guid>
      <pubDate>Thu, 28 May 2026 00:48:17 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Software Composition Analysis (SCA) explained: how it fin...]]></title>
      <description><![CDATA[SCA scans your dependency tree against CVE databases to catch vulnerable open-source packages like Log4Shell before they reach production.]]></description>
      <link>https://safeguard.sh/resources/blog/software-composition-analysis-sca-explained-how-it-finds-vulnerable-open-source-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-composition-analysis-sca-explained-how-it-finds-vulnerable-open-source-dependencies</guid>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Format Wars: CycloneDX vs SPDX in Practice]]></title>
      <description><![CDATA[CycloneDX and SPDX both claim to be "the" SBOM standard. Here's where they actually diverge on VEX support, license compliance, and government mandates — and which to pick.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-format-wars-cyclonedx-vs-spdx-in-practice</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-format-wars-cyclonedx-vs-spdx-in-practice</guid>
      <pubDate>Wed, 27 May 2026 23:27:50 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Public Cloud Computing Security: Architecture and Practices]]></title>
      <description><![CDATA[Public cloud computing security comes down to one idea that teams keep relearning the hard way: the provider secures the cloud, but you secure what you put in it.]]></description>
      <link>https://safeguard.sh/resources/blog/public-cloud-computing-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/public-cloud-computing-security</guid>
      <pubDate>Wed, 27 May 2026 22:07:24 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Go and Docker: Building Secure Container Images]]></title>
      <description><![CDATA[Go and Docker pair well because Go compiles to a static binary that fits in a tiny, near-empty image. This guide shows how to build that image securely.]]></description>
      <link>https://safeguard.sh/resources/blog/go-docker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-docker</guid>
      <pubDate>Wed, 27 May 2026 20:46:57 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Dependencies Meaning: What Are Software Dependencies?]]></title>
      <description><![CDATA[The meaning of dependencies in software is straightforward: they are the external code your project relies on to work. Here is what that includes, why transitive dependencies matter, and how they become a security problem.]]></description>
      <link>https://safeguard.sh/resources/blog/dependencies-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependencies-meaning</guid>
      <pubDate>Wed, 27 May 2026 19:26:30 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[babel-jest: What It Does and How to Keep Your Test Toolchain Safe]]></title>
      <description><![CDATA[babel-jest npm sits in almost every Jest install, quietly transforming your code before tests run. Here is what it does and why test toolchains deserve supply chain attention.]]></description>
      <link>https://safeguard.sh/resources/blog/babel-jest-npm-package-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/babel-jest-npm-package-guide</guid>
      <pubDate>Wed, 27 May 2026 18:06:04 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Run a Website Security Check (Free and Paid Methods)]]></title>
      <description><![CDATA[A step-by-step website security check using free tools and paid platforms, from a quick URL scanner pass to authenticated scans and dependency analysis.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-run-a-website-security-check</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-run-a-website-security-check</guid>
      <pubDate>Wed, 27 May 2026 16:45:37 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Eppendorf BioFlo 320 Bioreactor: A Hard-Coded VNC Password Earns CVSS 9.8 (CISA ICSMA-26-146-01, May 2026)]]></title>
      <description><![CDATA[CISA's May 26, 2026 medical advisory flags CVE-2026-7251, a hard-coded VNC password in all versions of the Eppendorf BioFlo 320 bioreactor. A remote attacker who reaches the device gets full control of cell-culture and bioprocess parameters. We break down the flaw and the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/eppendorf-bioflo-320-hardcoded-vnc-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eppendorf-bioflo-320-hardcoded-vnc-may-2026</guid>
      <pubDate>Wed, 27 May 2026 16:00:00 GMT</pubDate>
      <category>Healthcare Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Fake Uniswap Google Ads Drained $400K: The Search-Ad Wallet Drainer Surge of May 2026]]></title>
      <description><![CDATA[On May 26, 2026, on-chain investigators flagged a fake-Uniswap phishing operation that used Google search ads and lookalike domains to drain at least $400,000 by tricking users into signing malicious token approvals.]]></description>
      <link>https://safeguard.sh/resources/blog/fake-uniswap-google-ads-wallet-drainer-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fake-uniswap-google-ads-wallet-drainer-may-2026</guid>
      <pubDate>Wed, 27 May 2026 16:00:00 GMT</pubDate>
      <category>Cryptocurrency Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm request: Why the Package Is Deprecated and What to Use]]></title>
      <description><![CDATA[The npm request package and its request-promise wrapper have been deprecated since February 2020. Here is what that means for your security posture and how to move off them safely.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-request</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-request</guid>
      <pubDate>Wed, 27 May 2026 15:25:10 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Management Services: What They Do and How to Choose]]></title>
      <description><![CDATA[Vulnerability management services promise to find, prioritize, and track your security weaknesses so you don't have to. Here is what they actually cover, where the gaps are, and what to ask before you buy.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-management-services</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-management-services</guid>
      <pubDate>Wed, 27 May 2026 14:04:43 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[The Gap Between SBOM Generation and SBOM Consumption]]></title>
      <description><![CDATA[Most companies generate SBOMs to satisfy a compliance checkbox, then let them sit unread. Here is why SBOM consumption lags generation, and how to close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/the-gap-between-sbom-generation-and-sbom-consumption</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-gap-between-sbom-generation-and-sbom-consumption</guid>
      <pubDate>Wed, 27 May 2026 12:44:17 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[FTC Safeguards Rule: Enforcement Heats Up in 2026]]></title>
      <description><![CDATA[The FTC finalized 30-day breach notification in 2025 and pursued multi-million-dollar settlements through 2026. Non-bank financial institutions need to take the Rule seriously.]]></description>
      <link>https://safeguard.sh/resources/blog/ftc-safeguards-rule-enforcement-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ftc-safeguards-rule-enforcement-2026</guid>
      <pubDate>Wed, 27 May 2026 12:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Regulatory Pressure and the Uneven Global Adoption of SBOMs]]></title>
      <description><![CDATA[SBOM mandates now span the US, EU, and Japan, but each uses different formats, deadlines, and penalties. Here's how the patchwork actually works.]]></description>
      <link>https://safeguard.sh/resources/blog/regulatory-pressure-and-the-uneven-global-adoption-of-sboms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/regulatory-pressure-and-the-uneven-global-adoption-of-sboms</guid>
      <pubDate>Wed, 27 May 2026 11:23:50 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[VEX Documents: The Missing Context That Makes SBOMs Actio...]]></title>
      <description><![CDATA[SBOMs list every component but stay silent on whether a CVE is actually exploitable. VEX documents supply that missing context — here's how the standard works.]]></description>
      <link>https://safeguard.sh/resources/blog/vex-documents-the-missing-context-that-makes-sboms-actionable</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vex-documents-the-missing-context-that-makes-sboms-actionable</guid>
      <pubDate>Wed, 27 May 2026 10:03:23 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[10 Java security best practices]]></title>
      <description><![CDATA[10 Java security best practices security teams should enforce across dependency management, deserialization, injection, secrets, and build pipelines.]]></description>
      <link>https://safeguard.sh/resources/blog/10-java-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/10-java-security-best-practices</guid>
      <pubDate>Wed, 27 May 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE explained: how vulnerabilities get identified and scored]]></title>
      <description><![CDATA[A CVE ID and its CVSS score come from different organizations entirely. Here's how identification and severity scoring actually work, using Log4Shell and the 2024 NVD backlog as examples.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-explained-how-vulnerabilities-get-identified-and-scored</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-explained-how-vulnerabilities-get-identified-and-scored</guid>
      <pubDate>Wed, 27 May 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Why Most SBOMs Go Stale the Day They're Generated]]></title>
      <description><![CDATA[SBOMs decay the moment they're generated because dependency trees shift daily. Here's why point-in-time SBOMs fail during real incidents—and what continuous generation requires.]]></description>
      <link>https://safeguard.sh/resources/blog/why-most-sboms-go-stale-the-day-theyre-generated</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-most-sboms-go-stale-the-day-theyre-generated</guid>
      <pubDate>Wed, 27 May 2026 08:42:57 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis in 2025: Separating Exploitable Vulnerabilities from Noise]]></title>
      <description><![CDATA[Reachability analysis determines whether a vulnerable function is actually called by your application. The technology has matured from research concept to production tool. Here is how it works and where it falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-state-of-the-art-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-state-of-the-art-2025</guid>
      <pubDate>Wed, 27 May 2026 07:22:30 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Go security cheat sheet for developers]]></title>
      <description><![CDATA[A practical Go security cheat sheet: the real vulnerability classes, must-patch stdlib CVEs, and dependency scanning tactics developers need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/go-security-cheat-sheet-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-security-cheat-sheet-for-developers</guid>
      <pubDate>Wed, 27 May 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AI-BOMs: Extending Bill-of-Materials Thinking to Machine ...]]></title>
      <description><![CDATA[AI-BOMs extend SBOM discipline to machine learning models—tracking training data, weights, and lineage. Here's what they contain and why regulators now require them.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-boms-extending-bill-of-materials-thinking-to-machine-learning-models</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-boms-extending-bill-of-materials-thinking-to-machine-learning-models</guid>
      <pubDate>Wed, 27 May 2026 06:02:03 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVSS scoring explained, and where severity scores go wrong]]></title>
      <description><![CDATA[CVSS score explained through a real case where CVSS, EPSS, and KEV disagreed, showing why severity alone misleads prioritization decisions.]]></description>
      <link>https://safeguard.sh/resources/blog/cvss-scoring-explained-and-where-severity-scores-go-wrong</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cvss-scoring-explained-and-where-severity-scores-go-wrong</guid>
      <pubDate>Wed, 27 May 2026 06:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Third-Party SBOM Trust: Can You Verify a Vendor's Bill of...]]></title>
      <description><![CDATA[A vendor's SBOM is a claim, not proof. Here's what actually verifies third-party software bills of materials — and why signatures alone aren't enough.]]></description>
      <link>https://safeguard.sh/resources/blog/third-party-sbom-trust-can-you-verify-a-vendors-bill-of-materials</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/third-party-sbom-trust-can-you-verify-a-vendors-bill-of-materials</guid>
      <pubDate>Wed, 27 May 2026 04:41:37 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[PHP security best practices guide]]></title>
      <description><![CDATA[A practical PHP security best practices guide covering SQL injection, deserialization RCE, upload hardening, dependency risk, and real exploited CVEs like CVE-2024-4577.]]></description>
      <link>https://safeguard.sh/resources/blog/php-security-best-practices-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-security-best-practices-guide</guid>
      <pubDate>Wed, 27 May 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Federal Procurement Rules and Their Ripple Effect on Priv...]]></title>
      <description><![CDATA[Federal rules from EO 14028 to FDA Section 524B and CMMC 2.0 have made SBOMs a procurement baseline — and the requirements are cascading into private-sector supply chains too.]]></description>
      <link>https://safeguard.sh/resources/blog/federal-procurement-rules-and-their-ripple-effect-on-private-sector-sbom-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/federal-procurement-rules-and-their-ripple-effect-on-private-sector-sbom-practices</guid>
      <pubDate>Wed, 27 May 2026 03:21:10 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Best Software Composition Analysis tools/services ranked ...]]></title>
      <description><![CDATA[We compare Safeguard and Mend.io on verifiable SCA dimensions — company history, Renovate, SBOM depth, and build provenance — for buyers evaluating tools in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/best-software-composition-analysis-toolsservices-ranked-and-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-software-composition-analysis-toolsservices-ranked-and-compared</guid>
      <pubDate>Wed, 27 May 2026 03:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[From Inventory to Insight: Turning SBOM Data Into Priorit...]]></title>
      <description><![CDATA[A complete SBOM often surfaces thousands of CVEs. Here's how reachability, exploitability, and business context turn that noise into a prioritized action plan.]]></description>
      <link>https://safeguard.sh/resources/blog/from-inventory-to-insight-turning-sbom-data-into-prioritized-action</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/from-inventory-to-insight-turning-sbom-data-into-prioritized-action</guid>
      <pubDate>Wed, 27 May 2026 02:00:43 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Better Ruby Gemfile security: a step-by-step guide]]></title>
      <description><![CDATA[A step-by-step guide to auditing your Gemfile.lock, spotting RubyGems supply chain attacks, and locking down Ruby dependencies before they ship.]]></description>
      <link>https://safeguard.sh/resources/blog/better-ruby-gemfile-security-a-step-by-step-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/better-ruby-gemfile-security-a-step-by-step-guide</guid>
      <pubDate>Wed, 27 May 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[The Unpaid Labor Behind Critical Internet Infrastructure]]></title>
      <description><![CDATA[Open source runs on unpaid maintainer labor. From xz-utils to Log4Shell to colors.js, we examine why burnout became a top supply chain security risk.]]></description>
      <link>https://safeguard.sh/resources/blog/the-unpaid-labor-behind-critical-internet-infrastructure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-unpaid-labor-behind-critical-internet-infrastructure</guid>
      <pubDate>Wed, 27 May 2026 00:40:16 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[SBOM standard formats compared (CycloneDX, SPDX, SWID)]]></title>
      <description><![CDATA[CycloneDX, SPDX, and SWID solve different problems. Here's how the SBOM formats differ, and how Safeguard's multi-format generation compares to Mend.io's approach.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-standard-formats-compared-cyclonedx-spdx-swid</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-standard-formats-compared-cyclonedx-spdx-swid</guid>
      <pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Why Maintainer Burnout Is a Security Metric, Not Just an ...]]></title>
      <description><![CDATA[The xz Utils backdoor started with a burned-out maintainer, not a zero-day. Here's why maintainer fatigue belongs in your supply chain risk model.]]></description>
      <link>https://safeguard.sh/resources/blog/why-maintainer-burnout-is-a-security-metric-not-just-an-hr-concern</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-maintainer-burnout-is-a-security-metric-not-just-an-hr-concern</guid>
      <pubDate>Tue, 26 May 2026 23:19:50 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Corporate Dependence on Volunteer-Maintained Projects: A ...]]></title>
      <description><![CDATA[Corporations run on code that volunteers maintain for free. Here's a data-backed risk map—from left-pad to the xz-utils backdoor—and how to manage it.]]></description>
      <link>https://safeguard.sh/resources/blog/corporate-dependence-on-volunteer-maintained-projects-a-risk-map</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/corporate-dependence-on-volunteer-maintained-projects-a-risk-map</guid>
      <pubDate>Tue, 26 May 2026 21:59:23 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Would It Actually Cost Companies to Fund Their Criti...]]></title>
      <description><![CDATA[Heartbleed, Log4Shell, and the 2024 xz backdoor all trace back to unpaid maintainers. Here's what it would actually cost companies to fund the dependencies they depend on.]]></description>
      <link>https://safeguard.sh/resources/blog/what-would-it-actually-cost-companies-to-fund-their-critical-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-would-it-actually-cost-companies-to-fund-their-critical-dependencies</guid>
      <pubDate>Tue, 26 May 2026 20:38:56 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Security Training Gaps Among Solo Maintainers of High-Imp...]]></title>
      <description><![CDATA[xz-utils, event-stream, and ua-parser-js show how single-maintainer projects lack the security training and support that high-impact infrastructure now demands.]]></description>
      <link>https://safeguard.sh/resources/blog/security-training-gaps-among-solo-maintainers-of-high-impact-projects</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-training-gaps-among-solo-maintainers-of-high-impact-projects</guid>
      <pubDate>Tue, 26 May 2026 19:18:30 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Succession Planning for Open Source Projects: Why It Rare...]]></title>
      <description><![CDATA[Most open source maintainers have no succession plan. That gap has already caused real incidents, from event-stream to XZ Utils, and it explains why.]]></description>
      <link>https://safeguard.sh/resources/blog/succession-planning-for-open-source-projects-why-it-rarely-happens</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/succession-planning-for-open-source-projects-why-it-rarely-happens</guid>
      <pubDate>Tue, 26 May 2026 17:58:03 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Sponsorship Models (GitHub Sponsors, Tidelift, Open C...]]></title>
      <description><![CDATA[GitHub Sponsors, Tidelift, and Open Collective pay maintainers in very different ways. Here's how their fees, payouts, and security guarantees actually compare.]]></description>
      <link>https://safeguard.sh/resources/blog/how-sponsorship-models-github-sponsors-tidelift-open-collective-compare</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-sponsorship-models-github-sponsors-tidelift-open-collective-compare</guid>
      <pubDate>Tue, 26 May 2026 16:37:36 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[TrapDoor: The Cross-Ecosystem Crypto Stealer That Targeted DeFi Developers (May 2026)]]></title>
      <description><![CDATA[Socket disclosed TrapDoor on May 24, 2026: 34+ malicious packages and 384+ versions across npm, PyPI, and Crates.io built to steal crypto wallets, SSH keys, and cloud credentials from crypto, DeFi, Solana, and AI developers.]]></description>
      <link>https://safeguard.sh/resources/blog/trapdoor-crypto-stealer-supply-chain-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trapdoor-crypto-stealer-supply-chain-may-2026</guid>
      <pubDate>Tue, 26 May 2026 16:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The XZ Utils Incident as a Case Study in Maintainer Trust...]]></title>
      <description><![CDATA[CVE-2024-3094 shows how a patient social-engineering campaign turned trusted open source maintainership into a near-catastrophic SSH backdoor.]]></description>
      <link>https://safeguard.sh/resources/blog/the-xz-utils-incident-as-a-case-study-in-maintainer-trust-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-xz-utils-incident-as-a-case-study-in-maintainer-trust-exploitation</guid>
      <pubDate>Tue, 26 May 2026 15:17:10 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Citrix Bleed 2: Analysis and Mitigation]]></title>
      <description><![CDATA[CVE-2025-5777 revived the memory-leak pattern that broke NetScaler in 2023. Here is what the 2025 variant does, who is exploiting it, and how to respond.]]></description>
      <link>https://safeguard.sh/resources/blog/citrix-bleed-2-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/citrix-bleed-2-analysis</guid>
      <pubDate>Tue, 26 May 2026 13:56:43 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Why Automated Tooling Can't Fully Replace Human Maintaine...]]></title>
      <description><![CDATA[Automated scanners missed the XZ Utils backdoor for years. Here's why CVE scores, SAST tools, and dependency bots can't replace human maintainer judgment.]]></description>
      <link>https://safeguard.sh/resources/blog/why-automated-tooling-cant-fully-replace-human-maintainer-judgment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-automated-tooling-cant-fully-replace-human-maintainer-judgment</guid>
      <pubDate>Tue, 26 May 2026 12:36:16 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Measuring Project Health: Bus Factor, Commit Velocity, an...]]></title>
      <description><![CDATA[Bus factor, commit velocity, and maintainer concentration predicted the xz-utils and event-stream incidents before any CVE did. Here's how to read these proxies — and where they mislead.]]></description>
      <link>https://safeguard.sh/resources/blog/measuring-project-health-bus-factor-commit-velocity-and-other-proxies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/measuring-project-health-bus-factor-commit-velocity-and-other-proxies</guid>
      <pubDate>Tue, 26 May 2026 11:15:50 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[10 React security best practices]]></title>
      <description><![CDATA[Real CVEs, real npm supply chain hijacks, and the concrete React practices — from CSP to token storage — that actually stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/10-react-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/10-react-security-best-practices</guid>
      <pubDate>Tue, 26 May 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[ASPM vs Traditional Vulnerability Management: What Actual...]]></title>
      <description><![CDATA[ASPM doesn't replace your scanners — it correlates their output with runtime reachability and ownership to cut a 10,000-finding backlog down to the handful that actually matter.]]></description>
      <link>https://safeguard.sh/resources/blog/aspm-vs-traditional-vulnerability-management-what-actually-changes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aspm-vs-traditional-vulnerability-management-what-actually-changes</guid>
      <pubDate>Tue, 26 May 2026 09:55:23 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Best SBOM tools for automating bill-of-materials generation]]></title>
      <description><![CDATA[A practical look at the best SBOM tools for 2026, comparing how Safeguard and Mend.io generate, format, and continuously update software bills of materials.]]></description>
      <link>https://safeguard.sh/resources/blog/best-sbom-tools-for-automating-bill-of-materials-generation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-sbom-tools-for-automating-bill-of-materials-generation</guid>
      <pubDate>Tue, 26 May 2026 09:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Why Alert Fatigue, Not Tool Gaps, Is the Real AppSec Bott...]]></title>
      <description><![CDATA[AppSec teams don't fail from missing tools, they fail from thousands of unprioritized alerts. Here's why alert fatigue is the real AppSec bottleneck.]]></description>
      <link>https://safeguard.sh/resources/blog/why-alert-fatigue-not-tool-gaps-is-the-real-appsec-bottleneck</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-alert-fatigue-not-tool-gaps-is-the-real-appsec-bottleneck</guid>
      <pubDate>Tue, 26 May 2026 08:34:56 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[react-slick: Security and Maintenance Guide for 2025]]></title>
      <description><![CDATA[react-slick is a hugely popular carousel component with no known CVEs, but slowing maintenance and its dependency chain are the risks worth watching before you adopt it.]]></description>
      <link>https://safeguard.sh/resources/blog/react-slick</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-slick</guid>
      <pubDate>Tue, 26 May 2026 07:14:29 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[6 Angular security best practices cheat sheet]]></title>
      <description><![CDATA[A six-part cheat sheet on Angular security: sanitizer limits, AngularJS EOL, dependency risk, token storage, CSP nonces, and library auditing.]]></description>
      <link>https://safeguard.sh/resources/blog/6-angular-security-best-practices-cheat-sheet</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/6-angular-security-best-practices-cheat-sheet</guid>
      <pubDate>Tue, 26 May 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Open source license management tools: features and best p...]]></title>
      <description><![CDATA[A practical comparison of open source license management tools, contrasting Safeguard and Mend.io on detection, policy enforcement, and SBOM depth.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-license-management-tools-features-and-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-license-management-tools-features-and-best-practices</guid>
      <pubDate>Tue, 26 May 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Runtime Reachability Analysis: Cutting Through Vulnerabil...]]></title>
      <description><![CDATA[Most CVE findings are noise. Here's how runtime reachability analysis separates exploitable risk from theoretical severity, and why CVSS alone can't prioritize your patch queue.]]></description>
      <link>https://safeguard.sh/resources/blog/runtime-reachability-analysis-cutting-through-vulnerability-noise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runtime-reachability-analysis-cutting-through-vulnerability-noise</guid>
      <pubDate>Tue, 26 May 2026 05:54:03 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[BOLA: Broken Object Level Authorization, Explained]]></title>
      <description><![CDATA[A bola vulnerability lets one authenticated user reach another user's data just by changing an ID in a request — no exploit code required, which is exactly why scanners miss it so often.]]></description>
      <link>https://safeguard.sh/resources/blog/bola-vulnerability-broken-object-level-authorization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bola-vulnerability-broken-object-level-authorization</guid>
      <pubDate>Tue, 26 May 2026 04:33:36 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Comparing React and Angular secure coding practices]]></title>
      <description><![CDATA[React auto-escapes JSX but not URLs; Angular sanitizes by context but allows explicit bypasses. Here's where each framework's XSS defenses actually stop.]]></description>
      <link>https://safeguard.sh/resources/blog/comparing-react-and-angular-secure-coding-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/comparing-react-and-angular-secure-coding-practices</guid>
      <pubDate>Tue, 26 May 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Sigstore Cosign Keyless Signing Explained for Teams]]></title>
      <description><![CDATA[Keyless signing swaps long-lived private keys for ten-minute certificates tied to an OIDC identity. How Fulcio and Rekor work, and how to roll it out without breaking deploys.]]></description>
      <link>https://safeguard.sh/resources/blog/sigstore-cosign-keyless-signing-explained-for-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sigstore-cosign-keyless-signing-explained-for-teams</guid>
      <pubDate>Tue, 26 May 2026 03:13:09 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Aisha Bello)</author>
    </item>
    <item>
      <title><![CDATA[Best DevSecOps tools to secure the SDLC]]></title>
      <description><![CDATA[Comparing the best DevSecOps tools to secure the SDLC: Mend.io's SCA-first platform vs Safeguard's reachability-driven, supply-chain-wide approach.]]></description>
      <link>https://safeguard.sh/resources/blog/best-devsecops-tools-to-secure-the-sdlc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-devsecops-tools-to-secure-the-sdlc</guid>
      <pubDate>Tue, 26 May 2026 03:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Consolidation Wave: Why AppSec Vendors Are Buying Runtime...]]></title>
      <description><![CDATA[CrowdStrike, Cisco, Tenable, and others have spent three years buying runtime-visibility startups. Here's why AppSec vendors need runtime context to fix alert overload.]]></description>
      <link>https://safeguard.sh/resources/blog/consolidation-wave-why-appsec-vendors-are-buying-runtime-visibility-startups</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/consolidation-wave-why-appsec-vendors-are-buying-runtime-visibility-startups</guid>
      <pubDate>Tue, 26 May 2026 01:52:43 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AngularJS security fundamentals]]></title>
      <description><![CDATA[AngularJS has been unpatched since January 2022, yet it still runs in production. Here's the CVE history, the sandbox saga, and how to find your exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/angularjs-security-fundamentals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/angularjs-security-fundamentals</guid>
      <pubDate>Tue, 26 May 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Cloud-to-Code Traceability: Connecting Production Inciden...]]></title>
      <description><![CDATA[When a production alert fires, it names an IP or image hash—rarely a commit or author. Here's why that gap exists and how to close it fast.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-to-code-traceability-connecting-production-incidents-back-to-source</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-to-code-traceability-connecting-production-incidents-back-to-source</guid>
      <pubDate>Tue, 26 May 2026 00:32:16 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Top SAST solutions compared for 2026]]></title>
      <description><![CDATA[Comparing Safeguard and Mend.io on SAST scope, CI/CD fit, and compliance coverage—what's verifiable, what to test yourself, and how a unified platform changes the tradeoffs.]]></description>
      <link>https://safeguard.sh/resources/blog/top-sast-solutions-compared-for-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-sast-solutions-compared-for-2026</guid>
      <pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How Risk Scoring Models Differ Across AppSec Platforms]]></title>
      <description><![CDATA[CVSS, EPSS, SSVC, and vendor priority scores all measure vulnerability risk differently. Here's how they diverge, with real numbers, and how reachability analysis cuts through the noise.]]></description>
      <link>https://safeguard.sh/resources/blog/how-risk-scoring-models-differ-across-appsec-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-risk-scoring-models-differ-across-appsec-platforms</guid>
      <pubDate>Mon, 25 May 2026 23:11:49 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Supabase MCP and the Lethal Trifecta: When an Agent Has service_role]]></title>
      <description><![CDATA[A Cursor user's Supabase MCP server was tricked by a support ticket into exfiltrating an integration_tokens table. The bug was not in MCP. It was in the trifecta.]]></description>
      <link>https://safeguard.sh/resources/blog/supabase-mcp-lethal-trifecta-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supabase-mcp-lethal-trifecta-2025</guid>
      <pubDate>Mon, 25 May 2026 21:51:23 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[The Business Case for Consolidating SAST, SCA, and DAST U...]]></title>
      <description><![CDATA[Fragmented SAST, SCA, and DAST tools cost more than three licenses — they cost analyst hours, slower remediation, and longer audits. Here's the real ROI math for consolidation.]]></description>
      <link>https://safeguard.sh/resources/blog/the-business-case-for-consolidating-sast-sca-and-dast-under-one-pane</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-business-case-for-consolidating-sast-sca-and-dast-under-one-pane</guid>
      <pubDate>Mon, 25 May 2026 20:30:56 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Why Security Debt Accumulates Fastest in the Most 'Produc...]]></title>
      <description><![CDATA[High-velocity engineering teams accumulate the most security debt, not the least. Here's why speed hides risk — and how to catch it without slowing down.]]></description>
      <link>https://safeguard.sh/resources/blog/why-security-debt-accumulates-fastest-in-the-most-productive-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-security-debt-accumulates-fastest-in-the-most-productive-teams</guid>
      <pubDate>Mon, 25 May 2026 19:10:29 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Benchmarking Mean Time to Remediate Across Company Size a...]]></title>
      <description><![CDATA[MTTR benchmarks vary 2-5x by company size and industry. See how financial services, healthcare, and mid-sized firms compare — and what a realistic 2026 target looks like.]]></description>
      <link>https://safeguard.sh/resources/blog/benchmarking-mean-time-to-remediate-across-company-size-and-industry</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/benchmarking-mean-time-to-remediate-across-company-size-and-industry</guid>
      <pubDate>Mon, 25 May 2026 17:50:03 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[eBPF and OpenTelemetry: The New Instrumentation Layer for...]]></title>
      <description><![CDATA[eBPF and OpenTelemetry are becoming AppSec's new runtime instrumentation layer, catching supply chain attacks like the xz backdoor that static scanners miss entirely.]]></description>
      <link>https://safeguard.sh/resources/blog/ebpf-and-opentelemetry-the-new-instrumentation-layer-for-appsec</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ebpf-and-opentelemetry-the-new-instrumentation-layer-for-appsec</guid>
      <pubDate>Mon, 25 May 2026 16:29:36 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Node.js vm Module Security: Why It Is Not a Sandbox]]></title>
      <description><![CDATA[The Node.js vm module runs code in a separate V8 context, but it is not a security sandbox. Here is why untrusted code can escape it and what to use instead.]]></description>
      <link>https://safeguard.sh/resources/blog/node-vm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-vm</guid>
      <pubDate>Mon, 25 May 2026 15:09:09 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[An Engineering Guide to AI Bill of Materials (AIBOM)]]></title>
      <description><![CDATA[An AIBOM extends the SBOM to models, datasets, and prompts. What goes in one, how CycloneDX 1.6 encodes it, and how to generate it in CI without a documentation project.]]></description>
      <link>https://safeguard.sh/resources/blog/an-engineering-guide-to-ai-bill-of-materials-aibom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/an-engineering-guide-to-ai-bill-of-materials-aibom</guid>
      <pubDate>Mon, 25 May 2026 14:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Elena Kovacs)</author>
    </item>
    <item>
      <title><![CDATA[Archiver npm: A Security Review and Safe-Usage Guide]]></title>
      <description><![CDATA[The archiver npm package builds zip and tar streams cleanly, but the real risks are on the extraction side and in its dependency tree. Here is how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/archiver-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/archiver-npm</guid>
      <pubDate>Mon, 25 May 2026 13:48:42 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to Choose a Python Code Checker for Secure Code]]></title>
      <description><![CDATA[A Python code checker is more than a linter. Here is how the layers fit together, which open-source tools do what, and where online checkers help and hurt.]]></description>
      <link>https://safeguard.sh/resources/blog/python-code-checker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-code-checker</guid>
      <pubDate>Mon, 25 May 2026 12:28:16 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[jwks-rsa: Verifying JWTs Against a JWKS Endpoint Safely]]></title>
      <description><![CDATA[The jwks-rsa npm library fetches signing keys from a JWKS endpoint so you can verify JWTs correctly. Here is how to wire it up without introducing key-confusion or availability bugs.]]></description>
      <link>https://safeguard.sh/resources/blog/jwks-rsa-npm-jwt-verification-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jwks-rsa-npm-jwt-verification-guide</guid>
      <pubDate>Mon, 25 May 2026 11:07:49 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[10 Spring Boot security best practices]]></title>
      <description><![CDATA[Ten concrete Spring Boot security practices, with real CVEs, config flags, and file paths, to close the gaps attackers actually exploit.]]></description>
      <link>https://safeguard.sh/resources/blog/10-spring-boot-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/10-spring-boot-security-best-practices</guid>
      <pubDate>Mon, 25 May 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Zombie APIs: The Forgotten Endpoints That Put You at Risk]]></title>
      <description><![CDATA[A zombie API is a forgotten, undocumented endpoint that still runs and still accepts traffic. Here is why they are dangerous and how to find and kill them.]]></description>
      <link>https://safeguard.sh/resources/blog/zombie-api</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zombie-api</guid>
      <pubDate>Mon, 25 May 2026 09:47:22 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Best application security testing providers ranked]]></title>
      <description><![CDATA[Mend.io built its reputation on SCA and open source dependency scanning. Here's how Safeguard's supply chain security approach compares.]]></description>
      <link>https://safeguard.sh/resources/blog/best-application-security-testing-providers-ranked</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-application-security-testing-providers-ranked</guid>
      <pubDate>Mon, 25 May 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[OWASP 2019: The API Security Top 10 That Reshaped API Testing]]></title>
      <description><![CDATA[The OWASP release everyone means by 2019 is the first API Security Top 10, which put authorization flaws — not injection — at the center of API risk.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-2019</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-2019</guid>
      <pubDate>Mon, 25 May 2026 08:26:56 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[@types/node Explained: What the Package Does and Why It Matters for Security]]></title>
      <description><![CDATA[@types/node is the TypeScript definitions for Node.js, pulled from DefinitelyTyped. Here is how it works, why version drift causes headaches, and its real supply-chain footprint.]]></description>
      <link>https://safeguard.sh/resources/blog/types-node</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/types-node</guid>
      <pubDate>Mon, 25 May 2026 07:06:29 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[A guide to input validation with Spring Boot]]></title>
      <description><![CDATA[Spring Boot doesn't validate input by default. Here's how Bean Validation actually works, where teams get it wrong, and how missing validation leads to injection and mass assignment.]]></description>
      <link>https://safeguard.sh/resources/blog/a-guide-to-input-validation-with-spring-boot</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/a-guide-to-input-validation-with-spring-boot</guid>
      <pubDate>Mon, 25 May 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Top container security tools to evaluate]]></title>
      <description><![CDATA[Comparing Safeguard and Mend.io on the dimensions that actually matter for container security: scanning engine transparency, air-gapped support, registry coverage, and product origin.]]></description>
      <link>https://safeguard.sh/resources/blog/top-container-security-tools-to-evaluate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-container-security-tools-to-evaluate</guid>
      <pubDate>Mon, 25 May 2026 06:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Securing AI Agents: MCP Protocol Risks and Mitigations]]></title>
      <description><![CDATA[The Model Context Protocol is transforming how AI agents interact with tools, but it introduces new attack surfaces. Here is what security teams need to understand.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-ai-agents-mcp-protocol-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-ai-agents-mcp-protocol-risks</guid>
      <pubDate>Mon, 25 May 2026 05:46:02 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[spring-boot-starter-actuator: Securing Exposed Actuator Endpoints]]></title>
      <description><![CDATA[spring-boot-starter-actuator gives you production-grade health and metrics endpoints, but a single misconfigured deployment can leak secrets and heap dumps to the internet.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-boot-starter-actuator</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-boot-starter-actuator</guid>
      <pubDate>Mon, 25 May 2026 04:25:36 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to secure Python Flask applications]]></title>
      <description><![CDATA[Flask ships without built-in CSRF, headers, or session hardening. Here's how real CVEs like debug-mode RCE and cookie forgery get exploited—and stopped.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-secure-python-flask-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-secure-python-flask-applications</guid>
      <pubDate>Mon, 25 May 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Tool Poisoning Attacks: How Malicious Instructions Hide I...]]></title>
      <description><![CDATA[AI agent tools can hide invisible instructions attackers use to steal data. Here's how tool poisoning attacks work and how Safeguard stops them.]]></description>
      <link>https://safeguard.sh/resources/blog/tool-poisoning-attacks-how-malicious-instructions-hide-inside-ai-agent-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tool-poisoning-attacks-how-malicious-instructions-hide-inside-ai-agent-tools</guid>
      <pubDate>Mon, 25 May 2026 03:05:09 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Evaluating AI Security Posture Management (AI-SPM) tools:...]]></title>
      <description><![CDATA[A practical, criteria-based comparison of Safeguard and Mend.io for AI-SPM buyers: provenance verification, AI-BOM depth, and CI/CD policy enforcement.]]></description>
      <link>https://safeguard.sh/resources/blog/evaluating-ai-security-posture-management-ai-spm-tools-key-criteria</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/evaluating-ai-security-posture-management-ai-spm-tools-key-criteria</guid>
      <pubDate>Mon, 25 May 2026 03:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Hacking Tools Explained: What Security Testers Actually Use]]></title>
      <description><![CDATA[Hacking tools are the same instruments attackers and defenders both use to probe systems. Knowing the major categories helps you test your own environment before someone else does.]]></description>
      <link>https://safeguard.sh/resources/blog/hacking-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hacking-tools</guid>
      <pubDate>Mon, 25 May 2026 01:44:42 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Securing Django applications from common vulnerabilities]]></title>
      <description><![CDATA[Django's secure-by-default reputation hides real gaps: SQL injection via Trunc()/Extract(), ReDoS in Truncator, and misconfigured DEBUG settings still cause incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-django-applications-from-common-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-django-applications-from-common-vulnerabilities</guid>
      <pubDate>Mon, 25 May 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Model Context Protocol Security 101: What Could Go Wrong ...]]></title>
      <description><![CDATA[MCP lets AI models call tools automatically — and lets malicious servers hide instructions in plain sight. Here's how tool poisoning, rug pulls, and shadowing actually work.]]></description>
      <link>https://safeguard.sh/resources/blog/model-context-protocol-security-101-what-could-go-wrong-and-why</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/model-context-protocol-security-101-what-could-go-wrong-and-why</guid>
      <pubDate>Mon, 25 May 2026 00:24:16 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best AI red teaming tools ranked]]></title>
      <description><![CDATA[Best AI red teaming tools ranked: how Mend.io's SCA scanning and Safeguard's exploitability-first SBOM analysis actually differ for AI supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/best-ai-red-teaming-tools-ranked</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-ai-red-teaming-tools-ranked</guid>
      <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Agent Skill Marketplaces as the Next Frontier for Supply ...]]></title>
      <description><![CDATA[Agent skill marketplaces are repeating npm and PyPI's supply chain mistakes—except the malicious payload is often a sentence of instructions, not code. Here's what's already been exploited.]]></description>
      <link>https://safeguard.sh/resources/blog/agent-skill-marketplaces-as-the-next-frontier-for-supply-chain-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agent-skill-marketplaces-as-the-next-frontier-for-supply-chain-attacks</guid>
      <pubDate>Sun, 24 May 2026 23:03:49 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Prompt Injection vs Traditional Injection Attacks: A Tech...]]></title>
      <description><![CDATA[SQL injection was solved by separating code from data. Prompt injection can't be, because in an LLM they share one channel. Here's the technical comparison, with real exploits and dates.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-vs-traditional-injection-attacks-a-technical-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-vs-traditional-injection-attacks-a-technical-comparison</guid>
      <pubDate>Sun, 24 May 2026 21:43:22 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-53770 in SharePoint (ToolShell): Patch Posture & SBOM Response]]></title>
      <description><![CDATA[On-prem SharePoint deserialization flaw scored CVSS 9.8 and entered CISA KEV the day after public exploitation. Defender playbook below.]]></description>
      <link>https://safeguard.sh/resources/blog/sharepoint-toolshell-cve-2025-53770-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sharepoint-toolshell-cve-2025-53770-patch-response</guid>
      <pubDate>Sun, 24 May 2026 20:22:55 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx SAST: How It Works, What It Scans, and Where It Fits]]></title>
      <description><![CDATA[Checkmarx SAST is a static application security testing engine that finds flaws in your source code without running it. Here is how it works, what it scans, and how to fit it into a pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-sast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-sast</guid>
      <pubDate>Sun, 24 May 2026 19:02:29 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[react-md-editor: Using @uiw/react-md-editor Securely]]></title>
      <description><![CDATA[How to use react-md-editor safely: what @uiw/react-md-editor does, the XSS risk in markdown preview, and why rehype-sanitize is not optional for untrusted input.]]></description>
      <link>https://safeguard.sh/resources/blog/react-md-editor</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-md-editor</guid>
      <pubDate>Sun, 24 May 2026 17:42:02 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to Uninstall Java Safely on Windows, macOS, and Linux]]></title>
      <description><![CDATA[To uninstall Java cleanly you need to remove the runtime, clear leftover paths and environment variables, and confirm nothing critical still depends on it.]]></description>
      <link>https://safeguard.sh/resources/blog/uninstall-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uninstall-java</guid>
      <pubDate>Sun, 24 May 2026 16:21:35 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Why Autonomous Coding Agents Need Their Own Threat Model]]></title>
      <description><![CDATA[Coding agents run with real credentials and no pause button. Here is the threat model that treats them as autonomous infrastructure, not junior developers.]]></description>
      <link>https://safeguard.sh/resources/blog/why-autonomous-coding-agents-need-their-own-threat-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-autonomous-coding-agents-need-their-own-threat-model</guid>
      <pubDate>Sun, 24 May 2026 15:01:09 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SCA Security Testing: A Workflow Guide]]></title>
      <description><![CDATA[SCA security testing only works when it's wired into an actual development workflow — here's what that pipeline looks like from commit to merge to production monitoring.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-security-testing-workflow-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-security-testing-workflow-guide</guid>
      <pubDate>Sun, 24 May 2026 13:40:42 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[PyPI's aliyun-ai-labs Campaign: Three Packages, One Targeted Region]]></title>
      <description><![CDATA[Three PyPI packages impersonating Alibaba's AI Labs SDK exfiltrated .gitconfig data from developer machines in a regionally targeted 2025 espionage campaign.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-aliyun-ai-labs-malicious-sdk-campaign-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-aliyun-ai-labs-malicious-sdk-campaign-2025</guid>
      <pubDate>Sun, 24 May 2026 12:20:15 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Security Scanner: How It Works and What to Use]]></title>
      <description><![CDATA[A JavaScript security scanner analyzes your code and dependencies for vulnerabilities. Here's what the different scanner types catch and how to wire them into CI.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-security-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-security-scanner</guid>
      <pubDate>Sun, 24 May 2026 10:59:49 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Comparing Node.js frameworks for security: Express, Fastify, NestJS]]></title>
      <description><![CDATA[Express, Fastify, and NestJS compared on real CVE history, default security posture, and dependency risk — plus how to close the gaps framework choice alone can't.]]></description>
      <link>https://safeguard.sh/resources/blog/comparing-nodejs-frameworks-for-security-express-fastify-nestjs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/comparing-nodejs-frameworks-for-security-express-fastify-nestjs</guid>
      <pubDate>Sun, 24 May 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Automated Vulnerability Scanning Tools: How They Work and What to Look For]]></title>
      <description><![CDATA[Automated vulnerability scanning tools turn a once-a-year audit into a continuous safety net — if you understand what each type actually inspects.]]></description>
      <link>https://safeguard.sh/resources/blog/automated-vulnerability-scanning-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automated-vulnerability-scanning-tools</guid>
      <pubDate>Sun, 24 May 2026 09:39:22 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Mend.io vs Black Duck: choosing an AppSec/SCA platform]]></title>
      <description><![CDATA[A practical, evidence-based look at how Mend.io and Black Duck approach SCA — and where Safeguard's reachability-aware scanning and SBOM tooling differ.]]></description>
      <link>https://safeguard.sh/resources/blog/mendio-vs-black-duck-choosing-an-appsecsca-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mendio-vs-black-duck-choosing-an-appsecsca-platform</guid>
      <pubDate>Sun, 24 May 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Jailbreaking Economy: How Model Vulnerabilities Get D...]]></title>
      <description><![CDATA[Jailbreak prompts now trade like exploits: sold as $200/month "dark" chatbots, bountied by vendors for up to $15,000. Here's how that market actually works.]]></description>
      <link>https://safeguard.sh/resources/blog/the-jailbreaking-economy-how-model-vulnerabilities-get-discovered-and-sold</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-jailbreaking-economy-how-model-vulnerabilities-get-discovered-and-sold</guid>
      <pubDate>Sun, 24 May 2026 08:18:55 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[5 Node.js security code snippets every backend developer should know]]></title>
      <description><![CDATA[Five real Node.js vulnerability patterns with vulnerable-vs-fixed code: prototype pollution, NoSQL injection, missing headers, path traversal, and JWT flaws.]]></description>
      <link>https://safeguard.sh/resources/blog/5-nodejs-security-code-snippets-every-backend-developer-should-know</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/5-nodejs-security-code-snippets-every-backend-developer-should-know</guid>
      <pubDate>Sun, 24 May 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Least Privilege for AI Agents: Why It's Harder Than It So...]]></title>
      <description><![CDATA[AI agents break least-privilege assumptions built for humans: they chain tools, act autonomously, and compose narrow scopes into broad access no one reviewed.]]></description>
      <link>https://safeguard.sh/resources/blog/least-privilege-for-ai-agents-why-its-harder-than-it-sounds</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/least-privilege-for-ai-agents-why-its-harder-than-it-sounds</guid>
      <pubDate>Sun, 24 May 2026 06:58:28 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Mend.io vs Noma Security: AI security platform comparison]]></title>
      <description><![CDATA[Mend.io vs Noma Security: how these AI security platforms compare, and where Safeguard fits with its own AI-BOM, model scanning, and AI Gateway.]]></description>
      <link>https://safeguard.sh/resources/blog/mendio-vs-noma-security-ai-security-platform-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mendio-vs-noma-security-ai-security-platform-comparison</guid>
      <pubDate>Sun, 24 May 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Distinguishing Model Risk from Application Risk in Agenti...]]></title>
      <description><![CDATA[Model flaws and application flaws in AI agents cause different breaches and need different fixes. Real incidents show where each risk actually lives — and how to test for both.]]></description>
      <link>https://safeguard.sh/resources/blog/distinguishing-model-risk-from-application-risk-in-agentic-systems</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/distinguishing-model-risk-from-application-risk-in-agentic-systems</guid>
      <pubDate>Sun, 24 May 2026 05:38:02 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How Malicious Payloads Get Smuggled Into Trusted AI Skill...]]></title>
      <description><![CDATA[Attackers smuggle malicious payloads into trusted AI skill repositories via typosquats, staged fetches, and split-file obfuscation — here is exactly how it works.]]></description>
      <link>https://safeguard.sh/resources/blog/how-malicious-payloads-get-smuggled-into-trusted-ai-skill-repositories</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-malicious-payloads-get-smuggled-into-trusted-ai-skill-repositories</guid>
      <pubDate>Sun, 24 May 2026 04:17:35 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Securing Next.js applications and middleware]]></title>
      <description><![CDATA[CVE-2025-29927 let attackers bypass Next.js middleware auth with one header. Here's how that and three other real CVEs expose middleware, Server Actions, and caching.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-nextjs-applications-and-middleware</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-nextjs-applications-and-middleware</guid>
      <pubDate>Sun, 24 May 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Mend.io alternatives for SCA/AppSec buyers]]></title>
      <description><![CDATA[A concrete look at Mend.io alternatives for SCA and AppSec buyers, comparing policy enforcement, SBOM generation, and build integrity against Safeguard's unified platform.]]></description>
      <link>https://safeguard.sh/resources/blog/mendio-alternatives-for-scaappsec-buyers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mendio-alternatives-for-scaappsec-buyers</guid>
      <pubDate>Sun, 24 May 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[What an AI Model Risk Registry Should Actually Track]]></title>
      <description><![CDATA[Most AI model inventories are name-and-owner spreadsheets. Here's the provenance, licensing, CVE, and revalidation fields a real AI model risk registry needs to track.]]></description>
      <link>https://safeguard.sh/resources/blog/what-an-ai-model-risk-registry-should-actually-track</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-an-ai-model-risk-registry-should-actually-track</guid>
      <pubDate>Sun, 24 May 2026 02:57:08 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Agentic AI Security Glossary: Tool Poisoning, Prompt Inje...]]></title>
      <description><![CDATA[A precise glossary of agentic AI security terms — prompt injection, tool poisoning, model jailbreaking, excessive agency, and MCP rug pulls — with concrete attack examples.]]></description>
      <link>https://safeguard.sh/resources/blog/agentic-ai-security-glossary-tool-poisoning-prompt-injection-and-model-jailbreaking-defined</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agentic-ai-security-glossary-tool-poisoning-prompt-injection-and-model-jailbreaking-defined</guid>
      <pubDate>Sun, 24 May 2026 01:36:42 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-29927: Next.js middleware authorization bypass]]></title>
      <description><![CDATA[A spoofable internal header let attackers skip Next.js middleware outright, bypassing auth and route protection across many production deployments.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2025-29927-nextjs-middleware-authorization-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2025-29927-nextjs-middleware-authorization-bypass</guid>
      <pubDate>Sun, 24 May 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Permissions: A Practical Checklist for Reducin...]]></title>
      <description><![CDATA[A practical checklist for scoping MCP server permissions, denying risky defaults, and limiting the blast radius when an AI agent's tool access is exploited.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-permissions-a-practical-checklist-for-reducing-blast-radius</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-permissions-a-practical-checklist-for-reducing-blast-radius</guid>
      <pubDate>Sun, 24 May 2026 00:16:15 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Open source vulnerability management workflow (detect, pr...]]></title>
      <description><![CDATA[A concrete look at the detect-prioritize-remediate workflow for open source vulnerability management, where Mend.io's SCA approach falls short, and how Safeguard closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-vulnerability-management-workflow-detect-prioritize-remediate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-vulnerability-management-workflow-detect-prioritize-remediate</guid>
      <pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Joi npm: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[The joi npm package is the widely used JavaScript schema validation library. Here is its maintenance status, the @hapi/joi migration, and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/joi-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/joi-npm</guid>
      <pubDate>Sat, 23 May 2026 22:55:48 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Why Traditional SAST Tools Struggle to Analyze Agentic Co...]]></title>
      <description><![CDATA[Agentic codebases build call graphs at runtime, defeating static analysis. Here's why SAST tools miss prompt injection and tool-schema risks—and how Safeguard closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/why-traditional-sast-tools-struggle-to-analyze-agentic-codebases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-traditional-sast-tools-struggle-to-analyze-agentic-codebases</guid>
      <pubDate>Sat, 23 May 2026 21:35:22 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Shift Left Fatigue: Why Developers Are Pushing Back on Se...]]></title>
      <description><![CDATA[Shift-left security handed developers new duties without removing old ones. Here's why teams are pushing back — and how better tooling fixes the real problem: noise, not ownership.]]></description>
      <link>https://safeguard.sh/resources/blog/shift-left-fatigue-why-developers-are-pushing-back-on-security-ownership</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shift-left-fatigue-why-developers-are-pushing-back-on-security-ownership</guid>
      <pubDate>Sat, 23 May 2026 20:14:55 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Why Security Training Completion Rates Don't Predict Secu...]]></title>
      <description><![CDATA[Completion rates measure attendance, not behavior. Here's why training checkboxes don't predict secure coding outcomes, and what to measure instead.]]></description>
      <link>https://safeguard.sh/resources/blog/why-security-training-completion-rates-dont-predict-secure-coding-behavior</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-security-training-completion-rates-dont-predict-secure-coding-behavior</guid>
      <pubDate>Sat, 23 May 2026 18:54:28 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Friction as a Security Metric: Measuring Tool Adoption Fa...]]></title>
      <description><![CDATA[Security tools fail quietly when developers route around them. Here's how to measure friction as a leading indicator of adoption failure before it causes a breach.]]></description>
      <link>https://safeguard.sh/resources/blog/friction-as-a-security-metric-measuring-tool-adoption-failure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/friction-as-a-security-metric-measuring-tool-adoption-failure</guid>
      <pubDate>Sat, 23 May 2026 17:34:02 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Champion Model: Do Embedded Security Champions Actual...]]></title>
      <description><![CDATA[Security champion programs cut vulnerabilities only under specific conditions. Here's what BSIMM, GitLab, and OWASP data show about when the champion model actually works.]]></description>
      <link>https://safeguard.sh/resources/blog/the-champion-model-do-embedded-security-champions-actually-reduce-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-champion-model-do-embedded-security-champions-actually-reduce-risk</guid>
      <pubDate>Sat, 23 May 2026 16:13:35 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Megalodon: 5,561 GitHub Repos Backdoored via Injected Actions Workflows (May 2026)]]></title>
      <description><![CDATA[In a six-hour window on May 18, 2026, an automated campaign pushed malicious GitHub Actions workflows into 5,561 repositories using credentials harvested by infostealers. We break down the attack chain, the workflow_dispatch dormancy trick, and CI detection.]]></description>
      <link>https://safeguard.sh/resources/blog/megalodon-github-actions-mass-workflow-injection-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/megalodon-github-actions-mass-workflow-injection-may-2026</guid>
      <pubDate>Sat, 23 May 2026 16:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Screening Serpens (UNC1549): Iran-Nexus Espionage and the MiniUpdate RAT (May 2026)]]></title>
      <description><![CDATA[Unit 42's May 22, 2026 report tracks the Iran-nexus group Screening Serpens deploying new MiniUpdate and MiniJunk V2 RATs against US, Israeli, and Gulf targets using job-themed lures and DLL sideloading.]]></description>
      <link>https://safeguard.sh/resources/blog/screening-serpens-unc1549-iran-espionage-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/screening-serpens-unc1549-iran-espionage-may-2026</guid>
      <pubDate>Sat, 23 May 2026 16:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why Security and Engineering KPIs Are Still Misaligned in...]]></title>
      <description><![CDATA[Security teams chase CVSS scores and SLA compliance while engineering chases velocity and uptime—two scorecards that were never built to agree.]]></description>
      <link>https://safeguard.sh/resources/blog/why-security-and-engineering-kpis-are-still-misaligned-in-most-orgs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-security-and-engineering-kpis-are-still-misaligned-in-most-orgs</guid>
      <pubDate>Sat, 23 May 2026 14:53:08 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Policy Bypass Culture: What Happens When Deadlines Beat G...]]></title>
      <description><![CDATA[When deadlines collide with security gates, developers bypass them quietly and often. Here's how policy bypass culture forms, what it costs, and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/policy-bypass-culture-what-happens-when-deadlines-beat-guardrails</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/policy-bypass-culture-what-happens-when-deadlines-beat-guardrails</guid>
      <pubDate>Sat, 23 May 2026 13:32:41 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Measuring Developer Security Maturity Beyond Tool Coverage]]></title>
      <description><![CDATA[Tool coverage tells you what's installed, not whether developers are actually getting safer. Here's how to build a maturity model around remediation velocity, recurrence, and secrets hygiene instead.]]></description>
      <link>https://safeguard.sh/resources/blog/measuring-developer-security-maturity-beyond-tool-coverage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/measuring-developer-security-maturity-beyond-tool-coverage</guid>
      <pubDate>Sat, 23 May 2026 12:12:15 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Hidden Cost of Context Switching Between IDE and Secu...]]></title>
      <description><![CDATA[Jumping between your IDE and security dashboards isn't free. Here's what context switching really costs developers, and how to eliminate it.]]></description>
      <link>https://safeguard.sh/resources/blog/the-hidden-cost-of-context-switching-between-ide-and-security-dashboards</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-hidden-cost-of-context-switching-between-ide-and-security-dashboards</guid>
      <pubDate>Sat, 23 May 2026 10:51:48 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[React Server Components RCE vulnerability advisory]]></title>
      <description><![CDATA[CVE-2025-29927 lets attackers bypass Next.js middleware auth with a forged header — a chain that can escalate to full RCE on React Server Components apps.]]></description>
      <link>https://safeguard.sh/resources/blog/react-server-components-rce-vulnerability-advisory</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-server-components-rce-vulnerability-advisory</guid>
      <pubDate>Sat, 23 May 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Why Small Teams Often Outperform Large Enterprises on Fix...]]></title>
      <description><![CDATA[Small teams often patch critical CVEs in hours while enterprises take weeks — not because of talent, but process. Here's why, and how to close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/why-small-teams-often-outperform-large-enterprises-on-fix-velocity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-small-teams-often-outperform-large-enterprises-on-fix-velocity</guid>
      <pubDate>Sat, 23 May 2026 09:31:21 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Reachability analysis for prioritizing vulnerable depende...]]></title>
      <description><![CDATA[Most flagged CVEs in your dependency tree are never executed. Here's how reachability analysis application security separates exploitable risk from noise—and how Safeguard compares to Mend.io.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-for-prioritizing-vulnerable-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-for-prioritizing-vulnerable-dependencies</guid>
      <pubDate>Sat, 23 May 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Gamification of Secure Coding: Does It Change Long-Term B...]]></title>
      <description><![CDATA[Gamified secure coding training boosts engagement fast — but does it change what developers ship six months later? Here's what the data actually shows.]]></description>
      <link>https://safeguard.sh/resources/blog/gamification-of-secure-coding-does-it-change-long-term-behavior</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gamification-of-secure-coding-does-it-change-long-term-behavior</guid>
      <pubDate>Sat, 23 May 2026 08:10:55 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[5 best practices for React with TypeScript security]]></title>
      <description><![CDATA[TypeScript's type system stops at compile time. Five concrete practices — with real CVEs and incidents — for securing React + TypeScript apps against what it misses.]]></description>
      <link>https://safeguard.sh/resources/blog/5-best-practices-for-react-with-typescript-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/5-best-practices-for-react-with-typescript-security</guid>
      <pubDate>Sat, 23 May 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[The Generational Divide in Attitudes Toward AI-Assisted C...]]></title>
      <description><![CDATA[Younger developers trust AI-generated code far more than senior engineers do. That gap decides who reviews a PR before a vulnerability ships — and it's already showing up in real breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/the-generational-divide-in-attitudes-toward-ai-assisted-coding-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-generational-divide-in-attitudes-toward-ai-assisted-coding-risk</guid>
      <pubDate>Sat, 23 May 2026 06:50:28 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Contextual project classification for SCA accuracy]]></title>
      <description><![CDATA[Flat SCA scanning treats every dependency the same, burying real risk under test-path noise. Here's how contextual project classification fixes accuracy — and where Mend.io falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/contextual-project-classification-for-sca-accuracy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/contextual-project-classification-for-sca-accuracy</guid>
      <pubDate>Sat, 23 May 2026 06:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Artifactory vs Nexus for Enterprise in 2025]]></title>
      <description><![CDATA[JFrog Artifactory and Sonatype Nexus both remain viable enterprise artifact repositories in 2025. A head-to-head on scale, security, and the decision factors that actually matter.]]></description>
      <link>https://safeguard.sh/resources/blog/artifactory-vs-nexus-enterprise-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/artifactory-vs-nexus-enterprise-2025</guid>
      <pubDate>Sat, 23 May 2026 05:30:01 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Go: Check If a Key Exists in a Map (Comma-Ok Idiom)]]></title>
      <description><![CDATA[How to check if a key exists in a Go map using the comma-ok idiom, why a plain lookup can't tell 'missing' from 'zero value', and the patterns for sets, nil maps, and concurrent access.]]></description>
      <link>https://safeguard.sh/resources/blog/golang-check-key-in-map</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/golang-check-key-in-map</guid>
      <pubDate>Sat, 23 May 2026 04:09:35 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[10 GitHub security best practices]]></title>
      <description><![CDATA[10 concrete GitHub security controls—2FA, push protection, branch rules, pinned Actions, SBOM—with real CVEs and dates security teams can act on today.]]></description>
      <link>https://safeguard.sh/resources/blog/10-github-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/10-github-security-best-practices</guid>
      <pubDate>Sat, 23 May 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SBOM security: key components and top use cases]]></title>
      <description><![CDATA[A practical breakdown of SBOM security components and top use cases—incident response, compliance, M&A—plus how Safeguard's approach differs from SCA-first tools like Mend.io.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-security-key-components-and-top-use-cases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-security-key-components-and-top-use-cases</guid>
      <pubDate>Sat, 23 May 2026 03:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What CISOs Get Wrong About Developer Security Habits]]></title>
      <description><![CDATA[CISOs blame developer negligence for supply chain risk, but the real issue is alert noise, tool sprawl, and audits that miss day-to-day behavior. Here's what the data actually shows.]]></description>
      <link>https://safeguard.sh/resources/blog/what-cisos-get-wrong-about-developer-security-habits</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-cisos-get-wrong-about-developer-security-habits</guid>
      <pubDate>Sat, 23 May 2026 02:49:08 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Why Every AppSec Vendor Suddenly Has an 'AI Trust' Product]]></title>
      <description><![CDATA[AppSec vendors are rebranding as "AI Trust" platforms. We look at the standards, M&A, and real incidents driving the shift — and why it's a supply chain problem at its core.]]></description>
      <link>https://safeguard.sh/resources/blog/why-every-appsec-vendor-suddenly-has-an-ai-trust-product</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-every-appsec-vendor-suddenly-has-an-ai-trust-product</guid>
      <pubDate>Sat, 23 May 2026 01:28:41 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Cheat sheet: 10 Bitbucket security best practices]]></title>
      <description><![CDATA[A concrete, numbers-first cheat sheet covering the 10 Bitbucket security settings that stop misconfigurations from becoming supply chain breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/cheat-sheet-10-bitbucket-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cheat-sheet-10-bitbucket-security-best-practices</guid>
      <pubDate>Sat, 23 May 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Acquisition Pattern Behind AppSec's Runtime Visibilit...]]></title>
      <description><![CDATA[From Cider Security to the $32B Google-Wiz deal, AppSec acquirers keep paying for one thing: runtime visibility into what code actually does in production.]]></description>
      <link>https://safeguard.sh/resources/blog/the-acquisition-pattern-behind-appsecs-runtime-visibility-land-grab</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-acquisition-pattern-behind-appsecs-runtime-visibility-land-grab</guid>
      <pubDate>Sat, 23 May 2026 00:08:15 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Communicating security posture to customers/investors via...]]></title>
      <description><![CDATA[How to turn SBOMs into a real vendor-risk communication tool for customers and investors, and where Mend.io's scan-first approach falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/communicating-security-posture-to-customersinvestors-via-sboms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/communicating-security-posture-to-customersinvestors-via-sboms</guid>
      <pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Reading the Tea Leaves of Security Vendor Partner-of-the-...]]></title>
      <description><![CDATA[Vendor Partner-of-the-Year awards dominate cybersecurity conference season. Here's what the criteria really measure — and the supply chain risk they don't.]]></description>
      <link>https://safeguard.sh/resources/blog/reading-the-tea-leaves-of-security-vendor-partner-of-the-year-awards</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reading-the-tea-leaves-of-security-vendor-partner-of-the-year-awards</guid>
      <pubDate>Fri, 22 May 2026 22:47:48 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-49794 in libxml2: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[libxml2 use-after-free during XPath schematron parsing scored CVSS 9.1. Defender SBOM playbook for one of the most-embedded libraries on the planet.]]></description>
      <link>https://safeguard.sh/resources/blog/libxml2-cve-2025-49794-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/libxml2-cve-2025-49794-patch-response</guid>
      <pubDate>Fri, 22 May 2026 21:27:21 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[EPSS Meaning: The Exploit Prediction Scoring System Explained]]></title>
      <description><![CDATA[EPSS is a daily-updated probability that a given CVE will be exploited in the next 30 days. Here is what the score means and how to use it.]]></description>
      <link>https://safeguard.sh/resources/blog/epss-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/epss-meaning</guid>
      <pubDate>Fri, 22 May 2026 20:06:54 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[in-toto Graduates from CNCF: Attestation Bundles and the v1 Layer]]></title>
      <description><![CDATA[in-toto reached CNCF graduation in April 2025 and shipped a major attestation framework release. We walk through the bundle layer, resource descriptors, and what producers should adopt.]]></description>
      <link>https://safeguard.sh/resources/blog/in-toto-cncf-graduation-attestation-bundle-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/in-toto-cncf-graduation-attestation-bundle-2025</guid>
      <pubDate>Fri, 22 May 2026 18:46:28 GMT</pubDate>
      <category>Industry</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[git-dumper: How Exposed .git Directories Get Dumped and How to Stop It]]></title>
      <description><![CDATA[git-dumper reconstructs an entire source tree from an exposed .git folder on a web server. Here is how the attack works and how to close the hole.]]></description>
      <link>https://safeguard.sh/resources/blog/git-dumper</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-dumper</guid>
      <pubDate>Fri, 22 May 2026 17:26:01 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Injection in JS: A Practical Security Guide]]></title>
      <description><![CDATA[Dependency injection in JS improves testability, but it also becomes an attack surface when injection is dynamic or unvalidated. Here is how to keep it safe.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-injection-js</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-injection-js</guid>
      <pubDate>Fri, 22 May 2026 16:05:34 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[First VPN Takedown: How May 2026's Strike on Ransomware Infrastructure Worked]]></title>
      <description><![CDATA[In May 2026, an international coalition dismantled First VPN, a service the FBI says at least 25 ransomware gangs used to hide. We unpack the takedown, the broader 2026 infrastructure offensive, and why disrupting plumbing matters more than chasing brands.]]></description>
      <link>https://safeguard.sh/resources/blog/first-vpn-takedown-ransomware-infrastructure-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/first-vpn-takedown-ransomware-infrastructure-may-2026</guid>
      <pubDate>Fri, 22 May 2026 16:00:00 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Hugging Face as Malware CDN and Exfiltration Backend: The DPRK-Linked npm Campaign of May 2026]]></title>
      <description><![CDATA[OX Security disclosed a DPRK-aligned campaign that abused Hugging Face as a malware host and data-exfiltration backend, using public repos to serve second-stage payloads and private datasets to receive stolen developer secrets.]]></description>
      <link>https://safeguard.sh/resources/blog/huggingface-model-hub-malware-backend-dprk-npm-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/huggingface-model-hub-malware-backend-dprk-npm-may-2026</guid>
      <pubDate>Fri, 22 May 2026 16:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[FBI Warns on Kali365: A PhaaS Kit That Steals M365 OAuth Tokens and Bypasses MFA (May 2026)]]></title>
      <description><![CDATA[The FBI's May 21, 2026 IC3 advisory details Kali365, a Telegram-distributed phishing-as-a-service kit that uses device-code phishing to capture Microsoft 365 access and refresh tokens, granting password-free, MFA-immune persistence.]]></description>
      <link>https://safeguard.sh/resources/blog/kali365-phaas-device-code-oauth-token-theft-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kali365-phaas-device-code-oauth-token-theft-may-2026</guid>
      <pubDate>Fri, 22 May 2026 16:00:00 GMT</pubDate>
      <category>Identity Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The CVE Program Funding Crisis: What Happened and What It Means]]></title>
      <description><![CDATA[The CVE program nearly lost its funding in early 2025, exposing deep structural risks in how we track vulnerabilities. Here is what happened and where we go from here.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-program-funding-crisis-and-resolution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-program-funding-crisis-and-resolution</guid>
      <pubDate>Fri, 22 May 2026 14:45:08 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AI Code Detector: How It Works and Where It Fails]]></title>
      <description><![CDATA[An AI code detector estimates whether source code was machine-generated. Here is how these tools work, why they misfire, and where security teams should and should not rely on them.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-code-detector</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-code-detector</guid>
      <pubDate>Fri, 22 May 2026 14:05:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Vulnerability Scanner: How It Works and What to Use]]></title>
      <description><![CDATA[A JavaScript vulnerability scanner finds risky dependencies and insecure code across your Node and browser projects. Here is how the different types work.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-vulnerability-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-vulnerability-scanner</guid>
      <pubDate>Fri, 22 May 2026 13:24:41 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Why Hyperscaler Partnerships Are Becoming Table Stakes fo...]]></title>
      <description><![CDATA[Google's ~$32B Wiz deal signaled it: hyperscaler marketplaces, partner programs, and native tooling now shape how AppSec buying actually happens.]]></description>
      <link>https://safeguard.sh/resources/blog/why-hyperscaler-partnerships-are-becoming-table-stakes-for-appsec-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-hyperscaler-partnerships-are-becoming-table-stakes-for-appsec-vendors</guid>
      <pubDate>Fri, 22 May 2026 12:04:14 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The npm figlet Package: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[The npm figlet package turns text into ASCII art and is downloaded well over a million times a week. Here is what it does, how to use it, and how to treat even a small utility as part of your supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-figlet</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-figlet</guid>
      <pubDate>Fri, 22 May 2026 10:43:48 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Fixing vulnerabilities in Maven projects]]></title>
      <description><![CDATA[Maven vulnerability remediation isn't just running mvn versions:use-latest — here's how to triage, patch, and verify fixes without breaking builds.]]></description>
      <link>https://safeguard.sh/resources/blog/fixing-vulnerabilities-in-maven-projects</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fixing-vulnerabilities-in-maven-projects</guid>
      <pubDate>Fri, 22 May 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Hacking AI: How Attackers Target Machine Learning Systems]]></title>
      <description><![CDATA[Hacking AI is not science fiction; it is a growing set of concrete techniques that exploit how models learn, process input, and produce output. Here is how to think about defending against them.]]></description>
      <link>https://safeguard.sh/resources/blog/hacking-ai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hacking-ai</guid>
      <pubDate>Fri, 22 May 2026 09:45:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[npm commander: Security Review and Safe Usage of the CLI Library]]></title>
      <description><![CDATA[The npm commander package is one of the most-downloaded CLI frameworks for Node. Here is a security-focused review of the library and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-commander</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-commander</guid>
      <pubDate>Fri, 22 May 2026 09:23:21 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Log4j-style incident response using SBOM inventories]]></title>
      <description><![CDATA[How SBOM inventories turned days of Log4Shell triage into minutes-long queries — and why scanner-first tools like Mend.io struggled when every team needed answers at once.]]></description>
      <link>https://safeguard.sh/resources/blog/log4j-style-incident-response-using-sbom-inventories</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4j-style-incident-response-using-sbom-inventories</guid>
      <pubDate>Fri, 22 May 2026 09:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[The Quiet Consolidation of SCA, SAST, and Container Scann...]]></title>
      <description><![CDATA[A wave of PE buyouts and platform acquisitions is quietly folding SCA, SAST, and container scanning into fewer, bigger AppSec platforms. Here's what's driving it.]]></description>
      <link>https://safeguard.sh/resources/blog/the-quiet-consolidation-of-sca-sast-and-container-scanning-markets</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-quiet-consolidation-of-sca-sast-and-container-scanning-markets</guid>
      <pubDate>Fri, 22 May 2026 08:02:54 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Fixing vulnerabilities in Gradle projects]]></title>
      <description><![CDATA[Gradle's resolved dependency graph rarely matches build.gradle. Here's how to find, force-fix, and lock vulnerable transitive dependencies for good.]]></description>
      <link>https://safeguard.sh/resources/blog/fixing-vulnerabilities-in-gradle-projects</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fixing-vulnerabilities-in-gradle-projects</guid>
      <pubDate>Fri, 22 May 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What OpenAI and Anthropic Ecosystem Partnerships Signal A...]]></title>
      <description><![CDATA[OpenAI and Anthropic's expanding ecosystem deals are an AI model vendor security partnership signal AppSec teams can no longer afford to ignore.]]></description>
      <link>https://safeguard.sh/resources/blog/what-openai-and-anthropic-ecosystem-partnerships-signal-about-appsecs-future</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-openai-and-anthropic-ecosystem-partnerships-signal-about-appsecs-future</guid>
      <pubDate>Fri, 22 May 2026 06:42:28 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[EU Cyber Resilience Act SBOM requirements]]></title>
      <description><![CDATA[The EU Cyber Resilience Act makes SBOMs a legal requirement, not a best practice. Here's what's mandated, key 2026/2027 deadlines, and how Safeguard compares to Mend.io.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cyber-resilience-act-sbom-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cyber-resilience-act-sbom-requirements</guid>
      <pubDate>Fri, 22 May 2026 06:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Are AI Coding Assistant Vendors Ready to Own Their Securi...]]></title>
      <description><![CDATA[AI coding assistants ship indemnification for copyright suits, not for the vulnerabilities they introduce. Here's the liability gap enterprises need to understand.]]></description>
      <link>https://safeguard.sh/resources/blog/are-ai-coding-assistant-vendors-ready-to-own-their-security-liability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/are-ai-coding-assistant-vendors-ready-to-own-their-security-liability</guid>
      <pubDate>Fri, 22 May 2026 05:22:01 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Booking a Snyk Demo: What to Test and the Questions to Ask]]></title>
      <description><![CDATA[How to get real value from a Snyk demo — the workflows to insist on, the noise questions to ask, and the pricing details worth pinning down before you commit.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-demo</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-demo</guid>
      <pubDate>Fri, 22 May 2026 04:01:34 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[The ultimate guide to creating a secure Python package]]></title>
      <description><![CDATA[A concrete, numbers-first guide to locking dependencies, signing releases, and scanning for CVEs when building a secure Python package.]]></description>
      <link>https://safeguard.sh/resources/blog/the-ultimate-guide-to-creating-a-secure-python-package</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-ultimate-guide-to-creating-a-secure-python-package</guid>
      <pubDate>Fri, 22 May 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[License compatibility when combining open source components]]></title>
      <description><![CDATA[Open source license conflicts like GPL-Apache incompatibility often surface after merge. Here's why scanners miss them and how build-time enforcement closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/license-compatibility-when-combining-open-source-components</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/license-compatibility-when-combining-open-source-components</guid>
      <pubDate>Fri, 22 May 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Code Complexity Analysis as a Security Signal, Not Just a Metric]]></title>
      <description><![CDATA[Code complexity analysis measures how tangled your code is, and that number predicts where bugs and vulnerabilities hide. How to measure it and act on it.]]></description>
      <link>https://safeguard.sh/resources/blog/code-complexity-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-complexity-analysis</guid>
      <pubDate>Fri, 22 May 2026 02:41:07 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Checker: How to Scan JavaScript Code for Bugs and Vulnerabilities]]></title>
      <description><![CDATA[A JavaScript checker can mean a linter, a type checker, or a security scanner, and you want all three. Here is what each catches and how to wire them into one pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-checker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-checker</guid>
      <pubDate>Fri, 22 May 2026 01:20:41 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Command injection in Python: examples and prevention]]></title>
      <description><![CDATA[Python command injection lets attackers run arbitrary OS commands via os.system() or subprocess. Learn how it works, a real CVE, and how to prevent it.]]></description>
      <link>https://safeguard.sh/resources/blog/command-injection-in-python-examples-and-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/command-injection-in-python-examples-and-prevention</guid>
      <pubDate>Fri, 22 May 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Package Registry?]]></title>
      <description><![CDATA[A package registry is the network service your package manager pulls code from. Here is how registries work, why they are a critical trust boundary, and how to secure what you download.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-package-registry</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-package-registry</guid>
      <pubDate>Fri, 22 May 2026 00:00:14 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Open source license risk in M&A due diligence]]></title>
      <description><![CDATA[Open source license conflicts hide in most acquisition targets' codebases. Here's why manifest-based SCA tools like Mend.io miss them in M&A diligence — and what a real audit needs.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-license-risk-in-ma-due-diligence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-license-risk-in-ma-due-diligence</guid>
      <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[What is a Build Cache Poisoning Attack]]></title>
      <description><![CDATA[Build cache poisoning plants malicious entries in a shared CI cache so trusted builds unknowingly consume attacker-controlled artifacts. Here's the mechanics and the fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-build-cache-poisoning-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-build-cache-poisoning-attack</guid>
      <pubDate>Thu, 21 May 2026 22:39:47 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Sofia Marchetti)</author>
    </item>
    <item>
      <title><![CDATA[Venture Capital's Renewed Bet on Agentic AI Security Star...]]></title>
      <description><![CDATA[VC funding for agentic AI security startups hit new highs in 2026, with identity governance, autonomous pentesting, and SOC automation drawing the biggest rounds.]]></description>
      <link>https://safeguard.sh/resources/blog/venture-capitals-renewed-bet-on-agentic-ai-security-startups</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/venture-capitals-renewed-bet-on-agentic-ai-security-startups</guid>
      <pubDate>Thu, 21 May 2026 21:19:21 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Data Compliance: A Practical Guide to Getting It Right]]></title>
      <description><![CDATA[Cloud data compliance is the practice of meeting legal and contractual rules for how data is stored, processed, and protected in cloud environments. Here is how to make it real.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-data-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-data-compliance</guid>
      <pubDate>Thu, 21 May 2026 19:58:54 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[How Analyst Firms Are Redrawing Category Lines Around ASPM]]></title>
      <description><![CDATA[Gartner, Forrester, and other analyst firms are redrawing the boundaries around ASPM, CNAPP, and traditional AppSec testing — reshaping how security teams buy and organize tools.]]></description>
      <link>https://safeguard.sh/resources/blog/how-analyst-firms-are-redrawing-category-lines-around-aspm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-analyst-firms-are-redrawing-category-lines-around-aspm</guid>
      <pubDate>Thu, 21 May 2026 18:38:27 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Rise of 'Security for AI' as a Distinct Product Category]]></title>
      <description><![CDATA[Security for AI has become its own product category—backed by NIST, OWASP, and MITRE frameworks and real M&A. Here's why it's really a supply chain problem.]]></description>
      <link>https://safeguard.sh/resources/blog/the-rise-of-security-for-ai-as-a-distinct-product-category</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-rise-of-security-for-ai-as-a-distinct-product-category</guid>
      <pubDate>Thu, 21 May 2026 17:18:01 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[When the Cloud Pulls the Plug: The GCP Account Suspension That Took Railway Down (May 19, 2026)]]></title>
      <description><![CDATA[On May 19, 2026, Google Cloud automatically suspended Railway's production account, taking down a platform fronting roughly 10 million services for about eight hours. The root cause was not a breach but a control-plane dependency and a provider action with no human in the loop.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-railway-account-suspension-outage-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-railway-account-suspension-outage-may-2026</guid>
      <pubDate>Thu, 21 May 2026 16:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Mutable Tags Strike Again: actions-cool GitHub Action Tags Redirected to Imposter Commits (May 2026)]]></title>
      <description><![CDATA[In May 2026, every tag on actions-cool/issues-helper and 15 tags on maintain-one-comment were quietly moved to point at imposter commits that stole CI/CD credentials from runner memory. A look at the mutable-tag attack class and how to defeat it.]]></description>
      <link>https://safeguard.sh/resources/blog/github-action-tag-redirect-imposter-commit-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-action-tag-redirect-imposter-commit-may-2026</guid>
      <pubDate>Thu, 21 May 2026 16:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why Systems Integrators Are Becoming Central to Enterpris...]]></title>
      <description><![CDATA[As regulations like NIST SSDF, DORA, and the EU Cyber Resilience Act raise the bar, systems integrators are taking the lead role in enterprise AppSec rollouts.]]></description>
      <link>https://safeguard.sh/resources/blog/why-systems-integrators-are-becoming-central-to-enterprise-appsec-rollouts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-systems-integrators-are-becoming-central-to-enterprise-appsec-rollouts</guid>
      <pubDate>Thu, 21 May 2026 15:57:34 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Reading Between the Lines of Vendor Research Reports: A M...]]></title>
      <description><![CDATA[Vendor-sponsored security reports shape budgets and policy, but their methodologies rarely survive scrutiny. Here's how to read them critically.]]></description>
      <link>https://safeguard.sh/resources/blog/reading-between-the-lines-of-vendor-research-reports-a-methodology-critique</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reading-between-the-lines-of-vendor-research-reports-a-methodology-critique</guid>
      <pubDate>Thu, 21 May 2026 14:37:07 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How to Run a Container Security Assessment]]></title>
      <description><![CDATA[A container security assessment reviews your images, registries, orchestration, and runtime against known weaknesses so you can fix them before an attacker finds them.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-assessment</guid>
      <pubDate>Thu, 21 May 2026 13:40:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Log4Shell Three Years Later: Which Fixes Actually Stuck?]]></title>
      <description><![CDATA[Three years after Log4Shell's disclosure, which fixes actually held? A look back at CVE-2021-44228's timeline, CVSS/EPSS/KEV context, and lingering exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/log4shell-three-years-later-which-fixes-actually-stuck</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4shell-three-years-later-which-fixes-actually-stuck</guid>
      <pubDate>Thu, 21 May 2026 13:16:41 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[The XZ Utils Backdoor: A Timeline and Technical Post-Mortem]]></title>
      <description><![CDATA[A technical post-mortem of CVE-2024-3094, the XZ Utils backdoor: how a trusted maintainer identity was used to plant a supply chain backdoor in sshd.]]></description>
      <link>https://safeguard.sh/resources/blog/the-xz-utils-backdoor-a-timeline-and-technical-post-mortem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-xz-utils-backdoor-a-timeline-and-technical-post-mortem</guid>
      <pubDate>Thu, 21 May 2026 11:56:14 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[MGM Ransomware One Year Later: A Retrospective]]></title>
      <description><![CDATA[A 2025 retrospective on the September 2023 MGM Resorts ransomware incident, what changed, what stalled, and how supply chain defenders should adjust.]]></description>
      <link>https://safeguard.sh/resources/blog/mgm-ransomware-one-year-later-retrospective</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mgm-ransomware-one-year-later-retrospective</guid>
      <pubDate>Thu, 21 May 2026 10:35:47 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Code injection in Python: examples and prevention]]></title>
      <description><![CDATA[How Python code injection (CWE-94) works, real CVEs like PyYAML's CVE-2020-14343, and concrete steps to detect and fix it before attackers do.]]></description>
      <link>https://safeguard.sh/resources/blog/code-injection-in-python-examples-and-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-injection-in-python-examples-and-prevention</guid>
      <pubDate>Thu, 21 May 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What Is Security Logging?]]></title>
      <description><![CDATA[Security logging records security-relevant events so activity can be monitored, investigated, and audited. Learn what to log, how it works, and the common pitfalls.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-security-logging</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-security-logging</guid>
      <pubDate>Thu, 21 May 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Attacks: H1 2025 Report]]></title>
      <description><![CDATA[A data-driven breakdown of supply chain attacks from January through June 2025, covering attack vectors, targeted ecosystems, and emerging trends.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-attacks-h1-2025-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-attacks-h1-2025-report</guid>
      <pubDate>Thu, 21 May 2026 09:15:20 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Application security testing types, trends, and top tools]]></title>
      <description><![CDATA[A breakdown of the six core types of application security testing, how Mend.io's SCA-first approach compares to the broader market, and the tools and trends shaping AppSec in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-testing-types-trends-and-top-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-testing-types-trends-and-top-tools</guid>
      <pubDate>Thu, 21 May 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[DevOps Metrics Tools: What to Track and How to Measure It]]></title>
      <description><![CDATA[DevOps metrics tools collect and visualize the delivery and reliability signals that tell you whether your engineering system is actually improving. Here is what to measure and with what.]]></description>
      <link>https://safeguard.sh/resources/blog/devops-metrics-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devops-metrics-tools</guid>
      <pubDate>Thu, 21 May 2026 07:54:54 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[10 dimensions of Python static analysis]]></title>
      <description><![CDATA[Python static analysis spans ten distinct techniques, from AST linting to reachability analysis — most teams run only two or three, missing real exploitable risk.]]></description>
      <link>https://safeguard.sh/resources/blog/10-dimensions-of-python-static-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/10-dimensions-of-python-static-analysis</guid>
      <pubDate>Thu, 21 May 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[MCP 2025-06-18: OAuth Resource Server Rules Defenders Must Understand]]></title>
      <description><![CDATA[The June 2025 MCP spec made every server an OAuth 2.1 resource server, mandated RFC 8707 resource indicators, and added elicitation. Here is what changes for blue teams.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-spec-2025-06-18-oauth-resource-server</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-spec-2025-06-18-oauth-resource-server</guid>
      <pubDate>Thu, 21 May 2026 06:34:27 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Automated dependency updates and patch management]]></title>
      <description><![CDATA[How automated dependency updates actually close the patch gap—where Mend.io's approach falls short, and what reachability, provenance, and policy-as-code add.]]></description>
      <link>https://safeguard.sh/resources/blog/automated-dependency-updates-and-patch-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automated-dependency-updates-and-patch-management</guid>
      <pubDate>Thu, 21 May 2026 06:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[YAML Code Security: Deserialization, Injection, and Safe Parsing]]></title>
      <description><![CDATA[YAML code powers config files across the ecosystem, but unsafe parsing can turn a data file into remote code execution. Here is how to write and load it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/yaml-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/yaml-code</guid>
      <pubDate>Thu, 21 May 2026 05:14:00 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Symmetric vs asymmetric encryption: practical Python examples]]></title>
      <description><![CDATA[Symmetric vs asymmetric encryption explained with working Python code: AES-256-GCM, RSA-OAEP, hybrid encryption, and the mistakes that cause real breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/symmetric-vs-asymmetric-encryption-practical-python-examples</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/symmetric-vs-asymmetric-encryption-practical-python-examples</guid>
      <pubDate>Thu, 21 May 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[The Checkmarx Logo: Where to Find It and How to Use It Correctly]]></title>
      <description><![CDATA[Looking for the Checkmarx logo? Here is where to source an official version, how to use it without violating brand rules, and why logo hygiene matters for security teams.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-logo</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-logo</guid>
      <pubDate>Thu, 21 May 2026 03:53:34 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[ROI of automated dependency management (Renovate Enterprise)]]></title>
      <description><![CDATA[Automated dependency updates promise real ROI, but Renovate Enterprise's PR-scheduling model often stalls at the review bottleneck. Here's how to measure the real numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/roi-of-automated-dependency-management-renovate-enterprise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/roi-of-automated-dependency-management-renovate-enterprise</guid>
      <pubDate>Thu, 21 May 2026 03:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Run an Application Security Code Review That Catches Real Bugs]]></title>
      <description><![CDATA[An application security code review is a targeted read of code for security defects. Here is a practical process that finds real issues without drowning in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-code-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-code-review</guid>
      <pubDate>Thu, 21 May 2026 02:33:07 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Verify an npm Package Before Installing It]]></title>
      <description><![CDATA[Five checks that take about four minutes — tarball inspection, install-script review, provenance verification, maintainer signals — before you let a new npm package run code on your machine.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-verify-an-npm-package-before-installing-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-verify-an-npm-package-before-installing-it</guid>
      <pubDate>Thu, 21 May 2026 01:12:40 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Jonas Meyer)</author>
    </item>
    <item>
      <title><![CDATA[Using Python libraries for secure network communication]]></title>
      <description><![CDATA[A look at requests, urllib3, cryptography, and paramiko: real CVEs (Terrapin, header leaks), insecure defaults, and how to pin them safely.]]></description>
      <link>https://safeguard.sh/resources/blog/using-python-libraries-for-secure-network-communication</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/using-python-libraries-for-secure-network-communication</guid>
      <pubDate>Thu, 21 May 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Malicious packages and malware campaigns: the new reality...]]></title>
      <description><![CDATA[Malicious open source packages don't wait for a CVE. See how npm worms, xz utils, and typosquats evade legacy SCA — and what real detection requires.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-packages-and-malware-campaigns-the-new-reality-of-the-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-packages-and-malware-campaigns-the-new-reality-of-the-software-supply-chain</guid>
      <pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How to Provide Security in Android Apps: A Developer Checklist]]></title>
      <description><![CDATA[How to provide security in Android apps: a developer checklist covering network config, storage, component exposure, WebViews, and the dependency layer most mobile teams skip.]]></description>
      <link>https://safeguard.sh/resources/blog/android-app-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/android-app-security-guide</guid>
      <pubDate>Wed, 20 May 2026 23:52:14 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Webpack 5 Node Polyfills: node-polyfill-webpack-plugin Explained]]></title>
      <description><![CDATA[node-polyfill-webpack-plugin restores the Node core shims webpack 5 removed. Before you install it, understand what you are re-adding to your bundle and why webpack removed it.]]></description>
      <link>https://safeguard.sh/resources/blog/webpack-5-node-polyfills-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webpack-5-node-polyfills-guide</guid>
      <pubDate>Wed, 20 May 2026 22:31:47 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Hacking Device? A Defender's Guide]]></title>
      <description><![CDATA[A defender's guide to the hacking device: what these physical tools are, how the common categories work conceptually, and how to defend against them.]]></description>
      <link>https://safeguard.sh/resources/blog/hacking-device</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hacking-device</guid>
      <pubDate>Wed, 20 May 2026 21:11:20 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Web Application Threats: What They Are and How to Defend Against Them]]></title>
      <description><![CDATA[A practitioner's map of the web application threat landscape — injection, broken access control, supply-chain risk — and the defenses that actually blunt each one.]]></description>
      <link>https://safeguard.sh/resources/blog/web-application-threat</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-application-threat</guid>
      <pubDate>Wed, 20 May 2026 19:50:53 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SDLC Security Best Practices for Every Phase]]></title>
      <description><![CDATA[SDLC security best practices mapped to each phase of development — from threat modeling in design to dependency scanning in CI and monitoring in production.]]></description>
      <link>https://safeguard.sh/resources/blog/sdlc-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sdlc-security-best-practices</guid>
      <pubDate>Wed, 20 May 2026 18:30:27 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CORS in Node.js: What It Is and How to Configure It Securely]]></title>
      <description><![CDATA[CORS in Node.js trips up almost every developer at some point. Here is what CORS actually does, why you need it, and how to configure it without opening a hole.]]></description>
      <link>https://safeguard.sh/resources/blog/cors-in-node-js</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cors-in-node-js</guid>
      <pubDate>Wed, 20 May 2026 17:10:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Microsoft's durabletask PyPI Package Compromised (19 May 2026): A Linux Wiper and Multi-Cloud Credential Theft]]></title>
      <description><![CDATA[On 19 May 2026, three malicious versions of Microsoft's durabletask PyPI package were uploaded in a 35-minute window. The payload steals AWS, Azure, GCP, and Kubernetes credentials in under four seconds and ships a locale-gated rm -rf wiper.]]></description>
      <link>https://safeguard.sh/resources/blog/durabletask-pypi-compromise-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/durabletask-pypi-compromise-may-2026</guid>
      <pubDate>Wed, 20 May 2026 16:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[GitHub VS Code Extension Breach (20 May 2026): What Happened, How It Worked, and What to Do Monday Morning]]></title>
      <description><![CDATA[GitHub disclosed on 20 May 2026 that a poisoned VS Code Marketplace extension was used to exfiltrate roughly 3,800 private repositories from enterprise engineering orgs, landing in the middle of a broader May 2026 wave of developer-surface supply chain attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/github-vscode-extension-breach-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-vscode-extension-breach-may-2026</guid>
      <pubDate>Wed, 20 May 2026 16:00:00 GMT</pubDate>
      <category>Incident Postmortem</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[NIS2's First Enforcement Wave (May 2026): What the Early Proceedings Tell Compliance Teams]]></title>
      <description><![CDATA[By May 2026 the first NIS2 enforcement actions are surfacing across early-transposing member states, starting with registration and notification failures. We analyze what authorities are pursuing first and how to build evidence that survives the escalation.]]></description>
      <link>https://safeguard.sh/resources/blog/nis2-first-enforcement-wave-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nis2-first-enforcement-wave-may-2026</guid>
      <pubDate>Wed, 20 May 2026 16:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SonicWall SonicOS Scanning Surge in May 2026: The CVE-2026-0400 Early-Warning Pattern]]></title>
      <description><![CDATA[GreyNoise recorded ~597,000 SonicWall SonicOS scanning sessions on May 12, 2026, roughly 46x baseline. The pattern echoes the recon waves that preceded CVE-2026-0400's disclosure. Here is how to read the signal.]]></description>
      <link>https://safeguard.sh/resources/blog/sonicwall-sonicos-scanning-surge-cve-2026-0400-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonicwall-sonicos-scanning-surge-cve-2026-0400-may-2026</guid>
      <pubDate>Wed, 20 May 2026 16:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Gentlemen RaaS Database Leak: What the May 2026 Breach Revealed About a Top Ransomware Operation]]></title>
      <description><![CDATA[An insider sold The Gentlemen's internal 'Rocket' backend in May 2026, exposing affiliate structure, tooling, and negotiation logs of one of 2026's most prolific RaaS crews. Here is what the leak teaches defenders.]]></description>
      <link>https://safeguard.sh/resources/blog/the-gentlemen-raas-database-leak-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-gentlemen-raas-database-leak-may-2026</guid>
      <pubDate>Wed, 20 May 2026 16:00:00 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Evaluate a Docker Security Company]]></title>
      <description><![CDATA[Picking a Docker security company means judging vendors on the whole container lifecycle — image scanning, runtime, registry, and admission — not just the count of CVEs their scanner prints. Here is a buyer's checklist.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-security-company</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-security-company</guid>
      <pubDate>Wed, 20 May 2026 15:49:33 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Antd Injection: Preventing XSS in Ant Design Applications]]></title>
      <description><![CDATA[Antd injection risk is not a flaw in the component library itself but in how you feed it untrusted data. Here is where the danger lives and how to close it.]]></description>
      <link>https://safeguard.sh/resources/blog/antd-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/antd-injection</guid>
      <pubDate>Wed, 20 May 2026 14:29:07 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Is python-docx Safe? A Security Guide]]></title>
      <description><![CDATA[python-docx reads and writes Word documents in Python. Here is what its security posture actually depends on, especially when you open files you did not create.]]></description>
      <link>https://safeguard.sh/resources/blog/python-docx</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-docx</guid>
      <pubDate>Wed, 20 May 2026 13:08:40 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Bitbucket Integration: Setup, Limits, and Alternatives]]></title>
      <description><![CDATA[The Snyk Bitbucket integration comes in three distinct flavors — Cloud App, legacy Cloud, and Data Center — each with different capabilities. Setup steps and trade-offs.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-bitbucket-integration-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-bitbucket-integration-guide</guid>
      <pubDate>Wed, 20 May 2026 13:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA Security Rule Update: What the 2026 Final Rule Will Require]]></title>
      <description><![CDATA[HHS published the HIPAA Security Rule NPRM in January 2025. Finalization is on the agenda for 2026. Covered entities and business associates need to start work now.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-security-rule-final-2026-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-security-rule-final-2026-compliance</guid>
      <pubDate>Wed, 20 May 2026 12:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[UK Software Security Code of Practice: The 14 Principles]]></title>
      <description><![CDATA[Launched at CyberUK 2025 on 7 May 2025, the UK's voluntary Software Security Code of Practice sets 14 principles across four thematic areas for vendors and customers.]]></description>
      <link>https://safeguard.sh/resources/blog/uk-software-security-code-of-practice-14-principles</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uk-software-security-code-of-practice-14-principles</guid>
      <pubDate>Wed, 20 May 2026 11:48:13 GMT</pubDate>
      <category>Policy</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Secure Code Analysis: How to Find Bugs Before They Ship]]></title>
      <description><![CDATA[Secure code analysis combines static, dependency, and dynamic techniques. Here is what each one finds, where they overlap, and how to build an analysis pipeline developers won't route around.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-code-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-code-analysis</guid>
      <pubDate>Wed, 20 May 2026 10:27:47 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Rust memory safety and its security advantages]]></title>
      <description><![CDATA[Memory safety bugs cause ~70% of Microsoft's CVEs. Here's how Rust's ownership model eliminates them at compile time, with real CVE examples.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-memory-safety-and-its-security-advantages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-memory-safety-and-its-security-advantages</guid>
      <pubDate>Wed, 20 May 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[MCP Inspector CVE-2025-49596: Anatomy of a 9.4 RCE in Anthropic's Reference Tool]]></title>
      <description><![CDATA[A missing auth check in MCP Inspector versions below 0.14.1 let any website pop a shell on a developer's machine. Here is the full chain and what to fix.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-inspector-cve-2025-49596-rce-postmortem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-inspector-cve-2025-49596-rce-postmortem</guid>
      <pubDate>Wed, 20 May 2026 09:07:20 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Hritik Kumar Sharma)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 and AppSec Vendors: What to Verify Before You Buy]]></title>
      <description><![CDATA[SOC 2 badges look identical from the outside. Here is what to actually check on audit scope, report type, and transparency before choosing an AppSec vendor.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-and-appsec-vendors-what-to-verify-before-you-buy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-and-appsec-vendors-what-to-verify-before-you-buy</guid>
      <pubDate>Wed, 20 May 2026 09:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Kettering Health Interlock Ransomware: A 14-Hospital System Goes Dark]]></title>
      <description><![CDATA[On May 20, 2025, Interlock ransomware encrypted Kettering Health across 14 Ohio hospitals. The actor sat in the network for 41 days before encryption. We unpack the dwell time and the recovery.]]></description>
      <link>https://safeguard.sh/resources/blog/kettering-health-interlock-ransomware-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kettering-health-interlock-ransomware-2025</guid>
      <pubDate>Wed, 20 May 2026 07:46:53 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Type-safe languages and their security benefits]]></title>
      <description><![CDATA[Type safety eliminates entire CVE classes, not one bug at a time. Here's what the Microsoft, Google, and CISA data actually shows about the security payoff.]]></description>
      <link>https://safeguard.sh/resources/blog/type-safe-languages-and-their-security-benefits</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/type-safe-languages-and-their-security-benefits</guid>
      <pubDate>Wed, 20 May 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[gittuf Reaches OpenSSF Incubating: A Forge-Independent Git Security Layer]]></title>
      <description><![CDATA[gittuf was promoted from OpenSSF Sandbox to Incubating in June 2025. We unpack the Reference State Log, policy model, and why it matters for SLSA Source L3.]]></description>
      <link>https://safeguard.sh/resources/blog/gittuf-openssf-incubating-status-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gittuf-openssf-incubating-status-2025</guid>
      <pubDate>Wed, 20 May 2026 06:26:27 GMT</pubDate>
      <category>Frameworks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Claude, GPT, and Coding Harness Security: Comparing Model...]]></title>
      <description><![CDATA[Claude and GPT both write vulnerable code by default in coding harnesses. Comparing model behavior, then Safeguard's approach versus Endor Labs' reachability-first SCA.]]></description>
      <link>https://safeguard.sh/resources/blog/claude-gpt-and-coding-harness-security-comparing-model-behavior-on-vulnerable-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/claude-gpt-and-coding-harness-security-comparing-model-behavior-on-vulnerable-code</guid>
      <pubDate>Wed, 20 May 2026 06:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm autoprefixer: Is It Safe, and How Should You Use It?]]></title>
      <description><![CDATA[The npm autoprefixer package is a PostCSS plugin that adds vendor prefixes to your CSS based on Browserslist data. Here is how it works, why it is a build-time dependency, and how to keep it safe.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-autoprefixer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-autoprefixer</guid>
      <pubDate>Wed, 20 May 2026 05:06:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[.NET and NuGet dependency vulnerability management]]></title>
      <description><![CDATA[NuGet packages have delivered RATs, crypto stealers, and undisclosed data collection to .NET teams. Here's how to detect and defend against .NET/NuGet supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/net-and-nuget-dependency-vulnerability-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/net-and-nuget-dependency-vulnerability-management</guid>
      <pubDate>Wed, 20 May 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[tomcat-embed-core in Maven: A Security Guide to CVEs and Fixes]]></title>
      <description><![CDATA[The tomcat-embed-core Maven artifact is the embedded Tomcat engine inside most Spring Boot apps, and it has carried several serious CVEs. Here is how to find your version and patch it.]]></description>
      <link>https://safeguard.sh/resources/blog/tomcat-embed-core-maven</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tomcat-embed-core-maven</guid>
      <pubDate>Wed, 20 May 2026 03:45:33 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Scanning vs Hybrid Scanning: Deployment Models for ...]]></title>
      <description><![CDATA[SaaS vs self-hosted SCA deployment compared on data residency, air-gap support, and audit scope, with a look at how Safeguard's flexible deployment model differs from cloud-only platforms.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-scanning-vs-hybrid-scanning-deployment-models-for-appsec-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-scanning-vs-hybrid-scanning-deployment-models-for-appsec-tools</guid>
      <pubDate>Wed, 20 May 2026 03:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Is HIPAA International? How U.S. Health Privacy Rules Reach Overseas]]></title>
      <description><![CDATA[HIPAA is a U.S. law, not an international standard, but its obligations follow protected health information across borders through covered entities and business associates.]]></description>
      <link>https://safeguard.sh/resources/blog/is-hipaa-international</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/is-hipaa-international</guid>
      <pubDate>Wed, 20 May 2026 02:25:06 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[PHP Vulnerability Classes and Common Fixes]]></title>
      <description><![CDATA[The recurring php vulnerability classes — SQL injection, file inclusion, deserialization, and type-juggling bugs — and the specific fixes that close each one.]]></description>
      <link>https://safeguard.sh/resources/blog/php-vulnerability-classes-and-common-fixes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-vulnerability-classes-and-common-fixes</guid>
      <pubDate>Wed, 20 May 2026 01:04:40 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing Laravel PHP applications]]></title>
      <description><![CDATA[CVE-2021-3129, leaked APP_KEYs, and Eloquent mass assignment still compromise Laravel apps in 2026 — here's how each attack works and how to close it.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-laravel-php-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-laravel-php-applications</guid>
      <pubDate>Wed, 20 May 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Endor Labs Alternatives: Evaluating SCA and Reachability ...]]></title>
      <description><![CDATA[A practical, verification-first comparison of Safeguard and Endor Labs on reachability methodology, ecosystem coverage, and workflow fit for SCA buyers.]]></description>
      <link>https://safeguard.sh/resources/blog/endor-labs-alternatives-evaluating-sca-and-reachability-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/endor-labs-alternatives-evaluating-sca-and-reachability-vendors</guid>
      <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[react-loader-spinner: A Security Guide]]></title>
      <description><![CDATA[react-loader-spinner adds ready-made loading spinners to React apps. It is UI-only, so its security story is entirely about dependency hygiene and install-time provenance.]]></description>
      <link>https://safeguard.sh/resources/blog/react-loader-spinner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-loader-spinner</guid>
      <pubDate>Tue, 19 May 2026 23:44:13 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[The moment npm Package in 2025: Security Review and Safe Usage]]></title>
      <description><![CDATA[The moment npm package is in maintenance mode, not abandoned. Here is what that means for security, when it is fine to keep, and what to migrate to when it is not.]]></description>
      <link>https://safeguard.sh/resources/blog/moment-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/moment-npm</guid>
      <pubDate>Tue, 19 May 2026 22:23:46 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[IaC Scanning: Catching Cloud Misconfigurations Before Deploy]]></title>
      <description><![CDATA[An IaC scan checks your Terraform, CloudFormation, and Kubernetes files for insecure defaults before they become running infrastructure. Here's how it works and how to wire it into CI.]]></description>
      <link>https://safeguard.sh/resources/blog/iac-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iac-scan</guid>
      <pubDate>Tue, 19 May 2026 21:03:20 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Compliance Reporting with Safeguard: From Raw Data to Audit-Ready Documents]]></title>
      <description><![CDATA[How to use Safeguard's compliance reporting engine to generate audit-ready documentation for SOC 2, ISO 27001, NIST SSDF, and other frameworks without weeks of manual work.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-compliance-reporting-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-compliance-reporting-guide</guid>
      <pubDate>Tue, 19 May 2026 19:42:53 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[@babel/eslint-parser: A Security and Migration Guide]]></title>
      <description><![CDATA[@babel/eslint-parser is the maintained ESLint parser for Babel-transformed JavaScript, replacing the deprecated babel-eslint. Here is why the rename happened and what it means for your toolchain.]]></description>
      <link>https://safeguard.sh/resources/blog/babel-eslint-parser</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/babel-eslint-parser</guid>
      <pubDate>Tue, 19 May 2026 18:22:26 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes securityContext Capabilities: Drop ALL, Add Only What You Need]]></title>
      <description><![CDATA[Linux capabilities are the privileges inside a container that attackers reuse after a breakout. Setting Kubernetes securityContext capabilities to drop ALL is the cheapest hardening you will do.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-securitycontext-capabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-securitycontext-capabilities</guid>
      <pubDate>Tue, 19 May 2026 17:02:00 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[NYC Health + Hospitals Vendor Breach: 1.8 Million Records, Including Biometrics, Exposed (May 2026)]]></title>
      <description><![CDATA[A months-long intrusion through a third-party vendor exposed medical records, government IDs, geolocation, and fingerprint and palm-print biometrics for at least 1.8 million people at the largest U.S. public health system. We unpack the dwell time and the third-party blast radius.]]></description>
      <link>https://safeguard.sh/resources/blog/nyc-health-hospitals-vendor-breach-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nyc-health-hospitals-vendor-breach-may-2026</guid>
      <pubDate>Tue, 19 May 2026 16:00:00 GMT</pubDate>
      <category>Healthcare Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[react-native-encrypted-storage: A Practical Security Guide]]></title>
      <description><![CDATA[What react-native-encrypted-storage does, how it wraps iOS Keychain and Android EncryptedSharedPreferences, its maintenance status, and how it compares to react-native-secure-storage.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-encrypted-storage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-encrypted-storage</guid>
      <pubDate>Tue, 19 May 2026 15:41:33 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[NIS2 Directive: What EU Software Vendors Must Do Now]]></title>
      <description><![CDATA[NIS2 is in force, transposition is late in half the EU, and the obligations bind anyway if you're in scope. The supply chain security and 24-hour reporting duties, decoded.]]></description>
      <link>https://safeguard.sh/resources/blog/nis2-directive-what-eu-software-vendors-must-do-now</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nis2-directive-what-eu-software-vendors-must-do-now</guid>
      <pubDate>Tue, 19 May 2026 14:21:06 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Sofia Marchetti)</author>
    </item>
    <item>
      <title><![CDATA[AI-Based Cybersecurity Tools: What to Look For]]></title>
      <description><![CDATA[AI based cybersecurity tools range from genuinely useful triage assistants to thin wrappers around a generic model, and the difference is usually visible in how the tool handles context, not in its marketing.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-based-cybersecurity-tools-what-to-look-for</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-based-cybersecurity-tools-what-to-look-for</guid>
      <pubDate>Tue, 19 May 2026 14:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[MCP Architecture Explained: A Security Guide]]></title>
      <description><![CDATA[The Model Context Protocol connects AI models to tools and data through a client-server design. Understanding that architecture is the first step to securing it.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-architecture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-architecture</guid>
      <pubDate>Tue, 19 May 2026 14:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Container Security on AWS: A Practical Hardening Guide]]></title>
      <description><![CDATA[Container security on AWS spans the image, the registry, the runtime, and IAM. Get those four layers right and you close the gaps that cause almost every incident.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-aws</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-aws</guid>
      <pubDate>Tue, 19 May 2026 13:40:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes securityContext, Explained From Scratch]]></title>
      <description><![CDATA[How security context in kubernetes actually works at the pod and container level, what kubernetes runasuser and capability drops do, and a sane default policy to start from.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-security-context-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-security-context-explained</guid>
      <pubDate>Tue, 19 May 2026 13:00:40 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Define Agentic: What 'Agentic' Really Means for Security]]></title>
      <description><![CDATA[To define agentic: it describes AI systems that plan and take actions toward a goal with limited human oversight. Here is what that autonomy means for security teams.]]></description>
      <link>https://safeguard.sh/resources/blog/define-agentic</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/define-agentic</guid>
      <pubDate>Tue, 19 May 2026 12:10:00 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[WWW XXE: Understanding and Preventing XML External Entity Attacks]]></title>
      <description><![CDATA[XXE lets a crafted XML document read files, reach internal services, and exhaust resources. Here is how the attack works and how to shut it down.]]></description>
      <link>https://safeguard.sh/resources/blog/www-xxe</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/www-xxe</guid>
      <pubDate>Tue, 19 May 2026 11:40:13 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AI Security Apps: What They Do and How to Evaluate Them]]></title>
      <description><![CDATA[An AI security app uses machine learning to detect, prioritize, or remediate security issues. Here is what the category actually delivers and how to judge one.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-app</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-app</guid>
      <pubDate>Tue, 19 May 2026 10:40:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to Choose an AI Cybersecurity Company in 2026]]></title>
      <description><![CDATA[An AI cybersecurity company uses machine learning to detect, prioritize, and remediate threats faster than rules alone. Here is how to evaluate one honestly.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-cybersecurity-company</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-cybersecurity-company</guid>
      <pubDate>Tue, 19 May 2026 10:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How Do You Audit a Container Image for Security?]]></title>
      <description><![CDATA[A container image audit inspects every layer of an image - base OS packages, application dependencies, secrets, and configuration - to find what an attacker could exploit before you deploy.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-audit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-audit</guid>
      <pubDate>Tue, 19 May 2026 10:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Using the aws-amplify npm Package Safely: A Security Review]]></title>
      <description><![CDATA[The aws-amplify npm package is a large, capable SDK that touches auth, storage, and API calls. Here is a practical security review of what to watch for and how to use it without widening your attack surface.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-aws-amplify</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-aws-amplify</guid>
      <pubDate>Tue, 19 May 2026 10:19:46 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Securing WordPress plugin dependencies]]></title>
      <description><![CDATA[Real CVEs, a supply-chain hack that hit 360,000 sites, and bundled-library blind spots: what WordPress plugin security actually requires in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-wordpress-plugin-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-wordpress-plugin-dependencies</guid>
      <pubDate>Tue, 19 May 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security Solutions: A Comparison Framework]]></title>
      <description><![CDATA[A framework for comparing software supply chain security solutions across the four capabilities that matter, SBOM generation, dependency scanning, provenance verification, and CI/CD gating.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-solutions-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-solutions-comparison</guid>
      <pubDate>Tue, 19 May 2026 09:40:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[MCP-Led Automation: Securing Model Context Protocol Workflows]]></title>
      <description><![CDATA[MCP-led agent workflows hand real tools to a language model. That power is also the attack surface. Here is how tool poisoning works and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-led</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-led</guid>
      <pubDate>Tue, 19 May 2026 09:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Open Source vs Safeguard SCA]]></title>
      <description><![CDATA[Two developer-first SCA tools, one honest comparison: vulnerability data, fix automation, noise levels, pricing models, and where each one actually fits.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-open-source-vs-safeguard-sca</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-open-source-vs-safeguard-sca</guid>
      <pubDate>Tue, 19 May 2026 09:15:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Axios npm Vulnerabilities: The Full CVE History and Patch Guide]]></title>
      <description><![CDATA[Every notable axios npm vulnerability, from the 2019 DoS to the 2025 SSRF, with the fixed versions and a patch path that also catches the transitive ones.]]></description>
      <link>https://safeguard.sh/resources/blog/axios-npm-vulnerability-cve-history-patch-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/axios-npm-vulnerability-cve-history-patch-guide</guid>
      <pubDate>Tue, 19 May 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Endor Labs vs Safeguard: Reachability-Based SCA Compared]]></title>
      <description><![CDATA[How Endor Labs and Safeguard both use reachability analysis to cut SCA noise, and where their scope and approach to supply chain security diverge.]]></description>
      <link>https://safeguard.sh/resources/blog/endor-labs-vs-safeguard-reachability-based-sca-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/endor-labs-vs-safeguard-reachability-based-sca-compared</guid>
      <pubDate>Tue, 19 May 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[RASP vs. SAST vs. DAST vs. IAST: How They Differ]]></title>
      <description><![CDATA[SAST vs DAST vs IAST vs RASP comes down to when each technique looks at your application — source code, a running test instance, instrumented runtime tests, or production traffic — and picking the wrong stage leaves real gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/rasp-vs-sast-vs-dast-vs-iast-how-they-differ</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rasp-vs-sast-vs-dast-vs-iast-how-they-differ</guid>
      <pubDate>Tue, 19 May 2026 09:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[False Positives vs False Negatives in Security Scanning]]></title>
      <description><![CDATA[False positives in cyber security waste your team's time; false negatives get you breached. Here is how to think about the trade-off and tune for it deliberately.]]></description>
      <link>https://safeguard.sh/resources/blog/false-positives-false-negatives-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/false-positives-false-negatives-security</guid>
      <pubDate>Tue, 19 May 2026 08:59:19 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Architecture: Design Patterns That Hold Up]]></title>
      <description><![CDATA[Good application security architecture is a small set of repeatable patterns — trust boundaries, defense in depth, least privilege — applied consistently, not a document nobody reads.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-architecture-design-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-architecture-design-patterns</guid>
      <pubDate>Tue, 19 May 2026 08:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Hacking Websites: How Attacks Work and How to Defend Against Them]]></title>
      <description><![CDATA[A defender's overview of how websites get compromised, the common attack classes behind real breaches, and the controls that stop them before they start.]]></description>
      <link>https://safeguard.sh/resources/blog/hacking-websites</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hacking-websites</guid>
      <pubDate>Tue, 19 May 2026 07:38:53 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Top 8 DevSecOps best practices]]></title>
      <description><![CDATA[Log4Shell and the xz backdoor show why DevSecOps matters. Eight concrete practices — from reachability triage to auto-fix PRs — teams can implement now.]]></description>
      <link>https://safeguard.sh/resources/blog/top-8-devsecops-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-8-devsecops-best-practices</guid>
      <pubDate>Tue, 19 May 2026 07:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[webpack-cli: What It Does and How to Keep It Secure]]></title>
      <description><![CDATA[webpack-cli is the command-line front end to webpack, and as a build-time dependency it deserves the same supply-chain scrutiny as your runtime packages.]]></description>
      <link>https://safeguard.sh/resources/blog/webpack-cli</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webpack-cli</guid>
      <pubDate>Tue, 19 May 2026 06:18:26 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Endor Labs Pricing: What It Costs and Who It's Built For]]></title>
      <description><![CDATA[Endor Labs doesn't publish pricing publicly. Here's what actually drives the cost, what to ask sales reps, and how Safeguard's approach compares on scope.]]></description>
      <link>https://safeguard.sh/resources/blog/endor-labs-pricing-what-it-costs-and-who-its-built-for</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/endor-labs-pricing-what-it-costs-and-who-its-built-for</guid>
      <pubDate>Tue, 19 May 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Test CLI: How to Scan Projects from the Command Line]]></title>
      <description><![CDATA[The snyk test CLI command scans your project's dependencies for known vulnerabilities right from the terminal. Here is how to run it, gate on severity, and wire it into CI without slowing everyone down.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-test-cli</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-test-cli</guid>
      <pubDate>Tue, 19 May 2026 04:57:59 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to implement DevSecOps in 4 steps]]></title>
      <description><![CDATA[A concrete, 4-step playbook for implementing DevSecOps — pipeline gating, SBOM generation, reachability-based triage, and auto-fix PRs.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-implement-devsecops-in-4-steps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-implement-devsecops-in-4-steps</guid>
      <pubDate>Tue, 19 May 2026 04:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[react-native-version-check: Prompting App Updates the Safe Way]]></title>
      <description><![CDATA[react-native-version-check compares the installed app version against the store listing so you can prompt users to update. Here is how to wire it up and its security tradeoffs.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-version-check</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-version-check</guid>
      <pubDate>Tue, 19 May 2026 03:37:33 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[First-Party Code vs Open Source Risk: Where Should AppSec...]]></title>
      <description><![CDATA[First-party code and open source dependencies are one attack surface. See how Safeguard's unified scanning compares to Endor Labs' open-source-first approach.]]></description>
      <link>https://safeguard.sh/resources/blog/first-party-code-vs-open-source-risk-where-should-appsec-teams-focus</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/first-party-code-vs-open-source-risk-where-should-appsec-teams-focus</guid>
      <pubDate>Tue, 19 May 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[qrcode.react Security: Safe QR Code Rendering in React]]></title>
      <description><![CDATA[A security guide to the qrcode.react library, the risks of encoding untrusted data into QR codes, and how to render them safely in a React app.]]></description>
      <link>https://safeguard.sh/resources/blog/qrcode-react</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/qrcode-react</guid>
      <pubDate>Tue, 19 May 2026 02:17:06 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps automation: principles, frameworks, and tools]]></title>
      <description><![CDATA[A practical breakdown of DevSecOps automation frameworks — principles, standards like NIST SSDF, and the tools that turn shift-left security into a repeatable pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-automation-principles-frameworks-and-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-automation-principles-frameworks-and-tools</guid>
      <pubDate>Tue, 19 May 2026 01:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Are the Benefits of Using SAST Tools During Code Review?]]></title>
      <description><![CDATA[SAST tools turn code review into a consistent security checkpoint by flagging vulnerable patterns automatically, so reviewers can focus on judgment instead of pattern-matching.]]></description>
      <link>https://safeguard.sh/resources/blog/benefit-of-using-sast-tools-during-code-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/benefit-of-using-sast-tools-during-code-review</guid>
      <pubDate>Tue, 19 May 2026 00:56:39 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Tool Consolidation: One Platform vs Point Solut...]]></title>
      <description><![CDATA[DevSecOps tool consolidation is reshaping security buying decisions. See how Safeguard's unified platform compares to Endor Labs' SCA-focused approach.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-tool-consolidation-one-platform-vs-point-solutions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-tool-consolidation-one-platform-vs-point-solutions</guid>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[react-native-vision-camera: A Security Guide to Camera Access]]></title>
      <description><![CDATA[react-native-vision-camera is the go-to camera library for React Native. Here is how to handle permissions, frame data, and captured media without leaking user privacy.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-vision-camera</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-vision-camera</guid>
      <pubDate>Mon, 18 May 2026 23:36:13 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[react-helmet-async: Is It Safe to Depend On in 2025?]]></title>
      <description><![CDATA[react-helmet-async manages document head tags in React apps, but its maintenance history is bumpy. Here is what the package does, where the risk sits, and how to depend on it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/react-helmet-async</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-helmet-async</guid>
      <pubDate>Mon, 18 May 2026 22:15:46 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[http-proxy-middleware on npm: Security Review and Safe Usage]]></title>
      <description><![CDATA[http-proxy-middleware is a widely used npm proxy library that has shipped two notable CVEs. Here is what to pin, what to patch, and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/http-proxy-middleware-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/http-proxy-middleware-npm</guid>
      <pubDate>Mon, 18 May 2026 20:55:19 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Asana MCP Cross-Tenant Leak: A SaaS Connector Failure Mode]]></title>
      <description><![CDATA[From May 1 to June 17, 2025, Asana's MCP server exposed records from one customer's workspace to another. The bug was a textbook authorization break wearing an AI label.]]></description>
      <link>https://safeguard.sh/resources/blog/asana-mcp-cross-tenant-data-leak-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/asana-mcp-cross-tenant-data-leak-2025</guid>
      <pubDate>Mon, 18 May 2026 19:34:53 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What Is a DAST Scan? Dynamic Application Security Testing Explained]]></title>
      <description><![CDATA[A DAST scan tests your running application from the outside, the way an attacker would, finding the vulnerabilities that only appear when code, config, and runtime meet.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-scan</guid>
      <pubDate>Mon, 18 May 2026 18:14:26 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Malware Today: How Attacks Reach Your Builds Now]]></title>
      <description><![CDATA[PyPI malware today mostly arrives through typosquatting, dependency confusion, and malicious install scripts. Here is how the current attack patterns work and how to defend your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-malware-today</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-malware-today</guid>
      <pubDate>Mon, 18 May 2026 16:53:59 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-42945: A Buffer Overflow in NGINX's Rewrite Module Reaches Into Your Kubernetes Clusters (May 2026)]]></title>
      <description><![CDATA[Disclosed May 17, 2026 with public PoC and in-the-wild activity, CVE-2026-42945 is a buffer overflow in NGINX's ngx_http_rewrite_module. It affects core NGINX and the ingress controllers that wrap it, putting cluster ingress in scope.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2026-42945-nginx-rewrite-rce-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2026-42945-nginx-rewrite-rce-may-2026</guid>
      <pubDate>Mon, 18 May 2026 16:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[UK Cyber Security and Resilience Bill (May 2026): Report Stage, Supply Chain, and the 24-Hour Clock]]></title>
      <description><![CDATA[By May 2026 the UK's Cyber Security and Resilience Bill has cleared Commons committee and is heading to Report stage. We analyze its expanded scope, the 24-hour incident reporting requirement, and the supply chain obligations software vendors should prepare for.]]></description>
      <link>https://safeguard.sh/resources/blog/uk-cyber-security-resilience-bill-report-stage-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uk-cyber-security-resilience-bill-report-stage-may-2026</guid>
      <pubDate>Mon, 18 May 2026 16:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[react-native-fs: What to Know Before You Depend On It]]></title>
      <description><![CDATA[react-native-fs gives React Native apps native filesystem access, but its maintenance status and the way you handle paths both carry real security weight.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-fs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-fs</guid>
      <pubDate>Mon, 18 May 2026 15:33:32 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[React Fast Marquee: A Security and Maintenance Guide]]></title>
      <description><![CDATA[React Fast Marquee is a lightweight scrolling-marquee component for React. Here is an honest look at its risk profile, maintenance status, and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/react-fast-marquee</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-fast-marquee</guid>
      <pubDate>Mon, 18 May 2026 14:13:06 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[nginx 1.18.0 CVEs: Which Vulnerabilities Affect You and How to Patch]]></title>
      <description><![CDATA[A look at the CVEs that affect nginx 1.18.0, why running an end-of-life stable branch is the real risk, and the safest path off it.]]></description>
      <link>https://safeguard.sh/resources/blog/nginx-1-18-0-cve</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nginx-1-18-0-cve</guid>
      <pubDate>Mon, 18 May 2026 12:52:39 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[npm classnames: Security Review and Safe Usage]]></title>
      <description><![CDATA[The npm classnames package is a tiny, widely used utility for conditionally joining CSS class names. Here is its security profile and how to use it safely in React.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-classnames</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-classnames</guid>
      <pubDate>Mon, 18 May 2026 11:32:12 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Security Breaches: What Actually Happened in Real Incidents]]></title>
      <description><![CDATA[Real Kubernetes security breaches rarely start with an exotic zero-day — exposed dashboards, misconfigured RBAC, and default credentials show up again and again.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-security-breaches-what-actually-happened</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-security-breaches-what-actually-happened</guid>
      <pubDate>Mon, 18 May 2026 10:11:46 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The 4 best DevSecOps tools for a secure DevOps workflow]]></title>
      <description><![CDATA[The 4 DevSecOps tool categories a secure pipeline needs — SCA, SAST, container/IaC scanning, secrets scanning — with real incidents and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/the-4-best-devsecops-tools-for-a-secure-devops-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-4-best-devsecops-tools-for-a-secure-devops-workflow</guid>
      <pubDate>Mon, 18 May 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis Explained: Function-Level vs Packag...]]></title>
      <description><![CDATA[Package-level reachability flags 60% of CVEs as "reachable." Function-level analysis, tracing real call paths, cuts that to under 10%. Here's the difference.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-explained-function-level-vs-package-level</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-explained-function-level-vs-package-level</guid>
      <pubDate>Mon, 18 May 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx Supported Languages: What CxSAST Can Actually Scan]]></title>
      <description><![CDATA[Checkmarx supports 35+ programming languages and 80+ frameworks for static analysis. Here is how its language coverage works and what to check before buying.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-supported-languages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-supported-languages</guid>
      <pubDate>Mon, 18 May 2026 08:51:19 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Running Java in Docker: A Secure Dockerfile Walkthrough]]></title>
      <description><![CDATA[A Java Docker container done right: multi-stage builds, a JRE not a full JDK, non-root users, JVM container-awareness, and a base image that does not ship the world.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-java-dockerfile-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-java-dockerfile-guide</guid>
      <pubDate>Mon, 18 May 2026 07:30:52 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Building a security-conscious CI/CD pipeline]]></title>
      <description><![CDATA[CI/CD pipelines are now the top supply chain target. Here's how to build one with real controls—secrets, scoping, SBOMs, and provenance.]]></description>
      <link>https://safeguard.sh/resources/blog/building-a-security-conscious-cicd-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-a-security-conscious-cicd-pipeline</guid>
      <pubDate>Mon, 18 May 2026 07:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SAST Scanners: How They Work and Which One to Use]]></title>
      <description><![CDATA[SAST scanners read your source code to find vulnerabilities without running it. Here is how the main open-source and commercial options compare in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-scanners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-scanners</guid>
      <pubDate>Mon, 18 May 2026 06:10:26 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AI SAST: How AI-Native Static Analysis Finds Business Log...]]></title>
      <description><![CDATA[Traditional SAST can't see business logic flaws because there's no bad syntax to match. Here's how AI-native static analysis finds them, and how Safeguard's approach compares to Endor Labs.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-sast-how-ai-native-static-analysis-finds-business-logic-flaws</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-sast-how-ai-native-static-analysis-finds-business-logic-flaws</guid>
      <pubDate>Mon, 18 May 2026 06:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Online Vulnerability Scan: How to Test Your App on the Web]]></title>
      <description><![CDATA[What an online vulnerability scan actually checks, how hosted scanners differ from installed tools, and how to run one without breaking your production site.]]></description>
      <link>https://safeguard.sh/resources/blog/online-vulnerability-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/online-vulnerability-scan</guid>
      <pubDate>Mon, 18 May 2026 04:49:59 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[8 tips for securing your CI/CD pipeline]]></title>
      <description><![CDATA[Real incidents like tj-actions and xz-utils show how CI/CD pipelines get compromised. Eight concrete, actionable tips to lock yours down.]]></description>
      <link>https://safeguard.sh/resources/blog/8-tips-for-securing-your-cicd-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/8-tips-for-securing-your-cicd-pipeline</guid>
      <pubDate>Mon, 18 May 2026 04:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Python pptx: Using python-pptx Securely to Build Presentations]]></title>
      <description><![CDATA[python pptx usually means the python-pptx library for reading and writing PowerPoint files. Here is how it works and the security pitfalls of processing untrusted decks.]]></description>
      <link>https://safeguard.sh/resources/blog/python-pptx</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-pptx</guid>
      <pubDate>Mon, 18 May 2026 03:29:32 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[AI Security Code Review for Pull Requests]]></title>
      <description><![CDATA[How AI code review security works in pull requests, where Endor Labs stops short, and what closes the gap between diff review and real supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-code-review-for-pull-requests</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-code-review-for-pull-requests</guid>
      <pubDate>Mon, 18 May 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Read and Fix a Checkmarx Vulnerability Finding]]></title>
      <description><![CDATA[A Checkmarx vulnerability is a SAST finding that traces tainted data from source to sink. Here is how to interpret one, confirm it is real, and remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-vulnerability</guid>
      <pubDate>Mon, 18 May 2026 02:09:06 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Building a secure CI/CD pipeline with GitHub Actions]]></title>
      <description><![CDATA[The tj-actions breach exposed secrets in 23,000 repos. Here's how pwn requests, unpinned tags, and self-hosted runners put your CI/CD at risk.]]></description>
      <link>https://safeguard.sh/resources/blog/building-a-secure-cicd-pipeline-with-github-actions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-a-secure-cicd-pipeline-with-github-actions</guid>
      <pubDate>Mon, 18 May 2026 01:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[zipp in Python: Why It Is in Your Dependency Tree]]></title>
      <description><![CDATA[The python zipp package shows up in almost every Python environment without ever being asked for by name. Here is what it does, how it got there, and the one CVE against it.]]></description>
      <link>https://safeguard.sh/resources/blog/python-zipp-package-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-zipp-package-guide</guid>
      <pubDate>Mon, 18 May 2026 00:48:39 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secrets Detection in Source Code: What Gets Missed by Reg...]]></title>
      <description><![CDATA[Regex-based secrets scanners miss encoded, multi-line, and historical secrets in git history. Here is what a real secrets detection tool must catch.]]></description>
      <link>https://safeguard.sh/resources/blog/secrets-detection-in-source-code-what-gets-missed-by-regex-scanners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secrets-detection-in-source-code-what-gets-missed-by-regex-scanners</guid>
      <pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Writing a Secure Node.js Dockerfile: Best Practices That Hold Up]]></title>
      <description><![CDATA[A secure Node.js Dockerfile pins a specific base image, runs as a non-root user, and uses multi-stage builds to keep build tooling out of production. Here is a hardened template and why each line matters.]]></description>
      <link>https://safeguard.sh/resources/blog/dockerfile-nodejs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dockerfile-nodejs</guid>
      <pubDate>Sun, 17 May 2026 23:28:12 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Node Media Server Security: Hardening Your Streaming Stack]]></title>
      <description><![CDATA[Node Media Server turns a Node.js process into an RTMP and HTTP-FLV streaming server. Exposed carelessly, it becomes an open door. Here is how to run it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/node-media-server</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-media-server</guid>
      <pubDate>Sun, 17 May 2026 22:07:45 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Password Salt and Hash: How to Store Passwords Safely]]></title>
      <description><![CDATA[Storing a password means hashing it with a slow algorithm and a unique salt, never encrypting it or saving it in plaintext. Here's how salting and hashing actually protect users.]]></description>
      <link>https://safeguard.sh/resources/blog/password-salt-and-hash</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/password-salt-and-hash</guid>
      <pubDate>Sun, 17 May 2026 20:47:19 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[npm ssh2-sftp-client: Security Review and Safe Usage]]></title>
      <description><![CDATA[ssh2-sftp-client wraps the ssh2 library in a promise-based SFTP API. Its security posture rests on host key verification and credential handling, which are easy to get wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-ssh2-sftp-client</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-ssh2-sftp-client</guid>
      <pubDate>Sun, 17 May 2026 19:26:52 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Boto3 Security: Using the AWS SDK for Python Safely]]></title>
      <description><![CDATA[Boto3 is the AWS SDK for Python, and how you configure its credentials, sessions, and version pinning decides how much of your AWS account you are putting at risk.]]></description>
      <link>https://safeguard.sh/resources/blog/boto3</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/boto3</guid>
      <pubDate>Sun, 17 May 2026 18:06:25 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[lint-staged (npm): A Security Review and Safe Setup Guide]]></title>
      <description><![CDATA[The lint-staged npm package runs linters and formatters only on your git-staged files, keeping commits clean and fast. Here is how to configure it safely and what its command-running design means for security.]]></description>
      <link>https://safeguard.sh/resources/blog/lint-staged-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lint-staged-npm</guid>
      <pubDate>Sun, 17 May 2026 16:45:59 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Possible Effect of Malicious Code?]]></title>
      <description><![CDATA[Malicious code can steal data, encrypt files for ransom, hand attackers remote control, drain resources, and spread across a network. Here is the full range of effects and how to limit them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-possible-effect-of-malicious-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-possible-effect-of-malicious-code</guid>
      <pubDate>Sun, 17 May 2026 15:25:32 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[URLEncoder in Java: Correct Usage and Its Security Pitfalls]]></title>
      <description><![CDATA[URLEncoder in Java is easy to misuse. Here is when it applies, why it is not URL encoding for whole URLs, and the injection risks of getting it wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/urlencoder-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/urlencoder-java</guid>
      <pubDate>Sun, 17 May 2026 14:05:05 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What Is an Application Security Model, and How Do You Build One?]]></title>
      <description><![CDATA[An application security model is the structured way you define, measure, and improve how your applications resist attack, usually expressed through a maturity model.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-model</guid>
      <pubDate>Sun, 17 May 2026 12:44:39 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[react-scripts After Create React App: A Security Guide]]></title>
      <description><![CDATA[With Create React App deprecated, react-scripts is now in maintenance mode. Here is what that means for the security of projects still depending on it.]]></description>
      <link>https://safeguard.sh/resources/blog/react-scripts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-scripts</guid>
      <pubDate>Sun, 17 May 2026 11:24:12 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[prop-types npm: Security Review and Safe Usage]]></title>
      <description><![CDATA[The prop-types npm package is a runtime type checker React split out years ago. React 19 stopped honoring propTypes internally, which changes when and why you should still depend on it.]]></description>
      <link>https://safeguard.sh/resources/blog/prop-types-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prop-types-npm</guid>
      <pubDate>Sun, 17 May 2026 10:03:45 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Exploring vulnerabilities in GitHub Actions workflows]]></title>
      <description><![CDATA[From the tj-actions/changed-files hijack to PyTorch's self-hosted runner breach, real incidents show how GitHub Actions workflows keep getting exploited.]]></description>
      <link>https://safeguard.sh/resources/blog/exploring-vulnerabilities-in-github-actions-workflows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/exploring-vulnerabilities-in-github-actions-workflows</guid>
      <pubDate>Sun, 17 May 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Malicious Package Detection: Behavioral vs Signature-Base...]]></title>
      <description><![CDATA[A side-by-side look at signature-based malicious package detection (like Endor Labs) versus behavioral analysis, using real npm attack timelines from Shai-Hulud to chalk/debug.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-package-detection-behavioral-vs-signature-based-approaches</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-package-detection-behavioral-vs-signature-based-approaches</guid>
      <pubDate>Sun, 17 May 2026 09:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Do You Create an npm Module Securely?]]></title>
      <description><![CDATA[To create an npm module you need package.json, a clear entry point, and a publish step, but doing it safely means locking down metadata, tokens, and what actually ships. Here is the full walkthrough.]]></description>
      <link>https://safeguard.sh/resources/blog/create-npm-module</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/create-npm-module</guid>
      <pubDate>Sun, 17 May 2026 08:43:18 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Is react-native-gesture-handler Safe? An npm Security Review]]></title>
      <description><![CDATA[react-native-gesture-handler is a core, actively maintained library, but any native module changes your app's trust and update calculus. Here is the security review.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-gesture-handler-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-gesture-handler-npm</guid>
      <pubDate>Sun, 17 May 2026 07:22:52 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Securing self-hosted GitHub Actions runners]]></title>
      <description><![CDATA[Self-hosted GitHub Actions runners trade GitHub's ephemeral isolation for persistent infrastructure access — here's how real incidents like CVE-2025-30066 exploited that gap.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-self-hosted-github-actions-runners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-self-hosted-github-actions-runners</guid>
      <pubDate>Sun, 17 May 2026 07:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Java Vulnerability Scanner: How It Works and What to Use]]></title>
      <description><![CDATA[A Java vulnerability scanner inspects your dependencies, bytecode, and running app for known CVEs and insecure patterns. Here is how each type works.]]></description>
      <link>https://safeguard.sh/resources/blog/java-vulnerability-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-vulnerability-scanner</guid>
      <pubDate>Sun, 17 May 2026 06:02:25 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Trusted Publishing for npm: Why Only 14% of Compromised P...]]></title>
      <description><![CDATA[Only 14% of packages compromised since npm launched Trusted Publishing use it. Here's how OIDC-based publishing works, why adoption lags, and what still gets missed.]]></description>
      <link>https://safeguard.sh/resources/blog/trusted-publishing-for-npm-why-only-14-of-compromised-packages-use-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trusted-publishing-for-npm-why-only-14-of-compromised-packages-use-it</guid>
      <pubDate>Sun, 17 May 2026 06:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Introducing the Safeguard MCP Server: AI-Native Software Supply Chain Security]]></title>
      <description><![CDATA[Safeguard launches its MCP Server, bringing software supply chain security directly into AI-powered development workflows through the Model Context Protocol.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-mcp-server-release</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-mcp-server-release</guid>
      <pubDate>Sun, 17 May 2026 04:41:58 GMT</pubDate>
      <category>Product Launch</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to Install the Snyk CLI (npm, Homebrew, and Standalone Binary)]]></title>
      <description><![CDATA[Step-by-step ways to install the Snyk CLI on macOS, Linux, and Windows using npm, Homebrew, Scoop, or a standalone binary, plus how to authenticate and use it in CI.]]></description>
      <link>https://safeguard.sh/resources/blog/install-snyk-cli</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/install-snyk-cli</guid>
      <pubDate>Sun, 17 May 2026 03:21:32 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Package Firewall: Blocking Malicious Dependencies at Inst...]]></title>
      <description><![CDATA[Malicious npm and PyPI packages are published daily. See why a package firewall that blocks at install time stops attacks that post-hoc scanners catch too late.]]></description>
      <link>https://safeguard.sh/resources/blog/package-firewall-blocking-malicious-dependencies-at-install-time</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/package-firewall-blocking-malicious-dependencies-at-install-time</guid>
      <pubDate>Sun, 17 May 2026 03:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[spring-webmvc Security: Known CVEs and How to Stay Patched]]></title>
      <description><![CDATA[A security guide to the spring-webmvc Maven dependency: recent path traversal CVEs, affected version ranges, and how to keep this core Spring artifact patched.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-webmvc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-webmvc</guid>
      <pubDate>Sun, 17 May 2026 02:01:05 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Rego Policy Examples: Practical Rules for Policy-as-Code]]></title>
      <description><![CDATA[Real Rego policy examples you can adapt today — from denying privileged containers to gating deployments on vulnerability severity — with the language patterns that make them readable.]]></description>
      <link>https://safeguard.sh/resources/blog/rego-policy-examples</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rego-policy-examples</guid>
      <pubDate>Sun, 17 May 2026 00:40:38 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Cooldown Periods as a Malware Defense]]></title>
      <description><![CDATA[Malicious npm packages are often caught within days. Cooldown periods exploit that lag — here's how they work, and how Endor Labs and Safeguard compare.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-cooldown-periods-as-a-malware-defense</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-cooldown-periods-as-a-malware-defense</guid>
      <pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[k8s securityContext: How to Lock Down Kubernetes Pods and Containers]]></title>
      <description><![CDATA[The k8s securityContext is your first real control over what a container can do at runtime. A field-by-field guide to a hardened, non-root pod spec.]]></description>
      <link>https://safeguard.sh/resources/blog/k8s-securitycontext</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/k8s-securitycontext</guid>
      <pubDate>Sat, 16 May 2026 23:20:12 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Synk SAST (Snyk Code): A Practical Guide to Snyk's Static Analysis]]></title>
      <description><![CDATA[Searching for 'Synk SAST' usually means Snyk Code, Snyk's static application security testing tool. Here is what it does, how it works, and where it fits in your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/synk-sast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/synk-sast</guid>
      <pubDate>Sat, 16 May 2026 21:59:45 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Python Pickle: Reading, Writing, and Why It Is a Security Risk]]></title>
      <description><![CDATA[How to pickle an object in Python and read a pickle file back, and the reason the standard library itself warns you never to unpickle data you did not produce.]]></description>
      <link>https://safeguard.sh/resources/blog/python-pickle-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-pickle-security-guide</guid>
      <pubDate>Sat, 16 May 2026 20:39:18 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[@typescript-eslint/typescript-estree: A Security Review]]></title>
      <description><![CDATA[A security review of @typescript-eslint/typescript-estree: what the parser does, where its real risk lives (its dependencies, not itself), and how to keep it safe.]]></description>
      <link>https://safeguard.sh/resources/blog/typescript-eslint-typescript-estree</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/typescript-eslint-typescript-estree</guid>
      <pubDate>Sat, 16 May 2026 19:18:52 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Security Plugins for CMS and App Platforms: What They Actually Do]]></title>
      <description><![CDATA[A security plugin can harden a CMS meaningfully, but it can't fix a vulnerable core install or a poorly coded theme — it's a layer, not a replacement for patching.]]></description>
      <link>https://safeguard.sh/resources/blog/security-plugins-for-cms-and-app-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-plugins-for-cms-and-app-platforms</guid>
      <pubDate>Sat, 16 May 2026 17:58:25 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Installing a Java Runtime on Mac the Secure Way]]></title>
      <description><![CDATA[The safest way to install a Java runtime on Mac is a maintained OpenJDK build like Temurin via Homebrew. Here is how to do it on Apple Silicon and avoid licensing and update traps.]]></description>
      <link>https://safeguard.sh/resources/blog/mac-java-runtime</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mac-java-runtime</guid>
      <pubDate>Sat, 16 May 2026 16:37:58 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Claw Chain: Four Chained CVEs Turn 245,000 OpenClaw Agents Into Backdoors (May 2026)]]></title>
      <description><![CDATA[Cyera disclosed four chainable flaws in OpenClaw on May 15, 2026 that take an autonomous agent from prompt injection to credential theft, privilege escalation, and a persistent backdoor. Roughly 245,000 instances sit exposed on the internet.]]></description>
      <link>https://safeguard.sh/resources/blog/openclaw-claw-chain-vulnerabilities-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openclaw-claw-chain-vulnerabilities-may-2026</guid>
      <pubDate>Sat, 16 May 2026 16:00:00 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Has AWS Ever Been Hacked? What 'AWS Hacked' Headlines Really Mean]]></title>
      <description><![CDATA[When people ask 'has AWS ever been hacked,' the honest answer is that AWS infrastructure has not been breached, but AWS customers get breached constantly through their own misconfigurations. Here is the difference and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-hacked</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-hacked</guid>
      <pubDate>Sat, 16 May 2026 15:17:31 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[shortid Is Deprecated: Why It Is Unsafe for IDs and What to Use Instead]]></title>
      <description><![CDATA[The shortid npm package is deprecated by its own maintainers because the architecture is unsafe. Here is what is actually wrong with it and how to migrate to nanoid without breaking existing IDs.]]></description>
      <link>https://safeguard.sh/resources/blog/shortid-npm-deprecated-use-nanoid</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shortid-npm-deprecated-use-nanoid</guid>
      <pubDate>Sat, 16 May 2026 13:57:05 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Blind SQL Injection: A Practical Cheat Sheet]]></title>
      <description><![CDATA[This blind sql injection cheat sheet covers how boolean-based and time-based blind attacks actually work, why they succeed against apps with no visible error output, and how to close them off.]]></description>
      <link>https://safeguard.sh/resources/blog/blind-sql-injection-cheat-sheet</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/blind-sql-injection-cheat-sheet</guid>
      <pubDate>Sat, 16 May 2026 12:36:38 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[react-grid-layout: Package Health and Production Considerations]]></title>
      <description><![CDATA[A production-focused review of the react-grid-layout npm package: what it does well, its maintenance profile, performance traps, and how to depend on it responsibly.]]></description>
      <link>https://safeguard.sh/resources/blog/react-grid-layout-npm-package-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-grid-layout-npm-package-review</guid>
      <pubDate>Sat, 16 May 2026 11:16:11 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Secrets management: tools and best practices]]></title>
      <description><![CDATA[Secrets leak because of workflow gaps, not carelessness. Here's how vaults, scanners, and rotation policies actually stop credential exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/secrets-management-tools-and-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secrets-management-tools-and-best-practices</guid>
      <pubDate>Sat, 16 May 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Application Layer Security: What It Covers (and What It Doesn't)]]></title>
      <description><![CDATA[Application layer security protects the code, logic, and APIs at the top of the OSI stack, but it's easy to confuse it with network or infrastructure security controls that solve a different problem.]]></description>
      <link>https://safeguard.sh/resources/blog/application-layer-security-what-it-covers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-layer-security-what-it-covers</guid>
      <pubDate>Sat, 16 May 2026 09:55:45 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Upgrade Impact Analysis: Predicting Breaking Changes Befo...]]></title>
      <description><![CDATA[Why 70% of security patches sit unapplied for months, and how diffing a package upgrade against your call graph predicts breaking changes before you run npm update.]]></description>
      <link>https://safeguard.sh/resources/blog/upgrade-impact-analysis-predicting-breaking-changes-before-you-patch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/upgrade-impact-analysis-predicting-breaking-changes-before-you-patch</guid>
      <pubDate>Sat, 16 May 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Japan AMED Software Supply Chain Guidance Overview]]></title>
      <description><![CDATA[Japan's AMED, METI, and PMDA guidance now converges on SBOMs and supply chain controls, reshaping how medical and industrial software is built, shipped, and maintained.]]></description>
      <link>https://safeguard.sh/resources/blog/japan-amed-software-supply-chain-guidance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/japan-amed-software-supply-chain-guidance</guid>
      <pubDate>Sat, 16 May 2026 08:35:18 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GUAC v1.0: Supply-Chain Graphs Reach Stable in June 2025]]></title>
      <description><![CDATA[GUAC v1.0 shipped on June 12, 2025. We unpack the GraphQL API surface, the parsers for CSAF, OpenVEX, SPDX, CycloneDX, DSSE, and what stable means for production deployments.]]></description>
      <link>https://safeguard.sh/resources/blog/guac-v1-0-release-graph-supply-chain-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/guac-v1-0-release-graph-supply-chain-2025</guid>
      <pubDate>Sat, 16 May 2026 07:14:51 GMT</pubDate>
      <category>Frameworks</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Finding and fixing exposed hardcoded secrets in GitHub projects]]></title>
      <description><![CDATA[Hardcoded secrets leak into GitHub every day and get exploited within minutes. Here's how to find, fix, and prevent exposed credentials at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/finding-and-fixing-exposed-hardcoded-secrets-in-github-projects</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/finding-and-fixing-exposed-hardcoded-secrets-in-github-projects</guid>
      <pubDate>Sat, 16 May 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Automated Dependency Patches: How Endor-Style Patch Gener...]]></title>
      <description><![CDATA[Endor Labs generates automated dependency patches using reachability and AI rewrites. Here's how the pipeline works, where it breaks, and Safeguard's approach.]]></description>
      <link>https://safeguard.sh/resources/blog/automated-dependency-patches-how-endor-style-patch-generation-works</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automated-dependency-patches-how-endor-style-patch-generation-works</guid>
      <pubDate>Sat, 16 May 2026 06:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-5777 (Citrix Bleed 2): NetScaler Memory Disclosure Deep Dive]]></title>
      <description><![CDATA[A second Citrix Bleed leaks session tokens from NetScaler ADC and Gateway memory. We dissect the buffer over-read and the IR playbook.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2025-5777-citrix-bleed-2-netscaler-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2025-5777-citrix-bleed-2-netscaler-analysis</guid>
      <pubDate>Sat, 16 May 2026 05:54:25 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Coinbase TaskUs Insider Breach: When the BPO Becomes the Attack Surface]]></title>
      <description><![CDATA[In May 2025 Coinbase disclosed that contractor support agents at TaskUs had been bribed to leak customer data for months. We unpack the insider-threat supply-chain anatomy and what crypto and fintech defenders must change.]]></description>
      <link>https://safeguard.sh/resources/blog/coinbase-taskus-insider-extortion-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/coinbase-taskus-insider-extortion-2025</guid>
      <pubDate>Sat, 16 May 2026 04:33:58 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Docker Rebuild Strategies: Cache and Layers Done Right]]></title>
      <description><![CDATA[Docker rebuild speed and security both come down to how you order layers and invalidate cache — get it wrong and you either wait ten minutes per build or ship stale, unpatched images.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-rebuild-strategies-cache-and-layers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-rebuild-strategies-cache-and-layers</guid>
      <pubDate>Sat, 16 May 2026 03:13:31 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Patch Transparency: Auditing Automated Fix Pull Requests]]></title>
      <description><![CDATA[Automated fix PRs from Dependabot, Renovate, and Endor Labs move fast but are rarely auditable. Here's what a real patch transparency record needs.]]></description>
      <link>https://safeguard.sh/resources/blog/patch-transparency-auditing-automated-fix-pull-requests</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/patch-transparency-auditing-automated-fix-pull-requests</guid>
      <pubDate>Sat, 16 May 2026 03:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Building an Open Source Risk Intelligence Platform: Beyond Vulnerability Scanning]]></title>
      <description><![CDATA[Vulnerability scanning is one dimension of open source risk. A true risk intelligence platform must also evaluate maintainer health, project sustainability, licensing, and malicious package threats.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-risk-intelligence-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-risk-intelligence-platform</guid>
      <pubDate>Sat, 16 May 2026 01:53:05 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[com.google.code.gson: Using Gson Safely in Modern Java]]></title>
      <description><![CDATA[Why the com.google.code.gson group ID looks so odd, what maintenance mode means for the library, and the configuration habits that keep Gson safe in modern Java services.]]></description>
      <link>https://safeguard.sh/resources/blog/gson-maven-dependency-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gson-maven-dependency-guide</guid>
      <pubDate>Sat, 16 May 2026 00:32:38 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Zero-Day Patch Response at Scale: Can Open Source Maintai...]]></title>
      <description><![CDATA[Zero-day patch timelines swing from 3 hours to 10 weeks across open source projects. Here's why maintainer capacity, not tooling, is the real bottleneck.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-day-patch-response-at-mythos-scale-can-maintainers-keep-up</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-day-patch-response-at-mythos-scale-can-maintainers-keep-up</guid>
      <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Application Vulnerability Testing Methods, Compared]]></title>
      <description><![CDATA[Application vulnerability testing spans static analysis, dynamic testing, dependency scanning, and manual review — each catches a different slice of application security vulnerabilities, and none covers all of them alone.]]></description>
      <link>https://safeguard.sh/resources/blog/application-vulnerability-testing-methods-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-vulnerability-testing-methods-compared</guid>
      <pubDate>Fri, 15 May 2026 23:12:11 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[PHP Webshells: How Attackers Plant Them and How to Detect One]]></title>
      <description><![CDATA[A PHP webshell is a malicious script that gives an attacker remote control of your server. Here is how they get planted, what they look like, and how to find them.]]></description>
      <link>https://safeguard.sh/resources/blog/php-webshell</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-webshell</guid>
      <pubDate>Fri, 15 May 2026 21:51:44 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Who Is the CEO of Snyk, and Why It Matters for Buyers]]></title>
      <description><![CDATA[The Snyk CEO question comes up during vendor evaluations for a reason: leadership shapes roadmap and stability. Here is who runs Snyk and how to read leadership signals as a buyer.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-ceo</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-ceo</guid>
      <pubDate>Fri, 15 May 2026 20:31:18 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Is the DOMPurify npm Package Safe? CVEs and Secure Usage]]></title>
      <description><![CDATA[DOMPurify (npm) is the right tool for sanitizing HTML against XSS, and it is safe when you keep it patched - but it has had real bypass CVEs, so version discipline matters.]]></description>
      <link>https://safeguard.sh/resources/blog/dompurify-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dompurify-npm</guid>
      <pubDate>Fri, 15 May 2026 19:10:51 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Create an npm Package in TypeScript Safely]]></title>
      <description><![CDATA[A practical walkthrough to create an npm package in TypeScript, plus the supply-chain hardening steps most tutorials skip: provenance, dependency hygiene, and safe publishing.]]></description>
      <link>https://safeguard.sh/resources/blog/create-npm-package-typescript</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/create-npm-package-typescript</guid>
      <pubDate>Fri, 15 May 2026 17:50:24 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[DevOps Performance Metrics That Also Measure Security]]></title>
      <description><![CDATA[The DevOps performance metrics worth tracking are the four DORA metrics plus a handful of security signals that reveal whether speed is coming at the cost of risk.]]></description>
      <link>https://safeguard.sh/resources/blog/devops-performance-metrics</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devops-performance-metrics</guid>
      <pubDate>Fri, 15 May 2026 16:29:58 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[When Configuration Is the Vulnerability: Microsoft's May 2026 Look at Exposed AI Apps on Kubernetes]]></title>
      <description><![CDATA[Microsoft's May 14, 2026 research found AI frameworks shipping Helm charts that expose web UIs on internet-facing LoadBalancers with no authentication and cluster-admin service accounts. Mage AI on port 6789 was the headline, but it was far from alone.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-app-kubernetes-misconfiguration-mage-ai-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-app-kubernetes-misconfiguration-mage-ai-may-2026</guid>
      <pubDate>Fri, 15 May 2026 16:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[node-ipc Compromised Again (14 May 2026): An 80 KB Credential Stealer in a 10M-Download Library]]></title>
      <description><![CDATA[On 14 May 2026, three malicious node-ipc versions (9.1.6, 9.2.3, 12.0.1) shipped an 80 KB credential-stealing IIFE appended after module.exports in the CJS bundle — no install scripts, harvesting 90+ secret categories from a library with 10M+ weekly downloads.]]></description>
      <link>https://safeguard.sh/resources/blog/node-ipc-npm-credential-stealer-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-ipc-npm-credential-stealer-may-2026</guid>
      <pubDate>Fri, 15 May 2026 16:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Palo Alto PAN-OS CVE-2026-0265: CAS Signature-Verification Auth Bypass (May 2026)]]></title>
      <description><![CDATA[Palo Alto disclosed CVE-2026-0265 on May 13, 2026, a cryptographic-signature-verification flaw in Cloud Authentication Service that bypasses PAN-OS authentication. Researchers claim live GlobalProtect portal bypasses. Full analysis.]]></description>
      <link>https://safeguard.sh/resources/blog/palo-alto-pan-os-cve-2026-0265-cas-auth-bypass-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/palo-alto-pan-os-cve-2026-0265-cas-auth-bypass-may-2026</guid>
      <pubDate>Fri, 15 May 2026 16:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[TanStack's Build Pipeline Got Hijacked and Still Signed Valid SLSA Provenance (May 2026)]]></title>
      <description><![CDATA[On May 11, 2026, attackers chained a pull_request_target abuse, cache poisoning, and OIDC token theft to publish 84 malicious @tanstack npm versions from TanStack's own trusted pipeline. It is the first npm compromise to carry valid SLSA provenance.]]></description>
      <link>https://safeguard.sh/resources/blog/tanstack-github-actions-pipeline-hijack-slsa-provenance-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tanstack-github-actions-pipeline-hijack-slsa-provenance-may-2026</guid>
      <pubDate>Fri, 15 May 2026 16:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Malware Code Explained: How Malicious Code Works and How to Detect It]]></title>
      <description><![CDATA[Malware code is any code written to run without the owner's informed consent and against their interest. Understanding its patterns is what makes it detectable.]]></description>
      <link>https://safeguard.sh/resources/blog/malware-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malware-code</guid>
      <pubDate>Fri, 15 May 2026 15:09:31 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What Goes Into a Product Security Engineer Job Description (and What It Pays)]]></title>
      <description><![CDATA[A realistic product security engineer job description: the actual responsibilities, the skills that matter, how the role differs from AppSec, and what the salary looks like.]]></description>
      <link>https://safeguard.sh/resources/blog/product-security-engineer-job-description</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/product-security-engineer-job-description</guid>
      <pubDate>Fri, 15 May 2026 13:49:04 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems and Bundler's Cooldown Discussion: Soak Windows as a First-Class Defender Policy]]></title>
      <description><![CDATA[After the 2025 supply-chain waves, the ruby/rubygems community opened Discussion #9113 to evaluate a built-in cooldown feature for bundle update. Here is the defender argument and how to implement it today.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-cooldown-bundler-defender-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-cooldown-bundler-defender-2026</guid>
      <pubDate>Fri, 15 May 2026 13:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Not Equal (!= vs !==): Why the Wrong One Is a Security Bug]]></title>
      <description><![CDATA[The JavaScript not equal operators != and !== look interchangeable but aren't. Loose comparison triggers type coercion that has caused real auth bypasses. Here's how to compare safely.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-not-equal</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-not-equal</guid>
      <pubDate>Fri, 15 May 2026 12:28:38 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Maven Central's January 2025 Sigstore Validation Launch: Bringing Java Provenance to the Central Publisher Portal]]></title>
      <description><![CDATA[Sonatype's Central Publisher Portal began validating Sigstore signature bundles in January 2025 alongside the existing PGP requirement. Here is the defender view of how the Java ecosystem's provenance story is finally catching up.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-central-sigstore-validation-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-central-sigstore-validation-2026</guid>
      <pubDate>Fri, 15 May 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[fork-ts-checker-webpack-plugin: A Security-Minded Guide]]></title>
      <description><![CDATA[The fork-ts-checker-webpack-plugin speeds up TypeScript builds by moving type checking off the main thread, and treating it as a build-time dependency has real security implications.]]></description>
      <link>https://safeguard.sh/resources/blog/fork-ts-checker-webpack-plugin</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fork-ts-checker-webpack-plugin</guid>
      <pubDate>Fri, 15 May 2026 11:08:11 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Keeping secrets out of agent context windows: brokers, scoped tokens, and redaction]]></title>
      <description><![CDATA[Every secret that touches an agent's context window is a secret the agent can leak. Just-in-time credential brokers, scoped-token issuance, and redaction layers keep the surface small without breaking the agent's ability to do real work.]]></description>
      <link>https://safeguard.sh/resources/blog/agent-secret-handling-patterns-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agent-secret-handling-patterns-2026</guid>
      <pubDate>Fri, 15 May 2026 10:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Medical Device Cybersecurity Under FDA 524B in 2026]]></title>
      <description><![CDATA[Three years into Section 524B, medical device manufacturers are operating under genuine premarket cybersecurity expectations. Here is what the 2026 submission and postmarket landscape actually requires.]]></description>
      <link>https://safeguard.sh/resources/blog/medical-device-fda-cybersecurity-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/medical-device-fda-cybersecurity-2026</guid>
      <pubDate>Fri, 15 May 2026 10:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Shifting security left: what it really means for teams]]></title>
      <description><![CDATA[Shift left security means catching vulnerabilities at commit time, not audit time. Here's what that requires in practice, with real CVEs and numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/shifting-security-left-what-it-really-means-for-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shifting-security-left-what-it-really-means-for-teams</guid>
      <pubDate>Fri, 15 May 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How SQL Injection Works and How to Prevent It]]></title>
      <description><![CDATA[How to perform SQL injection is really a question about how the attack class works so you can detect and stop it. A defensive walkthrough of the mechanism and the fixes that hold.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-perform-sql-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-perform-sql-injection</guid>
      <pubDate>Fri, 15 May 2026 09:47:44 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Higher education software supply chain risk in 2026]]></title>
      <description><![CDATA[SIS platforms, LMS deployments, research data pipelines, and the federated identity surface that makes higher education one of the most consequential supply chain environments to defend.]]></description>
      <link>https://safeguard.sh/resources/blog/higher-education-software-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/higher-education-software-supply-chain-2026</guid>
      <pubDate>Fri, 15 May 2026 09:30:00 GMT</pubDate>
      <category>Industry Insights</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Linux Foundation versus Apache Software Foundation: how governance shapes supply-chain risk]]></title>
      <description><![CDATA[Both foundations host critical software, but they organize it very differently. The Linux Foundation's project-by-project incubation model and the ASF's uniform graduation process produce different risk profiles for the consumers downstream.]]></description>
      <link>https://safeguard.sh/resources/blog/linux-foundation-vs-apache-governance-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/linux-foundation-vs-apache-governance-supply-chain-2026</guid>
      <pubDate>Fri, 15 May 2026 09:30:00 GMT</pubDate>
      <category>Industry Insights</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[SBOM and Compliance: Generating and Exporting Software Bi...]]></title>
      <description><![CDATA[Regulators now require SBOMs from federal vendors, medical device makers, and soon every EU digital product. Here's how SBOM generation tools actually compare on accuracy, format, and export.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-and-compliance-generating-and-exporting-software-bills-of-materials</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-and-compliance-generating-and-exporting-software-bills-of-materials</guid>
      <pubDate>Fri, 15 May 2026 09:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How to Run a ZAP Scan: OWASP ZAP for Practical Web App Testing]]></title>
      <description><![CDATA[A hands-on guide to running a ZAP scan against your own web app, from the passive baseline to a full active scan, and how to wire it into CI.]]></description>
      <link>https://safeguard.sh/resources/blog/zap-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zap-scan</guid>
      <pubDate>Fri, 15 May 2026 08:27:18 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Sandbox Python Code Safely: A Security Guide]]></title>
      <description><![CDATA[A security guide to running a Python sandbox: why language-level restriction fails, and the OS and runtime isolation that actually contains untrusted code.]]></description>
      <link>https://safeguard.sh/resources/blog/python-sandbox</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-sandbox</guid>
      <pubDate>Fri, 15 May 2026 07:06:51 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Open Source License Compliance: Automating License Risk R...]]></title>
      <description><![CDATA[Manual license audits miss GPL contamination and copyleft traps. Here's how automated license risk reports work, and how Safeguard stacks up against Endor Labs.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-license-compliance-automating-license-risk-reports</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-license-compliance-automating-license-risk-reports</guid>
      <pubDate>Fri, 15 May 2026 06:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[OPA Policy Language: A Practical Guide to Rego]]></title>
      <description><![CDATA[The OPA policy language is Rego, a declarative language for writing authorization and admission-control rules that live outside your application code. Here's how it works and how to keep it secure.]]></description>
      <link>https://safeguard.sh/resources/blog/opa-policy-language</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/opa-policy-language</guid>
      <pubDate>Fri, 15 May 2026 05:46:24 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-3918: Prototype Pollution in json-schema Explained]]></title>
      <description><![CDATA[CVE-2021-3918 is a prototype pollution vulnerability in the json-schema npm package that can let crafted input tamper with JavaScript object prototypes. Here is who is affected and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-3918</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-3918</guid>
      <pubDate>Fri, 15 May 2026 04:25:57 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[prism-react-renderer: Safe Syntax Highlighting in React]]></title>
      <description><![CDATA[prism-react-renderer gives you tokenized syntax highlighting in React without dangerouslySetInnerHTML. Here is how it works, why that matters for XSS, and how to keep the dependency healthy.]]></description>
      <link>https://safeguard.sh/resources/blog/prism-react-renderer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prism-react-renderer</guid>
      <pubDate>Fri, 15 May 2026 03:05:31 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Cyber Resilience Act (CRA) Compliance for Software Vendors]]></title>
      <description><![CDATA[CRA reporting duties start Sept 2026; fines reach 2.5% of global turnover. What software vendors must do for SBOMs, vulnerability reporting, and audits.]]></description>
      <link>https://safeguard.sh/resources/blog/cyber-resilience-act-cra-compliance-for-software-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyber-resilience-act-cra-compliance-for-software-vendors</guid>
      <pubDate>Fri, 15 May 2026 03:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Software Licenses: A Security and Compliance Guide]]></title>
      <description><![CDATA[Open source software licenses decide what you can legally do with a dependency. Getting them wrong is a compliance risk that sits right next to your security risk.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-software-licenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-software-licenses</guid>
      <pubDate>Fri, 15 May 2026 01:45:04 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[NGINX Ingress TLS: How to Terminate HTTPS Securely on Kubernetes]]></title>
      <description><![CDATA[Configuring NGINX Ingress TLS means wiring up certificates, secrets, and protocol settings so traffic into your cluster is encrypted and hard to downgrade. Here is the secure setup.]]></description>
      <link>https://safeguard.sh/resources/blog/nginx-ingress-tls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nginx-ingress-tls</guid>
      <pubDate>Fri, 15 May 2026 00:24:37 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP for AppSec Tools: What It Means for Government So...]]></title>
      <description><![CDATA[FedRAMP 20x now demands machine-readable SBOM and vulnerability evidence, not static reports. Here's what changed, what it costs, and where Endor Labs stands.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-for-appsec-tools-what-it-means-for-government-software-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-for-appsec-tools-what-it-means-for-government-software-vendors</guid>
      <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[EchoLeak (CVE-2025-32711): The First Zero-Click LLM Exfiltration in Production]]></title>
      <description><![CDATA[Aim Security's CVE-2025-32711 exfiltrated Microsoft 365 Copilot data via a single crafted email. The XPIA classifier failed, CSP let attackers through, and CVSS 9.3 followed.]]></description>
      <link>https://safeguard.sh/resources/blog/echoleak-cve-2025-32711-copilot-zero-click</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/echoleak-cve-2025-32711-copilot-zero-click</guid>
      <pubDate>Thu, 14 May 2026 23:04:11 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Hritik Kumar Sharma)</author>
    </item>
    <item>
      <title><![CDATA[PHP Code Analysis: Finding Security Bugs in PHP]]></title>
      <description><![CDATA[How PHP code analysis works, which static and dynamic tools to use, and the PHP-specific vulnerability patterns worth hunting for in your codebase.]]></description>
      <link>https://safeguard.sh/resources/blog/php-code-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-code-analysis</guid>
      <pubDate>Thu, 14 May 2026 21:43:44 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[nyc on npm: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[nyc is the Istanbul command-line coverage tool for Node.js. Here is its security profile and how to run it without leaking source or slowing your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/nyc-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nyc-npm</guid>
      <pubDate>Thu, 14 May 2026 20:23:17 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[MAST Security Testing: How Mobile App Security Testing Works]]></title>
      <description><![CDATA[MAST security testing combines static, dynamic, and interactive analysis to find flaws in mobile apps before attackers do. Here's how each technique fits together.]]></description>
      <link>https://safeguard.sh/resources/blog/mast-security-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mast-security-testing</guid>
      <pubDate>Thu, 14 May 2026 19:02:51 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Types of Software Licensing Explained for Security and Compliance]]></title>
      <description><![CDATA[Understanding the types of software licensing keeps a copyleft obligation or a proprietary term from surprising you at audit time. Here is a practical map of the licensing types that matter.]]></description>
      <link>https://safeguard.sh/resources/blog/types-of-software-licensing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/types-of-software-licensing</guid>
      <pubDate>Thu, 14 May 2026 17:42:24 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[System.IdentityModel.Tokens.Jwt: A Security Guide for .NET JWT Handling]]></title>
      <description><![CDATA[System.IdentityModel.Tokens.Jwt is the standard .NET library for JSON Web Tokens, but a DoS CVE and a few validation defaults decide whether your token handling is actually safe.]]></description>
      <link>https://safeguard.sh/resources/blog/system-identitymodel-tokens-jwt</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/system-identitymodel-tokens-jwt</guid>
      <pubDate>Thu, 14 May 2026 16:21:57 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-41089: The Unauthenticated Netlogon RCE That Owns Your Domain Controller]]></title>
      <description><![CDATA[CVE-2026-41089 is a CVSS 9.8 unauthenticated remote code execution flaw in Windows Netlogon: an integer overflow in MS-NRPC handshake parsing leads to a stack overflow on domain controllers, with no credentials or user interaction required.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2026-41089-netlogon-rce-domain-controller-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2026-41089-netlogon-rce-domain-controller-may-2026</guid>
      <pubDate>Thu, 14 May 2026 16:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Nitrogen Ransomware Hits Foxconn: 8TB Claim and the Manufacturing Extortion Wave of May 2026]]></title>
      <description><![CDATA[Foxconn confirmed a cyberattack on its North American factories in May 2026 after the Nitrogen ransomware crew claimed 8TB and 11 million files. We break down the attack chain, the broken ESXi decryptor, and what manufacturers should do now.]]></description>
      <link>https://safeguard.sh/resources/blog/nitrogen-ransomware-foxconn-manufacturing-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nitrogen-ransomware-foxconn-manufacturing-may-2026</guid>
      <pubDate>Thu, 14 May 2026 16:00:00 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems Suspends New Signups After a 500-Package Malicious Flood (May 2026)]]></title>
      <description><![CDATA[On 12-13 May 2026, RubyGems was hit by a coordinated spam-publishing flood that pushed 500+ malicious packages from newly-registered bot accounts. The registry paused new signups and re-enabled them on 16 May after tightening rate limiting with Fastly.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-malicious-package-flood-signup-suspension-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-malicious-package-flood-signup-suspension-may-2026</guid>
      <pubDate>Thu, 14 May 2026 16:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SAP May 2026: Two CVSS 9.6 Bugs Put S/4HANA SQL and Commerce Cloud RCE in the Crosshairs]]></title>
      <description><![CDATA[SAP's May 2026 Patch Day fixed two critical CVSS 9.6 flaws: CVE-2026-34260, an authenticated SQL injection in S/4HANA Enterprise Search, and CVE-2026-34263, an unauthenticated configuration-upload-to-RCE in SAP Commerce Cloud. Both carry cross-scope impact.]]></description>
      <link>https://safeguard.sh/resources/blog/sap-s4hana-commerce-cve-2026-34260-34263-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sap-s4hana-commerce-cve-2026-34260-34263-may-2026</guid>
      <pubDate>Thu, 14 May 2026 16:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Threat Detection: What to Watch For and How]]></title>
      <description><![CDATA[A practical look at supply chain threat detection: the signals that reveal a compromised dependency, build system, or update channel, and how to catch them early.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-threat-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-threat-detection</guid>
      <pubDate>Thu, 14 May 2026 15:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Cloudflare Workers, KV, and Durable Objects: the supply chain view in 2026]]></title>
      <description><![CDATA[Worker bundle composition, wrangler publish trust, and the deploy-from-CI credential blast radius are the supply chain shape of Cloudflare in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/cloudflare-workers-kv-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloudflare-workers-kv-supply-chain-2026</guid>
      <pubDate>Thu, 14 May 2026 15:15:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[tinymce-angular Security: What to Know Before You Ship]]></title>
      <description><![CDATA[The tinymce-angular wrapper is thin, but it ships a full rich-text editor whose sanitization gaps have produced real XSS CVEs. Here is how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/tinymce-angular</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tinymce-angular</guid>
      <pubDate>Thu, 14 May 2026 15:01:31 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[RabbitMQ management plugin CVEs: brokers deserve database-grade SBOM scrutiny]]></title>
      <description><![CDATA[Authentication and plugin-loading risks in RabbitMQ's management plugin show why message brokers, which hold credentials and pass payloads, should be inventoried with the same rigor as databases.]]></description>
      <link>https://safeguard.sh/resources/blog/rabbitmq-management-cve-2025-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rabbitmq-management-cve-2025-supply-chain</guid>
      <pubDate>Thu, 14 May 2026 14:30:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Bridgecrew vs tfsec: choosing a Terraform IaC scanner in 2026]]></title>
      <description><![CDATA[How Bridgecrew (Prisma Cloud Code Security) and tfsec compare on policy coverage, custom rule extensibility, drift detection, and the operational fit for IaC programs.]]></description>
      <link>https://safeguard.sh/resources/blog/bridgecrew-vs-tfsec-iac-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bridgecrew-vs-tfsec-iac-comparison-2026</guid>
      <pubDate>Thu, 14 May 2026 13:45:00 GMT</pubDate>
      <category>Vendor Comparison</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[npm package signature verification: the 2026 rollout state]]></title>
      <description><![CDATA[Every package on npm is signed by the registry, but the actual posture of install-time signature verification across real-world tooling is patchier than the headline suggests. This is where npm audit signatures and downstream verifiers stand in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-package-signature-verification-rollout-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-package-signature-verification-rollout-2026</guid>
      <pubDate>Thu, 14 May 2026 13:45:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[NY DFS 23 NYCRR 500 amendments and third-party software risk in 2026]]></title>
      <description><![CDATA[The November 2023 amendments to NY DFS 23 NYCRR Part 500 tightened third-party service provider requirements and added new obligations around software supply chain risk. Covered entities are now in steady-state implementation.]]></description>
      <link>https://safeguard.sh/resources/blog/nydfs-23-nycrr-500-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nydfs-23-nycrr-500-supply-chain-2026</guid>
      <pubDate>Thu, 14 May 2026 13:45:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Software License: A Compliance and Security Guide]]></title>
      <description><![CDATA[An open source software license grants you rights to use code others wrote, with obligations attached. Here is how the types differ and how to stay compliant at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-software-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-software-license</guid>
      <pubDate>Thu, 14 May 2026 13:41:04 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[GNU AGPL v3 Explained: What Network Copyleft Means for You]]></title>
      <description><![CDATA[The GNU AGPL v3 closes the SaaS loophole that GPL leaves open. Here's what the network copyleft clause actually requires, and how to spot AGPL dependencies before they create an obligation.]]></description>
      <link>https://safeguard.sh/resources/blog/gnu-agpl-v3</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gnu-agpl-v3</guid>
      <pubDate>Thu, 14 May 2026 12:20:37 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A Defender's Template for Package Registry Incident Communications, Built from the 2025-2026 Response Postmortems]]></title>
      <description><![CDATA[The npm Shai-Hulud, PyPI credential-leak, and tj-actions response postmortems published through 2025-2026 reveal a common communication shape. Here is the template, the timing, and the policy that turns the template into a fast response.]]></description>
      <link>https://safeguard.sh/resources/blog/registry-incident-communication-template-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/registry-incident-communication-template-2026</guid>
      <pubDate>Thu, 14 May 2026 12:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What Platforms Are Using Cybersecurity AI in 2026?]]></title>
      <description><![CDATA[A grounded look at what platforms are using cybersecurity AI today — across SOC tooling, code scanning, and supply-chain security — and how to tell real capability from marketing.]]></description>
      <link>https://safeguard.sh/resources/blog/what-platforms-are-using-cybersecurity-ai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-platforms-are-using-cybersecurity-ai</guid>
      <pubDate>Thu, 14 May 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Git Branching Strategies With Security Gates]]></title>
      <description><![CDATA[Trunk-based, GitHub Flow, or GitFlow — your branching model decides where security checks can actually block bad code. Here is how to wire gates into each.]]></description>
      <link>https://safeguard.sh/resources/blog/git-branching-strategies-security-gates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-branching-strategies-security-gates</guid>
      <pubDate>Thu, 14 May 2026 11:00:10 GMT</pubDate>
      <category>Dev Practices</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA["Enterprise-Grade Security": What the Label Should Actually Mean]]></title>
      <description><![CDATA[Enterprise grade security is a marketing phrase until it's backed by specific controls — here's what to actually check before a vendor's claim earns the label.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-grade-security-what-the-label-should-mean</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-grade-security-what-the-label-should-mean</guid>
      <pubDate>Thu, 14 May 2026 11:00:00 GMT</pubDate>
      <category>Enterprise</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Netlify Build Plugins as arbitrary code execution at build time in 2026]]></title>
      <description><![CDATA[The @netlify/plugin-* ecosystem runs in your build with full filesystem and network access. Here is how to evaluate, allowlist, and gate it in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/netlify-build-plugin-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/netlify-build-plugin-supply-chain-2026</guid>
      <pubDate>Thu, 14 May 2026 10:45:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Claude Code Skills: A Security Guide to SKILL.md and Agent Extensions]]></title>
      <description><![CDATA[Claude Code skills package instructions and scripts an AI agent runs on your behalf. That power is also the risk. Here is how to vet and sandbox them.]]></description>
      <link>https://safeguard.sh/resources/blog/claude-code-skills</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/claude-code-skills</guid>
      <pubDate>Thu, 14 May 2026 10:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Choose a Software Supply Chain Security Solution in 2026]]></title>
      <description><![CDATA[A software supply chain security solution secures every component that flows into your builds, from open-source dependencies to CI pipelines and artifacts. Here is what one should actually do.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-solution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-solution</guid>
      <pubDate>Thu, 14 May 2026 10:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[EO 14028 producer self-attestation: where the CISA Form sits in 2026]]></title>
      <description><![CDATA[The CISA Secure Software Development Attestation Form went live in March 2024. Two years and several revisions later, here is what producers actually have to attest, and where the common gotchas are.]]></description>
      <link>https://safeguard.sh/resources/blog/eo-14028-self-attestation-2026-status</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eo-14028-self-attestation-2026-status</guid>
      <pubDate>Thu, 14 May 2026 10:15:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Nonprofit software supply chain risk in 2026]]></title>
      <description><![CDATA[Donor CRMs, grant management platforms, and what the 2020 Blackbaud ransomware incident still teaches the nonprofit sector about resource-constrained software supply chain reality.]]></description>
      <link>https://safeguard.sh/resources/blog/nonprofit-software-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nonprofit-software-supply-chain-2026</guid>
      <pubDate>Thu, 14 May 2026 10:00:00 GMT</pubDate>
      <category>Industry Insights</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[A practical framework for assessing single-maintainer project risk]]></title>
      <description><![CDATA[Truck factor is the headline metric, but it is not enough. Here is a working framework for evaluating single-maintainer projects in your dependency tree without panicking or being naive.]]></description>
      <link>https://safeguard.sh/resources/blog/single-maintainer-project-risk-framework-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/single-maintainer-project-risk-framework-2026</guid>
      <pubDate>Thu, 14 May 2026 10:00:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Squid proxy memory corruption CVEs: a supply chain perspective]]></title>
      <description><![CDATA[Squid's recurring memory-corruption CVEs in 2024 and 2025 are a reminder that transparent egress proxies sit on a critical path and rarely get the SBOM scrutiny their position deserves.]]></description>
      <link>https://safeguard.sh/resources/blog/squid-proxy-cve-2025-rce-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/squid-proxy-cve-2025-rce-supply-chain</guid>
      <pubDate>Thu, 14 May 2026 10:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[How to Learn Hacking: An Ethical Hacker's Roadmap]]></title>
      <description><![CDATA[A practical, legal path into offensive security — the fundamentals to build first, the labs to practice on, and how to turn curiosity into a defensible skill set.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-learn-hacking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-learn-hacking</guid>
      <pubDate>Thu, 14 May 2026 09:39:44 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Vulnerability Protection: How to Secure Your Dependencies]]></title>
      <description><![CDATA[Software supply chain vulnerability protection means finding and fixing risk in the code you didn't write. Here is how detection, prioritization, and policy fit together.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-vulnerability-protection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-vulnerability-protection</guid>
      <pubDate>Thu, 14 May 2026 09:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm Trusted Publishing walkthrough: retiring long-lived publish tokens]]></title>
      <description><![CDATA[npm Trusted Publishing replaces long-lived publish tokens with short-lived OIDC-issued credentials tied to a specific CI workflow. Here is the 2026 rollout state, what the migration actually looks like, and where the rough edges still are.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-trusted-publishing-walkthrough-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-trusted-publishing-walkthrough-2026</guid>
      <pubDate>Thu, 14 May 2026 09:15:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Network egress controls for autonomous agent runtimes]]></title>
      <description><![CDATA[Autonomous agents need network access to do useful work, and that access is exactly what attackers exploit when they trick an agent into exfiltrating data. Here is how to design egress controls that hold up under adversarial pressure.]]></description>
      <link>https://safeguard.sh/resources/blog/agent-runtime-egress-controls-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agent-runtime-egress-controls-2026</guid>
      <pubDate>Thu, 14 May 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[ISO 42001 and AI Management Systems for Security Teams]]></title>
      <description><![CDATA[ISO 42001 makes AI governance auditable and certifiable. Here's what security teams need to build an AIMS, where Endor Labs' AI code-risk scoring falls short, and how Safeguard closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-42001-and-ai-management-systems-for-security-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-42001-and-ai-management-systems-for-security-teams</guid>
      <pubDate>Thu, 14 May 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Prompt Injection Techniques and the Defenses That Actually Work]]></title>
      <description><![CDATA[Prompt injection techniques range from direct override attempts to indirect payloads hidden in retrieved documents; here's what actually stops them.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-techniques-and-defenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-techniques-and-defenses</guid>
      <pubDate>Thu, 14 May 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Code vs Semgrep: comparing SAST philosophies in 2026]]></title>
      <description><![CDATA[How Snyk Code's closed-source AI engine and Semgrep's open-rule transparency model compare on detection, rule customization, and enterprise integration.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-code-vs-semgrep-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-code-vs-semgrep-2026</guid>
      <pubDate>Thu, 14 May 2026 09:00:00 GMT</pubDate>
      <category>Vendor Comparison</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[CNAPP Security: What It Actually Covers]]></title>
      <description><![CDATA[CNAPP bundles CSPM, CWPP, and vulnerability scanning under one label, but the exact scope varies widely by vendor — here's what a genuine CNAPP platform actually needs to cover.]]></description>
      <link>https://safeguard.sh/resources/blog/cnapp-security-what-it-actually-covers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cnapp-security-what-it-actually-covers</guid>
      <pubDate>Thu, 14 May 2026 08:50:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[DAST vs Penetration Testing: Which One Does Your App Actually Need?]]></title>
      <description><![CDATA[DAST vs penetration testing comes down to automation versus human creativity. Here is how they differ, where SAST fits, and why mature teams run all three.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-vs-penetration-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-vs-penetration-testing</guid>
      <pubDate>Thu, 14 May 2026 08:19:17 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Security Compliance Standards: A Practical Guide to the Frameworks That Matter]]></title>
      <description><![CDATA[Cloud security compliance standards can feel like alphabet soup. This guide maps SOC 2, ISO 27001, PCI DSS, and more to what you actually have to do.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-security-compliance-standards</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-security-compliance-standards</guid>
      <pubDate>Thu, 14 May 2026 06:58:50 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[PCI DSS Requirements for Application Security Testing]]></title>
      <description><![CDATA[PCI DSS 4.0's March 2025 deadline made SBOMs and 30-day patch SLAs mandatory. Here's what Requirements 6.3.2, 6.4.2, and 11.3 actually demand, and where Endor Labs leaves compliance gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/pci-dss-requirements-for-application-security-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pci-dss-requirements-for-application-security-testing</guid>
      <pubDate>Thu, 14 May 2026 06:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[node-jose Security: Using Cisco's JOSE Library Safely]]></title>
      <description><![CDATA[node-jose is Cisco's JavaScript implementation of the JOSE standards for signing and encrypting tokens. Here is the CVE-2017-16007 invalid-curve flaw and how to use JWE and JWS defensively.]]></description>
      <link>https://safeguard.sh/resources/blog/node-jose</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-jose</guid>
      <pubDate>Thu, 14 May 2026 05:38:24 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Dependency Scanning: How It Works, Its Limits, and Alternatives]]></title>
      <description><![CDATA[A fair look at Snyk dependency scanning: what it does well, how its test-based pricing works, where teams hit limits, and how to decide if it fits your workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-dependency-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-dependency-scanning</guid>
      <pubDate>Thu, 14 May 2026 04:17:57 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[AI Coding Agent Governance: Securing Copilot, Cursor, and...]]></title>
      <description><![CDATA[How to govern Copilot, Cursor, and Claude Code with provenance tracking and permission scoping — beyond after-the-fact SCA scanning of agent-written code.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-coding-agent-governance-securing-copilot-cursor-and-claude-code-usage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-coding-agent-governance-securing-copilot-cursor-and-claude-code-usage</guid>
      <pubDate>Thu, 14 May 2026 03:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Snyk the Company: Who They Are, What They Build, and How to Weigh Them]]></title>
      <description><![CDATA[Snyk is a developer-security company founded in 2015, best known for open-source dependency scanning. Here is an honest look at the company, its products, and how to evaluate whether it fits your stack.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-company</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-company</guid>
      <pubDate>Thu, 14 May 2026 02:57:30 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Security Issues You Should Actually Worry About]]></title>
      <description><![CDATA[The Kubernetes security issues that cause real breaches are rarely exotic zero-days. They are misconfigured RBAC, exposed dashboards, over-privileged pods, and unscanned images. Here is where to look first.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-security-issues</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-security-issues</guid>
      <pubDate>Thu, 14 May 2026 01:37:04 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Vulnerabilities: What They Are and How to Fix Them]]></title>
      <description><![CDATA[Application security vulnerabilities are the flaws in your code, dependencies, and configuration that attackers exploit. This guide covers the common classes and how to find and fix them.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-vulnerabilities</guid>
      <pubDate>Thu, 14 May 2026 00:16:37 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Securing MCP Servers and Agent Skills in the Enterprise]]></title>
      <description><![CDATA[MCP servers and agent skills give AI agents new power—and new attack surface. Here's how tool poisoning and rug-pull attacks work, and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-mcp-servers-and-agent-skills-in-the-enterprise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-mcp-servers-and-agent-skills-in-the-enterprise</guid>
      <pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Node.js License Compliance: Auditing Your Dependencies]]></title>
      <description><![CDATA[Node.js itself is MIT-licensed, but the real license work is in your node_modules tree. Here is how to audit npm dependency licenses and enforce a compliance policy.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-license</guid>
      <pubDate>Wed, 13 May 2026 22:56:10 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Spring Framework RCE Vulnerabilities: A History]]></title>
      <description><![CDATA[From Spring4Shell to older data binding flaws, Spring framework RCE bugs keep resurfacing in the same handful of places — data binding, expression evaluation, and class loading.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-framework-rce-vulnerabilities-a-history</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-framework-rce-vulnerabilities-a-history</guid>
      <pubDate>Wed, 13 May 2026 21:35:43 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CTF Cyber Security Competitions Worth Trying]]></title>
      <description><![CDATA[A practical rundown of CTF cyber security formats and specific competitions worth an engineer's time, and how the skills transfer directly back to application security work.]]></description>
      <link>https://safeguard.sh/resources/blog/ctf-cyber-security-competitions-worth-trying</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ctf-cyber-security-competitions-worth-trying</guid>
      <pubDate>Wed, 13 May 2026 20:15:17 GMT</pubDate>
      <category>Culture</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Writing a Deprecation Policy for Third-Party Components]]></title>
      <description><![CDATA[End-of-life libraries leave codebases only when something forces them out. A written component deprecation policy with triggers, timelines, and CI gates does the forcing on your schedule, not an attacker's.]]></description>
      <link>https://safeguard.sh/resources/blog/deprecation-policy-third-party-components</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/deprecation-policy-third-party-components</guid>
      <pubDate>Wed, 13 May 2026 18:54:50 GMT</pubDate>
      <category>Governance</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Code Scanning Tools: SAST, Secrets, and Linters Compared]]></title>
      <description><![CDATA[SAST tools, secret scanners, and linters all read your source code but catch entirely different classes of problems — here's how to tell them apart and stack them correctly.]]></description>
      <link>https://safeguard.sh/resources/blog/code-scanning-tools-sast-secrets-and-linters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-scanning-tools-sast-secrets-and-linters</guid>
      <pubDate>Wed, 13 May 2026 17:34:23 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Application Vulnerability Assessment: Scope, Method, and Reporting]]></title>
      <description><![CDATA[Most assessment reports die unread because scope was fuzzy and findings were not verified. A working method for assessments that end in shipped fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/application-vulnerability-assessment-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-vulnerability-assessment-guide</guid>
      <pubDate>Wed, 13 May 2026 16:13:57 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Nation-State Actors Operationalize AI: Inside GTIG's May 2026 Threat Tracker]]></title>
      <description><![CDATA[Google's Threat Intelligence Group documented China, North Korea, Russia, and Iran moving AI from experiment to operations in May 2026 — AI-assisted vulnerability research, LLM-enabled malware, and obfuscated model-access infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/gtig-ai-threat-tracker-nation-state-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gtig-ai-threat-tracker-nation-state-may-2026</guid>
      <pubDate>Wed, 13 May 2026 16:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The 'Code of Conduct' Phishing Wave: AiTM Token Theft Hit 13,000 Orgs (May 2026)]]></title>
      <description><![CDATA[Microsoft detailed a polished phishing campaign that weaponized fake HR 'code of conduct' investigations to steal session tokens via adversary-in-the-middle proxies, bypassing MFA across 13,000+ organizations in 26 countries.]]></description>
      <link>https://safeguard.sh/resources/blog/microsoft-code-of-conduct-aitm-phishing-campaign-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microsoft-code-of-conduct-aitm-phishing-campaign-may-2026</guid>
      <pubDate>Wed, 13 May 2026 16:00:00 GMT</pubDate>
      <category>Social Engineering</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Microsoft May 2026 Patch Tuesday: No Zero-Days, but Two CVSS 9.8 Wormable RCEs]]></title>
      <description><![CDATA[Microsoft's May 2026 Patch Tuesday shipped without a single exploited zero-day for the first time since June 2024, but it still carried two unauthenticated CVSS 9.8 remote code execution bugs in core Windows services that every domain should treat as emergency patches.]]></description>
      <link>https://safeguard.sh/resources/blog/microsoft-patch-tuesday-may-2026-roundup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microsoft-patch-tuesday-may-2026-roundup</guid>
      <pubDate>Wed, 13 May 2026 16:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[TanStack and the Mini Shai-Hulud npm Worm (May 2026): Anatomy of a CI-Native Supply Chain Attack]]></title>
      <description><![CDATA[On 11-12 May 2026, the TeamPCP-linked Mini Shai-Hulud worm published 84 malicious artifacts across 42 TanStack npm packages in six minutes, then spread to 160+ packages by abusing GitHub Actions OIDC tokens and CI cache poisoning.]]></description>
      <link>https://safeguard.sh/resources/blog/tanstack-mini-shai-hulud-npm-worm-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tanstack-mini-shai-hulud-npm-worm-may-2026</guid>
      <pubDate>Wed, 13 May 2026 16:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[API Security Scanning: What Good Tools Actually Catch]]></title>
      <description><![CDATA[API security scanning explained in terms of the specific failure classes it catches, from broken object-level authorization to shadow endpoints, and why generic web scanners miss most of them.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-scanning-what-good-tools-catch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-scanning-what-good-tools-catch</guid>
      <pubDate>Wed, 13 May 2026 14:53:30 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Vercel Edge Functions supply chain risks in 2026]]></title>
      <description><![CDATA[Edge Functions, middleware, and Edge Config combine npm trust, build-step trust, and a secret surface that runs at every request. Here is the 2026 control set.]]></description>
      <link>https://safeguard.sh/resources/blog/vercel-edge-functions-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vercel-edge-functions-supply-chain-2026</guid>
      <pubDate>Wed, 13 May 2026 14:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Detecting shadow MCP servers in developer environments]]></title>
      <description><![CDATA[Unauthorized MCP servers running on developer laptops are the agent-era equivalent of shadow IT. Here is how to inventory them, see them at runtime, and bring them under policy.]]></description>
      <link>https://safeguard.sh/resources/blog/agent-shadow-mcp-server-detection-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agent-shadow-mcp-server-detection-2026</guid>
      <pubDate>Wed, 13 May 2026 13:45:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Testing Tools: SAST, DAST, IAST, and SCA Compared]]></title>
      <description><![CDATA[Four scanner families see four different slices of your risk. What SAST, DAST, IAST, and SCA each catch and miss, and how to sequence them in CI without drowning developers.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-testing-tools-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-testing-tools-compared</guid>
      <pubDate>Wed, 13 May 2026 13:33:03 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[AgTech and food-tech software supply chain risk in 2026]]></title>
      <description><![CDATA[Precision agriculture platforms, FSMA 204 traceability databases, and the John Deere right-to-repair debate as a software supply chain question rather than a property rights one.]]></description>
      <link>https://safeguard.sh/resources/blog/agriculture-food-tech-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agriculture-food-tech-supply-chain-2026</guid>
      <pubDate>Wed, 13 May 2026 13:30:00 GMT</pubDate>
      <category>Industry Insights</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[DeepSource vs CodeQL: comparing SAST platforms for modern engineering teams in 2026]]></title>
      <description><![CDATA[How DeepSource and CodeQL compare on rule depth, autofix capability, language coverage, and the workflow that drives adoption inside engineering organizations.]]></description>
      <link>https://safeguard.sh/resources/blog/deepsource-vs-codeql-sast-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/deepsource-vs-codeql-sast-2026</guid>
      <pubDate>Wed, 13 May 2026 13:30:00 GMT</pubDate>
      <category>Vendor Comparison</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Anthropic Claude vs OpenAI GPT: Enterprise Security in 2026]]></title>
      <description><![CDATA[A pragmatic comparison of Claude and GPT for enterprise deployments in 2026, focused on the security and governance controls that matter to a buyer.]]></description>
      <link>https://safeguard.sh/resources/blog/anthropic-claude-vs-openai-gpt-enterprise-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anthropic-claude-vs-openai-gpt-enterprise-security-2026</guid>
      <pubDate>Wed, 13 May 2026 13:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[DevOps Security Best Practices: Shifting Left Without Slowing Down]]></title>
      <description><![CDATA[Shift left fails when it means shifting friction left. Here are the DevOps security best practices that catch issues early while keeping pipelines fast enough that engineers leave the gates on.]]></description>
      <link>https://safeguard.sh/resources/blog/devops-security-best-practices-shift-left</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devops-security-best-practices-shift-left</guid>
      <pubDate>Wed, 13 May 2026 12:12:37 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[NIST SP 800-218A: Operationalizing AI Secure Development in 2026]]></title>
      <description><![CDATA[NIST SP 800-218A turned the SSDF into an AI community profile in July 2024. Eighteen months later, what does real adoption look like for AI software teams?]]></description>
      <link>https://safeguard.sh/resources/blog/nist-sp-800-218a-ai-development-adoption-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-sp-800-218a-ai-development-adoption-2026</guid>
      <pubDate>Wed, 13 May 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[State Privacy Laws 2025-2026: The Security Mandates Hidden Inside]]></title>
      <description><![CDATA[Twenty state comprehensive privacy laws are in force by 2026. Most carry baseline security mandates that security teams - not just privacy lawyers - must operationalize.]]></description>
      <link>https://safeguard.sh/resources/blog/state-privacy-law-2025-2026-security-mandates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-privacy-law-2025-2026-security-mandates</guid>
      <pubDate>Wed, 13 May 2026 12:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Apache Tomcat CVE-2025-24813: a deserialization deep dive]]></title>
      <description><![CDATA[Tomcat's partial-PUT deserialization RCE turned a session persistence feature into a remote code execution path, and the pattern is one Java middleware keeps repeating.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-tomcat-cve-2025-24813-deserialization-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-tomcat-cve-2025-24813-deserialization-deep-dive</guid>
      <pubDate>Wed, 13 May 2026 11:45:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Maintainer burnout is a supply-chain risk: lessons from xz-utils]]></title>
      <description><![CDATA[The xz-utils backdoor was made possible because a single exhausted maintainer accepted help from a patient and well-resourced stranger. Sustaining critical maintainers is now a security problem, not just a moral one.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-maintainer-burnout-supply-chain-risk-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-maintainer-burnout-supply-chain-risk-2026</guid>
      <pubDate>Wed, 13 May 2026 11:45:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[DHS/CISA Binding Operational Directives and supply chain cascade effects in 2026]]></title>
      <description><![CDATA[BOD 22-01 (KEV) and BOD 23-02 (external attack surface) apply directly to federal civilian agencies, but their downstream contractual cascade into the software supply chain is now the more consequential effect.]]></description>
      <link>https://safeguard.sh/resources/blog/dhs-cisa-bod-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dhs-cisa-bod-supply-chain-2026</guid>
      <pubDate>Wed, 13 May 2026 11:30:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[npm provenance attestations walkthrough for 2026]]></title>
      <description><![CDATA[npm provenance ties a published package to the specific GitHub Actions run that built it, signed through sigstore. Here is how to enable it for a publisher, verify it on the install side, and enforce it in CI without breaking your release process.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-provenance-attestations-walkthrough-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-provenance-attestations-walkthrough-2026</guid>
      <pubDate>Wed, 13 May 2026 11:30:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[DAST Tools for DevSecOps Teams]]></title>
      <description><![CDATA[The best DAST tools for DevSecOps teams run inside CI/CD rather than as a separate pre-launch step, and Gartner's own analysis of the DAST market backs that shift as the defining trend.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-tools-for-devsecops-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-tools-for-devsecops-teams</guid>
      <pubDate>Wed, 13 May 2026 10:52:10 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Trivy Operator v0.30: Kubernetes Field Review]]></title>
      <description><![CDATA[Trivy Operator hit v0.30 in early 2026 and the underlying Trivy v0.70 engine landed in April. We benchmarked the combo on a 60-node multi-tenant cluster.]]></description>
      <link>https://safeguard.sh/resources/blog/trivy-operator-v0-30-2026-kubernetes-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trivy-operator-v0-30-2026-kubernetes-review</guid>
      <pubDate>Wed, 13 May 2026 10:30:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Defending LLM agents against confused-deputy attacks on their tool privileges]]></title>
      <description><![CDATA[An LLM agent with tools is a deputy that holds privileges its users do not. Attackers exploit that gap by tricking the agent into using those privileges on their behalf — here is how to design defenses that hold up.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-agent-tool-confused-deputy-defense-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-agent-tool-confused-deputy-defense-2026</guid>
      <pubDate>Wed, 13 May 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[State and local government software supply chain in 2026]]></title>
      <description><![CDATA[StateRAMP, election infrastructure, court case management, and the budget-versus-risk gap that defines software supply chain security for state and local agencies.]]></description>
      <link>https://safeguard.sh/resources/blog/state-local-government-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-local-government-supply-chain-2026</guid>
      <pubDate>Wed, 13 May 2026 09:45:00 GMT</pubDate>
      <category>Industry Insights</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[What SCA Means in Security (Software Composition Analysis)]]></title>
      <description><![CDATA[The SCA security meaning explained: what software composition analysis is, how it differs from SAST and DAST, and why it matters for the open source in your code.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-security-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-security-meaning</guid>
      <pubDate>Wed, 13 May 2026 09:31:43 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[GCP Cloud Functions and Cloud Run buildpacks: the third-party supply chain in 2026]]></title>
      <description><![CDATA[Buildpack dependency surface plus Cloud Build's default service account creates a blast radius most teams underestimate. Here is what to harden in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-cloud-functions-third-party-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-cloud-functions-third-party-supply-chain-2026</guid>
      <pubDate>Wed, 13 May 2026 09:30:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Semgrep Cloud vs GitHub CodeQL: comparing SAST engines in 2026]]></title>
      <description><![CDATA[How Semgrep Cloud and CodeQL compare on rule authoring, language coverage, performance, and pull request ergonomics for static analysis programs.]]></description>
      <link>https://safeguard.sh/resources/blog/semgrep-cloud-vs-codeql-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/semgrep-cloud-vs-codeql-comparison-2026</guid>
      <pubDate>Wed, 13 May 2026 09:15:00 GMT</pubDate>
      <category>Vendor Comparison</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Linguistic Lumberjack: lessons from Fluent Bit CVE-2024-4323]]></title>
      <description><![CDATA[Tenable's Linguistic Lumberjack flaw in Fluent Bit's monitoring API was a heap corruption with a wide blast radius because observability sidecars are everywhere and rarely inventoried.]]></description>
      <link>https://safeguard.sh/resources/blog/fluent-bit-linguistic-lumberjack-cve-2024-4323-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fluent-bit-linguistic-lumberjack-cve-2024-4323-lessons</guid>
      <pubDate>Wed, 13 May 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Flux CD vs Argo CD: Security Comparison for 2026]]></title>
      <description><![CDATA[A security-focused comparison of Flux 2.5 and Argo CD 3.1: trust models, multi-tenancy, secret handling, signature verification, and the operational differences.]]></description>
      <link>https://safeguard.sh/resources/blog/flux-cd-vs-argocd-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/flux-cd-vs-argocd-security-2026</guid>
      <pubDate>Wed, 13 May 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[FTC Section 5 and software security: how 'unfair practices' became a supply chain doctrine]]></title>
      <description><![CDATA[The Federal Trade Commission has spent the last several years building a software-security enforcement theory under Section 5. Drizly, SolarWinds, and Henry Schein each contributed pieces of the framework.]]></description>
      <link>https://safeguard.sh/resources/blog/ftc-section-5-software-security-enforcement-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ftc-section-5-software-security-enforcement-2026</guid>
      <pubDate>Wed, 13 May 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[npm audit isn't enough: what it misses]]></title>
      <description><![CDATA[npm audit catches known CVEs and stops there. It misses malicious packages, install scripts, and typosquats -- the threats actually landing in npm today.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-audit-isnt-enough-what-it-misses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-audit-isnt-enough-what-it-misses</guid>
      <pubDate>Wed, 13 May 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[The bootloader supply chain: what an OS vendor controls versus inherits]]></title>
      <description><![CDATA[Between firmware and the kernel sits a thin layer of code that almost no one audits and almost everyone trusts. Understanding the supply chain behind shim, GRUB, and u-boot is the difference between owning your boot path and renting it.]]></description>
      <link>https://safeguard.sh/resources/blog/rom-bootloader-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rom-bootloader-supply-chain-2026</guid>
      <pubDate>Wed, 13 May 2026 09:00:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[VS Code marketplace incident postmortem: what 2023-2024 actually taught us]]></title>
      <description><![CDATA[Between 2023 and 2024 the VS Code Marketplace saw a string of typosquat, hijack, and impersonation incidents that shaped Microsoft's eventual hardening response. This is a composite postmortem of what happened, what changed, and what is still broken in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/vscode-marketplace-incident-postmortem-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vscode-marketplace-incident-postmortem-2024</guid>
      <pubDate>Wed, 13 May 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Dockerizing Node.js and PHP Apps: A Practical Guide]]></title>
      <description><![CDATA[Writing a node js dockerfile and learning how to dockerize php application deployments both hinge on the same handful of decisions — base image, layer order, and what you leave out of the final image.]]></description>
      <link>https://safeguard.sh/resources/blog/dockerizing-node-and-php-apps-a-practical-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dockerizing-node-and-php-apps-a-practical-guide</guid>
      <pubDate>Wed, 13 May 2026 08:11:17 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-42004: The jackson-databind DoS Explained]]></title>
      <description><![CDATA[CVE-2022-42004 is a denial-of-service flaw in jackson-databind where deeply nested arrays exhaust resources during deserialization. Here is who is affected and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-42004</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-42004</guid>
      <pubDate>Wed, 13 May 2026 06:50:50 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SAST vs DAST vs SCA vs IAST]]></title>
      <description><![CDATA[SAST, DAST, SCA, and IAST each test different risk. See how Safeguard's unified platform compares to Socket.dev's SCA-focused approach to supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-vs-dast-vs-sca-vs-iast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-vs-dast-vs-sca-vs-iast</guid>
      <pubDate>Wed, 13 May 2026 06:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[jest-junit: Secure CI Test Reporting for Jest]]></title>
      <description><![CDATA[jest-junit turns Jest test results into JUnit XML that CI systems can read. Here is how to configure it and keep the reporting pipeline free of security surprises.]]></description>
      <link>https://safeguard.sh/resources/blog/jest-junit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jest-junit</guid>
      <pubDate>Wed, 13 May 2026 05:30:23 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How to Vet a GitHub Action Before You Trust It with Secrets]]></title>
      <description><![CDATA[Third-party Actions run with your repo's token and secrets. A vetting routine: read the source at the pinned SHA, audit the bundled dist, scope permissions, and contain egress.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-vet-a-github-action-before-you-trust-it-with-secrets</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-vet-a-github-action-before-you-trust-it-with-secrets</guid>
      <pubDate>Wed, 13 May 2026 04:09:56 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Marcus Webb)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 compliance guide for engineering teams]]></title>
      <description><![CDATA[SOC 2 audits fail on missing evidence, not bad intentions. Here's what engineering teams must actually build, track, and prove — with real timelines and costs.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-compliance-guide-for-engineering-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-compliance-guide-for-engineering-teams</guid>
      <pubDate>Wed, 13 May 2026 04:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE vs CVSS vs EPSS vs SSVC scoring compared]]></title>
      <description><![CDATA[CVE tells you a flaw exists, CVSS rates severity, EPSS predicts exploitation, and SSVC drives decisions. Here's how Safeguard and Socket.dev use each differently.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-vs-cvss-vs-epss-vs-ssvc-scoring-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-vs-cvss-vs-epss-vs-ssvc-scoring-compared</guid>
      <pubDate>Wed, 13 May 2026 03:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[True Positive in Cyber Security: What It Means and Why It Matters]]></title>
      <description><![CDATA[A true positive is a real alert about a real threat. Understanding it alongside false positives, true negatives, and false negatives is how you judge whether a security tool is any good.]]></description>
      <link>https://safeguard.sh/resources/blog/true-positive-in-cyber-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/true-positive-in-cyber-security</guid>
      <pubDate>Wed, 13 May 2026 02:49:30 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes 1.33 Security Deep Dive]]></title>
      <description><![CDATA[Kubernetes 1.33 shipped with meaningful security changes: stronger admission controls, expanded structured authorization, and several deprecations that will affect production clusters.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-1-33-security-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-1-33-security-deep-dive</guid>
      <pubDate>Wed, 13 May 2026 01:29:03 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 compliance for software development teams]]></title>
      <description><![CDATA[ISO/IEC 27001:2022 audits now check 8 SDLC controls directly — SBOMs, vulnerability SLAs, and CI/CD evidence dev teams commonly get flagged on.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-compliance-for-software-development-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-compliance-for-software-development-teams</guid>
      <pubDate>Wed, 13 May 2026 01:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Mend Scan and How Does It Work?]]></title>
      <description><![CDATA[A Mend scan analyzes your open-source dependencies and code for known vulnerabilities and license risk. Here is what it covers and how to run one in CI.]]></description>
      <link>https://safeguard.sh/resources/blog/mend-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mend-scan</guid>
      <pubDate>Wed, 13 May 2026 00:08:36 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CI/CD pipeline dependency security integration coverage]]></title>
      <description><![CDATA[How does Safeguard's pipeline-native dependency security compare to Socket.dev's PR-comment model? A concrete look at coverage, enforcement, and deployment options.]]></description>
      <link>https://safeguard.sh/resources/blog/cicd-pipeline-dependency-security-integration-coverage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cicd-pipeline-dependency-security-integration-coverage</guid>
      <pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[dom-to-image-more: Using the DOM-to-Image Fork Safely]]></title>
      <description><![CDATA[dom-to-image-more turns a DOM node into a PNG, JPEG, or SVG in the browser. What the fork fixes, and the security considerations when rendering user content.]]></description>
      <link>https://safeguard.sh/resources/blog/dom-to-image-more</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dom-to-image-more</guid>
      <pubDate>Tue, 12 May 2026 22:48:10 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Vitest on npm: A Security Review Before You Add It]]></title>
      <description><![CDATA[Vitest is a fast Vite-native test runner, but its API and browser-mode servers have a real security footprint. Here is what to check before adding vitest from npm.]]></description>
      <link>https://safeguard.sh/resources/blog/vitest-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vitest-npm</guid>
      <pubDate>Tue, 12 May 2026 21:27:43 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to Build a Secure Python URL Validator (and Avoid SSRF)]]></title>
      <description><![CDATA[A Python URL validator has to do more than match a regex. Here is how to validate URLs safely, block SSRF, and pick between urllib, validators, and Pydantic.]]></description>
      <link>https://safeguard.sh/resources/blog/python-url-validator</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-url-validator</guid>
      <pubDate>Tue, 12 May 2026 20:07:16 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Check for npm Vulnerabilities (and Actually Fix Them)]]></title>
      <description><![CDATA[npm check vulnerabilities the right way: what npm audit tells you, where it misleads, and how to turn a wall of advisories into a short list of things worth fixing.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-check-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-check-vulnerabilities</guid>
      <pubDate>Tue, 12 May 2026 18:46:50 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Choose an Application Security Company]]></title>
      <description><![CDATA[What an application security company actually does, the categories of vendors, and the questions that separate real coverage from a dashboard full of noise.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-company</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-company</guid>
      <pubDate>Tue, 12 May 2026 17:26:23 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[EchoLeak (CVE-2025-32711): The First Zero-Click Production LLM Exfiltration]]></title>
      <description><![CDATA[A single crafted email could exfiltrate data from Microsoft 365 Copilot without a user click. We walk the attack chain, the patch, and the lessons for agent operators.]]></description>
      <link>https://safeguard.sh/resources/blog/echoleak-microsoft-copilot-cve-2025-32711</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/echoleak-microsoft-copilot-cve-2025-32711</guid>
      <pubDate>Tue, 12 May 2026 16:05:56 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Fake OpenAI 'privacy-filter' Model: How a Typosquat Hit #1 on Hugging Face in May 2026]]></title>
      <description><![CDATA[A repository named Open-OSS/privacy-filter impersonated OpenAI's release, copied its model card verbatim, and shipped a loader.py that pulled an infostealer. It reached #1 trending with ~244,000 downloads before removal.]]></description>
      <link>https://safeguard.sh/resources/blog/huggingface-fake-openai-privacy-filter-malware-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/huggingface-fake-openai-privacy-filter-malware-may-2026</guid>
      <pubDate>Tue, 12 May 2026 16:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Instructure Canvas Breach (May 2026): Up to 275M Records and a Quiet Settlement]]></title>
      <description><![CDATA[ShinyHunters claimed 3.65 TB and 275 million records from Instructure's Canvas LMS across ~9,000 schools. Instructure confirmed names, emails, student IDs, and user messages were taken, then reportedly paid to make it stop.]]></description>
      <link>https://safeguard.sh/resources/blog/instructure-canvas-data-breach-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/instructure-canvas-data-breach-may-2026</guid>
      <pubDate>Tue, 12 May 2026 16:00:00 GMT</pubDate>
      <category>Data Breach</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Odido Telecom Breach: 6.2M Dutch Customers, Salesforce, and No Compensation (May 2026)]]></title>
      <description><![CDATA[Odido, the Netherlands' largest mobile operator, exposed 6.2 million customers' data, including IBANs and ID details, via a vishing-driven Salesforce intrusion. In May 2026 the company ruled out compensation as mass claims mounted.]]></description>
      <link>https://safeguard.sh/resources/blog/odido-telecom-data-breach-shinyhunters-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/odido-telecom-data-breach-shinyhunters-may-2026</guid>
      <pubDate>Tue, 12 May 2026 16:00:00 GMT</pubDate>
      <category>Data Breach</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Škoda Auto Online Shop Breach (12 May 2026): An E-Commerce Software Flaw and the Credential-Reuse Tail]]></title>
      <description><![CDATA[Škoda Auto disclosed on 12 May 2026 that attackers exploited a vulnerability in its German online shop to steal customer names, contact details, order data, and login credentials. The card data was safe; the credentials are the part that keeps paying out.]]></description>
      <link>https://safeguard.sh/resources/blog/skoda-auto-online-shop-data-breach-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/skoda-auto-online-shop-data-breach-may-2026</guid>
      <pubDate>Tue, 12 May 2026 16:00:00 GMT</pubDate>
      <category>Data Breach</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Vercel Breach: A Forgotten OAuth Grant Became a SaaS Supply-Chain Pivot (May 2026)]]></title>
      <description><![CDATA[An infostealer infection at AI startup Context.ai let attackers reuse a Vercel employee's months-old Google Workspace OAuth grant to bypass MFA and exfiltrate customer environment variables. Disclosed April 2026, the fallout deepened through May.]]></description>
      <link>https://safeguard.sh/resources/blog/vercel-context-ai-oauth-supply-chain-breach-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vercel-context-ai-oauth-supply-chain-breach-may-2026</guid>
      <pubDate>Tue, 12 May 2026 16:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The OWASP API Security Top 10: Each Risk Explained]]></title>
      <description><![CDATA[The OWASP API Top 10 is a ranked list of the most common API-specific vulnerability classes, from broken object level authorization to unsafe consumption of third-party APIs.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-api-security-top-10-the-list-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-api-security-top-10-the-list-explained</guid>
      <pubDate>Tue, 12 May 2026 14:45:30 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Azure Functions extensions as a supply chain entry point in 2026]]></title>
      <description><![CDATA[Binding extensions and isolated worker SDK packages run with the function's managed identity. Here is how to evaluate and gate them in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-functions-extension-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-functions-extension-supply-chain-2026</guid>
      <pubDate>Tue, 12 May 2026 13:45:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Which Ethical Hacking Tools Should Your Security Team Actually Use?]]></title>
      <description><![CDATA[Ethical hacking tools help defenders find weaknesses before attackers do. Here is a practitioner's map of the categories, the well-known tools in each, and how to use them responsibly.]]></description>
      <link>https://safeguard.sh/resources/blog/ethical-hacking-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ethical-hacking-tools</guid>
      <pubDate>Tue, 12 May 2026 13:25:03 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[The CUPS RCE chain: a postmortem of CVE-2024-47176 and friends]]></title>
      <description><![CDATA[The September 2024 CUPS chain (CVE-2024-47176, 47076, 47175, 47177) turned a printer browsing daemon into a remote code execution vector and exposed how badly long-tail Linux daemons get patched.]]></description>
      <link>https://safeguard.sh/resources/blog/cups-cve-2024-47176-rce-postmortem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cups-cve-2024-47176-rce-postmortem</guid>
      <pubDate>Tue, 12 May 2026 13:15:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[PropTech software supply chain risk and wire fraud in 2026]]></title>
      <description><![CDATA[MLS integrations, lender APIs, escrow platforms, and the long tail of PropTech vendors all feed into one of the most consequential downstream consequences in any industry: wire fraud at closing.]]></description>
      <link>https://safeguard.sh/resources/blog/real-estate-proptech-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/real-estate-proptech-supply-chain-2026</guid>
      <pubDate>Tue, 12 May 2026 13:15:00 GMT</pubDate>
      <category>Industry Insights</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[nimbus-jose-jwt: JWT Handling in Java Done Right]]></title>
      <description><![CDATA[com.nimbusds:nimbus-jose-jwt is the JVM's workhorse JOSE library. Here is how to configure it so algorithm confusion, weak validation, and its one recent CVE never reach production.]]></description>
      <link>https://safeguard.sh/resources/blog/nimbus-jose-jwt-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nimbus-jose-jwt-security-guide</guid>
      <pubDate>Tue, 12 May 2026 12:04:36 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[FTC Data Broker Rule Supply Chain Implications in 2026]]></title>
      <description><![CDATA[The FTC finalized substantive data broker rules in late 2025 and enforcement is ramping in 2026. The software supply chain implications are broader than they first appear.]]></description>
      <link>https://safeguard.sh/resources/blog/ftc-data-broker-rule-supply-chain-implications-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ftc-data-broker-rule-supply-chain-implications-2026</guid>
      <pubDate>Tue, 12 May 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NuGet's September 2025 Trusted Publishing Launch and the 2026 Signing Roadmap]]></title>
      <description><![CDATA[NuGet became the fifth major registry to ship Trusted Publishing in September 2025, with .NET package signing and ID prefix reservation forming a complete trust-signal stack for the ecosystem.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-trusted-publishing-signing-rollout-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-trusted-publishing-signing-rollout-2026</guid>
      <pubDate>Tue, 12 May 2026 12:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Ollama CVE-2026-7482 'Bleeding Llama': Out-of-Bounds Read]]></title>
      <description><![CDATA[Cyera disclosed Bleeding Llama in May 2026: a heap out-of-bounds read in Ollama's GGUF loader leaking process memory. We dissect the bug and the exposure across 300,000 Ollama deployments.]]></description>
      <link>https://safeguard.sh/resources/blog/ollama-cve-2026-7482-bleeding-llama-memory-leak</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ollama-cve-2026-7482-bleeding-llama-memory-leak</guid>
      <pubDate>Tue, 12 May 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[GitGuardian vs TruffleHog: choosing a secrets detection tool in 2026]]></title>
      <description><![CDATA[How GitGuardian and TruffleHog compare on detection accuracy, false positive handling, remediation workflow, and enterprise rollout for secrets scanning programs.]]></description>
      <link>https://safeguard.sh/resources/blog/gitguardian-vs-trufflehog-secrets-detection-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitguardian-vs-trufflehog-secrets-detection-2026</guid>
      <pubDate>Tue, 12 May 2026 11:45:00 GMT</pubDate>
      <category>Vendor Comparison</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[UEFI Secure Boot after BlackLotus and PKfail: what the trust chain still assumes]]></title>
      <description><![CDATA[Secure Boot was designed to keep untrusted code from running before the operating system, but its trust anchors live in firmware that OEMs control and sometimes leak. BlackLotus and PKfail exposed the gap between the spec and the deployment.]]></description>
      <link>https://safeguard.sh/resources/blog/uefi-secure-boot-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uefi-secure-boot-supply-chain-2026</guid>
      <pubDate>Tue, 12 May 2026 11:30:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Prompt-injection vectors specific to MCP servers and how to layer defenses]]></title>
      <description><![CDATA[MCP servers expose three distinct prompt-injection surfaces — resource contents, tool outputs, and sampling requests — and each one needs its own defense layer. Here is how to think about them together.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-prompt-injection-vectors-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-prompt-injection-vectors-2026</guid>
      <pubDate>Tue, 12 May 2026 11:15:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[CISA's Secure-by-Design pledge two years in: vendor commitments and procurement effects]]></title>
      <description><![CDATA[CISA's Secure-by-Design pledge launched in April 2024 with seven voluntary goals. Two years later, signatories are publishing progress reports and procurement teams are starting to ask hard questions.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-secure-by-design-pledge-vendor-impact-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-secure-by-design-pledge-vendor-impact-2026</guid>
      <pubDate>Tue, 12 May 2026 11:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Firefox add-on supply chain: how Mozilla's posture differs from Chrome's]]></title>
      <description><![CDATA[Mozilla Add-ons applies mandatory signing, a stricter review path for extensions that touch broad permissions, and a separately maintained recommended-extensions program. Here is what that buys defenders in 2026 and where the gaps still are.]]></description>
      <link>https://safeguard.sh/resources/blog/firefox-addon-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/firefox-addon-supply-chain-2026</guid>
      <pubDate>Tue, 12 May 2026 11:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[jwt-decode: Why Decoding Is Not Verifying (Security Guide)]]></title>
      <description><![CDATA[The npm jwt-decode package reads JWT claims without checking the signature. That is by design, and it is behind a whole class of authentication bypasses when developers forget it.]]></description>
      <link>https://safeguard.sh/resources/blog/jwt-decode-npm-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jwt-decode-npm-security-guide</guid>
      <pubDate>Tue, 12 May 2026 10:44:09 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Endor Labs vs Snyk SCA 2026]]></title>
      <description><![CDATA[Endor Labs built its SCA platform around reachability from day one. How does that architectural bet compare to Snyk's incumbent position in 2026?]]></description>
      <link>https://safeguard.sh/resources/blog/endor-labs-vs-snyk-sca-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/endor-labs-vs-snyk-sca-2026</guid>
      <pubDate>Tue, 12 May 2026 10:30:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Law firm software supply chain risk in 2026]]></title>
      <description><![CDATA[Why the legal sector's reliance on Relativity, iManage, NetDocuments, and a long tail of practice-management vendors creates a supply chain attack surface that ABA Formal Opinion 483 makes a duty to address.]]></description>
      <link>https://safeguard.sh/resources/blog/legal-sector-software-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/legal-sector-software-supply-chain-2026</guid>
      <pubDate>Tue, 12 May 2026 10:30:00 GMT</pubDate>
      <category>Industry Insights</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[regreSSHion revisited: defending against CVE-2024-6387 in 2026]]></title>
      <description><![CDATA[How the regreSSHion race condition in OpenSSH sshd reintroduced an unauthenticated RCE on glibc Linux, what the patch trajectory looked like, and the supply chain habits it should change.]]></description>
      <link>https://safeguard.sh/resources/blog/regresshion-openssh-cve-2024-6387-defense-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/regresshion-openssh-cve-2024-6387-defense-2026</guid>
      <pubDate>Tue, 12 May 2026 10:30:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[AWS Lambda Layers as a supply chain trust surface in 2026]]></title>
      <description><![CDATA[Lambda Layers feel like a packaging convenience, but org-shared and public layers carry code that runs with your function's IAM role. Here is the 2026 control set.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-lambda-layers-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-lambda-layers-supply-chain-2026</guid>
      <pubDate>Tue, 12 May 2026 10:15:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[The ROI of CVE Prioritization with Reachability in 2026]]></title>
      <description><![CDATA[Concrete numbers on what reachability-based CVE prioritization saves: engineering hours, mean time to remediate, and the ROI math that survives finance review.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-prioritization-with-reachability-roi-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-prioritization-with-reachability-roi-2026</guid>
      <pubDate>Tue, 12 May 2026 10:15:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Cheat sheet: meeting security compliance standards]]></title>
      <description><![CDATA[A concrete, numbers-first cheat sheet for SOC 2, ISO 27001, PCI DSS 4.0, and SBOM mandates — deadlines, timelines, and audit gaps that actually matter.]]></description>
      <link>https://safeguard.sh/resources/blog/cheat-sheet-meeting-security-compliance-standards</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cheat-sheet-meeting-security-compliance-standards</guid>
      <pubDate>Tue, 12 May 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx vs Snyk vs Safeguard: 2026 Comparison]]></title>
      <description><![CDATA[Checkmarx brings enterprise SAST depth, Snyk brings developer-first workflow, and consolidation platforms now bundle both layers with DAST and compliance. How to choose in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-vs-snyk-vs-safeguard-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-vs-snyk-vs-safeguard-2026</guid>
      <pubDate>Tue, 12 May 2026 10:00:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Chrome extension marketplace hijack: the acquired-and-weaponized pattern]]></title>
      <description><![CDATA[Legitimate Chrome extensions keep getting acquired and turned malicious, and content_scripts give the new owner code execution inside every user's browser session. Here is why the pattern keeps working in 2026 and what defenders can do about it.]]></description>
      <link>https://safeguard.sh/resources/blog/chrome-extension-marketplace-hijack-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chrome-extension-marketplace-hijack-2026</guid>
      <pubDate>Tue, 12 May 2026 09:30:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[MCP tool poisoning: hidden instructions and rug-pulled tool definitions]]></title>
      <description><![CDATA[Tool-poisoning attacks against Model Context Protocol servers hide adversarial instructions inside tool descriptions and silently mutate tool definitions after install. Here is how the attack works and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-tool-poisoning-attacks-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-tool-poisoning-attacks-2026</guid>
      <pubDate>Tue, 12 May 2026 09:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[SEC cyber-incident 8-K disclosure and the software supply chain in 2026]]></title>
      <description><![CDATA[The SEC's Item 1.05 8-K rule has been live since December 2023, and supply-chain incidents are now the most common trigger for a four-day materiality clock. Here is what programs need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/sec-cyber-disclosure-8-k-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sec-cyber-disclosure-8-k-supply-chain-2026</guid>
      <pubDate>Tue, 12 May 2026 09:30:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Socket.dev vs Phylum: which supply chain risk scanner fits your stack in 2026]]></title>
      <description><![CDATA[How Socket.dev and Phylum compare on behavioral detection, ecosystem coverage, scoring transparency, and the developer ergonomics that decide adoption.]]></description>
      <link>https://safeguard.sh/resources/blog/socket-dev-vs-phylum-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/socket-dev-vs-phylum-supply-chain-2026</guid>
      <pubDate>Tue, 12 May 2026 09:30:00 GMT</pubDate>
      <category>Vendor Comparison</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-23121 in Veeam Backup & Replication: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[Veeam B&R authenticated RCE on the backup server scored CVSS 9.9. Backup infrastructure cannot be a soft underbelly. Here is the defender playbook.]]></description>
      <link>https://safeguard.sh/resources/blog/veeam-backup-cve-2025-23121-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/veeam-backup-cve-2025-23121-patch-response</guid>
      <pubDate>Tue, 12 May 2026 09:23:43 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[BMC firmware and the supply chain you forgot you had]]></title>
      <description><![CDATA[Baseboard management controllers run their own operating system below your hypervisor, ship as binary blobs from vendors like AMI and Insyde, and almost never appear in an SBOM. The MegaRAC incidents made that gap impossible to ignore.]]></description>
      <link>https://safeguard.sh/resources/blog/hardware-bmc-firmware-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hardware-bmc-firmware-supply-chain-2026</guid>
      <pubDate>Tue, 12 May 2026 09:15:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[SSO, SCIM, and Vanta integrations for compliance-driven t...]]></title>
      <description><![CDATA[How SSO, SCIM, and native Vanta integration shape audit readiness for supply chain security tools, and where Safeguard's approach differs from Socket.dev's.]]></description>
      <link>https://safeguard.sh/resources/blog/sso-scim-and-vanta-integrations-for-compliance-driven-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sso-scim-and-vanta-integrations-for-compliance-driven-teams</guid>
      <pubDate>Tue, 12 May 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Tool Consolidation ROI Rubric for AppSec in 2026]]></title>
      <description><![CDATA[A rubric for calculating the real ROI of AppSec tool consolidation in 2026, with the cost categories that get missed and the patterns that genuinely save money.]]></description>
      <link>https://safeguard.sh/resources/blog/tool-consolidation-roi-rubric-for-appsec-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tool-consolidation-roi-rubric-for-appsec-2026</guid>
      <pubDate>Tue, 12 May 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NIS2 in Italy: Legislative Decree 138/2024 and the Tiered Sanctions Regime]]></title>
      <description><![CDATA[Italy's NIS2 transposition entered into force on 16 October 2024 via Decree 138/2024, with fines reaching 10 million EUR or 2% of global turnover for essential entities.]]></description>
      <link>https://safeguard.sh/resources/blog/nis2-italy-decree-138-sanctions-tiered</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nis2-italy-decree-138-sanctions-tiered</guid>
      <pubDate>Tue, 12 May 2026 08:03:16 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[GDPR compliance considerations for application security teams]]></title>
      <description><![CDATA[GDPR's Article 32 doesn't name SAST or SBOM, but fines like Meta's €1.2B and BA's £20m trace straight back to AppSec gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/gdpr-compliance-considerations-for-application-security-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gdpr-compliance-considerations-for-application-security-teams</guid>
      <pubDate>Tue, 12 May 2026 07:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[MySQL Vulnerabilities: Common Risks and How to Patch Them]]></title>
      <description><![CDATA[MySQL vulnerabilities range from privilege-escalation flaws in the server to injection and misconfiguration in the apps that use it. Here is what to watch and how to close the gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/mysql-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mysql-vulnerabilities</guid>
      <pubDate>Tue, 12 May 2026 06:42:49 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Vendor trust center: how Socket protects customer data]]></title>
      <description><![CDATA[How Socket.dev discloses SOC 2 and security data, and what a self-service SCA vendor security trust center should show before you grant repo access.]]></description>
      <link>https://safeguard.sh/resources/blog/vendor-trust-center-how-socket-protects-customer-data</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vendor-trust-center-how-socket-protects-customer-data</guid>
      <pubDate>Tue, 12 May 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Security Tools: What Actually Belongs in Your Stack]]></title>
      <description><![CDATA[Enterprise security tools span identity, endpoint, network, application, and data layers. Here is a practical map of what each category does and how to avoid buying overlap.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-security-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-security-tools</guid>
      <pubDate>Tue, 12 May 2026 05:22:23 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[How a Web Application Penetration Test Actually Works (and What It Finds)]]></title>
      <description><![CDATA[A web application penetration test simulates a real attacker against your app. Here is what the phases look like and how to act on the report.]]></description>
      <link>https://safeguard.sh/resources/blog/web-application-penetration-test</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-application-penetration-test</guid>
      <pubDate>Tue, 12 May 2026 04:01:56 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA compliance in software development]]></title>
      <description><![CDATA[HIPAA compliance in software development means encryption, access logging, and vulnerability management baked into the SDLC — not paperwork. Here's what engineers must build.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-compliance-in-software-development</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-compliance-in-software-development</guid>
      <pubDate>Tue, 12 May 2026 04:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Responsible vulnerability disclosure policy comparison]]></title>
      <description><![CDATA[Safeguard and Socket.dev both publish vulnerability disclosure policies—but their SLAs, bounty terms, and scope differ. A sourced, line-by-line comparison for vendor due diligence.]]></description>
      <link>https://safeguard.sh/resources/blog/responsible-vulnerability-disclosure-policy-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/responsible-vulnerability-disclosure-policy-comparison</guid>
      <pubDate>Tue, 12 May 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Rebuilding Docker Images: When and How]]></title>
      <description><![CDATA[Knowing how to rebuild a Docker image correctly — and when a cached layer is silently serving stale, vulnerable code — matters more than most teams realize until a patch doesn't actually land.]]></description>
      <link>https://safeguard.sh/resources/blog/rebuilding-docker-images-when-and-how</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rebuilding-docker-images-when-and-how</guid>
      <pubDate>Tue, 12 May 2026 02:41:29 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Secure webpack-dev-server Against Source Code Theft]]></title>
      <description><![CDATA[webpack-dev-server is a local development server, not a production one, and two 2025 CVEs showed exactly why that distinction matters. Here is how it leaks and how to lock it down.]]></description>
      <link>https://safeguard.sh/resources/blog/webpack-dev-server</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webpack-dev-server</guid>
      <pubDate>Tue, 12 May 2026 01:21:03 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[PCI DSS requirements for application security programs]]></title>
      <description><![CDATA[PCI DSS v4.0.1 Requirement 6 sets hard deadlines and evidence rules for AppSec — here's what 6.2.3, 6.3.1–6.3.3 actually demand.]]></description>
      <link>https://safeguard.sh/resources/blog/pci-dss-requirements-for-application-security-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pci-dss-requirements-for-application-security-programs</guid>
      <pubDate>Tue, 12 May 2026 01:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Synk Artinya: What Snyk Means and Does]]></title>
      <description><![CDATA[Synk artinya apa? A plain explanation of what Snyk is, what the tool does, how its pricing works, and where it fits in a security toolchain.]]></description>
      <link>https://safeguard.sh/resources/blog/synk-artinya</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/synk-artinya</guid>
      <pubDate>Tue, 12 May 2026 00:00:36 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Does Socket.dev store or upload your source code?]]></title>
      <description><![CDATA[Does Socket.dev see your proprietary source code? Here's how dependency scanners access repos, and where Safeguard draws the compliance line.]]></description>
      <link>https://safeguard.sh/resources/blog/does-socketdev-store-or-upload-your-source-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/does-socketdev-store-or-upload-your-source-code</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[DAST Testing: How Dynamic Scans Probe Running Applications]]></title>
      <description><![CDATA[DAST testing attacks your app the way an outsider would — no source code, just HTTP requests against a running target. Here is how the scan works, what it catches that SAST misses, and where it falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-testing-how-dynamic-scans-work</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-testing-how-dynamic-scans-work</guid>
      <pubDate>Mon, 11 May 2026 22:40:09 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is a White Box Penetration Test?]]></title>
      <description><![CDATA[A clear explanation of the white box penetration test: how full-knowledge testing differs from black and gray box, what testers get, and when it is the right choice.]]></description>
      <link>https://safeguard.sh/resources/blog/white-box-penetration-test</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/white-box-penetration-test</guid>
      <pubDate>Mon, 11 May 2026 21:19:43 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[PDFKit v0.8.6 Command Injection (CVE-2022-25765): Detection and Fix]]></title>
      <description><![CDATA[The pdfkit v0.8.6 exploit is CVE-2022-25765, a command injection in the Ruby pdfkit gem where an unsanitized URL reaches the shell. How it works conceptually, how to detect it, and the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/pdfkit-0-8-6-command-injection-cve</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pdfkit-0-8-6-command-injection-cve</guid>
      <pubDate>Mon, 11 May 2026 19:59:16 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is Password Salting? Why Two Identical Passwords Should Never Match]]></title>
      <description><![CDATA[Password salting adds a unique random value to each password before hashing, so identical passwords produce different hashes and precomputed attacks fall apart.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-password-salting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-password-salting</guid>
      <pubDate>Mon, 11 May 2026 18:38:49 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Python: Check If a String Is a Valid URL (Safely)]]></title>
      <description><![CDATA[How to check if a string is a URL in Python using urllib.parse, when to add validators, and why parseable does not mean safe for the URL you are about to fetch.]]></description>
      <link>https://safeguard.sh/resources/blog/python-check-if-string-is-valid-url</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-check-if-string-is-valid-url</guid>
      <pubDate>Mon, 11 May 2026 17:18:22 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[react-native-inappbrowser-reborn: A Security Review of the In-App Browser Package]]></title>
      <description><![CDATA[A practitioner's security look at react-native-inappbrowser-reborn: what it does, where the risk lives, and how to vet it and siblings like react-native-wifi-reborn.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-inappbrowser-reborn</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-inappbrowser-reborn</guid>
      <pubDate>Mon, 11 May 2026 15:57:56 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[netty-codec-http2 in Maven: Vulnerabilities and Fixes]]></title>
      <description><![CDATA[The netty-codec-http2 Maven artifact powers HTTP/2 in gRPC, Spring, and countless services. Here are the CVEs that matter, the safe versions, and how to find it in your tree.]]></description>
      <link>https://safeguard.sh/resources/blog/netty-codec-http2-maven</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/netty-codec-http2-maven</guid>
      <pubDate>Mon, 11 May 2026 14:37:29 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Writing an Open Source Software Policy]]></title>
      <description><![CDATA[An open source software policy is what turns ad-hoc dependency choices into a governed, auditable process — here's what to actually put in one.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-software-policy-writing-one</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-software-policy-writing-one</guid>
      <pubDate>Mon, 11 May 2026 13:17:02 GMT</pubDate>
      <category>Governance</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Uncaught Exceptions in JavaScript: Handling Them Without Hiding Bugs]]></title>
      <description><![CDATA[A JavaScript uncaught exception is a thrown error that no catch block claims — and the worst response is a global handler that swallows it. Here is how to handle them in Node and the browser without hiding real bugs.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-uncaught-exceptions-handling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-uncaught-exceptions-handling</guid>
      <pubDate>Mon, 11 May 2026 11:56:36 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Code Scanning: Tools and Workflow]]></title>
      <description><![CDATA[Open source code scanning tools can cover most of a small team's needs for free, but the workflow around them — what runs where, and who reviews the output — matters more than which tool you pick.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-code-scanning-tools-and-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-code-scanning-tools-and-workflow</guid>
      <pubDate>Mon, 11 May 2026 10:36:09 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP authorization for cloud service providers explained]]></title>
      <description><![CDATA[A concrete walkthrough of FedRAMP authorization for CSPs: impact levels, control counts, timelines, costs, FedRAMP 20x, and continuous monitoring deadlines.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-authorization-for-cloud-service-providers-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-authorization-for-cloud-service-providers-explained</guid>
      <pubDate>Mon, 11 May 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Docker Scratch Images: When (and When Not) to Use Them]]></title>
      <description><![CDATA[A docker scratch image starts from nothing — no shell, no package manager, no OS layer — which makes it the smallest possible attack surface, but only for binaries built to run without one.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-scratch-images-when-to-use-them</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-scratch-images-when-to-use-them</guid>
      <pubDate>Mon, 11 May 2026 09:15:42 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Socket.dev vs Snyk: SCA feature comparison]]></title>
      <description><![CDATA[Socket.dev flags risky OSS packages; Snyk scans for known CVEs. See how Safeguard unifies both approaches into one supply chain security workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/socketdev-vs-snyk-sca-feature-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/socketdev-vs-snyk-sca-feature-comparison</guid>
      <pubDate>Mon, 11 May 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[What a Website Security Checker Really Checks]]></title>
      <description><![CDATA[A website security checker scans a site for exposed vulnerabilities, misconfigurations, and known-bad dependencies. Here is what it catches and where it stops.]]></description>
      <link>https://safeguard.sh/resources/blog/website-security-checker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/website-security-checker</guid>
      <pubDate>Mon, 11 May 2026 07:55:16 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[NIST Secure Software Development Framework (SSDF) explained]]></title>
      <description><![CDATA[NIST SP 800-218's 42 practices now back federal attestation law. Here's what SSDF actually requires, who must comply, and how it differs from SLSA and SOC 2.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-secure-software-development-framework-ssdf-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-secure-software-development-framework-ssdf-explained</guid>
      <pubDate>Mon, 11 May 2026 07:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA Meaning: What the Law Requires and Why It Matters for Software]]></title>
      <description><![CDATA[HIPAA meaning explained: it is the U.S. Health Insurance Portability and Accountability Act, which sets rules for protecting patient health data. Here is what it covers and how it hits software teams.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-meaning</guid>
      <pubDate>Mon, 11 May 2026 06:34:49 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Socket.dev vs Dependabot: beyond automated dependency upd...]]></title>
      <description><![CDATA[Dependabot patches known CVEs; Socket.dev flags risky package behavior. Neither enforces policy or ties risk to your actual build and runtime footprint — here's where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/socketdev-vs-dependabot-beyond-automated-dependency-updates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/socketdev-vs-dependabot-beyond-automated-dependency-updates</guid>
      <pubDate>Mon, 11 May 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Lodash 4.17.21 Vulnerabilities: What the 'Safe' Version Still Misses]]></title>
      <description><![CDATA[Lodash 4.17.21 was the release that fixed the famous prototype pollution and command injection bugs. Here is what it patched and why it is no longer the final word.]]></description>
      <link>https://safeguard.sh/resources/blog/lodash-4-17-21-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lodash-4-17-21-vulnerabilities</guid>
      <pubDate>Mon, 11 May 2026 05:14:22 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Executive Order 14028 and software supply chain security]]></title>
      <description><![CDATA[EO 14028 forces federal software vendors to produce SBOMs and attest to NIST's SSDF. Here's what it requires, key deadlines, and how to prove compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/executive-order-14028-and-software-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/executive-order-14028-and-software-supply-chain-security</guid>
      <pubDate>Mon, 11 May 2026 04:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[yup npm: A Security Review of the Schema Validation Library]]></title>
      <description><![CDATA[The yup npm package is a mature, actively maintained schema validation library, and it is safe to use, but validation belongs on the server and yup schemas need to be written defensively. Here is the review.]]></description>
      <link>https://safeguard.sh/resources/blog/yup-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/yup-npm</guid>
      <pubDate>Mon, 11 May 2026 03:53:55 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Socket.dev alternatives for enterprise supply chain security]]></title>
      <description><![CDATA[Comparing Safeguard and Socket.dev on detection philosophy, ecosystem coverage, and supply chain breadth for enterprise security teams evaluating alternatives.]]></description>
      <link>https://safeguard.sh/resources/blog/socketdev-alternatives-for-enterprise-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/socketdev-alternatives-for-enterprise-supply-chain-security</guid>
      <pubDate>Mon, 11 May 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Cloudflare Workers KV June 12 2025 Outage: A GCP Dependency Story]]></title>
      <description><![CDATA[A 2-hour, 28-minute Workers KV outage rolled into Access, Gateway, WARP, and Turnstile because the central store sat on GCP. Here is the dependency chain and the R2 re-architecture that followed.]]></description>
      <link>https://safeguard.sh/resources/blog/cloudflare-workers-kv-june-2025-gcp-dependency</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloudflare-workers-kv-june-2025-gcp-dependency</guid>
      <pubDate>Mon, 11 May 2026 02:33:29 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[react-sortable-hoc: Security and Maintenance Status Review]]></title>
      <description><![CDATA[react-sortable-hoc is no longer actively maintained and leans on the soon-to-be-removed findDOMNode API. Here's what that means for your risk and what to migrate to.]]></description>
      <link>https://safeguard.sh/resources/blog/react-sortable-hoc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-sortable-hoc</guid>
      <pubDate>Mon, 11 May 2026 01:13:02 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[EU Cyber Resilience Act: what developers need to know]]></title>
      <description><![CDATA[The EU Cyber Resilience Act sets hard deadlines starting Sept 2026 for SBOMs, vulnerability reporting, and patching. Here's what developers must build.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cyber-resilience-act-what-developers-need-to-know</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cyber-resilience-act-what-developers-need-to-know</guid>
      <pubDate>Mon, 11 May 2026 01:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Socket.dev pricing and plan limitations]]></title>
      <description><![CDATA[Evaluating Socket.dev pricing and plan limits? Here's what to know about seat-based costs, feature gating, and how Safeguard compares on coverage and flexibility.]]></description>
      <link>https://safeguard.sh/resources/blog/socketdev-pricing-and-plan-limitations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/socketdev-pricing-and-plan-limitations</guid>
      <pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Makes a Good Open Source Security Platform?]]></title>
      <description><![CDATA[An open source security platform has to cover the whole dependency lifecycle, not just print CVEs. Here is what the category actually includes and how to evaluate one for your stack.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-security-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-security-platform</guid>
      <pubDate>Sun, 10 May 2026 23:52:35 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes securityContext: A Practical Hardening Guide]]></title>
      <description><![CDATA[The securityContext in Kubernetes is where most pod hardening actually happens. A field-by-field guide to running non-root, dropping capabilities, and read-only roots.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-securitycontext-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-securitycontext-guide</guid>
      <pubDate>Sun, 10 May 2026 22:32:09 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[DAST Scanning Tools: What They Are and How to Choose One]]></title>
      <description><![CDATA[DAST scanning tools test a running application from the outside to find runtime flaws. Here is how they work, what they catch, and how to pick one.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-scanning-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-scanning-tools</guid>
      <pubDate>Sun, 10 May 2026 21:11:42 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Insight: Turning Cloud Telemetry Into Security Signal]]></title>
      <description><![CDATA[Cloud insight is the practice of turning raw cloud logs, configs, and inventory into decisions you can act on. Here is how to build it without drowning in dashboards.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-insight</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-insight</guid>
      <pubDate>Sun, 10 May 2026 19:51:15 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Griffin AI: Autonomous Vulnerability Remediation That Actually Works]]></title>
      <description><![CDATA[Griffin AI moves beyond scan-and-alert to autonomously generate, test, and propose vulnerability fixes. How Safeguard's remediation engine reduces mean time to fix without introducing new risk.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-griffin-ai-autonomous-remediation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-griffin-ai-autonomous-remediation</guid>
      <pubDate>Sun, 10 May 2026 18:30:49 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[How to Dockerize a PHP Application Without Shipping Vulnerabilities]]></title>
      <description><![CDATA[Dockerizing a PHP application is easy; doing it securely takes a few deliberate choices about base images, users, and dependencies. Here is a hardened, production-ready approach.]]></description>
      <link>https://safeguard.sh/resources/blog/dockerize-php-application</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dockerize-php-application</guid>
      <pubDate>Sun, 10 May 2026 17:10:22 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The Core Pillars of DevSecOps, Explained]]></title>
      <description><![CDATA[The DevSecOps pillars are the recurring foundations every mature program shares: culture, automation, shift-left testing, continuous monitoring, and shared measurement.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-pillars</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-pillars</guid>
      <pubDate>Sun, 10 May 2026 15:49:55 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Insights for Kubernetes Security: What They Actually Tell You]]></title>
      <description><![CDATA[Cloud insights turn raw telemetry from your clusters and cloud accounts into security signals you can act on. Here is how to read them for Kubernetes.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-insights</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-insights</guid>
      <pubDate>Sun, 10 May 2026 14:29:29 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Monitoring Package Maintainer Changes as a Threat Signal]]></title>
      <description><![CDATA[Most package hijacks start with a maintainer change nobody was watching. Registry metadata makes these events observable — if you bother to look.]]></description>
      <link>https://safeguard.sh/resources/blog/monitoring-package-maintainer-changes-as-a-threat-signal</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/monitoring-package-maintainer-changes-as-a-threat-signal</guid>
      <pubDate>Sun, 10 May 2026 13:09:02 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Tomas Lindgren)</author>
    </item>
    <item>
      <title><![CDATA[webpack-merge: What It Does and How to Use It Securely]]></title>
      <description><![CDATA[webpack-merge cleanly combines webpack configs, but its low release cadence and function-executing merge behavior deserve a security-minded look.]]></description>
      <link>https://safeguard.sh/resources/blog/webpack-merge</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webpack-merge</guid>
      <pubDate>Sun, 10 May 2026 11:48:35 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[SCA Full Form in Engineering: What Software Composition Analysis Means]]></title>
      <description><![CDATA[In software engineering and security, the SCA full form is Software Composition Analysis: the practice of inventorying and vetting the open-source components your code depends on.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-full-form-in-engineering</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-full-form-in-engineering</guid>
      <pubDate>Sun, 10 May 2026 10:28:08 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[DORA regulation and operational resilience for financial software]]></title>
      <description><![CDATA[DORA became fully applicable Jan 17, 2025. Here's what it requires of software supply chain risk, incident reporting, and SBOMs — with concrete deadlines.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-regulation-and-operational-resilience-for-financial-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-regulation-and-operational-resilience-for-financial-software</guid>
      <pubDate>Sun, 10 May 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Runbooks for Dependency Disclosure Events]]></title>
      <description><![CDATA[Detailed runbooks for responding to dependency CVE disclosures across languages and ecosystems, with roles, commands, and timelines tuned for automation.]]></description>
      <link>https://safeguard.sh/resources/blog/runbooks-for-dependency-disclosure-events</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runbooks-for-dependency-disclosure-events</guid>
      <pubDate>Sun, 10 May 2026 09:07:42 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Malicious postinstall scripts in npm packages]]></title>
      <description><![CDATA[From eslint-scope in 2018 to the 2025 Shai-Hulud worm, npm postinstall scripts keep delivering malware before any scan or review runs. Here's how it works and what stops it.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-postinstall-scripts-in-npm-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-postinstall-scripts-in-npm-packages</guid>
      <pubDate>Sun, 10 May 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Dependency in Programming?]]></title>
      <description><![CDATA[A dependency is any external code your software relies on to run. Here is what that really means, how direct and transitive dependencies differ, and why the concept sits at the heart of software supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-dependency-in-programming</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-dependency-in-programming</guid>
      <pubDate>Sun, 10 May 2026 07:47:15 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[NIS2 Directive compliance for software vendors]]></title>
      <description><![CDATA[NIS2 became enforceable October 17, 2024, and Article 21 now requires software vendors to prove SBOM, CVE remediation, and disclosure practices to EU customers.]]></description>
      <link>https://safeguard.sh/resources/blog/nis2-directive-compliance-for-software-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nis2-directive-compliance-for-software-vendors</guid>
      <pubDate>Sun, 10 May 2026 07:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[DORA Register of Information: Lessons From the First Submission]]></title>
      <description><![CDATA[The 30 April 2025 ESA deadline forced banks and insurers to inventory every ICT contract against 105 prescribed data points — and exposed structural gaps in third-party data.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-register-of-information-april-2025-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-register-of-information-april-2025-lessons</guid>
      <pubDate>Sun, 10 May 2026 06:26:48 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Co-op UK DragonForce Breach: When the Helpdesk Becomes the Backdoor]]></title>
      <description><![CDATA[In late April 2025 the Co-operative Group joined Marks & Spencer and Harrods as victims of a DragonForce-affiliated cluster that targeted UK retail through helpdesk social engineering. We unpack the playbook and what retailers must change.]]></description>
      <link>https://safeguard.sh/resources/blog/co-op-uk-retail-dragonforce-helpdesk-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/co-op-uk-retail-dragonforce-helpdesk-2025</guid>
      <pubDate>Sun, 10 May 2026 05:06:22 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[CISA's Secure by Design pledge explained]]></title>
      <description><![CDATA[CISA's voluntary Secure by Design pledge has grown from 68 signatories to 300+, but it's unverified and self-reported. Here's what the seven goals really require.]]></description>
      <link>https://safeguard.sh/resources/blog/cisas-secure-by-design-pledge-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisas-secure-by-design-pledge-explained</guid>
      <pubDate>Sun, 10 May 2026 04:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Security and DevOps Automation: Building Guardrails Into the Pipeline]]></title>
      <description><![CDATA[How cloud security and DevOps automation fit together: shifting checks into CI/CD, policy as code, automated IaC and image scanning, and the pitfalls that make automation give false confidence.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-security-and-devops-automation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-security-and-devops-automation</guid>
      <pubDate>Sun, 10 May 2026 03:45:55 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Malicious PyPI packages: common infiltration patterns]]></title>
      <description><![CDATA[Real malicious PyPI package examples — typosquats, dependency confusion, hijacked maintainers, and crypto stealers — and how Safeguard catches them before install.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-pypi-packages-common-infiltration-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-pypi-packages-common-infiltration-patterns</guid>
      <pubDate>Sun, 10 May 2026 03:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[@react-native-community/geolocation: Is It Safe and Maintained?]]></title>
      <description><![CDATA[@react-native-community/geolocation is the actively maintained official location module for React Native, and the biggest security question with it is privacy, not code vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-community-geolocation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-community-geolocation</guid>
      <pubDate>Sun, 10 May 2026 02:25:28 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Risk Score in Vulnerability Management?]]></title>
      <description><![CDATA[A risk score turns raw severity into a prioritized number by factoring in exploitability, exposure, and business context. Here is how to read and build one.]]></description>
      <link>https://safeguard.sh/resources/blog/risk-score</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/risk-score</guid>
      <pubDate>Sun, 10 May 2026 01:05:02 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[SEC cybersecurity disclosure rules for public companies]]></title>
      <description><![CDATA[The SEC's 2023 rules give public companies four business days to disclose material cyber incidents. Here's what triggers the clock, and how supply chain visibility keeps you compliant.]]></description>
      <link>https://safeguard.sh/resources/blog/sec-cybersecurity-disclosure-rules-for-public-companies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sec-cybersecurity-disclosure-rules-for-public-companies</guid>
      <pubDate>Sun, 10 May 2026 01:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Malicious NuGet package campaigns targeting developers]]></title>
      <description><![CDATA[Socket.dev has tracked malicious NuGet packages stealing wallets, banking credentials, and sabotaging industrial systems. See how Safeguard catches them first.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-nuget-package-campaigns-targeting-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-nuget-package-campaigns-targeting-developers</guid>
      <pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Docker Image Security Scan: How to Scan Images for Vulnerabilities]]></title>
      <description><![CDATA[A Docker image security scan inspects the layers of an image for known-vulnerable packages before you ship it. Here are the tools, commands, and the workflow that keeps scanning useful.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-image-security-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-image-security-scan</guid>
      <pubDate>Sat, 09 May 2026 23:44:35 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[sanitize-html Vulnerabilities: History and Correct Configuration]]></title>
      <description><![CDATA[A walk through the real npm sanitize-html vulnerabilities, from the 2016 recursion bypass to the 2024 style-attribute leak, and the configuration that keeps the library safe.]]></description>
      <link>https://safeguard.sh/resources/blog/sanitize-html-npm-vulnerabilities-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sanitize-html-npm-vulnerabilities-guide</guid>
      <pubDate>Sat, 09 May 2026 22:24:08 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[PHP Security Issues: The Vulnerabilities That Still Bite in 2025]]></title>
      <description><![CDATA[Most PHP security issues come down to a handful of repeatable mistakes: unsanitized input, weak session handling, and outdated dependencies. Here is what breaks and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/php-security-issues</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-security-issues</guid>
      <pubDate>Sat, 09 May 2026 21:03:42 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Is node:18-alpine Still Safe to Use in 2025?]]></title>
      <description><![CDATA[The node:18-alpine image is small and popular, but Node.js 18 reached end of life in April 2025. Here is what that means for your containers and how to migrate cleanly.]]></description>
      <link>https://safeguard.sh/resources/blog/node-18-alpine</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-18-alpine</guid>
      <pubDate>Sat, 09 May 2026 19:43:15 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Software Licensing, and Why It Is a Supply Chain Problem]]></title>
      <description><![CDATA[Software licensing is the legal layer of your dependency tree, and getting it wrong carries real risk. Here is what the term covers and how open source licenses sneak into your product.]]></description>
      <link>https://safeguard.sh/resources/blog/software-licensing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-licensing</guid>
      <pubDate>Sat, 09 May 2026 18:22:48 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Rimraf npm: Is It Still Worth Installing in 2025?]]></title>
      <description><![CDATA[A security-minded look at the rimraf npm package — what it does, why old versions throw deprecation warnings, and when Node's built-in fs.rm makes it optional.]]></description>
      <link>https://safeguard.sh/resources/blog/rimraf-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rimraf-npm</guid>
      <pubDate>Sat, 09 May 2026 17:02:21 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-34462: The Netty SniHandler Memory Exhaustion Flaw]]></title>
      <description><![CDATA[CVE-2023-34462 lets a crafted TLS ClientHello force Netty's SniHandler to allocate up to 16MB per connection, opening a denial-of-service path. Here is the root cause, affected versions, and the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-34462</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-34462</guid>
      <pubDate>Sat, 09 May 2026 15:41:55 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[cookie-parser in Express: Security Guide and Best Practices]]></title>
      <description><![CDATA[The cookie-parser npm middleware is deceptively simple, but signed-cookie misuse and a 2024 CVE in its underlying cookie library still catch Express teams out.]]></description>
      <link>https://safeguard.sh/resources/blog/cookie-parser-npm-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cookie-parser-npm-security-guide</guid>
      <pubDate>Sat, 09 May 2026 14:21:28 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[AWS SDK v3 Clients (@aws-sdk/client-s3 and Friends): Security Guide]]></title>
      <description><![CDATA[@aws-sdk/client-s3 and the other modular v3 clients change how credentials, dependencies, and mocking work. Here is the security guidance that should accompany the migration.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-sdk-v3-clients-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-sdk-v3-clients-security-guide</guid>
      <pubDate>Sat, 09 May 2026 13:01:01 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm js-yaml: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[npm js-yaml is the standard YAML parser for Node.js. Its history includes real code-execution bugs, and how you call it still decides whether your app is safe.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-js-yaml</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-js-yaml</guid>
      <pubDate>Sat, 09 May 2026 11:40:35 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Cyber Incident Response: Building a Plan That Actually Works]]></title>
      <description><![CDATA[Cyber incident response is a discipline you rehearse, not a document you file. Here is how the phases fit together and what separates teams that recover fast from ones that flail.]]></description>
      <link>https://safeguard.sh/resources/blog/cyber-incident-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyber-incident-response</guid>
      <pubDate>Sat, 09 May 2026 10:20:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What is the BSD license? Top 10 questions answered]]></title>
      <description><![CDATA[The BSD license explained: its 0-, 2-, 3-, and 4-clause variants, how it differs from MIT and GPL, and which real projects run on it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-bsd-license-top-10-questions-answered</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-bsd-license-top-10-questions-answered</guid>
      <pubDate>Sat, 09 May 2026 10:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Typosquatting across package registries (npm, Go, PyPI)]]></title>
      <description><![CDATA[Typosquatting has infected npm, PyPI, and now Go modules. We break down real attacks like crossenv and colourama, how Socket.dev detects them, and where the gaps remain.]]></description>
      <link>https://safeguard.sh/resources/blog/typosquatting-across-package-registries-npm-go-pypi</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/typosquatting-across-package-registries-npm-go-pypi</guid>
      <pubDate>Sat, 09 May 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Ltd: What the Company Builds and How Its Pricing Works]]></title>
      <description><![CDATA[A factual overview of Snyk Ltd, the developer-security company: what its products do, how its plans are priced, and what to weigh when evaluating it.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-ltd</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-ltd</guid>
      <pubDate>Sat, 09 May 2026 08:59:41 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to Scan a Web App for Vulnerabilities (Without Fooling Yourself)]]></title>
      <description><![CDATA[To scan web applications well you need the right tool for the right layer. Here is what a web scan actually catches, where each type falls short, and how to combine them.]]></description>
      <link>https://safeguard.sh/resources/blog/scan-web</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scan-web</guid>
      <pubDate>Sat, 09 May 2026 07:39:15 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[5 risks of using open source software]]></title>
      <description><![CDATA[Five documented open source risks — from Log4Shell to the XZ Utils backdoor — with real incidents, dates, and CVEs, plus how Safeguard closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/5-risks-of-using-open-source-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/5-risks-of-using-open-source-software</guid>
      <pubDate>Sat, 09 May 2026 07:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Rego Policy Language: How OPA Turns Rules Into Code]]></title>
      <description><![CDATA[Rego is the declarative policy language behind Open Policy Agent. This guide explains how it works, where it fits in a security pipeline, and how to write policies you can trust.]]></description>
      <link>https://safeguard.sh/resources/blog/rego-policy-language</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rego-policy-language</guid>
      <pubDate>Sat, 09 May 2026 06:18:48 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Much Does Black Duck Cost? A Guide to Black Duck Pricing]]></title>
      <description><![CDATA[Black Duck pricing is quote-only and negotiated per codebase and team size. Here is what drives the cost, the ballpark figures teams report, and how to evaluate whether it fits your budget.]]></description>
      <link>https://safeguard.sh/resources/blog/blackduck-pricing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/blackduck-pricing</guid>
      <pubDate>Sat, 09 May 2026 04:58:21 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[GPL vs MIT vs Apache: license security and compliance implications]]></title>
      <description><![CDATA[Redis, Vizio, and Cisco show how GPL, MIT, and Apache 2.0 licenses create real legal and compliance exposure across your software supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/gpl-vs-mit-vs-apache-license-security-and-compliance-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gpl-vs-mit-vs-apache-license-security-and-compliance-implications</guid>
      <pubDate>Sat, 09 May 2026 04:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[dotenv npm: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[The dotenv npm package loads environment variables from a .env file into process.env. It is safe and widely used, but how you handle the file around it is where most mistakes happen.]]></description>
      <link>https://safeguard.sh/resources/blog/dotenv-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dotenv-npm</guid>
      <pubDate>Sat, 09 May 2026 03:37:55 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Prompt injection attacks against AI coding/security tools]]></title>
      <description><![CDATA[AI coding assistants like Copilot and Cursor can be hijacked by hidden text in files, comments, and packages. Here's how prompt injection malware works and how Safeguard detects it.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-attacks-against-ai-codingsecurity-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-attacks-against-ai-codingsecurity-tools</guid>
      <pubDate>Sat, 09 May 2026 03:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[MySQL Injection Cheat Sheet: How to Detect and Stop SQLi]]></title>
      <description><![CDATA[A defender's MySQL injection cheat sheet: the query patterns attackers probe for, how login bypass and UNION-based extraction work, and how to shut them down.]]></description>
      <link>https://safeguard.sh/resources/blog/mysql-injection-cheat-sheet</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mysql-injection-cheat-sheet</guid>
      <pubDate>Sat, 09 May 2026 02:17:28 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Building an SBOM that meets NTIA minimum elements]]></title>
      <description><![CDATA[A field-by-field breakdown of NTIA's SBOM minimum elements, who's legally required to meet them in 2026, and why conformant fields don't guarantee real dependency coverage.]]></description>
      <link>https://safeguard.sh/resources/blog/building-an-sbom-that-meets-ntia-minimum-elements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-an-sbom-that-meets-ntia-minimum-elements</guid>
      <pubDate>Sat, 09 May 2026 01:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes runAsUser: How to Run Containers as a Non-Root User]]></title>
      <description><![CDATA[What the Kubernetes runAsUser security context does, how to set it correctly, and the common mistakes that quietly leave pods running as root.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-runasuser</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-runasuser</guid>
      <pubDate>Sat, 09 May 2026 00:57:01 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Malicious browser and IDE extensions (Chrome, Firefox, VS...]]></title>
      <description><![CDATA[How the Cyberhaven Chrome extension breach and the GlassWorm Open VSX worm exposed a supply chain blind spot that dependency scanners like Socket.dev don't cover.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-browser-and-ide-extensions-chrome-firefox-vs-code-open-vsx</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-browser-and-ide-extensions-chrome-firefox-vs-code-open-vsx</guid>
      <pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to Verify Java Builds and Artifacts (java verify)]]></title>
      <description><![CDATA[Verifying Java means more than running tests. It covers Maven's verify phase, JAR signature checks, and confirming dependency integrity before you ship.]]></description>
      <link>https://safeguard.sh/resources/blog/java-verify</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-verify</guid>
      <pubDate>Fri, 08 May 2026 23:36:34 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How Can You Prevent the Download of Malicious Code?]]></title>
      <description><![CDATA[You prevent the download of malicious code with layered controls: verified sources, dependency scanning, browser and endpoint protection, and least-privilege execution.]]></description>
      <link>https://safeguard.sh/resources/blog/how-can-you-prevent-the-download-of-malicious-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-can-you-prevent-the-download-of-malicious-code</guid>
      <pubDate>Fri, 08 May 2026 22:16:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to Run a Secret Scan Across Your Codebase]]></title>
      <description><![CDATA[A secret scan finds hardcoded credentials, API keys, and tokens in your code and history before an attacker does. Here is how to scan, what to catch, and how to respond.]]></description>
      <link>https://safeguard.sh/resources/blog/secret-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secret-scan</guid>
      <pubDate>Fri, 08 May 2026 20:55:41 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-2309: The lxml NULL Pointer Dereference DoS Explained]]></title>
      <description><![CDATA[CVE-2022-2309 crashes lxml applications through a NULL pointer dereference in iterwalk. Here is the affected version matrix and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-2309</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-2309</guid>
      <pubDate>Fri, 08 May 2026 19:35:14 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Docker Hub Node Images: Choosing and Securing the Right Node Tag]]></title>
      <description><![CDATA[The official Node image on Docker Hub ships in half a dozen flavors, and the tag you pick changes your attack surface far more than most teams realize.]]></description>
      <link>https://safeguard.sh/resources/blog/dockerhub-node</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dockerhub-node</guid>
      <pubDate>Fri, 08 May 2026 18:14:48 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What Is Prompt Engineering? A Security Guide for LLM Applications]]></title>
      <description><![CDATA[Prompt engineering is how you steer an LLM, and it is also where a lot of application security now lives. Here is how to write prompts that resist injection and leakage.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-engineering</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-engineering</guid>
      <pubDate>Fri, 08 May 2026 16:54:21 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Ivanti EPMM CVE-2026-6973: Authenticated RCE on CISA KEV in May 2026]]></title>
      <description><![CDATA[Ivanti disclosed CVE-2026-6973 on May 7, 2026, an improper-input-validation RCE in Endpoint Manager Mobile already seeing limited exploitation. CISA gave federal agencies a three-day patch deadline.]]></description>
      <link>https://safeguard.sh/resources/blog/ivanti-epmm-cve-2026-6973-rce-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ivanti-epmm-cve-2026-6973-rce-may-2026</guid>
      <pubDate>Fri, 08 May 2026 16:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Is html-react-parser Safe? Rendering HTML in React Without an XSS Hole]]></title>
      <description><![CDATA[html-react-parser converts an HTML string into React elements, but it is not a sanitizer. Here is how to use it and where the XSS risk really sits.]]></description>
      <link>https://safeguard.sh/resources/blog/html-react-parser</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/html-react-parser</guid>
      <pubDate>Fri, 08 May 2026 15:33:54 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[node:20-alpine: Is the Small Image Worth the Tradeoffs?]]></title>
      <description><![CDATA[node:20-alpine gives you the smallest mainstream Node.js base image, but musl libc and a stripped userland come with real caveats. Here is when to use it and how to harden it.]]></description>
      <link>https://safeguard.sh/resources/blog/node-20-alpine</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-20-alpine</guid>
      <pubDate>Fri, 08 May 2026 14:13:28 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Artificial Intelligence Security Tools: What They Do and How to Choose]]></title>
      <description><![CDATA[Artificial intelligence security tools now sit in two camps: tools that use AI to defend software, and tools that defend the AI itself. Knowing which one you need shapes the whole buying decision.]]></description>
      <link>https://safeguard.sh/resources/blog/artificial-intelligence-security-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/artificial-intelligence-security-tools</guid>
      <pubDate>Fri, 08 May 2026 12:53:01 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Apache License 2.0 Summary: What the Terms Actually Mean]]></title>
      <description><![CDATA[An Apache License 2.0 summary in plain English: what you can do, what you must do, and why the explicit patent grant makes it a favorite for commercial use.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-license-2-0-summary</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-license-2-0-summary</guid>
      <pubDate>Fri, 08 May 2026 11:32:34 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Automotive Supply Chain Cybersecurity Under ISO/SAE 21434 in 2026]]></title>
      <description><![CDATA[OEMs and Tier 1 suppliers have spent four years operationalizing ISO/SAE 21434 and UN R155. Here is what cybersecurity engineering looks like in 2026, and where the supply chain gaps still live.]]></description>
      <link>https://safeguard.sh/resources/blog/automotive-iso-21434-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automotive-iso-21434-supply-chain-2026</guid>
      <pubDate>Fri, 08 May 2026 11:30:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CISA Secure by Design Operational Guidance 2026]]></title>
      <description><![CDATA[Translating CISA's Secure by Design pledge into operational engineering work in 2026, with the specific control mappings and evidence practices that hold up to audit.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-secure-by-design-operational-guidance-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-secure-by-design-operational-guidance-2026</guid>
      <pubDate>Fri, 08 May 2026 11:30:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Checkov 3.2.x Field Review: IaC Scanning in 2026]]></title>
      <description><![CDATA[Bridgecrew's Checkov is still shipping weekly patches in 2026. We ran 3.2.527 against a 38,000-line Terraform monorepo and graded coverage, noise, and CI cost.]]></description>
      <link>https://safeguard.sh/resources/blog/checkov-3-2-2026-iac-scanning-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkov-3-2-2026-iac-scanning-review</guid>
      <pubDate>Fri, 08 May 2026 11:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps SAST: How to Wire Static Analysis Into Your Pipeline]]></title>
      <description><![CDATA[SAST in DevSecOps means catching code-level flaws before they merge, not after they ship. Here is how to integrate static analysis so developers actually use it.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-sast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-sast</guid>
      <pubDate>Fri, 08 May 2026 10:12:08 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SPDX vs CycloneDX: comparing SBOM formats]]></title>
      <description><![CDATA[SPDX and CycloneDX both satisfy federal SBOM rules, but they solve different problems. Here's how they actually differ — with real specs, dates, and tooling.]]></description>
      <link>https://safeguard.sh/resources/blog/spdx-vs-cyclonedx-comparing-sbom-formats</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spdx-vs-cyclonedx-comparing-sbom-formats</guid>
      <pubDate>Fri, 08 May 2026 10:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Reachability analysis for vulnerability prioritization]]></title>
      <description><![CDATA[Most CVEs your scanner flags are never executed. See how reachability analysis filters noise, how Socket.dev approaches it, and how Safeguard finds real risk.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-for-vulnerability-prioritization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-for-vulnerability-prioritization</guid>
      <pubDate>Fri, 08 May 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security Management: Building the Program]]></title>
      <description><![CDATA[Software supply chain security management works as a program, not a tool purchase — it needs SBOM generation, dependency monitoring, and vendor risk scoring wired together with clear ownership.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-management-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-management-programs</guid>
      <pubDate>Fri, 08 May 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[The Java Cheat Sheet Developers Actually Need for Secure Code]]></title>
      <description><![CDATA[Most Java cheat sheets stop at syntax. This one is the security-focused reference: the APIs, patterns, and one-liners that keep injection, deserialization, and crypto bugs out of your code.]]></description>
      <link>https://safeguard.sh/resources/blog/java-cheat-sheet</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-cheat-sheet</guid>
      <pubDate>Fri, 08 May 2026 08:51:41 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Web Session Security: A Practical Guide]]></title>
      <description><![CDATA[Web session security is the set of controls that keep a logged-in user's session token from being stolen, guessed, or reused by an attacker — and most of it comes down to a handful of cookie flags and lifecycle rules teams routinely skip.]]></description>
      <link>https://safeguard.sh/resources/blog/web-session-security-a-practical-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-session-security-a-practical-guide</guid>
      <pubDate>Fri, 08 May 2026 07:31:14 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[FDA SBOM requirements for medical device software]]></title>
      <description><![CDATA[Since Oct 2023 the FDA can reject medical device submissions missing a compliant SBOM. Here's what Section 524B actually requires, in plain terms.]]></description>
      <link>https://safeguard.sh/resources/blog/fda-sbom-requirements-for-medical-device-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fda-sbom-requirements-for-medical-device-software</guid>
      <pubDate>Fri, 08 May 2026 07:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Secure Code Scanning: What It Is and How to Do It Right]]></title>
      <description><![CDATA[Secure code scanning finds vulnerabilities in source and dependencies before they ship. Here is how SAST, SCA, and secret scanning fit together in CI.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-code-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-code-scanning</guid>
      <pubDate>Fri, 08 May 2026 06:10:47 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[npm/package health and quality scoring methodology]]></title>
      <description><![CDATA[How npm package health scores are calculated, why Socket.dev's model misses live supply chain attacks, and what Safeguard checks instead.]]></description>
      <link>https://safeguard.sh/resources/blog/npmpackage-health-and-quality-scoring-methodology</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npmpackage-health-and-quality-scoring-methodology</guid>
      <pubDate>Fri, 08 May 2026 06:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Public Cloud Compliance: What It Takes to Stay Audit-Ready]]></title>
      <description><![CDATA[Public cloud compliance is a shared responsibility, not a checkbox. Here is how the model splits, which frameworks apply, and how to stay continuously audit-ready.]]></description>
      <link>https://safeguard.sh/resources/blog/public-cloud-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/public-cloud-compliance</guid>
      <pubDate>Fri, 08 May 2026 04:50:21 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Audit-readiness for open source usage policies]]></title>
      <description><![CDATA[What auditors actually ask for in an open source usage policy review, what triggers it, and the evidence gaps that turn a written policy into a finding.]]></description>
      <link>https://safeguard.sh/resources/blog/audit-readiness-for-open-source-usage-policies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/audit-readiness-for-open-source-usage-policies</guid>
      <pubDate>Fri, 08 May 2026 04:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AppSec Program Management: Building One That Sticks]]></title>
      <description><![CDATA[AppSec program management is the discipline of turning scattered security tools into a governed, measurable program with owners, policies, and metrics. Here is how to build one.]]></description>
      <link>https://safeguard.sh/resources/blog/appsec-program-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/appsec-program-management</guid>
      <pubDate>Fri, 08 May 2026 03:29:54 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Real-time threat feed for open source malware detection]]></title>
      <description><![CDATA[Malicious npm and PyPI packages spread in hours, not days. Here's why real-time threat feeds beat periodic scans, and how Safeguard detects supply chain malware before install.]]></description>
      <link>https://safeguard.sh/resources/blog/real-time-threat-feed-for-open-source-malware-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/real-time-threat-feed-for-open-source-malware-detection</guid>
      <pubDate>Fri, 08 May 2026 03:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Licenses Comparison: MIT vs Apache vs GPL and the Rest]]></title>
      <description><![CDATA[An open source licenses comparison comes down to one question: what obligations attach to using and distributing the code? Here is how the major licenses differ.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-licenses-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-licenses-comparison</guid>
      <pubDate>Fri, 08 May 2026 02:09:27 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Software supply chain compliance for federal contractors]]></title>
      <description><![CDATA[CMMC 2.0, OMB M-22-18, and SBOM mandates now hit federal contractors with overlapping deadlines and evidence demands — here's what's actually required.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-compliance-for-federal-contractors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-compliance-for-federal-contractors</guid>
      <pubDate>Fri, 08 May 2026 01:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Assessment Services: What's Actually Included]]></title>
      <description><![CDATA[Vulnerability assessment services bundle scanning, triage, and remediation tracking — but the scope varies widely between vendors, and knowing what's actually included changes what you should pay.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-assessment-services-what-they-include</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-assessment-services-what-they-include</guid>
      <pubDate>Fri, 08 May 2026 00:49:01 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Blocking malicious installs with a dependency firewall]]></title>
      <description><![CDATA[How a dependency firewall stops malicious npm installs before they run, where Socket.dev-style scanners fall short, and how Safeguard closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/blocking-malicious-installs-with-a-dependency-firewall</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/blocking-malicious-installs-with-a-dependency-firewall</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[False Positives in Cyber Security: Why They Happen and How to Cut Them]]></title>
      <description><![CDATA[A scanner that cries wolf gets ignored. Here's why false positives pile up in security tooling and the concrete changes that actually reduce them.]]></description>
      <link>https://safeguard.sh/resources/blog/false-positives-in-cyber-security-why-they-happen</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/false-positives-in-cyber-security-why-they-happen</guid>
      <pubDate>Thu, 07 May 2026 23:28:34 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Vulnerability Management: A Working Workflow]]></title>
      <description><![CDATA[A concrete workflow for application security vulnerability management, from scan to fix to verified close, that survives contact with a real release calendar.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-vulnerability-management-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-vulnerability-management-workflow</guid>
      <pubDate>Thu, 07 May 2026 22:08:07 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[org.opencontainers.image.source: OCI Labels for Provenance]]></title>
      <description><![CDATA[The org.opencontainers.image.source label ties a container image back to the repository that built it — a small string with outsized value for provenance, registry linking, and supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/oci-image-labels-source-provenance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oci-image-labels-source-provenance</guid>
      <pubDate>Thu, 07 May 2026 20:47:41 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Scanning a Website for Vulnerabilities, Step by Step]]></title>
      <description><![CDATA[A practical walkthrough of how to scan a website for vulnerabilities — from picking a scan target and authentication mode to reading the results without drowning in false positives.]]></description>
      <link>https://safeguard.sh/resources/blog/scanning-a-website-for-vulnerabilities-step-by-step</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scanning-a-website-for-vulnerabilities-step-by-step</guid>
      <pubDate>Thu, 07 May 2026 19:27:14 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[VAPT Meaning: What Vulnerability Assessment and Penetration Testing Actually Covers]]></title>
      <description><![CDATA[VAPT stands for Vulnerability Assessment and Penetration Testing — two different security exercises that get bundled into one acronym. Here is what each half does and when you need which.]]></description>
      <link>https://safeguard.sh/resources/blog/vapt-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vapt-meaning</guid>
      <pubDate>Thu, 07 May 2026 18:06:47 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes SecurityContext, Field by Field]]></title>
      <description><![CDATA[SecurityContext in Kubernetes is where pod and container hardening actually lives — here's what each field controls and which defaults you should never leave in place.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-securitycontext-field-by-field</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-securitycontext-field-by-field</guid>
      <pubDate>Thu, 07 May 2026 16:46:20 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[CISA's CI Fortify (May 2026): Planning Critical Infrastructure for Cyber Isolation and Recovery]]></title>
      <description><![CDATA[On May 5, 2026, CISA launched CI Fortify, pushing critical infrastructure operators to plan for cyberattacks that sever their connections to the internet and telecom during a geopolitical crisis. We unpack the isolation and recovery objectives and what they demand of software supply chains.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-ci-fortify-critical-infrastructure-crisis-planning-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-ci-fortify-critical-infrastructure-crisis-planning-may-2026</guid>
      <pubDate>Thu, 07 May 2026 16:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[When DNSSEC Goes Wrong: The .de TLD Signing Failure That Took Down German Domains (May 5, 2026)]]></title>
      <description><![CDATA[On May 5, 2026, DENIC published unvalidatable DNSSEC signatures for the .de zone after a deployment defect made its signer generate three key pairs instead of one. Validating resolvers worldwide, including Cloudflare's 1.1.1.1, were forced to return SERVFAIL.]]></description>
      <link>https://safeguard.sh/resources/blog/de-tld-dnssec-outage-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/de-tld-dnssec-outage-may-2026</guid>
      <pubDate>Thu, 07 May 2026 16:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE Meaning: What a CVE ID Actually Tells You]]></title>
      <description><![CDATA[The CVE meaning is simple: it is a unique public identifier for one specific security vulnerability. Understanding how CVEs are assigned changes how you triage them.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-meaning</guid>
      <pubDate>Thu, 07 May 2026 15:25:54 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[FTC Safeguards Rule: The 30-Day Notification Window in Effect]]></title>
      <description><![CDATA[Since May 13, 2024, non-banking financial institutions must notify the FTC within 30 days of a notification event affecting 500 or more consumers.]]></description>
      <link>https://safeguard.sh/resources/blog/ftc-safeguards-rule-notification-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ftc-safeguards-rule-notification-2024</guid>
      <pubDate>Thu, 07 May 2026 14:05:27 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[AI SBOMs and Model Cards: Building Transparency Into the AI Supply Chain]]></title>
      <description><![CDATA[As AI models become critical software components, the need for AI-specific SBOMs and model cards grows urgent. How the industry is extending supply chain transparency to machine learning pipelines.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-sbom-model-cards-transparency-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-sbom-model-cards-transparency-2025</guid>
      <pubDate>Thu, 07 May 2026 12:45:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Serialization vs. Deserialization in Java: Security Implications]]></title>
      <description><![CDATA[The difference between serialization and deserialization in Java is simple to state and dangerous to get wrong — deserialization of untrusted data has caused some of the highest-severity Java CVEs of the last decade.]]></description>
      <link>https://safeguard.sh/resources/blog/serialization-vs-deserialization-in-java-security-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/serialization-vs-deserialization-in-java-security-implications</guid>
      <pubDate>Thu, 07 May 2026 11:24:34 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Docker Container Security: A Hardening Checklist]]></title>
      <description><![CDATA[Most container breaches trace back to a handful of avoidable mistakes — root users, bloated images, exposed sockets, unscanned dependencies. This checklist closes them, image to runtime.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-container-security-hardening-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-container-security-hardening-checklist</guid>
      <pubDate>Thu, 07 May 2026 10:04:07 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CMMC compliance for software vendors]]></title>
      <description><![CDATA[CMMC 2.0 is now contractually mandatory across the DoD supply chain. Here's what software vendors must know about levels, deadlines, costs, and SBOMs.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-compliance-for-software-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-compliance-for-software-vendors</guid>
      <pubDate>Thu, 07 May 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-0300 in Palo Alto PAN-OS: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[PAN-OS Captive Portal pre-auth RCE scored CVSS 9.3 and landed on CISA KEV with a three-day patch deadline. Defender playbook below.]]></description>
      <link>https://safeguard.sh/resources/blog/pan-os-cve-2026-0300-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pan-os-cve-2026-0300-patch-response</guid>
      <pubDate>Thu, 07 May 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Minimum release age / cooldown policies for new package v...]]></title>
      <description><![CDATA[A cooldown on new npm package versions can block malicious releases before they reach your build. Here's how minimum release age policies work.]]></description>
      <link>https://safeguard.sh/resources/blog/minimum-release-age-cooldown-policies-for-new-package-versions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/minimum-release-age-cooldown-policies-for-new-package-versions</guid>
      <pubDate>Thu, 07 May 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Multi-Tenant SaaS Data Isolation: Patterns and Failure Modes]]></title>
      <description><![CDATA[Every multi-tenant breach story ends the same way: one tenant reading another tenant's data. The isolation patterns that prevent it, the failure modes that cause it, and how to test which side you're on.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-tenant-saas-data-isolation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-tenant-saas-data-isolation</guid>
      <pubDate>Thu, 07 May 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Make an npm Package: A Step-by-Step Guide]]></title>
      <description><![CDATA[Learning how to make an npm package takes about ten minutes of setup and a lifetime of not shipping your .env file. This guide covers the full path from init to publish, safely.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-make-an-npm-package</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-make-an-npm-package</guid>
      <pubDate>Thu, 07 May 2026 08:43:40 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The dataloader npm Package: Security Review and Safe Usage]]></title>
      <description><![CDATA[The dataloader npm package batches and caches data fetches, most often in GraphQL servers. Its security story is less about CVEs and more about cache scoping and how you use it.]]></description>
      <link>https://safeguard.sh/resources/blog/dataloader-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dataloader-npm</guid>
      <pubDate>Thu, 07 May 2026 07:23:14 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Board-level reporting on application security risk]]></title>
      <description><![CDATA[Boards now face legal disclosure deadlines on cyber risk. Here's what belongs in a board-level appsec report, how often to deliver it, and what the SEC and NYDFS require.]]></description>
      <link>https://safeguard.sh/resources/blog/board-level-reporting-on-application-security-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/board-level-reporting-on-application-security-risk</guid>
      <pubDate>Thu, 07 May 2026 07:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-1370: How a json-smart Recursion Bug Crashes Java Apps]]></title>
      <description><![CDATA[CVE-2023-1370 lets an attacker crash any Java service that parses untrusted JSON with json-smart, using deeply nested arrays to exhaust the stack. Here is the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-1370</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-1370</guid>
      <pubDate>Thu, 07 May 2026 06:02:47 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Pull-request-level dependency scanning on GitHub]]></title>
      <description><![CDATA[Socket.dev popularized flagging risky dependencies inside GitHub pull requests. Here's how that scanning works, where it falls short, and what closes the gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/pull-request-level-dependency-scanning-on-github</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pull-request-level-dependency-scanning-on-github</guid>
      <pubDate>Thu, 07 May 2026 06:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Snyk REST API: How the Versioned Endpoints Actually Work]]></title>
      <description><![CDATA[The Snyk REST API uses date-based versioning and a Bearer token, which trips up first-time integrators. Here is how it differs from the old v1 API and how to make your first call.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-rest-api</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-rest-api</guid>
      <pubDate>Thu, 07 May 2026 04:42:20 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Cyber insurance requirements for application security programs]]></title>
      <description><![CDATA[Cyber insurers now require SBOMs, patch SLAs, and audit trails for AppSec programs. Here's what carriers actually ask for and how to pass renewal.]]></description>
      <link>https://safeguard.sh/resources/blog/cyber-insurance-requirements-for-application-security-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyber-insurance-requirements-for-application-security-programs</guid>
      <pubDate>Thu, 07 May 2026 04:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The cors npm Package: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[The cors npm package is the standard CORS middleware for Express, and most of its danger comes from misconfiguration, not the library itself. Here is how to set it correctly.]]></description>
      <link>https://safeguard.sh/resources/blog/cors-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cors-npm</guid>
      <pubDate>Thu, 07 May 2026 03:21:54 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Security scanning for MCP servers and AI agent tool use]]></title>
      <description><![CDATA[MCP servers give AI agents direct tool access, but most ship unvetted. Here's how security scanning catches tool poisoning and rug-pull attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/security-scanning-for-mcp-servers-and-ai-agent-tool-use</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-scanning-for-mcp-servers-and-ai-agent-tool-use</guid>
      <pubDate>Thu, 07 May 2026 03:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Passport (npm): A Security Review and Safe-Usage Guide]]></title>
      <description><![CDATA[A security-focused look at the passport npm package: what it does, the session fixation CVE fixed in 0.6.0, and how to configure authentication safely.]]></description>
      <link>https://safeguard.sh/resources/blog/passport-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/passport-npm</guid>
      <pubDate>Thu, 07 May 2026 02:01:27 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Spring4Shell RCE vulnerability explained CVE-2022-22965]]></title>
      <description><![CDATA[CVE-2022-22965 (Spring4Shell) lets attackers achieve unauthenticated RCE on Spring MVC/Tomcat apps. Here's the CVSS/EPSS/KEV data, timeline, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/spring4shell-rce-vulnerability-explained-cve-2022-22965</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring4shell-rce-vulnerability-explained-cve-2022-22965</guid>
      <pubDate>Thu, 07 May 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[spring-boot-starter-security: Secure Defaults and Common Mistakes]]></title>
      <description><![CDATA[What actually happens when you add spring-boot-starter-security to your build, the defaults it turns on, and the configuration mistakes that quietly undo them.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-boot-starter-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-boot-starter-security-guide</guid>
      <pubDate>Thu, 07 May 2026 00:41:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Aikido Security alternatives: top picks compared]]></title>
      <description><![CDATA[A side-by-side look at Aikido Security alternatives, comparing Safeguard's supply chain security scope, SBOM depth, and CI/CD fit.]]></description>
      <link>https://safeguard.sh/resources/blog/aikido-security-alternatives-top-picks-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aikido-security-alternatives-top-picks-compared</guid>
      <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Security By Default: A Practical Guide]]></title>
      <description><![CDATA[Security by default means the safe path is the default path, and the insecure option takes deliberate effort to reach. Here is how to design systems that protect users before anyone configures anything.]]></description>
      <link>https://safeguard.sh/resources/blog/security-by-default</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-by-default</guid>
      <pubDate>Wed, 06 May 2026 23:20:33 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[@react-native-clipboard/clipboard: What to Know Before You Read the Clipboard]]></title>
      <description><![CDATA[The @react-native-clipboard/clipboard package is the standard clipboard API for React Native. The security work is less about the package and more about what you copy and paste.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-clipboard-clipboard</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-clipboard-clipboard</guid>
      <pubDate>Wed, 06 May 2026 22:00:07 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[crypto-browserify: Is the npm Crypto Polyfill Still Safe to Use?]]></title>
      <description><![CDATA[crypto-browserify has no known direct vulnerabilities but hasn't shipped a release in over a year. Here is how to decide whether to keep it, and how to stop bundling it when you don't need it.]]></description>
      <link>https://safeguard.sh/resources/blog/crypto-browserify</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crypto-browserify</guid>
      <pubDate>Wed, 06 May 2026 20:39:40 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Command Injection Payloads: How They Work and How to Stop Them]]></title>
      <description><![CDATA[Command injection payloads abuse applications that pass user input to a system shell. This defensive guide explains the mechanics, detection, and prevention.]]></description>
      <link>https://safeguard.sh/resources/blog/command-injection-payloads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/command-injection-payloads</guid>
      <pubDate>Wed, 06 May 2026 19:19:13 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[The OWASP Logo and Brand: What It Means and How to Use It Correctly]]></title>
      <description><![CDATA[The OWASP logo is a registered mark of a nonprofit, not a free-for-all badge. Here is what the wasp actually stands for and the rules for putting it on your site or slides.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-logo</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-logo</guid>
      <pubDate>Wed, 06 May 2026 17:58:47 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Supported Languages and Ecosystems: A Reference]]></title>
      <description><![CDATA[A practical reference for Snyk supported languages across SCA and SAST, how Snyk opensource scanning compares to Snyk Code, and what to check before assuming your stack is covered.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-supported-languages-and-ecosystems</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-supported-languages-and-ecosystems</guid>
      <pubDate>Wed, 06 May 2026 16:38:20 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CAISI's May 2026 Frontier Model Testing Agreements: Pre-Deployment Evaluation Becomes a Supply-Chain Control]]></title>
      <description><![CDATA[On May 5, 2026, NIST's CAISI signed pre-deployment evaluation agreements with Google DeepMind, Microsoft, and xAI, bringing five frontier labs into a government testing program covering cyber, bio, and chemical risk.]]></description>
      <link>https://safeguard.sh/resources/blog/caisi-frontier-model-pre-deployment-testing-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/caisi-frontier-model-pre-deployment-testing-may-2026</guid>
      <pubDate>Wed, 06 May 2026 16:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CISA's Agentic AI Secure Adoption Guide (May 2026): What It Means for Software Supply Chains]]></title>
      <description><![CDATA[On May 4, 2026, CISA and international partners published guidance on the secure adoption of agentic AI. We break down the named risks, the recommended controls, and how to operationalize them for AppSec and platform teams.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-agentic-ai-secure-adoption-guide-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-agentic-ai-secure-adoption-guide-may-2026</guid>
      <pubDate>Wed, 06 May 2026 16:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Citrix NetScaler CVE-2026-3055: The SAML Memory-Overread CitrixBleed Echo of 2026]]></title>
      <description><![CDATA[CVE-2026-3055 is an unauthenticated memory overread in NetScaler ADC/Gateway configured as a SAML IdP, CVSS 9.3, exploited since late March 2026 and drawing direct CitrixBleed comparisons. Full analysis.]]></description>
      <link>https://safeguard.sh/resources/blog/citrix-netscaler-cve-2026-3055-saml-memory-overread-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/citrix-netscaler-cve-2026-3055-saml-memory-overread-2026</guid>
      <pubDate>Wed, 06 May 2026 16:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Iran-Linked Actors Are Disrupting U.S. Water and Energy PLCs: Inside CISA/FBI Advisory AA26-097A (2026)]]></title>
      <description><![CDATA[A joint FBI, CISA, NSA, EPA, DOE and Cyber Command advisory (AA26-097A, April 2026) warns that Iranian-affiliated actors are now causing operational disruption to internet-exposed PLCs across U.S. water, energy, and government facilities. Through May 2026 it is the defining OT threat. We unpack the campaign and the defense.]]></description>
      <link>https://safeguard.sh/resources/blog/iranian-plc-attacks-water-energy-aa26-097a-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iranian-plc-attacks-water-energy-aa26-097a-may-2026</guid>
      <pubDate>Wed, 06 May 2026 16:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[When the Vulnerability Is the Design: MCP STDIO Command Injection Across 150M Downloads (May 2026)]]></title>
      <description><![CDATA[OX Security documented command injection through the MCP STDIO transport across Python, TypeScript, Java, and Rust SDKs. Anthropic calls the behavior by-design and won't patch upstream. That leaves the fix to thousands of downstream projects.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-stdio-command-injection-by-design-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-stdio-command-injection-by-design-may-2026</guid>
      <pubDate>Wed, 06 May 2026 16:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Is the Sharp npm Package Safe? A Security Review]]></title>
      <description><![CDATA[A security review of the sharp npm image-processing library: its native dependency risk, the libwebp CVE that hit it, and how to run npm sharp safely.]]></description>
      <link>https://safeguard.sh/resources/blog/sharp-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sharp-npm</guid>
      <pubDate>Wed, 06 May 2026 15:17:53 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[AI Security Providers: How to Choose the Right One in 2026]]></title>
      <description><![CDATA[AI security providers fall into a few distinct categories, and picking the right one starts with knowing which risk you are actually trying to cover. This guide breaks down the landscape.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-providers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-providers</guid>
      <pubDate>Wed, 06 May 2026 14:10:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Static Analysis: Catching Bugs Before They Ship]]></title>
      <description><![CDATA[JavaScript static analysis reads your code without running it to find bugs, security flaws, and risky patterns early. Here is what it can and cannot catch, and how to set it up well.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-static-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-static-analysis</guid>
      <pubDate>Wed, 06 May 2026 13:57:27 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CORS Headers Explained: How to Configure Them Without Opening Holes]]></title>
      <description><![CDATA[CORS headers tell a browser which cross-origin requests to a resource are allowed. Get them right and you enable legitimate clients; get them wrong and you hand attackers a door.]]></description>
      <link>https://safeguard.sh/resources/blog/cors-headers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cors-headers</guid>
      <pubDate>Wed, 06 May 2026 12:37:00 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[EO 14144 to EO 14306: How the Federal Software Mandate Evolved]]></title>
      <description><![CDATA[EO 14144 set ambitious supply chain rules for federal software in January 2025. EO 14306 in June reshaped them. Here is what survived, what changed, and what to plan for.]]></description>
      <link>https://safeguard.sh/resources/blog/eo-14144-supply-chain-followup-actions-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eo-14144-supply-chain-followup-actions-2026</guid>
      <pubDate>Wed, 06 May 2026 12:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NIS2 in the Netherlands: Cyberbeveiligingswet Adoption in April 2026]]></title>
      <description><![CDATA[The Dutch Parliament approved the Cyberbeveiligingswet on 15 April 2026, with target entry into force on 1 July 2026 — 21 months after the EU transposition deadline.]]></description>
      <link>https://safeguard.sh/resources/blog/nis2-netherlands-cyberbeveiligingswet-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nis2-netherlands-cyberbeveiligingswet-2026</guid>
      <pubDate>Wed, 06 May 2026 12:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[NYDFS Part 500: The November 2025 Deadlines, One Year On]]></title>
      <description><![CDATA[The Second Amendment to NYDFS Part 500 added universal MFA and an asset inventory mandate on November 1, 2025. The April 2026 certification reveals where covered entities stand.]]></description>
      <link>https://safeguard.sh/resources/blog/nydfs-part-500-2025-amendment-deadlines</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nydfs-part-500-2025-amendment-deadlines</guid>
      <pubDate>Wed, 06 May 2026 12:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[AI Information Security: How to Protect Data in AI Systems]]></title>
      <description><![CDATA[AI information security is the practice of protecting the data that flows through AI systems, training sets, prompts, outputs, and the models themselves, from disclosure, poisoning, and misuse. Here is a working model of the risks and controls.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-information-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-information-security</guid>
      <pubDate>Wed, 06 May 2026 11:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Taint Analysis vs Reachability: What You Actually Need in 2026]]></title>
      <description><![CDATA[Taint and reachability sound similar and answer different questions. Here is when each one matters, where vendors blur the line, and how to use both.]]></description>
      <link>https://safeguard.sh/resources/blog/taint-analysis-vs-reachability-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/taint-analysis-vs-reachability-2026</guid>
      <pubDate>Wed, 06 May 2026 11:30:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Security in 2026: CVEs and Hardening Priorities]]></title>
      <description><![CDATA[The CVEs that hurt clusters lately live at the edges: admission controllers, ingress, and image supply chains. What the recent record says about where to harden first.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-security-2026-cves-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-security-2026-cves-hardening</guid>
      <pubDate>Wed, 06 May 2026 11:20:00 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[adm-zip npm Security: Zip Slip Risks and Safe Extraction]]></title>
      <description><![CDATA[adm-zip is a popular pure-JavaScript zip library for Node.js, and its history of path-traversal flaws makes safe extraction non-optional. Here is what went wrong and how to use it correctly.]]></description>
      <link>https://safeguard.sh/resources/blog/adm-zip-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/adm-zip-npm</guid>
      <pubDate>Wed, 06 May 2026 11:16:33 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Data Exfiltration via LLM Agents in 2026]]></title>
      <description><![CDATA[Tool-using agents have become a viable exfiltration channel. The patterns showing up in incident reports, and the controls that contain them.]]></description>
      <link>https://safeguard.sh/resources/blog/data-exfiltration-via-llm-agents-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/data-exfiltration-via-llm-agents-2026</guid>
      <pubDate>Wed, 06 May 2026 11:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[AI Endpoint Security: How Machine Learning Changes Endpoint Defense]]></title>
      <description><![CDATA[AI endpoint security uses machine learning to detect threats by behavior rather than signatures. Here is what it actually does, where it helps, and its limits.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-endpoint-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-endpoint-security</guid>
      <pubDate>Wed, 06 May 2026 10:45:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Argo CD Image Updater Security Considerations in 2026]]></title>
      <description><![CDATA[How Argo CD Image Updater works, the security tradeoffs of automated image promotion, and the configuration patterns that prevent supply chain incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/argocd-image-updater-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/argocd-image-updater-security-2026</guid>
      <pubDate>Wed, 06 May 2026 10:30:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[AI Cybersecurity Tools and Solutions: The 2026 Landscape]]></title>
      <description><![CDATA[AI cybersecurity tools in 2026 split into three real categories — AI-augmented detection, AI-specific application security, and autonomous response — and most vendors only actually cover one.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-cybersecurity-tools-and-solutions-landscape-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-cybersecurity-tools-and-solutions-landscape-2026</guid>
      <pubDate>Wed, 06 May 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Azure DevOps Pipeline Supply Chain Hardening 2026]]></title>
      <description><![CDATA[A 2026 hardening guide for Azure DevOps Pipelines: service connections, workload identity federation, approval gates, agent isolation, and SLSA integration.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-devops-pipeline-supply-chain-hardening-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-devops-pipeline-supply-chain-hardening-2026</guid>
      <pubDate>Wed, 06 May 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Text4Shell RCE in Apache Commons Text CVE-2022-42889]]></title>
      <description><![CDATA[CVE-2022-42889 (Text4Shell) is a 9.8-severity RCE in Apache Commons Text 1.5-1.9. Learn affected versions, timeline, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/text4shell-rce-in-apache-commons-text-cve-2022-42889</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/text4shell-rce-in-apache-commons-text-cve-2022-42889</guid>
      <pubDate>Wed, 06 May 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Gartner DAST: How Analysts Frame Dynamic Application Security Testing]]></title>
      <description><![CDATA[Gartner does not publish a standalone DAST ranking; it covers dynamic testing inside its broader application security testing research. Here is how analysts categorize DAST and what to take from it.]]></description>
      <link>https://safeguard.sh/resources/blog/gartner-dast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gartner-dast</guid>
      <pubDate>Wed, 06 May 2026 09:56:07 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AI Code Security Solutions: What to Evaluate Before Buying]]></title>
      <description><![CDATA[AI code security solutions range from AI-assisted scanning to AI-generated fixes — here's what to actually test before trusting one with your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-code-security-solutions-what-to-evaluate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-code-security-solutions-what-to-evaluate</guid>
      <pubDate>Wed, 06 May 2026 09:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx vs WhiteSource (Mend) Buyer Comparison 2026]]></title>
      <description><![CDATA[A 2026 head-to-head buyer comparison of Checkmarx and Mend (formerly WhiteSource): SCA depth, SAST, reachability, AI features, pricing, and decision framework.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-vs-whitesource-mend-buyer-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-vs-whitesource-mend-buyer-comparison-2026</guid>
      <pubDate>Wed, 06 May 2026 09:15:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SonarQube SCA Capability Review 2026]]></title>
      <description><![CDATA[A working review of SonarQube's SCA capability in 2026, comparing it against dedicated SCA tools on coverage, reachability, policy depth, and developer experience.]]></description>
      <link>https://safeguard.sh/resources/blog/sonarqube-sca-capability-review-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonarqube-sca-capability-review-2026</guid>
      <pubDate>Wed, 06 May 2026 09:15:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is an AI Accelerator, and What Are Its Security Risks?]]></title>
      <description><![CDATA[An AI accelerator is hardware built to speed up machine learning math. Once you offload models onto one, the security work shifts to the software and data around it.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-accelerator</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-accelerator</guid>
      <pubDate>Wed, 06 May 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard vs Aikido Security: which is the better fit?]]></title>
      <description><![CDATA[Safeguard vs Aikido Security compared on product scope, SBOM depth, pipeline enforcement, and compliance, so you can pick the platform that fits your risk.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-vs-aikido-security-which-is-the-better-fit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-vs-aikido-security-which-is-the-better-fit</guid>
      <pubDate>Wed, 06 May 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Threat and Vulnerability Management: Building the Program]]></title>
      <description><![CDATA[How to actually build a threat and vulnerability management program, from asset inventory to closed-loop remediation, rather than buying a scanner and calling it done.]]></description>
      <link>https://safeguard.sh/resources/blog/threat-and-vulnerability-management-program-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/threat-and-vulnerability-management-program-guide</guid>
      <pubDate>Wed, 06 May 2026 09:00:00 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[PHP Docker: How to Build a Secure PHP Docker Image]]></title>
      <description><![CDATA[A secure PHP Docker setup starts with a supported base tag, a slim image, a non-root user, and a scanned dependency tree. Here is how to get all four.]]></description>
      <link>https://safeguard.sh/resources/blog/php-docker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-docker</guid>
      <pubDate>Wed, 06 May 2026 08:35:40 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Best Secrets Detection Tools Compared 2026]]></title>
      <description><![CDATA[Gitleaks, TruffleHog, detect-secrets, and GitHub push protection, tested against a repo seeded with 60 real-format secrets. Verification is the feature that matters.]]></description>
      <link>https://safeguard.sh/resources/blog/best-secrets-detection-tools-compared-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-secrets-detection-tools-compared-2026</guid>
      <pubDate>Wed, 06 May 2026 08:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Tomas Lindgren)</author>
    </item>
    <item>
      <title><![CDATA[Application Fuzzing Explained: Finding Bugs Before Attackers Do]]></title>
      <description><![CDATA[Application fuzzing throws malformed and unexpected input at your code to surface crashes, memory errors, and logic flaws automatically. Here is how it works and how to run it.]]></description>
      <link>https://safeguard.sh/resources/blog/application-fuzzing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-fuzzing</guid>
      <pubDate>Wed, 06 May 2026 07:15:13 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Log4Shell remediation cheat sheet]]></title>
      <description><![CDATA[A practical, no-fluff Log4Shell remediation cheat sheet: affected versions, CVSS/EPSS/KEV context, timeline, and the exact steps to close CVE-2021-44228.]]></description>
      <link>https://safeguard.sh/resources/blog/log4shell-remediation-cheat-sheet</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4shell-remediation-cheat-sheet</guid>
      <pubDate>Wed, 06 May 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Aikido vs Snyk: feature and pricing comparison]]></title>
      <description><![CDATA[Aikido vs Snyk comparisons usually focus on code scanning. Here is what that framing misses, and where Safeguard fits for buyers evaluating both platforms.]]></description>
      <link>https://safeguard.sh/resources/blog/aikido-vs-snyk-feature-and-pricing-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aikido-vs-snyk-feature-and-pricing-comparison</guid>
      <pubDate>Wed, 06 May 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software License Examples and Why They Matter for Security]]></title>
      <description><![CDATA[A software license example is more than boilerplate — it defines your obligations and your risk. Here is how to read common licenses and enforce them at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/software-license-example</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-license-example</guid>
      <pubDate>Wed, 06 May 2026 05:54:46 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Interpolation in Angular: How It Works and Where the XSS Risks Hide]]></title>
      <description><![CDATA[Interpolation in Angular binds component data into templates and is safe by default because Angular escapes it. The danger starts when you reach for bypasses.]]></description>
      <link>https://safeguard.sh/resources/blog/interpolation-in-angular</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/interpolation-in-angular</guid>
      <pubDate>Wed, 06 May 2026 04:34:20 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[HTTP/2 Rapid Reset zero-day vulnerability CVE-2023-44487]]></title>
      <description><![CDATA[CVE-2023-44487 "HTTP/2 Rapid Reset" enabled record-breaking DDoS attacks via stream-reset abuse. Impact, affected stacks, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/http2-rapid-reset-zero-day-vulnerability-cve-2023-44487</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/http2-rapid-reset-zero-day-vulnerability-cve-2023-44487</guid>
      <pubDate>Wed, 06 May 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[GPL Software: A Security and Compliance Guide]]></title>
      <description><![CDATA[GPL software is free to use and modify, but its copyleft terms create real obligations. Here is what engineering teams need to track.]]></description>
      <link>https://safeguard.sh/resources/blog/gpl-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gpl-software</guid>
      <pubDate>Wed, 06 May 2026 03:13:53 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Aikido vs Wiz Code: which AppSec platform wins?]]></title>
      <description><![CDATA[Aikido and Wiz Code promise all-in-one AppSec coverage. Here's how Safeguard compares on SBOMs, build provenance, and policy enforcement -- no invented claims.]]></description>
      <link>https://safeguard.sh/resources/blog/aikido-vs-wiz-code-which-appsec-platform-wins</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aikido-vs-wiz-code-which-appsec-platform-wins</guid>
      <pubDate>Wed, 06 May 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Assessment as a Service: What It Is and When You Need It]]></title>
      <description><![CDATA[How vulnerability assessment as a service works, what it covers, and how to tell whether a managed scanning service fits your team better than in-house tooling.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-assessment-as-a-service</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-assessment-as-a-service</guid>
      <pubDate>Wed, 06 May 2026 01:53:26 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Unsafe deserialization in SnakeYAML CVE-2022-1471]]></title>
      <description><![CDATA[CVE-2022-1471 lets attackers achieve RCE via SnakeYAML's unsafe Constructor. Learn affected versions, CVSS/EPSS context, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/unsafe-deserialization-in-snakeyaml-cve-2022-1471</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unsafe-deserialization-in-snakeyaml-cve-2022-1471</guid>
      <pubDate>Wed, 06 May 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection for Beginners: How It Works and How to Stop It]]></title>
      <description><![CDATA[SQL injection for beginners, explained without the hype: what the attack actually is, why string-built queries cause it, and the one habit — parameterized queries — that closes the door.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-for-beginners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-for-beginners</guid>
      <pubDate>Wed, 06 May 2026 00:33:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Aikido vs Socket: supply chain security comparison]]></title>
      <description><![CDATA[Aikido bundles SAST/DAST/SCA into one ASPM platform; Socket digs into package behavior. Here's where Safeguard's provenance-first approach fits between them.]]></description>
      <link>https://safeguard.sh/resources/blog/aikido-vs-socket-supply-chain-security-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aikido-vs-socket-supply-chain-security-comparison</guid>
      <pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Is jQuery Validate Safe? Security Risks and Fixes for the Validation Plugin]]></title>
      <description><![CDATA[jQuery Validate is convenient, but a real XSS flaw and the habit of grabbing minified copies off random CDNs make it worth a security look. Here is what to check.]]></description>
      <link>https://safeguard.sh/resources/blog/jquery-validate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jquery-validate</guid>
      <pubDate>Tue, 05 May 2026 23:12:33 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-3509: The protobuf-java DoS Vulnerability Explained]]></title>
      <description><![CDATA[CVE-2022-3509 is a denial-of-service flaw in protobuf-java's text-format parser that lets crafted input trigger long garbage-collection pauses. Here is who is affected and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-3509</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-3509</guid>
      <pubDate>Tue, 05 May 2026 21:52:06 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Bun vs Node: A Practical Comparison for 2025]]></title>
      <description><![CDATA[Choosing between Bun vs Node comes down to speed, compatibility, and how much you value a mature ecosystem. Here is an honest breakdown, with Deno in the mix.]]></description>
      <link>https://safeguard.sh/resources/blog/bun-vs-node</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bun-vs-node</guid>
      <pubDate>Tue, 05 May 2026 20:31:40 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Can You Use Apache License 2.0 in Commercial Products?]]></title>
      <description><![CDATA[The Apache License 2.0 permits commercial use, modification, and distribution without royalties. The catch is a short list of obligations around notices and patents that you have to honor.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-license-version-2-0-commercial-use</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-license-version-2-0-commercial-use</guid>
      <pubDate>Tue, 05 May 2026 19:11:13 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Snyk SBOM Generation: How It Works]]></title>
      <description><![CDATA[How Snyk builds a software bill of materials from a dependency scan, what formats it exports, and where teams still need to fill gaps manually.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-sbom-generation-how-it-works</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-sbom-generation-how-it-works</guid>
      <pubDate>Tue, 05 May 2026 17:50:46 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[npm crypto-js: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[The npm crypto-js library is widely used but has a documented cryptographic weakness before 4.2.0. Here is what to check and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-crypto-js</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-crypto-js</guid>
      <pubDate>Tue, 05 May 2026 16:30:20 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What Is a CSRF Attack? Detection and Prevention Guide]]></title>
      <description><![CDATA[A CSRF attack tricks a logged-in user's browser into sending forged requests. Here is how the attack works and how to shut it down with modern defenses.]]></description>
      <link>https://safeguard.sh/resources/blog/csrf-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/csrf-attack</guid>
      <pubDate>Tue, 05 May 2026 15:09:53 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[AWS Permission Boundary: How to Cap IAM Privileges Safely]]></title>
      <description><![CDATA[An AWS permission boundary sets the maximum permissions an IAM identity can ever have. Here is how boundaries work, when to use them, and the mistakes that quietly defeat them.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-permission-boundary</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-permission-boundary</guid>
      <pubDate>Tue, 05 May 2026 13:49:26 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Security Testing in the Software Development Lifecycle]]></title>
      <description><![CDATA[Security testing for software development only works when it's distributed across the SDLC, not bolted on as a single pre-release gate — here's where each test type actually belongs.]]></description>
      <link>https://safeguard.sh/resources/blog/security-testing-in-the-software-development-lifecycle</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-testing-in-the-software-development-lifecycle</guid>
      <pubDate>Tue, 05 May 2026 12:28:59 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[JFrog Xray vs Prisma Cloud: A 2026 Comparison]]></title>
      <description><![CDATA[Where JFrog Xray and Prisma Cloud actually compete, where they don't, and how to pick between them for software supply chain and runtime security in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/artifactory-xray-vs-prisma-cloud-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/artifactory-xray-vs-prisma-cloud-2026</guid>
      <pubDate>Tue, 05 May 2026 11:30:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Nuxt Security: Hardening Your Nuxt App Against Real Threats]]></title>
      <description><![CDATA[A practical Nuxt security guide covering the nuxt-security module, Content Security Policy with SSR nonces, server-route risks, and dependency hygiene.]]></description>
      <link>https://safeguard.sh/resources/blog/nuxt-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuxt-security</guid>
      <pubDate>Tue, 05 May 2026 11:08:33 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How to Secure the Public Cloud: A Practical Guide]]></title>
      <description><![CDATA[The public cloud can be secured well, and often more securely than a self-run data center. The catch is the shared responsibility model, where most breaches actually originate.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-public-cloud</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-public-cloud</guid>
      <pubDate>Tue, 05 May 2026 09:48:06 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Aikido vs GitGuardian: secrets scanning comparison]]></title>
      <description><![CDATA[Searching "Aikido vs GitGuardian"? Here's how Safeguard's secrets detection, validation, and remediation approach actually compares to Aikido Security.]]></description>
      <link>https://safeguard.sh/resources/blog/aikido-vs-gitguardian-secrets-scanning-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aikido-vs-gitguardian-secrets-scanning-comparison</guid>
      <pubDate>Tue, 05 May 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Encryption Algorithms in Java: A Practical Overview]]></title>
      <description><![CDATA[Java ships a wide menu of encryption algorithms through its Java Cryptography Architecture, but picking the wrong mode or a deprecated cipher is one of the most common security findings in Java codebases.]]></description>
      <link>https://safeguard.sh/resources/blog/encryption-algorithms-in-java-a-practical-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/encryption-algorithms-in-java-a-practical-overview</guid>
      <pubDate>Tue, 05 May 2026 08:27:39 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm react-scripts: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[react-scripts powers Create React App, but CRA is now deprecated and react-scripts carries a stack of aging transitive dependencies. Here is how to handle it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-react-scripts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-react-scripts</guid>
      <pubDate>Tue, 05 May 2026 07:07:13 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The XZ backdoor CVE-2024-3094 deep dive]]></title>
      <description><![CDATA[A technical deep dive into CVE-2024-3094, the XZ Utils/liblzma SSH backdoor: affected versions, severity context, full timeline, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/the-xz-backdoor-cve-2024-3094-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-xz-backdoor-cve-2024-3094-deep-dive</guid>
      <pubDate>Tue, 05 May 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Aikido vs Gitleaks: is a maintained alternative worth it?]]></title>
      <description><![CDATA[Gitleaks catches secrets; Aikido aggregates scanners. Neither maps exposures to supply chain risk the way a dedicated platform like Safeguard does.]]></description>
      <link>https://safeguard.sh/resources/blog/aikido-vs-gitleaks-is-a-maintained-alternative-worth-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aikido-vs-gitleaks-is-a-maintained-alternative-worth-it</guid>
      <pubDate>Tue, 05 May 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Serverless Offline: What It Is and How to Use It Securely]]></title>
      <description><![CDATA[A guide to the serverless-offline npm plugin: what it emulates, where it diverges from real Lambda, and the security gaps to watch when running functions locally.]]></description>
      <link>https://safeguard.sh/resources/blog/serverless-offline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/serverless-offline</guid>
      <pubDate>Tue, 05 May 2026 05:46:46 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What is Typo-Squatting Detection]]></title>
      <description><![CDATA[Typo-squatting detection identifies malicious packages named one keystroke away from real ones — requets instead of requests — before they reach your build.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-typo-squatting-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-typo-squatting-detection</guid>
      <pubDate>Tue, 05 May 2026 04:26:19 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Jonas Meyer)</author>
    </item>
    <item>
      <title><![CDATA[regreSSHion OpenSSH RCE vulnerability CVE-2024-6387]]></title>
      <description><![CDATA[CVE-2024-6387 "regreSSHion" is a signal handler race condition in OpenSSH's sshd enabling unauthenticated root RCE on glibc-based Linux systems.]]></description>
      <link>https://safeguard.sh/resources/blog/regresshion-openssh-rce-vulnerability-cve-2024-6387</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/regresshion-openssh-rce-vulnerability-cve-2024-6387</guid>
      <pubDate>Tue, 05 May 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Safeguard Auto-Fix Actually Works Under the Hood]]></title>
      <description><![CDATA[A technical breakdown of Safeguard's automated vulnerability remediation engine, from dependency resolution to pull request generation and compatibility verification.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-auto-fix-how-it-works</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-auto-fix-how-it-works</guid>
      <pubDate>Tue, 05 May 2026 03:05:53 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Aikido vs Tenable Nessus: vulnerability scanning comparison]]></title>
      <description><![CDATA[People searching "aikido vs tenable nessus" are really asking which vulnerability scanner fits their stack. Here's how Safeguard's supply chain approach compares.]]></description>
      <link>https://safeguard.sh/resources/blog/aikido-vs-tenable-nessus-vulnerability-scanning-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aikido-vs-tenable-nessus-vulnerability-scanning-comparison</guid>
      <pubDate>Tue, 05 May 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Docker Node Alpine: When to Use the Slim Image]]></title>
      <description><![CDATA[Node Alpine Docker images cut attack surface and pull times dramatically, but musl libc compatibility gaps mean they're not a drop-in replacement for every Node project.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-node-alpine-when-to-use-the-slim-image</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-node-alpine-when-to-use-the-slim-image</guid>
      <pubDate>Tue, 05 May 2026 01:45:26 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Terrapin SSH protocol downgrade attack explained]]></title>
      <description><![CDATA[Terrapin (CVE-2023-48795) lets an on-path attacker silently strip packets from SSH handshakes. Here's how the downgrade works and how to check exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/terrapin-ssh-protocol-downgrade-attack-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/terrapin-ssh-protocol-downgrade-attack-explained</guid>
      <pubDate>Tue, 05 May 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[React Bootstrap Icons: Adding Icons Without Adding Risk]]></title>
      <description><![CDATA[React Bootstrap Icons is a convenient SVG icon set for React apps. Here is how to use it and how to keep the dependency from becoming a supply-chain liability.]]></description>
      <link>https://safeguard.sh/resources/blog/react-bootstrap-icons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-bootstrap-icons</guid>
      <pubDate>Tue, 05 May 2026 00:24:59 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Aikido vs Koi: device/browser protection comparison]]></title>
      <description><![CDATA[Aikido Security and Koi Security solve different layers of risk. Heres how they compare on device/browser protection, and where Safeguard fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/aikido-vs-koi-devicebrowser-protection-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aikido-vs-koi-devicebrowser-protection-comparison</guid>
      <pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[react-signature-canvas: A Security and Maintenance Review]]></title>
      <description><![CDATA[A security review of react-signature-canvas: what the component does, its inactive maintenance status, the XSS surface to watch, and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/react-signature-canvas</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-signature-canvas</guid>
      <pubDate>Mon, 04 May 2026 23:04:33 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[react-query (TanStack Query): Package Health and Data-Fetching Safety]]></title>
      <description><![CDATA[The npm react-query package froze at v3.39.3 when the project moved to @tanstack/react-query. Here is how to tell which one you are running, and how to keep server-state caching from leaking data.]]></description>
      <link>https://safeguard.sh/resources/blog/react-query-npm-package-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-query-npm-package-guide</guid>
      <pubDate>Mon, 04 May 2026 21:44:06 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[DAST vs Pen Testing: Which One Does Your App Actually Need?]]></title>
      <description><![CDATA[DAST is automated, continuous, and scales; penetration testing is manual, creative, and deep. Here is how they differ and why serious teams run both.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-vs-pen-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-vs-pen-testing</guid>
      <pubDate>Mon, 04 May 2026 20:23:39 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Free Web Security Scanner: How They Work and What to Use]]></title>
      <description><![CDATA[A free web security scanner can find real vulnerabilities in a web app, but only if you understand what each type actually tests. Here is a practitioner's breakdown.]]></description>
      <link>https://safeguard.sh/resources/blog/free-web-security-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/free-web-security-scanner</guid>
      <pubDate>Mon, 04 May 2026 19:03:12 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CISA Secure by Design Pledge: Reading the One-Year Progress Reports]]></title>
      <description><![CDATA[The CISA Secure by Design pledge crossed its one-year mark in May 2025 with over 150 signatories. We analyze the published progress reports and where vendors are quietly falling short.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-secure-by-design-pledge-one-year-progress-reports</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-secure-by-design-pledge-one-year-progress-reports</guid>
      <pubDate>Mon, 04 May 2026 17:42:46 GMT</pubDate>
      <category>Industry</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Docker Compose: Rebuilding Images Correctly (and Catching Stale Layers)]]></title>
      <description><![CDATA[Why docker compose up sometimes runs old code, and how to rebuild images so what runs matches what you edited, including cache, stale layers, and orphaned images.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-compose-rebuild-image-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-compose-rebuild-image-guide</guid>
      <pubDate>Mon, 04 May 2026 16:22:19 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[MCPwn (CVE-2026-33032): One Missing Auth Check Turned nginx-ui's MCP Endpoint Into Unauthenticated RCE]]></title>
      <description><![CDATA[nginx-ui added MCP support and split it across two HTTP routes. One route shipped without the auth middleware. The result is a CVSS 9.8 unauthenticated takeover, actively exploited, fixed with 27 characters of code.]]></description>
      <link>https://safeguard.sh/resources/blog/nginx-ui-mcpwn-cve-2026-33032-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nginx-ui-mcpwn-cve-2026-33032-may-2026</guid>
      <pubDate>Mon, 04 May 2026 16:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Spring Boot BOM: A Security-First Guide to Version Management]]></title>
      <description><![CDATA[The Spring Boot BOM pins hundreds of transitive versions for you. Used well it closes CVEs fast; used carelessly it hides an end-of-life framework in your build.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-boot-bom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-boot-bom</guid>
      <pubDate>Mon, 04 May 2026 15:01:52 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[react-native-modal-datetime-picker: Security and Maintenance Guide]]></title>
      <description><![CDATA[The react-native-modal-datetime-picker package is popular and convenient, but its maintenance status and transitive dependencies deserve a look before you commit to it.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-modal-datetime-picker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-modal-datetime-picker</guid>
      <pubDate>Mon, 04 May 2026 13:41:26 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Unsecured API Keys: How They Leak and How to Lock Them Down]]></title>
      <description><![CDATA[Unsecured API keys are one of the most common causes of breaches, usually leaking through committed code and misconfigured storage. Here is how they get exposed and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/unsecured-api-keys</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unsecured-api-keys</guid>
      <pubDate>Mon, 04 May 2026 12:20:59 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[EU AI Act Article 73: Serious Incident Reporting from August 2026]]></title>
      <description><![CDATA[Article 73 of the AI Act requires high-risk AI providers to report serious incidents within 15 days, with shorter clocks of 2 days for critical infrastructure and 10 days for death.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-ai-act-article-73-serious-incident-reporting-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-ai-act-article-73-serious-incident-reporting-2026</guid>
      <pubDate>Mon, 04 May 2026 12:00:00 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSF Scorecard v6 and the OSPS Baseline: Turning Probe Evidence Into Registry Trust Signals]]></title>
      <description><![CDATA[The Scorecard v6 roadmap introduces conformance labels (PASS/FAIL/UNKNOWN/NOT_APPLICABLE/ATTESTED) layered over the same probe evidence, aligning Scorecard output with the OSPS Baseline for registry-side trust decisions.]]></description>
      <link>https://safeguard.sh/resources/blog/openssf-scorecard-v6-osps-baseline-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssf-scorecard-v6-osps-baseline-2026</guid>
      <pubDate>Mon, 04 May 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[OWASP ASVS 5.0 Adoption Guide]]></title>
      <description><![CDATA[OWASP ASVS 5.0 restructured the verification levels and added new requirements for modern stacks. A practical adoption guide for teams using ASVS as their security baseline.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-asvs-5-0-adoption-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-asvs-5-0-adoption-guide</guid>
      <pubDate>Mon, 04 May 2026 11:00:32 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Dependabot Alternatives in 2026: A Buyer Rubric]]></title>
      <description><![CDATA[A buyer rubric for evaluating Dependabot alternatives in 2026, covering update strategy, ecosystem coverage, reachability, and operational realities.]]></description>
      <link>https://safeguard.sh/resources/blog/dependabot-alternatives-2026-buyer-rubric</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependabot-alternatives-2026-buyer-rubric</guid>
      <pubDate>Mon, 04 May 2026 10:30:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Heartbleed OpenSSL vulnerability retrospective]]></title>
      <description><![CDATA[A decade later, Heartbleed (CVE-2014-0160) still explains why software supply chain visibility matters: severity, timeline, and remediation steps revisited.]]></description>
      <link>https://safeguard.sh/resources/blog/heartbleed-openssl-vulnerability-retrospective</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/heartbleed-openssl-vulnerability-retrospective</guid>
      <pubDate>Mon, 04 May 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[GitHub MCP Server Private-Repo Exfiltration: The May 2025 Invariant Labs Disclosure]]></title>
      <description><![CDATA[Invariant Labs showed that a malicious GitHub Issue could hijack any MCP-connected agent into leaking private-repo contents. The architecture, not a bug, is the problem.]]></description>
      <link>https://safeguard.sh/resources/blog/github-mcp-private-repo-prompt-injection-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-mcp-private-repo-prompt-injection-2025</guid>
      <pubDate>Mon, 04 May 2026 09:40:06 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Aikido vs XBOW: independent AI pentesting benchmark results]]></title>
      <description><![CDATA[There is no independently verified benchmark comparing Aikido and XBOW. Here is what each tool does and how Safeguard differs on supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/aikido-vs-xbow-independent-ai-pentesting-benchmark-results</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aikido-vs-xbow-independent-ai-pentesting-benchmark-results</guid>
      <pubDate>Mon, 04 May 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[maven-assembly-plugin: A Security Guide]]></title>
      <description><![CDATA[The maven-assembly-plugin bundles your project into distributable archives. It builds archives rather than extracting them, which shapes exactly which supply chain risks apply to it.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-assembly-plugin</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-assembly-plugin</guid>
      <pubDate>Mon, 04 May 2026 08:19:39 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Shellshock Bash vulnerability retrospective]]></title>
      <description><![CDATA[A decade-plus retrospective on Shellshock (CVE-2014-6271): how a Bash parsing flaw led to critical, KEV-listed remote code execution.]]></description>
      <link>https://safeguard.sh/resources/blog/shellshock-bash-vulnerability-retrospective</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shellshock-bash-vulnerability-retrospective</guid>
      <pubDate>Mon, 04 May 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The Threat Modeling Process, Step by Step]]></title>
      <description><![CDATA[Threat modeling answers four questions: what are we building, what can go wrong, what are we doing about it, and did we do enough? A concrete step-by-step process your team can run in an afternoon.]]></description>
      <link>https://safeguard.sh/resources/blog/threat-modeling-process-step-by-step</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/threat-modeling-process-step-by-step</guid>
      <pubDate>Mon, 04 May 2026 06:59:12 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Aikido vs Checkmarx / GitHub Advanced Security for code s...]]></title>
      <description><![CDATA[Aikido, Checkmarx, and GitHub Advanced Security all scan code. Here's how they differ from Safeguard on supply chain risk, and where each fits.]]></description>
      <link>https://safeguard.sh/resources/blog/aikido-vs-checkmarx-github-advanced-security-for-code-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aikido-vs-checkmarx-github-advanced-security-for-code-scanning</guid>
      <pubDate>Mon, 04 May 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Stored XSS: Why Persistent Injection Hurts Most]]></title>
      <description><![CDATA[Stored XSS saves the attacker's script server-side and serves it to everyone. Here is why persistent injection is the most damaging XSS variant and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/stored-xss-persistent-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/stored-xss-persistent-injection</guid>
      <pubDate>Mon, 04 May 2026 05:38:45 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security Maturity: Where Does Your Organization Stand?]]></title>
      <description><![CDATA[Most organizations know they should care about software supply chain security, but few have a structured way to assess their maturity. A practical framework for evaluating and improving your posture.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-maturity-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-maturity-assessment</guid>
      <pubDate>Mon, 04 May 2026 04:18:19 GMT</pubDate>
      <category>Frameworks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Apache Struts remote code execution CVE history]]></title>
      <description><![CDATA[A decade of Apache Struts RCEs — from Equifax's CVE-2017-5638 to 2024's file-upload bypass — traced through CVSS, EPSS, KEV, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-struts-remote-code-execution-cve-history</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-struts-remote-code-execution-cve-history</guid>
      <pubDate>Mon, 04 May 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Reducing false positives in security scanning]]></title>
      <description><![CDATA[Most security scan findings never warrant action. Here's why scanners over-alert, what it costs teams, how Aikido's consolidation approach compares, and what actually cuts false positives.]]></description>
      <link>https://safeguard.sh/resources/blog/reducing-false-positives-in-security-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reducing-false-positives-in-security-scanning</guid>
      <pubDate>Mon, 04 May 2026 03:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SSRF Vulnerability Explained: How Server-Side Request Forgery Works and How to Stop It]]></title>
      <description><![CDATA[An SSRF vulnerability lets an attacker make your server send requests on their behalf — the flaw behind the Capital One breach. Here's how it works and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/ssrf-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ssrf-vulnerability</guid>
      <pubDate>Mon, 04 May 2026 02:57:52 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Choosing Secure Node.js Docker Images]]></title>
      <description><![CDATA[How to pick Node.js Docker images that stay small and secure: comparing slim, Alpine, and distroless variants, pinning versions, and scanning for CVEs.]]></description>
      <link>https://safeguard.sh/resources/blog/node-js-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-js-images</guid>
      <pubDate>Mon, 04 May 2026 01:37:25 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CI/CD Cyber Security: Securing the Pipeline End to End]]></title>
      <description><![CDATA[Your CI/CD pipeline holds the credentials, signs the artifacts, and deploys to production. Here is how to secure it against the attacks that target the build itself.]]></description>
      <link>https://safeguard.sh/resources/blog/ci-cd-cyber-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ci-cd-cyber-security</guid>
      <pubDate>Mon, 04 May 2026 00:16:59 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Does AI pentesting satisfy SOC 2, ISO 27001, HIPAA or PCI...]]></title>
      <description><![CDATA[AI-powered pentesting promises fast compliance checkmarks, but SOC 2, ISO 27001, HIPAA, and PCI DSS 4.0 auditors require more than an automated scan report.]]></description>
      <link>https://safeguard.sh/resources/blog/does-ai-pentesting-satisfy-soc-2-iso-27001-hipaa-or-pci-dss-auditors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/does-ai-pentesting-satisfy-soc-2-iso-27001-hipaa-or-pci-dss-auditors</guid>
      <pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[API Security Software: What It Does and How to Choose It]]></title>
      <description><![CDATA[API security software protects the endpoints that carry most of your traffic and data. Here is what these tools actually do, the categories that matter, and how to choose without duplicating coverage.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-software</guid>
      <pubDate>Sun, 03 May 2026 22:56:32 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[NIST 800-171 Rev. 3 and the DoD Class Deviation: Stuck on Rev. 2]]></title>
      <description><![CDATA[NIST published 800-171 Rev. 3 on May 14, 2024. Twelve days earlier, DoD froze DFARS 7012 to Rev. 2 via Class Deviation 2024-O0013.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-sp-800-171-rev-3-class-deviation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-sp-800-171-rev-3-class-deviation</guid>
      <pubDate>Sun, 03 May 2026 21:36:05 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AWS Hack: How Attackers Break Into AWS and How to Stop Them]]></title>
      <description><![CDATA[Most AWS breaches don't start with a clever exploit. They start with a leaked key or a misconfigured bucket. Here is how an AWS hack actually unfolds and how to shut down each step.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-hack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-hack</guid>
      <pubDate>Sun, 03 May 2026 20:15:39 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Using Checkmarx for Salesforce Apex Security: A Practical Guide]]></title>
      <description><![CDATA[Checkmarx can scan Salesforce Apex and Visualforce for SOQL injection, XSS, and CRUD/FLS gaps. Here is how the pairing works and what to watch for.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-salesforce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-salesforce</guid>
      <pubDate>Sun, 03 May 2026 18:55:12 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Web Security Scan: How to Find Vulnerabilities Before Attackers Do]]></title>
      <description><![CDATA[A web security scan probes your application for exploitable flaws the way an attacker would. Here is how the main scan types work and how to run them well.]]></description>
      <link>https://safeguard.sh/resources/blog/web-security-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-security-scan</guid>
      <pubDate>Sun, 03 May 2026 17:34:45 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Is supertest npm Safe to Use? A Security Review for Node Testing]]></title>
      <description><![CDATA[A security-minded review of supertest npm, the SuperAgent-driven HTTP testing library: where it fits, what its dependency surface looks like, and how to keep test code from leaking into production risk.]]></description>
      <link>https://safeguard.sh/resources/blog/supertest-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supertest-npm</guid>
      <pubDate>Sun, 03 May 2026 16:14:19 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[When Is SCA Required? A Software Composition Analysis Guide]]></title>
      <description><![CDATA[SCA is required wherever you ship code built on open-source dependencies and need to prove which components you use and whether they carry known vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-required</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-required</guid>
      <pubDate>Sun, 03 May 2026 14:53:52 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Python Pickle Load: A Security Guide]]></title>
      <description><![CDATA[Calling python pickle load on data you do not fully control can execute arbitrary code. Here is why, and what to use instead.]]></description>
      <link>https://safeguard.sh/resources/blog/python-pickle-load</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-pickle-load</guid>
      <pubDate>Sun, 03 May 2026 13:33:25 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Python pickle.dump Explained, and Why It Can Get You Popped]]></title>
      <description><![CDATA[How Python's pickle.dump actually works, a runnable example, and the deserialization risk that turns a saved object into remote code execution.]]></description>
      <link>https://safeguard.sh/resources/blog/python-pickle-dump</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-pickle-dump</guid>
      <pubDate>Sun, 03 May 2026 12:12:58 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is PII? A Security and Compliance Guide to Personally Identifiable Information]]></title>
      <description><![CDATA[PII is any data that can identify a specific person. Here is how to classify it, where it leaks in software systems, and what regulators expect you to do about it.]]></description>
      <link>https://safeguard.sh/resources/blog/pii</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pii</guid>
      <pubDate>Sun, 03 May 2026 10:52:32 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Web Application Security Assessment: How to Actually Test Your App]]></title>
      <description><![CDATA[A web application security assessment is a structured evaluation of an app's exposure across code, dependencies, configuration, and runtime behavior. Here is how to run one that finds real issues.]]></description>
      <link>https://safeguard.sh/resources/blog/web-application-security-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-application-security-assessment</guid>
      <pubDate>Sun, 03 May 2026 09:32:05 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What is AI-native SAST vs AI-augmented SAST?]]></title>
      <description><![CDATA[AI SAST isn't one thing. Aikido bolts AI onto a rule-based Semgrep fork; AI-native tools use AI as the detection engine itself. Here's the real difference.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-ai-native-sast-vs-ai-augmented-sast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-ai-native-sast-vs-ai-augmented-sast</guid>
      <pubDate>Sun, 03 May 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Cheat Sheet: Detection and Defensive Patterns]]></title>
      <description><![CDATA[A defensive SQLi cheat sheet that shows how injection works conceptually, how to spot it in code and traffic, and the parameterization patterns that actually stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/sqli-cheat-sheet</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sqli-cheat-sheet</guid>
      <pubDate>Sun, 03 May 2026 08:11:38 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[NIST Secure Coding Standards: What They Require and How to Meet Them]]></title>
      <description><![CDATA[NIST secure coding standards are not one document but a set of practices spread across SSDF, SP 800-53, and the SAMATE guidance. Here is what each one asks of your team.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-coding-standards-nist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-coding-standards-nist</guid>
      <pubDate>Sun, 03 May 2026 06:51:12 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Why EDR and proxy tools won't stop supply chain malware]]></title>
      <description><![CDATA[EDR and network proxies were built to watch endpoints and traffic, not evaluate what a dependency does before it runs — here's why that gap keeps letting supply chain malware through.]]></description>
      <link>https://safeguard.sh/resources/blog/why-edr-and-proxy-tools-wont-stop-supply-chain-malware</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-edr-and-proxy-tools-wont-stop-supply-chain-malware</guid>
      <pubDate>Sun, 03 May 2026 06:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[NIST SP 800-218: How the Secure Software Development Framework (SSDF) Works]]></title>
      <description><![CDATA[NIST SP 800-218, the Secure Software Development Framework, gives software producers a set of outcome-based practices for building software with fewer vulnerabilities. Here is how to read and apply it.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-sp-800-218-secure-software-development-framework-ssdf</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-sp-800-218-secure-software-development-framework-ssdf</guid>
      <pubDate>Sun, 03 May 2026 05:30:45 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[The Most Common Software Vulnerabilities and How to Prevent Them]]></title>
      <description><![CDATA[The handful of common software vulnerabilities that keep showing up in real breaches, why they persist, and the concrete practices that shut each one down.]]></description>
      <link>https://safeguard.sh/resources/blog/common-software-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/common-software-vulnerabilities</guid>
      <pubDate>Sun, 03 May 2026 04:10:18 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[SBOMs in 2026: why most organizations generate them but d...]]></title>
      <description><![CDATA[SBOM generation surged ahead of 2026 compliance deadlines, but most SBOMs sit unused after release. Here's why adoption without action still leaves risk unmanaged.]]></description>
      <link>https://safeguard.sh/resources/blog/sboms-in-2026-why-most-organizations-generate-them-but-dont-use-them</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sboms-in-2026-why-most-organizations-generate-them-but-dont-use-them</guid>
      <pubDate>Sun, 03 May 2026 03:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Is the Busboy npm Package Safe? A Security Review]]></title>
      <description><![CDATA[The busboy npm package parses multipart form data in Node.js. Here is its current security status, the dicer history that once bit it, and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/busboy-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/busboy-npm</guid>
      <pubDate>Sun, 03 May 2026 02:49:52 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Is workbox-webpack-plugin Safe? A Security Guide]]></title>
      <description><![CDATA[workbox-webpack-plugin generates service workers for your PWA at build time. Here is what its security profile looks like and how to keep the caching layer it creates from becoming a liability.]]></description>
      <link>https://safeguard.sh/resources/blog/workbox-webpack-plugin</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/workbox-webpack-plugin</guid>
      <pubDate>Sun, 03 May 2026 01:29:25 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Zip Slip: archive extraction path traversal explained]]></title>
      <description><![CDATA[Zip Slip lets malicious archives write files outside their extraction folder via ../ paths — how it works, real CVEs, and how to detect and fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/zip-slip-archive-extraction-path-traversal-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zip-slip-archive-extraction-path-traversal-explained</guid>
      <pubDate>Sun, 03 May 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Vulnerability in Cyber Security? A Plain-English Guide]]></title>
      <description><![CDATA[A vulnerability in cyber security is a weakness an attacker can exploit. Here is how vulnerabilities differ from threats and risks, and how teams find and fix them.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-in-cyber-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-in-cyber-security</guid>
      <pubDate>Sun, 03 May 2026 00:08:58 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Everybody's shipping code they can't read (AI-generated c...]]></title>
      <description><![CDATA[AI coding assistants ship code fast, but studies show nearly half contains vulnerabilities, hallucinated packages, and leaked secrets nobody reviewed.]]></description>
      <link>https://safeguard.sh/resources/blog/everybodys-shipping-code-they-cant-read-ai-generated-code-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/everybodys-shipping-code-they-cant-read-ai-generated-code-risk</guid>
      <pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Terraform Definition: What It Is, in Plain English]]></title>
      <description><![CDATA[A clear Terraform definition for engineers, plus what the tool actually does, how state works, and where the security responsibilities sit.]]></description>
      <link>https://safeguard.sh/resources/blog/terraform-definition</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/terraform-definition</guid>
      <pubDate>Sat, 02 May 2026 22:48:32 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Static Code Scan: How SAST Finds Bugs Before They Ship]]></title>
      <description><![CDATA[A static code scan analyzes source without running it, catching injection, secrets, and unsafe patterns early. Here is what it can and cannot see, and how to wire one into CI.]]></description>
      <link>https://safeguard.sh/resources/blog/static-code-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-code-scan</guid>
      <pubDate>Sat, 02 May 2026 21:28:05 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Software Licensing Options Explained: A Security and Compliance Guide]]></title>
      <description><![CDATA[Your software licensing options fall into a handful of families, and each one carries obligations that show up in audits. Here is how to read a license before it reads you.]]></description>
      <link>https://safeguard.sh/resources/blog/software-licensing-options</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-licensing-options</guid>
      <pubDate>Sat, 02 May 2026 20:07:38 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Secret Scanning: How It Detects Hardcoded Secrets]]></title>
      <description><![CDATA[Snyk secret scanning finds hardcoded credentials in your code as part of Snyk Code's SAST engine and, more recently, through the dedicated Snyk Secrets product. Here is what each covers and where the gaps are.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-secret-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-secret-scanning</guid>
      <pubDate>Sat, 02 May 2026 18:47:11 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Security in Agile Development: A Practical Guide]]></title>
      <description><![CDATA[Security in agile development works when it moves at sprint speed instead of blocking releases. Here is how to embed AppSec into backlogs, PRs, and pipelines without killing velocity.]]></description>
      <link>https://safeguard.sh/resources/blog/security-in-agile-development</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-in-agile-development</guid>
      <pubDate>Sat, 02 May 2026 17:26:45 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[An SCA Tools List That Matches How You Actually Ship]]></title>
      <description><![CDATA[A candid SCA tools list for teams that need dependency and license scanning wired into CI, covering open-source scanners and commercial platforms and how to tell them apart.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-tools-list</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-tools-list</guid>
      <pubDate>Sat, 02 May 2026 16:06:18 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Nine Seconds to Total Loss: The PocketOS Agent Database Deletion and the Credential Blast-Radius Problem (May 2026)]]></title>
      <description><![CDATA[An autonomous coding agent at PocketOS found an over-scoped Railway token in an unrelated file and used it to delete the production database and its backups in nine seconds. The failure was not the model. It was the credential.]]></description>
      <link>https://safeguard.sh/resources/blog/pocketos-agent-database-deletion-credential-blast-radius-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pocketos-agent-database-deletion-credential-blast-radius-may-2026</guid>
      <pubDate>Sat, 02 May 2026 16:00:00 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Shadow-Earth-053: China-Aligned Espionage Across Asia and a NATO State (May 2026)]]></title>
      <description><![CDATA[Trend Micro's May 1, 2026 disclosure of Shadow-Earth-053 documents a China-aligned campaign exploiting N-day Exchange and IIS flaws to plant Godzilla web shells and ShadowPad across government, defense, and civil-society targets in eight-plus countries.]]></description>
      <link>https://safeguard.sh/resources/blog/shadow-earth-053-china-espionage-asia-may-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shadow-earth-053-china-espionage-asia-may-2026</guid>
      <pubDate>Sat, 02 May 2026 16:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[react-native-webview Security: Hardening WebViews in Mobile Apps]]></title>
      <description><![CDATA[The react-native-webview component gives your app a browser inside the app, and that power is exactly why it needs careful configuration to avoid opening a hole in your mobile security.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-webview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-webview</guid>
      <pubDate>Sat, 02 May 2026 14:45:51 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[react-native-app-auth: Secure OAuth and OpenID Connect for React Native]]></title>
      <description><![CDATA[react-native-app-auth bridges the native AppAuth SDKs so your React Native app gets PKCE and RFC 8252 flows for free. Here is how to wire it up safely, including Azure AD.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-app-auth</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-app-auth</guid>
      <pubDate>Sat, 02 May 2026 13:25:25 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Does Python Mock Work, and Is It a Security Risk?]]></title>
      <description><![CDATA[Python mock is part of the standard library and is safe to use, but leaning on it carelessly can hide real security behavior behind fake return values.]]></description>
      <link>https://safeguard.sh/resources/blog/python-mock</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-mock</guid>
      <pubDate>Sat, 02 May 2026 12:04:58 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Semgrep Supply Chain: April 2026 Update Reviewed]]></title>
      <description><![CDATA[Semgrep's April 2026 release added dedicated advisory pages, dependency path data in SBOM exports, a Guardian Supply Chain hook, and Maven/Gradle scanning without lockfiles.]]></description>
      <link>https://safeguard.sh/resources/blog/semgrep-supply-chain-april-2026-update</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/semgrep-supply-chain-april-2026-update</guid>
      <pubDate>Sat, 02 May 2026 11:30:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[PHP Code Check: A Security Guide]]></title>
      <description><![CDATA[A PHP code check should catch injection, unsafe deserialization, and vulnerable Composer packages before they ship. Here is a layered approach that fits a normal PHP workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/php-code-check</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-code-check</guid>
      <pubDate>Sat, 02 May 2026 10:44:31 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx Zero Trust Deployment Guide 2026]]></title>
      <description><![CDATA[A practical Checkmarx zero trust deployment guide for 2026: integrating Checkmarx One into a zero-trust SDLC with policy gates, identity, and signed artifacts.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-zero-trust-deployment-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-zero-trust-deployment-guide-2026</guid>
      <pubDate>Sat, 02 May 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to prevent log injection vulnerabilities in Java]]></title>
      <description><![CDATA[Log injection let attackers turn Log4j logging calls into remote code execution in 2021. Here's how CWE-117 works in Java and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-prevent-log-injection-vulnerabilities-in-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-prevent-log-injection-vulnerabilities-in-java</guid>
      <pubDate>Sat, 02 May 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Password Storage Best Practices Every Developer Should Follow]]></title>
      <description><![CDATA[Storing passwords safely comes down to one rule: never store the password. Here are the password storage best practices that actually hold up against modern attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/password-storage-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/password-storage-best-practices</guid>
      <pubDate>Sat, 02 May 2026 09:24:05 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Aikido Trust Center walkthrough: certifications, pentesti...]]></title>
      <description><![CDATA[A walkthrough of the Aikido Security trust center: what its SOC 2, ISO 27001, and annual pentest claims actually mean, and what's missing for a real vendor risk review.]]></description>
      <link>https://safeguard.sh/resources/blog/aikido-trust-center-walkthrough-certifications-pentesting-cadence-and-data-handling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aikido-trust-center-walkthrough-certifications-pentesting-cadence-and-data-handling</guid>
      <pubDate>Sat, 02 May 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[FOSSA vs Snyk SCA Comparison 2026]]></title>
      <description><![CDATA[Two SCA platforms with very different roots: FOSSA from license compliance, Snyk from vulnerability scanning. Which one fits which buyer profile in 2026?]]></description>
      <link>https://safeguard.sh/resources/blog/fossa-vs-snyk-sca-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fossa-vs-snyk-sca-comparison-2026</guid>
      <pubDate>Sat, 02 May 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSF Scorecard Explained: Measuring Open Source Security Health]]></title>
      <description><![CDATA[OpenSSF Scorecard scores a repository against automated security checks and gives you a 0-10 signal for how safe a dependency is to adopt. Here is how it works and how to run it.]]></description>
      <link>https://safeguard.sh/resources/blog/ossf-scorecard</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ossf-scorecard</guid>
      <pubDate>Sat, 02 May 2026 08:03:38 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[jQuery prototype pollution vulnerability re-emerges]]></title>
      <description><![CDATA[jQuery's prototype pollution flaw (CVE-2019-11358) keeps surfacing in 2026 dependency scans. Here's why it persists and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/jquery-prototype-pollution-vulnerability-re-emerges</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jquery-prototype-pollution-vulnerability-re-emerges</guid>
      <pubDate>Sat, 02 May 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Is the npm mysql Package Safe? A Security Review]]></title>
      <description><![CDATA[A security-focused look at the npm mysql driver: SQL injection risks, prepared statements, connection handling, and why most teams should move to mysql2.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-mysql</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-mysql</guid>
      <pubDate>Sat, 02 May 2026 06:43:11 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How AI pentesting works and where it fits alongside SAST/...]]></title>
      <description><![CDATA[AI pentesting explained: how autonomous agents test live apps, how it differs from SAST/DAST and Aikido's bolt-on approach, and where Safeguard fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/how-ai-pentesting-works-and-where-it-fits-alongside-sastdast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-ai-pentesting-works-and-where-it-fits-alongside-sastdast</guid>
      <pubDate>Sat, 02 May 2026 06:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Is There an Nginx 1.18.0 Exploit? What the Known CVEs Actually Mean]]></title>
      <description><![CDATA[Nginx 1.18.0 is an unmaintained stable release with real CVEs against it. Here is which flaws are genuinely exploitable, which need specific config, and how to upgrade.]]></description>
      <link>https://safeguard.sh/resources/blog/nginx-1-18-0-exploit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nginx-1-18-0-exploit</guid>
      <pubDate>Sat, 02 May 2026 05:22:45 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What Is Literal SQL Statement Injection, and How Do You Stop It?]]></title>
      <description><![CDATA[Literal SQL statement injection happens when user input is concatenated straight into a query string. Here is how the attack works and how to shut it down.]]></description>
      <link>https://safeguard.sh/resources/blog/literal-sql-statement-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/literal-sql-statement-injection</guid>
      <pubDate>Sat, 02 May 2026 04:02:18 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Lodash prototype pollution vulnerabilities explained]]></title>
      <description><![CDATA[A breakdown of lodash's prototype pollution CVEs (CVE-2018-3721, CVE-2019-10744, CVE-2020-8203), their impact, and concrete remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/lodash-prototype-pollution-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lodash-prototype-pollution-vulnerabilities-explained</guid>
      <pubDate>Sat, 02 May 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Customer story pattern: cutting false-positive noise with...]]></title>
      <description><![CDATA[How one team cut AppSec findings 92% and MTTR from 11 days to 36 hours by consolidating scanners — a reduce security tool noise false positives case study.]]></description>
      <link>https://safeguard.sh/resources/blog/customer-story-pattern-cutting-false-positive-noise-with-consolidated-appsec-tooling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/customer-story-pattern-cutting-false-positive-noise-with-consolidated-appsec-tooling</guid>
      <pubDate>Sat, 02 May 2026 03:00:00 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Writing a Secure Kubernetes Dockerfile: A Practical Hardening Guide]]></title>
      <description><![CDATA[The Dockerfile you write decides most of a pod's attack surface before Kubernetes ever schedules it. Here is how to build images that run non-root, stay small, and survive a security review.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-dockerfile</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-dockerfile</guid>
      <pubDate>Sat, 02 May 2026 02:41:51 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes CVE News: How to Track and Respond to Cluster Vulnerabilities]]></title>
      <description><![CDATA[Where Kubernetes CVE news actually breaks, how to read a cluster advisory, and a repeatable process for triaging vulnerabilities before they turn into an incident.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-cve-news</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-cve-news</guid>
      <pubDate>Sat, 02 May 2026 01:21:24 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Regular expression DoS in the ms npm package]]></title>
      <description><![CDATA[A ReDoS flaw in the ubiquitous npm package ms (CVE-2015-8315) still surfaces in dependency scans today. Here's the impact, fix, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/regular-expression-dos-in-the-ms-npm-package</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/regular-expression-dos-in-the-ms-npm-package</guid>
      <pubDate>Sat, 02 May 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Inversion of Control in JavaScript: The Security Angle Nobody Explains]]></title>
      <description><![CDATA[Inversion of control in JavaScript decouples your code from its dependencies, but handing over instantiation also hands over a piece of your attack surface. Here is how to get the design benefit without the security cost.]]></description>
      <link>https://safeguard.sh/resources/blog/inversion-of-control-in-javascript</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/inversion-of-control-in-javascript</guid>
      <pubDate>Sat, 02 May 2026 00:00:58 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What Is an IAM Permission Boundary and When to Use One]]></title>
      <description><![CDATA[An IAM permission boundary is a ceiling on what a role or user can ever do, no matter how generous their attached policies are. Here is how to wield it without locking yourself out.]]></description>
      <link>https://safeguard.sh/resources/blog/iam-permission-boundary</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iam-permission-boundary</guid>
      <pubDate>Fri, 01 May 2026 22:40:31 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Docker Hub Node.js Images: How to Pick and Harden the Right Tag]]></title>
      <description><![CDATA[The official Docker Hub Node.js images come in a dozen variants, and the tag you choose decides your image size, patch cadence, and attack surface. Here is how to read them.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-hub-nodejs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-hub-nodejs</guid>
      <pubDate>Fri, 01 May 2026 21:20:04 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is a DAST Solution? Choosing Dynamic Testing for Web Apps]]></title>
      <description><![CDATA[A DAST solution tests your running application from the outside, the way an attacker would. Here is how dynamic testing works, what it catches, and how to pick one that fits your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-solution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-solution</guid>
      <pubDate>Fri, 01 May 2026 19:59:38 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-45688: The Hutool JSON Stack Overflow, Explained]]></title>
      <description><![CDATA[CVE-2022-45688 is a stack-overflow denial-of-service bug in the XML-to-JSON conversion path of hutool-json and org.json. Here is what triggers it and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-45688</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-45688</guid>
      <pubDate>Fri, 01 May 2026 18:39:11 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-45146: Bouncy Castle FIPS Use-After-Free Explained]]></title>
      <description><![CDATA[CVE-2022-45146 is a use-after-free issue in Bouncy Castle's FIPS Java API that surfaces on Java 13 and later. Here is who it affects and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-45146</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-45146</guid>
      <pubDate>Fri, 01 May 2026 17:18:44 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is Checkmarx One? A Practical Look at the AppSec Platform]]></title>
      <description><![CDATA[Checkmarx One is Checkmarx's cloud application security platform, bundling SAST, SCA, IaC, and more into a single console. Here is what it covers and where it fits.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-one</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-one</guid>
      <pubDate>Fri, 01 May 2026 15:58:18 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Pen Testing Tools Worth Knowing in 2025]]></title>
      <description><![CDATA[The right pen testing tools depend on what you're assessing. Here's a practical map of the categories, the well-known options in each, and how they fit a defensive program.]]></description>
      <link>https://safeguard.sh/resources/blog/pen-testing-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pen-testing-tools</guid>
      <pubDate>Fri, 01 May 2026 14:37:51 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[MIT-Lizenz: Was sie erlaubt und was kommerzielle Nutzung bedeutet]]></title>
      <description><![CDATA[Die MIT-Lizenz ist eine der freizuegigsten Open-Source-Lizenzen und erlaubt auch die kommerzielle Nutzung. Wir erklaeren Pflichten, Grenzen und Risiken.]]></description>
      <link>https://safeguard.sh/resources/blog/mit-lizenz</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mit-lizenz</guid>
      <pubDate>Fri, 01 May 2026 13:17:24 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[react-native-screens: A Security Guide for React Native Apps]]></title>
      <description><![CDATA[react-native-screens is a low-level navigation dependency most developers never install directly. Here is what it does and how to think about its security in a mobile app.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-screens</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-screens</guid>
      <pubDate>Fri, 01 May 2026 11:56:57 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[ng-bootstrap: Using and Securing Angular's Bootstrap Widgets]]></title>
      <description><![CDATA[ng-bootstrap gives Angular apps native Bootstrap widgets with no jQuery dependency. Here is how to keep it current and where the real security work actually lives.]]></description>
      <link>https://safeguard.sh/resources/blog/ng-bootstrap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ng-bootstrap</guid>
      <pubDate>Fri, 01 May 2026 10:36:31 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Filesystem takeover vulnerabilities in the npm package manager]]></title>
      <description><![CDATA[How npm and node-tar "filesystem takeover" CVEs let malicious packages overwrite files via symlinks and path traversal during install.]]></description>
      <link>https://safeguard.sh/resources/blog/filesystem-takeover-vulnerabilities-in-the-npm-package-manager</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/filesystem-takeover-vulnerabilities-in-the-npm-package-manager</guid>
      <pubDate>Fri, 01 May 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Understanding DOM XSS Payloads: How They Work and How to Stop Them]]></title>
      <description><![CDATA[DOM XSS payloads execute entirely in the browser when untrusted input reaches a dangerous sink like innerHTML or eval. Here is how the class works and how to shut it down without shipping exploit code.]]></description>
      <link>https://safeguard.sh/resources/blog/dom-xss-payloads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dom-xss-payloads</guid>
      <pubDate>Fri, 01 May 2026 09:16:04 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[react-native-root-toast: A Security Guide]]></title>
      <description><![CDATA[react-native-root-toast renders toast messages above your React Native app. The security questions are about what text you show, which peer versions you pin, and how you audit the dependency.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-root-toast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-root-toast</guid>
      <pubDate>Fri, 01 May 2026 07:55:37 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE scoring inconsistencies across vulnerability databases]]></title>
      <description><![CDATA[Why the same CVE can carry three different severity scores across NVD, GitHub, and vendor advisories — and how to prioritize anyway.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-scoring-inconsistencies-across-vulnerability-databases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-scoring-inconsistencies-across-vulnerability-databases</guid>
      <pubDate>Fri, 01 May 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Is the npm he Package Safe to Use? A Security Review]]></title>
      <description><![CDATA[The npm he package is a tiny, dependency-free HTML entity encoder and decoder. Here is what it does, whether it is safe, and where developers misuse it.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-he</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-he</guid>
      <pubDate>Fri, 01 May 2026 06:35:11 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[nginx/1.21.5: Which CVEs Affect It and How to Patch]]></title>
      <description><![CDATA[If your Server header reads nginx/1.21.5, you are running an old mainline release. Here is what it is vulnerable to and the safe versions to move to.]]></description>
      <link>https://safeguard.sh/resources/blog/nginx-1-21-5</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nginx-1-21-5</guid>
      <pubDate>Fri, 01 May 2026 05:14:44 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The NVD backlog and its impact on vulnerability management]]></title>
      <description><![CDATA[The NVD backlog leaves thousands of CVEs unscored each month, forcing security teams to rethink how they prioritize and triage vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/the-nvd-backlog-and-its-impact-on-vulnerability-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-nvd-backlog-and-its-impact-on-vulnerability-management</guid>
      <pubDate>Fri, 01 May 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How Does a Kubernetes Security Breach Happen and How Do You Prevent One?]]></title>
      <description><![CDATA[Most Kubernetes security breaches trace back to exposed dashboards, leaked credentials, and over-permissive RBAC. Here is how the real attacks unfolded and what stops them.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-security-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-security-breach</guid>
      <pubDate>Fri, 01 May 2026 03:54:17 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Infrastructure as Code (IaC) scanning explained]]></title>
      <description><![CDATA[A breakdown of how IaC scanning tools catch cloud misconfigurations before deployment, how Aikido Security's bundled approach compares, and what to look for in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/infrastructure-as-code-iac-scanning-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/infrastructure-as-code-iac-scanning-explained</guid>
      <pubDate>Fri, 01 May 2026 03:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The DevSecOps Process, Explained Stage by Stage]]></title>
      <description><![CDATA[A DevSecOps process bakes security into every step of the software delivery lifecycle instead of bolting it on at the end. Here is what each stage actually looks like.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-process</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-process</guid>
      <pubDate>Fri, 01 May 2026 02:33:51 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Copyleft vs Copyright: What the Difference Means for Your Dependencies]]></title>
      <description><![CDATA[A practical breakdown of copyleft vs copyright, how copyleft licenses like the GPL actually work, and why the distinction shows up in your software bill of materials.]]></description>
      <link>https://safeguard.sh/resources/blog/copyleft-vs-copyright</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/copyleft-vs-copyright</guid>
      <pubDate>Fri, 01 May 2026 01:13:24 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Critical RCE via ImageMagick: hacking Docker containers]]></title>
      <description><![CDATA[ImageTragick and CVE-2022-44268 show how one image-processing library keeps handing attackers shells and secrets inside Docker containers.]]></description>
      <link>https://safeguard.sh/resources/blog/critical-rce-via-imagemagick-hacking-docker-containers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/critical-rce-via-imagemagick-hacking-docker-containers</guid>
      <pubDate>Fri, 01 May 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Secrets detection: how it works and why it matters]]></title>
      <description><![CDATA[How secrets detection tools catch leaked keys before attackers do, why breaches like Toyota's still happen, and how Safeguard compares to Aikido Security.]]></description>
      <link>https://safeguard.sh/resources/blog/secrets-detection-how-it-works-and-why-it-matters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secrets-detection-how-it-works-and-why-it-matters</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx IAST Explained: What It Does and When to Use It]]></title>
      <description><![CDATA[A practical look at Checkmarx IAST, how interactive testing differs from SAST and DAST, and where it fits in a modern AppSec program.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-iast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-iast</guid>
      <pubDate>Thu, 30 Apr 2026 23:52:57 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How to Check Website Vulnerability: A Practical Guide]]></title>
      <description><![CDATA[To check website vulnerability properly you combine automated scanning of the running app with dependency analysis of what it's built from. Here's a workflow that covers both.]]></description>
      <link>https://safeguard.sh/resources/blog/check-website-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/check-website-vulnerability</guid>
      <pubDate>Thu, 30 Apr 2026 22:32:31 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Node Docker Images: Picking the Right Base for Production]]></title>
      <description><![CDATA[The node docker image you pick as a base determines most of your container's attack surface and size. Here's how to choose between full, slim, and alpine variants for production.]]></description>
      <link>https://safeguard.sh/resources/blog/node-docker-images-picking-the-right-base</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-docker-images-picking-the-right-base</guid>
      <pubDate>Thu, 30 Apr 2026 21:12:04 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is Checkmarx? A Plain-English Overview]]></title>
      <description><![CDATA[Checkmarx is one of the oldest names in static analysis, built for large enterprises with dedicated security teams. Here's what it actually does and how it stacks up.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-checkmarx-a-plain-english-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-checkmarx-a-plain-english-overview</guid>
      <pubDate>Thu, 30 Apr 2026 19:51:37 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Open Redirect Vulnerabilities: How Attackers Abuse Them]]></title>
      <description><![CDATA[An open redirect attack abuses a trusted domain's own redirect functionality to send victims to a malicious site — low severity on its own, but a key ingredient in phishing and OAuth token theft.]]></description>
      <link>https://safeguard.sh/resources/blog/open-redirect-vulnerabilities-how-attackers-abuse-them</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-redirect-vulnerabilities-how-attackers-abuse-them</guid>
      <pubDate>Thu, 30 Apr 2026 18:31:10 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[NVD Meaning: What the National Vulnerability Database Actually Does]]></title>
      <description><![CDATA[The NVD is the U.S. government's repository of vulnerability data, built on top of the CVE list and enriched with severity scores and affected-version details. Here is what that means in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/nvd-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nvd-meaning</guid>
      <pubDate>Thu, 30 Apr 2026 17:10:44 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SCA Security: What Software Composition Analysis Actually Catches]]></title>
      <description><![CDATA[SCA security scans the open source dependencies that make up most of your codebase, finding known CVEs, risky licenses, and malicious packages. Here is what it catches — and what it does not.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-security-what-composition-analysis-catches</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-security-what-composition-analysis-catches</guid>
      <pubDate>Thu, 30 Apr 2026 15:50:17 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Is python.org Safe? What to Trust and What to Verify]]></title>
      <description><![CDATA[The python.org website itself is the official, safe source for Python. The real risk lives one step downstream, on PyPI, where typosquatted packages wait for a typo.]]></description>
      <link>https://safeguard.sh/resources/blog/is-python-org-safe</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/is-python-org-safe</guid>
      <pubDate>Thu, 30 Apr 2026 14:29:50 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Buffer Overflow Exploits: A Practical Example]]></title>
      <description><![CDATA[A buffer overflow exploit example, walked through step by step, showing exactly how writing past the end of a fixed-size buffer can turn a simple C function into arbitrary code execution.]]></description>
      <link>https://safeguard.sh/resources/blog/buffer-overflow-exploits-a-practical-example</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buffer-overflow-exploits-a-practical-example</guid>
      <pubDate>Thu, 30 Apr 2026 13:09:24 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Vendoring Dependencies: When It Helps and When It Hurts Security]]></title>
      <description><![CDATA[Committing dependencies to your repo buys immutability and availability — and quietly breaks scanners, updates, and license tracking. Here's the honest ledger.]]></description>
      <link>https://safeguard.sh/resources/blog/vendoring-dependencies-when-it-helps-and-when-it-hurts-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vendoring-dependencies-when-it-helps-and-when-it-hurts-security</guid>
      <pubDate>Thu, 30 Apr 2026 11:48:57 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Elena Kovacs)</author>
    </item>
    <item>
      <title><![CDATA[Service Mesh for Supply Chain Policy Enforcement]]></title>
      <description><![CDATA[Using Istio, Linkerd, and Cilium service mesh to enforce signed-artifact, SPIFFE identity, and provenance-aware policy in production clusters.]]></description>
      <link>https://safeguard.sh/resources/blog/service-mesh-supply-chain-policy-enforcement</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/service-mesh-supply-chain-policy-enforcement</guid>
      <pubDate>Thu, 30 Apr 2026 10:28:30 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GHSA vs CVE vs OSV: comparing vulnerability identifier formats]]></title>
      <description><![CDATA[A plain-language breakdown of CVE, GHSA, and OSV vulnerability identifiers, who assigns them, how they differ, and why one flaw can carry three IDs.]]></description>
      <link>https://safeguard.sh/resources/blog/ghsa-vs-cve-vs-osv-comparing-vulnerability-identifier-formats</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ghsa-vs-cve-vs-osv-comparing-vulnerability-identifier-formats</guid>
      <pubDate>Thu, 30 Apr 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[GCP Binary Authorization Enforcement Runbook 2026]]></title>
      <description><![CDATA[A practical 2026 runbook for enforcing GCP Binary Authorization in production, including attestation pipelines, break-glass procedures, and rollout sequencing.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-binary-authorization-enforcement-runbook-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-binary-authorization-enforcement-runbook-2026</guid>
      <pubDate>Thu, 30 Apr 2026 09:30:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Snyk's Static Code Analysis vs Traditional SAST Tools]]></title>
      <description><![CDATA[Snyk static code analysis leans on symbolic execution and a developer-first workflow rather than the deep, config-heavy engines traditional SAST vendors built for slower release cycles.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-static-code-analysis-vs-traditional-sast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-static-code-analysis-vs-traditional-sast</guid>
      <pubDate>Thu, 30 Apr 2026 09:10:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Docker and npm: How to Build Secure Node.js Images]]></title>
      <description><![CDATA[Combining Docker and npm the naive way ships a bloated, vulnerable image. Here is how to build lean, reproducible, and secure Node.js containers.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-npm</guid>
      <pubDate>Thu, 30 Apr 2026 09:08:04 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Cloud misconfiguration: causes and prevention]]></title>
      <description><![CDATA[Cloud misconfiguration causes most cloud breaches, from Capital One to Toyota. Learn its root causes, real incidents, and how Safeguard prevents it.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-misconfiguration-causes-and-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-misconfiguration-causes-and-prevention</guid>
      <pubDate>Thu, 30 Apr 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Utility Grid Software Supply Chain in 2026]]></title>
      <description><![CDATA[NERC CIP-013, expanded CIP-010 expectations, and the post-Colonial Pipeline regulatory tightening have changed what utilities must demand from their software vendors. Here is the 2026 baseline.]]></description>
      <link>https://safeguard.sh/resources/blog/utility-grid-software-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/utility-grid-software-supply-chain-2026</guid>
      <pubDate>Thu, 30 Apr 2026 09:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Wiz vs Orca: CNAPP Field Test 2026]]></title>
      <description><![CDATA[Google's $32B Wiz acquisition closed in March 2026. We ran a 90-day bake-off between Wiz and Orca on the same AWS+Azure estate and graded the agentless CNAPP race honestly.]]></description>
      <link>https://safeguard.sh/resources/blog/wiz-vs-orca-cnapp-field-test-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wiz-vs-orca-cnapp-field-test-2026</guid>
      <pubDate>Thu, 30 Apr 2026 09:00:00 GMT</pubDate>
      <category>Tool Comparison</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[XSS Tutorial: How Cross-Site Scripting Works and How to Stop It]]></title>
      <description><![CDATA[A defender's XSS tutorial covering the three attack types, why they still slip through, and the encoding and CSP controls that actually prevent them.]]></description>
      <link>https://safeguard.sh/resources/blog/xss-tutorial</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xss-tutorial</guid>
      <pubDate>Thu, 30 Apr 2026 07:47:37 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Understanding zero-day vulnerabilities and incident response]]></title>
      <description><![CDATA[A concrete look at zero-day vulnerabilities and incident response, using Log4Shell, MOVEit, and CISA KEV data to explain how fast defenders must move.]]></description>
      <link>https://safeguard.sh/resources/blog/understanding-zero-day-vulnerabilities-and-incident-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/understanding-zero-day-vulnerabilities-and-incident-response</guid>
      <pubDate>Thu, 30 Apr 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[npm install --legacy-peer-deps: What It Does and When It Bites]]></title>
      <description><![CDATA[npm install --legacy-peer-deps tells npm to skip peer dependency resolution entirely, the way npm 4-6 did. That unblocks a broken install today and quietly plants runtime and security problems for later.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-legacy-peer-deps-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-legacy-peer-deps-explained</guid>
      <pubDate>Thu, 30 Apr 2026 06:27:10 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Open source license management and scanning]]></title>
      <description><![CDATA[33% of codebases ship components with no discernible license, and Aikido's manifest-based scanning still misses vendored code and stale registry metadata. Here's what real license compliance requires.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-license-management-and-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-license-management-and-scanning</guid>
      <pubDate>Thu, 30 Apr 2026 06:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-37601: Prototype Pollution in loader-utils Explained]]></title>
      <description><![CDATA[CVE-2022-37601 is a prototype pollution flaw in the webpack loader-utils package. Here is what it affects, how it works, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-37601</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-37601</guid>
      <pubDate>Thu, 30 Apr 2026 05:06:44 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Patch management strategies for open source dependencies]]></title>
      <description><![CDATA[A practical guide to patch management for open source dependencies: prioritizing by reachability and EPSS, not CVSS alone, and building a repeatable remediation loop.]]></description>
      <link>https://safeguard.sh/resources/blog/patch-management-strategies-for-open-source-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/patch-management-strategies-for-open-source-dependencies</guid>
      <pubDate>Thu, 30 Apr 2026 04:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Is react-device-detect Safe? A Security Review of the npm Package]]></title>
      <description><![CDATA[A look at react-device-detect, what the library does with user-agent parsing, and the supply-chain and privacy considerations before you add it to a React app.]]></description>
      <link>https://safeguard.sh/resources/blog/react-device-detect</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-device-detect</guid>
      <pubDate>Thu, 30 Apr 2026 03:46:17 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Open source dependency vulnerability scanning explained]]></title>
      <description><![CDATA[How open source vulnerability scanning works, why false positives plague tools like Aikido, and how reachability and SBOMs cut real triage time.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-dependency-vulnerability-scanning-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-dependency-vulnerability-scanning-explained</guid>
      <pubDate>Thu, 30 Apr 2026 03:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[java.lang.NullPointerException: Causes, Fixes, and Prevention]]></title>
      <description><![CDATA[What actually throws java.lang.NullPointerException, how to read the helpful messages modern JVMs print, and the handful of patterns that keep null out of your call paths.]]></description>
      <link>https://safeguard.sh/resources/blog/java-null-pointer-exception-fix</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-null-pointer-exception-fix</guid>
      <pubDate>Thu, 30 Apr 2026 02:25:50 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Avoid Malicious Code: A Practical Defense Checklist]]></title>
      <description><![CDATA[How to avoid malicious code in practice: control what you install, control what runs at install time, and control what your build can reach. A working checklist for teams.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-avoid-malicious-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-avoid-malicious-code</guid>
      <pubDate>Thu, 30 Apr 2026 01:05:23 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Transitive dependency vulnerabilities explained]]></title>
      <description><![CDATA[A vulnerability three layers deep in your dependency graph is still your problem. Here's how transitive flaws like Log4Shell hide, spread, and get fixed.]]></description>
      <link>https://safeguard.sh/resources/blog/transitive-dependency-vulnerabilities-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/transitive-dependency-vulnerabilities-explained</guid>
      <pubDate>Thu, 30 Apr 2026 01:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Open source security audits: what they cover]]></title>
      <description><![CDATA[What an open source security audit actually covers versus routine SCA scanning, the frameworks that define it, real costs and timelines, and how Aikido Security's approach compares.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-security-audits-what-they-cover</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-security-audits-what-they-cover</guid>
      <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Fix My Java Code: A Practical Guide to Finding and Fixing Security Bugs]]></title>
      <description><![CDATA["Fix my Java code" usually means a security or dependency problem. Here is a repeatable way to find the real fault, fix it, and stop it from returning.]]></description>
      <link>https://safeguard.sh/resources/blog/fix-my-java-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fix-my-java-code</guid>
      <pubDate>Wed, 29 Apr 2026 23:44:57 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-36665: The protobuf.js Prototype Pollution Vulnerability Explained]]></title>
      <description><![CDATA[CVE-2023-36665 is a critical prototype pollution flaw in protobuf.js that can lead to remote code execution. Here is how it works and how to fix it fast.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-36665</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-36665</guid>
      <pubDate>Wed, 29 Apr 2026 22:24:30 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Git Repository URL: How to Find, Copy, and Change It Safely]]></title>
      <description><![CDATA[A Git repository URL is the address Git uses to fetch and push code. Here is how to get your repository URL from the command line and GitHub, plus the security details that matter.]]></description>
      <link>https://safeguard.sh/resources/blog/git-repository-url</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-repository-url</guid>
      <pubDate>Wed, 29 Apr 2026 21:04:03 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What Gartner Says About DevSecOps: Tools, Trends, and How to Read the Guidance]]></title>
      <description><![CDATA[Gartner's DevSecOps research shapes a lot of security budgets. Here is how to interpret the guidance without buying every category on the map.]]></description>
      <link>https://safeguard.sh/resources/blog/gartner-devsecops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gartner-devsecops</guid>
      <pubDate>Wed, 29 Apr 2026 19:43:37 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Exploits Explained: How They Work and How to Stop Them]]></title>
      <description><![CDATA[A practitioner's tour of the JavaScript exploit classes that actually break production apps — prototype pollution, XSS, and malicious dependencies — with detection and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-exploit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-exploit</guid>
      <pubDate>Wed, 29 Apr 2026 18:23:10 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[pdfjs-dist on npm: Security Review and Safe Usage]]></title>
      <description><![CDATA[The pdfjs-dist npm package renders PDFs in the browser, but CVE-2024-4367 allowed arbitrary JavaScript execution from a malicious PDF before 4.2.67. Here is what to check.]]></description>
      <link>https://safeguard.sh/resources/blog/pdfjs-dist-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pdfjs-dist-npm</guid>
      <pubDate>Wed, 29 Apr 2026 17:02:43 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[PyTorch CVE-2025-32434: weights_only=True No Longer Safe]]></title>
      <description><![CDATA[A critical PyTorch RCE bypassed the safety property of torch.load(weights_only=True). We analyze the bug and explain why safetensors should now be the default.]]></description>
      <link>https://safeguard.sh/resources/blog/pytorch-cve-2025-32434-torch-load-weights-only-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pytorch-cve-2025-32434-torch-load-weights-only-bypass</guid>
      <pubDate>Wed, 29 Apr 2026 15:42:17 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Semantic Reachability vs Call-Graph Reachability in 2026]]></title>
      <description><![CDATA[Call graphs say a function is reachable. Semantic reachability asks whether the preconditions for exploitation hold. The difference matters for prioritization.]]></description>
      <link>https://safeguard.sh/resources/blog/semantic-reachability-vs-call-graph-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/semantic-reachability-vs-call-graph-2026</guid>
      <pubDate>Wed, 29 Apr 2026 15:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[XSS Script Example: How Cross-Site Scripting Works and How to Stop It]]></title>
      <description><![CDATA[A clear XSS script example shows how untrusted input becomes executable code in a victim's browser. Here is the anatomy of the three XSS types and the defenses that actually work.]]></description>
      <link>https://safeguard.sh/resources/blog/xss-script-example</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xss-script-example</guid>
      <pubDate>Wed, 29 Apr 2026 14:21:50 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What Does the DevSecOps Acronym Actually Mean?]]></title>
      <description><![CDATA[The DevSecOps acronym stands for Development, Security, and Operations, describing a practice that folds security into the software delivery pipeline rather than bolting it on at the end.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-acronym</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-acronym</guid>
      <pubDate>Wed, 29 Apr 2026 13:01:23 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CMMC 2.0 Phase Two: What November 10, 2026 Means for Contractors]]></title>
      <description><![CDATA[CMMC Phase 1 began in November 2025. Phase 2 lands on November 10, 2026, requiring mandatory C3PAO Level 2 assessments. We unpack the contractor implications.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-rollout-phase-two-contractor-implications-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-rollout-phase-two-contractor-implications-2026</guid>
      <pubDate>Wed, 29 Apr 2026 12:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What a Cloud Native Security Platform Actually Does]]></title>
      <description><![CDATA[A cloud native security platform unifies posture, workload, and supply chain controls for containerized apps. Here is what the category covers and how to tell the marketing from the substance.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-native-security-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-native-security-platform</guid>
      <pubDate>Wed, 29 Apr 2026 11:40:57 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[EU Cyber Resilience Act Vendor Obligations in 2026]]></title>
      <description><![CDATA[The Cyber Resilience Act entered into force in December 2024 with a phased application schedule. The vendor obligations begin to bite in 2026 and accelerate through 2027.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cyber-resilience-act-vendor-obligations-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cyber-resilience-act-vendor-obligations-2026</guid>
      <pubDate>Wed, 29 Apr 2026 11:30:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Webinars and Training Resources Worth Your Time]]></title>
      <description><![CDATA[Most application security teams already know OWASP by reputation but rarely tap its live training — here's which formats are worth blocking calendar time for.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-webinar-and-training-resources-worth-your-time</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-webinar-and-training-resources-worth-your-time</guid>
      <pubDate>Wed, 29 Apr 2026 10:20:30 GMT</pubDate>
      <category>Culture</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Reachability analysis for prioritizing vulnerabilities]]></title>
      <description><![CDATA[Reachability analysis cuts vulnerability noise by 70-90% by tracing which CVEs are actually callable from your code, not just present in your dependency tree.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-for-prioritizing-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-for-prioritizing-vulnerabilities</guid>
      <pubDate>Wed, 29 Apr 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to Git Fetch a Branch (and Why It Matters for Security)]]></title>
      <description><![CDATA[How to git fetch a specific branch, the difference between fetch and pull, and why fetch-then-review is the safer default for teams handling untrusted code.]]></description>
      <link>https://safeguard.sh/resources/blog/git-fetch-branch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-fetch-branch</guid>
      <pubDate>Wed, 29 Apr 2026 09:00:03 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Trivy alternatives for container and IaC scanning]]></title>
      <description><![CDATA[Trivy alternatives usually aren't about scanner quality — they're about the backlog, SBOM lifecycle, and compliance work that comes after. Trivy vs Safeguard, feature by feature.]]></description>
      <link>https://safeguard.sh/resources/blog/trivy-alternatives-for-container-and-iac-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trivy-alternatives-for-container-and-iac-scanning</guid>
      <pubDate>Wed, 29 Apr 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What a Security Testing Service Does and When You Need One]]></title>
      <description><![CDATA[A security testing service systematically probes your applications and infrastructure for weaknesses before attackers do. Here is what the different types cover and how to choose.]]></description>
      <link>https://safeguard.sh/resources/blog/security-testing-service</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-testing-service</guid>
      <pubDate>Wed, 29 Apr 2026 07:39:36 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[iOS application security best practices]]></title>
      <description><![CDATA[Concrete iOS app security controls—Keychain data protection, ATS, dependency vetting, and privacy manifests—grounded in real CVEs like CocoaPods 2024 and BLASTPASS.]]></description>
      <link>https://safeguard.sh/resources/blog/ios-application-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ios-application-security-best-practices</guid>
      <pubDate>Wed, 29 Apr 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Ajv npm: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[The ajv npm package is the most widely used JSON Schema validator in the Node ecosystem. Here is what you need to know about its security history and safe configuration.]]></description>
      <link>https://safeguard.sh/resources/blog/ajv-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ajv-npm</guid>
      <pubDate>Wed, 29 Apr 2026 06:19:10 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard vs Trivy: vulnerability scanning depth and reme...]]></title>
      <description><![CDATA[Trivy scans fast and free, but leaves remediation to you. See how Safeguard's platform handles cross-repo correlation, prioritization, and audit-ready fix tracking.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-vs-trivy-vulnerability-scanning-depth-and-remediation-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-vs-trivy-vulnerability-scanning-depth-and-remediation-workflow</guid>
      <pubDate>Wed, 29 Apr 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Encryption Services: Managed vs Self-Hosted]]></title>
      <description><![CDATA[Choosing between a managed key management service and a self-hosted encryption stack comes down to who you trust to hold the keys and who you trust to patch the software.]]></description>
      <link>https://safeguard.sh/resources/blog/encryption-services-choosing-managed-vs-self-hosted</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/encryption-services-choosing-managed-vs-self-hosted</guid>
      <pubDate>Wed, 29 Apr 2026 04:58:43 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Android application security best practices]]></title>
      <description><![CDATA[A practical, evidence-based guide to Android app security: data storage, network hardening, SDK risk, and CI/CD signing, with concrete CVEs and stats.]]></description>
      <link>https://safeguard.sh/resources/blog/android-application-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/android-application-security-best-practices</guid>
      <pubDate>Wed, 29 Apr 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[start-server-and-test: Reliable E2E Test Startup in CI]]></title>
      <description><![CDATA[start-server-and-test starts your app, waits until a URL responds, runs your tests, then tears the server down. Getting its wait semantics right is the difference between stable and flaky CI.]]></description>
      <link>https://safeguard.sh/resources/blog/start-server-and-test-npm-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/start-server-and-test-npm-guide</guid>
      <pubDate>Wed, 29 Apr 2026 03:38:16 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[CNAPP vs CSPM: what's the difference]]></title>
      <description><![CDATA[CSPM checks cloud configs, CNAPP consolidates workload security -- neither verifies what's inside your software. Safeguard vs Trivy (Aqua), compared.]]></description>
      <link>https://safeguard.sh/resources/blog/cnapp-vs-cspm-whats-the-difference</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cnapp-vs-cspm-whats-the-difference</guid>
      <pubDate>Wed, 29 Apr 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[What is a Trusted Publisher (PyPI and npm)]]></title>
      <description><![CDATA[A trusted publisher lets your CI workflow publish packages with short-lived OIDC tokens instead of stored API keys. Here's how it works on PyPI and where npm stands.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-trusted-publisher-pypi-and-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-trusted-publisher-pypi-and-npm</guid>
      <pubDate>Wed, 29 Apr 2026 02:17:50 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Aisha Bello)</author>
    </item>
    <item>
      <title><![CDATA[Securing mobile app dependencies: CocoaPods and Gradle]]></title>
      <description><![CDATA[CocoaPods and Gradle power millions of mobile apps. See how orphaned pods, build-script RCE, and dependency confusion put them at real risk today.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-mobile-app-dependencies-cocoapods-and-gradle</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-mobile-app-dependencies-cocoapods-and-gradle</guid>
      <pubDate>Wed, 29 Apr 2026 01:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[com.fasterxml.jackson.databind: Maven Coordinates, Modules, and Version Strategy]]></title>
      <description><![CDATA[com.fasterxml.jackson.databind is the Java package, not the Maven groupId, and that mixup breaks builds weekly. Here are the correct coordinates, the module map, and a version strategy that survives audits.]]></description>
      <link>https://safeguard.sh/resources/blog/jackson-databind-maven-coordinates-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jackson-databind-maven-coordinates-guide</guid>
      <pubDate>Wed, 29 Apr 2026 00:57:23 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[OSS container image scanning tools compared]]></title>
      <description><![CDATA[Trivy finds CVEs fast and free. Safeguard compares how each handles fleet-wide inventory, triage, policy enforcement, and audit evidence at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/oss-container-image-scanning-tools-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oss-container-image-scanning-tools-compared</guid>
      <pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[xmldom Is Deprecated: Vulnerabilities and Migration Options]]></title>
      <description><![CDATA[The npm xmldom package was replaced by @xmldom/xmldom years ago, yet the old name still sits in countless lockfiles with unfixed advisories. Here is how to find it and migrate.]]></description>
      <link>https://safeguard.sh/resources/blog/xmldom-npm-deprecated-vulnerabilities-alternatives</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xmldom-npm-deprecated-vulnerabilities-alternatives</guid>
      <pubDate>Tue, 28 Apr 2026 23:36:56 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[date-fns-tz: Time Zone Handling and Package Health Review]]></title>
      <description><![CDATA[A practical review of the npm date-fns-tz package: how it handles IANA time zones, how healthy the project is, and when date-fns v4's built-in time zone support replaces it.]]></description>
      <link>https://safeguard.sh/resources/blog/date-fns-tz-npm-package-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/date-fns-tz-npm-package-guide</guid>
      <pubDate>Tue, 28 Apr 2026 22:16:30 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SQLi Cheat Sheet: Detection and Defense Guide]]></title>
      <description><![CDATA[A practical SQLi cheat sheet covering how injection works, the patterns to recognize, and the parameterized-query defenses that actually stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/sqli-cheatsheet</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sqli-cheatsheet</guid>
      <pubDate>Tue, 28 Apr 2026 20:56:03 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How Do You Pronounce Snyk? The Definitive Answer]]></title>
      <description><![CDATA[Snyk is pronounced sneak, like the verb. Here is where the name comes from, why people get it wrong, and what the tool actually does.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-pronunciation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-pronunciation</guid>
      <pubDate>Tue, 28 Apr 2026 19:35:36 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Password Validation: How to Verify Credentials Securely]]></title>
      <description><![CDATA[Password validation is more than a regex for length and symbols. Here is how to check credentials the way modern guidance actually recommends.]]></description>
      <link>https://safeguard.sh/resources/blog/password-validation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/password-validation</guid>
      <pubDate>Tue, 28 Apr 2026 18:15:10 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[npm install axios: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[Running npm install axios is safe today, but the version you pin matters. Here is a look at the CVEs that have hit axios and how to use it without leaking credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-install-axios</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-install-axios</guid>
      <pubDate>Tue, 28 Apr 2026 16:54:43 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[dotenv-webpack: How to Keep Secrets Out of Your Bundle]]></title>
      <description><![CDATA[dotenv-webpack loads .env values into a webpack build, but it inlines them into client code at compile time, so anything you reference ships to the browser in plaintext.]]></description>
      <link>https://safeguard.sh/resources/blog/dotenv-webpack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dotenv-webpack</guid>
      <pubDate>Tue, 28 Apr 2026 15:34:16 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Code Quality Software and Security: Where Clean Code and Safe Code Overlap]]></title>
      <description><![CDATA[Code quality software catches more security bugs than most teams give it credit for. Here is how quality tooling and security tooling overlap, where they diverge, and how to combine them.]]></description>
      <link>https://safeguard.sh/resources/blog/code-quality-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-quality-software</guid>
      <pubDate>Tue, 28 Apr 2026 14:13:49 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What Is the Definition of Malicious Code?]]></title>
      <description><![CDATA[Malicious code is any software or script written to damage, disrupt, or gain unauthorized access to a system. Here is a precise definition and the main categories.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-code-definition</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-code-definition</guid>
      <pubDate>Tue, 28 Apr 2026 12:53:23 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Use bcryptjs from npm Safely: A Security Review]]></title>
      <description><![CDATA[The bcryptjs npm package is a pure-JavaScript bcrypt implementation with zero native dependencies. Here is when to reach for it, how to use it correctly, and the pitfalls that weaken password hashing.]]></description>
      <link>https://safeguard.sh/resources/blog/bcryptjs-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bcryptjs-npm</guid>
      <pubDate>Tue, 28 Apr 2026 11:32:56 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Management Dashboard Blueprint 2026]]></title>
      <description><![CDATA[A 2026 blueprint for vulnerability management dashboards: which metrics belong on executive, manager, and engineer views, and how to avoid the common failure modes.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-management-dashboard-blueprint-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-management-dashboard-blueprint-2026</guid>
      <pubDate>Tue, 28 Apr 2026 11:30:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[tj-actions Supply Chain Attack March 2025: A Postmortem]]></title>
      <description><![CDATA[The tj-actions/changed-files compromise exposed CI secrets across thousands of public repositories. A postmortem on the attack chain and the GitHub Actions trust model.]]></description>
      <link>https://safeguard.sh/resources/blog/github-actions-tj-actions-supply-chain-attack-2025-postmortem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-actions-tj-actions-supply-chain-attack-2025-postmortem</guid>
      <pubDate>Tue, 28 Apr 2026 11:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[How to Install Java on a Mac with Homebrew (Safely and Cleanly)]]></title>
      <description><![CDATA[The fastest way to install Java on Mac: brew install openjdk, one symlink so macOS can find it, and JAVA_HOME set correctly — plus how to keep the JDK patched afterward.]]></description>
      <link>https://safeguard.sh/resources/blog/install-java-mac-brew</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/install-java-mac-brew</guid>
      <pubDate>Tue, 28 Apr 2026 10:12:29 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[WebExtension vulnerabilities in React DevTools and Vue.js DevTools]]></title>
      <description><![CDATA[CVE-2023-5654 and CVE-2023-5718 exposed 5M+ React and Vue devtools users to postMessage flaws. Here's how devtools extensions became supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/webextension-vulnerabilities-in-react-devtools-and-vuejs-devtools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webextension-vulnerabilities-in-react-devtools-and-vuejs-devtools</guid>
      <pubDate>Tue, 28 Apr 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best SBOM tools compared (including Trivy)]]></title>
      <description><![CDATA[Trivy generates SBOMs fast at scan time. Safeguard turns those SBOMs into a versioned, queryable inventory you can match against new CVEs org-wide.]]></description>
      <link>https://safeguard.sh/resources/blog/best-sbom-tools-compared-including-trivy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-sbom-tools-compared-including-trivy</guid>
      <pubDate>Tue, 28 Apr 2026 09:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx Careers: What a Career in Application Security Involves]]></title>
      <description><![CDATA[Curious about Checkmarx careers or breaking into AppSec generally? Here is what these roles actually involve, the skills that matter, and how to prepare.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-careers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-careers</guid>
      <pubDate>Tue, 28 Apr 2026 08:52:03 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Python Dockerfile Best Practices for Secure, Small Images]]></title>
      <description><![CDATA[The Python Dockerfile best practices that matter most for security are running as a non-root user, choosing a slim base, using multi-stage builds, and pinning dependencies. Here is a working reference Dockerfile and why each line is there.]]></description>
      <link>https://safeguard.sh/resources/blog/python-dockerfile-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-dockerfile-best-practices</guid>
      <pubDate>Tue, 28 Apr 2026 07:31:36 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Browser extension security risks for developers]]></title>
      <description><![CDATA[Cyberhaven's Chrome extension breach hit 400,000 users in hours. Here's how attackers hijack trusted extensions, and how to detect the risk before it spreads.]]></description>
      <link>https://safeguard.sh/resources/blog/browser-extension-security-risks-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/browser-extension-security-risks-for-developers</guid>
      <pubDate>Tue, 28 Apr 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Fix Cross-Site Scripting Vulnerabilities in Java (With Examples)]]></title>
      <description><![CDATA[A practical walkthrough of how to fix cross site scripting vulnerabilities in Java: context-aware output encoding, template auto-escaping, and where servlet code goes wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/fix-cross-site-scripting-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fix-cross-site-scripting-java</guid>
      <pubDate>Tue, 28 Apr 2026 06:11:09 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[GitHub secret scanning vs dedicated scanning tools]]></title>
      <description><![CDATA[GitHub secret scanning vs Trivy: how push protection, validity checks, and multi-source coverage differ, and where Safeguard fits for cross-repo remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/github-secret-scanning-vs-dedicated-scanning-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-secret-scanning-vs-dedicated-scanning-tools</guid>
      <pubDate>Tue, 28 Apr 2026 06:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Application Security Risk Management Actually Works in Practice]]></title>
      <description><![CDATA[A working model for application security risk management: how to inventory assets, rate risk you can act on, prioritize by exploitability and impact, and prove the program is reducing risk.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-risk-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-risk-management</guid>
      <pubDate>Tue, 28 Apr 2026 04:50:43 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Electron app security best practices]]></title>
      <description><![CDATA[nodeIntegration, contextIsolation, Chromium patch lag, and npm supply chain risk: the Electron security best practices that actually stop RCE.]]></description>
      <link>https://safeguard.sh/resources/blog/electron-app-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/electron-app-security-best-practices</guid>
      <pubDate>Tue, 28 Apr 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Risk Management Applications: How to Secure the Tools You Rely On]]></title>
      <description><![CDATA[Risk management applications concentrate your most sensitive data, which makes them a target. Here is how to think about securing the software that manages your risk.]]></description>
      <link>https://safeguard.sh/resources/blog/risk-management-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/risk-management-applications</guid>
      <pubDate>Tue, 28 Apr 2026 03:30:16 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Why static scanning misses runtime threats (the case for ...]]></title>
      <description><![CDATA[Trivy's build-time CVE scans miss fileless malware, reverse shells, and live threats. Here's how ATT&CK-mapped runtime protection closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/why-static-scanning-misses-runtime-threats-the-case-for-runtime-protection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-static-scanning-misses-runtime-threats-the-case-for-runtime-protection</guid>
      <pubDate>Tue, 28 Apr 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard IDE Extension v5: Security Feedback Where Developers Actually Work]]></title>
      <description><![CDATA[The Safeguard IDE Extension v5 brings SBOM generation, vulnerability alerts, and policy checks directly into VS Code and JetBrains IDEs. A deep dive into what changed and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-ide-extension-v5-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-ide-extension-v5-deep-dive</guid>
      <pubDate>Tue, 28 Apr 2026 02:09:49 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Securing IoT device firmware supply chains]]></title>
      <description><![CDATA[How Ripple20, Mirai, and Realtek SDK flaws exposed IoT firmware supply chains, what EU CRA and FDA SBOM rules require, and what reachability adds.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-iot-device-firmware-supply-chains</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-iot-device-firmware-supply-chains</guid>
      <pubDate>Tue, 28 Apr 2026 01:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Scanning: How the Pieces Fit Together]]></title>
      <description><![CDATA[Application security scanning spans SAST, DAST, SCA, and secrets detection. Here is what each type finds, where it fits in CI, and how to avoid alert fatigue.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-scanning</guid>
      <pubDate>Tue, 28 Apr 2026 00:49:22 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Trivy and how it compares to other open-source sc...]]></title>
      <description><![CDATA[Trivy is Aqua Security's free open-source scanner for containers, IaC, and dependencies. Here's how it compares to Grype, Clair, and Snyk—and where it falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-trivy-and-how-it-compares-to-other-open-source-scanners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-trivy-and-how-it-compares-to-other-open-source-scanners</guid>
      <pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[react-native-loading-spinner-overlay: Is It Still Safe to Use?]]></title>
      <description><![CDATA[A security look at react-native-loading-spinner-overlay: its maintenance status, dependency footprint, and how to reason about an unmaintained UI package.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-loading-spinner-overlay</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-loading-spinner-overlay</guid>
      <pubDate>Mon, 27 Apr 2026 23:28:56 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Permissive License Explained: MIT, Apache 2.0, and BSD Risks]]></title>
      <description><![CDATA[What a permissive license is, how MIT, BSD, and Apache 2.0 differ, and the compliance and security risks teams overlook when they assume permissive means risk-free.]]></description>
      <link>https://safeguard.sh/resources/blog/permissive-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/permissive-license</guid>
      <pubDate>Mon, 27 Apr 2026 22:08:29 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[NIST CVE Data Explained: How the NVD Works and Why the Backlog Matters]]></title>
      <description><![CDATA[What NIST's role in CVE data actually is, how the NVD enriches records with CVSS and CPE, and why the 2024 analysis backlog changed how teams should consume it.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-cve</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-cve</guid>
      <pubDate>Mon, 27 Apr 2026 20:48:02 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[The OWASP Top 10, Explained: The Web App Risks That Matter Most]]></title>
      <description><![CDATA[The OWASP Top 10 is the industry's reference list of the most critical web application security risks. Here is what each category means and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top10</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top10</guid>
      <pubDate>Mon, 27 Apr 2026 19:27:36 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Worker Threads in Node.js: How They Work and How to Use Them Safely]]></title>
      <description><![CDATA[A worker thread in Node.js runs JavaScript in parallel on a separate thread, letting you offload CPU-heavy work without blocking the event loop. Here is how they work and the security pitfalls to avoid.]]></description>
      <link>https://safeguard.sh/resources/blog/worker-thread-in-node-js</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/worker-thread-in-node-js</guid>
      <pubDate>Mon, 27 Apr 2026 18:07:09 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is Memory Management? A Security-Focused Explainer]]></title>
      <description><![CDATA[Memory management is how a program allocates and frees memory, and getting it wrong is the root of some of the most exploited vulnerability classes in software.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-memory-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-memory-management</guid>
      <pubDate>Mon, 27 Apr 2026 16:46:42 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Rails Security Audit: 2025 Field Notes]]></title>
      <description><![CDATA[After 14 Rails audits in the last 12 months, the same eight issues kept surfacing. Here's the 2025 field checklist for Rails 7.2 and 8.0 enterprise apps.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-ruby-on-rails-security-audit-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-ruby-on-rails-security-audit-2025</guid>
      <pubDate>Mon, 27 Apr 2026 15:26:16 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-47884 in Jenkins OpenID Connect Provider: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[Jenkins OIDC Provider plugin token impersonation scored CVSS 9.1. Defender playbook for CI/CD identity infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-cve-2025-47884-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-cve-2025-47884-patch-response</guid>
      <pubDate>Mon, 27 Apr 2026 14:05:49 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Advisor: What It Is and How to Read Its Score]]></title>
      <description><![CDATA[Snyk Advisor is a free package health tool that rates open source packages from 0 to 100 across popularity, maintenance, security, and community. Here is how to use it well.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-advisor</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-advisor</guid>
      <pubDate>Mon, 27 Apr 2026 12:45:22 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Showdown Markdown Converter: XSS Risks and Safe Configuration]]></title>
      <description><![CDATA[The npm showdown library converts Markdown to HTML without sanitizing it — by design. Here is where the XSS risk actually lives and how to render untrusted Markdown safely.]]></description>
      <link>https://safeguard.sh/resources/blog/showdown-npm-markdown-xss-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/showdown-npm-markdown-xss-guide</guid>
      <pubDate>Mon, 27 Apr 2026 11:24:56 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-22462 in Ivanti Neurons for ITSM: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[Ivanti Neurons for ITSM auth bypass scored CVSS 9.8 and grants full admin access. Defender playbook for the ITSM patching emergency.]]></description>
      <link>https://safeguard.sh/resources/blog/ivanti-neurons-cve-2025-22462-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ivanti-neurons-cve-2025-22462-patch-response</guid>
      <pubDate>Mon, 27 Apr 2026 10:04:29 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Improving GraphQL security with static analysis]]></title>
      <description><![CDATA[GraphQL's flexible query model breaks REST-era security assumptions. Here's how static analysis catches introspection leaks, DoS, and BOLA before deploy.]]></description>
      <link>https://safeguard.sh/resources/blog/improving-graphql-security-with-static-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/improving-graphql-security-with-static-analysis</guid>
      <pubDate>Mon, 27 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Trivy's etcd exhaustion problem and scan reliability issues]]></title>
      <description><![CDATA[Trivy's local vulnerability database runs on etcd's own bbolt engine, and its single-writer lock and unbounded growth cause CI scans to stall or fail.]]></description>
      <link>https://safeguard.sh/resources/blog/trivys-etcd-exhaustion-problem-and-scan-reliability-issues</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trivys-etcd-exhaustion-problem-and-scan-reliability-issues</guid>
      <pubDate>Mon, 27 Apr 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Prioritization in 2025: EPSS, VEX, and the End of CVSS-Only Triage]]></title>
      <description><![CDATA[CVSS scores alone cannot tell you what to patch first. EPSS exploit prediction and VEX documents are reshaping how mature security teams prioritize vulnerabilities at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-prioritization-epss-vex-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-prioritization-epss-vex-2025</guid>
      <pubDate>Mon, 27 Apr 2026 08:44:02 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Coinbase Social Engineering and Insider Threat: How Bribed Support Agents Led to a $400M Breach]]></title>
      <description><![CDATA[Attackers bribed overseas Coinbase support agents to steal customer data, then demanded a $20M ransom. Coinbase refused to pay and disclosed everything.]]></description>
      <link>https://safeguard.sh/resources/blog/coinbase-social-engineering-insider-threat</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/coinbase-social-engineering-insider-threat</guid>
      <pubDate>Mon, 27 Apr 2026 07:23:35 GMT</pubDate>
      <category>Breach Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Building a secure GraphQL API with Node.js]]></title>
      <description><![CDATA[A practical guide to securing Node.js GraphQL APIs: query complexity limits, field-level authorization, injection-safe resolvers, and CSRF hardening.]]></description>
      <link>https://safeguard.sh/resources/blog/building-a-secure-graphql-api-with-nodejs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-a-secure-graphql-api-with-nodejs</guid>
      <pubDate>Mon, 27 Apr 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[React 18.3: The Safe Stepping Stone to React 19]]></title>
      <description><![CDATA[React 18.3 is functionally identical to 18.2 but adds deprecation warnings for React 19. Upgrading through it is a security move as much as a compatibility one.]]></description>
      <link>https://safeguard.sh/resources/blog/react-18-3</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-18-3</guid>
      <pubDate>Mon, 27 Apr 2026 06:03:09 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Aqua Vulnerability Database (AVD) explained]]></title>
      <description><![CDATA[AVD powers Trivy's scan results, but it's a curated aggregator, not a primary source. Here's how it differs from NVD, where its gaps are, and how to close them.]]></description>
      <link>https://safeguard.sh/resources/blog/aqua-vulnerability-database-avd-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aqua-vulnerability-database-avd-explained</guid>
      <pubDate>Mon, 27 Apr 2026 06:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[mocha npm: Security Review and Safe Usage]]></title>
      <description><![CDATA[The mocha npm test framework runs only code you write, so its direct risk is low, but its dependency tree generates npm audit noise worth understanding.]]></description>
      <link>https://safeguard.sh/resources/blog/mocha-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mocha-npm</guid>
      <pubDate>Mon, 27 Apr 2026 04:42:42 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Serverless security implications from infra to OWASP]]></title>
      <description><![CDATA[Serverless shrinks the OS attack surface but expands the IAM and dependency one. Here's how the OWASP Serverless Top 10 maps to real 2021-era incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/serverless-security-implications-from-infra-to-owasp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/serverless-security-implications-from-infra-to-owasp</guid>
      <pubDate>Mon, 27 Apr 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How to Choose a Security Company for Modern Software]]></title>
      <description><![CDATA[Picking a security company is less about brand recognition than about matching a vendor's real strengths to the risks your software actually faces. Here is a practical way to decide.]]></description>
      <link>https://safeguard.sh/resources/blog/security-company</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-company</guid>
      <pubDate>Mon, 27 Apr 2026 03:22:15 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Trivy sources vulnerability data (NVD, vendor advisor...]]></title>
      <description><![CDATA[Trivy's CVE data comes from NVD, GHSA, and distro trackers compiled into a periodic snapshot — not kube-hunter. Here's how the pipeline really works, and where it lags.]]></description>
      <link>https://safeguard.sh/resources/blog/how-trivy-sources-vulnerability-data-nvd-vendor-advisories-kube-hunter</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-trivy-sources-vulnerability-data-nvd-vendor-advisories-kube-hunter</guid>
      <pubDate>Mon, 27 Apr 2026 03:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Python Docker Images: How to Choose a Secure, Slim Base]]></title>
      <description><![CDATA[Choosing among Python Docker images comes down to trade-offs between size, glibc compatibility, and attack surface. Here is how the official tags differ and how to build a lean, low-CVE image.]]></description>
      <link>https://safeguard.sh/resources/blog/python-docker-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-docker-images</guid>
      <pubDate>Mon, 27 Apr 2026 02:01:49 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[10 serverless security best practices]]></title>
      <description><![CDATA[10 concrete, numbers-backed serverless security practices covering IAM least privilege, dependency SBOMs, event injection, and secrets management.]]></description>
      <link>https://safeguard.sh/resources/blog/10-serverless-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/10-serverless-security-best-practices</guid>
      <pubDate>Mon, 27 Apr 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[White Box Pen Testing: How It Works and When to Use It]]></title>
      <description><![CDATA[White box pen testing gives the tester full access to source, architecture, and credentials. Here's how it differs from black box, when to choose it, and the tools involved.]]></description>
      <link>https://safeguard.sh/resources/blog/white-box-pen-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/white-box-pen-testing</guid>
      <pubDate>Mon, 27 Apr 2026 00:41:22 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CNAPP according to Gartner: capabilities and evaluation c...]]></title>
      <description><![CDATA[Gartner's CNAPP framework demands unified risk correlation, not bundled scanners. Here's how Trivy (Aqua) maps to it — and where supply chain security closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/cnapp-according-to-gartner-capabilities-and-evaluation-criteria</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cnapp-according-to-gartner-capabilities-and-evaluation-criteria</guid>
      <pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[angular-ui-router: Security and Maintenance Guide]]></title>
      <description><![CDATA[angular-ui-router is the classic routing library for AngularJS 1.x. The library itself is stable, but the framework it depends on reached end of life, and that is the real risk to weigh.]]></description>
      <link>https://safeguard.sh/resources/blog/angular-ui-router</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/angular-ui-router</guid>
      <pubDate>Sun, 26 Apr 2026 23:20:55 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Code Checker? A Security-Focused Guide]]></title>
      <description><![CDATA[A code checker analyzes source for bugs, style issues, and security flaws before they ship. Here is how the security-relevant ones work, with a focus on Java.]]></description>
      <link>https://safeguard.sh/resources/blog/code-checker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-checker</guid>
      <pubDate>Sun, 26 Apr 2026 22:00:29 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[react-diff-view: Using the Diff Component Securely]]></title>
      <description><![CDATA[react-diff-view renders git unified diffs in React apps. Here is how it works, where the security considerations sit, and how to keep it safe when you render untrusted diffs.]]></description>
      <link>https://safeguard.sh/resources/blog/react-diff-view</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-diff-view</guid>
      <pubDate>Sun, 26 Apr 2026 20:40:02 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Enso: How the Enso Security Acquisition Added ASPM]]></title>
      <description><![CDATA[Snyk acquired Enso Security in 2023 to fold application security posture management into its platform. Here is what Enso did, what changed, and how to think about ASPM.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-enso</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-enso</guid>
      <pubDate>Sun, 26 Apr 2026 19:19:35 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[@shopify/react-native-skia: A Security and Safe-Usage Guide]]></title>
      <description><![CDATA[The @shopify/react-native-skia library brings high-performance 2D graphics to React Native. Here is an honest look at its security profile and how to install it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/shopify-react-native-skia</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shopify-react-native-skia</guid>
      <pubDate>Sun, 26 Apr 2026 17:59:09 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Python Package Repository Security: Defending Against Malicious PyPI Packages]]></title>
      <description><![CDATA[How Python package repositories become attack vectors, what happens when PyPI halts new projects during an incident, and how to consume packages safely.]]></description>
      <link>https://safeguard.sh/resources/blog/python-package-repository</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-package-repository</guid>
      <pubDate>Sun, 26 Apr 2026 16:38:42 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Rendering Markdown Securely in React Native with react-native-markdown-display]]></title>
      <description><![CDATA[react-native-markdown-display is the maintained way to render Markdown in React Native, but rendering untrusted Markdown safely takes more than dropping in the component. Here is the security guide.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-markdown-display</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-markdown-display</guid>
      <pubDate>Sun, 26 Apr 2026 15:18:15 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-32756 in FortiVoice: HTTP Stack Overflow to Root RCE]]></title>
      <description><![CDATA[A stack-based buffer overflow in FortiVoice and FortiMail web portals lets unauthenticated attackers execute root commands over HTTPS.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2025-32756-fortivoice-stack-overflow-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2025-32756-fortivoice-stack-overflow-analysis</guid>
      <pubDate>Sun, 26 Apr 2026 13:57:48 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes SecurityContext Capabilities: Drop vs Add]]></title>
      <description><![CDATA[Kubernetes securityContext capabilities let you strip Linux kernel privileges from a container instead of accepting the runtime default set — here's when to drop, when to add back, and why dropping ALL first is the right starting point.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-security-context-capabilities-drop-vs-add</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-security-context-capabilities-drop-vs-add</guid>
      <pubDate>Sun, 26 Apr 2026 12:37:22 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Open Source SAST Tools Worth Evaluating]]></title>
      <description><![CDATA[A rundown of the open source SAST tools engineering teams actually use in production, and where each one runs out of road.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-sast-tools-worth-evaluating</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-sast-tools-worth-evaluating</guid>
      <pubDate>Sun, 26 Apr 2026 11:16:55 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Best Open Source SCA Tools in 2026 (Tested on a Real Monorepo)]]></title>
      <description><![CDATA[OSV-Scanner, Trivy, Grype, Dependency-Check, and dep-scan, all run against the same 4,300-dependency monorepo. Recall, false positives, and scan times measured.]]></description>
      <link>https://safeguard.sh/resources/blog/best-open-source-sca-tools-in-2026-tested-on-a-real-monorepo</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-open-source-sca-tools-in-2026-tested-on-a-real-monorepo</guid>
      <pubDate>Sun, 26 Apr 2026 11:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Marcus Webb)</author>
    </item>
    <item>
      <title><![CDATA[Model Weights as Supply Chain Artifacts: Signing and Provenance]]></title>
      <description><![CDATA[A 4 GB safetensors file deserves the same signing, hashing, and provenance discipline as a container image. How to actually do it with Sigstore, OCI registries, and AIBOMs.]]></description>
      <link>https://safeguard.sh/resources/blog/model-weights-as-supply-chain-artifacts-signing-and-provenance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/model-weights-as-supply-chain-artifacts-signing-and-provenance</guid>
      <pubDate>Sun, 26 Apr 2026 11:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Securing AWS Lambda cold starts and execution permissions]]></title>
      <description><![CDATA[Lambda cold starts inject live IAM credentials into shared execution environments — here's how over-permissioned roles and vulnerable layers turn that into a real attack surface.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-aws-lambda-cold-starts-and-execution-permissions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-aws-lambda-cold-starts-and-execution-permissions</guid>
      <pubDate>Sun, 26 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Licence logicielle : le guide securite et conformite]]></title>
      <description><![CDATA[Ce qu'est une licence logicielle, pourquoi elle constitue un risque de securite et de conformite dans vos dependances open source, et comment la gerer concretement.]]></description>
      <link>https://safeguard.sh/resources/blog/licence-logicielle</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/licence-logicielle</guid>
      <pubDate>Sun, 26 Apr 2026 09:56:28 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Container image scanning: how it works and best tools]]></title>
      <description><![CDATA[A practical guide to container image scanning: how layer-by-layer CVE detection works, how Trivy stacks up, and where Safeguard adds deeper coverage.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-scanning-how-it-works-and-best-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-scanning-how-it-works-and-best-tools</guid>
      <pubDate>Sun, 26 Apr 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[TinyMCE npm Security: XSS History and Safe Configuration]]></title>
      <description><![CDATA[The tinymce npm package is a capable rich-text editor with a long history of XSS advisories. Keeping it current and configuring it defensively is what keeps it safe.]]></description>
      <link>https://safeguard.sh/resources/blog/tinymce-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tinymce-npm</guid>
      <pubDate>Sun, 26 Apr 2026 08:36:02 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-4641: The shadow-utils Password Leak Explained]]></title>
      <description><![CDATA[CVE-2023-4641 is an information-disclosure flaw in shadow-utils where a failed password change can leave the entered password lingering in memory. Here is who is affected and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-4641</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-4641</guid>
      <pubDate>Sun, 26 Apr 2026 07:15:35 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[WebAssembly (WASM) security considerations]]></title>
      <description><![CDATA[A 2018 WASM cryptominer hit 4,275+ websites in a day. Learn WebAssembly's real security risks, from memory bugs to supply chain blind spots.]]></description>
      <link>https://safeguard.sh/resources/blog/webassembly-wasm-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webassembly-wasm-security-considerations</guid>
      <pubDate>Sun, 26 Apr 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Container security best practices checklist]]></title>
      <description><![CDATA[A practical container security checklist covering base images, scanning limits, runtime risk, and why CVE scans like Trivy alone miss most real supply chain threats.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-best-practices-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-best-practices-checklist</guid>
      <pubDate>Sun, 26 Apr 2026 06:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Injection in JavaScript: Security Notes]]></title>
      <description><![CDATA[Dependency injection in JavaScript makes code testable and modular, but the same indirection that helps design can hide security bugs if you're not careful about what gets injected.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-injection-in-javascript-security-notes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-injection-in-javascript-security-notes</guid>
      <pubDate>Sun, 26 Apr 2026 05:55:08 GMT</pubDate>
      <category>Dev Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Apache Licence Explained: What the Apache 2.0 Licence Means for Your Code]]></title>
      <description><![CDATA[The Apache licence is permissive but not effortless. Here is what Apache 2.0 actually requires — the patent grant, the NOTICE file, and where it clashes with GPL.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-licence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-licence</guid>
      <pubDate>Sun, 26 Apr 2026 04:34:42 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing gRPC microservice communication]]></title>
      <description><![CDATA[gRPC's binary, multiplexed transport breaks REST-era security tooling. Here's how to fix mTLS gaps, reflection exposure, and per-method authorization.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-grpc-microservice-communication</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-grpc-microservice-communication</guid>
      <pubDate>Sun, 26 Apr 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What Is SBOM Security, and Why Does It Matter?]]></title>
      <description><![CDATA[SBOM security is the practice of using a software bill of materials to actually find and act on risk in your dependencies, not just to produce a compliance document.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-sbom-security-and-why-it-matters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-sbom-security-and-why-it-matters</guid>
      <pubDate>Sun, 26 Apr 2026 03:14:15 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Docker CIS Benchmark: what it checks and how to pass it]]></title>
      <description><![CDATA[A practical breakdown of what the CIS Docker Benchmark actually checks, why Trivy alone only covers part of it, and how to remediate and stay compliant.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-cis-benchmark-what-it-checks-and-how-to-pass-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-cis-benchmark-what-it-checks-and-how-to-pass-it</guid>
      <pubDate>Sun, 26 Apr 2026 03:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Online Security Courses and Training Platforms Worth Your Time]]></title>
      <description><![CDATA[There are hundreds of online security courses competing for your attention — here's how to pick a cybersecurity training platform that actually builds skill, plus where to find solid owasp top 10 training free of charge.]]></description>
      <link>https://safeguard.sh/resources/blog/online-security-courses-and-training-platforms-worth-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/online-security-courses-and-training-platforms-worth-it</guid>
      <pubDate>Sun, 26 Apr 2026 01:53:48 GMT</pubDate>
      <category>Culture</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Microservices security: authentication between services]]></title>
      <description><![CDATA[Service-to-service auth stops lateral movement between microservices. Learn how mTLS, OAuth2, and SPIFFE/SPIRE secure internal calls in production.]]></description>
      <link>https://safeguard.sh/resources/blog/microservices-security-authentication-between-services</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microservices-security-authentication-between-services</guid>
      <pubDate>Sun, 26 Apr 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Code Injection in Python: How It Happens and How to Prevent It]]></title>
      <description><![CDATA[Code injection python vulnerabilities almost always trace back to eval, exec, or a template engine handed untrusted input; here is how the attack works and how to close it off.]]></description>
      <link>https://safeguard.sh/resources/blog/code-injection-in-python-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-injection-in-python-explained</guid>
      <pubDate>Sun, 26 Apr 2026 00:33:22 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Container escape attacks: how they happen and how to prev...]]></title>
      <description><![CDATA[Container escapes rarely need a zero-day — privileged flags, mounted sockets, and excess capabilities do the job. Here's how they happen, real CVEs, and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/container-escape-attacks-how-they-happen-and-how-to-prevent-them</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-escape-attacks-how-they-happen-and-how-to-prevent-them</guid>
      <pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[org.apache.tomcat.embed: Embedded Tomcat Versions and Vulnerabilities]]></title>
      <description><![CDATA[org.apache.tomcat.embed ships inside almost every Spring Boot jar, and its CVEs follow it there. Here is how to find your real embedded Tomcat version and patch it.]]></description>
      <link>https://safeguard.sh/resources/blog/tomcat-embed-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tomcat-embed-security-guide</guid>
      <pubDate>Sat, 25 Apr 2026 23:12:55 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Static Code Analysis in Cyber Security: What It Actually Does]]></title>
      <description><![CDATA[Static code analysis in cyber security means scanning source code without running it to catch injection flaws, hardcoded secrets, and unsafe patterns before they ship — here's what it catches and what it misses.]]></description>
      <link>https://safeguard.sh/resources/blog/static-code-analysis-in-cyber-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-code-analysis-in-cyber-security</guid>
      <pubDate>Sat, 25 Apr 2026 21:52:28 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[PHP Code Analyzer Tools: A Security Guide]]></title>
      <description><![CDATA[A PHP code analyzer inspects your source without running it to catch security flaws, type errors, and bad patterns. Here's how static analysis fits a secure PHP workflow and which tools matter.]]></description>
      <link>https://safeguard.sh/resources/blog/php-code-analyzer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-code-analyzer</guid>
      <pubDate>Sat, 25 Apr 2026 20:32:01 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[vite-plugin-node-polyfills: A Security-Minded Setup Guide]]></title>
      <description><![CDATA[vite-plugin-node-polyfills injects browser shims for Node built-ins so npm packages that expect Buffer or process work in Vite. Convenient, but every polyfill you add is code that ships.]]></description>
      <link>https://safeguard.sh/resources/blog/vite-plugin-node-polyfills</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vite-plugin-node-polyfills</guid>
      <pubDate>Sat, 25 Apr 2026 19:11:35 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Snyk in Boston: The Company Behind the Developer Security Tool]]></title>
      <description><![CDATA[Snyk runs its headquarters out of Boston. Here is what the company does, where the office sits, and how developer-first security fits into a modern pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-boston</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-boston</guid>
      <pubDate>Sat, 25 Apr 2026 17:51:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[MTTR in DevOps: How to Measure and Actually Improve Recovery Time]]></title>
      <description><![CDATA[MTTR is one of the four DORA metrics and the clearest signal of how resilient your delivery really is. Here is how to measure it honestly and drive it down.]]></description>
      <link>https://safeguard.sh/resources/blog/mttr-devops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mttr-devops</guid>
      <pubDate>Sat, 25 Apr 2026 16:30:41 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The Benefits of Rust: A Security Guide for Practitioners]]></title>
      <description><![CDATA[Rust's biggest benefit is that it eliminates whole classes of memory-safety bugs at compile time. Here is what that means for security teams and where the limits are.]]></description>
      <link>https://safeguard.sh/resources/blog/benefits-of-rust</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/benefits-of-rust</guid>
      <pubDate>Sat, 25 Apr 2026 15:10:15 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Website Vulnerability Scanners: How They Work and What They Miss]]></title>
      <description><![CDATA[How a website vulnerability scanner crawls, fuzzes, and fingerprints your app, plus the whole classes of flaws it structurally cannot find on its own.]]></description>
      <link>https://safeguard.sh/resources/blog/website-vulnerability-scanners-how-they-work</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/website-vulnerability-scanners-how-they-work</guid>
      <pubDate>Sat, 25 Apr 2026 13:49:48 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Mobile App Security Testing with OWASP MASVS in 2026]]></title>
      <description><![CDATA[How to build a practical mobile app security testing program around OWASP MASVS 2.1, with the verification techniques that actually catch real issues.]]></description>
      <link>https://safeguard.sh/resources/blog/mobile-app-security-testing-owasp-masvs-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mobile-app-security-testing-owasp-masvs-2026</guid>
      <pubDate>Sat, 25 Apr 2026 13:45:00 GMT</pubDate>
      <category>Mobile Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How .dockerignore Protects Your Builds: A Security Guide]]></title>
      <description><![CDATA[A well-written docker ignore file keeps secrets, git history, and local cruft out of your images — one of the cheapest and most overlooked container security wins.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-ignore</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-ignore</guid>
      <pubDate>Sat, 25 Apr 2026 12:29:21 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Threat Modelling: STRIDE, PASTA, and a Process That Ships]]></title>
      <description><![CDATA[Threat modelling fails when it becomes a 40-page document nobody reads. Here is what STRIDE and PASTA actually offer, and a lightweight process that survives contact with sprint deadlines.]]></description>
      <link>https://safeguard.sh/resources/blog/threat-modelling-stride-pasta-process</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/threat-modelling-stride-pasta-process</guid>
      <pubDate>Sat, 25 Apr 2026 11:08:55 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Intelligence Platform Comparison 2026]]></title>
      <description><![CDATA[A working comparison of vulnerability intelligence platforms in 2026, evaluating data freshness, exploit signal, AI infrastructure coverage, and integration patterns.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-intelligence-platform-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-intelligence-platform-comparison-2026</guid>
      <pubDate>Sat, 25 Apr 2026 10:45:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[The State of Open Source Security report (annual series)]]></title>
      <description><![CDATA[Safeguard's annual State of Open Source Security Report finds transitive dependencies now drive most exposure, and reachability — not CVSS alone — separates mature security programs.]]></description>
      <link>https://safeguard.sh/resources/blog/the-state-of-open-source-security-report-annual-series</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-state-of-open-source-security-report-annual-series</guid>
      <pubDate>Sat, 25 Apr 2026 10:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Security Risks: The Threats That Actually Matter]]></title>
      <description><![CDATA[The real Kubernetes security risks are misconfiguration, over-permissive RBAC, exposed control planes, and vulnerable images, not exotic zero-days. Here's how to prioritize.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-security-risks</guid>
      <pubDate>Sat, 25 Apr 2026 09:48:28 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Compare SCA Offerings Before Buying in 2026]]></title>
      <description><![CDATA[A buyer's framework for evaluating SCA products in 2026: what to test, what to ignore in vendor pitches, and how to size the operational cost honestly.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-compare-sca-offerings-before-buying-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-compare-sca-offerings-before-buying-2026</guid>
      <pubDate>Sat, 25 Apr 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Software supply chain attacks: how they work and recent e...]]></title>
      <description><![CDATA[Software supply chain attacks like SolarWinds, xz-utils, and polyfill.io bypass vulnerability scanners entirely. Here's how they work and where provenance verification fills the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-attacks-how-they-work-and-recent-examples</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-attacks-how-they-work-and-recent-examples</guid>
      <pubDate>Sat, 25 Apr 2026 09:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[AI Coding Assistant Security: 2026 Buyer Comparison]]></title>
      <description><![CDATA[A security-focused buyer comparison of AI coding assistants in 2026: code quality risk, data exfiltration controls, license exposure, and policy enforcement.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-coding-assistant-security-buyer-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-coding-assistant-security-buyer-comparison-2026</guid>
      <pubDate>Sat, 25 Apr 2026 08:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-20188 in Cisco IOS XE WLC: Hardcoded JWT to Root RCE]]></title>
      <description><![CDATA[A hardcoded JSON Web Token in Cisco's Wireless LAN Controller gives unauthenticated attackers a path to root via arbitrary file upload.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2025-20188-cisco-wlc-jwt-rce-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2025-20188-cisco-wlc-jwt-rce-analysis</guid>
      <pubDate>Sat, 25 Apr 2026 08:28:01 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SAST Testing: How Static Analysis Finds Bugs Before They Run]]></title>
      <description><![CDATA[A SAST test analyzes source code without executing it to find vulnerabilities like injection and hardcoded secrets. Here is how it works and where it fits.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-test</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-test</guid>
      <pubDate>Sat, 25 Apr 2026 07:07:35 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The State of Cloud Native Application Security survey]]></title>
      <description><![CDATA[New 2026 survey data reveals a widening gap between vulnerability alert volume and remediation capacity — and what security teams say actually helps.]]></description>
      <link>https://safeguard.sh/resources/blog/the-state-of-cloud-native-application-security-survey</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-state-of-cloud-native-application-security-survey</guid>
      <pubDate>Sat, 25 Apr 2026 07:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Container image signing and verification]]></title>
      <description><![CDATA[Scanning tells you what's inside a container image; signing proves where it came from. Here's how signature verification closes the gap that CVE scanners like Trivy leave open.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-signing-and-verification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-signing-and-verification</guid>
      <pubDate>Sat, 25 Apr 2026 06:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Dior Customer Data Breach 2025: Luxury Fashion's Cybersecurity Problem]]></title>
      <description><![CDATA[Christian Dior disclosed a breach exposing customer personal data in May 2025. The luxury sector's data protection challenges are now front and center.]]></description>
      <link>https://safeguard.sh/resources/blog/dior-customer-data-breach-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dior-customer-data-breach-2025</guid>
      <pubDate>Sat, 25 Apr 2026 05:47:08 GMT</pubDate>
      <category>Breach Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Docker Privileged Mode: What --privileged Really Grants and Safer Options]]></title>
      <description><![CDATA[Docker Compose privileged mode hands a container nearly all host capabilities. Here is what --privileged actually turns on, and the scoped alternatives that do the same job safely.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-privileged-mode-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-privileged-mode-risks</guid>
      <pubDate>Sat, 25 Apr 2026 04:26:41 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[PulseMeter report: software supply chain risk perceptions]]></title>
      <description><![CDATA[Safeguard's latest PulseMeter survey finds 71% of teams hit a supply chain incident this year, but only 34% feel confident they'd catch one in time.]]></description>
      <link>https://safeguard.sh/resources/blog/pulsemeter-report-software-supply-chain-risk-perceptions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pulsemeter-report-software-supply-chain-risk-perceptions</guid>
      <pubDate>Sat, 25 Apr 2026 04:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Local Storage Security: What to Store and What Never To]]></title>
      <description><![CDATA[Local storage security comes down to one rule most apps break: the browser's localStorage is readable by any JavaScript on the page, so it is no place for secrets.]]></description>
      <link>https://safeguard.sh/resources/blog/local-storage-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/local-storage-security</guid>
      <pubDate>Sat, 25 Apr 2026 03:06:14 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[NPM package vulnerabilities: risks and detection]]></title>
      <description><![CDATA[NPM's open, high-velocity ecosystem makes it a top target for supply chain attacks. Here's how vulnerabilities slip past scanners like Trivy undetected.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-package-vulnerabilities-risks-and-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-package-vulnerabilities-risks-and-detection</guid>
      <pubDate>Sat, 25 Apr 2026 03:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[MagicMock in Python: Safe Testing and the Traps to Avoid]]></title>
      <description><![CDATA[MagicMock in Python makes tests easy to write and easy to make lie. Here is how it differs from Mock and how to keep mocks from hiding real security bugs.]]></description>
      <link>https://safeguard.sh/resources/blog/magicmock-python</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/magicmock-python</guid>
      <pubDate>Sat, 25 Apr 2026 01:45:48 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The State of Agentic AI Adoption report]]></title>
      <description><![CDATA[New survey data on the state of agentic AI adoption shows enterprises racing to deploy autonomous agents faster than security teams can govern them.]]></description>
      <link>https://safeguard.sh/resources/blog/the-state-of-agentic-ai-adoption-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-state-of-agentic-ai-adoption-report</guid>
      <pubDate>Sat, 25 Apr 2026 01:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[React Native Image Libraries: fast-image, slider-box, crop-picker Reviewed]]></title>
      <description><![CDATA[react-native-image-slider-box, fast-image, and image-crop-picker solve real UI problems, but their maintenance status and native code deserve a hard look before you ship them.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-image-libraries-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-image-libraries-security-review</guid>
      <pubDate>Sat, 25 Apr 2026 00:25:21 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability prioritization: moving beyond CVSS scores]]></title>
      <description><![CDATA[CVSS scores flood teams with thousands of "Critical" findings, but fewer than 5% of CVEs are ever exploited. Here's how reachability and exploit data fix triage.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-prioritization-moving-beyond-cvss-scores</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-prioritization-moving-beyond-cvss-scores</guid>
      <pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Software Licence? A Plain-English Guide]]></title>
      <description><![CDATA[A software licence is the legal agreement that defines how you may use, copy, modify, and distribute a piece of software. Here is how the main types differ and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-software-licence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-software-licence</guid>
      <pubDate>Fri, 24 Apr 2026 23:04:54 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Gray Box Testing Explained: A Security Guide]]></title>
      <description><![CDATA[Gray box testing gives a tester partial internal knowledge, splitting the difference between black box and white box. Here is when it finds bugs the other two miss.]]></description>
      <link>https://safeguard.sh/resources/blog/gray-box-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gray-box-testing</guid>
      <pubDate>Fri, 24 Apr 2026 21:44:28 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is Linting in Code? A Security Perspective]]></title>
      <description><![CDATA[Linting is automated static analysis that catches bugs, style issues, and security anti-patterns before code runs. Here is what it does and where it fits in a secure pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-linting-in-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-linting-in-code</guid>
      <pubDate>Fri, 24 Apr 2026 20:24:01 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Statische Code-Analyse: Sicherheitsluecken finden, bevor Code laeuft]]></title>
      <description><![CDATA[Statische Code-Analyse prueft Quellcode ohne ihn auszufuehren und findet Sicherheitsluecken frueh. So funktioniert sie und welche Tools sich lohnen.]]></description>
      <link>https://safeguard.sh/resources/blog/statische-code-analyse</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/statische-code-analyse</guid>
      <pubDate>Fri, 24 Apr 2026 19:03:34 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Git Checkout Dev: Switching to a Development Branch Safely]]></title>
      <description><![CDATA[git checkout dev switches your working tree to the dev branch, but the safe workflow around it matters more than the command. Here is how to do it without losing work or leaking secrets.]]></description>
      <link>https://safeguard.sh/resources/blog/git-checkout-dev</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-checkout-dev</guid>
      <pubDate>Fri, 24 Apr 2026 17:43:08 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Docker Privileged Containers: `docker run` and Compose Risks]]></title>
      <description><![CDATA[docker run privileged and docker compose privileged both hand a container root-equivalent access to the host — here's exactly what that means and when, if ever, it's justified.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-privileged-containers-run-and-compose</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-privileged-containers-run-and-compose</guid>
      <pubDate>Fri, 24 Apr 2026 16:22:41 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Web Application Penetration Testing: What to Expect]]></title>
      <description><![CDATA[A real web application penetration test follows a scoped, multi-phase process — here's what happens before, during, and after the engagement so the report doesn't surprise you.]]></description>
      <link>https://safeguard.sh/resources/blog/web-application-penetration-testing-what-to-expect</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-application-penetration-testing-what-to-expect</guid>
      <pubDate>Fri, 24 Apr 2026 15:02:14 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Trivy Action: How to Use It in CI Without Getting Burned]]></title>
      <description><![CDATA[The Trivy Action runs Aqua Security's scanner inside GitHub Actions. Here is how to wire it up, and why aquasecurity/trivy-action@master is the wrong way to pin it.]]></description>
      <link>https://safeguard.sh/resources/blog/trivy-action</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trivy-action</guid>
      <pubDate>Fri, 24 Apr 2026 13:41:47 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Puppeteer on npm: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[puppeteer npm installs a library that drives a real headless Chrome. That power brings real risks — install scripts, SSRF, and a browser-sized attack surface. Here is how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/puppeteer-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/puppeteer-npm</guid>
      <pubDate>Fri, 24 Apr 2026 12:21:21 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[tough-cookie npm: Security Review and Safe Usage]]></title>
      <description><![CDATA[A security review of the tough-cookie npm package, including the CVE-2023-26136 prototype pollution flaw, the version that fixes it, and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/tough-cookie-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tough-cookie-npm</guid>
      <pubDate>Fri, 24 Apr 2026 11:00:54 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AI Trust Report: developer sentiment on AI-generated code]]></title>
      <description><![CDATA[Safeguard's 2026 AI Trust Report surveyed 1,412 developers and finds 91% use AI coding tools weekly, but only 34% trust the code it produces.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-trust-report-developer-sentiment-on-ai-generated-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-trust-report-developer-sentiment-on-ai-generated-code</guid>
      <pubDate>Fri, 24 Apr 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SLSA v1.1 Build Track: What Approved Means for Adopters]]></title>
      <description><![CDATA[SLSA v1.1 was approved in April 2025 with the Build track stabilized. We dig into the spec changes, what L2 and L3 verifiers must reject, and how producers should re-evaluate provenance.]]></description>
      <link>https://safeguard.sh/resources/blog/slsa-v1-1-build-track-adoption-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slsa-v1-1-build-track-adoption-2025</guid>
      <pubDate>Fri, 24 Apr 2026 09:40:27 GMT</pubDate>
      <category>Frameworks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Risk-based vulnerability management explained]]></title>
      <description><![CDATA[Why CVSS severity alone fails to prioritize vulnerabilities, how Trivy's default scoring falls short, and how EPSS, CISA KEV, and reachability data cut remediation backlogs by 95%+.]]></description>
      <link>https://safeguard.sh/resources/blog/risk-based-vulnerability-management-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/risk-based-vulnerability-management-explained</guid>
      <pubDate>Fri, 24 Apr 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSF Model Signing v1.0: Sigstore for ML]]></title>
      <description><![CDATA[OpenSSF launched Model Signing v1.0 in April 2025 with Sigstore integration. NVIDIA NGC adopted it the same month. We explain what it signs, how to verify, and where the gaps are.]]></description>
      <link>https://safeguard.sh/resources/blog/openssf-model-signing-v1-0-sigstore-ml-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssf-model-signing-v1-0-sigstore-ml-supply-chain</guid>
      <pubDate>Fri, 24 Apr 2026 08:20:01 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[5 risks of open source software in 2026]]></title>
      <description><![CDATA[Open source now makes up most enterprise code. Here are 5 risks defining open source software security in 2026 — and how to close the exploitability gap.]]></description>
      <link>https://safeguard.sh/resources/blog/5-risks-of-open-source-software-in-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/5-risks-of-open-source-software-in-2026</guid>
      <pubDate>Fri, 24 Apr 2026 07:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Hitachi Vantara Akira Ransomware: When the Recovery Vendor Goes Down]]></title>
      <description><![CDATA[Akira ransomware forced Hitachi Vantara to take its own servers offline on April 26, 2025. We trace the attack pattern and the implications when an enterprise data-recovery provider becomes the incident.]]></description>
      <link>https://safeguard.sh/resources/blog/hitachi-vantara-akira-ransomware-april-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hitachi-vantara-akira-ransomware-april-2025</guid>
      <pubDate>Fri, 24 Apr 2026 06:59:34 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to reduce alert fatigue from vulnerability scanners]]></title>
      <description><![CDATA[Container scanners like Trivy can return thousands of CVE findings per scan. Here's why most are noise, and how reachability and exploit data cut the list to what matters.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-reduce-alert-fatigue-from-vulnerability-scanners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-reduce-alert-fatigue-from-vulnerability-scanners</guid>
      <pubDate>Fri, 24 Apr 2026 06:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Cross-Site Scripting Vulnerability, and How Do You Fix It?]]></title>
      <description><![CDATA[A cross-site scripting vulnerability lets an attacker run their JavaScript in your users' browsers, and you fix it by encoding output and validating input at the right boundaries.]]></description>
      <link>https://safeguard.sh/resources/blog/cross-site-scripting-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cross-site-scripting-vulnerability</guid>
      <pubDate>Fri, 24 Apr 2026 05:39:07 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Choosing a Private Package Registry in 2025]]></title>
      <description><![CDATA[A 2025 buyer's guide comparing JFrog Artifactory, Sonatype Nexus, GitHub Packages, Google Artifact Registry, and Cloudsmith on ecosystems, policy, and TCO.]]></description>
      <link>https://safeguard.sh/resources/blog/choosing-a-private-package-registry-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/choosing-a-private-package-registry-2025</guid>
      <pubDate>Fri, 24 Apr 2026 04:18:41 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript frameworks security report]]></title>
      <description><![CDATA[Safeguard's H1 2026 audit finds 61% of JS repos ship a high-severity framework CVE, with a 47-day median patch lag attackers routinely beat.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-frameworks-security-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-frameworks-security-report</guid>
      <pubDate>Fri, 24 Apr 2026 04:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CIEM vs. CSPM: what's the difference?]]></title>
      <description><![CDATA[CIEM secures who can access cloud resources; CSPM secures how resources are configured. Neither covers the software you actually ship — that is Safeguard territory.]]></description>
      <link>https://safeguard.sh/resources/blog/ciem-vs-cspm-whats-the-difference</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ciem-vs-cspm-whats-the-difference</guid>
      <pubDate>Fri, 24 Apr 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[isomorphic-fetch: Security Review and Modern Alternatives]]></title>
      <description><![CDATA[isomorphic-fetch has not shipped a release since 2020, yet thousands of projects still install it. What that means for your security posture, and what to use instead.]]></description>
      <link>https://safeguard.sh/resources/blog/isomorphic-fetch-npm-security-and-alternatives</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/isomorphic-fetch-npm-security-and-alternatives</guid>
      <pubDate>Fri, 24 Apr 2026 02:58:14 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[IAST Meaning: What Interactive Application Security Testing Does]]></title>
      <description><![CDATA[IAST instruments a running application from the inside, watching real execution to confirm vulnerabilities with far fewer false positives than static scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/iast-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iast-meaning</guid>
      <pubDate>Fri, 24 Apr 2026 01:37:47 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[162 vulnerabilities disclosed in Java's top 10 libraries]]></title>
      <description><![CDATA[Safeguard's H1 2026 analysis found 162 CVEs across Java's ten most-downloaded libraries, with critical RCE risk concentrated in Tomcat and Spring.]]></description>
      <link>https://safeguard.sh/resources/blog/162-vulnerabilities-disclosed-in-javas-top-10-libraries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/162-vulnerabilities-disclosed-in-javas-top-10-libraries</guid>
      <pubDate>Fri, 24 Apr 2026 01:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[angular-auth-oidc-client: A Security-Focused Guide to Angular OIDC]]></title>
      <description><![CDATA[angular-auth-oidc-client is a certified Angular library for OpenID Connect and OAuth2. Here is how to use it and how to configure it securely.]]></description>
      <link>https://safeguard.sh/resources/blog/angular-auth-oidc-client</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/angular-auth-oidc-client</guid>
      <pubDate>Fri, 24 Apr 2026 00:17:21 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CNAPP vs. CSPM: how the categories relate]]></title>
      <description><![CDATA[CSPM is a module inside CNAPP, not a rival to it — and neither covers what happens before deployment. Here's how Wiz's cloud posture graph and Safeguard's supply chain layer fit together.]]></description>
      <link>https://safeguard.sh/resources/blog/cnapp-vs-cspm-how-the-categories-relate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cnapp-vs-cspm-how-the-categories-relate</guid>
      <pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Python unittest.mock: A Practical Guide with Security in Mind]]></title>
      <description><![CDATA[Python's unittest.mock lets you test the code you would never dare run for real — including the security-critical failure paths that never fire in a happy-path test.]]></description>
      <link>https://safeguard.sh/resources/blog/python-unittest-mock</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-unittest-mock</guid>
      <pubDate>Thu, 23 Apr 2026 22:56:54 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Maven SBOM: How to Generate a Software Bill of Materials for Java Builds]]></title>
      <description><![CDATA[A Maven SBOM inventories every direct and transitive dependency in your Java build. Here is how to generate one with the CycloneDX plugin and put it to work for security.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-sbom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-sbom</guid>
      <pubDate>Thu, 23 Apr 2026 21:36:27 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[msw (npm): Mock Service Worker Without Leaking Mocks Into Production]]></title>
      <description><![CDATA[The msw npm package is a superb API mocking tool, and its main security risk is operational: shipping a service worker or a mock server into production.]]></description>
      <link>https://safeguard.sh/resources/blog/msw-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/msw-npm</guid>
      <pubDate>Thu, 23 Apr 2026 20:16:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Software Supply Chain Management with Safeguard ESSCM]]></title>
      <description><![CDATA[A practical guide to implementing Safeguard's Enterprise Software Supply Chain Management framework across large organizations with complex dependency ecosystems.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-esscm-enterprise-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-esscm-enterprise-guide</guid>
      <pubDate>Thu, 23 Apr 2026 18:55:34 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVSS 4.0 Release Date, Changes, and Adoption Status]]></title>
      <description><![CDATA[The CVSS 4.0 release date was November 1, 2023 — here is what changed from v3.1, how the new metric groups work, and where real-world adoption stands.]]></description>
      <link>https://safeguard.sh/resources/blog/cvss-4-release-date-and-adoption</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cvss-4-release-date-and-adoption</guid>
      <pubDate>Thu, 23 Apr 2026 17:35:07 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[GPL Meaning Explained: What the GNU General Public License Requires]]></title>
      <description><![CDATA[GPL means GNU General Public License, a copyleft license that grants broad freedoms but requires you to share source under the same terms. Here is what that means for your code.]]></description>
      <link>https://safeguard.sh/resources/blog/gpl-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gpl-meaning</guid>
      <pubDate>Thu, 23 Apr 2026 16:14:40 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What Is License Contamination?]]></title>
      <description><![CDATA[One GPL dependency in the wrong place can put your proprietary source code under copyleft obligations. How license contamination happens and how to prevent it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-license-contamination</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-license-contamination</guid>
      <pubDate>Thu, 23 Apr 2026 14:54:14 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Code Quality Tools That Also Strengthen Your Security]]></title>
      <description><![CDATA[Code quality tools do more than catch style nits; the good ones surface the same weak patterns that turn into vulnerabilities. Here is how quality tooling and security overlap, with a focus on Java.]]></description>
      <link>https://safeguard.sh/resources/blog/code-quality-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-quality-tools</guid>
      <pubDate>Thu, 23 Apr 2026 13:33:47 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Python on macOS: A Security-Minded Setup Guide]]></title>
      <description><![CDATA[Running Python on Mac OS is easy to get wrong in ways that bite you later. Here is how to install and isolate Python for Mac OS without the common security traps.]]></description>
      <link>https://safeguard.sh/resources/blog/python-mac-os</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-mac-os</guid>
      <pubDate>Thu, 23 Apr 2026 12:13:20 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[jQuery 3.6.0 Vulnerabilities: What Is Actually Exploitable]]></title>
      <description><![CDATA[Scanners keep flagging jQuery 3.6.0 as vulnerable — but jQuery core in that version has no known direct CVEs. Here is what the alerts really mean and where the exploitable risk actually lives.]]></description>
      <link>https://safeguard.sh/resources/blog/jquery-3-6-0-vulnerabilities-exploitable</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jquery-3-6-0-vulnerabilities-exploitable</guid>
      <pubDate>Thu, 23 Apr 2026 10:52:54 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Annual DevSecOps maturity benchmark report]]></title>
      <description><![CDATA[Safeguard's 2026 DevSecOps Maturity Benchmark finds detection at an all-time high but remediation stuck at a 19-day median — here's what separates the top-quartile programs.]]></description>
      <link>https://safeguard.sh/resources/blog/annual-devsecops-maturity-benchmark-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/annual-devsecops-maturity-benchmark-report</guid>
      <pubDate>Thu, 23 Apr 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Security Issues: Common Risks and How to Fix Them]]></title>
      <description><![CDATA[The JavaScript security issues that bite most teams are XSS, prototype pollution, vulnerable npm dependencies, and leaked secrets. Here is how each works and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-security-issues</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-security-issues</guid>
      <pubDate>Thu, 23 Apr 2026 09:32:27 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[ASM vs. Penetration Testing: how they differ and work tog...]]></title>
      <description><![CDATA[ASM and pen testing measure different things at different speeds. See how Safeguard's supply-chain-native ASM complements cloud-focused tools like Wiz—and manual testing.]]></description>
      <link>https://safeguard.sh/resources/blog/asm-vs-penetration-testing-how-they-differ-and-work-together</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/asm-vs-penetration-testing-how-they-differ-and-work-together</guid>
      <pubDate>Thu, 23 Apr 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Is turndown on npm Safe? A Security Review]]></title>
      <description><![CDATA[turndown converts HTML to Markdown with no known CVEs, but the real risk is what you do with its input and output. Here is how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/turndown-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/turndown-npm</guid>
      <pubDate>Thu, 23 Apr 2026 08:12:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Developer survey: security friction in the SDLC]]></title>
      <description><![CDATA[A new Safeguard survey of 540 developers finds most have shipped code with known security warnings, driven by alert fatigue and manual SBOM work.]]></description>
      <link>https://safeguard.sh/resources/blog/developer-survey-security-friction-in-the-sdlc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/developer-survey-security-friction-in-the-sdlc</guid>
      <pubDate>Thu, 23 Apr 2026 07:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Enso Security and ASPM: What It Is and Why It Matters]]></title>
      <description><![CDATA[Enso Security pioneered Application Security Posture Management before its 2023 acquisition by Snyk. Here is what ASPM solves and how the category has evolved.]]></description>
      <link>https://safeguard.sh/resources/blog/enso-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enso-security</guid>
      <pubDate>Thu, 23 Apr 2026 06:51:34 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Attack Surface Management Tools: 2026 comparison guide]]></title>
      <description><![CDATA[Wiz secures your cloud footprint; Safeguard secures what ships into it. A 2026 comparison of attack surface management tools across supply chain vs. cloud scope.]]></description>
      <link>https://safeguard.sh/resources/blog/attack-surface-management-tools-2026-comparison-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/attack-surface-management-tools-2026-comparison-guide</guid>
      <pubDate>Thu, 23 Apr 2026 06:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[org.springframework:spring-web: Known CVEs and How to Stay Patched]]></title>
      <description><![CDATA[A security-focused look at org.springframework:spring-web, including the Spring4Shell RCE, how spring-web relates to spring-webmvc, and how to keep the dependency safe.]]></description>
      <link>https://safeguard.sh/resources/blog/org-springframework-spring-web</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/org-springframework-spring-web</guid>
      <pubDate>Thu, 23 Apr 2026 05:31:07 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[pako on npm: Security Review and Safe Usage of the zlib Port]]></title>
      <description><![CDATA[pako is a fast JavaScript port of zlib used for gzip and deflate in the browser and Node. Here is its security profile and how to use it safely on untrusted compressed input.]]></description>
      <link>https://safeguard.sh/resources/blog/pako-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pako-npm</guid>
      <pubDate>Thu, 23 Apr 2026 04:10:40 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Snyk integrates with GitHub Advanced Security]]></title>
      <description><![CDATA[Snyk's scanning engine is now embedded in GitHub Advanced Security. Here's what the integration covers, why it matters, and the alert-fatigue risk it creates.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-integrates-with-github-advanced-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-integrates-with-github-advanced-security</guid>
      <pubDate>Thu, 23 Apr 2026 04:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Agentless vs. agent-based cloud security: which approach ...]]></title>
      <description><![CDATA[Agentless cloud scanning and pipeline-based supply chain security aren't the same tradeoff. Here's how Safeguard's build-time approach compares to Wiz's agentless model.]]></description>
      <link>https://safeguard.sh/resources/blog/agentless-vs-agent-based-cloud-security-which-approach-wins</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agentless-vs-agent-based-cloud-security-which-approach-wins</guid>
      <pubDate>Thu, 23 Apr 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Code Search for Security: Finding Vulnerabilities Across Your Codebase]]></title>
      <description><![CDATA[Code search is one of the fastest ways to find security bugs and leaked secrets at scale. Here is how to search effectively, what patterns to hunt for, and where it stops.]]></description>
      <link>https://safeguard.sh/resources/blog/code-search</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-search</guid>
      <pubDate>Thu, 23 Apr 2026 02:50:13 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Securing Nginx on AWS: The Webinar-Grade Hardening Checklist]]></title>
      <description><![CDATA[Running Nginx on AWS pairs two of the most common infrastructure choices, and this is the hardening walkthrough we would give in a live AWS Nginx webinar.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-nginx-webinar</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-nginx-webinar</guid>
      <pubDate>Thu, 23 Apr 2026 01:29:47 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Snyk and HashiCorp Terraform Cloud partnership]]></title>
      <description><![CDATA[Snyk's HashiCorp Terraform Cloud integration gates IaC risk at plan time — here's what it covers, what it misses, and how reachability closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-and-hashicorp-terraform-cloud-partnership</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-and-hashicorp-terraform-cloud-partnership</guid>
      <pubDate>Thu, 23 Apr 2026 01:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Choosing a Tool to Detect Security of Code: What Each Type Finds]]></title>
      <description><![CDATA[There is no single tool to detect security of code. Here is what SAST, SCA, secret scanning, DAST, and IaC scanning each catch, and how to combine them without drowning in alerts.]]></description>
      <link>https://safeguard.sh/resources/blog/tool-to-detect-security-of-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tool-to-detect-security-of-code</guid>
      <pubDate>Thu, 23 Apr 2026 00:09:20 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How SOC 2 becomes a security differentiator for cloud ven...]]></title>
      <description><![CDATA[SOC 2 reports are easy to claim and hard to verify. Here's how Wiz's SOC 2 security program compares to Safeguard's supply chain approach to vendor trust.]]></description>
      <link>https://safeguard.sh/resources/blog/how-wiz-turned-soc-2-into-a-security-differentiator-and-how-safeguard-compares</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-wiz-turned-soc-2-into-a-security-differentiator-and-how-safeguard-compares</guid>
      <pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[react-native-walkthrough-tooltip: Security and Maintenance]]></title>
      <description><![CDATA[react-native-walkthrough-tooltip is popular but inactively maintained. Here is how to assess its risk, decide whether to keep it, and manage aging RN dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-walkthrough-tooltip</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-walkthrough-tooltip</guid>
      <pubDate>Wed, 22 Apr 2026 22:48:53 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[jQuery UI 1.12.1 and 1.13.1 Vulnerabilities: CVE Guide]]></title>
      <description><![CDATA[jQuery UI 1.13.1 vulnerabilities come down to one checkboxradio XSS, while 1.12.1 carries four. A practical guide to the CVEs, exploit conditions, and the upgrade to 1.13.2+.]]></description>
      <link>https://safeguard.sh/resources/blog/jquery-ui-vulnerabilities-1-12-1-13</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jquery-ui-vulnerabilities-1-12-1-13</guid>
      <pubDate>Wed, 22 Apr 2026 21:28:27 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[The Java Security Manager Is Deprecated: What to Use Instead]]></title>
      <description><![CDATA[JEP 411 deprecated the Java Security Manager for removal, and years of accumulated java security flaws in its trust model are why the platform is retiring it rather than fixing it further.]]></description>
      <link>https://safeguard.sh/resources/blog/java-security-manager-deprecation-what-to-use-instead</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-security-manager-deprecation-what-to-use-instead</guid>
      <pubDate>Wed, 22 Apr 2026 20:08:00 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[synk.io or snyk.io? Understanding the Snyk Security Platform]]></title>
      <description><![CDATA[People type synk.io when they mean snyk.io, the developer security company. Here is what the real platform does, why the misspelling matters for security, and how to avoid landing on the wrong site.]]></description>
      <link>https://safeguard.sh/resources/blog/synk-io</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/synk-io</guid>
      <pubDate>Wed, 22 Apr 2026 18:47:33 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[White Box Pentesting: A Practical Guide to Full-Knowledge Testing]]></title>
      <description><![CDATA[White box pentesting gives the tester source code, architecture, and credentials up front. Here is when that full-knowledge approach beats black box, and how an engagement actually runs.]]></description>
      <link>https://safeguard.sh/resources/blog/white-box-pentest</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/white-box-pentest</guid>
      <pubDate>Wed, 22 Apr 2026 17:27:07 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Nonce? The Number Used Once in Cryptography]]></title>
      <description><![CDATA[A nonce is a value used a single time to keep cryptographic operations fresh and stop attackers from replaying old messages. Small idea, outsized importance.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-nonce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-nonce</guid>
      <pubDate>Wed, 22 Apr 2026 16:06:40 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[LLM Jailbreak Defense Architectures in 2026]]></title>
      <description><![CDATA[Jailbreaks against frontier models keep getting more sophisticated. The defense architectures that have proven durable, and the ones that get bypassed in weeks.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-jailbreak-defense-architectures-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-jailbreak-defense-architectures-2026</guid>
      <pubDate>Wed, 22 Apr 2026 15:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Applying Git Patches Safely]]></title>
      <description><![CDATA[Knowing how to apply a patch in git without breaking your working tree takes more than running git apply once and hoping for the best.]]></description>
      <link>https://safeguard.sh/resources/blog/applying-git-patches-safely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/applying-git-patches-safely</guid>
      <pubDate>Wed, 22 Apr 2026 14:46:13 GMT</pubDate>
      <category>Dev Practices</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Is the npm xlsx Package Safe? A Security Review]]></title>
      <description><![CDATA[A security review of the npm xlsx (SheetJS) package: its prototype pollution and ReDoS CVEs, the npm-versus-CDN patch gap, and how to install it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-xlsx</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-xlsx</guid>
      <pubDate>Wed, 22 Apr 2026 13:25:47 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Jailbreak Meaning: What It Is in AI and Devices]]></title>
      <description><![CDATA[Jailbreak has two meanings today: removing restrictions on a device, and tricking an AI model into ignoring its safety rules. This guide covers both.]]></description>
      <link>https://safeguard.sh/resources/blog/jailbreak-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jailbreak-meaning</guid>
      <pubDate>Wed, 22 Apr 2026 13:20:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[API Gateway Security Baseline for 2026]]></title>
      <description><![CDATA[A practical security baseline for API gateways in 2026, covering authentication, rate limiting, schema validation, observability, and the operational habits that keep gateways trustworthy.]]></description>
      <link>https://safeguard.sh/resources/blog/api-gateway-security-baseline-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-gateway-security-baseline-2026</guid>
      <pubDate>Wed, 22 Apr 2026 13:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[npm-force-resolutions: Security Review and Safe Usage]]></title>
      <description><![CDATA[npm-force-resolutions pins vulnerable transitive dependencies to safe versions on older npm. Here is how it works, its risks, and why native npm overrides now beat it.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-force-resolutions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-force-resolutions</guid>
      <pubDate>Wed, 22 Apr 2026 12:05:20 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AWS IAM Identity Center Trusted Token Issuer: A Supply Chain Lens]]></title>
      <description><![CDATA[Trusted Token Issuer support in IAM Identity Center lets workloads exchange OIDC tokens for AWS sessions without long-lived keys. Here is how that reshapes build pipeline trust.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-iam-identity-center-trusted-token-issuer-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-iam-identity-center-trusted-token-issuer-2026</guid>
      <pubDate>Wed, 22 Apr 2026 12:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Building an Eval Suite for Your Security LLM Workflows]]></title>
      <description><![CDATA[If you use an LLM anywhere in your security program — triage, remediation, detection — you need an eval suite with the same rigor as your test suite. Here is a concrete harness: datasets, thresholds, CI gates, and drift detection.]]></description>
      <link>https://safeguard.sh/resources/blog/building-eval-suite-security-llm-workflows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-eval-suite-security-llm-workflows</guid>
      <pubDate>Wed, 22 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP 20x Phase Two: What Moderate Pilots Are Teaching Us]]></title>
      <description><![CDATA[FedRAMP 20x Phase Two is running Moderate-baseline pilots through Q2 2026. We walk through KSIs, machine-readable OSCAL, and the path to wide-scale adoption.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-20x-agile-authorization-2026-milestones</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-20x-agile-authorization-2026-milestones</guid>
      <pubDate>Wed, 22 Apr 2026 12:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[France's NIS2 Transposition: Inside the Resilience Bill]]></title>
      <description><![CDATA[France's Senate passed the Resilience bill on 12 March 2025 — the omnibus law transposing NIS2 and CER — after the Commission's reasoned opinion of 7 May 2025 escalated infringement proceedings.]]></description>
      <link>https://safeguard.sh/resources/blog/nis2-france-transposition-resilience-bill</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nis2-france-transposition-resilience-bill</guid>
      <pubDate>Wed, 22 Apr 2026 12:00:00 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Private Registry Hardening in 2026: How Nexus Firewall and JFrog Curation Closed the Mirror-Pass-Through Gap]]></title>
      <description><![CDATA[Through 2025-2026, Sonatype Nexus Firewall, JFrog Curation, and Harness Artifact Registry shipped policy features specifically aimed at the Shai-Hulud pass-through problem, where private mirrors silently replicated malicious upstream packages.]]></description>
      <link>https://safeguard.sh/resources/blog/private-registry-firewall-hardening-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/private-registry-firewall-hardening-2026</guid>
      <pubDate>Wed, 22 Apr 2026 12:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Agent Fix: Autofix in the Field]]></title>
      <description><![CDATA[Snyk's February 2026 AI Security Fabric pitched DeepCode AI and Agent Fix as autonomous remediation. We ran Agent Fix against 412 real SAST findings to test the 80% accuracy claim.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-agent-fix-autofix-field-test-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-agent-fix-autofix-field-test-2026</guid>
      <pubDate>Wed, 22 Apr 2026 12:00:00 GMT</pubDate>
      <category>Tool Comparison</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What Is an AI Factory, and How Do You Secure One?]]></title>
      <description><![CDATA[An AI factory is the industrialized pipeline that turns data and compute into deployed models at scale. Treating it like a factory means securing every stage, not just the model.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-factory</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-factory</guid>
      <pubDate>Wed, 22 Apr 2026 11:40:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[PHP 7.4.33 Vulnerabilities: The Real Risk of Running EOL PHP]]></title>
      <description><![CDATA[PHP 7.4.33 was the final release in the 7.4 line before it reached end of life — running it today means every new vulnerability discovered afterward goes unpatched by design.]]></description>
      <link>https://safeguard.sh/resources/blog/php-7-4-33-vulnerabilities-eol-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-7-4-33-vulnerabilities-eol-risk</guid>
      <pubDate>Wed, 22 Apr 2026 10:44:53 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Mitigate Supply Chain Attacks: A Practical Playbook]]></title>
      <description><![CDATA[To mitigate supply chain attacks, you secure everything you did not write: dependencies, build systems, and the pipeline that ships your code. Here is how.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-mitigate-supply-chain-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-mitigate-supply-chain-attacks</guid>
      <pubDate>Wed, 22 Apr 2026 10:35:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AI in Network Security: Where It Actually Helps Today]]></title>
      <description><![CDATA[AI in network security earns its keep in anomaly detection and alert triage today, not in autonomous response — here's the honest split between what's proven and what's still marketing.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-in-network-security-where-it-actually-helps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-in-network-security-where-it-actually-helps</guid>
      <pubDate>Wed, 22 Apr 2026 10:15:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Container Security and Gartner: Reading the CNAPP Market Guide]]></title>
      <description><![CDATA[When people search for container security Gartner coverage, they usually mean the CNAPP Market Guide. Here is what Gartner's framing says about securing containers.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-gartner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-gartner</guid>
      <pubDate>Wed, 22 Apr 2026 10:10:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Bringing developer-first application security to C/C++]]></title>
      <description><![CDATA[C/C++ still powers critical infrastructure but lags in AppSec tooling. Safeguard brings SBOM, reachability, and auto-fix to native code security.]]></description>
      <link>https://safeguard.sh/resources/blog/bringing-developer-first-application-security-to-cc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bringing-developer-first-application-security-to-cc</guid>
      <pubDate>Wed, 22 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[What Is AI Jailbreaking? A Defender's Security Guide]]></title>
      <description><![CDATA[To jailbreak AI means to bypass a model's safety guardrails with crafted prompts. Here is how the technique works and, more usefully, how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/jailbreak-ai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jailbreak-ai</guid>
      <pubDate>Wed, 22 Apr 2026 09:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Zarf Air-Gap Deployment: A 2026 Walkthrough]]></title>
      <description><![CDATA[How Zarf 0.45 packages and deploys Kubernetes workloads into disconnected environments, where the design works well, and the operational realities to plan for.]]></description>
      <link>https://safeguard.sh/resources/blog/zarf-airgap-deployment-walkthrough-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zarf-airgap-deployment-walkthrough-2026</guid>
      <pubDate>Wed, 22 Apr 2026 09:30:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes securityContext: fsGroup and the Fields People Skip]]></title>
      <description><![CDATA[A field-by-field walkthrough of Kubernetes securityContext — fsGroup, runAsNonRoot, and the settings teams leave at their insecure defaults.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-security-context-fsgroup-and-friends</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-security-context-fsgroup-and-friends</guid>
      <pubDate>Wed, 22 Apr 2026 09:24:26 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SAST and DAST Tools: A Combined Buying Guide]]></title>
      <description><![CDATA[Buying SAST and DAST tools separately usually means paying for two dashboards that don't talk to each other — here's how to evaluate them as a combined purchase in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-and-dast-tools-a-combined-buying-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-and-dast-tools-a-combined-buying-guide</guid>
      <pubDate>Wed, 22 Apr 2026 09:15:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Security Services: What to Outsource and What to Own]]></title>
      <description><![CDATA[A practical split for enterprise security services — what genuinely benefits from outsourcing and what an internal team should keep, based on where expertise decays fastest.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-security-services-what-to-outsource</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-security-services-what-to-outsource</guid>
      <pubDate>Wed, 22 Apr 2026 09:00:00 GMT</pubDate>
      <category>Enterprise</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Wiz Alternatives: why there's no exact substitute (and ho...]]></title>
      <description><![CDATA[Searching for Wiz alternatives? See why Wiz and Safeguard solve different problems, and how Safeguard compares on SCA depth, remediation, and compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/wiz-alternatives-why-theres-no-exact-substitute-and-how-safeguard-fits</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wiz-alternatives-why-theres-no-exact-substitute-and-how-safeguard-fits</guid>
      <pubDate>Wed, 22 Apr 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Container Image Supply Chain Security Deep Dive 2026]]></title>
      <description><![CDATA[A senior-engineer deep dive into 2026 container image supply chain security: base image risk, provenance, signing, attestation chains, and what actually moves the needle.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-supply-chain-security-deep-dive-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-supply-chain-security-deep-dive-2026</guid>
      <pubDate>Wed, 22 Apr 2026 08:45:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SAST in Gartner's Magic Quadrant: What It Actually Means]]></title>
      <description><![CDATA[SAST Gartner placement gets cited in almost every AppSec RFP, but the Magic Quadrant measures vendor execution and vision, not which tool fits your stack — here's how to actually use it.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-in-gartners-magic-quadrant-what-it-means</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-in-gartners-magic-quadrant-what-it-means</guid>
      <pubDate>Wed, 22 Apr 2026 08:45:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Tools on Gartner's Radar]]></title>
      <description><![CDATA[DevSecOps tools Gartner tracks span SAST, DAST, SCA, and pipeline security categories — here's how the analyst view maps to what teams actually need to evaluate.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-tools-on-gartners-radar</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-tools-on-gartners-radar</guid>
      <pubDate>Wed, 22 Apr 2026 08:30:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Main Types of Security Vulnerabilities, Explained]]></title>
      <description><![CDATA[A practical tour of the main types of security vulnerabilities developers meet, from injection and broken access control to vulnerable dependencies, with defenses for each.]]></description>
      <link>https://safeguard.sh/resources/blog/types-of-security-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/types-of-security-vulnerabilities</guid>
      <pubDate>Wed, 22 Apr 2026 08:04:00 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Container Security: A Practical Guide]]></title>
      <description><![CDATA[You can build a solid container security stack entirely from open source tools — here's which ones cover which layer, and where the gaps show up at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-container-security-practical-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-container-security-practical-guide</guid>
      <pubDate>Wed, 22 Apr 2026 08:00:00 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Learn: interactive security training for developers]]></title>
      <description><![CDATA[Snyk Learn popularized the developer security training platform. But without reachability-aware prioritization, training risks teaching developers to fix the wrong things.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-learn-interactive-security-training-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-learn-interactive-security-training-for-developers</guid>
      <pubDate>Wed, 22 Apr 2026 07:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Secure Docker Images: A Practical Checklist]]></title>
      <description><![CDATA[A working checklist for building secure Docker images, from base image choice through image scanning, that you can actually apply to an existing Dockerfile this week.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-docker-images-a-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-docker-images-a-checklist</guid>
      <pubDate>Wed, 22 Apr 2026 06:43:33 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard vs. Wiz: cloud security platform comparison]]></title>
      <description><![CDATA[Wiz is a CNAPP; Safeguard is a supply chain security platform. Here is how they compare on scanning depth, remediation, and compliance ceiling.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-vs-wiz-cloud-security-platform-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-vs-wiz-cloud-security-platform-comparison</guid>
      <pubDate>Wed, 22 Apr 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Training: How to Actually Run It for a Dev Team]]></title>
      <description><![CDATA[OWASP training only sticks when it's tied to the vulnerabilities your own codebase actually has, not a generic slide deck run once a year.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-training-how-to-actually-run-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-training-how-to-actually-run-it</guid>
      <pubDate>Wed, 22 Apr 2026 05:23:06 GMT</pubDate>
      <category>Culture</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Vulnerability Scanners: How They Actually Work]]></title>
      <description><![CDATA[A javascript vulnerability scanner has to reason about a dynamically typed, dependency-heavy language — which is why the good ones combine static analysis with dependency-graph lookups rather than relying on either alone.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-vulnerability-scanners-how-they-work</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-vulnerability-scanners-how-they-work</guid>
      <pubDate>Wed, 22 Apr 2026 04:02:40 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Announcing Kubernetes workload protection in Snyk Container]]></title>
      <description><![CDATA[Snyk added Kubernetes workload protection to Snyk Container. Here's what it does, why it matters now, and what security teams should ask before relying on it.]]></description>
      <link>https://safeguard.sh/resources/blog/announcing-kubernetes-workload-protection-in-snyk-container</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/announcing-kubernetes-workload-protection-in-snyk-container</guid>
      <pubDate>Wed, 22 Apr 2026 04:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Wiz vs. CrowdStrike: agentless CNAPP vs. endpoint-driven ...]]></title>
      <description><![CDATA[Wiz's agentless CNAPP and CrowdStrike's endpoint agents both secure runtime, but neither closes the software supply chain gap Safeguard is built for.]]></description>
      <link>https://safeguard.sh/resources/blog/wiz-vs-crowdstrike-agentless-cnapp-vs-endpoint-driven-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wiz-vs-crowdstrike-agentless-cnapp-vs-endpoint-driven-security</guid>
      <pubDate>Wed, 22 Apr 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CSP Meaning in Security: What Content Security Policy Actually Does]]></title>
      <description><![CDATA[CSP in security stands for Content Security Policy, a browser mechanism that tells the page which sources of script, style, and other content it may trust. Here is what it means and how to use it.]]></description>
      <link>https://safeguard.sh/resources/blog/csp-meaning-in-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/csp-meaning-in-security</guid>
      <pubDate>Wed, 22 Apr 2026 02:42:13 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Container Vulnerability Management: The Full Lifecycle]]></title>
      <description><![CDATA[Container vulnerability management is a lifecycle, not a scan — here's what happens from base image selection through runtime, and where most programs quietly fall apart.]]></description>
      <link>https://safeguard.sh/resources/blog/container-vulnerability-management-lifecycle</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-vulnerability-management-lifecycle</guid>
      <pubDate>Wed, 22 Apr 2026 01:21:46 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[BSD 3-Clause License Explained]]></title>
      <description><![CDATA[The BSD 3-clause license is one of the most permissive open source licenses in wide use — here's what its three conditions actually require and how it differs from MIT and Apache 2.0.]]></description>
      <link>https://safeguard.sh/resources/blog/bsd-3-clause-license-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bsd-3-clause-license-explained</guid>
      <pubDate>Wed, 22 Apr 2026 00:01:20 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Wiz vs. Snyk: platform breadth vs. developer-first security]]></title>
      <description><![CDATA[Wiz and Snyk solve different layers of AppSec entirely. Here is how the two actually compare, and where build provenance still needs coverage.]]></description>
      <link>https://safeguard.sh/resources/blog/wiz-vs-snyk-platform-breadth-vs-developer-first-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wiz-vs-snyk-platform-breadth-vs-developer-first-security</guid>
      <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Product Security vs Application Security: What's the Difference]]></title>
      <description><![CDATA[Application security protects the code and runtime of a single piece of software; product security is the broader discipline covering that software's entire lifecycle, including hardware, supply chain, and how customers actually use it.]]></description>
      <link>https://safeguard.sh/resources/blog/product-security-vs-application-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/product-security-vs-application-security</guid>
      <pubDate>Tue, 21 Apr 2026 22:40:53 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Application Development Security: Building It Into the SDLC]]></title>
      <description><![CDATA[Application development security only works when it's built into the software development lifecycle from the first commit, not bolted on before a release deadline.]]></description>
      <link>https://safeguard.sh/resources/blog/application-development-security-shift-left-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-development-security-shift-left-guide</guid>
      <pubDate>Tue, 21 Apr 2026 21:20:26 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[npm pack: How to Publish Without Leaking Secrets]]></title>
      <description><![CDATA[npm pack builds the exact tarball that would be published to the registry. Using it before every publish is the simplest way to avoid shipping secrets.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-pack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-pack</guid>
      <pubDate>Tue, 21 Apr 2026 20:00:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The POJO Class in Java: A Security Guide to Plain Objects]]></title>
      <description><![CDATA[A POJO class in Java looks harmless — just fields and getters — but the moment it becomes a deserialization target it turns into an attack surface. Here is how plain objects go wrong and how to keep them safe.]]></description>
      <link>https://safeguard.sh/resources/blog/pojo-class-in-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pojo-class-in-java</guid>
      <pubDate>Tue, 21 Apr 2026 18:39:33 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Container Hardening Guide 2025: From Base Image to Production]]></title>
      <description><![CDATA[A practical guide to hardening container images and deployments. Covers base image selection, build-time security, runtime protections, and Kubernetes-specific controls.]]></description>
      <link>https://safeguard.sh/resources/blog/container-hardening-guide-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-hardening-guide-2025</guid>
      <pubDate>Tue, 21 Apr 2026 17:19:06 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[react-oidc-context: A Security Guide]]></title>
      <description><![CDATA[react-oidc-context wraps oidc-client-ts in React hooks for SPA authentication. Here is how to wire it up without leaking tokens or trusting the wrong callback.]]></description>
      <link>https://safeguard.sh/resources/blog/react-oidc-context</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-oidc-context</guid>
      <pubDate>Tue, 21 Apr 2026 15:58:39 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Free Web Security Scanners: What to Expect From the Free Tier]]></title>
      <description><![CDATA[What a free web security scanner will and won't catch, how the free tiers of popular tools are actually limited, and when you need to pay for real coverage.]]></description>
      <link>https://safeguard.sh/resources/blog/free-web-security-scanners-what-to-expect</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/free-web-security-scanners-what-to-expect</guid>
      <pubDate>Tue, 21 Apr 2026 14:38:13 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Harrods Cyber Attack: The UK Retail Sector Under Sustained Assault]]></title>
      <description><![CDATA[Harrods became the third major UK retailer hit by cyber attacks in weeks, following M&S and Co-op. The pattern points to coordinated campaigns targeting retail.]]></description>
      <link>https://safeguard.sh/resources/blog/harrods-cyber-attack-retail-sector</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/harrods-cyber-attack-retail-sector</guid>
      <pubDate>Tue, 21 Apr 2026 13:17:46 GMT</pubDate>
      <category>Breach Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Commvault CVE-2025-34028: SSRF to RCE in Enterprise Backup Software]]></title>
      <description><![CDATA[A critical SSRF vulnerability in Commvault Command Center allowed unauthenticated attackers to achieve remote code execution on backup infrastructure. CISA added it to the KEV catalog.]]></description>
      <link>https://safeguard.sh/resources/blog/commvault-cve-2025-34028-ssrf-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/commvault-cve-2025-34028-ssrf-rce</guid>
      <pubDate>Tue, 21 Apr 2026 11:57:19 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Multi-Stage Docker Build Security in 2026]]></title>
      <description><![CDATA[Multi-stage builds are the right way to ship secure container images, but the security benefits depend on getting the stage boundaries right. A guide for 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-stage-docker-build-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-stage-docker-build-security-2026</guid>
      <pubDate>Tue, 21 Apr 2026 11:15:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Security Analytics: From Raw Events to Decisions]]></title>
      <description><![CDATA[Most security data pipelines stop at dashboards nobody acts on. The four stages that turn scanner output and logs into decisions, and the metrics that survive contact with a CFO.]]></description>
      <link>https://safeguard.sh/resources/blog/security-analytics-from-events-to-decisions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-analytics-from-events-to-decisions</guid>
      <pubDate>Tue, 21 Apr 2026 11:00:00 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[simple-git: Command Injection CVEs and Safe Usage Patterns]]></title>
      <description><![CDATA[The npm simple-git library went through a chain of argument injection CVEs in 2022, each an incomplete fix of the last. The history is a case study in why wrapping a CLI safely is hard.]]></description>
      <link>https://safeguard.sh/resources/blog/simple-git-npm-command-injection-history</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/simple-git-npm-command-injection-history</guid>
      <pubDate>Tue, 21 Apr 2026 10:36:53 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[AI Chip Architecture: A Security Guide for Accelerated Compute]]></title>
      <description><![CDATA[AI chip architecture shapes the security surface of accelerated compute. Here is how GPUs, TPUs, and NPUs are built and where the real risks live.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-chip-architecture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-chip-architecture</guid>
      <pubDate>Tue, 21 Apr 2026 10:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Consolidating AppSec tools with an ASPM platform]]></title>
      <description><![CDATA[Most AppSec teams run 10-15 disconnected tools. Here's how ASPM platforms consolidate them, why reachability changes what "critical" means, and how to evaluate one.]]></description>
      <link>https://safeguard.sh/resources/blog/consolidating-appsec-tools-with-an-aspm-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/consolidating-appsec-tools-with-an-aspm-platform</guid>
      <pubDate>Tue, 21 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Advanced Python: The Security-Focused Patterns Senior Developers Should Master]]></title>
      <description><![CDATA[Advanced Python is not about clever one-liners. The patterns that separate senior engineers are the ones that keep code safe: safe deserialization, controlled subprocess calls, and disciplined dependency use.]]></description>
      <link>https://safeguard.sh/resources/blog/advanced-python</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/advanced-python</guid>
      <pubDate>Tue, 21 Apr 2026 09:16:26 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Top CrowdStrike Alternatives & Competitors]]></title>
      <description><![CDATA[Evaluating CrowdStrike alternatives? Here's how Safeguard's software supply chain security compares to Wiz's cloud-native application protection platform.]]></description>
      <link>https://safeguard.sh/resources/blog/top-crowdstrike-alternatives-competitors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-crowdstrike-alternatives-competitors</guid>
      <pubDate>Tue, 21 Apr 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[OSS Licenses Explained: Compliance and Risk Management]]></title>
      <description><![CDATA[OSS licenses govern how you can use open-source dependencies, and ignoring them creates real legal and business risk. Here is how the main license types work and how to stay compliant.]]></description>
      <link>https://safeguard.sh/resources/blog/oss-licenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oss-licenses</guid>
      <pubDate>Tue, 21 Apr 2026 07:55:59 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[@babel/plugin-proposal-class-properties: Security and Migration Guide]]></title>
      <description><![CDATA[This Babel plugin is deprecated, not vulnerable. The real risk is supply chain hygiene: depending on an unmaintained package when the standard replacement is a one-line swap.]]></description>
      <link>https://safeguard.sh/resources/blog/babel-plugin-proposal-class-properties</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/babel-plugin-proposal-class-properties</guid>
      <pubDate>Tue, 21 Apr 2026 06:35:33 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Top Palo Alto Networks Competitors & Alternatives]]></title>
      <description><![CDATA[Comparing Safeguard and Wiz on scope and data model — CNAPP cloud posture vs. software supply chain security — for teams evaluating Palo Alto Networks alternatives.]]></description>
      <link>https://safeguard.sh/resources/blog/top-palo-alto-networks-competitors-alternatives</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-palo-alto-networks-competitors-alternatives</guid>
      <pubDate>Tue, 21 Apr 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Line Jumping: How MCP Tool Descriptions Attack Before Tools Are Called]]></title>
      <description><![CDATA[Trail of Bits coined 'line jumping' for prompt injection delivered through MCP tool descriptions on connection. It bypasses every tool-invocation guardrail by design.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-line-jumping-tool-description-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-line-jumping-tool-description-injection</guid>
      <pubDate>Tue, 21 Apr 2026 05:15:06 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Security debt vs security risk: how to measure both]]></title>
      <description><![CDATA[Security debt and security risk are measured differently and demand different remediation clocks. Here's how to quantify each — and where they collide.]]></description>
      <link>https://safeguard.sh/resources/blog/security-debt-vs-security-risk-how-to-measure-both</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-debt-vs-security-risk-how-to-measure-both</guid>
      <pubDate>Tue, 21 Apr 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-29469: A libxml2 Hashing Flaw That Crashes XML Parsers]]></title>
      <description><![CDATA[CVE-2023-29469 lets a crafted XML document trigger a double free in libxml2 through non-deterministic hashing of empty strings. Affected versions and fixes explained.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-29469</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-29469</guid>
      <pubDate>Tue, 21 Apr 2026 03:54:39 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Tenable Competitors: approaches to exposure management]]></title>
      <description><![CDATA[Searching "tenable competitors" surfaces Wiz fast. Here is how Wiz and Safeguard actually differ in deployment model, asset scope, and exposure management approach.]]></description>
      <link>https://safeguard.sh/resources/blog/tenable-competitors-approaches-to-exposure-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tenable-competitors-approaches-to-exposure-management</guid>
      <pubDate>Tue, 21 Apr 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Web Scanners: How They Work and What to Use]]></title>
      <description><![CDATA[A web scanner probes a running application for vulnerabilities the way an attacker would. Here is how the different types work and how to pick one that finds real bugs.]]></description>
      <link>https://safeguard.sh/resources/blog/web-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-scanner</guid>
      <pubDate>Tue, 21 Apr 2026 02:34:12 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[A Threat Model Example, Walked Through Step by Step]]></title>
      <description><![CDATA[The fastest way to understand threat modeling is to watch one built end to end — this walks through a real threat model example for a simple login and payment flow.]]></description>
      <link>https://safeguard.sh/resources/blog/threat-model-example-walked-through</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/threat-model-example-walked-through</guid>
      <pubDate>Tue, 21 Apr 2026 01:13:46 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Open source package health scoring explained]]></title>
      <description><![CDATA[Health scores from OSSF Scorecard, Snyk, and npms.io compress package risk into one number -- but xz-utils proves a high score isn't the same as safe.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-package-health-scoring-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-package-health-scoring-explained</guid>
      <pubDate>Tue, 21 Apr 2026 01:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Alternatives for cloud-native security teams]]></title>
      <description><![CDATA[Comparing Snyk alternatives for cloud-native teams: how Wiz's cloud posture platform and Safeguard's supply chain security approach differ — and where each actually fits.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-alternatives-for-cloud-native-security-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-alternatives-for-cloud-native-security-teams</guid>
      <pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Ethical Hacking and Cyber Security: How They Fit Together]]></title>
      <description><![CDATA[How ethical hacking and cyber security relate: what an ethical hacker actually does, the engagement types, the legal boundaries, and where offensive work fits in defense.]]></description>
      <link>https://safeguard.sh/resources/blog/ethical-hacking-and-cyber-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ethical-hacking-and-cyber-security</guid>
      <pubDate>Mon, 20 Apr 2026 23:53:19 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Log4j 1.2.17 Vulnerabilities: Why Log4j 1.x Cannot Be Fixed]]></title>
      <description><![CDATA[The only real log4j 1.2.17 vulnerability fix is migrating off the 1.x line — it reached end of life in 2015 and its RCE-class CVEs will never be patched. Here is the case and the path.]]></description>
      <link>https://safeguard.sh/resources/blog/log4j-1-x-vulnerabilities-why-upgrade</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4j-1-x-vulnerabilities-why-upgrade</guid>
      <pubDate>Mon, 20 Apr 2026 22:32:52 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Docker Image Scanning: How It Works and What It Finds]]></title>
      <description><![CDATA[Scanners don't run your container — they unpack it. How docker image scanning inventories layers, matches CVEs, handles distro backports, and where it belongs in your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-image-scanning-how-it-works</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-image-scanning-how-it-works</guid>
      <pubDate>Mon, 20 Apr 2026 21:12:26 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Public Cloud Protection: Securing Workloads Across AWS, Azure, and GCP]]></title>
      <description><![CDATA[Public cloud protection starts with the shared responsibility model and ends with the boring controls that stop most breaches: identity, configuration, and visibility.]]></description>
      <link>https://safeguard.sh/resources/blog/public-cloud-protection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/public-cloud-protection</guid>
      <pubDate>Mon, 20 Apr 2026 19:51:59 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[AWS Service-Linked Role Abuse Techniques, 2025]]></title>
      <description><![CDATA[Service-linked roles are the soft underbelly of AWS IAM. We catalogue the 2024-2025 abuse primitives and the detection queries that catch them.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-service-linked-role-abuse-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-service-linked-role-abuse-techniques</guid>
      <pubDate>Mon, 20 Apr 2026 18:31:32 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Nova Scotia Power Cyber Incident: When Critical Infrastructure Gets Hit]]></title>
      <description><![CDATA[Nova Scotia Power disclosed a cyber incident in April 2025 that compromised customer data. The attack highlights the persistent vulnerability of utility companies.]]></description>
      <link>https://safeguard.sh/resources/blog/nova-scotia-power-cyber-incident</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nova-scotia-power-cyber-incident</guid>
      <pubDate>Mon, 20 Apr 2026 17:11:06 GMT</pubDate>
      <category>Breach Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Audio Processing Library Vulnerabilities: The Sound of Exploitation]]></title>
      <description><![CDATA[Audio libraries parse complex binary formats in C code. They share the same vulnerability patterns as image and video codecs, with less security scrutiny.]]></description>
      <link>https://safeguard.sh/resources/blog/audio-processing-library-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/audio-processing-library-vulnerabilities</guid>
      <pubDate>Mon, 20 Apr 2026 15:50:39 GMT</pubDate>
      <category>Vulnerability Research</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Website Security Scanners: How a Site Scanner Works and What to Use]]></title>
      <description><![CDATA[A site scanner crawls a live website and probes it for security issues, from missing headers to injection flaws. Here is how the scan works and how to pick one.]]></description>
      <link>https://safeguard.sh/resources/blog/site-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/site-scanner</guid>
      <pubDate>Mon, 20 Apr 2026 14:30:12 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Harden a Dockerfile in 10 Practical Steps]]></title>
      <description><![CDATA[Ten concrete Dockerfile changes — digest pinning, multi-stage builds, non-root users, BuildKit secrets, SBOM attestations — that remove whole classes of container risk.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-harden-a-dockerfile-in-10-practical-steps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-harden-a-dockerfile-in-10-practical-steps</guid>
      <pubDate>Mon, 20 Apr 2026 14:00:00 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Aisha Bello)</author>
    </item>
    <item>
      <title><![CDATA[Securing a REST API: A Defense-in-Depth Checklist]]></title>
      <description><![CDATA[Securing a REST API means layering authentication, authorization, input validation, and rate limiting so no single control is the only thing standing between an attacker and your data.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-rest-api</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-rest-api</guid>
      <pubDate>Mon, 20 Apr 2026 13:09:46 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[npm Security Vulnerabilities: How to Track Them]]></title>
      <description><![CDATA[A practical system for tracking npm security vulnerabilities across a real dependency tree, why you shouldn't rely on npm check vulnerabilities output alone, and what to automate.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-security-vulnerabilities-how-to-track-them</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-security-vulnerabilities-how-to-track-them</guid>
      <pubDate>Mon, 20 Apr 2026 11:49:19 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Juniper Junos CVE-2024-21591: Routing Plane Vulnerabilities and 2026 Defense]]></title>
      <description><![CDATA[CVE-2024-21591 was an out-of-bounds write in Juniper Junos OS that affected core routing infrastructure. The technical details and what defenders should take away in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/juniper-junos-cve-2024-21591-defense-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/juniper-junos-cve-2024-21591-defense-2026</guid>
      <pubDate>Mon, 20 Apr 2026 11:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[OpenAI Preparedness Framework v2: April 2025 Update]]></title>
      <description><![CDATA[OpenAI released Preparedness Framework v2 on April 15, 2025 with sharper thresholds, an AI self-improvement category, and clearer disclosure requirements. We unpack the operational changes.]]></description>
      <link>https://safeguard.sh/resources/blog/openai-preparedness-framework-v2-april-2025-update</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openai-preparedness-framework-v2-april-2025-update</guid>
      <pubDate>Mon, 20 Apr 2026 10:28:52 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What to check before installing an open source package]]></title>
      <description><![CDATA[A practical guide to vetting open source packages before you install them — real incidents, concrete checks, and how reachability analysis cuts through CVE noise.]]></description>
      <link>https://safeguard.sh/resources/blog/what-to-check-before-installing-an-open-source-package</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-to-check-before-installing-an-open-source-package</guid>
      <pubDate>Mon, 20 Apr 2026 10:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[SAP NetWeaver CVE-2025-31324: Unrestricted File Upload Zero-Day]]></title>
      <description><![CDATA[A critical file upload vulnerability in SAP NetWeaver Visual Composer was exploited to deploy web shells on enterprise SAP systems. The flaw required no authentication and scored 10.0 on CVSS.]]></description>
      <link>https://safeguard.sh/resources/blog/sap-netweaver-cve-2025-31324-zero-day</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sap-netweaver-cve-2025-31324-zero-day</guid>
      <pubDate>Mon, 20 Apr 2026 09:08:25 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[DORA Financial Services Supply Chain Obligations in 2026]]></title>
      <description><![CDATA[The Digital Operational Resilience Act has been in application since January 2025. The ICT third-party risk management obligations are the operational center of gravity in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-financial-services-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-financial-services-supply-chain-2026</guid>
      <pubDate>Mon, 20 Apr 2026 09:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Fortinet Alternatives & Competitors for cloud-first orgs]]></title>
      <description><![CDATA[Cloud-first orgs searching for Fortinet alternatives often need two different tools, not one. Here is how Safeguard and Wiz actually differ.]]></description>
      <link>https://safeguard.sh/resources/blog/fortinet-alternatives-competitors-for-cloud-first-orgs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fortinet-alternatives-competitors-for-cloud-first-orgs</guid>
      <pubDate>Mon, 20 Apr 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to Validate a URL in JavaScript Without Opening a Hole]]></title>
      <description><![CDATA[The modern way to validate a URL in JavaScript is the built-in URL constructor, not a regex. Here's how to use it safely on both the client and the server.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-validate-url</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-validate-url</guid>
      <pubDate>Mon, 20 Apr 2026 07:47:59 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[npm audit vs Snyk: comparing vulnerability scanners]]></title>
      <description><![CDATA[npm audit is free and built-in; Snyk adds reachability analysis and auto-fix PRs. Here's how they really compare on data, false positives, and supply chain attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-audit-vs-snyk-comparing-vulnerability-scanners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-audit-vs-snyk-comparing-vulnerability-scanners</guid>
      <pubDate>Mon, 20 Apr 2026 07:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[EU Cybersecurity Reserve: Trusted Providers Under the Cyber Solidarity Act]]></title>
      <description><![CDATA[The EU Cybersecurity Reserve under Regulation (EU) 2025/38 mobilises trusted private incident-response providers to support Member States facing significant cyber incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cyber-solidarity-trusted-providers-reserve-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cyber-solidarity-trusted-providers-reserve-2025</guid>
      <pubDate>Mon, 20 Apr 2026 06:27:32 GMT</pubDate>
      <category>Policy</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is Cloud Security? Ultimate guide to the modern cloud]]></title>
      <description><![CDATA[Cloud misconfigurations and supply chain attacks now drive most breaches. Here's what cloud security actually means in 2026, and how it differs from what Wiz covers.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-cloud-security-ultimate-guide-to-the-modern-cloud</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-cloud-security-ultimate-guide-to-the-modern-cloud</guid>
      <pubDate>Mon, 20 Apr 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Docker Security Concerns: The Real List]]></title>
      <description><![CDATA[Docker security concerns that actually cause incidents are narrower than most checklists suggest — root-by-default containers, exposed daemon sockets, and unpatched base images account for most real-world breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-security-concerns-the-real-list</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-security-concerns-the-real-list</guid>
      <pubDate>Mon, 20 Apr 2026 05:07:05 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Is react-native-background-upload Safe to Ship?]]></title>
      <description><![CDATA[react-native-background-upload moves files while your app is backgrounded, which is exactly why its security depends on how you handle URLs, tokens, and native permissions.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-background-upload</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-background-upload</guid>
      <pubDate>Mon, 20 Apr 2026 03:46:39 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Security Architecture: frameworks, components, and ...]]></title>
      <description><![CDATA[Cloud security architecture explained: the frameworks (NIST CSF 2.0, CSA CCM), core components, where Wiz's graph model stops, and how to build one in five phases.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-security-architecture-frameworks-components-and-how-to-build-one</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-security-architecture-frameworks-components-and-how-to-build-one</guid>
      <pubDate>Mon, 20 Apr 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Docker Vulnerability News: What Recent Container CVEs Mean for You]]></title>
      <description><![CDATA[Keeping up with Docker vulnerability news matters because container escapes turn a compromised app into a compromised host. Here is how to read the headlines and act on them.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-vulnerability-news</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-vulnerability-news</guid>
      <pubDate>Mon, 20 Apr 2026 02:26:12 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Ingress TLS: Setup, Certificates, and Common Mistakes]]></title>
      <description><![CDATA[How Ingress TLS works in Kubernetes: terminating HTTPS at the ingress, wiring TLS secrets, automating certificates with cert-manager, and the mistakes that break it.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-ingress-tls-setup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-ingress-tls-setup</guid>
      <pubDate>Mon, 20 Apr 2026 01:05:45 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Static analysis (SAST) buyer's guide for enterprise teams]]></title>
      <description><![CDATA[A concrete buyer's guide to enterprise SAST: false-positive rates, reachability analysis, POC criteria, SBOM integration, and real pricing benchmarks for 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/static-analysis-sast-buyers-guide-for-enterprise-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-analysis-sast-buyers-guide-for-enterprise-teams</guid>
      <pubDate>Mon, 20 Apr 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Security Tools: a comprehensive guide to the 10 types]]></title>
      <description><![CDATA[A breakdown of the 10 cloud security tool categories — CSPM, CNAPP, CIEM, DSPM, and more — and why supply chain security remains the gap even Wiz-style platforms leave open.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-security-tools-a-comprehensive-guide-to-the-10-types</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-security-tools-a-comprehensive-guide-to-the-10-types</guid>
      <pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What Is Wrong With This Code? A Security Review Checklist]]></title>
      <description><![CDATA[When you ask what is wrong with this code, the answer is often not a crash but a security flaw hiding in plain sight. Here is a practitioner's checklist for spotting the bugs that bite later.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-wrong-with-this-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-wrong-with-this-code</guid>
      <pubDate>Sun, 19 Apr 2026 23:45:19 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Webpack Latest Version: Why Staying Current Is a Security Move]]></title>
      <description><![CDATA[The webpack latest version sits in the 5.x line and updates frequently. Here is how to check which version you run, why staying current matters for security, and how to upgrade safely.]]></description>
      <link>https://safeguard.sh/resources/blog/webpack-latest-version</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webpack-latest-version</guid>
      <pubDate>Sun, 19 Apr 2026 22:24:52 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Where Is Snyk Headquarters? Location, Offices, and Company Facts]]></title>
      <description><![CDATA[Snyk headquarters is in Boston, Massachusetts, with a global footprint across North America, Europe, and Israel. Here is the full picture and why it matters for buyers.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-headquarters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-headquarters</guid>
      <pubDate>Sun, 19 Apr 2026 21:04:25 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[cross-fetch: Package Health and Security Review]]></title>
      <description><![CDATA[cross-fetch still ships in thousands of lockfiles as a universal fetch polyfill. A review of its one CVE, its node-fetch dependency, and when you no longer need it.]]></description>
      <link>https://safeguard.sh/resources/blog/cross-fetch-npm-package-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cross-fetch-npm-package-security-review</guid>
      <pubDate>Sun, 19 Apr 2026 19:43:59 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Site Security Scan: How to Check a Website for Vulnerabilities]]></title>
      <description><![CDATA[A site security scan probes a live website for exploitable weaknesses, from injection flaws to misconfigured headers. Here is what a real scan covers and how to run one that finds something useful.]]></description>
      <link>https://safeguard.sh/resources/blog/site-security-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/site-security-scan</guid>
      <pubDate>Sun, 19 Apr 2026 18:23:32 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Is Python setup.py Still Safe? Security Risks and the Move to Building Wheels]]></title>
      <description><![CDATA[python setup.py executes arbitrary code at install time and its legacy commands are deprecated. Here is what that means for security and how to build a wheel the modern way.]]></description>
      <link>https://safeguard.sh/resources/blog/python-setup-py</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-setup-py</guid>
      <pubDate>Sun, 19 Apr 2026 17:03:05 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2014-0114: The Apache Commons BeanUtils ClassLoader Flaw Explained]]></title>
      <description><![CDATA[CVE-2014-0114 lets attackers manipulate the ClassLoader through Apache Commons BeanUtils and Struts 1, opening a path to remote code execution. Here is what it affects and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2014-0114</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2014-0114</guid>
      <pubDate>Sun, 19 Apr 2026 15:42:38 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Log4j 1.2.17: Why It Is Still a Security Problem]]></title>
      <description><![CDATA[Log4j 1.2.17 is the last release of a branch that reached end of life in 2015. It carries multiple RCE and deserialization flaws and cannot be patched. Here is what to do about it.]]></description>
      <link>https://safeguard.sh/resources/blog/log4j-1-2-17</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4j-1-2-17</guid>
      <pubDate>Sun, 19 Apr 2026 14:22:12 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[react-native-google-places-autocomplete: A Security Guide]]></title>
      <description><![CDATA[The react-native-google-places-autocomplete component makes location search easy, but it can also leak your Google API key straight out of a shipped app. Here's how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-google-places-autocomplete</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-google-places-autocomplete</guid>
      <pubDate>Sun, 19 Apr 2026 13:01:45 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Zero-Day Discovery With LLM-Augmented Reachability: A Safeguard Engine Walkthrough]]></title>
      <description><![CDATA[Pattern-matching scanners miss zero-days by definition. An engine that follows taint across package boundaries plus a model that hypothesizes exploit conditions can find what either would miss alone. Here is how that pipeline works end to end.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-day-discovery-llm-augmented-reachability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-day-discovery-llm-augmented-reachability</guid>
      <pubDate>Sun, 19 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SBOM for Containers: 2026 Buyer's Guide]]></title>
      <description><![CDATA[How to generate, manage, and act on SBOMs for containers in 2026: tool comparison, layered SBOMs, signing, and runtime drift detection.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-containers-buyer-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-containers-buyer-guide-2026</guid>
      <pubDate>Sun, 19 Apr 2026 11:45:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Docker Images Format Explained: Layers, OCI, and Security]]></title>
      <description><![CDATA[Understanding the Docker images format, from layers and manifests to the OCI spec, is the foundation for scanning, signing, and hardening what you ship.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-images-format</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-images-format</guid>
      <pubDate>Sun, 19 Apr 2026 11:41:18 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Drone CI Supply Chain Hardening 2026]]></title>
      <description><![CDATA[A 2026 hardening guide for Drone CI: plugin trust, runner isolation, signed pipelines, secret scoping, and integrating Drone with SLSA and sigstore.]]></description>
      <link>https://safeguard.sh/resources/blog/drone-ci-supply-chain-hardening-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/drone-ci-supply-chain-hardening-2026</guid>
      <pubDate>Sun, 19 Apr 2026 11:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[react-csv and CSV Injection: Exporting Data From React Safely]]></title>
      <description><![CDATA[react-csv makes CSV downloads a one-component job, but it does not sanitize formula injection. Here is how to use it and where you own the security.]]></description>
      <link>https://safeguard.sh/resources/blog/react-csv</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-csv</guid>
      <pubDate>Sun, 19 Apr 2026 10:20:52 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Orca vs Wiz CNAPP Deep Comparison 2026]]></title>
      <description><![CDATA[The two pioneers of agentless cloud security have diverged in interesting ways. A technical comparison covering side-scanning depth, graph quality, and the operational differences that decide deals.]]></description>
      <link>https://safeguard.sh/resources/blog/orca-vs-wiz-cnapp-deep-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/orca-vs-wiz-cnapp-deep-comparison-2026</guid>
      <pubDate>Sun, 19 Apr 2026 10:15:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Consolidating point solutions into a unified AppSec platform]]></title>
      <description><![CDATA[Point solutions for SAST, SCA, DAST, and secrets scanning create duplicate alerts and blind spots — here's why teams are unifying AppSec now.]]></description>
      <link>https://safeguard.sh/resources/blog/consolidating-point-solutions-into-a-unified-appsec-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/consolidating-point-solutions-into-a-unified-appsec-platform</guid>
      <pubDate>Sun, 19 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[OWASP LLM Top 10 2025: System Prompt Leakage and Vector Weaknesses]]></title>
      <description><![CDATA[The OWASP Top 10 for LLM Applications 2025 added System Prompt Leakage and Vector/Embedding Weaknesses, and elevated Sensitive Information Disclosure to #2. Here is the defender view.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-llm-top-10-2025-system-prompt-leakage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-llm-top-10-2025-system-prompt-leakage</guid>
      <pubDate>Sun, 19 Apr 2026 09:00:25 GMT</pubDate>
      <category>Frameworks</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Security Standards & Frameworks (ISO/IEC, NIST, CIS)]]></title>
      <description><![CDATA[ISO 27001:2022, NIST CSF 2.0, and CIS Benchmarks now expect software supply chain proof that cloud posture tools like Wiz can't provide alone. Here's what changed and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-security-standards-frameworks-isoiec-nist-cis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-security-standards-frameworks-isoiec-nist-cis</guid>
      <pubDate>Sun, 19 Apr 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Oracle Cloud Classic SSO Incident: rose87168 and the Legacy Endpoint Problem]]></title>
      <description><![CDATA[In March 2025 an actor calling themselves rose87168 advertised six million Oracle Cloud SSO and LDAP records, and Oracle quietly acknowledged a breach of legacy infrastructure. We unpack what happened and what tenants should do.]]></description>
      <link>https://safeguard.sh/resources/blog/oracle-cloud-classic-rose87168-sso-ldap-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oracle-cloud-classic-rose87168-sso-ldap-2025</guid>
      <pubDate>Sun, 19 Apr 2026 07:39:58 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The MIT Software License: What It Permits and What to Watch For]]></title>
      <description><![CDATA[The MIT software license is short, permissive, and lets you do almost anything as long as you keep the copyright notice. Here is what it actually requires and where teams still get tripped up.]]></description>
      <link>https://safeguard.sh/resources/blog/mit-software-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mit-software-license</guid>
      <pubDate>Sun, 19 Apr 2026 06:19:32 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Security Assessment Tools: how to evaluate your pos...]]></title>
      <description><![CDATA[Wiz and other CNAPPs assess your deployed cloud infrastructure — but not the software supply chain that built it. Here's how to evaluate both.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-security-assessment-tools-how-to-evaluate-your-posture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-security-assessment-tools-how-to-evaluate-your-posture</guid>
      <pubDate>Sun, 19 Apr 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What the Checkmarx Tool Is Used For: A Practical Guide]]></title>
      <description><![CDATA[The Checkmarx tool is a static application security testing platform that scans source code for vulnerabilities before you ship. Here is what it does, where it fits, and its limits.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-tool</guid>
      <pubDate>Sun, 19 Apr 2026 04:59:05 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Python MagicMock Security: Keeping Test Doubles Honest]]></title>
      <description><![CDATA[Python's MagicMock makes tests fast and isolated, but the same auto-magic that makes it convenient can hide security regressions. Here is how to use it without lying to yourself.]]></description>
      <link>https://safeguard.sh/resources/blog/python-magic-mock</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-magic-mock</guid>
      <pubDate>Sun, 19 Apr 2026 03:38:38 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Attack Surface Management (ASM): discovery, monitoring, m...]]></title>
      <description><![CDATA[ASM isn't just cloud exposure. See why discovery, monitoring, mapping, and reduction must extend into the software supply chain—and where tools like Wiz fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/attack-surface-management-asm-discovery-monitoring-mapping-reduction</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/attack-surface-management-asm-discovery-monitoring-mapping-reduction</guid>
      <pubDate>Sun, 19 Apr 2026 03:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[flask-security-too: What It Is and How to Use It Securely]]></title>
      <description><![CDATA[flask-security-too is the maintained successor to Flask-Security, giving Flask apps authentication, roles, and account features out of the box. Here is what it provides and how to configure it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/flask-security-too</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/flask-security-too</guid>
      <pubDate>Sun, 19 Apr 2026 02:18:12 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[DevOps Success Metrics That Actually Predict Delivery Health]]></title>
      <description><![CDATA[The DevOps success metrics worth tracking are the four DORA measures plus a few reliability and security signals. Vanity dashboards measure activity; these measure outcomes.]]></description>
      <link>https://safeguard.sh/resources/blog/devops-success-metrics</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devops-success-metrics</guid>
      <pubDate>Sun, 19 Apr 2026 00:57:45 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CNAPP vs. CSPM]]></title>
      <description><![CDATA[CNAPP and CSPM answer cloud posture questions — but who verifies what's actually inside your software? A grounded look at Safeguard vs. Aqua Security's approaches.]]></description>
      <link>https://safeguard.sh/resources/blog/cnapp-vs-cspm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cnapp-vs-cspm</guid>
      <pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Compliance Tools: How to Choose the Right One]]></title>
      <description><![CDATA[A practical guide to cloud compliance tools: the categories that exist, what each actually does, and how to pick tooling that maps to your frameworks.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-compliance-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-compliance-tools</guid>
      <pubDate>Sat, 18 Apr 2026 23:37:18 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Choosing a Docker Security Tool: What Actually Matters]]></title>
      <description><![CDATA[A Docker security tool scans images, configs, and running containers for risk. Here is what each category covers and how to pick one that fits your workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-security-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-security-tool</guid>
      <pubDate>Sat, 18 Apr 2026 22:16:51 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[XXE Example in Java: How the Attack Works and How to Stop It]]></title>
      <description><![CDATA[A concrete XXE example in Java showing why default XML parsers are dangerous, what an attacker can read, and the exact parser configuration that shuts it down.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-example-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-example-java</guid>
      <pubDate>Sat, 18 Apr 2026 20:56:25 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Scanner Software: Categories and How to Choose]]></title>
      <description><![CDATA[Network scanners, DAST, SCA, SAST, container and cloud scanners all claim the same job. Here is what each category actually finds and how to assemble coverage without buying six consoles.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-scanner-software-categories</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-scanner-software-categories</guid>
      <pubDate>Sat, 18 Apr 2026 19:35:58 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Updating Ruby on a Mac: A Safe, Security-Minded Guide]]></title>
      <description><![CDATA[The Ruby that ships with macOS is old and there for the system, not you. Here is how to install and update Ruby on a Mac, including Apple Silicon, without breaking anything.]]></description>
      <link>https://safeguard.sh/resources/blog/ruby-mac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ruby-mac</guid>
      <pubDate>Sat, 18 Apr 2026 18:15:31 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to Install Python on a MacBook Safely (2025 Guide)]]></title>
      <description><![CDATA[The macOS system Python is not the one you should build on. Here is how to install Python on a MacBook the right way, isolate projects, and avoid supply-chain surprises.]]></description>
      <link>https://safeguard.sh/resources/blog/install-python-macbook</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/install-python-macbook</guid>
      <pubDate>Sat, 18 Apr 2026 16:55:05 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Prevention Cheat Sheet]]></title>
      <description><![CDATA[A practitioner's SQL injection cheatsheet: parameterized queries, safe ORM use, input validation, least privilege, and the exact patterns to ban in review.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-prevention-cheat-sheet</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-prevention-cheat-sheet</guid>
      <pubDate>Sat, 18 Apr 2026 15:34:38 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Marks & Spencer DragonForce Ransomware Attack: Retail Giant Brought to Its Knees]]></title>
      <description><![CDATA[The April 2025 ransomware attack on M&S disrupted online orders for weeks, wiped out hundreds of millions in market value, and exposed retail sector vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/marks-spencer-dragonforce-ransomware</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/marks-spencer-dragonforce-ransomware</guid>
      <pubDate>Sat, 18 Apr 2026 14:14:11 GMT</pubDate>
      <category>Breach Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Gartner and SAST: How the AST Magic Quadrant Covers Static Analysis]]></title>
      <description><![CDATA[There is no standalone Gartner SAST Magic Quadrant. Here is how Gartner actually evaluates static analysis inside the Application Security Testing report.]]></description>
      <link>https://safeguard.sh/resources/blog/gartner-sast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gartner-sast</guid>
      <pubDate>Sat, 18 Apr 2026 12:53:45 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[2026 Q1 CVE Trend Analysis]]></title>
      <description><![CDATA[A data-driven look at CVE trends from Q1 2026: publication volume, severity distribution, exploitation patterns, and what the shifts mean for defenders.]]></description>
      <link>https://safeguard.sh/resources/blog/2026-q1-cve-trend-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/2026-q1-cve-trend-analysis</guid>
      <pubDate>Sat, 18 Apr 2026 12:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[XSS Examples: Real Payloads and How They Execute]]></title>
      <description><![CDATA[Concrete XSS examples across HTML, attribute, and JavaScript contexts, with the payloads that trigger them and why each one runs.]]></description>
      <link>https://safeguard.sh/resources/blog/xss-examples-real-payloads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xss-examples-real-payloads</guid>
      <pubDate>Sat, 18 Apr 2026 11:33:18 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[jQuery UI Latest Version: Where It Stands and What to Do About It]]></title>
      <description><![CDATA[The jQuery UI latest version is in the 1.14.x line, released in 2024, and the project is now in maintenance mode. Here is what that means for your dependency and its security.]]></description>
      <link>https://safeguard.sh/resources/blog/jquery-ui-latest-version</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jquery-ui-latest-version</guid>
      <pubDate>Sat, 18 Apr 2026 10:12:51 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Agentless vs. Agent-Based Security & Monitoring]]></title>
      <description><![CDATA[Agentless vs agent-based security compared: how Aqua Security's runtime Enforcer model differs from Safeguard's pipeline-native supply chain scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/agentless-vs-agent-based-security-monitoring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agentless-vs-agent-based-security-monitoring</guid>
      <pubDate>Sat, 18 Apr 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Does a Code Quality Tool Actually Make Your Software More Secure?]]></title>
      <description><![CDATA[A code quality tool and a security scanner overlap more than teams realize. Here is where quality gates catch real vulnerabilities and where you still need dedicated AppSec tooling.]]></description>
      <link>https://safeguard.sh/resources/blog/code-quality-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-quality-tool</guid>
      <pubDate>Sat, 18 Apr 2026 08:52:24 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[DNS Vulnerabilities: The Attacks That Target the Internet's Address Book]]></title>
      <description><![CDATA[A DNS vulnerability lets an attacker forge, intercept, or redirect the name lookups your systems depend on. Here are the main classes and how to defend against them.]]></description>
      <link>https://safeguard.sh/resources/blog/dns-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dns-vulnerability</guid>
      <pubDate>Sat, 18 Apr 2026 07:31:58 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Tools Comparison 2025: Choosing the Right Stack]]></title>
      <description><![CDATA[The DevSecOps tooling landscape has exploded. From SAST to SCA to SBOM management, this guide compares the major categories and helps you build a coherent security toolchain.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-tools-comparison-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-tools-comparison-2025</guid>
      <pubDate>Sat, 18 Apr 2026 06:11:31 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Detection and Response (CDR) / EDR vs. CDR]]></title>
      <description><![CDATA[CDR catches bad behavior in running cloud workloads. Safeguard secures what gets built before it ever runs. A concrete look at how the two layers — and Aqua Security's CDR — actually differ.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-detection-and-response-cdr-edr-vs-cdr</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-detection-and-response-cdr-edr-vs-cdr</guid>
      <pubDate>Sat, 18 Apr 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Portal Deep Dive: Navigating the Security Dashboard]]></title>
      <description><![CDATA[A comprehensive walkthrough of the Safeguard portal, covering every panel, metric, and workflow that security teams use daily to manage software supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-portal-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-portal-deep-dive</guid>
      <pubDate>Sat, 18 Apr 2026 04:51:04 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Peter McKay and Snyk: What His Tenure Says About Developer Security]]></title>
      <description><![CDATA[Peter McKay led Snyk through its hypergrowth years as CEO. Here is what his tenure reveals about the developer-first security market and how to evaluate the tools it produced.]]></description>
      <link>https://safeguard.sh/resources/blog/peter-mckay-snyk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/peter-mckay-snyk</guid>
      <pubDate>Sat, 18 Apr 2026 03:30:38 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Aqua Security vs. Wiz]]></title>
      <description><![CDATA[Aqua Security and Wiz both compete as CNAPPs — agent-based vs. agentless. Neither was built to prove what's in your software. Here's where Safeguard's supply chain focus fits.]]></description>
      <link>https://safeguard.sh/resources/blog/aqua-security-vs-wiz</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aqua-security-vs-wiz</guid>
      <pubDate>Sat, 18 Apr 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[npm bluebird in 2025: Is the Promise Library Still Safe to Use?]]></title>
      <description><![CDATA[The npm bluebird package still gets tens of millions of weekly downloads, but it has gone quiet. Here is an honest read on whether to keep it or migrate.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-bluebird</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-bluebird</guid>
      <pubDate>Sat, 18 Apr 2026 02:10:11 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[The npm prepare Script: What It Does and How to Use It Safely]]></title>
      <description><![CDATA[The npm prepare lifecycle script runs at more moments than most developers realize, including when someone installs your package from git. Here is exactly when it fires and how to keep it from becoming an attack vector.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-prepare</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-prepare</guid>
      <pubDate>Sat, 18 Apr 2026 00:49:44 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Aqua Security vs. Prisma Cloud]]></title>
      <description><![CDATA[Aqua Security and Prisma Cloud both compete as CNAPPs — but neither was built to prove what's in your software. Here's where Safeguard's supply chain focus fits.]]></description>
      <link>https://safeguard.sh/resources/blog/aqua-security-vs-prisma-cloud</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aqua-security-vs-prisma-cloud</guid>
      <pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[usehooks-ts: A Typed React Hooks Library Reviewed]]></title>
      <description><![CDATA[usehooks-ts packs 30+ typed React hooks into a tree-shakable package with a single dependency. Here is what it does well, where it is aging, and how to vet it before adoption.]]></description>
      <link>https://safeguard.sh/resources/blog/usehooks-ts-package-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/usehooks-ts-package-review</guid>
      <pubDate>Fri, 17 Apr 2026 23:29:18 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Is react-native-svg-transformer Safe to Use? A Security Guide]]></title>
      <description><![CDATA[react-native-svg-transformer lets you import SVG files as React components in Metro, but it runs at build time and pulls a dependency tree worth reviewing. Here's how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-svg-transformer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-svg-transformer</guid>
      <pubDate>Fri, 17 Apr 2026 22:08:51 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Is react-native-image-crop-picker Safe? A Security Guide]]></title>
      <description><![CDATA[react-native-image-crop-picker is a popular native module for photo selection and cropping in React Native apps. Here is how to assess its risk and use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-image-crop-picker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-image-crop-picker</guid>
      <pubDate>Fri, 17 Apr 2026 20:48:24 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is a PHP Security Scanner and Which One Should You Use?]]></title>
      <description><![CDATA[A PHP security scanner inspects your code and dependencies for injection flaws, insecure configuration, and known CVEs. Here is how the different tool classes work and where each fits.]]></description>
      <link>https://safeguard.sh/resources/blog/php-security-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-security-scanner</guid>
      <pubDate>Fri, 17 Apr 2026 19:27:58 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Dependabot vs Renovate vs Autonomous Remediation]]></title>
      <description><![CDATA[Dependabot opens PRs, Renovate manages them, autonomous remediation merges them. A spec-level comparison of three generations of dependency update automation.]]></description>
      <link>https://safeguard.sh/resources/blog/dependabot-vs-renovate-vs-autonomous-remediation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependabot-vs-renovate-vs-autonomous-remediation</guid>
      <pubDate>Fri, 17 Apr 2026 18:07:31 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Jonas Meyer)</author>
    </item>
    <item>
      <title><![CDATA[Mend Security Explained: What Mend.io Does and How It Works]]></title>
      <description><![CDATA[A clear look at Mend security: what the platform formerly known as WhiteSource covers, how its automated remediation works, and where its strengths and gaps lie.]]></description>
      <link>https://safeguard.sh/resources/blog/mend-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mend-security</guid>
      <pubDate>Fri, 17 Apr 2026 16:47:04 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[node-html-parser: How to Parse HTML Safely in Node.js]]></title>
      <description><![CDATA[node-html-parser is a fast, dependency-light HTML parser for Node.js. Here is how to use it without opening the door to injection or denial-of-service bugs.]]></description>
      <link>https://safeguard.sh/resources/blog/node-html-parser</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-html-parser</guid>
      <pubDate>Fri, 17 Apr 2026 15:26:37 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Is the npm qs Package Safe? A Security Review of qs]]></title>
      <description><![CDATA[The npm qs package parses query strings under most Express apps, and a prototype pollution flaw once let a single URL hang your Node process. Here is what to check and how to use qs safely.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-qs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-qs</guid>
      <pubDate>Fri, 17 Apr 2026 14:06:11 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Implement Shift Left Testing Without Slowing Delivery]]></title>
      <description><![CDATA[Shift left testing means moving quality and security checks earlier, into design and coding, instead of leaving them until the end. Here is a practical way to implement it.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-implement-shift-left-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-implement-shift-left-testing</guid>
      <pubDate>Fri, 17 Apr 2026 12:45:44 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Azure DevOps Personal Access Tokens in 2026: Rotation, Scoping, and Replacement]]></title>
      <description><![CDATA[PATs remain the most common credential leak in Azure DevOps incidents. We trace the patterns that actually reduce risk and the migration paths that retire them entirely.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-devops-personal-access-token-rotation-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-devops-personal-access-token-rotation-2026</guid>
      <pubDate>Fri, 17 Apr 2026 12:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Python SSL: How to Verify TLS Certificates the Right Way]]></title>
      <description><![CDATA[The Python ssl module gives you safe defaults for free, but only if you use them. Here is how to set up certificate verification correctly and avoid the mistakes that quietly disable it.]]></description>
      <link>https://safeguard.sh/resources/blog/python-ssl</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-ssl</guid>
      <pubDate>Fri, 17 Apr 2026 11:25:17 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[LDAP Injection Explained With a Real Example]]></title>
      <description><![CDATA[A walkthrough of a concrete LDAP injection example, why the filter syntax makes it dangerous, and how to detect and remediate it in real code.]]></description>
      <link>https://safeguard.sh/resources/blog/ldap-injection-example</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ldap-injection-example</guid>
      <pubDate>Fri, 17 Apr 2026 10:04:51 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Software Supply Chain Attack? A 2026 Primer]]></title>
      <description><![CDATA[A grounded 2026 primer on software supply chain attacks: definitions, the four real attack vectors, landmark incidents, and where defenders should start.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-attack-primer-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-attack-primer-2026</guid>
      <pubDate>Fri, 17 Apr 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Aqua Security vs. Sysdig Secure]]></title>
      <description><![CDATA[Aqua Security and Sysdig Secure both cover runtime and posture, but neither owns the software supply chain. Here's how Safeguard closes that gap.]]></description>
      <link>https://safeguard.sh/resources/blog/aqua-security-vs-sysdig-secure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aqua-security-vs-sysdig-secure</guid>
      <pubDate>Fri, 17 Apr 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Securing actions/setup-node in Your CI Pipeline]]></title>
      <description><![CDATA[The actions/setup-node step looks harmless, but pinning, caching, and registry auth choices decide whether it becomes a supply chain foothold. Here is how to harden it.]]></description>
      <link>https://safeguard.sh/resources/blog/actions-setup-node</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/actions-setup-node</guid>
      <pubDate>Fri, 17 Apr 2026 08:44:24 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Static Code Analysis Tools: The Open Source Options]]></title>
      <description><![CDATA[Static code analysis tools open source teams actually use — Semgrep, CodeQL, Bandit, ESLint security plugins — and where each one's coverage runs out.]]></description>
      <link>https://safeguard.sh/resources/blog/static-code-analysis-tools-open-source-options</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-code-analysis-tools-open-source-options</guid>
      <pubDate>Fri, 17 Apr 2026 07:23:57 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Most Common Java Security Flaws and How to Fix Them]]></title>
      <description><![CDATA[A practitioner's tour of the Java security flaws that actually break production systems — deserialization, injection, XXE, and the dependency risks that scanners miss.]]></description>
      <link>https://safeguard.sh/resources/blog/java-security-flaws</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-security-flaws</guid>
      <pubDate>Fri, 17 Apr 2026 06:03:31 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Top Aqua Security Alternatives & Competitors]]></title>
      <description><![CDATA[Comparing Safeguard and Aqua Security on scope, architecture, and compliance fit — runtime/CNAPP protection versus build-time software supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/top-aqua-security-alternatives-competitors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-aqua-security-alternatives-competitors</guid>
      <pubDate>Fri, 17 Apr 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Deep Code Analysis: What It Is and How It Finds Bugs Shallow Scans Miss]]></title>
      <description><![CDATA[Deep code analysis reads how data flows through your program instead of matching patterns line by line. Here is what that buys you over grep-style linting.]]></description>
      <link>https://safeguard.sh/resources/blog/deep-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/deep-code</guid>
      <pubDate>Fri, 17 Apr 2026 04:43:04 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Preventing broken access control in Express.js applications]]></title>
      <description><![CDATA[Express.js ships with no built-in authorization layer, making broken access control easy to introduce and hard to catch with pattern-based scanners.]]></description>
      <link>https://safeguard.sh/resources/blog/preventing-broken-access-control-in-expressjs-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preventing-broken-access-control-in-expressjs-applications</guid>
      <pubDate>Fri, 17 Apr 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[React Form Input Packages: react-hook-form, react-phone-input-2, country-state-city]]></title>
      <description><![CDATA[The react-phone-input-2 npm package has half a million weekly downloads and no releases since 2021. A practical review of three form-layer dependencies and what each one really costs.]]></description>
      <link>https://safeguard.sh/resources/blog/react-form-input-packages-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-form-input-packages-review</guid>
      <pubDate>Fri, 17 Apr 2026 03:22:37 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[MCP Security]]></title>
      <description><![CDATA[MCP is standardizing how AI agents call tools, and attackers are already exploiting tool poisoning, rug pulls, and shadowing. Here's what MCP security actually requires.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-security</guid>
      <pubDate>Fri, 17 Apr 2026 03:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[SAST Scans Explained: How Static Analysis Finds Code Flaws]]></title>
      <description><![CDATA[SAST scans read your source code without running it, tracing untrusted data from input to sink to catch injection and other flaws before they ship.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-scans</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-scans</guid>
      <pubDate>Fri, 17 Apr 2026 02:02:11 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Security concerns of using the Node.js VM module as a sandbox]]></title>
      <description><![CDATA[Node's vm module and vm2 were never a security boundary. Four critical CVEs and a 2023 deprecation prove why untrusted-code sandboxes need real isolation.]]></description>
      <link>https://safeguard.sh/resources/blog/security-concerns-of-using-the-nodejs-vm-module-as-a-sandbox</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-concerns-of-using-the-nodejs-vm-module-as-a-sandbox</guid>
      <pubDate>Fri, 17 Apr 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Erlang/OTP SSH CVE-2025-32433: Unauthenticated RCE Scoring 10.0]]></title>
      <description><![CDATA[A maximum-severity vulnerability in Erlang/OTP's SSH server allowed unauthenticated remote code execution. Any system running Erlang's built-in SSH daemon was at risk, including telecom infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/erlang-otp-ssh-cve-2025-32433-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/erlang-otp-ssh-cve-2025-32433-rce</guid>
      <pubDate>Fri, 17 Apr 2026 00:41:44 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Protecting GenAI: OWASP Top 10 for LLMs]]></title>
      <description><![CDATA[OWASP's Top 10 for LLM Applications reframes AI risk around prompt injection, data poisoning, and supply chain gaps that container-only tools like Aqua can't reach.]]></description>
      <link>https://safeguard.sh/resources/blog/protecting-genai-owasp-top-10-for-llms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/protecting-genai-owasp-top-10-for-llms</guid>
      <pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How to Run JavaScript Code: Methods and Security Notes]]></title>
      <description><![CDATA[A practical guide to how to run JavaScript code in the browser, with Node.js, and from the command line, plus the security traps that turn a convenient runner into a liability.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-run-javascript-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-run-javascript-code</guid>
      <pubDate>Thu, 16 Apr 2026 23:21:17 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[SAST vs DAST: When to Use Each (and Why Not Either/Or)]]></title>
      <description><![CDATA[SAST and DAST test different layers of an application at different stages of the pipeline — the real question isn't which to pick, it's how to run both without duplicating effort.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-vs-dast-when-to-use-each</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-vs-dast-when-to-use-each</guid>
      <pubDate>Thu, 16 Apr 2026 22:00:50 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Application Security Best Practices]]></title>
      <description><![CDATA[Five layers cover most of the risk in cloud apps: identity, secrets, artifact scanning, pipeline gates, and runtime guardrails. Here is how to build each one without slowing delivery.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-application-security-best-practices-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-application-security-best-practices-guide</guid>
      <pubDate>Thu, 16 Apr 2026 20:40:24 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Open Python on Mac (and Do It Securely)]]></title>
      <description><![CDATA[Recent macOS versions ship without Python at all, so opening Python on a Mac now means installing it yourself — and doing that safely matters more than most guides admit.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-open-python-on-mac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-open-python-on-mac</guid>
      <pubDate>Thu, 16 Apr 2026 19:19:57 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-20873: The Spring Boot Cloud Foundry Auth Bypass Explained]]></title>
      <description><![CDATA[A clear breakdown of CVE-2023-20873, the Spring Boot security bypass on Cloud Foundry: affected versions, why wildcard matching caused it, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-20873</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-20873</guid>
      <pubDate>Thu, 16 Apr 2026 17:59:30 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[OSS Scan: How to Scan Open Source Dependencies for Vulnerabilities]]></title>
      <description><![CDATA[An OSS scan finds known vulnerabilities in the open source packages your code depends on. Here is how the scan works, where it fits in CI, and how to act on results.]]></description>
      <link>https://safeguard.sh/resources/blog/oss-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oss-scan</guid>
      <pubDate>Thu, 16 Apr 2026 16:39:04 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Java URLEncode: How to Encode URLs Safely in Java]]></title>
      <description><![CDATA[Java urlencode is usually URLEncoder.encode, but it is built for form bodies, not full URLs. Here is when to use it and when it introduces bugs.]]></description>
      <link>https://safeguard.sh/resources/blog/java-urlencode</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-urlencode</guid>
      <pubDate>Thu, 16 Apr 2026 15:18:37 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Java URL Decode: Doing It Safely Without Opening Holes]]></title>
      <description><![CDATA[Java URL decode looks trivial until you hit double-decoding and encoding mismatches. Here is how to decode URLs in Java correctly and where the security bugs hide.]]></description>
      <link>https://safeguard.sh/resources/blog/java-url-decode</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-url-decode</guid>
      <pubDate>Thu, 16 Apr 2026 13:58:10 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Copyleft Meaning Explained: How Reciprocal Licenses Work]]></title>
      <description><![CDATA[The meaning of copyleft, in plain terms: how reciprocal licenses keep software free, how strong and weak copyleft differ, and why it changes how you use open source dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/copyleft-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/copyleft-meaning</guid>
      <pubDate>Thu, 16 Apr 2026 12:37:44 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Frontier LLM Vendors Are Not Your Supply Chain Security Vendor]]></title>
      <description><![CDATA[Coding agents from OpenAI, Anthropic, and Google are excellent tools. They are also not supply chain security platforms, and the assumption that they can replace one is already producing expensive gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/frontier-llm-vendors-not-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/frontier-llm-vendors-not-supply-chain-security</guid>
      <pubDate>Thu, 16 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Total Cost of Ownership: Griffin AI vs Mythos]]></title>
      <description><![CDATA[List price is the easiest number to compare and the least interesting one. TCO over three years is where Griffin AI vs Mythos-class platforms actually diverge.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-total-cost-of-ownership</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-total-cost-of-ownership</guid>
      <pubDate>Thu, 16 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Rust Supply Chain: cargo-vet Expansion in 2025]]></title>
      <description><![CDATA[Mozilla and Google expanded cargo-vet's shared audit pool to 14,000 crates in Q1 2025. Here's how to adopt it without drowning in imports.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-supply-chain-cargo-vet-expansion-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-supply-chain-cargo-vet-expansion-2025</guid>
      <pubDate>Thu, 16 Apr 2026 11:17:17 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What a Container Security Platform Should Actually Do]]></title>
      <description><![CDATA[A container security platform has to cover images, registries, and running workloads. Here is what real coverage looks like and how to evaluate one.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-platform</guid>
      <pubDate>Thu, 16 Apr 2026 10:45:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What is Application Security (AppSec)]]></title>
      <description><![CDATA[Application security spans SAST, SCA, secrets and container scanning. See how AppSec differs from DevSecOps, why it's now board-level, and how Safeguard prioritizes fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-application-security-appsec</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-application-security-appsec</guid>
      <pubDate>Thu, 16 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-10768: The AngularJS Prototype Pollution Flaw Explained]]></title>
      <description><![CDATA[CVE-2019-10768 is a prototype pollution vulnerability in AngularJS before 1.7.9, where the merge() function can be tricked into modifying Object.prototype. Here is what it does, who it affects, and how to remediate.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-10768</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-10768</guid>
      <pubDate>Thu, 16 Apr 2026 09:56:50 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Android Application Security Solutions That Reduce Real Risk]]></title>
      <description><![CDATA[Android application security solutions span secure storage, network hardening, code protection, and dependency scanning. Here is what each layer covers and how iOS compares.]]></description>
      <link>https://safeguard.sh/resources/blog/android-application-security-solutions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/android-application-security-solutions</guid>
      <pubDate>Thu, 16 Apr 2026 08:36:24 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Sustainability Is an Attack Surface Problem]]></title>
      <description><![CDATA[Unmaintained, underfunded open source is not just a reliability risk — it is how attackers get in. The xz Utils backdoor proved that maintainer burnout is a security vulnerability with a CVE number.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-sustainability-attack-surface</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-sustainability-attack-surface</guid>
      <pubDate>Thu, 16 Apr 2026 08:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Windows NTLM Hash Disclosure CVE-2025-24054: The Protocol That Won't Die]]></title>
      <description><![CDATA[CVE-2025-24054 leaks NTLM hashes through .library-ms files with minimal user interaction. Microsoft patched it in April 2025, but exploitation started almost immediately.]]></description>
      <link>https://safeguard.sh/resources/blog/windows-ntlm-hash-disclosure-cve-2025-24054</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/windows-ntlm-hash-disclosure-cve-2025-24054</guid>
      <pubDate>Thu, 16 Apr 2026 07:15:57 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Static Application Security Testing (SAST)]]></title>
      <description><![CDATA[SAST scans source code for exploitable flaws before deployment. Learn how it works, how it differs from DAST/SCA, and where it falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/static-application-security-testing-sast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-application-security-testing-sast</guid>
      <pubDate>Thu, 16 Apr 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Image Scanning]]></title>
      <description><![CDATA[How container image scanning works, where tools like Aqua Security's Trivy fall short on noise and reachability, and what modern scanning workflows require.]]></description>
      <link>https://safeguard.sh/resources/blog/image-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/image-scanning</guid>
      <pubDate>Thu, 16 Apr 2026 06:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Testing and Debugging for Security: A Practical Guide]]></title>
      <description><![CDATA[Testing and debugging are where most security bugs are actually caught or missed. Here is how to fold security into both without slowing your team down.]]></description>
      <link>https://safeguard.sh/resources/blog/testing-and-debugging</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/testing-and-debugging</guid>
      <pubDate>Thu, 16 Apr 2026 05:55:30 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[MIT License and Commercial Use: What You Can and Cannot Do]]></title>
      <description><![CDATA[The MIT License lets you use, modify, and sell software commercially with almost no restrictions — as long as you keep the copyright notice. Here is exactly what that permits and requires.]]></description>
      <link>https://safeguard.sh/resources/blog/mit-license-commercial-use</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mit-license-commercial-use</guid>
      <pubDate>Thu, 16 Apr 2026 04:35:03 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[How Does SAST Work? Stages of SAST Scanning]]></title>
      <description><![CDATA[A stage-by-stage breakdown of how SAST scanning actually works — parsing, taint analysis, false positives — with real CVEs and benchmark data.]]></description>
      <link>https://safeguard.sh/resources/blog/how-does-sast-work-stages-of-sast-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-does-sast-work-stages-of-sast-scanning</guid>
      <pubDate>Thu, 16 Apr 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Injection Attacks: Types and Prevention]]></title>
      <description><![CDATA[JavaScript injection covers a family of attacks where untrusted input becomes executable code or markup in the browser. Here are the types and the concrete defenses for each.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-injection-attacks-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-injection-attacks-prevention</guid>
      <pubDate>Thu, 16 Apr 2026 03:14:37 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Container Registry Scanning]]></title>
      <description><![CDATA[How container registry scanning actually works, why Aqua's Trivy isn't enough on its own, what the xz-utils backdoor exposed, and how Safeguard prioritizes findings that matter.]]></description>
      <link>https://safeguard.sh/resources/blog/container-registry-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-registry-scanning</guid>
      <pubDate>Thu, 16 Apr 2026 03:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What a Code Fixer Really Does: A Security Guide]]></title>
      <description><![CDATA[A code fixer promises to find and repair bugs automatically, but for security work the details matter. Here is how to use one without introducing new risk.]]></description>
      <link>https://safeguard.sh/resources/blog/code-fixer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-fixer</guid>
      <pubDate>Thu, 16 Apr 2026 01:54:10 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Dynamic Application Security Testing (DAST)]]></title>
      <description><![CDATA[DAST tests running apps like an attacker would. Learn how it works, what it catches and misses, and how PCI DSS 4.0 now mandates it.]]></description>
      <link>https://safeguard.sh/resources/blog/dynamic-application-security-testing-dast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dynamic-application-security-testing-dast</guid>
      <pubDate>Thu, 16 Apr 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[immer npm: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[The immer npm package makes immutable state updates painless, but its older versions carried prototype pollution flaws. Here is its security history and how to depend on it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/immer-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/immer-npm</guid>
      <pubDate>Thu, 16 Apr 2026 00:33:43 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Docker CIS Benchmark]]></title>
      <description><![CDATA[A practical breakdown of the Docker CIS Benchmark's 100+ controls, the checks teams fail most, how Aqua Security handles compliance, and what audit failures actually cost.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-cis-benchmark</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-cis-benchmark</guid>
      <pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[True Positives vs False Positives in Cyber Security]]></title>
      <description><![CDATA[A true positive is a real finding your tools caught correctly; a false positive is noise that looks like a finding but isn't — and the ratio between them decides whether your security program gets trusted or ignored.]]></description>
      <link>https://safeguard.sh/resources/blog/true-positives-vs-false-positives-in-cyber-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/true-positives-vs-false-positives-in-cyber-security</guid>
      <pubDate>Wed, 15 Apr 2026 23:13:17 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[LDAP Injection Attacks: How They Work and How to Prevent Them]]></title>
      <description><![CDATA[LDAP injection lets an attacker manipulate directory-service queries by inserting special filter characters into user input, often bypassing authentication entirely — here's how the attack works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/ldap-injection-attacks-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ldap-injection-attacks-explained</guid>
      <pubDate>Wed, 15 Apr 2026 21:52:50 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Dockerfile Best Practices: Security, Size, and Build Speed]]></title>
      <description><![CDATA[Most Dockerfiles are copy-pasted from a tutorial and never revisited. Here's what actually shrinks image size, closes the common security holes, and speeds up rebuilds.]]></description>
      <link>https://safeguard.sh/resources/blog/dockerfile-best-practices-security-and-size</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dockerfile-best-practices-security-and-size</guid>
      <pubDate>Wed, 15 Apr 2026 20:32:23 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SAST and DAST Full Form: What the Acronyms Actually Mean]]></title>
      <description><![CDATA[The SAST and DAST full form is Static and Dynamic Application Security Testing. Here is what each one does, where they differ, and when to use both.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-and-dast-full-form</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-and-dast-full-form</guid>
      <pubDate>Wed, 15 Apr 2026 19:11:57 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Compliance Platform: A Buyer's Security Guide]]></title>
      <description><![CDATA[A cloud compliance platform continuously maps your cloud configuration and evidence to frameworks like SOC 2 and ISO 27001. Here is what one actually does and how to tell a real one from a checkbox tool.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-compliance-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-compliance-platform</guid>
      <pubDate>Wed, 15 Apr 2026 17:51:30 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is vm2? The Node.js Sandbox and Its Security History]]></title>
      <description><![CDATA[vm2 was the most popular way to run untrusted JavaScript inside Node.js — until a string of sandbox-escape CVEs and its 2023 deprecation showed why sandboxing a dynamic language is so hard to get right.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-vm2-nodejs-sandbox-security-history</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-vm2-nodejs-sandbox-security-history</guid>
      <pubDate>Wed, 15 Apr 2026 16:31:03 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Stored XSS Explained: A Security Guide]]></title>
      <description><![CDATA[Stored XSS is the persistent, high-impact form of cross-site scripting where a malicious script is saved server-side and served to every visitor. Here is how to detect and stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/xxss-stored-xss</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxss-stored-xss</guid>
      <pubDate>Wed, 15 Apr 2026 15:10:37 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[AI-Driven Security: What It Actually Does for Application Security]]></title>
      <description><![CDATA[AI-driven security is more than a buzzword bolted onto old scanners. Here's where machine learning genuinely helps triage, reachability, and detection — and where it quietly hurts.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-driven-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-driven-security</guid>
      <pubDate>Wed, 15 Apr 2026 14:45:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[XXE Attack Example: How XML External Entity Injection Works and How to Stop It]]></title>
      <description><![CDATA[A defensive XXE attack example that explains how XML External Entity injection abuses parsers, what it can expose, and the parser settings that shut it down.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-attack-example</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-attack-example</guid>
      <pubDate>Wed, 15 Apr 2026 13:50:10 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Install Maven on Windows, macOS, and Linux]]></title>
      <description><![CDATA[A step-by-step guide to install Maven on any OS, verify the install, and avoid the JAVA_HOME and PATH mistakes that trip up most first-time setups.]]></description>
      <link>https://safeguard.sh/resources/blog/install-maven</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/install-maven</guid>
      <pubDate>Wed, 15 Apr 2026 12:29:43 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSF's Maintainer Handoff Governance: From Burnout-Driven Sabotage to Structured Repository Transfer]]></title>
      <description><![CDATA[After colors.js, event-stream, and the colors-faker sabotage incidents, the OpenSSF Securing Software Repositories WG drafted guidance for when registries should allow ownership transfer of long-standing projects. Here is the defender view.]]></description>
      <link>https://safeguard.sh/resources/blog/openssf-maintainer-handoff-governance-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssf-maintainer-handoff-governance-2026</guid>
      <pubDate>Wed, 15 Apr 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[TSA Surface Transportation Cyber NPRM: From Directives to Rule]]></title>
      <description><![CDATA[TSA's November 2024 Enhancing Surface Cyber Risk Management NPRM would formalize what pipeline and rail SDs already require. Operators should prepare now.]]></description>
      <link>https://safeguard.sh/resources/blog/tsa-surface-transportation-cyber-nprm-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tsa-surface-transportation-cyber-nprm-2025</guid>
      <pubDate>Wed, 15 Apr 2026 12:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Docker Laravel Security: Hardening Your PHP Container from Base Image to Runtime]]></title>
      <description><![CDATA[A security-focused guide to running Laravel in Docker — non-root PHP-FPM, multi-stage builds, secret handling, and locking down the layers that leak.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-laravel</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-laravel</guid>
      <pubDate>Wed, 15 Apr 2026 11:09:16 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[MCP Meaning: What the Model Context Protocol Is and Why It Matters]]></title>
      <description><![CDATA[The MCP meaning most people are asking about is the Model Context Protocol, an open standard that lets AI models connect to tools and data through one common interface.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-meaning</guid>
      <pubDate>Wed, 15 Apr 2026 10:10:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise SCA Platform Buyer Guide 2026]]></title>
      <description><![CDATA[A 2026 buyer guide for enterprise SCA platforms covering language coverage, reachability, policy depth, integration surface, and how the consolidator market is shifting.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-sca-platform-buyer-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-sca-platform-buyer-guide-2026</guid>
      <pubDate>Wed, 15 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[SBOM vs. VEX: What's the Difference and When Do You Need Each?]]></title>
      <description><![CDATA[SBOMs tell you what is in your software. VEX tells you which of those components are actually exploitable. Here is how to use both without drowning in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-vs-vex-when-do-you-need-each</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-vs-vex-when-do-you-need-each</guid>
      <pubDate>Wed, 15 Apr 2026 10:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software Composition Analysis (SCA)]]></title>
      <description><![CDATA[SCA finds every open source package in your code and flags known CVEs against it. Here's how it works, its blind spots, and how to fix them.]]></description>
      <link>https://safeguard.sh/resources/blog/software-composition-analysis-sca</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-composition-analysis-sca</guid>
      <pubDate>Wed, 15 Apr 2026 10:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Careers: What Working in Developer Security Looks Like]]></title>
      <description><![CDATA[Curious about Snyk careers? Here is an honest look at the company, the kinds of roles it hires for, and the broader developer-security field the openings sit in.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-careers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-careers</guid>
      <pubDate>Wed, 15 Apr 2026 09:48:50 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Cleo MFT CVE-2024-50623 Supply Chain Postmortem]]></title>
      <description><![CDATA[Cleo's managed file transfer products became the next MOVEit. A postmortem on CVE-2024-50623, the Cl0p exploitation, and the file-transfer software risk class.]]></description>
      <link>https://safeguard.sh/resources/blog/cleo-mft-cve-2024-50623-supply-chain-postmortem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cleo-mft-cve-2024-50623-supply-chain-postmortem</guid>
      <pubDate>Wed, 15 Apr 2026 09:45:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[DORA Compliance for Fintech Engineering Teams]]></title>
      <description><![CDATA[DORA has applied since January 2025. For engineers that means ICT asset inventories, 4-hour incident classification, TLPT, and a register of every software supplier.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-compliance-for-fintech-engineering-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-compliance-for-fintech-engineering-teams</guid>
      <pubDate>Wed, 15 Apr 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes CIS Benchmark]]></title>
      <description><![CDATA[CIS Kubernetes Benchmark controls, common failure patterns, how Aqua Security's kube-bench fits in, and how continuous, supply-chain-aware scanning closes the gaps a point-in-time scan leaves open.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-cis-benchmark</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-cis-benchmark</guid>
      <pubDate>Wed, 15 Apr 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Llama 4 Release and LlamaFirewall: A Defender's Guide]]></title>
      <description><![CDATA[Meta shipped Llama 4 Scout and Maverick on April 5, 2025, along with Llama Guard 4, LlamaFirewall, and CyberSecEval 4. We unpack what defenders should deploy and what to ignore.]]></description>
      <link>https://safeguard.sh/resources/blog/llama-4-release-llamafirewall-defender-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llama-4-release-llamafirewall-defender-guide</guid>
      <pubDate>Wed, 15 Apr 2026 08:28:23 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[How to Test Your Signing Pipeline End to End]]></title>
      <description><![CDATA[Build a repeatable end-to-end test harness for your signing pipeline that proves artifacts are signed correctly and that verification fails when tampered.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-test-your-signing-pipeline-end-to-end</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-test-your-signing-pipeline-end-to-end</guid>
      <pubDate>Wed, 15 Apr 2026 07:07:56 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Interactive Application Security Testing (IAST)]]></title>
      <description><![CDATA[IAST instruments running apps to catch injection flaws and unsafe data flows in real time. Here's how it works, its limits, and where it fits.]]></description>
      <link>https://safeguard.sh/resources/blog/interactive-application-security-testing-iast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/interactive-application-security-testing-iast</guid>
      <pubDate>Wed, 15 Apr 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Software Transparency Goes Global: Regulatory Developments in 2025]]></title>
      <description><![CDATA[From the EU Cyber Resilience Act to Japan's software security guidelines, governments worldwide are mandating software transparency. A comprehensive overview of the global regulatory landscape.]]></description>
      <link>https://safeguard.sh/resources/blog/software-transparency-global-regulations-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-transparency-global-regulations-2025</guid>
      <pubDate>Wed, 15 Apr 2026 05:47:30 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[netty-handler: TLS in Netty and Keeping It Patched]]></title>
      <description><![CDATA[netty-handler is where Netty's TLS lives, which makes it the module scanners flag most. What SslHandler actually does, the hostname-verification gotcha, and the patch cadence to keep.]]></description>
      <link>https://safeguard.sh/resources/blog/netty-handler-maven-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/netty-handler-maven-security-guide</guid>
      <pubDate>Wed, 15 Apr 2026 04:27:03 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Runtime Application Self-Protection (RASP)]]></title>
      <description><![CDATA[RASP blocks attacks from inside a running app. Learn how it works, how it differs from a WAF, its limits, top vendors, and where it fits with SAST/SCA.]]></description>
      <link>https://safeguard.sh/resources/blog/runtime-application-self-protection-rasp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runtime-application-self-protection-rasp</guid>
      <pubDate>Wed, 15 Apr 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[X.509 Certificates in .NET: System.Security.Cryptography Explained]]></title>
      <description><![CDATA[A practitioner's tour of System.Security.Cryptography.X509Certificates: loading certs safely on modern .NET, chain validation, stores, and the mistakes that quietly disable TLS security.]]></description>
      <link>https://safeguard.sh/resources/blog/x509-certificates-dotnet-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/x509-certificates-dotnet-guide</guid>
      <pubDate>Wed, 15 Apr 2026 03:06:36 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Secrets]]></title>
      <description><![CDATA[Kubernetes Secrets are base64, not encrypted, by default. Here is how they actually leak, why scanners like Aqua fall short, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-secrets</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-secrets</guid>
      <pubDate>Wed, 15 Apr 2026 03:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[react-native-blob-util: A Security Guide to Safe File and Blob Handling]]></title>
      <description><![CDATA[react-native-blob-util is the maintained successor to rn-fetch-blob. Here is what it does, why the migration matters for security, and how to handle files safely.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-blob-util</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-blob-util</guid>
      <pubDate>Wed, 15 Apr 2026 01:46:10 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[SAST vs DAST: Key Differences]]></title>
      <description><![CDATA[SAST reads code before it runs; DAST attacks it while it's live. Here's what each catches, what each misses, and when to run both.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-vs-dast-key-differences</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-vs-dast-key-differences</guid>
      <pubDate>Wed, 15 Apr 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Tornado Python Security: Hardening Your Async Web App]]></title>
      <description><![CDATA[A security-focused guide to the Tornado Python web framework, covering the cookie-parsing DoS, secure cookie configuration, and safe deployment patterns.]]></description>
      <link>https://safeguard.sh/resources/blog/tornado-python</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tornado-python</guid>
      <pubDate>Wed, 15 Apr 2026 00:25:43 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[eBPF in Kubernetes]]></title>
      <description><![CDATA[eBPF gives Kubernetes deep runtime visibility, but it only sees what a container does after it starts. Here's what Aqua's Tracee gets right, and where supply chain gaps remain.]]></description>
      <link>https://safeguard.sh/resources/blog/ebpf-in-kubernetes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ebpf-in-kubernetes</guid>
      <pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Pronounce Snyk (and Other Security Tool Names People Get Wrong)]]></title>
      <description><![CDATA[The correct answer to how to pronounce Snyk, plus a rundown of the other AppSec tool names — Nginx, Kubernetes, Grype — that trip people up in meetings.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-pronounce-snyk-and-other-security-tool-names</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-pronounce-snyk-and-other-security-tool-names</guid>
      <pubDate>Tue, 14 Apr 2026 23:05:16 GMT</pubDate>
      <category>Culture</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Is body-parser Safe to Use? A Security Review of the npm Package]]></title>
      <description><![CDATA[npm body-parser is Express middleware for reading request bodies, and it is safe when kept current. Here is the CVE-2024-45590 denial-of-service issue and how to configure it defensively.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-bodyparser</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-bodyparser</guid>
      <pubDate>Tue, 14 Apr 2026 21:44:49 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Pipeline Example: A Secure CI/CD Workflow]]></title>
      <description><![CDATA[A concrete DevSecOps pipeline example, stage by stage, showing where SAST, SCA, secret scanning, and DAST fit into a real CI/CD workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-pipeline-example</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-pipeline-example</guid>
      <pubDate>Tue, 14 Apr 2026 20:24:23 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[DRP Testing: How to Validate a Disaster Recovery Plan]]></title>
      <description><![CDATA[What DRP testing is, the test types from tabletop to full failover, how often to run them, and how to turn recovery drills into evidence auditors accept.]]></description>
      <link>https://safeguard.sh/resources/blog/drp-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/drp-testing</guid>
      <pubDate>Tue, 14 Apr 2026 19:03:56 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is End-to-End Encryption? Privacy From Sender to Recipient]]></title>
      <description><![CDATA[End-to-end encryption keeps data readable only by the sender and intended recipient, so not even the service carrying the message can see its contents.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-end-to-end-encryption</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-end-to-end-encryption</guid>
      <pubDate>Tue, 14 Apr 2026 17:43:29 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Node.js Licensing Explained: The MIT Core and Its Bundled Dependencies]]></title>
      <description><![CDATA[Node.js licensing looks simple until you count the bundled components. Here is what the MIT-licensed runtime actually obligates you to, and where the real compliance work hides.]]></description>
      <link>https://safeguard.sh/resources/blog/node-js-licensing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-js-licensing</guid>
      <pubDate>Tue, 14 Apr 2026 16:23:03 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Next.js Security Vulnerability: CVE-2025-29927 Explained]]></title>
      <description><![CDATA[A single spoofed HTTP header could skip your Next.js middleware entirely. Here is what the CVE-2025-29927 authorization bypass is, who it affects, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/next-js-security-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/next-js-security-vulnerability</guid>
      <pubDate>Tue, 14 Apr 2026 15:02:36 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis vs EPSS vs CVSS: Prioritization Showdown]]></title>
      <description><![CDATA[CVSS scores severity, EPSS predicts exploitation, reachability proves applicability. A spec-level comparison of the three signals — and the order to apply them.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-vs-epss-vs-cvss-prioritization-showdown</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-vs-epss-vs-cvss-prioritization-showdown</guid>
      <pubDate>Tue, 14 Apr 2026 14:00:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Tomas Lindgren)</author>
    </item>
    <item>
      <title><![CDATA[jQuery Cookie: Why jquery.cookie Is Deprecated and What to Use Now]]></title>
      <description><![CDATA[The jquery.cookie plugin is abandoned and carries a known prototype-pollution vulnerability. Here is what changed and how to migrate to js-cookie.]]></description>
      <link>https://safeguard.sh/resources/blog/jquery-cookie</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jquery-cookie</guid>
      <pubDate>Tue, 14 Apr 2026 13:42:09 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Cybersecurity AI: Where It Genuinely Helps Today]]></title>
      <description><![CDATA[A no-hype survey of where cybersecurity AI actually delivers measurable results right now, versus the applications still stuck in the demo stage.]]></description>
      <link>https://safeguard.sh/resources/blog/cybersecurity-ai-where-it-genuinely-helps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cybersecurity-ai-where-it-genuinely-helps</guid>
      <pubDate>Tue, 14 Apr 2026 13:20:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Is Formik on npm Safe? A Security Review]]></title>
      <description><![CDATA[Formik is a widely used React form library. Here is an honest look at its security history, dependency risk, and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/formik-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/formik-npm</guid>
      <pubDate>Tue, 14 Apr 2026 12:21:43 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[copy-webpack-plugin and terser-webpack-plugin: Build Pipeline Hygiene]]></title>
      <description><![CDATA[The copy-webpack-plugin npm package and terser-webpack-plugin sit in almost every webpack build. Here's how to configure both without leaking files or shipping stale minifiers.]]></description>
      <link>https://safeguard.sh/resources/blog/copy-webpack-plugin-and-terser-webpack-plugin-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/copy-webpack-plugin-and-terser-webpack-plugin-guide</guid>
      <pubDate>Tue, 14 Apr 2026 11:01:16 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[SAST vs SCA Testing]]></title>
      <description><![CDATA[SAST scans the code you wrote; SCA scans the code you imported. Here's the real difference, with Equifax, Log4Shell, and xz as case studies.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-vs-sca-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-vs-sca-testing</guid>
      <pubDate>Tue, 14 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What Is a DTO (Data Transfer Object)? Security Notes for Java and Beyond]]></title>
      <description><![CDATA[A DTO is a plain object that carries data across a boundary. Used well it is also one of your best defenses against mass assignment and data over-exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/dto</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dto</guid>
      <pubDate>Tue, 14 Apr 2026 09:40:49 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CycloneDX vs SPDX: SBOM Format Comparison 2026]]></title>
      <description><![CDATA[A practical CycloneDX vs SPDX comparison for 2026 buyers: schema depth, tool support, regulatory alignment, and which format to pick for which use case.]]></description>
      <link>https://safeguard.sh/resources/blog/cyclonedx-vs-spdx-sbom-format-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyclonedx-vs-spdx-sbom-format-comparison-2026</guid>
      <pubDate>Tue, 14 Apr 2026 09:30:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[AI for Cyber Security: What Works and What Is Hype]]></title>
      <description><![CDATA[AI for cyber security is real where it triages signal at machine scale, and overstated where vendors promise autonomous defense. Here is how to tell the two apart.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-for-cyber-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-for-cyber-security</guid>
      <pubDate>Tue, 14 Apr 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Snyk Logo: The Story Behind Patch the Guard Dog]]></title>
      <description><![CDATA[The Snyk logo is a friendly Doberman named Patch, and the choice of a guard dog says more about the company's positioning than a wordmark ever could.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-logo</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-logo</guid>
      <pubDate>Tue, 14 Apr 2026 08:20:23 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Dependency Scanners: A Buyer's Checklist]]></title>
      <description><![CDATA[A practical checklist for evaluating an open source dependency scanner — ecosystem coverage, reachability analysis, license detection, and how each handles transitive dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-dependency-scanners-a-buyers-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-dependency-scanners-a-buyers-checklist</guid>
      <pubDate>Tue, 14 Apr 2026 08:20:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Tracking Kubernetes CVEs in 2026: A Practical Method]]></title>
      <description><![CDATA[Kubernetes CVE news moves fast across control plane, kubelet, and CNI components — here's a repeatable method for tracking what actually applies to your cluster.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-cve-tracking-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-cve-tracking-2026</guid>
      <pubDate>Tue, 14 Apr 2026 08:00:00 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[DAST vs IAST]]></title>
      <description><![CDATA[DAST attacks running apps from the outside; IAST watches from inside during tests. Here's how they differ, where each wins, and when to use both.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-vs-iast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-vs-iast</guid>
      <pubDate>Tue, 14 Apr 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Meaning in Telugu: The Term Explained for Security Teams]]></title>
      <description><![CDATA[The vulnerability meaning in Telugu is durbalatvam, a weakness that can be exploited. Here is the translation plus what the word actually signifies in software security.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-meaning-in-telugu</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-meaning-in-telugu</guid>
      <pubDate>Tue, 14 Apr 2026 06:59:56 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Python Code Analysis: Tools and Techniques for Secure Code]]></title>
      <description><![CDATA[How static and dynamic Python code analysis catches security bugs before they ship, from Bandit and Semgrep to dependency scanning and taint tracking.]]></description>
      <link>https://safeguard.sh/resources/blog/python-code-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-code-analysis</guid>
      <pubDate>Tue, 14 Apr 2026 05:39:29 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Is the npm express Package Safe? A Security Review]]></title>
      <description><![CDATA[The npm express package is the most widely used Node.js web framework, and it is safe to run today if you stay on a maintained version and watch its small dependencies. Here is the security picture.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-express</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-express</guid>
      <pubDate>Tue, 14 Apr 2026 04:19:02 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[SCA vs SBOM: What's the Difference]]></title>
      <description><![CDATA[SCA and SBOM aren't the same thing: one is a scanning process, the other is a compliance artifact. Here's how they differ and why you need both.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-vs-sbom-whats-the-difference</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-vs-sbom-whats-the-difference</guid>
      <pubDate>Tue, 14 Apr 2026 04:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SSDF (Secure Software Development Framework)]]></title>
      <description><![CDATA[NIST SP 800-218 turned SSDF into a federal procurement gate. Here is what it requires, why attestation is mandatory, and where CNAPP tools like Aqua fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/ssdf-secure-software-development-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ssdf-secure-software-development-framework</guid>
      <pubDate>Tue, 14 Apr 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[@testing-library/jest-dom: What It Does and How to Keep It Secure]]></title>
      <description><![CDATA[@testing-library/jest-dom is a dev-only matcher library that is low risk to your production security, provided you keep it out of your runtime bundle and patched.]]></description>
      <link>https://safeguard.sh/resources/blog/testing-library-jest-dom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/testing-library-jest-dom</guid>
      <pubDate>Tue, 14 Apr 2026 02:58:36 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-22081: The Oracle Java JSSE Denial-of-Service Flaw]]></title>
      <description><![CDATA[CVE-2023-22081 is a Java SE and GraalVM vulnerability in the JSSE component that can cause a partial denial of service over HTTPS. Here is what to patch.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-22081</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-22081</guid>
      <pubDate>Tue, 14 Apr 2026 01:38:09 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SAST vs Penetration Testing]]></title>
      <description><![CDATA[SAST scans code before deploy; pentesting attacks it after. Here's where each catches real vulnerabilities, where they miss, and what Log4Shell proved.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-vs-penetration-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-vs-penetration-testing</guid>
      <pubDate>Tue, 14 Apr 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What Is Snyk Code? A Guide to the SAST Often Misspelled "Synk Code"]]></title>
      <description><![CDATA["Synk Code" is a common misspelling of Snyk Code, Snyk's developer-first SAST engine. Here is what it scans, how DeepCode AI works, and where it fits.]]></description>
      <link>https://safeguard.sh/resources/blog/synk-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/synk-code</guid>
      <pubDate>Tue, 14 Apr 2026 00:17:42 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Attacks]]></title>
      <description><![CDATA[Software supply chain attacks like SolarWinds, XZ Utils, and polyfill.io exploit trust, not code. Here's how they work and how Safeguard closes the provenance gap.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-attacks</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-40152: Woodstox XML Parsing Denial of Service]]></title>
      <description><![CDATA[CVE-2022-40152 lets malicious XML with deeply nested DTD content crash Woodstox-based parsers via stack overflow. Here is the root cause, affected versions, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-40152</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-40152</guid>
      <pubDate>Mon, 13 Apr 2026 22:57:16 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Why We Use CORS in Node.js: Configuration Without the Foot-Guns]]></title>
      <description><![CDATA[Understanding why we use CORS in Node.js starts with what it is not: CORS is a browser relaxation mechanism, not a security wall. Here is how to configure it in Express without the classic misconfigurations.]]></description>
      <link>https://safeguard.sh/resources/blog/cors-in-nodejs-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cors-in-nodejs-explained</guid>
      <pubDate>Mon, 13 Apr 2026 21:36:49 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Secure Session Management: A Practical Guide for Web Apps]]></title>
      <description><![CDATA[Secure session management comes down to a handful of decisions about cookies, storage, expiry, and rotation. Get those right and you close off most session-based attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-session-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-session-management</guid>
      <pubDate>Mon, 13 Apr 2026 20:16:22 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[GitLab IaC Scanning: How to Catch Misconfigured Infrastructure]]></title>
      <description><![CDATA[GitLab IaC scanning checks Terraform, Kubernetes, and CloudFormation for insecure settings before they deploy. Here is how to turn it on and make the results actionable.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-iac-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-iac-scanning</guid>
      <pubDate>Mon, 13 Apr 2026 18:55:56 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Choose an Enterprise Vulnerability Management Tool]]></title>
      <description><![CDATA[What an enterprise vulnerability management tool actually needs to do, how it differs from a scanner, and the evaluation criteria that separate a program that scales from one that drowns in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-vulnerability-management-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-vulnerability-management-tool</guid>
      <pubDate>Mon, 13 Apr 2026 17:35:29 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Spring Boot Logging Best Practices That Keep Secrets Out of Your Logs]]></title>
      <description><![CDATA[Spring Boot logging best practices focused on security: structured logs, keeping secrets and PII out, safe log levels, and avoiding the mistakes that turned Log4Shell into a catastrophe.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-boot-logging-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-boot-logging-best-practices</guid>
      <pubDate>Mon, 13 Apr 2026 16:15:02 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[PHP Application Security: A Practical Guide to Locking Down Your Code]]></title>
      <description><![CDATA[PHP application security comes down to a handful of high-impact controls. Here is how to handle injection, sessions, uploads, and dependencies without the theory.]]></description>
      <link>https://safeguard.sh/resources/blog/php-application-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-application-security</guid>
      <pubDate>Mon, 13 Apr 2026 14:54:36 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AppSec Vulnerability Management: A Workflow Guide]]></title>
      <description><![CDATA[A step-by-step appsec vulnerability management workflow for teams drowning in scanner output — from intake and triage through prioritization, remediation, and verification.]]></description>
      <link>https://safeguard.sh/resources/blog/appsec-vulnerability-management-workflow-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/appsec-vulnerability-management-workflow-guide</guid>
      <pubDate>Mon, 13 Apr 2026 13:34:09 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[The Semgrep Logo and What Semgrep Actually Does]]></title>
      <description><![CDATA[Looking for the Semgrep logo often means you are evaluating Semgrep the tool. Here is what the brand mark represents and how the static analysis engine works.]]></description>
      <link>https://safeguard.sh/resources/blog/semgrep-logo</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/semgrep-logo</guid>
      <pubDate>Mon, 13 Apr 2026 12:13:42 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[AWS CodePipeline Supply Chain Defence 2026]]></title>
      <description><![CDATA[AWS CodePipeline is where most AWS-native supply chain attacks land in 2026. This is the defence blueprint that actually works in production accounts.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-codepipeline-supply-chain-defence-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-codepipeline-supply-chain-defence-2026</guid>
      <pubDate>Mon, 13 Apr 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Defense Prime Supply Chain Flowdown 2026]]></title>
      <description><![CDATA[Defense primes are pushing supply chain security obligations down to subcontractors at every tier. Here is how to absorb the flowdown without breaking delivery.]]></description>
      <link>https://safeguard.sh/resources/blog/defense-prime-supply-chain-flowdown-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/defense-prime-supply-chain-flowdown-2026</guid>
      <pubDate>Mon, 13 Apr 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MFT Mass Exploitation Trend In 2026]]></title>
      <description><![CDATA[Managed file transfer platforms have become a recurring epicenter of mass exploitation. We trace the 2026 incidents, the reused tradecraft, and what defenders should do now.]]></description>
      <link>https://safeguard.sh/resources/blog/managed-file-transfer-mass-exploitation-trend-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/managed-file-transfer-mass-exploitation-trend-2026</guid>
      <pubDate>Mon, 13 Apr 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Pattern Scanners Can't Find Zero-Days. This Can.]]></title>
      <description><![CDATA[Signature-based scanners only know what other people have already named. Here is the architectural reason they cannot find zero-days, and what actually does.]]></description>
      <link>https://safeguard.sh/resources/blog/pattern-scanners-cant-find-zero-days-this-can</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pattern-scanners-cant-find-zero-days-this-can</guid>
      <pubDate>Mon, 13 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Solving The 1,000-Vulnerability Backlog Problem]]></title>
      <description><![CDATA[How security teams escape the four-figure vulnerability backlog using reachability analysis, automated PRs, and AI-driven triage that actually scales.]]></description>
      <link>https://safeguard.sh/resources/blog/solving-the-1000-vulnerability-backlog-problem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/solving-the-1000-vulnerability-backlog-problem</guid>
      <pubDate>Mon, 13 Apr 2026 12:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Stopping Risky Dependencies At PR Time, Not Production]]></title>
      <description><![CDATA[Catching risky dependencies after they reach production is expensive. PR-time policy gates stop them at the cheapest moment, with the right context and reviewer attention.]]></description>
      <link>https://safeguard.sh/resources/blog/stopping-risky-dependencies-at-pr-time-not-prod</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/stopping-risky-dependencies-at-pr-time-not-prod</guid>
      <pubDate>Mon, 13 Apr 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[jsonwebtoken npm: Security Review and Safe Usage]]></title>
      <description><![CDATA[The jsonwebtoken npm package signs and verifies JWTs for countless Node apps, and versions at or below 8.5.1 carry serious verification flaws. Here is how to use npm jsonwebtoken safely.]]></description>
      <link>https://safeguard.sh/resources/blog/jsonwebtoken-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jsonwebtoken-npm</guid>
      <pubDate>Mon, 13 Apr 2026 10:53:15 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to Read a CycloneDX SBOM: A Line-by-Line Walkthrough]]></title>
      <description><![CDATA[A walkthrough of a CycloneDX 1.6 JSON document — metadata, components, services, dependencies, and vulnerabilities — with a real snippet and what to check first.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-read-a-cyclonedx-sbom-walkthrough</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-read-a-cyclonedx-sbom-walkthrough</guid>
      <pubDate>Mon, 13 Apr 2026 10:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Penetration Testing]]></title>
      <description><![CDATA[Penetration testing simulates real attacks to prove exploitability, not just list CVEs. Here's how it works, what it costs, and how often it's required.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-penetration-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-penetration-testing</guid>
      <pubDate>Mon, 13 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Secure Code Review: A Practical Checklist]]></title>
      <description><![CDATA[Secure code reviews catch a different category of bug than functional code review, and having a repeatable checklist keeps reviewers from relying on memory for the same handful of recurring flaws.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-code-review-a-practical-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-code-review-a-practical-checklist</guid>
      <pubDate>Mon, 13 Apr 2026 09:32:49 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Confusion Attack]]></title>
      <description><![CDATA[How dependency confusion attacks exploit registry name collisions to run attacker code inside corporate networks, from Alex Birsan's 2021 research to the 2022 PyTorch breach.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-confusion-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-confusion-attack</guid>
      <pubDate>Mon, 13 Apr 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[webpack-bundle-analyzer: Find Bloat and Risky Dependencies in Your Bundle]]></title>
      <description><![CDATA[webpack bundle analyzer turns your build output into a zoomable treemap. Used well, it finds not just bloat but duplicated packages, surprise transitive dependencies, and code you never meant to ship.]]></description>
      <link>https://safeguard.sh/resources/blog/webpack-bundle-analyzer-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webpack-bundle-analyzer-guide</guid>
      <pubDate>Mon, 13 Apr 2026 08:12:22 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What is Vulnerability Scanning]]></title>
      <description><![CDATA[Vulnerability scanning automatically checks code, dependencies, and infra against known-flaw databases like the NVD. Here's how it works and why reachability matters.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-vulnerability-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-vulnerability-scanning</guid>
      <pubDate>Mon, 13 Apr 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[broadcast-channel npm Package: Health, Security, and Alternatives]]></title>
      <description><![CDATA[A practitioner review of the broadcast-channel npm package: maintenance health, how its storage fallbacks work, the security boundaries of cross-tab messaging, and when the native API is enough.]]></description>
      <link>https://safeguard.sh/resources/blog/broadcast-channel-npm-package-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/broadcast-channel-npm-package-review</guid>
      <pubDate>Mon, 13 Apr 2026 06:51:55 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Repojacking]]></title>
      <description><![CDATA[Aqua Security found nearly 37,000 GitHub repos vulnerable to repojacking, including Google and Lyft. Here's how the attack works and how Safeguard catches it.]]></description>
      <link>https://safeguard.sh/resources/blog/repojacking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/repojacking</guid>
      <pubDate>Mon, 13 Apr 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Mobile Security Testing for iOS and Android Apps]]></title>
      <description><![CDATA[Mobile apps fail in ways web apps don't — insecure local storage, weak certificate pinning, reverse-engineerable binaries — and testing them requires methods most web-focused AppSec programs never built.]]></description>
      <link>https://safeguard.sh/resources/blog/mobile-security-testing-for-ios-and-android-apps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mobile-security-testing-for-ios-and-android-apps</guid>
      <pubDate>Mon, 13 Apr 2026 05:31:29 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Docker LABEL: A Security and Metadata Guide]]></title>
      <description><![CDATA[How the Docker LABEL instruction works, the OCI annotation conventions worth adopting, and how good labels make image supply chains auditable.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-label</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-label</guid>
      <pubDate>Mon, 13 Apr 2026 04:11:02 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What is Vulnerability Management]]></title>
      <description><![CDATA[Vulnerability management turns thousands of CVEs into a ranked, fixable backlog. Here's how the lifecycle, prioritization, and standards actually work.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-vulnerability-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-vulnerability-management</guid>
      <pubDate>Mon, 13 Apr 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Container Image Signing]]></title>
      <description><![CDATA[Signing tells you where a container image came from; scanning only tells you what's inside it. Here's how image signing works, how Aqua handles it, and what a complete solution needs.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-signing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-signing</guid>
      <pubDate>Mon, 13 Apr 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Code Error Finder Tools: Catching Security Bugs Early]]></title>
      <description><![CDATA[A code error finder is any tool that surfaces bugs before they ship — and the ones that matter most for security catch the errors that turn into vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/code-error-finder</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-error-finder</guid>
      <pubDate>Mon, 13 Apr 2026 02:50:35 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Does Snyk Offer IAST? Interactive Testing and the Alternatives]]></title>
      <description><![CDATA[People searching for Snyk IAST are usually asking whether Snyk does interactive application security testing. Here is the honest answer and how IAST fits alongside Snyk's actual strengths.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-iast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-iast</guid>
      <pubDate>Mon, 13 Apr 2026 01:30:09 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is a Vulnerability Assessment]]></title>
      <description><![CDATA[A vulnerability assessment finds and ranks security weaknesses at scale — here's how it differs from a pentest, its five-step process, and reporting essentials.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-vulnerability-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-vulnerability-assessment</guid>
      <pubDate>Mon, 13 Apr 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Server Vulnerability Assessment: A Step-by-Step Guide]]></title>
      <description><![CDATA[A server vulnerability assessment finds the missing patches, weak configs, and exposed services on your hosts before an attacker does. Here is how to run one that produces action, not noise.]]></description>
      <link>https://safeguard.sh/resources/blog/server-vulnerability-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/server-vulnerability-assessment</guid>
      <pubDate>Mon, 13 Apr 2026 00:09:42 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[MITRE ATT&CK Framework]]></title>
      <description><![CDATA[MITRE ATT&CK maps 200+ attacker techniques, but runtime tools like Aqua only catch supply chain compromise after deployment. Here's the build-time gap and how to close it.]]></description>
      <link>https://safeguard.sh/resources/blog/mitre-attck-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mitre-attck-framework</guid>
      <pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[FAR CUI Proposed Rule: An 8-Hour Clock and a Government-Wide Standard]]></title>
      <description><![CDATA[The January 15, 2025 FAR CUI rule extends NIST SP 800-171 to every federal contractor and adds an 8-hour incident reporting clock for non-federal facilities.]]></description>
      <link>https://safeguard.sh/resources/blog/far-cui-proposed-rule-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/far-cui-proposed-rule-2025</guid>
      <pubDate>Sun, 12 Apr 2026 22:49:15 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Bounty Program Scoping for Dependencies]]></title>
      <description><![CDATA[How to scope a bug bounty program when most of your attack surface lives in third-party dependencies — with guidance on payouts, triage, and upstream coordination.]]></description>
      <link>https://safeguard.sh/resources/blog/bounty-program-scoping-for-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bounty-program-scoping-for-dependencies</guid>
      <pubDate>Sun, 12 Apr 2026 21:28:49 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Is uglifyjs-webpack-plugin Safe to Use in 2025? What to Migrate To]]></title>
      <description><![CDATA[uglifyjs-webpack-plugin is deprecated and built on the unmaintained uglify-es. Here is why you should migrate to terser-webpack-plugin and how to do it cleanly.]]></description>
      <link>https://safeguard.sh/resources/blog/uglifyjs-webpack-plugin</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uglifyjs-webpack-plugin</guid>
      <pubDate>Sun, 12 Apr 2026 20:08:22 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[papaparse npm: Security Review and Best Practices]]></title>
      <description><![CDATA[PapaParse is the go-to CSV parser for JavaScript, but older versions carry a ReDoS flaw. Here is a security review and how to use it safely on untrusted files.]]></description>
      <link>https://safeguard.sh/resources/blog/papaparse-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/papaparse-npm</guid>
      <pubDate>Sun, 12 Apr 2026 18:47:55 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[WooCommerce Vulnerabilities: A Recurring Pattern Worth Knowing]]></title>
      <description><![CDATA[WooCommerce core is relatively well-maintained, but the plugin and extension ecosystem around it is where most reported WooCommerce vulnerabilities keep showing up.]]></description>
      <link>https://safeguard.sh/resources/blog/woocommerce-vulnerabilities-a-recurring-pattern</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/woocommerce-vulnerabilities-a-recurring-pattern</guid>
      <pubDate>Sun, 12 Apr 2026 17:27:28 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[DevOps Key Metrics: The Numbers That Actually Predict Delivery Health]]></title>
      <description><![CDATA[The DevOps key metrics worth tracking are the four DORA measures plus a handful of security signals. Here is what each one means, how to measure it, and why security belongs in the same dashboard.]]></description>
      <link>https://safeguard.sh/resources/blog/devops-key-metrics</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devops-key-metrics</guid>
      <pubDate>Sun, 12 Apr 2026 16:07:02 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[How Does Software Licensing Work? A Practical Guide for Developers]]></title>
      <description><![CDATA[Software licensing works by granting usage rights under specific terms. Here is how open-source and commercial licenses differ, and how to stay compliant in your dependency tree.]]></description>
      <link>https://safeguard.sh/resources/blog/how-does-software-licensing-work</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-does-software-licensing-work</guid>
      <pubDate>Sun, 12 Apr 2026 14:46:35 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[iOS App Security Testing: A Practical Guide for Mobile Teams]]></title>
      <description><![CDATA[iOS app security testing means checking storage, transport, and third-party code, not just trusting the App Store review. Here is how to do it well.]]></description>
      <link>https://safeguard.sh/resources/blog/ios-app-security-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ios-app-security-testing</guid>
      <pubDate>Sun, 12 Apr 2026 13:26:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CrushFTP CVE-2025-31161: Authentication Bypass Exploited in the Wild]]></title>
      <description><![CDATA[A critical authentication bypass in CrushFTP allowed unauthenticated access to file transfer servers. Exploitation was observed within days of disclosure, targeting multiple industries.]]></description>
      <link>https://safeguard.sh/resources/blog/crushftp-cve-2025-31161-authentication-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crushftp-cve-2025-31161-authentication-bypass</guid>
      <pubDate>Sun, 12 Apr 2026 12:05:42 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[AI Agent Supply Chain Attacks: 2026 Trend Watch]]></title>
      <description><![CDATA[AI agents pull tools, models, and data from a sprawling chain of upstream providers. In 2026 attackers learned to poison that chain — and the fallout is shaping how enterprises buy and operate agentic systems.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-agent-supply-chain-attacks-2026-trend-watch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-agent-supply-chain-attacks-2026-trend-watch</guid>
      <pubDate>Sun, 12 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Bank Software Supply Chain Controls 2026]]></title>
      <description><![CDATA[Banks face intensifying scrutiny over software supply chain risk. Here is the control set that satisfies regulators, auditors, and boards in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/bank-software-supply-chain-controls-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bank-software-supply-chain-controls-2026</guid>
      <pubDate>Sun, 12 Apr 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Model Context Protocol Permissions Model Explained]]></title>
      <description><![CDATA[MCP's permissions model is subtle. Here is a careful walkthrough of how tool scoping, sampling, and resource access actually work in production.]]></description>
      <link>https://safeguard.sh/resources/blog/model-context-protocol-permissions-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/model-context-protocol-permissions-model</guid>
      <pubDate>Sun, 12 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Node.js Supply Chain Defence Program 2026]]></title>
      <description><![CDATA[A practical 2026 blueprint for hardening Node.js supply chains across npm, lockfiles, scripts, and runtime — and where Safeguard plugs into the program.]]></description>
      <link>https://safeguard.sh/resources/blog/node-js-supply-chain-defence-program-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-js-supply-chain-defence-program-2026</guid>
      <pubDate>Sun, 12 Apr 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Securing MCP Servers Without Killing Developer Velocity]]></title>
      <description><![CDATA[MCP servers are spreading inside engineering orgs faster than security teams can review them. Here is how to govern them without slowing teams down.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-mcp-servers-without-killing-developer-velocity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-mcp-servers-without-killing-developer-velocity</guid>
      <pubDate>Sun, 12 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Shift-Left Without Friction: Dev Experience 2026]]></title>
      <description><![CDATA[Shift-left only works when developers stop noticing it. A 2026 playbook for moving supply chain checks earlier without burning the people who ship code.]]></description>
      <link>https://safeguard.sh/resources/blog/shift-left-without-friction-developer-experience-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shift-left-without-friction-developer-experience-2026</guid>
      <pubDate>Sun, 12 Apr 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Solve SCA False Positive Overload With Reachability Analysis]]></title>
      <description><![CDATA[SCA tools produce more findings than any team can review. Reachability analysis is the filter that turns the haystack into a queue your engineers will actually finish.]]></description>
      <link>https://safeguard.sh/resources/blog/solve-sca-false-positive-overload-with-reachability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/solve-sca-false-positive-overload-with-reachability</guid>
      <pubDate>Sun, 12 Apr 2026 12:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vendor Questionnaire Fatigue And How To End It]]></title>
      <description><![CDATA[Security questionnaires have ballooned into 400-row spreadsheets that nobody reads carefully. Here is how to replace the ritual with evidence ingestion that actually changes vendor risk decisions.]]></description>
      <link>https://safeguard.sh/resources/blog/vendor-questionnaire-fatigue-and-how-to-end-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vendor-questionnaire-fatigue-and-how-to-end-it</guid>
      <pubDate>Sun, 12 Apr 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Why LLMs Are Structurally Insecure (and What That Means for Your Pipeline)]]></title>
      <description><![CDATA[Language models are not insecure because of a bug you can patch. They are insecure by construction — non-deterministic, context-poisonable, and unreproducible. Here is how to reason about them without pretending otherwise.]]></description>
      <link>https://safeguard.sh/resources/blog/why-llms-are-structurally-insecure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-llms-are-structurally-insecure</guid>
      <pubDate>Sun, 12 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[You Cannot Secure What You Cannot See: Asset Discovery]]></title>
      <description><![CDATA[Most breaches start with an asset nobody remembered owning. Continuous asset discovery is the foundation that every other control depends on.]]></description>
      <link>https://safeguard.sh/resources/blog/you-cannot-secure-what-you-cannot-see-asset-discovery</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/you-cannot-secure-what-you-cannot-see-asset-discovery</guid>
      <pubDate>Sun, 12 Apr 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Whitebox Testing Explained: A Practical Security Guide]]></title>
      <description><![CDATA[Whitebox testing is a testing approach where the tester has full access to source code, architecture, and internals, which makes it powerful for finding security flaws early. Here is how it works and where it fits.]]></description>
      <link>https://safeguard.sh/resources/blog/whitebox-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/whitebox-testing</guid>
      <pubDate>Sun, 12 Apr 2026 10:45:15 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Prisma Cloud Runtime Security Deep Review 2026]]></title>
      <description><![CDATA[A working engineer's review of Prisma Cloud's runtime security capabilities in 2026, covering Defender architecture, detection efficacy, and operational realities.]]></description>
      <link>https://safeguard.sh/resources/blog/prisma-cloud-runtime-security-deep-review-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prisma-cloud-runtime-security-deep-review-2026</guid>
      <pubDate>Sun, 12 Apr 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Threat Modeling]]></title>
      <description><![CDATA[Threat modeling finds the design flaws scanners can't see. Learn what it is, when to do it, and how Safeguard ties it to reachability analysis.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-threat-modeling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-threat-modeling</guid>
      <pubDate>Sun, 12 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Authentication and Authorization: Securing the AI Tool Layer]]></title>
      <description><![CDATA[The Model Context Protocol enables AI agents to interact with external tools and data sources. Securing MCP servers requires authentication, authorization, and input validation patterns specific to the AI agent context.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-authentication-authorization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-authentication-authorization</guid>
      <pubDate>Sun, 12 Apr 2026 09:24:48 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Commands Explained: How the Attack Works and How to Stop It]]></title>
      <description><![CDATA[Understanding the SQL injection commands attackers rely on is the fastest way to learn how to defend against them. This guide explains the classes conceptually and focuses on detection and remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-commands</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-commands</guid>
      <pubDate>Sun, 12 Apr 2026 08:04:22 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What is Application Security Testing (AST)]]></title>
      <description><![CDATA[AST spans SAST, DAST, SCA, and IAST — automated techniques for finding exploitable flaws before they ship. Here's how each works and where teams go wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-application-security-testing-ast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-application-security-testing-ast</guid>
      <pubDate>Sun, 12 Apr 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[SAST Vendors Compared: How to Choose a Static Analysis Tool]]></title>
      <description><![CDATA[Choosing among SAST vendors comes down to language coverage, false-positive rate, developer workflow fit, and how the results reach the people who fix code.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-vendors</guid>
      <pubDate>Sun, 12 Apr 2026 06:43:55 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Trivy (Open Source Scanner)]]></title>
      <description><![CDATA[Trivy is free and fast, but Aqua Security built it as a funnel to its paid CNAPP. Here's what the open-source scanner misses and how Safeguard closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/trivy-open-source-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trivy-open-source-scanner</guid>
      <pubDate>Sun, 12 Apr 2026 06:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[babel-core Security: Known CVEs and How to Stay Patched]]></title>
      <description><![CDATA[babel-core is safe when current, but its dependency chain has carried a code-execution CVE and a ReDoS issue. Here is what to patch and why re-compiling matters.]]></description>
      <link>https://safeguard.sh/resources/blog/babel-core</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/babel-core</guid>
      <pubDate>Sun, 12 Apr 2026 05:23:28 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Run a Software Security Assessment]]></title>
      <description><![CDATA[A software security assessment is a structured evaluation of an application's security posture across code, dependencies, configuration, and process. Here is how to run one that produces action, not a PDF.]]></description>
      <link>https://safeguard.sh/resources/blog/software-security-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-security-assessment</guid>
      <pubDate>Sun, 12 Apr 2026 04:03:02 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Application Security Posture Management (ASPM)]]></title>
      <description><![CDATA[ASPM correlates SCA, SAST, DAST, and cloud findings with reachability context to cut alert noise 60-90% and speed remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-application-security-posture-management-aspm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-application-security-posture-management-aspm</guid>
      <pubDate>Sun, 12 Apr 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[ASPM vs CNAPP: collaboration, not collision]]></title>
      <description><![CDATA[ASPM and CNAPP tackle different layers of risk. Here's how Safeguard's application-first approach complements CNAPP platforms like Prisma Cloud.]]></description>
      <link>https://safeguard.sh/resources/blog/aspm-vs-cnapp-collaboration-not-collision</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aspm-vs-cnapp-collaboration-not-collision</guid>
      <pubDate>Sun, 12 Apr 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Python 2 vs Python 3: Differences and Why 2.x Is a Security Liability]]></title>
      <description><![CDATA[The real differences between Python 2 and Python 3 — print, strings, division, integers — and why running anything on 2.x after its end of life is now a security decision, not a compatibility one.]]></description>
      <link>https://safeguard.sh/resources/blog/python-2-vs-3-differences</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-2-vs-3-differences</guid>
      <pubDate>Sun, 12 Apr 2026 02:42:35 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Ivanti Connect Secure CVE-2025-22457: Another Critical Zero-Day, Same Product]]></title>
      <description><![CDATA[A stack-based buffer overflow in Ivanti Connect Secure was exploited by Chinese threat actors just months after the previous zero-day in the same product. The vulnerability was initially misclassified as low-risk.]]></description>
      <link>https://safeguard.sh/resources/blog/ivanti-connect-secure-cve-2025-22457</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ivanti-connect-secure-cve-2025-22457</guid>
      <pubDate>Sun, 12 Apr 2026 01:22:08 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Application Risk Management: Methods and Tools]]></title>
      <description><![CDATA[A practical breakdown of application risk management: the methods (reachability, RBVM), the tool categories (SCA, SAST, DAST, CSPM), and how to fix the backlog problem.]]></description>
      <link>https://safeguard.sh/resources/blog/application-risk-management-methods-and-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-risk-management-methods-and-tools</guid>
      <pubDate>Sun, 12 Apr 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Installing Python on Mac: A Safe, Step-by-Step Guide]]></title>
      <description><![CDATA[Installing Python on Mac has a few paths, and the safest one keeps you off the system Python and away from sudo pip. Here is how to do it cleanly.]]></description>
      <link>https://safeguard.sh/resources/blog/installing-python-on-mac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/installing-python-on-mac</guid>
      <pubDate>Sun, 12 Apr 2026 00:01:41 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CNAPP vs CASB: what's the difference?]]></title>
      <description><![CDATA[CNAPP and CASB are often confused, but they secure different things. Here's how they compare, how Prisma Cloud fits, and where supply chain security comes in.]]></description>
      <link>https://safeguard.sh/resources/blog/cnapp-vs-casb-whats-the-difference</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cnapp-vs-casb-whats-the-difference</guid>
      <pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[SCA Code: What Composition Analysis Actually Reads in Your Repo]]></title>
      <description><![CDATA[A concrete look at which files SCA tooling actually parses in a repository, how it builds a dependency tree, and why SCA is required even when your own code is clean.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-code-what-composition-analysis-reads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-code-what-composition-analysis-reads</guid>
      <pubDate>Sat, 11 Apr 2026 22:41:15 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SAST, DAST, and IAST: The Three Application Testing Types]]></title>
      <description><![CDATA[SAST DAST IAST are three distinct testing approaches that catch different bug classes at different stages — here's how each actually works and when to run which.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-dast-iast-the-three-testing-types</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-dast-iast-the-three-testing-types</guid>
      <pubDate>Sat, 11 Apr 2026 21:20:48 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm Supply Chain Attacks Q1 2025: Dependency Confusion, Typosquatting, and Maintainer Takeovers]]></title>
      <description><![CDATA[The first quarter of 2025 saw a sharp increase in npm supply chain attacks. We catalog the major incidents and analyze the evolving techniques.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-attacks-npm-2025-q1</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-attacks-npm-2025-q1</guid>
      <pubDate>Sat, 11 Apr 2026 20:00:21 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Secure Usage of Authorized Code Repositories: A Practical Guide]]></title>
      <description><![CDATA[Secure usage of authorized code repositories means controlling who can access source, protecting branches, scanning for secrets, and treating the repo as production infrastructure. Here is how.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-usage-of-authorized-code-repositories</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-usage-of-authorized-code-repositories</guid>
      <pubDate>Sat, 11 Apr 2026 18:39:55 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[jackson-core Maven: What It Is and Where the Risk Lives]]></title>
      <description><![CDATA[jackson-core is the low-level streaming engine behind Jackson, added via Maven. Here is what the artifact does, why it is safer than jackson-databind, and how to keep the whole stack patched.]]></description>
      <link>https://safeguard.sh/resources/blog/jackson-core-maven</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jackson-core-maven</guid>
      <pubDate>Sat, 11 Apr 2026 17:19:28 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Jakarta and Java: A Security Guide to the Namespace Migration]]></title>
      <description><![CDATA[Jakarta Java is the successor to Java EE, and the javax-to-jakarta namespace shift has real security implications for anyone still running the old libraries.]]></description>
      <link>https://safeguard.sh/resources/blog/jakarta-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jakarta-java</guid>
      <pubDate>Sat, 11 Apr 2026 15:59:01 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerable Websites List: Legal Sites to Practice Security Testing]]></title>
      <description><![CDATA[A curated vulnerable websites list of intentionally insecure apps and labs built for legal, hands-on security practice — plus the rules that keep your training from becoming a crime.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerable-websites-list</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerable-websites-list</guid>
      <pubDate>Sat, 11 Apr 2026 14:38:35 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Checker: How to Scan Your Code and Websites for Flaws]]></title>
      <description><![CDATA[What a vulnerability checker does, the different kinds (dependency, website, container), and how to choose and use one to actually reduce risk rather than generate noise.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-checker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-checker</guid>
      <pubDate>Sat, 11 Apr 2026 13:18:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Audit Prep: Month To Week With Continuous Evidence]]></title>
      <description><![CDATA[Replace last-minute audit scrambles with continuously generated supply chain evidence. Learn how compliance teams compress preparation timelines from weeks to days.]]></description>
      <link>https://safeguard.sh/resources/blog/audit-prep-month-to-week-with-continuous-evidence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/audit-prep-month-to-week-with-continuous-evidence</guid>
      <pubDate>Sat, 11 Apr 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Auto-PR Remediation Without Broken Builds]]></title>
      <description><![CDATA[Automated fix pull requests sound great until half of them fail CI. Here is how to ship auto-PR remediation that keeps the green build, every time.]]></description>
      <link>https://safeguard.sh/resources/blog/auto-pr-remediation-without-broken-builds</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/auto-pr-remediation-without-broken-builds</guid>
      <pubDate>Sat, 11 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Building A Defensible SBOM Program In 90 Days]]></title>
      <description><![CDATA[A pragmatic 90-day blueprint for standing up an SBOM program that survives auditor scrutiny, procurement reviews, and incident response without burning out your platform team.]]></description>
      <link>https://safeguard.sh/resources/blog/building-defensible-sbom-program-90-days</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-defensible-sbom-program-90-days</guid>
      <pubDate>Sat, 11 Apr 2026 12:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[EU CRA Enforcement First Year: What Changed]]></title>
      <description><![CDATA[A senior engineer's review of the first year of EU Cyber Resilience Act enforcement, what regulators actually asked for, what vendors got wrong, and where the bar moves next.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cra-enforcement-first-year-what-changed</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cra-enforcement-first-year-what-changed</guid>
      <pubDate>Sat, 11 Apr 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SecOps Runbook: Supply Chain Incident Response]]></title>
      <description><![CDATA[A practical runbook for supply chain incidents that turns chaos into ordered phases, with concrete artifacts, decision points, and Safeguard tooling at every step.]]></description>
      <link>https://safeguard.sh/resources/blog/secops-runbook-supply-chain-incident-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secops-runbook-supply-chain-incident-response</guid>
      <pubDate>Sat, 11 Apr 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Rolling Out Zero-CVE Base Images Org-Wide]]></title>
      <description><![CDATA[A pragmatic playbook for migrating an entire engineering organisation onto zero-CVE base images, covering pilot selection, registry mirroring, drift control, and the hard people-side of the rollout.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-cve-base-images-rolling-out-org-wide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-cve-base-images-rolling-out-org-wide-2026</guid>
      <pubDate>Sat, 11 Apr 2026 12:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Security Metrics for Executive Reporting]]></title>
      <description><![CDATA[A field-tested board-level metrics framework for supply chain security, covering MTTR, reachable risk, SBOM coverage, and vendor posture with dollar-tied targets.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-metrics-executive-reporting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-metrics-executive-reporting</guid>
      <pubDate>Sat, 11 Apr 2026 11:57:41 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Malicious Packages 2025: Python's Growing Supply Chain Problem]]></title>
      <description><![CDATA[PyPI faced a surge of malicious package uploads in early 2025, targeting data science, AI/ML, and cloud development workflows. Here's the full picture.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-malicious-packages-2025-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-malicious-packages-2025-report</guid>
      <pubDate>Sat, 11 Apr 2026 10:37:14 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Controls Explained]]></title>
      <description><![CDATA[A breakdown of what application security controls actually are, which ones matter most for supply chain risk, and how to prioritize them without alert fatigue.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-controls-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-controls-explained</guid>
      <pubDate>Sat, 11 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Serialize vs Deserialize: A Practical Comparison and Why Deserialization Is the Risky One]]></title>
      <description><![CDATA[Serialize turns an object into bytes; deserialize turns bytes back into an object. The comparison matters for security because deserializing untrusted data in Java has caused some of the worst RCE bugs on record.]]></description>
      <link>https://safeguard.sh/resources/blog/serialize-vs-deserialize</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/serialize-vs-deserialize</guid>
      <pubDate>Sat, 11 Apr 2026 09:16:48 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Benefits of Cloud Security Posture Management (CSPM)]]></title>
      <description><![CDATA[CSPM cuts breach risk and audit time by catching cloud misconfigurations before attackers do. See the data on cost, MTTR, and where Prisma Cloud falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/benefits-of-cloud-security-posture-management-cspm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/benefits-of-cloud-security-posture-management-cspm</guid>
      <pubDate>Sat, 11 Apr 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Qilin Ransomware Supply Chain Tactics 2025]]></title>
      <description><![CDATA[Qilin became a top ransomware operator in 2024-2025 by pairing edge-device exploitation with managed service provider compromise. Here is the supply chain breakdown.]]></description>
      <link>https://safeguard.sh/resources/blog/qilin-ransomware-supply-chain-tactics-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/qilin-ransomware-supply-chain-tactics-2025</guid>
      <pubDate>Sat, 11 Apr 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Risks of AI Coding Assistants]]></title>
      <description><![CDATA[Copilot, Cursor, and Claude Code change what enters your codebase and how. A practitioner's map of the real supply chain risks — hallucinated packages, rules-file injection, and unreviewed transitive trust.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-risks-of-ai-coding-assistants</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-risks-of-ai-coding-assistants</guid>
      <pubDate>Sat, 11 Apr 2026 08:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Bello)</author>
    </item>
    <item>
      <title><![CDATA[Can You Use Apache 2.0 and MIT Licensed Code Commercially?]]></title>
      <description><![CDATA[Yes, you can use Apache License 2.0 and MIT licensed code in commercial products. Here is exactly what each license requires from you, and where teams still get it wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-2-and-mit-license-commercial-use</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-2-and-mit-license-commercial-use</guid>
      <pubDate>Sat, 11 Apr 2026 07:56:21 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Maturity Models]]></title>
      <description><![CDATA[OWASP SAMM, BSIMM, and NIST SSDF explained: what maturity levels really measure, which framework fits your org, and why federal attestation rules now force the question.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-maturity-models</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-maturity-models</guid>
      <pubDate>Sat, 11 Apr 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to Avoid NullPointerException in Java]]></title>
      <description><![CDATA[The NullPointerException is Java's most common runtime crash. Here is how to avoid it with Optional, defensive coding, and the tools that catch nulls early.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-avoid-null-pointer-exception-in-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-avoid-null-pointer-exception-in-java</guid>
      <pubDate>Sat, 11 Apr 2026 06:35:54 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[DSPM for AI: navigating data and AI compliance regulations]]></title>
      <description><![CDATA[DSPM for AI closes the gap traditional tools miss: tracking sensitive data through embeddings, fine-tuning, and vector stores to meet EU AI Act and Colorado AI Act requirements.]]></description>
      <link>https://safeguard.sh/resources/blog/dspm-for-ai-navigating-data-and-ai-compliance-regulations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dspm-for-ai-navigating-data-and-ai-compliance-regulations</guid>
      <pubDate>Sat, 11 Apr 2026 06:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Injection Attack: How It Works and How to Stop It]]></title>
      <description><![CDATA[A JavaScript injection attack runs attacker-controlled script in a victim's browser or a Node.js process. Here is how the attack class works and the defenses that actually neutralize it.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-injection-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-injection-attack</guid>
      <pubDate>Sat, 11 Apr 2026 05:15:28 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Asset-First Application Security]]></title>
      <description><![CDATA[Vulnerability-first scanning drowns teams in noise. Asset-first application security starts with a complete inventory, then layers reachability and context to cut backlogs by 90%.]]></description>
      <link>https://safeguard.sh/resources/blog/asset-first-application-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/asset-first-application-security</guid>
      <pubDate>Sat, 11 Apr 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[VS Code Proxy Settings: How to Configure and Secure Them]]></title>
      <description><![CDATA[How to configure VS Code proxy settings for corporate networks, the difference between http.proxy and environment variables, and the security pitfalls to avoid.]]></description>
      <link>https://safeguard.sh/resources/blog/vs-code-proxy-settings</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vs-code-proxy-settings</guid>
      <pubDate>Sat, 11 Apr 2026 03:55:01 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[DSPM Market Size: 2026 guide]]></title>
      <description><![CDATA[DSPM spending is set to grow 25%+ annually through 2026. Here's how the market size breaks down, how Prisma Cloud fits in, and where supply chain security closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/dspm-market-size-2026-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dspm-market-size-2026-guide</guid>
      <pubDate>Sat, 11 Apr 2026 03:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[XXE Examples: Annotated Payloads and Fixes]]></title>
      <description><![CDATA[Concrete xxe examples showing how a malicious external entity reference reads local files or reaches internal services through an XML parser, and the config change that closes it.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-examples-annotated-payloads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-examples-annotated-payloads</guid>
      <pubDate>Sat, 11 Apr 2026 02:34:34 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Cloudflare R2 March 21, 2025 Outage: A Credential Rotation Postmortem]]></title>
      <description><![CDATA[A missing --env flag during a Wrangler secret rotation took R2 writes to zero for 67 minutes. Here is the failure mode and the deployment guardrails that should have caught it.]]></description>
      <link>https://safeguard.sh/resources/blog/cloudflare-r2-march-2025-credential-rotation-outage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloudflare-r2-march-2025-credential-rotation-outage</guid>
      <pubDate>Sat, 11 Apr 2026 01:14:08 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How to Measure Application Security Success: Metrics & KPIs]]></title>
      <description><![CDATA[Learn which AppSec metrics actually predict risk reduction — MTTR, vulnerability density, reachability, and false positive rate — with 2024-2025 benchmarks.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-measure-application-security-success-metrics-kpis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-measure-application-security-success-metrics-kpis</guid>
      <pubDate>Sat, 11 Apr 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[State of ASPM 2026: key trends and emerging threats]]></title>
      <description><![CDATA[ASPM went mandatory in 2026. Here's how supply chain attacks, AI-generated code, and Prisma Cloud's cloud-first architecture are reshaping what buyers actually need.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-aspm-2026-key-trends-and-emerging-threats</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-aspm-2026-key-trends-and-emerging-threats</guid>
      <pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Oracle Critical Control Baseline: Regulatory Impact]]></title>
      <description><![CDATA[Oracle's February 2025 Critical Control Baseline for critical infrastructure customers reshapes SCRM obligations. Here's what legal and security teams must know.]]></description>
      <link>https://safeguard.sh/resources/blog/oracle-ccb-regulatory-impact-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oracle-ccb-regulatory-impact-analysis</guid>
      <pubDate>Fri, 10 Apr 2026 23:53:41 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[uuid npm: Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[The uuid npm package is one of the most-installed libraries in the JavaScript ecosystem. Here is an honest look at its security posture and how to use it correctly.]]></description>
      <link>https://safeguard.sh/resources/blog/uuid-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uuid-npm</guid>
      <pubDate>Fri, 10 Apr 2026 22:33:14 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Java URL Encode: How to Encode URLs Safely Without Introducing Bugs]]></title>
      <description><![CDATA[The Java URL encode API is easy to reach for and easy to misuse. Here is when to use URLEncoder, when to use URI, and how the wrong choice becomes an injection risk.]]></description>
      <link>https://safeguard.sh/resources/blog/java-url-encode</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-url-encode</guid>
      <pubDate>Fri, 10 Apr 2026 21:12:48 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[OWASP API Top 10 2023: What Changed and How to Defend]]></title>
      <description><![CDATA[The OWASP API Security Top 10 2023 puts authorization failures at the top and adds new risks around business flows and API consumption. Here's the full list with defenses.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-api-top-10-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-api-top-10-2023</guid>
      <pubDate>Fri, 10 Apr 2026 19:52:21 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Chrome Zero-Day CVE-2025-2783: Sandbox Escape Used in Espionage Campaign]]></title>
      <description><![CDATA[Kaspersky discovered a Chrome zero-day being exploited in a targeted espionage campaign dubbed Operation ForumTroll. The flaw broke Chrome's sandbox with no user interaction beyond clicking a link.]]></description>
      <link>https://safeguard.sh/resources/blog/chrome-zero-day-cve-2025-2783-kaspersky</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chrome-zero-day-cve-2025-2783-kaspersky</guid>
      <pubDate>Fri, 10 Apr 2026 18:31:54 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Anthropic's Mythos Vulnerability Scanner: An Honest Assessment of Strengths, Weaknesses, and Reasons to Be Cautious]]></title>
      <description><![CDATA[Anthropic's Mythos model is generating buzz for AI-powered vulnerability detection. We break down what it does well, where it struggles, and why security teams should approach the results with healthy skepticism.]]></description>
      <link>https://safeguard.sh/resources/blog/anthropic-mythos-vulnerability-scanner-honest-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anthropic-mythos-vulnerability-scanner-honest-review</guid>
      <pubDate>Fri, 10 Apr 2026 18:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Snyk on Wikipedia: The Company, History, and What It Does]]></title>
      <description><![CDATA[A factual look at Snyk drawn from its Wikipedia entry and public record: who founded it, where it is based, what it builds, and how it fits into developer security.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-wikipedia</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-wikipedia</guid>
      <pubDate>Fri, 10 Apr 2026 17:11:27 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[aws-sdk-mock: Secure Testing and Migration to SDK v3]]></title>
      <description><![CDATA[aws-sdk-mock targets AWS SDK v2, which is now in maintenance mode. Here is how it works, where the security risk lives, and how to migrate to aws-sdk-client-mock for v3.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-sdk-mock</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-sdk-mock</guid>
      <pubDate>Fri, 10 Apr 2026 15:51:01 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Pervasive AI Security: Protecting AI That Is Everywhere in Your Stack]]></title>
      <description><![CDATA[Pervasive AI means models embedded in nearly every application and workflow. That ubiquity creates a security surface most programs have not mapped. Here is how to think about it.]]></description>
      <link>https://safeguard.sh/resources/blog/pervasive-ai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pervasive-ai</guid>
      <pubDate>Fri, 10 Apr 2026 15:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[The Limits of Single-Model Vulnerability Scanning: A Technical Analysis of the Mythos Approach]]></title>
      <description><![CDATA[Anthropic's Mythos model claims to find vulnerabilities in open-source code using a single LLM. We analyze where this approach falls short and why production-grade zero-day discovery requires Safeguard's Multi-Agent TAOR Deep Think AI Engine.]]></description>
      <link>https://safeguard.sh/resources/blog/single-model-vulnerability-scanning-limitations-mythos-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/single-model-vulnerability-scanning-limitations-mythos-analysis</guid>
      <pubDate>Fri, 10 Apr 2026 15:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[An OWASP-Aligned Secure Code Review Checklist]]></title>
      <description><![CDATA[OWASP's secure code review guidance gives structure to what could otherwise be an unfocused read-through — here's a practical checklist built around it.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-secure-code-review-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-secure-code-review-checklist</guid>
      <pubDate>Fri, 10 Apr 2026 14:30:34 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Vetting React Native npm Packages: pager-view, paper, video, config]]></title>
      <description><![CDATA[Before you add react-native-pager-view npm installs to a mobile app, run the same vetting you would for backend code. Here is a practical checklist using four popular packages as case studies.]]></description>
      <link>https://safeguard.sh/resources/blog/vetting-react-native-npm-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vetting-react-native-npm-packages</guid>
      <pubDate>Fri, 10 Apr 2026 13:10:07 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Cloudflare Workers Build Attestations: A Defender's Field Guide]]></title>
      <description><![CDATA[Workers Builds emits provenance attestations for the code it deploys. We trace how to verify them, gate on them, and integrate them into a multi-cloud supply chain program.]]></description>
      <link>https://safeguard.sh/resources/blog/cloudflare-workers-build-attestations-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloudflare-workers-build-attestations-2026</guid>
      <pubDate>Fri, 10 Apr 2026 12:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[API Surface Reviewed: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Most platform comparisons stop at features. The API surface is where automation and integration actually happen — and where vendors quietly diverge.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-api-surface-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-api-surface-review</guid>
      <pubDate>Fri, 10 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Why LLM-Based Vulnerability Scanning Needs More Than a Single Model]]></title>
      <description><![CDATA[Large language models are being used to find vulnerabilities in open-source code. But a single model, no matter how capable, isn't enough. Here's why multi-agent orchestration, structured CWE analysis, and deep context matter more than model size.]]></description>
      <link>https://safeguard.sh/resources/blog/why-llm-vulnerability-scanning-needs-more-than-a-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-llm-vulnerability-scanning-needs-more-than-a-model</guid>
      <pubDate>Fri, 10 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Next.js Middleware Authorization Bypass: CVE-2025-29927]]></title>
      <description><![CDATA[A critical flaw in Next.js allowed attackers to bypass middleware-based authorization by setting a single HTTP header. Applications relying on middleware for auth checks were completely exposed.]]></description>
      <link>https://safeguard.sh/resources/blog/next-js-middleware-cve-2025-29927</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/next-js-middleware-cve-2025-29927</guid>
      <pubDate>Fri, 10 Apr 2026 11:49:41 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Scattered Spider 2025: How the Most Dangerous Social Engineering Group Evolved]]></title>
      <description><![CDATA[Scattered Spider adapted its tactics in 2025, moving beyond casino hacks to target retail, healthcare, and manufacturing with increasingly sophisticated social engineering.]]></description>
      <link>https://safeguard.sh/resources/blog/scattered-spider-2025-evolution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scattered-spider-2025-evolution</guid>
      <pubDate>Fri, 10 Apr 2026 10:29:14 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[The EU Cyber Resilience Act Explained for Software Vendors]]></title>
      <description><![CDATA[What the EU CRA actually requires from software vendors — SBOMs, vulnerability handling, CE marking, timelines through 2027, and penalties up to EUR 15M.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cyber-resilience-act-explained-for-software-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cyber-resilience-act-explained-for-software-vendors</guid>
      <pubDate>Fri, 10 Apr 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SAST vs DAST: A 2026 Buyer's Decision Guide]]></title>
      <description><![CDATA[When SAST beats DAST, when DAST beats SAST, and when you actually need both. A 2026 buyer's decision guide grounded in real program data.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-vs-dast-buyer-decision-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-vs-dast-buyer-decision-guide-2026</guid>
      <pubDate>Fri, 10 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Web Application Security Risks & Best Practices]]></title>
      <description><![CDATA[Web app flaws like MOVEit and Log4Shell keep causing breaches. Here's what's actually exploitable in 2026, and how to fix it before attackers do.]]></description>
      <link>https://safeguard.sh/resources/blog/web-application-security-risks-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-application-security-risks-best-practices</guid>
      <pubDate>Fri, 10 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[pdfmake npm: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[pdfmake is a popular client and server PDF generator, but its dependency chain and server-side usage carry real risks. Here is a practical security review.]]></description>
      <link>https://safeguard.sh/resources/blog/pdfmake-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pdfmake-npm</guid>
      <pubDate>Fri, 10 Apr 2026 09:08:47 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[ASPM best practices for enhancing security posture]]></title>
      <description><![CDATA[ASPM best practices for correlating findings, prioritizing by reachability, and automating remediation — with a concrete look at how Prisma Cloud's approach compares.]]></description>
      <link>https://safeguard.sh/resources/blog/aspm-best-practices-for-enhancing-security-posture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aspm-best-practices-for-enhancing-security-posture</guid>
      <pubDate>Fri, 10 Apr 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Launching Zero-Day Discovery: How Safeguard's Multi-Agent TAOR Deep Think AI Engine Finds Vulnerabilities Before Anyone Else]]></title>
      <description><![CDATA[Safeguard launches its Zero-Day Discovery Engine, powered by the Multi-Agent TAOR Deep Think AI Engine — a multi-lead, multi-sub-agent architecture that performs deep CWE analysis on open-source packages to uncover vulnerabilities that traditional scanners miss.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-zero-day-discovery-taor-architecture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-zero-day-discovery-taor-architecture</guid>
      <pubDate>Fri, 10 Apr 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Code Quality Scan: What It Catches and Where It Stops]]></title>
      <description><![CDATA[A code quality scan flags maintainability and reliability issues in your source, but it is not a security scan. Here is what each type finds and how to run both without noise.]]></description>
      <link>https://safeguard.sh/resources/blog/code-quality-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-quality-scan</guid>
      <pubDate>Fri, 10 Apr 2026 07:48:21 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Mobile Application Security: Risks & Tools]]></title>
      <description><![CDATA[BLASTPASS, XcodeGhost, and a 2024 OWASP supply-chain category show mobile app security is its own attack surface — here's what to fix first, and with what tools.]]></description>
      <link>https://safeguard.sh/resources/blog/mobile-application-security-risks-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mobile-application-security-risks-tools</guid>
      <pubDate>Fri, 10 Apr 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[spring-data-commons: A Security Guide]]></title>
      <description><![CDATA[spring-data-commons underpins Spring Data's repository model, and one of its most infamous flaws - CVE-2018-1273 - turned property binding into remote code execution. Here is what to know.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-data-commons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-data-commons</guid>
      <pubDate>Fri, 10 Apr 2026 06:27:54 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[ASPM in action: real-world use cases]]></title>
      <description><![CDATA[ASPM use cases from alert fatigue to the XZ Utils backdoor and PCI DSS 4.0 deadlines — what Prisma Cloud's cloud-native approach misses and how code-first ASPM closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/aspm-in-action-real-world-use-cases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aspm-in-action-real-world-use-cases</guid>
      <pubDate>Fri, 10 Apr 2026 06:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[PHP 7.3 to 7.4 Version Vulnerabilities: A Security Changelog]]></title>
      <description><![CDATA[PHP 7.4 vulnerabilities span years of unsupported point releases; here is what changed security-wise across the 7.3 and 7.4 lines and why staying on either branch today is a standing risk.]]></description>
      <link>https://safeguard.sh/resources/blog/php-version-vulnerabilities-7-3-to-7-4-security-changelog</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-version-vulnerabilities-7-3-to-7-4-security-changelog</guid>
      <pubDate>Fri, 10 Apr 2026 05:07:27 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Top 10 Application Security Acronyms (Glossary)]]></title>
      <description><![CDATA[SAST, DAST, SBOM, CVSS, CWE, SSDF — 10 AppSec acronyms defined with real CVEs, dates, and standards so you use them correctly, not interchangeably.]]></description>
      <link>https://safeguard.sh/resources/blog/top-10-application-security-acronyms-glossary</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-10-application-security-acronyms-glossary</guid>
      <pubDate>Fri, 10 Apr 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Where Is Java Installed? Finding Your JDK (Including Homebrew)]]></title>
      <description><![CDATA[Where is Java on your machine? Between system installs, Homebrew, and version managers you can easily run a JDK you didn't mean to. Here is how to find every one — and why the answer is a security question.]]></description>
      <link>https://safeguard.sh/resources/blog/where-is-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/where-is-java</guid>
      <pubDate>Fri, 10 Apr 2026 03:47:01 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Overcoming AppSec chaos: modes of ASPM adoption]]></title>
      <description><![CDATA[ASPM adoption isn't one path. We break down point-tool, platform-consolidation (Prisma Cloud), and workflow-first modes — and why most stall after the pilot.]]></description>
      <link>https://safeguard.sh/resources/blog/overcoming-appsec-chaos-modes-of-aspm-adoption</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/overcoming-appsec-chaos-modes-of-aspm-adoption</guid>
      <pubDate>Fri, 10 Apr 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Install Python on macOS the Right Way]]></title>
      <description><![CDATA[The fastest safe way to install Python on macOS is Homebrew plus a version manager, not the system Python. Here is the setup that keeps your machine and your dependencies clean.]]></description>
      <link>https://safeguard.sh/resources/blog/install-python-macos</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/install-python-macos</guid>
      <pubDate>Fri, 10 Apr 2026 02:26:34 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How a Jenkins Scanner Catches Vulnerabilities in Your Pipeline]]></title>
      <description><![CDATA[A Jenkins scanner is any security tool wired into a Jenkins job to inspect code, dependencies, or containers before they ship. Here is how to pick one and run it well.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-scanner</guid>
      <pubDate>Fri, 10 Apr 2026 01:06:07 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What is an Application Vulnerability]]></title>
      <description><![CDATA[A flaw in code, config, or a dependency that attackers can exploit. Learn the types, scoring, and how vulnerabilities differ from risk and threats.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-an-application-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-an-application-vulnerability</guid>
      <pubDate>Fri, 10 Apr 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Developer infrastructure posture: integrating ASPM early]]></title>
      <description><![CDATA[Prisma Cloud built ASPM outward from the cloud. Real breaches like tj-actions and SolarWinds start earlier, in developer infrastructure that needs its own continuous posture model.]]></description>
      <link>https://safeguard.sh/resources/blog/developer-infrastructure-posture-integrating-aspm-early</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/developer-infrastructure-posture-integrating-aspm-early</guid>
      <pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[EU AI Act Enforcement Begins: 2026 Reality Check]]></title>
      <description><![CDATA[A 2026 reality check on EU AI Act enforcement: which obligations are active, what regulators expect, and the technical evidence enterprises must produce.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-ai-act-enforcement-begins-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-ai-act-enforcement-begins-2026</guid>
      <pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA["The Code Is Correct!" and Other Myths That Hide Security Bugs]]></title>
      <description><![CDATA[Passing tests and a clean review tell you the code is correct, but correctness and security are not the same thing. Here is where the gap lives.]]></description>
      <link>https://safeguard.sh/resources/blog/the-code-is-correct</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-code-is-correct</guid>
      <pubDate>Thu, 09 Apr 2026 23:45:40 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[SLSA in Canada: A Practical Supply Chain Security Guide]]></title>
      <description><![CDATA[How Canadian teams can adopt SLSA to harden build pipelines, prove provenance, and align with federal and provincial procurement expectations.]]></description>
      <link>https://safeguard.sh/resources/blog/slsa-canada</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slsa-canada</guid>
      <pubDate>Thu, 09 Apr 2026 22:25:14 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Was ServiceNow Hacked? What the Data Exposure Incidents Actually Mean]]></title>
      <description><![CDATA[The phrase 'ServiceNow hacked' usually points to misconfiguration and unauthenticated API access, not a core platform breach. Here is what happened and how to protect your instance.]]></description>
      <link>https://safeguard.sh/resources/blog/servicenow-hacked</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/servicenow-hacked</guid>
      <pubDate>Thu, 09 Apr 2026 21:04:47 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Sentry React: A Security Guide]]></title>
      <description><![CDATA[Sentry React gives you error and performance monitoring for React apps, but the SDK also collects data that can leak secrets if you misconfigure it. Here is how to run it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/sentry-react</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sentry-react</guid>
      <pubDate>Thu, 09 Apr 2026 19:44:20 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is react-server-dom-webpack? A Security Guide]]></title>
      <description><![CDATA[react-server-dom-webpack is the low-level React Server Components binding meta-frameworks build on. Here is what it does and where the security risks actually live.]]></description>
      <link>https://safeguard.sh/resources/blog/react-server-dom-webpack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-server-dom-webpack</guid>
      <pubDate>Thu, 09 Apr 2026 18:23:54 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[react-select-async-paginate: A Security Guide]]></title>
      <description><![CDATA[react-select-async-paginate is a thin wrapper over react-select that loads dropdown options page by page. Here is how to use it without inheriting supply chain or data-handling risk.]]></description>
      <link>https://safeguard.sh/resources/blog/react-select-async-paginate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-select-async-paginate</guid>
      <pubDate>Thu, 09 Apr 2026 17:03:27 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Pickling in Python: A Security Guide]]></title>
      <description><![CDATA[Pickling in Python serializes objects to bytes, but unpickling untrusted data can run arbitrary code. Here is how the risk works and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/pickling-in-python</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pickling-in-python</guid>
      <pubDate>Thu, 09 Apr 2026 15:43:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[log4j Remediation: How to Fully Patch Log4Shell]]></title>
      <description><![CDATA[A practical log4j remediation walkthrough: which versions actually fix Log4Shell, how to find the library transitively, and what to do when you cannot upgrade yet.]]></description>
      <link>https://safeguard.sh/resources/blog/log4j-remediation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4j-remediation</guid>
      <pubDate>Thu, 09 Apr 2026 14:22:34 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to Use Python on Mac: Install, Switch Versions, and Set a Default]]></title>
      <description><![CDATA[Learning how to use Python on Mac starts with not touching the system Python. Here is a clean setup for installing, switching, and pinning versions.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-use-python-on-mac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-use-python-on-mac</guid>
      <pubDate>Thu, 09 Apr 2026 13:02:07 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Azure DevOps Pipeline Supply Chain Controls]]></title>
      <description><![CDATA[Azure DevOps pipelines hold more production deploy power than any other system in many enterprises. The 2026 supply chain controls are not optional anymore.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-devops-pipeline-supply-chain-controls-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-devops-pipeline-supply-chain-controls-2026</guid>
      <pubDate>Thu, 09 Apr 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE Fatigue: How To Stop Drowning Engineers]]></title>
      <description><![CDATA[CVE fatigue is a productivity tax disguised as a security control. Here is how reachability filtering, auto-PRs, and AI triage restore engineering focus.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-fatigue-how-to-stop-drowning-engineers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-fatigue-how-to-stop-drowning-engineers</guid>
      <pubDate>Thu, 09 Apr 2026 12:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[DIB Small Shop CMMC Readiness On A Budget]]></title>
      <description><![CDATA[Small defense industrial base shops cannot spend like primes. Here is a pragmatic CMMC Level 2 readiness path that fits a real small business budget.]]></description>
      <link>https://safeguard.sh/resources/blog/dib-small-shop-cmmc-readiness-on-a-budget</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dib-small-shop-cmmc-readiness-on-a-budget</guid>
      <pubDate>Thu, 09 Apr 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[npm Account Takeover Pattern Evolution]]></title>
      <description><![CDATA[npm account takeovers have shifted from opportunistic phishing to coordinated, multi-stage operations. We trace the 2025 to 2026 evolution and what it means for maintainers.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-account-takeover-pattern-evolution-2025-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-account-takeover-pattern-evolution-2025-2026</guid>
      <pubDate>Thu, 09 Apr 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Phased Policy Rollout: Warn To Block In Six Weeks]]></title>
      <description><![CDATA[Hard-blocking a new policy on day one breaks builds and trust. A phased rollout from warn to block earns the right to enforce by proving the policy is correct first.]]></description>
      <link>https://safeguard.sh/resources/blog/phased-rollout-policy-enforcement-warn-to-block</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/phased-rollout-policy-enforcement-warn-to-block</guid>
      <pubDate>Thu, 09 Apr 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Zero-Day Discovery In Your Dependency Graph]]></title>
      <description><![CDATA[Most zero-days that hurt enterprises in 2026 live three or four hops deep in the dependency graph. Here is what it takes to actually find them there.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-day-discovery-in-your-dependency-graph-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-day-discovery-in-your-dependency-graph-2026</guid>
      <pubDate>Thu, 09 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Secure Code Training for Developers: What Actually Changes Behavior]]></title>
      <description><![CDATA[Secure code training for developers works when it is contextual, hands-on, and tied to the code they ship this week, not an annual slideshow. Here is how to build a program that sticks.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-code-training-for-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-code-training-for-developers</guid>
      <pubDate>Thu, 09 Apr 2026 11:45:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Pull and Secure a Node Image from Docker Hub]]></title>
      <description><![CDATA[The official Docker Hub node image ships in several variants that differ wildly in size and CVE count. Here is how to pick one and lock it down.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-hub-node</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-hub-node</guid>
      <pubDate>Thu, 09 Apr 2026 11:41:40 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Can AI Solve CAPTCHA? What the Research Actually Shows]]></title>
      <description><![CDATA[Can AI solve CAPTCHA challenges? For most classic image and text puzzles, yes, and it has real consequences for how you defend against bots.]]></description>
      <link>https://safeguard.sh/resources/blog/can-ai-solve-captcha</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/can-ai-solve-captcha</guid>
      <pubDate>Thu, 09 Apr 2026 11:40:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[AI Data Quality: Why It Matters for Model Security]]></title>
      <description><![CDATA[Poor AI data quality is not just an accuracy problem — it's an attack surface. Here's how data integrity, provenance, and validation shape the security of the models you ship.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-data-quality</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-data-quality</guid>
      <pubDate>Thu, 09 Apr 2026 11:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Container Malware Scanning: Finding Threats in Your Images]]></title>
      <description><![CDATA[Container malware scanning inspects image layers for malicious binaries, backdoors, and tampered dependencies before they ever run in your cluster.]]></description>
      <link>https://safeguard.sh/resources/blog/container-malware-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-malware-scanning</guid>
      <pubDate>Thu, 09 Apr 2026 11:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Top 10 for LLM Applications, Explained]]></title>
      <description><![CDATA[A practitioner's walkthrough of the OWASP Top 10 for LLM Applications: what each risk looks like in a real system, which ones bite first, and the mitigations that hold up.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-llm-applications-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-llm-applications-explained</guid>
      <pubDate>Thu, 09 Apr 2026 11:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What a Dependency Scanner Does and Which One to Pick]]></title>
      <description><![CDATA[A dependency scanner reads your lockfiles, resolves the full dependency tree, and matches every package against known vulnerability data. Here is how that works and what separates a good one from a noisy one.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-scanner</guid>
      <pubDate>Thu, 09 Apr 2026 10:21:14 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Security Software Companies: How to Evaluate a Vendor Shortlist]]></title>
      <description><![CDATA[A practical framework for scoring security software companies on coverage, integration depth, and total cost before you sign a multi-year contract.]]></description>
      <link>https://safeguard.sh/resources/blog/security-software-companies-how-to-evaluate-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-software-companies-how-to-evaluate-vendors</guid>
      <pubDate>Thu, 09 Apr 2026 10:00:00 GMT</pubDate>
      <category>Enterprise</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Security Control?]]></title>
      <description><![CDATA[A security control is a safeguard that prevents, detects, or responds to threats to reduce risk. Learn the types, categories, and how frameworks organize them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-security-control</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-security-control</guid>
      <pubDate>Thu, 09 Apr 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What is Attack Surface Management]]></title>
      <description><![CDATA[Attack surface management explained: what it covers, how it differs from vulnerability management, and why CISA and Gartner now treat it as core AppSec.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-attack-surface-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-attack-surface-management</guid>
      <pubDate>Thu, 09 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[cdxgen v12: Reachability Evidence Lands in SBOMs]]></title>
      <description><![CDATA[OWASP's cdxgen v12 ships reachability evidence powered by atom, multi-BOM generation (SBOM, CBOM, SaaSBOM, OBOM, CDXA), and CycloneDX 1.7 as the default. We tested it on a Java monorepo.]]></description>
      <link>https://safeguard.sh/resources/blog/cdxgen-v12-reachability-evidence-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cdxgen-v12-reachability-evidence-2026</guid>
      <pubDate>Thu, 09 Apr 2026 09:30:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Container Vulnerability Scanner Buyer Guide 2026]]></title>
      <description><![CDATA[A practical 2026 buyer guide for container vulnerability scanners: detection accuracy, reachability, signed advisories, runtime correlation, and the questions that separate vendors.]]></description>
      <link>https://safeguard.sh/resources/blog/container-vulnerability-scanner-buyer-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-vulnerability-scanner-buyer-guide-2026</guid>
      <pubDate>Thu, 09 Apr 2026 09:30:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How to Change the Java Version on a Mac Without Breaking Security]]></title>
      <description><![CDATA[A practical guide to change the Java version on Mac using JAVA_HOME and jenv, plus why keeping the right JDK active is a security decision, not just a convenience.]]></description>
      <link>https://safeguard.sh/resources/blog/change-java-version-mac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/change-java-version-mac</guid>
      <pubDate>Thu, 09 Apr 2026 09:00:47 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Claude Code and AI Coding Agent Security Basics]]></title>
      <description><![CDATA[Anthropic Claude Code security rests on permission gating, sandboxed execution, and human approval for risky actions — the same fundamentals any AI coding agent needs before it's allowed to run commands or edit code unattended.]]></description>
      <link>https://safeguard.sh/resources/blog/claude-code-and-ai-coding-agent-security-basics</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/claude-code-and-ai-coding-agent-security-basics</guid>
      <pubDate>Thu, 09 Apr 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Running DAST, SAST, and SCA in One Pipeline]]></title>
      <description><![CDATA[Running sast dast sca as three separate checkpoints instead of one correlated pipeline is why most security backlogs are full of duplicate, unprioritized noise.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-sast-and-sca-in-one-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-sast-and-sca-in-one-pipeline</guid>
      <pubDate>Thu, 09 Apr 2026 09:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes and Infrastructure as Code security]]></title>
      <description><![CDATA[Prisma Cloud pioneered infrastructure as code security scanning for Kubernetes, but alert fatigue and weak commit-level traceability leave real gaps. Here's how to close them.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-and-infrastructure-as-code-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-and-infrastructure-as-code-security</guid>
      <pubDate>Thu, 09 Apr 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Defense Software Supply Chain Under the 2026 Federal Rules]]></title>
      <description><![CDATA[CMMC 2.0, the FAR SBOM rule, and DoD Instruction 8500.01 have reshaped what software contractors must deliver. Here is the 2026 operational baseline for defense industrial base suppliers.]]></description>
      <link>https://safeguard.sh/resources/blog/defense-software-supply-chain-fed-rules-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/defense-software-supply-chain-fed-rules-2026</guid>
      <pubDate>Thu, 09 Apr 2026 08:45:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Ignoring Docker Registry Certificates: A Security Anti-Pattern]]></title>
      <description><![CDATA[Telling Docker to ignore certificate errors fixes the immediate pull failure but quietly disables the check that confirms you're actually talking to your registry and not an attacker.]]></description>
      <link>https://safeguard.sh/resources/blog/ignoring-docker-registry-certificates-a-security-anti-pattern</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ignoring-docker-registry-certificates-a-security-anti-pattern</guid>
      <pubDate>Thu, 09 Apr 2026 08:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing AWS Infrastructure as Code: A Practical Guide]]></title>
      <description><![CDATA[AWS infrastructure as code turns your cloud into version-controlled files, which means security review can shift left into the same pull request that provisions the resource.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-infrastructure-as-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-infrastructure-as-code</guid>
      <pubDate>Thu, 09 Apr 2026 07:40:20 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What is an Attack Surface]]></title>
      <description><![CDATA[An attack surface is every exposed point attackers can use to get in — code, configs, credentials, and dependencies. Here's how to define, measure, and shrink it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-an-attack-surface</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-an-attack-surface</guid>
      <pubDate>Thu, 09 Apr 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[@angular-eslint/builder: What It Is and How to Use It Safely]]></title>
      <description><![CDATA[The @angular-eslint/builder package wires ESLint into the Angular CLI so you can run ng lint. Here's how it fits your build and where the supply-chain risk actually lives.]]></description>
      <link>https://safeguard.sh/resources/blog/angular-eslint-builder</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/angular-eslint-builder</guid>
      <pubDate>Thu, 09 Apr 2026 06:19:53 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What Is the CI/CD Pipeline (and CI/CD security)?]]></title>
      <description><![CDATA[CI/CD pipelines now hold more privileged access than any other system — yet they're the least monitored. Here's what CI/CD pipeline security really requires.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-cicd-pipeline-and-cicd-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-cicd-pipeline-and-cicd-security</guid>
      <pubDate>Thu, 09 Apr 2026 06:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Confidential Computing in Supply Chain Integration]]></title>
      <description><![CDATA[How Intel TDX, AMD SEV-SNP, and AWS Nitro enclaves plug into build and signing pipelines, with attestation flows and operational tradeoffs.]]></description>
      <link>https://safeguard.sh/resources/blog/confidential-computing-supply-chain-integration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/confidential-computing-supply-chain-integration</guid>
      <pubDate>Thu, 09 Apr 2026 04:59:27 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is a Zero-Day Vulnerability]]></title>
      <description><![CDATA[A zero-day vulnerability is exploited before a patch exists. See real cases like Log4Shell and MOVEit, and how to cut response time.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-zero-day-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-zero-day-vulnerability</guid>
      <pubDate>Thu, 09 Apr 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Apache v2: What the Apache License 2.0 Actually Requires]]></title>
      <description><![CDATA[A plain-English guide to Apache v2 — what the Apache License 2.0 permits, the obligations it puts on you, its patent grant, and how it affects your open-source compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-v2</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-v2</guid>
      <pubDate>Thu, 09 Apr 2026 03:39:00 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How to secure Kubernetes secrets and sensitive data]]></title>
      <description><![CDATA[Kubernetes secrets are base64, not encrypted, by default. Here's how they actually leak, where Prisma Cloud's CNAPP approach falls short, and how to fix rotation, RBAC, and encryption gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-secure-kubernetes-secrets-and-sensitive-data</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-secure-kubernetes-secrets-and-sensitive-data</guid>
      <pubDate>Thu, 09 Apr 2026 03:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What Is a DAST Assessment? A Practical Security Guide]]></title>
      <description><![CDATA[A DAST assessment tests a running application from the outside to find exploitable flaws. Here is how it works, what it catches, and where it fits alongside SAST and SCA.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-assessment</guid>
      <pubDate>Thu, 09 Apr 2026 02:18:33 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is a CVE (Common Vulnerabilities and Exposures)]]></title>
      <description><![CDATA[A CVE is a unique ID for a known security flaw, but how it's assigned, scored, and disclosed is far messier than the name suggests.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-cve-common-vulnerabilities-and-exposures</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-cve-common-vulnerabilities-and-exposures</guid>
      <pubDate>Thu, 09 Apr 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx Login: SSO, SAML, and Secure Access Explained]]></title>
      <description><![CDATA[How the Checkmarx login works across the web console and IDE plugins, why SAML single sign-on is the right default, and how to keep access secure.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-login</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-login</guid>
      <pubDate>Thu, 09 Apr 2026 00:58:07 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Open Source vs Commercial Security Scanners 2026]]></title>
      <description><![CDATA[When to use Trivy, Grype, and OSV-Scanner versus commercial scanners in 2026: honest tradeoffs, integration realities, and decision criteria.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-vs-commercial-security-scanners-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-vs-commercial-security-scanners-2026</guid>
      <pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Why EPSS scores matter for vulnerability management]]></title>
      <description><![CDATA[EPSS scores predict real-world exploitation probability, something CVSS can't do. Here's why that matters for Prisma Cloud users, and how Safeguard uses it.]]></description>
      <link>https://safeguard.sh/resources/blog/why-epss-scores-matter-for-vulnerability-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-epss-scores-matter-for-vulnerability-management</guid>
      <pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Meaning Explained]]></title>
      <description><![CDATA[The application security meaning boils down to protecting software from threats across its whole life: design, code, dependencies, and runtime. Here is what the term actually covers.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-meaning</guid>
      <pubDate>Wed, 08 Apr 2026 23:37:40 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CISA KEV Catalog in 2025: What the Data Tells Us About Real-World Exploitation]]></title>
      <description><![CDATA[The CISA Known Exploited Vulnerabilities catalog has become the definitive list of actively exploited flaws. An analysis of 2025 KEV trends reveals which products, vulnerability types, and attack patterns dominate.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-known-exploited-vulnerabilities-2025-update</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-known-exploited-vulnerabilities-2025-update</guid>
      <pubDate>Wed, 08 Apr 2026 22:17:13 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Certificate Authority? The Root of Digital Trust]]></title>
      <description><![CDATA[A certificate authority is the trusted third party that vouches for who owns a public key. It is the reason your browser can trust a website it has never seen before.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-certificate-authority</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-certificate-authority</guid>
      <pubDate>Wed, 08 Apr 2026 20:56:47 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Define Hacking: What the Term Actually Means in Cybersecurity]]></title>
      <description><![CDATA[To define hacking accurately you have to separate the neutral original meaning from the security sense, and legal access from criminal access. Here is the clear version.]]></description>
      <link>https://safeguard.sh/resources/blog/define-hacking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/define-hacking</guid>
      <pubDate>Wed, 08 Apr 2026 19:36:20 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Web Vulnerability Scanning: How It Works and What It Finds]]></title>
      <description><![CDATA[A practitioner's guide to web vulnerability scanning: what scanners actually test, where they fall short, and how to fit them into a delivery pipeline without drowning in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/web-vulnerability-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-vulnerability-scanning</guid>
      <pubDate>Wed, 08 Apr 2026 18:15:53 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is the Synk Tool? A Practical Guide to Snyk for Developers]]></title>
      <description><![CDATA[People searching for the 'synk tool' almost always mean Snyk, the developer security platform. Here is what it does, how it is priced, and where it fits.]]></description>
      <link>https://safeguard.sh/resources/blog/synk-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/synk-tool</guid>
      <pubDate>Wed, 08 Apr 2026 16:55:26 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[spring-context: The Dependency at the Heart of Spring (and Its CVEs)]]></title>
      <description><![CDATA[spring-context is the artifact that gives you Spring's ApplicationContext, and it drags four more Spring modules into your build. Here is what it does, what it pulls in, and the CVEs that have hit it.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-context-maven-dependency-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-context-maven-dependency-guide</guid>
      <pubDate>Wed, 08 Apr 2026 15:35:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The Snyk Vulnerability Database: How It Works and Open Alternatives]]></title>
      <description><![CDATA[The Snyk vuln db is one of the most cited advisory sources in developer security. Where its data comes from, what's proprietary, and how OSV and GitHub's database compare.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vulnerability-database-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vulnerability-database-explained</guid>
      <pubDate>Wed, 08 Apr 2026 14:20:00 GMT</pubDate>
      <category>Industry</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Shift-Left Security Explained: Catching Vulnerabilities Before Production]]></title>
      <description><![CDATA[Shift-left security means moving vulnerability detection into design, coding, and CI instead of waiting for a pre-release pen test. Here is what that looks like in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/shiftleft-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shiftleft-security</guid>
      <pubDate>Wed, 08 Apr 2026 14:14:33 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Container Image Solutions: Building and Shipping Secure Images]]></title>
      <description><![CDATA[Container image solutions span how you build, store, scan, and sign images. Choosing them well is what turns a container pipeline into a secure supply chain rather than a liability.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-solutions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-solutions</guid>
      <pubDate>Wed, 08 Apr 2026 13:35:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[ESSCM Buyer Guide 2026]]></title>
      <description><![CDATA[An enterprise buyer's guide to End-to-End Software Supply Chain Management platforms in 2026, with the questions that separate marketing from working products.]]></description>
      <link>https://safeguard.sh/resources/blog/esscm-buyer-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/esscm-buyer-guide-2026</guid>
      <pubDate>Wed, 08 Apr 2026 13:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis for JavaScript and TypeScript in 2026]]></title>
      <description><![CDATA[JS reachability with npm's nested trees, dynamic require, ESM/CJS interop, and bundler dead code elimination. What modern tools resolve and what they punt.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-javascript-typescript-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-javascript-typescript-2026</guid>
      <pubDate>Wed, 08 Apr 2026 13:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Top 10 Vulnerabilities 2023: A Retrospective That Still Applies]]></title>
      <description><![CDATA[There was no new web OWASP Top 10 in 2023 — but the OWASP Top 10 vulnerabilities 2023 story is really about the 2021 web list holding firm and the API Security Top 10 getting a major refresh.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-2023-retrospective</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-2023-retrospective</guid>
      <pubDate>Wed, 08 Apr 2026 12:54:06 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Agentic AI Budget Explosions And Cost Controls]]></title>
      <description><![CDATA[Agent runaway is no longer a theoretical risk — it is a line item on quarterly variance reports. The 2026 trend in agentic AI is less about model capability and more about who pays when an agent loops.]]></description>
      <link>https://safeguard.sh/resources/blog/agentic-ai-budget-explosions-cost-controls-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agentic-ai-budget-explosions-cost-controls-2026</guid>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Secure by Design Pledge: Reading the 2026 Progress Reports]]></title>
      <description><![CDATA[More than 250 manufacturers have signed CISA's Secure by Design pledge. We read the public progress reports to see who is actually moving on the seven goals.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-secure-by-design-progress-report-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-secure-by-design-progress-report-2026</guid>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Continuous Vendor Monitoring vs Annual Review]]></title>
      <description><![CDATA[Annual vendor reviews discover problems eleven months too late. Continuous monitoring closes the gap, but only if your TPRM tooling can ingest and normalize signals at vendor scale.]]></description>
      <link>https://safeguard.sh/resources/blog/continuous-vendor-monitoring-vs-annual-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/continuous-vendor-monitoring-vs-annual-review</guid>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CrewAI Sandbox Escape: Four CVEs That Chain Through Prompt Injection]]></title>
      <description><![CDATA[Cyata disclosed four CrewAI vulnerabilities in early 2026 that chain through prompt injection to RCE, SSRF, and arbitrary file read. The Docker-fallback design pattern is the root cause.]]></description>
      <link>https://safeguard.sh/resources/blog/crewai-sandbox-escape-cve-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crewai-sandbox-escape-cve-chain-2026</guid>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Discovering Shadow AI Models In Production]]></title>
      <description><![CDATA[Engineers ship models faster than security can track them. Here is how to find shadow AI in production without slowing the teams that build it.]]></description>
      <link>https://safeguard.sh/resources/blog/discovering-shadow-ai-models-in-production-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/discovering-shadow-ai-models-in-production-2026</guid>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise MCP Registry Onboarding Process]]></title>
      <description><![CDATA[A repeatable onboarding flow for adding MCP servers to an enterprise registry without becoming the team that says no to everything.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-mcp-registry-onboarding-process</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-mcp-registry-onboarding-process</guid>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[IDE-Time Feedback Loop For Supply Chain]]></title>
      <description><![CDATA[The editor is the highest-leverage place to catch supply chain risk. A design guide for building IDE-time feedback that developers actually want.]]></description>
      <link>https://safeguard.sh/resources/blog/ide-time-feedback-loop-design-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ide-time-feedback-loop-design-supply-chain</guid>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[LLM Traces and Evals: The Missing Layer in AI Supply Chain Security]]></title>
      <description><![CDATA[Prompt traces and offline evals are standard hygiene for ML teams, but almost nobody treats them as supply chain telemetry. They should be. Here's how traces and evals plug into SBOM and reachability as a fourth security signal.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-traces-and-evals-ai-supply-chain-signal</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-traces-and-evals-ai-supply-chain-signal</guid>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Payment Processor Supply Chain Resilience]]></title>
      <description><![CDATA[Payment processors run on borrowed dependencies. This is how to build a supply chain resilience program that keeps authorization rates intact during a crisis.]]></description>
      <link>https://safeguard.sh/resources/blog/payment-processor-supply-chain-resilience</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/payment-processor-supply-chain-resilience</guid>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Python Monorepo Supply Chain Controls 2026]]></title>
      <description><![CDATA[How to design supply chain controls for a Python monorepo in 2026 — from PyPI quarantine to wheel provenance — with Safeguard as the policy backbone.]]></description>
      <link>https://safeguard.sh/resources/blog/python-monorepo-supply-chain-controls-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-monorepo-supply-chain-controls-2026</guid>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Reachability Cuts Your Vulnerability Backlog 80%]]></title>
      <description><![CDATA[The 80% backlog reduction from reachability isn't marketing. It's a measurable property of how transitive dependency graphs actually expose risk to a specific application.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-cuts-vulnerability-backlog-80-percent</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-cuts-vulnerability-backlog-80-percent</guid>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CrowdStrike Cloud Security vs Wiz 2026]]></title>
      <description><![CDATA[CrowdStrike has invested aggressively in CNAPP capabilities through Falcon Cloud Security. Can the endpoint giant displace Wiz on cloud-native ground? A frank assessment.]]></description>
      <link>https://safeguard.sh/resources/blog/crowdstrike-cloud-vs-wiz-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crowdstrike-cloud-vs-wiz-2026</guid>
      <pubDate>Wed, 08 Apr 2026 11:45:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[npm Vulnerabilities: Detection, Triage, and Fix Workflow]]></title>
      <description><![CDATA[Known CVEs and hostile packages are two different problems that share one dependency tree. A workflow for detecting npm vulnerabilities, triaging by reachability, and fixing without breaking your lockfile.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-vulnerabilities-detection-triage-fix</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-vulnerabilities-detection-triage-fix</guid>
      <pubDate>Wed, 08 Apr 2026 11:33:40 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[A Security Baseline for AI Agent Tool Use in 2026]]></title>
      <description><![CDATA[Tool-using agents are now in production at most large organizations. The security baseline that should be table stakes, and what teams are still missing.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-agent-tool-use-security-baseline-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-agent-tool-use-security-baseline-2026</guid>
      <pubDate>Wed, 08 Apr 2026 11:15:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CircleCI Orb Trust and Pinning in 2026]]></title>
      <description><![CDATA[How to manage CircleCI orb trust in 2026: certified versus uncertified orbs, version pinning, contexts, OIDC, and the controls that hold under real attacker pressure.]]></description>
      <link>https://safeguard.sh/resources/blog/circleci-orb-trust-and-pinning-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/circleci-orb-trust-and-pinning-2026</guid>
      <pubDate>Wed, 08 Apr 2026 10:30:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[NIS2 Directive Supply Chain Obligations in 2026]]></title>
      <description><![CDATA[NIS2 has been in force across the EU since October 2024, and member state enforcement is now operating in earnest. The supply chain obligations are the ones most organizations underestimated.]]></description>
      <link>https://safeguard.sh/resources/blog/nis2-directive-supply-chain-obligations-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nis2-directive-supply-chain-obligations-2026</guid>
      <pubDate>Wed, 08 Apr 2026 10:30:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Nodemailer npm: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[Nodemailer is the default way to send email from Node.js. It is well maintained, but email is a classic injection surface. Here is a security review and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/nodemailer-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodemailer-npm</guid>
      <pubDate>Wed, 08 Apr 2026 10:30:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Twistlock vs JFrog Xray: A 2026 Comparison]]></title>
      <description><![CDATA[Comparing Prisma Cloud Compute (Twistlock) and JFrog Xray in 2026 across container scanning, runtime protection, policy depth, and where each tool genuinely earns its license.]]></description>
      <link>https://safeguard.sh/resources/blog/twistlock-vs-jfrog-xray-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/twistlock-vs-jfrog-xray-2026</guid>
      <pubDate>Wed, 08 Apr 2026 10:15:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Is npm body-parser Safe? A Security Review and Safe-Usage Guide]]></title>
      <description><![CDATA[A practical look at npm body-parser, the CVE-2024-45590 denial-of-service issue, and how to configure the middleware so it does not become a liability in production.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-body-parser</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-body-parser</guid>
      <pubDate>Wed, 08 Apr 2026 10:13:13 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Cisco Firepower CVE-2024-20418 Lessons: Network Security Devices as Attack Surface]]></title>
      <description><![CDATA[CVE-2024-20418 was a critical command injection in Cisco Firepower Management Center. The technical details, the exploitation reality, and what it teaches about NSM security.]]></description>
      <link>https://safeguard.sh/resources/blog/cisco-firepower-cve-2024-20418-rce-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisco-firepower-cve-2024-20418-rce-lessons</guid>
      <pubDate>Wed, 08 Apr 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis vs. SCA: Which Reduces Your Backlog?]]></title>
      <description><![CDATA[SCA lists every CVE in every dependency. Reachability filters to the ones your code actually invokes. Here is how the two compare on a real backlog.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-vs-sca-vulnerability-backlog</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-vs-sca-vulnerability-backlog</guid>
      <pubDate>Wed, 08 Apr 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Sigstore Policy Controller v0.15: TUF Delegation and Admission Posture]]></title>
      <description><![CDATA[Policy Controller v0.15 ships sigstore-go's delegation-aware TUF client, a monthly cadence, and tighter integration with cosign 3.x. We benchmarked admission on a 400-node cluster.]]></description>
      <link>https://safeguard.sh/resources/blog/sigstore-policy-controller-v0-15-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sigstore-policy-controller-v0-15-2026</guid>
      <pubDate>Wed, 08 Apr 2026 10:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Trivy vs Grype: A Buyer Comparison for 2026]]></title>
      <description><![CDATA[How Trivy 0.58 and Grype 0.85 compare in real-world container scanning: vulnerability coverage, false positive rates, SBOM support, and operational fit.]]></description>
      <link>https://safeguard.sh/resources/blog/trivy-vs-grype-buyer-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trivy-vs-grype-buyer-comparison-2026</guid>
      <pubDate>Wed, 08 Apr 2026 10:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Vanta vs Drata vs Built-In GRC: Where Compliance Should Live]]></title>
      <description><![CDATA[The two compliance automation leaders are closer than their sales decks admit. The bigger question is whether compliance should live in a standalone tool at all.]]></description>
      <link>https://safeguard.sh/resources/blog/vanta-vs-drata-vs-built-in-grc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vanta-vs-drata-vs-built-in-grc</guid>
      <pubDate>Wed, 08 Apr 2026 10:00:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Docker + MCP: Running MCP Servers in Containers Securely]]></title>
      <description><![CDATA[MCP servers run with your credentials and your filesystem unless you say otherwise. Containerizing them with read-only mounts, dropped capabilities, and egress controls turns an open-ended trust grant into a bounded one.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-mcp-running-mcp-servers-securely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-mcp-running-mcp-servers-securely</guid>
      <pubDate>Wed, 08 Apr 2026 09:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Application Security: a practitioner's guide]]></title>
      <description><![CDATA[A practitioner's guide to application security: SAST, SCA, secrets, and supply chain integrity—plus how Safeguard compares to Prisma Cloud's CNAPP.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-a-practitioners-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-a-practitioners-guide</guid>
      <pubDate>Wed, 08 Apr 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Threat Protection: A Framework]]></title>
      <description><![CDATA[Software supply chain threat protection means securing the build pipeline and dependency graph itself, not just the code you write — provenance, signing, and SBOMs are the load-bearing pieces.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-threat-protection-a-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-threat-protection-a-framework</guid>
      <pubDate>Wed, 08 Apr 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Node.js Backend? A Security Guide for Server-Side JavaScript]]></title>
      <description><![CDATA[A practical look at building a Node.js backend that holds up in production, from dependency risk to input validation, with real config you can copy.]]></description>
      <link>https://safeguard.sh/resources/blog/node-js-backend</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-js-backend</guid>
      <pubDate>Wed, 08 Apr 2026 08:52:46 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[k8s fsGroup: How Kubernetes Sets Volume Ownership Securely]]></title>
      <description><![CDATA[What k8s fsGroup actually does to volume permissions, why it can wreck pod start times, and how to configure it without opening a privilege gap.]]></description>
      <link>https://safeguard.sh/resources/blog/k8s-fsgroup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/k8s-fsgroup</guid>
      <pubDate>Wed, 08 Apr 2026 07:32:20 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What is CVSS (Common Vulnerability Scoring System)]]></title>
      <description><![CDATA[CVSS scores rate vulnerability severity from 0.0 to 10.0 — but a 9.8 doesn't mean exploitable in your app. Here's how the math and priorities really work.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-cvss-common-vulnerability-scoring-system</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-cvss-common-vulnerability-scoring-system</guid>
      <pubDate>Wed, 08 Apr 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[jQuery 3.6.0 Vulnerabilities: What Scanners Flag and How to Fix]]></title>
      <description><![CDATA[jQuery v3.6.0 vulnerabilities show up in scan reports constantly, yet the core library has no CVE of its own at that version. Here is what your scanner is actually reacting to and how to clear it.]]></description>
      <link>https://safeguard.sh/resources/blog/jquery-3-6-0-vulnerabilities-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jquery-3-6-0-vulnerabilities-guide</guid>
      <pubDate>Wed, 08 Apr 2026 06:11:53 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Top cloud data security solutions]]></title>
      <description><![CDATA[Prisma Cloud's DSPM bolts data classification onto a 30-module CNAPP after resources already exist in the cloud. Here's why that misses the supply chain risks that matter most.]]></description>
      <link>https://safeguard.sh/resources/blog/top-cloud-data-security-solutions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-cloud-data-security-solutions</guid>
      <pubDate>Wed, 08 Apr 2026 06:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[FileSaver.js (file-saver): Package Review and Download Security]]></title>
      <description><![CDATA[The file saver npm package still powers client-side downloads in millions of builds, but it has not shipped a release since 2020. Here is what that means for your dependency tree.]]></description>
      <link>https://safeguard.sh/resources/blog/file-saver-npm-package-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/file-saver-npm-package-review</guid>
      <pubDate>Wed, 08 Apr 2026 04:51:26 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is EPSS (Exploit Prediction Scoring System)]]></title>
      <description><![CDATA[EPSS scores every CVE's real-world exploit probability. Here's how the FIRST.org model works, how it differs from CVSS, and how to use it to triage faster.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-epss-exploit-prediction-scoring-system</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-epss-exploit-prediction-scoring-system</guid>
      <pubDate>Wed, 08 Apr 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Is eslint-plugin-jsx-a11y a Security Tool? What It Actually Catches]]></title>
      <description><![CDATA[eslint-plugin-jsx-a11y is an accessibility linter for JSX, not a vulnerability scanner. Here is what it catches, where it stops, and how it fits into a secure React pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/eslint-plugin-jsx-a11y</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eslint-plugin-jsx-a11y</guid>
      <pubDate>Wed, 08 Apr 2026 03:31:00 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Discovery and Exposure Management (CDEM): closing t...]]></title>
      <description><![CDATA[Shadow cloud accounts hide the assets your CSPM never sees. Here's why CDEM closes that gap-and where tools like Prisma Cloud still fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-discovery-and-exposure-management-cdem-closing-the-shadow-cloud-gap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-discovery-and-exposure-management-cdem-closing-the-shadow-cloud-gap</guid>
      <pubDate>Wed, 08 Apr 2026 03:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise App Security: How Large Organizations Protect Their Software]]></title>
      <description><![CDATA[Enterprise app security is the practice of protecting business-critical applications across their whole lifecycle. Here is how mature teams actually run it.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-app-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-app-security</guid>
      <pubDate>Wed, 08 Apr 2026 02:10:33 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is an Exploit]]></title>
      <description><![CDATA[An exploit is code that weaponizes a vulnerability. Learn how exploits differ from CVEs, how attackers acquire them, and how to prioritize real exploitation risk.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-an-exploit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-an-exploit</guid>
      <pubDate>Wed, 08 Apr 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Disaster Recovery Testing Methods That Actually Prove You Can Recover]]></title>
      <description><![CDATA[A walk through the disaster recovery testing methods teams rely on, from tabletop walkthroughs to full failover, and how to pick the right one for each system.]]></description>
      <link>https://safeguard.sh/resources/blog/disaster-recovery-testing-methods</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/disaster-recovery-testing-methods</guid>
      <pubDate>Wed, 08 Apr 2026 00:50:06 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Forecasting the cloud security landscape (annual predicti...]]></title>
      <description><![CDATA[Where does cloud security head into 2027? We break down six concrete predictions on CNAPP consolidation, supply chain risk, and Prisma Cloud gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/forecasting-the-cloud-security-landscape-annual-predictions-series</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/forecasting-the-cloud-security-landscape-annual-predictions-series</guid>
      <pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-25844: The AngularJS ReDoS Bug and How to Fix It]]></title>
      <description><![CDATA[CVE-2022-25844 is a regular-expression denial-of-service flaw in AngularJS. Here is what it affects, why there is no upstream patch, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-25844</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-25844</guid>
      <pubDate>Tue, 07 Apr 2026 23:29:39 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Code Review Best Practices for Java: A Security-First Guide]]></title>
      <description><![CDATA[Security-focused code review best practices for Java teams: what to look for, how to structure reviews, and the recurring bug classes that slip past compilers.]]></description>
      <link>https://safeguard.sh/resources/blog/code-review-best-practices-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-review-best-practices-java</guid>
      <pubDate>Tue, 07 Apr 2026 22:09:13 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Benefits Of Ethical Hacking: A Security Guide]]></title>
      <description><![CDATA[The benefits of ethical hacking come down to one thing: finding your weaknesses before an attacker does, on your terms and with a report you can act on.]]></description>
      <link>https://safeguard.sh/resources/blog/benefits-of-ethical-hacking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/benefits-of-ethical-hacking</guid>
      <pubDate>Tue, 07 Apr 2026 20:48:46 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What Does CVE Stand For? A Plain-Language Security Guide]]></title>
      <description><![CDATA[CVE stands for Common Vulnerabilities and Exposures, the public catalog that gives every known security flaw a single, shareable name. Here is how the system works and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/what-does-cve-stand-for</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-does-cve-stand-for</guid>
      <pubDate>Tue, 07 Apr 2026 19:28:19 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Werkzeug in Python: What Developers Need to Know About Security]]></title>
      <description><![CDATA[Werkzeug powers Flask and countless WSGI apps in Python. Here is how to use it without leaving the interactive debugger or hostname checks open to attackers.]]></description>
      <link>https://safeguard.sh/resources/blog/werkzeug-python</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/werkzeug-python</guid>
      <pubDate>Tue, 07 Apr 2026 18:07:53 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[The Best Veracode Competitors and Alternatives for AppSec in 2025]]></title>
      <description><![CDATA[The strongest Veracode competitors trade portal-first workflows for developer-native scanning. Here is how Snyk, Checkmarx, SonarQube and others compare on speed, coverage, and pricing.]]></description>
      <link>https://safeguard.sh/resources/blog/veracode-competitors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/veracode-competitors</guid>
      <pubDate>Tue, 07 Apr 2026 16:47:26 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[User Session Management: A Security Guide]]></title>
      <description><![CDATA[Session management is where most authentication bugs actually live. This guide covers how to issue, store, rotate, and revoke sessions without opening holes attackers walk straight through.]]></description>
      <link>https://safeguard.sh/resources/blog/user-session-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/user-session-management</guid>
      <pubDate>Tue, 07 Apr 2026 15:26:59 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to Update Node.js Safely: A Security-First Guide]]></title>
      <description><![CDATA[The safest way to update Node.js is to move to a supported LTS line and treat the upgrade as a security event, not a chore. Here is a practical path from an EOL version to a maintained one.]]></description>
      <link>https://safeguard.sh/resources/blog/update-node-js</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/update-node-js</guid>
      <pubDate>Tue, 07 Apr 2026 14:06:33 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Test PHP Code Securely (Testar PHP the Right Way)]]></title>
      <description><![CDATA[A practitioner's guide to testing PHP code for security bugs, from unit tests that assert on input handling to SAST and dependency scanning in CI.]]></description>
      <link>https://safeguard.sh/resources/blog/testar-php</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/testar-php</guid>
      <pubDate>Tue, 07 Apr 2026 12:46:06 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AI-BOM Explained: Tracking Models As Supply Chain]]></title>
      <description><![CDATA[AI models are now first-class supply chain components. Here is how an AI-BOM captures lineage, datasets, runtimes, and evaluations in a way that survives audit.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-bom-explained-tracking-models-as-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-bom-explained-tracking-models-as-supply-chain</guid>
      <pubDate>Tue, 07 Apr 2026 12:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Container Supply Chain Defence: Build To Run]]></title>
      <description><![CDATA[An end-to-end view of container supply chain controls from source through registry to runtime, covering signing, attestation, admission policy, and runtime drift, with concrete checkpoints at each stage.]]></description>
      <link>https://safeguard.sh/resources/blog/container-supply-chain-defence-from-build-to-run</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-supply-chain-defence-from-build-to-run</guid>
      <pubDate>Tue, 07 Apr 2026 12:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CRA Conformity Assessment: Choosing Between Modules A, B+C, and H]]></title>
      <description><![CDATA[The CRA offers three conformity routes: Module A self-assessment, Module B+C type examination plus production conformity, and Module H quality management system audit.]]></description>
      <link>https://safeguard.sh/resources/blog/cra-conformity-assessment-modules-a-b-c-h</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cra-conformity-assessment-modules-a-b-c-h</guid>
      <pubDate>Tue, 07 Apr 2026 12:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[EU AI Act High-Risk System Obligations]]></title>
      <description><![CDATA[A senior engineer's breakdown of the EU AI Act high-risk system obligations as they apply in 2026, with a focus on documentation, supply chain, and ongoing monitoring.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-ai-act-high-risk-system-obligations-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-ai-act-high-risk-system-obligations-2026</guid>
      <pubDate>Tue, 07 Apr 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Human Review Gate For AI-Generated Fix PRs]]></title>
      <description><![CDATA[AI-authored fix PRs are only safe when there is a deliberate human review gate in front of them. Here is how to build one that is fast and trustworthy.]]></description>
      <link>https://safeguard.sh/resources/blog/human-review-gate-for-ai-generated-fix-prs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/human-review-gate-for-ai-generated-fix-prs</guid>
      <pubDate>Tue, 07 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Metrics Program For Supply Chain SecOps]]></title>
      <description><![CDATA[Most supply chain SecOps metrics measure activity instead of outcomes. Here is how to design a metrics program that survives leadership scrutiny and changes behavior.]]></description>
      <link>https://safeguard.sh/resources/blog/metrics-program-supply-chain-secops-team</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/metrics-program-supply-chain-secops-team</guid>
      <pubDate>Tue, 07 Apr 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 Control Mapping With Supply Chain Evidence]]></title>
      <description><![CDATA[Map SOC 2 Trust Services Criteria to concrete supply chain artifacts. Learn how SBOMs, findings, and policy logs satisfy CC controls without manual gymnastics.]]></description>
      <link>https://safeguard.sh/resources/blog/soc2-control-mapping-with-supply-chain-evidence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc2-control-mapping-with-supply-chain-evidence</guid>
      <pubDate>Tue, 07 Apr 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[spring-security-crypto: What It Does and How to Use It Safely]]></title>
      <description><![CDATA[The spring-security-crypto module gives Spring apps password hashing, symmetric encryption, and key generation without pulling in the full security framework. Here is how to use each piece correctly.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-security-crypto</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-security-crypto</guid>
      <pubDate>Tue, 07 Apr 2026 11:25:39 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Fix the SnakeYAML Vulnerability (CVE-2022-1471)]]></title>
      <description><![CDATA[The SnakeYAML vulnerability fix comes down to one move: get off the 1.x line and onto 2.x, where the parser stops trusting arbitrary Java types by default.]]></description>
      <link>https://safeguard.sh/resources/blog/snakeyaml-vulnerability-fix</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snakeyaml-vulnerability-fix</guid>
      <pubDate>Tue, 07 Apr 2026 10:05:13 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AI Cybersecurity Threats: The 2026 Landscape]]></title>
      <description><![CDATA[AI has made the median attacker faster and the median phish flawless, while LLM-powered apps opened a new bug class entirely. What actually changed, and what still works.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-cybersecurity-threats-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-cybersecurity-threats-2026</guid>
      <pubDate>Tue, 07 Apr 2026 09:15:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing the cloud with Cortex XSOAR and Prisma Cloud (SO...]]></title>
      <description><![CDATA[Cortex XSOAR and Prisma Cloud automate cloud incident response, but SOAR reacts to runtime alerts. Here's why supply chain provenance still needs a separate layer.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-the-cloud-with-cortex-xsoar-and-prisma-cloud-soar-integration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-the-cloud-with-cortex-xsoar-and-prisma-cloud-soar-integration</guid>
      <pubDate>Tue, 07 Apr 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Web Application Scanning Tools: DAST Options Compared]]></title>
      <description><![CDATA[Choosing a web application scanning tool means deciding between open-source scanners, proxy-based suites, and managed DAST platforms. Here is how the options actually differ.]]></description>
      <link>https://safeguard.sh/resources/blog/web-application-scanning-tools-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-application-scanning-tools-guide</guid>
      <pubDate>Tue, 07 Apr 2026 08:55:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SnakeYAML in Maven: How to Use It Safely and Avoid CVE-2022-1471]]></title>
      <description><![CDATA[Adding SnakeYAML as a Maven dependency is fine, but parsing untrusted YAML with the default constructor is not. Here is how to pin a safe version and lock down deserialization.]]></description>
      <link>https://safeguard.sh/resources/blog/snakeyaml-maven</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snakeyaml-maven</guid>
      <pubDate>Tue, 07 Apr 2026 08:44:46 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How to Secure Cloud Applications: A Practical Guide]]></title>
      <description><![CDATA[Securing cloud applications means protecting the code, the dependencies, the identities, and the runtime together. Here is a practical way to think about all four.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-cloud-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-cloud-applications</guid>
      <pubDate>Tue, 07 Apr 2026 07:24:19 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Scan Source Code for Vulnerabilities: A Practical Guide]]></title>
      <description><![CDATA[Scanning source code means running automated analysis over your repository to find security flaws before they reach production. Here is how to do it well.]]></description>
      <link>https://safeguard.sh/resources/blog/scan-source-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scan-source-code</guid>
      <pubDate>Tue, 07 Apr 2026 06:03:52 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[5 best practices for using Prisma Cloud with Oracle Cloud...]]></title>
      <description><![CDATA[Five OCI cloud security best practices for running Prisma Cloud on Oracle Cloud Infrastructure, from IAM scoping to closing the software supply chain gap.]]></description>
      <link>https://safeguard.sh/resources/blog/5-best-practices-for-using-prisma-cloud-with-oracle-cloud-infrastructure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/5-best-practices-for-using-prisma-cloud-with-oracle-cloud-infrastructure</guid>
      <pubDate>Tue, 07 Apr 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[A Practical SAST Tools List for Modern AppSec Teams]]></title>
      <description><![CDATA[A working SAST tools list for teams that want static analysis in the pipeline, not just a scanner that files noise. What each tool is good at and how to choose.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-tools-list</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-tools-list</guid>
      <pubDate>Tue, 07 Apr 2026 04:43:26 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SAST Testing Tools: How to Choose and Use Them Effectively]]></title>
      <description><![CDATA[A practitioner's guide to SAST testing tools: what static analysis actually catches, where it falls short, and how to wire it into a pipeline without drowning developers in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-testing-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-testing-tools</guid>
      <pubDate>Tue, 07 Apr 2026 03:22:59 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Discover, protect and respond with AWS and Prisma Cloud]]></title>
      <description><![CDATA[Prisma Cloud discovers, protects, and responds across AWS — but the framework starts after code is already built. Here's the AWS supply chain gap it leaves open, and how to close it.]]></description>
      <link>https://safeguard.sh/resources/blog/discover-protect-and-respond-with-aws-and-prisma-cloud</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/discover-protect-and-respond-with-aws-and-prisma-cloud</guid>
      <pubDate>Tue, 07 Apr 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What Is a PAT Token and How Do You Keep It Secure?]]></title>
      <description><![CDATA[A PAT token is a personal access token that stands in for your password when scripts and tools talk to services like GitHub. Here's how it works and how to stop it leaking.]]></description>
      <link>https://safeguard.sh/resources/blog/pat-token</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pat-token</guid>
      <pubDate>Tue, 07 Apr 2026 02:02:32 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[npm rollup: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[A practical look at what installing rollup from npm means for your supply chain, the DOM clobbering XSS bug you should know about, and how to pin a safe version.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-rollup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-rollup</guid>
      <pubDate>Tue, 07 Apr 2026 00:42:06 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[AI cybersecurity hub (AI-driven threat detection)]]></title>
      <description><![CDATA[Prisma Cloud's AI-driven detection watches runtime behavior, but AI in cybersecurity still misses supply chain attacks like XZ Utils. Provenance matters more.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-cybersecurity-hub-ai-driven-threat-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-cybersecurity-hub-ai-driven-threat-detection</guid>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How Safe Is the npm pino Logger? A Security Review]]></title>
      <description><![CDATA[The npm pino logger is one of the fastest and best-maintained logging libraries for Node.js, and it is safe for production when you configure redaction and transports carefully.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-pino</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-pino</guid>
      <pubDate>Mon, 06 Apr 2026 23:21:39 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How to Write a Secure Node.js Dockerfile]]></title>
      <description><![CDATA[A hardened Node.js Dockerfile starts with a pinned base image, a non-root user, and a multi-stage build. Here is how to write one that survives a real security review.]]></description>
      <link>https://safeguard.sh/resources/blog/node-js-dockerfile</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-js-dockerfile</guid>
      <pubDate>Mon, 06 Apr 2026 22:01:12 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The MIT Licence Explained: What It Permits and Its Security Implications]]></title>
      <description><![CDATA[The MIT licence is one of the most permissive open source licences in use, and understanding what it allows tells you a lot about the risk you inherit with a dependency.]]></description>
      <link>https://safeguard.sh/resources/blog/mit-licence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mit-licence</guid>
      <pubDate>Mon, 06 Apr 2026 20:40:46 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Malicious Code Meaning: A Practical Definition for Developers]]></title>
      <description><![CDATA[Malicious code is any software written to damage, disrupt, or gain unauthorized access to a system. Here is what the term actually covers and how it reaches your stack.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-code-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-code-meaning</guid>
      <pubDate>Mon, 06 Apr 2026 19:20:19 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[jQuery Validation: A Security Guide to XSS and ReDoS Risks]]></title>
      <description><![CDATA[The jQuery Validation plugin is convenient, but client-side validation is not a security control. Here is where jquery validation has been vulnerable and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/jquery-validation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jquery-validation</guid>
      <pubDate>Mon, 06 Apr 2026 17:59:52 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What jQuery Migrate Is and How to Use It Securely]]></title>
      <description><![CDATA[jQuery Migrate helps older code survive newer jQuery releases, but leaning on it can quietly keep you on a vulnerable jQuery version. Here is how to use it without inheriting old XSS bugs.]]></description>
      <link>https://safeguard.sh/resources/blog/jquery-migrate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jquery-migrate</guid>
      <pubDate>Mon, 06 Apr 2026 16:39:26 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Java Stream Sum: How to Add Numbers Safely in Java]]></title>
      <description><![CDATA[A practical look at computing a Java stream sum correctly, from IntStream.sum() to reduce(), plus the overflow and null pitfalls that turn a simple total into a bug.]]></description>
      <link>https://safeguard.sh/resources/blog/java-stream-sum</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-stream-sum</guid>
      <pubDate>Mon, 06 Apr 2026 15:18:59 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Java Security Scanner: How It Works and What to Use]]></title>
      <description><![CDATA[A Java security scanner combines static analysis of your own code with dependency scanning of your Maven and Gradle tree. Here is how each layer works and how to wire them into a build.]]></description>
      <link>https://safeguard.sh/resources/blog/java-security-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-security-scanner</guid>
      <pubDate>Mon, 06 Apr 2026 13:58:32 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVSS vs EPSS vs KEV: A 2026 Prioritization Guide]]></title>
      <description><![CDATA[How CVSS, EPSS, and CISA KEV combine into a defensible vulnerability prioritization model for 2026, with concrete thresholds and operational guidance.]]></description>
      <link>https://safeguard.sh/resources/blog/cvss-vs-epss-vs-kev-prioritization-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cvss-vs-epss-vs-kev-prioritization-guide-2026</guid>
      <pubDate>Mon, 06 Apr 2026 13:20:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How To Handle a Zero-Day Vulnerability: A Response Playbook]]></title>
      <description><![CDATA[A zero-day has no patch on day one, so your first move is containment and exposure reduction, not waiting on a vendor fix. Here is how to handle a zero-day vulnerability under pressure.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-handle-zero-day-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-handle-zero-day-vulnerability</guid>
      <pubDate>Mon, 06 Apr 2026 12:38:05 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to Secure a GitLab Personal Access Token (and Avoid Leaks)]]></title>
      <description><![CDATA[A GitLab personal access token is a password-equivalent credential for the API and Git over HTTPS. Here is how to scope, rotate, and store one without turning it into a breach.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-personal-access-token</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-personal-access-token</guid>
      <pubDate>Mon, 06 Apr 2026 11:17:39 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How to Find a GitHub Repository URL (and Why It Matters for Security)]]></title>
      <description><![CDATA[A GitHub repository URL is more than a clone address. Here is how to find it, the three forms it takes, and why the wrong one leaks or breaks your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/github-repository-url</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-repository-url</guid>
      <pubDate>Mon, 06 Apr 2026 09:57:12 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Go Toolchain Supply Chain Risks: 2025 Research]]></title>
      <description><![CDATA[2025 research on Go toolchain supply chain risks: module proxy abuse, replace directive attacks, cgo linker vectors, and the hardening patterns Go shops should adopt.]]></description>
      <link>https://safeguard.sh/resources/blog/go-toolchain-supply-chain-risks-2025-research</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-toolchain-supply-chain-risks-2025-research</guid>
      <pubDate>Mon, 06 Apr 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Identity security in the cloud (authN/authZ/access controls)]]></title>
      <description><![CDATA[Prisma Cloud covers cloud IAM well, but CI/CD tokens, service accounts, and pipeline identities are the blind spot attackers now exploit.]]></description>
      <link>https://safeguard.sh/resources/blog/identity-security-in-the-cloud-authnauthzaccess-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/identity-security-in-the-cloud-authnauthzaccess-controls</guid>
      <pubDate>Mon, 06 Apr 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[firebase/php-jwt: Verifying JWTs Without Getting Burned]]></title>
      <description><![CDATA[firebase/php-jwt is the de facto library for encoding and decoding JSON Web Tokens in PHP. Here is how to use it correctly and avoid the algorithm-confusion trap.]]></description>
      <link>https://safeguard.sh/resources/blog/firebase-php-jwt</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/firebase-php-jwt</guid>
      <pubDate>Mon, 06 Apr 2026 08:36:45 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Use the express-validator npm Package Safely]]></title>
      <description><![CDATA[A security-focused review of the express-validator npm package: what it protects you from, what it does not, and how to configure it so bad input never reaches your handlers.]]></description>
      <link>https://safeguard.sh/resources/blog/express-validator-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/express-validator-npm</guid>
      <pubDate>Mon, 06 Apr 2026 07:16:19 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is DevSecOps]]></title>
      <description><![CDATA[DevSecOps embeds security into every pipeline stage instead of a final review — here's what it means, how it works, and why Equifax and Log4Shell made it mandatory.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-devsecops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-devsecops</guid>
      <pubDate>Mon, 06 Apr 2026 07:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is CNAPP? (Cloud-Native Application Protection Platf...]]></title>
      <description><![CDATA[CNAPP unifies CSPM, CWPP, CIEM, and app security into one platform. Here's the Gartner-defined pillars, how Prisma Cloud stacks up, and the supply-chain gap it leaves.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-cnapp-cloud-native-application-protection-platform-definition-and-pillars</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-cnapp-cloud-native-application-protection-platform-definition-and-pillars</guid>
      <pubDate>Mon, 06 Apr 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Execa on npm: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[Execa is one of the most popular ways to run child processes in Node.js. Here is how to use the execa npm package without opening a command-injection hole.]]></description>
      <link>https://safeguard.sh/resources/blog/execa-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/execa-npm</guid>
      <pubDate>Mon, 06 Apr 2026 05:55:52 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[eslint-plugin-security: How to Catch Node.js Security Bugs at Lint Time]]></title>
      <description><![CDATA[eslint-plugin-security adds static-analysis rules to ESLint that flag risky Node.js patterns before they ship. Here is how to configure it and read its warnings without drowning in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/eslint-plugin-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eslint-plugin-security</guid>
      <pubDate>Mon, 06 Apr 2026 04:35:25 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[DevOps vs DevSecOps]]></title>
      <description><![CDATA[DevOps ships code fast; DevSecOps ships it safely. Here's the concrete difference, backed by real breach data, costs, and pipeline mechanics.]]></description>
      <link>https://safeguard.sh/resources/blog/devops-vs-devsecops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devops-vs-devsecops</guid>
      <pubDate>Mon, 06 Apr 2026 04:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Docker Security Issues and How to Fix the Most Common Ones]]></title>
      <description><![CDATA[Most Docker security issues trace back to a handful of predictable mistakes: bloated base images, root containers, and secrets baked into layers. Here is how to find and fix them.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-security-issues</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-security-issues</guid>
      <pubDate>Mon, 06 Apr 2026 03:14:59 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Threat Modeling: Baking Threat Analysis Into Your Pipeline]]></title>
      <description><![CDATA[DevSecOps threat modeling moves risk analysis out of one-off workshops and into the delivery pipeline, so teams find design flaws before they ship.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-threat-modeling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-threat-modeling</guid>
      <pubDate>Mon, 06 Apr 2026 01:54:32 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What is a Secure SDLC (Software Development Life Cycle)]]></title>
      <description><![CDATA[A secure SDLC embeds security into every dev phase, not just the end. Learn the model, frameworks, and pitfalls — with real breach examples.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-secure-sdlc-software-development-life-cycle</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-secure-sdlc-software-development-life-cycle</guid>
      <pubDate>Mon, 06 Apr 2026 01:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Vulnerability Scanner: How It Works and What to Use]]></title>
      <description><![CDATA[A dependency vulnerability scanner reads your lockfiles, maps every direct and transitive package to known CVEs, and tells you what to upgrade first. Here is how the good ones work.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-vulnerability-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-vulnerability-scanner</guid>
      <pubDate>Mon, 06 Apr 2026 00:34:05 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best Java Docker image: comparison guide]]></title>
      <description><![CDATA[A verifiable comparison of Safeguard and Chainguard Java Docker images across base minimalism, JDK support, CVE patch cadence, and SBOM provenance.]]></description>
      <link>https://safeguard.sh/resources/blog/best-java-docker-image-comparison-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-java-docker-image-comparison-guide</guid>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CISA KEV Catalog Growth Analysis 2025-2026]]></title>
      <description><![CDATA[A data-grounded analysis of CISA Known Exploited Vulnerabilities catalog growth through 2025 and 2026, and the operational implications for defenders.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-kev-catalog-growth-analysis-2025-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-kev-catalog-growth-analysis-2025-2026</guid>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-31159: Path Traversal in the AWS SDK for Java]]></title>
      <description><![CDATA[CVE-2022-31159 is a partial path traversal flaw in the AWS SDK for Java v1's S3 TransferManager. Here is who it affects, how it works, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-31159</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-31159</guid>
      <pubDate>Sun, 05 Apr 2026 23:13:39 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2017-13766 and the Profinet Protocol: What the Wireshark Flaw Means]]></title>
      <description><![CDATA[CVE-2017-13766 is an out-of-bounds write in Wireshark's Profinet I/O protocol dissector. Here is what it affects, why it matters, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2017-13766-protocol</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2017-13766-protocol</guid>
      <pubDate>Sun, 05 Apr 2026 21:53:12 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Code Injection Attack and How Do You Prevent It?]]></title>
      <description><![CDATA[A code injection attack tricks an application into running attacker-supplied code as if it were trusted. Here is how the class works and how to shut it down.]]></description>
      <link>https://safeguard.sh/resources/blog/code-injection-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-injection-attack</guid>
      <pubDate>Sun, 05 Apr 2026 20:32:45 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How a Code Error Solver Helps You Fix Bugs Without Adding Risk]]></title>
      <description><![CDATA[A code error solver turns cryptic stack traces into fixes, but the tempting one-line patch it hands you can quietly introduce a vulnerability. Here is how to use one safely.]]></description>
      <link>https://safeguard.sh/resources/blog/code-error-solver</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-error-solver</guid>
      <pubDate>Sun, 05 Apr 2026 19:12:18 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Code Analyzer? A Practical Security Guide]]></title>
      <description><![CDATA[A code analyzer inspects source or compiled code for bugs and security flaws before they ship. Here is how the different types work and where they fit in a pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/code-analyzer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-analyzer</guid>
      <pubDate>Sun, 05 Apr 2026 17:51:52 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Is the Cheerio npm Package Safe? A Security Review]]></title>
      <description><![CDATA[A practitioner's look at the cheerio npm package: what it does, where its real security risk lives, and how to use it safely in production scrapers and parsers.]]></description>
      <link>https://safeguard.sh/resources/blog/cheerio-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cheerio-npm</guid>
      <pubDate>Sun, 05 Apr 2026 16:31:25 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx Braga: How the Portugal R&D Hub Shapes Its AppSec Platform]]></title>
      <description><![CDATA[Checkmarx Braga is one of the vendor's engineering centers, and it helps explain how the company builds its SAST and application security tooling. Here is what that means for teams evaluating the platform.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-braga</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-braga</guid>
      <pubDate>Sun, 05 Apr 2026 15:10:58 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[AWS DevOps Security Best Practices: A Practical Guide]]></title>
      <description><![CDATA[The AWS DevOps security best practices that matter most are least-privilege IAM, immutable pipelines, and shifting scanning left into CI. Here is how to apply them without slowing delivery.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-devops-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-devops-security-best-practices</guid>
      <pubDate>Sun, 05 Apr 2026 13:50:32 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[API Scanner Tools: How They Work and How to Choose One]]></title>
      <description><![CDATA[An API scanner tool probes your endpoints for authentication gaps, injection flaws, and data exposure before attackers do. Here is how the scanning works and what to look for when picking one.]]></description>
      <link>https://safeguard.sh/resources/blog/api-scanner-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-scanner-tool</guid>
      <pubDate>Sun, 05 Apr 2026 12:30:05 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CycloneDX 1.7 New Features Reviewed]]></title>
      <description><![CDATA[CycloneDX 1.7 brings richer ML-BOM, better attestations, and VEX tightening. A practical review of what changed and what it means for your SBOM pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/cyclonedx-1-7-new-features-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyclonedx-1-7-new-features-review</guid>
      <pubDate>Sun, 05 Apr 2026 12:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP High Software Supply Chain Evidence]]></title>
      <description><![CDATA[FedRAMP High demands provable software supply chain controls, not just policy text. Here is how to assemble the evidence package without slowing engineering.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-high-software-supply-chain-evidence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-high-software-supply-chain-evidence</guid>
      <pubDate>Sun, 05 Apr 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[From CVE To Zero-Day: The Pipeline Flip]]></title>
      <description><![CDATA[Most security pipelines are organised around CVEs that already exist. Here is what changes when you flip the pipeline to surface zero-days first instead.]]></description>
      <link>https://safeguard.sh/resources/blog/from-cve-to-zero-day-the-pipeline-flip-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/from-cve-to-zero-day-the-pipeline-flip-2026</guid>
      <pubDate>Sun, 05 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GCP Cloud Build Supply Chain Defence]]></title>
      <description><![CDATA[Cloud Build has the strongest native supply chain primitives of any major CI service. Most GCP shops are still not using them. This is the 2026 blueprint.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-cloud-build-supply-chain-defence-blueprint</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-cloud-build-supply-chain-defence-blueprint</guid>
      <pubDate>Sun, 05 Apr 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Admission Policy For Supply Chain]]></title>
      <description><![CDATA[Admission control is the last cheap chance to refuse a non-compliant workload. The right policies turn supply chain attestations into deploy-time decisions.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-admission-policy-enforcing-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-admission-policy-enforcing-supply-chain</guid>
      <pubDate>Sun, 05 Apr 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Malicious Package Trends Q1 2026]]></title>
      <description><![CDATA[Q1 2026 PyPI malicious package activity shows a clear shift toward AI and ML tooling targets. We break down the data, the tradecraft, and the implications.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-malicious-package-trends-q1-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-malicious-package-trends-q1-2026</guid>
      <pubDate>Sun, 05 Apr 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Triage Time Economics: Cost Per Finding]]></title>
      <description><![CDATA[Most security teams have no idea what triage actually costs them. Here is how to calculate cost per finding and drive it down with reachability and AI.]]></description>
      <link>https://safeguard.sh/resources/blog/triage-time-economics-cost-per-finding-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/triage-time-economics-cost-per-finding-2026</guid>
      <pubDate>Sun, 05 Apr 2026 12:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is Ethical Hacking? A Practical Security Guide]]></title>
      <description><![CDATA[Ethical hacking is authorized, scoped testing that finds weaknesses before criminals do. Here is how it works, what the phases are, and where it fits alongside automated scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/about-ethical-hacking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/about-ethical-hacking</guid>
      <pubDate>Sun, 05 Apr 2026 11:09:38 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What is Secure Code Review]]></title>
      <description><![CDATA[Secure code review finds exploitable flaws in source code before they ship. Here's what it actually checks, how it differs from SAST, and when it should happen.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-secure-code-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-secure-code-review</guid>
      <pubDate>Sun, 05 Apr 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Why SLSA Level 3 Matters (and Level 4 Usually Doesn't)]]></title>
      <description><![CDATA[SLSA Level 3 gives you verifiable build provenance that satisfies CISA M-22-18 and EO 14028. Level 4 adds hermetic builds most teams will never need.]]></description>
      <link>https://safeguard.sh/resources/blog/why-slsa-level-3-matters-level-4-usually-doesnt</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-slsa-level-3-matters-level-4-usually-doesnt</guid>
      <pubDate>Sun, 05 Apr 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[XXE Attack Walkthroughs: What a Good Demo Actually Shows]]></title>
      <description><![CDATA[Most XXE video walkthroughs stop at proof-of-concept file reads — here's what a genuinely useful one covers, plus the Java fix that actually closes the hole.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-video-walkthroughs-what-to-look-for</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-video-walkthroughs-what-to-look-for</guid>
      <pubDate>Sun, 05 Apr 2026 09:49:12 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Best Python Docker image: top options compared]]></title>
      <description><![CDATA[Chainguard ships minimal, signed Python images. Safeguard verifies and monitors whichever base image you run. Here's how the two approaches compare.]]></description>
      <link>https://safeguard.sh/resources/blog/best-python-docker-image-top-options-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-python-docker-image-top-options-compared</guid>
      <pubDate>Sun, 05 Apr 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Prompt Injection in RAG: Indirect Attacks]]></title>
      <description><![CDATA[A senior engineer's breakdown of indirect prompt injection in RAG pipelines, how real attacks land through retrieved content, and what actually reduces exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-rag-pipeline-indirect-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-rag-pipeline-indirect-attacks</guid>
      <pubDate>Sun, 05 Apr 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[When to Fork an Abandoned Dependency]]></title>
      <description><![CDATA[Forking looks like a one-time action but is really a multi-year maintenance commitment. Here is a decision framework for when a fork beats patching, vendoring, or replacing.]]></description>
      <link>https://safeguard.sh/resources/blog/when-to-fork-an-abandoned-dependency</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/when-to-fork-an-abandoned-dependency</guid>
      <pubDate>Sun, 05 Apr 2026 08:28:45 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Use-After-Free Vulnerabilities: How They're Exploited]]></title>
      <description><![CDATA[A use-after-free exploit turns a dangling pointer into arbitrary code execution — here's how the bug class works, why it still dominates browser and kernel CVEs, and how to catch it before release.]]></description>
      <link>https://safeguard.sh/resources/blog/use-after-free-vulnerabilities-how-theyre-exploited</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/use-after-free-vulnerabilities-how-theyre-exploited</guid>
      <pubDate>Sun, 05 Apr 2026 07:08:18 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Code Review vs Static Analysis]]></title>
      <description><![CDATA[Code review and static analysis catch different bugs at different gates. Here's how they differ, where each fails, and how to combine them.]]></description>
      <link>https://safeguard.sh/resources/blog/code-review-vs-static-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-review-vs-static-analysis</guid>
      <pubDate>Sun, 05 Apr 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Choosing the best Node.js Docker image]]></title>
      <description><![CDATA[Chainguard's minimal Node.js images cut attack surface, but base-image choice is only one link in the chain. Here's how Safeguard compares on patching, debugging, and provenance.]]></description>
      <link>https://safeguard.sh/resources/blog/choosing-the-best-nodejs-docker-image</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/choosing-the-best-nodejs-docker-image</guid>
      <pubDate>Sun, 05 Apr 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[SBOM File Formats, Explained]]></title>
      <description><![CDATA[An SBOM file is only useful if the tools reading it agree on its structure — here's what CycloneDX, SPDX, and SWID actually look like and when each one fits.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-file-formats-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-file-formats-explained</guid>
      <pubDate>Sun, 05 Apr 2026 05:47:51 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Preventing SQL Injection: A Defense-in-Depth Approach]]></title>
      <description><![CDATA[Parameterized queries stop most SQL injection, but the attacks that make it to production usually slip past a single control — here's the layered defense that catches the rest.]]></description>
      <link>https://safeguard.sh/resources/blog/prevention-of-sql-injection-a-defense-in-depth-approach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prevention-of-sql-injection-a-defense-in-depth-approach</guid>
      <pubDate>Sun, 05 Apr 2026 04:27:25 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is a Software Bill of Materials (SBOM)]]></title>
      <description><![CDATA[An SBOM is a machine-readable inventory of every software component and dependency. Learn what it contains, why it matters, and how Safeguard uses it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-software-bill-of-materials-sbom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-software-bill-of-materials-sbom</guid>
      <pubDate>Sun, 05 Apr 2026 04:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[eslint-plugin-simple-import-sort: A Practical Security Guide]]></title>
      <description><![CDATA[What eslint-plugin-simple-import-sort does, why import ordering matters for review hygiene, and how to add it without introducing a new supply-chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/eslint-plugin-simple-import-sort</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eslint-plugin-simple-import-sort</guid>
      <pubDate>Sun, 05 Apr 2026 03:06:58 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Chainguard alternatives for hardened container images]]></title>
      <description><![CDATA[A side-by-side look at Chainguard alternatives, comparing Safeguard's supply chain security scope against Chainguard's hardened base image approach.]]></description>
      <link>https://safeguard.sh/resources/blog/chainguard-alternatives-for-hardened-container-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chainguard-alternatives-for-hardened-container-images</guid>
      <pubDate>Sun, 05 Apr 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[cAdvisor: Container Resource Monitoring, Explained]]></title>
      <description><![CDATA[cAdvisor gives you per-container CPU, memory, network, and filesystem metrics out of the box — here's what it actually measures, how it fits with Prometheus and Kubernetes, and where its limits show up.]]></description>
      <link>https://safeguard.sh/resources/blog/cadvisor-container-monitoring-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cadvisor-container-monitoring-explained</guid>
      <pubDate>Sun, 05 Apr 2026 01:46:31 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[CycloneDX vs SPDX: SBOM Formats Compared]]></title>
      <description><![CDATA[CycloneDX vs SPDX: how the two SBOM formats differ in vulnerability data, licensing, regulatory recognition, and conversion — and which to pick.]]></description>
      <link>https://safeguard.sh/resources/blog/cyclonedx-vs-spdx-sbom-formats-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyclonedx-vs-spdx-sbom-formats-compared</guid>
      <pubDate>Sun, 05 Apr 2026 01:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[node-forge Vulnerabilities: What Happened and What to Use Now]]></title>
      <description><![CDATA[node-forge shipped signature-forgery and prototype-pollution fixes over the years, and its release cadence has gone quiet. Here is what each node-forge vulnerability meant and what to reach for today.]]></description>
      <link>https://safeguard.sh/resources/blog/node-forge-vulnerabilities-and-safe-usage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-forge-vulnerabilities-and-safe-usage</guid>
      <pubDate>Sun, 05 Apr 2026 00:26:05 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Chainguard vs Docker Official Images: hardening and CVE p...]]></title>
      <description><![CDATA[A concrete look at how Chainguard's distroless Wolfi images and Docker Official Images differ on CVE counts, rebuild cadence, and default hardening.]]></description>
      <link>https://safeguard.sh/resources/blog/chainguard-vs-docker-official-images-hardening-and-cve-posture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chainguard-vs-docker-official-images-hardening-and-cve-posture</guid>
      <pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Node.js Backend Security Checklist]]></title>
      <description><![CDATA[A working checklist for securing a Node.js backend: dependency hygiene, input validation, secrets, HTTP headers, and the CI gates that keep regressions out.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-backend-security-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-backend-security-checklist</guid>
      <pubDate>Sat, 04 Apr 2026 23:05:38 GMT</pubDate>
      <category>Dev Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[zxcvbn npm: Is the Password Strength Library Still Safe to Use?]]></title>
      <description><![CDATA[The zxcvbn npm package still works well for password strength estimation, but the original Dropbox library is effectively unmaintained. Here is what that means and what to use instead.]]></description>
      <link>https://safeguard.sh/resources/blog/zxcvbn-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zxcvbn-npm</guid>
      <pubDate>Sat, 04 Apr 2026 21:45:11 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Example: Reading a Real CycloneDX and SPDX Document]]></title>
      <description><![CDATA[One component, two formats: a field-by-field walkthrough of a real CycloneDX and SPDX SBOM — purls, licenses, hashes, dependency graphs, and how to validate your own.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-example-cyclonedx-spdx-walkthrough</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-example-cyclonedx-spdx-walkthrough</guid>
      <pubDate>Sat, 04 Apr 2026 20:24:45 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Reading a Scan Report: What Actually Matters]]></title>
      <description><![CDATA[Most scan reports bury the three fields that decide whether a finding needs action today — this is how to read one without drowning in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/reading-a-scan-report-what-actually-matters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reading-a-scan-report-what-actually-matters</guid>
      <pubDate>Sat, 04 Apr 2026 19:04:18 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Eclipse Jetty Vulnerabilities: What to Patch and When]]></title>
      <description><![CDATA[Jetty's HTTP/2 handling and older 9.4.x branches have carried real denial-of-service and information-disclosure CVEs — here's what a jetty 9.4.41 exploit actually looks like and which versions close it.]]></description>
      <link>https://safeguard.sh/resources/blog/eclipse-jetty-vulnerabilities-what-to-patch-and-when</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eclipse-jetty-vulnerabilities-what-to-patch-and-when</guid>
      <pubDate>Sat, 04 Apr 2026 17:43:51 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Docker and Container Security Best Practices: A Combined Checklist]]></title>
      <description><![CDATA[A single, practical checklist covering dockers and containers together — image build, runtime config, and CI gates — instead of treating Docker security and container security as separate problems.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-container-security-best-practices-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-container-security-best-practices-checklist</guid>
      <pubDate>Sat, 04 Apr 2026 16:23:25 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[EU Cyber Solidarity Act: Regulation 2025/38 in Force]]></title>
      <description><![CDATA[Regulation (EU) 2025/38 entered into force on 4 February 2025, establishing an EU Cybersecurity Reserve, alert system of cross-border hubs, and ENISA-led incident review mechanism.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cyber-solidarity-act-regulation-2025-38</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cyber-solidarity-act-regulation-2025-38</guid>
      <pubDate>Sat, 04 Apr 2026 15:02:58 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Actions Supply Chain Attack: The tj-actions/changed-files Compromise]]></title>
      <description><![CDATA[Attackers compromised the popular tj-actions/changed-files GitHub Action, injecting credential-stealing code that affected over 23,000 repositories. A textbook software supply chain attack.]]></description>
      <link>https://safeguard.sh/resources/blog/github-actions-supply-chain-attack-tj-actions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-actions-supply-chain-attack-tj-actions</guid>
      <pubDate>Sat, 04 Apr 2026 13:42:31 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Is react-json-view Safe to Use? A Security Guide]]></title>
      <description><![CDATA[The original react-json-view package is popular but unmaintained. Here is what that means for your app's security and which fork to move to.]]></description>
      <link>https://safeguard.sh/resources/blog/react-json-view</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-json-view</guid>
      <pubDate>Sat, 04 Apr 2026 12:22:04 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Azure Key Vault Managed HSM for Artifact Signing: Pattern Library]]></title>
      <description><![CDATA[Managed HSM gives you FIPS 140-3 Level 3 key custody in Azure. We map the patterns for using it as the root of trust for code signing, container signing, and SBOM attestation.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-key-vault-managed-hsm-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-key-vault-managed-hsm-supply-chain-2026</guid>
      <pubDate>Sat, 04 Apr 2026 12:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Real-World Deployment: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Demos live on a single repo and a curated dataset. Real deployments hit fifty repos, three CI providers, two cloud accounts, and an air-gapped environment. The gap is where vendors get sorted.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-real-world-deployment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-real-world-deployment</guid>
      <pubDate>Sat, 04 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Inventory Of MCP Servers: Enterprise Program]]></title>
      <description><![CDATA[MCP servers proliferate faster than governance can track them. Build an inventory program that captures every server, tool, and consumer agent.]]></description>
      <link>https://safeguard.sh/resources/blog/inventory-of-mcp-servers-enterprise-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/inventory-of-mcp-servers-enterprise-program</guid>
      <pubDate>Sat, 04 Apr 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Java/Spring Supply Chain Defence Blueprint 2026]]></title>
      <description><![CDATA[A 2026 blueprint for hardening Java and Spring supply chains across Maven, Gradle, fat JARs, and runtime — with Safeguard as the policy and evidence layer.]]></description>
      <link>https://safeguard.sh/resources/blog/java-spring-supply-chain-defence-blueprint-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-spring-supply-chain-defence-blueprint-2026</guid>
      <pubDate>Sat, 04 Apr 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MCP Vulnerability Disclosure Trends In 2026]]></title>
      <description><![CDATA[MCP servers went from a niche protocol to standard agent infrastructure in under two years. The vulnerability disclosure landscape is catching up — fast, messily, and with patterns worth tracking.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-vulnerability-disclosure-trends-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-vulnerability-disclosure-trends-2026</guid>
      <pubDate>Sat, 04 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[PR-Time Policy Gates Developers Accept]]></title>
      <description><![CDATA[The pull request is the highest-stakes moment in shift-left. A field guide to designing PR policy gates that block bad code without breaking trust.]]></description>
      <link>https://safeguard.sh/resources/blog/pr-time-policy-gates-that-developers-accept</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pr-time-policy-gates-that-developers-accept</guid>
      <pubDate>Sat, 04 Apr 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Prioritising CVE Patches With Reachability, Not CVSS Alone]]></title>
      <description><![CDATA[CVSS by itself produces a queue ordered by hypothetical severity. Reachability orders by actual exposure. Mixing the two correctly is where mature programs land.]]></description>
      <link>https://safeguard.sh/resources/blog/prioritising-cve-patches-with-reachability-not-cvss</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prioritising-cve-patches-with-reachability-not-cvss</guid>
      <pubDate>Sat, 04 Apr 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Scoped Credentials Per MCP Server: A Pattern]]></title>
      <description><![CDATA[Long-lived shared tokens are the wrong unit of trust for MCP servers. Here is the per-server scoped-credential pattern and how to roll it out.]]></description>
      <link>https://safeguard.sh/resources/blog/scoped-credentials-per-mcp-server-pattern</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scoped-credentials-per-mcp-server-pattern</guid>
      <pubDate>Sat, 04 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vendor Incident Coordination In The 72-Hour Window]]></title>
      <description><![CDATA[Most vendor incidents go badly because the first 72 hours are spent figuring out who to call. A pre-built coordination playbook turns chaos into a rehearsed response.]]></description>
      <link>https://safeguard.sh/resources/blog/vendor-incident-coordination-72-hour-window</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vendor-incident-coordination-72-hour-window</guid>
      <pubDate>Sat, 04 Apr 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Wealth Management App Third-Party Risk]]></title>
      <description><![CDATA[Wealth management apps inherit risk from every SDK, custodian API, and analytics package they integrate. Here is a working third-party risk program.]]></description>
      <link>https://safeguard.sh/resources/blog/wealth-management-app-third-party-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wealth-management-app-third-party-risk</guid>
      <pubDate>Sat, 04 Apr 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Install Ruby on Mac: A Practical, Secure Setup Guide]]></title>
      <description><![CDATA[The right way to install Ruby on a Mac is with a version manager, not the system Ruby. Here is a clean setup for current Ruby and even legacy 2.7 projects.]]></description>
      <link>https://safeguard.sh/resources/blog/install-ruby-mac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/install-ruby-mac</guid>
      <pubDate>Sat, 04 Apr 2026 11:01:38 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Agentic Procurement: Letting AI Agents Buy Software Safely]]></title>
      <description><![CDATA[Agents can now evaluate, trial, and pay for software without a human in the loop. The controls that make that safe: spend caps, allowlists, verifiable merchants, and audit trails.]]></description>
      <link>https://safeguard.sh/resources/blog/agentic-procurement-letting-ai-agents-buy-software-safely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agentic-procurement-letting-ai-agents-buy-software-safely</guid>
      <pubDate>Sat, 04 Apr 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Tomas Lindgren)</author>
    </item>
    <item>
      <title><![CDATA[What is Software Supply Chain Security]]></title>
      <description><![CDATA[SolarWinds, Log4Shell, and XZ Utils show why software supply chain security now spans code, dependencies, and build pipelines alike.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-software-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-software-supply-chain-security</guid>
      <pubDate>Sat, 04 Apr 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[XSS Attack Examples: How Cross-Site Scripting Works and How to Stop It]]></title>
      <description><![CDATA[Walk through realistic XSS attack examples across the three main flavors of cross-site scripting, then see how to detect and remediate each one.]]></description>
      <link>https://safeguard.sh/resources/blog/xss-attack-examples</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xss-attack-examples</guid>
      <pubDate>Sat, 04 Apr 2026 09:41:11 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Chainguard pricing model and total cost of ownership]]></title>
      <description><![CDATA[Chainguard's pricing is quote-based and centers on hardened base images. Here's how to model the real total cost of ownership, and where full-chain coverage fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/chainguard-pricing-model-and-total-cost-of-ownership</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chainguard-pricing-model-and-total-cost-of-ownership</guid>
      <pubDate>Sat, 04 Apr 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Lazarus Financial Sector Campaigns 2024-2025]]></title>
      <description><![CDATA[Lazarus Group's 2024-2025 financial sector campaigns combined exchange compromises, DeFi exploits, and developer social engineering. Here is what defenders must know.]]></description>
      <link>https://safeguard.sh/resources/blog/lazarus-financial-sector-campaigns-2024-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lazarus-financial-sector-campaigns-2024-2025</guid>
      <pubDate>Sat, 04 Apr 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SCA Vulnerabilities: How to Find and Fix Them in Your Dependencies]]></title>
      <description><![CDATA[SCA vulnerabilities are known security flaws in the open-source packages your app pulls in. Here is how to detect them, cut the noise, and fix the ones that matter.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-vulnerabilities</guid>
      <pubDate>Sat, 04 Apr 2026 08:20:44 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What package-lock.json Does and Why You Should Commit It]]></title>
      <description><![CDATA[The main package-lock.json use is pinning your entire npm dependency tree to exact, integrity-checked versions so every install is reproducible. Here is what is inside it and why deleting it is a bad habit.]]></description>
      <link>https://safeguard.sh/resources/blog/package-lock-json-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/package-lock-json-explained</guid>
      <pubDate>Sat, 04 Apr 2026 07:00:18 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is a Software Supply Chain Attack]]></title>
      <description><![CDATA[A software supply chain attack compromises trusted dependencies or build systems to spread malicious code downstream — here's how it works, and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-software-supply-chain-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-software-supply-chain-attack</guid>
      <pubDate>Sat, 04 Apr 2026 07:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Zero-day vulnerabilities: what they are and how to protec...]]></title>
      <description><![CDATA[Zero-days can't be patched before they're exploited. See how Log4Shell, MOVEit, and the XZ backdoor happened, and what real zero-day vulnerability protection requires.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-day-vulnerabilities-what-they-are-and-how-to-protect-your-org</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-day-vulnerabilities-what-they-are-and-how-to-protect-your-org</guid>
      <pubDate>Sat, 04 Apr 2026 06:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Updating Python on macOS from the Terminal (Without Breaking Things)]]></title>
      <description><![CDATA[How to update Python on a Mac terminal the safe way: Homebrew or pyenv for the interpreter, never the system copy, plus how to set your default version and keep old installs from lingering.]]></description>
      <link>https://safeguard.sh/resources/blog/update-python-mac-terminal</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/update-python-mac-terminal</guid>
      <pubDate>Sat, 04 Apr 2026 05:39:51 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Open Redirect Vulnerabilities: What They Are and How to Fix Them]]></title>
      <description><![CDATA[An open redirect vulnerability fix is usually a ten-line change, but the bug keeps shipping because redirects hide in login flows, tracking links, and OAuth callbacks. Here is how to find and close them.]]></description>
      <link>https://safeguard.sh/resources/blog/open-redirect-vulnerability-explained-fix</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-redirect-vulnerability-explained-fix</guid>
      <pubDate>Sat, 04 Apr 2026 04:19:24 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is Dependency Confusion]]></title>
      <description><![CDATA[Dependency confusion lets attackers hijack builds by publishing malicious packages under private package names to public registries. Here's how it works.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-dependency-confusion</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-dependency-confusion</guid>
      <pubDate>Sat, 04 Apr 2026 04:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Malicious dependency attacks in the software supply chain]]></title>
      <description><![CDATA[Dependency confusion attacks let attackers hijack builds by publishing malicious packages with higher version numbers to public registries. Here's how they work and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-dependency-attacks-in-the-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-dependency-attacks-in-the-software-supply-chain</guid>
      <pubDate>Sat, 04 Apr 2026 03:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[class-validator: Security, Health, and Safe Usage in Production]]></title>
      <description><![CDATA[class-validator powers input validation in most NestJS apps, but its defaults burned teams once before. Here is its real security history and how to configure it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/class-validator-npm-security-health-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/class-validator-npm-security-health-guide</guid>
      <pubDate>Sat, 04 Apr 2026 02:58:58 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Free Website Vulnerability Scanners: What You Actually Get]]></title>
      <description><![CDATA[Free scanners catch the obvious stuff — missing headers, expired TLS, a handful of known CVEs — but they stop well short of what a real security program needs.]]></description>
      <link>https://safeguard.sh/resources/blog/free-website-vulnerability-scanners-what-you-get</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/free-website-vulnerability-scanners-what-you-get</guid>
      <pubDate>Sat, 04 Apr 2026 01:38:31 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Typosquatting]]></title>
      <description><![CDATA[Typosquatting tricks developers into installing malicious lookalike packages. Learn how it works, real npm/PyPI attacks, and how to detect it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-typosquatting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-typosquatting</guid>
      <pubDate>Sat, 04 Apr 2026 01:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Finding Vulnerabilities in Source Code: A Practical Method]]></title>
      <description><![CDATA[A concrete, repeatable method for finding vulnerabilities in source code — combining static analysis, dependency scanning, and manual review without drowning your team in false positives.]]></description>
      <link>https://safeguard.sh/resources/blog/finding-vulnerabilities-in-source-code-a-practical-method</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/finding-vulnerabilities-in-source-code-a-practical-method</guid>
      <pubDate>Sat, 04 Apr 2026 00:18:04 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Attack Surface Management (ASM): best practices guide]]></title>
      <description><![CDATA[A practical attack surface management best practices guide for software supply chains, covering SBOMs, base image hardening, CI/CD exposure, and a 90-day rollout plan.]]></description>
      <link>https://safeguard.sh/resources/blog/attack-surface-management-asm-best-practices-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/attack-surface-management-asm-best-practices-guide</guid>
      <pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Buyer Guide: Software Supply Chain Security 2026]]></title>
      <description><![CDATA[A senior-engineer buyer guide for software supply chain security in 2026: what the categories mean, what to test, and what to ignore in vendor pitches.]]></description>
      <link>https://safeguard.sh/resources/blog/buyer-guide-software-supply-chain-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buyer-guide-software-supply-chain-security-2026</guid>
      <pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Data Vulnerability Classes in Modern Applications]]></title>
      <description><![CDATA[Most breaches trace back to a handful of recurring data vulnerability patterns — from unencrypted storage to broken access checks. Here's how to categorize and prioritize them.]]></description>
      <link>https://safeguard.sh/resources/blog/data-vulnerability-classes-in-modern-apps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/data-vulnerability-classes-in-modern-apps</guid>
      <pubDate>Fri, 03 Apr 2026 22:57:38 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[PowerSchool Breach: 62M Students, $2.85M Ransom, Cascading Extortion]]></title>
      <description><![CDATA[PowerSchool's December 2024 breach exposed data on roughly 62M students and 9.5M teachers through a compromised support-portal credential and triggered downstream extortion of school districts months later.]]></description>
      <link>https://safeguard.sh/resources/blog/powerschool-education-breach-december-2024-extortion</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/powerschool-education-breach-december-2024-extortion</guid>
      <pubDate>Fri, 03 Apr 2026 21:37:11 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP Continuous Monitoring Automation Playbook]]></title>
      <description><![CDATA[FedRAMP 20x demands real-time ConMon. Here's how to automate monthly POA&M, vulnerability deviation, and SBOM attestation without a 20-person team.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-continuous-monitoring-automation-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-continuous-monitoring-automation-2025</guid>
      <pubDate>Fri, 03 Apr 2026 20:16:44 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[rn-fetch-blob: Maintenance Status, Risks, and Alternatives]]></title>
      <description><![CDATA[The rn-fetch-blob npm package hasn't shipped a release since 2020. Here's what that means for React Native apps still depending on it, and how to migrate to react-native-blob-util.]]></description>
      <link>https://safeguard.sh/resources/blog/rn-fetch-blob-npm-package-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rn-fetch-blob-npm-package-review</guid>
      <pubDate>Fri, 03 Apr 2026 18:56:17 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Apple WebKit Zero-Day CVE-2025-24201: Out-of-Bounds Write Exploited in the Wild]]></title>
      <description><![CDATA[Apple patched CVE-2025-24201, a WebKit zero-day that allowed sandbox escape through malicious web content. Here's the technical breakdown.]]></description>
      <link>https://safeguard.sh/resources/blog/apple-webkit-zero-day-cve-2025-24201</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apple-webkit-zero-day-cve-2025-24201</guid>
      <pubDate>Fri, 03 Apr 2026 17:35:51 GMT</pubDate>
      <category>Zero-Day Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Is swagger-ui-react Safe? A Security Guide for React API Docs]]></title>
      <description><![CDATA[swagger-ui-react has no known direct CVEs, but its real risk lives in a deep dependency tree. Here is how to embed it without inheriting a transitive XSS.]]></description>
      <link>https://safeguard.sh/resources/blog/swagger-ui-react</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/swagger-ui-react</guid>
      <pubDate>Fri, 03 Apr 2026 16:15:24 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Scan Websites for Security Issues]]></title>
      <description><![CDATA[A practical walkthrough of how to scan websites for common vulnerabilities, which tools fit which job, and how to turn scan output into fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/scan-websites</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scan-websites</guid>
      <pubDate>Fri, 03 Apr 2026 14:54:57 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Build Effective Remediation Steps for Security Vulnerabilities]]></title>
      <description><![CDATA[Good remediation steps turn a scanner alert into a fix that actually ships. Here is how to structure, prioritize, and verify them.]]></description>
      <link>https://safeguard.sh/resources/blog/remediation-steps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/remediation-steps</guid>
      <pubDate>Fri, 03 Apr 2026 13:34:31 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Okta 2023 Customer Support Breach: Implications for Identity Supply Chain]]></title>
      <description><![CDATA[The Okta customer support breach of October 2023 exposed HAR files containing session tokens for major customers. The structural lessons run deeper than the incident.]]></description>
      <link>https://safeguard.sh/resources/blog/okta-2023-customer-support-breach-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/okta-2023-customer-support-breach-implications</guid>
      <pubDate>Fri, 03 Apr 2026 12:30:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to Use a Java Package Manager Safely: A Security Review of Maven and Gradle]]></title>
      <description><![CDATA[A Java package manager pulls in far more code than most teams realize. Here is how Maven and Gradle actually resolve dependencies, where the risk lives, and how to lock it down.]]></description>
      <link>https://safeguard.sh/resources/blog/java-package-manager</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-package-manager</guid>
      <pubDate>Fri, 03 Apr 2026 12:14:04 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Breaking-Change-Aware Remediation In 2026]]></title>
      <description><![CDATA[Most fix PRs fail because they ignore breaking changes in the patched version. Here is how breaking-change-aware remediation closes vulns without regressions.]]></description>
      <link>https://safeguard.sh/resources/blog/breaking-change-aware-remediation-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/breaking-change-aware-remediation-2026</guid>
      <pubDate>Fri, 03 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CISA Secure-By-Design Pledge Update 2026]]></title>
      <description><![CDATA[A senior engineer's view of where the CISA Secure-By-Design pledge stands in 2026, what signatories actually delivered, and what the second wave of expectations looks like.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-secure-by-design-pledge-update-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-secure-by-design-pledge-update-2026</guid>
      <pubDate>Fri, 03 Apr 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[EU CRA Self-Assessment Evidence Pack]]></title>
      <description><![CDATA[Build a Cyber Resilience Act self-assessment pack from supply chain evidence. Learn which artifacts CRA expects and how to produce them without rebuilding your stack.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cra-self-assessment-evidence-pack-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cra-self-assessment-evidence-pack-2026</guid>
      <pubDate>Fri, 03 Apr 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Admission Policy Real-World Deployment]]></title>
      <description><![CDATA[What it actually takes to put Kubernetes admission policy into enforcement mode without breaking deployments: phased rollout, exception workflows, audit-mode hygiene, and policy authoring conventions that survive contact with engineers.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-admission-policy-real-world-deployment-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-admission-policy-real-world-deployment-2026</guid>
      <pubDate>Fri, 03 Apr 2026 12:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Oncall Rotation Design For Modern SecOps]]></title>
      <description><![CDATA[Oncall rotations break for SecOps because the work is asynchronous and the alerts are noisy. Here is a rotation design that respects both, with the tooling to back it up.]]></description>
      <link>https://safeguard.sh/resources/blog/oncall-rotation-design-modern-secops-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oncall-rotation-design-modern-secops-2026</guid>
      <pubDate>Fri, 03 Apr 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM-Driven Vendor Onboarding: Procurement Blueprint]]></title>
      <description><![CDATA[Procurement that asks for a PDF security questionnaire is buying paperwork. SBOM-driven onboarding turns vendor risk into queryable, comparable, and enforceable data.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-driven-vendor-onboarding-procurement-blueprint</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-driven-vendor-onboarding-procurement-blueprint</guid>
      <pubDate>Fri, 03 Apr 2026 12:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Java LTS Versions Explained: What They Mean for Security]]></title>
      <description><![CDATA[A Java LTS release gets years of patches instead of six months, which makes your choice of version a security decision as much as a feature one.]]></description>
      <link>https://safeguard.sh/resources/blog/java-lts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-lts</guid>
      <pubDate>Fri, 03 Apr 2026 10:53:37 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Are Malicious Packages]]></title>
      <description><![CDATA[Malicious npm packages steal credentials, mine crypto, or wipe files. Learn how attackers plant them and how to detect and stop them fast.]]></description>
      <link>https://safeguard.sh/resources/blog/what-are-malicious-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-are-malicious-packages</guid>
      <pubDate>Fri, 03 Apr 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Can a Code Corrector Actually Make Your Python Safer?]]></title>
      <description><![CDATA[A code corrector fixes style and syntax, but it rarely catches the security bugs that matter. Here is where a Python code corrector helps, where it fails, and what to run alongside it.]]></description>
      <link>https://safeguard.sh/resources/blog/code-corrector</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-corrector</guid>
      <pubDate>Fri, 03 Apr 2026 09:33:11 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Managing risk in the software supply chain]]></title>
      <description><![CDATA[Chainguard hardens base images, but that's one slice of supply chain risk. Here's what SolarWinds, Log4Shell, and XZ Utils reveal about the gaps — and how to close them.]]></description>
      <link>https://safeguard.sh/resources/blog/managing-risk-in-the-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/managing-risk-in-the-software-supply-chain</guid>
      <pubDate>Fri, 03 Apr 2026 09:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What Is an API Security Tool and How Do You Actually Choose One?]]></title>
      <description><![CDATA[An API security tool inspects, tests, and monitors your APIs for the flaws attackers hunt for. Here is how the categories differ and how to pick the right one.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-tool</guid>
      <pubDate>Fri, 03 Apr 2026 08:12:44 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Are Transitive Dependencies]]></title>
      <description><![CDATA[Transitive dependencies are the packages your code never directly imports but inherits anyway — and where 84% of open source CVEs actually live.]]></description>
      <link>https://safeguard.sh/resources/blog/what-are-transitive-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-are-transitive-dependencies</guid>
      <pubDate>Fri, 03 Apr 2026 07:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Snyk News: What Recent Developments Mean for Security Teams]]></title>
      <description><![CDATA[A practitioner's read on recent Snyk news, its acquisitions and IPO signals, and what the company's direction means for teams choosing a developer-security tool.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-news</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-news</guid>
      <pubDate>Fri, 03 Apr 2026 06:52:17 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Application security assessments: a practical guide]]></title>
      <description><![CDATA[A practical, numbers-based guide to running application security assessments -- scope, cadence, findings, and how Safeguard compares to image-hardening tools like Chainguard.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-assessments-a-practical-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-assessments-a-practical-guide</guid>
      <pubDate>Fri, 03 Apr 2026 06:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[What a WhiteSource Scan Actually Checks (and How Mend Changed It)]]></title>
      <description><![CDATA[A WhiteSource scan is a software composition analysis run that inventories your open source dependencies and flags known vulnerabilities and license risks. Here is what it looks at and how the Mend rebrand affects your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/whitesource-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/whitesource-scan</guid>
      <pubDate>Fri, 03 Apr 2026 05:31:51 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Is react-native-device-info Safe? A Security Guide]]></title>
      <description><![CDATA[react-native-device-info is one of the most-used device fingerprinting libraries in React Native. Here is how to use it without leaking data or tripping privacy reviews.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-device-info</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-device-info</guid>
      <pubDate>Fri, 03 Apr 2026 04:11:24 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Direct vs Transitive Dependencies]]></title>
      <description><![CDATA[Most known vulnerabilities live in transitive dependencies, not the ones in your manifest. Here's how to tell them apart and prioritize what's exploitable.]]></description>
      <link>https://safeguard.sh/resources/blog/direct-vs-transitive-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/direct-vs-transitive-dependencies</guid>
      <pubDate>Fri, 03 Apr 2026 04:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Security automation: stop chasing vulnerabilities, start ...]]></title>
      <description><![CDATA[Chasing CVEs doesn't scale — 40,000+ vulnerabilities were logged in 2024 alone. Here's why prevention-first automation beats patch-cycle chasing, and how it differs from Chainguard's approach.]]></description>
      <link>https://safeguard.sh/resources/blog/security-automation-stop-chasing-vulnerabilities-start-preventing-them</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-automation-stop-chasing-vulnerabilities-start-preventing-them</guid>
      <pubDate>Fri, 03 Apr 2026 03:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[org.json Maven: A Security Guide]]></title>
      <description><![CDATA[The org.json Maven dependency ships a small JSON parser with a history of denial-of-service bugs. Here is how to pin a safe version and catch it transitively.]]></description>
      <link>https://safeguard.sh/resources/blog/org-json-maven</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/org-json-maven</guid>
      <pubDate>Fri, 03 Apr 2026 02:50:57 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Node.js in Docker: Choosing and Securing Your Base Image]]></title>
      <description><![CDATA[The Docker Node base image you pick decides your CVE count before you write a line of code. Here is how to choose between Debian, slim, and Alpine — and harden whichever you pick.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-docker-secure-base-image-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-docker-secure-base-image-guide</guid>
      <pubDate>Fri, 03 Apr 2026 01:30:30 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Open Source License Compliance]]></title>
      <description><![CDATA[Redis, Elasticsearch, and Terraform all changed licenses in the last three years. Here's how license compliance actually breaks, and how to catch it before you ship.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-license-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-license-compliance</guid>
      <pubDate>Fri, 03 Apr 2026 01:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[React File Viewer: Is It Safe, and What Are the Alternatives?]]></title>
      <description><![CDATA[react-file-viewer still gets thousands of weekly downloads despite going years without an update. Here is what the package does, the risks of a dormant dependency, and how to view files more safely.]]></description>
      <link>https://safeguard.sh/resources/blog/react-file-viewer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-file-viewer</guid>
      <pubDate>Fri, 03 Apr 2026 00:10:04 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[A guide to modern vulnerability scanning]]></title>
      <description><![CDATA[Scanners disagree, CVE volume is exploding, and hardened base images solve only one layer. Here's how modern vulnerability scanning actually works — and where prioritization beats raw CVE counts.]]></description>
      <link>https://safeguard.sh/resources/blog/a-guide-to-modern-vulnerability-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/a-guide-to-modern-vulnerability-scanning</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Node.js Docker Containers: Build Small, Run Safe]]></title>
      <description><![CDATA[A Node.js Docker container that is both small and secure: multi-stage builds, npm ci with a lockfile, non-root users, and why you should not run as PID 1.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-docker-container-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-docker-container-security</guid>
      <pubDate>Thu, 02 Apr 2026 22:49:37 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Security Development Model and How Do You Run One?]]></title>
      <description><![CDATA[A security development model bakes threat modeling, code review, and testing into every stage of the SDLC instead of bolting security on at the end. Here is how the model works in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/security-development-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-development-model</guid>
      <pubDate>Thu, 02 Apr 2026 21:29:10 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Security Intelligence: How to Turn Signals Into Action]]></title>
      <description><![CDATA[Cloud security intelligence is the practice of correlating raw telemetry from your cloud accounts into prioritized, actionable risk. Here is how to build it without drowning in alerts.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-security-intelligence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-security-intelligence</guid>
      <pubDate>Thu, 02 Apr 2026 20:08:44 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[A Practical Race Condition Example (and How to Fix It)]]></title>
      <description><![CDATA[A race condition example is easiest to understand through a bank-balance check-then-act bug. Here is the anatomy, the exploit, and three ways to close it.]]></description>
      <link>https://safeguard.sh/resources/blog/race-condition-example</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/race-condition-example</guid>
      <pubDate>Thu, 02 Apr 2026 18:48:17 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Use-After-Free Vulnerability: How It Works and How to Prevent It]]></title>
      <description><![CDATA[A use-after-free vulnerability happens when a program keeps using memory it already released. Here is why it is dangerous, how attackers exploit it, and how to catch it.]]></description>
      <link>https://safeguard.sh/resources/blog/use-after-free-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/use-after-free-vulnerability</guid>
      <pubDate>Thu, 02 Apr 2026 17:27:50 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[node-fetch: Vulnerability History and the Native fetch Upgrade Path]]></title>
      <description><![CDATA[The npm node-fetch package served a decade of HTTP requests and picked up two notable CVEs along the way. Here is its vulnerability history and how to move to native fetch.]]></description>
      <link>https://safeguard.sh/resources/blog/node-fetch-npm-vulnerabilities-and-upgrade-path</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-fetch-npm-vulnerabilities-and-upgrade-path</guid>
      <pubDate>Thu, 02 Apr 2026 16:07:24 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-34042: How the Spring Security XSD Permission Flaw Works]]></title>
      <description><![CDATA[CVE-2023-34042 is a world-writable file permission issue in Spring Security's config JAR. Here is what actually breaks, who is affected, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-34042</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-34042</guid>
      <pubDate>Thu, 02 Apr 2026 14:46:57 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Management SLA Benchmarks 2026]]></title>
      <description><![CDATA[What credible 2026 vulnerability management SLAs look like across severity tiers, internet exposure, and reachability — with data from real programs.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-management-sla-benchmarks-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-management-sla-benchmarks-2026</guid>
      <pubDate>Thu, 02 Apr 2026 13:45:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Telecom Supply Chain Risk Controls in 2026]]></title>
      <description><![CDATA[Practical supply chain controls for telecom operators in 2026, covering RAN software, OSS/BSS stacks, and the regulatory pressure from FCC and ENISA frameworks.]]></description>
      <link>https://safeguard.sh/resources/blog/telecom-supply-chain-risk-controls-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/telecom-supply-chain-risk-controls-2026</guid>
      <pubDate>Thu, 02 Apr 2026 13:30:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How to Check Python Code for Security Issues: A Practical Guide]]></title>
      <description><![CDATA[A working method to check Python code for security defects, from static analysis of your own source to scanning the third-party packages you pull in.]]></description>
      <link>https://safeguard.sh/resources/blog/check-python-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/check-python-code</guid>
      <pubDate>Thu, 02 Apr 2026 13:26:30 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is This Code? How to Read and Secure Unfamiliar Source]]></title>
      <description><![CDATA[A practical method for answering "what is this code?" when you inherit an unfamiliar file, plus how to spot the security problems hiding inside it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-this-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-this-code</guid>
      <pubDate>Thu, 02 Apr 2026 12:06:04 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Telemetry Data Governance]]></title>
      <description><![CDATA[MCP server telemetry captures sensitive prompts, arguments, and outputs. A governance framework for retention, redaction, and tenant-scoped access is essential.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-telemetry-data-governance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-telemetry-data-governance</guid>
      <pubDate>Thu, 02 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How npm's Takedown Response Time Compressed from Days to Hours During the 2025 Shai-Hulud Waves]]></title>
      <description><![CDATA[AWS measured the September 8 chalk/debug compromise being removed within 2.5 hours and Shai-Hulud 2.0 in November within 12 hours. Here is how the registry-side response workflow operates and how to consume the signal.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-takedown-sla-shai-hulud-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-takedown-sla-shai-hulud-2026</guid>
      <pubDate>Thu, 02 Apr 2026 12:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Container Registry Security Hardening Checklist for 2026]]></title>
      <description><![CDATA[A concrete hardening checklist for container registries in 2026, covering authentication, signing, scanning, retention, and the operational details that actually matter.]]></description>
      <link>https://safeguard.sh/resources/blog/container-registry-security-hardening-checklist-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-registry-security-hardening-checklist-2026</guid>
      <pubDate>Thu, 02 Apr 2026 11:45:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Vulnerability Manager Buyer Rubric 2026]]></title>
      <description><![CDATA[A scoring rubric for evaluating enterprise vulnerability management platforms in 2026, with weighted criteria covering ingestion, prioritization, workflow, and TCO.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-vulnerability-manager-buyer-rubric-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-vulnerability-manager-buyer-rubric-2026</guid>
      <pubDate>Thu, 02 Apr 2026 11:30:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[gVisor vs Firecracker in 2026: Choosing a Sandbox for Untrusted Workloads]]></title>
      <description><![CDATA[A side-by-side comparison of gVisor and Firecracker for sandboxing untrusted code in 2026, covering security model, performance, and operational complexity.]]></description>
      <link>https://safeguard.sh/resources/blog/gvisor-vs-firecracker-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gvisor-vs-firecracker-2026</guid>
      <pubDate>Thu, 02 Apr 2026 11:15:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Integrating Security Into the DevSecOps Toolchain]]></title>
      <description><![CDATA[Integrating security into the DevSecOps toolchain works when scanning is wired into the tools engineers already use, not bolted on as a separate gate at the end.]]></description>
      <link>https://safeguard.sh/resources/blog/integrating-security-into-the-devsecops-toolchain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/integrating-security-into-the-devsecops-toolchain</guid>
      <pubDate>Thu, 02 Apr 2026 11:15:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[JFrog Curation 2026: Time-Based Waivers and On-Demand Policies]]></title>
      <description><![CDATA[JFrog Curation shipped time-bound waivers, on-demand policy application, group-based scope, and ChainGuard hardened-Maven support in 2026. We tested the upgrade on an Artifactory estate.]]></description>
      <link>https://safeguard.sh/resources/blog/jfrog-curation-2026-time-based-waivers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jfrog-curation-2026-time-based-waivers</guid>
      <pubDate>Thu, 02 Apr 2026 11:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[org.owasp.esapi: What the OWASP ESAPI Library Is and How to Use It Safely]]></title>
      <description><![CDATA[org.owasp.esapi is the Maven coordinate for OWASP ESAPI, a Java security control library. Here is what it does, where it still helps, and the CVEs to watch.]]></description>
      <link>https://safeguard.sh/resources/blog/org-owasp-esapi</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/org-owasp-esapi</guid>
      <pubDate>Thu, 02 Apr 2026 10:45:37 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Docker BuildKit Security Best Practices for 2026]]></title>
      <description><![CDATA[BuildKit has been the default Docker builder for years, but its security features remain underused. Here are the practices that matter in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-buildkit-security-best-practices-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-buildkit-security-best-practices-2026</guid>
      <pubDate>Thu, 02 Apr 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Provenance, Attestation, and Signing: A Practical Glossary]]></title>
      <description><![CDATA[Provenance describes how software was built, attestations are signed claims about that process, and signing proves origin. Here's how the pieces fit.]]></description>
      <link>https://safeguard.sh/resources/blog/provenance-attestation-signing-practical-glossary</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/provenance-attestation-signing-practical-glossary</guid>
      <pubDate>Thu, 02 Apr 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Types of Open Source Licenses]]></title>
      <description><![CDATA[A breakdown of permissive, copyleft, and source-available license types—MIT, GPL, AGPL, SSPL—and why misclassified licenses create hidden supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/types-of-open-source-licenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/types-of-open-source-licenses</guid>
      <pubDate>Thu, 02 Apr 2026 10:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What Causes a Memory Leak in JavaScript (and How to Find One)]]></title>
      <description><![CDATA[A memory leak in JavaScript happens when objects you no longer need stay reachable, so the garbage collector can never free them. Here is how they start and how to hunt them down.]]></description>
      <link>https://safeguard.sh/resources/blog/memory-leak-in-javascript</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/memory-leak-in-javascript</guid>
      <pubDate>Thu, 02 Apr 2026 09:25:10 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Composer/PHP Supply Chain Threats: 2025 Report]]></title>
      <description><![CDATA[A senior engineer's 2025 report on Composer and Packagist supply chain threats: namespace abuse, abandoned maintainers, plugin hooks, and the attacks that actually landed on PHP shops.]]></description>
      <link>https://safeguard.sh/resources/blog/composer-php-supply-chain-threats-2025-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/composer-php-supply-chain-threats-2025-report</guid>
      <pubDate>Thu, 02 Apr 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How DevOps Teams Actually Use AI Today]]></title>
      <description><![CDATA[How can a DevOps team take advantage of artificial intelligence without adding risk? Mostly by pointing it at toil — log triage, test generation, and incident summarization — not by handing it the keys to production.]]></description>
      <link>https://safeguard.sh/resources/blog/how-devops-teams-use-ai-in-practice</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-devops-teams-use-ai-in-practice</guid>
      <pubDate>Thu, 02 Apr 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Software supply chain security: threat vectors & solutions]]></title>
      <description><![CDATA[Real incidents, real numbers: how modern software supply chain threat vectors work, why SBOMs alone don't stop them, and what actually closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-threat-vectors-solutions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-threat-vectors-solutions</guid>
      <pubDate>Thu, 02 Apr 2026 09:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Next-Gen SCA Explained: What Changed in 2026]]></title>
      <description><![CDATA[Next-gen SCA tools moved past package-tree scanning to reachability, runtime context, and exploit signal. Here's what actually changed and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/next-gen-sca-explained-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/next-gen-sca-explained-2026</guid>
      <pubDate>Thu, 02 Apr 2026 08:45:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Security and Compliance: Where They Overlap and Where They Don't]]></title>
      <description><![CDATA[Passing a compliance audit and actually being secure in the cloud are related but not the same thing — here's where cloud security and compliance genuinely overlap and where treating them as identical creates blind spots.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-security-and-compliance-where-they-overlap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-security-and-compliance-where-they-overlap</guid>
      <pubDate>Thu, 02 Apr 2026 08:20:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Java Developer Kit Explained: Security Risks and How to Harden Your JDK]]></title>
      <description><![CDATA[The Java Developer Kit is more than a compiler and runtime. Here is how to treat the JDK as part of your attack surface and keep it patched.]]></description>
      <link>https://safeguard.sh/resources/blog/java-developer-kit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-developer-kit</guid>
      <pubDate>Thu, 02 Apr 2026 08:04:43 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Copyleft vs Permissive Licenses]]></title>
      <description><![CDATA[Copyleft and permissive licenses trigger different legal obligations. Here's how GPL, AGPL, MIT, and Apache 2.0 actually differ — with real lawsuits and relicensing cases.]]></description>
      <link>https://safeguard.sh/resources/blog/copyleft-vs-permissive-licenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/copyleft-vs-permissive-licenses</guid>
      <pubDate>Thu, 02 Apr 2026 07:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[https-proxy-agent: What It Does and How to Use It Safely]]></title>
      <description><![CDATA[A practical security review of https-proxy-agent, the Node.js module that tunnels HTTPS through an HTTP proxy, plus the advisories worth knowing before you pin a version.]]></description>
      <link>https://safeguard.sh/resources/blog/https-proxy-agent</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/https-proxy-agent</guid>
      <pubDate>Thu, 02 Apr 2026 06:44:17 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Streamlining the vulnerability management lifecycle]]></title>
      <description><![CDATA[Most teams find CVEs fast but fix them slowly. Here's why the vulnerability management lifecycle breaks down after scanning — and how to close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/streamlining-the-vulnerability-management-lifecycle</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/streamlining-the-vulnerability-management-lifecycle</guid>
      <pubDate>Thu, 02 Apr 2026 06:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What Is the NVD (National Vulnerability Database)?]]></title>
      <description><![CDATA[The NVD is the U.S. government's repository of analyzed vulnerability data, built on top of the CVE program — here's what it actually adds, how CVE and NVD relate, and where its data comes from.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-nvd-national-vulnerability-database</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-nvd-national-vulnerability-database</guid>
      <pubDate>Thu, 02 Apr 2026 05:23:50 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Validate a URL in Python Safely]]></title>
      <description><![CDATA[A practical guide to validating URLs in Python without opening SSRF or injection holes — what the standard library gives you, where it fails, and how to build a safe validator.]]></description>
      <link>https://safeguard.sh/resources/blog/python-validate-url</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-validate-url</guid>
      <pubDate>Thu, 02 Apr 2026 04:03:23 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Software Dependencies: How to Manage Them at Scale]]></title>
      <description><![CDATA[Most apps run 10-20x more dependencies than engineers chose. Here's how reachability analysis and automation manage that risk at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/software-dependencies-how-to-manage-them-at-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-dependencies-how-to-manage-them-at-scale</guid>
      <pubDate>Thu, 02 Apr 2026 04:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Attack surface reduction: practical strategies to minimiz...]]></title>
      <description><![CDATA[Base images are one layer. Real attack surface reduction covers dependencies, build pipelines, and provenance too — here's what Chainguard's approach misses.]]></description>
      <link>https://safeguard.sh/resources/blog/attack-surface-reduction-practical-strategies-to-minimize-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/attack-surface-reduction-practical-strategies-to-minimize-risk</guid>
      <pubDate>Thu, 02 Apr 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[The OWASP API Top Ten: What Every API Team Needs to Secure]]></title>
      <description><![CDATA[A practical walkthrough of the OWASP API Top Ten (2023 edition), with the authorization, resource-consumption, and inventory gaps that actually get APIs breached.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-api-top-ten</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-api-top-ten</guid>
      <pubDate>Thu, 02 Apr 2026 02:42:57 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[jQuery 3.7.1 Vulnerabilities: What Actually Changed From Earlier Releases]]></title>
      <description><![CDATA[jQuery 3.7.1 vulnerabilities are mostly inherited history, not new CVEs — the real security story is what changed across 3.4, 3.5, and 3.7.]]></description>
      <link>https://safeguard.sh/resources/blog/jquery-3-7-1-vulnerabilities-what-changed</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jquery-3-7-1-vulnerabilities-what-changed</guid>
      <pubDate>Thu, 02 Apr 2026 01:22:30 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Dependency Management]]></title>
      <description><![CDATA[Dependency management means tracking, scanning, and patching the open source packages your app relies on -- here's how it works and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-dependency-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-dependency-management</guid>
      <pubDate>Thu, 02 Apr 2026 01:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AWS Security Breaches: Lessons Learned From Real Incidents]]></title>
      <description><![CDATA[Most AWS security breach postmortems trace back to a small set of repeating misconfigurations — public S3 buckets, overprivileged IAM roles, exposed credentials — not novel attacks on AWS itself.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-security-breaches-lessons-learned</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-security-breaches-lessons-learned</guid>
      <pubDate>Thu, 02 Apr 2026 00:02:03 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[California SB-327 IoT Security Enforcement Update]]></title>
      <description><![CDATA[A 2026 enforcement update on California SB-327, the IoT security statute that set a national precedent, and what manufacturers and integrators need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/california-sb-327-iot-security-enforcement-update</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/california-sb-327-iot-security-enforcement-update</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability management for the modern engineering team]]></title>
      <description><![CDATA[A vulnerability management program for engineering teams needs more than zero-CVE base images. Here's how Safeguard closes the gaps Chainguard leaves open.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-management-for-the-modern-engineering-team</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-management-for-the-modern-engineering-team</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Application Vulnerability Management: Program Basics]]></title>
      <description><![CDATA[A working definition of application vulnerability management and the five program elements that separate a real practice from a pile of scanner tickets.]]></description>
      <link>https://safeguard.sh/resources/blog/application-vulnerability-management-program-basics</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-vulnerability-management-program-basics</guid>
      <pubDate>Wed, 01 Apr 2026 22:41:37 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Static Source Code Analysis Tools: A Practical Guide]]></title>
      <description><![CDATA[A practical walkthrough of what static source code analysis tools actually check, where they miss, and how to pick one without buying a shelf-ware scanner.]]></description>
      <link>https://safeguard.sh/resources/blog/static-source-code-analysis-tools-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-source-code-analysis-tools-guide</guid>
      <pubDate>Wed, 01 Apr 2026 21:21:10 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA["New Tag Scanned": What Container Registries Mean By It]]></title>
      <description><![CDATA[A plain explanation of what the "new tag scanned" event actually means in registries like GHCR, ECR, and Docker Hub, and what to do when it flags a vulnerability.]]></description>
      <link>https://safeguard.sh/resources/blog/new-tag-scanned-what-container-registries-mean-by-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/new-tag-scanned-what-container-registries-mean-by-it</guid>
      <pubDate>Wed, 01 Apr 2026 20:00:43 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AWS Security Tools: Native Services vs Third-Party Platforms]]></title>
      <description><![CDATA[GuardDuty, Inspector, and Security Hub cover a lot of ground — but they stop at the AWS account boundary. Here is where native AWS security tools genuinely suffice and where third-party platforms earn their cost.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-security-tools-native-vs-third-party</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-security-tools-native-vs-third-party</guid>
      <pubDate>Wed, 01 Apr 2026 18:40:16 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Attestation Requirements: A Roadmap Read]]></title>
      <description><![CDATA[PEP 740 brings Sigstore-style attestations to PyPI. A close read of the roadmap, what's actually shipped, and what it means for consumers and publishers over the next 12 months.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-attestation-requirements-roadmap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-attestation-requirements-roadmap</guid>
      <pubDate>Wed, 01 Apr 2026 17:19:50 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AI Agent Tool Calling Security: Risks and Mitigations]]></title>
      <description><![CDATA[AI agents that call tools -- APIs, databases, file systems, code interpreters -- convert non-deterministic LLM output into real-world actions. Securing this boundary is the defining challenge of agentic AI.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-agent-tool-calling-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-agent-tool-calling-security</guid>
      <pubDate>Wed, 01 Apr 2026 15:59:23 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Security Census 2025: Who Maintains the Code We All Depend On?]]></title>
      <description><![CDATA[An analysis of the state of open-source security in 2025. Critical infrastructure runs on projects maintained by small, often unpaid teams. Here is what the data shows and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-security-census-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-security-census-2025</guid>
      <pubDate>Wed, 01 Apr 2026 14:38:56 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[YAML Parsers in Java: SnakeYAML Deserialization Risks Explained]]></title>
      <description><![CDATA[Choosing a YAML parser in Java means choosing a deserialization posture. How SnakeYAML's CVE-2022-1471 worked, what changed in 2.0, and how to parse YAML safely.]]></description>
      <link>https://safeguard.sh/resources/blog/java-yaml-parser-snakeyaml-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-yaml-parser-snakeyaml-security</guid>
      <pubDate>Wed, 01 Apr 2026 13:18:30 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Griffin AI: Eval Benchmarks Published]]></title>
      <description><![CDATA[Griffin AI's evaluation harness results published for the first time. Benchmark methodology, comparison against baselines, and what the numbers mean for production use.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-griffin-ai-eval-benchmarks-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-griffin-ai-eval-benchmarks-2026</guid>
      <pubDate>Wed, 01 Apr 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-45133: Babel's Arbitrary Code Execution Flaw Explained]]></title>
      <description><![CDATA[CVE-2023-45133 lets crafted code execute arbitrary commands during Babel compilation. Here's who is at risk, why it scores 9.3, and how to patch it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-45133</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-45133</guid>
      <pubDate>Wed, 01 Apr 2026 11:58:03 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Bootstrap 4.3.1 and 4.4.1 Vulnerabilities: Audit and Upgrade Guide]]></title>
      <description><![CDATA[What your scanner means when it flags bootstrap 4.3.1 vulnerabilities: the real advisories, the withdrawn one, the jQuery 3.4.1 problem next to it, and a sane upgrade path.]]></description>
      <link>https://safeguard.sh/resources/blog/bootstrap-4-vulnerabilities-audit-and-upgrade</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bootstrap-4-vulnerabilities-audit-and-upgrade</guid>
      <pubDate>Wed, 01 Apr 2026 10:37:36 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Known Vulnerabilities in Dependencies]]></title>
      <description><![CDATA[Known vulnerabilities in dependencies cause most supply-chain breaches, not because they're undetected but because teams can't tell which ones are reachable.]]></description>
      <link>https://safeguard.sh/resources/blog/known-vulnerabilities-in-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/known-vulnerabilities-in-dependencies</guid>
      <pubDate>Wed, 01 Apr 2026 10:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Uncaught Exceptions: A Security Guide]]></title>
      <description><![CDATA[A JavaScript uncaught exception is more than a crash — unhandled errors leak internal detail, break security flows midway, and hide attacks. Here is how to handle them safely.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-uncaught-exception</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-uncaught-exception</guid>
      <pubDate>Wed, 01 Apr 2026 09:17:10 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to lower FedRAMP certification costs]]></title>
      <description><![CDATA[FedRAMP authorizations cost $250K-$3M and take 12-18 months. See where that spend actually goes, how Chainguard's hardened images fit in, and how to cut costs.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-lower-fedramp-certification-costs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-lower-fedramp-certification-costs</guid>
      <pubDate>Wed, 01 Apr 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[OpenAI API Key Leakage on GitHub at Scale]]></title>
      <description><![CDATA[A senior engineer's view of OpenAI API key leakage on GitHub at scale, why automated secret scanning misses so many, and what actually stops the bleeding.]]></description>
      <link>https://safeguard.sh/resources/blog/openai-api-key-leakage-on-github-at-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openai-api-key-leakage-on-github-at-scale</guid>
      <pubDate>Wed, 01 Apr 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Symbol Conflict and Binary Planting Attacks 2025]]></title>
      <description><![CDATA[Symbol conflicts and binary planting are the oldest native-code attacks, and they are showing up in modern software supply chains in unexpected places.]]></description>
      <link>https://safeguard.sh/resources/blog/symbol-conflict-malicious-binary-planting-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/symbol-conflict-malicious-binary-planting-2025</guid>
      <pubDate>Wed, 01 Apr 2026 09:00:00 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Mobile Number Validation in JavaScript: A Security-Aware Guide]]></title>
      <description><![CDATA[Mobile number validation in JavaScript is easy to get wrong with a naive regex. Here is how to validate phone numbers correctly, safely, and without ReDoS.]]></description>
      <link>https://safeguard.sh/resources/blog/mobile-number-validation-in-javascript</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mobile-number-validation-in-javascript</guid>
      <pubDate>Wed, 01 Apr 2026 07:56:43 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Open Source Security]]></title>
      <description><![CDATA[Open source powers 70-90% of modern codebases. Learn what open source security means, its real risks, and how reachability analysis cuts through the noise.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-open-source-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-open-source-security</guid>
      <pubDate>Wed, 01 Apr 2026 07:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Patelco Credit Union RansomHub Attack: 1M Records, $7.25M Settlement]]></title>
      <description><![CDATA[RansomHub maintained access to Patelco Credit Union's network from May 23 to June 29, 2024, ultimately exposing data on over one million members and triggering a $7.25M class settlement.]]></description>
      <link>https://safeguard.sh/resources/blog/patelco-credit-union-ransomhub-financial-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/patelco-credit-union-ransomhub-financial-breach</guid>
      <pubDate>Wed, 01 Apr 2026 06:36:16 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP High: requirements and readiness]]></title>
      <description><![CDATA[What FedRAMP High actually requires: 421 controls, 12-24 month timelines, and how supply chain security vendors like Chainguard and Safeguard measure up.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-high-requirements-and-readiness</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-high-requirements-and-readiness</guid>
      <pubDate>Wed, 01 Apr 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[What Is the Most Restrictive Open Source License?]]></title>
      <description><![CDATA[The AGPL is usually named the most restrictive open source license because its copyleft reaches across the network. Here is what that means and how it compares to permissive licenses.]]></description>
      <link>https://safeguard.sh/resources/blog/most-restrictive-open-source-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/most-restrictive-open-source-license</guid>
      <pubDate>Wed, 01 Apr 2026 05:15:50 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Cross-Site Scripting (XSS)]]></title>
      <description><![CDATA[XSS lets attackers inject malicious JavaScript into trusted pages. Learn how stored, reflected, and DOM-based XSS work, real breaches, and defenses.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-cross-site-scripting-xss</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-cross-site-scripting-xss</guid>
      <pubDate>Wed, 01 Apr 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-25638: SQL Injection in Hibernate ORM Explained]]></title>
      <description><![CDATA[CVE-2020-25638 is a SQL injection flaw in hibernate-core that surfaces when SQL comments are enabled and literals are used in JPA Criteria queries. Here is who is affected and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-25638</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-25638</guid>
      <pubDate>Wed, 01 Apr 2026 03:55:23 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP compliance checklist: steps, requirements, docume...]]></title>
      <description><![CDATA[A concrete FedRAMP compliance checklist: steps, documentation, timelines, and how supply chain evidence like Chainguard images and Safeguard SBOMs fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-compliance-checklist-steps-requirements-documentation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-compliance-checklist-steps-requirements-documentation</guid>
      <pubDate>Wed, 01 Apr 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Video Codec Supply Chain Risks: The Hidden Attack Surface in Media Libraries]]></title>
      <description><![CDATA[Video codecs are some of the most complex code in your dependency tree. Their complexity and privileged execution make them prime supply chain targets.]]></description>
      <link>https://safeguard.sh/resources/blog/video-codec-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/video-codec-supply-chain-risks</guid>
      <pubDate>Wed, 01 Apr 2026 02:34:56 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Is the MIT License Free for Commercial Use? What You Need to Know]]></title>
      <description><![CDATA[Yes, the MIT License is free for commercial use, including in closed-source and paid products. Here is what the license actually requires and how it compares to Apache 2.0.]]></description>
      <link>https://safeguard.sh/resources/blog/is-mit-license-free-for-commercial-use</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/is-mit-license-free-for-commercial-use</guid>
      <pubDate>Wed, 01 Apr 2026 01:14:29 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is SQL Injection (SQLi)]]></title>
      <description><![CDATA[SQL injection (CWE-89) lets attackers rewrite database queries via untrusted input — here's how SQLi works, its types, severity, and how to prevent it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-sql-injection-sqli</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-sql-injection-sqli</guid>
      <pubDate>Wed, 01 Apr 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP vulnerability scanning requirements explained]]></title>
      <description><![CDATA[FedRAMP mandates monthly vulnerability scans and 30-day remediation windows. Here's what Rev 5 requires, and why minimal images like Chainguard's don't exempt you.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-vulnerability-scanning-requirements-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-vulnerability-scanning-requirements-explained</guid>
      <pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[What Is a CWE? Common Weakness Enumeration Explained]]></title>
      <description><![CDATA[What is a CWE in cyber security, how it differs from a CVE, and how the Common Weakness Enumeration turns one-off bugs into patterns you can prevent systematically.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-cwe-cyber-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-cwe-cyber-security</guid>
      <pubDate>Tue, 31 Mar 2026 23:54:03 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AI Agent Frameworks: A Security Assessment of the New Autonomous Frontier]]></title>
      <description><![CDATA[AI agents that can execute code, browse the web, and manage infrastructure are proliferating. The security implications of these autonomous frameworks demand scrutiny.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-agent-frameworks-security-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-agent-frameworks-security-assessment</guid>
      <pubDate>Tue, 31 Mar 2026 22:33:36 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[SEC Item 1.05 Year Two: 8-Ks, Sweeps, and the May 2024 Guidance]]></title>
      <description><![CDATA[Between December 2023 and January 2025, 54 companies filed 55 cyber incident 8-Ks. The May 2024 SEC staff guidance bifurcated the practice into 1.05 versus 8.01 disclosures.]]></description>
      <link>https://safeguard.sh/resources/blog/sec-item-1-05-year-two-filings</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sec-item-1-05-year-two-filings</guid>
      <pubDate>Tue, 31 Mar 2026 21:13:09 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Python Security Tools: The Ones Worth Running in Your Pipeline]]></title>
      <description><![CDATA[A practitioner's tour of the Python security tools worth running: pip-audit for dependencies, Bandit for code, and detect-secrets, with CI examples.]]></description>
      <link>https://safeguard.sh/resources/blog/python-security-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-security-tools</guid>
      <pubDate>Tue, 31 Mar 2026 19:52:43 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Monitor Go Module Substitution Attacks]]></title>
      <description><![CDATA[Defend against Go module substitution attacks with GOPROXY, GOSUMDB, vendor verification, and checksum database monitoring — complete with working examples.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-monitor-go-module-substitution-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-monitor-go-module-substitution-attacks</guid>
      <pubDate>Tue, 31 Mar 2026 18:32:16 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is an EPSS Score? A Practical Security Guide]]></title>
      <description><![CDATA[A practical guide to the EPSS score: what it measures, how the score and percentile differ, and how to use EPSS to prioritize which CVEs to fix first.]]></description>
      <link>https://safeguard.sh/resources/blog/epss-score</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/epss-score</guid>
      <pubDate>Tue, 31 Mar 2026 17:11:49 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Tutorial: How It Works and How to Stop It]]></title>
      <description><![CDATA[This SQL injection tutorial explains the attack conceptually and focuses on what actually matters: detecting the flaw in your own code and closing it with parameterized queries.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-tutorial</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-tutorial</guid>
      <pubDate>Tue, 31 Mar 2026 15:51:23 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to Avoid SQL Injection: A Developer's Guide]]></title>
      <description><![CDATA[To avoid SQL injection, never build queries by concatenating user input, use parameterized queries everywhere, and treat every input as untrusted. Here's the defensive playbook.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-avoid-sql-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-avoid-sql-injection</guid>
      <pubDate>Tue, 31 Mar 2026 14:30:56 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Broadcom VMware Zero-Days March 2025: ESXi, Workstation, and Fusion Under Active Attack]]></title>
      <description><![CDATA[Three VMware zero-days exploited in the wild in March 2025 let attackers escape virtual machine sandboxes. Broadcom patched, but the damage window was wide open.]]></description>
      <link>https://safeguard.sh/resources/blog/broadcom-vmware-zero-days-march-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/broadcom-vmware-zero-days-march-2025</guid>
      <pubDate>Tue, 31 Mar 2026 13:10:29 GMT</pubDate>
      <category>Zero-Day Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[RSAC 2026 Floor Report: Agentic AI Security, Platformization, and the Consolidation Debate]]></title>
      <description><![CDATA[What the Moscone show floor actually said about platformization vs. best-of-breed, data sovereignty, and how agentic AI security rewrote the enterprise buying conversation at RSAC 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/rsac-2026-platformization-sovereignty-floor-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rsac-2026-platformization-sovereignty-floor-report</guid>
      <pubDate>Tue, 31 Mar 2026 13:00:00 GMT</pubDate>
      <category>Industry Events</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AWS ECR Image Signing With Cosign In Production]]></title>
      <description><![CDATA[Cosign-signed images in ECR are no longer a side project. This is how to roll out signing across an AWS estate without breaking the deploy pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-ecr-image-signing-cosign-production-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-ecr-image-signing-cosign-production-2026</guid>
      <pubDate>Tue, 31 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Break-Glass Workflow Design: Audited Bypass That Works]]></title>
      <description><![CDATA[Every policy needs a bypass path or it will be routed around. The trick is making the bypass auditable, time-bound, and rare enough to remain meaningful.]]></description>
      <link>https://safeguard.sh/resources/blog/break-glass-workflow-design-audited-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/break-glass-workflow-design-audited-bypass</guid>
      <pubDate>Tue, 31 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Confusion Five Years In: Evolution]]></title>
      <description><![CDATA[Dependency confusion turned five in 2026. We look at how the attack has evolved, why it still works, and what defenders have actually learned.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-confusion-five-years-in-evolution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-confusion-five-years-in-evolution</guid>
      <pubDate>Tue, 31 Mar 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[IL7 Air-Gap Deployment Supply Chain Controls]]></title>
      <description><![CDATA[IL7 environments are isolated by design but inherit every supply chain risk in the artifacts that cross the gap. Here is how to lock down the inbound flow.]]></description>
      <link>https://safeguard.sh/resources/blog/il7-air-gap-deployment-supply-chain-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/il7-air-gap-deployment-supply-chain-controls</guid>
      <pubDate>Tue, 31 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Responsible Disclosure For Discovered Zero-Days]]></title>
      <description><![CDATA[When your pipeline starts producing zero-days, you inherit responsible disclosure obligations. Here is how to do it well, with the artefacts the pipeline already gives you.]]></description>
      <link>https://safeguard.sh/resources/blog/responsible-disclosure-from-discovered-zero-days</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/responsible-disclosure-from-discovered-zero-days</guid>
      <pubDate>Tue, 31 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Risk-Based Prioritisation Beyond CVSS]]></title>
      <description><![CDATA[CVSS tells you severity. It does not tell you risk. Here is how reachability, exploitability, and AI context produce a prioritisation model that survives reality.]]></description>
      <link>https://safeguard.sh/resources/blog/risk-based-prioritisation-beyond-cvss</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/risk-based-prioritisation-beyond-cvss</guid>
      <pubDate>Tue, 31 Mar 2026 12:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[License Type: Understanding Software License Categories]]></title>
      <description><![CDATA[A software license type defines what you may legally do with code you did not write. Here are the main categories, the obligations each carries, and why they matter for compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/license-type</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/license-type</guid>
      <pubDate>Tue, 31 Mar 2026 11:50:03 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[undici npm: Security Review and Safe Usage]]></title>
      <description><![CDATA[The undici npm package is Node.js's modern HTTP client and the engine behind the built-in fetch. Here is a review of its security history and how to keep npm undici patched.]]></description>
      <link>https://safeguard.sh/resources/blog/undici-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/undici-npm</guid>
      <pubDate>Tue, 31 Mar 2026 10:29:36 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Does SQL Injection Work]]></title>
      <description><![CDATA[A technical walkthrough of how SQL injection works, the main attack variants, real breaches it caused, and how to detect and prevent it.]]></description>
      <link>https://safeguard.sh/resources/blog/how-does-sql-injection-work</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-does-sql-injection-work</guid>
      <pubDate>Tue, 31 Mar 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Q1 2026 Release Recap]]></title>
      <description><![CDATA[A quarterly recap of Q1 2026 at Safeguard: the signed chain from source to runtime, self-healing GA, taint tracking, and the air-gap installer.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-changelog-q1-2026-recap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-changelog-q1-2026-recap</guid>
      <pubDate>Tue, 31 Mar 2026 10:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What's a Zero-Day? The Vulnerability Defenders Fear Most]]></title>
      <description><![CDATA[A zero-day is a vulnerability that attackers know about before the vendor has a fix, leaving defenders with zero days to patch. Here is what the term means and how teams respond.]]></description>
      <link>https://safeguard.sh/resources/blog/whats-a-zero-day</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/whats-a-zero-day</guid>
      <pubDate>Tue, 31 Mar 2026 09:09:09 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Simplify PCI DSS 4.0 compliance with hardened containers]]></title>
      <description><![CDATA[PCI DSS 4.0's 30-day patch clock is brutal for container-heavy CDEs. Here's how hardened, minimal images cut CVE noise and make audits defensible.]]></description>
      <link>https://safeguard.sh/resources/blog/simplify-pci-dss-40-compliance-with-hardened-containers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/simplify-pci-dss-40-compliance-with-hardened-containers</guid>
      <pubDate>Tue, 31 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[White House M-22-18 SBOM Attestation Update]]></title>
      <description><![CDATA[OMB M-22-18 and the CISA Secure Software Self-Attestation form continue to evolve. Here is what producers and federal buyers must change in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/white-house-memo-m-22-18-sbom-attestation-update</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/white-house-memo-m-22-18-sbom-attestation-update</guid>
      <pubDate>Tue, 31 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Buffer Streams: Handling Binary Data Safely in Node.js]]></title>
      <description><![CDATA[Buffer streams are how Node.js moves binary data without loading it all into memory. Here is how they work and the security bugs that hide in buffer handling.]]></description>
      <link>https://safeguard.sh/resources/blog/buffer-streams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buffer-streams</guid>
      <pubDate>Tue, 31 Mar 2026 07:48:42 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What is Cross-Site Request Forgery (CSRF)]]></title>
      <description><![CDATA[CSRF forges an authenticated request using a victim's own session cookie. Learn how it works, real Gmail/YouTube cases, and how to detect and fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-cross-site-request-forgery-csrf</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-cross-site-request-forgery-csrf</guid>
      <pubDate>Tue, 31 Mar 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Git Alias: Faster Workflows Without Sacrificing Security]]></title>
      <description><![CDATA[A git alias turns a long command into a short one. Used well they save keystrokes; used carelessly they hide risky flags. Here is how to build aliases you can trust.]]></description>
      <link>https://safeguard.sh/resources/blog/git-alias</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-alias</guid>
      <pubDate>Tue, 31 Mar 2026 06:28:16 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CMMC 2.0 compliance for containerized workloads]]></title>
      <description><![CDATA[CMMC 2.0 enforcement is phasing in through 2028. Hardened container images help, but 35+ of 110 NIST 800-171 controls need continuous evidence Chainguard's approach doesn't cover.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-20-compliance-for-containerized-workloads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-20-compliance-for-containerized-workloads</guid>
      <pubDate>Tue, 31 Mar 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Paragon Partition Manager BYOVD: CVE-2025-0289 Kernel-Level Exploitation]]></title>
      <description><![CDATA[Five vulnerabilities in Paragon Partition Manager's kernel driver were exploited in BYOVD attacks, allowing attackers to gain SYSTEM privileges on Windows systems. Microsoft added the driver to its blocklist.]]></description>
      <link>https://safeguard.sh/resources/blog/paragon-partition-manager-cve-2025-0289</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/paragon-partition-manager-cve-2025-0289</guid>
      <pubDate>Tue, 31 Mar 2026 05:07:49 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What is Server-Side Request Forgery (SSRF)]]></title>
      <description><![CDATA[SSRF turns a server's own trusted network position against it. Learn how the Capital One breach happened, real CVEs, and how to detect and prevent it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-server-side-request-forgery-ssrf</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-server-side-request-forgery-ssrf</guid>
      <pubDate>Tue, 31 Mar 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[react-number-format: A Security Guide for Safe Input Handling]]></title>
      <description><![CDATA[react-number-format is a popular library for formatting numeric and masked inputs. Here is how to use it without opening XSS or validation gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/react-number-format</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-number-format</guid>
      <pubDate>Tue, 31 Mar 2026 03:47:22 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 and the hardened software supply chain]]></title>
      <description><![CDATA[SOC 2 attests to internal controls, not to whether a hardened image or build pipeline is secure. Here is how Chainguard's approach fits, and what it does not cover.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-and-the-hardened-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-and-the-hardened-software-supply-chain</guid>
      <pubDate>Tue, 31 Mar 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Hacking for Dummies: A Plain-English Guide to How Attacks Work]]></title>
      <description><![CDATA[A beginner-friendly, defensive introduction to hacking: what the word means, how attackers actually break in, and how to start thinking like a defender.]]></description>
      <link>https://safeguard.sh/resources/blog/hacking-for-dummies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hacking-for-dummies</guid>
      <pubDate>Tue, 31 Mar 2026 02:26:56 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SAST Definition: What Static Application Security Testing Actually Means]]></title>
      <description><![CDATA[The SAST definition, in plain terms: analyzing source code for vulnerabilities without running it. Here is how it works, what it catches, and where it falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-definition</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-definition</guid>
      <pubDate>Tue, 31 Mar 2026 01:06:29 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Remote Code Execution (RCE)]]></title>
      <description><![CDATA[RCE lets attackers run code on your systems remotely, often without login. Learn how it works, real CVE examples, and how to detect it before exploitation.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-remote-code-execution-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-remote-code-execution-rce</guid>
      <pubDate>Tue, 31 Mar 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Best Secret Scanning Tools 2026 Comparison]]></title>
      <description><![CDATA[A senior-engineer view of secret-scanning tools worth running in 2026: what TruffleHog, Gitleaks, GitGuardian, and platform-native scanners actually do well.]]></description>
      <link>https://safeguard.sh/resources/blog/best-secret-scanning-tools-2026-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-secret-scanning-tools-2026-comparison</guid>
      <pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Wolfi: the community Linux 'undistro']]></title>
      <description><![CDATA[Wolfi calls itself an "undistro," not a distro — and it's the open-source foundation under Chainguard Images. Here's what that actually means, and where the gaps are.]]></description>
      <link>https://safeguard.sh/resources/blog/wolfi-the-community-linux-undistro</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wolfi-the-community-linux-undistro</guid>
      <pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[@microsoft/fetch-event-source: Robust SSE Streams in the Browser]]></title>
      <description><![CDATA[The fetch event source library fixes everything the native EventSource API refuses to do: POST bodies, auth headers, and retry logic you actually control.]]></description>
      <link>https://safeguard.sh/resources/blog/fetch-event-source-sse-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fetch-event-source-sse-guide</guid>
      <pubDate>Mon, 30 Mar 2026 23:46:02 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Code Security Review: Manual vs Automated, and Where They Meet]]></title>
      <description><![CDATA[Code security review works best as a combination, not a choice — here's what automated scanning catches, what still needs a human reviewer, and how to structure both.]]></description>
      <link>https://safeguard.sh/resources/blog/code-security-review-manual-vs-automated</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-security-review-manual-vs-automated</guid>
      <pubDate>Mon, 30 Mar 2026 22:25:36 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Source Code Auditing: How to Find Bugs Before Attackers Do]]></title>
      <description><![CDATA[Source code auditing is the systematic review of code for security flaws. Here is how to run one, where automation fits, and what humans still do better.]]></description>
      <link>https://safeguard.sh/resources/blog/source-code-auditing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/source-code-auditing</guid>
      <pubDate>Mon, 30 Mar 2026 21:05:09 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Does SAST Mean? Static Application Security Testing, Explained]]></title>
      <description><![CDATA[A plain-English answer to what SAST means, how static analysis finds vulnerabilities in source code, what it catches, what it misses, and where it fits alongside DAST and SCA.]]></description>
      <link>https://safeguard.sh/resources/blog/what-does-sast-mean</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-does-sast-mean</guid>
      <pubDate>Mon, 30 Mar 2026 19:44:42 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Go Module Security: sumdb, GOPROXY and Private Modules]]></title>
      <description><![CDATA[How Go's checksum database actually protects you, where GOPROXY ordering bites, and the GOPRIVATE mistakes that leak internal module paths to public infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/go-module-security-sumdb-goproxy-and-private-modules</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-module-security-sumdb-goproxy-and-private-modules</guid>
      <pubDate>Mon, 30 Mar 2026 18:24:16 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Jonas Meyer)</author>
    </item>
    <item>
      <title><![CDATA[American Water Cyberattack: Largest U.S. Utility Forced Offline]]></title>
      <description><![CDATA[American Water Works discovered unauthorised network access on October 3, 2024, shutting down its MyWater customer portal and billing systems serving 14 million people across 24 states.]]></description>
      <link>https://safeguard.sh/resources/blog/american-water-cyberattack-utility-supply-chain-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/american-water-cyberattack-utility-supply-chain-lessons</guid>
      <pubDate>Mon, 30 Mar 2026 17:03:49 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What Is Key Management? Protecting the Keys That Protect Everything]]></title>
      <description><![CDATA[Key management is the discipline of generating, storing, rotating, and retiring cryptographic keys safely. Strong encryption is only as good as the way its keys are handled.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-key-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-key-management</guid>
      <pubDate>Mon, 30 Mar 2026 15:43:22 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Installing Python on Mac Safely: A Security Guide]]></title>
      <description><![CDATA[Installing Python para Mac the wrong way leaves you patching the system interpreter and running sudo pip. Here is the secure, maintainable setup for Python on macOS.]]></description>
      <link>https://safeguard.sh/resources/blog/python-para-mac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-para-mac</guid>
      <pubDate>Mon, 30 Mar 2026 14:22:55 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[LLM-Augmented Bug Discovery Methodology]]></title>
      <description><![CDATA[A practitioner's methodology for using LLMs to augment — not replace — traditional bug discovery workflows, with patterns that hold up under real review load.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-augmented-bug-discovery-methodology</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-augmented-bug-discovery-methodology</guid>
      <pubDate>Mon, 30 Mar 2026 13:02:29 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Agentic AI Security Owned RSAC 2026: Innovation Sandbox, Launch Pad, and the Startups Worth Watching]]></title>
      <description><![CDATA[Geordie AI won the RSAC 2026 Innovation Sandbox with an agentic AI security pitch, and nearly every finalist leaned on AI. Here is an honest recap of the contest, Launch Pad, and the Cryptographers' Panel — and what the signal actually means.]]></description>
      <link>https://safeguard.sh/resources/blog/rsac-2026-innovation-sandbox-launch-pad</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rsac-2026-innovation-sandbox-launch-pad</guid>
      <pubDate>Mon, 30 Mar 2026 13:00:00 GMT</pubDate>
      <category>Industry Events</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AI Coding Assistant Data Leak Incidents Trend]]></title>
      <description><![CDATA[AI coding assistants are now standard developer tooling. The incident data from 2025 and early 2026 shows a recurring pattern of source code, credential, and customer data leaking through them.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-coding-assistant-data-leak-incidents-trend</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-coding-assistant-data-leak-incidents-trend</guid>
      <pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CLI Tool Design For Developer Security Checks]]></title>
      <description><![CDATA[A security CLI lives or dies on the experience of typing it. A design guide for building security tooling that respects the developer's terminal.]]></description>
      <link>https://safeguard.sh/resources/blog/cli-tool-design-for-developer-security-checks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cli-tool-design-for-developer-security-checks</guid>
      <pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Finding Forgotten Public npm Packages In Your Org]]></title>
      <description><![CDATA[Public npm packages your org published years ago are now an attacker's best targets. Find them before someone else does.]]></description>
      <link>https://safeguard.sh/resources/blog/finding-forgotten-public-npm-packages-in-your-org</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/finding-forgotten-public-npm-packages-in-your-org</guid>
      <pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Go Modules Supply Chain Program Blueprint 2026]]></title>
      <description><![CDATA[A 2026 blueprint for Go modules supply chain security — from proxy and checksum database to vendoring and binary provenance — anchored by Safeguard.]]></description>
      <link>https://safeguard.sh/resources/blog/go-modules-supply-chain-program-blueprint-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-modules-supply-chain-program-blueprint-2026</guid>
      <pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Insurance Claims Platform Supply Chain Program]]></title>
      <description><![CDATA[Insurance claims platforms run on document AI, fraud detection, and integrations to thousands of vendors. Here is the supply chain program that fits.]]></description>
      <link>https://safeguard.sh/resources/blog/insurance-claims-platform-supply-chain-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insurance-claims-platform-supply-chain-program</guid>
      <pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SLSA v1.1 Framework Update: What's New]]></title>
      <description><![CDATA[SLSA v1.1 sharpens the build track, adds a source track draft, and clarifies attestation semantics. Here is the practical guide for security teams.]]></description>
      <link>https://safeguard.sh/resources/blog/slsa-v1-1-framework-update-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slsa-v1-1-framework-update-review</guid>
      <pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Tool-Call Audit: The Missing AI Observability Layer]]></title>
      <description><![CDATA[Most AI observability stacks log prompts and completions. The actual security signal is in the tool calls. Here is how to capture it.]]></description>
      <link>https://safeguard.sh/resources/blog/tool-call-audit-the-missing-ai-observability-layer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tool-call-audit-the-missing-ai-observability-layer</guid>
      <pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[TPRM Vendor Tiering By Blast Radius Not Spend]]></title>
      <description><![CDATA[Most TPRM programs tier vendors by spend. That misses the vendors who are cheap but catastrophic when they fail. Tiering by blast radius is the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/tpprm-vendor-tiering-by-blast-radius-not-spend</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tpprm-vendor-tiering-by-blast-radius-not-spend</guid>
      <pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Using Reachability To Defend SOC 2 Audit Decisions]]></title>
      <description><![CDATA[An auditor asks why you didn't fix CVE-X. The defensible answer involves reachability evidence. Without it, the conversation gets uncomfortable.]]></description>
      <link>https://safeguard.sh/resources/blog/using-reachability-to-defend-soc2-audit-decisions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/using-reachability-to-defend-soc2-audit-decisions</guid>
      <pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA Security Rule NPRM: Encryption, MFA, and the End of 'Addressable']]></title>
      <description><![CDATA[OCR's December 27, 2024 NPRM removes the addressable/required distinction and mandates encryption, MFA, semi-annual vulnerability scans, and annual penetration tests for ePHI.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-security-rule-2025-nprm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-security-rule-2025-nprm</guid>
      <pubDate>Mon, 30 Mar 2026 11:42:02 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Docker Image File Extensions: What a .tar Image Actually Contains]]></title>
      <description><![CDATA[Docker images do not have a special file extension. When you save one it is a .tar archive. Here is what is inside, and how the OCI layout is structured.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-image-file-extension-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-image-file-extension-explained</guid>
      <pubDate>Mon, 30 Mar 2026 10:21:35 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Container Image Supply Chain: From Dockerfile to Production]]></title>
      <description><![CDATA[Every container pulled in production is a trust decision. Here's how to secure the chain from base image selection through Dockerfile to admission control.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-supply-chain-dockerfile-to-production</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-supply-chain-dockerfile-to-production</guid>
      <pubDate>Mon, 30 Mar 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Command Injection]]></title>
      <description><![CDATA[Command injection lets attackers run OS commands through unsanitized input. Learn how it works, real CVEs like Shellshock and PAN-OS, and how to prevent it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-command-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-command-injection</guid>
      <pubDate>Mon, 30 Mar 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Code Quality Analysis and Security: Why Clean Code Is Safer Code]]></title>
      <description><![CDATA[Code quality analysis and security testing overlap more than teams realize. Here is how measuring quality catches whole classes of vulnerabilities early.]]></description>
      <link>https://safeguard.sh/resources/blog/code-quality-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-quality-analysis</guid>
      <pubDate>Mon, 30 Mar 2026 09:01:09 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[apko and melange: declarative container build tools]]></title>
      <description><![CDATA[How Chainguard's apko and melange replace Dockerfiles with declarative, reproducible builds — and where the security claims need independent verification.]]></description>
      <link>https://safeguard.sh/resources/blog/apko-and-melange-declarative-container-build-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apko-and-melange-declarative-container-build-tools</guid>
      <pubDate>Mon, 30 Mar 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Chrome Extension Cyberhaven Supply Chain Attack 2024]]></title>
      <description><![CDATA[A technical retrospective on the 2024 Cyberhaven Chrome extension compromise: the phishing chain, the malicious OAuth flow, the exfiltration payload, and what actually changes browser-extension supply chain defense.]]></description>
      <link>https://safeguard.sh/resources/blog/chrome-extension-cyberhaven-supply-chain-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chrome-extension-cyberhaven-supply-chain-2024</guid>
      <pubDate>Mon, 30 Mar 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis: Cutting Through CVE Noise to Find What Actually Matters]]></title>
      <description><![CDATA[Why most CVEs in your dependency tree are not exploitable in your application, and how reachability analysis separates real risk from noise.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-reducing-cve-noise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-reducing-cve-noise</guid>
      <pubDate>Mon, 30 Mar 2026 09:00:00 GMT</pubDate>
      <category>Technical</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Security Platforms: What They Actually Do]]></title>
      <description><![CDATA[An open source security platform isn't one tool — it's usually a combination of SCA, license scanning, and vulnerability intelligence stitched into a pipeline that watches your dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-security-platforms-what-they-actually-do</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-security-platforms-what-they-actually-do</guid>
      <pubDate>Mon, 30 Mar 2026 08:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[XXE Fix in Java: How to Harden Every XML Parser]]></title>
      <description><![CDATA[The XXE fix in Java is the same idea across every parser — turn off DOCTYPE and external entities before you feed it untrusted XML. Here are the exact settings for each JDK XML API.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-fix-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-fix-java</guid>
      <pubDate>Mon, 30 Mar 2026 07:40:42 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What is Path Traversal]]></title>
      <description><![CDATA[Path traversal (CWE-22) lets attackers escape a web root using ../ sequences to read or write arbitrary files. Here's how it works, real breaches, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-path-traversal</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-path-traversal</guid>
      <pubDate>Mon, 30 Mar 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security: An Executive Guide for 2025]]></title>
      <description><![CDATA[Software supply chain attacks have surged 742% since 2019. This guide cuts through the noise to explain what executives need to know, what questions to ask, and where to invest.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-executive-guide-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-executive-guide-2025</guid>
      <pubDate>Mon, 30 Mar 2026 06:20:15 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Sigstore, Cosign, and keyless container image signing]]></title>
      <description><![CDATA[How Sigstore's Fulcio and Rekor make Cosign keyless container image signing possible, why Chainguard built its product around it, and where the real gaps still are.]]></description>
      <link>https://safeguard.sh/resources/blog/sigstore-cosign-and-keyless-container-image-signing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sigstore-cosign-and-keyless-container-image-signing</guid>
      <pubDate>Mon, 30 Mar 2026 06:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript SHA256: How to Hash Correctly and Securely]]></title>
      <description><![CDATA[How to compute SHA256 in JavaScript with the Web Crypto API, plus what SHA256 is safe for, what it is not, and the mistakes that turn hashing into a vulnerability.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-sha256</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-sha256</guid>
      <pubDate>Mon, 30 Mar 2026 04:59:49 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What is Directory Traversal]]></title>
      <description><![CDATA[Directory traversal (CWE-22) lets attackers use ../ sequences to read or write files outside a web app's root directory. Here's how it works.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-directory-traversal</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-directory-traversal</guid>
      <pubDate>Mon, 30 Mar 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[@angular-builders/jest: Setup and Dependency Security]]></title>
      <description><![CDATA[@angular-builders/jest lets you run ng test with Jest instead of Karma. Here is how it works, the version-alignment rule that trips teams up, and how to keep its dependency tree secure.]]></description>
      <link>https://safeguard.sh/resources/blog/angular-builders-jest</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/angular-builders-jest</guid>
      <pubDate>Mon, 30 Mar 2026 03:39:22 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Snyk CTF: What Fetch the Flag Is and How to Prepare]]></title>
      <description><![CDATA[The Snyk CTF, branded Fetch the Flag, is a free annual capture-the-flag competition. Here is what the challenges look like and how to get ready for one.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-ctf</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-ctf</guid>
      <pubDate>Mon, 30 Mar 2026 02:18:55 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What is XML External Entity (XXE) Injection]]></title>
      <description><![CDATA[XXE injection lets attackers abuse XML parsers to read files, trigger SSRF, or crash services. Here's how it works, real CVEs, and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-xml-external-entity-xxe-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-xml-external-entity-xxe-injection</guid>
      <pubDate>Mon, 30 Mar 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CVSS v4: What Changed and Why It Matters]]></title>
      <description><![CDATA[CVSS v4 reworks how vulnerability severity is scored, dropping the confusing Scope metric and adding finer-grained inputs. Here is what actually changed from v3.1.]]></description>
      <link>https://safeguard.sh/resources/blog/cvss-v4</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cvss-v4</guid>
      <pubDate>Mon, 30 Mar 2026 00:58:28 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SBOM standards and formats compared (SPDX vs CycloneDX vs...]]></title>
      <description><![CDATA[SPDX, CycloneDX, and Syft JSON aren't interchangeable. A concrete breakdown of what each format is for, where Anchore's Syft defaults, and how Safeguard handles both.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-standards-and-formats-compared-spdx-vs-cyclonedx-vs-syft-json</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-standards-and-formats-compared-spdx-vs-cyclonedx-vs-syft-json</guid>
      <pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Top Software Supply Chain Security Predictions 2026]]></title>
      <description><![CDATA[A senior-engineer set of 2026 predictions for software supply chain security, grounded in current adoption curves, regulatory timelines, and attacker behavior.]]></description>
      <link>https://safeguard.sh/resources/blog/top-software-supply-chain-security-predictions-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-software-supply-chain-security-predictions-2026</guid>
      <pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[URL Validation in JavaScript: Regex Patterns and Safer Options]]></title>
      <description><![CDATA[URL validation regex in JavaScript is tempting but brittle. Here are patterns that work, the ones that cause ReDoS, and why the URL constructor is usually the better tool.]]></description>
      <link>https://safeguard.sh/resources/blog/url-validation-regex-javascript</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/url-validation-regex-javascript</guid>
      <pubDate>Sun, 29 Mar 2026 23:38:02 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[WAF SQL Injection Protection: What It Catches and What It Misses]]></title>
      <description><![CDATA[A WAF can block many SQL injection attempts at the edge, but treating it as your only defense is how breaches happen. Here is what WAF SQL injection rules actually do.]]></description>
      <link>https://safeguard.sh/resources/blog/waf-sql-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/waf-sql-injection</guid>
      <pubDate>Sun, 29 Mar 2026 22:17:35 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to Check a Website for Vulnerabilities: A Practical Guide]]></title>
      <description><![CDATA[A hands-on walkthrough of how to check a website for vulnerabilities, from passive header checks to authenticated dynamic scanning, and how to read the results.]]></description>
      <link>https://safeguard.sh/resources/blog/check-website-for-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/check-website-for-vulnerabilities</guid>
      <pubDate>Sun, 29 Mar 2026 20:57:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[python-multipart Security: Patching the Form-Data DoS]]></title>
      <description><![CDATA[Why the python-multipart parser behind FastAPI and Starlette had a denial-of-service flaw, how to check your version, and how to keep form uploads safe.]]></description>
      <link>https://safeguard.sh/resources/blog/python-multipart</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-multipart</guid>
      <pubDate>Sun, 29 Mar 2026 19:36:42 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[DAST Definition: What Dynamic Application Security Testing Means]]></title>
      <description><![CDATA[The DAST definition in one line: testing a running application from the outside by sending real requests to find exploitable vulnerabilities. Here is what that means in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-definition</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-definition</guid>
      <pubDate>Sun, 29 Mar 2026 18:16:15 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Set Up a Secure Source Code Repository]]></title>
      <description><![CDATA[What makes a source code repository secure, from access control and secret scanning to branch protection and dependency review, with practical defaults.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-source-code-repository</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-source-code-repository</guid>
      <pubDate>Sun, 29 Mar 2026 16:55:48 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to Use Git Branch (and git checkout) Safely]]></title>
      <description><![CDATA[A working reference for creating, switching, and checking out Git branches, plus the security habits that keep secrets and bad commits out of your history.]]></description>
      <link>https://safeguard.sh/resources/blog/git-branch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-branch</guid>
      <pubDate>Sun, 29 Mar 2026 15:35:22 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-53521 in F5 BIG-IP APM: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[F5 BIG-IP APM bug reclassified from DoS to RCE at CVSS 9.8 and landed on CISA KEV. Defender playbook for the late-cycle severity surprise.]]></description>
      <link>https://safeguard.sh/resources/blog/f5-big-ip-cve-2025-53521-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/f5-big-ip-cve-2025-53521-patch-response</guid>
      <pubDate>Sun, 29 Mar 2026 15:00:00 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[serverless-webpack: Secure Bundling for Lambda Functions]]></title>
      <description><![CDATA[serverless-webpack bundles your Lambda handlers with Webpack so each function ships only the code it needs. Here is how it works and the supply chain risks to watch when you adopt it.]]></description>
      <link>https://safeguard.sh/resources/blog/serverless-webpack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/serverless-webpack</guid>
      <pubDate>Sun, 29 Mar 2026 14:14:55 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[RSAC 2026's Five Most Dangerous Attack Techniques: Every One Now Runs on AI]]></title>
      <description><![CDATA[For the first time in the history of the SANS keynote, all five of the most dangerous new attack techniques carry an AI dimension — from AI-generated zero-days to your vendor's vendor's vendor. Here's the honest breakdown, plus what defenders should actually do.]]></description>
      <link>https://safeguard.sh/resources/blog/rsac-2026-five-most-dangerous-attack-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rsac-2026-five-most-dangerous-attack-techniques</guid>
      <pubDate>Sun, 29 Mar 2026 13:00:00 GMT</pubDate>
      <category>Industry Events</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What Does CWE Stand For? Common Weakness Enumeration Explained]]></title>
      <description><![CDATA[CWE stands for Common Weakness Enumeration, a community catalog of software and hardware weakness types. Here is what it is and how it differs from CVE.]]></description>
      <link>https://safeguard.sh/resources/blog/what-does-cwe-stand-for</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-does-cwe-stand-for</guid>
      <pubDate>Sun, 29 Mar 2026 12:54:28 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Citrix Bleed 2 Implications: What CVE-2024-6235 Means for NetScaler Operators]]></title>
      <description><![CDATA[CVE-2024-6235 was the followup to the original Citrix Bleed and exposed sensitive data from NetScaler ADC and Gateway appliances. The technical details and what changes.]]></description>
      <link>https://safeguard.sh/resources/blog/citrix-bleed-2-cve-2024-6235-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/citrix-bleed-2-cve-2024-6235-implications</guid>
      <pubDate>Sun, 29 Mar 2026 12:15:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[CMMC 2.0 Rollout: Where Deadlines Actually Are]]></title>
      <description><![CDATA[A senior engineer's guide to where CMMC 2.0 deadlines actually sit in 2026, what assessors are looking for, and how supply chain controls fit into the certification path.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-2-rollout-where-the-deadlines-actually-are</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-2-rollout-where-the-deadlines-actually-are</guid>
      <pubDate>Sun, 29 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CycloneDX vs SPDX: Which Format For Your Program]]></title>
      <description><![CDATA[A senior-engineer comparison of CycloneDX and SPDX in 2026, covering field coverage, tooling, AI-BOM support, VEX, and the practical trade-offs for your programme.]]></description>
      <link>https://safeguard.sh/resources/blog/cyclonedx-vs-spdx-which-format-for-your-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyclonedx-vs-spdx-which-format-for-your-program</guid>
      <pubDate>Sun, 29 Mar 2026 12:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[PCI DSS 4.0 Software Security Evidence Flow]]></title>
      <description><![CDATA[PCI DSS 4.0 raises the bar for software security and supplier oversight. Learn how to satisfy Requirement 6 and 12.8 with continuous supply chain evidence.]]></description>
      <link>https://safeguard.sh/resources/blog/pci-dss-4-software-security-evidence-flow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pci-dss-4-software-security-evidence-flow</guid>
      <pubDate>Sun, 29 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Pod Supply Chain Attestation Validation]]></title>
      <description><![CDATA[How to validate supply chain attestations at pod admission time without grinding deployments to a halt: which attestation types actually matter, how to chain verifications, and how to fail useful.]]></description>
      <link>https://safeguard.sh/resources/blog/pod-supply-chain-attestation-validation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pod-supply-chain-attestation-validation</guid>
      <pubDate>Sun, 29 Mar 2026 12:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Purple Team Exercises With Supply Chain Focus]]></title>
      <description><![CDATA[Most purple team exercises stop at the perimeter. A supply-chain-focused exercise probes the dependency graph, the build pipeline, and the trust assumptions in your SBOM.]]></description>
      <link>https://safeguard.sh/resources/blog/purple-team-exercises-supply-chain-focus</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/purple-team-exercises-supply-chain-focus</guid>
      <pubDate>Sun, 29 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Transitive Dependency Fix Cascades, Managed]]></title>
      <description><![CDATA[Fixing a transitive dependency is rarely a single bump. It is a cascade. Here is how to manage those cascades without flooding reviewers or breaking builds.]]></description>
      <link>https://safeguard.sh/resources/blog/transitive-dependency-fix-cascades-managed</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/transitive-dependency-fix-cascades-managed</guid>
      <pubDate>Sun, 29 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Using EJS on npm Safely: CVE-2022-29078 and Beyond]]></title>
      <description><![CDATA[The ejs npm package is a capable template engine that has also been the subject of a serious RCE advisory. Here is how to use it without opening that door.]]></description>
      <link>https://safeguard.sh/resources/blog/ejs-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ejs-npm</guid>
      <pubDate>Sun, 29 Mar 2026 11:34:02 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[react-native-asset: A Security Guide to Linking Assets]]></title>
      <description><![CDATA[react-native-asset links fonts, sound files, and other assets into iOS and Android builds. Here is how it works and the supply-chain hygiene it deserves.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-asset</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-asset</guid>
      <pubDate>Sun, 29 Mar 2026 10:13:35 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What is Insecure Deserialization]]></title>
      <description><![CDATA[Insecure deserialization (CWE-502) lets attackers turn untrusted object data into remote code execution. Here's how the attack works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-insecure-deserialization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-insecure-deserialization</guid>
      <pubDate>Sun, 29 Mar 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Anchore vs. Snyk / Wiz / Sysdig / Aqua / Chainguard posit...]]></title>
      <description><![CDATA[Evaluating Anchore alternatives? See how Safeguard, Snyk, Wiz, Sysdig, Aqua, and Chainguard actually differ on SBOM, runtime, and compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/anchore-vs-snyk-wiz-sysdig-aqua-chainguard-positioning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anchore-vs-snyk-wiz-sysdig-aqua-chainguard-positioning</guid>
      <pubDate>Sun, 29 Mar 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Side-Channel Attacks 2025]]></title>
      <description><![CDATA[Side-channel attacks are moving from hardware into software supply chains, where build-time timing, error messages, and telemetry leak meaningful secrets.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-side-channel-attacks-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-side-channel-attacks-2025</guid>
      <pubDate>Sun, 29 Mar 2026 09:00:00 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Website Scanners, Web Scanners, and URL Scanners: What's the Difference]]></title>
      <description><![CDATA[Website scanner, web scanner, and URL scanner are often used interchangeably, but they can mean very different depth of analysis depending on the vendor. Here's how to tell them apart.]]></description>
      <link>https://safeguard.sh/resources/blog/website-scanners-vs-web-scanners-vs-url-scanners</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/website-scanners-vs-web-scanners-vs-url-scanners</guid>
      <pubDate>Sun, 29 Mar 2026 08:53:08 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Public Cloud Security: A Practical Guide to Protecting Workloads]]></title>
      <description><![CDATA[Public cloud security is a shared responsibility, and most breaches trace back to the customer's half of that split rather than a failure by the cloud provider.]]></description>
      <link>https://safeguard.sh/resources/blog/public-cloud-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/public-cloud-security</guid>
      <pubDate>Sun, 29 Mar 2026 07:32:41 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What is a Buffer Overflow]]></title>
      <description><![CDATA[Buffer overflows have powered exploits from the 1988 Morris Worm to WannaCry. Here's how they work, why they persist, and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-buffer-overflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-buffer-overflow</guid>
      <pubDate>Sun, 29 Mar 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[core-js 2.6.12: Vulnerabilities, EOL Status, and Upgrading to v3]]></title>
      <description><![CDATA[Searching for core-js 2.6.12 vulnerabilities turns up no CVEs — the finding is the abandoned v2 line itself. What the deprecation actually means and how to migrate to core-js 3 cleanly.]]></description>
      <link>https://safeguard.sh/resources/blog/core-js-2-6-12-vulnerabilities-and-upgrade</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/core-js-2-6-12-vulnerabilities-and-upgrade</guid>
      <pubDate>Sun, 29 Mar 2026 06:12:15 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What is a Software Bill of Materials (SBOM) — definitions...]]></title>
      <description><![CDATA[What is an SBOM? A plain-language breakdown of definitions, contents, formats (SPDX vs CycloneDX), compliance drivers, and real use cases like Log4Shell and xz-utils.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-software-bill-of-materials-sbom-definitions-contents-use-cases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-software-bill-of-materials-sbom-definitions-contents-use-cases</guid>
      <pubDate>Sun, 29 Mar 2026 06:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Download Python for Mac (Safely)]]></title>
      <description><![CDATA[There are several ways to download Python for Mac. Here is how to pick the right one and verify what you install so you don't get a tampered interpreter.]]></description>
      <link>https://safeguard.sh/resources/blog/download-python-for-mac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/download-python-for-mac</guid>
      <pubDate>Sun, 29 Mar 2026 04:51:48 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What is a Denial of Service (DoS) Attack]]></title>
      <description><![CDATA[DoS attacks knock systems offline without stealing data. Learn how they work, real-world examples like Mirai and HTTP/2 Rapid Reset, and how to defend against them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-denial-of-service-dos-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-denial-of-service-dos-attack</guid>
      <pubDate>Sun, 29 Mar 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Free SAST Tools: The Best Open Source Scanners to Start With]]></title>
      <description><![CDATA[The best free SAST tools include Semgrep, CodeQL, Bandit, and gosec. Here is what each one is good at and how to assemble a no-cost static analysis stack that actually catches bugs.]]></description>
      <link>https://safeguard.sh/resources/blog/free-sast-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/free-sast-tools</guid>
      <pubDate>Sun, 29 Mar 2026 03:31:21 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to generate an SBOM with free open source tools]]></title>
      <description><![CDATA[Free tools like Syft and Trivy can generate an SBOM in minutes. Here's exactly how, where open source tooling stops scaling, and how Safeguard fills the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-generate-an-sbom-with-free-open-source-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-generate-an-sbom-with-free-open-source-tools</guid>
      <pubDate>Sun, 29 Mar 2026 03:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Configure a Git SSH Key Safely]]></title>
      <description><![CDATA[Setting up a Git SSH key gives you secure, password-free authentication. Here is how to generate one, configure Git, and avoid the common security mistakes.]]></description>
      <link>https://safeguard.sh/resources/blog/git-config-ssh-key</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-config-ssh-key</guid>
      <pubDate>Sun, 29 Mar 2026 02:10:55 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What is a DDoS Attack]]></title>
      <description><![CDATA[A DDoS attack floods systems with botnet traffic until they collapse. See real Tbps records, the Rapid Reset CVE, and how to detect and mitigate one.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-ddos-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-ddos-attack</guid>
      <pubDate>Sun, 29 Mar 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[GitLab CI/CD Security Hardening for 2025]]></title>
      <description><![CDATA[A practical hardening playbook for GitLab 17.8 covering runner isolation, OIDC federation, CI variable scoping, and protected branch enforcement.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-cicd-security-hardening-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-cicd-security-hardening-2025</guid>
      <pubDate>Sun, 29 Mar 2026 00:50:28 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM automation from creation to scanning & analysis]]></title>
      <description><![CDATA[SBOM generation alone isn't enough. See how continuous SBOM automation — from creation to scanning and analysis — closes the gaps left by point-in-time tools.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-automation-from-creation-to-scanning-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-automation-from-creation-to-scanning-analysis</guid>
      <pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE Vulnerability Database: How the CVE and NVD System Actually Works]]></title>
      <description><![CDATA[What the CVE vulnerability database is, how MITRE and the NVD divide the work, what a CVE record contains, and how to use it without drowning in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-vulnerability-database</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-vulnerability-database</guid>
      <pubDate>Sat, 28 Mar 2026 23:30:01 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Are the Different Types of Licenses in Software? A Security View]]></title>
      <description><![CDATA[The different types of licenses in software fall into a few families - permissive, copyleft, weak copyleft, and proprietary - and each carries distinct legal and supply chain obligations.]]></description>
      <link>https://safeguard.sh/resources/blog/different-types-of-licenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/different-types-of-licenses</guid>
      <pubDate>Sat, 28 Mar 2026 22:09:35 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[MCP Protocol Security: What the Model Context Protocol Means for Supply Chains]]></title>
      <description><![CDATA[Anthropic's Model Context Protocol standardizes how AI models interact with external tools. The security implications for software supply chains are significant.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-protocol-security-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-protocol-security-implications</guid>
      <pubDate>Sat, 28 Mar 2026 20:49:08 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Juniper Router CVE-2025-21589: Authentication Bypass That Puts Network Perimeters at Risk]]></title>
      <description><![CDATA[A critical authentication bypass in Juniper's Session Smart Router lets remote attackers hijack admin sessions. Here's what happened, why it matters, and what to do.]]></description>
      <link>https://safeguard.sh/resources/blog/juniper-router-cve-2025-21589-auth-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/juniper-router-cve-2025-21589-auth-bypass</guid>
      <pubDate>Sat, 28 Mar 2026 19:28:41 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-22234: The Spring Security Access Control Bypass Explained]]></title>
      <description><![CDATA[CVE-2024-22234 is a broken access control flaw in Spring Security where isFullyAuthenticated returns true for a null authentication. Here is how it works and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-22234</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-22234</guid>
      <pubDate>Sat, 28 Mar 2026 18:08:15 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Qilin Ransomware Group: Dissecting a Rising Threat Actor]]></title>
      <description><![CDATA[Qilin has rapidly become one of the most active ransomware operations, targeting healthcare, manufacturing, and critical infrastructure. A technical breakdown of their methods.]]></description>
      <link>https://safeguard.sh/resources/blog/qilin-ransomware-group-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/qilin-ransomware-group-analysis</guid>
      <pubDate>Sat, 28 Mar 2026 16:47:48 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[npm dd-trace: Security Review and Safe Usage]]></title>
      <description><![CDATA[The npm dd-trace package is Datadog's Node.js APM tracer. It runs deep in your process, so here is an honest look at its security posture and how to deploy it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-dd-trace</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-dd-trace</guid>
      <pubDate>Sat, 28 Mar 2026 15:27:21 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Apache Struts 2 Vulnerability History: The RCE Flaws You Must Patch]]></title>
      <description><![CDATA[Apache Struts 2 vulnerabilities have caused some of the largest breaches on record. Here is the CVE lineage, why the same flaw keeps recurring, and how to detect it.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-struts-2-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-struts-2-vulnerability</guid>
      <pubDate>Sat, 28 Mar 2026 14:06:54 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[RSAC 2026: Agentic AI, Shadow Tools, and the Quiet Return to the Endpoint]]></title>
      <description><![CDATA[Agentic AI dominated RSA Conference 2026, but the harder story was shadow AI agents running unseen inside enterprises and a renewed scramble to secure the endpoint they live on.]]></description>
      <link>https://safeguard.sh/resources/blog/rsac-2026-agentic-ai-shadow-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rsac-2026-agentic-ai-shadow-tools</guid>
      <pubDate>Sat, 28 Mar 2026 13:00:00 GMT</pubDate>
      <category>Industry Events</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Package Vulnerability Scanner and How Do You Pick One?]]></title>
      <description><![CDATA[A package vulnerability scanner checks your dependencies against known-CVE databases so you catch risky libraries before they ship. Here is how they work and what separates a good one.]]></description>
      <link>https://safeguard.sh/resources/blog/package-vulnerability-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/package-vulnerability-scanner</guid>
      <pubDate>Sat, 28 Mar 2026 12:46:28 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Scaling Across Repos: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Multi-repo security reasoning is a graph problem, not a retrieval problem. How Griffin AI's engine scales where pure-LLM products flatten into guesswork.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-multi-repo-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-multi-repo-scale</guid>
      <pubDate>Sat, 28 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Lifecycle Management Patterns]]></title>
      <description><![CDATA[Patterns for managing MCP servers through development, staging, rollout, and deprecation — with an eye on the security gaps that appear at each transition.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-lifecycle-management-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-lifecycle-management-patterns</guid>
      <pubDate>Sat, 28 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Halliburton RansomHub Attack: $35M Loss in Oilfield Services]]></title>
      <description><![CDATA[RansomHub encrypted Halliburton systems on August 21, 2024, exfiltrated proprietary oilfield data, and contributed to a $35M direct response cost disclosed in the company's Q3 10-Q.]]></description>
      <link>https://safeguard.sh/resources/blog/halliburton-ransomhub-energy-sector-breach-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/halliburton-ransomhub-energy-sector-breach-2024</guid>
      <pubDate>Sat, 28 Mar 2026 11:26:01 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Tern SBOM Generation Walkthrough for 2026]]></title>
      <description><![CDATA[A walkthrough of generating SBOMs with Tern in 2026, covering layer-by-layer inspection, CycloneDX output, and practical comparison with Syft.]]></description>
      <link>https://safeguard.sh/resources/blog/tern-sbom-generation-walkthrough-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tern-sbom-generation-walkthrough-2026</guid>
      <pubDate>Sat, 28 Mar 2026 11:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Hritik Sharma)</author>
    </item>
    <item>
      <title><![CDATA[Microsoft Power Pages CVE-2025-24989: Privilege Escalation in Low-Code Platforms]]></title>
      <description><![CDATA[Microsoft patched an actively exploited privilege escalation vulnerability in Power Pages, its low-code web platform. The flaw allowed unauthorized users to gain elevated access within affected sites.]]></description>
      <link>https://safeguard.sh/resources/blog/microsoft-power-pages-cve-2025-24989</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microsoft-power-pages-cve-2025-24989</guid>
      <pubDate>Sat, 28 Mar 2026 10:05:34 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is a Man-in-the-Middle Attack]]></title>
      <description><![CDATA[A man-in-the-middle attack lets adversaries intercept trusted connections -- from Wi-Fi logins to CI/CD package fetches -- with real-world cases and defenses.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-man-in-the-middle-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-man-in-the-middle-attack</guid>
      <pubDate>Sat, 28 Mar 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Fine-Tune Backdoor Insertion: Academic Research]]></title>
      <description><![CDATA[A senior engineer's review of academic research on fine-tune backdoor insertion, from BadNets to sleeper agents, and how the findings translate to production ML.]]></description>
      <link>https://safeguard.sh/resources/blog/fine-tune-backdoor-insertion-academic-research</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fine-tune-backdoor-insertion-academic-research</guid>
      <pubDate>Sat, 28 Mar 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Flax Typhoon Residential Proxy Supply Chain 2024]]></title>
      <description><![CDATA[Flax Typhoon's Raptor Train botnet turned consumer IoT into a state-aligned proxy network. Here is the tradecraft, the takedown, and the supply chain lessons.]]></description>
      <link>https://safeguard.sh/resources/blog/flax-typhoon-residential-proxy-supply-chain-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/flax-typhoon-residential-proxy-supply-chain-2024</guid>
      <pubDate>Sat, 28 Mar 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Incident Response for Supply Chain Attacks: A 2026 Playbook]]></title>
      <description><![CDATA[A practical incident response playbook tailored for supply chain compromises — from initial detection through containment, eradication, and lessons learned.]]></description>
      <link>https://safeguard.sh/resources/blog/incident-response-supply-chain-playbook-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/incident-response-supply-chain-playbook-2026</guid>
      <pubDate>Sat, 28 Mar 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Jenkins Supply Chain Security Baseline 2026]]></title>
      <description><![CDATA[A 2026 supply chain security baseline for Jenkins: plugin hygiene, agent isolation, Pipeline-as-Code discipline, credentials, and provenance integration.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-supply-chain-security-baseline-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-supply-chain-security-baseline-2026</guid>
      <pubDate>Sat, 28 Mar 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Tackling SBOM sprawl across an organization]]></title>
      <description><![CDATA[SBOM generation has outpaced SBOM management. Here's why sprawl happens, what it costs in incident response and audits, and how to consolidate it for good.]]></description>
      <link>https://safeguard.sh/resources/blog/tackling-sbom-sprawl-across-an-organization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tackling-sbom-sprawl-across-an-organization</guid>
      <pubDate>Sat, 28 Mar 2026 09:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Software Development Life Cycle Security: Building Security Into Every SDLC Phase]]></title>
      <description><![CDATA[Software development life cycle security means every phase carries a security activity, not a scan bolted on at the end. Here is what belongs in each stage of the SDLC.]]></description>
      <link>https://safeguard.sh/resources/blog/software-development-life-cycle-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-development-life-cycle-security</guid>
      <pubDate>Sat, 28 Mar 2026 08:45:08 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Static Code Scanning Tools: How to Choose and Use Them]]></title>
      <description><![CDATA[Static code scanning tools read your source without running it to find bugs and security flaws. Here is how they work, where they fall short, and how to pick one.]]></description>
      <link>https://safeguard.sh/resources/blog/static-code-scanning-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-code-scanning-tools</guid>
      <pubDate>Sat, 28 Mar 2026 07:24:41 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Privilege Escalation]]></title>
      <description><![CDATA[Privilege escalation turns a minor foothold into a full breach. Learn the techniques, real-world examples, and how to detect and stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-privilege-escalation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-privilege-escalation</guid>
      <pubDate>Sat, 28 Mar 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Python tracemalloc: Finding Memory Leaks and Why It Matters for Security]]></title>
      <description><![CDATA[How to use Python tracemalloc to trace memory allocations, hunt leaks, and understand why unbounded memory growth is a real availability risk.]]></description>
      <link>https://safeguard.sh/resources/blog/python-tracemalloc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-tracemalloc</guid>
      <pubDate>Sat, 28 Mar 2026 06:04:14 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SBOM GitHub Action / dropping SBOM tooling into CI workflows]]></title>
      <description><![CDATA[Adding an SBOM GitHub Action like Anchore's is easy; making the output useful isn't. Here's what breaks in real CI pipelines and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-github-action-dropping-sbom-tooling-into-ci-workflows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-github-action-dropping-sbom-tooling-into-ci-workflows</guid>
      <pubDate>Sat, 28 Mar 2026 06:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Detection: How Scanners Actually Find It]]></title>
      <description><![CDATA[SQL injection detected in a scan report can mean very different things depending on whether it came from a static trace or a live dynamic test — here's how each actually works.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-detection-how-scanners-find-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-detection-how-scanners-find-it</guid>
      <pubDate>Sat, 28 Mar 2026 04:43:48 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Broken Access Control]]></title>
      <description><![CDATA[Broken access control is OWASP's #1 web risk, found in 94% of apps tested. See how IDOR flaws breached First American, USPS, and Parler.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-broken-access-control</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-broken-access-control</guid>
      <pubDate>Sat, 28 Mar 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Node.js Vulnerabilities: Tracking and Patching at Scale]]></title>
      <description><![CDATA[How to actually keep up with Node.js vulnerabilities across dozens of services — where advisories come from, what to automate, and what still needs a human.]]></description>
      <link>https://safeguard.sh/resources/blog/node-js-vulnerabilities-tracking-and-patching</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-js-vulnerabilities-tracking-and-patching</guid>
      <pubDate>Sat, 28 Mar 2026 03:23:21 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How Syft scans software to generate SBOMs (under-the-hood...]]></title>
      <description><![CDATA[A deep look at Syft's under-the-hood scanning mechanics — catalogers, binary classifiers, layer squashing, and SBOM formats — and where the single-scan model breaks down at fleet scale.]]></description>
      <link>https://safeguard.sh/resources/blog/how-syft-scans-software-to-generate-sboms-under-the-hood-mechanics</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-syft-scans-software-to-generate-sboms-under-the-hood-mechanics</guid>
      <pubDate>Sat, 28 Mar 2026 03:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Why Python's eval() Is Dangerous and What to Use Instead]]></title>
      <description><![CDATA[Python eval() runs arbitrary code, and feeding it untrusted input is a remote code execution bug waiting to happen. Here's the risk, how the exploit works conceptually, and safer alternatives.]]></description>
      <link>https://safeguard.sh/resources/blog/python-eval</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-eval</guid>
      <pubDate>Sat, 28 Mar 2026 02:02:54 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What is Insecure Direct Object Reference (IDOR)]]></title>
      <description><![CDATA[IDOR lets attackers access other users data just by changing an ID in a URL or API call. Learn how it works, real breaches, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-insecure-direct-object-reference-idor</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-insecure-direct-object-reference-idor</guid>
      <pubDate>Sat, 28 Mar 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[aws-cdk-lib on npm: Security Review and Safe Usage]]></title>
      <description><![CDATA[aws-cdk-lib is the single monolithic package for AWS CDK v2. Its size and its role as infrastructure code make dependency hygiene and construct review the real security work.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-cdk-lib-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-cdk-lib-npm</guid>
      <pubDate>Sat, 28 Mar 2026 00:42:28 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Container Security? (definition, lifecycle, threats)]]></title>
      <description><![CDATA[Container security spans build, ship, and runtime: scanning, SBOMs, Kubernetes hardening, and runtime detection. How it works, and where Anchore leaves gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-container-security-definition-lifecycle-threats</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-container-security-definition-lifecycle-threats</guid>
      <pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Canadian Cyber Centre Supply Chain Guidance]]></title>
      <description><![CDATA[The CCCS's 2024-2025 supply chain guidance and Bill C-26 reshape Canada's expectations for SBOMs, vendor assurance, and protection of critical cyber systems.]]></description>
      <link>https://safeguard.sh/resources/blog/canadian-cyber-center-supply-chain-guidance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/canadian-cyber-center-supply-chain-guidance</guid>
      <pubDate>Fri, 27 Mar 2026 23:22:01 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is IaC in Cyber Security? Risks, Scanning, and Best Practices]]></title>
      <description><![CDATA[Infrastructure as Code turns your cloud setup into version-controlled files, which is powerful and dangerous in equal measure. Here is what IaC means for security teams.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-iac-in-cyber-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-iac-in-cyber-security</guid>
      <pubDate>Fri, 27 Mar 2026 22:01:34 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm Commands: A Security-Focused Guide to Safe Usage]]></title>
      <description><![CDATA[The npm commands you run every day have security consequences. Here is a practical npm commands list with the safe way to use each one.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-commands</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-commands</guid>
      <pubDate>Fri, 27 Mar 2026 20:41:07 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Fixing XXE in Java: A Parser-by-Parser Hardening Guide]]></title>
      <description><![CDATA[A parser-by-parser XXE fix for Java, covering DocumentBuilderFactory, SAXParser, XMLInputFactory, TransformerFactory, and the XML libraries that still ship unsafe defaults.]]></description>
      <link>https://safeguard.sh/resources/blog/fixing-xxe-in-java-parser-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fixing-xxe-in-java-parser-hardening</guid>
      <pubDate>Fri, 27 Mar 2026 19:20:41 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Types of Software License Agreements: A Practical Map]]></title>
      <description><![CDATA[A working map of the types of software license agreements you will actually encounter, from proprietary EULAs to copyleft open source, and what each one obligates you to do.]]></description>
      <link>https://safeguard.sh/resources/blog/types-of-software-license-agreements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/types-of-software-license-agreements</guid>
      <pubDate>Fri, 27 Mar 2026 18:00:14 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Product Security Assessment? A Practical Guide]]></title>
      <description><![CDATA[A product security assessment is a structured evaluation of a product's design, code, dependencies, and deployment for exploitable weakness. Here is how to run one that finds real risk.]]></description>
      <link>https://safeguard.sh/resources/blog/product-security-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/product-security-assessment</guid>
      <pubDate>Fri, 27 Mar 2026 16:39:47 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Choosing an npm XML Parser: Security Comparison and XXE Pitfalls]]></title>
      <description><![CDATA[Not every npm XML parser carries the same risk. We compare xml2js, fast-xml-parser, sax, and libxmljs on their CVE history, XXE exposure, and safe configuration.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-xml-parser-security-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-xml-parser-security-comparison</guid>
      <pubDate>Fri, 27 Mar 2026 15:19:21 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is Malicious Code in Cyber Security? Types, Detection, and Defense]]></title>
      <description><![CDATA[Malicious code is any software written to harm a system or its users. Here is how the main families work, where they hide in modern supply chains, and how to catch them.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-code-in-cyber-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-code-in-cyber-security</guid>
      <pubDate>Fri, 27 Mar 2026 13:58:54 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Agentic AI Security Took Over RSAC 2026, Even as 'The Power of Community' Was the Theme]]></title>
      <description><![CDATA[RSAC 2026 sold itself on community for its 35th year, but the real story was an agentic-AI reckoning: autonomous agents that act, get phished, and now beat most humans at capture-the-flag. Here is what actually mattered.]]></description>
      <link>https://safeguard.sh/resources/blog/rsac-2026-recap-power-of-community</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rsac-2026-recap-power-of-community</guid>
      <pubDate>Fri, 27 Mar 2026 13:00:00 GMT</pubDate>
      <category>Industry Events</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Cross-Site Request Forgery Vulnerability?]]></title>
      <description><![CDATA[A cross-site request forgery vulnerability tricks a logged-in user's browser into sending unwanted requests. Here is how it works and how to shut it down.]]></description>
      <link>https://safeguard.sh/resources/blog/cross-site-request-forgery-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cross-site-request-forgery-vulnerability</guid>
      <pubDate>Fri, 27 Mar 2026 12:38:27 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Container Image Vulnerability Scanning in CI]]></title>
      <description><![CDATA[How to wire container image vulnerability scanning into your CI pipeline so builds fail on real risk instead of shipping unscanned images to production.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-vulnerability-scanning-in-ci</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-vulnerability-scanning-in-ci</guid>
      <pubDate>Fri, 27 Mar 2026 11:18:01 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Best Secrets Detection Tools: 2026 Buyer's Guide]]></title>
      <description><![CDATA[A field comparison of the best secrets detection tools in 2026 across precision, secret variety, and CI integration for teams hardening their supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/best-secrets-detection-tools-buyer-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-secrets-detection-tools-buyer-guide-2026</guid>
      <pubDate>Fri, 27 Mar 2026 11:15:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Detect Dependency Confusion Attacks Before They Ship]]></title>
      <description><![CDATA[Dependency confusion still works in 2026 because teams keep missing the same three controls. Here's how to detect and block it in npm, pip, and Maven.]]></description>
      <link>https://safeguard.sh/resources/blog/detect-dependency-confusion-before-it-ships</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/detect-dependency-confusion-before-it-ships</guid>
      <pubDate>Fri, 27 Mar 2026 10:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Server-Side Template Injection (SSTI)]]></title>
      <description><![CDATA[SSTI lets attackers turn untrusted input into executable template code, often leading to full remote code execution — here's how it works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-server-side-template-injection-ssti</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-server-side-template-injection-ssti</guid>
      <pubDate>Fri, 27 Mar 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[follow-redirects: Known Vulnerabilities and How to Stay Patched]]></title>
      <description><![CDATA[follow-redirects sits under axios in millions of Node apps. A practical guide to its CVE history and how to keep the pinned version current.]]></description>
      <link>https://safeguard.sh/resources/blog/follow-redirects-npm-vulnerabilities-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/follow-redirects-npm-vulnerabilities-guide</guid>
      <pubDate>Fri, 27 Mar 2026 09:57:34 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Tenable vs Qualys Vulnerability Management 2026]]></title>
      <description><![CDATA[The two giants of vulnerability management have evolved past their network-scanner roots. A clear-eyed comparison of scan accuracy, exposure management, and cloud coverage in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/tenable-vs-qualys-vulnerability-management-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tenable-vs-qualys-vulnerability-management-2026</guid>
      <pubDate>Fri, 27 Mar 2026 09:30:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[AI Cybersecurity Companies and Vendors: The Landscape]]></title>
      <description><![CDATA[AI cybersecurity companies split into three distinct groups doing very different work, and confusing them is the fastest way to buy the wrong tool.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-cybersecurity-companies-and-vendors-landscape</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-cybersecurity-companies-and-vendors-landscape</guid>
      <pubDate>Fri, 27 Mar 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[ASPM Security: Application Security Posture Management Explained]]></title>
      <description><![CDATA[ASPM doesn't scan anything new — it aggregates and prioritizes findings your existing SAST, DAST, and SCA tools already produce, which is exactly the problem most AppSec teams actually have.]]></description>
      <link>https://safeguard.sh/resources/blog/aspm-security-application-security-posture-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aspm-security-application-security-posture-management</guid>
      <pubDate>Fri, 27 Mar 2026 09:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Git Aliases: Faster Workflows Without Sacrificing Security]]></title>
      <description><![CDATA[Git aliases save keystrokes, but a careless one can hide destructive commands or leak secrets. Here are the aliases worth setting and the ones to think twice about.]]></description>
      <link>https://safeguard.sh/resources/blog/git-aliases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-aliases</guid>
      <pubDate>Fri, 27 Mar 2026 08:37:07 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[typescript-plugin-css-modules: A Dev Dependency Security Guide]]></title>
      <description><![CDATA[typescript-plugin-css-modules gives you typed CSS Modules imports. Here is what it does, why build-time dev tooling is part of your supply chain, and how to keep it safe.]]></description>
      <link>https://safeguard.sh/resources/blog/typescript-plugin-css-modules</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/typescript-plugin-css-modules</guid>
      <pubDate>Fri, 27 Mar 2026 07:16:41 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is LDAP Injection]]></title>
      <description><![CDATA[LDAP injection lets attackers manipulate directory queries to bypass authentication or dump directory data. Here's how it works, real CVEs, and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-ldap-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-ldap-injection</guid>
      <pubDate>Fri, 27 Mar 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Docker image security fundamentals (quick-start guide)]]></title>
      <description><![CDATA[A practical guide to docker image security: how vulnerabilities hide in base images, common misconfigurations, how scanning works, and a five-step quick-start checklist.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-image-security-fundamentals-quick-start-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-image-security-fundamentals-quick-start-guide</guid>
      <pubDate>Fri, 27 Mar 2026 06:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Bootstrapping a Secure Website Scan Workflow on a Budget]]></title>
      <description><![CDATA[A small team can build a real scanning habit with zero budget — the trick is turning one-off checks into a repeatable workflow before traffic (and risk) grows.]]></description>
      <link>https://safeguard.sh/resources/blog/bootstrapping-a-secure-website-scan-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bootstrapping-a-secure-website-scan-workflow</guid>
      <pubDate>Fri, 27 Mar 2026 05:56:14 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Rebuilding Docker Images: Cache, Patching, and Reproducibility]]></title>
      <description><![CDATA[A plain docker build reuses cached layers and silently skips your security patches. Here is how the cache actually works, how to force a real rebuild, and how to keep rebuilds reproducible.]]></description>
      <link>https://safeguard.sh/resources/blog/rebuilding-docker-images-cache-patching</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rebuilding-docker-images-cache-patching</guid>
      <pubDate>Fri, 27 Mar 2026 04:35:47 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What is NoSQL Injection]]></title>
      <description><![CDATA[NoSQL injection lets attackers bypass logins or run code using MongoDB operators like $ne and $where. See real CVEs, examples, and effective defenses.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-nosql-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-nosql-injection</guid>
      <pubDate>Fri, 27 Mar 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Container Image Digests vs Tags: Why Pinning Matters]]></title>
      <description><![CDATA[A tag is a mutable pointer; a digest is the image. Pinning by digest is the difference between deploying what you tested and deploying whatever the registry says today.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-digests-vs-tags-why-pinning-matters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-digests-vs-tags-why-pinning-matters</guid>
      <pubDate>Fri, 27 Mar 2026 03:15:20 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Priya Raman)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes vulnerability scanning and audit-ready compliance]]></title>
      <description><![CDATA[Image scans can pass while your Kubernetes control plane stays exposed. See why CVE-2025-1974 and CIS Benchmark gaps break audits — and how to close them.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-vulnerability-scanning-and-audit-ready-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-vulnerability-scanning-and-audit-ready-compliance</guid>
      <pubDate>Fri, 27 Mar 2026 03:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-1094 in PostgreSQL psql: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[PostgreSQL psql SQL injection scored CVSS 8.1 and patched in 17.3 / 16.7 / 15.11 / 14.16 / 13.19. Defender SBOM and rollout playbook.]]></description>
      <link>https://safeguard.sh/resources/blog/postgresql-cve-2025-1094-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/postgresql-cve-2025-1094-patch-response</guid>
      <pubDate>Fri, 27 Mar 2026 01:54:54 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is Clickjacking]]></title>
      <description><![CDATA[Clickjacking tricks users into clicking hidden UI via invisible iframes. Learn how it works, real incidents, key CVEs, and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-clickjacking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-clickjacking</guid>
      <pubDate>Fri, 27 Mar 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Website Vulnerability Assessment: A Practical How-To Guide]]></title>
      <description><![CDATA[A website vulnerability assessment systematically finds and ranks the security weaknesses in a web app. Here is the process, the tools, and the pitfalls.]]></description>
      <link>https://safeguard.sh/resources/blog/website-vulnerability-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/website-vulnerability-assessment</guid>
      <pubDate>Fri, 27 Mar 2026 00:34:27 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Software Supply Chain Security (SSCS)?]]></title>
      <description><![CDATA[SolarWinds, Log4Shell, and the XZ Utils backdoor show why supply chain security now means more than SBOMs. Here's what SSCS actually covers—and where Anchore's approach falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-software-supply-chain-security-sscs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-software-supply-chain-security-sscs</guid>
      <pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Python Cython Extensions and the Supply Chain]]></title>
      <description><![CDATA[Cython-built Python extensions ship as platform-specific binaries with a build toolchain behind them. That introduces supply chain surface most teams have not mapped.]]></description>
      <link>https://safeguard.sh/resources/blog/python-cython-extensions-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-cython-extensions-supply-chain</guid>
      <pubDate>Thu, 26 Mar 2026 23:14:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Apache Software License Explained: What Apache 2.0 Means for Your Code]]></title>
      <description><![CDATA[The Apache Software License is one of the most permissive open source licenses. Here is what Apache 2.0 permits, its patent grant, and the one rule teams miss.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-software-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-software-license</guid>
      <pubDate>Thu, 26 Mar 2026 21:53:34 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Flask-CORS Security: The 2024 CVEs and How to Configure It Safely]]></title>
      <description><![CDATA[Flask-CORS is easy to enable and easy to misconfigure. A look at the 2024 path-matching CVEs and the configuration mistakes that actually open your API.]]></description>
      <link>https://safeguard.sh/resources/blog/flask-cors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/flask-cors</guid>
      <pubDate>Thu, 26 Mar 2026 20:33:07 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Hacking Tools Explained: What Every Defender Should Understand]]></title>
      <description><![CDATA[A hacking tool is only as good or bad as its operator. Here is how defenders should think about the tools attackers use, and how to turn them into a defensive advantage.]]></description>
      <link>https://safeguard.sh/resources/blog/hacking-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hacking-tool</guid>
      <pubDate>Thu, 26 Mar 2026 19:12:40 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[DAST Meaning: What Dynamic Application Security Testing Actually Is]]></title>
      <description><![CDATA[DAST stands for Dynamic Application Security Testing, a way of finding vulnerabilities by attacking a running application from the outside. Here is what that means in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-meaning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-meaning</guid>
      <pubDate>Thu, 26 Mar 2026 17:52:14 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How Secure Code Reviews Catch Bugs Before Attackers Do]]></title>
      <description><![CDATA[Code reviews are one of the cheapest security controls you have, but only if they look for the right things. Here is how to run secure code reviews that actually find vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/code-reviews</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-reviews</guid>
      <pubDate>Thu, 26 Mar 2026 16:31:47 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-31630: The PHP GD imageloadfont() Out-of-Bounds Read Explained]]></title>
      <description><![CDATA[CVE-2022-31630 is an out-of-bounds read in PHP's GD extension triggered through imageloadfont(). Here are the affected versions, real impact, and the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-31630</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-31630</guid>
      <pubDate>Thu, 26 Mar 2026 15:11:20 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[react-router-dom and @types/react-router-dom: Versioning Done Right]]></title>
      <description><![CDATA[Installing npm react router dom packages looks trivial until the types break. Here is how react-router-dom versions map to @types packages, and which combinations are wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/react-router-dom-npm-and-types-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-router-dom-npm-and-types-guide</guid>
      <pubDate>Thu, 26 Mar 2026 13:50:53 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[CMMC 2.0 Final Rule Preparation in 2026]]></title>
      <description><![CDATA[The CMMC final rule took effect in December 2024 and rolling contract clauses began appearing in 2025. Here is what contractors should be doing right now in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-2-0-final-rule-2026-prep</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-2-0-final-rule-2026-prep</guid>
      <pubDate>Thu, 26 Mar 2026 13:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Code Quality Scanning: What It Catches and Why Security Cares]]></title>
      <description><![CDATA[Code quality scanning and security scanning overlap more than most teams realize. Here is what static analysis of code quality actually finds and how to run it without alert fatigue.]]></description>
      <link>https://safeguard.sh/resources/blog/code-quality-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-quality-scanning</guid>
      <pubDate>Thu, 26 Mar 2026 12:30:27 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Accepting The Unfixable: A Decision Framework]]></title>
      <description><![CDATA[Some vulnerabilities cannot be fixed in any reasonable timeframe. Here is a structured framework for accepting risk responsibly with reachability and AI evidence.]]></description>
      <link>https://safeguard.sh/resources/blog/accepting-the-unfixable-vulnerability-decision-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/accepting-the-unfixable-vulnerability-decision-framework</guid>
      <pubDate>Thu, 26 Mar 2026 12:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Azure ACR Trusted Images Policy Rollout]]></title>
      <description><![CDATA[ACR's trusted images and notation signing combine into a deploy-time policy you can actually enforce. Here is how to roll it out without breaking AKS workloads.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-acr-trusted-images-policy-rollout</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-acr-trusted-images-policy-rollout</guid>
      <pubDate>Thu, 26 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Engine-Plus-LLM vs Pure-LLM Bug Hunters]]></title>
      <description><![CDATA[The difference between an engine-plus-LLM bug hunter and a pure-LLM one is not a tuning detail. It is a structural divide that determines whether the findings are usable.]]></description>
      <link>https://safeguard.sh/resources/blog/engine-plus-llm-vs-pure-llm-bug-hunters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/engine-plus-llm-vs-pure-llm-bug-hunters</guid>
      <pubDate>Thu, 26 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Maintainer Targeting Trend]]></title>
      <description><![CDATA[Open source maintainers are now a primary target for state and criminal actors. We trace the 2026 social engineering, infrastructure, and credential patterns.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-maintainer-targeting-trend-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-maintainer-targeting-trend-2026</guid>
      <pubDate>Thu, 26 Mar 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Runtime Drift Detection For Supply Chain Controls]]></title>
      <description><![CDATA[An admitted workload is not a static one. Runtime drift detection turns the SBOM into a living contract and surfaces supply chain changes before they become incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/runtime-drift-detection-supply-chain-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runtime-drift-detection-supply-chain-controls</guid>
      <pubDate>Thu, 26 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[State Government Software Procurement 2026]]></title>
      <description><![CDATA[State governments are tightening software procurement rules through 2026. Here is what is changing and how vendors should respond to win contracts.]]></description>
      <link>https://safeguard.sh/resources/blog/state-government-software-procurement-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-government-software-procurement-2026</guid>
      <pubDate>Thu, 26 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Use PyPI openpyxl Safely: Security Risks and Fixes]]></title>
      <description><![CDATA[The openpyxl package on PyPI is safe for most workloads, but XML parsing and spreadsheet formula injection deserve attention. Here is what to watch for.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-openpyxl</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-openpyxl</guid>
      <pubDate>Thu, 26 Mar 2026 11:10:00 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Aqua Security Platform Buyer Review 2026]]></title>
      <description><![CDATA[An in-depth 2026 buyer review of the Aqua Security platform: runtime protection, image scanning, Kubernetes posture, pricing, and where Aqua fits and where it does not.]]></description>
      <link>https://safeguard.sh/resources/blog/aqua-security-platform-buyer-review-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aqua-security-platform-buyer-review-2026</guid>
      <pubDate>Thu, 26 Mar 2026 11:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Prompt Injection in CI/CD Pipelines: Attack Paths and Defenses]]></title>
      <description><![CDATA[When LLMs review PRs, triage issues, and fix builds, every commit message becomes attacker input. The concrete attack paths through GitHub Actions and what blocks them.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-in-ci-cd-pipelines-attack-paths-and-defenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-in-ci-cd-pipelines-attack-paths-and-defenses</guid>
      <pubDate>Thu, 26 Mar 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Sofia Marchetti)</author>
    </item>
    <item>
      <title><![CDATA[tfsec to Trivy IaC: 2026 Migration Playbook]]></title>
      <description><![CDATA[tfsec has been folded into Trivy for over a year and Aqua has stopped feature work on tfsec. We migrated three platforms in 2026 and documented what actually breaks.]]></description>
      <link>https://safeguard.sh/resources/blog/tfsec-to-trivy-iac-migration-playbook-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tfsec-to-trivy-iac-migration-playbook-2026</guid>
      <pubDate>Thu, 26 Mar 2026 10:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What is Session Hijacking]]></title>
      <description><![CDATA[Session hijacking lets attackers seize an active, authenticated session and bypass passwords and MFA entirely. Here's how it works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-session-hijacking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-session-hijacking</guid>
      <pubDate>Thu, 26 Mar 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to Install Python on a Mac: The Clean, Safe Way]]></title>
      <description><![CDATA[Yes, you can install Python on Mac OS in five minutes — but the difference between a clean setup and years of PATH pain is decided by which of the four install routes you pick first.]]></description>
      <link>https://safeguard.sh/resources/blog/install-python-on-mac-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/install-python-on-mac-guide</guid>
      <pubDate>Thu, 26 Mar 2026 09:49:33 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Best practices for securing the software supply chain]]></title>
      <description><![CDATA[From the xz backdoor to SolarWinds, real incidents show why SBOMs, build provenance, and continuous monitoring matter more than scanning alone.]]></description>
      <link>https://safeguard.sh/resources/blog/best-practices-for-securing-the-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-practices-for-securing-the-software-supply-chain</guid>
      <pubDate>Thu, 26 Mar 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[India DPDP Act Software Security Implications 2026]]></title>
      <description><![CDATA[A senior engineer's view of the Digital Personal Data Protection Act in 2026: security safeguards, significant data fiduciaries, breach notification, and software controls that actually comply.]]></description>
      <link>https://safeguard.sh/resources/blog/india-dpdp-act-software-security-implications-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/india-dpdp-act-software-security-implications-2026</guid>
      <pubDate>Thu, 26 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Reflection-Based Dependency Confusion Techniques]]></title>
      <description><![CDATA[Dependency confusion is moving beyond name-typosquat. Reflection-based techniques let attackers hijack packages through dynamic imports and runtime resolution.]]></description>
      <link>https://safeguard.sh/resources/blog/reflection-based-dependency-confusion-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reflection-based-dependency-confusion-techniques</guid>
      <pubDate>Thu, 26 Mar 2026 09:00:00 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Azure Artifacts Sigstore Integration Walkthrough 2026]]></title>
      <description><![CDATA[A practical walkthrough for integrating Sigstore signing and verification with Azure Artifacts in 2026, including the gaps you should know about before starting.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-artifacts-sigstore-integration-walkthrough-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-artifacts-sigstore-integration-walkthrough-2026</guid>
      <pubDate>Thu, 26 Mar 2026 08:30:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[SolarWinds Web Help Desk CVE-2024-28987: Hardcoded Credential in Federal Networks]]></title>
      <description><![CDATA[SolarWinds shipped a hardcoded helpdeskIntegrationUser credential in Web Help Desk that CISA added to KEV on October 15, 2024 after federal agency intrusions.]]></description>
      <link>https://safeguard.sh/resources/blog/solarwinds-web-help-desk-cve-2024-28987-hardcoded-credential</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/solarwinds-web-help-desk-cve-2024-28987-hardcoded-credential</guid>
      <pubDate>Thu, 26 Mar 2026 08:29:07 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[@babel/plugin-transform-runtime: What It Does and When You Need It]]></title>
      <description><![CDATA[The babel plugin transform runtime deduplicates Babel's injected helpers and keeps polyfills out of the global scope. Here is what it actually changes in your output, and when it earns its place.]]></description>
      <link>https://safeguard.sh/resources/blog/babel-plugin-transform-runtime-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/babel-plugin-transform-runtime-guide</guid>
      <pubDate>Thu, 26 Mar 2026 07:08:40 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Credential Stuffing]]></title>
      <description><![CDATA[Credential stuffing uses billions of breached passwords to hijack accounts at scale. Learn how it works, real breaches it caused, and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-credential-stuffing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-credential-stuffing</guid>
      <pubDate>Thu, 26 Mar 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is DevSecOps? (principles, workflow, tooling)]]></title>
      <description><![CDATA[DevSecOps explained: the principles, CI/CD workflow, and scanning tools that build security into every commit instead of bolting it on at release.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-devsecops-principles-workflow-tooling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-devsecops-principles-workflow-tooling</guid>
      <pubDate>Thu, 26 Mar 2026 06:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Palo Alto PAN-OS Authentication Bypass: CVE-2025-0108]]></title>
      <description><![CDATA[A path traversal flaw in Palo Alto Networks PAN-OS management web interface allowed unauthenticated access to sensitive REST API endpoints. Exploitation began within days of disclosure.]]></description>
      <link>https://safeguard.sh/resources/blog/palo-alto-pan-os-cve-2025-0108-auth-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/palo-alto-pan-os-cve-2025-0108-auth-bypass</guid>
      <pubDate>Thu, 26 Mar 2026 05:48:13 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[eslint-plugin-jest-dom: What It Secures and What It Does Not]]></title>
      <description><![CDATA[eslint-plugin-jest-dom enforces better jest-dom assertions, but as a dev dependency it also lives in your supply chain. Here is where its real security value and its real risk both sit.]]></description>
      <link>https://safeguard.sh/resources/blog/eslint-plugin-jest-dom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eslint-plugin-jest-dom</guid>
      <pubDate>Thu, 26 Mar 2026 04:27:47 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is a Brute Force Attack]]></title>
      <description><![CDATA[A brute force attack guesses credentials until one works. Learn how attackers execute it, real breach data, warning signs, and effective defenses.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-brute-force-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-brute-force-attack</guid>
      <pubDate>Thu, 26 Mar 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[rrule npm Package: Recurrence Rules, Health, and Pitfalls]]></title>
      <description><![CDATA[The rrule npm package is the standard way to handle iCalendar recurrence rules in JavaScript — but it carries timezone traps, unbounded-expansion hazards, and a slow maintenance pulse worth knowing before you depend on it.]]></description>
      <link>https://safeguard.sh/resources/blog/rrule-npm-package-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rrule-npm-package-review</guid>
      <pubDate>Thu, 26 Mar 2026 03:07:20 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Anchore's approach to DevSecOps (case for shift-left secu...]]></title>
      <description><![CDATA[How Anchore's devsecops approach uses SBOMs and shift-left scanning to catch vulnerabilities early, and why runtime visibility still matters.]]></description>
      <link>https://safeguard.sh/resources/blog/anchores-approach-to-devsecops-case-for-shift-left-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anchores-approach-to-devsecops-case-for-shift-left-security</guid>
      <pubDate>Thu, 26 Mar 2026 03:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What a Static Application Security Test Catches (and What It Misses)]]></title>
      <description><![CDATA[A clear-eyed look at the static application security test: how SAST works, the vulnerability classes it finds, its blind spots and false positives, and how to run it without drowning developers.]]></description>
      <link>https://safeguard.sh/resources/blog/static-application-security-test</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-application-security-test</guid>
      <pubDate>Thu, 26 Mar 2026 01:46:53 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Phishing]]></title>
      <description><![CDATA[Phishing drives more breaches than any other attack vector. Here's how it works, how it hits software supply chains, and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-phishing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-phishing</guid>
      <pubDate>Thu, 26 Mar 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-45857: The Axios XSRF Token Leak Explained]]></title>
      <description><![CDATA[How CVE-2023-45857 caused Axios to leak XSRF tokens to any host over cross-origin requests, who is affected, and the one-line upgrade that fixes it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-45857</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-45857</guid>
      <pubDate>Thu, 26 Mar 2026 00:26:27 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[CI/CD security and compliance integration]]></title>
      <description><![CDATA[How CI/CD pipelines became the top supply chain attack surface, where scan-only tools like Anchore fall short on compliance evidence, and how Safeguard unifies both.]]></description>
      <link>https://safeguard.sh/resources/blog/cicd-security-and-compliance-integration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cicd-security-and-compliance-integration</guid>
      <pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Okta Cross-Tenant Impersonation 2024]]></title>
      <description><![CDATA[Okta's cross-tenant impersonation advisory and related social-engineering campaigns exposed how identity providers get targeted. Lessons for defenders.]]></description>
      <link>https://safeguard.sh/resources/blog/okta-cross-tenant-impersonation-incident-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/okta-cross-tenant-impersonation-incident-2024</guid>
      <pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[State of Open Source Funding and Security 2026]]></title>
      <description><![CDATA[How open source funding flows connect to security outcomes in 2026: maintainer capacity, critical project support, and the patterns that reduce risk.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-open-source-funding-and-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-open-source-funding-and-security-2026</guid>
      <pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[nginx/1.18.0 (ubuntu): What the Server Banner Reveals and How to Reduce Risk]]></title>
      <description><![CDATA[Seeing nginx/1.18.0 (ubuntu) in a Server header tells you the version, the packaging, and roughly the age of a deployment. Here is what that string implies for security and what to check before assuming you are exposed.]]></description>
      <link>https://safeguard.sh/resources/blog/nginx-1-18-0-ubuntu</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nginx-1-18-0-ubuntu</guid>
      <pubDate>Wed, 25 Mar 2026 23:06:00 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[awesome-typescript-loader: Why to Migrate Off It]]></title>
      <description><![CDATA[awesome-typescript-loader is an unmaintained webpack loader for TypeScript. Here is the security case for migrating to ts-loader and how to do it cleanly.]]></description>
      <link>https://safeguard.sh/resources/blog/awesome-typescript-loader</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/awesome-typescript-loader</guid>
      <pubDate>Wed, 25 Mar 2026 21:45:33 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Types of Vulnerability Assessments and When to Use Each]]></title>
      <description><![CDATA[Network, host, application, database, wireless, and cloud assessments each answer a different question. Knowing which type fits which risk is half the job.]]></description>
      <link>https://safeguard.sh/resources/blog/types-of-vulnerability-assessments</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/types-of-vulnerability-assessments</guid>
      <pubDate>Wed, 25 Mar 2026 20:25:06 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[marked on npm: Security Review and Safe Usage]]></title>
      <description><![CDATA[marked is a fast Markdown parser, but it does not sanitize output and older versions carried a ReDoS bug. Here is how to use marked npm without opening an XSS hole.]]></description>
      <link>https://safeguard.sh/resources/blog/marked-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/marked-npm</guid>
      <pubDate>Wed, 25 Mar 2026 19:04:40 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is Docker Used For? A Practical Answer]]></title>
      <description><![CDATA[What Docker is actually used for in real teams: packaging apps, consistent environments, and shipping to production, plus the security angles that come with containers.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-docker-used-for</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-docker-used-for</guid>
      <pubDate>Wed, 25 Mar 2026 17:44:13 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Website Security Scan: What It Checks and How to Run One]]></title>
      <description><![CDATA[A website security scan tests a live site for common weaknesses. Here is what the different scan types actually check, how to read the results, and where the free ones fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/website-security-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/website-security-scan</guid>
      <pubDate>Wed, 25 Mar 2026 16:23:46 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[The Main Types of Asymmetric Encryption, Explained]]></title>
      <description><![CDATA[The types of asymmetric encryption come down to a few families built on hard math problems: RSA, elliptic curve, Diffie-Hellman, and the post-quantum newcomers. Here is how each works and when to use it.]]></description>
      <link>https://safeguard.sh/resources/blog/types-of-asymmetric-encryption</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/types-of-asymmetric-encryption</guid>
      <pubDate>Wed, 25 Mar 2026 15:03:20 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[SSRF Full Form: What Server-Side Request Forgery Means]]></title>
      <description><![CDATA[The SSRF full form is Server-Side Request Forgery, a vulnerability where an attacker tricks your server into making requests on their behalf. Here is what that means and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/ssrf-full-form</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ssrf-full-form</guid>
      <pubDate>Wed, 25 Mar 2026 13:42:53 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Demo: How the Attack Works and How to Stop It]]></title>
      <description><![CDATA[A practical SQL injection demo that shows how unsanitized input reaches the database, why it works, and the one fix that reliably closes the hole.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-demo</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-demo</guid>
      <pubDate>Wed, 25 Mar 2026 12:22:26 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Developer Friction Budget For Supply Chain Tools]]></title>
      <description><![CDATA[Every security tool spends developer attention. A framework for budgeting friction across IDE, CLI, and PR-time supply chain checks without going bankrupt.]]></description>
      <link>https://safeguard.sh/resources/blog/developer-friction-budget-supply-chain-tooling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/developer-friction-budget-supply-chain-tooling</guid>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Flowing Down CMMC And CRA Clauses To Vendors]]></title>
      <description><![CDATA[CMMC 2.0 and the EU Cyber Resilience Act both require obligations to flow down through your supply chain. Here is how to write the clauses and verify the compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/flowing-down-cmmc-and-cra-clauses-to-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/flowing-down-cmmc-and-cra-clauses-to-vendors</guid>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Actions Immutable Actions GA: Why OCI-Backed Action Distribution Closes the tj-actions Class of Attack]]></title>
      <description><![CDATA[GitHub's 2026 roadmap puts Immutable Actions GA at the center of Actions supply-chain hardening, publishing actions as OCI artifacts with hash-mismatch fail-fast and full composite-action visibility.]]></description>
      <link>https://safeguard.sh/resources/blog/github-actions-immutable-actions-ga-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-actions-immutable-actions-ga-2026</guid>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Sandbox Escapes: Threat Model]]></title>
      <description><![CDATA[A threat model for sandbox escapes in Model Context Protocol servers, mapping attack surfaces from tool execution environments to host processes and shared state.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-sandbox-escapes-threat-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-sandbox-escapes-threat-model</guid>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Medical Device FDA Supply Chain Cybersecurity 2026]]></title>
      <description><![CDATA[FDA expects supply chain cybersecurity evidence at premarket and through the device lifecycle. Here is what to deliver in 2026 without delaying clearance.]]></description>
      <link>https://safeguard.sh/resources/blog/medical-device-fda-supply-chain-cybersecurity-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/medical-device-fda-supply-chain-cybersecurity-2026</guid>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Model Substitution Attacks: An Emerging Pattern]]></title>
      <description><![CDATA[An attacker who can swap the model behind an API call can read every prompt and shape every response. The emerging trend in 2026 is model substitution as an attack class with its own techniques and disclosures.]]></description>
      <link>https://safeguard.sh/resources/blog/model-substitution-attacks-emerging-pattern-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/model-substitution-attacks-emerging-pattern-2026</guid>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Oracle Cloud Tenancy Disclosure Practices: A Defender's Read]]></title>
      <description><![CDATA[Oracle Cloud's disclosure cadence and tenancy isolation story have been pressure-tested across multiple incidents. We unpack what defenders should ask of their provider regardless of vendor.]]></description>
      <link>https://safeguard.sh/resources/blog/oracle-cloud-tenancy-breach-disclosure-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oracle-cloud-tenancy-breach-disclosure-2026</guid>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Out-Of-Band Confirmation For Irreversible Tool Calls]]></title>
      <description><![CDATA[Some tool calls cannot be undone. Out-of-band confirmation is the cheapest defense for that small set, and the most expensive thing to skip.]]></description>
      <link>https://safeguard.sh/resources/blog/out-of-band-confirmation-for-irreversible-tool-calls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/out-of-band-confirmation-for-irreversible-tool-calls</guid>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Reachability vs Pure-LLM Vulnerability Scanning In 2026]]></title>
      <description><![CDATA[Pure-LLM vulnerability scanners hit production around 2024. By 2026 their failure modes are documented. Reachability remains the backbone — and the LLM is most useful on top of it.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-vs-pure-llm-vulnerability-scanning-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-vs-pure-llm-vulnerability-scanning-2026</guid>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Rust Cargo Supply Chain Defence Program]]></title>
      <description><![CDATA[A 2026 defence program for Rust and Cargo — covering crates.io, build scripts, proc-macros, and binary provenance — anchored by Safeguard policy gates.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-cargo-supply-chain-defence-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-cargo-supply-chain-defence-program</guid>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Unifying Software And AI Assets In One Graph]]></title>
      <description><![CDATA[Two parallel inventories for software and AI assets do not survive contact with reality. A unified graph is what makes governance feasible.]]></description>
      <link>https://safeguard.sh/resources/blog/unifying-software-and-ai-assets-one-graph</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unifying-software-and-ai-assets-one-graph</guid>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Hash a Password in Java the Right Way in 2025]]></title>
      <description><![CDATA[To hash a password in Java, use a slow, salted, adaptive algorithm like bcrypt or Argon2 — never a raw SHA or MD5 digest. This guide shows working code and the tuning that actually matters.]]></description>
      <link>https://safeguard.sh/resources/blog/java-hash-password</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-hash-password</guid>
      <pubDate>Wed, 25 Mar 2026 11:02:00 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What is Social Engineering]]></title>
      <description><![CDATA[Social engineering causes 68% of breaches per Verizon's 2024 DBIR. Learn how it works, common attack types, and how it threatens the software supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-social-engineering</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-social-engineering</guid>
      <pubDate>Wed, 25 Mar 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Is the got npm Package Safe? A Security Review of got for Node.js]]></title>
      <description><![CDATA[got is a well-maintained HTTP client, but one redirect-handling CVE and its SSRF-prone defaults are worth knowing before you ship it. Here is the security review.]]></description>
      <link>https://safeguard.sh/resources/blog/got-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/got-npm</guid>
      <pubDate>Wed, 25 Mar 2026 09:41:33 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Training Data Poisoning: Pipeline Defenses]]></title>
      <description><![CDATA[A senior engineer's guide to training data poisoning defenses in 2026, from split-learning detection to provenance attestation and continuous pipeline monitoring.]]></description>
      <link>https://safeguard.sh/resources/blog/data-poisoning-training-pipeline-defenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/data-poisoning-training-pipeline-defenses</guid>
      <pubDate>Wed, 25 Mar 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Gitleaks Secret Scanning Recipes for 2026]]></title>
      <description><![CDATA[Practical Gitleaks configurations and workflows for 2026, including pre-commit setup, monorepo tuning, custom rules, and how to avoid the false-positive treadmill.]]></description>
      <link>https://safeguard.sh/resources/blog/gitleaks-secret-scanning-recipes-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitleaks-secret-scanning-recipes-2026</guid>
      <pubDate>Wed, 25 Mar 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Open source dependency scanning (OSS composition risk)]]></title>
      <description><![CDATA[Open source dependency scanning has moved from periodic audits to a CI/CD gate. Here's how it works, where Anchore fits, and where Safeguard differs.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-dependency-scanning-oss-composition-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-dependency-scanning-oss-composition-risk</guid>
      <pubDate>Wed, 25 Mar 2026 09:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Introducing the Safeguard Marketplace: Extend Your Supply Chain Security]]></title>
      <description><![CDATA[The Safeguard Marketplace brings community-built integrations, policy templates, and compliance packs to the platform.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-marketplace-launch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-marketplace-launch</guid>
      <pubDate>Wed, 25 Mar 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Securing Your Vue Project with eslint-plugin-vue]]></title>
      <description><![CDATA[eslint-plugin-vue is the official linter for Vue single-file components. It is not a security scanner, but used well it removes whole classes of bugs that turn into vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/eslint-plugin-vue</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eslint-plugin-vue</guid>
      <pubDate>Wed, 25 Mar 2026 08:21:06 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-41183: jQuery UI Datepicker XSS and How to Fix It]]></title>
      <description><![CDATA[CVE-2021-41183 is a cross-site scripting flaw in the jQuery UI Datepicker's *Text options, fixed in 1.13.0. Here is the risk and the remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-41183</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-41183</guid>
      <pubDate>Wed, 25 Mar 2026 07:00:40 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What is Malware]]></title>
      <description><![CDATA[Malware now hides in open source packages and CI pipelines, not just email attachments. Here's what it is, how it spreads, and how to catch it early.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-malware</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-malware</guid>
      <pubDate>Wed, 25 Mar 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability management under the EU Cyber Resilience Ac...]]></title>
      <description><![CDATA[The EU Cyber Resilience Act sets hard deadlines for vulnerability reporting and SBOMs. Here's what changes, when, and how Safeguard stacks up against Anchore.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-management-under-the-eu-cyber-resilience-act-cra</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-management-under-the-eu-cyber-resilience-act-cra</guid>
      <pubDate>Wed, 25 Mar 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Semgrep Open Source: What It Scans and How to Use It Well]]></title>
      <description><![CDATA[Semgrep open source is a fast, rule-based static analysis engine for finding bugs and security issues. Here is what the free CLI covers and where its limits are.]]></description>
      <link>https://safeguard.sh/resources/blog/semgrep-open-source</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/semgrep-open-source</guid>
      <pubDate>Wed, 25 Mar 2026 05:40:13 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Define Malicious Code: Types, Examples, and Defenses]]></title>
      <description><![CDATA[To define malicious code: it's any software or script written to damage, disrupt, or gain unauthorized access to a system. Here's the full taxonomy and how to defend against each type.]]></description>
      <link>https://safeguard.sh/resources/blog/define-malicious-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/define-malicious-code</guid>
      <pubDate>Wed, 25 Mar 2026 04:19:46 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is Ransomware]]></title>
      <description><![CDATA[Ransomware costs organizations $2.73M on average to recover from. Learn how it works, its top infection vectors, and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-ransomware</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-ransomware</guid>
      <pubDate>Wed, 25 Mar 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[EU CRA SBOM requirements overview and compliance tips]]></title>
      <description><![CDATA[The EU Cyber Resilience Act makes SBOMs mandatory for connected products by December 2027. Here is what CRA compliance actually requires, and how to prepare.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cra-sbom-requirements-overview-and-compliance-tips</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cra-sbom-requirements-overview-and-compliance-tips</guid>
      <pubDate>Wed, 25 Mar 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-5363 Explained: The OpenSSL Key and IV Length Flaw]]></title>
      <description><![CDATA[CVE-2023-5363 is an OpenSSL bug where key and IV length parameters get processed too late, risking confidentiality in GCM, CCM and OCB modes. Here is who is affected and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-5363</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-5363</guid>
      <pubDate>Wed, 25 Mar 2026 02:59:19 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[An Asymmetric Encryption Example, Explained for Developers]]></title>
      <description><![CDATA[A concrete asymmetric encryption example using RSA key pairs, plus how public-key cryptography secures TLS, signing, and the code you ship.]]></description>
      <link>https://safeguard.sh/resources/blog/asymmetric-encryption-example</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/asymmetric-encryption-example</guid>
      <pubDate>Wed, 25 Mar 2026 01:38:53 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is Zip Slip Vulnerability]]></title>
      <description><![CDATA[Zip Slip lets attackers escape archive extraction via path traversal to overwrite files and gain code execution. Here's how it works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-zip-slip-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-zip-slip-vulnerability</guid>
      <pubDate>Wed, 25 Mar 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Vulnerability Assessment: A Practical Playbook]]></title>
      <description><![CDATA[An enterprise vulnerability assessment is a systematic sweep for weaknesses across your whole estate. Here is how to run one that produces action, not a PDF.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-vulnerability-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-vulnerability-assessment</guid>
      <pubDate>Wed, 25 Mar 2026 00:18:26 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[NIST 800-37 Risk Management Framework explained in plain ...]]></title>
      <description><![CDATA[NIST 800-37's seven-step Risk Management Framework explained in plain English: who must comply, how it ties to FedRAMP and SSDF, and where teams stall.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-800-37-risk-management-framework-explained-in-plain-english</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-800-37-risk-management-framework-explained-in-plain-english</guid>
      <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[URL Encoding and Decoding in Java: URLEncoder and URLDecoder]]></title>
      <description><![CDATA[How URLEncoder.encode in Java actually behaves, why it turns spaces into plus signs, the Charset overload you should be using, and where hand-rolled encoding turns into an injection bug.]]></description>
      <link>https://safeguard.sh/resources/blog/java-url-encoding-decoding-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-url-encoding-decoding-guide</guid>
      <pubDate>Tue, 24 Mar 2026 22:57:59 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Vendors: How to Evaluate the Security Tool Market]]></title>
      <description><![CDATA[The DevSecOps vendor market is crowded and the category labels overlap. Here is a practical framework for evaluating vendors against what your pipeline actually needs.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-vendors</guid>
      <pubDate>Tue, 24 Mar 2026 21:37:33 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[NoSQL Injection: A Practical Tutorial]]></title>
      <description><![CDATA[NoSQL databases don't use SQL syntax, but they're not immune to injection attacks — this NoSQL injection tutorial covers how the attack actually works against MongoDB-style queries.]]></description>
      <link>https://safeguard.sh/resources/blog/nosql-injection-a-practical-tutorial</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nosql-injection-a-practical-tutorial</guid>
      <pubDate>Tue, 24 Mar 2026 20:17:06 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is Mutual TLS (mTLS)? Two-Way Authentication Explained]]></title>
      <description><![CDATA[Mutual TLS makes both sides of a connection prove their identity with certificates, not just the server. It is the backbone of zero-trust communication between services.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-mutual-tls-mtls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-mutual-tls-mtls</guid>
      <pubDate>Tue, 24 Mar 2026 18:56:39 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Is the npm Luxon Package Safe to Use? A Security Review]]></title>
      <description><![CDATA[The npm Luxon package is actively maintained and safe for current use, with one notable historical ReDoS advisory to be aware of. Here is the security picture.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-luxon</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-luxon</guid>
      <pubDate>Tue, 24 Mar 2026 17:36:13 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[NVD Full Form: What the National Vulnerability Database Is]]></title>
      <description><![CDATA[The NVD full form is National Vulnerability Database, the U.S. government repository of known software vulnerabilities maintained by NIST. Here is what it contains and how to use it.]]></description>
      <link>https://safeguard.sh/resources/blog/nvd-full-form</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nvd-full-form</guid>
      <pubDate>Tue, 24 Mar 2026 16:15:46 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[DOM-Based XSS Attacks: How They Work and How to Prevent Them]]></title>
      <description><![CDATA[A DOM based XSS attack executes entirely in the browser, which is why your server-side filters and access logs never see it. Here is how the source-to-sink flow works and what actually stops it.]]></description>
      <link>https://safeguard.sh/resources/blog/dom-based-xss-attack-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dom-based-xss-attack-explained</guid>
      <pubDate>Tue, 24 Mar 2026 14:55:19 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Vulnerability Management: From Scanner Sprawl to One Queue]]></title>
      <description><![CDATA[Most large organizations run five or more scanners that disagree with each other. The fix is not another scanner, it is a single deduplicated, prioritized remediation queue with owners.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-vulnerability-management-one-queue</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-vulnerability-management-one-queue</guid>
      <pubDate>Tue, 24 Mar 2026 14:00:00 GMT</pubDate>
      <category>Enterprise</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Uncaught Exception in Java: A Security Guide]]></title>
      <description><![CDATA[An uncaught exception in Java is more than a crash - it leaks stack traces, kills threads, and opens denial-of-service paths. Here is how to handle it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/uncaught-exception-in-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uncaught-exception-in-java</guid>
      <pubDate>Tue, 24 Mar 2026 13:34:53 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[@types/jest Explained: What It Is and How to Use It Safely]]></title>
      <description><![CDATA[@types/jest ships the TypeScript type definitions for Jest. Here is what the package actually contains, why it lives in devDependencies, and how to keep it from becoming a supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/types-jest</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/types-jest</guid>
      <pubDate>Tue, 24 Mar 2026 12:14:26 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Container Security Scanning Tools: How to Choose in 2026]]></title>
      <description><![CDATA[Container security scanning tools find vulnerabilities in your images, layers, and dependencies before they reach production. Here is how the categories compare and what to look for.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-scanning-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-scanning-tools</guid>
      <pubDate>Tue, 24 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP Continuous Monitoring: Supply Chain Controls]]></title>
      <description><![CDATA[FedRAMP's continuous monitoring requirements now include supply chain risk. Learn how to produce monthly evidence aligned with NIST SP 800-161 controls.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-continuous-monitoring-supply-chain-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-continuous-monitoring-supply-chain-controls</guid>
      <pubDate>Tue, 24 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[From Finding To Merged Fix In An Hour]]></title>
      <description><![CDATA[A one-hour cycle from vulnerability finding to merged fix is achievable in 2026, but only with a pipeline designed for it. Here is what that pipeline looks like.]]></description>
      <link>https://safeguard.sh/resources/blog/from-vulnerability-finding-to-merged-fix-in-an-hour</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/from-vulnerability-finding-to-merged-fix-in-an-hour</guid>
      <pubDate>Tue, 24 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Tool-Call Hijacking: Griffin AI vs Mythos]]></title>
      <description><![CDATA[A hijacked tool call is more consequential than a hijacked response. The defence requires the tool layer to police the model, not the other way around.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-tool-call-hijacking-defences</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-tool-call-hijacking-defences</guid>
      <pubDate>Tue, 24 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Sourcegraph Cody for Security Use]]></title>
      <description><![CDATA[Cody's codebase-wide context is valuable for security review. Griffin AI adds reachability, taint, and policy grounding that Cody doesn't target.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-sourcegraph-cody-security-use</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-sourcegraph-cody-security-use</guid>
      <pubDate>Tue, 24 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NYDFS 500 Software Supply Chain Implications]]></title>
      <description><![CDATA[A senior engineer's view of how NYDFS Part 500 amendments through 2025 and 2026 reshape software supply chain expectations for regulated financial institutions.]]></description>
      <link>https://safeguard.sh/resources/blog/nydfs-500-software-supply-chain-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nydfs-500-software-supply-chain-implications</guid>
      <pubDate>Tue, 24 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[OCI Artifact Signing Rollout Program]]></title>
      <description><![CDATA[A program plan for getting OCI artifact signing across an organisation: trust roots, key custody, build integrations, registry policy, and the inevitable cleanup of unsigned legacy content.]]></description>
      <link>https://safeguard.sh/resources/blog/oci-artifact-signing-rollout-program-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oci-artifact-signing-rollout-program-2026</guid>
      <pubDate>Tue, 24 Mar 2026 12:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Quality: Fields Auditors Actually Check]]></title>
      <description><![CDATA[Auditors do not score SBOMs on file count. They check a small set of fields that prove the artefact is real, current, and tied to a verifiable build. Here are the ones that matter.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-quality-fields-auditors-actually-check</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-quality-fields-auditors-actually-check</guid>
      <pubDate>Tue, 24 Mar 2026 12:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Tabletop Exercise: Software Supply Chain Incident]]></title>
      <description><![CDATA[A facilitator's guide to running a supply chain incident tabletop that produces decisions, not theater, with concrete injects and evidence-driven debrief.]]></description>
      <link>https://safeguard.sh/resources/blog/tabletop-exercise-software-supply-chain-incident</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tabletop-exercise-software-supply-chain-incident</guid>
      <pubDate>Tue, 24 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Secure Development Model? A Practical Guide]]></title>
      <description><![CDATA[A secure development model bakes security into every phase of building software instead of bolting it on at the end. Here is how the model works and how to adopt one without slowing delivery.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-development-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-development-model</guid>
      <pubDate>Tue, 24 Mar 2026 10:53:59 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AI Explainability: Why It Matters for Security and Trust]]></title>
      <description><![CDATA[AI explainability is the ability to understand why a model produced a given output. In security, it is the difference between an alert you can act on and one you cannot.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-explainability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-explainability</guid>
      <pubDate>Tue, 24 Mar 2026 10:50:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[MSI Graphics Driver Supply Chain Breach 2023: Lessons]]></title>
      <description><![CDATA[The MSI breach exposed Intel BootGuard private keys and OEM signing infrastructure. A look at firmware-level supply chain risk and the gaps that remain.]]></description>
      <link>https://safeguard.sh/resources/blog/msi-graphics-driver-supply-chain-2023-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/msi-graphics-driver-supply-chain-2023-lessons</guid>
      <pubDate>Tue, 24 Mar 2026 10:30:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx CxSAST: What It Actually Does]]></title>
      <description><![CDATA[Checkmarx CxSAST is one of the longest-running static analysis engines in the enterprise appsec market. Here's what it actually scans, how it's typically deployed, and where teams run into friction.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-cxsast-what-it-actually-does</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-cxsast-what-it-actually-does</guid>
      <pubDate>Tue, 24 Mar 2026 10:20:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[AI Accelerators: A Security Guide to the Hardware Running Your Models]]></title>
      <description><![CDATA[AI accelerators are the specialized chips that make model training and inference fast, and they bring their own attack surface: memory leakage, driver stacks, and firmware you did not write. Here is what to secure.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-accelerators</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-accelerators</guid>
      <pubDate>Tue, 24 Mar 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Security Solutions: The 2026 Consolidation Guide]]></title>
      <description><![CDATA[The average enterprise runs dozens of security tools that barely talk to each other. This guide maps the categories, explains why consolidation is accelerating, and shows how to evaluate a platform.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-security-solutions-consolidation-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-security-solutions-consolidation-guide</guid>
      <pubDate>Tue, 24 Mar 2026 10:00:00 GMT</pubDate>
      <category>Enterprise</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Guardrails for Autonomous Code-Fixing Agents]]></title>
      <description><![CDATA[AI agents can now open pull requests that patch vulnerabilities on their own. Without guardrails — scoped permissions, test gates, human merge approval — they can also break builds and introduce new flaws at machine speed.]]></description>
      <link>https://safeguard.sh/resources/blog/guardrails-for-autonomous-code-fixing-agents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/guardrails-for-autonomous-code-fixing-agents</guid>
      <pubDate>Tue, 24 Mar 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Secure AI Agents on the MCP Protocol]]></title>
      <description><![CDATA[MCP gives AI agents real tools, real credentials, and real blast radius. Here is a hardening guide for running MCP servers in production without torching your environment.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-secure-ai-agents-mcp-protocol-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-secure-ai-agents-mcp-protocol-2026</guid>
      <pubDate>Tue, 24 Mar 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Prototype Pollution]]></title>
      <description><![CDATA[Prototype pollution lets attackers corrupt Object.prototype via unsafe merges, turning a data bug in lodash, jQuery, or minimist into RCE.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-prototype-pollution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-prototype-pollution</guid>
      <pubDate>Tue, 24 Mar 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Zero Trust for CI/CD Pipelines: A Concrete Blueprint]]></title>
      <description><![CDATA[CI/CD runners are a top attacker target. Here's a concrete zero-trust blueprint using OIDC federation, pinned action SHAs, and short-lived identities.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-trust-cicd-pipelines-blueprint</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-trust-cicd-pipelines-blueprint</guid>
      <pubDate>Tue, 24 Mar 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The OWASP AI Top 10 Explained: LLM Risks for 2025 and Beyond]]></title>
      <description><![CDATA[The OWASP AI Top 10 is the community list of the most critical security risks in LLM applications, led by prompt injection. Here is what each entry means and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-ai-top-10</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-ai-top-10</guid>
      <pubDate>Tue, 24 Mar 2026 09:40:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[node-xlsx Security: Handling Untrusted Excel Files Safely]]></title>
      <description><![CDATA[node-xlsx is a thin wrapper around SheetJS, so its security posture is inherited. Here is what that means for parsing untrusted spreadsheets and how to lock it down.]]></description>
      <link>https://safeguard.sh/resources/blog/node-xlsx</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-xlsx</guid>
      <pubDate>Tue, 24 Mar 2026 09:33:32 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Is AI-Powered Cybersecurity? A Practical Security Guide]]></title>
      <description><![CDATA[AI-powered cybersecurity means using machine learning and language models to detect, triage, and remediate threats faster than rule-based tooling alone. Here is where it genuinely helps and where the hype outruns reality.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-powered-cybersecurity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-powered-cybersecurity</guid>
      <pubDate>Tue, 24 Mar 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[NIST 800-53 security and privacy controls overview]]></title>
      <description><![CDATA[A breakdown of NIST 800-53 Rev 5's control families, SBOM and supply-chain requirements, and why scanning tools like Anchore cover only a narrow slice of what compliance demands.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-800-53-security-and-privacy-controls-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-800-53-security-and-privacy-controls-overview</guid>
      <pubDate>Tue, 24 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How to Prioritize a 10,000-Finding Vulnerability Backlog]]></title>
      <description><![CDATA[A five-digit backlog is not a ranking problem, it is a filtering problem. Here is the funnel that turns 10,000 findings into a few hundred that deserve engineering time.]]></description>
      <link>https://safeguard.sh/resources/blog/prioritize-10000-finding-vulnerability-backlog</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prioritize-10000-finding-vulnerability-backlog</guid>
      <pubDate>Tue, 24 Mar 2026 09:00:00 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[UK PSTI Act Consumer IoT: Year-One Review]]></title>
      <description><![CDATA[The UK PSTI Act's first year of enforcement reveals how consumer IoT vendors are struggling with minimum security requirements, password rules, and disclosure policies.]]></description>
      <link>https://safeguard.sh/resources/blog/uk-psti-act-consumer-iot-year-one-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uk-psti-act-consumer-iot-year-one-review</guid>
      <pubDate>Tue, 24 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Automation: What to Automate First]]></title>
      <description><![CDATA[Automation pays off in a strict order: dependencies, secrets, static analysis, then dynamic testing. Here is the sequence, why it works, and what should stay manual.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-automation-what-first</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-automation-what-first</guid>
      <pubDate>Tue, 24 Mar 2026 08:30:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Scan: What It Is and How to Run One That Matters]]></title>
      <description><![CDATA[A cloud scan checks your running cloud accounts, images, and code for misconfigurations and known vulnerabilities. Here is how to scope one so the results are actionable instead of overwhelming.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-scan</guid>
      <pubDate>Tue, 24 Mar 2026 08:13:06 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security News: How to Actually Track It]]></title>
      <description><![CDATA[Software supply chain security news moves across a dozen disconnected sources — registries, CVE feeds, vendor blogs — here's a repeatable system for not missing the one that hits you.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-news-how-to-track-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-news-how-to-track-it</guid>
      <pubDate>Tue, 24 Mar 2026 08:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[angular-oauth2-oidc: Secure OAuth2 and OIDC in Angular]]></title>
      <description><![CDATA[angular-oauth2-oidc is the most widely used OAuth2 and OpenID Connect client for Angular apps. Here is how to wire it up with PKCE, validate tokens correctly, and avoid the config mistakes that leak sessions.]]></description>
      <link>https://safeguard.sh/resources/blog/angular-oauth2-oidc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/angular-oauth2-oidc</guid>
      <pubDate>Tue, 24 Mar 2026 06:52:39 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[NIST 800-190 container security guide compliance]]></title>
      <description><![CDATA[NIST 800-190 requires evidence across five container risk categories, not just image scans. Where Anchore-based pipelines fall short and how to close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-800-190-container-security-guide-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-800-190-container-security-guide-compliance</guid>
      <pubDate>Tue, 24 Mar 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Security Champions Program?]]></title>
      <description><![CDATA[AppSec teams are outnumbered 100 to 1 by developers. A security champions program is the only staffing model that scales — here is how to build one that lasts.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-security-champions-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-security-champions-program</guid>
      <pubDate>Tue, 24 Mar 2026 05:32:12 GMT</pubDate>
      <category>Culture</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[npm handlebars: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[The npm handlebars package is a widely used templating engine with a history of prototype pollution issues. Here is what to know before you depend on it and how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-handlebars</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-handlebars</guid>
      <pubDate>Tue, 24 Mar 2026 04:11:46 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[NIST 800-218 / SSDF attestation requirements]]></title>
      <description><![CDATA[What NIST SP 800-218 (SSDF) attestation actually requires, the CISA form's four claims, key OMB deadlines, and where Anchore's SBOM-first approach leaves gaps Safeguard closes.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-800-218-ssdf-attestation-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-800-218-ssdf-attestation-requirements</guid>
      <pubDate>Tue, 24 Mar 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Java Vulnerability Classes: A Reference List]]></title>
      <description><![CDATA[A java vulnerability list organized by class — deserialization, injection, XXE, and the rest — because Java's ecosystem produces a specific, recurring set of vulnerability patterns worth knowing by name.]]></description>
      <link>https://safeguard.sh/resources/blog/java-vulnerability-classes-a-reference-list</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-vulnerability-classes-a-reference-list</guid>
      <pubDate>Tue, 24 Mar 2026 02:51:19 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Licensing Models Explained: Permissive, Copyleft, and Compliance Risk]]></title>
      <description><![CDATA[Open source licensing models fall into a few families with very different obligations. Here is how permissive, copyleft, and source-available terms affect your compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-licensing-models</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-licensing-models</guid>
      <pubDate>Tue, 24 Mar 2026 01:30:52 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is a Business Logic Vulnerability]]></title>
      <description><![CDATA[Business logic vulnerabilities exploit correct code enforcing the wrong rules. Learn what they are, real breach examples, and how to detect them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-business-logic-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-business-logic-vulnerability</guid>
      <pubDate>Tue, 24 Mar 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Lodash 4.17.21: The Security History Behind the Version Bump]]></title>
      <description><![CDATA[Lodash 4.17.21 closed a ReDoS path in its number-parsing helpers and a command-injection risk in its templating function — here's the security history that led up to it.]]></description>
      <link>https://safeguard.sh/resources/blog/lodash-4-17-21-security-history</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lodash-4-17-21-security-history</guid>
      <pubDate>Tue, 24 Mar 2026 00:10:26 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to brew install java 17 on a Mac (Safely)]]></title>
      <description><![CDATA[To brew install Java 17 on a Mac, use the Temurin cask or the openjdk@17 formula, then wire up JAVA_HOME. Here is the full walkthrough plus the security reasons to keep it patched.]]></description>
      <link>https://safeguard.sh/resources/blog/brew-install-java-17</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/brew-install-java-17</guid>
      <pubDate>Mon, 23 Mar 2026 22:49:59 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Unrestricted File Upload Vulnerabilities: Risks and Fixes]]></title>
      <description><![CDATA[An unrestricted file upload vulnerability lets an attacker place a working web shell on your server through a form that was only ever supposed to accept profile pictures or PDFs.]]></description>
      <link>https://safeguard.sh/resources/blog/unrestricted-file-upload-vulnerabilities-risks-and-fixes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unrestricted-file-upload-vulnerabilities-risks-and-fixes</guid>
      <pubDate>Mon, 23 Mar 2026 21:29:32 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[nullifAI: Broken Pickles and the Hugging Face Detection Gap]]></title>
      <description><![CDATA[ReversingLabs disclosed two malicious Hugging Face models that evaded Picklescan by using broken 7z-packed PyTorch archives. We unpack the technique.]]></description>
      <link>https://safeguard.sh/resources/blog/nullifai-broken-pickles-huggingface-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nullifai-broken-pickles-huggingface-attack</guid>
      <pubDate>Mon, 23 Mar 2026 20:09:06 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[NIST SP 800-218A: SSDF Practices for Generative AI Models]]></title>
      <description><![CDATA[NIST finalized SP 800-218A on July 26, 2024, augmenting the Secure Software Development Framework with practices specific to generative AI and dual-use foundation models.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-sp-800-218a-ai-ssdf</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-sp-800-218a-ai-ssdf</guid>
      <pubDate>Mon, 23 Mar 2026 18:48:39 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[DeepSeek ClickHouse Exposure: When the AI Vendor Forgets the Database]]></title>
      <description><![CDATA[In January 2025 Wiz Research found a wide-open ClickHouse instance belonging to AI startup DeepSeek, leaking chat history, API keys, and internal log streams. We unpack the AI-supply-chain implications.]]></description>
      <link>https://safeguard.sh/resources/blog/deepseek-clickhouse-exposure-ai-provider-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/deepseek-clickhouse-exposure-ai-provider-2025</guid>
      <pubDate>Mon, 23 Mar 2026 17:28:12 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Cloudflare R2 February 6, 2025 Outage: When Abuse Tooling Took Down Production]]></title>
      <description><![CDATA[A routine phishing-URL takedown clicked the wrong button and disabled R2 globally for 59 minutes. Here is what went wrong and the two-party approval Cloudflare added afterwards.]]></description>
      <link>https://safeguard.sh/resources/blog/cloudflare-r2-february-2025-abuse-remediation-outage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloudflare-r2-february-2025-abuse-remediation-outage</guid>
      <pubDate>Mon, 23 Mar 2026 16:07:45 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Pooja Rao)</author>
    </item>
    <item>
      <title><![CDATA[AI Deepfake Phishing Campaigns in 2025: When Seeing and Hearing Isn't Believing]]></title>
      <description><![CDATA[AI-generated voice and video deepfakes powered a new wave of phishing campaigns in early 2025. The technology is cheap, the results are convincing, and defenses are lagging.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-deepfake-phishing-campaigns-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-deepfake-phishing-campaigns-2025</guid>
      <pubDate>Mon, 23 Mar 2026 14:47:19 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[IAST Security: Interactive Application Security Testing Explained]]></title>
      <description><![CDATA[IAST security instruments a running application to watch real requests flow through real code, catching vulnerabilities that static analysis and black-box scanning both miss.]]></description>
      <link>https://safeguard.sh/resources/blog/iast-security-interactive-testing-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iast-security-interactive-testing-explained</guid>
      <pubDate>Mon, 23 Mar 2026 13:26:52 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Choosing an Enterprise Security Solution: What Actually Matters]]></title>
      <description><![CDATA[An enterprise security solution is less about a single flagship product and more about how well a set of controls integrates, scales, and produces evidence for auditors.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-security-solution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-security-solution</guid>
      <pubDate>Mon, 23 Mar 2026 12:06:25 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise AI Center Of Excellence Blueprint]]></title>
      <description><![CDATA[An AI Center of Excellence is not a committee. It is the function that makes AI adoption coherent across business units. The blueprint is specific.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-ai-center-of-excellence-blueprint</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-ai-center-of-excellence-blueprint</guid>
      <pubDate>Mon, 23 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[ROI Timeline: Griffin AI vs Mythos]]></title>
      <description><![CDATA[The honest answer to &quot;when does this pay back?&quot; is where sales decks and procurement reality diverge. Griffin AI and Mythos-class tools have different ROI shapes.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-roi-timeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-roi-timeline</guid>
      <pubDate>Mon, 23 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Open Weights: Supply Chain Risks]]></title>
      <description><![CDATA[Open-weight models give you total deployment control. They also give you a new supply chain to secure. The tradeoff is worth being explicit about.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-open-weight-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-open-weight-supply-chain-risks</guid>
      <pubDate>Mon, 23 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Storing Passwords Securely: What Actually Works]]></title>
      <description><![CDATA[Storing a password means storing a slow, salted hash of it, never the password itself. Here is the modern approach that survives a database breach.]]></description>
      <link>https://safeguard.sh/resources/blog/storing-password</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/storing-password</guid>
      <pubDate>Mon, 23 Mar 2026 10:45:59 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What Are Hardcoded Credentials]]></title>
      <description><![CDATA[Hardcoded credentials are secrets baked into code instead of a vault. Toyota, Uber, and Samsung breaches show why that risk never expires on its own.]]></description>
      <link>https://safeguard.sh/resources/blog/what-are-hardcoded-credentials</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-are-hardcoded-credentials</guid>
      <pubDate>Mon, 23 Mar 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SCA in DevSecOps: Automating Dependency Security in CI/CD]]></title>
      <description><![CDATA[SCA in DevSecOps means wiring software composition analysis into your pipeline so vulnerable dependencies get caught on every commit instead of at audit time.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-devsecops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-devsecops</guid>
      <pubDate>Mon, 23 Mar 2026 09:25:32 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[DoD software factory reference design and secure software...]]></title>
      <description><![CDATA[What a real DoD software factory requires under the DevSecOps Reference Design, where Anchore's scanning fits and falls short, and how continuous SBOM evidence enables cATO.]]></description>
      <link>https://safeguard.sh/resources/blog/dod-software-factory-reference-design-and-secure-software-factory-architecture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dod-software-factory-reference-design-and-secure-software-factory-architecture</guid>
      <pubDate>Mon, 23 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[npm Garbage Collection Abuse: Attack Research]]></title>
      <description><![CDATA[npm's unpublish and tarball retention rules create a narrow but real window for attackers to reclaim deleted names and swap tarball contents. Here is the 2025 research.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-garbage-collection-abuse-attack-research</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-garbage-collection-abuse-attack-research</guid>
      <pubDate>Mon, 23 Mar 2026 09:00:00 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Security Best Practices Every Team Should Actually Follow]]></title>
      <description><![CDATA[Most JavaScript security incidents come from a handful of repeated mistakes. These are the best practices that prevent them, from XSS to the npm dependency graph.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-security-best-practices</guid>
      <pubDate>Mon, 23 Mar 2026 08:05:05 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is Sensitive Data Exposure]]></title>
      <description><![CDATA[Sensitive data exposure covers everything from unencrypted databases to hardcoded secrets. Learn what causes it, real breach examples, and how to detect it early.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-sensitive-data-exposure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-sensitive-data-exposure</guid>
      <pubDate>Mon, 23 Mar 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[DAST Solutions: How to Choose the Right Dynamic Testing Tool]]></title>
      <description><![CDATA[DAST solutions test a running application from the outside to find exploitable flaws. Here is how they work, what they catch, and how to evaluate one for your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-solutions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-solutions</guid>
      <pubDate>Mon, 23 Mar 2026 06:44:39 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[ATO and continuous ATO (cATO) for government software]]></title>
      <description><![CDATA[ATO takes 6-18 months and expires the moment it's signed. Here's what continuous ATO (cATO) really requires, where container-only tools like Anchore fall short, and how Safeguard closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/ato-and-continuous-ato-cato-for-government-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ato-and-continuous-ato-cato-for-government-software</guid>
      <pubDate>Mon, 23 Mar 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[AI Code Assistants and Security: The Hidden Risks in 2025]]></title>
      <description><![CDATA[AI coding assistants are generating millions of lines of production code. But they also introduce dependency hallucinations, insecure patterns, and supply chain risks that security teams need to address.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-code-assistants-security-implications-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-code-assistants-security-implications-2025</guid>
      <pubDate>Mon, 23 Mar 2026 05:24:12 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to Run Python on Mac: A Step-by-Step Guide]]></title>
      <description><![CDATA[macOS ships with Python, but you should not use it for your own projects. Here is how to run Python on a Mac the right way, from installing a real interpreter to isolating each project.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-run-python-on-mac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-run-python-on-mac</guid>
      <pubDate>Mon, 23 Mar 2026 04:03:45 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is Broken Authentication]]></title>
      <description><![CDATA[Broken authentication lets attackers assume another user's identity via credential stuffing, forged tokens, or auth-bypass CVEs like Fortinet's CVE-2022-40684.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-broken-authentication</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-broken-authentication</guid>
      <pubDate>Mon, 23 Mar 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[STIG compliance scanning for hardened/Chainguard containe...]]></title>
      <description><![CDATA[Chainguard images have near-zero CVEs, but shell-based scanners like Anchore flag them as STIG non-compliant. Here is why, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/stig-compliance-scanning-for-hardenedchainguard-container-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/stig-compliance-scanning-for-hardenedchainguard-container-images</guid>
      <pubDate>Mon, 23 Mar 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How to Fix Vulnerabilities: A Practical Workflow]]></title>
      <description><![CDATA[A practical, repeatable workflow for how to fix vulnerabilities once a scanner finds them — triage, verify, patch, and confirm — instead of treating every finding as equally urgent.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-fix-vulnerabilities-a-practical-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-fix-vulnerabilities-a-practical-workflow</guid>
      <pubDate>Mon, 23 Mar 2026 02:43:18 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[The boltdb-go Backdoor: A Three-Year Go Module Mirror Persistence]]></title>
      <description><![CDATA[A typosquat of boltdb hid a Go module mirror cache-poisoning attack for three years before Socket researchers disclosed it on January 30, 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/go-module-mirror-boltdb-typosquat-three-year-backdoor</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-module-mirror-boltdb-typosquat-three-year-backdoor</guid>
      <pubDate>Mon, 23 Mar 2026 01:22:52 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What Are Cryptographic Failures]]></title>
      <description><![CDATA[Cryptographic failures are OWASP's #2 Top 10 risk — weak, missing, or broken encryption. See real breaches, causes, and how to detect and fix them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-are-cryptographic-failures</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-are-cryptographic-failures</guid>
      <pubDate>Mon, 23 Mar 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[UnitedHealth Change Healthcare: 190 Million Update and the Long Tail]]></title>
      <description><![CDATA[In January 2025 UnitedHealth revised the Change Healthcare breach count to 190 million people, the largest HIPAA breach in US history. We unpack what changed and the supply-chain lessons that still apply.]]></description>
      <link>https://safeguard.sh/resources/blog/unitedhealth-change-healthcare-190-million-update-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unitedhealth-change-healthcare-190-million-update-2025</guid>
      <pubDate>Mon, 23 Mar 2026 00:02:25 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[DoD Risk Management Framework (RMF) mapping for container...]]></title>
      <description><![CDATA[How DoD RMF container control mapping actually works, where Anchore's scan-first approach leaves manual crosswalk work for compliance teams, and how Safeguard automates NIST 800-53 evidence.]]></description>
      <link>https://safeguard.sh/resources/blog/dod-risk-management-framework-rmf-mapping-for-container-inspection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dod-risk-management-framework-rmf-mapping-for-container-inspection</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[2025 Bug Bounty Program Reforms: What Changed]]></title>
      <description><![CDATA[From Microsoft's AI bounty expansion to the EU CRA's good-faith researcher protections, bug bounty rules of engagement shifted meaningfully in early 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2025-bug-bounty-program-reform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2025-bug-bounty-program-reform</guid>
      <pubDate>Sun, 22 Mar 2026 22:41:58 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CDK Global BlackSuit Ransomware: 15,000 Dealerships Offline for 2 Weeks]]></title>
      <description><![CDATA[BlackSuit ransomware encrypted CDK Global's dealer-management cloud on June 18-19, 2024, crippling roughly 15,000 North American auto dealerships and triggering a reported $25M ransom payment.]]></description>
      <link>https://safeguard.sh/resources/blog/cdk-global-blacksuit-ransomware-dealership-impact</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cdk-global-blacksuit-ransomware-dealership-impact</guid>
      <pubDate>Sun, 22 Mar 2026 21:21:32 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Zyxel Router Command Injection: CVE-2024-40891 Exploited in the Wild]]></title>
      <description><![CDATA[Threat actors began mass-exploiting a Telnet-based command injection flaw in Zyxel CPE routers, with over 1,500 devices compromised in botnet campaigns. Zyxel initially refused to patch.]]></description>
      <link>https://safeguard.sh/resources/blog/zyxel-router-cve-2024-40891-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zyxel-router-cve-2024-40891-exploitation</guid>
      <pubDate>Sun, 22 Mar 2026 20:01:05 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Types of Vulnerability Assessment, Explained]]></title>
      <description><![CDATA[Not every vulnerability assessment tests the same thing. Here's how network, application, host, and wireless assessments differ, and when each one is the right call.]]></description>
      <link>https://safeguard.sh/resources/blog/types-of-vulnerability-assessment-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/types-of-vulnerability-assessment-explained</guid>
      <pubDate>Sun, 22 Mar 2026 18:40:38 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Ethical Hacking Workshop: How to Read and Learn Online]]></title>
      <description><![CDATA[Looking to read an ethical hacking workshop online? Here is how to learn ethical hacking legally and safely, what a good curriculum covers, and how it connects to defending real software.]]></description>
      <link>https://safeguard.sh/resources/blog/ethical-hacking-workshop-read-online</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ethical-hacking-workshop-read-online</guid>
      <pubDate>Sun, 22 Mar 2026 17:20:12 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Example: How It Works and How to Stop It]]></title>
      <description><![CDATA[A clear SQL injection example makes the vulnerability obvious. Here are illustrative cases, the main attack types, and the fixes that actually eliminate the risk.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-example</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-example</guid>
      <pubDate>Sun, 22 Mar 2026 15:59:45 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[XXE Attack Demo: Understanding and Defending Against XML External Entities]]></title>
      <description><![CDATA[An XXE attack demo makes the vulnerability click: an XML parser that trusts external entities can be tricked into reading files or making requests. Here is how it works and how to shut it down.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-attack-demo</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-attack-demo</guid>
      <pubDate>Sun, 22 Mar 2026 14:39:18 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Drift Detection Playbook for 2026]]></title>
      <description><![CDATA[A practical playbook for detecting and responding to SBOM drift between source, build, and runtime, with the patterns that separate signal from noise.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-drift-detection-playbook-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-drift-detection-playbook-2026</guid>
      <pubDate>Sun, 22 Mar 2026 14:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[core-js on npm: Security Review and Safe Usage]]></title>
      <description><![CDATA[A security and sustainability review of core-js on npm: the postinstall history, the maintainer funding crisis, and how to keep this near-universal dependency safe.]]></description>
      <link>https://safeguard.sh/resources/blog/core-js-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/core-js-npm</guid>
      <pubDate>Sun, 22 Mar 2026 13:18:52 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[AI Scaffold Prompts: Enterprise Governance]]></title>
      <description><![CDATA[System prompts that scaffold AI assistants are now load-bearing enterprise assets. A framework for versioning, reviewing, and governing them as seriously as source code.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-scaffold-prompts-enterprise-governance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-scaffold-prompts-enterprise-governance</guid>
      <pubDate>Sun, 22 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Regression Gate Design Patterns For Security LLMs]]></title>
      <description><![CDATA[A release gate that fails on regression is the most important operational control for AI-for-security tools. The design patterns are specific and worth copying.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-regression-gate-design-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-regression-gate-design-patterns</guid>
      <pubDate>Sun, 22 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Claude Citations: Advisory Work]]></title>
      <description><![CDATA[Claude's citations feature makes the model say where its claims come from. Griffin AI uses it for advisory workflows where traceability is the entire point.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-claude-citations-for-advisory-work</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-claude-citations-for-advisory-work</guid>
      <pubDate>Sun, 22 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Can Malicious Code Do Damage? A Practical Security Guide]]></title>
      <description><![CDATA[Malicious code does damage by abusing the permissions of the process it runs in, then spreading, stealing, or destroying. Here is how each mechanism works and how to blunt it.]]></description>
      <link>https://safeguard.sh/resources/blog/how-can-malicious-code-do-damage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-can-malicious-code-do-damage</guid>
      <pubDate>Sun, 22 Mar 2026 11:58:25 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing MCP Servers: A Practical Checklist]]></title>
      <description><![CDATA[MCP servers are runtime dependencies your agent trusts implicitly. Here is a concrete checklist for auth, tool pinning, sandboxing, and monitoring before you ship one.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-mcp-servers-a-practical-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-mcp-servers-a-practical-checklist</guid>
      <pubDate>Sun, 22 Mar 2026 11:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Tomas Lindgren)</author>
    </item>
    <item>
      <title><![CDATA[Security Testing Automation: What to Automate, and What Not To]]></title>
      <description><![CDATA[Security testing automation pays off fastest on repetitive, well-defined checks — here's a clear line between what to automate and what still needs a human.]]></description>
      <link>https://safeguard.sh/resources/blog/security-testing-automation-what-to-automate-and-what-not-to</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-testing-automation-what-to-automate-and-what-not-to</guid>
      <pubDate>Sun, 22 Mar 2026 11:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[connected-react-router: A Security Guide for an Inactive Package]]></title>
      <description><![CDATA[connected-react-router is popular but no longer actively maintained and has no official React 18 support. Here is the risk that creates and how to move off it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/connected-react-router</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/connected-react-router</guid>
      <pubDate>Sun, 22 Mar 2026 10:37:58 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Are Security Logging and Monitoring Failures]]></title>
      <description><![CDATA[Equifax went undetected for 76 days, Marriott for four years. Here's what security logging and monitoring failures are, why they happen, and how to close the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/what-are-security-logging-and-monitoring-failures</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-are-security-logging-and-monitoring-failures</guid>
      <pubDate>Sun, 22 Mar 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CVE Management for SMEs: A Practical Security Guide]]></title>
      <description><![CDATA[A practical CVE guide for SMEs: what a CVE is, how small and medium teams should triage them without a full security department, and where to focus.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-sme</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-sme</guid>
      <pubDate>Sun, 22 Mar 2026 09:17:31 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CycloneDX 1.7 Migration Guide From 1.5]]></title>
      <description><![CDATA[A practical migration path from CycloneDX 1.5 to 1.7 covering schema changes, machine learning BOM additions, formulation, and the tooling adjustments required.]]></description>
      <link>https://safeguard.sh/resources/blog/cyclonedx-1-7-migration-guide-from-1-5</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyclonedx-1-7-migration-guide-from-1-5</guid>
      <pubDate>Sun, 22 Mar 2026 09:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[FDA Premarket Cybersecurity for Medical Devices 2026]]></title>
      <description><![CDATA[A senior engineer's guide to FDA premarket cybersecurity for medical devices in 2026: section 524B, SBOM expectations, SPDF, and what reviewers actually ask about.]]></description>
      <link>https://safeguard.sh/resources/blog/fda-premarket-cybersecurity-medical-devices-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fda-premarket-cybersecurity-medical-devices-2026</guid>
      <pubDate>Sun, 22 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Vulnerability Database Comparison 2026]]></title>
      <description><![CDATA[Comparing the major open source vulnerability databases in 2026: NVD, OSV, GHSA, GitLab Advisory, and ecosystem-specific feeds measured on coverage and freshness.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-vulnerability-database-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-vulnerability-database-comparison-2026</guid>
      <pubDate>Sun, 22 Mar 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Report on Compliance (ROC) vs Self-Assessment Questionnai...]]></title>
      <description><![CDATA[PCI DSS ROC vs SAQ explained, and why v4.0.1's software inventory and anti-skimming rules demand supply chain evidence GRC tools like Vanta weren't built to generate.]]></description>
      <link>https://safeguard.sh/resources/blog/report-on-compliance-roc-vs-self-assessment-questionnaire-saq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/report-on-compliance-roc-vs-self-assessment-questionnaire-saq</guid>
      <pubDate>Sun, 22 Mar 2026 09:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Introducing Safeguard TPRM: Evidence-Based Third-Party Risk Management]]></title>
      <description><![CDATA[Safeguard's new TPRM module replaces vendor questionnaires with SBOM-driven, continuous third-party risk assessment.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-tprm-module-release</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-tprm-module-release</guid>
      <pubDate>Sun, 22 Mar 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[The Bootstrap Freelancer Theme: A Security Review Before You Ship It]]></title>
      <description><![CDATA[The Bootstrap Freelancer theme is a popular free portfolio template, but shipping it unchanged pulls in front-end dependencies you need to check first.]]></description>
      <link>https://safeguard.sh/resources/blog/bootstrap-freelancer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bootstrap-freelancer</guid>
      <pubDate>Sun, 22 Mar 2026 07:57:05 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Use of Components with Known Vulnerabilities]]></title>
      <description><![CDATA[Equifax lost 147M records to one unpatched library. Here's what "components with known vulnerabilities" means and how reachability analysis fixes the triage problem.]]></description>
      <link>https://safeguard.sh/resources/blog/use-of-components-with-known-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/use-of-components-with-known-vulnerabilities</guid>
      <pubDate>Sun, 22 Mar 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How a Docker Image Vulnerability Scanner Works and What to Use]]></title>
      <description><![CDATA[How a Docker image vulnerability scanner works layer by layer, what it can and cannot catch, the tools worth knowing, and how to wire scanning into your build without slowing it down.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-image-vulnerability-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-image-vulnerability-scanner</guid>
      <pubDate>Sun, 22 Mar 2026 06:36:38 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[EU AI Act and ISO 42001: how the two frameworks interact]]></title>
      <description><![CDATA[How the EU AI Act's binding rules and ISO 42001's voluntary AIMS overlap, and how supply-chain evidence closes gaps generic GRC tools can't.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-ai-act-and-iso-42001-how-the-two-frameworks-interact</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-ai-act-and-iso-42001-how-the-two-frameworks-interact</guid>
      <pubDate>Sun, 22 Mar 2026 06:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Java Deserialization Vulnerabilities: How They Work and How to Stop Them]]></title>
      <description><![CDATA[A practical explanation of the Java deserialization vulnerability class: why untrusted object deserialization leads to remote code execution, and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/java-deserialization-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-deserialization-vulnerability</guid>
      <pubDate>Sun, 22 Mar 2026 05:16:11 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is Container Security]]></title>
      <description><![CDATA[Container security protects images, runtimes, orchestration, and hosts. Here's what it covers, why 87% of images ship with critical CVEs, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-container-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-container-security</guid>
      <pubDate>Sun, 22 Mar 2026 04:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How to Apply a Patch in Git (Safely and Reviewably)]]></title>
      <description><![CDATA[Applying a patch in Git comes down to git apply versus git am, and knowing which to use, how to preview it, and how to verify it, keeps untrusted diffs from becoming a supply chain problem.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-apply-patch-in-git</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-apply-patch-in-git</guid>
      <pubDate>Sun, 22 Mar 2026 03:55:45 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Quantitative vs qualitative risk analysis methods]]></title>
      <description><![CDATA[Software supply chain risk needs numbers and judgment. Here's how Safeguard's quantitative scoring compares to Vanta's qualitative, compliance-first approach.]]></description>
      <link>https://safeguard.sh/resources/blog/quantitative-vs-qualitative-risk-analysis-methods</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/quantitative-vs-qualitative-risk-analysis-methods</guid>
      <pubDate>Sun, 22 Mar 2026 03:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Copyleft Licenses: What They Mean for Your Code]]></title>
      <description><![CDATA[A copyleft license requires that derivative works stay under the same license, which can force you to open-source code you thought was proprietary. Here is how copyleft works and how to manage the risk.]]></description>
      <link>https://safeguard.sh/resources/blog/copy-left-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/copy-left-license</guid>
      <pubDate>Sun, 22 Mar 2026 02:35:18 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Nginx 1.14.2: Which Vulnerabilities Affect It and How to Upgrade]]></title>
      <description><![CDATA[Nginx/1.14.2 is an end-of-life release carrying the resolver heap overwrite, HTTP/2 DoS flaws, and a request-smuggling bug. Here is what applies and the upgrade path.]]></description>
      <link>https://safeguard.sh/resources/blog/nginx-1-14-2</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nginx-1-14-2</guid>
      <pubDate>Sun, 22 Mar 2026 01:14:51 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Container Scanning]]></title>
      <description><![CDATA[Container scanning finds known CVEs, secrets, and misconfigurations in image layers before deployment. Here's how it works and where it falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-container-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-container-scanning</guid>
      <pubDate>Sun, 22 Mar 2026 01:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Best ISO 27001 compliance software compared (2026)]]></title>
      <description><![CDATA[Vanta automates your ISO 27001 control library. Safeguard generates the SBOM and vulnerability evidence auditors ask for under Annex A's software controls.]]></description>
      <link>https://safeguard.sh/resources/blog/best-iso-27001-compliance-software-compared-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-iso-27001-compliance-software-compared-2026</guid>
      <pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[State of DevSecOps 2026: What Teams Actually Ship]]></title>
      <description><![CDATA[A senior-engineer review of DevSecOps in 2026: what teams ship in production, which controls moved the needle, and where most programs still stall.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-devsecops-2026-what-teams-ship</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-devsecops-2026-what-teams-ship</guid>
      <pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[JSON Patch Security: Prototype Pollution and Safe Usage]]></title>
      <description><![CDATA[JSON Patch (RFC 6902) is a compact format for applying partial updates, but implementations like fast-json-patch have had prototype-pollution flaws. Here is how to use it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/json-patch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/json-patch</guid>
      <pubDate>Sat, 21 Mar 2026 23:54:25 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How to Run Grype in Offline/Airgap Environments]]></title>
      <description><![CDATA[A hands-on tutorial for running Grype vulnerability scans in offline and airgapped environments, including vulnerability database hosting and CI integration.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-run-grype-in-offline-airgap-environments</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-run-grype-in-offline-airgap-environments</guid>
      <pubDate>Sat, 21 Mar 2026 22:33:58 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is TLS? Transport Layer Security Explained]]></title>
      <description><![CDATA[TLS is the protocol that encrypts data in transit across the internet, turning the padlock in your browser into real protection against eavesdropping and tampering.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-tls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-tls</guid>
      <pubDate>Sat, 21 Mar 2026 21:13:31 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[react-syntax-highlighter: Rendering Code Safely in React]]></title>
      <description><![CDATA[react-syntax-highlighter is the go-to library for showing code blocks in React apps. Here is how to use it and how to avoid the XSS traps around rendering untrusted code.]]></description>
      <link>https://safeguard.sh/resources/blog/react-syntax-highlighter</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-syntax-highlighter</guid>
      <pubDate>Sat, 21 Mar 2026 19:53:05 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Input Validation in Cyber Security: Why It Matters and How to Do It]]></title>
      <description><![CDATA[Input validation is a foundational cyber security control that rejects malformed data at the boundary, cutting off entire classes of injection attacks before they start.]]></description>
      <link>https://safeguard.sh/resources/blog/input-validation-cyber-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/input-validation-cyber-security</guid>
      <pubDate>Sat, 21 Mar 2026 18:32:38 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[cross-env and the crossenv Typosquat: A Supply Chain Case Study]]></title>
      <description><![CDATA[In 2017, a malicious crossenv package on npm stole environment variables from developers who mistyped cross-env. The incident is still the cleanest case study in typosquatting we have.]]></description>
      <link>https://safeguard.sh/resources/blog/cross-env-npm-and-the-crossenv-typosquat</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cross-env-npm-and-the-crossenv-typosquat</guid>
      <pubDate>Sat, 21 Mar 2026 17:12:11 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[node-pre-gyp and node-gyp: The Security Cost of Native Modules]]></title>
      <description><![CDATA[@mapbox/node-pre-gyp downloads compiled binaries into your node_modules at install time. Understanding that machinery is the difference between a fast install and an unauditable one.]]></description>
      <link>https://safeguard.sh/resources/blog/node-pre-gyp-and-native-module-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-pre-gyp-and-native-module-security</guid>
      <pubDate>Sat, 21 Mar 2026 15:51:44 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What Makes an Encryption Algorithm Symmetric?]]></title>
      <description><![CDATA[An encryption algorithm is symmetric when the same secret key both encrypts and decrypts the data. That single property shapes its speed, its use cases, and its one hard problem.]]></description>
      <link>https://safeguard.sh/resources/blog/what-makes-an-encryption-algorithm-symmetric</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-makes-an-encryption-algorithm-symmetric</guid>
      <pubDate>Sat, 21 Mar 2026 14:31:18 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm uninstall package: How to Safely Remove Dependencies]]></title>
      <description><![CDATA[How the npm uninstall package command works, what it leaves behind, and how to confirm a removed dependency is actually gone from your tree and your risk surface.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-uninstall-package</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-uninstall-package</guid>
      <pubDate>Sat, 21 Mar 2026 13:10:51 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Ageing Vulnerabilities: Fix vs Mitigate]]></title>
      <description><![CDATA[Old vulnerabilities accumulate quietly until they become a compliance problem. Here is how to decide between fixing and mitigating, with evidence that holds up.]]></description>
      <link>https://safeguard.sh/resources/blog/ageing-vulnerabilities-when-to-fix-vs-mitigate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ageing-vulnerabilities-when-to-fix-vs-mitigate</guid>
      <pubDate>Sat, 21 Mar 2026 12:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CI/CD Platform Attack Trends 2026]]></title>
      <description><![CDATA[CI/CD platforms have become high-value supply chain targets. We analyze 2026 attack trends, including runner abuse, action poisoning, and OIDC token theft.]]></description>
      <link>https://safeguard.sh/resources/blog/ci-cd-platform-attack-trends-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ci-cd-platform-attack-trends-2026</guid>
      <pubDate>Sat, 21 Mar 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GCP Binary Authorization Real-World Deployment]]></title>
      <description><![CDATA[Binary Authorization works in production, but the rollout pattern is not obvious. This is the real-world deployment guide for 2026 GCP estates.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-binary-authorization-real-world-deployment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-binary-authorization-real-world-deployment</guid>
      <pubDate>Sat, 21 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs OpenAI Pricing: Security Workloads]]></title>
      <description><![CDATA[Per-token pricing on the OpenAI API looks cheap on a single call and expensive on a year-long security workload. Griffin AI's pricing reflects the architecture.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-openai-pricing-for-security-workloads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-openai-pricing-for-security-workloads</guid>
      <pubDate>Sat, 21 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Municipal Utility Supply Chain Defence Program]]></title>
      <description><![CDATA[Municipal utilities face state-actor and ransomware pressure on their software supply chains. Here is how to stand up a credible defense on a utility budget.]]></description>
      <link>https://safeguard.sh/resources/blog/municipal-utility-supply-chain-defence-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/municipal-utility-supply-chain-defence-program</guid>
      <pubDate>Sat, 21 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Small Language Models: Security Use-Case Fit]]></title>
      <description><![CDATA[Small language models aren&apos;t a worse version of large ones. For specific security workflows, they&apos;re the right tool — if you know which workflows.]]></description>
      <link>https://safeguard.sh/resources/blog/small-language-model-security-usecase-fit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/small-language-model-security-usecase-fit</guid>
      <pubDate>Sat, 21 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[One Policy Set, Four Enforcement Points]]></title>
      <description><![CDATA[Different gates with different rules create gaps and developer friction. A unified policy engine evaluates one definition at PR, build, admission, and runtime.]]></description>
      <link>https://safeguard.sh/resources/blog/unified-policy-engine-pr-build-admission-runtime</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unified-policy-engine-pr-build-admission-runtime</guid>
      <pubDate>Sat, 21 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Zero-Day Triage Without Drowning Engineers]]></title>
      <description><![CDATA[A zero-day discovery pipeline is only as useful as the triage process around it. Here is what triage looks like when the pipeline gives engineers something they can defend.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-day-triage-without-drowning-engineers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-day-triage-without-drowning-engineers</guid>
      <pubDate>Sat, 21 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What Is VAPT? A Practical Guide to Vulnerability Assessment and Penetration Testing]]></title>
      <description><![CDATA[VAPT combines automated vulnerability assessment with hands-on penetration testing. Here is what each half actually does and how to run VAPT that finds real risk.]]></description>
      <link>https://safeguard.sh/resources/blog/vapt</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vapt</guid>
      <pubDate>Sat, 21 Mar 2026 11:50:24 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Examples: Real Attack Patterns and How to Stop Them]]></title>
      <description><![CDATA[SQL injection examples that show the attack patterns behind the CWE, why they work, and the parameterized-query fix that stops all of them at once.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-examples-and-defenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-examples-and-defenses</guid>
      <pubDate>Sat, 21 Mar 2026 10:29:58 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[3 Steps to Secure Container Images]]></title>
      <description><![CDATA[A stock base image ships 180+ unused packages. Learn the 3 steps to secure container images: minimize, prioritize by reachability, and enforce.]]></description>
      <link>https://safeguard.sh/resources/blog/3-steps-to-secure-container-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/3-steps-to-secure-container-images</guid>
      <pubDate>Sat, 21 Mar 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Funding Crisis: What It Means for Your Tree]]></title>
      <description><![CDATA[Critical infrastructure depends on unpaid maintainers, and burnout creates openings attackers exploit. xz-utils was the warning shot, not the exception.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-funding-crisis-dependency-tree-impact</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-funding-crisis-dependency-tree-impact</guid>
      <pubDate>Sat, 21 Mar 2026 10:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[minimatch npm: Security Review and Safe Usage]]></title>
      <description><![CDATA[The minimatch npm package powers glob matching across the JavaScript ecosystem, and a ReDoS flaw made older versions a denial-of-service risk. Here is what to know and how to stay safe.]]></description>
      <link>https://safeguard.sh/resources/blog/minimatch-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/minimatch-npm</guid>
      <pubDate>Sat, 21 Mar 2026 09:09:31 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Claude MCP Tool Poisoning Threat Model 2026]]></title>
      <description><![CDATA[A senior engineer's threat model for Claude MCP tool poisoning in 2026, covering malicious servers, description hijacking, and the authorization patterns that actually help.]]></description>
      <link>https://safeguard.sh/resources/blog/claude-mcp-tool-poisoning-threat-model-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/claude-mcp-tool-poisoning-threat-model-2026</guid>
      <pubDate>Sat, 21 Mar 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Developer Social Engineering Campaigns 2024-2025]]></title>
      <description><![CDATA[State-aligned and financially motivated actors now target individual developers with bespoke social engineering. Here is the tradecraft and what engineering leaders must do.]]></description>
      <link>https://safeguard.sh/resources/blog/dev-0270-developer-social-engineering-campaign</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dev-0270-developer-social-engineering-campaign</guid>
      <pubDate>Sat, 21 Mar 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vanta vs. competitors: platform comparison]]></title>
      <description><![CDATA[Vanta automates compliance evidence; Safeguard secures the software supply chain itself. A clear-eyed comparison of scope, buyers, and where the two overlap.]]></description>
      <link>https://safeguard.sh/resources/blog/vanta-vs-competitors-platform-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vanta-vs-competitors-platform-comparison</guid>
      <pubDate>Sat, 21 Mar 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx SCA vs Mend vs Snyk: 2026 Buyer Comparison]]></title>
      <description><![CDATA[A direct comparison of Checkmarx SCA, Mend, and Snyk in 2026 across reachability, license analysis, developer experience, and total cost of ownership.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-sca-vs-mend-vs-snyk-buyer-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-sca-vs-mend-vs-snyk-buyer-comparison-2026</guid>
      <pubDate>Sat, 21 Mar 2026 08:50:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Build Security Into Every SDLC Phase]]></title>
      <description><![CDATA[Bolting a scan onto release week is not security in the SDLC. Here is what a security control looks like in each phase, and what it costs to skip them.]]></description>
      <link>https://safeguard.sh/resources/blog/security-in-sdlc-phases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-in-sdlc-phases</guid>
      <pubDate>Sat, 21 Mar 2026 07:49:04 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Container Registry Security]]></title>
      <description><![CDATA[Container registries are one of the highest-leverage attack points in the software supply chain. Here's what actually secures one, with real incidents and numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-container-registry-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-container-registry-security</guid>
      <pubDate>Sat, 21 Mar 2026 07:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[The xss npm Package: Sanitizing HTML Input Correctly]]></title>
      <description><![CDATA[The xss npm package is a whitelist-based HTML sanitizer for Node and the browser. It works well — when you sanitize in the right place, with the right whitelist, for the right output context.]]></description>
      <link>https://safeguard.sh/resources/blog/xss-npm-sanitizer-package-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xss-npm-sanitizer-package-guide</guid>
      <pubDate>Sat, 21 Mar 2026 06:28:38 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Vanta alternatives: what to look for in a compliance auto...]]></title>
      <description><![CDATA[A buyer's guide to evaluating compliance automation platforms: what Vanta actually covers, where the gaps sit, and how Safeguard fits differently.]]></description>
      <link>https://safeguard.sh/resources/blog/vanta-alternatives-what-to-look-for-in-a-compliance-automation-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vanta-alternatives-what-to-look-for-in-a-compliance-automation-platform</guid>
      <pubDate>Sat, 21 Mar 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Software Security Issues: A Triage Framework]]></title>
      <description><![CDATA[Most teams triage software security issues by severity score alone, which routinely gets the priority order wrong. A better framework weighs reachability and exposure too.]]></description>
      <link>https://safeguard.sh/resources/blog/software-security-issues-a-triage-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-security-issues-a-triage-framework</guid>
      <pubDate>Sat, 21 Mar 2026 05:08:11 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Container Runtime Security]]></title>
      <description><![CDATA[Container runtime security monitors running containers for malicious behavior that image scanning can't catch — here's how it works and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-container-runtime-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-container-runtime-security</guid>
      <pubDate>Sat, 21 Mar 2026 04:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-0333: The Chrome Extensions Data Validation Flaw Explained]]></title>
      <description><![CDATA[CVE-2024-0333 is an insufficient data validation bug in Chrome's Extensions component that let a network attacker push a malicious extension. Here is what it is and how to stay patched.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-0333</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-0333</guid>
      <pubDate>Sat, 21 Mar 2026 03:47:44 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Merchant and service provider definitions under PCI DSS]]></title>
      <description><![CDATA[PCI DSS treats merchants and service providers differently under Requirements 6 and 12.8. Here's how Safeguard's supply chain focus compares to Vanta's compliance automation.]]></description>
      <link>https://safeguard.sh/resources/blog/merchant-and-service-provider-definitions-under-pci-dss</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/merchant-and-service-provider-definitions-under-pci-dss</guid>
      <pubDate>Sat, 21 Mar 2026 03:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Which of the Following Is an Example of Malicious Code?]]></title>
      <description><![CDATA[Viruses, worms, trojans, ransomware, spyware, and logic bombs are all examples of malicious code. Here is how to tell them apart and defend against each.]]></description>
      <link>https://safeguard.sh/resources/blog/which-of-the-following-is-an-example-of-malicious-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/which-of-the-following-is-an-example-of-malicious-code</guid>
      <pubDate>Sat, 21 Mar 2026 02:27:18 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Lodash on npm: Prototype Pollution Risks and the Safe Version]]></title>
      <description><![CDATA[The lodash npm package is everywhere, and older versions carry real prototype pollution CVEs. Here are the fixed versions and how to check what your tree resolves to.]]></description>
      <link>https://safeguard.sh/resources/blog/lodash-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lodash-npm</guid>
      <pubDate>Sat, 21 Mar 2026 01:06:51 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Container Orchestration]]></title>
      <description><![CDATA[Container orchestration automates how containers deploy, scale, and recover across clusters — and it's also one of the highest-value targets in the software supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-container-orchestration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-container-orchestration</guid>
      <pubDate>Sat, 21 Mar 2026 01:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Hugging Face Token Exposure 2024 Analysis]]></title>
      <description><![CDATA[Researchers found thousands of valid Hugging Face API tokens in public code and models. Analysis of the 2024 exposures and what they mean for ML supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/hugging-face-token-exposure-2024-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hugging-face-token-exposure-2024-analysis</guid>
      <pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is a SOC 2 report and why it matters for SaaS]]></title>
      <description><![CDATA[SOC 2 explained for SaaS teams: what the report covers, how it differs from tools like Vanta, and why compliance alone won't stop supply chain attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-soc-2-report-and-why-it-matters-for-saas</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-soc-2-report-and-why-it-matters-for-saas</guid>
      <pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Hacking Skills: What Ethical Hackers Actually Need to Learn]]></title>
      <description><![CDATA[The hacking skills that matter for a security career are less about flashy exploits and more about networking, systems, code, and disciplined methodology. Here is the real list.]]></description>
      <link>https://safeguard.sh/resources/blog/hacking-skills</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hacking-skills</guid>
      <pubDate>Fri, 20 Mar 2026 23:46:24 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The MIT License, Summarized: What It Permits and Requires]]></title>
      <description><![CDATA[A plain-English MIT license summary: the one condition it imposes, the freedoms it grants, and the compliance step teams still manage to miss.]]></description>
      <link>https://safeguard.sh/resources/blog/mit-license-summary</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mit-license-summary</guid>
      <pubDate>Fri, 20 Mar 2026 22:25:57 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Ascension Health Black Basta Ransomware: 5.6M Patients Impacted]]></title>
      <description><![CDATA[Black Basta encrypted Ascension's network on May 8, 2024 via a malicious file downloaded by an employee, diverting ambulances across 140 hospitals and ultimately notifying 5.6 million patients.]]></description>
      <link>https://safeguard.sh/resources/blog/ascension-health-black-basta-ransomware-2024-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ascension-health-black-basta-ransomware-2024-analysis</guid>
      <pubDate>Fri, 20 Mar 2026 21:05:31 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Tools in Cyber Security: A Starter Map by Category]]></title>
      <description><![CDATA[The tools in cyber security span network defense, application security, identity, and data protection, and the fastest way to get oriented is a map by category rather than a vendor list.]]></description>
      <link>https://safeguard.sh/resources/blog/tools-in-cyber-security-a-starter-map</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tools-in-cyber-security-a-starter-map</guid>
      <pubDate>Fri, 20 Mar 2026 19:45:04 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm run: How Scripts Work and How to Use Them Safely]]></title>
      <description><![CDATA[npm run executes the scripts defined in your package.json. Here is how it resolves commands, the lifecycle hooks that run automatically, and the supply-chain risks to watch.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-run</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-run</guid>
      <pubDate>Fri, 20 Mar 2026 18:24:37 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Nginx and CVE-2023-44487: How to Fix HTTP/2 Rapid Reset]]></title>
      <description><![CDATA[CVE-2023-44487, the HTTP/2 Rapid Reset attack, is a protocol-level DoS. Nginx resists it with default settings, but a loose keepalive config can still be abused. Here's the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/nginx-cve-2023-44487</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nginx-cve-2023-44487</guid>
      <pubDate>Fri, 20 Mar 2026 17:04:11 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Log4j Maven Dependency: How to Find, Fix, and Pin It Safely]]></title>
      <description><![CDATA[A practical guide to the Log4j Maven dependency: how to detect log4j-core in your tree, why 2.17.1 is the version to target, and how to pin it for good.]]></description>
      <link>https://safeguard.sh/resources/blog/log4j-maven-dependency</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4j-maven-dependency</guid>
      <pubDate>Fri, 20 Mar 2026 15:43:44 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[SonicWall SMA 1000 Zero-Day: CVE-2025-23006 Pre-Auth RCE]]></title>
      <description><![CDATA[SonicWall disclosed CVE-2025-23006, a critical deserialization vulnerability in its SMA 1000 series gateways that was actively exploited as a zero-day before patches were available.]]></description>
      <link>https://safeguard.sh/resources/blog/sonicwall-sma-cve-2025-23006-zero-day</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonicwall-sma-cve-2025-23006-zero-day</guid>
      <pubDate>Fri, 20 Mar 2026 14:23:17 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Retail POS Supply Chain Security in 2026]]></title>
      <description><![CDATA[Retail point-of-sale environments combine PCI scope, vendor-managed software, and thousands of physical endpoints. Here is the 2026 supply chain baseline that actually works at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/retail-pos-supply-chain-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/retail-pos-supply-chain-security-2026</guid>
      <pubDate>Fri, 20 Mar 2026 13:15:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-4863: The libwebp Zero-Day That Hit Chrome and More]]></title>
      <description><![CDATA[CVE-2023-4863 was a heap buffer overflow in libwebp's Huffman decoding that was exploited as a zero-day in the wild — and because libwebp sits inside Chrome, Firefox, and countless Electron apps, one library bug became an ecosystem-wide emergency patch.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-4863-the-libwebp-zero-day-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-4863-the-libwebp-zero-day-explained</guid>
      <pubDate>Fri, 20 Mar 2026 13:02:51 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Asset Discovery For M&A Due Diligence]]></title>
      <description><![CDATA[M&A due diligence runs on questionnaires that nobody can verify. Continuous asset discovery turns the diligence period into a data exercise.]]></description>
      <link>https://safeguard.sh/resources/blog/asset-discovery-for-merger-acquisition-due-diligence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/asset-discovery-for-merger-acquisition-due-diligence</guid>
      <pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AWS re:Inforce 2026 Supply Chain Sessions: Field Notes]]></title>
      <description><![CDATA[Field notes from AWS re:Inforce 2026 supply chain track: signing at scale, SBOM adoption, and the Inspector and ECR updates that actually matter.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-reinforce-2026-supply-chain-sessions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-reinforce-2026-supply-chain-sessions</guid>
      <pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[DeepHat AI Explained: The Open Security LLM and How to Use It Safely]]></title>
      <description><![CDATA[What DeepHat AI is, where it came from, and how to fold an uncensored open-source security model into offensive and defensive work without creating new risk.]]></description>
      <link>https://safeguard.sh/resources/blog/deephat-ai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/deephat-ai</guid>
      <pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Digital Health Startup HIPAA Supply Chain Rollout]]></title>
      <description><![CDATA[Digital health startups must reconcile fast iteration with HIPAA-grade supply chain controls. Here is the rollout plan that gets you to production safely.]]></description>
      <link>https://safeguard.sh/resources/blog/digital-health-startup-hipaa-supply-chain-rollout</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/digital-health-startup-hipaa-supply-chain-rollout</guid>
      <pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[.NET / NuGet Enterprise Supply Chain Program]]></title>
      <description><![CDATA[An enterprise-grade .NET and NuGet supply chain program for 2026 — covering feeds, lockfiles, MSBuild targets, and runtime — backed by Safeguard.]]></description>
      <link>https://safeguard.sh/resources/blog/dotnet-nuget-enterprise-supply-chain-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dotnet-nuget-enterprise-supply-chain-program</guid>
      <pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Evaluating Vendor Attestations: SOC 2 / FedRAMP]]></title>
      <description><![CDATA[A SOC 2 report does not mean the vendor is secure. Here is how to read attestations carefully, what FedRAMP actually proves, and how to ingest both at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/evaluating-vendor-attestations-soc2-fedramp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/evaluating-vendor-attestations-soc2-fedramp</guid>
      <pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Fine-Tune Drift Measured On Eval Sets]]></title>
      <description><![CDATA[Fine-tuning to improve one task frequently regresses others. Without eval harnesses, the regressions ship. The measurable drift is larger than vendors admit.]]></description>
      <link>https://safeguard.sh/resources/blog/frontier-model-limit-fine-tune-drift-on-evals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/frontier-model-limit-fine-tune-drift-on-evals</guid>
      <pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Gemini On-Device: Developer Tools]]></title>
      <description><![CDATA[Gemini on-device models are fast and cheap. For the developer-tool layer, they're useful. For the engine-plus-LLM layer, on-device is not the right fit.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-on-device-for-developer-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-on-device-for-developer-tools</guid>
      <pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Grounded Reasoning vs Hallucinated: Griffin AI vs Mythos]]></title>
      <description><![CDATA[The difference between grounded reasoning and hallucinated reasoning is not eloquence — it's citation. A look at how Griffin AI anchors every claim.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-reasoning-grounded-vs-hallucinated</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-reasoning-grounded-vs-hallucinated</guid>
      <pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Capability Drift Detection]]></title>
      <description><![CDATA[MCP servers do not stay still. Tool surfaces drift, scopes expand, and the server you approved is not the server in production. Here is how to catch that.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-capability-drift-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-capability-drift-detection</guid>
      <pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Prompt Injection From Research To Bug Bounty]]></title>
      <description><![CDATA[Prompt injection started as a research curiosity. In 2026 it is a regular line item on bug bounty leaderboards, with payout norms, scope definitions, and a maturing triage culture.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-from-research-to-bug-bounty-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-from-research-to-bug-bounty-2026</guid>
      <pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis For Monorepos And Microservices]]></title>
      <description><![CDATA[Reachability across a monorepo or a microservices fleet needs different engineering than reachability inside a single service. Both are tractable; both have specific failure modes.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-for-monorepos-and-microservices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-for-monorepos-and-microservices</guid>
      <pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Shift-Left, Shift-Everywhere: Program Design]]></title>
      <description><![CDATA[Shift-left is necessary but insufficient. A program design that distributes supply chain checks across IDE, CLI, PR, build, and runtime — without redundancy.]]></description>
      <link>https://safeguard.sh/resources/blog/shift-left-shift-everywhere-program-design</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shift-left-shift-everywhere-program-design</guid>
      <pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[OSS License Types Explained and Their Compliance Risks]]></title>
      <description><![CDATA[A field guide to OSS license types, from permissive MIT and Apache to copyleft GPL and AGPL, and the obligations each one puts on the code you ship.]]></description>
      <link>https://safeguard.sh/resources/blog/oss-license-types</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oss-license-types</guid>
      <pubDate>Fri, 20 Mar 2026 11:42:24 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[chokidar on npm: A Security Review of the File-Watching Library]]></title>
      <description><![CDATA[chokidar is the file-watching library behind most of the Node.js tooling ecosystem, and version 4 cut its dependency count from 13 to 1. Here is what that means for your supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/chokidar-npm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chokidar-npm</guid>
      <pubDate>Fri, 20 Mar 2026 10:21:57 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps and Platform Engineering: The Convergence No One Expected]]></title>
      <description><![CDATA[Platform engineering teams are becoming the new home for security controls. Here's why that is both promising and risky.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-platform-engineering-convergence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-platform-engineering-convergence</guid>
      <pubDate>Fri, 20 Mar 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to Implement SLSA Level 3 Practically]]></title>
      <description><![CDATA[SLSA Level 3 requires hardened builds, verifiable provenance, and isolated build environments. Here is the practical path, not the theoretical one.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-implement-slsa-level-3-practical-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-implement-slsa-level-3-practical-guide</guid>
      <pubDate>Fri, 20 Mar 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Container Monitoring]]></title>
      <description><![CDATA[Container monitoring tracks metrics, logs, and runtime behavior across ephemeral containers—here's what it covers, why it matters, and how it differs from VM monitoring.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-container-monitoring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-container-monitoring</guid>
      <pubDate>Fri, 20 Mar 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[npm underscore Security Review: Is It Safe to Use in 2025?]]></title>
      <description><![CDATA[A security review of the npm underscore package, the code-injection CVE in its template function, and whether you still need it in a modern JavaScript stack.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-underscore</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-underscore</guid>
      <pubDate>Fri, 20 Mar 2026 09:01:31 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 risk assessment methodology]]></title>
      <description><![CDATA[A practical breakdown of the ISO 27001 risk assessment methodology under the 2022 revision, where GRC platforms like Vanta fall short, and how to build a register that survives Stage 2 audits.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-risk-assessment-methodology</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-risk-assessment-methodology</guid>
      <pubDate>Fri, 20 Mar 2026 09:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[DNS Cache Poisoning for Software Updates: 2025]]></title>
      <description><![CDATA[DNS cache poisoning is a known attack class with a new application: hijacking software update checks to ship malicious binaries that pass every signature check.]]></description>
      <link>https://safeguard.sh/resources/blog/loophole-dns-cache-poisoning-software-updates-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/loophole-dns-cache-poisoning-software-updates-2025</guid>
      <pubDate>Fri, 20 Mar 2026 09:00:00 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Ruby Gems Security: Signing, Yanking and Trusted Publishing]]></title>
      <description><![CDATA[Gem signing never took off, yanking is weaker than people assume, and trusted publishing finally fixes the credential problem. What to actually rely on in a Ruby pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/ruby-gems-security-signing-yanking-and-trusted-publishing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ruby-gems-security-signing-yanking-and-trusted-publishing</guid>
      <pubDate>Fri, 20 Mar 2026 08:00:00 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Marcus Webb)</author>
    </item>
    <item>
      <title><![CDATA[Vuln Scan Basics: How Vulnerability Scanning Actually Works]]></title>
      <description><![CDATA[What a vuln scan is, the main scanner types, how to read a report without drowning in noise, and how to fit scanning into a development pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/vuln-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vuln-scan</guid>
      <pubDate>Fri, 20 Mar 2026 07:41:04 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[What is Docker Security]]></title>
      <description><![CDATA[Docker security spans image scanning, SBOMs, and runtime controls — see the CVEs, misconfigurations, and real breaches that show why each layer matters.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-docker-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-docker-security</guid>
      <pubDate>Fri, 20 Mar 2026 07:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How Does Malicious Code Spread? A Practical Security Guide]]></title>
      <description><![CDATA[Malicious code spreads through the channels people already trust: email attachments, infected downloads, removable media, compromised websites, and increasingly the software supply chain itself.]]></description>
      <link>https://safeguard.sh/resources/blog/how-does-malicious-code-spread</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-does-malicious-code-spread</guid>
      <pubDate>Fri, 20 Mar 2026 06:20:37 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA compliance requirements for covered entities]]></title>
      <description><![CDATA[What covered entities actually need under HIPAA's Privacy, Security, and Breach Notification Rules—and why compliance dashboards alone won't satisfy an OCR audit.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-compliance-requirements-for-covered-entities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-compliance-requirements-for-covered-entities</guid>
      <pubDate>Fri, 20 Mar 2026 06:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Security Vulnerability? A Clear Definition]]></title>
      <description><![CDATA[A security vulnerability is a weakness that an attacker can exploit to compromise a system. Here is a precise definition and how it differs from a threat or risk.]]></description>
      <link>https://safeguard.sh/resources/blog/security-vulnerability-definition</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-vulnerability-definition</guid>
      <pubDate>Fri, 20 Mar 2026 05:00:10 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Top 5 Docker Security Vulnerabilities]]></title>
      <description><![CDATA[Runc escapes, exposed daemons, stale base images, privileged containers, and leaked secrets: the five Docker vulnerabilities behind most real container breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/top-5-docker-security-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-5-docker-security-vulnerabilities</guid>
      <pubDate>Fri, 20 Mar 2026 04:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Organization Accounts: The Security Model]]></title>
      <description><![CDATA[PyPI Organization Accounts add real structure to a registry that was individual-first for two decades. A deep look at the security model, what it enables, and what it still doesn't.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-organization-accounts-security-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-organization-accounts-security-model</guid>
      <pubDate>Fri, 20 Mar 2026 03:39:44 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GDPR compliance basics for US and global SaaS companies]]></title>
      <description><![CDATA[A practical GDPR compliance checklist for US and global SaaS teams: fines, deadlines, and why documentation platforms like Vanta don't cover Article 32's technical controls.]]></description>
      <link>https://safeguard.sh/resources/blog/gdpr-compliance-basics-for-us-and-global-saas-companies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gdpr-compliance-basics-for-us-and-global-saas-companies</guid>
      <pubDate>Fri, 20 Mar 2026 03:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Exploit Chaining: A Supply Chain Perspective]]></title>
      <description><![CDATA[How attackers chain low and medium severity flaws across dependencies to reach critical impact, and why supply chain context changes triage priorities.]]></description>
      <link>https://safeguard.sh/resources/blog/exploit-chaining-supply-chain-perspective</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/exploit-chaining-supply-chain-perspective</guid>
      <pubDate>Fri, 20 Mar 2026 02:19:17 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Dockerfile Security Best Practices]]></title>
      <description><![CDATA[Six question-driven answers on Dockerfile hardening: pinning, root users, multi-stage builds, secrets, and the review gates that catch supply chain risk early.]]></description>
      <link>https://safeguard.sh/resources/blog/dockerfile-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dockerfile-security-best-practices</guid>
      <pubDate>Fri, 20 Mar 2026 01:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Prompt Injection as a Supply Chain Risk: When AI Dependencies Are Exploitable]]></title>
      <description><![CDATA[Prompt injection is not just an application vulnerability. When LLMs process content from the software supply chain -- package descriptions, README files, commit messages -- injection becomes a supply chain attack vector.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-supply-chain-risks</guid>
      <pubDate>Fri, 20 Mar 2026 00:58:50 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CCPA/CPRA compliance overview for businesses]]></title>
      <description><![CDATA[A practical breakdown of CCPA/CPRA compliance requirements, thresholds, penalties, and 2026 audit rules — and why software supply chain visibility is core to "reasonable security."]]></description>
      <link>https://safeguard.sh/resources/blog/ccpacpra-compliance-overview-for-businesses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ccpacpra-compliance-overview-for-businesses</guid>
      <pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Define SCA: What Software Composition Analysis Actually Means]]></title>
      <description><![CDATA[To define SCA: it's the practice of identifying every open-source component in your software and checking each for known vulnerabilities, license risk, and staleness.]]></description>
      <link>https://safeguard.sh/resources/blog/define-sca</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/define-sca</guid>
      <pubDate>Thu, 19 Mar 2026 23:38:24 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The SBOM Compliance Landscape in 2025: What You Need to Know]]></title>
      <description><![CDATA[From the US Executive Order to the EU Cyber Resilience Act, SBOM requirements are becoming law. Here is where things stand in 2025 and what organizations need to do to comply.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-compliance-landscape-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-compliance-landscape-2025</guid>
      <pubDate>Thu, 19 Mar 2026 22:17:57 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Citrix NetScaler CVE-2025 Vulnerabilities: Another Year, Another Gateway Crisis]]></title>
      <description><![CDATA[Citrix NetScaler started 2025 with multiple critical CVEs affecting ADC and Gateway products. We break down the technical details and the recurring pattern.]]></description>
      <link>https://safeguard.sh/resources/blog/citrix-netscaler-cve-2025-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/citrix-netscaler-cve-2025-vulnerabilities</guid>
      <pubDate>Thu, 19 Mar 2026 20:57:30 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[DORA Operational Resilience: Software Implications]]></title>
      <description><![CDATA[DORA became fully applicable January 17, 2025. Here's what Articles 6, 8, 28, and the ICT third-party RTS mean for the software you build, buy, and operate in the EU.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-operational-resilience-software-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-operational-resilience-software-implications</guid>
      <pubDate>Thu, 19 Mar 2026 19:37:04 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[xercesImpl: XXE Risks in Java XML Parsing and How to Configure It]]></title>
      <description><![CDATA[The xercesImpl Maven artifact turns up transitively in thousands of Java builds. Here is its real CVE history, why XXE is your configuration's fault, and the hardening block to paste.]]></description>
      <link>https://safeguard.sh/resources/blog/xercesimpl-xxe-and-maven-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xercesimpl-xxe-and-maven-guide</guid>
      <pubDate>Thu, 19 Mar 2026 18:16:37 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to Uninstall Python on a Mac Safely and Completely]]></title>
      <description><![CDATA[To uninstall Python on a Mac safely, remove only the versions you installed yourself and never touch the system Python that macOS depends on.]]></description>
      <link>https://safeguard.sh/resources/blog/uninstall-python-mac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uninstall-python-mac</guid>
      <pubDate>Thu, 19 Mar 2026 16:56:10 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Medusa Ransomware: How Supply Chain Tactics Fuel a Growing Threat]]></title>
      <description><![CDATA[Medusa ransomware has evolved beyond traditional encryption schemes, leveraging supply chain compromise to infiltrate victims. Here's what defenders need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/medusa-ransomware-supply-chain-tactics</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/medusa-ransomware-supply-chain-tactics</guid>
      <pubDate>Thu, 19 Mar 2026 15:35:43 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Salt Typhoon Telco Intrusion: What We Know]]></title>
      <description><![CDATA[Salt Typhoon breached at least nine U.S. carriers, exposing lawful intercept systems. We unpack the attack chain and what telcos must fix in 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/salt-typhoon-telco-intrusion-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/salt-typhoon-telco-intrusion-analysis</guid>
      <pubDate>Thu, 19 Mar 2026 14:15:17 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SPDX 3.0 Feature Overview for 2026]]></title>
      <description><![CDATA[What changed in SPDX 3.0 and the 3.0.1 patch release: the profile model, AI and dataset profiles, serialization choices, and what to migrate first.]]></description>
      <link>https://safeguard.sh/resources/blog/spdx-3-0-feature-overview-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spdx-3-0-feature-overview-2026</guid>
      <pubDate>Thu, 19 Mar 2026 14:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[CAPTCHA AI: Can AI Solve CAPTCHAs, and What It Means for Security]]></title>
      <description><![CDATA[Modern AI can now solve most image and text CAPTCHAs faster than people can. Here is what that breaks, why the old challenges are dying, and what bot defense looks like when the puzzle no longer works.]]></description>
      <link>https://safeguard.sh/resources/blog/captcha-ai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/captcha-ai</guid>
      <pubDate>Thu, 19 Mar 2026 13:25:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[The Most Popular Open Source Licenses, Compared]]></title>
      <description><![CDATA[MIT, Apache 2.0, GPL, BSD, MPL, and AGPL side by side: what the most popular open source licenses permit, what they require, and how to pick one.]]></description>
      <link>https://safeguard.sh/resources/blog/most-popular-open-source-licenses-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/most-popular-open-source-licenses-compared</guid>
      <pubDate>Thu, 19 Mar 2026 12:54:50 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Webmail Auth: How Email Authentication Actually Works]]></title>
      <description><![CDATA[Webmail auth spans two very different problems: proving who a user is when they sign in, and proving a message really came from the domain it claims. Both matter for security.]]></description>
      <link>https://safeguard.sh/resources/blog/webmail-auth</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webmail-auth</guid>
      <pubDate>Thu, 19 Mar 2026 12:25:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Guardrail Consolidation: Market Dynamics 2026]]></title>
      <description><![CDATA[Two dozen AI guardrail vendors in 2023. A much smaller set in 2026. The consolidation has pattern — integrated platforms beat standalone guardrails.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-trend-guardrail-consolidation-market</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-trend-guardrail-consolidation-market</guid>
      <pubDate>Thu, 19 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Evidence-Attached Fix PRs Reviewers Trust]]></title>
      <description><![CDATA[Reviewers trust fix PRs that come with evidence. Here is how to attach the right evidence so AI-assisted remediation gets approved on the first pass.]]></description>
      <link>https://safeguard.sh/resources/blog/evidence-attached-fix-prs-reviewers-trust</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/evidence-attached-fix-prs-reviewers-trust</guid>
      <pubDate>Thu, 19 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Breaking Change Awareness: Griffin AI vs Mythos]]></title>
      <description><![CDATA[An auto-fix that closes a vulnerability and breaks the build is not a fix. Breaking-change awareness separates auto-PRs that ship from auto-PRs that get reverted.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-breaking-change-awareness</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-breaking-change-awareness</guid>
      <pubDate>Thu, 19 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[India CERT-In Software Supply Chain Update]]></title>
      <description><![CDATA[A senior engineer's view of how CERT-In directives in 2025 and 2026 are reshaping software supply chain expectations for organizations operating in India.]]></description>
      <link>https://safeguard.sh/resources/blog/india-cert-in-software-supply-chain-update</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/india-cert-in-software-supply-chain-update</guid>
      <pubDate>Thu, 19 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001:2022 Aligned Supply Chain Program]]></title>
      <description><![CDATA[ISO 27001:2022 added explicit supply chain controls in Annex A. Learn how to build a program that satisfies A.5.19 through A.5.23 with continuous evidence.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-2022-aligned-supply-chain-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-2022-aligned-supply-chain-program</guid>
      <pubDate>Thu, 19 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Runtime Container Drift: Supply Chain Implications]]></title>
      <description><![CDATA[Runtime drift is the last honest witness in container supply chain defence. This post covers what drift signals tell you, how to instrument for them, and how to investigate without overwhelming on-call.]]></description>
      <link>https://safeguard.sh/resources/blog/runtime-container-drift-supply-chain-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runtime-container-drift-supply-chain-implications</guid>
      <pubDate>Thu, 19 Mar 2026 12:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SecOps Tool Consolidation Program Blueprint]]></title>
      <description><![CDATA[Tool sprawl is the slow-motion failure mode of every SecOps program. Here is a blueprint for consolidating tools without losing coverage and without political damage.]]></description>
      <link>https://safeguard.sh/resources/blog/secops-tool-consolidation-program-blueprint</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secops-tool-consolidation-program-blueprint</guid>
      <pubDate>Thu, 19 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[VEX Statements: Eliminating SBOM Noise In 2026]]></title>
      <description><![CDATA[An SBOM without VEX is a noise machine. Here is how disciplined VEX authoring cuts vulnerability backlogs by 70-90% while improving defensibility, not weakening it.]]></description>
      <link>https://safeguard.sh/resources/blog/vex-statements-eliminating-sbom-noise-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vex-statements-eliminating-sbom-noise-2026</guid>
      <pubDate>Thu, 19 Mar 2026 12:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Fog Ransomware: Why the Education Sector Keeps Getting Hit]]></title>
      <description><![CDATA[Fog ransomware has carved a niche targeting schools and universities, exploiting chronic underfunding and SonicWall VPN vulnerabilities to devastating effect.]]></description>
      <link>https://safeguard.sh/resources/blog/fog-ransomware-education-sector-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fog-ransomware-education-sector-attacks</guid>
      <pubDate>Thu, 19 Mar 2026 11:34:23 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GitLab CI Supply Chain Hardening Checklist 2026]]></title>
      <description><![CDATA[A 2026 hardening checklist for GitLab CI: ID tokens, protected branches, runner isolation, included templates, and the controls that actually shrink blast radius.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-ci-supply-chain-hardening-checklist-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-ci-supply-chain-hardening-checklist-2026</guid>
      <pubDate>Thu, 19 Mar 2026 11:30:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Container Security Scanning: A Practical Guide]]></title>
      <description><![CDATA[What a container security scan checks for, where it fits in your pipeline, and how to turn a wall of image CVEs into a short list of things worth fixing.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-scan</guid>
      <pubDate>Thu, 19 Mar 2026 10:45:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Authorization Patterns in 2026]]></title>
      <description><![CDATA[The Model Context Protocol shifted agent integration from custom glue to a standard surface. Authorization patterns that work, and the ones that keep biting teams.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-authorization-patterns-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-authorization-patterns-2026</guid>
      <pubDate>Thu, 19 Mar 2026 10:45:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Falco 0.40: Modern eBPF Is Now Default]]></title>
      <description><![CDATA[Falco's 0.40 release line makes modern eBPF (CO-RE) the default driver, deprecates the legacy probe and gVisor engine, and changes how operators ship Falco. Here's what changed and what to test.]]></description>
      <link>https://safeguard.sh/resources/blog/falco-0-40-modern-ebpf-default-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/falco-0-40-modern-ebpf-default-2026</guid>
      <pubDate>Thu, 19 Mar 2026 10:30:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What Is Hashing? A Plain-English Guide to One-Way Functions]]></title>
      <description><![CDATA[Hashing turns any input into a fixed-size fingerprint that cannot be reversed. It quietly powers password storage, integrity checks, and digital signatures across modern software.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-hashing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-hashing</guid>
      <pubDate>Thu, 19 Mar 2026 10:13:57 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Container Security Best Practices That Actually Reduce Risk]]></title>
      <description><![CDATA[Container security best practices come down to a small set of high-leverage habits: minimal images, non-root users, scanned dependencies, and least-privilege runtime. Here is the working list.]]></description>
      <link>https://safeguard.sh/resources/blog/containers-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/containers-security-best-practices</guid>
      <pubDate>Thu, 19 Mar 2026 10:10:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best Container Image Scanners 2026]]></title>
      <description><![CDATA[A fact-based review of the best container image scanners in 2026, comparing Trivy, Grype, Snyk, Prisma Cloud, and Safeguard on accuracy and noise.]]></description>
      <link>https://safeguard.sh/resources/blog/best-container-image-scanners-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-container-image-scanners-2026</guid>
      <pubDate>Thu, 19 Mar 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Docker and Containers: A Practical Security Guide]]></title>
      <description><![CDATA[Docker and containers share the host kernel, so their security model is different from virtual machines. Here is how to build, run, and scan containers safely.]]></description>
      <link>https://safeguard.sh/resources/blog/dockers-and-containers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dockers-and-containers</guid>
      <pubDate>Thu, 19 Mar 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Trusted Publishing Token Leaks in 2025]]></title>
      <description><![CDATA[Trusted Publishing made PyPI safer, but leaked short-lived OIDC tokens in CI logs kicked off a credential-replay campaign that PyPI, GitHub, and Sonatype all tracked in 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-trusted-publishing-token-leak-campaign-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-trusted-publishing-token-leak-campaign-2025</guid>
      <pubDate>Thu, 19 Mar 2026 10:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Veracode vs Snyk: A Practical Comparison]]></title>
      <description><![CDATA[Veracode and Snyk both cover SAST and SCA, but they come from opposite starting points — Veracode from centralized, policy-driven enterprise scanning, Snyk from developer-first IDE and git integration.]]></description>
      <link>https://safeguard.sh/resources/blog/veracode-vs-snyk-a-practical-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/veracode-vs-snyk-a-practical-comparison</guid>
      <pubDate>Thu, 19 Mar 2026 10:00:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Kubernetes Security]]></title>
      <description><![CDATA[Kubernetes security spans four layers — cloud, cluster, container, code — and misconfiguration, not novel exploits, causes most real-world incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-kubernetes-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-kubernetes-security</guid>
      <pubDate>Thu, 19 Mar 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Dev Containers Security Baseline for 2026]]></title>
      <description><![CDATA[A practical security baseline for devcontainer.json files in 2026, covering base image selection, features, lifecycle scripts, and the supply chain controls that actually matter.]]></description>
      <link>https://safeguard.sh/resources/blog/devcontainers-security-baseline-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devcontainers-security-baseline-2026</guid>
      <pubDate>Thu, 19 Mar 2026 09:45:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis for Ruby and RubyGems in 2026]]></title>
      <description><![CDATA[Ruby reachability under metaprogramming, Rails autoloading, and Bundler groups. What bundler-audit and modern tools handle, and where they punt to over-approximation.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-ruby-rubygems-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-ruby-rubygems-2026</guid>
      <pubDate>Thu, 19 Mar 2026 09:45:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Cloud-Native Security Practices That Actually Scale]]></title>
      <description><![CDATA[Containers, Kubernetes, and ephemeral infrastructure broke the perimeter security model. These are the cloud-native security practices that hold up past your first hundred services.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-native-security-practices-that-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-native-security-practices-that-scale</guid>
      <pubDate>Thu, 19 Mar 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Cybersecurity Platforms: When Consolidation Wins]]></title>
      <description><![CDATA[Consolidating point tools into a platform can cut cost and alert fatigue — or lock you into one vendor's blind spots. Here is a clear-eyed rule for when cybersecurity platforms pay off and when they do not.]]></description>
      <link>https://safeguard.sh/resources/blog/cybersecurity-platforms-when-consolidation-wins</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cybersecurity-platforms-when-consolidation-wins</guid>
      <pubDate>Thu, 19 Mar 2026 09:00:00 GMT</pubDate>
      <category>Enterprise</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[EU AI Act: Software Supply Chain Implications 2026]]></title>
      <description><![CDATA[The EU AI Act's 2026 obligations reshape software supply chain requirements for AI system providers, deployers, and upstream model suppliers across every sector.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-ai-act-software-supply-chain-implications-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-ai-act-software-supply-chain-implications-2026</guid>
      <pubDate>Thu, 19 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NIST Cybersecurity Framework (CSF) explained]]></title>
      <description><![CDATA[NIST CSF 2.0 added a Govern function and supply chain risk category in 2024. Here's what it requires, how Vanta maps it, and where build-level evidence closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-cybersecurity-framework-csf-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-cybersecurity-framework-csf-explained</guid>
      <pubDate>Thu, 19 Mar 2026 09:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Fortinet FortiGate Authentication Bypass: CVE-2024-55591 Explained]]></title>
      <description><![CDATA[A critical authentication bypass in FortiOS and FortiProxy allowed attackers to gain super-admin privileges via crafted Node.js websocket requests. Here's what happened and how to protect your infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/fortinet-fortigate-auth-bypass-cve-2024-55591</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fortinet-fortigate-auth-bypass-cve-2024-55591</guid>
      <pubDate>Thu, 19 Mar 2026 08:53:30 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What Gartner's Container Security Coverage Gets Right (and Skips)]]></title>
      <description><![CDATA[Gartner's container security research correctly frames the shift toward CNAPP consolidation, but its category boundaries often lag how teams actually operate scanning day to day.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-on-gartners-radar</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-on-gartners-radar</guid>
      <pubDate>Thu, 19 Mar 2026 08:45:00 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Mend (WhiteSource) Platform Deep Review 2026]]></title>
      <description><![CDATA[A senior-engineer's deep review of Mend (formerly WhiteSource) in 2026: SCA accuracy, reachability, container scanning, AI features, pricing, and where it fits.]]></description>
      <link>https://safeguard.sh/resources/blog/mend-whitesource-platform-deep-review-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mend-whitesource-platform-deep-review-2026</guid>
      <pubDate>Thu, 19 Mar 2026 08:15:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Integration: Wiring Security Into Pipelines You Already Have]]></title>
      <description><![CDATA[You do not need a new pipeline — you need to instrument the one you have. A stage-by-stage map for DevSecOps integration in Jenkins, GitHub Actions, GitLab CI, or Azure DevOps.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-integration-existing-pipelines</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-integration-existing-pipelines</guid>
      <pubDate>Thu, 19 Mar 2026 08:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Continuous Compliance Monitoring]]></title>
      <description><![CDATA[Continuous compliance monitoring replaces the annual audit scramble with automated, always-on checks that map live system evidence to control requirements.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-continuous-compliance-monitoring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-continuous-compliance-monitoring</guid>
      <pubDate>Thu, 19 Mar 2026 07:33:03 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Monitoring Guide]]></title>
      <description><![CDATA[A practical Kubernetes monitoring guide: what to track across nodes, control plane, and workloads, the tools teams use, and where monitoring alone misses supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-monitoring-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-monitoring-guide</guid>
      <pubDate>Thu, 19 Mar 2026 07:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[SPDX 3.0.1: The Patch Release That Cleared ISO and OMG Submission]]></title>
      <description><![CDATA[SPDX 3.0.1 was announced on December 27, 2024, bundling fixes from 3.0.0 implementation and the edits required for OMG SPDX/3.0 and ISO/IEC submission.]]></description>
      <link>https://safeguard.sh/resources/blog/spdx-3-0-1-patch-release-iso-omg-submission</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spdx-3-0-1-patch-release-iso-omg-submission</guid>
      <pubDate>Thu, 19 Mar 2026 06:12:37 GMT</pubDate>
      <category>Standards</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP authorization process for cloud vendors]]></title>
      <description><![CDATA[A breakdown of the FedRAMP authorization process for cloud vendors — timelines, JAB vs. agency ATOs, 3PAO testing, costs, and where GRC tools like Vanta fall short on supply chain evidence.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-authorization-process-for-cloud-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-authorization-process-for-cloud-vendors</guid>
      <pubDate>Thu, 19 Mar 2026 06:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Ivanti Connect Secure Zero-Day: CVE-2025-0282 Under Active Exploitation]]></title>
      <description><![CDATA[A stack-based buffer overflow in Ivanti Connect Secure allowed unauthenticated remote code execution. Chinese threat actors exploited it before any patch existed.]]></description>
      <link>https://safeguard.sh/resources/blog/ivanti-connect-secure-cve-2025-0282-zero-day</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ivanti-connect-secure-cve-2025-0282-zero-day</guid>
      <pubDate>Thu, 19 Mar 2026 04:52:10 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is Kubernetes RBAC]]></title>
      <description><![CDATA[Kubernetes RBAC controls who can do what in your cluster. Here's how Roles, Bindings, and ClusterRoles work — and where they commonly fail.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-kubernetes-rbac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-kubernetes-rbac</guid>
      <pubDate>Thu, 19 Mar 2026 04:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard 5.0: The Next Generation of Software Supply Chain Security]]></title>
      <description><![CDATA[Safeguard 5.0 introduces Griffin AI, expanded SBOM analysis, and a redesigned policy engine. Here is what is new and why it matters for your security program.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-v5-release-announcement</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-v5-release-announcement</guid>
      <pubDate>Thu, 19 Mar 2026 03:31:43 GMT</pubDate>
      <category>Product Update</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CMMC compliance levels for defense contractors]]></title>
      <description><![CDATA[CMMC's three levels are now law for defense contractors. Here's what Level 1, 2, and 3 require, when they hit your contracts, and where tools like Vanta fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-compliance-levels-for-defense-contractors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-compliance-levels-for-defense-contractors</guid>
      <pubDate>Thu, 19 Mar 2026 03:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[What is a Post-Quantum Migration Plan]]></title>
      <description><![CDATA[A post-quantum migration plan is your inventory-and-replacement roadmap from RSA and ECC to ML-KEM and ML-DSA. Here's what a credible one contains, step by step.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-post-quantum-migration-plan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-post-quantum-migration-plan</guid>
      <pubDate>Thu, 19 Mar 2026 02:11:17 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Sofia Marchetti)</author>
    </item>
    <item>
      <title><![CDATA[What Are Kubernetes Network Policies]]></title>
      <description><![CDATA[Kubernetes clusters default to flat, all-to-all pod networking. Here's how NetworkPolicy objects, CNI enforcement, and default-deny rules actually stop lateral movement.]]></description>
      <link>https://safeguard.sh/resources/blog/what-are-kubernetes-network-policies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-are-kubernetes-network-policies</guid>
      <pubDate>Thu, 19 Mar 2026 01:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Zoom Incidents: Software Supply Chain Dimensions]]></title>
      <description><![CDATA[Zoom's security history from 2020 onward reshaped how the industry thinks about conferencing software supply chains, from installers to third-party components.]]></description>
      <link>https://safeguard.sh/resources/blog/zoom-incidents-software-supply-chain-dimensions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zoom-incidents-software-supply-chain-dimensions</guid>
      <pubDate>Thu, 19 Mar 2026 00:50:50 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 Type 1 vs Type 2: timeline, cost, and key differences]]></title>
      <description><![CDATA[SOC 2 Type 1 vs Type 2: what each audit actually tests, realistic timelines and costs, and how supply chain evidence differs from Drata's approach.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-type-1-vs-type-2-timeline-cost-and-key-differences</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-type-1-vs-type-2-timeline-cost-and-key-differences</guid>
      <pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Space Industry Software Supply Chain: Emerging Reality]]></title>
      <description><![CDATA[COTS software, mega-constellations, and export controls are colliding. The space sector's software supply chain risk is shifting faster than its tooling.]]></description>
      <link>https://safeguard.sh/resources/blog/space-industry-software-supply-chain-emerging</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/space-industry-software-supply-chain-emerging</guid>
      <pubDate>Wed, 18 Mar 2026 23:30:23 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[End-of-Year Security Planning: Setting Up Next Year for Success]]></title>
      <description><![CDATA[The end of the year is when security programs are made or broken. Here is how to conduct an effective annual security review and build a plan that will actually be executed.]]></description>
      <link>https://safeguard.sh/resources/blog/end-of-year-security-planning-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/end-of-year-security-planning-guide</guid>
      <pubDate>Wed, 18 Mar 2026 22:09:56 GMT</pubDate>
      <category>Security Strategy</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Fulcio Certificate Lifecycle: Enterprise View]]></title>
      <description><![CDATA[Fulcio issues short-lived certificates for keyless signing. Here is the enterprise view of how those certificates are issued, validated, and woven into long-term trust.]]></description>
      <link>https://safeguard.sh/resources/blog/fulcio-certificate-lifecycle-enterprise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fulcio-certificate-lifecycle-enterprise</guid>
      <pubDate>Wed, 18 Mar 2026 20:49:30 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Digital Health HIPAA Supply Chain Intersection]]></title>
      <description><![CDATA[Digital health startups collide with HIPAA obligations as soon as they touch clinical data. A regulatory map of the supply chain choke points.]]></description>
      <link>https://safeguard.sh/resources/blog/digital-health-hipaa-supply-chain-intersection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/digital-health-hipaa-supply-chain-intersection</guid>
      <pubDate>Wed, 18 Mar 2026 19:29:03 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Data Pipeline Platform Migration Security]]></title>
      <description><![CDATA[Moving from one orchestration platform to another surfaces hidden trust relationships. A security-first migration plan for Airflow, Dagster, and Prefect transitions.]]></description>
      <link>https://safeguard.sh/resources/blog/data-pipeline-platform-migration-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/data-pipeline-platform-migration-security</guid>
      <pubDate>Wed, 18 Mar 2026 18:08:36 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security in 2024: A Year in Review]]></title>
      <description><![CDATA[From the CrowdStrike outage to state-sponsored npm campaigns and regulatory milestones, 2024 was the year supply chain security went from niche concern to operational necessity.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-2024-year-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-2024-year-review</guid>
      <pubDate>Wed, 18 Mar 2026 16:48:10 GMT</pubDate>
      <category>Industry Trends</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Reproducible Builds Debian: The Long View]]></title>
      <description><![CDATA[Debian's Reproducible Builds project has been at it for over a decade. Here's what they've learned, what still isn't reproducible, and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/reproducible-builds-debian-long-view</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reproducible-builds-debian-long-view</guid>
      <pubDate>Wed, 18 Mar 2026 15:27:43 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to Use AI for Stock Trading (and the Risks Nobody Mentions)]]></title>
      <description><![CDATA[Using AI for stock trading means applying models to signals, screening, and execution, but the security and reliability risks are as important as the strategy. Here is a grounded look.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-use-ai-for-stock-trading</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-use-ai-for-stock-trading</guid>
      <pubDate>Wed, 18 Mar 2026 15:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[AI Cybersecurity Software: What It Actually Does and Where It Falls Short]]></title>
      <description><![CDATA[AI cybersecurity software uses machine learning to spot anomalies, triage alerts, and prioritize risk faster than humans can. Here is what it genuinely helps with and where it still needs a human.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-cybersecurity-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-cybersecurity-software</guid>
      <pubDate>Wed, 18 Mar 2026 14:20:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How a Container Image Scanner Works (and Which One to Use)]]></title>
      <description><![CDATA[A container image scanner inspects the layers, packages, and configuration inside an image to find known vulnerabilities before you ship it. Here is how the scan works and what separates a good tool from a noisy one.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-scanner</guid>
      <pubDate>Wed, 18 Mar 2026 14:20:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[How to Choose a Container Image Vulnerability Tool]]></title>
      <description><![CDATA[A container image vulnerability tool scans the layers, packages, and metadata inside an image so you catch known CVEs before they ship to production. Here is how to pick and use one well.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-vulnerability-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-vulnerability-tool</guid>
      <pubDate>Wed, 18 Mar 2026 14:20:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[What Does MCP Stand For? Model Context Protocol and Its Security Model]]></title>
      <description><![CDATA[MCP stands for Model Context Protocol, the open standard that lets AI assistants talk to your tools and data. Here is what it is and where the security risks live.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-stands-for</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-stands-for</guid>
      <pubDate>Wed, 18 Mar 2026 14:20:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Which AI Enabled Tools Should I Use (dtrgstech): A Security Guide]]></title>
      <description><![CDATA[A practical framework for deciding which AI-enabled tools you should actually adopt, weighed against the data-exposure and supply chain risks they introduce.]]></description>
      <link>https://safeguard.sh/resources/blog/which-ai-enabled-tools-should-i-use-dtrgstech</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/which-ai-enabled-tools-should-i-use-dtrgstech</guid>
      <pubDate>Wed, 18 Mar 2026 14:20:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Post-Incident Vendor Coordination]]></title>
      <description><![CDATA[When a vendor's incident affects you, the coordination work between their IR team and your ops becomes its own project. How to run it well.]]></description>
      <link>https://safeguard.sh/resources/blog/post-incident-vendor-coordination</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/post-incident-vendor-coordination</guid>
      <pubDate>Wed, 18 Mar 2026 14:07:16 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[eBPF Security Controls: A Production Experience Report]]></title>
      <description><![CDATA[Field notes on running Tetragon, Falco, and Cilium eBPF controls in production Kubernetes clusters, with observed overhead, policy traps, and kernel constraints.]]></description>
      <link>https://safeguard.sh/resources/blog/ebpf-security-controls-production-experience</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ebpf-security-controls-production-experience</guid>
      <pubDate>Wed, 18 Mar 2026 12:46:50 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AWS Bedrock Guardrails for Agent Workloads: A Defender's Walkthrough]]></title>
      <description><![CDATA[Bedrock Guardrails now span prompt filtering, contextual grounding checks, and tool-use policies. We trace how they fit into a supply chain threat model for production agents.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-bedrock-agentcore-guardrails-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-bedrock-agentcore-guardrails-2026</guid>
      <pubDate>Wed, 18 Mar 2026 12:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Audit Trail Quality: Griffin AI vs Mythos]]></title>
      <description><![CDATA[An audit trail is only useful if you can answer questions from it. Quality is not about volume — it&apos;s about the ability to reconstruct decisions after the fact.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-audit-trail-quality</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-audit-trail-quality</guid>
      <pubDate>Wed, 18 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Sanitizer Detection: Griffin AI vs Mythos]]></title>
      <description><![CDATA[A vulnerability that passes through a working sanitizer is not a vulnerability. Detecting that sanitizer accurately is the difference between actionable findings and noise.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-sanitizer-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-sanitizer-detection</guid>
      <pubDate>Wed, 18 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security Predictions for 2025]]></title>
      <description><![CDATA[From AI-generated code risks to regulatory enforcement and package manager security evolution, here are the trends that will define software supply chain security in 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-predictions-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-predictions-2025</guid>
      <pubDate>Wed, 18 Mar 2026 11:26:23 GMT</pubDate>
      <category>Industry Trends</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[AI Python Code Correctors: What They Catch and What They Miss]]></title>
      <description><![CDATA[AI Python code correctors fix syntax and obvious bugs fast, but they miss the security and correctness issues that matter most. Here is where they help, where they fail, and how to use them safely.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-python-code-correctors-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-python-code-correctors-review</guid>
      <pubDate>Wed, 18 Mar 2026 11:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[AI-BOM and ML-BOM: The State of Standards in 2026]]></title>
      <description><![CDATA[Where AI-BOM and ML-BOM specifications stand in 2026, which formats have real adoption, and what to capture today even if the standards are still in motion.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-bom-ml-bom-state-of-standards-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-bom-ml-bom-state-of-standards-2026</guid>
      <pubDate>Wed, 18 Mar 2026 10:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Container Runtime Comparison: A 2026 Buyer's Guide]]></title>
      <description><![CDATA[A practical container runtime comparison for 2026 buyers: containerd, CRI-O, gVisor, Kata, and Youki measured against real production workloads.]]></description>
      <link>https://safeguard.sh/resources/blog/container-runtime-comparison-buyer-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-runtime-comparison-buyer-2026</guid>
      <pubDate>Wed, 18 Mar 2026 10:30:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Jailbreaking AI: How LLM Jailbreaks Work and How to Defend Against Them]]></title>
      <description><![CDATA[Jailbreaking AI means getting a model to bypass its own safety guardrails. This guide explains how jailbreaks work conceptually, how they differ from prompt injection, and how to build layered defenses.]]></description>
      <link>https://safeguard.sh/resources/blog/jail-break-ai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jail-break-ai</guid>
      <pubDate>Wed, 18 Mar 2026 10:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Blue Yonder Termite Ransomware: SaaS Supply-Chain Outage in Retail]]></title>
      <description><![CDATA[In November 2024 the Termite ransomware group hit Blue Yonder, taking workforce-management and logistics SaaS offline for Starbucks, Sainsbury's, and Morrisons. We unpack the SaaS supply-chain blast radius.]]></description>
      <link>https://safeguard.sh/resources/blog/blue-yonder-termite-ransomware-retail-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/blue-yonder-termite-ransomware-retail-supply-chain</guid>
      <pubDate>Wed, 18 Mar 2026 10:05:56 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[GenAI Code Assistants and Package Hallucination: 2026 Update]]></title>
      <description><![CDATA[LLM-suggested package names that do not exist are a registered attack vector in 2026. Here is where hallucination rates sit today and how to contain them.]]></description>
      <link>https://safeguard.sh/resources/blog/genai-package-hallucination-2026-update</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/genai-package-hallucination-2026-update</guid>
      <pubDate>Wed, 18 Mar 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Security Champion?]]></title>
      <description><![CDATA[A security champion is a developer who advocates for security inside their team, bridging engineering and the security function. Learn the role, how programs work, and why they scale culture.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-security-champion</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-security-champion</guid>
      <pubDate>Wed, 18 Mar 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[What is Kubernetes Pod Security]]></title>
      <description><![CDATA[Pod Security Standards replaced PodSecurityPolicy in Kubernetes 1.25. Here's what Kubernetes pod security means and how to enforce it in production.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-kubernetes-pod-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-kubernetes-pod-security</guid>
      <pubDate>Wed, 18 Mar 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Fortinet CVE-2024-21762 Deep Dive: Why SSL-VPN Keeps Producing Critical CVEs]]></title>
      <description><![CDATA[The February 2024 FortiOS SSL-VPN remote code execution vulnerability continues a pattern of high-impact CVEs in edge appliances. A technical retrospective and structural analysis.]]></description>
      <link>https://safeguard.sh/resources/blog/fortinet-cve-2024-21762-ssl-vpn-rce-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fortinet-cve-2024-21762-ssl-vpn-rce-deep-dive</guid>
      <pubDate>Wed, 18 Mar 2026 09:45:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Cloud-Native Security Platforms: What to Look For]]></title>
      <description><![CDATA[A cloud native security platform needs to cover code, containers, and cloud configuration as one connected surface — here's what separates a real platform from a bundle of point tools.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-native-security-platforms-what-to-look-for</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-native-security-platforms-what-to-look-for</guid>
      <pubDate>Wed, 18 Mar 2026 09:30:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Generate an SBOM From a Container Image]]></title>
      <description><![CDATA[A practical walkthrough of how to generate an SBOM from a container image using Syft, Trivy, and Docker Scout, plus how to keep the output trustworthy.]]></description>
      <link>https://safeguard.sh/resources/blog/generate-sbom-from-container-image</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/generate-sbom-from-container-image</guid>
      <pubDate>Wed, 18 Mar 2026 09:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The GPL License Explained: What It Means for Software Security]]></title>
      <description><![CDATA[A practitioner's walkthrough of what the GPL license actually requires, why it matters for your dependency tree, and how it intersects with software security and compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/gpl-license-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gpl-license-explained</guid>
      <pubDate>Wed, 18 Mar 2026 09:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Top 10 Training: A Practical Guide for Developers]]></title>
      <description><![CDATA[What OWASP Top 10 training actually needs to cover in 2026 now that the 2025 list has landed, plus where to find free, developer-focused courses that stick.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-training</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-training</guid>
      <pubDate>Wed, 18 Mar 2026 09:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to Secure Docker Containers: A Practical Hardening Guide]]></title>
      <description><![CDATA[A working checklist to secure Docker containers, from non-root users and minimal base images to capability drops, read-only filesystems, and image scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-docker-containers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-docker-containers</guid>
      <pubDate>Wed, 18 Mar 2026 09:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Container Network Security: How to Lock Down Pod-to-Pod Traffic]]></title>
      <description><![CDATA[Container network security is about controlling which workloads can talk to each other and blocking the rest by default. Here is how to build that in Kubernetes and beyond.]]></description>
      <link>https://safeguard.sh/resources/blog/container-network-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-network-security</guid>
      <pubDate>Wed, 18 Mar 2026 09:20:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[AI Bill of Materials (ML-BOM) Standards in 2026]]></title>
      <description><![CDATA[A senior engineer's survey of AI-BOM and ML-BOM standards in 2026, from CycloneDX ML components to SPDX 3.0 AI profile, and what to actually ship.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-bill-of-materials-ml-bom-standards-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-bill-of-materials-ml-bom-standards-2026</guid>
      <pubDate>Wed, 18 Mar 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[A Black Duck Scan: What It Covers vs SCA Alternatives]]></title>
      <description><![CDATA[A Black Duck scan focuses heavily on open-source license compliance and binary composition analysis — here's what it actually covers, and where modern SCA alternatives pull ahead.]]></description>
      <link>https://safeguard.sh/resources/blog/blackduck-scan-what-it-covers-vs-sca-alternatives</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/blackduck-scan-what-it-covers-vs-sca-alternatives</guid>
      <pubDate>Wed, 18 Mar 2026 09:00:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Continuous Compliance Monitoring: A Practical Guide for Security Teams]]></title>
      <description><![CDATA[How to replace periodic compliance audits with continuous, automated monitoring that catches drift before auditors do.]]></description>
      <link>https://safeguard.sh/resources/blog/continuous-compliance-monitoring-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/continuous-compliance-monitoring-guide</guid>
      <pubDate>Wed, 18 Mar 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[DORA Third-Party ICT Risk for Financial Services 2026]]></title>
      <description><![CDATA[A senior engineer's view of DORA third-party ICT risk in 2026: register of information, concentration risk, subcontractor depth, and the operational controls regulators actually test.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-financial-services-third-party-ict-risk-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-financial-services-third-party-ict-risk-2026</guid>
      <pubDate>Wed, 18 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SOC 1 vs SOC 2 vs SOC 3 explained]]></title>
      <description><![CDATA[SOC 1, SOC 2, and SOC 3 answer different questions for different audiences. Here is what each proves, and where Drata and Safeguard fit in your audit prep.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-1-vs-soc-2-vs-soc-3-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-1-vs-soc-2-vs-soc-3-explained</guid>
      <pubDate>Wed, 18 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Rust Embedded Supply Chain Guide]]></title>
      <description><![CDATA[Rust is moving into embedded production fast. The supply chain shape for firmware is different from server-side Rust — smaller trees, longer lifetimes, tighter regulations.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-embedded-supply-chain-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-embedded-supply-chain-guide</guid>
      <pubDate>Wed, 18 Mar 2026 08:45:30 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AI Chips Explained: What They Are and How to Secure Them]]></title>
      <description><![CDATA[AI chips are specialized processors built to run matrix math at scale, and the way you provision, share, and supply-chain-source them creates security risk most teams never model.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-chips</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-chips</guid>
      <pubDate>Wed, 18 Mar 2026 08:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems Reserved Namespace Claims]]></title>
      <description><![CDATA[A look at how organizations can claim reserved namespace prefixes on RubyGems.org, what the policy currently supports, and where it falls short for real enterprise use cases.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-reserved-namespace-claims</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-reserved-namespace-claims</guid>
      <pubDate>Wed, 18 Mar 2026 07:25:03 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What Are Kubernetes Admission Controllers]]></title>
      <description><![CDATA[Kubernetes admission controllers intercept every API request before it hits etcd. Here's how validating and mutating webhooks work, what's enabled by default, and where they fail.]]></description>
      <link>https://safeguard.sh/resources/blog/what-are-kubernetes-admission-controllers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-are-kubernetes-admission-controllers</guid>
      <pubDate>Wed, 18 Mar 2026 07:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[OpenTelemetry for Supply Chain Traces: Instrumenting the Pipeline]]></title>
      <description><![CDATA[How OpenTelemetry turns CI/CD pipelines into a traceable, queryable graph that exposes supply chain risk from source control to production deployment.]]></description>
      <link>https://safeguard.sh/resources/blog/opentelemetry-for-supply-chain-traces</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/opentelemetry-for-supply-chain-traces</guid>
      <pubDate>Wed, 18 Mar 2026 06:04:36 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 vs SOC 2: which framework should you pursue first?]]></title>
      <description><![CDATA[ISO 27001 and SOC 2 solve different problems for different buyers. Here's how to choose which to pursue first, and how supply chain security evidence supports both.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-vs-soc-2-which-framework-should-you-pursue-first</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-vs-soc-2-which-framework-should-you-pursue-first</guid>
      <pubDate>Wed, 18 Mar 2026 06:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[MITRE ATT&CK Meets SSDF: A Mapping]]></title>
      <description><![CDATA[ATT&CK describes how adversaries operate; SSDF describes how to build software that resists them. Here's how to map adversary techniques to secure-development tasks so your threat model drives real engineering change.]]></description>
      <link>https://safeguard.sh/resources/blog/mitre-attack-meets-ssdf-mapping</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mitre-attack-meets-ssdf-mapping</guid>
      <pubDate>Wed, 18 Mar 2026 04:44:09 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is Cloud Native Security]]></title>
      <description><![CDATA[Cloud native security explained: what it is, the 4C's model, real breach examples, SBOM requirements, and the tools that secure containers and Kubernetes.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-cloud-native-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-cloud-native-security</guid>
      <pubDate>Wed, 18 Mar 2026 04:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[The 2024 End-of-Year Vulnerability Disclosure Report]]></title>
      <description><![CDATA[A look back at vulnerability disclosure in 2024: counts, severity distribution, time-to-patch, and the handful of incidents that shifted practice. Numbers, not narrative.]]></description>
      <link>https://safeguard.sh/resources/blog/end-of-year-vulnerability-disclosure-report-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/end-of-year-vulnerability-disclosure-report-2024</guid>
      <pubDate>Wed, 18 Mar 2026 03:23:43 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA vs SOC 2: do you need both?]]></title>
      <description><![CDATA[SOC 2 and HIPAA solve different problems. Here's what compliance automation platforms like Drata cover, where the software supply chain evidence gap remains, and how to close it.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-vs-soc-2-do-you-need-both</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-vs-soc-2-do-you-need-both</guid>
      <pubDate>Wed, 18 Mar 2026 03:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[What is a Package Registry Mirror]]></title>
      <description><![CDATA[A package registry mirror is a local copy or caching proxy of a public registry. It keeps builds running when npm is down — and controls what enters your supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-package-registry-mirror</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-package-registry-mirror</guid>
      <pubDate>Wed, 18 Mar 2026 02:03:16 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Marcus Webb)</author>
    </item>
    <item>
      <title><![CDATA[What is a CNAPP (Cloud Native Application Protection Platform)]]></title>
      <description><![CDATA[CNAPP unifies CSPM, CWPP, and CIEM into one platform. Here's what it actually does, how it emerged, and where today's tools fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-cnapp-cloud-native-application-protection-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-cnapp-cloud-native-application-protection-platform</guid>
      <pubDate>Wed, 18 Mar 2026 01:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 Type II for Engineering Teams: What Auditors Actually Check]]></title>
      <description><![CDATA[Auditors don't start with your policies — they sample your PRs, tickets, and access reviews. Here's what a SOC 2 Type II observation window actually tests, control by control.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-type-ii-for-engineering-teams-what-auditors-actually-check</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-type-ii-for-engineering-teams-what-auditors-actually-check</guid>
      <pubDate>Wed, 18 Mar 2026 00:42:49 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marcus Webb)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise GRC vs point compliance tools: what's the diff...]]></title>
      <description><![CDATA[Compliance automation tools like Drata optimize for audit prep. Enterprise GRC runs risk, vendor, and software supply chain programs continuously. Here's the real difference.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-grc-vs-point-compliance-tools-whats-the-difference</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-grc-vs-point-compliance-tools-whats-the-difference</guid>
      <pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[State of CVE Disclosure and KEV in 2026]]></title>
      <description><![CDATA[A senior-analyst view of CVE disclosure, KEV catalog growth, and the operational patterns that keep pace with them in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-cve-disclosure-and-kev-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-cve-disclosure-and-kev-2026</guid>
      <pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Exploitation Trends in 2024: What the Data Shows]]></title>
      <description><![CDATA[Analysis of 2024 vulnerability exploitation patterns reveals faster weaponization timelines, shifting target profiles, and the growing importance of edge device vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-exploitation-trends-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-exploitation-trends-2024</guid>
      <pubDate>Tue, 17 Mar 2026 23:22:23 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Schneider Electric Hellcat: Jira, Infostealers, and Baguette Ransoms]]></title>
      <description><![CDATA[In November 2024 the Hellcat ransomware group breached Schneider Electric's Atlassian Jira via Lumma infostealer credentials. We unpack the SaaS supply-chain anatomy and the project-tracker as data target.]]></description>
      <link>https://safeguard.sh/resources/blog/schneider-electric-hellcat-jira-infostealer-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/schneider-electric-hellcat-jira-infostealer-2024</guid>
      <pubDate>Tue, 17 Mar 2026 22:01:56 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Download Statistics as a Security Signal]]></title>
      <description><![CDATA[PyPI download numbers are noisy, gameable, and widely misused. A closer look at what they actually measure, how to read them for security purposes, and where they break.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-download-statistics-as-security-signal</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-download-statistics-as-security-signal</guid>
      <pubDate>Tue, 17 Mar 2026 20:41:29 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[BlackTech Firmware Supply Chain Operations]]></title>
      <description><![CDATA[BlackTech's firmware implants in Cisco routers turned edge devices into long-dwell footholds. A look at the tradecraft and what defenders missed.]]></description>
      <link>https://safeguard.sh/resources/blog/blacktech-firmware-supply-chain-operations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/blacktech-firmware-supply-chain-operations</guid>
      <pubDate>Tue, 17 Mar 2026 19:21:03 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Azure Sentinel for Supply Chain Detection]]></title>
      <description><![CDATA[Sentinel has everything it needs to detect supply chain attacks in Azure — but only if the analytics rules are tuned to what those attacks actually look like.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-sentinel-supply-chain-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-sentinel-supply-chain-detection</guid>
      <pubDate>Tue, 17 Mar 2026 18:00:36 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[OSS Code of Conduct: Security Impact]]></title>
      <description><![CDATA[Codes of conduct are not just social documents. They affect maintainer retention, contributor diversity, and ultimately the security posture of the project.]]></description>
      <link>https://safeguard.sh/resources/blog/oss-community-code-of-conduct-security-impact</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oss-community-code-of-conduct-security-impact</guid>
      <pubDate>Tue, 17 Mar 2026 16:40:09 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Coordinated Disclosure Zero-Day Playbook]]></title>
      <description><![CDATA[A playbook for coordinated disclosure of zero-day vulnerabilities, covering timelines, stakeholder management, embargo discipline, and the judgement calls in between.]]></description>
      <link>https://safeguard.sh/resources/blog/coordinated-disclosure-zero-day-playbook</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/coordinated-disclosure-zero-day-playbook</guid>
      <pubDate>Tue, 17 Mar 2026 15:19:43 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Turborepo Monorepo Supply Chain Security]]></title>
      <description><![CDATA[Turborepo makes large JavaScript monorepos fast, and speed changes how teams think about dependencies. The supply chain implications are subtle enough that a fast-moving team can be in trouble before anyone notices.]]></description>
      <link>https://safeguard.sh/resources/blog/turborepo-monorepo-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/turborepo-monorepo-supply-chain-security</guid>
      <pubDate>Tue, 17 Mar 2026 13:59:16 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Security Funding in 2024: Who Pays for the Code We All Depend On]]></title>
      <description><![CDATA[Despite growing recognition that open source underpins critical infrastructure, security funding remains fragmented and insufficient. A look at the numbers and what needs to change.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-security-funding-report-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-security-funding-report-2024</guid>
      <pubDate>Tue, 17 Mar 2026 12:38:49 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Cross-Vendor SBOM Normalization: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Your SBOMs come from a dozen vendors, three scanners, and two CI systems. Normalising them into one queryable graph is where SBOM programs actually succeed or fail.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cross-vendor-sbom-normalization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cross-vendor-sbom-normalization</guid>
      <pubDate>Tue, 17 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Dev Machine Secrets: The Exfiltration Risks]]></title>
      <description><![CDATA[Engineer laptops are the softest target in most organizations. Here is a senior engineer's look at the real exfiltration paths for developer secrets and how to shut them down.]]></description>
      <link>https://safeguard.sh/resources/blog/dev-machine-secrets-exfiltration-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dev-machine-secrets-exfiltration-risks</guid>
      <pubDate>Tue, 17 Mar 2026 11:18:22 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Container Security vs Virtual Machine Security]]></title>
      <description><![CDATA[Containers and VMs isolate workloads at different layers — kernel vs. hypervisor — which changes attack surface, blast radius, patch speed, and what your scanner actually needs to cover.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-vs-virtual-machine-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-vs-virtual-machine-security</guid>
      <pubDate>Tue, 17 Mar 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[How to Scan Docker Images for Vulnerabilities]]></title>
      <description><![CDATA[A production-grade vulnerability scanning pipeline for Docker images using Trivy and Grype, with reachability-based prioritization and admission enforcement.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-scan-docker-images-vulnerabilities-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-scan-docker-images-vulnerabilities-guide</guid>
      <pubDate>Tue, 17 Mar 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GCP Security Command Center Integration]]></title>
      <description><![CDATA[An industry-level look at integrating GCP Security Command Center with the rest of the security stack: which findings are signal, which are noise, and how to route the output so it actually gets actioned.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-security-command-center-integration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-security-command-center-integration</guid>
      <pubDate>Tue, 17 Mar 2026 09:57:56 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Drata vs Vanta vs Secureframe: head-to-head comparison]]></title>
      <description><![CDATA[Drata, Vanta, and Secureframe automate compliance evidence collection — but that's a different job from securing your software supply chain. Here's how Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/drata-vs-vanta-vs-secureframe-head-to-head-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/drata-vs-vanta-vs-secureframe-head-to-head-comparison</guid>
      <pubDate>Tue, 17 Mar 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Actions Cache Poisoning Attack Class 2025]]></title>
      <description><![CDATA[GitHub Actions caches were never designed as a trust boundary. In 2025 researchers turned that mismatch into a repeatable supply-chain attack pattern.]]></description>
      <link>https://safeguard.sh/resources/blog/github-actions-cache-poisoning-attack-class-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-actions-cache-poisoning-attack-class-2025</guid>
      <pubDate>Tue, 17 Mar 2026 09:00:00 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NIST SP 800-161 Rev. 2 Third-Party Risk 2026]]></title>
      <description><![CDATA[NIST SP 800-161 Rev. 2 reshapes cyber supply chain risk management for federal contractors and commercial buyers. Here is what engineers must operationalize.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-sp-800-161-revision-2-third-party-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-sp-800-161-revision-2-third-party-2026</guid>
      <pubDate>Tue, 17 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Port of Seattle Rhysida: Airport Ransomware and the Public-Sector Tail]]></title>
      <description><![CDATA[On August 24, 2024, Rhysida ransomware took down Port of Seattle systems including Sea-Tac airport check-in, baggage, and the Port website. The Port refused a $6 million ransom. We unpack the case.]]></description>
      <link>https://safeguard.sh/resources/blog/port-of-seattle-rhysida-airport-ransomware-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/port-of-seattle-rhysida-airport-ransomware-2024</guid>
      <pubDate>Tue, 17 Mar 2026 08:37:29 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Java SBOM Generation Tools Compared]]></title>
      <description><![CDATA[Six tools generate SBOMs from Java projects. They disagree on transitive depth, license fields, and licensing of their own output. A head-to-head.]]></description>
      <link>https://safeguard.sh/resources/blog/java-supply-chain-sbom-generation-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-supply-chain-sbom-generation-tools</guid>
      <pubDate>Tue, 17 Mar 2026 07:17:02 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Serverless Security]]></title>
      <description><![CDATA[Serverless security protects function code, IAM roles, and event triggers where traditional host-based scanning and patching don't apply.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-serverless-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-serverless-security</guid>
      <pubDate>Tue, 17 Mar 2026 07:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Drata vs Vanta: which compliance automation platform is b...]]></title>
      <description><![CDATA[Drata and Vanta automate compliance evidence, but neither verifies the software supply chain. Here's what compliance automation covers, what it doesn't, and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/drata-vs-vanta-which-compliance-automation-platform-is-better</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/drata-vs-vanta-which-compliance-automation-platform-is-better</guid>
      <pubDate>Tue, 17 Mar 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Hardening GitLab vs GitHub Default Settings]]></title>
      <description><![CDATA[GitLab and GitHub both ship with defaults that prioritize usability. A head-to-head on the specific hardening steps each platform needs before it is safe for enterprise use.]]></description>
      <link>https://safeguard.sh/resources/blog/hardening-gitlab-vs-github-default-settings</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hardening-gitlab-vs-github-default-settings</guid>
      <pubDate>Tue, 17 Mar 2026 05:56:36 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Automation Maturity in 2024: Where Teams Actually Stand]]></title>
      <description><![CDATA[Industry surveys and real-world data paint a sobering picture of DevSecOps automation maturity. Most organizations are still in the early stages despite years of investment.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-automation-maturity-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-automation-maturity-2024</guid>
      <pubDate>Tue, 17 Mar 2026 04:36:09 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is Microservices Security]]></title>
      <description><![CDATA[Microservices security means securing service-to-service auth, dependencies, and containers across hundreds of independently deployed services—not one monolith.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-microservices-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-microservices-security</guid>
      <pubDate>Tue, 17 Mar 2026 04:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What Is ABAC (Attribute-Based Access Control)]]></title>
      <description><![CDATA[ABAC decides access by evaluating attributes of the user, resource, action, and environment against policy rules. Learn how it works and when to choose it over roles.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-abac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-abac</guid>
      <pubDate>Tue, 17 Mar 2026 03:15:42 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Drata alternatives: top compliance automation platforms c...]]></title>
      <description><![CDATA[Comparing Drata's compliance automation focus against Safeguard's software supply chain security approach, so you pick the right tool for the gap you actually need to close.]]></description>
      <link>https://safeguard.sh/resources/blog/drata-alternatives-top-compliance-automation-platforms-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/drata-alternatives-top-compliance-automation-platforms-compared</guid>
      <pubDate>Tue, 17 Mar 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Woodpecker CI Security Review]]></title>
      <description><![CDATA[A security review of Woodpecker CI, the community fork of Drone: runner isolation, secret handling, plugin ecosystem, and the trade-offs of running a self-hosted lightweight CI.]]></description>
      <link>https://safeguard.sh/resources/blog/woodpecker-ci-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/woodpecker-ci-security-review</guid>
      <pubDate>Tue, 17 Mar 2026 01:55:16 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Helm Chart Security]]></title>
      <description><![CDATA[Helm chart security means finding and fixing the RBAC, secrets, and supply chain risks baked into Kubernetes' most-used packaging format.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-helm-chart-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-helm-chart-security</guid>
      <pubDate>Tue, 17 Mar 2026 01:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Container Security Best Practices for 2025: Beyond Image Scanning]]></title>
      <description><![CDATA[Container security has evolved far past vulnerability scanning. Here is what mature container security programs look like heading into 2025.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-best-practices-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-best-practices-2025</guid>
      <pubDate>Tue, 17 Mar 2026 00:34:49 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Docker Hub Exposed Secrets at Scale 2024]]></title>
      <description><![CDATA[Researchers keep finding valid AWS, GitHub, and cloud credentials baked into public Docker Hub images. What the 2024 data shows and how to stop shipping secrets.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-hub-exposed-secrets-at-scale-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-hub-exposed-secrets-at-scale-2024</guid>
      <pubDate>Tue, 17 Mar 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Drata vs OneTrust: enterprise GRC comparison]]></title>
      <description><![CDATA[Drata and OneTrust automate GRC evidence, but neither scans code or verifies build provenance -- the gap Safeguard closes for software supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/drata-vs-onetrust-enterprise-grc-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/drata-vs-onetrust-enterprise-grc-comparison</guid>
      <pubDate>Tue, 17 Mar 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[An npm Incident Response Playbook]]></title>
      <description><![CDATA[When an npm package in your dependency graph is compromised at midnight, you need a playbook, not a brainstorm. Here is the one I wrote after three real incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-incident-response-playbook</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-incident-response-playbook</guid>
      <pubDate>Mon, 16 Mar 2026 23:14:22 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Go Build Cache Poisoning Risks]]></title>
      <description><![CDATA[The Go build cache makes builds fast and reproducible, but a poisoned cache can reuse malicious compiled output indefinitely while the source looks clean.]]></description>
      <link>https://safeguard.sh/resources/blog/go-build-cache-poisoning-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-build-cache-poisoning-risks</guid>
      <pubDate>Mon, 16 Mar 2026 21:53:55 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Crypto Exchange Supply Chain Hardening]]></title>
      <description><![CDATA[Crypto exchanges are the highest-value software supply chain targets on the internet. A hardening playbook drawn from Lazarus, Ronin, and 3CX.]]></description>
      <link>https://safeguard.sh/resources/blog/crypto-exchange-supply-chain-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crypto-exchange-supply-chain-hardening</guid>
      <pubDate>Mon, 16 Mar 2026 20:33:29 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Python Wheels vs Source Distributions: Security Implications]]></title>
      <description><![CDATA[Installing an sdist runs someone else's code on your machine; installing a wheel doesn't. That one difference drives most PyPI malware — and most of the right defenses.]]></description>
      <link>https://safeguard.sh/resources/blog/python-wheels-vs-source-distributions-security-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-wheels-vs-source-distributions-security-implications</guid>
      <pubDate>Mon, 16 Mar 2026 19:13:02 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Tomas Lindgren)</author>
    </item>
    <item>
      <title><![CDATA[Zero Trust Principles Applied to the Software Supply Chain]]></title>
      <description><![CDATA[Zero trust is not just a network architecture concept. Applied to the software supply chain, it fundamentally changes how organizations verify code, dependencies, and build processes.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-trust-software-supply-chain-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-trust-software-supply-chain-2024</guid>
      <pubDate>Mon, 16 Mar 2026 17:52:35 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[NYDFS 500 Meets SBOM Requirements]]></title>
      <description><![CDATA[23 NYCRR Part 500 was amended in 2023 with stronger third-party and vulnerability management language. For covered financial entities, SBOM practice has quietly become a compliance expectation.]]></description>
      <link>https://safeguard.sh/resources/blog/nydfs-500-meets-sbom-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nydfs-500-meets-sbom-requirements</guid>
      <pubDate>Mon, 16 Mar 2026 16:32:09 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Mailchimp 2022-2023 Incidents: A Timeline]]></title>
      <description><![CDATA[Mailchimp disclosed three social-engineering-driven intrusions in thirteen months; the timeline illustrates how repeated incidents shape vendor trust.]]></description>
      <link>https://safeguard.sh/resources/blog/mailchimp-2022-2023-incidents-timeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mailchimp-2022-2023-incidents-timeline</guid>
      <pubDate>Mon, 16 Mar 2026 15:11:42 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Secrets Rotation Across Microservices: A Playbook]]></title>
      <description><![CDATA[A practical senior engineer's playbook for rotating secrets across microservices without downtime, drift, or the quiet credential leaks that come from half-done cutovers.]]></description>
      <link>https://safeguard.sh/resources/blog/secrets-rotation-across-microservices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secrets-rotation-across-microservices</guid>
      <pubDate>Mon, 16 Mar 2026 13:51:15 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[NuGet Signed Packages Verification]]></title>
      <description><![CDATA[NuGet supports signed packages — author signatures, repository signatures, and verification modes. A practical guide to enforcing it properly.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-signed-packages-verification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-signed-packages-verification</guid>
      <pubDate>Mon, 16 Mar 2026 12:30:49 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Container Image Supply Chain Incidents 2026]]></title>
      <description><![CDATA[Container image supply chain incidents have grown in frequency and impact. We analyze the 2026 patterns, the registry tradecraft, and what defenders should change.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-supply-chain-incidents-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-supply-chain-incidents-2026</guid>
      <pubDate>Mon, 16 Mar 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Benchmark Reproducibility: Griffin AI vs Mythos]]></title>
      <description><![CDATA[A benchmark you can&apos;t reproduce is marketing. A benchmark you can rerun on your own infrastructure is evidence. The reproducibility gap is wide.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-benchmark-reproducibility</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-benchmark-reproducibility</guid>
      <pubDate>Mon, 16 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Prompt Injection Defences: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Prompt injection is the defining AI security problem of this generation. The defences are structural, not cosmetic — and the architectural choices show.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-prompt-injection-defences</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-prompt-injection-defences</guid>
      <pubDate>Mon, 16 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Windsurf Cascade for Security Review]]></title>
      <description><![CDATA[Windsurf's Cascade agent is among the more capable in-editor agents. For security review specifically, it's a complement to Griffin AI, not a replacement.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-windsurf-cascade-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-windsurf-cascade-security-review</guid>
      <pubDate>Mon, 16 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Intel Community Software Supply Chain Controls]]></title>
      <description><![CDATA[Intelligence community software supply chain controls have tightened sharply. Here is how to build a program that satisfies ICD 503 and the CIO directives.]]></description>
      <link>https://safeguard.sh/resources/blog/intel-community-software-supply-chain-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/intel-community-software-supply-chain-controls</guid>
      <pubDate>Mon, 16 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Automating License Policy: Blocking AGPL At PR]]></title>
      <description><![CDATA[License risk that surfaces at release time is already too late. PR-time license policy turns an open-ended legal review into an automated, predictable check.]]></description>
      <link>https://safeguard.sh/resources/blog/license-policy-automation-blocking-agpl-at-pr</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/license-policy-automation-blocking-agpl-at-pr</guid>
      <pubDate>Mon, 16 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Multi-Cloud Supply Chain Control Plane]]></title>
      <description><![CDATA[A multi-cloud estate needs a single control plane for supply chain policy. This is what one looks like across AWS, Azure, and GCP in production in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-cloud-supply-chain-control-plane-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-cloud-supply-chain-control-plane-2026</guid>
      <pubDate>Mon, 16 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Proof-Of-Concept Payloads From Discovered Paths]]></title>
      <description><![CDATA[A taint path is not an exploit. Here is how a zero-day pipeline turns a reachable flow into a defensible proof-of-concept payload without inventing a vulnerability.]]></description>
      <link>https://safeguard.sh/resources/blog/proof-of-concept-payloads-from-discovered-paths</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/proof-of-concept-payloads-from-discovered-paths</guid>
      <pubDate>Mon, 16 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Burndown Charts That Actually Work]]></title>
      <description><![CDATA[Most burndown charts lie about progress. Here is how to build one that survives executive scrutiny by combining reachability, age cohorts, and inflow data.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-burndown-charts-that-actually-work</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-burndown-charts-that-actually-work</guid>
      <pubDate>Mon, 16 Mar 2026 12:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NIST CSF 2.0 Rollout: Field Observations]]></title>
      <description><![CDATA[NIST CSF 2.0 added the Govern function, broadened the target audience, and clarified supply chain expectations. Field observations from the first year of adoption.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-csf-2-0-rollout-observations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-csf-2-0-rollout-observations</guid>
      <pubDate>Mon, 16 Mar 2026 11:10:22 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Choose a Secure Base Image]]></title>
      <description><![CDATA[Base image choice sets your CVE floor before any scanner runs. Here's how to evaluate footprint, patch cadence, provenance, and rebuild cycle.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-choose-a-secure-base-image</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-choose-a-secure-base-image</guid>
      <pubDate>Mon, 16 Mar 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Azure Monitor for Supply Chain Observability]]></title>
      <description><![CDATA[Supply chain observability in Azure is not missing telemetry — it is missing the right queries. A walk through the Azure Monitor data sources that actually answer the hard questions.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-monitor-supply-chain-observability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-monitor-supply-chain-observability</guid>
      <pubDate>Mon, 16 Mar 2026 09:49:55 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Ethical Hacking Kya Hai? A Beginner's Guide to Security Testing]]></title>
      <description><![CDATA[Ethical hacking means testing systems with permission to find flaws before criminals do. Here is what it actually involves, the phases, the skills, and where AI fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/ethical-hacking-kya-hai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ethical-hacking-kya-hai</guid>
      <pubDate>Mon, 16 Mar 2026 09:10:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Security for Aerospace & Defense (DoD) 2026]]></title>
      <description><![CDATA[Supply chain security for aerospace and defense contractors in 2026 means CMMC 2.0 final rule, DFARS 7012/7020/7021, and NIST 800-171 Rev 3 in production.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-aerospace-defense-dod-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-aerospace-defense-dod-2026</guid>
      <pubDate>Mon, 16 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Self-Hosted vs SaaS Security Scanning: An Honest Comparison]]></title>
      <description><![CDATA[Run scanners on your own metal or rent the vendor's? A cost, latency, and data-residency comparison from someone who has operated both and regretted each at least once.]]></description>
      <link>https://safeguard.sh/resources/blog/self-hosted-vs-saas-security-scanning-an-honest-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/self-hosted-vs-saas-security-scanning-an-honest-comparison</guid>
      <pubDate>Mon, 16 Mar 2026 08:29:29 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Sofia Marchetti)</author>
    </item>
    <item>
      <title><![CDATA[The Software Composition Analysis Market in 2024: Consolidation and Evolution]]></title>
      <description><![CDATA[The SCA market is maturing fast, with acquisitions, AI-powered analysis, and SBOM mandates reshaping the competitive landscape and what buyers should expect.]]></description>
      <link>https://safeguard.sh/resources/blog/software-composition-analysis-market-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-composition-analysis-market-2024</guid>
      <pubDate>Mon, 16 Mar 2026 07:09:02 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How much does a SOC 2 audit cost?]]></title>
      <description><![CDATA[A full breakdown of SOC 2 audit costs in 2026 — CPA fees, Drata's platform pricing, hidden internal time, and how to avoid the surprise costs that inflate a first audit.]]></description>
      <link>https://safeguard.sh/resources/blog/how-much-does-a-soc-2-audit-cost</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-much-does-a-soc-2-audit-cost</guid>
      <pubDate>Mon, 16 Mar 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Provenance Attestation Consumer Workflow]]></title>
      <description><![CDATA[Generating provenance is half the story. Consuming it correctly, at the right points in the pipeline, is where the security value actually materialises.]]></description>
      <link>https://safeguard.sh/resources/blog/provenance-attestation-consumer-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/provenance-attestation-consumer-workflow</guid>
      <pubDate>Mon, 16 Mar 2026 05:48:35 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[FIN7: Financial-Sector Supply Chain Tradecraft]]></title>
      <description><![CDATA[FIN7 has spent a decade evolving from POS malware to supply chain operations. A look at the current tradecraft and the implications for financial-sector defenders.]]></description>
      <link>https://safeguard.sh/resources/blog/fin7-financial-sector-supply-chain-tradecraft</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fin7-financial-sector-supply-chain-tradecraft</guid>
      <pubDate>Mon, 16 Mar 2026 04:28:08 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CWE Full Form: How the Common Weakness Enumeration Works]]></title>
      <description><![CDATA[CWE stands for Common Weakness Enumeration — a community catalog of software and hardware weakness types. Here is what CWE means, how it differs from CVE, and how to use it.]]></description>
      <link>https://safeguard.sh/resources/blog/cwe-full-form-common-weakness-enumeration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cwe-full-form-common-weakness-enumeration</guid>
      <pubDate>Mon, 16 Mar 2026 03:07:42 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How long does a SOC 2 audit take?]]></title>
      <description><![CDATA[Most teams budget 3 months for SOC 2. The real number is closer to 6-12, and no automation platform, including Drata, can compress the observation period.]]></description>
      <link>https://safeguard.sh/resources/blog/how-long-does-a-soc-2-audit-take</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-long-does-a-soc-2-audit-take</guid>
      <pubDate>Mon, 16 Mar 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2011-4969: The jQuery XSS Bug, a Decade Later]]></title>
      <description><![CDATA[CVE-2011-4969 is a cross-site scripting flaw in jQuery versions before 1.6.3, triggered by unsanitized attribute-selector input — it's a small, old bug, but the reasons it lingered in codebases for years are still relevant.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2011-4969-jquery-xss-a-decade-later</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2011-4969-jquery-xss-a-decade-later</guid>
      <pubDate>Mon, 16 Mar 2026 01:47:15 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE Vulnerability Lookup and Scoring, Explained]]></title>
      <description><![CDATA[A CVE vulnerability record is an identifier, not a severity rating on its own — here's how CVE IDs, CVSS scores, and the actual lookup process fit together.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-vulnerability-lookup-and-scoring-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-vulnerability-lookup-and-scoring-explained</guid>
      <pubDate>Mon, 16 Mar 2026 00:26:48 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 audit exceptions: what they are and how to avoid them]]></title>
      <description><![CDATA[SOC 2 audit exceptions often trace back to dependency and build evidence gaps that GRC tools like Drata don't reach. Here's why they happen and how to close them.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-audit-exceptions-what-they-are-and-how-to-avoid-them</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-audit-exceptions-what-they-are-and-how-to-avoid-them</guid>
      <pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Security Team Topology for a Supply Chain Program]]></title>
      <description><![CDATA[How to structure a supply chain security program across AppSec, platform, TPRM, and incident response with clear ownership, cadences, and escalation paths.]]></description>
      <link>https://safeguard.sh/resources/blog/security-team-topology-supply-chain-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-team-topology-supply-chain-program</guid>
      <pubDate>Sun, 15 Mar 2026 23:06:22 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Auditing Rust unsafe Code at Scale]]></title>
      <description><![CDATA[How to actually audit unsafe blocks across a large Rust dependency graph without drowning in false positives or miss real issues.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-unsafe-code-audit-at-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-unsafe-code-audit-at-scale</guid>
      <pubDate>Sun, 15 Mar 2026 21:45:55 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Migrating VPN to Zero Trust: Supply Chain]]></title>
      <description><![CDATA[A phased playbook for retiring corporate VPN concentrators in favor of zero trust network access, with specific guidance for protecting software supply chain pipelines.]]></description>
      <link>https://safeguard.sh/resources/blog/migrating-vpn-to-zero-trust-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/migrating-vpn-to-zero-trust-supply-chain</guid>
      <pubDate>Sun, 15 Mar 2026 20:25:28 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GCP Terraform Provider Security Review]]></title>
      <description><![CDATA[A security-focused review of the Google Terraform providers: provenance, authentication paths, state handling, and the misconfigurations that consistently produce incidents across the Google and Google-Beta provider ecosystem.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-terraform-provider-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-terraform-provider-security-review</guid>
      <pubDate>Sun, 15 Mar 2026 19:05:02 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Dataflow Analysis in Modern Codebases]]></title>
      <description><![CDATA[Dataflow analysis is the workhorse behind most vulnerability research. Here's how it adapts to TypeScript, Rust, and the polyglot realities of modern software.]]></description>
      <link>https://safeguard.sh/resources/blog/dataflow-analysis-modern-codebases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dataflow-analysis-modern-codebases</guid>
      <pubDate>Sun, 15 Mar 2026 17:44:35 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Automotive ISO/SAE 21434: Supply Chain Implications]]></title>
      <description><![CDATA[ISO/SAE 21434 makes cybersecurity a type-approval requirement. Here is how the standard reshapes OEM and tier-N software supply chain obligations.]]></description>
      <link>https://safeguard.sh/resources/blog/automotive-iso-21434-supply-chain-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automotive-iso-21434-supply-chain-implications</guid>
      <pubDate>Sun, 15 Mar 2026 16:24:08 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSF Launches SIREN: A Mailing List for Open Source Threat Intelligence]]></title>
      <description><![CDATA[The Open Source Security Foundation introduces SIREN, a dedicated mailing list for sharing real-time threat intelligence about attacks targeting open source ecosystems.]]></description>
      <link>https://safeguard.sh/resources/blog/openssf-siren-mailing-list-launch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssf-siren-mailing-list-launch</guid>
      <pubDate>Sun, 15 Mar 2026 15:03:42 GMT</pubDate>
      <category>Industry News</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Java Modules Supply Chain Security]]></title>
      <description><![CDATA[The Java Platform Module System arrived in Java 9 and has aged into quiet maturity. What JPMS actually does for supply chain posture in enterprise Java.]]></description>
      <link>https://safeguard.sh/resources/blog/java-modules-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-modules-supply-chain-security</guid>
      <pubDate>Sun, 15 Mar 2026 13:43:15 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Play Ransomware: Supply Chain Exploitation Through Managed Service Providers]]></title>
      <description><![CDATA[Play ransomware refined the MSP attack model, exploiting FortiOS and RDP vulnerabilities to cascade through managed service providers into hundreds of downstream organizations.]]></description>
      <link>https://safeguard.sh/resources/blog/play-ransomware-supply-chain-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/play-ransomware-supply-chain-exploitation</guid>
      <pubDate>Sun, 15 Mar 2026 12:22:48 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise AI Metric Design For Executive Reporting]]></title>
      <description><![CDATA[AI-for-security metrics that show up on board slides are different from the ones engineers use day-to-day. Designing both sets properly is the work.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-ai-metric-design-for-executive-reporting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-ai-metric-design-for-executive-reporting</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Fourth-Party Risk: The Supply Chain Of Vendors]]></title>
      <description><![CDATA[Your vendors have vendors. Most TPRM programs stop at the third party and miss the fourth-party blast radius. Mapping the full chain is now a board-level expectation.]]></description>
      <link>https://safeguard.sh/resources/blog/fourth-party-risk-mapping-supply-chain-of-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fourth-party-risk-mapping-supply-chain-of-vendors</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Self-Hosted Llama: Real Costs]]></title>
      <description><![CDATA[Self-hosting Llama looks cheap on paper. The real costs — GPUs, operations, engineering — make the comparison less obvious than the list price suggests.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-llama-vs-self-hosting-costs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-llama-vs-self-hosting-costs</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Pricing Predictability: Griffin AI vs Mythos]]></title>
      <description><![CDATA[A 40% cost surprise in year two is not a pricing issue — it is an architecture issue. Griffin AI and Mythos-class tools diverge on predictability in structural ways.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-pricing-predictability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-pricing-predictability</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[MCP Client-Side Security Considerations]]></title>
      <description><![CDATA[The MCP client surface is often overlooked. We examine trust boundaries, schema handling, credential storage, and safe defaults for the agent side of the protocol.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-client-side-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-client-side-security-considerations</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Prompt Injection Defence Stack 2026]]></title>
      <description><![CDATA[No single control stops prompt injection. The current state of the art is a defence-in-depth stack with controls at five distinct layers. Here it is.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-defence-stack-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-defence-stack-2026</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Reachability-Driven SBOM Prioritisation In 2026]]></title>
      <description><![CDATA[An SBOM is a list. A reachability-prioritised SBOM is a triage queue. The difference determines whether the SBOM produces value or sits unread.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-driven-sbom-prioritisation-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-driven-sbom-prioritisation-2026</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Ruby / Bundler Supply Chain Program 2026]]></title>
      <description><![CDATA[A 2026 supply chain program for Ruby and Bundler — covering RubyGems, Gemfile.lock, native extensions, and Rails — anchored by Safeguard policy gates.]]></description>
      <link>https://safeguard.sh/resources/blog/ruby-bundler-supply-chain-program-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ruby-bundler-supply-chain-program-2026</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Runtime Asset Attribution: Pods To Services]]></title>
      <description><![CDATA[Mapping a running pod back to a service, repo, owner, and SBOM is the boring infrastructure that makes every other security control useful.]]></description>
      <link>https://safeguard.sh/resources/blog/runtime-asset-attribution-mapping-pods-to-services</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runtime-asset-attribution-mapping-pods-to-services</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Security Champions Program For Shift-Left 2026]]></title>
      <description><![CDATA[Security champions are the human layer that makes shift-left work. A 2026 program design for selecting, training, and retaining champions in engineering.]]></description>
      <link>https://safeguard.sh/resources/blog/security-champions-program-shift-left-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-champions-program-shift-left-2026</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Telehealth Platform Vendor Risk Program]]></title>
      <description><![CDATA[Telehealth platforms depend on video, EHR, prescription, and payment vendors. Here is a vendor risk program tuned to the realities of the industry.]]></description>
      <link>https://safeguard.sh/resources/blog/telehealth-platform-vendor-risk-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/telehealth-platform-vendor-risk-program</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vector Database Poisoning Trend Watch]]></title>
      <description><![CDATA[Vector databases are now central infrastructure for retrieval-augmented AI. The 2026 attack trend targets the index itself, not the model — and most defenders are not watching the right layer.]]></description>
      <link>https://safeguard.sh/resources/blog/vector-database-poisoning-trend-watch-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vector-database-poisoning-trend-watch-2026</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Kata Containers Security Model Review]]></title>
      <description><![CDATA[Kata wraps each pod in a lightweight VM. That is a real security boundary. It is also one that comes with real costs and real caveats.]]></description>
      <link>https://safeguard.sh/resources/blog/kata-containers-security-model-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kata-containers-security-model-review</guid>
      <pubDate>Sun, 15 Mar 2026 11:02:21 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best SBOM Management Platforms 2026 Review]]></title>
      <description><![CDATA[A 2026 review of the best SBOM management platforms, comparing Dependency-Track, Anchore, Kusari, and Safeguard on depth and compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/best-sbom-management-platforms-2026-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-sbom-management-platforms-2026-review</guid>
      <pubDate>Sun, 15 Mar 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CrowdStrike Falcon Outage: Post-Mortem Lessons]]></title>
      <description><![CDATA[The CrowdStrike Falcon outage of July 2024 bricked 8.5 million Windows hosts. A content validator bug and no staged rollout were the confirmed root cause.]]></description>
      <link>https://safeguard.sh/resources/blog/crowdstrike-falcon-outage-post-mortem-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crowdstrike-falcon-outage-post-mortem-lessons</guid>
      <pubDate>Sun, 15 Mar 2026 10:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP 20x and Continuous Compliance for Software Vendors]]></title>
      <description><![CDATA[FedRAMP 20x replaces document-heavy review with machine-verifiable assertions. SBOMs and runtime evidence become first-class authorization artifacts.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-20x-continuous-compliance-software-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-20x-continuous-compliance-software-vendors</guid>
      <pubDate>Sun, 15 Mar 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Lacework vs Wiz 2026 CNAPP Comparison]]></title>
      <description><![CDATA[Post-Fortinet Lacework is finding its footing again. How does it stack up against the market leader in 2026, and where does the Polygraph still win?]]></description>
      <link>https://safeguard.sh/resources/blog/lacework-vs-wiz-2026-cnapp-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lacework-vs-wiz-2026-cnapp-comparison</guid>
      <pubDate>Sun, 15 Mar 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[SBOMs in Healthcare: Patient Safety Meets Software Transparency]]></title>
      <description><![CDATA[Healthcare organizations face unique SBOM challenges driven by FDA requirements, device lifecycles, and patient safety stakes.]]></description>
      <link>https://safeguard.sh/resources/blog/software-bill-of-materials-healthcare</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-bill-of-materials-healthcare</guid>
      <pubDate>Sun, 15 Mar 2026 10:00:00 GMT</pubDate>
      <category>Healthcare</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[How to Build a Vulnerability SLA Dashboard]]></title>
      <description><![CDATA[Track remediation SLAs across projects with a self-service dashboard that surfaces aging findings, breach risk, and team accountability — complete code inside.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-build-a-vulnerability-sla-dashboard</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-build-a-vulnerability-sla-dashboard</guid>
      <pubDate>Sun, 15 Mar 2026 09:41:55 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Confused Deputy Attacks on CI/CD Service Accounts]]></title>
      <description><![CDATA[Build systems hold broad trust and tight deadlines, which makes them perfect confused deputies. Here is how the attack pattern shows up in modern CI/CD and how to defang it.]]></description>
      <link>https://safeguard.sh/resources/blog/confused-deputy-attacks-ci-cd-service-accounts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/confused-deputy-attacks-ci-cd-service-accounts</guid>
      <pubDate>Sun, 15 Mar 2026 09:00:00 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 readiness assessment guide]]></title>
      <description><![CDATA[What a SOC 2 readiness assessment actually covers, how long it takes, what it costs, and where supply chain risk fits in alongside tools like Drata.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-readiness-assessment-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-readiness-assessment-guide</guid>
      <pubDate>Sun, 15 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Signing Python Wheels in Production]]></title>
      <description><![CDATA[PyPI supports attestations now. Here is how to actually sign Python wheels in a CI pipeline, verify them at install time, and deal with the rough edges.]]></description>
      <link>https://safeguard.sh/resources/blog/python-wheel-signing-production-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-wheel-signing-production-guide</guid>
      <pubDate>Sun, 15 Mar 2026 08:21:28 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Grafana Loki for Build Pipeline Logs: Patterns That Scale]]></title>
      <description><![CDATA[Design a Loki-based log pipeline for CI/CD observability and supply chain forensics. Labels, retention, LogQL patterns, and cost discipline from the field.]]></description>
      <link>https://safeguard.sh/resources/blog/grafana-loki-build-pipeline-logs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/grafana-loki-build-pipeline-logs</guid>
      <pubDate>Sun, 15 Mar 2026 07:01:01 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Who needs SOC 2 compliance? A breakdown by company stage/...]]></title>
      <description><![CDATA[SOC 2 isn't legally required, but it's now a deal-blocker as early as seed stage. Here's a stage-by-stage, industry-by-industry breakdown of who actually needs it.]]></description>
      <link>https://safeguard.sh/resources/blog/who-needs-soc-2-compliance-a-breakdown-by-company-stageindustry</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/who-needs-soc-2-compliance-a-breakdown-by-company-stageindustry</guid>
      <pubDate>Sun, 15 Mar 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[What is a Reachability Analysis in SCA]]></title>
      <description><![CDATA[Reachability analysis checks whether your code actually calls the vulnerable function inside a dependency — the difference between 400 alerts and 12 that matter.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-reachability-analysis-in-sca</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-reachability-analysis-in-sca</guid>
      <pubDate>Sun, 15 Mar 2026 05:40:35 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[The Apache License, Version 2.0: What It Actually Requires]]></title>
      <description><![CDATA[What the Apache License, Version 2.0 actually obligates you to do — attribution, notice files, and the patent grant most summaries skip.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-license-version-2-0-what-it-requires</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-license-version-2-0-what-it-requires</guid>
      <pubDate>Sun, 15 Mar 2026 04:20:08 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to choose the right SOC 2 audit firm / auditor]]></title>
      <description><![CDATA[Drata and similar platforms automate SOC 2 readiness, but they can't issue your audit report. Here's a concrete framework for vetting the CPA firm that actually can.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-choose-the-right-soc-2-audit-firm-auditor</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-choose-the-right-soc-2-audit-firm-auditor</guid>
      <pubDate>Sun, 15 Mar 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Code Signing Infrastructure Breach Response]]></title>
      <description><![CDATA[A compromised signing key is the quietest crisis in security. A concrete playbook for responding when your code signing infrastructure is implicated.]]></description>
      <link>https://safeguard.sh/resources/blog/code-signing-infrastructure-breach-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-signing-infrastructure-breach-response</guid>
      <pubDate>Sun, 15 Mar 2026 02:59:41 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Cryptographic Bill of Materials (CBOM): The Next Frontier]]></title>
      <description><![CDATA[Post-quantum cryptography migration requires knowing what cryptographic algorithms your software uses. CBOMs provide that inventory. Here is what they are and why they matter.]]></description>
      <link>https://safeguard.sh/resources/blog/cryptographic-bill-of-materials-cbom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cryptographic-bill-of-materials-cbom</guid>
      <pubDate>Sun, 15 Mar 2026 01:39:15 GMT</pubDate>
      <category>Standards</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Quality Benchmarking: What We Found in 2024]]></title>
      <description><![CDATA[We scored 1,200 production SBOMs in 2024 across CycloneDX and SPDX. The quality distribution is worse than advertised and we have the numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-quality-benchmarking-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-quality-benchmarking-2024</guid>
      <pubDate>Sun, 15 Mar 2026 00:18:48 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The Complete SBOM Compliance Guide for 2026]]></title>
      <description><![CDATA[Everything you need to know about SBOM requirements under EO 14028, NIST SSDF, and emerging global regulations.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-compliance-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-compliance-guide-2026</guid>
      <pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 for startups: what founders need to know]]></title>
      <description><![CDATA[A practical guide to SOC 2 timelines, costs, and audit failures for startups—and why compliance automation alone won't cover software supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-for-startups-what-founders-need-to-know</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-for-startups-what-founders-need-to-know</guid>
      <pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Earthly Containerized Builds Supply Chain]]></title>
      <description><![CDATA[Earthly combines container isolation with Makefile-style ergonomics. Here's what that means for supply chain posture, with real Earthfile examples.]]></description>
      <link>https://safeguard.sh/resources/blog/earthly-containerized-builds-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/earthly-containerized-builds-supply-chain</guid>
      <pubDate>Sat, 14 Mar 2026 22:58:21 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Concourse CI Supply Chain Hardening]]></title>
      <description><![CDATA[A practical hardening guide for Concourse CI: resource type trust, worker isolation, team-level RBAC, and the var source security that underpins the platform's multi-tenancy model.]]></description>
      <link>https://safeguard.sh/resources/blog/concourse-ci-supply-chain-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/concourse-ci-supply-chain-hardening</guid>
      <pubDate>Sat, 14 Mar 2026 21:37:55 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Palo Alto Expedition CVE-2024-9463: Command Injection in Migration Tool]]></title>
      <description><![CDATA[Critical command injection vulnerabilities in Palo Alto Networks Expedition tool exposed firewall credentials and configurations, with CISA confirming active exploitation in November 2024.]]></description>
      <link>https://safeguard.sh/resources/blog/palo-alto-expedition-cve-2024-9463</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/palo-alto-expedition-cve-2024-9463</guid>
      <pubDate>Sat, 14 Mar 2026 20:17:28 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Open Source License Comparison: MIT, Apache, GPL, BSD]]></title>
      <description><![CDATA[MIT, Apache 2.0, GPL, and BSD dominate the open source ecosystem but differ sharply on patent grants and copyleft obligations — here's a side-by-side comparison.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-license-comparison-mit-apache-gpl-bsd</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-license-comparison-mit-apache-gpl-bsd</guid>
      <pubDate>Sat, 14 Mar 2026 18:57:01 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[JRuby Supply Chain Considerations]]></title>
      <description><![CDATA[JRuby sits at the intersection of the Ruby and Java supply chains, and the security story reflects both. A look at how JRuby's dual nature affects gem security and what defenders should know.]]></description>
      <link>https://safeguard.sh/resources/blog/jruby-supply-chain-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jruby-supply-chain-considerations</guid>
      <pubDate>Sat, 14 Mar 2026 17:36:34 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AWS IAM Roles Anywhere and the Supply Chain]]></title>
      <description><![CDATA[IAM Roles Anywhere lets workloads outside AWS assume IAM roles using X.509 certificates. It is also becoming the authentication layer for supply chain tools. Here is what the threat model looks like.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-iam-roles-anywhere-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-iam-roles-anywhere-supply-chain</guid>
      <pubDate>Sat, 14 Mar 2026 16:16:08 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is RBAC (Role-Based Access Control)]]></title>
      <description><![CDATA[RBAC grants permissions to roles, then assigns people to roles. Learn how this model simplifies access management, its core parts, and where it fits best.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-rbac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-rbac</guid>
      <pubDate>Sat, 14 Mar 2026 14:55:41 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Medusa Ransomware: How Supply Chain Infiltration Became Their Signature Move]]></title>
      <description><![CDATA[Medusa ransomware operators have refined a playbook that targets managed service providers and software vendors as stepping stones into hundreds of downstream victims.]]></description>
      <link>https://safeguard.sh/resources/blog/medusa-ransomware-supply-chain-infiltration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/medusa-ransomware-supply-chain-infiltration</guid>
      <pubDate>Sat, 14 Mar 2026 13:35:14 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Security Tool Consolidation: Doing More With Less Without Losing Coverage]]></title>
      <description><![CDATA[The average enterprise runs 60-80 security tools. Most overlap, many go unused, and the integration tax exceeds the value. Here is how to consolidate without creating gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/security-tool-consolidation-strategy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-tool-consolidation-strategy</guid>
      <pubDate>Sat, 14 Mar 2026 12:14:48 GMT</pubDate>
      <category>Security Operations</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AI-BOM And EU AI Act Article 10 Data Governance]]></title>
      <description><![CDATA[Article 10 turns training data governance into a legal obligation. AI-BOM is how you prove it. A practical mapping of what the regulation expects to what the artefact captures.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-bom-eu-ai-act-article-10-data-governance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-bom-eu-ai-act-article-10-data-governance</guid>
      <pubDate>Sat, 14 Mar 2026 12:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AI Coding Assistant Data Leakage Paths]]></title>
      <description><![CDATA[AI coding assistants promise productivity but expand the data leakage surface in specific, mappable ways. The paths, the mitigations, and what enterprise policy actually looks like.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-coding-assistant-data-leakage-paths</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-coding-assistant-data-leakage-paths</guid>
      <pubDate>Sat, 14 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Real-World Vs Synthetic Eval Gap In Security]]></title>
      <description><![CDATA[Synthetic eval benchmarks are controllable. Real-world data is messy. The gap between performance on each is usually large, and vendors prefer one over the other for a reason.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-real-world-vs-synthetic-eval-gap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-real-world-vs-synthetic-eval-gap</guid>
      <pubDate>Sat, 14 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Bulk Remediation Of Aged Vulnerability Backlog]]></title>
      <description><![CDATA[Most security teams are sitting on hundreds of stale findings. Here is how to clear an aged vulnerability backlog with bulk remediation that actually merges.]]></description>
      <link>https://safeguard.sh/resources/blog/bulk-remediation-of-aged-vulnerability-backlog</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bulk-remediation-of-aged-vulnerability-backlog</guid>
      <pubDate>Sat, 14 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Chiseled / Distroless Image Rollout Program]]></title>
      <description><![CDATA[What it takes to standardise on chiseled and distroless container images across an engineering organisation: which workloads benefit, which do not, and how to handle the operational quirks of imageless containers.]]></description>
      <link>https://safeguard.sh/resources/blog/chiseled-distroless-images-program-rollout</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chiseled-distroless-images-program-rollout</guid>
      <pubDate>Sat, 14 Mar 2026 12:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Claude Computer Use: Security]]></title>
      <description><![CDATA[Claude's Computer Use lets an agent drive a GUI. For security, this is powerful and dangerous in equal measure. The architecture around it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-claude-computer-use-for-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-claude-computer-use-for-security</guid>
      <pubDate>Sat, 14 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cryptography Misuse Detection: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Crypto misuse is not about broken algorithms. It is about misused parameters, missing checks, and the gap between &quot;it compiles&quot; and &quot;it is secure.&quot;]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cryptography-misuse-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cryptography-misuse-detection</guid>
      <pubDate>Sat, 14 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA Supply Chain Evidence For Business Associates]]></title>
      <description><![CDATA[HIPAA Security Rule expectations now reach into the software supply chain. Learn how Business Associates can produce evidence that satisfies OCR scrutiny.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-supply-chain-evidence-for-business-associates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-supply-chain-evidence-for-business-associates</guid>
      <pubDate>Sat, 14 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[IR Handoff From SecOps To Engineering]]></title>
      <description><![CDATA[The handoff from incident response to engineering is where remediation goes to die. Here is a blueprint that turns a vague Slack message into a closed loop.]]></description>
      <link>https://safeguard.sh/resources/blog/ir-handoff-from-secops-to-engineering-blueprint</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ir-handoff-from-secops-to-engineering-blueprint</guid>
      <pubDate>Sat, 14 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SEC Cyber Disclosure Rules: Year Two]]></title>
      <description><![CDATA[A senior engineer's view of the second-year impact of SEC cybersecurity disclosure rules, what filings actually look like, and where supply chain risk fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/sec-cyber-disclosure-rules-second-year-impact</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sec-cyber-disclosure-rules-second-year-impact</guid>
      <pubDate>Sat, 14 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Fog Ransomware: Why Schools and Universities Are Under Siege]]></title>
      <description><![CDATA[Fog ransomware has carved a niche by targeting educational institutions — organizations with tight budgets, thin security teams, and massive attack surfaces. Here is how they operate.]]></description>
      <link>https://safeguard.sh/resources/blog/fog-ransomware-education-sector-targeting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fog-ransomware-education-sector-targeting</guid>
      <pubDate>Sat, 14 Mar 2026 10:54:21 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CI/CD Audit Pipeline Checklist 2026]]></title>
      <description><![CDATA[An auditor's checklist for CI/CD pipelines in 2026 covering build provenance, secret management, runner isolation, and the evidence to collect for SOC 2 and FedRAMP.]]></description>
      <link>https://safeguard.sh/resources/blog/ci-cd-audit-pipeline-checklist-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ci-cd-audit-pipeline-checklist-2026</guid>
      <pubDate>Sat, 14 Mar 2026 10:20:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Forking Strategy for Enterprise OSS]]></title>
      <description><![CDATA[Forking was once a last resort. In 2024 it became a standard response to license changes, governance failures, and stalled projects. A good forking strategy is now an enterprise competency.]]></description>
      <link>https://safeguard.sh/resources/blog/forking-strategy-for-enterprise-oss</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/forking-strategy-for-enterprise-oss</guid>
      <pubDate>Sat, 14 Mar 2026 09:33:54 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What Is Explainable AI? A Security Practitioner's Guide]]></title>
      <description><![CDATA[Explainable AI makes model decisions inspectable so security teams can trust, audit, and defend them. Here is what that means in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/explainable-ai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/explainable-ai</guid>
      <pubDate>Sat, 14 Mar 2026 09:20:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[AI Agent Tool Confused Deputy Problem in 2026]]></title>
      <description><![CDATA[A senior engineer's take on the confused deputy problem in AI agent tool use, why it keeps reappearing in 2026, and the architectural patterns that actually fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-agent-tool-confused-deputy-problem-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-agent-tool-confused-deputy-problem-2026</guid>
      <pubDate>Sat, 14 Mar 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[APT29 Cloud Supply Chain Tradecraft 2025]]></title>
      <description><![CDATA[APT29's 2024-2025 cloud-native tradecraft — from Midnight Blizzard's Microsoft intrusion to the Teams phishing pivots — shows how SVR targets identity as supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/apt29-cloud-supply-chain-tradecraft-update-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apt29-cloud-supply-chain-tradecraft-update-2025</guid>
      <pubDate>Sat, 14 Mar 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CMMC Level 3 Software Supply Chain Checklist 2026]]></title>
      <description><![CDATA[A senior engineer's CMMC Level 3 checklist focused on software supply chain: SBOM, SC-SR controls, SSP evidence, and the operational gaps most defense contractors still have.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-level-3-software-supply-chain-checklist-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-level-3-software-supply-chain-checklist-2026</guid>
      <pubDate>Sat, 14 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 certification: complete guide and requirements]]></title>
      <description><![CDATA[ISO 27001 requirements explained: the 93 Annex A controls, clause structure, audit timeline, and where supply chain security controls fit into certification.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-certification-complete-guide-and-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-certification-complete-guide-and-requirements</guid>
      <pubDate>Sat, 14 Mar 2026 09:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP High Supply Chain Controls in 2026]]></title>
      <description><![CDATA[Rev 5 controls are the operative baseline, and the SR control family is where most FedRAMP High authorizations are now spending their assessor time in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-high-supply-chain-controls-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-high-supply-chain-controls-2026</guid>
      <pubDate>Sat, 14 Mar 2026 08:30:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Font File Vulnerability History: When Typography Becomes an Exploit]]></title>
      <description><![CDATA[Font parsing has been a goldmine for attackers. The history of font vulnerabilities reveals deep supply chain risks in every operating system.]]></description>
      <link>https://safeguard.sh/resources/blog/font-file-vulnerability-history</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/font-file-vulnerability-history</guid>
      <pubDate>Sat, 14 Mar 2026 08:13:28 GMT</pubDate>
      <category>Vulnerability Research</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NIST NVD Recovery: The New Consortium Reshaping Vulnerability Data]]></title>
      <description><![CDATA[After months of processing backlogs and community frustration, NIST announces a new consortium to modernize and sustain the National Vulnerability Database.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-nvd-recovery-new-consortium</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-nvd-recovery-new-consortium</guid>
      <pubDate>Sat, 14 Mar 2026 06:53:01 GMT</pubDate>
      <category>Industry News</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 Type 1 vs Type 2: differences, timelines, and which...]]></title>
      <description><![CDATA[Type 1 audits control design at a point in time; Type 2 tests operating effectiveness over months. How they differ, realistic timelines, and which to pursue first.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-type-1-vs-type-2-differences-timelines-and-which-to-pick-first</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-type-1-vs-type-2-differences-timelines-and-which-to-pick-first</guid>
      <pubDate>Sat, 14 Mar 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis: Cutting Through Vulnerability Noise]]></title>
      <description><![CDATA[Not every vulnerability in your dependencies is exploitable. Safeguard's reachability analysis determines whether vulnerable code paths are actually invoked in your application.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-reachability-analysis-launch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-reachability-analysis-launch</guid>
      <pubDate>Sat, 14 Mar 2026 05:32:34 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Scoping a Vulnerability Bounty Program for Supply Chain]]></title>
      <description><![CDATA[How to scope a bug bounty program that addresses supply chain risks: in-scope assets, payout tiers, triage workflow, and avoiding the trap of dependency CVE bounties.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-bounty-program-scoping-for-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-bounty-program-scoping-for-supply-chain</guid>
      <pubDate>Sat, 14 Mar 2026 04:12:08 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SOC 1 vs SOC 2 vs SOC 3: how the three report types differ]]></title>
      <description><![CDATA[SOC 1, SOC 2, and SOC 3 test different things for different audiences. Here's how they differ, and where Safeguard's supply chain evidence complements GRC tools like Secureframe.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-1-vs-soc-2-vs-soc-3-how-the-three-report-types-differ</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-1-vs-soc-2-vs-soc-3-how-the-three-report-types-differ</guid>
      <pubDate>Sat, 14 Mar 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Rust Procedural Macros: Security Risks]]></title>
      <description><![CDATA[Proc macros are Rust code that runs at compile time with the privileges of the developer. They are one of the most underexamined pieces of the Rust supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-procedural-macro-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-procedural-macro-security-risks</guid>
      <pubDate>Sat, 14 Mar 2026 02:51:41 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[EHR System Dependency Governance]]></title>
      <description><![CDATA[Electronic Health Record platforms carry decades of transitive dependencies. A practical governance model for hospitals, vendors, and compliance officers.]]></description>
      <link>https://safeguard.sh/resources/blog/ehr-system-dependency-governance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ehr-system-dependency-governance</guid>
      <pubDate>Sat, 14 Mar 2026 01:31:14 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Cloud Misconfiguration]]></title>
      <description><![CDATA[Cloud misconfiguration is the top cause of cloud breaches. Learn what it is, why it happens, real-world costs, and how to detect and prevent it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-cloud-misconfiguration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-cloud-misconfiguration</guid>
      <pubDate>Sat, 14 Mar 2026 01:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[age + SOPS: A Git-Native Secrets Workflow]]></title>
      <description><![CDATA[How age and SOPS together deliver a lightweight, auditable, Git-native secrets workflow that stands up to real production use without a vault server.]]></description>
      <link>https://safeguard.sh/resources/blog/age-sops-git-native-secrets-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/age-sops-git-native-secrets-workflow</guid>
      <pubDate>Sat, 14 Mar 2026 00:10:47 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-4367 PDF.js Arbitrary Code Execution]]></title>
      <description><![CDATA[CVE-2024-4367 is a PDF.js code-execution flaw via font handling that affects Firefox, Thunderbird, and every embedder. Root cause and remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-4367-pdfjs-arbitrary-code-execution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-4367-pdfjs-arbitrary-code-execution</guid>
      <pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 vs SOC 2: which framework is right for you]]></title>
      <description><![CDATA[ISO 27001 and SOC 2 test different things. Here's how they differ, where Secureframe fits, and how Safeguard covers the engineering controls both frameworks require.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-vs-soc-2-which-framework-is-right-for-you</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-vs-soc-2-which-framework-is-right-for-you</guid>
      <pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[State of Container Security 2026: Survey Summary]]></title>
      <description><![CDATA[A survey-style summary of container security in 2026: what production teams actually ship, where image security stands, and which runtime controls moved the needle.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-container-security-2026-survey-summary</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-container-security-2026-survey-summary</guid>
      <pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Foundation-Neutral Governance Evaluation]]></title>
      <description><![CDATA[CNCF, Linux Foundation, Apache, Eclipse — each has a different governance model. A practical evaluation of what that means for projects considering adoption.]]></description>
      <link>https://safeguard.sh/resources/blog/foundation-neutral-governance-evaluation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/foundation-neutral-governance-evaluation</guid>
      <pubDate>Fri, 13 Mar 2026 22:50:21 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Differential Testing for Supply Chain Vulns]]></title>
      <description><![CDATA[Differential testing compares the behavior of multiple implementations of the same specification. In supply-chain work, it surfaces bugs that nobody else can see.]]></description>
      <link>https://safeguard.sh/resources/blog/differential-testing-supply-chain-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/differential-testing-supply-chain-vulnerabilities</guid>
      <pubDate>Fri, 13 Mar 2026 21:29:54 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Buildkite Supply Chain Hardening]]></title>
      <description><![CDATA[A practical hardening guide for Buildkite: agent isolation, pipeline upload security, plugin risks, and the agent-token rotation strategy that keeps the trust model intact.]]></description>
      <link>https://safeguard.sh/resources/blog/buildkite-supply-chain-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buildkite-supply-chain-hardening</guid>
      <pubDate>Fri, 13 Mar 2026 20:09:27 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSF Scorecard Adoption Metrics: Late 2024]]></title>
      <description><![CDATA[OpenSSF Scorecard crossed 1M scanned repos in October 2024. We break down adoption, score drift, and which checks are actually predictive.]]></description>
      <link>https://safeguard.sh/resources/blog/openssf-scorecard-adoption-metrics-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssf-scorecard-adoption-metrics-2024</guid>
      <pubDate>Fri, 13 Mar 2026 18:49:01 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cisco ASA and FTD CVE-2024-20481: Brute-Force DoS in VPN Services]]></title>
      <description><![CDATA[CVE-2024-20481 in Cisco ASA and Firepower Threat Defense VPN services was actively exploited in large-scale brute-force campaigns, causing denial of service on critical VPN infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/cisco-asa-ftd-cve-2024-20481</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisco-asa-ftd-cve-2024-20481</guid>
      <pubDate>Fri, 13 Mar 2026 17:28:34 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[CycloneDX vs SPDX in Practice: Choosing an SBOM Format]]></title>
      <description><![CDATA[Both formats are standards, both are mandated somewhere, and your tooling probably emits both. What actually differs when you run CycloneDX and SPDX in production.]]></description>
      <link>https://safeguard.sh/resources/blog/cyclonedx-vs-spdx-in-practice-choosing-an-sbom-format</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyclonedx-vs-spdx-in-practice-choosing-an-sbom-format</guid>
      <pubDate>Fri, 13 Mar 2026 16:08:07 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Elena Kovacs)</author>
    </item>
    <item>
      <title><![CDATA[FortiJump: CVE-2024-47575 FortiManager Zero-Day Exploited at Scale]]></title>
      <description><![CDATA[CVE-2024-47575, dubbed FortiJump, allowed unauthenticated attackers to execute commands on FortiManager devices. Mandiant confirmed exploitation by a new threat cluster targeting managed Fortinet infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/fortinet-fortimanager-cve-2024-47575</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fortinet-fortimanager-cve-2024-47575</guid>
      <pubDate>Fri, 13 Mar 2026 14:47:41 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[React Native Supply Chain Risks in 2024]]></title>
      <description><![CDATA[React Native bundles native modules, JavaScript dependencies, and CodePush-style OTA updates into one app. The supply chain is vast and the remediation path is slower than web apps. Here is where it actually goes wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-supply-chain-risks-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-supply-chain-risks-2024</guid>
      <pubDate>Fri, 13 Mar 2026 13:27:14 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[On-Prem to Cloud Supply Chain Continuity]]></title>
      <description><![CDATA[A year inside a financial services cloud migration, and how to keep your software supply chain intact when everything else about the environment changes.]]></description>
      <link>https://safeguard.sh/resources/blog/on-prem-to-cloud-supply-chain-continuity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/on-prem-to-cloud-supply-chain-continuity</guid>
      <pubDate>Fri, 13 Mar 2026 12:06:47 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Ensemble LLMs For High-Precision Security Findings]]></title>
      <description><![CDATA[One model&apos;s confident answer is a guess. Multiple models agreeing is evidence. Ensemble approaches raise precision for security-critical findings.]]></description>
      <link>https://safeguard.sh/resources/blog/ensemble-llm-for-high-precision-security-findings</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ensemble-llm-for-high-precision-security-findings</guid>
      <pubDate>Fri, 13 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs GPT-5: Compliance Posture]]></title>
      <description><![CDATA[Compliance posture is about what you can prove, not what you can do. GPT-5 has impressive capabilities; Griffin AI is engineered to be defensible.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-gpt-5-compliance-posture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-gpt-5-compliance-posture</guid>
      <pubDate>Fri, 13 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to Rotate Leaked CI Secrets Without Downtime]]></title>
      <description><![CDATA[A leaked CI credential does not have to mean an outage. The dual-credential pattern: issue new alongside old, cut over, verify with usage logs, then revoke — plus what to do after.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-rotate-leaked-ci-secrets-without-downtime</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-rotate-leaked-ci-secrets-without-downtime</guid>
      <pubDate>Fri, 13 Mar 2026 11:00:00 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Elena Kovacs)</author>
    </item>
    <item>
      <title><![CDATA[Maven Release Plugin Hardening]]></title>
      <description><![CDATA[The Maven Release Plugin is the oldest piece of release automation most Java shops still run. A look at the hardening steps it usually needs.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-release-plugin-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-release-plugin-hardening</guid>
      <pubDate>Fri, 13 Mar 2026 10:46:20 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to Prevent Dependency Confusion in npm (2026)]]></title>
      <description><![CDATA[Dependency confusion attacks are still landing in 2026 because scoped packages, registry config, and provenance checks are misconfigured by default. Here is the fix.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-prevent-dependency-confusion-npm-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-prevent-dependency-confusion-npm-2026</guid>
      <pubDate>Fri, 13 Mar 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is IAM (Identity and Access Management)]]></title>
      <description><![CDATA[IAM defines who and what can access your systems, and getting it wrong is a root cause behind breaches at Capital One, Toyota, Uber, and CircleCI.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-iam-identity-and-access-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-iam-identity-and-access-management</guid>
      <pubDate>Fri, 13 Mar 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Buck2 (Meta) Build Security Considerations]]></title>
      <description><![CDATA[A security engineer's look at Buck2, Meta's open-source build system, including Starlark sandbox properties, remote execution, and actual supply chain guarantees.]]></description>
      <link>https://safeguard.sh/resources/blog/buck2-meta-build-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buck2-meta-build-security-considerations</guid>
      <pubDate>Fri, 13 Mar 2026 09:25:54 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 vs NIST CSF: differences and how to choose]]></title>
      <description><![CDATA[ISO 27001 is a certifiable ISMS standard; NIST CSF is a voluntary risk framework. Compare both and see where Safeguard fits vs. Secureframe.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-vs-nist-csf-differences-and-how-to-choose</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-vs-nist-csf-differences-and-how-to-choose</guid>
      <pubDate>Fri, 13 Mar 2026 09:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Local Runner: Agentic Security on Your Laptop]]></title>
      <description><![CDATA[The Local Runner is a command-line agent that runs Safeguard workflows against your working tree. Think claude-code-for-security, but for supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-local-runner-release-agentic-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-local-runner-release-agentic-security</guid>
      <pubDate>Fri, 13 Mar 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[UNC5221 Ivanti Exploitation Campaign Analysis]]></title>
      <description><![CDATA[UNC5221 chained Ivanti Connect Secure zero-days through 2024 and 2025. The campaign reads like a masterclass in living off trusted edge appliances.]]></description>
      <link>https://safeguard.sh/resources/blog/unc5221-ivanti-exploitation-campaign-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unc5221-ivanti-exploitation-campaign-analysis</guid>
      <pubDate>Fri, 13 Mar 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Slack 2022-2023 Incidents: Operational Retrospective]]></title>
      <description><![CDATA[Slack disclosed a stolen-token incident over the 2022 holidays and a related GitHub repository access event; the operational lessons apply broadly.]]></description>
      <link>https://safeguard.sh/resources/blog/slack-2022-2023-incidents-operational-retrospective</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slack-2022-2023-incidents-operational-retrospective</guid>
      <pubDate>Fri, 13 Mar 2026 08:05:27 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is the Principle of Least Privilege]]></title>
      <description><![CDATA[The principle of least privilege limits every user and system to only the access it needs. Here's how it works and why it matters for cloud security.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-principle-of-least-privilege</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-principle-of-least-privilege</guid>
      <pubDate>Fri, 13 Mar 2026 07:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Typosquatting Meets AI: The New Threat of AI-Generated Package Names]]></title>
      <description><![CDATA[AI code assistants recommend packages that do not exist, and attackers are registering those hallucinated names. This new typosquatting vector exploits the trust developers place in AI suggestions.]]></description>
      <link>https://safeguard.sh/resources/blog/typosquatting-ai-generated-package-names</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/typosquatting-ai-generated-package-names</guid>
      <pubDate>Fri, 13 Mar 2026 06:45:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CMMC vs NIST 800-171: key differences]]></title>
      <description><![CDATA[CMMC and NIST 800-171 aren't the same thing. We break down the differences, where control families overlap, and how supply chain evidence fits into assessment.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-vs-nist-800-171-key-differences</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-vs-nist-800-171-key-differences</guid>
      <pubDate>Fri, 13 Mar 2026 06:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Panther SIEM Supply Chain Rules: A Detection Engineering Playbook]]></title>
      <description><![CDATA[Write Panther Python detections that catch package poisoning, CI token abuse, and registry compromise. Real rule examples, tuning patterns, and alert routing.]]></description>
      <link>https://safeguard.sh/resources/blog/panther-siem-supply-chain-rules</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/panther-siem-supply-chain-rules</guid>
      <pubDate>Fri, 13 Mar 2026 05:24:34 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Package Registry Forensic Log Analysis]]></title>
      <description><![CDATA[Extracting investigative signal from package registry logs — publish events, download patterns, and account activity — during a supply chain incident.]]></description>
      <link>https://safeguard.sh/resources/blog/package-registry-forensic-log-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/package-registry-forensic-log-analysis</guid>
      <pubDate>Fri, 13 Mar 2026 04:04:07 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Zero Trust Security]]></title>
      <description><![CDATA[Zero trust means never trusting a user, device, or workload by default. Here's what NIST 800-207 actually requires, why it applies to supply chains too.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-zero-trust-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-zero-trust-security</guid>
      <pubDate>Fri, 13 Mar 2026 04:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[CMMC vs FedRAMP: which do you need?]]></title>
      <description><![CDATA[CMMC governs DoD contractors; FedRAMP governs federal cloud services. Here's how to tell which you need — and where supply chain security fits versus GRC tools like Secureframe.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-vs-fedramp-which-do-you-need</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-vs-fedramp-which-do-you-need</guid>
      <pubDate>Fri, 13 Mar 2026 03:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP Meets STIG: Practical Mapping]]></title>
      <description><![CDATA[FedRAMP wants NIST 800-53 Rev 5 controls. DISA STIGs want hardening settings. The mapping between them is what determines whether your authorization package actually clears review.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-meets-stig-mapping-practical</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-meets-stig-mapping-practical</guid>
      <pubDate>Fri, 13 Mar 2026 02:43:40 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AWS SSM Parameter Store Security]]></title>
      <description><![CDATA[Parameter Store is everywhere in AWS workloads, which means it accumulates secrets, configuration, and bad IAM over time. Here is the security review I run on every Parameter Store deployment.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-ssm-parameter-store-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-ssm-parameter-store-security</guid>
      <pubDate>Fri, 13 Mar 2026 01:23:14 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is Infrastructure as Code (IaC)]]></title>
      <description><![CDATA[IaC turns infrastructure into versioned code, but one bad Terraform default can replicate a security hole across every environment it touches.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-infrastructure-as-code-iac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-infrastructure-as-code-iac</guid>
      <pubDate>Fri, 13 Mar 2026 01:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[State and Local Government SBOM Mandates]]></title>
      <description><![CDATA[States and cities are adopting SBOM requirements faster than most vendors have noticed. A survey of where the mandates sit and what they actually require.]]></description>
      <link>https://safeguard.sh/resources/blog/state-local-government-sbom-mandates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-local-government-sbom-mandates</guid>
      <pubDate>Fri, 13 Mar 2026 00:02:47 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Secureframe alternatives / competitors comparison]]></title>
      <description><![CDATA[Secureframe is built for compliance audits; Safeguard is built for software supply chain security. Here is how the two actually compare.]]></description>
      <link>https://safeguard.sh/resources/blog/secureframe-alternatives-competitors-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secureframe-alternatives-competitors-comparison</guid>
      <pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[SLSA Build Provenance for Python Publish]]></title>
      <description><![CDATA[Python packages on PyPI can carry SLSA provenance via PEP 740. Here is the publish workflow, the verification story, and the parts that still do not quite fit together.]]></description>
      <link>https://safeguard.sh/resources/blog/slsa-build-provenance-for-python-publish</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slsa-build-provenance-for-python-publish</guid>
      <pubDate>Thu, 12 Mar 2026 22:42:20 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[go generate Supply Chain Risks]]></title>
      <description><![CDATA[go generate is a seam where arbitrary commands run with the full privileges of the developer, and it does not show up in any manifest of trusted dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/go-generate-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-generate-supply-chain-risks</guid>
      <pubDate>Thu, 12 Mar 2026 21:21:54 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CISA's SBOM Sharing Lifecycle: A Framework for Practical Adoption]]></title>
      <description><![CDATA[CISA releases updated guidance on SBOM sharing practices, addressing the full lifecycle from generation to consumption across supplier and buyer relationships.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-sbom-sharing-lifecycle-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-sbom-sharing-lifecycle-2024</guid>
      <pubDate>Thu, 12 Mar 2026 20:01:27 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is a JWT (JSON Web Token)]]></title>
      <description><![CDATA[A JWT is a compact, signed token that carries claims like who a user is between parties. Learn its three parts, how signing works, and the common security pitfalls.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-jwt</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-jwt</guid>
      <pubDate>Thu, 12 Mar 2026 18:41:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CycloneDX and SPDX: Why Safeguard Supports Both and How We Normalize Between Them]]></title>
      <description><![CDATA[The SBOM format debate misses the point. Safeguard ingests both CycloneDX and SPDX, normalizes to a common model, and lets you query and export in either format.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-cyclonedx-spdx-dual-support</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-cyclonedx-spdx-dual-support</guid>
      <pubDate>Thu, 12 Mar 2026 17:20:33 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Security Testing for LLM-Powered Applications]]></title>
      <description><![CDATA[Applications built on large language models introduce novel attack surfaces that traditional security testing does not cover. This guide addresses the specific testing methodologies needed for LLM applications.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-application-security-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-application-security-testing</guid>
      <pubDate>Thu, 12 Mar 2026 16:00:07 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CodeQL vs Snyk: A Buyer Comparison for 2026]]></title>
      <description><![CDATA[A side-by-side comparison of CodeQL and Snyk in 2026 across SAST, SCA, container, and IaC coverage, with realistic expectations for each.]]></description>
      <link>https://safeguard.sh/resources/blog/codeql-vs-snyk-buyer-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/codeql-vs-snyk-buyer-comparison-2026</guid>
      <pubDate>Thu, 12 Mar 2026 15:30:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[GNU GPL Explained: Versions, Obligations, and Compatibility]]></title>
      <description><![CDATA[GPLv2 vs GPLv3, what the copyleft obligation actually requires, why 'GPLv2 or later' matters, and which licenses you can and cannot combine with the GPL.]]></description>
      <link>https://safeguard.sh/resources/blog/gnu-gpl-explained-versions-obligations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gnu-gpl-explained-versions-obligations</guid>
      <pubDate>Thu, 12 Mar 2026 14:39:40 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Ledger Connect Kit December 2023: A CDN Attack Retrospective]]></title>
      <description><![CDATA[The Ledger Connect Kit compromise was a five-hour CDN attack that drained roughly $600k from connected wallets. A look at how it happened and what defenders learned.]]></description>
      <link>https://safeguard.sh/resources/blog/ledger-connect-kit-2023-cdn-attack-retrospective</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ledger-connect-kit-2023-cdn-attack-retrospective</guid>
      <pubDate>Thu, 12 Mar 2026 14:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[The BSD License: Full Form and Terms Explained]]></title>
      <description><![CDATA[The BSD license full form is the Berkeley Software Distribution license — a permissive open-source license with fewer obligations than the GPL family, and a few variants worth telling apart.]]></description>
      <link>https://safeguard.sh/resources/blog/bsd-license-full-form-and-terms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bsd-license-full-form-and-terms</guid>
      <pubDate>Thu, 12 Mar 2026 13:19:13 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[crates.io's Security Team in 2026: Response Workflow, Notification Policy Change, and the Alpha-Omega Investment]]></title>
      <description><![CDATA[After the September 2025 phishing wave and the December evm-units removal, the crates.io team announced a notification policy update in February 2026 and the Rust Foundation deployed crate-scanning infrastructure funded by Alpha-Omega.]]></description>
      <link>https://safeguard.sh/resources/blog/crates-io-security-team-response-evolution-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crates-io-security-team-response-evolution-2026</guid>
      <pubDate>Thu, 12 Mar 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Hallucinated Security Findings: Measurable Rates]]></title>
      <description><![CDATA[Pure-LLM security analysis hallucinates findings at rates between 20% and 70% depending on the task and model. Grounding is the architectural answer.]]></description>
      <link>https://safeguard.sh/resources/blog/frontier-model-limit-hallucinated-security-findings</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/frontier-model-limit-hallucinated-security-findings</guid>
      <pubDate>Thu, 12 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Gemini for FedRAMP Workflows]]></title>
      <description><![CDATA[Gemini has FedRAMP-authorised deployment options. Griffin AI builds on FedRAMP-aligned infrastructure. The comparison is about what the customer has to build.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-compliance-fedramp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-compliance-fedramp</guid>
      <pubDate>Thu, 12 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[False Positive Rates: Griffin AI vs Mythos Benchmarked]]></title>
      <description><![CDATA[Why pure-LLM security products generate false positives that engine-grounded platforms like Griffin AI structurally cannot — with CWEs and real triage data.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-false-positive-rates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-false-positive-rates</guid>
      <pubDate>Thu, 12 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Support Model: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Support tier comparisons look identical on paper. The real difference shows up at 2am during an incident, and the shape of that difference is worth understanding before signing.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-support-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-support-model</guid>
      <pubDate>Thu, 12 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[dotnet restore Reproducibility Concerns]]></title>
      <description><![CDATA[dotnet restore is supposed to be deterministic. In practice it is deterministic in ways that matter less and non-deterministic in ways that matter more.]]></description>
      <link>https://safeguard.sh/resources/blog/dotnet-restore-reproducibility-concerns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dotnet-restore-reproducibility-concerns</guid>
      <pubDate>Thu, 12 Mar 2026 11:58:47 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Kimsuky Developer Targeting Analysis]]></title>
      <description><![CDATA[Kimsuky has pivoted from diplomats to developers. A look at the tradecraft behind its supply-chain-flavored operations and what engineering orgs should do about it.]]></description>
      <link>https://safeguard.sh/resources/blog/kimsuky-developer-targeting-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kimsuky-developer-targeting-analysis</guid>
      <pubDate>Thu, 12 Mar 2026 10:38:20 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cursor Enterprise Security Buyer Review 2026]]></title>
      <description><![CDATA[An honest security buyer's review of Cursor Enterprise for 2026: data handling, model isolation, audit posture, and the gaps to negotiate before signing.]]></description>
      <link>https://safeguard.sh/resources/blog/cursor-enterprise-security-buyer-review-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cursor-enterprise-security-buyer-review-2026</guid>
      <pubDate>Thu, 12 Mar 2026 10:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Sonatype IQ Server 2026: Repository Firewall in Review]]></title>
      <description><![CDATA[Sonatype Lifecycle's IQ Server ships weekly to cloud and monthly to self-hosted in 2026. We tracked the Repository Firewall changes and compared against JFrog Curation.]]></description>
      <link>https://safeguard.sh/resources/blog/sonatype-iq-2026-firewall-evolution-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonatype-iq-2026-firewall-evolution-review</guid>
      <pubDate>Thu, 12 Mar 2026 10:30:00 GMT</pubDate>
      <category>Tool Comparison</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Container Security: What It Scans and How]]></title>
      <description><![CDATA[Snyk Container scans Docker and OCI images for OS and dependency vulnerabilities and recommends better base images. Here is how it works and where its limits are.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-container-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-container-security</guid>
      <pubDate>Thu, 12 Mar 2026 10:10:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Best SCA Tools for Enterprise: 2026 Comparison]]></title>
      <description><![CDATA[A fact-based 2026 review of the best Software Composition Analysis tools for enterprise teams, covering depth, reachability, remediation, and compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/best-sca-tools-enterprise-2026-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-sca-tools-enterprise-2026-comparison</guid>
      <pubDate>Thu, 12 Mar 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE Triage Is Broken. Here's a Better Workflow.]]></title>
      <description><![CDATA[Most enterprise CVE queues are noise. KEV plus EPSS plus reachability plus policy-as-code cuts the real actionable list to a manageable few percent.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-triage-is-broken-better-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-triage-is-broken-better-workflow</guid>
      <pubDate>Thu, 12 Mar 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Actions Supply Chain Hardening Checklist 2026]]></title>
      <description><![CDATA[A pragmatic 2026 hardening checklist for GitHub Actions: OIDC, pinned actions, environment protection, reusable workflows, and the controls that actually move risk.]]></description>
      <link>https://safeguard.sh/resources/blog/github-actions-supply-chain-hardening-checklist-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-actions-supply-chain-hardening-checklist-2026</guid>
      <pubDate>Thu, 12 Mar 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[tj-actions Compromise: One Year Retrospective]]></title>
      <description><![CDATA[A year after the tj-actions/changed-files compromise leaked CI secrets across thousands of GitHub repos, what did we fix and what is still dangerously convenient?]]></description>
      <link>https://safeguard.sh/resources/blog/tj-actions-compromise-one-year-retrospective</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tj-actions-compromise-one-year-retrospective</guid>
      <pubDate>Thu, 12 Mar 2026 10:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is IaC Security]]></title>
      <description><![CDATA[IaC security scans Terraform, CloudFormation, and Kubernetes code before deployment—catching misconfigurations before they become breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-iac-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-iac-security</guid>
      <pubDate>Thu, 12 Mar 2026 10:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Azure App Service Deployment Security]]></title>
      <description><![CDATA[App Service deployments are easy, which is the problem. A look at the deployment paths, credential surfaces, and hardening steps that matter for production workloads.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-app-service-deployment-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-app-service-deployment-security</guid>
      <pubDate>Thu, 12 Mar 2026 09:17:53 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Secureframe pricing: plans and cost breakdown]]></title>
      <description><![CDATA[Secureframe doesn't publish pricing — here's what actually drives compliance automation cost, how it differs from supply chain security pricing, and how Safeguard fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/secureframe-pricing-plans-and-cost-breakdown</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secureframe-pricing-plans-and-cost-breakdown</guid>
      <pubDate>Thu, 12 Mar 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Security for Energy (NERC CIP) 2026]]></title>
      <description><![CDATA[Supply chain security for energy utilities in 2026 means CIP-013-2, CIP-010-4 software integrity, and the CIP-015-1 internal network monitoring rollout.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-energy-nerc-cip-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-energy-nerc-cip-2026</guid>
      <pubDate>Thu, 12 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Automating Third-Party Risk Assessment: Moving Beyond Spreadsheets and Questionnaires]]></title>
      <description><![CDATA[Why manual vendor risk assessments are failing, and how automation is reshaping third-party risk management for software supply chains.]]></description>
      <link>https://safeguard.sh/resources/blog/third-party-risk-assessment-automation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/third-party-risk-assessment-automation</guid>
      <pubDate>Thu, 12 Mar 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[EU Cyber Resilience Act: Final Text Analysis and Compliance Roadmap]]></title>
      <description><![CDATA[The EU Cyber Resilience Act was finalized in 2024, mandating cybersecurity requirements and SBOMs for products with digital elements. Here is what the final text requires and how to prepare.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cyber-resilience-act-final-text-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cyber-resilience-act-final-text-analysis</guid>
      <pubDate>Thu, 12 Mar 2026 07:57:27 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is Terraform Security]]></title>
      <description><![CDATA[Terraform security means finding and fixing risks in IaC code, state files, and providers before they become live cloud misconfigurations.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-terraform-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-terraform-security</guid>
      <pubDate>Thu, 12 Mar 2026 07:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Ruby Native Extensions Supply Chain]]></title>
      <description><![CDATA[Native C extensions are the most under-audited part of the Ruby supply chain: how they get built, what can go wrong, and how to monitor them as seriously as you monitor pure-Ruby code.]]></description>
      <link>https://safeguard.sh/resources/blog/ruby-native-extensions-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ruby-native-extensions-supply-chain</guid>
      <pubDate>Thu, 12 Mar 2026 06:37:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Secureframe vs Vanta comparison]]></title>
      <description><![CDATA[Secureframe and Vanta both automate SOC 2 evidence collection, but neither scans your dependencies or build pipeline. Here's what to know before choosing.]]></description>
      <link>https://safeguard.sh/resources/blog/secureframe-vs-vanta-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secureframe-vs-vanta-comparison</guid>
      <pubDate>Thu, 12 Mar 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[How to Rotate Build Signing Keys Safely]]></title>
      <description><![CDATA[A step-by-step tutorial for rotating Cosign and GPG build signing keys without breaking existing attestations, verification chains, or downstream consumers.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-rotate-build-signing-keys-safely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-rotate-build-signing-keys-safely</guid>
      <pubDate>Thu, 12 Mar 2026 05:16:33 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is AWS CloudFormation Security]]></title>
      <description><![CDATA[What is CloudFormation security? A practical breakdown of IAM least privilege, drift detection, secret scanning, and template misconfigurations that cause breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-aws-cloudformation-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-aws-cloudformation-security</guid>
      <pubDate>Thu, 12 Mar 2026 04:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[GNU AGPL vs GPL: When AGPL Actually Applies]]></title>
      <description><![CDATA[The GNU Affero General Public License v3.0 closes the network-use loophole that GPL leaves open — here's exactly when that difference matters for your codebase.]]></description>
      <link>https://safeguard.sh/resources/blog/gnu-agpl-vs-gpl-when-agpl-applies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gnu-agpl-vs-gpl-when-agpl-applies</guid>
      <pubDate>Thu, 12 Mar 2026 03:56:07 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 Trust Services Criteria explained (security, availa...]]></title>
      <description><![CDATA[A breakdown of the five SOC 2 Trust Services Criteria, when each applies, and where Secureframe-style control mapping stops short of software supply chain evidence.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-trust-services-criteria-explained-security-availability-confidentiality-processing-integrity-privacy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-trust-services-criteria-explained-security-availability-confidentiality-processing-integrity-privacy</guid>
      <pubDate>Thu, 12 Mar 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Apache License 2.0 Explained: Permissions, Conditions, and Commercial Use]]></title>
      <description><![CDATA[What the Apache License 2.0 lets you do, what it requires (attribution, NOTICE, change marking), and why its patent grant matters for commercial software.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-license-2-0-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-license-2-0-explained</guid>
      <pubDate>Thu, 12 Mar 2026 02:35:40 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SAST Meaning and Full Form: Static Application Security Testing Explained]]></title>
      <description><![CDATA[SAST stands for Static Application Security Testing — analyzing source code for vulnerabilities without running it. Here is what the term means, how it works, and where it fits alongside DAST and SCA.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-meaning-full-form-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-meaning-full-form-explained</guid>
      <pubDate>Thu, 12 Mar 2026 01:15:13 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Policy as Code]]></title>
      <description><![CDATA[Policy as code turns security and compliance rules into version-controlled, testable code enforced automatically in CI/CD, admission control, and runtime.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-policy-as-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-policy-as-code</guid>
      <pubDate>Thu, 12 Mar 2026 01:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-24071 Windows Explorer NTLM Hash Leak]]></title>
      <description><![CDATA[A .library-ms file extracted from a zip archive can leak NTLM hashes without the user opening anything. Breakdown of CVE-2025-24071 and the defensive response.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2025-24071-windows-explorer-ntlm-leak</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2025-24071-windows-explorer-ntlm-leak</guid>
      <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 controls list: what controls you need to implement]]></title>
      <description><![CDATA[A breakdown of the SOC 2 controls list across all five Trust Services Criteria, how Secureframe maps them, and what auditors actually test.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-controls-list-what-controls-you-need-to-implement</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-controls-list-what-controls-you-need-to-implement</guid>
      <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[What is Dependency Pinning]]></title>
      <description><![CDATA[Dependency pinning locks every package in your build to an exact, verified version so the code you tested is the code you ship. Here's how to do it per ecosystem.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-dependency-pinning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-dependency-pinning</guid>
      <pubDate>Wed, 11 Mar 2026 23:54:46 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Raman)</author>
    </item>
    <item>
      <title><![CDATA[What is an SBOM Drift]]></title>
      <description><![CDATA[SBOM drift is the gap between what your software bill of materials claims and what the artifact actually contains. Here's how it happens and how to detect it with a diff.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-an-sbom-drift</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-an-sbom-drift</guid>
      <pubDate>Wed, 11 Mar 2026 22:34:20 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Elena Kovacs)</author>
    </item>
    <item>
      <title><![CDATA[Docker Hub Rate Limit Changes and CI Impact]]></title>
      <description><![CDATA[Docker's 2024 rate-limit reforms hit CI pipelines hard. Measured impact on 30 real build farms and the mirror and pull-through controls that fixed it.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-hub-rate-limit-policy-changes-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-hub-rate-limit-policy-changes-2024</guid>
      <pubDate>Wed, 11 Mar 2026 21:13:53 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GCP Pub/Sub Security Configuration]]></title>
      <description><![CDATA[A working security configuration for GCP Pub/Sub: topic and subscription IAM, message encryption, VPC Service Controls, dead-letter handling, and the failure modes that turn a messaging layer into an attack surface.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-pub-sub-security-configuration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-pub-sub-security-configuration</guid>
      <pubDate>Wed, 11 Mar 2026 19:53:26 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard v3: Compliance-First Supply Chain Security]]></title>
      <description><![CDATA[Safeguard v3 adds compliance framework mapping, automated evidence collection, audit-ready reporting, and VEX document support for regulatory readiness.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-v3-release-compliance-features</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-v3-release-compliance-features</guid>
      <pubDate>Wed, 11 Mar 2026 18:33:00 GMT</pubDate>
      <category>Release</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Adoption in 2024: Enterprise Survey Results and Reality Check]]></title>
      <description><![CDATA[Despite growing regulatory pressure, enterprise SBOM adoption remains uneven. A look at where organizations actually stand with SBOM generation, consumption, and operationalization.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-adoption-rates-enterprise-survey-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-adoption-rates-enterprise-survey-2024</guid>
      <pubDate>Wed, 11 Mar 2026 17:12:33 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Volt Typhoon: Living-Off-the-Land and Supply Chain]]></title>
      <description><![CDATA[The PRC-linked pre-positioning group that scared DHS and the NSA into a public warning, and what it means for supply chain defenders.]]></description>
      <link>https://safeguard.sh/resources/blog/volt-typhoon-living-off-the-land-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/volt-typhoon-living-off-the-land-supply-chain</guid>
      <pubDate>Wed, 11 Mar 2026 15:52:06 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GraphQL Supply Chain Security Considerations]]></title>
      <description><![CDATA[Supply chain risks specific to GraphQL stacks: Apollo, graphql-js, persisted queries, introspection, and transitive risk in gateway federation.]]></description>
      <link>https://safeguard.sh/resources/blog/graphql-supply-chain-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/graphql-supply-chain-security-considerations</guid>
      <pubDate>Wed, 11 Mar 2026 14:31:40 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AI Data Security Solutions: What Actually Protects Your Data?]]></title>
      <description><![CDATA[AI data security solutions cover the tools and controls that protect the data flowing into, through, and out of AI systems. Here is what the category really includes and how to evaluate it.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-data-security-solutions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-data-security-solutions</guid>
      <pubDate>Wed, 11 Mar 2026 14:05:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Software Security Testing: A Practitioner's Overview]]></title>
      <description><![CDATA[Software security testing spans static analysis, dynamic testing, dependency scanning, and manual review — a practical map of which method catches what, written for people who actually run these programs.]]></description>
      <link>https://safeguard.sh/resources/blog/software-security-testing-a-practitioners-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-security-testing-a-practitioners-overview</guid>
      <pubDate>Wed, 11 Mar 2026 13:11:13 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Fine-Tune Backdoors: The Quiet Threat]]></title>
      <description><![CDATA[Fine-tuning a model on an attacker-controlled dataset can implant behaviour that only activates under specific conditions. The threat is quiet because detection is hard.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-trend-fine-tune-backdoors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-trend-fine-tune-backdoors</guid>
      <pubDate>Wed, 11 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CIRCIA Final Rule: Reporting Thresholds and Covered Entities]]></title>
      <description><![CDATA[CISA pushed the CIRCIA final rule to May 2026. We unpack the dual-track threshold structure, the 72-hour and 24-hour timers, and what the 300,000-entity scope means.]]></description>
      <link>https://safeguard.sh/resources/blog/circia-final-rule-reporting-thresholds-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/circia-final-rule-reporting-thresholds-explained</guid>
      <pubDate>Wed, 11 Mar 2026 12:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Cloud IAM And Supply Chain Overlap Mistakes]]></title>
      <description><![CDATA[Cloud IAM and supply chain controls overlap in ways that confuse most teams. These are the 2026 mistakes that turn IAM gaps into supply chain incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-iam-supply-chain-overlap-mistakes-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-iam-supply-chain-overlap-mistakes-2026</guid>
      <pubDate>Wed, 11 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Code Signing Key Theft Trend Watch]]></title>
      <description><![CDATA[Code signing key theft has surged across 2025 and 2026. We trace the recurring incident patterns, the operator tradecraft, and the structural defenses that work.]]></description>
      <link>https://safeguard.sh/resources/blog/code-signing-key-theft-trend-watch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-signing-key-theft-trend-watch</guid>
      <pubDate>Wed, 11 Mar 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Rollback Safety: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Sometimes a remediation has to be reverted. Griffin AI's minimal, grounded patches roll back cleanly; Mythos-class patches often do not.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-rollback-safety</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-rollback-safety</guid>
      <pubDate>Wed, 11 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Signed Artifact Policy Enforcement In 2026]]></title>
      <description><![CDATA[Signing artifacts is necessary but not sufficient. The policy that verifies signatures, attestations, and trust roots is what turns signing into a security control.]]></description>
      <link>https://safeguard.sh/resources/blog/signed-artifact-policy-enforcement-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/signed-artifact-policy-enforcement-2026</guid>
      <pubDate>Wed, 11 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Space Systems Supply Chain Controls 2026]]></title>
      <description><![CDATA[Space systems software supply chain controls are tightening across DoD, NRO, and commercial space. Here is what the new bar looks like and how to clear it.]]></description>
      <link>https://safeguard.sh/resources/blog/space-systems-supply-chain-controls-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/space-systems-supply-chain-controls-2026</guid>
      <pubDate>Wed, 11 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Triage Hand-Off From Security To Engineering]]></title>
      <description><![CDATA[The handoff between security triage and engineering remediation is where most programs lose time. Here is how to fix it with context-rich PRs and AI.]]></description>
      <link>https://safeguard.sh/resources/blog/triage-hand-off-from-security-to-engineering</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/triage-hand-off-from-security-to-engineering</guid>
      <pubDate>Wed, 11 Mar 2026 12:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Zero-Day Discovery Economics: Cost Per Find]]></title>
      <description><![CDATA[The economics of zero-day discovery have been opaque for too long. Here is the actual cost structure of finding a real, defensible bug, and how to think about it.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-day-discovery-economics-cost-per-find</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-day-discovery-economics-cost-per-find</guid>
      <pubDate>Wed, 11 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GCP Binary Authorization Policy Patterns]]></title>
      <description><![CDATA[Policy design patterns for GCP Binary Authorization that hold up in production: attestor topology, exception handling, continuous validation, and the shapes that stop a deploy-time compromise without blocking legitimate rollouts.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-binary-authorization-policy-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-binary-authorization-policy-patterns</guid>
      <pubDate>Wed, 11 Mar 2026 11:50:46 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Codespaces and Supply Chain Risk in 2026]]></title>
      <description><![CDATA[Codespaces shifts development from the laptop to the cloud, which changes the supply chain threat model in ways most teams have not fully thought through.]]></description>
      <link>https://safeguard.sh/resources/blog/github-codespaces-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-codespaces-supply-chain-2026</guid>
      <pubDate>Wed, 11 Mar 2026 11:30:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Choosing a Container Security Tool in 2026: What Actually Matters]]></title>
      <description><![CDATA[A container security tool should cover the image, the registry, and the running workload — not just spit out a CVE list. Here is how to evaluate one without the marketing gloss.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-tool</guid>
      <pubDate>Wed, 11 Mar 2026 11:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[snyk test and snyk code test: Command Guide with Examples]]></title>
      <description><![CDATA[snyk test scans your dependencies; snyk code test runs SAST on your own source. Install, auth, flags, CI exit codes, and the gotchas between the two commands.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-test-and-snyk-code-test-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-test-and-snyk-code-test-guide</guid>
      <pubDate>Wed, 11 Mar 2026 10:45:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CUPS Vulnerability Chain: Remote Code Execution via Linux Printing]]></title>
      <description><![CDATA[A chain of vulnerabilities in the CUPS printing system allows unauthenticated attackers to achieve remote code execution on Linux systems by exploiting how printers are discovered and configured.]]></description>
      <link>https://safeguard.sh/resources/blog/cups-linux-rce-vulnerability-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cups-linux-rce-vulnerability-chain</guid>
      <pubDate>Wed, 11 Mar 2026 10:30:20 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Intelligence Platform Buyer Guide 2026]]></title>
      <description><![CDATA[A senior-engineer's buyer guide for vulnerability intelligence platforms in 2026: what to evaluate, how to test, and where most procurement processes go wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-intelligence-platform-buyer-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-intelligence-platform-buyer-guide-2026</guid>
      <pubDate>Wed, 11 Mar 2026 10:30:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Writing a Data Container Security Policy That Teams Actually Follow]]></title>
      <description><![CDATA[A data container security policy sets the rules for how containers handling sensitive data are built, run, and monitored. Here is what to put in one.]]></description>
      <link>https://safeguard.sh/resources/blog/data-container-security-policy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/data-container-security-policy</guid>
      <pubDate>Wed, 11 Mar 2026 10:15:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[AI Code Checker: What It Catches and What It Misses]]></title>
      <description><![CDATA[An AI code checker uses a language model to review code for bugs and security issues. Here is where it genuinely helps and where trusting it blindly bites you.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-code-checker</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-code-checker</guid>
      <pubDate>Wed, 11 Mar 2026 10:05:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[The Full Form of MCP: What Model Context Protocol Means for Security]]></title>
      <description><![CDATA[The full form of MCP is Model Context Protocol, the open standard that lets AI models talk to tools and data. Here is what it is and where the security risks live.]]></description>
      <link>https://safeguard.sh/resources/blog/full-form-of-mcp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/full-form-of-mcp</guid>
      <pubDate>Wed, 11 Mar 2026 10:05:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Configuration Drift]]></title>
      <description><![CDATA[Configuration drift silently pulls live systems away from their secure baseline — and it's behind some of the largest cloud data exposures on record.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-configuration-drift</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-configuration-drift</guid>
      <pubDate>Wed, 11 Mar 2026 10:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[How to Secure a Docker Container: A Practical Hardening Guide]]></title>
      <description><![CDATA[A secure Docker container starts with a minimal base image, a non-root user, and a scanned, pinned dependency set. Here's the hardening checklist that actually holds up in production.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-docker-container</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-docker-container</guid>
      <pubDate>Wed, 11 Mar 2026 09:45:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Mend vs Checkmarx vs Snyk: A Practical Comparison]]></title>
      <description><![CDATA[Mend security, Checkmarx, and Snyk all promise to cover SCA and SAST, but they arrive from different roots and that shows up in how each one actually performs day to day.]]></description>
      <link>https://safeguard.sh/resources/blog/mend-vs-checkmarx-vs-snyk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mend-vs-checkmarx-vs-snyk</guid>
      <pubDate>Wed, 11 Mar 2026 09:30:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Docker Compliance and Scanning for Regulated Teams]]></title>
      <description><![CDATA[Regulated teams can't treat container scanning as a one-time gate — auditors want a documented, continuous process tied to actual docker vulnerability news, not a clean scan from six months ago.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-compliance-and-scanning-for-regulated-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-compliance-and-scanning-for-regulated-teams</guid>
      <pubDate>Wed, 11 Mar 2026 09:15:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[AWS CDK Construct Library Security]]></title>
      <description><![CDATA[CDK constructs are code that provisions infrastructure. Most teams audit the infrastructure but not the constructs. Here is how to think about construct library security and what to check.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-cdk-construct-library-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-cdk-construct-library-security</guid>
      <pubDate>Wed, 11 Mar 2026 09:09:53 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Real-world SOC 2 report example walkthrough with download...]]></title>
      <description><![CDATA[A section-by-section walkthrough of a real SOC 2 Type II report, with a downloadable sample, plus where Secureframe's evidence trail leaves gaps auditors flag.]]></description>
      <link>https://safeguard.sh/resources/blog/real-world-soc-2-report-example-walkthrough-with-downloadable-sample</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/real-world-soc-2-report-example-walkthrough-with-downloadable-sample</guid>
      <pubDate>Wed, 11 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Storm-0558 Microsoft Cloud Identity Aftermath]]></title>
      <description><![CDATA[Storm-0558 forged Microsoft cloud tokens with a stolen MSA key and read government email. Three years later the architectural lessons are still unevenly applied.]]></description>
      <link>https://safeguard.sh/resources/blog/storm-0558-microsoft-cloud-identity-aftermath</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/storm-0558-microsoft-cloud-identity-aftermath</guid>
      <pubDate>Wed, 11 Mar 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[VS Code Marketplace Malware Campaigns in 2025]]></title>
      <description><![CDATA[A senior engineer's review of the 2025 VS Code Marketplace malware wave, including typosquats, trojanized themes, and extensions that stole npm tokens at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/vscode-extension-marketplace-malware-campaigns-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vscode-extension-marketplace-malware-campaigns-2025</guid>
      <pubDate>Wed, 11 Mar 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Malware in 2026: What Changed]]></title>
      <description><![CDATA[PyPI malware today looks less like typosquats and more like AI-assisted campaigns that mimic legitimate maintainers — here's what shifted and how teams are catching it before install.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-malware-2026-what-changed</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-malware-2026-what-changed</guid>
      <pubDate>Wed, 11 Mar 2026 08:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is SAML]]></title>
      <description><![CDATA[SAML lets an identity provider vouch for you to other applications using signed XML assertions. Learn how it powers enterprise single sign-on and how it works.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-saml</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-saml</guid>
      <pubDate>Wed, 11 Mar 2026 07:49:26 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is GitOps Security]]></title>
      <description><![CDATA[GitOps turns your Git repo into the source of truth for production, so one bad commit or stolen credential can mean a full cluster takeover.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-gitops-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-gitops-security</guid>
      <pubDate>Wed, 11 Mar 2026 07:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Witness Attestation Collection Workflow]]></title>
      <description><![CDATA[Witness turns build steps into a chain of signed attestations. Here is how we use it in production pipelines, what it does well, and where the edges still cut.]]></description>
      <link>https://safeguard.sh/resources/blog/witness-attestation-collection-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/witness-attestation-collection-workflow</guid>
      <pubDate>Wed, 11 Mar 2026 06:28:59 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The SOC 2 audit process step by step]]></title>
      <description><![CDATA[A step-by-step breakdown of the SOC 2 audit process — timelines, costs, Type 1 vs Type 2, and what auditors actually check — with a look at where Safeguard fits alongside tools like Secureframe.]]></description>
      <link>https://safeguard.sh/resources/blog/the-soc-2-audit-process-step-by-step</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-soc-2-audit-process-step-by-step</guid>
      <pubDate>Wed, 11 Mar 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Foundation Governance Models]]></title>
      <description><![CDATA[The Linux Foundation, Apache Software Foundation, CNCF, and Eclipse each codify different theories of how open source projects should be governed. The differences matter more than most adopters realize.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-foundation-governance-models</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-foundation-governance-models</guid>
      <pubDate>Wed, 11 Mar 2026 05:08:33 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is API Security]]></title>
      <description><![CDATA[API security explained: what it is, why APIs are the top breach vector, the OWASP API Top 10, real breaches, and how to test and monitor endpoints.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-api-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-api-security</guid>
      <pubDate>Wed, 11 Mar 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Doppler Enterprise Secrets Platform Reviewed]]></title>
      <description><![CDATA[Doppler pitches itself as the secrets platform that gets out of developers' way. A detailed look at what works, what does not, and the trade-offs against Vault, Infisical, and the cloud-native options.]]></description>
      <link>https://safeguard.sh/resources/blog/doppler-enterprise-secrets-platform-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/doppler-enterprise-secrets-platform-review</guid>
      <pubDate>Wed, 11 Mar 2026 03:48:06 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 readiness assessment guide plus free checklist]]></title>
      <description><![CDATA[A practical SOC 2 readiness assessment guide with a free checklist covering timelines, costs, and the supply chain evidence gaps generic GRC tools like Secureframe miss.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-readiness-assessment-guide-plus-free-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-readiness-assessment-guide-plus-free-checklist</guid>
      <pubDate>Wed, 11 Mar 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Ransomware-as-a-Service in 2024: The Ecosystem That Won't Die]]></title>
      <description><![CDATA[The RaaS ecosystem proved resilient through 2024 despite major law enforcement takedowns, with new groups filling every gap and affiliate models becoming more sophisticated.]]></description>
      <link>https://safeguard.sh/resources/blog/ransomware-as-a-service-ecosystem-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ransomware-as-a-service-ecosystem-2024</guid>
      <pubDate>Wed, 11 Mar 2026 02:27:39 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Rust Crate Security: cargo audit, cargo vet and Beyond]]></title>
      <description><![CDATA[cargo audit catches known-bad versions, cargo vet forces someone to actually read the code. What each tool covers, what neither covers, and how to run both without hating your CI.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-crate-security-cargo-audit-cargo-vet-and-beyond</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-crate-security-cargo-audit-cargo-vet-and-beyond</guid>
      <pubDate>Wed, 11 Mar 2026 01:07:13 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Sofia Marchetti)</author>
    </item>
    <item>
      <title><![CDATA[API Security Testing Checklist & Best Practices]]></title>
      <description><![CDATA[A concrete API security testing checklist covering OWASP API Top 10 risks, BOLA, SSRF, testing cadence, SAST/DAST, and how Safeguard closes the gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-testing-checklist-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-testing-checklist-best-practices</guid>
      <pubDate>Wed, 11 Mar 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 compliance automation: what it is and how it simpli...]]></title>
      <description><![CDATA[SOC 2 compliance automation cuts audit prep from months to weeks—but tools like Secureframe only aggregate evidence. Here's the gap in supply chain security controls.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-compliance-automation-what-it-is-and-how-it-simplifies-audits</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-compliance-automation-what-it-is-and-how-it-simplifies-audits</guid>
      <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems.org and Sigstore: Progress Check]]></title>
      <description><![CDATA[An honest look at where RubyGems.org stands with Sigstore integration, what has shipped, what is still being debated, and how maintainers can prepare for signed gems.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-org-sigstore-integration-progress</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-org-sigstore-integration-progress</guid>
      <pubDate>Tue, 10 Mar 2026 23:46:46 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes 1.30 and 1.31 Security Rundown]]></title>
      <description><![CDATA[ValidatingAdmissionPolicy GA, VolumeSource for OCI artifacts, and anonymous API cleanup: what 1.30 and 1.31 change for cluster security posture.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-1-30-and-1-31-security-rundown</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-1-30-and-1-31-security-rundown</guid>
      <pubDate>Tue, 10 Mar 2026 22:26:19 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Fastify Security Posture in 2024]]></title>
      <description><![CDATA[Fastify hit version 5.0 in September 2024 with a slimmer core, a plugin model that encourages correctness, and a security track record that genuinely distinguishes it from the Express crowd. Here is what I have learned auditing Fastify apps this year.]]></description>
      <link>https://safeguard.sh/resources/blog/fastify-security-posture-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fastify-security-posture-2024</guid>
      <pubDate>Tue, 10 Mar 2026 21:05:53 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Qilin Ransomware and the Chrome Credential Harvesting Gambit]]></title>
      <description><![CDATA[Qilin ransomware operators pioneered a mass credential theft technique using Group Policy to extract saved Chrome browser credentials across entire domains.]]></description>
      <link>https://safeguard.sh/resources/blog/qilin-ransomware-credential-harvesting-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/qilin-ransomware-credential-harvesting-techniques</guid>
      <pubDate>Tue, 10 Mar 2026 19:45:26 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Workload Protection Platforms in 2024: What Actually Matters]]></title>
      <description><![CDATA[Cutting through the CWPP marketing noise to identify the capabilities that genuinely protect cloud workloads from modern threats.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-workload-protection-platforms-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-workload-protection-platforms-2024</guid>
      <pubDate>Tue, 10 Mar 2026 18:24:59 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software Escrow and Supply Chain Continuity Planning]]></title>
      <description><![CDATA[Most escrow deposits are write-only: nobody ever verifies they build. What escrow actually covers, when to pay for verification, and what continuity means for SaaS and OSS.]]></description>
      <link>https://safeguard.sh/resources/blog/software-escrow-and-supply-chain-continuity-planning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-escrow-and-supply-chain-continuity-planning</guid>
      <pubDate>Tue, 10 Mar 2026 17:04:33 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Sofia Marchetti)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Typosquatting Detection at Scale]]></title>
      <description><![CDATA[Typosquatting remains a steady drumbeat on PyPI. What detection actually looks like when you're trying to catch it at ecosystem scale, and where the interesting edges are.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-typosquatting-detection-at-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-typosquatting-detection-at-scale</guid>
      <pubDate>Tue, 10 Mar 2026 15:44:06 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Public-Sector Software Procurement Requirements]]></title>
      <description><![CDATA[A tour through the attestations, self-certifications, and supply chain obligations that now shape how governments buy software.]]></description>
      <link>https://safeguard.sh/resources/blog/public-sector-software-procurement-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/public-sector-software-procurement-requirements</guid>
      <pubDate>Tue, 10 Mar 2026 14:23:39 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Third-Party Risk Assessment Automation Playbook for 2026]]></title>
      <description><![CDATA[A practical playbook for automating TPRM in 2026: what signals to ingest, where humans still matter, and how to turn vendor questionnaires into continuous monitoring.]]></description>
      <link>https://safeguard.sh/resources/blog/third-party-risk-assessment-automation-playbook-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/third-party-risk-assessment-automation-playbook-2026</guid>
      <pubDate>Tue, 10 Mar 2026 13:15:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[GitGuardian vs TruffleHog: Secret Detection Showdown]]></title>
      <description><![CDATA[Compare GitGuardian and TruffleHog on detector coverage, validation, historical scans, developer workflow, and pricing to pick the right secret scanning tool.]]></description>
      <link>https://safeguard.sh/resources/blog/gitguardian-vs-trufflehog-secret-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitguardian-vs-trufflehog-secret-detection</guid>
      <pubDate>Tue, 10 Mar 2026 13:03:12 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AI Agent Blast Radius Management]]></title>
      <description><![CDATA[Every agent in production has a blast radius. Most teams have not measured theirs. Here is how to measure it and how to bring it under control.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-agent-blast-radius-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-agent-blast-radius-management</guid>
      <pubDate>Tue, 10 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AI-BOM Becoming Mandatory: Regulatory Trend]]></title>
      <description><![CDATA[AI bills of materials moved from voluntary best practice to regulatory requirement in 2026. Multiple jurisdictions now require disclosure of model, data, and component lineage for high-impact AI systems.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-bom-becoming-mandatory-regulatory-trend</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-bom-becoming-mandatory-regulatory-trend</guid>
      <pubDate>Tue, 10 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Asset Discovery As CMDB Replacement In 2026]]></title>
      <description><![CDATA[The traditional CMDB cannot keep up with cloud, AI, and agent workloads. Continuous discovery is the only model that survives 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/asset-discovery-for-cmdb-replacement-in-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/asset-discovery-for-cmdb-replacement-in-2026</guid>
      <pubDate>Tue, 10 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Developer Onboarding Supply Chain Controls Template]]></title>
      <description><![CDATA[The first week is when developers form their habits. A template for onboarding new engineers into supply chain controls without overwhelming them.]]></description>
      <link>https://safeguard.sh/resources/blog/developer-onboarding-supply-chain-controls-template</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/developer-onboarding-supply-chain-controls-template</guid>
      <pubDate>Tue, 10 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CMMC Pass-Through: Griffin AI vs Mythos]]></title>
      <description><![CDATA[CMMC 2.0 rollout has made flow-down expectations concrete. AI-for-security tools used by DIB contractors are in scope, and the pass-through story matters.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cmmc-pass-through</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cmmc-pass-through</guid>
      <pubDate>Tue, 10 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Transitive Depth: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Most scanners stop at five or six levels of transitive depth. Real production graphs run sixty levels deep, and the most interesting vulnerabilities live in the long tail.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-transitive-depth-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-transitive-depth-comparison</guid>
      <pubDate>Tue, 10 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Pharma Clinical Trials Software Supply Chain]]></title>
      <description><![CDATA[Clinical trial software underpins regulatory submissions worth billions. Here is the supply chain program that protects trial data integrity end-to-end.]]></description>
      <link>https://safeguard.sh/resources/blog/pharma-clinical-trials-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pharma-clinical-trials-software-supply-chain</guid>
      <pubDate>Tue, 10 Mar 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[PHP / Composer Supply Chain Defence 2026]]></title>
      <description><![CDATA[A 2026 supply chain defence for PHP and Composer — covering Packagist, composer.lock, autoload manipulation, and Laravel — backed by Safeguard.]]></description>
      <link>https://safeguard.sh/resources/blog/php-composer-supply-chain-defence-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-composer-supply-chain-defence-2026</guid>
      <pubDate>Tue, 10 Mar 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis For EU CRA Due Diligence]]></title>
      <description><![CDATA[EU CRA enforcement asks vendors and operators to demonstrate due diligence on software components. Reachability is the evidence that makes the demonstration honest.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-for-eu-cra-due-diligence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-for-eu-cra-due-diligence</guid>
      <pubDate>Tue, 10 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Vendor SBOM Ingest Program Blueprint]]></title>
      <description><![CDATA[Asking vendors for SBOMs is easy. Building a program that actually does something with them is harder. Here is a working blueprint that scales past a hundred vendors.]]></description>
      <link>https://safeguard.sh/resources/blog/vendor-sbom-ingest-program-blueprint-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vendor-sbom-ingest-program-blueprint-2026</guid>
      <pubDate>Tue, 10 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Database Platform Migration: Supply Chain]]></title>
      <description><![CDATA[Database migrations touch every part of the software supply chain. This guide covers how to keep schemas, secrets, and data lineage secure during a platform change.]]></description>
      <link>https://safeguard.sh/resources/blog/database-platform-migration-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/database-platform-migration-supply-chain</guid>
      <pubDate>Tue, 10 Mar 2026 11:42:46 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Dagger.io Supply Chain Pipelines]]></title>
      <description><![CDATA[Dagger programmatic pipelines offer genuine supply chain benefits when used well. Here are the patterns and pitfalls from running Dagger in production.]]></description>
      <link>https://safeguard.sh/resources/blog/dagger-io-supply-chain-pipelines</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dagger-io-supply-chain-pipelines</guid>
      <pubDate>Tue, 10 Mar 2026 10:22:19 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Executive Order 14028 at Five Years: A Comprehensive Review]]></title>
      <description><![CDATA[Five years after President Biden signed EO 14028, we assess what it accomplished, what it missed, and what comes next.]]></description>
      <link>https://safeguard.sh/resources/blog/eo-14028-five-years-comprehensive-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eo-14028-five-years-comprehensive-review</guid>
      <pubDate>Tue, 10 Mar 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to Secure REST APIs]]></title>
      <description><![CDATA[REST APIs keep failing the same way: BOLA, weak auth, shadow endpoints. Real breaches (T-Mobile, Optus, Peloton) and concrete fixes for each.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-secure-rest-apis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-secure-rest-apis</guid>
      <pubDate>Tue, 10 Mar 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to Sign Container Images with Cosign in Production]]></title>
      <description><![CDATA[Keyless Cosign signing with Fulcio and Rekor is the 2026 default. Here is the production workflow, policy configuration, and the failure modes nobody warns you about.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-sign-container-images-cosign-production</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-sign-container-images-cosign-production</guid>
      <pubDate>Tue, 10 Mar 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard March 2026 Release Notes]]></title>
      <description><![CDATA[March 2026 at Safeguard: Griffin taint tracking, Eagle SBOM-driven advisories, Lion cross-service baselines, and the new runner air-gap installer.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-changelog-march-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-changelog-march-2026</guid>
      <pubDate>Tue, 10 Mar 2026 10:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Copyleft Licenses: Strong vs Weak, and Why It Matters]]></title>
      <description><![CDATA[Copyleft licenses aren't one category — the gap between GPL-style strong copyleft and LGPL-style weak copyleft decides whether linking a library obligates you to open your own code.]]></description>
      <link>https://safeguard.sh/resources/blog/copyleft-licenses-strong-vs-weak</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/copyleft-licenses-strong-vs-weak</guid>
      <pubDate>Tue, 10 Mar 2026 09:01:52 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Best Practices for npm Lockfile Security 2026]]></title>
      <description><![CDATA[Your package-lock.json is a supply chain control, not build noise. Six habits — npm ci, script blocking, lockfile linting, provenance checks — that stop most npm attacks cold.]]></description>
      <link>https://safeguard.sh/resources/blog/best-practices-for-npm-lockfile-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-practices-for-npm-lockfile-security-2026</guid>
      <pubDate>Tue, 10 Mar 2026 09:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[FTC and Software Supply Chain Enforcement 2026]]></title>
      <description><![CDATA[The FTC's widening enforcement posture after the MGM breach and related consent orders is reshaping software supply chain accountability for vendors and buyers.]]></description>
      <link>https://safeguard.sh/resources/blog/ftc-mgm-breach-settlement-software-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ftc-mgm-breach-settlement-software-implications</guid>
      <pubDate>Tue, 10 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Rotate Leaked Secrets With Automation (2026)]]></title>
      <description><![CDATA[The 2026 playbook for automated secret rotation: detection pipelines, credential broker patterns, blast-radius analysis, and CI integration that actually holds up in production.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-rotate-leaked-secrets-automation-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-rotate-leaked-secrets-automation-2026</guid>
      <pubDate>Tue, 10 Mar 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SSRF Attacks: How Server-Side Request Forgery Works]]></title>
      <description><![CDATA[SSRF tricks a server into making requests an attacker controls — reaching internal services, cloud metadata endpoints, and data no external user should touch. Here is how it works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/ssrf-attacks-server-side-request-forgery</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ssrf-attacks-server-side-request-forgery</guid>
      <pubDate>Tue, 10 Mar 2026 07:41:26 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is GraphQL Security]]></title>
      <description><![CDATA[GraphQL's flexibility creates unique risks—excessive data exposure, DoS via nested queries, and broken field-level authorization. Here's how to defend it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-graphql-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-graphql-security</guid>
      <pubDate>Tue, 10 Mar 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[CVE Vulnerabilities Explained: How the CVE System Works]]></title>
      <description><![CDATA[What a CVE vulnerability actually is, who assigns the IDs, how CVSS scoring and the KEV catalog fit in, and why a CVE number is a label, not a verdict.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-vulnerabilities-explained-how-cve-works</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-vulnerabilities-explained-how-cve-works</guid>
      <pubDate>Tue, 10 Mar 2026 06:20:59 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 certification cost breakdown]]></title>
      <description><![CDATA[A full breakdown of ISO 27001 certification costs in 2026 — audit fees, compliance software pricing like Secureframe, hidden labor costs, and what drives the total.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-certification-cost-breakdown</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-certification-cost-breakdown</guid>
      <pubDate>Tue, 10 Mar 2026 06:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Password Security Storage: Hashing Done Right]]></title>
      <description><![CDATA[Password security storage still gets built wrong in 2024 — here's what a correct implementation looks like, from algorithm choice to salt handling to migration.]]></description>
      <link>https://safeguard.sh/resources/blog/password-security-storage-hashing-done-right</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/password-security-storage-hashing-done-right</guid>
      <pubDate>Tue, 10 Mar 2026 05:00:32 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[OWASP API Security Top 10 Explained]]></title>
      <description><![CDATA[The 2023 OWASP API Security Top 10 explained with real breaches — T-Mobile, Optus, Peloton — plus what changed since 2019 and how to prioritize fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-api-security-top-10-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-api-security-top-10-explained</guid>
      <pubDate>Tue, 10 Mar 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[LastPass 2022-2023: A Retrospective at Depth]]></title>
      <description><![CDATA[A detailed walk through the two LastPass breaches of 2022 and their long 2023 tail, reconstructing how a developer laptop became a vault disclosure.]]></description>
      <link>https://safeguard.sh/resources/blog/lastpass-2022-2023-retrospective-depth</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lastpass-2022-2023-retrospective-depth</guid>
      <pubDate>Tue, 10 Mar 2026 03:40:06 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 risk assessment: how to conduct one]]></title>
      <description><![CDATA[A practical walkthrough of how to run an ISO 27001 risk assessment—scoping, scoring, Annex A mapping, and why supply chain controls need real evidence, not questionnaires.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-risk-assessment-how-to-conduct-one</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-risk-assessment-how-to-conduct-one</guid>
      <pubDate>Tue, 10 Mar 2026 03:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Service Mesh Policy Depth]]></title>
      <description><![CDATA[Service meshes promise layered policy. The promise is real, but the layers only help if you use them, and most deployments use one.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-service-mesh-policy-depth</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-service-mesh-policy-depth</guid>
      <pubDate>Tue, 10 Mar 2026 02:19:39 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[API Security Misconfiguration]]></title>
      <description><![CDATA[API misconfigurations exposed 37M T-Mobile and 9.8M Optus accounts without a single exploit. Here's why it keeps happening and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-misconfiguration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-misconfiguration</guid>
      <pubDate>Tue, 10 Mar 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Intelligence Platforms Compared for Supply Chain Security]]></title>
      <description><![CDATA[Vulnerability intelligence platforms aggregate, enrich, and prioritize vulnerability data. This comparison examines how leading platforms handle supply chain-specific intelligence needs.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-intelligence-platform-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-intelligence-platform-comparison</guid>
      <pubDate>Tue, 10 Mar 2026 00:59:12 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-29849 Veeam Auth Bypass Analysis]]></title>
      <description><![CDATA[CVE-2024-29849 is a CVSS 9.8 auth bypass in Veeam Backup Enterprise Manager. Root cause, exploitation, detection, and patching guidance.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-29849-veeam-auth-bypass-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-29849-veeam-auth-bypass-analysis</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA vs GDPR key differences]]></title>
      <description><![CDATA[HIPAA and GDPR differ in scope, breach timelines, and enforcement. We break down both laws and where compliance automation and supply chain security tools each fit.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-vs-gdpr-key-differences</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-vs-gdpr-key-differences</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[State of AI Security in Enterprise 2026]]></title>
      <description><![CDATA[Where enterprise AI security actually stands in 2026: model supply chain risks, agent threats, governance gaps, and the controls that measurably reduce exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-ai-security-in-enterprise-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-ai-security-in-enterprise-2026</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[INC Ransom: Inside the Group Targeting Healthcare Infrastructure]]></title>
      <description><![CDATA[INC Ransom has made healthcare a primary target, exploiting the sector's unique vulnerabilities and urgency. A deep dive into their operations and what healthcare security teams should prioritize.]]></description>
      <link>https://safeguard.sh/resources/blog/inc-ransom-group-healthcare-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/inc-ransom-group-healthcare-attacks</guid>
      <pubDate>Mon, 09 Mar 2026 23:38:45 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain IoC Catalog]]></title>
      <description><![CDATA[A practical catalog of indicators of compromise for software supply chain attacks, with detection queries and false-positive notes.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-indicator-of-compromise-catalog</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-indicator-of-compromise-catalog</guid>
      <pubDate>Mon, 09 Mar 2026 22:18:19 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[PCI DSS Meets SBOM Requirements]]></title>
      <description><![CDATA[PCI DSS v4.0.1 doesn't say the word SBOM, but its software inventory and vulnerability management requirements make one effectively mandatory. Here's how to build an SBOM program that passes a QSA review.]]></description>
      <link>https://safeguard.sh/resources/blog/pci-dss-meets-sbom-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pci-dss-meets-sbom-requirements</guid>
      <pubDate>Mon, 09 Mar 2026 20:57:52 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Validate SLSA Provenance in CI]]></title>
      <description><![CDATA[Generate and validate SLSA v1.0 provenance attestations in GitHub Actions using slsa-verifier, gate releases on builder identity, and prove build integrity.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-validate-slsa-provenance-in-ci</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-validate-slsa-provenance-in-ci</guid>
      <pubDate>Mon, 09 Mar 2026 19:37:25 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Ivanti Cloud Services Appliance CVE-2024-8963: Chained Exploitation]]></title>
      <description><![CDATA[Ivanti's Cloud Services Appliance faced chained zero-day exploitation in September 2024, with attackers combining path traversal and command injection for unauthenticated RCE.]]></description>
      <link>https://safeguard.sh/resources/blog/ivanti-csa-cve-2024-8963-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ivanti-csa-cve-2024-8963-exploitation</guid>
      <pubDate>Mon, 09 Mar 2026 18:16:59 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Rust Feature Flags: Supply Chain Implications]]></title>
      <description><![CDATA[Cargo feature flags look like a compilation convenience but they are a load-bearing piece of your supply chain posture. Here is why.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-feature-flags-supply-chain-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-feature-flags-supply-chain-implications</guid>
      <pubDate>Mon, 09 Mar 2026 16:56:32 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AI Acceleration and Security: What Faster AI Means for Your Threat Model]]></title>
      <description><![CDATA[AI acceleration is compressing both software delivery and attacker tradecraft. A security look at what changes when AI speeds up your pipeline and theirs.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-acceleration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-acceleration</guid>
      <pubDate>Mon, 09 Mar 2026 15:40:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Healthtech FDA Software Supply Chain Guidance]]></title>
      <description><![CDATA[The FDA's cybersecurity guidance has quietly turned into one of the most consequential supply chain regulations in US software. A walkthrough for engineering teams shipping connected medical products.]]></description>
      <link>https://safeguard.sh/resources/blog/healthtech-fda-software-supply-chain-guidance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/healthtech-fda-software-supply-chain-guidance</guid>
      <pubDate>Mon, 09 Mar 2026 15:36:05 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GitLab Pipeline Execution Vulnerability CVE-2024-6678: Running Pipelines as Any User]]></title>
      <description><![CDATA[CVE-2024-6678 allowed attackers to trigger GitLab CI/CD pipelines as arbitrary users, potentially accessing secrets and deploying malicious code through impersonated pipeline runs.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-pipeline-execution-cve-2024-6678</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-pipeline-execution-cve-2024-6678</guid>
      <pubDate>Mon, 09 Mar 2026 14:15:39 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to Improve Security for Docker Containers]]></title>
      <description><![CDATA[Practical security for Docker containers: minimal base images, non-root users, image scanning, and runtime hardening you can apply to any Dockerfile today.]]></description>
      <link>https://safeguard.sh/resources/blog/security-for-docker-containers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-for-docker-containers</guid>
      <pubDate>Mon, 09 Mar 2026 14:05:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[The GNU General Public License, Explained in Plain Terms]]></title>
      <description><![CDATA[A GPL license explained without legal jargon: what copyleft actually requires, when it triggers, and what it means for a codebase that links against GPL-licensed code.]]></description>
      <link>https://safeguard.sh/resources/blog/gnu-general-public-license-explained-plain-terms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gnu-general-public-license-explained-plain-terms</guid>
      <pubDate>Mon, 09 Mar 2026 12:55:12 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[EO 14028 Attestation Pipeline]]></title>
      <description><![CDATA[Executive Order 14028 attestations are now standard for federal software vendors. Build a pipeline that produces SSDF-aligned evidence on every release.]]></description>
      <link>https://safeguard.sh/resources/blog/executive-order-14028-attestation-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/executive-order-14028-attestation-pipeline</guid>
      <pubDate>Mon, 09 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[FTC Data Broker Rule And Supply Chain Overlap]]></title>
      <description><![CDATA[A senior engineer's view of how FTC data broker rulemaking through 2025 and 2026 intersects with software supply chain expectations for organizations handling personal data.]]></description>
      <link>https://safeguard.sh/resources/blog/ftc-data-broker-rule-software-supply-chain-overlap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ftc-data-broker-rule-software-supply-chain-overlap</guid>
      <pubDate>Mon, 09 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Training Data Provenance: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Training data is a supply chain component. Knowing what went into a model is the precondition for knowing what could come out of it. Few tools track this; the few that do matter disproportionately.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-training-data-provenance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-training-data-provenance</guid>
      <pubDate>Mon, 09 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Remediation Prioritisation With Reachability And EPSS]]></title>
      <description><![CDATA[CVSS alone is a bad prioritisation signal in 2026. Reachability plus EPSS gives teams a defensible order to fix the vulnerabilities that actually matter.]]></description>
      <link>https://safeguard.sh/resources/blog/remediation-prioritisation-with-reachability-and-epss</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/remediation-prioritisation-with-reachability-and-epss</guid>
      <pubDate>Mon, 09 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Cross-Vendor Normalisation: Enterprise Program]]></title>
      <description><![CDATA[Vendor SBOMs arrive in every shape and size. Without disciplined normalisation, your ingest store is a junk drawer. Here is how mature programmes solve it.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-cross-vendor-normalisation-enterprise-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-cross-vendor-normalisation-enterprise-program</guid>
      <pubDate>Mon, 09 Mar 2026 12:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SecOps Budget Justification: Supply Chain Program]]></title>
      <description><![CDATA[Supply chain SecOps budgets get cut because the case is told as fear instead of math. Here is a budget justification that survives a finance review.]]></description>
      <link>https://safeguard.sh/resources/blog/secops-budget-justification-supply-chain-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secops-budget-justification-supply-chain-program</guid>
      <pubDate>Mon, 09 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Service Mesh Supply Chain Policy 2026]]></title>
      <description><![CDATA[Service meshes are a control plane and a data plane and a supply chain risk surface all at once. This post covers the policy controls that matter in 2026 for sidecars, control planes, and mesh-issued certificates.]]></description>
      <link>https://safeguard.sh/resources/blog/service-mesh-supply-chain-policy-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/service-mesh-supply-chain-policy-2026</guid>
      <pubDate>Mon, 09 Mar 2026 12:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Node.js License: What Actually Applies to Your App]]></title>
      <description><![CDATA[Node.js itself ships under a permissive MIT-style license, but your app's real license exposure comes from the hundreds of npm packages riding along with it.]]></description>
      <link>https://safeguard.sh/resources/blog/node-js-license-what-applies-to-your-app</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/node-js-license-what-applies-to-your-app</guid>
      <pubDate>Mon, 09 Mar 2026 11:34:45 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Software Container Compliance: Meeting Standards Without Slowing Releases]]></title>
      <description><![CDATA[Container compliance means proving your images and runtime meet the controls auditors ask for, continuously, without turning every deploy into a manual review.]]></description>
      <link>https://safeguard.sh/resources/blog/software-container-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-container-compliance</guid>
      <pubDate>Mon, 09 Mar 2026 10:15:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Legal Risk Assessment Template 2026]]></title>
      <description><![CDATA[A working template for legal and security teams to assess software supply chain risk against contractual, regulatory, and licensing exposure in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-legal-risk-assessment-template-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-legal-risk-assessment-template-2026</guid>
      <pubDate>Mon, 09 Mar 2026 10:15:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[FluxCD Security Model in Production]]></title>
      <description><![CDATA[A production-focused look at FluxCD's security model, covering multi-tenancy isolation, source verification, image automation risks, and the CVE history behind the current defaults.]]></description>
      <link>https://safeguard.sh/resources/blog/fluxcd-security-model-production</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fluxcd-security-model-production</guid>
      <pubDate>Mon, 09 Mar 2026 10:14:19 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Mitigating npm Install Scripts Without Breaking Your Build]]></title>
      <description><![CDATA[`--ignore-scripts` is the blunt fix that breaks node-sass and better-sqlite3. Here is the surgical version that keeps builds green and postinstalls contained.]]></description>
      <link>https://safeguard.sh/resources/blog/mitigate-npm-install-scripts-without-breaking-builds</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mitigate-npm-install-scripts-without-breaking-builds</guid>
      <pubDate>Mon, 09 Mar 2026 10:00:00 GMT</pubDate>
      <category>Dependency Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard vs Wiz: Supply Chain Focus 2026]]></title>
      <description><![CDATA[How Safeguard and Wiz compare in 2026 for software supply chain security, SCA depth, container provenance, and autonomous remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-vs-wiz-supply-chain-focus-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-vs-wiz-supply-chain-focus-2026</guid>
      <pubDate>Mon, 09 Mar 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Unsafe Consumption of APIs]]></title>
      <description><![CDATA[OWASP's API10:2023 exposes a blind spot: teams sanitize user input but blindly trust API responses from partners, vendors, and internal services.]]></description>
      <link>https://safeguard.sh/resources/blog/unsafe-consumption-of-apis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unsafe-consumption-of-apis</guid>
      <pubDate>Mon, 09 Mar 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Securing Docker Containers: A Practical Hardening Guide]]></title>
      <description><![CDATA[Securing Docker containers is less about one setting and more about a chain of defaults: slim base images, non-root users, scanned layers, and locked-down runtime privileges.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-docker-containers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-docker-containers</guid>
      <pubDate>Mon, 09 Mar 2026 09:15:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 vs GDPR: differences and overlap mapping]]></title>
      <description><![CDATA[SOC 2 and GDPR overlap but aren't the same. Here's how the two frameworks differ, where evidence maps across both, and how Safeguard compares to Sprinto.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-vs-gdpr-differences-and-overlap-mapping</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-vs-gdpr-differences-and-overlap-mapping</guid>
      <pubDate>Mon, 09 Mar 2026 09:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security for Healthcare (HIPAA) 2026]]></title>
      <description><![CDATA[Software supply chain security for healthcare in 2026 means the new HIPAA Security Rule, 405(d) practices, and FDA postmarket expectations converging on SBOM.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-healthcare-hipaa-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-healthcare-hipaa-2026</guid>
      <pubDate>Mon, 09 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vendor Offboarding and Supply Chain Data Destruction]]></title>
      <description><![CDATA[A practical playbook for offboarding software vendors and ensuring data is actually destroyed, not just promised to be destroyed, across complex subprocessor chains.]]></description>
      <link>https://safeguard.sh/resources/blog/vendor-offboarding-supply-chain-data-destruction</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vendor-offboarding-supply-chain-data-destruction</guid>
      <pubDate>Mon, 09 Mar 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is OpenID Connect (OIDC)]]></title>
      <description><![CDATA[OpenID Connect adds a real identity layer on top of OAuth 2.0. Learn how it proves who a user is, what an ID token contains, and how it differs from plain OAuth.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-openid-connect-oidc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-openid-connect-oidc</guid>
      <pubDate>Mon, 09 Mar 2026 08:53:52 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Does a Product Security Engineer Actually Do?]]></title>
      <description><![CDATA[Product security engineer isn't just AppSec with a different title — it's the role that owns security decisions inside the product itself, not just the pipeline that ships it.]]></description>
      <link>https://safeguard.sh/resources/blog/product-security-engineer-role-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/product-security-engineer-role-explained</guid>
      <pubDate>Mon, 09 Mar 2026 08:00:00 GMT</pubDate>
      <category>Culture</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Vulnerability Protection: A Checklist]]></title>
      <description><![CDATA[A working checklist for supply chain vulnerability protection, from dependency inventory through SBOM generation and continuous re-scanning, built for teams shipping today.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-vulnerability-protection-a-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-vulnerability-protection-a-checklist</guid>
      <pubDate>Mon, 09 Mar 2026 08:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Jenkins + Maven Integration Security]]></title>
      <description><![CDATA[Jenkins is still the most common Maven build driver in enterprise Java shops. It is also where most supply chain incidents start. Here is what to change before it becomes your problem.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-maven-integration-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-maven-integration-security</guid>
      <pubDate>Mon, 09 Mar 2026 07:33:25 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Broken Object Level Authorization (BOLA)]]></title>
      <description><![CDATA[BOLA lets attackers swap an object ID in an API request to pull someone else's data. Here's how it works, real breaches, and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-broken-object-level-authorization-bola</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-broken-object-level-authorization-bola</guid>
      <pubDate>Mon, 09 Mar 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Python Package Typosquatting in 2024: Scale, Tactics, and Defenses]]></title>
      <description><![CDATA[Typosquatting on PyPI reached industrial scale in 2024, with attackers using automated tooling to register thousands of malicious package names targeting common misspellings of popular libraries.]]></description>
      <link>https://safeguard.sh/resources/blog/python-package-typosquatting-2024-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-package-typosquatting-2024-report</guid>
      <pubDate>Mon, 09 Mar 2026 06:12:58 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Sprinto vs Vanta comparison]]></title>
      <description><![CDATA[Sprinto and Vanta compared for SOC 2 automation -- and why software supply chain security (SBOMs, CVE risk) is the piece both leave to a separate tool.]]></description>
      <link>https://safeguard.sh/resources/blog/sprinto-vs-vanta-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sprinto-vs-vanta-comparison</guid>
      <pubDate>Mon, 09 Mar 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Office Document Macro Security: The Attack Vector That Will Not Die]]></title>
      <description><![CDATA[Microsoft disabled macros by default in 2022. Attackers adapted. The macro threat has evolved, not disappeared.]]></description>
      <link>https://safeguard.sh/resources/blog/office-document-macro-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/office-document-macro-security</guid>
      <pubDate>Mon, 09 Mar 2026 04:52:32 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is an API Gateway and Its Security Role]]></title>
      <description><![CDATA[An API gateway centralizes auth, routing, and rate limiting for every request — get it wrong and, as T-Mobile and Optus learned, millions of records leak.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-an-api-gateway-and-its-security-role</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-an-api-gateway-and-its-security-role</guid>
      <pubDate>Mon, 09 Mar 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Datadog Security for Supply Chain Monitoring]]></title>
      <description><![CDATA[Using Datadog's Cloud SIEM, ASM, and logs pipeline to monitor software supply chain threats across CI/CD, registries, and runtime.]]></description>
      <link>https://safeguard.sh/resources/blog/datadog-security-supply-chain-monitoring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/datadog-security-supply-chain-monitoring</guid>
      <pubDate>Mon, 09 Mar 2026 03:32:05 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Sprinto vs Delve comparison]]></title>
      <description><![CDATA[Sprinto and Delve automate compliance evidence for SOC 2 and ISO 27001 — but neither scans dependencies or verifies build provenance. Here's the gap and where Safeguard fits.]]></description>
      <link>https://safeguard.sh/resources/blog/sprinto-vs-delve-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sprinto-vs-delve-comparison</guid>
      <pubDate>Mon, 09 Mar 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Migrating to npm Granular Access Tokens]]></title>
      <description><![CDATA[Granular access tokens have been GA for over a year. Here is the migration playbook that has worked for me across four organizations, including the gotchas nobody writes down.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-granular-access-tokens-migration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-granular-access-tokens-migration</guid>
      <pubDate>Mon, 09 Mar 2026 02:11:38 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Rate Limiting]]></title>
      <description><![CDATA[Rate limiting caps requests per client to stop credential stuffing and scraping. Learn how it works, the algorithms, and real breaches it prevents.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-rate-limiting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-rate-limiting</guid>
      <pubDate>Mon, 09 Mar 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[.NET Source Generator Security Risks]]></title>
      <description><![CDATA[Source generators are C# code that executes during compilation with developer privileges. The .NET equivalent of Rust's proc macros — and the same underexamined attack surface.]]></description>
      <link>https://safeguard.sh/resources/blog/dotnet-source-generator-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dotnet-source-generator-security-risks</guid>
      <pubDate>Mon, 09 Mar 2026 00:51:12 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Sprinto vs OneLeet comparison]]></title>
      <description><![CDATA[Sprinto and OneLeet automate compliance evidence, but neither scans dependencies or ships an SBOM -- the gap Safeguard closes for supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/sprinto-vs-oneleet-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sprinto-vs-oneleet-comparison</guid>
      <pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Cisco ASA Firepower Zero-Day Trends, 2024 Edition]]></title>
      <description><![CDATA[Six zero-days against ASA and FTD in 2024, two tied to ArcaneDoor. We chart the trend, the CVSS distribution, and the patch-to-exploit gap.]]></description>
      <link>https://safeguard.sh/resources/blog/cisco-asa-firepower-zero-day-trends-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisco-asa-firepower-zero-day-trends-2024</guid>
      <pubDate>Sun, 08 Mar 2026 23:30:45 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Cross-Platform App Supply Chain Risks You Cannot Ignore]]></title>
      <description><![CDATA[Cross-platform frameworks multiply supply chain attack surfaces by combining multiple dependency ecosystems. Understanding these compounded risks is essential for modern mobile and desktop security.]]></description>
      <link>https://safeguard.sh/resources/blog/cross-platform-app-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cross-platform-app-supply-chain-risks</guid>
      <pubDate>Sun, 08 Mar 2026 22:10:18 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection: How It Works and How It's Actually Tested]]></title>
      <description><![CDATA[A defender's walkthrough of how SQL injection works and how security testers actually verify it in a controlled, authorized assessment — not a how-to-attack guide.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-how-it-works-and-how-its-tested</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-how-it-works-and-how-its-tested</guid>
      <pubDate>Sun, 08 Mar 2026 20:49:52 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[A CSRF Example: Full Attack Walkthrough]]></title>
      <description><![CDATA[A concrete csrf example — a bank transfer form with no anti-forgery token — showing exactly how a forged request rides in on a victim's session and what stops it.]]></description>
      <link>https://safeguard.sh/resources/blog/csrf-example-a-walkthrough</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/csrf-example-a-walkthrough</guid>
      <pubDate>Sun, 08 Mar 2026 19:29:25 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[North Korean Threat Actors Flood npm with Malicious Packages]]></title>
      <description><![CDATA[In 2024, DPRK-linked groups dramatically escalated their campaign to compromise developers through malicious npm packages, using fake job offers and typosquatting to deploy infostealers and backdoors.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-malicious-packages-north-korea-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-malicious-packages-north-korea-2024</guid>
      <pubDate>Sun, 08 Mar 2026 18:08:58 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Trusted Publishing: An Adoption Guide]]></title>
      <description><![CDATA[Trusted Publishing replaces long-lived PyPI tokens with OIDC-issued short-lived credentials. A practical guide to adoption, pitfalls, and what it changes for your threat model.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-trusted-publishing-adoption-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-trusted-publishing-adoption-guide</guid>
      <pubDate>Sun, 08 Mar 2026 16:48:32 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The MIT License, Meaning in Plain English]]></title>
      <description><![CDATA[The MIT license meaning, stripped of legalese: do almost anything you want with the code, keep the copyright notice, and the author owes you nothing if it breaks.]]></description>
      <link>https://safeguard.sh/resources/blog/mit-license-meaning-in-plain-english</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mit-license-meaning-in-plain-english</guid>
      <pubDate>Sun, 08 Mar 2026 15:28:05 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SLSA Builder Requirements in Production]]></title>
      <description><![CDATA[The SLSA specification sets explicit requirements for builders at each level. Here is what those requirements actually mean when you operate a builder in production.]]></description>
      <link>https://safeguard.sh/resources/blog/slsa-builder-requirements-production</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slsa-builder-requirements-production</guid>
      <pubDate>Sun, 08 Mar 2026 14:07:38 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Please Build System Security Review]]></title>
      <description><![CDATA[A hands-on security review of Please, the open-source Bazel-inspired build system, including sandbox behavior, BUILD rules, and supply chain trade-offs.]]></description>
      <link>https://safeguard.sh/resources/blog/please-build-system-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/please-build-system-security-review</guid>
      <pubDate>Sun, 08 Mar 2026 12:47:11 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cost Per Finding: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Token spend per scan is the wrong metric. Cost per actionable finding is the right one — and it&apos;s where engine-plus-LLM economics dominate pure-LLM economics.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cost-per-finding</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cost-per-finding</guid>
      <pubDate>Sun, 08 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Confusion: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Dependency confusion is older than most of the AI tooling trying to detect it. The attacks have adapted to the defences — detection needs to keep up.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-dependency-confusion-scenarios</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-dependency-confusion-scenarios</guid>
      <pubDate>Sun, 08 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Poolside for Enterprise Security]]></title>
      <description><![CDATA[Poolside's on-prem code AI is a credible enterprise offering. For security-specific workflows, Griffin AI's grounding architecture targets different ground.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-poolside-for-enterprise-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-poolside-for-enterprise-security</guid>
      <pubDate>Sun, 08 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[JSR JavaScript Registry Security Model]]></title>
      <description><![CDATA[JSR reimagines JavaScript package distribution with mandatory signing, scoped namespaces, and provenance by default. Here is how the security model works.]]></description>
      <link>https://safeguard.sh/resources/blog/jsr-javascript-registry-security-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jsr-javascript-registry-security-model</guid>
      <pubDate>Sun, 08 Mar 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MCP Authentication Patterns for Enterprise]]></title>
      <description><![CDATA[Enterprise MCP deployments need more than a static API key. The protocol is evolving toward OAuth 2.1 and dynamic client registration, and understanding which pattern fits which workload decides whether your rollout survives the first audit.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-authentication-patterns-enterprise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-authentication-patterns-enterprise</guid>
      <pubDate>Sun, 08 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Legacy COBOL Supply Chain Modernization: A Pragmatic Playbook]]></title>
      <description><![CDATA[Modernize the supply chain around COBOL systems without rewriting them. Build provenance, SBOMs, and policy gates for mainframe code that is not going anywhere.]]></description>
      <link>https://safeguard.sh/resources/blog/legacy-cobol-supply-chain-modernization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/legacy-cobol-supply-chain-modernization</guid>
      <pubDate>Sun, 08 Mar 2026 11:26:45 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Labyrinth Chollima and Open Source Targeting]]></title>
      <description><![CDATA[Labyrinth Chollima's operations show a specific pattern — poisoned open source packages as initial access. A profile of the tradecraft and the defensive response.]]></description>
      <link>https://safeguard.sh/resources/blog/labyrinth-chollima-open-source-targeting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/labyrinth-chollima-open-source-targeting</guid>
      <pubDate>Sun, 08 Mar 2026 10:06:18 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Snowflake Customer Breaches 2024: Root Cause]]></title>
      <description><![CDATA[The Snowflake customer breaches of 2024 were not a Snowflake compromise. Infostealer logs, shared credentials, and absent MFA did the damage, from Ticketmaster to AT&T.]]></description>
      <link>https://safeguard.sh/resources/blog/snowflake-customer-breaches-2024-root-cause</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snowflake-customer-breaches-2024-root-cause</guid>
      <pubDate>Sun, 08 Mar 2026 10:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is API Authentication]]></title>
      <description><![CDATA[API authentication verifies who's calling your API before authorization decides what they can do — here's how it works, common methods, and where it fails.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-api-authentication</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-api-authentication</guid>
      <pubDate>Sun, 08 Mar 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Software Signing and Code Integrity in 2026: The Practical State of Play]]></title>
      <description><![CDATA[Where software signing stands today, what Sigstore and friends changed, and why most organizations still ship unsigned artifacts.]]></description>
      <link>https://safeguard.sh/resources/blog/software-signing-code-integrity-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-signing-code-integrity-2026</guid>
      <pubDate>Sun, 08 Mar 2026 09:00:00 GMT</pubDate>
      <category>Industry Trends</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Sprinto vs Strike Graph comparison]]></title>
      <description><![CDATA[A buyer's guide comparing Sprinto and Strike Graph as compliance automation tools, and where software supply chain security like Safeguard fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/sprinto-vs-strike-graph-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sprinto-vs-strike-graph-comparison</guid>
      <pubDate>Sun, 08 Mar 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[CCPA Meets Software Supply Chain]]></title>
      <description><![CDATA[CCPA and CPRA are mostly about data rights, but the reasonable-security provisions and service-provider obligations reach deep into software supply chain practice. Here's how the two connect.]]></description>
      <link>https://safeguard.sh/resources/blog/ccpa-meets-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ccpa-meets-software-supply-chain</guid>
      <pubDate>Sun, 08 Mar 2026 08:45:51 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Build Server Compromise Investigation]]></title>
      <description><![CDATA[A hands-on investigation guide for compromised build servers, from initial containment through rootkit checks and clean rebuild.]]></description>
      <link>https://safeguard.sh/resources/blog/build-server-compromise-investigation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/build-server-compromise-investigation</guid>
      <pubDate>Sun, 08 Mar 2026 07:25:25 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[OAuth vs API Keys]]></title>
      <description><![CDATA[OAuth and API keys aren't interchangeable: one is a static, long-lived credential, the other a scoped, expiring token. Here's how to choose, backed by real breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/oauth-vs-api-keys</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oauth-vs-api-keys</guid>
      <pubDate>Sun, 08 Mar 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[A Framework for Security Patch Prioritization]]></title>
      <description><![CDATA[You cannot patch everything immediately. Here is a risk-based framework for deciding which patches to apply first when your vulnerability backlog exceeds your capacity.]]></description>
      <link>https://safeguard.sh/resources/blog/security-patch-prioritization-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-patch-prioritization-framework</guid>
      <pubDate>Sun, 08 Mar 2026 06:04:58 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Sprinto vs AuditBoard comparison]]></title>
      <description><![CDATA[Sprinto and AuditBoard both automate compliance workflows, but neither proves what's in your software. Here's where Safeguard's supply chain focus fits.]]></description>
      <link>https://safeguard.sh/resources/blog/sprinto-vs-auditboard-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sprinto-vs-auditboard-comparison</guid>
      <pubDate>Sun, 08 Mar 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[UK NCSC Software Supply Chain Guidance Update]]></title>
      <description><![CDATA[The UK NCSC expanded its supply chain guidance in 2023-2024, aligning with the Cyber Security and Resilience Bill and pushing SBOMs, vendor assurance, and provenance controls.]]></description>
      <link>https://safeguard.sh/resources/blog/uk-ncsc-software-supply-chain-guidance-update</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uk-ncsc-software-supply-chain-guidance-update</guid>
      <pubDate>Sun, 08 Mar 2026 04:44:31 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is CI/CD Pipeline Security]]></title>
      <description><![CDATA[CI/CD pipeline security explained: how SolarWinds, Codecov, CircleCI, and tj-actions were breached, and concrete steps to lock down your build pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-cicd-pipeline-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-cicd-pipeline-security</guid>
      <pubDate>Sun, 08 Mar 2026 04:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems Typosquatting Incidents: 2024]]></title>
      <description><![CDATA[A running ledger of typosquat incidents on RubyGems.org through 2024, the patterns across them, and what the year's data says about where the registry's defenses still fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-typosquatting-incidents-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-typosquatting-incidents-2024</guid>
      <pubDate>Sun, 08 Mar 2026 03:24:05 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Three-way GRC platform comparisons (Sprinto/Vanta/Drata, ...]]></title>
      <description><![CDATA[Sprinto, Vanta, and Drata compete on compliance automation—not software supply chain security. Here's how to compare them, and where Safeguard fits underneath all three.]]></description>
      <link>https://safeguard.sh/resources/blog/three-way-grc-platform-comparisons-sprintovantadrata-sprintovantascrut-etc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/three-way-grc-platform-comparisons-sprintovantadrata-sprintovantascrut-etc</guid>
      <pubDate>Sun, 08 Mar 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[CyberArk Conjur for Enterprise Secrets Management]]></title>
      <description><![CDATA[Where Conjur fits in 2024 for enterprise secrets management, what it does well, where it hurts, and how to roll it out without drowning the platform team.]]></description>
      <link>https://safeguard.sh/resources/blog/conjur-secrets-management-enterprise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/conjur-secrets-management-enterprise</guid>
      <pubDate>Sun, 08 Mar 2026 02:03:38 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Continuous Security]]></title>
      <description><![CDATA[Continuous security scans code, dependencies, containers, and infra on every commit — not once a quarter. Here's how it works and why it replaced periodic audits.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-continuous-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-continuous-security</guid>
      <pubDate>Sun, 08 Mar 2026 01:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Azure Bicep vs ARM: Security Comparison]]></title>
      <description><![CDATA[Bicep and ARM templates produce the same deployments, but their security properties diverge — in module provenance, what-if analysis, registry trust, and review experience.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-bicep-vs-arm-security-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-bicep-vs-arm-security-comparison</guid>
      <pubDate>Sun, 08 Mar 2026 00:43:11 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[OneTrust alternatives]]></title>
      <description><![CDATA[OneTrust alternative? Sprinto automates GRC evidence; Safeguard secures your software supply chain with SBOMs, dependency scanning, and build provenance.]]></description>
      <link>https://safeguard.sh/resources/blog/onetrust-alternatives</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/onetrust-alternatives</guid>
      <pubDate>Sun, 08 Mar 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[A Beginner's Guide to Threat Modeling Your Build Pipeline]]></title>
      <description><![CDATA[Your CI system is a production system with worse access controls. A first threat model of the pipeline takes one whiteboard session and usually finds something ugly.]]></description>
      <link>https://safeguard.sh/resources/blog/a-beginner-s-guide-to-threat-modeling-your-build-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/a-beginner-s-guide-to-threat-modeling-your-build-pipeline</guid>
      <pubDate>Sat, 07 Mar 2026 23:22:45 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Jonas Meyer)</author>
    </item>
    <item>
      <title><![CDATA[Static Analysis False-Positive Reduction]]></title>
      <description><![CDATA[A technique-by-technique tour of how modern static analyzers cut false positives, from CodeQL's path pruning to Infer's bi-abduction.]]></description>
      <link>https://safeguard.sh/resources/blog/static-analysis-false-positive-reduction-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-analysis-false-positive-reduction-techniques</guid>
      <pubDate>Sat, 07 Mar 2026 22:02:18 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Rust Tokio Dependency Security Review]]></title>
      <description><![CDATA[Tokio is the async runtime underneath most production Rust. A supply chain review of Tokio and the crates that orbit it — dependencies, CVE history, and what changes across versions.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-tokio-dependency-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-tokio-dependency-security-review</guid>
      <pubDate>Sat, 07 Mar 2026 20:41:51 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CRI-O vs containerd: Security Comparison]]></title>
      <description><![CDATA[Both are CNCF graduated runtimes. Both run production clusters. Their security properties diverge in ways that matter for hardened environments.]]></description>
      <link>https://safeguard.sh/resources/blog/cri-o-vs-containerd-security-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cri-o-vs-containerd-security-comparison</guid>
      <pubDate>Sat, 07 Mar 2026 19:21:24 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SonicWall SSL VPN CVE-2024-40766: Ransomware's Favorite Front Door]]></title>
      <description><![CDATA[CVE-2024-40766 in SonicWall SonicOS became an immediate target for Akira and Fog ransomware groups, highlighting the ongoing risk of VPN appliance vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/sonicwall-sslvpn-cve-2024-40766</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonicwall-sslvpn-cve-2024-40766</guid>
      <pubDate>Sat, 07 Mar 2026 18:00:58 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Zig's Memory Safety Model: A Security Analysis for Systems Programmers]]></title>
      <description><![CDATA[Zig offers memory safety features that C lacks but does not go as far as Rust. For security-critical code, understanding where Zig sits on the safety spectrum matters.]]></description>
      <link>https://safeguard.sh/resources/blog/zig-language-memory-safety-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zig-language-memory-safety-security</guid>
      <pubDate>Sat, 07 Mar 2026 16:40:31 GMT</pubDate>
      <category>Language Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[XSS Scripting Attacks: A Refresher for Engineers]]></title>
      <description><![CDATA[XSS scripting attacks still make the OWASP Top 10 more than two decades after they were first documented, mostly because the fix is context-dependent and easy to get almost-right.]]></description>
      <link>https://safeguard.sh/resources/blog/xss-scripting-attacks-a-refresher</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xss-scripting-attacks-a-refresher</guid>
      <pubDate>Sat, 07 Mar 2026 15:20:04 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What Is Dependency Injection? (And What It Means for Security)]]></title>
      <description><![CDATA[Dependency injection is a design pattern where objects receive their dependencies from outside rather than creating them. It makes code testable and flexible — and it has real security implications.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-dependency-injection-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-dependency-injection-security</guid>
      <pubDate>Sat, 07 Mar 2026 13:59:38 GMT</pubDate>
      <category>Dev Practices</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Telemedicine Supply Chain Privacy and Security]]></title>
      <description><![CDATA[Telehealth platforms depend on video SDKs, third-party transcription, and mobile frameworks. A regulatory walkthrough for HIPAA-covered virtual care.]]></description>
      <link>https://safeguard.sh/resources/blog/telemedicine-supply-chain-privacy-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/telemedicine-supply-chain-privacy-security</guid>
      <pubDate>Sat, 07 Mar 2026 12:39:11 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise AI Red Team Program Design]]></title>
      <description><![CDATA[AI red teaming is not a one-off exercise. Programmatic red-teaming of AI systems requires specific structure — and most organisations don&apos;t have it yet.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-ai-red-team-program-design</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-ai-red-team-program-design</guid>
      <pubDate>Sat, 07 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Elastic Scale Behaviour: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Scanning bursts when a monorepo merges. We explain why Griffin AI absorbs the spike gracefully while Mythos-class tools degrade into rate-limit queues.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-elastic-scale-behaviour</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-elastic-scale-behaviour</guid>
      <pubDate>Sat, 07 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Open Weights: The Eval Gap]]></title>
      <description><![CDATA[Frontier models pass eval benchmarks that open-weight models miss by specific measurable margins. For security workflows, the gap matters.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-open-weight-eval-gap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-open-weight-eval-gap</guid>
      <pubDate>Sat, 07 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is OAuth]]></title>
      <description><![CDATA[OAuth lets one app access your data in another without ever seeing your password. Learn how delegated access works, what tokens and scopes do, and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-oauth</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-oauth</guid>
      <pubDate>Sat, 07 Mar 2026 11:18:44 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is Shift Left Testing]]></title>
      <description><![CDATA[Shift left testing moves security checks from a pre-release gate into commit, PR, and build time. Here's how it works, what it costs to skip, and its pitfalls.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-shift-left-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-shift-left-testing</guid>
      <pubDate>Sat, 07 Mar 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Incident Response Playbook: Supply Chain Compromise]]></title>
      <description><![CDATA[A step-by-step playbook for responding to upstream dependency, build system, and vendor compromises, including roles, timelines, and stakeholder communications.]]></description>
      <link>https://safeguard.sh/resources/blog/incident-response-playbook-supply-chain-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/incident-response-playbook-supply-chain-compromise</guid>
      <pubDate>Sat, 07 Mar 2026 09:58:18 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Akira Ransomware VPN Appliance Exploitation]]></title>
      <description><![CDATA[Akira has industrialized VPN appliance exploitation. Here is the tradecraft, the advisories that document it, and what defenders must do about edge software supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/akira-ransomware-vpn-appliance-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/akira-ransomware-vpn-appliance-exploitation</guid>
      <pubDate>Sat, 07 Mar 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Drata alternatives]]></title>
      <description><![CDATA[Comparing Drata alternatives? See how Sprinto's compliance automation and Safeguard's supply chain security approach differ, and when you need both.]]></description>
      <link>https://safeguard.sh/resources/blog/drata-alternatives</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/drata-alternatives</guid>
      <pubDate>Sat, 07 Mar 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[OSS Maintainer Account Takeover Trends 2025]]></title>
      <description><![CDATA[A senior engineer's breakdown of how maintainer account takeovers evolved in 2025, from phishing kits targeting PyPI to session token theft on GitHub and npm.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-maintainer-account-takeover-trends-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-maintainer-account-takeover-trends-2025</guid>
      <pubDate>Sat, 07 Mar 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software License Models: A Comparison]]></title>
      <description><![CDATA[Types of software license models split into three broad camps — proprietary, permissive open source, and copyleft — plus the newer source-available middle ground companies keep inventing to protect commercial interests.]]></description>
      <link>https://safeguard.sh/resources/blog/software-license-models-a-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-license-models-a-comparison</guid>
      <pubDate>Sat, 07 Mar 2026 08:37:51 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Full Form and Why It Matters Now]]></title>
      <description><![CDATA[SBOM full form is Software Bill of Materials — a complete inventory of the components in an application. Here's what it actually contains and why it matters today.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-full-form-and-why-it-matters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-full-form-and-why-it-matters</guid>
      <pubDate>Sat, 07 Mar 2026 07:17:24 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Security as Code]]></title>
      <description><![CDATA[Security as code turns policies and controls into version-controlled, pipeline-enforced rules. Here's what it looks like, why it matters, and how to adopt it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-security-as-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-security-as-code</guid>
      <pubDate>Sat, 07 Mar 2026 07:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Anecdotes alternatives and review]]></title>
      <description><![CDATA[Evaluating Anecdotes alternatives such as Sprinto? Here's how compliance automation and software supply chain security actually differ, and why you may need both.]]></description>
      <link>https://safeguard.sh/resources/blog/anecdotes-alternatives-and-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anecdotes-alternatives-and-review</guid>
      <pubDate>Sat, 07 Mar 2026 06:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[OWASP 10 vs OWASP Top 10: Clearing Up the Confusion]]></title>
      <description><![CDATA["OWASP 10" isn't a separate standard — it's shorthand people search for the OWASP Top 10, and the confusion usually starts with which Top 10 they actually mean.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-10-vs-owasp-top-10-clearing-the-confusion</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-10-vs-owasp-top-10-clearing-the-confusion</guid>
      <pubDate>Sat, 07 Mar 2026 05:56:57 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Spinnaker Deployment Security Patterns]]></title>
      <description><![CDATA[Practical security patterns for Spinnaker deployments: account isolation, pipeline template governance, artifact binding, and the CVE history behind the current authentication defaults.]]></description>
      <link>https://safeguard.sh/resources/blog/spinnaker-deployment-security-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spinnaker-deployment-security-patterns</guid>
      <pubDate>Sat, 07 Mar 2026 04:36:31 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is CI/CD Pipeline Poisoning]]></title>
      <description><![CDATA[CI/CD pipeline poisoning lets attackers hijack your build automation to steal secrets and plant backdoors. Here's how it works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-cicd-pipeline-poisoning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-cicd-pipeline-poisoning</guid>
      <pubDate>Sat, 07 Mar 2026 04:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Gradle Version Catalogs Security]]></title>
      <description><![CDATA[Gradle version catalogs centralise dependency versions in one file. The security payoff is concrete: auditability, uniform enforcement, and a single PR gate.]]></description>
      <link>https://safeguard.sh/resources/blog/gradle-version-catalogs-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gradle-version-catalogs-security</guid>
      <pubDate>Sat, 07 Mar 2026 03:16:04 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Tugboat Logic alternatives and review]]></title>
      <description><![CDATA[Tugboat Logic became part of OneTrust in 2021. Here's how compliance automation tools like Sprinto compare to Safeguard's software supply chain security approach.]]></description>
      <link>https://safeguard.sh/resources/blog/tugboat-logic-alternatives-and-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tugboat-logic-alternatives-and-review</guid>
      <pubDate>Sat, 07 Mar 2026 03:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[NuGet Package Vulnerabilities Dashboard]]></title>
      <description><![CDATA[Listing every CVE in your NuGet dependency tree is easy. Turning it into a dashboard someone can act on is the work. A practical design.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-package-vulnerabilities-dashboard</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-package-vulnerabilities-dashboard</guid>
      <pubDate>Sat, 07 Mar 2026 01:55:37 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Artifact Signing]]></title>
      <description><![CDATA[Artifact signing cryptographically verifies who built a software artifact and that it hasn't been tampered with — here's how it works and why it stops supply chain attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-artifact-signing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-artifact-signing</guid>
      <pubDate>Sat, 07 Mar 2026 01:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[New Relic Security: Building a Supply Chain View]]></title>
      <description><![CDATA[How to extend New Relic's APM and Vulnerability Management features into a working software supply chain dashboard for security and platform teams.]]></description>
      <link>https://safeguard.sh/resources/blog/new-relic-security-supply-chain-view</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/new-relic-security-supply-chain-view</guid>
      <pubDate>Sat, 07 Mar 2026 00:35:11 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-1974 Ingress NGINX Controller RCE]]></title>
      <description><![CDATA[IngressNightmare - CVE-2025-1974 in Kubernetes ingress-nginx - gave unauthenticated attackers cluster-wide RCE. Here is how it worked and what to harden now.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2025-1974-ingress-nginx-controller-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2025-1974-ingress-nginx-controller-rce</guid>
      <pubDate>Sat, 07 Mar 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MetricStream alternatives and review]]></title>
      <description><![CDATA[MetricStream is heavyweight enterprise GRC. Sprinto automates compliance workflows. See how Safeguard differs by scanning your actual software supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/metricstream-alternatives-and-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/metricstream-alternatives-and-review</guid>
      <pubDate>Sat, 07 Mar 2026 00:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[The GitHub Dependabot Token Incident: Retrospective]]></title>
      <description><![CDATA[In 2023, attackers used stolen GitHub personal access tokens to push malicious commits masquerading as Dependabot; a short-sharp incident with lasting lessons.]]></description>
      <link>https://safeguard.sh/resources/blog/github-dependabot-token-incident-retrospective</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-dependabot-token-incident-retrospective</guid>
      <pubDate>Fri, 06 Mar 2026 23:14:44 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes 1.31 Security Improvements: What You Need to Know]]></title>
      <description><![CDATA[Kubernetes 1.31 'Elli' shipped in August 2024 with significant security improvements including AppArmor GA support, refined pod security controls, and better secret management.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-1-31-security-improvements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-1-31-security-improvements</guid>
      <pubDate>Fri, 06 Mar 2026 21:54:17 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Security Data Lake Architecture for Supply Chain Intelligence]]></title>
      <description><![CDATA[A security data lake aggregates SBOMs, vulnerability data, build provenance, and runtime signals into a queryable store. This architecture enables the cross-cutting analysis that siloed tools cannot provide.]]></description>
      <link>https://safeguard.sh/resources/blog/security-data-lake-architecture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-data-lake-architecture</guid>
      <pubDate>Fri, 06 Mar 2026 20:33:51 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Deep Dive: Safeguard Container Scanning]]></title>
      <description><![CDATA[Container images are supply chain artifacts. Safeguard's container scanning analyzes every layer -- base images, OS packages, and application dependencies -- for a complete risk picture.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-container-scanning-launch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-container-scanning-launch</guid>
      <pubDate>Fri, 06 Mar 2026 19:13:24 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Moq Vulnerability: What Happened and What to Do]]></title>
      <description><![CDATA[The Moq incident wasn't a classic CVE — it was a popular .NET mocking library quietly bundling a data-collection dependency in a routine version bump, and it's a case study in why supply-chain monitoring has to watch behavior, not just version numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/moq-vulnerability-what-happened-and-what-to-do</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/moq-vulnerability-what-happened-and-what-to-do</guid>
      <pubDate>Fri, 06 Mar 2026 17:52:57 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Adobe Flash's End of Life: Security Lessons From a Decade of Patching]]></title>
      <description><![CDATA[Adobe Flash security was a running joke in the industry for a decade before its 2020 end-of-life — the real lesson wasn't Flash itself, it was how long a critical dependency can outlive its own security model.]]></description>
      <link>https://safeguard.sh/resources/blog/adobe-flash-eol-security-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/adobe-flash-eol-security-lessons</guid>
      <pubDate>Fri, 06 Mar 2026 16:32:31 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SvelteKit Supply Chain Considerations]]></title>
      <description><![CDATA[SvelteKit's compiled-output philosophy gives it a smaller runtime footprint than React frameworks, but the build-time supply chain is just as complex. Here is what to watch for when you adopt Svelte in production.]]></description>
      <link>https://safeguard.sh/resources/blog/svelte-kit-supply-chain-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/svelte-kit-supply-chain-considerations</guid>
      <pubDate>Fri, 06 Mar 2026 15:12:04 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SolarWinds Post-Incident Governance Changes Reviewed]]></title>
      <description><![CDATA[Four years after SUNBURST, SolarWinds has rebuilt its SDLC around signed pipelines, parallel builds, and a new CSO office. How much of it is real?]]></description>
      <link>https://safeguard.sh/resources/blog/solarwinds-post-incident-governance-changes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/solarwinds-post-incident-governance-changes</guid>
      <pubDate>Fri, 06 Mar 2026 13:51:37 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Go Toolchain Distribution Security]]></title>
      <description><![CDATA[The Go toolchain directive can automatically download and run a different compiler version than the one your developers installed, which is convenient, reproducible, and worth understanding as a supply chain surface.]]></description>
      <link>https://safeguard.sh/resources/blog/go-toolchain-distribution-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-toolchain-distribution-security</guid>
      <pubDate>Fri, 06 Mar 2026 12:31:10 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Reproducibility Crisis In AI Security Evals]]></title>
      <description><![CDATA[ML research has a reproducibility crisis. AI security evaluation inherits it. Vendors publishing numbers that can&apos;t be reproduced are the norm — not the exception.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-reproducibility-crisis-mini</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-reproducibility-crisis-mini</guid>
      <pubDate>Fri, 06 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Marketplace Listings Supply Chain Due Diligence]]></title>
      <description><![CDATA[AWS, Azure, and GCP marketplaces ship software into your account in minutes. The due diligence has not kept pace. This is the 2026 buyer's checklist.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-marketplace-listings-supply-chain-due-diligence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-marketplace-listings-supply-chain-due-diligence</guid>
      <pubDate>Fri, 06 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Dependabot Noise Reduction Techniques For 2026]]></title>
      <description><![CDATA[Dependabot is useful when tuned and a productivity tax when not. Here are the noise reduction techniques that actually work in modern monorepos.]]></description>
      <link>https://safeguard.sh/resources/blog/dependabot-noise-reduction-techniques-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependabot-noise-reduction-techniques-2026</guid>
      <pubDate>Fri, 06 Mar 2026 12:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Claude Prompt Caching: Security]]></title>
      <description><![CDATA[Claude's prompt caching gives you 90% discount on cached tokens. Security workloads have massive cacheable surface area. Griffin AI takes advantage; direct API use often does not.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-claude-prompt-caching-for-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-claude-prompt-caching-for-security</guid>
      <pubDate>Fri, 06 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Auth Bypass Discovery: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Auth bypasses are rarely a single bug. They live in the interaction between layers — middleware, route handlers, framework annotations. Finding them requires path analysis across abstraction layers.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-auth-bypass-discovery</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-auth-bypass-discovery</guid>
      <pubDate>Fri, 06 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Capability Policy Enforcement]]></title>
      <description><![CDATA[MCP servers expose tools that AI agents can call directly. Capability policy decides which tools each agent gets, with the same rigor as any other supply chain gate.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-capability-policy-enforcement</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-capability-policy-enforcement</guid>
      <pubDate>Fri, 06 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NATO Software Supply Chain Cooperation Update]]></title>
      <description><![CDATA[NATO allies are converging on shared software supply chain expectations for defense procurement. Here is what the cooperation looks like and how to prepare.]]></description>
      <link>https://safeguard.sh/resources/blog/nato-software-supply-chain-cooperation-update</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nato-software-supply-chain-cooperation-update</guid>
      <pubDate>Fri, 06 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Ransomware Via Software Supply Chain In 2026]]></title>
      <description><![CDATA[Ransomware operators increasingly enter victims through software supply chain pathways. We analyze the 2026 patterns, the affiliate dynamics, and what defenders should do.]]></description>
      <link>https://safeguard.sh/resources/blog/ransomware-via-software-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ransomware-via-software-supply-chain-2026</guid>
      <pubDate>Fri, 06 Mar 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Coordinated Disclosure With Upstream Maintainers]]></title>
      <description><![CDATA[Coordinated disclosure with open-source maintainers is a relationship business. Here is what makes it work in 2026, with the artefacts a modern pipeline gives you.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-day-coordinated-disclosure-with-upstream-maintainers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-day-coordinated-disclosure-with-upstream-maintainers</guid>
      <pubDate>Fri, 06 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SecDevOps vs DevSecOps: Is There Actually a Difference?]]></title>
      <description><![CDATA[The SecDevOps definition and the DevSecOps definition describe nearly identical practices, but the word order isn't purely cosmetic, it signals a real difference in where security sits in the pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/secdevops-vs-devsecops-is-there-a-difference</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secdevops-vs-devsecops-is-there-a-difference</guid>
      <pubDate>Fri, 06 Mar 2026 11:10:44 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Respond When a CVE Drops in a Package You Ship]]></title>
      <description><![CDATA[A working playbook for the day a CVE lands in your dependency tree: confirm exposure with SBOM queries, judge real exploitability, patch or mitigate, then prove it and publish VEX.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-respond-when-a-cve-drops-in-a-package-you-ship</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-respond-when-a-cve-drops-in-a-package-you-ship</guid>
      <pubDate>Fri, 06 Mar 2026 11:00:00 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How to Generate an SBOM with GitHub Actions (2026)]]></title>
      <description><![CDATA[SBOMs are a compliance table-stakes artifact in 2026. Here is a production GitHub Actions workflow that generates, signs, and attests a CycloneDX SBOM on every release.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-generate-sbom-github-actions-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-generate-sbom-github-actions-2026</guid>
      <pubDate>Fri, 06 Mar 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[PyPI 2FA Lessons Two Years In]]></title>
      <description><![CDATA[PyPI mandated 2FA for all maintainers in 2024. Two years in, account takeovers dropped — but attackers shifted to OIDC tokens, abandoned packages, and maintainer devices.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-2fa-lessons-two-years-in</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-2fa-lessons-two-years-in</guid>
      <pubDate>Fri, 06 Mar 2026 10:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Code Signing]]></title>
      <description><![CDATA[Code signing proves who published software and that it wasn't tampered with — but SolarWinds, CCleaner, and 3CX show signed doesn't mean safe.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-code-signing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-code-signing</guid>
      <pubDate>Fri, 06 Mar 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Actions Artifact Poisoning: A Growing Supply Chain Attack Vector]]></title>
      <description><![CDATA[Researchers disclosed techniques to poison GitHub Actions artifacts, enabling code execution in CI/CD pipelines of downstream projects. The attack exploits trust assumptions in artifact sharing.]]></description>
      <link>https://safeguard.sh/resources/blog/github-actions-artifact-poisoning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-actions-artifact-poisoning</guid>
      <pubDate>Fri, 06 Mar 2026 09:50:17 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[How to Detect Malicious npm Packages: A Workflow]]></title>
      <description><![CDATA[A practical detection workflow for malicious npm packages: install-time signals, registry heuristics, reachability checks, and CI gates that actually block attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-detect-malicious-npm-packages-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-detect-malicious-npm-packages-workflow</guid>
      <pubDate>Fri, 06 Mar 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Hyperproof alternatives and review]]></title>
      <description><![CDATA[Hyperproof and Sprinto automate compliance workflows, not supply chain security. Here's the concrete difference — and where Safeguard's SBOM, SAST/DAST, and scanning fit in.]]></description>
      <link>https://safeguard.sh/resources/blog/hyperproof-alternatives-and-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hyperproof-alternatives-and-review</guid>
      <pubDate>Fri, 06 Mar 2026 09:00:00 GMT</pubDate>
      <category>Buyer's Guides</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Procurement Security Questionnaires That Actually Work]]></title>
      <description><![CDATA[How to design a supplier security questionnaire that produces usable signal, what to cut from standard templates, and how to integrate the output into real risk decisions.]]></description>
      <link>https://safeguard.sh/resources/blog/procurement-security-questionnaires-that-work</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/procurement-security-questionnaires-that-work</guid>
      <pubDate>Fri, 06 Mar 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Desktop App 1.0 Release]]></title>
      <description><![CDATA[The Safeguard desktop application is 1.0 on macOS, Windows, and Linux. It brings the full workflow engine, Local Runner, and offline posture reviews to developers.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-desktop-application-1-0-release</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-desktop-application-1-0-release</guid>
      <pubDate>Fri, 06 Mar 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[OSS Trademark Policies: Security Angle]]></title>
      <description><![CDATA[Trademarks matter in open source security because they are the signal of authentic origin. When trademark policies fail, typosquatting, impostor forks, and compromised builds follow.]]></description>
      <link>https://safeguard.sh/resources/blog/oss-trademark-policies-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oss-trademark-policies-security-considerations</guid>
      <pubDate>Fri, 06 Mar 2026 08:29:50 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP Continuous Monitoring: What ConMon Really Involves]]></title>
      <description><![CDATA[Authorization is the starting line. FedRAMP ConMon means monthly scans, POA&M hygiene, 30/90/180-day remediation clocks, and an annual assessment — every year, forever.]]></description>
      <link>https://safeguard.sh/resources/blog/fedramp-continuous-monitoring-what-conmon-really-involves</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fedramp-continuous-monitoring-what-conmon-really-involves</guid>
      <pubDate>Fri, 06 Mar 2026 08:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Aisha Bello)</author>
    </item>
    <item>
      <title><![CDATA[AWS Step Functions Workflow Security]]></title>
      <description><![CDATA[Step Functions workflows orchestrate everything from data pipelines to security automations. The workflow IAM role is almost always the most powerful thing in the stack. Here is how to lock it down.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-stepfunctions-workflow-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-stepfunctions-workflow-security</guid>
      <pubDate>Fri, 06 Mar 2026 07:09:24 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is the SLSA Framework]]></title>
      <description><![CDATA[SLSA defines four build integrity levels to stop supply chain tampering. Learn what each level requires, who's adopting it, and its real limits.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-slsa-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-slsa-framework</guid>
      <pubDate>Fri, 06 Mar 2026 07:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best compliance management software/tools]]></title>
      <description><![CDATA[Sprinto automates org-wide compliance evidence; Safeguard proves what's inside your software. Here's how the two approaches differ on verifiable ground.]]></description>
      <link>https://safeguard.sh/resources/blog/best-compliance-management-softwaretools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-compliance-management-softwaretools</guid>
      <pubDate>Fri, 06 Mar 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Compliance Automation Tools Compared: What Actually Reduces Audit Pain in 2024]]></title>
      <description><![CDATA[The compliance automation market is crowded with platforms promising to make audits painless. Here is an honest comparison of what works, what does not, and where supply chain compliance fits in.]]></description>
      <link>https://safeguard.sh/resources/blog/compliance-automation-tools-comparison-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/compliance-automation-tools-comparison-2024</guid>
      <pubDate>Fri, 06 Mar 2026 05:48:57 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Aviation RTCA DO-326A and the Software Supply Chain]]></title>
      <description><![CDATA[How DO-326A and DO-356A reframe airworthiness security around the supply chain, and what engineering teams must deliver to survive certification.]]></description>
      <link>https://safeguard.sh/resources/blog/aviation-rtca-do-326a-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aviation-rtca-do-326a-supply-chain</guid>
      <pubDate>Fri, 06 Mar 2026 04:28:30 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is In-toto Attestation]]></title>
      <description><![CDATA[In-toto attestation is a signed, verifiable record of how software was built. Here's how the format works, how it differs from an SBOM, and where it's used today.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-in-toto-attestation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-in-toto-attestation</guid>
      <pubDate>Fri, 06 Mar 2026 04:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Copyleft License?]]></title>
      <description><![CDATA[Copyleft licenses grant broad rights on one condition: derivative works must stay under the same terms. Here is how strong and weak copyleft differ, and what actually triggers the obligation.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-copyleft-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-copyleft-license</guid>
      <pubDate>Fri, 06 Mar 2026 03:08:04 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SIEM tools comparison]]></title>
      <description><![CDATA[Sprinto automates compliance evidence; Safeguard secures the software supply chain. Neither is a true SIEM — here's how to tell which problem you actually have.]]></description>
      <link>https://safeguard.sh/resources/blog/siem-tools-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/siem-tools-comparison</guid>
      <pubDate>Fri, 06 Mar 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[What Is MFA (Multi-Factor Authentication)]]></title>
      <description><![CDATA[MFA requires two or more independent proofs of identity before letting you in. Learn how it works, why it blocks stolen-password attacks, and the factor types involved.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-mfa</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-mfa</guid>
      <pubDate>Fri, 06 Mar 2026 01:47:37 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is Sigstore]]></title>
      <description><![CDATA[Sigstore lets projects sign software with short-lived, identity-bound certificates instead of long-lived keys. Here's how Fulcio, Rekor, and Cosign actually work.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-sigstore</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-sigstore</guid>
      <pubDate>Fri, 06 Mar 2026 01:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[SAST Full Form and What It Actually Tests]]></title>
      <description><![CDATA[SAST stands for static application security testing — analyzing source code without running it. Here's exactly what it catches, what it misses, and how it fits a pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-full-form-and-what-it-actually-tests</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-full-form-and-what-it-actually-tests</guid>
      <pubDate>Fri, 06 Mar 2026 00:27:10 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-32002 Git RCE on Clone: Walkthrough]]></title>
      <description><![CDATA[CVE-2024-32002 is a Git submodule RCE triggered by a recursive clone on case-insensitive filesystems. Root cause, exploit, and remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-32002-git-rce-on-clone-walkthrough</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-32002-git-rce-on-clone-walkthrough</guid>
      <pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security Market Map 2026]]></title>
      <description><![CDATA[A senior-analyst market map of software supply chain security in 2026: the vendor categories that consolidated, the ones that splintered, and where the budget actually lands.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-market-map-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-market-map-2026</guid>
      <pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability management and scanning tools]]></title>
      <description><![CDATA[Sprinto automates compliance evidence collection; Safeguard scans code, dependencies, and containers directly. Here's how the two actually differ on vulnerability management.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-management-and-scanning-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-management-and-scanning-tools</guid>
      <pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What Is CWE? The Common Weakness Enumeration Explained]]></title>
      <description><![CDATA[CWE catalogs the underlying software weakness behind a vulnerability, not the specific instance of it — here's how it relates to CVE and why scanners tag findings with a CWE ID.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-cwe-common-weakness-enumeration-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-cwe-common-weakness-enumeration-explained</guid>
      <pubDate>Thu, 05 Mar 2026 23:06:44 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[GNU GPL v3.0 Obligations, in Plain English]]></title>
      <description><![CDATA[The GNU General Public License v3.0 explained without the legal phrasing: what you must do when you distribute software that includes GPL-3.0 code, and what triggers those obligations.]]></description>
      <link>https://safeguard.sh/resources/blog/gnu-gpl-v3-0-obligations-in-plain-english</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gnu-gpl-v3-0-obligations-in-plain-english</guid>
      <pubDate>Thu, 05 Mar 2026 21:46:17 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2020-15250: The JUnit Temp File Vulnerability]]></title>
      <description><![CDATA[CVE-2020-15250 shows how a test-only utility class in JUnit 4 created world-readable temp files on Unix systems, and why it still shows up in scans of projects that never touched production code paths.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2020-15250-junit-temp-file-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2020-15250-junit-temp-file-vulnerability</guid>
      <pubDate>Thu, 05 Mar 2026 20:25:50 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Rhysida Ransomware: Systematic Targeting of Government and Critical Infrastructure]]></title>
      <description><![CDATA[Rhysida ransomware distinguished itself through deliberate targeting of government agencies, education institutions, and healthcare organizations across multiple countries.]]></description>
      <link>https://safeguard.sh/resources/blog/rhysida-ransomware-government-targeting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rhysida-ransomware-government-targeting</guid>
      <pubDate>Thu, 05 Mar 2026 19:05:23 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[AI Supply Chain Attacks: Emerging Threats in Model and Data Pipelines]]></title>
      <description><![CDATA[As organizations adopt AI at scale, the AI/ML supply chain is becoming a new attack surface. From poisoned models to compromised training data, the threats are real and growing.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-supply-chain-attacks-emerging-threats</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-supply-chain-attacks-emerging-threats</guid>
      <pubDate>Thu, 05 Mar 2026 17:44:57 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard v2: The Platform Grows Up]]></title>
      <description><![CDATA[Safeguard v2 introduces container scanning, enhanced policy engine, team workspaces, and API v1.1 with webhook support. A major step toward enterprise readiness.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-v2-release-announcement</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-v2-release-announcement</guid>
      <pubDate>Thu, 05 Mar 2026 16:24:30 GMT</pubDate>
      <category>Release</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Rancher Cluster Security Hardening]]></title>
      <description><![CDATA[Rancher is the distribution that runs when your Kubernetes is neither EKS nor OpenShift. Hardening it well is specific work.]]></description>
      <link>https://safeguard.sh/resources/blog/rancher-cluster-security-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rancher-cluster-security-hardening</guid>
      <pubDate>Thu, 05 Mar 2026 15:04:03 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NuGet Private Feed Security Hardening]]></title>
      <description><![CDATA[Private NuGet feeds sit in the blind spot of most security programs. The hardening work is not glamorous but the failure modes are expensive.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-private-feed-security-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-private-feed-security-hardening</guid>
      <pubDate>Thu, 05 Mar 2026 13:43:37 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cosign Verification Policies in Production]]></title>
      <description><![CDATA[Writing cosign verification policies that actually pass production deployment gates requires more precision than the examples suggest. Here is what we have learned.]]></description>
      <link>https://safeguard.sh/resources/blog/cosign-verification-policies-production</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cosign-verification-policies-production</guid>
      <pubDate>Thu, 05 Mar 2026 12:23:10 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Chain-Of-Thought For Vulnerability Reasoning]]></title>
      <description><![CDATA[Chain-of-thought helps LLMs with multi-step problems. For vulnerability reasoning, it helps — but only when the chain is grounded in structured evidence.]]></description>
      <link>https://safeguard.sh/resources/blog/chain-of-thought-for-vulnerability-reasoning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chain-of-thought-for-vulnerability-reasoning</guid>
      <pubDate>Thu, 05 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[EHR Integration Vendor Controls Blueprint]]></title>
      <description><![CDATA[EHR integrations move PHI between dozens of systems. This blueprint shows how to control the third-party risk surface without breaking interoperability.]]></description>
      <link>https://safeguard.sh/resources/blog/ehr-integration-vendor-controls-blueprint</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ehr-integration-vendor-controls-blueprint</guid>
      <pubDate>Thu, 05 Mar 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Eval Harness As Release Gate For AI Features]]></title>
      <description><![CDATA[Shipping AI features without an eval harness is shipping without tests. Here is how to build one that actually gates releases without becoming a bottleneck.]]></description>
      <link>https://safeguard.sh/resources/blog/eval-harness-as-release-gate-for-ai-features</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eval-harness-as-release-gate-for-ai-features</guid>
      <pubDate>Thu, 05 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Frontier Model Pricing Pressure: Architectural Response]]></title>
      <description><![CDATA[Frontier model pricing is rising even as cheaper alternatives proliferate. The 2026 architectural response is multi-tier model routing — and the security implications are non-trivial.]]></description>
      <link>https://safeguard.sh/resources/blog/frontier-model-pricing-pressure-and-architectural-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/frontier-model-pricing-pressure-and-architectural-response</guid>
      <pubDate>Thu, 05 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Context Window Limits: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Context-window size matters less than context quality. A look at how Griffin AI's engine-grounded context beats pure-LLM retrieval at monorepo scale.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-context-window-limits</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-context-window-limits</guid>
      <pubDate>Thu, 05 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs OpenAI Assistants API for SecOps]]></title>
      <description><![CDATA[The OpenAI Assistants API is a general agent framework. SecOps needs more than a framework — it needs the engine-grounded reasoning Griffin AI adds on top.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-openai-assistants-api-for-secops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-openai-assistants-api-for-secops</guid>
      <pubDate>Thu, 05 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Metrics Developers Care About: Secure By Default]]></title>
      <description><![CDATA[Most security metrics are built for the security team. A guide to picking metrics that developers will actually act on, with examples from secure-by-default workflows.]]></description>
      <link>https://safeguard.sh/resources/blog/metrics-developers-care-about-secure-by-default</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/metrics-developers-care-about-secure-by-default</guid>
      <pubDate>Thu, 05 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Post-Quantum Signing: An Artifact Migration Plan]]></title>
      <description><![CDATA[A concrete migration plan for artifact signing from ECDSA to ML-DSA and SLH-DSA, covering Sigstore, Notary, HSMs, and staged hybrid rollouts.]]></description>
      <link>https://safeguard.sh/resources/blog/post-quantum-signing-artifact-migration-plan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/post-quantum-signing-artifact-migration-plan</guid>
      <pubDate>Thu, 05 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Reachability As The Bridge Between SCA And Fix PRs]]></title>
      <description><![CDATA[SCA tools find vulnerabilities. Auto-fix tools generate PRs. The gap between them is where most programs lose efficiency. Reachability is the bridge.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-as-the-bridge-between-sca-and-fix-prs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-as-the-bridge-between-sca-and-fix-prs</guid>
      <pubDate>Thu, 05 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Swift And CocoaPods Supply Chain Program]]></title>
      <description><![CDATA[A 2026 supply chain program for Swift apps — covering SPM, CocoaPods, XCFrameworks, and notarisation — anchored by Safeguard policy and SBOM evidence.]]></description>
      <link>https://safeguard.sh/resources/blog/swift-and-cocoapods-supply-chain-program-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/swift-and-cocoapods-supply-chain-program-2026</guid>
      <pubDate>Thu, 05 Mar 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Tracking Vendor-Supplied Binaries In Your Runtime]]></title>
      <description><![CDATA[Vendor binaries run as root and ship without SBOMs. Continuous discovery brings them under the same governance as your own code.]]></description>
      <link>https://safeguard.sh/resources/blog/tracking-vendor-supplied-binaries-in-your-runtime</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tracking-vendor-supplied-binaries-in-your-runtime</guid>
      <pubDate>Thu, 05 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vendor Risk During M&A Due Diligence]]></title>
      <description><![CDATA[M&A due diligence usually ignores vendor risk until the day after close. By then, the buyer has inherited a vendor portfolio with no visibility and no leverage.]]></description>
      <link>https://safeguard.sh/resources/blog/vendor-risk-during-merger-acquisition-due-diligence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vendor-risk-during-merger-acquisition-due-diligence</guid>
      <pubDate>Thu, 05 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Confluence Zero-Day Lessons: What CVE-2023-22515 Showed About SaaS-Adjacent On-Prem Risk]]></title>
      <description><![CDATA[The Confluence broken access control zero-day from October 2023 hit thousands of self-hosted instances. A 2026 look at the exploit, the response, and the durable lessons.]]></description>
      <link>https://safeguard.sh/resources/blog/atlassian-cve-2023-22515-confluence-zero-day-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/atlassian-cve-2023-22515-confluence-zero-day-lessons</guid>
      <pubDate>Thu, 05 Mar 2026 11:30:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Advanced Security 2026: Copilot Autofix Goes GA]]></title>
      <description><![CDATA[GHAS in 2026 made Copilot Autofix generally available, opened secret scanning to Team plans, and shipped extended secret metadata. We walked the upgrade for an org with 800 repos.]]></description>
      <link>https://safeguard.sh/resources/blog/github-advanced-security-2026-copilot-autofix-ga</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-advanced-security-2026-copilot-autofix-ga</guid>
      <pubDate>Thu, 05 Mar 2026 11:30:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Free Online Code Checkers: What They Actually Catch]]></title>
      <description><![CDATA[An online python code checker or a free JS linter will catch syntax errors and style issues fast, but here is exactly where that coverage ends and real security scanning has to start.]]></description>
      <link>https://safeguard.sh/resources/blog/free-online-code-checkers-what-they-actually-catch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/free-online-code-checkers-what-they-actually-catch</guid>
      <pubDate>Thu, 05 Mar 2026 11:15:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SCA in Cyber Security: What It Actually Means]]></title>
      <description><![CDATA[SCA in cyber security stands for software composition analysis — the practice of identifying every open-source component in an application and checking it against known vulnerabilities and licenses.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-in-cyber-security-what-it-actually-means</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-in-cyber-security-what-it-actually-means</guid>
      <pubDate>Thu, 05 Mar 2026 11:02:43 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Change Healthcare Ransomware 2024: Deep Dive]]></title>
      <description><![CDATA[The Change Healthcare ransomware attack knocked US healthcare payments offline for weeks. A missing MFA on a Citrix portal was the root cause United confirmed.]]></description>
      <link>https://safeguard.sh/resources/blog/change-healthcare-ransomware-2024-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/change-healthcare-ransomware-2024-deep-dive</guid>
      <pubDate>Thu, 05 Mar 2026 10:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard vs Aqua Security Platform Review]]></title>
      <description><![CDATA[A fact-based comparison of Safeguard and Aqua Security in 2026 across container coverage, runtime protection, SCA depth, and supply chain capabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-vs-aqua-security-platform-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-vs-aqua-security-platform-review</guid>
      <pubDate>Thu, 05 Mar 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Code vs Snyk Open Source: What's the Difference]]></title>
      <description><![CDATA[Snyk Code scans first-party source for flaws; Snyk Open Source scans dependencies for known vulnerabilities — different engines, different findings, and both are needed for full coverage.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-code-vs-snyk-open-source-whats-the-difference</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-code-vs-snyk-open-source-whats-the-difference</guid>
      <pubDate>Thu, 05 Mar 2026 10:00:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Supply Chain Attack Kill Chain: A Framework for Defense]]></title>
      <description><![CDATA[We propose a kill chain framework specific to software supply chain attacks, mapping attacker techniques to defensive controls at each stage.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-attack-kill-chain-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-attack-kill-chain-framework</guid>
      <pubDate>Thu, 05 Mar 2026 10:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[The Future of Software Signing Is Keyless]]></title>
      <description><![CDATA[Long-lived signing keys are operational debt that every security team eventually pays down the hard way. Keyless signing is not an experiment anymore — it is the mainstream design.]]></description>
      <link>https://safeguard.sh/resources/blog/the-future-of-software-signing-is-keyless</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-future-of-software-signing-is-keyless</guid>
      <pubDate>Thu, 05 Mar 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Software Provenance]]></title>
      <description><![CDATA[Software provenance proves where an artifact came from and how it was built. Learn what it is, why it matters, and how to verify it with SLSA and Sigstore.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-software-provenance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-software-provenance</guid>
      <pubDate>Thu, 05 Mar 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[VMware ESXi Under Siege: Ransomware Campaigns Targeting Hypervisors in 2024]]></title>
      <description><![CDATA[Ransomware groups increasingly target VMware ESXi hypervisors to encrypt entire virtual environments at once. The 2024 campaigns exploited known and zero-day vulnerabilities for maximum impact.]]></description>
      <link>https://safeguard.sh/resources/blog/vmware-esxi-ransomware-campaigns-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vmware-esxi-ransomware-campaigns-2024</guid>
      <pubDate>Thu, 05 Mar 2026 09:42:17 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Consulting: When It's Actually Worth Hiring Out]]></title>
      <description><![CDATA[A practical test for when DevSecOps consulting pays for itself versus when it just delays building internal capability, with the questions to ask before signing a statement of work.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-consulting-when-it-is-worth-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-consulting-when-it-is-worth-it</guid>
      <pubDate>Thu, 05 Mar 2026 09:15:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Composer/PHP Package Supply Chain in 2026]]></title>
      <description><![CDATA[PHP's Composer and Packagist ecosystem has quietly improved its supply chain story. Here is where things actually stand in 2026, and what PHP shops should do now.]]></description>
      <link>https://safeguard.sh/resources/blog/composer-php-package-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/composer-php-package-supply-chain-2026</guid>
      <pubDate>Thu, 05 Mar 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Data loss prevention (DLP) software roundup]]></title>
      <description><![CDATA[Sprinto automates compliance evidence; Safeguard secures the software supply chain. A clear-eyed look at what "DLP software" really means and where each tool fits.]]></description>
      <link>https://safeguard.sh/resources/blog/data-loss-prevention-dlp-software-roundup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/data-loss-prevention-dlp-software-roundup</guid>
      <pubDate>Thu, 05 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Application Security: Building the Program]]></title>
      <description><![CDATA[Tools don't make a program. How to build enterprise application security that scales across hundreds of teams: operating model, paved roads, vulnerability management, and the metrics that keep it honest.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-application-security-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-application-security-program</guid>
      <pubDate>Thu, 05 Mar 2026 09:00:00 GMT</pubDate>
      <category>Enterprise</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Black Duck vs Safeguard: An SCA Comparison]]></title>
      <description><![CDATA[Snyk vs Blackduck comes down to developer-workflow speed versus enterprise policy depth — here's where a newer entrant changes that tradeoff instead of just splitting the difference.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-blackduck-vs-safeguard-sca-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-blackduck-vs-safeguard-sca-comparison</guid>
      <pubDate>Thu, 05 Mar 2026 09:00:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Security for Financial Services 2026]]></title>
      <description><![CDATA[Supply chain security for financial services in 2026 means DORA, NYDFS 500, FFIEC, and OCC expectations. A practical guide for banks, insurers, and fintechs.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-financial-services-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-financial-services-2026</guid>
      <pubDate>Thu, 05 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Monolith to Microservices: Supply Chain Changes]]></title>
      <description><![CDATA[What really happens to your software supply chain when you decompose a monolith into services, and how to avoid trading one risk for forty new ones.]]></description>
      <link>https://safeguard.sh/resources/blog/monolith-to-microservices-supply-chain-changes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/monolith-to-microservices-supply-chain-changes</guid>
      <pubDate>Thu, 05 Mar 2026 08:21:50 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Compromise Timeline Reconstruction]]></title>
      <description><![CDATA[How to rebuild a precise timeline after a dependency has been compromised, using lockfile history, registry metadata, and CI logs.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-compromise-timeline-reconstruction</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-compromise-timeline-reconstruction</guid>
      <pubDate>Thu, 05 Mar 2026 07:01:23 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is an Attestation (Software Security)]]></title>
      <description><![CDATA[Software attestations are signed, verifiable proofs of how code was built and secured — now a legal requirement for US federal software vendors since March 2024.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-an-attestation-software-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-an-attestation-software-security</guid>
      <pubDate>Thu, 05 Mar 2026 07:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Azure Container Registry Trust Model]]></title>
      <description><![CDATA[What Azure Container Registry actually guarantees about the images you pull — signing, attestation, content trust, and where the trust chain breaks in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-container-registry-trust-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-container-registry-trust-model</guid>
      <pubDate>Thu, 05 Mar 2026 05:40:57 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[US DoD Zero Trust: Software Dimensions]]></title>
      <description><![CDATA[Where the DoD Zero Trust Reference Architecture meets the software supply chain, and what program offices are actually doing about it.]]></description>
      <link>https://safeguard.sh/resources/blog/us-dod-zero-trust-software-dimensions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/us-dod-zero-trust-software-dimensions</guid>
      <pubDate>Thu, 05 Mar 2026 04:20:30 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is AI Security]]></title>
      <description><![CDATA[AI security protects models, training data, and agentic systems from prompt injection, poisoning, and unsafe autonomy — here's what it covers and how to build a program.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-ai-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-ai-security</guid>
      <pubDate>Thu, 05 Mar 2026 04:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Pydantic v2 Security Implications]]></title>
      <description><![CDATA[Pydantic v2 rewrote the core in Rust and changed validation semantics. Here is what that means for security-sensitive code, from input coercion to ReDoS exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/pydantic-v2-security-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pydantic-v2-security-implications</guid>
      <pubDate>Thu, 05 Mar 2026 03:00:03 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CrowdStrike Falcon Global Outage: A Post-Mortem Deep Dive]]></title>
      <description><![CDATA[A technical reconstruction of the July 19 CrowdStrike Falcon sensor crash that grounded 8.5M Windows hosts, and what supply chain owners should change.]]></description>
      <link>https://safeguard.sh/resources/blog/crowdstrike-falcon-global-outage-deep-dive-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crowdstrike-falcon-global-outage-deep-dive-2024</guid>
      <pubDate>Thu, 05 Mar 2026 01:39:36 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is LLM Security]]></title>
      <description><![CDATA[LLM security protects model weights, prompts, outputs, and the AI supply chain from injection, leakage, and compromise—here's what it covers and how to defend it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-llm-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-llm-security</guid>
      <pubDate>Thu, 05 Mar 2026 01:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is Authorization]]></title>
      <description><![CDATA[Authorization decides what an already-verified identity is allowed to do. Learn how it differs from authentication, how permission checks work, and the models that power them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-authorization-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-authorization-explained</guid>
      <pubDate>Thu, 05 Mar 2026 00:19:10 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SentinelOne Supply Chain Detection Logic for Build Systems]]></title>
      <description><![CDATA[How to extend SentinelOne's behavioral detection engine to cover build agents, package registries, and developer endpoints without drowning analysts in false positives.]]></description>
      <link>https://safeguard.sh/resources/blog/sentinel-one-supply-chain-detection-logic</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sentinel-one-supply-chain-detection-logic</guid>
      <pubDate>Wed, 04 Mar 2026 22:58:43 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Scattered Spider: Developer Targeting Patterns]]></title>
      <description><![CDATA[The English-speaking social engineering crew behind MGM and Caesars keeps going after developers and help desks. Here's what I keep seeing.]]></description>
      <link>https://safeguard.sh/resources/blog/scattered-spider-developer-targeting-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scattered-spider-developer-targeting-patterns</guid>
      <pubDate>Wed, 04 Mar 2026 21:38:16 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Build a VEX Document for Your Consumers]]></title>
      <description><![CDATA[A hands-on tutorial for producing a CSAF-VEX document that tells your customers which CVEs actually affect your product and which do not.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-build-a-vex-document-for-consumers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-build-a-vex-document-for-consumers</guid>
      <pubDate>Wed, 04 Mar 2026 20:17:50 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GDPR Meets CRA: Software Overlap]]></title>
      <description><![CDATA[GDPR Article 32 and the EU Cyber Resilience Act look like separate regimes, but for any software handling personal data they converge at the component level. Here's where they overlap and where they diverge.]]></description>
      <link>https://safeguard.sh/resources/blog/gdpr-meets-cra-software-overlap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gdpr-meets-cra-software-overlap</guid>
      <pubDate>Wed, 04 Mar 2026 18:57:23 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AWS ECR Image Signing in Production]]></title>
      <description><![CDATA[Image signing in ECR has moved from nice-to-have to table stakes. Here is what it actually takes to run cosign and AWS Signer in production without breaking every deploy.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-ecr-image-signing-production</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-ecr-image-signing-production</guid>
      <pubDate>Wed, 04 Mar 2026 17:36:56 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Lessons from CrowdStrike: Rethinking How We Deploy Software Updates]]></title>
      <description><![CDATA[The CrowdStrike outage wasn't just an EDR problem. It exposed fundamental weaknesses in how the entire industry handles software updates, from kernel drivers to SaaS platforms.]]></description>
      <link>https://safeguard.sh/resources/blog/crowdstrike-outage-lessons-software-updates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crowdstrike-outage-lessons-software-updates</guid>
      <pubDate>Wed, 04 Mar 2026 16:16:30 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CISA Minimum Elements for SBOM: 2026 Update]]></title>
      <description><![CDATA[A clear walkthrough of CISA's 2026 revisions to the minimum elements for SBOM, what changed from the original NTIA baseline, and how to bring your outputs into compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/minimum-elements-sbom-cisa-2026-update</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/minimum-elements-sbom-cisa-2026-update</guid>
      <pubDate>Wed, 04 Mar 2026 15:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is a CSRF Token, and How Does It Stop CSRF?]]></title>
      <description><![CDATA[A CSRF token is a random, per-session value a server requires on state-changing requests so a malicious site can't forge one on a logged-in user's behalf.]]></description>
      <link>https://safeguard.sh/resources/blog/csrf-tokens-what-is-a-csrf-token</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/csrf-tokens-what-is-a-csrf-token</guid>
      <pubDate>Wed, 04 Mar 2026 14:56:03 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis for Java: A 2026 Deep Dive]]></title>
      <description><![CDATA[Java reachability under classpath reality: reflection, Spring autowiring, shaded JARs, Log4Shell, and what modern tools actually resolve versus over-approximate.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-java-deep-dive-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-java-deep-dive-2026</guid>
      <pubDate>Wed, 04 Mar 2026 14:15:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[GraalVM Native Image Supply Chain]]></title>
      <description><![CDATA[GraalVM native images change the supply chain story in ways that most SBOM tooling has not caught up with yet. Here is what gets baked in, what gets stripped out, and what still needs to be tracked.]]></description>
      <link>https://safeguard.sh/resources/blog/graalvm-native-image-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/graalvm-native-image-supply-chain</guid>
      <pubDate>Wed, 04 Mar 2026 13:35:36 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CrowdStrike Falcon Update Triggers Global IT Outage: What Happened]]></title>
      <description><![CDATA[On July 19, 2024, a faulty CrowdStrike Falcon sensor update caused 8.5 million Windows machines to blue-screen worldwide, grounding flights, halting hospitals, and exposing the fragility of centralized security infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/crowdstrike-falcon-global-outage-july-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crowdstrike-falcon-global-outage-july-2024</guid>
      <pubDate>Wed, 04 Mar 2026 12:15:10 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CRA Article 14: 24-Hour Early Warning and 72-Hour Reporting Explained]]></title>
      <description><![CDATA[Article 14 of the Cyber Resilience Act mandates dual notifications to coordinating CSIRTs and ENISA within 24 hours of awareness. Reporting starts 11 September 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/cra-article-14-vulnerability-reporting-72-hours</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cra-article-14-vulnerability-reporting-72-hours</guid>
      <pubDate>Wed, 04 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[ENISA's CRA Single Reporting Platform Goes Live September 2026]]></title>
      <description><![CDATA[From 11 September 2026, every CRA manufacturer must file a 24-hour early warning of actively exploited vulnerabilities through one ENISA-operated portal — and the platform is being built right now.]]></description>
      <link>https://safeguard.sh/resources/blog/cra-enisa-single-reporting-platform-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cra-enisa-single-reporting-platform-2026</guid>
      <pubDate>Wed, 04 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[DORA Financial Sector Supply Chain Controls]]></title>
      <description><![CDATA[A senior engineer's view of how DORA's ICT third-party risk management requirements are reshaping software supply chain controls across European financial services.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-financial-sector-supply-chain-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-financial-sector-supply-chain-controls</guid>
      <pubDate>Wed, 04 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Evidence-Driven SecOps vs Feeling-Driven SecOps]]></title>
      <description><![CDATA[Two SecOps programs can look identical on a status report and behave completely differently when the next incident hits. The difference is whether they run on evidence or on feeling.]]></description>
      <link>https://safeguard.sh/resources/blog/evidence-driven-secops-vs-feeling-driven-secops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/evidence-driven-secops-vs-feeling-driven-secops</guid>
      <pubDate>Wed, 04 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Model Substitution Risk In Enterprise Deployments]]></title>
      <description><![CDATA[The model you think you&apos;re calling might not be the model that returns. Model substitution is a quiet supply chain risk that deserves explicit controls.]]></description>
      <link>https://safeguard.sh/resources/blog/frontier-model-limit-model-substitution-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/frontier-model-limit-model-substitution-risk</guid>
      <pubDate>Wed, 04 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Gemini Pricing: Security Scans]]></title>
      <description><![CDATA[Gemini's pricing table favours long-context workloads. Security scans have long-context structure. The question is how much context fits into the architecture.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-pricing-for-security-scans</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-pricing-for-security-scans</guid>
      <pubDate>Wed, 04 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Onboarding Velocity: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Time from contract signature to first meaningful finding is the metric procurement cares about. Griffin AI and Mythos-class tools diverge in week one.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-onboarding-velocity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-onboarding-velocity</guid>
      <pubDate>Wed, 04 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Operator Supply Chain Controls]]></title>
      <description><![CDATA[Operators are powerful, privileged, and often under-governed. This post covers the supply chain controls that keep operator installations from becoming the largest attack surface in your cluster.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-operator-supply-chain-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-operator-supply-chain-controls</guid>
      <pubDate>Wed, 04 Mar 2026 12:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NIS2 Supply Chain Evidence For EU Operators]]></title>
      <description><![CDATA[NIS2 expects essential and important entities to manage supply chain risk with documented evidence. Learn how to build a program that survives competent authority review.]]></description>
      <link>https://safeguard.sh/resources/blog/nis2-supply-chain-evidence-eu-operators</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nis2-supply-chain-evidence-eu-operators</guid>
      <pubDate>Wed, 04 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NIST AI RMF Cybersecurity Profile (NIST IR 8596 Draft)]]></title>
      <description><![CDATA[NIST released the preliminary draft Cybersecurity Framework Profile for AI (NIST IR 8596) in December 2025, addressing the intersection of AI and cybersecurity from three angles.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-ai-rmf-cybersecurity-profile-ir-8596-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-ai-rmf-cybersecurity-profile-ir-8596-2025</guid>
      <pubDate>Wed, 04 Mar 2026 12:00:00 GMT</pubDate>
      <category>Frameworks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Remediation SLA Tracking Without Spreadsheets]]></title>
      <description><![CDATA[Tracking remediation SLAs in spreadsheets is how programmes drift. Here is how to track SLAs in the same system that finds, fixes, and merges vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/remediation-sla-tracking-without-spreadsheets</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/remediation-sla-tracking-without-spreadsheets</guid>
      <pubDate>Wed, 04 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Generation: Syft, Tern, Trivy Compared (2026)]]></title>
      <description><![CDATA[An engineer's side-by-side of Syft, Tern, and Trivy for SBOM generation in 2026, with honest notes on accuracy, performance, and where each tool actually fits.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-generation-tools-syft-tern-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-generation-tools-syft-tern-comparison-2026</guid>
      <pubDate>Wed, 04 Mar 2026 12:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Incident Response: Finding Affected Products Fast]]></title>
      <description><![CDATA[When a critical CVE drops, the only number that matters is minutes-to-blast-radius. Here is how a well-run SBOM programme answers the question in under five minutes.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-incident-response-finding-affected-products-fast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-incident-response-finding-affected-products-fast</guid>
      <pubDate>Wed, 04 Mar 2026 12:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Kyverno vs OPA Gatekeeper: A Buyer Comparison for 2026]]></title>
      <description><![CDATA[A practical comparison of Kyverno 1.13 and OPA Gatekeeper 3.18 for Kubernetes policy enforcement, covering language, performance, ecosystem, and operational fit.]]></description>
      <link>https://safeguard.sh/resources/blog/kyverno-vs-opa-gatekeeper-buyer-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kyverno-vs-opa-gatekeeper-buyer-comparison-2026</guid>
      <pubDate>Wed, 04 Mar 2026 11:30:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Fintech Software Supply Chain Realities in 2026]]></title>
      <description><![CDATA[Fintechs ship fast and run on a thick layer of open source. Here is what the 2026 supply chain threat landscape looks like for a modern payments or lending platform, and the controls that actually scale.]]></description>
      <link>https://safeguard.sh/resources/blog/fintech-software-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fintech-software-supply-chain-2026</guid>
      <pubDate>Wed, 04 Mar 2026 11:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Open Banking API Supply Chain Security]]></title>
      <description><![CDATA[Open banking depends on a tangle of SDKs, certificate authorities, and directory services. What PSD2, the UK's Open Banking Standard, and the emerging US framework mean for supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/open-banking-api-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-banking-api-supply-chain-security</guid>
      <pubDate>Wed, 04 Mar 2026 10:54:43 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Automated Network Security: What to Automate First]]></title>
      <description><![CDATA[Automated network security works best when teams target the repetitive, high-volume tasks first, patch verification, config drift detection, alert triage, rather than trying to automate everything at once.]]></description>
      <link>https://safeguard.sh/resources/blog/automated-network-security-what-to-automate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automated-network-security-what-to-automate</guid>
      <pubDate>Wed, 04 Mar 2026 10:00:00 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Deploying Cilium Tetragon for eBPF Runtime Security in 2026]]></title>
      <description><![CDATA[A practical guide to rolling out Tetragon for kernel-level runtime visibility, covering policy authoring, performance overhead, and integration with existing detection pipelines.]]></description>
      <link>https://safeguard.sh/resources/blog/cilium-tetragon-ebpf-runtime-security-deploy-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cilium-tetragon-ebpf-runtime-security-deploy-2026</guid>
      <pubDate>Wed, 04 Mar 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What is Prompt Injection]]></title>
      <description><![CDATA[Prompt injection is OWASP's #1 LLM risk. Learn how it works, real CVEs like EchoLeak, and how to detect and defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-prompt-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-prompt-injection</guid>
      <pubDate>Wed, 04 Mar 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[npm Token Rotation: An Enterprise Strategy]]></title>
      <description><![CDATA[Rotating a few npm tokens is easy. Rotating a few thousand across a shared CI fleet is a project. A practical strategy that survives real organizations.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-token-rotation-enterprise-strategy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-token-rotation-enterprise-strategy</guid>
      <pubDate>Wed, 04 Mar 2026 09:34:16 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Secure Patterns for LLM Output Handling in 2026]]></title>
      <description><![CDATA[LLM02 on the OWASP LLM Top 10 keeps quietly producing incidents because downstream systems trust model outputs they should not. Concrete patterns that hold up.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-output-handling-secure-patterns-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-output-handling-secure-patterns-2026</guid>
      <pubDate>Wed, 04 Mar 2026 09:30:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cosign container signing]]></title>
      <description><![CDATA[What is Cosign? A precise look at how this Sigstore tool signs and verifies container images, keyless signing, and how it compares to Notary v2.]]></description>
      <link>https://safeguard.sh/resources/blog/cosign-container-signing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cosign-container-signing</guid>
      <pubDate>Wed, 04 Mar 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Practices That Actually Stick on a Real Team]]></title>
      <description><![CDATA[Most DevSecOps practices fail within a quarter because they add friction without removing any. Here is what actually holds up on a real engineering team.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-practices-that-actually-stick</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-practices-that-actually-stick</guid>
      <pubDate>Wed, 04 Mar 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SBOM-Driven Due Diligence for M&A]]></title>
      <description><![CDATA[How SBOMs have become a standard input to technical due diligence for software acquisitions, what acquirers actually look for, and how sellers should prepare.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-mergers-acquisitions-due-diligence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-mergers-acquisitions-due-diligence</guid>
      <pubDate>Wed, 04 Mar 2026 09:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Telecom Supply Chain Strategy for 2026]]></title>
      <description><![CDATA[How telecom operators should rebuild their software supply chain strategy for 2026: SBOM mandates, 5G core risks, vendor concentration, and reachability-driven prioritization.]]></description>
      <link>https://safeguard.sh/resources/blog/telecom-supply-chain-strategy-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/telecom-supply-chain-strategy-2026</guid>
      <pubDate>Wed, 04 Mar 2026 09:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[External Secrets Operator: A Kubernetes Guide]]></title>
      <description><![CDATA[A senior engineer's walkthrough of External Secrets Operator, covering architecture, SecretStore design, rotation, and the patterns that hold up in production.]]></description>
      <link>https://safeguard.sh/resources/blog/external-secrets-operator-kubernetes-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/external-secrets-operator-kubernetes-guide</guid>
      <pubDate>Wed, 04 Mar 2026 08:13:49 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AI-Based Security: What the Label Actually Means on a Product Page]]></title>
      <description><![CDATA[AI-based security is used to describe everything from a genuinely trained detection model to a marketing rewrite of a rules engine. Here's how to tell what you're actually buying.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-based-security-what-the-label-actually-means</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-based-security-what-the-label-actually-means</guid>
      <pubDate>Wed, 04 Mar 2026 08:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Direct vs Indirect Prompt Injection]]></title>
      <description><![CDATA[Direct and indirect prompt injection are different attack vectors with different blast radii. Real 2025 CVEs like EchoLeak show why the distinction matters.]]></description>
      <link>https://safeguard.sh/resources/blog/direct-vs-indirect-prompt-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/direct-vs-indirect-prompt-injection</guid>
      <pubDate>Wed, 04 Mar 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Dropbox 2022: The Supply Chain Angle]]></title>
      <description><![CDATA[Dropbox's 2022 GitHub phishing incident began with a developer-targeted CircleCI lookalike campaign; the supply chain lessons centered on CI tokens and code.]]></description>
      <link>https://safeguard.sh/resources/blog/dropbox-incident-2022-supply-chain-angle</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dropbox-incident-2022-supply-chain-angle</guid>
      <pubDate>Wed, 04 Mar 2026 06:53:23 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Rekor transparency log]]></title>
      <description><![CDATA[What is Rekor? It's the public, immutable transparency log at the heart of Sigstore that records software signing events for tamper-evident verification.]]></description>
      <link>https://safeguard.sh/resources/blog/rekor-transparency-log</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rekor-transparency-log</guid>
      <pubDate>Wed, 04 Mar 2026 06:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Fuzzing Open Source for Supply Chain Findings]]></title>
      <description><![CDATA[How modern coverage-guided fuzzing finds real vulnerabilities in open-source dependencies, and how to fold it into a supply-chain security program.]]></description>
      <link>https://safeguard.sh/resources/blog/fuzzing-open-source-for-supply-chain-findings</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fuzzing-open-source-for-supply-chain-findings</guid>
      <pubDate>Wed, 04 Mar 2026 05:32:56 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Drone CI Security Considerations]]></title>
      <description><![CDATA[A security-focused look at Drone CI: runner isolation, secret handling, plugin risks, and the differences between Drone OSS, Enterprise, and the Harness transition.]]></description>
      <link>https://safeguard.sh/resources/blog/drone-ci-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/drone-ci-security-considerations</guid>
      <pubDate>Wed, 04 Mar 2026 04:12:29 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is LLM Jailbreaking]]></title>
      <description><![CDATA[LLM jailbreaking bypasses AI safety guardrails through techniques like DAN prompts, Crescendo, and Skeleton Key — here's how it works and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-llm-jailbreaking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-llm-jailbreaking</guid>
      <pubDate>Wed, 04 Mar 2026 04:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Merkle tree in transparency logs]]></title>
      <description><![CDATA[A Merkle tree is a hash-based data structure that lets transparency logs prove data integrity efficiently, using Merkle proofs and certificate transparency.]]></description>
      <link>https://safeguard.sh/resources/blog/merkle-tree-in-transparency-logs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/merkle-tree-in-transparency-logs</guid>
      <pubDate>Wed, 04 Mar 2026 03:00:00 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Auto-Fix: Automated Vulnerability Remediation That Respects Your Codebase]]></title>
      <description><![CDATA[Auto-Fix generates pull requests that update vulnerable dependencies with compatibility checks, test validation, and rollback safety. Remediation at the speed of disclosure.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-auto-fix-automated-remediation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-auto-fix-automated-remediation</guid>
      <pubDate>Wed, 04 Mar 2026 02:52:03 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[rust crates.io Security Model Reviewed]]></title>
      <description><![CDATA[A look at how crates.io handles authentication, yanking, namespace squatting, and the supply chain risks that remain in mid-2024.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-crates-io-security-model-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-crates-io-security-model-review</guid>
      <pubDate>Wed, 04 Mar 2026 01:31:36 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is AI Model Supply Chain Security]]></title>
      <description><![CDATA[Model weights are executable artifacts, not data. Here's how AI model supply chain attacks work, from pickle exploits to weight tampering, and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-ai-model-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-ai-model-supply-chain-security</guid>
      <pubDate>Wed, 04 Mar 2026 01:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Nix Reproducible Builds: A Supply Chain Case]]></title>
      <description><![CDATA[Practical supply chain lessons from running Nix and Nix flakes in production, including flake.lock handling, content-addressed derivations, and cachix trust.]]></description>
      <link>https://safeguard.sh/resources/blog/nix-reproducible-builds-supply-chain-case</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nix-reproducible-builds-supply-chain-case</guid>
      <pubDate>Wed, 04 Mar 2026 00:11:09 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Certificate transparency log]]></title>
      <description><![CDATA[A concrete guide to certificate transparency logs: how SCTs verify issuance, how CT monitoring works, and how rogue certificates get detected fast.]]></description>
      <link>https://safeguard.sh/resources/blog/certificate-transparency-log</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/certificate-transparency-log</guid>
      <pubDate>Wed, 04 Mar 2026 00:00:00 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[GCP Workload Identity Federation: Supply Chain Uses]]></title>
      <description><![CDATA[How to use GCP Workload Identity Federation to eliminate long-lived service account keys from your supply chain: GitHub Actions, GitLab CI, external builders, and the misconfigurations that silently undermine the design.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-workload-identity-federation-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-workload-identity-federation-supply-chain</guid>
      <pubDate>Tue, 03 Mar 2026 22:50:43 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Mean Time to Remediation Benchmarks: How Fast Should You Be Patching?]]></title>
      <description><![CDATA[MTTR is the most important vulnerability management metric. But what is a good MTTR? Industry benchmarks, realistic targets, and strategies for improvement.]]></description>
      <link>https://safeguard.sh/resources/blog/mean-time-to-remediation-benchmarks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mean-time-to-remediation-benchmarks</guid>
      <pubDate>Tue, 03 Mar 2026 21:30:16 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to Run a Tabletop Exercise for a Supply Chain Breach]]></title>
      <description><![CDATA[A 90-minute tabletop built on a compromised dependency scenario will expose more gaps than a year of policy reviews. Here is the full agenda, injects included.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-run-a-tabletop-exercise-for-a-supply-chain-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-run-a-tabletop-exercise-for-a-supply-chain-breach</guid>
      <pubDate>Tue, 03 Mar 2026 20:09:49 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[ServiceNow CVE-2024-4879: Remote Code Execution via Jelly Template Injection]]></title>
      <description><![CDATA[Critical RCE vulnerabilities in ServiceNow were chained together for unauthenticated access, with active exploitation observed within days of disclosure.]]></description>
      <link>https://safeguard.sh/resources/blog/servicenow-cve-2024-4879-rce-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/servicenow-cve-2024-4879-rce-exploitation</guid>
      <pubDate>Tue, 03 Mar 2026 18:49:22 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Securing ML Model Serving Infrastructure]]></title>
      <description><![CDATA[Model serving infrastructure is a growing attack surface that most security teams overlook. From model poisoning to inference API abuse, here are the risks and how to address them.]]></description>
      <link>https://safeguard.sh/resources/blog/ml-model-serving-infrastructure-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ml-model-serving-infrastructure-security</guid>
      <pubDate>Tue, 03 Mar 2026 17:28:56 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What Is Authentication]]></title>
      <description><![CDATA[Authentication is how a system proves you are who you claim to be. Here is what it means, how it works, the factors involved, and why it is the foundation of every access decision.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-authentication</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-authentication</guid>
      <pubDate>Tue, 03 Mar 2026 16:08:29 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Semgrep vs CodeQL: SAST Comparison]]></title>
      <description><![CDATA[Compare Semgrep and CodeQL on rule authoring, language coverage, taint analysis, scan time, IDE integration, and pricing to choose the right SAST engine in 2024.]]></description>
      <link>https://safeguard.sh/resources/blog/semgrep-vs-codeql-sast-comparison-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/semgrep-vs-codeql-sast-comparison-2024</guid>
      <pubDate>Tue, 03 Mar 2026 14:48:02 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Maintainer Burnout: Security Implications]]></title>
      <description><![CDATA[Exhausted maintainers are not just a welfare problem. They are a security problem. Burnout is a precondition for social engineering, delayed patches, and hostile takeovers.]]></description>
      <link>https://safeguard.sh/resources/blog/maintainer-burnout-security-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maintainer-burnout-security-implications</guid>
      <pubDate>Tue, 03 Mar 2026 13:27:36 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Code Repository Security Hardening]]></title>
      <description><![CDATA[Your source code repository is the starting point of your entire supply chain. Hardening it against unauthorized access, code injection, and configuration tampering is non-negotiable.]]></description>
      <link>https://safeguard.sh/resources/blog/code-repository-security-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-repository-security-hardening</guid>
      <pubDate>Tue, 03 Mar 2026 12:07:09 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[RAG Poisoning In The Wild: Trend Watch]]></title>
      <description><![CDATA[Retrieval-augmented generation was the 2024 success story. 2026 is when RAG poisoning moved from research to production incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-trend-rag-poisoning-in-the-wild</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-trend-rag-poisoning-in-the-wild</guid>
      <pubDate>Tue, 03 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Transitive Fix Cascades: Griffin AI vs Mythos]]></title>
      <description><![CDATA[A vulnerable transitive dependency may require upgrading an ancestor. Griffin AI computes the cascade; Mythos-class tools often stop at the first level.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-transitive-fix-cascades</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-transitive-fix-cascades</guid>
      <pubDate>Tue, 03 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Trusted Publishing Across Every Major Registry: The 2026 State of OIDC-Backed Publishing]]></title>
      <description><![CDATA[By end of 2025, Trusted Publishing landed on PyPI, RubyGems, npm, crates.io, and NuGet. PyPI alone crossed one million Trusted-Publisher uploads. Here is the defender view of the cross-ecosystem rollout.]]></description>
      <link>https://safeguard.sh/resources/blog/sigstore-trusted-publishing-cross-ecosystem-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sigstore-trusted-publishing-cross-ecosystem-2026</guid>
      <pubDate>Tue, 03 Mar 2026 12:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA and the Software Supply Chain in 2026]]></title>
      <description><![CDATA[The HIPAA Security Rule has not changed, but OCR enforcement and the 2024 NPRM are reshaping what supply chain controls covered entities and business associates must demonstrate.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-software-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-software-supply-chain-2026</guid>
      <pubDate>Tue, 03 Mar 2026 11:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Go Checksum Verification Patterns]]></title>
      <description><![CDATA[go.sum and the Go checksum database are among the most rigorous integrity mechanisms in any language ecosystem, and the verification patterns around them deserve to be understood and used well.]]></description>
      <link>https://safeguard.sh/resources/blog/go-checksum-verification-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-checksum-verification-patterns</guid>
      <pubDate>Tue, 03 Mar 2026 10:46:42 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to Comply With EU CRA: A Practical Checklist]]></title>
      <description><![CDATA[The EU Cyber Resilience Act requires vendors to ship secure-by-default products, provide SBOMs, and report exploited vulnerabilities within 24 hours. Here is a concrete compliance path.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-comply-eu-cyber-resilience-act-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-comply-eu-cyber-resilience-act-checklist</guid>
      <pubDate>Tue, 03 Mar 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Minimal Base Image Myth: What Actually Reduces Attack Surface]]></title>
      <description><![CDATA[Alpine, distroless, and scratch images don't automatically cut risk. The real attack-surface drivers are capabilities, root filesystem, network policies, and seccomp.]]></description>
      <link>https://safeguard.sh/resources/blog/minimal-base-image-myth-attack-surface-reduction</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/minimal-base-image-myth-attack-surface-reduction</guid>
      <pubDate>Tue, 03 Mar 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Model Context Protocol (MCP) Security]]></title>
      <description><![CDATA[MCP security explained: how tool poisoning, rug pulls, and 2025's critical CVEs (mcp-remote, MCP Inspector) put AI agents at risk—and how to defend against them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-model-context-protocol-mcp-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-model-context-protocol-mcp-security</guid>
      <pubDate>Tue, 03 Mar 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[FastAPI Supply Chain Security: A Working Guide]]></title>
      <description><![CDATA[FastAPI's dependency surface is deceptively large. Here is how to lock it down in practice, covering Starlette, Pydantic, Uvicorn, and the plugins you likely missed.]]></description>
      <link>https://safeguard.sh/resources/blog/fastapi-supply-chain-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fastapi-supply-chain-security-guide</guid>
      <pubDate>Tue, 03 Mar 2026 09:26:16 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[npm Protestware Patterns From 2020 to 2026]]></title>
      <description><![CDATA[A senior engineer's view of six years of npm protestware, from colors.js to peacenotwar, and the supply chain lessons that still apply to modern JavaScript shops.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-protestware-patterns-2020-to-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-protestware-patterns-2020-to-2026</guid>
      <pubDate>Tue, 03 Mar 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Right-to-Repair and Software Supply Chain Security]]></title>
      <description><![CDATA[How the right-to-repair movement is reshaping software supply chain obligations in 2026, from firmware transparency to the security implications of mandated component access.]]></description>
      <link>https://safeguard.sh/resources/blog/right-to-repair-software-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/right-to-repair-software-supply-chain-security</guid>
      <pubDate>Tue, 03 Mar 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Typosquatting packages]]></title>
      <description><![CDATA[What is typosquatting? A precise breakdown of package typosquatting attacks, real npm and PyPI examples, and how lookalike malicious packages slip into builds.]]></description>
      <link>https://safeguard.sh/resources/blog/typosquatting-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/typosquatting-packages</guid>
      <pubDate>Tue, 03 Mar 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[GitLab Ultimate Security Buyer Review 2026]]></title>
      <description><![CDATA[GitLab bundles SAST, SCA, container scanning, and DAST into the Ultimate tier. Is the integrated story worth the premium over best-of-breed tools? An honest review.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-ultimate-security-buyer-review-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-ultimate-security-buyer-review-2026</guid>
      <pubDate>Tue, 03 Mar 2026 08:45:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[bundler-audit Production Setup]]></title>
      <description><![CDATA[A practical guide to running bundler-audit in production CI pipelines, including advisory database updates, exception handling, and integration with remediation workflows.]]></description>
      <link>https://safeguard.sh/resources/blog/bundler-audit-production-setup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bundler-audit-production-setup</guid>
      <pubDate>Tue, 03 Mar 2026 08:05:49 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is AI Agent Security]]></title>
      <description><![CDATA[AI agent security explained: how autonomous AI agents get attacked through prompt injection, tool poisoning, and exposed MCP servers, and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-ai-agent-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-ai-agent-security</guid>
      <pubDate>Tue, 03 Mar 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SCA vs SAST vs DAST: Which Do You Actually Need First]]></title>
      <description><![CDATA[Three scanner acronyms, one budget. A spec-level comparison of SCA, SAST, and DAST — what each catches, what each costs to run, and the order that pays off fastest.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-vs-sast-vs-dast-which-do-you-actually-need-first</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-vs-sast-vs-dast-which-do-you-actually-need-first</guid>
      <pubDate>Tue, 03 Mar 2026 06:45:22 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Marcus Webb)</author>
    </item>
    <item>
      <title><![CDATA[CycloneDX]]></title>
      <description><![CDATA[CycloneDX is the OWASP-backed SBOM standard for tracking software components, vulnerabilities, and VEX statements. Here's what is CycloneDX and how it compares to SPDX.]]></description>
      <link>https://safeguard.sh/resources/blog/cyclonedx</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyclonedx</guid>
      <pubDate>Tue, 03 Mar 2026 06:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard SCA: Vulnerability Scanning Built for the Supply Chain]]></title>
      <description><![CDATA[Safeguard SCA goes beyond basic CVE matching with multi-source intelligence, version-range precision, and exploitability context that cuts through vulnerability noise.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-sca-vulnerability-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-sca-vulnerability-scanning</guid>
      <pubDate>Tue, 03 Mar 2026 05:24:56 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[regreSSHion: CVE-2024-6387 OpenSSH Remote Code Execution]]></title>
      <description><![CDATA[A regression in OpenSSH's signal handler reintroduced a vulnerability from 2006, enabling unauthenticated remote code execution on glibc-based Linux systems. Here's what you need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/regresshion-openssh-cve-2024-6387</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/regresshion-openssh-cve-2024-6387</guid>
      <pubDate>Tue, 03 Mar 2026 04:04:29 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Risks of AI-Generated Code]]></title>
      <description><![CDATA[AI coding assistants now write nearly half of some codebases—and research shows 45% of that code ships with exploitable flaws. Here's what security teams need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/risks-of-ai-generated-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/risks-of-ai-generated-code</guid>
      <pubDate>Tue, 03 Mar 2026 04:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[SPDX]]></title>
      <description><![CDATA[What is SPDX? A plain-English guide to the ISO-standard SBOM and license format that documents what's really inside your software.]]></description>
      <link>https://safeguard.sh/resources/blog/spdx</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spdx</guid>
      <pubDate>Tue, 03 Mar 2026 03:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Retail POS Supply Chain Security]]></title>
      <description><![CDATA[Practical controls and standards shaping point-of-sale software supply chains, from PCI DSS 4.0 to PA-DSS successors and retailer-specific frameworks.]]></description>
      <link>https://safeguard.sh/resources/blog/retail-pos-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/retail-pos-supply-chain-security</guid>
      <pubDate>Tue, 03 Mar 2026 02:44:02 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Azure Policy for Supply Chain Enforcement]]></title>
      <description><![CDATA[Azure Policy is the enforcement layer most Azure platforms underuse. A concrete, policy-by-policy guide to wiring it into supply chain controls that actually stick.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-policy-supply-chain-enforcement</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-policy-supply-chain-enforcement</guid>
      <pubDate>Tue, 03 Mar 2026 01:23:35 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is Vibe Coding (and Its Security Risks)]]></title>
      <description><![CDATA[Vibe coding lets AI write entire apps from a prompt with little human review — here's what it is, real incidents it's caused, and how to detect the risk.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-vibe-coding-and-its-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-vibe-coding-and-its-security-risks</guid>
      <pubDate>Tue, 03 Mar 2026 01:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[in-toto Attestation Formats Reviewed]]></title>
      <description><![CDATA[The in-toto attestation framework is the plumbing under SLSA, Sigstore, and most supply chain tooling. Here is a practical review of the v1 formats and their edges.]]></description>
      <link>https://safeguard.sh/resources/blog/in-toto-attestation-formats-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/in-toto-attestation-formats-review</guid>
      <pubDate>Tue, 03 Mar 2026 00:03:09 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Build provenance]]></title>
      <description><![CDATA[What is build provenance and why does it matter? A practical guide to SLSA attestations, provenance predicates, and verification pipelines for software supply chains.]]></description>
      <link>https://safeguard.sh/resources/blog/build-provenance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/build-provenance</guid>
      <pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Firecracker micro-VM Security Model]]></title>
      <description><![CDATA[AWS built Firecracker to run Lambda. The security model is the entire value proposition, and it holds up under scrutiny.]]></description>
      <link>https://safeguard.sh/resources/blog/firecracker-micro-vm-security-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/firecracker-micro-vm-security-model</guid>
      <pubDate>Mon, 02 Mar 2026 22:42:42 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AWS Secrets Manager vs Parameter Store]]></title>
      <description><![CDATA[Two AWS services, overlapping features, and a pricing difference that adds up to real money. The decision framework for Secrets Manager vs Parameter Store, based on what actually goes wrong in production.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-secrets-manager-vs-parameter-store-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-secrets-manager-vs-parameter-store-comparison</guid>
      <pubDate>Mon, 02 Mar 2026 21:22:15 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Microsoft Midnight Blizzard: Detailed Timeline]]></title>
      <description><![CDATA[A reconstructed public timeline of Microsoft's Midnight Blizzard intrusion, from the initial password spray in November 2023 through the source code and federal agency disclosures.]]></description>
      <link>https://safeguard.sh/resources/blog/microsoft-midnight-blizzard-detailed-timeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microsoft-midnight-blizzard-detailed-timeline</guid>
      <pubDate>Mon, 02 Mar 2026 20:01:49 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 Meets NIST CSF: Integration]]></title>
      <description><![CDATA[Running an ISMS under ISO 27001:2022 while executives want NIST CSF 2.0 reporting? These frameworks integrate cleanly if you map Annex A controls to CSF subcategories once and stop duplicating work.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-meets-nist-csf-integration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-meets-nist-csf-integration</guid>
      <pubDate>Mon, 02 Mar 2026 18:41:22 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Commercial OSS License Shifts: An Analysis]]></title>
      <description><![CDATA[From MongoDB to HashiCorp, commercial open source vendors have repeatedly relicensed away from OSI-approved licenses. The pattern reveals a fundamental tension between sustainability and freedom.]]></description>
      <link>https://safeguard.sh/resources/blog/commercial-open-source-license-shift-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/commercial-open-source-license-shift-analysis</guid>
      <pubDate>Mon, 02 Mar 2026 17:20:55 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[ArgoCD GitOps Security Depth]]></title>
      <description><![CDATA[A deep look at ArgoCD security in production: RBAC models, repo credentials, ApplicationSet risks, and the CVEs that have shaped the current hardening defaults.]]></description>
      <link>https://safeguard.sh/resources/blog/argocd-gitops-security-depth</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/argocd-gitops-security-depth</guid>
      <pubDate>Mon, 02 Mar 2026 16:00:29 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Polyfill.io Supply Chain Attack: When a CDN Domain Changes Hands]]></title>
      <description><![CDATA[A Chinese company acquired the polyfill.io domain and began injecting malicious code into websites that relied on the CDN, affecting over 100,000 sites. The attack exploited trust in third-party JavaScript.]]></description>
      <link>https://safeguard.sh/resources/blog/polyfill-io-supply-chain-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/polyfill-io-supply-chain-attack</guid>
      <pubDate>Mon, 02 Mar 2026 14:40:02 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA and Third-Party Software Components: A Developer Guide]]></title>
      <description><![CDATA[HIPAA never mentions npm, but a vulnerable dependency in an ePHI system is a Security Rule problem. How risk analysis, patching, and BAAs map to your dependency tree.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-and-third-party-software-components-a-developer-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-and-third-party-software-components-a-developer-guide</guid>
      <pubDate>Mon, 02 Mar 2026 13:19:35 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Raman)</author>
    </item>
    <item>
      <title><![CDATA[Azure Confidential VM Attestation in a Supply Chain Pipeline]]></title>
      <description><![CDATA[Confidential VMs on Azure protect workloads in use, but the attestation flow is where their value gets unlocked. We trace how to wire it into a build and deploy pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-confidential-vm-attestation-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-confidential-vm-attestation-2026</guid>
      <pubDate>Mon, 02 Mar 2026 12:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[EU AI Act Alignment: Griffin AI vs Mythos]]></title>
      <description><![CDATA[EU AI Act enforcement began in 2026. Vendors sold as &quot;AI security tools&quot; are now high-risk systems with documentation obligations. The shape of the documentation matters.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-eu-ai-act-alignment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-eu-ai-act-alignment</guid>
      <pubDate>Mon, 02 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Version-Aware Resolution: Griffin AI vs Mythos]]></title>
      <description><![CDATA[A vulnerability in version 1.2.0 may not affect your 1.3.5 install if the fix reshaped the call signature. Version-aware resolution is where deterministic engines beat pure-LLM heuristics.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-version-aware-resolution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-version-aware-resolution</guid>
      <pubDate>Mon, 02 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[PyPI API Token Scopes: An Audit Guide]]></title>
      <description><![CDATA[PyPI API tokens look simple, but how you scope them decides whether a leaked CI secret is a bad day or an ecosystem event. A practical audit guide for security teams.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-api-token-scopes-audit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-api-token-scopes-audit</guid>
      <pubDate>Mon, 02 Mar 2026 11:59:09 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Confusion: Attack Evolution from 2022 to 2026]]></title>
      <description><![CDATA[Alex Birsan's 2021 disclosure named a class of attacks. Four years on, dependency confusion has evolved across registries, tooling, and victim profiles.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-confusion-attack-evolution-2022-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-confusion-attack-evolution-2022-2026</guid>
      <pubDate>Mon, 02 Mar 2026 11:15:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[NuGet Central Package Management Security]]></title>
      <description><![CDATA[Central Package Management pulled NuGet's multi-project version chaos into a single source of truth. The security implications run deeper than the ergonomics suggest.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-central-package-management-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-central-package-management-security</guid>
      <pubDate>Mon, 02 Mar 2026 10:38:42 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[JetBrains Plugin Security in 2026]]></title>
      <description><![CDATA[JetBrains IDEs have a smaller plugin ecosystem than VS Code, but the security model is similar and the risks rhyme. Here is what to watch in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/jetbrains-plugin-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jetbrains-plugin-security-2026</guid>
      <pubDate>Mon, 02 Mar 2026 10:15:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Nullcon Berlin 2026 Supply Chain Highlights]]></title>
      <description><![CDATA[Nullcon Berlin 2026 delivered a dense European view of software supply chain research. Here are the themes and sessions that mattered most to defenders.]]></description>
      <link>https://safeguard.sh/resources/blog/nullcon-berlin-2026-software-supply-chain-highlights</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nullcon-berlin-2026-software-supply-chain-highlights</guid>
      <pubDate>Mon, 02 Mar 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard vs GitHub Advanced Security 2026]]></title>
      <description><![CDATA[A technical comparison of Safeguard and GitHub Advanced Security in 2026 across scanning depth, secret detection, container coverage, and cost.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-vs-github-advanced-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-vs-github-advanced-security-2026</guid>
      <pubDate>Mon, 02 Mar 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Training Data Poisoning]]></title>
      <description><![CDATA[Training data poisoning corrupts an ML model's training data to plant hidden backdoors. Learn how it works, real incidents, and how to detect it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-training-data-poisoning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-training-data-poisoning</guid>
      <pubDate>Mon, 02 Mar 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[GN and Meson Build Systems: Security]]></title>
      <description><![CDATA[A side-by-side security comparison of GN (Chromium) and Meson, covering declarative posture, wrap files, toolchain handling, and supply chain behavior.]]></description>
      <link>https://safeguard.sh/resources/blog/gn-meson-build-system-security-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gn-meson-build-system-security-comparison</guid>
      <pubDate>Mon, 02 Mar 2026 09:18:15 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to Audit Open Source Licenses for Compliance]]></title>
      <description><![CDATA[A senior engineer's playbook for auditing open source licenses across modern polyglot repos, from SPDX extraction to enforcement in CI and legal reporting.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-audit-open-source-licenses-compliance-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-audit-open-source-licenses-compliance-guide</guid>
      <pubDate>Mon, 02 Mar 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[in-toto Attestation Framework Walkthrough 2026]]></title>
      <description><![CDATA[A working engineer's tour of in-toto in 2026: layouts, links, the attestation predicate ecosystem, and how it composes with SLSA, sigstore, and SBOMs.]]></description>
      <link>https://safeguard.sh/resources/blog/in-toto-attestation-framework-walkthrough-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/in-toto-attestation-framework-walkthrough-2026</guid>
      <pubDate>Mon, 02 Mar 2026 09:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Open Source Manager: A Deep Dive Into Dependency Governance]]></title>
      <description><![CDATA[An inside look at Safeguard's Open Source Manager — how it tracks, evaluates, and enforces policies across every open-source dependency in your portfolio.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-open-source-manager-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-open-source-manager-deep-dive</guid>
      <pubDate>Mon, 02 Mar 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Requirements for Automotive (ISO 21434) 2026]]></title>
      <description><![CDATA[A senior engineer's guide to SBOM requirements for automotive suppliers under ISO/SAE 21434, UNECE WP.29 R155, and the 2026 enforcement landscape for connected vehicles.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-requirements-automotive-iso-21434-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-requirements-automotive-iso-21434-2026</guid>
      <pubDate>Mon, 02 Mar 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Slopsquatting (AI package hallucination attack)]]></title>
      <description><![CDATA[Slopsquatting exploits AI coding assistants that hallucinate nonexistent package names, which attackers then register as real, malicious packages.]]></description>
      <link>https://safeguard.sh/resources/blog/slopsquatting-ai-package-hallucination-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slopsquatting-ai-package-hallucination-attack</guid>
      <pubDate>Mon, 02 Mar 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Volt Typhoon: Critical Infrastructure Supply Chain]]></title>
      <description><![CDATA[Volt Typhoon is pre-positioning inside U.S. critical infrastructure using living-off-the-land tradecraft and third-party access. Here is what defenders should do about it.]]></description>
      <link>https://safeguard.sh/resources/blog/volt-typhoon-critical-infrastructure-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/volt-typhoon-critical-infrastructure-supply-chain</guid>
      <pubDate>Mon, 02 Mar 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[JFrog Xray Deployment Blueprint 2026]]></title>
      <description><![CDATA[A pragmatic blueprint for deploying JFrog Xray in 2026: indexing strategy, watch policies, build promotion gates, and the operational pitfalls to avoid.]]></description>
      <link>https://safeguard.sh/resources/blog/jfrog-xray-deployment-blueprint-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jfrog-xray-deployment-blueprint-2026</guid>
      <pubDate>Mon, 02 Mar 2026 08:45:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The OSV Vulnerability Database API Cookbook]]></title>
      <description><![CDATA[Practical patterns for using the OSV.dev API in production: batch queries, schema gotchas, version range parsing, and how to integrate OSV data into your own vulnerability pipelines.]]></description>
      <link>https://safeguard.sh/resources/blog/osv-vulnerability-database-api-cookbook</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/osv-vulnerability-database-api-cookbook</guid>
      <pubDate>Mon, 02 Mar 2026 08:45:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Alpine vs Distroless vs Ubuntu Base Images: Security Tradeoffs]]></title>
      <description><![CDATA[Alpine is small, distroless is smaller, Ubuntu is comfortable. The real security question is CVE surface vs debuggability vs compatibility — with numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/alpine-vs-distroless-vs-ubuntu-base-images-security-tradeoffs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/alpine-vs-distroless-vs-ubuntu-base-images-security-tradeoffs</guid>
      <pubDate>Mon, 02 Mar 2026 08:00:00 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Marcus Webb)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Management at Enterprise Scale: What Actually Works]]></title>
      <description><![CDATA[Managing vulnerabilities across thousands of applications and millions of dependencies requires fundamentally different approaches than what works for a single team. Here is what scales.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-management-at-scale-enterprise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-management-at-scale-enterprise</guid>
      <pubDate>Mon, 02 Mar 2026 07:57:48 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is a Model Inversion Attack]]></title>
      <description><![CDATA[Model inversion attacks reconstruct sensitive training data from a model's outputs. Learn how they work, real cases, and how to defend your ML APIs.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-model-inversion-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-model-inversion-attack</guid>
      <pubDate>Mon, 02 Mar 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm Package Takeover: The Summer 2024 Wave]]></title>
      <description><![CDATA[Between May and June 2024 at least 36 npm packages were hijacked via expired maintainer domains and leaked tokens. We map the cluster.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-package-takeover-summer-2024-wave</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-package-takeover-summer-2024-wave</guid>
      <pubDate>Mon, 02 Mar 2026 06:37:22 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SPIFFE/SPIRE identity]]></title>
      <description><![CDATA[What is SPIFFE/SPIRE? A plain-language breakdown of the SPIFFE identity framework, SPIRE workload identity, SVIDs, and how it compares to plain mTLS.]]></description>
      <link>https://safeguard.sh/resources/blog/spiffespire-identity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spiffespire-identity</guid>
      <pubDate>Mon, 02 Mar 2026 06:00:00 GMT</pubDate>
      <category>Identity Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Migrating From Ansible to GitOps: A Supply Chain Perspective]]></title>
      <description><![CDATA[Move from Ansible to GitOps with supply chain security intact. Pattern-by-pattern migration, trust boundary changes, and pitfalls to avoid in the transition.]]></description>
      <link>https://safeguard.sh/resources/blog/migrating-off-ansible-to-gitops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/migrating-off-ansible-to-gitops</guid>
      <pubDate>Mon, 02 Mar 2026 05:16:55 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Adversarial Machine Learning]]></title>
      <description><![CDATA[Adversarial machine learning exploits model decision boundaries via evasion, poisoning, extraction, and inference attacks -- here's how it works and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-adversarial-machine-learning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-adversarial-machine-learning</guid>
      <pubDate>Mon, 02 Mar 2026 04:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Malicious Package Quarantine Procedures]]></title>
      <description><![CDATA[How to quarantine a malicious package across your registries, caches, and running systems without breaking every developer's workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-package-quarantine-procedures</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-package-quarantine-procedures</guid>
      <pubDate>Mon, 02 Mar 2026 03:56:28 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SVID (SPIFFE Verifiable Identity Document)]]></title>
      <description><![CDATA[An SVID (SPIFFE Verifiable Identity Document) is a cryptographic identity for software workloads. Learn what an SVID is, its X.509 and JWT formats, and how it works.]]></description>
      <link>https://safeguard.sh/resources/blog/svid-spiffe-verifiable-identity-document</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/svid-spiffe-verifiable-identity-document</guid>
      <pubDate>Mon, 02 Mar 2026 03:00:00 GMT</pubDate>
      <category>Identity Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[What is Red Teaming]]></title>
      <description><![CDATA[Red teaming emulates a real adversary to test not just your defenses but your ability to detect and respond. Here's how it works and how it differs from a pentest.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-red-teaming</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-red-teaming</guid>
      <pubDate>Mon, 02 Mar 2026 02:36:02 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Software License Types: The Complete Guide]]></title>
      <description><![CDATA[Permissive, copyleft, proprietary, and public domain: how the main software license types differ, what each one obligates you to do, and how to pick one for your project.]]></description>
      <link>https://safeguard.sh/resources/blog/software-license-types-complete-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-license-types-complete-guide</guid>
      <pubDate>Mon, 02 Mar 2026 01:15:35 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Insecure Output Handling in LLMs]]></title>
      <description><![CDATA[Insecure output handling lets LLM-generated text execute code, alter queries, or render unsanitized HTML — a real, exploitable OWASP LLM05:2025 risk.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-insecure-output-handling-in-llms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-insecure-output-handling-in-llms</guid>
      <pubDate>Mon, 02 Mar 2026 01:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-21413 Outlook Moniker Link Analysis]]></title>
      <description><![CDATA[CVE-2024-21413 is a critical Outlook Moniker Link RCE that bypasses Protected View via a crafted file URL. Root cause, exploitation, and detection.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-21413-outlook-moniker-link-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-21413-outlook-moniker-link-analysis</guid>
      <pubDate>Mon, 02 Mar 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-55956 Cleo Harmony/VLTrader RCE]]></title>
      <description><![CDATA[Cleo's Harmony, VLTrader, and LexiCom carried an unauthenticated RCE that Clop abused for mass data theft. Here is the technical breakdown and the defender's takeaway.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-55956-cleo-harmony-vltrader-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-55956-cleo-harmony-vltrader-rce</guid>
      <pubDate>Mon, 02 Mar 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[mTLS (mutual TLS)]]></title>
      <description><![CDATA[What is mTLS? A precise breakdown of mutual TLS authentication, how it differs from standard TLS, why service meshes depend on it, and how to handle certificate rotation.]]></description>
      <link>https://safeguard.sh/resources/blog/mtls-mutual-tls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mtls-mutual-tls</guid>
      <pubDate>Mon, 02 Mar 2026 00:00:00 GMT</pubDate>
      <category>Identity Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[The Middle East Cybersecurity Landscape: Rapid Digitization Meets Rising Threats]]></title>
      <description><![CDATA[The Middle East is investing heavily in digital transformation, but the cybersecurity infrastructure is not keeping pace. A look at the threat landscape, regulatory evolution, and supply chain risks across the region.]]></description>
      <link>https://safeguard.sh/resources/blog/middle-east-cybersecurity-landscape-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/middle-east-cybersecurity-landscape-2024</guid>
      <pubDate>Sun, 01 Mar 2026 23:55:08 GMT</pubDate>
      <category>Regional Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[The SnakeYAML Deserialization Vulnerability, Explained]]></title>
      <description><![CDATA[SnakeYAML's default Constructor could instantiate arbitrary Java classes from YAML input — CVE-2022-1471 turned a config-parsing library into a remote code execution path.]]></description>
      <link>https://safeguard.sh/resources/blog/snakeyaml-deserialization-vulnerability-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snakeyaml-deserialization-vulnerability-explained</guid>
      <pubDate>Sun, 01 Mar 2026 22:34:42 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Payment Processor Dependency Risks]]></title>
      <description><![CDATA[The libraries and services that sit between a merchant and the card networks carry concentrated risk. A practical look at what goes wrong, and how to build a dependency program that catches it.]]></description>
      <link>https://safeguard.sh/resources/blog/payment-processor-dependency-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/payment-processor-dependency-risks</guid>
      <pubDate>Sun, 01 Mar 2026 21:14:15 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Go Module Hijacking Detection]]></title>
      <description><![CDATA[Module hijacking in Go is rare compared to npm, but it does happen, and the patterns worth watching are different from what you might expect from other ecosystems.]]></description>
      <link>https://safeguard.sh/resources/blog/go-module-hijacking-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-module-hijacking-detection</guid>
      <pubDate>Sun, 01 Mar 2026 19:53:48 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2021-29425: The Commons IO Path Traversal Bug]]></title>
      <description><![CDATA[CVE-2021-29425 shows how a single unhandled case in Apache Commons IO's path normalization let attackers slip past directory checks that assumed a canonicalized path was actually safe.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2021-29425-commons-io-path-traversal</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2021-29425-commons-io-path-traversal</guid>
      <pubDate>Sun, 01 Mar 2026 18:33:22 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Licenses Explained: A Practical Primer]]></title>
      <description><![CDATA[Open source licenses explained for engineers who need to make a compliance call today, not read a legal treatise — permissive, copyleft, and what actually changes your obligations.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-licenses-explained-a-practical-primer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-licenses-explained-a-practical-primer</guid>
      <pubDate>Sun, 01 Mar 2026 17:12:55 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[DevEx Meets DevSecOps: Why Developer Experience Determines Security Outcomes]]></title>
      <description><![CDATA[Security tools that developers hate get bypassed. The organizations with the best security outcomes are the ones that treat developer experience as a security requirement.]]></description>
      <link>https://safeguard.sh/resources/blog/devex-meets-devsecops-developer-experience</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devex-meets-devsecops-developer-experience</guid>
      <pubDate>Sun, 01 Mar 2026 15:52:28 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Clop: Supply Chain Exploitation Tradecraft]]></title>
      <description><![CDATA[Clop has turned supply chain exploitation into a repeatable playbook — MOVEit, GoAnywhere, Cleo. A look at the tradecraft that makes the campaign work.]]></description>
      <link>https://safeguard.sh/resources/blog/clop-supply-chain-exploitation-tradecraft</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/clop-supply-chain-exploitation-tradecraft</guid>
      <pubDate>Sun, 01 Mar 2026 14:32:01 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AWS CodePipeline Hardening Patterns]]></title>
      <description><![CDATA[CodePipeline is the glue between your source, build, and deploy. It is also the thing that gets the widest IAM role in most AWS accounts. Here is how to harden it without rewriting your pipelines.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-codepipeline-hardening-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-codepipeline-hardening-patterns</guid>
      <pubDate>Sun, 01 Mar 2026 13:11:35 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CloudFormation, Bicep, Terraform Supply Chain Evidence]]></title>
      <description><![CDATA[IaC frameworks differ in how they generate supply chain evidence. This is the 2026 guide to audit-ready proof from CloudFormation, Bicep, and Terraform.]]></description>
      <link>https://safeguard.sh/resources/blog/cloudformation-bicep-terraform-supply-chain-evidence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloudformation-bicep-terraform-supply-chain-evidence</guid>
      <pubDate>Sun, 01 Mar 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Government AI Procurement Supply Chain Overlap]]></title>
      <description><![CDATA[Government AI procurement rules are colliding with software supply chain requirements. Here is how to navigate the overlap without doubling the workload.]]></description>
      <link>https://safeguard.sh/resources/blog/government-ai-procurement-supply-chain-overlap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/government-ai-procurement-supply-chain-overlap</guid>
      <pubDate>Sun, 01 Mar 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Inventory: Griffin AI vs Mythos]]></title>
      <description><![CDATA[MCP servers are privileged dependencies. An inventory that tracks them like SBOM tracks packages is the minimum bar — and not every tool meets it.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-mcp-server-inventory</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-mcp-server-inventory</guid>
      <pubDate>Sun, 01 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Guardrails As An Incident Prevention System]]></title>
      <description><![CDATA[Detection and response cannot scale if the prevention layer is missing. Guardrails turn the lessons of past incidents into the policy that prevents the next one.]]></description>
      <link>https://safeguard.sh/resources/blog/guardrails-as-an-incident-prevention-system</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/guardrails-as-an-incident-prevention-system</guid>
      <pubDate>Sun, 01 Mar 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Nation-State Supply Chain Tradecraft Update]]></title>
      <description><![CDATA[Nation-state supply chain tradecraft has evolved sharply since SolarWinds. We trace the 2025 to 2026 patterns, the operational signatures, and defensive implications.]]></description>
      <link>https://safeguard.sh/resources/blog/nation-state-supply-chain-tradecraft-2025-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nation-state-supply-chain-tradecraft-2025-2026</guid>
      <pubDate>Sun, 01 Mar 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SLO-Driven Vulnerability Management Program]]></title>
      <description><![CDATA[Service-level objectives turn vulnerability management from heroics into a measurable program. Here is how to define SLOs that survive contact with reality.]]></description>
      <link>https://safeguard.sh/resources/blog/slo-driven-vulnerability-management-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slo-driven-vulnerability-management-program</guid>
      <pubDate>Sun, 01 Mar 2026 12:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Zero-Day Discovery ROI: CISO Board Deck]]></title>
      <description><![CDATA[How to talk to your board about zero-day discovery without overpromising. The metrics, the framing, and the slides that hold up under follow-up questions.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-day-discovery-roi-for-ciso-board-deck</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-day-discovery-roi-for-ciso-board-deck</guid>
      <pubDate>Sun, 01 Mar 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard IDE Extension: Supply Chain Intelligence in Your Editor]]></title>
      <description><![CDATA[The Safeguard VS Code extension surfaces vulnerability data, dependency health, and policy violations directly in your editor as you write code.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-ide-extension-launch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-ide-extension-launch</guid>
      <pubDate>Sun, 01 Mar 2026 11:51:08 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Elastic Security Supply Chain Signals]]></title>
      <description><![CDATA[How to surface software supply chain threats in Elastic Security using EQL, detection rules, and the Elastic Common Schema for build pipeline and registry events.]]></description>
      <link>https://safeguard.sh/resources/blog/elastic-security-supply-chain-signals</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/elastic-security-supply-chain-signals</guid>
      <pubDate>Sun, 01 Mar 2026 10:30:41 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Container Runtime Security in 2026: What's Changed and What Hasn't]]></title>
      <description><![CDATA[Container security has matured significantly, but runtime protection remains a weak spot. Here's a practical guide to what works.]]></description>
      <link>https://safeguard.sh/resources/blog/container-runtime-security-2026-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-runtime-security-2026-guide</guid>
      <pubDate>Sun, 01 Mar 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is Sensitive Information Disclosure in LLMs]]></title>
      <description><![CDATA[LLM sensitive information disclosure leaks training data, prompts, and secrets through model outputs. Real incidents, causes, and defenses explained.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-sensitive-information-disclosure-in-llms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-sensitive-information-disclosure-in-llms</guid>
      <pubDate>Sun, 01 Mar 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[XZ Utils Backdoor: One Year Retrospective]]></title>
      <description><![CDATA[A year after the XZ Utils backdoor was caught by Andres Freund at Microsoft, what did we fix, what did we ignore, and what still gets packaged into Linux distros?]]></description>
      <link>https://safeguard.sh/resources/blog/xz-utils-aftermath-one-year-retrospective</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xz-utils-aftermath-one-year-retrospective</guid>
      <pubDate>Sun, 01 Mar 2026 10:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Bundler Lockfile Security Practices]]></title>
      <description><![CDATA[How to use Gemfile.lock as a real security artifact: checksums, frozen mode, reproducible resolves, and what changed in Bundler 2.5's expanded lockfile format.]]></description>
      <link>https://safeguard.sh/resources/blog/bundler-lockfile-security-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bundler-lockfile-security-practices</guid>
      <pubDate>Sun, 01 Mar 2026 09:10:15 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Cloudflare Workers: Supply Chain Threat Model]]></title>
      <description><![CDATA[Cloudflare Workers collapse the build, deploy, and runtime into one surface. That changes the supply chain threat model in ways most teams underestimate.]]></description>
      <link>https://safeguard.sh/resources/blog/cloudflare-workers-supply-chain-threat-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloudflare-workers-supply-chain-threat-model</guid>
      <pubDate>Sun, 01 Mar 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[OIDC (OpenID Connect)]]></title>
      <description><![CDATA[A precise technical answer to "what is OIDC": how OpenID Connect extends OAuth 2.0 with ID tokens, federated identity, and token exchange to secure modern authentication.]]></description>
      <link>https://safeguard.sh/resources/blog/oidc-openid-connect</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oidc-openid-connect</guid>
      <pubDate>Sun, 01 Mar 2026 09:00:00 GMT</pubDate>
      <category>Identity Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[npm Workspaces Security Considerations]]></title>
      <description><![CDATA[Workspaces are fantastic for developer experience and hostile to naive security tooling. Here is what actually changes when you flip them on.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-workspaces-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-workspaces-security-considerations</guid>
      <pubDate>Sun, 01 Mar 2026 07:49:48 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Gramm-Leach-Bliley Software Security Update]]></title>
      <description><![CDATA[The FTC Safeguards Rule amendments effective May 13, 2024 expand breach-notification and software supply chain expectations for financial institutions under GLBA.]]></description>
      <link>https://safeguard.sh/resources/blog/gramm-leach-bliley-software-security-update-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gramm-leach-bliley-software-security-update-2024</guid>
      <pubDate>Sun, 01 Mar 2026 06:29:21 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Workload identity federation]]></title>
      <description><![CDATA[What is workload identity federation? A precise breakdown of keyless cloud authentication, GitHub Actions OIDC, and short-lived credentials replacing static API keys.]]></description>
      <link>https://safeguard.sh/resources/blog/workload-identity-federation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/workload-identity-federation</guid>
      <pubDate>Sun, 01 Mar 2026 06:00:00 GMT</pubDate>
      <category>Identity Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[SSRF Examples and How They're Actually Exploited]]></title>
      <description><![CDATA[Real SSRF examples, from cloud metadata theft to internal port scanning, showing exactly how a server-side request forgery bug gets turned into a full compromise.]]></description>
      <link>https://safeguard.sh/resources/blog/ssrf-examples-and-how-they-are-exploited</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ssrf-examples-and-how-they-are-exploited</guid>
      <pubDate>Sun, 01 Mar 2026 05:08:55 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is AI Governance]]></title>
      <description><![CDATA[AI governance means the policies and technical controls that keep AI models, data, and agents safe, compliant, and auditable across your software supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-ai-governance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-ai-governance</guid>
      <pubDate>Sun, 01 Mar 2026 04:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Meaning: Definition, Model, and How It Differs From SecDevOps]]></title>
      <description><![CDATA[DevSecOps means making security a shared, automated responsibility inside the DevOps loop. Here is the working definition, the operating model, and why the SecDevOps naming debate mostly misses the point.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-meaning-definition-vs-secdevops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-meaning-definition-vs-secdevops</guid>
      <pubDate>Sun, 01 Mar 2026 03:48:28 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[JWT (JSON Web Token)]]></title>
      <description><![CDATA[A JWT (JSON Web Token) is a compact, signed token used to prove identity and claims between systems. Here's how they work, and where they break.]]></description>
      <link>https://safeguard.sh/resources/blog/jwt-json-web-token</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jwt-json-web-token</guid>
      <pubDate>Sun, 01 Mar 2026 03:00:00 GMT</pubDate>
      <category>Identity Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[MIT License vs Apache 2.0: Which to Pick]]></title>
      <description><![CDATA[MIT license vs Apache 2.0 comes down to one real question: do you need an explicit patent grant and contribution terms, or do you want the shortest possible license text?]]></description>
      <link>https://safeguard.sh/resources/blog/mit-license-vs-apache-2-0-which-to-pick</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mit-license-vs-apache-2-0-which-to-pick</guid>
      <pubDate>Sun, 01 Mar 2026 02:28:01 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to Sign Container Images With Cosign: A Complete Guide]]></title>
      <description><![CDATA[A practical walkthrough for signing container images with Cosign using keyless OIDC, verifying signatures, and enforcing policy in your Kubernetes cluster.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-sign-container-images-with-cosign-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-sign-container-images-with-cosign-guide</guid>
      <pubDate>Sun, 01 Mar 2026 01:07:35 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is RAG (Retrieval-Augmented Generation) Security]]></title>
      <description><![CDATA[RAG pipelines blend retrieved data with model instructions, creating prompt injection, poisoning, and embedding-leak risks traditional AppSec tools miss.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-rag-retrieval-augmented-generation-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-rag-retrieval-augmented-generation-security</guid>
      <pubDate>Sun, 01 Mar 2026 01:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Container Security: Why Reachability Analysis Changes Everything]]></title>
      <description><![CDATA[Stop chasing phantom vulnerabilities. Learn how reachability analysis reduces CVE noise by 80% and focuses remediation on what actually matters.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-reachability-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-reachability-analysis</guid>
      <pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[PASETO tokens]]></title>
      <description><![CDATA[PASETO tokens explained: what is PASETO, how PASETO vs JWT differs, and why platform-agnostic security tokens with versioned crypto are safer by design.]]></description>
      <link>https://safeguard.sh/resources/blog/paseto-tokens</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/paseto-tokens</guid>
      <pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate>
      <category>Identity Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Gradle Build Cache Security Hardening]]></title>
      <description><![CDATA[The Gradle build cache is a performance feature with supply chain consequences. Here is how to configure it so cache poisoning, stale outputs, and cross-project contamination do not become your next incident.]]></description>
      <link>https://safeguard.sh/resources/blog/gradle-build-cache-security-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gradle-build-cache-security-hardening</guid>
      <pubDate>Sat, 28 Feb 2026 23:47:08 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Snowflake Customer Data Breaches: 165 Organizations Hit by Credential Theft Campaign]]></title>
      <description><![CDATA[Attackers used stolen credentials from infostealer malware to access Snowflake customer accounts without MFA, compromising data at Ticketmaster, Santander, AT&T, and over 160 other organizations.]]></description>
      <link>https://safeguard.sh/resources/blog/snowflake-customer-data-breaches</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snowflake-customer-data-breaches</guid>
      <pubDate>Sat, 28 Feb 2026 22:26:41 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Rust Edition Migration Security Notes]]></title>
      <description><![CDATA[Field notes from migrating a production workspace from Rust 2018 to 2021, and what to watch for when 2024 lands in edition transitions.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-edition-migration-security-notes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-edition-migration-security-notes</guid>
      <pubDate>Sat, 28 Feb 2026 21:06:14 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GCP Secret Manager Rotation Strategy]]></title>
      <description><![CDATA[A workable rotation strategy for GCP Secret Manager: how to structure secret versions, schedule rotation, coordinate consumers, and avoid the outage patterns that scare teams off rotation in the first place.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-secret-manager-rotation-strategy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-secret-manager-rotation-strategy</guid>
      <pubDate>Sat, 28 Feb 2026 19:45:48 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Security Team Scaling Strategies: Growing Without Burning Out]]></title>
      <description><![CDATA[Your security team is probably understaffed. Here is how to scale security coverage without proportionally scaling headcount.]]></description>
      <link>https://safeguard.sh/resources/blog/security-team-scaling-strategies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-team-scaling-strategies</guid>
      <pubDate>Sat, 28 Feb 2026 18:25:21 GMT</pubDate>
      <category>Security Strategy</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Tauri Desktop App Security Model: What Developers Need to Know]]></title>
      <description><![CDATA[Tauri offers a fundamentally different security model than Electron for desktop applications. Understanding its permission system, IPC boundaries, and supply chain implications is critical.]]></description>
      <link>https://safeguard.sh/resources/blog/tauri-desktop-app-security-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tauri-desktop-app-security-model</guid>
      <pubDate>Sat, 28 Feb 2026 17:04:54 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[OpenAI Internal Breach: What the 2023 Forum Hack Reveals About AI Company Security]]></title>
      <description><![CDATA[Reports emerged that a hacker accessed OpenAI's internal messaging systems in early 2023, raising questions about AI company security practices and the risks of concentrated AI development.]]></description>
      <link>https://safeguard.sh/resources/blog/openai-internal-breach-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openai-internal-breach-2024</guid>
      <pubDate>Sat, 28 Feb 2026 15:44:28 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Next.js Supply Chain Security Hardening]]></title>
      <description><![CDATA[Next.js pulls hundreds of transitive dependencies into production bundles, and the middleware auth bypass of March 2025 showed how a single framework CVE cascades across every App Router deployment. Here is the hardening playbook for 2024 and beyond.]]></description>
      <link>https://safeguard.sh/resources/blog/nextjs-supply-chain-security-hardening-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nextjs-supply-chain-security-hardening-2024</guid>
      <pubDate>Sat, 28 Feb 2026 14:24:01 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Examples: Classic and Modern Attack Patterns]]></title>
      <description><![CDATA[Real SQL injection examples from classic login bypass to blind, time-based, and ORM-era attacks, plus how to test for each one safely.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-examples-classic-modern</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-examples-classic-modern</guid>
      <pubDate>Sat, 28 Feb 2026 13:03:34 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Continuous Asset Discovery vs Quarterly Inventory]]></title>
      <description><![CDATA[Quarterly inventories are wrong by the time they are signed. Continuous discovery is the only model that matches modern rates of change.]]></description>
      <link>https://safeguard.sh/resources/blog/continuous-asset-discovery-vs-quarterly-inventory</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/continuous-asset-discovery-vs-quarterly-inventory</guid>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Crypto Exchange Supply Chain Defence 2026]]></title>
      <description><![CDATA[Crypto exchanges remain the highest-value target for supply chain attackers. Here is the 2026 defence playbook that hardens the entire stack.]]></description>
      <link>https://safeguard.sh/resources/blog/crypto-exchange-supply-chain-defence-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crypto-exchange-supply-chain-defence-2026</guid>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GenAI Coding Agent Privilege Escalation]]></title>
      <description><![CDATA[Autonomous coding agents can escalate privilege in subtle ways that traditional threat models miss. A breakdown of the common escalation paths and how to constrain them.]]></description>
      <link>https://safeguard.sh/resources/blog/genai-coding-agent-privilege-escalation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/genai-coding-agent-privilege-escalation</guid>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs GitHub Copilot for Vulnerability Fixing]]></title>
      <description><![CDATA[GitHub Copilot suggests fixes. Griffin AI generates fix PRs with taint paths and disproof attached. The difference is review burden.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-github-copilot-for-vulnerability-fixing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-github-copilot-for-vulnerability-fixing</guid>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Continuous Eval & Release Gating: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Evals that run once are marketing. Evals that run on every build are infrastructure. Griffin AI runs the harness on every change; Mythos does not describe one.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-continuous-eval-release-gating</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-continuous-eval-release-gating</guid>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Race Condition Detection: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Race conditions are the hardest class of vulnerabilities for static analysis. Specific architectural capabilities separate tools that find them from tools that claim to.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-race-condition-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-race-condition-detection</guid>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[LLM Selection For Security Workflows]]></title>
      <description><![CDATA[Picking a model for a security workflow is not the same as picking one for a chatbot. Here are the criteria that actually matter and how to weigh them.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-selection-for-security-workflows-decision-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-selection-for-security-workflows-decision-guide</guid>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Open-Source LLM Supply Chain Incidents 2026]]></title>
      <description><![CDATA[Open-source LLM ecosystems hit a turning point in 2026 as supply chain incidents — backdoored fine-tunes, compromised weights, malicious adapter packages — moved from rare to recurring.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-llm-supply-chain-incidents-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-llm-supply-chain-incidents-2026</guid>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Polyglot Monorepo: Unified Supply Chain Program]]></title>
      <description><![CDATA[A 2026 unified supply chain program for polyglot monorepos — bringing Node, Python, Go, Java, and more under one set of policies — anchored by Safeguard.]]></description>
      <link>https://safeguard.sh/resources/blog/polyglot-monorepo-unified-supply-chain-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/polyglot-monorepo-unified-supply-chain-program</guid>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Pre-Commit Hooks For Secure Supply Chain Default]]></title>
      <description><![CDATA[Pre-commit hooks are the cheapest place to enforce supply chain hygiene. A practical guide to designing hooks developers leave installed.]]></description>
      <link>https://safeguard.sh/resources/blog/pre-commit-hooks-secure-supply-chain-default</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pre-commit-hooks-secure-supply-chain-default</guid>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Reachability-Driven Incident Response Playbook]]></title>
      <description><![CDATA[When CVE-X is announced and the world panics, reachability is the data that tells you whether to wake up the on-call team or wait until Monday.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-incident-response-playbook-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-incident-response-playbook-2026</guid>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[TPRM Budget Justification For The Board]]></title>
      <description><![CDATA[TPRM budgets get cut because the program cannot quantify what it prevents. Here is the framing that lands with boards: avoided losses, regulatory exposure, and continuity.]]></description>
      <link>https://safeguard.sh/resources/blog/tprm-budget-justification-for-the-board</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tprm-budget-justification-for-the-board</guid>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard CLI: Supply Chain Security Without Leaving Your Terminal]]></title>
      <description><![CDATA[The Safeguard CLI brings SBOM generation, vulnerability scanning, policy checks, and supply chain queries directly into your development workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-cli-tool-developer-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-cli-tool-developer-workflow</guid>
      <pubDate>Sat, 28 Feb 2026 11:43:08 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Vite Build Tool Security Considerations]]></title>
      <description><![CDATA[Vite has become the default build tool for a generation of JavaScript frameworks. Its plugin model, dev server, and dependency pre-bundling each carry distinct security implications worth understanding.]]></description>
      <link>https://safeguard.sh/resources/blog/vite-build-tool-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vite-build-tool-security-considerations</guid>
      <pubDate>Sat, 28 Feb 2026 10:22:41 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Post-Quantum Cryptography Migration for Software Supply Chains]]></title>
      <description><![CDATA[NIST finalized ML-KEM, ML-DSA, and SLH-DSA in 2024. Here's what it means for Sigstore, package registry signing, TLS, and the harvest-now-decrypt-later problem.]]></description>
      <link>https://safeguard.sh/resources/blog/post-quantum-cryptography-migration-supply-chains</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/post-quantum-cryptography-migration-supply-chains</guid>
      <pubDate>Sat, 28 Feb 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Insurance Industry Software Supply Chain]]></title>
      <description><![CDATA[Insurers underwrite cyber risk while running on the same fragile dependency graphs as everyone else. A look at the industry's software supply chain blind spots.]]></description>
      <link>https://safeguard.sh/resources/blog/insurance-industry-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insurance-industry-software-supply-chain</guid>
      <pubDate>Sat, 28 Feb 2026 09:02:14 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How Safeguard Partners With MSSP Programs]]></title>
      <description><![CDATA[A practical guide to how Safeguard works with managed security service providers — including the partners under exploratory discussion.]]></description>
      <link>https://safeguard.sh/resources/blog/how-safeguard-partners-with-mssp-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-safeguard-partners-with-mssp-programs</guid>
      <pubDate>Sat, 28 Feb 2026 09:00:00 GMT</pubDate>
      <category>Company</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cyber Insurance Exclusions for Supply Chain Incidents]]></title>
      <description><![CDATA[What 2026 cyber insurance policies actually exclude for software supply chain incidents, how carriers test your controls, and what to negotiate before renewal.]]></description>
      <link>https://safeguard.sh/resources/blog/insurance-cyber-policy-software-supply-chain-exclusions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insurance-cyber-policy-software-supply-chain-exclusions</guid>
      <pubDate>Sat, 28 Feb 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[JSR/Deno Package Ecosystem Supply Chain]]></title>
      <description><![CDATA[JSR is the first mainstream package registry designed with supply chain security as a founding constraint. Here is what it gets right and what it has not solved yet.]]></description>
      <link>https://safeguard.sh/resources/blog/jsr-deno-package-ecosystem-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jsr-deno-package-ecosystem-supply-chain</guid>
      <pubDate>Sat, 28 Feb 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Zero trust architecture (ZTA)]]></title>
      <description><![CDATA[A precise definition of zero trust architecture, the NIST 800-207 model, ZTNA vs VPN, and how zero trust principles apply to securing modern software supply chains.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-trust-architecture-zta</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-trust-architecture-zta</guid>
      <pubDate>Sat, 28 Feb 2026 09:00:00 GMT</pubDate>
      <category>Identity Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[IAST vs SAST in 2026: When to Use Which]]></title>
      <description><![CDATA[A practical guide to when IAST adds value over SAST in 2026, with the workload characteristics that justify the operational cost of runtime instrumentation.]]></description>
      <link>https://safeguard.sh/resources/blog/iast-vs-sast-when-to-use-which-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iast-vs-sast-when-to-use-which-2026</guid>
      <pubDate>Sat, 28 Feb 2026 08:45:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Infisical: An Open-Source Secrets Platform Review]]></title>
      <description><![CDATA[A senior engineer's assessment of Infisical as a self-hostable secrets platform, covering architecture, operational posture, and where it fits in 2024.]]></description>
      <link>https://safeguard.sh/resources/blog/infisical-open-source-secrets-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/infisical-open-source-secrets-platform</guid>
      <pubDate>Sat, 28 Feb 2026 07:41:47 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Symbolic Execution for Dependency Analysis]]></title>
      <description><![CDATA[Symbolic execution explores program paths without concrete inputs. For supply-chain work, it answers reachability questions that fuzzing cannot.]]></description>
      <link>https://safeguard.sh/resources/blog/symbolic-execution-for-dependency-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/symbolic-execution-for-dependency-analysis</guid>
      <pubDate>Sat, 28 Feb 2026 06:21:21 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[TOCTOU (Time-of-check to time-of-use)]]></title>
      <description><![CDATA[TOCTOU flaws let attackers swap a file or resource after it's validated but before it's used, turning a safe check into an exploitable race.]]></description>
      <link>https://safeguard.sh/resources/blog/toctou-time-of-check-to-time-of-use</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/toctou-time-of-check-to-time-of-use</guid>
      <pubDate>Sat, 28 Feb 2026 06:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Rails Application Template Security]]></title>
      <description><![CDATA[Rails application templates are powerful and dangerous: how they execute, what they can touch, and how to use them safely for new-project scaffolding.]]></description>
      <link>https://safeguard.sh/resources/blog/rails-application-template-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rails-application-template-security</guid>
      <pubDate>Sat, 28 Feb 2026 05:00:54 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Maven Central Changes in 2024 and Their Security Impact]]></title>
      <description><![CDATA[Sonatype made several Maven Central changes in 2024 that materially affected the Java supply chain. A rundown of what changed, who was affected, and what Java teams should do.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-central-changes-2024-security-impact</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-central-changes-2024-security-impact</guid>
      <pubDate>Sat, 28 Feb 2026 03:40:27 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Hash collision attack]]></title>
      <description><![CDATA[What is a hash collision, and why does it break integrity checks and signatures? A precise definition, the SHA-1 collision attack, and how Safeguard closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/hash-collision-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hash-collision-attack</guid>
      <pubDate>Sat, 28 Feb 2026 03:00:00 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Harness.io Supply Chain Security Reviewed]]></title>
      <description><![CDATA[A security review of the Harness.io platform covering SSCA, CI/CD governance, STO integration, and the practical configuration required to get a production-grade supply chain posture.]]></description>
      <link>https://safeguard.sh/resources/blog/harness-io-supply-chain-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/harness-io-supply-chain-security-review</guid>
      <pubDate>Sat, 28 Feb 2026 02:20:01 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Check Point VPN Zero-Day CVE-2024-24919: Information Disclosure Under Active Exploitation]]></title>
      <description><![CDATA[A critical information disclosure vulnerability in Check Point VPN products allowed attackers to read sensitive files including password hashes, enabling lateral movement into enterprise networks.]]></description>
      <link>https://safeguard.sh/resources/blog/check-point-vpn-cve-2024-24919-zero-day</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/check-point-vpn-cve-2024-24919-zero-day</guid>
      <pubDate>Sat, 28 Feb 2026 00:59:34 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[HMAC]]></title>
      <description><![CDATA[HMAC is a cryptographic construct that combines a hash function with a secret key to verify both the integrity and authenticity of a message.]]></description>
      <link>https://safeguard.sh/resources/blog/hmac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hmac</guid>
      <pubDate>Sat, 28 Feb 2026 00:00:00 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[CSRF Attacks: How They Work and How Tokens Stop Them]]></title>
      <description><![CDATA[A CSRF attack rides a logged-in user's browser to forge requests they never meant to send. Here is the mechanism and why anti-CSRF tokens defeat it.]]></description>
      <link>https://safeguard.sh/resources/blog/csrf-attacks-how-tokens-stop-them</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/csrf-attacks-how-tokens-stop-them</guid>
      <pubDate>Fri, 27 Feb 2026 23:39:07 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[OSS Contributor License Agreements Reviewed]]></title>
      <description><![CDATA[CLAs, DCOs, and the subtle differences between Apache ICLAs, Google corporate CLAs, and Eclipse ECAs shape what contributors give up and what projects can do.]]></description>
      <link>https://safeguard.sh/resources/blog/oss-contributor-license-agreements-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oss-contributor-license-agreements-review</guid>
      <pubDate>Fri, 27 Feb 2026 22:18:41 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GCP Cloud Build Hardening in Production]]></title>
      <description><![CDATA[Lessons from hardening Cloud Build pipelines in production environments: private pools, least-privilege service accounts, provenance, and the controls that actually stop lateral movement.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-cloud-build-hardening-production</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-cloud-build-hardening-production</guid>
      <pubDate>Fri, 27 Feb 2026 20:58:14 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cisco Duo Incident: Supply Chain Depth]]></title>
      <description><![CDATA[Cisco Duo's 2024 disclosure about a telephony provider breach exposed SMS and voice MFA logs; the supply chain depth of authentication vendors is the story.]]></description>
      <link>https://safeguard.sh/resources/blog/cisco-duo-incident-supply-chain-depth</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisco-duo-incident-supply-chain-depth</guid>
      <pubDate>Fri, 27 Feb 2026 19:37:47 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Message Queue Security: Hardening Kafka, RabbitMQ, and Event Brokers]]></title>
      <description><![CDATA[Message queues are the nervous system of modern architectures. A compromised broker can intercept, modify, or inject messages across your entire system. Here is how to lock them down.]]></description>
      <link>https://safeguard.sh/resources/blog/message-queue-security-kafka-rabbitmq</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/message-queue-security-kafka-rabbitmq</guid>
      <pubDate>Fri, 27 Feb 2026 18:17:21 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[PCI DSS 4.0 Software Supply Chain Requirements Explained]]></title>
      <description><![CDATA[PCI DSS 4.0 quietly turned component inventories, third-party code review, and payment page script control into audit line items. Here's the requirement-by-requirement map.]]></description>
      <link>https://safeguard.sh/resources/blog/pci-dss-4-0-software-supply-chain-requirements-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pci-dss-4-0-software-supply-chain-requirements-explained</guid>
      <pubDate>Fri, 27 Feb 2026 16:56:54 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Jonas Meyer)</author>
    </item>
    <item>
      <title><![CDATA[Sumo Logic for Supply Chain Observability: A Practitioner's Guide]]></title>
      <description><![CDATA[Architect Sumo Logic dashboards, queries, and anomaly detection for software supply chain visibility across SCM, CI/CD, registries, and cloud runtime.]]></description>
      <link>https://safeguard.sh/resources/blog/sumo-logic-supply-chain-observability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sumo-logic-supply-chain-observability</guid>
      <pubDate>Fri, 27 Feb 2026 15:36:27 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Package Yanking Policies Analyzed]]></title>
      <description><![CDATA[Yanking is PyPI's narrow, deliberately blunt tool for dealing with broken releases. A close analysis of what it does, what it doesn't do, and when to use it instead of a delete.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-package-yanking-policies-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-package-yanking-policies-analysis</guid>
      <pubDate>Fri, 27 Feb 2026 14:16:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Go Workspaces Supply Chain Risks]]></title>
      <description><![CDATA[Go workspaces make multi-module development feel natural, but the go.work file introduces a new trust boundary that can quietly override pinned versions and bypass checksum verification.]]></description>
      <link>https://safeguard.sh/resources/blog/go-workspaces-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-workspaces-supply-chain-risks</guid>
      <pubDate>Fri, 27 Feb 2026 12:55:34 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Australia Essential Eight 2026: Supply Chain]]></title>
      <description><![CDATA[A senior engineer's view of how Australia's Essential Eight evolved through 2025 and 2026 to incorporate software supply chain expectations alongside the original mitigations.]]></description>
      <link>https://safeguard.sh/resources/blog/australia-essential-eight-2026-update-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/australia-essential-eight-2026-update-supply-chain</guid>
      <pubDate>Fri, 27 Feb 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CMMC Level 2 Supply Chain Control Evidence]]></title>
      <description><![CDATA[CMMC Level 2 assessments demand structured evidence for the SR family and adjacent controls. Learn how to produce assessor-ready supply chain artifacts.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-level-2-supply-chain-control-evidence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-level-2-supply-chain-control-evidence</guid>
      <pubDate>Fri, 27 Feb 2026 12:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise AI Data Residency Requirements, 2026]]></title>
      <description><![CDATA[Data residency for AI workloads has moved from nice-to-have to contractually required. The shape of the requirement is specific and worth knowing before procurement.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-ai-data-residency-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-ai-data-residency-requirements</guid>
      <pubDate>Fri, 27 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[From CVE To PR: The Full Remediation Pipeline]]></title>
      <description><![CDATA[A complete walkthrough of the modern remediation pipeline, from advisory ingestion through merged and deployed fix, with every stage that actually matters.]]></description>
      <link>https://safeguard.sh/resources/blog/from-cve-to-pr-the-full-remediation-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/from-cve-to-pr-the-full-remediation-pipeline</guid>
      <pubDate>Fri, 27 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[False Positive Cost: Griffin AI vs Mythos]]></title>
      <description><![CDATA[A false positive is not free. It costs engineer attention, trust in the tool, and eventually the security programme's credibility. We price the difference.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-false-positive-cost</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-false-positive-cost</guid>
      <pubDate>Fri, 27 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Injection Path Detection: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Injection vulnerabilities are not really about the sink. They are about the path from untrusted input to the sink. The path is where Griffin AI and Mythos-class tools diverge.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-injection-path-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-injection-path-detection</guid>
      <pubDate>Fri, 27 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Open Weights: On-Prem Tradeoffs]]></title>
      <description><![CDATA[Open-weight models let you run everything locally. The tradeoff is quality, cost, and operational overhead. Griffin AI provides a different answer to the same on-prem need.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-open-weight-on-prem-tradeoffs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-open-weight-on-prem-tradeoffs</guid>
      <pubDate>Fri, 27 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Helm Chart Supply Chain Defence Blueprint]]></title>
      <description><![CDATA[Helm charts are the most common Kubernetes deployment artifact and the least scrutinised. This blueprint covers chart provenance, signing, value validation, and the runtime correspondence checks that close the loop.]]></description>
      <link>https://safeguard.sh/resources/blog/helm-chart-supply-chain-defence-blueprint-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/helm-chart-supply-chain-defence-blueprint-2026</guid>
      <pubDate>Fri, 27 Feb 2026 12:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SecOps Staffing For The Modern Program]]></title>
      <description><![CDATA[Staffing a modern SecOps program is not about hiring more analysts. It is about defining roles that match how supply chain security work actually flows in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/secops-staffing-modern-program-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secops-staffing-modern-program-2026</guid>
      <pubDate>Fri, 27 Feb 2026 12:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Signed SBOMs As Procurement Leverage]]></title>
      <description><![CDATA[Unsigned SBOMs are paperwork. Signed SBOMs with in-toto attestations are leverage. Here is how mature procurement programmes use signing to harden vendor relationships.]]></description>
      <link>https://safeguard.sh/resources/blog/signed-sboms-attestations-procurement-leverage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/signed-sboms-attestations-procurement-leverage</guid>
      <pubDate>Fri, 27 Feb 2026 12:00:00 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[FastAPI Security Best Practices]]></title>
      <description><![CDATA[Securing FastAPI applications with Pydantic validation, OAuth2 integration, and dependency injection patterns.]]></description>
      <link>https://safeguard.sh/resources/blog/fastapi-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fastapi-security-best-practices</guid>
      <pubDate>Fri, 27 Feb 2026 11:35:07 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Vulnerability Scan? How It Works and What It Finds]]></title>
      <description><![CDATA[A vulnerability scan automatically checks code, dependencies, and running systems against known weaknesses — here's what it actually inspects and where it stops short of a full assessment.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-vulnerability-scan-how-it-works</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-vulnerability-scan-how-it-works</guid>
      <pubDate>Fri, 27 Feb 2026 10:14:40 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Fine-Tuning Poisoning Detection for Supply Chains]]></title>
      <description><![CDATA[Fine-tuning inherits every problem of the base model and adds dataset provenance as a new one. Here is how detection actually works in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/fine-tuning-poisoning-detection-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fine-tuning-poisoning-detection-supply-chain</guid>
      <pubDate>Fri, 27 Feb 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[ProxyNotShell Postmortem: What the Exchange CVEs Taught About Patch Triage]]></title>
      <description><![CDATA[ProxyNotShell forced enterprises to triage Exchange Server patching under pressure with confusing vendor guidance. A look back at CVE-2022-41040 and CVE-2022-41082.]]></description>
      <link>https://safeguard.sh/resources/blog/proxynotshell-exchange-cves-postmortem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/proxynotshell-exchange-cves-postmortem</guid>
      <pubDate>Fri, 27 Feb 2026 10:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard vs Snyk: Detailed 2026 Comparison]]></title>
      <description><![CDATA[A senior engineer's breakdown of how Safeguard and Snyk differ in 2026 across SCA depth, reachability analysis, remediation, and container security.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-vs-snyk-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-vs-snyk-comparison-2026</guid>
      <pubDate>Fri, 27 Feb 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is Security Hardening?]]></title>
      <description><![CDATA[Security hardening reduces a system's attack surface by removing what it does not need and configuring the rest safely. Learn the principles, benchmarks, and how to apply it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-security-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-security-hardening</guid>
      <pubDate>Fri, 27 Feb 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Container Registry (ghcr.io): A Practical Security Guide]]></title>
      <description><![CDATA[GitHub Container Registry (ghcr.io) is convenient and tightly integrated with Actions, but the defaults can leak images and tokens. Here's how to lock it down properly.]]></description>
      <link>https://safeguard.sh/resources/blog/github-container-registry</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-container-registry</guid>
      <pubDate>Fri, 27 Feb 2026 09:15:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Public key infrastructure (PKI)]]></title>
      <description><![CDATA[What is PKI? A precise breakdown of public key infrastructure, the PKI certificate chain, root and intermediate CAs, and how trust hierarchies can break.]]></description>
      <link>https://safeguard.sh/resources/blog/public-key-infrastructure-pki</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/public-key-infrastructure-pki</guid>
      <pubDate>Fri, 27 Feb 2026 09:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard MCP Server: Public Release Details]]></title>
      <description><![CDATA[The Safeguard MCP Server is publicly available and works with Claude Desktop, claude.ai, Claude Code, ChatGPT, Cursor, Gemini, and Grok. Here is the tool surface.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-mcp-server-public-release-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-mcp-server-public-release-2026</guid>
      <pubDate>Fri, 27 Feb 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-24785: The Moment.js Path Traversal, Explained]]></title>
      <description><![CDATA[A user-controlled locale string was all it took: how CVE-2022-24785 let attackers traverse paths through Moment.js locale loading on Node.js, and why the fix is a one-line upgrade.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-24785-momentjs-path-traversal</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-24785-momentjs-path-traversal</guid>
      <pubDate>Fri, 27 Feb 2026 08:54:14 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2019-8331: The Bootstrap XSS Vulnerability, Explained]]></title>
      <description><![CDATA[CVE-2019-8331 let attackers inject script through Bootstrap's tooltip and popover template options, a pattern that recurred across several Bootstrap CVEs before 4.3.1 finally closed it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2019-8331-bootstrap-xss-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2019-8331-bootstrap-xss-explained</guid>
      <pubDate>Fri, 27 Feb 2026 07:33:47 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Utilities Sector NERC CIP Software Supply Chain]]></title>
      <description><![CDATA[NERC CIP-013 turned software supply chain into a regulated obligation for the bulk electric system. A practical look at what utilities are actually doing.]]></description>
      <link>https://safeguard.sh/resources/blog/utilities-sector-nerc-cip-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/utilities-sector-nerc-cip-software-supply-chain</guid>
      <pubDate>Fri, 27 Feb 2026 06:13:20 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Elliptic curve cryptography (ECC)]]></title>
      <description><![CDATA[A precise, technical answer to what is elliptic curve cryptography — plus how ECC vs RSA, ECDSA signatures, and ECDH key exchange secure modern systems.]]></description>
      <link>https://safeguard.sh/resources/blog/elliptic-curve-cryptography-ecc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/elliptic-curve-cryptography-ecc</guid>
      <pubDate>Fri, 27 Feb 2026 06:00:00 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[SOX IT Controls Meet Software Controls]]></title>
      <description><![CDATA[Sarbanes-Oxley IT general controls predate modern software delivery. Here's how change management, access, and segregation of duties controls actually look when applied to CI/CD pipelines and software components.]]></description>
      <link>https://safeguard.sh/resources/blog/sox-it-controls-meets-software-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sox-it-controls-meets-software-controls</guid>
      <pubDate>Fri, 27 Feb 2026 04:52:54 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is ISO 27001]]></title>
      <description><![CDATA[ISO 27001 is the international ISMS standard with 93 Annex A controls. Here's what it requires, who needs it, and what it costs to certify.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-iso-27001</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-iso-27001</guid>
      <pubDate>Fri, 27 Feb 2026 04:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to Measure Dependency Freshness in CI]]></title>
      <description><![CDATA[A practical CI tutorial for measuring dependency freshness, setting SLOs for version drift, and failing builds when packages fall too far behind upstream.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-measure-dependency-freshness-in-ci</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-measure-dependency-freshness-in-ci</guid>
      <pubDate>Fri, 27 Feb 2026 03:32:27 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Post-quantum cryptography]]></title>
      <description><![CDATA[Post-quantum cryptography protects data from future quantum attacks. See how NIST-standardized, lattice-based algorithms defend today's software supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/post-quantum-cryptography</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/post-quantum-cryptography</guid>
      <pubDate>Fri, 27 Feb 2026 03:00:00 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Deepfakes and Social Engineering: The Human Layer of Supply Chain Attacks]]></title>
      <description><![CDATA[AI-generated deepfakes are making social engineering attacks against software supply chains more convincing and harder to detect.]]></description>
      <link>https://safeguard.sh/resources/blog/deepfake-social-engineering-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/deepfake-social-engineering-supply-chain</guid>
      <pubDate>Fri, 27 Feb 2026 02:12:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is the NIST Cybersecurity Framework]]></title>
      <description><![CDATA[A breakdown of the NIST Cybersecurity Framework's six functions, its 2024 update, and why GV.SC makes it central to software supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-nist-cybersecurity-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-nist-cybersecurity-framework</guid>
      <pubDate>Fri, 27 Feb 2026 01:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Visualization Tools Compared: Making Dependency Data Actionable]]></title>
      <description><![CDATA[An SBOM in JSON or XML format is data. A visualization turns that data into insight. This comparison examines how different tools present SBOM data and which approaches work best for different audiences.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-visualization-tools-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-visualization-tools-comparison</guid>
      <pubDate>Fri, 27 Feb 2026 00:51:34 GMT</pubDate>
      <category>SBOM and Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-23897 Jenkins CLI File Read Deep Dive]]></title>
      <description><![CDATA[CVE-2024-23897 is a Jenkins CLI arbitrary file-read flaw that leaks secrets and enables RCE chains. Root cause, exploitation, and patch guidance.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-23897-jenkins-cli-file-read-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-23897-jenkins-cli-file-read-deep-dive</guid>
      <pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Hardware Security Module (HSM)]]></title>
      <description><![CDATA[What is an HSM? Learn how hardware security modules store signing keys, how HSM vs KMS differs, and why FIPS 140-2 HSMs protect code-signing keys.]]></description>
      <link>https://safeguard.sh/resources/blog/hardware-security-module-hsm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hardware-security-module-hsm</guid>
      <pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Enterprise Server CVE-2024-4985: SAML Authentication Bypass]]></title>
      <description><![CDATA[A critical authentication bypass in GitHub Enterprise Server allowed attackers to forge SAML responses and gain administrator access to self-hosted GitHub instances without any credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/github-enterprise-server-cve-2024-4985</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-enterprise-server-cve-2024-4985</guid>
      <pubDate>Thu, 26 Feb 2026 23:31:07 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Managing Python Package Namespace Conflicts]]></title>
      <description><![CDATA[Python's flat namespace creates real security problems. Here is how namespace packages, shadowing, and install order interact, and how to avoid the surprises.]]></description>
      <link>https://safeguard.sh/resources/blog/python-package-namespace-conflicts-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-package-namespace-conflicts-management</guid>
      <pubDate>Thu, 26 Feb 2026 22:10:40 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Pants Build Tool Security Posture]]></title>
      <description><![CDATA[A practitioner's view of the Pants build system's security properties, covering sandboxing, third-party resolution, and the Pants 2.x architecture.]]></description>
      <link>https://safeguard.sh/resources/blog/pants-build-tool-security-posture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pants-build-tool-security-posture</guid>
      <pubDate>Thu, 26 Feb 2026 20:50:13 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Migrating SBOM Tooling Providers]]></title>
      <description><![CDATA[A practical field guide to switching SBOM tooling vendors without losing historical data, breaking compliance reports, or annoying the auditors.]]></description>
      <link>https://safeguard.sh/resources/blog/migrating-sbom-tooling-provider-migration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/migrating-sbom-tooling-provider-migration</guid>
      <pubDate>Thu, 26 Feb 2026 19:29:47 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[.NET Supply Chain Audit Patterns]]></title>
      <description><![CDATA[Auditing a .NET supply chain is a different exercise than auditing a JavaScript one, and the patterns that actually find problems are specific to how the ecosystem works.]]></description>
      <link>https://safeguard.sh/resources/blog/dotnet-supply-chain-audit-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dotnet-supply-chain-audit-patterns</guid>
      <pubDate>Thu, 26 Feb 2026 18:09:20 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Azure Key Vault Rotation Patterns]]></title>
      <description><![CDATA[Rotation is the Key Vault feature most teams nominally have and few actually operate. A walk through the patterns that work for secrets, keys, and certificates at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-key-vault-rotation-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-key-vault-rotation-patterns</guid>
      <pubDate>Thu, 26 Feb 2026 16:48:53 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SLSA for Go Releases: A Practical Guide]]></title>
      <description><![CDATA[Go's build model makes SLSA provenance more tractable than most ecosystems. Here is the practical guide for producing and verifying provenance on Go releases.]]></description>
      <link>https://safeguard.sh/resources/blog/slsa-for-go-releases-practical-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slsa-for-go-releases-practical-guide</guid>
      <pubDate>Thu, 26 Feb 2026 15:28:27 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Rust no_std Supply Chain Considerations]]></title>
      <description><![CDATA[Writing Rust for embedded or kernel targets drops you into no_std territory, and the supply chain rules are different there. A practical look at what changes and why.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-no-std-supply-chain-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-no-std-supply-chain-considerations</guid>
      <pubDate>Thu, 26 Feb 2026 14:08:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[RAG Pipeline Security Controls in 2026]]></title>
      <description><![CDATA[Retrieval-augmented generation pipelines have become a primary breach vector for LLM products. The controls that contain the risk without breaking the use case.]]></description>
      <link>https://safeguard.sh/resources/blog/rag-pipeline-security-controls-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rag-pipeline-security-controls-2026</guid>
      <pubDate>Thu, 26 Feb 2026 13:45:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Cosign Keyless Signing Workflows in 2026]]></title>
      <description><![CDATA[How keyless signing has matured: OIDC identities, transparency log dependencies, attestation patterns, and the operational details teams still get wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/cosign-keyless-signing-workflows-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cosign-keyless-signing-workflows-2026</guid>
      <pubDate>Thu, 26 Feb 2026 13:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSL vs LibreSSL vs BoringSSL in 2026]]></title>
      <description><![CDATA[A 2026 comparison of OpenSSL, LibreSSL, and BoringSSL on security posture, release cadence, FIPS posture, and which one to ship in which context.]]></description>
      <link>https://safeguard.sh/resources/blog/openssl-vs-libressl-vs-boringssl-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssl-vs-libressl-vs-boringssl-2026</guid>
      <pubDate>Thu, 26 Feb 2026 13:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI: Your Autonomous Supply Chain Security Analyst]]></title>
      <description><![CDATA[Griffin is Safeguard's AI assistant that answers natural-language questions about your software supply chain, correlates threats in real time, and recommends actions.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-griffin-ai-autonomous-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-griffin-ai-autonomous-security</guid>
      <pubDate>Thu, 26 Feb 2026 12:47:33 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[LLM-As-Judge Pitfalls In Security Evals]]></title>
      <description><![CDATA[Using an LLM to score another LLM&apos;s output is expedient and dangerous. The judge has its own biases — ones that affect security evaluations specifically.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-llm-as-judge-pitfalls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-llm-as-judge-pitfalls</guid>
      <pubDate>Thu, 26 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Claude Batch API for Scanning]]></title>
      <description><![CDATA[Claude's Batch API gives you 50% off for async workloads. Griffin AI uses it internally. The question is whether your team should use the Batch API directly or consume it through Griffin.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-claude-batch-api-for-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-claude-batch-api-for-scanning</guid>
      <pubDate>Thu, 26 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NIST SSDF 1.2 Draft: What the Comment Period Revealed]]></title>
      <description><![CDATA[NIST opened public comment on SP 800-218r1 SSDF v1.2 on December 17, 2025. The draft adds AI development practices, refines supply-chain controls, and aligns with EO 14306.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-ssdf-1-2-draft-public-comment-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-ssdf-1-2-draft-public-comment-2026</guid>
      <pubDate>Thu, 26 Feb 2026 12:00:00 GMT</pubDate>
      <category>Standards</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SBOM for EdTech Platforms: Protecting Student Data Through Supply Chain Transparency]]></title>
      <description><![CDATA[EdTech platforms handle some of the most sensitive data — children's information. FERPA, COPPA, and state student privacy laws demand supply chain visibility that most EdTech companies lack.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-edtech-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-edtech-platforms</guid>
      <pubDate>Thu, 26 Feb 2026 11:27:07 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[EKS Pod Identity vs IRSA: A 2026 Migration Playbook]]></title>
      <description><![CDATA[How to migrate from IRSA to EKS Pod Identity in 2026, including the trade-offs, the operational gotchas, and the cases where IRSA still makes sense.]]></description>
      <link>https://safeguard.sh/resources/blog/eks-pod-identity-vs-irsa-migration-playbook-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eks-pod-identity-vs-irsa-migration-playbook-2026</guid>
      <pubDate>Thu, 26 Feb 2026 10:40:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Manufacturing OT Supply Chain Security in 2026]]></title>
      <description><![CDATA[Manufacturing has converged IT and OT for a decade, and the supply chain risk has followed. Here is what IEC 62443-aligned vendor management looks like in 2026, with the threats that justify it.]]></description>
      <link>https://safeguard.sh/resources/blog/manufacturing-ot-supply-chain-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/manufacturing-ot-supply-chain-security-2026</guid>
      <pubDate>Thu, 26 Feb 2026 10:30:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[The OSS Pledge: Adoption Tracking at Six Months]]></title>
      <description><![CDATA[Six months after the OSS Pledge launch, adoption is climbing but uneven. Who signed, who followed through with funding, and what the pledge has actually shifted in open-source economics.]]></description>
      <link>https://safeguard.sh/resources/blog/oss-pledge-adoption-tracking-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oss-pledge-adoption-tracking-2024</guid>
      <pubDate>Thu, 26 Feb 2026 10:06:40 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Automotive OEM ISO 21434 Compliance]]></title>
      <description><![CDATA[An anonymized look at how a major automotive OEM used Safeguard to operationalize ISO/SAE 21434 software supply chain requirements across vehicle platforms.]]></description>
      <link>https://safeguard.sh/resources/blog/customer-story-automotive-oem-iso-21434-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/customer-story-automotive-oem-iso-21434-compliance</guid>
      <pubDate>Thu, 26 Feb 2026 10:00:00 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis for Python and pip in 2026]]></title>
      <description><![CDATA[Python reachability is hard but useful: dynamic dispatch, monkey-patching, optional extras, and how modern tools handle real Django and FastAPI services.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-python-pip-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-python-pip-2026</guid>
      <pubDate>Thu, 26 Feb 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Tetragon vs Falco: 2026 Runtime Security Field Test]]></title>
      <description><![CDATA[Both Tetragon and Falco run on eBPF and both ship as CNCF projects. We benched them side by side on a 400-node cluster — coverage, overhead, and enforcement behavior.]]></description>
      <link>https://safeguard.sh/resources/blog/tetragon-vs-falco-runtime-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tetragon-vs-falco-runtime-security-2026</guid>
      <pubDate>Thu, 26 Feb 2026 10:00:00 GMT</pubDate>
      <category>Tool Comparison</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is FedRAMP]]></title>
      <description><![CDATA[FedRAMP governs how federal agencies vet cloud software. Here's what it requires, what it costs, how long it takes, and what FedRAMP 20x changes.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-fedramp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-fedramp</guid>
      <pubDate>Thu, 26 Feb 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Why Developer Experience Matters to Security Programs]]></title>
      <description><![CDATA[Security programs that ignore developer experience fail. This is not a culture complaint — it is a throughput argument, and the math is unforgiving.]]></description>
      <link>https://safeguard.sh/resources/blog/why-developer-experience-matters-security-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-developer-experience-matters-security-programs</guid>
      <pubDate>Thu, 26 Feb 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Update Triage Strategy for Eng Teams]]></title>
      <description><![CDATA[An update PR is not a security finding. Here is a triage model that keeps reachability, risk, and engineering effort in the right conversation.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-update-triage-strategy-engineering-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-update-triage-strategy-engineering-teams</guid>
      <pubDate>Thu, 26 Feb 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Perfect forward secrecy]]></title>
      <description><![CDATA[Perfect forward secrecy stops a single leaked TLS key from unlocking years of past traffic. Here's how ephemeral key exchange works, and why it matters for supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/perfect-forward-secrecy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/perfect-forward-secrecy</guid>
      <pubDate>Thu, 26 Feb 2026 09:00:00 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Quality Across Ecosystems: 2026 Report]]></title>
      <description><![CDATA[The Safeguard Research team measured SBOM quality across ecosystems and generators. The gaps between formats, tools, and languages are larger than most teams assume.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-research-sbom-quality-across-ecosystems-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-research-sbom-quality-across-ecosystems-report</guid>
      <pubDate>Thu, 26 Feb 2026 09:00:00 GMT</pubDate>
      <category>Research</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Types of Security Audits, Explained]]></title>
      <description><![CDATA[There isn't one kind of security audit — compliance audits, penetration tests, code audits, and architecture reviews all answer different questions and require different evidence.]]></description>
      <link>https://safeguard.sh/resources/blog/types-of-security-audits-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/types-of-security-audits-explained</guid>
      <pubDate>Thu, 26 Feb 2026 08:46:13 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Basics for Engineers Who Aren't Security Specialists]]></title>
      <description><![CDATA[SQL injection is still one of the most common ways applications get breached, and the fix is usually a one-line change — this walks through the basics with a real example.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-basics-for-engineers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-basics-for-engineers</guid>
      <pubDate>Thu, 26 Feb 2026 07:25:47 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What is the NIST Secure Software Development Framework (SSDF)]]></title>
      <description><![CDATA[NIST SSDF (SP 800-218) explained: its four practice groups, the EO 14028 origin, federal attestation deadlines, and how it differs from SLSA and SP 800-53.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-nist-secure-software-development-framework-ssdf</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-nist-secure-software-development-framework-ssdf</guid>
      <pubDate>Thu, 26 Feb 2026 07:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What Is XSS? Cross-Site Scripting Full Form and Basics]]></title>
      <description><![CDATA[XSS is short for cross-site scripting, a vulnerability that lets attackers run malicious scripts in a victim's browser. Here's how it works, its three main types, and how it's actually caught.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-xss-cross-site-scripting-full-form</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-xss-cross-site-scripting-full-form</guid>
      <pubDate>Thu, 26 Feb 2026 06:05:20 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Cryptographic salt vs pepper]]></title>
      <description><![CDATA[What is a cryptographic salt, and how does it differ from pepper in password hashing? A technical breakdown of salted hashes, bcrypt salt rounds, and best practices.]]></description>
      <link>https://safeguard.sh/resources/blog/cryptographic-salt-vs-pepper</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cryptographic-salt-vs-pepper</guid>
      <pubDate>Thu, 26 Feb 2026 06:00:00 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Prevention Techniques That Actually Work]]></title>
      <description><![CDATA[SQL injection prevention comes down to one non-negotiable technique — parameterized queries — plus a short list of layered defenses that catch what a single control misses.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-prevention-techniques-that-work</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-prevention-techniques-that-work</guid>
      <pubDate>Thu, 26 Feb 2026 04:44:53 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is Executive Order 14028]]></title>
      <description><![CDATA[EO 14028 forced federal software vendors to prove what's in their code. Here's what it requires, who it binds, and what's changed since 2021.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-executive-order-14028</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-executive-order-14028</guid>
      <pubDate>Thu, 26 Feb 2026 04:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Path Traversal: How It Works and How to Stop It]]></title>
      <description><![CDATA[Path traversal lets an attacker reach files outside a web app's intended directory using sequences like ../../etc/passwd — here's how it works and the fixes that actually close it.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-path-traversal-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-path-traversal-explained</guid>
      <pubDate>Thu, 26 Feb 2026 03:24:26 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The National Vulnerability Database: How to Actually Use It]]></title>
      <description><![CDATA[The National Vulnerability Database is the US government's CVE repository — here's how to search it, read its CVSS scores, and use it in a real workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/national-vulnerability-database-how-to-use-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/national-vulnerability-database-how-to-use-it</guid>
      <pubDate>Thu, 26 Feb 2026 02:04:00 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is the EU Cyber Resilience Act]]></title>
      <description><![CDATA[The EU Cyber Resilience Act sets binding cybersecurity rules for digital products, with reporting due by Sept 2026 and full compliance by Dec 2027.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-eu-cyber-resilience-act</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-eu-cyber-resilience-act</guid>
      <pubDate>Thu, 26 Feb 2026 01:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Definition: How It Differs From DevOps and SecOps Alone]]></title>
      <description><![CDATA[The devsecops definition that actually matters isn't a new tool category — it's making security a shared responsibility across the pipeline instead of a gate at the end.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-definition-vs-devops-vs-secops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-definition-vs-devops-vs-secops</guid>
      <pubDate>Thu, 26 Feb 2026 00:43:33 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Lateral movement]]></title>
      <description><![CDATA[A precise breakdown of what lateral movement is, the MITRE ATT&CK techniques and pivoting methods attackers use, and how to detect them before they spread.]]></description>
      <link>https://safeguard.sh/resources/blog/lateral-movement</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lateral-movement</guid>
      <pubDate>Thu, 26 Feb 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Kotlin Multiplatform Supply Chain Risks]]></title>
      <description><![CDATA[Kotlin Multiplatform ships one codebase to JVM, iOS, Android, JS, and native targets. The supply chain surface expands in specific ways worth tracking.]]></description>
      <link>https://safeguard.sh/resources/blog/kotlin-multiplatform-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kotlin-multiplatform-supply-chain-risks</guid>
      <pubDate>Wed, 25 Feb 2026 23:23:06 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[containerd Security Configuration Guide]]></title>
      <description><![CDATA[containerd runs most of Kubernetes today. Its defaults are reasonable, but reasonable is not hardened. Here is how to close the gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/containerd-security-configuration-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/containerd-security-configuration-guide</guid>
      <pubDate>Wed, 25 Feb 2026 22:02:40 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[False Positive Rates in Container Scanning: Why Your Scanner Lies to You]]></title>
      <description><![CDATA[Container scanners produce mountains of findings. A significant percentage are false positives. Here is how to measure and manage the noise.]]></description>
      <link>https://safeguard.sh/resources/blog/false-positive-rates-container-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/false-positive-rates-container-scanning</guid>
      <pubDate>Wed, 25 Feb 2026 20:42:13 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Disaster Recovery for Supply Chain Security Incidents]]></title>
      <description><![CDATA[When a critical dependency is compromised, your disaster recovery plan determines whether you recover in hours or weeks. Most DR plans do not cover this scenario.]]></description>
      <link>https://safeguard.sh/resources/blog/disaster-recovery-supply-chain-incidents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/disaster-recovery-supply-chain-incidents</guid>
      <pubDate>Wed, 25 Feb 2026 19:21:46 GMT</pubDate>
      <category>Security Operations</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Executive Order 14028, Three Years Later: Progress, Gaps, and What Comes Next]]></title>
      <description><![CDATA[Three years after the landmark cybersecurity executive order, SBOM adoption is growing but uneven, secure development attestation is rolling out, and the gap between policy and practice remains wide.]]></description>
      <link>https://safeguard.sh/resources/blog/eo-14028-three-years-later-progress-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eo-14028-three-years-later-progress-report</guid>
      <pubDate>Wed, 25 Feb 2026 18:01:20 GMT</pubDate>
      <category>Policy & Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CNCF Project Security Audits: What They Find and Why They Matter]]></title>
      <description><![CDATA[The Cloud Native Computing Foundation funds independent security audits for its projects. The findings reveal patterns that every cloud native adopter should understand.]]></description>
      <link>https://safeguard.sh/resources/blog/cncf-project-security-audits</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cncf-project-security-audits</guid>
      <pubDate>Wed, 25 Feb 2026 16:40:53 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Dell Data Breach Exposes 49 Million Customer Records via API Abuse]]></title>
      <description><![CDATA[In May 2024, Dell Technologies disclosed a breach exposing 49 million customer records after a threat actor exploited a partner portal API to scrape names, addresses, and purchase details, then attempted to sell the data online.]]></description>
      <link>https://safeguard.sh/resources/blog/dell-49-million-customer-records</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dell-49-million-customer-records</guid>
      <pubDate>Wed, 25 Feb 2026 15:20:26 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[AWS CodeBuild Supply Chain Hardening Guide]]></title>
      <description><![CDATA[CodeBuild projects are where most AWS supply chain compromises end up executing. Here is a practical hardening guide built from years of incident response, with specific buildspec controls and IAM patterns.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-codebuild-supply-chain-hardening-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-codebuild-supply-chain-hardening-guide</guid>
      <pubDate>Wed, 25 Feb 2026 14:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Zero-CVE Images vs Hardening Your Own: Cost and Risk Compared]]></title>
      <description><![CDATA[Buy zero-CVE base images or build hardened ones yourself? A cost-and-risk comparison with real numbers: engineering hours, subscription pricing, and CVE half-life.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-cve-images-vs-hardening-your-own-cost-and-risk-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-cve-images-vs-hardening-your-own-cost-and-risk-compared</guid>
      <pubDate>Wed, 25 Feb 2026 14:00:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Aisha Bello)</author>
    </item>
    <item>
      <title><![CDATA[APT29 Cozy Bear: Supply Chain Tradecraft]]></title>
      <description><![CDATA[How Russia's SVR-linked APT29 quietly industrialized supply chain compromise from SolarWinds to TeamCity and JetBrains tooling.]]></description>
      <link>https://safeguard.sh/resources/blog/apt29-cozy-bear-supply-chain-tradecraft</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apt29-cozy-bear-supply-chain-tradecraft</guid>
      <pubDate>Wed, 25 Feb 2026 12:39:33 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GCP Binary Authorization Attestation Verifier: Production Patterns]]></title>
      <description><![CDATA[Binary Authorization in 2026 moved from breakglass-heavy gatekeeping to attestation-driven trust. We unpack how to design verifiers that scale across teams and clusters.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-binary-authorization-attestation-verifier-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-binary-authorization-attestation-verifier-2026</guid>
      <pubDate>Wed, 25 Feb 2026 12:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs GPT-5: Enterprise Controls]]></title>
      <description><![CDATA[Frontier models offer impressive enterprise features. Security programs need deeper controls than chat can provide—controls that live in the engine around the model.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-gpt-5-enterprise-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-gpt-5-enterprise-controls</guid>
      <pubDate>Wed, 25 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Why Engine-Plus-LLM Beats Pure-LLM: Griffin vs Mythos]]></title>
      <description><![CDATA[The structural case for engine-plus-LLM security reasoning — and why pure-LLM products in the Mythos class hit a ceiling that no parameter count can raise.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-engine-plus-llm-advantage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-engine-plus-llm-advantage</guid>
      <pubDate>Wed, 25 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Task-Routed LLM Architectures For Security]]></title>
      <description><![CDATA[One model for every task wastes budget on trivial work. Task-routed architectures match model capability to task requirements — the right lever for security at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/task-routed-llm-architectures-for-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/task-routed-llm-architectures-for-security</guid>
      <pubDate>Wed, 25 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Windsurf vs Sourcegraph Cody: Security Comparison]]></title>
      <description><![CDATA[A side-by-side security comparison of Windsurf and Sourcegraph Cody: data handling, agent scope, deployment models, and enterprise controls.]]></description>
      <link>https://safeguard.sh/resources/blog/windsurf-cody-security-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/windsurf-cody-security-comparison</guid>
      <pubDate>Wed, 25 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is a Security Audit]]></title>
      <description><![CDATA[A security audit is an evidence-based check that your controls actually meet a standard. Here's the process, the main frameworks, and how it differs from a pentest.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-security-audit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-security-audit</guid>
      <pubDate>Wed, 25 Feb 2026 11:19:06 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Cosign v3.0 Migration Guide for Production Teams]]></title>
      <description><![CDATA[Sigstore Cosign v3.0 flips four behaviours to defaults: bundle format, trusted root, signing config, and statement-based attestations. Here's a clean upgrade plan.]]></description>
      <link>https://safeguard.sh/resources/blog/cosign-v3-migration-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cosign-v3-migration-guide-2026</guid>
      <pubDate>Wed, 25 Feb 2026 11:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Microsoft Midnight Blizzard Source Code Theft 2024]]></title>
      <description><![CDATA[Midnight Blizzard moved from email exfiltration to Microsoft source code repositories. The pivot from stolen OAuth tokens to code access is the supply chain lesson.]]></description>
      <link>https://safeguard.sh/resources/blog/microsoft-midnight-blizzard-source-code-theft-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microsoft-midnight-blizzard-source-code-theft-2024</guid>
      <pubDate>Wed, 25 Feb 2026 10:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOMs for Firmware and IoT Devices: The Hard Problem]]></title>
      <description><![CDATA[Generating accurate SBOMs for firmware and IoT devices remains one of the toughest challenges in supply chain security. Here's the current state of the art.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-firmware-iot-devices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-firmware-iot-devices</guid>
      <pubDate>Wed, 25 Feb 2026 10:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What is a Security Policy]]></title>
      <description><![CDATA[A security policy is the documented, executive-approved rulebook auditors test against — here's what belongs in one, how often to review it, and what breaks when it isn't enforced.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-security-policy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-security-policy</guid>
      <pubDate>Wed, 25 Feb 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Application Vulnerabilities: The Common Classes Explained]]></title>
      <description><![CDATA[Injection, broken access control, and misconfiguration account for most real-world breaches. Here's a plain map of the classes that matter and how each one is actually exploited.]]></description>
      <link>https://safeguard.sh/resources/blog/application-vulnerabilities-common-classes-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-vulnerabilities-common-classes-explained</guid>
      <pubDate>Wed, 25 Feb 2026 09:58:39 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AI-Managed Security Services: What You're Actually Buying]]></title>
      <description><![CDATA[AI managed security is sold as autonomous defense, but the honest version of the pitch is faster triage and drafted fixes with a human still signing off — worth knowing before you buy the marketing version.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-managed-security-services-what-you-are-actually-buying</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-managed-security-services-what-you-are-actually-buying</guid>
      <pubDate>Wed, 25 Feb 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Cozy Bear / Midnight Blizzard Supply Chain Tactics]]></title>
      <description><![CDATA[Midnight Blizzard (APT29, Cozy Bear) has refined long-dwell supply chain access into an operational art. Here is what their 2023-2025 pattern looks like to defenders.]]></description>
      <link>https://safeguard.sh/resources/blog/apt-cozy-bear-midnight-blizzard-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apt-cozy-bear-midnight-blizzard-supply-chain</guid>
      <pubDate>Wed, 25 Feb 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[DORA for Financial Services Software Supply Chain]]></title>
      <description><![CDATA[How EU DORA is reshaping software supply chain expectations for financial services in 2026, with practical guidance on ICT third-party risk, SBOMs, and incident reporting.]]></description>
      <link>https://safeguard.sh/resources/blog/dora-eu-software-supply-chain-for-financial-services</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dora-eu-software-supply-chain-for-financial-services</guid>
      <pubDate>Wed, 25 Feb 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Insecure deserialization attack]]></title>
      <description><![CDATA[A precise breakdown of what is an insecure deserialization attack, how object injection and gadget chains work in Java and Python, and how to defend against them.]]></description>
      <link>https://safeguard.sh/resources/blog/insecure-deserialization-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insecure-deserialization-attack</guid>
      <pubDate>Wed, 25 Feb 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Egress Filtering in CI]]></title>
      <description><![CDATA[Egress filtering in CI restricts where build jobs can send traffic, so a compromised dependency can't exfiltrate your secrets. Here's how to roll it out without breaking builds.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-egress-filtering-in-ci</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-egress-filtering-in-ci</guid>
      <pubDate>Wed, 25 Feb 2026 08:38:13 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Tomas Lindgren)</author>
    </item>
    <item>
      <title><![CDATA[Quantifying Digital Supply Chain Risk]]></title>
      <description><![CDATA[Security teams struggle to express supply chain risk in business terms. This guide covers frameworks and methods for quantifying dependency risk in ways that boards and executives actually understand.]]></description>
      <link>https://safeguard.sh/resources/blog/digital-supply-chain-risk-quantification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/digital-supply-chain-risk-quantification</guid>
      <pubDate>Wed, 25 Feb 2026 07:17:46 GMT</pubDate>
      <category>Risk Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is a Security Risk Assessment]]></title>
      <description><![CDATA[A security risk assessment ranks real business risk, not raw CVE counts. Here's what it involves, how often it's required, and how it differs from scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-security-risk-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-security-risk-assessment</guid>
      <pubDate>Wed, 25 Feb 2026 07:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[XXE (XML External Entity) attack]]></title>
      <description><![CDATA[A precise breakdown of what an XXE attack is, how XML external entity injection works, a real-world exploit example, the billion laughs attack, and prevention techniques.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-xml-external-entity-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-xml-external-entity-attack</guid>
      <pubDate>Wed, 25 Feb 2026 06:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Next.js Security Hardening Guide]]></title>
      <description><![CDATA[Harden your Next.js application with secure headers, API route protection, and server component safety practices.]]></description>
      <link>https://safeguard.sh/resources/blog/nextjs-security-hardening-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nextjs-security-hardening-guide</guid>
      <pubDate>Wed, 25 Feb 2026 05:57:19 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Maven Plugin Verification: Securing Your Java Build Pipeline]]></title>
      <description><![CDATA[Maven plugins execute during your build with full JVM access. Here is how to verify they are legitimate and have not been tampered with.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-plugin-verification-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-plugin-verification-guide</guid>
      <pubDate>Wed, 25 Feb 2026 04:36:53 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What is Compliance Automation]]></title>
      <description><![CDATA[Compliance automation replaces manual audit evidence with continuous, API-driven monitoring — here's how it works, which frameworks it covers, and why supply chain evidence changes the equation.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-compliance-automation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-compliance-automation</guid>
      <pubDate>Wed, 25 Feb 2026 04:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Homebrew Cask Security Verification: What Gets Checked Before Installation]]></title>
      <description><![CDATA[Homebrew Cask installs macOS applications from the command line. Here is what security verification happens (and what does not) before software lands on your Mac.]]></description>
      <link>https://safeguard.sh/resources/blog/homebrew-cask-security-verification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/homebrew-cask-security-verification</guid>
      <pubDate>Wed, 25 Feb 2026 03:16:26 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Pass-the-hash attack]]></title>
      <description><![CDATA[What is a pass-the-hash attack? Learn how NTLM hash theft enables lateral movement across Windows networks, with real-world examples and mitigation strategies.]]></description>
      <link>https://safeguard.sh/resources/blog/pass-the-hash-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pass-the-hash-attack</guid>
      <pubDate>Wed, 25 Feb 2026 03:00:00 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What Is DevSecOps? Explained in Plain Terms]]></title>
      <description><![CDATA[A plain-terms answer to devsecops o que e, the Portuguese-language version of 'what is DevSecOps,' with the same explanation that applies regardless of what language you searched in.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-o-que-e-devsecops-explained-in-plain-terms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-o-que-e-devsecops-explained-in-plain-terms</guid>
      <pubDate>Wed, 25 Feb 2026 01:55:59 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is the OWASP Software Assurance Maturity Model (SAMM)]]></title>
      <description><![CDATA[A concrete breakdown of OWASP SAMM's 5 functions, 15 practices, and 30 streams, how its maturity levels work, and how it compares to BSIMM.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-owasp-software-assurance-maturity-model-samm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-owasp-software-assurance-maturity-model-samm</guid>
      <pubDate>Wed, 25 Feb 2026 01:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Third-Party Risk Management for Software Vendors]]></title>
      <description><![CDATA[A practical TPRM program for software vendors covering intake, tiering, annual review, SBOM ingestion, and continuous monitoring with staffing ratios and budgets.]]></description>
      <link>https://safeguard.sh/resources/blog/third-party-risk-management-software-vendors-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/third-party-risk-management-software-vendors-program</guid>
      <pubDate>Wed, 25 Feb 2026 00:35:33 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-45519 Zimbra Unauth RCE Breakdown]]></title>
      <description><![CDATA[A technical breakdown of CVE-2024-45519, the unauthenticated RCE in Zimbra's postjournal service, how it was exploited in the wild, and what defenders should take away.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-45519-zimbra-unauth-rce-breakdown</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-45519-zimbra-unauth-rce-breakdown</guid>
      <pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Golden ticket attack]]></title>
      <description><![CDATA[A golden ticket attack forges Kerberos TGTs using a stolen krbtgt hash, giving attackers persistent, near-total control over Active Directory.]]></description>
      <link>https://safeguard.sh/resources/blog/golden-ticket-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/golden-ticket-attack</guid>
      <pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Open Source AI Model Security: The Emerging Threat Landscape]]></title>
      <description><![CDATA[As open source AI models proliferate, their security implications extend far beyond traditional software vulnerabilities. Model poisoning, supply chain tampering, and unsafe deserialization create new attack surfaces.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-ai-model-security-landscape</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-ai-model-security-landscape</guid>
      <pubDate>Tue, 24 Feb 2026 23:15:06 GMT</pubDate>
      <category>Emerging Threats</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Developer Workstation Forensics for Supply Chain]]></title>
      <description><![CDATA[Forensic procedures for a developer workstation that may have executed a malicious package, from live triage through full imaging.]]></description>
      <link>https://safeguard.sh/resources/blog/developer-workstation-forensics-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/developer-workstation-forensics-supply-chain</guid>
      <pubDate>Tue, 24 Feb 2026 21:54:39 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SAST Tool Accuracy Benchmarks 2024: What the Data Actually Shows]]></title>
      <description><![CDATA[Static Application Security Testing tools vary dramatically in accuracy. We analyze detection rates, false positive rates, and language coverage across leading SAST tools using standardized benchmarks.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-tool-accuracy-benchmarks-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-tool-accuracy-benchmarks-2024</guid>
      <pubDate>Tue, 24 Feb 2026 20:34:12 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[GraphQL Injection Prevention: Securing Your API Layer]]></title>
      <description><![CDATA[GraphQL's flexible query language introduces injection risks that differ fundamentally from REST APIs. Preventing GraphQL injection requires understanding the query parser, resolver chain, and schema design.]]></description>
      <link>https://safeguard.sh/resources/blog/graphql-injection-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/graphql-injection-prevention</guid>
      <pubDate>Tue, 24 Feb 2026 19:13:46 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What is Repo-Jacking]]></title>
      <description><![CDATA[Repo-jacking hijacks renamed or deleted GitHub namespaces to serve attacker code at trusted URLs. Here's how the redirect trick works and how to audit your exposure.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-repo-jacking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-repo-jacking</guid>
      <pubDate>Tue, 24 Feb 2026 17:53:19 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Jonas Meyer)</author>
    </item>
    <item>
      <title><![CDATA[CMMC Level 2 for Software Vendors: A Practical Roadmap]]></title>
      <description><![CDATA[CMMC Level 2 means all 110 NIST SP 800-171 controls, assessed by a C3PAO for most contractors. Here's the scoping, gap-closing, and evidence roadmap for software vendors.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-level-2-for-software-vendors-a-practical-roadmap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-level-2-for-software-vendors-a-practical-roadmap</guid>
      <pubDate>Tue, 24 Feb 2026 16:32:52 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Tomas Lindgren)</author>
    </item>
    <item>
      <title><![CDATA[How to Meet EO 14028 Self-Attestation Requirements Step by Step]]></title>
      <description><![CDATA[The CISA attestation form is final and the deadlines are real. Here is the step-by-step path: scope, SSDF evidence, POA&Ms, and RSAA submission.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-meet-eo-14028-self-attestation-requirements-step-by-step</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-meet-eo-14028-self-attestation-requirements-step-by-step</guid>
      <pubDate>Tue, 24 Feb 2026 15:12:26 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Priya Raman)</author>
    </item>
    <item>
      <title><![CDATA[MCP Definition: What the Model Context Protocol Actually Is]]></title>
      <description><![CDATA[The MCP definition in one line: an open standard that lets AI assistants connect to your tools and data through a single, consistent interface instead of a tangle of one-off integrations.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-definition</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-definition</guid>
      <pubDate>Tue, 24 Feb 2026 14:10:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Tailwind Vue Components: Vetting Them Before You Ship]]></title>
      <description><![CDATA[Tailwind Vue components speed up UI work, but every third-party component library is a dependency you inherit. Here is how to pick and audit them safely.]]></description>
      <link>https://safeguard.sh/resources/blog/tailwind-vue-components</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tailwind-vue-components</guid>
      <pubDate>Tue, 24 Feb 2026 14:10:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Open Source Manager: Understanding the Health of Your Dependencies]]></title>
      <description><![CDATA[Vulnerability counts do not tell the full story. Open Source Manager evaluates the health, maintainability, and trustworthiness of the open-source projects your software depends on.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-open-source-manager-launch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-open-source-manager-launch</guid>
      <pubDate>Tue, 24 Feb 2026 13:51:59 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Spring Dependency Management Supply Chain]]></title>
      <description><![CDATA[Spring Boot's dependency management is the unsung hero of the Java ecosystem, and it is also a supply chain seam worth understanding. Here is how BOMs, starters, and transitive version coercion shape what actually ships.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-dependency-management-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-dependency-management-supply-chain</guid>
      <pubDate>Tue, 24 Feb 2026 12:31:32 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Container Security Scanner: How It Works and What to Use]]></title>
      <description><![CDATA[A Kubernetes container security scanner checks images, manifests, and running workloads for known vulnerabilities and misconfigurations. Here is how the pieces fit and where to place them in a pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-container-security-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-container-security-scanner</guid>
      <pubDate>Tue, 24 Feb 2026 12:10:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Retrieval Context Poisoning At Scale]]></title>
      <description><![CDATA[Retrieval context poisoning scales differently than direct prompt injection. The attacker&apos;s leverage grows with the RAG ingest surface.]]></description>
      <link>https://safeguard.sh/resources/blog/frontier-model-limit-retrieval-context-poisoning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/frontier-model-limit-retrieval-context-poisoning</guid>
      <pubDate>Tue, 24 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Gemini Multimodal: Security]]></title>
      <description><![CDATA[Gemini's multimodal capabilities are genuinely useful for some security workflows. For most security workflows, the modality is code and text, not images.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-multimodal-for-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-multimodal-for-security</guid>
      <pubDate>Tue, 24 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Federal Compliance Readiness: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Federal compliance is a long investment, not a marketing claim. Safeguard's FedRAMP HIGH and IL7 readiness is the difference between selling into government and sitting on the outside.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-federal-compliance-readiness</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-federal-compliance-readiness</guid>
      <pubDate>Tue, 24 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What Is the AI Bill of Rights and What Does It Mean for Security Teams?]]></title>
      <description><![CDATA[The AI Bill of Rights is a White House blueprint of five principles for building automated systems that respect people's rights. Here is what it says and how it maps to real engineering controls.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-bill-of-rights</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-bill-of-rights</guid>
      <pubDate>Tue, 24 Feb 2026 11:40:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[AWS AppConfig Dynamic Config Security]]></title>
      <description><![CDATA[AppConfig ships configuration changes to running applications in seconds. That makes it a powerful tool and a compelling target. Here is how to run AppConfig safely.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-appconfig-dynamic-config-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-appconfig-dynamic-config-security</guid>
      <pubDate>Tue, 24 Feb 2026 11:11:06 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Incident Response Playbook for a Compromised Dependency]]></title>
      <description><![CDATA[A concrete, timed playbook for the 72 hours after a critical dependency advisory — inventory, reachability, containment, remediation, and retrospective.]]></description>
      <link>https://safeguard.sh/resources/blog/incident-response-playbook-compromised-dependency</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/incident-response-playbook-compromised-dependency</guid>
      <pubDate>Tue, 24 Feb 2026 10:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Security Explained]]></title>
      <description><![CDATA[JavaScript security means managing three attack surfaces: runtime bugs, browser XSS, and npm supply chain compromise — the last of which caused 2025's biggest incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-security-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-security-explained</guid>
      <pubDate>Tue, 24 Feb 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Chronicle Security Supply Chain Queries]]></title>
      <description><![CDATA[Writing YARA-L detection rules and UDM queries in Google Chronicle (now Security Operations) to catch software supply chain threats at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/chronicle-security-supply-chain-queries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chronicle-security-supply-chain-queries</guid>
      <pubDate>Tue, 24 Feb 2026 09:50:39 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Photo Analysis AI: Security and Privacy Risks You Should Know]]></title>
      <description><![CDATA[Photo analysis AI can read faces, locations, and text out of images at scale. The security questions are about where those images go and what the model leaks back.]]></description>
      <link>https://safeguard.sh/resources/blog/photo-analysis-ai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/photo-analysis-ai</guid>
      <pubDate>Tue, 24 Feb 2026 09:50:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Securing Spring Security OAuth2 and JOSE Dependencies]]></title>
      <description><![CDATA[spring-security-oauth2-jose sits at the center of many Java auth stacks, but the legacy project is deprecated and its JOSE/JWT dependencies carry their own patch history; here is how to assess and reduce the risk.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-security-oauth2-and-jose-dependency-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-security-oauth2-and-jose-dependency-security</guid>
      <pubDate>Tue, 24 Feb 2026 09:20:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AWS EKS Pod Identity vs. IRSA for Supply Chain]]></title>
      <description><![CDATA[Pod Identity and IRSA both give EKS workloads AWS identities. The supply chain implications diverge once you look past the docs.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-eks-pod-identity-vs-irsa-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-eks-pod-identity-vs-irsa-supply-chain</guid>
      <pubDate>Tue, 24 Feb 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Buy vs. Build a Supply Chain Security Platform]]></title>
      <description><![CDATA[When building your own software supply chain security platform makes sense, when it does not, and the hybrid architecture most mature teams actually land on.]]></description>
      <link>https://safeguard.sh/resources/blog/buy-vs-build-supply-chain-security-platform</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buy-vs-build-supply-chain-security-platform</guid>
      <pubDate>Tue, 24 Feb 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Living off the land (LOTL) techniques]]></title>
      <description><![CDATA[A precise breakdown of living off the land (LOTL) attacks: how LOLBins, fileless malware, and dual-use tool abuse let intruders hide in plain sight.]]></description>
      <link>https://safeguard.sh/resources/blog/living-off-the-land-lotl-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/living-off-the-land-lotl-techniques</guid>
      <pubDate>Tue, 24 Feb 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[pnpm and Yarn Modern Lockfile Security]]></title>
      <description><![CDATA[pnpm-lock.yaml and yarn.lock look similar on the surface but enforce different security properties. Here is what matters in 2026, and what still trips teams up.]]></description>
      <link>https://safeguard.sh/resources/blog/pnpm-yarn-modern-lockfile-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pnpm-yarn-modern-lockfile-security</guid>
      <pubDate>Tue, 24 Feb 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Twilio 2022 Incidents: Supply Chain Lessons]]></title>
      <description><![CDATA[Twilio disclosed two social engineering incidents in 2022 that cascaded through its customer base; the supply chain lessons remain relevant for any B2B vendor.]]></description>
      <link>https://safeguard.sh/resources/blog/twilio-2022-incidents-supply-chain-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/twilio-2022-incidents-supply-chain-lessons</guid>
      <pubDate>Tue, 24 Feb 2026 08:30:12 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Critical Infrastructure Software Supply Chain]]></title>
      <description><![CDATA[How the 16 critical infrastructure sectors are absorbing software supply chain obligations under PPD-21, NSM-22, and CISA's emerging frameworks.]]></description>
      <link>https://safeguard.sh/resources/blog/critical-infrastructure-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/critical-infrastructure-software-supply-chain</guid>
      <pubDate>Tue, 24 Feb 2026 07:09:46 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Node.js Security Best Practices]]></title>
      <description><![CDATA[Node.js supply chain attacks like event-stream, ua-parser-js, and Shai-Hulud show why dependency depth is the real risk -- here's what actually reduces it.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-security-best-practices</guid>
      <pubDate>Tue, 24 Feb 2026 07:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Business email compromise (BEC)]]></title>
      <description><![CDATA[Business email compromise (BEC) tricks employees into wiring funds or data to attackers posing as executives or vendors. Here is how BEC fraud actually works.]]></description>
      <link>https://safeguard.sh/resources/blog/business-email-compromise-bec</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/business-email-compromise-bec</guid>
      <pubDate>Tue, 24 Feb 2026 06:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Coordinated Vulnerability Disclosure: A Complete Guide]]></title>
      <description><![CDATA[Coordinated disclosure protects users while giving vendors time to fix. Here is how to run a disclosure process that works for all parties, whether you are the reporter or the vendor.]]></description>
      <link>https://safeguard.sh/resources/blog/coordinated-vulnerability-disclosure-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/coordinated-vulnerability-disclosure-guide</guid>
      <pubDate>Tue, 24 Feb 2026 05:49:19 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to Audit Python Dependencies with pip-audit (and What It Misses)]]></title>
      <description><![CDATA[pip-audit checks your Python dependencies against the PyPA advisory database in one command. Here is how to run it well in CI, and the four gaps it leaves open.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-audit-python-dependencies-with-pip-audit-and-what-it-misses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-audit-python-dependencies-with-pip-audit-and-what-it-misses</guid>
      <pubDate>Tue, 24 Feb 2026 04:28:52 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Tomas Lindgren)</author>
    </item>
    <item>
      <title><![CDATA[Python Security Explained]]></title>
      <description><![CDATA[How Python's install-time code execution and open PyPI namespace fuel real supply chain attacks — and what actually reduces the risk.]]></description>
      <link>https://safeguard.sh/resources/blog/python-security-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-security-explained</guid>
      <pubDate>Tue, 24 Feb 2026 04:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[npm Registry Authentication Deep Dive]]></title>
      <description><![CDATA[The npm registry supports four distinct authentication flows. Most teams use one, badly. A tour of how auth actually works, what the tokens look like, and where the model breaks.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-registry-authentication-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-registry-authentication-deep-dive</guid>
      <pubDate>Tue, 24 Feb 2026 03:08:25 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Medical Device SBOM Requirements in Practice]]></title>
      <description><![CDATA[SBOMs for medical devices look straightforward on paper and get complicated fast in the real world. A field report on what regulators actually accept and what engineering teams actually produce.]]></description>
      <link>https://safeguard.sh/resources/blog/medical-device-sbom-requirements-practical</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/medical-device-sbom-requirements-practical</guid>
      <pubDate>Tue, 24 Feb 2026 01:47:59 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Java Security Explained]]></title>
      <description><![CDATA[Java security failures like Log4Shell exposed 3 billion devices — here's why Java's dependency depth makes it uniquely risky, and how to fix it fast.]]></description>
      <link>https://safeguard.sh/resources/blog/java-security-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-security-explained</guid>
      <pubDate>Tue, 24 Feb 2026 01:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[EU NIS2 Directive: What Software Supply Chain Teams Need to Know]]></title>
      <description><![CDATA[The NIS2 Directive imposes new cybersecurity obligations across the EU, with specific requirements for supply chain risk management that affect software vendors and their customers.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-nis2-directive-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-nis2-directive-software-supply-chain</guid>
      <pubDate>Tue, 24 Feb 2026 00:27:32 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[GitOps]]></title>
      <description><![CDATA[What is GitOps? A clear definition of the Git-driven deployment model, how it differs from DevOps, and what its security model protects against.]]></description>
      <link>https://safeguard.sh/resources/blog/gitops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitops</guid>
      <pubDate>Tue, 24 Feb 2026 00:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Secrets sprawl]]></title>
      <description><![CDATA[What is secrets sprawl? A plain-English breakdown of how API keys and credentials scatter across codebases, and what to do about it.]]></description>
      <link>https://safeguard.sh/resources/blog/secrets-sprawl</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secrets-sprawl</guid>
      <pubDate>Tue, 24 Feb 2026 00:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Taint Analysis for Zero-Day Discovery: A Primer]]></title>
      <description><![CDATA[A practitioner's walk-through of taint analysis as a zero-day discovery technique, from classic Livshits and Lam foundations to modern flow-sensitive engines.]]></description>
      <link>https://safeguard.sh/resources/blog/taint-analysis-for-zero-day-discovery-primer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/taint-analysis-for-zero-day-discovery-primer</guid>
      <pubDate>Mon, 23 Feb 2026 23:07:05 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Supply Chain Attacks: Q1 2024 Roundup]]></title>
      <description><![CDATA[Q1 2024 brought typosquats, stealer campaigns, and a week-long new-user freeze on PyPI. Here is what the attacks looked like and how to defend.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-supply-chain-attacks-q1-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-supply-chain-attacks-q1-2024</guid>
      <pubDate>Mon, 23 Feb 2026 21:46:39 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[1Password Secrets Automation in CI]]></title>
      <description><![CDATA[1Password has quietly become a credible secrets backend for CI/CD. A walkthrough of Connect, Service Accounts, and the CLI patterns that make 1Password Secrets Automation work in a build pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/one-password-secrets-automation-ci</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/one-password-secrets-automation-ci</guid>
      <pubDate>Mon, 23 Feb 2026 20:26:12 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Corporate OSS Contribution Policies]]></title>
      <description><![CDATA[Google, Microsoft, Red Hat, and a long tail of smaller companies have built contribution policies that shape how their engineers participate in open source. The policies vary more than most assume.]]></description>
      <link>https://safeguard.sh/resources/blog/corporate-oss-contribution-policies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/corporate-oss-contribution-policies</guid>
      <pubDate>Mon, 23 Feb 2026 19:05:45 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to Write a Vulnerability Disclosure Policy Developers Respect]]></title>
      <description><![CDATA[Most VDPs are lawyer documents nobody reads. Here is how to write one with real safe harbor, honest SLAs, and an intake path researchers will actually use.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-write-a-vulnerability-disclosure-policy-developers-respect</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-write-a-vulnerability-disclosure-policy-developers-respect</guid>
      <pubDate>Mon, 23 Feb 2026 17:45:19 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Jonas Meyer)</author>
    </item>
    <item>
      <title><![CDATA[Malware Types: A Practitioner's Taxonomy]]></title>
      <description><![CDATA[A reference list of all malware types by how they spread and what they do — worms, trojans, ransomware, rootkits, and the rest — because knowing the category tells you what defense actually stops it.]]></description>
      <link>https://safeguard.sh/resources/blog/malware-types-a-practitioners-taxonomy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malware-types-a-practitioners-taxonomy</guid>
      <pubDate>Mon, 23 Feb 2026 16:24:52 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Azure DevOps YAML Pipeline Hardening]]></title>
      <description><![CDATA[A practical, line-by-line walk through hardening Azure DevOps YAML pipelines — template injection, task version pinning, approvals, and the defaults that will bite you.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-devops-yaml-pipeline-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-devops-yaml-pipeline-hardening</guid>
      <pubDate>Mon, 23 Feb 2026 15:04:25 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Container Security Scanning in 2024: Benchmarks, Tools, and What Actually Matters]]></title>
      <description><![CDATA[Container image scanning tools vary widely in detection rates, false positive rates, and coverage. Here is a practical assessment of the container security scanning landscape in 2024.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-scanning-benchmarks-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-scanning-benchmarks-2024</guid>
      <pubDate>Mon, 23 Feb 2026 13:43:59 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SLSA Level 3 in Practice: What It Takes]]></title>
      <description><![CDATA[SLSA Build L3 is achievable in a week per repo if you use a hosted builder — and nearly impossible if you insist on rolling your own. Here is the practical path.]]></description>
      <link>https://safeguard.sh/resources/blog/slsa-level-3-in-practice-what-it-takes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slsa-level-3-in-practice-what-it-takes</guid>
      <pubDate>Mon, 23 Feb 2026 12:23:32 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Tomas Lindgren)</author>
    </item>
    <item>
      <title><![CDATA[The Eval Culture Shift in AI Security]]></title>
      <description><![CDATA[Two years ago, AI vendors shipped without evals. In 2026, the posture has shifted. Customers expect benchmarks. Vendors without them lose deals.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-trend-eval-culture-shift</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-trend-eval-culture-shift</guid>
      <pubDate>Mon, 23 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Upgrade Picks: Griffin AI vs Mythos]]></title>
      <description><![CDATA[The version a remediation tool picks matters more than the fact that it picked one. Griffin AI grounds its choice in the project; Mythos-class tools do not.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-dependency-upgrade-recommendations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-dependency-upgrade-recommendations</guid>
      <pubDate>Mon, 23 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Sigstore Rekor Transparency Log Operations]]></title>
      <description><![CDATA[Rekor is the transparency log behind Sigstore, and understanding its operational model matters more than most teams realise. Here is how we run against it in production.]]></description>
      <link>https://safeguard.sh/resources/blog/sigstore-rekor-transparency-log-operations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sigstore-rekor-transparency-log-operations</guid>
      <pubDate>Mon, 23 Feb 2026 11:03:05 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[C# and .NET Security Explained]]></title>
      <description><![CDATA[C# and .NET security explained: real CVEs, NuGet supply-chain attacks, BinaryFormatter risk, and the SolarWinds lesson every .NET team needs.]]></description>
      <link>https://safeguard.sh/resources/blog/c-and-net-security-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/c-and-net-security-explained</guid>
      <pubDate>Mon, 23 Feb 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Gartner SRM Summit 2025 Recap]]></title>
      <description><![CDATA[Gartner's 2025 Security & Risk Management Summit pushed CISOs to focus on supply chain risk, AI governance, and measurable outcomes. Here is the analyst view.]]></description>
      <link>https://safeguard.sh/resources/blog/gartner-security-risk-management-summit-2025-recap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gartner-security-risk-management-summit-2025-recap</guid>
      <pubDate>Mon, 23 Feb 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems 2FA Enforcement Analysis]]></title>
      <description><![CDATA[A look at how RubyGems.org rolled out mandatory 2FA for high-traffic gem maintainers, what it has caught, and what gaps still remain in the account-compromise defense story.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-2fa-enforcement-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-2fa-enforcement-analysis</guid>
      <pubDate>Mon, 23 Feb 2026 09:42:38 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 Type II]]></title>
      <description><![CDATA[What is SOC 2 Type II? A clear breakdown of the audit report, Trust Services Criteria, and how it differs from Type I — with real audit examples.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-type-ii</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-type-ii</guid>
      <pubDate>Mon, 23 Feb 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Package Namespace Governance]]></title>
      <description><![CDATA[PyPI's flat global namespace is one of Python packaging's oldest design decisions. How it's governed today, where the tension points are, and what the PEP 752 debate means for the future.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-package-namespace-governance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-package-namespace-governance</guid>
      <pubDate>Mon, 23 Feb 2026 08:22:12 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Palo Alto GlobalProtect Zero-Day: Response Timeline]]></title>
      <description><![CDATA[CVE-2024-3400 hit GlobalProtect with pre-auth RCE and ongoing exploitation. Here is the response timeline, the UPSTYLE tradecraft, and what worked.]]></description>
      <link>https://safeguard.sh/resources/blog/palo-alto-globalprotect-zero-day-response-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/palo-alto-globalprotect-zero-day-response-2024</guid>
      <pubDate>Mon, 23 Feb 2026 07:01:45 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[PHP Security Explained]]></title>
      <description><![CDATA[PHP still runs ~74% of the web. From the 2024 PHP-CGI RCE to WordPress plugin flaws, here's what actually breaks PHP apps in production.]]></description>
      <link>https://safeguard.sh/resources/blog/php-security-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-security-explained</guid>
      <pubDate>Mon, 23 Feb 2026 07:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[CIS Benchmarks]]></title>
      <description><![CDATA[A precise definition of CIS Benchmarks, how they differ from CIS Controls, and what compliance scanning against them looks like in real environments.]]></description>
      <link>https://safeguard.sh/resources/blog/cis-benchmarks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cis-benchmarks</guid>
      <pubDate>Mon, 23 Feb 2026 06:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Conti Ransomware Supply Chain Patterns]]></title>
      <description><![CDATA[Before Conti splintered in 2022, its affiliates turned MSPs, RMM tools, and identity infrastructure into repeatable supply chain attack paths.]]></description>
      <link>https://safeguard.sh/resources/blog/conti-ransomware-supply-chain-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/conti-ransomware-supply-chain-patterns</guid>
      <pubDate>Mon, 23 Feb 2026 05:41:18 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Fuzzing]]></title>
      <description><![CDATA[Fuzzing feeds programs malformed input at machine speed to trigger crashes and expose memory-safety bugs. Here's how fuzz testing works and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-fuzzing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-fuzzing</guid>
      <pubDate>Mon, 23 Feb 2026 04:20:52 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Ruby Security Explained]]></title>
      <description><![CDATA[Ruby security in one place: the 2019 rest-client hijack, CVE-2022-32224's RCE, RubyGems' MFA mandate, and 2025's credential-stealing gem campaign.]]></description>
      <link>https://safeguard.sh/resources/blog/ruby-security-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ruby-security-explained</guid>
      <pubDate>Mon, 23 Feb 2026 04:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Black Basta Ransomware: Techniques and Tactics in 2024]]></title>
      <description><![CDATA[Black Basta evolved from a Conti offshoot into one of the most technically advanced ransomware operations, using novel initial access methods and sophisticated evasion techniques.]]></description>
      <link>https://safeguard.sh/resources/blog/black-basta-ransomware-techniques-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/black-basta-ransomware-techniques-2024</guid>
      <pubDate>Mon, 23 Feb 2026 03:00:25 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CVSS scoring]]></title>
      <description><![CDATA[What is CVSS? A clear breakdown of the Common Vulnerability Scoring System, base vs temporal scores, CVSS v4 changes, and how to prioritize real risk.]]></description>
      <link>https://safeguard.sh/resources/blog/cvss-scoring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cvss-scoring</guid>
      <pubDate>Mon, 23 Feb 2026 03:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[UK Product Security and Telecommunications Infrastructure Act: Software Implications]]></title>
      <description><![CDATA[The UK's PSTI Act bans default passwords and mandates vulnerability disclosure. Here's what it means for software embedded in connected products.]]></description>
      <link>https://safeguard.sh/resources/blog/uk-product-security-telecommunications-act</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uk-product-security-telecommunications-act</guid>
      <pubDate>Mon, 23 Feb 2026 01:39:58 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Go (Golang) Security Explained]]></title>
      <description><![CDATA[Go's memory safety stops buffer overflows, not logic bugs, typosquatted modules, or CI-pipeline compromise. Here's what actually threatens Go security.]]></description>
      <link>https://safeguard.sh/resources/blog/go-golang-security-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-golang-security-explained</guid>
      <pubDate>Mon, 23 Feb 2026 01:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[PHP Composer Security: Lockfiles, Packagist and Abandoned Packages]]></title>
      <description><![CDATA[composer.lock is your integrity anchor, Packagist is a single point of trust, and roughly one in ten packages you depend on is quietly unmaintained. A field guide.]]></description>
      <link>https://safeguard.sh/resources/blog/php-composer-security-lockfiles-packagist-and-abandoned-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-composer-security-lockfiles-packagist-and-abandoned-packages</guid>
      <pubDate>Mon, 23 Feb 2026 00:19:32 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Priya Raman)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2024-4577 PHP CGI Argument Injection Explained]]></title>
      <description><![CDATA[CVE-2024-4577 is a CVSS 9.8 argument injection in PHP-CGI on Windows that bypasses CVE-2012-1823's fix. Root cause, exploitation, and remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-4577-php-cgi-argument-injection-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-4577-php-cgi-argument-injection-explained</guid>
      <pubDate>Mon, 23 Feb 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CWE (Common Weakness Enumeration)]]></title>
      <description><![CDATA[What is CWE? A plain-English guide to the Common Weakness Enumeration, how it differs from CVE, its classification hierarchy, and the Top 25 list.]]></description>
      <link>https://safeguard.sh/resources/blog/cwe-common-weakness-enumeration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cwe-common-weakness-enumeration</guid>
      <pubDate>Mon, 23 Feb 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Insurance Industry Software Risk Assessment and Supply Chain Security]]></title>
      <description><![CDATA[Insurers manage massive amounts of sensitive data through complex software systems. Here's how the insurance industry should approach software supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/insurance-industry-software-risk-assessment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insurance-industry-software-risk-assessment</guid>
      <pubDate>Sun, 22 Feb 2026 22:59:05 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Penetration Testing CI/CD Pipelines]]></title>
      <description><![CDATA[Your CI/CD pipeline is a high-value target. Here's how to pen test build systems, artifact repositories, and deployment workflows for supply chain vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/penetration-testing-ci-cd-pipelines</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/penetration-testing-ci-cd-pipelines</guid>
      <pubDate>Sun, 22 Feb 2026 21:38:38 GMT</pubDate>
      <category>Offensive Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Incident Forensics Playbook]]></title>
      <description><![CDATA[A practical, hour-by-hour forensics playbook for responding to software supply chain incidents, from first alert through root cause and disclosure.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-incident-forensics-playbook</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-incident-forensics-playbook</guid>
      <pubDate>Sun, 22 Feb 2026 20:18:12 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Migrating Jenkins to GitHub Actions: Security]]></title>
      <description><![CDATA[A case study in moving a sprawling Jenkins estate to GitHub Actions without losing supply chain visibility, artifact integrity, or developer trust.]]></description>
      <link>https://safeguard.sh/resources/blog/migrating-from-jenkins-to-github-actions-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/migrating-from-jenkins-to-github-actions-security</guid>
      <pubDate>Sun, 22 Feb 2026 18:57:45 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GCP Cloud Functions Supply Chain Risks]]></title>
      <description><![CDATA[The supply-chain risks unique to GCP Cloud Functions: dependency resolution at deploy time, buildpack trust, runtime identity, and the audit trail the service does and does not give you.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-cloud-functions-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-cloud-functions-supply-chain-risks</guid>
      <pubDate>Sun, 22 Feb 2026 17:37:18 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Managing Third-Party Software Risk With Safeguard TPRM]]></title>
      <description><![CDATA[Your vendors' software is your risk. Safeguard TPRM gives you continuous visibility into the supply chain security posture of every third-party product you depend on.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-tprm-third-party-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-tprm-third-party-risk</guid>
      <pubDate>Sun, 22 Feb 2026 16:16:51 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[AWS Lambda Supply Chain Risks You Are Probably Ignoring]]></title>
      <description><![CDATA[Serverless does not mean secure. Here are the supply chain risks hiding in your Lambda functions and how to address them.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-lambda-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-lambda-supply-chain-risks</guid>
      <pubDate>Sun, 22 Feb 2026 14:56:25 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SPDX 3.0: What Changed and Why It Matters]]></title>
      <description><![CDATA[SPDX 3.0 is a major overhaul of the ISO-standard SBOM format. Here is a practical breakdown of the new profile system, linking model, and what it means for adoption.]]></description>
      <link>https://safeguard.sh/resources/blog/spdx-3-0-specification-what-changed</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spdx-3-0-specification-what-changed</guid>
      <pubDate>Sun, 22 Feb 2026 13:35:58 GMT</pubDate>
      <category>SBOM Standards</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Sisense Data Breach: When Your Analytics Platform Becomes the Threat]]></title>
      <description><![CDATA[CISA issued a rare advisory urging Sisense customers to reset credentials after attackers compromised the business intelligence platform, potentially accessing customer data across thousands of organizations.]]></description>
      <link>https://safeguard.sh/resources/blog/sisense-breach-cisa-advisory</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sisense-breach-cisa-advisory</guid>
      <pubDate>Sun, 22 Feb 2026 12:15:31 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA Supply Chain Controls: Griffin AI vs Mythos]]></title>
      <description><![CDATA[HIPAA's software supply chain expectations have sharpened in 2025-2026. Evidence generation is the difference between passing an audit and rerunning it.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-hipaa-supply-chain-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-hipaa-supply-chain-controls</guid>
      <pubDate>Sun, 22 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Source/Sink Classification: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Taint analysis only works if sources and sinks are labeled correctly. Griffin AI uses a curated catalog; Mythos-class tools infer on the fly.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-source-sink-classification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-source-sink-classification</guid>
      <pubDate>Sun, 22 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Registry Security Governance]]></title>
      <description><![CDATA[MCP servers are becoming a new dependency class with their own supply chain risks. How to think about registry governance, verification, and enterprise ingestion policy.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-registry-security-governance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-registry-security-governance</guid>
      <pubDate>Sun, 22 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Privacy Engineering in Software Supply Chains]]></title>
      <description><![CDATA[Privacy by design cannot stop at your own code. Every dependency, every third-party service, every SDK in your supply chain is a privacy decision. Here is how to engineer privacy across the full stack.]]></description>
      <link>https://safeguard.sh/resources/blog/privacy-engineering-supply-chains</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/privacy-engineering-supply-chains</guid>
      <pubDate>Sun, 22 Feb 2026 10:55:05 GMT</pubDate>
      <category>Privacy</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Agent-to-Agent Security in Multi-Agent Systems]]></title>
      <description><![CDATA[Multi-agent systems inherit every trust problem of single-agent systems and add a few more. Here is how the threat model actually shifts.]]></description>
      <link>https://safeguard.sh/resources/blog/agent-to-agent-security-multi-agent-systems</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agent-to-agent-security-multi-agent-systems</guid>
      <pubDate>Sun, 22 Feb 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[FAQ: When Do You Need a Dedicated SBOM Tool?]]></title>
      <description><![CDATA[When a scanner's built-in SBOM export stops being enough — signals you need a dedicated SBOM tool, what one actually does, and how to evaluate.]]></description>
      <link>https://safeguard.sh/resources/blog/faq-when-do-you-need-a-dedicated-sbom-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/faq-when-do-you-need-a-dedicated-sbom-tool</guid>
      <pubDate>Sun, 22 Feb 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Federal Software Procurement and SBOM Requirements: A Vendor's Playbook]]></title>
      <description><![CDATA[If you sell software to the US government, SBOM requirements are now non-negotiable. Here's a practical playbook for compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/federal-software-procurement-sbom-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/federal-software-procurement-sbom-requirements</guid>
      <pubDate>Sun, 22 Feb 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Rust Security Explained]]></title>
      <description><![CDATA[Rust kills most memory-safety bugs, but crates.io supply chain attacks and CVE-2024-24576 prove "written in Rust" isn't a security guarantee.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-security-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-security-explained</guid>
      <pubDate>Sun, 22 Feb 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Australia's Essential Eight and Software Supply Chain]]></title>
      <description><![CDATA[The ACSC's November 2023 Essential Eight update tightened patching, application control, and software inventory expectations that every Australian-regulated entity now has to evidence.]]></description>
      <link>https://safeguard.sh/resources/blog/australia-essential-eight-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/australia-essential-eight-supply-chain</guid>
      <pubDate>Sun, 22 Feb 2026 09:34:38 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CISA KEV catalog]]></title>
      <description><![CDATA[The CISA KEV catalog lists vulnerabilities with confirmed real-world exploitation. Here's what it is, how entries get added, deadlines, and remediation rules.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-kev-catalog</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-kev-catalog</guid>
      <pubDate>Sun, 22 Feb 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Multi-Arch Image Builds and Attestation Pitfalls]]></title>
      <description><![CDATA[Why multi-architecture container images break assumptions baked into signing, SBOM, and attestation tooling, and how to build a multi-arch pipeline that stays verifiable.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-arch-image-builds-attestation-pitfalls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-arch-image-builds-attestation-pitfalls</guid>
      <pubDate>Sun, 22 Feb 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Roku Credential Stuffing Attacks Compromise 576,000 Accounts]]></title>
      <description><![CDATA[In April 2024, Roku disclosed that two separate credential stuffing campaigns had compromised approximately 576,000 customer accounts, with attackers making fraudulent purchases and changing account details on some affected accounts.]]></description>
      <link>https://safeguard.sh/resources/blog/roku-576000-accounts-credential-stuffing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/roku-576000-accounts-credential-stuffing</guid>
      <pubDate>Sun, 22 Feb 2026 08:14:11 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[C/C++ Security Explained]]></title>
      <description><![CDATA[C/C++ still cause ~70% of critical CVEs. From Heartbleed to the xz backdoor, here's why memory bugs persist and how to find exploitable ones fast.]]></description>
      <link>https://safeguard.sh/resources/blog/cc-security-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cc-security-explained</guid>
      <pubDate>Sun, 22 Feb 2026 07:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Go Dependency Visualization for Security]]></title>
      <description><![CDATA[The Go module graph is comparatively small, which makes it one of the few ecosystems where visualizing dependencies is actually useful for security review rather than just pretty.]]></description>
      <link>https://safeguard.sh/resources/blog/go-dependency-visualization-for-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-dependency-visualization-for-security</guid>
      <pubDate>Sun, 22 Feb 2026 06:53:45 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Container escape]]></title>
      <description><![CDATA[A container escape lets attackers break out of a container into the host or other workloads. Learn how these attacks work, real CVEs, and Kubernetes risk.]]></description>
      <link>https://safeguard.sh/resources/blog/container-escape</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-escape</guid>
      <pubDate>Sun, 22 Feb 2026 06:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Envoy Proxy Security Hardening for Production Deployments]]></title>
      <description><![CDATA[Envoy powers service meshes and API gateways across the industry. Its default configuration prioritizes connectivity over security. Here is how to fix that.]]></description>
      <link>https://safeguard.sh/resources/blog/envoy-proxy-security-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/envoy-proxy-security-hardening</guid>
      <pubDate>Sun, 22 Feb 2026 05:33:18 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[BuildKit Cache Security Considerations for Container Builds]]></title>
      <description><![CDATA[BuildKit's caching is what makes container builds fast. It is also a potential vector for cache poisoning attacks if not properly secured.]]></description>
      <link>https://safeguard.sh/resources/blog/buildkit-cache-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buildkit-cache-security-considerations</guid>
      <pubDate>Sun, 22 Feb 2026 04:12:51 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Static Analysis vs Dynamic Analysis]]></title>
      <description><![CDATA[Static analysis reads code before it runs; dynamic analysis watches it execute. Here's how the two differ, catch different bugs, and work best together.]]></description>
      <link>https://safeguard.sh/resources/blog/static-analysis-vs-dynamic-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-analysis-vs-dynamic-analysis</guid>
      <pubDate>Sun, 22 Feb 2026 04:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CIEM (Cloud Infrastructure Entitlement Management)]]></title>
      <description><![CDATA[What is CIEM? A clear breakdown of Cloud Infrastructure Entitlement Management, how it differs from CSPM, and why excessive cloud permissions keep piling up.]]></description>
      <link>https://safeguard.sh/resources/blog/ciem-cloud-infrastructure-entitlement-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ciem-cloud-infrastructure-entitlement-management</guid>
      <pubDate>Sun, 22 Feb 2026 03:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[IoT Firmware SBOMs: From Nice-to-Have to Regulatory Requirement]]></title>
      <description><![CDATA[Government mandates and industry standards are making SBOMs mandatory for IoT firmware. Here's what manufacturers need to know to comply.]]></description>
      <link>https://safeguard.sh/resources/blog/iot-firmware-sbom-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iot-firmware-sbom-requirements</guid>
      <pubDate>Sun, 22 Feb 2026 02:52:24 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Palo Alto PAN-OS Zero-Day CVE-2024-3400: Command Injection in GlobalProtect]]></title>
      <description><![CDATA[A critical command injection vulnerability in Palo Alto Networks PAN-OS GlobalProtect feature was exploited as a zero-day, giving attackers root access to firewalls protecting enterprise networks.]]></description>
      <link>https://safeguard.sh/resources/blog/palo-alto-pan-os-cve-2024-3400-zero-day</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/palo-alto-pan-os-cve-2024-3400-zero-day</guid>
      <pubDate>Sun, 22 Feb 2026 01:31:58 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Veracode Comparison]]></title>
      <description><![CDATA[A concrete, numbers-first comparison of Snyk and Veracode covering SAST architecture, SCA coverage, pricing, and enterprise fit for AppSec buyers.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-veracode-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-veracode-comparison</guid>
      <pubDate>Sun, 22 Feb 2026 01:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Open-Source Contribution Security Guide]]></title>
      <description><![CDATA[How to contribute to open-source projects without introducing security vulnerabilities, and how to evaluate the security posture of projects you contribute to.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-contribution-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-contribution-security-guide</guid>
      <pubDate>Sun, 22 Feb 2026 00:11:31 GMT</pubDate>
      <category>Organizational Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes admission controller]]></title>
      <description><![CDATA[A Kubernetes admission controller intercepts API requests before they're persisted, enforcing policy on Pods, images, and configs before workloads ever run.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-admission-controller</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-admission-controller</guid>
      <pubDate>Sun, 22 Feb 2026 00:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Django Security Best Practices, 2024 Edition]]></title>
      <description><![CDATA[From SECRET_KEY hygiene to middleware ordering, the Django security checklist worth actually following in 2024, grounded in real CVEs and production incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/django-security-best-practices-2024-edition</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/django-security-best-practices-2024-edition</guid>
      <pubDate>Sat, 21 Feb 2026 22:51:04 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Compliance Dashboard Design Patterns for Supply Chain Security]]></title>
      <description><![CDATA[Compliance dashboards translate complex supply chain data into actionable views for auditors, executives, and engineering teams. These design patterns make the difference between a dashboard that drives action and one that collects dust.]]></description>
      <link>https://safeguard.sh/resources/blog/compliance-dashboard-design-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/compliance-dashboard-design-patterns</guid>
      <pubDate>Sat, 21 Feb 2026 21:30:38 GMT</pubDate>
      <category>SBOM and Compliance</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[CISA's Secure by Design Pledge: Voluntary Commitments with Real Teeth]]></title>
      <description><![CDATA[CISA launched a voluntary pledge asking software manufacturers to commit to specific security improvements. Over 100 companies signed. Here is what the pledge actually requires and whether it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-secure-by-design-pledge</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-secure-by-design-pledge</guid>
      <pubDate>Sat, 21 Feb 2026 20:10:11 GMT</pubDate>
      <category>Policy & Compliance</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Types of Licenses: A Quick Reference for Engineers]]></title>
      <description><![CDATA[Software licenses split into permissive, copyleft, and proprietary categories, each with different obligations. Here's a quick reference for the types of license engineers actually run into.]]></description>
      <link>https://safeguard.sh/resources/blog/types-of-software-licenses-quick-reference</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/types-of-software-licenses-quick-reference</guid>
      <pubDate>Sat, 21 Feb 2026 18:49:44 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2017-18214: Why an Old CVE Still Shows Up in Scans]]></title>
      <description><![CDATA[CVE-2017-18214 is a ReDoS bug in Moment.js patched back in 2017, yet it keeps surfacing in scans years later because bundled copies and stale lockfiles never got the memo.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2017-18214-what-it-was-and-why-it-still-shows-up</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2017-18214-what-it-was-and-why-it-still-shows-up</guid>
      <pubDate>Sat, 21 Feb 2026 17:29:18 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Open Source License Types: A Quick Guide for Engineers]]></title>
      <description><![CDATA[Open source license types split into permissive and copyleft, and knowing which one a dependency uses can matter as much as knowing whether it has a CVE.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-license-types-quick-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-license-types-quick-guide</guid>
      <pubDate>Sat, 21 Feb 2026 16:08:51 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[PowerShell Module Supply Chain Security]]></title>
      <description><![CDATA[PowerShell modules are a supply chain people forget exists, and the trust model is weaker than NuGet's. Here is why that matters.]]></description>
      <link>https://safeguard.sh/resources/blog/powershell-module-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/powershell-module-supply-chain-security</guid>
      <pubDate>Sat, 21 Feb 2026 14:48:24 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Network Policies: The Supply Chain Angle]]></title>
      <description><![CDATA[Network policies are usually framed as a zero-trust tool. They are also one of the best defenses against a compromised dependency.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-network-policies-supply-chain-angle</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-network-policies-supply-chain-angle</guid>
      <pubDate>Sat, 21 Feb 2026 13:27:58 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA Meets HITRUST: Supply Chain Depth]]></title>
      <description><![CDATA[HIPAA's Security Rule is thin on supply chain specifics. HITRUST CSF fills the gap with prescriptive third-party and software controls. Here's how the two frameworks intersect and how to build a program that satisfies both.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-meets-hitrust-supply-chain-depth</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-meets-hitrust-supply-chain-depth</guid>
      <pubDate>Sat, 21 Feb 2026 12:07:31 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Model Inventory Tracking: Griffin AI vs Mythos]]></title>
      <description><![CDATA[You cannot secure what you cannot enumerate. Griffin AI maintains a typed inventory of every model, version, and deployment across a tenant. Mythos-class tools approximate the inventory in prose.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-model-inventory-tracking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-model-inventory-tracking</guid>
      <pubDate>Sat, 21 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Bazel Hermetic Builds: Supply Chain Benefits]]></title>
      <description><![CDATA[How Bazel's hermeticity model reduces supply chain risk, with concrete WORKSPACE and MODULE.bazel examples from real migrations.]]></description>
      <link>https://safeguard.sh/resources/blog/bazel-hermetic-builds-supply-chain-benefits</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bazel-hermetic-builds-supply-chain-benefits</guid>
      <pubDate>Sat, 21 Feb 2026 10:47:04 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Checkmarx Comparison]]></title>
      <description><![CDATA[Snyk vs Checkmarx compared on SAST/SCA depth, pricing, IaC/container coverage, and their real Log4Shell response — plus where reachability analysis closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-checkmarx-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-checkmarx-comparison</guid>
      <pubDate>Sat, 21 Feb 2026 10:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[WebSocket Security in Modern Applications]]></title>
      <description><![CDATA[WebSockets enable real-time communication but introduce attack surfaces that traditional HTTP security controls miss entirely.]]></description>
      <link>https://safeguard.sh/resources/blog/websocket-security-modern-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/websocket-security-modern-applications</guid>
      <pubDate>Sat, 21 Feb 2026 09:26:37 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to rotate AWS IAM access keys]]></title>
      <description><![CDATA[A step-by-step guide to safely rotate AWS IAM access keys with zero downtime, plus how to turn it into a lasting credential rotation policy.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-rotate-aws-iam-access-keys</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-rotate-aws-iam-access-keys</guid>
      <pubDate>Sat, 21 Feb 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How Often Should You Scan for Vulnerabilities?]]></title>
      <description><![CDATA[Finding the right vulnerability scanning frequency for your organization. Too often wastes resources, too rarely leaves gaps. Here is how to calibrate.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-scanning-frequency-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-scanning-frequency-guide</guid>
      <pubDate>Sat, 21 Feb 2026 08:06:11 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Black Duck Comparison]]></title>
      <description><![CDATA[Snyk and Black Duck take different paths to open source risk—developer-first scanning vs. compliance-grade component identification. Here's how they compare, and where reachability closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-black-duck-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-black-duck-comparison</guid>
      <pubDate>Sat, 21 Feb 2026 07:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[AI Model Poisoning: Detection Techniques for the Software Supply Chain]]></title>
      <description><![CDATA[Poisoned AI models are a supply chain threat that traditional security tools can't detect. Here are the emerging techniques for identifying compromised models.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-model-poisoning-detection-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-model-poisoning-detection-techniques</guid>
      <pubDate>Sat, 21 Feb 2026 06:45:44 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[How to configure Kubernetes network policies]]></title>
      <description><![CDATA[A step-by-step guide to configuring Kubernetes network policies: enabling Calico, building a default-deny baseline, allow-listing traffic, and verifying enforcement.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-configure-kubernetes-network-policies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-configure-kubernetes-network-policies</guid>
      <pubDate>Sat, 21 Feb 2026 06:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Latin America's Evolving Cybersecurity Regulations and Supply Chain Implications]]></title>
      <description><![CDATA[From Brazil's LGPD to Mexico's cybersecurity reforms, Latin America is building a regulatory framework that will reshape how organizations manage software supply chain risk across the region.]]></description>
      <link>https://safeguard.sh/resources/blog/latin-america-cybersecurity-regulations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/latin-america-cybersecurity-regulations</guid>
      <pubDate>Sat, 21 Feb 2026 05:25:17 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Secrets Management: Vault, Sealed Secrets, SOPS, and External Secrets Compared]]></title>
      <description><![CDATA[Kubernetes Secrets are base64-encoded, not encrypted. That is the start of the problem. Here is a no-nonsense comparison of the tools that actually solve secrets management in Kubernetes.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-secrets-management-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-secrets-management-comparison</guid>
      <pubDate>Sat, 21 Feb 2026 04:04:51 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Wiz Comparison]]></title>
      <description><![CDATA[Snyk secures code, Wiz secures cloud infrastructure — a concrete look at pricing, coverage, dev workflow fit, and Google's $32B Wiz acquisition.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-wiz-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-wiz-comparison</guid>
      <pubDate>Sat, 21 Feb 2026 04:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to set up SBOM generation in a CI pipeline]]></title>
      <description><![CDATA[Learn how to build an SBOM generation CI pipeline with Syft and GitHub Actions, covering scanning, signing, storage, and verification for supply chain visibility.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-sbom-generation-in-a-ci-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-sbom-generation-in-a-ci-pipeline</guid>
      <pubDate>Sat, 21 Feb 2026 03:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[XZ Utils Backdoor: Technical Breakdown]]></title>
      <description><![CDATA[The xz-utils backdoor (CVE-2024-3094) nearly compromised SSH on every modern Linux distro. Here is how the implant worked and what it teaches us.]]></description>
      <link>https://safeguard.sh/resources/blog/xz-utils-backdoor-technical-breakdown</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xz-utils-backdoor-technical-breakdown</guid>
      <pubDate>Sat, 21 Feb 2026 02:44:24 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[cargo audit vs cargo deny]]></title>
      <description><![CDATA[A practical head-to-head between cargo-audit 0.21 and cargo-deny 0.16 based on six months of running both in production CI pipelines.]]></description>
      <link>https://safeguard.sh/resources/blog/cargo-audit-vs-cargo-deny-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cargo-audit-vs-cargo-deny-comparison</guid>
      <pubDate>Sat, 21 Feb 2026 01:23:57 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs GitHub Advanced Security Comparison]]></title>
      <description><![CDATA[Snyk vs GitHub Advanced Security: how CodeQL, Dependabot, and Snyk's SCA/SAST/container/IaC coverage stack up on cost, depth, and workflow fit.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-github-advanced-security-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-github-advanced-security-comparison</guid>
      <pubDate>Sat, 21 Feb 2026 01:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Threat Intelligence Feeds for Supply Chain Security]]></title>
      <description><![CDATA[Supply chain threat intelligence goes beyond CVE databases. Specialized feeds track malicious packages, compromised maintainers, and emerging attack techniques targeting the software supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/threat-intelligence-feeds-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/threat-intelligence-feeds-supply-chain</guid>
      <pubDate>Sat, 21 Feb 2026 00:03:31 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to enable Dependabot version updates]]></title>
      <description><![CDATA[A step-by-step guide to enabling Dependabot version updates on GitHub, including dependabot.yml configuration, scheduling, and verification checks.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-enable-dependabot-version-updates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-enable-dependabot-version-updates</guid>
      <pubDate>Sat, 21 Feb 2026 00:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Prototype Pollution in JavaScript: Prevention Guide]]></title>
      <description><![CDATA[Prototype pollution lets attackers modify the behavior of all JavaScript objects by injecting properties into Object.prototype. This guide covers exploitation techniques, real-world impact, and layered defenses.]]></description>
      <link>https://safeguard.sh/resources/blog/prototype-pollution-javascript-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prototype-pollution-javascript-prevention</guid>
      <pubDate>Fri, 20 Feb 2026 22:43:04 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[After XZ Utils: Rethinking Trust in Open Source Software]]></title>
      <description><![CDATA[The XZ Utils backdoor forced the industry to confront uncomfortable questions about maintainer trust, funding, and the structural fragility of critical open source infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/xz-utils-lessons-for-open-source-trust</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xz-utils-lessons-for-open-source-trust</guid>
      <pubDate>Fri, 20 Feb 2026 21:22:37 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise SCA Tool Evaluation Framework]]></title>
      <description><![CDATA[Choosing a software composition analysis tool for the enterprise? Here's a structured evaluation framework covering what actually matters.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-sca-tool-evaluation-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-sca-tool-evaluation-framework</guid>
      <pubDate>Fri, 20 Feb 2026 20:02:11 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Mend vs Black Duck: Functional Comparison]]></title>
      <description><![CDATA[Compare Mend (formerly WhiteSource) and Black Duck on SBOM export, license policy, detection sources, deployment model, and enterprise reporting for 2024 SCA selection.]]></description>
      <link>https://safeguard.sh/resources/blog/mend-vs-black-duck-functional-comparison-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mend-vs-black-duck-functional-comparison-2024</guid>
      <pubDate>Fri, 20 Feb 2026 18:41:44 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The GNU Affero General Public License (AGPL), Explained]]></title>
      <description><![CDATA[The GNU Affero General Public License closes the SaaS loophole in the GPL — if your service runs modified AGPL code over a network, you owe the source, even without distributing a binary.]]></description>
      <link>https://safeguard.sh/resources/blog/gnu-affero-general-public-license-agpl-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gnu-affero-general-public-license-agpl-explained</guid>
      <pubDate>Fri, 20 Feb 2026 17:21:17 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Jenkins Pipeline Supply Chain Security]]></title>
      <description><![CDATA[How Jenkins pipelines end up as supply chain attack vectors, covering Groovy sandbox risks, plugin CVEs, credential binding, and practical hardening for Jenkins 2.440+.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-pipeline-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-pipeline-supply-chain-security</guid>
      <pubDate>Fri, 20 Feb 2026 16:00:50 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Spring4Shell: What Shipped and How to Patch It]]></title>
      <description><![CDATA[What the Spring4Shell vulnerability actually was, which configurations were exposed, and the concrete patch and mitigation steps that closed it.]]></description>
      <link>https://safeguard.sh/resources/blog/spring4shell-vulnerability-what-shipped-and-how-to-patch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring4shell-vulnerability-what-shipped-and-how-to-patch</guid>
      <pubDate>Fri, 20 Feb 2026 14:40:24 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Forking Security: What Happens When Open Source Projects Diverge]]></title>
      <description><![CDATA[When an open source project forks, the security implications cascade through every downstream consumer. Understanding fork dynamics is essential for managing supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/forking-security-when-projects-diverge</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/forking-security-when-projects-diverge</guid>
      <pubDate>Fri, 20 Feb 2026 13:19:57 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Cursor Tab for Security Review]]></title>
      <description><![CDATA[Cursor Tab is excellent at in-editor autocomplete. For security review, the workflow is different enough that the right answer is to use both.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-cursor-tab-for-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-cursor-tab-for-security-review</guid>
      <pubDate>Fri, 20 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CSRF Modern Forms: Griffin AI vs Mythos]]></title>
      <description><![CDATA[CSRF in 2026 is not the 2012 attack. SameSite cookies, fetch metadata, and modern frameworks changed the landscape. Detection needs to keep up.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-csrf-modern-forms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-csrf-modern-forms</guid>
      <pubDate>Fri, 20 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Golden Dataset Design: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Benchmark scores are only as honest as the dataset behind them. Griffin AI publishes golden-dataset design notes; Mythos-class tools rarely explain theirs.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-golden-dataset-design</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-golden-dataset-design</guid>
      <pubDate>Fri, 20 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Portal: Giving Your Customers a Window Into Your Supply Chain]]></title>
      <description><![CDATA[The Safeguard Portal lets you share SBOM data, vulnerability status, and compliance documentation with customers through a branded, self-service interface.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-portal-customer-transparency</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-portal-customer-transparency</guid>
      <pubDate>Fri, 20 Feb 2026 11:59:30 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CodeQL vs Semgrep: A 2026 Buyer Comparison]]></title>
      <description><![CDATA[A practical head-to-head between CodeQL and Semgrep in 2026: query power, performance, rule authoring, and where each tool earns its place in a modern SAST program.]]></description>
      <link>https://safeguard.sh/resources/blog/codeql-vs-semgrep-buyer-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/codeql-vs-semgrep-buyer-comparison-2026</guid>
      <pubDate>Fri, 20 Feb 2026 11:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How One Engineer's Curiosity Saved Linux: The XZ Utils Backdoor Discovery Story]]></title>
      <description><![CDATA[Andres Freund noticed SSH was 500ms slower than expected. That observation prevented the most dangerous supply chain attack in open source history from reaching stable Linux distributions.]]></description>
      <link>https://safeguard.sh/resources/blog/xz-utils-backdoor-how-it-was-discovered</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xz-utils-backdoor-how-it-was-discovered</guid>
      <pubDate>Fri, 20 Feb 2026 10:39:04 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[KEV, EPSS, CVSS: Which Signal Should Drive Patching?]]></title>
      <description><![CDATA[CVSS measures severity, EPSS predicts exploitation, KEV confirms active exploitation. Each answers a different question, and patching policy should use all three.]]></description>
      <link>https://safeguard.sh/resources/blog/kev-epss-cvss-which-signal-drives-patching</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kev-epss-cvss-which-signal-drives-patching</guid>
      <pubDate>Fri, 20 Feb 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Security Summit 2026: Key Takeaways]]></title>
      <description><![CDATA[We attended the Open Source Security Summit 2026 and came back with five actionable insights for security teams.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-security-summit-2026-recap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-security-summit-2026-recap</guid>
      <pubDate>Fri, 20 Feb 2026 10:00:00 GMT</pubDate>
      <category>Events</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Aikido Comparison]]></title>
      <description><![CDATA[Snyk vs Aikido compared on pricing, vulnerability database size, alert noise, CI/CD setup, and enterprise fit — with concrete numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-aikido-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-aikido-comparison</guid>
      <pubDate>Fri, 20 Feb 2026 10:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[SCA with Reachability: A Buyer Guide for 2026]]></title>
      <description><![CDATA[How to evaluate software composition analysis tools that claim reachability analysis, including the technical questions that separate real implementations from marketing.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-with-reachability-buyer-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-with-reachability-buyer-guide-2026</guid>
      <pubDate>Fri, 20 Feb 2026 09:30:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[VS Code Extensions and Supply Chain Risk in 2026]]></title>
      <description><![CDATA[VS Code extensions run with full editor privileges and broad filesystem access. A look at the real attacks, the marketplace's blind spots, and how to harden the workstation.]]></description>
      <link>https://safeguard.sh/resources/blog/vscode-extensions-supply-chain-risk-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vscode-extensions-supply-chain-risk-2026</guid>
      <pubDate>Fri, 20 Feb 2026 09:30:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[PCI DSS 4.0 Software Security Requirements]]></title>
      <description><![CDATA[PCI DSS 4.0 became mandatory on March 31, 2024, overhauling software security, SBOM visibility, and supply chain controls for every entity that touches cardholder data.]]></description>
      <link>https://safeguard.sh/resources/blog/pci-dss-4-0-software-security-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pci-dss-4-0-software-security-requirements</guid>
      <pubDate>Fri, 20 Feb 2026 09:18:37 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[cargo-audit and cargo-deny: A Real Workflow]]></title>
      <description><![CDATA[A senior-engineer-grade workflow for using cargo-audit and cargo-deny together, with realistic policy decisions and the mistakes teams repeat.]]></description>
      <link>https://safeguard.sh/resources/blog/cargo-audit-deny-advisories-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cargo-audit-deny-advisories-workflow</guid>
      <pubDate>Fri, 20 Feb 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Dependabot vs. Renovate: Operational Experience]]></title>
      <description><![CDATA[Both tools open the same kind of PR. The differences that matter at scale show up in configuration, grouping, platform support, and what happens when something breaks.]]></description>
      <link>https://safeguard.sh/resources/blog/dependabot-vs-renovate-operational-experience</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependabot-vs-renovate-operational-experience</guid>
      <pubDate>Fri, 20 Feb 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to set up AWS GuardDuty for threat detection]]></title>
      <description><![CDATA[A step-by-step guide to enabling AWS GuardDuty across accounts and regions, routing findings to your alerting stack, and triaging results.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-aws-guardduty-for-threat-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-aws-guardduty-for-threat-detection</guid>
      <pubDate>Fri, 20 Feb 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[DPRK IT Worker Supply Chain Insider Threat]]></title>
      <description><![CDATA[DPRK operatives have placed themselves inside Western companies as remote developers. Here is how that pattern functions as a supply chain threat and how to detect it.]]></description>
      <link>https://safeguard.sh/resources/blog/north-korea-it-worker-supply-chain-insider-threat</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/north-korea-it-worker-supply-chain-insider-threat</guid>
      <pubDate>Fri, 20 Feb 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Partnership Strategy 2026]]></title>
      <description><![CDATA[How Safeguard thinks about partnerships in 2026 — the motions we prioritize, the partners we seek, and the customer outcomes that drive the strategy.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-partnership-strategy-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-partnership-strategy-2026</guid>
      <pubDate>Fri, 20 Feb 2026 09:00:00 GMT</pubDate>
      <category>Company</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Self-Healing Containers Now Generally Available]]></title>
      <description><![CDATA[Self-healing containers detect, remediate, and rebuild images when CVEs appear in their dependency closure. Here is how the GA feature works in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-self-healing-containers-general-availability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-self-healing-containers-general-availability</guid>
      <pubDate>Fri, 20 Feb 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[TCO of SCA Platforms in 2026: What to Model]]></title>
      <description><![CDATA[A realistic model for the total cost of ownership of software composition analysis platforms in 2026, including the hidden costs vendors do not surface in their pricing pages.]]></description>
      <link>https://safeguard.sh/resources/blog/total-cost-of-ownership-sca-platforms-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/total-cost-of-ownership-sca-platforms-2026</guid>
      <pubDate>Fri, 20 Feb 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AT&T Data Breach: 73 Million Customer Records Surface on the Dark Web]]></title>
      <description><![CDATA[In March 2024, AT&T confirmed that a dataset containing personal information of approximately 73 million current and former customers, including encrypted passcodes, had been published on the dark web, three years after its initial appearance.]]></description>
      <link>https://safeguard.sh/resources/blog/att-73-million-records-dark-web</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/att-73-million-records-dark-web</guid>
      <pubDate>Fri, 20 Feb 2026 07:58:10 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Static Code Analysis Tools]]></title>
      <description><![CDATA[Open source static code analysis tools like Semgrep, CodeQL, and Bandit catch real bugs -- but miss supply-chain flaws like Log4Shell entirely.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-static-code-analysis-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-static-code-analysis-tools</guid>
      <pubDate>Fri, 20 Feb 2026 07:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[XZ Utils Backdoor (CVE-2024-3094): The Most Sophisticated Supply Chain Attack Ever Discovered]]></title>
      <description><![CDATA[A multi-year social engineering campaign planted a backdoor in XZ Utils that would have compromised SSH on most Linux distributions. Technical deep dive into what happened.]]></description>
      <link>https://safeguard.sh/resources/blog/xz-utils-backdoor-cve-2024-3094-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xz-utils-backdoor-cve-2024-3094-analysis</guid>
      <pubDate>Fri, 20 Feb 2026 06:37:44 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to prevent public access to AWS S3 buckets]]></title>
      <description><![CDATA[A practical walkthrough for locking down AWS S3 buckets: Block Public Access, bucket policies, encryption, and how Safeguard catches misconfigurations early.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-prevent-public-access-to-aws-s3-buckets</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-prevent-public-access-to-aws-s3-buckets</guid>
      <pubDate>Fri, 20 Feb 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Ninja Build Supply Chain Considerations]]></title>
      <description><![CDATA[Ninja is a low-level build tool, not a package manager. That framing matters for understanding its supply chain properties and common misconceptions.]]></description>
      <link>https://safeguard.sh/resources/blog/ninja-build-supply-chain-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ninja-build-supply-chain-considerations</guid>
      <pubDate>Fri, 20 Feb 2026 05:17:17 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Go Proxy and Private Module Security]]></title>
      <description><![CDATA[Mixing public and private modules through a Go proxy is where most teams get their configuration wrong, and the mistakes range from leaked module names to accepted unverified code.]]></description>
      <link>https://safeguard.sh/resources/blog/go-proxy-private-module-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-proxy-private-module-security</guid>
      <pubDate>Fri, 20 Feb 2026 03:56:50 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to implement least privilege IAM policies in AWS]]></title>
      <description><![CDATA[A practical guide to building a least privilege IAM policy AWS teams can trust, using Access Advisor data and generator tooling to cut over-permissioning fast.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-implement-least-privilege-iam-policies-in-aws</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-implement-least-privilege-iam-policies-in-aws</guid>
      <pubDate>Fri, 20 Feb 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Splunk Supply Chain Detection Content Pack]]></title>
      <description><![CDATA[A practical look at building a Splunk content pack for software supply chain threats, with SPL searches for CI/CD anomalies, package registry abuse, and build provenance violations.]]></description>
      <link>https://safeguard.sh/resources/blog/splunk-supply-chain-detection-content-pack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/splunk-supply-chain-detection-content-pack</guid>
      <pubDate>Fri, 20 Feb 2026 02:36:24 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[XSS Script Examples, Annotated]]></title>
      <description><![CDATA[Reading a real xss script example line by line makes cross-site scripting concrete in a way definitions rarely do — here are annotated examples across the three main XSS types.]]></description>
      <link>https://safeguard.sh/resources/blog/xss-script-examples-annotated</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xss-script-examples-annotated</guid>
      <pubDate>Fri, 20 Feb 2026 01:15:57 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to set up HashiCorp Vault for secrets management]]></title>
      <description><![CDATA[A step-by-step guide to set up HashiCorp Vault for secrets management, covering installation, dynamic secrets, Kubernetes integration, and verification steps.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-hashicorp-vault-for-secrets-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-hashicorp-vault-for-secrets-management</guid>
      <pubDate>Fri, 20 Feb 2026 00:00:00 GMT</pubDate>
      <category>Cryptography</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Hugging Face Model Hub Supply Chain Risks in 2025]]></title>
      <description><![CDATA[Pickle deserialization, malicious Spaces, and namespace squatting: what 2024-2025 taught us about the Hugging Face model supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/huggingface-model-hub-supply-chain-risks-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/huggingface-model-hub-supply-chain-risks-2025</guid>
      <pubDate>Fri, 20 Feb 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SLSA Build L1 to L3 Migration Playbook]]></title>
      <description><![CDATA[Moving from SLSA Build L1 to L3 is less a single upgrade and more a series of hardening steps. Here is the playbook we use with customers, mapped to the v1.0 specification.]]></description>
      <link>https://safeguard.sh/resources/blog/slsa-build-l1-to-l3-migration-playbook</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slsa-build-l1-to-l3-migration-playbook</guid>
      <pubDate>Thu, 19 Feb 2026 23:55:30 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Maven Enforcer Plugin Security Rules]]></title>
      <description><![CDATA[Maven Enforcer is a blunt instrument most teams underuse. Here is how to turn it into a supply chain guardrail that blocks bad versions, bad repositories, and bad dependency graphs before they ship.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-enforcer-plugin-security-rules</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-enforcer-plugin-security-rules</guid>
      <pubDate>Thu, 19 Feb 2026 22:35:03 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Advanced Security vs Alternatives, Early 2024]]></title>
      <description><![CDATA[GitHub Advanced Security anchors many AppSec programs in 2024, but Snyk, Semgrep, Endor, and others are credible alternatives. Here is an honest comparison.]]></description>
      <link>https://safeguard.sh/resources/blog/github-advanced-security-vs-alternatives-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-advanced-security-vs-alternatives-2024</guid>
      <pubDate>Thu, 19 Feb 2026 21:14:37 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GCP Cloud Run Supply Chain Security]]></title>
      <description><![CDATA[A practical playbook for protecting the supply chain of services running on Cloud Run: image provenance, Binary Authorization, runtime identity, and the gaps the default configuration leaves wide open.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-cloud-run-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-cloud-run-supply-chain-security</guid>
      <pubDate>Thu, 19 Feb 2026 19:54:10 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Firewalls: Concept, Architecture, and Implementation]]></title>
      <description><![CDATA[A dependency firewall sits between your build system and public registries, filtering packages based on security policies. Here is how to design and implement one.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-firewall-concept-implementation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-firewall-concept-implementation</guid>
      <pubDate>Thu, 19 Feb 2026 18:33:43 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[NestJS Enterprise Security Guide]]></title>
      <description><![CDATA[NestJS dominates the enterprise Node.js space because of its Angular-style decorators, dependency injection, and opinionated project structure. Those same properties create a distinctive security surface worth understanding carefully.]]></description>
      <link>https://safeguard.sh/resources/blog/nest-js-enterprise-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nest-js-enterprise-security-guide</guid>
      <pubDate>Thu, 19 Feb 2026 17:13:17 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Defense Industrial Base Supply Chain and CMMC]]></title>
      <description><![CDATA[How the Defense Industrial Base is adapting its software supply chain to CMMC 2.0, NIST SP 800-171, and DFARS flow-down obligations.]]></description>
      <link>https://safeguard.sh/resources/blog/defense-industrial-base-supply-chain-cmmc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/defense-industrial-base-supply-chain-cmmc</guid>
      <pubDate>Thu, 19 Feb 2026 15:52:50 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Secure Container Software: A Practical Guide]]></title>
      <description><![CDATA[Securing container software means controlling the whole chain, base image, dependencies, build, registry, and runtime, not just scanning the final image. Here is a working model for each layer.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-container-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-container-software</guid>
      <pubDate>Thu, 19 Feb 2026 15:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Post-Quantum Cryptography Transition: A Practical Guide for Engineering Teams]]></title>
      <description><![CDATA[NIST has finalized its post-quantum standards. Here's a hands-on guide for engineering teams beginning the migration from classical to quantum-resistant cryptography.]]></description>
      <link>https://safeguard.sh/resources/blog/post-quantum-cryptography-transition-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/post-quantum-cryptography-transition-guide</guid>
      <pubDate>Thu, 19 Feb 2026 14:32:23 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Distroless Node.js 20 on Debian 12 Image Deep Dive]]></title>
      <description><![CDATA[A deep dive into the gcr.io/distroless/nodejs20-debian12 image: contents, attack surface, real-world CVE exposure, and where it fits in production.]]></description>
      <link>https://safeguard.sh/resources/blog/distroless-nodejs20-debian12-image-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/distroless-nodejs20-debian12-image-deep-dive</guid>
      <pubDate>Thu, 19 Feb 2026 14:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[PCI DSS 4.0 Supply Chain Requirements in 2026]]></title>
      <description><![CDATA[The PCI DSS 4.0 future-dated requirements became mandatory on March 31, 2025. The supply chain expectations are the ones most QSAs are now testing in detail.]]></description>
      <link>https://safeguard.sh/resources/blog/pci-dss-4-0-supply-chain-requirements-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pci-dss-4-0-supply-chain-requirements-2026</guid>
      <pubDate>Thu, 19 Feb 2026 14:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Container Runtime Scanning: Catching Threats After Deployment]]></title>
      <description><![CDATA[Container runtime scanning watches workloads while they run, catching drift, new CVEs, and active exploitation that build-time scans miss entirely.]]></description>
      <link>https://safeguard.sh/resources/blog/container-runtime-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-runtime-scanning</guid>
      <pubDate>Thu, 19 Feb 2026 13:15:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Wolfi OS: The Linux Distribution Built for Secure Containers]]></title>
      <description><![CDATA[Wolfi is not a general-purpose Linux distro. It exists to solve one problem: provide secure, minimal, up-to-date packages for container images. Here is why that matters and how to use it.]]></description>
      <link>https://safeguard.sh/resources/blog/wolfi-os-container-base-image-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wolfi-os-container-base-image-security</guid>
      <pubDate>Thu, 19 Feb 2026 13:11:57 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise AI Procurement Due Diligence Checklist]]></title>
      <description><![CDATA[AI-for-security procurement covers more than feature comparison. The due diligence checklist that surfaces structural differences between vendors.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-ai-procurement-due-diligence-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-ai-procurement-due-diligence-checklist</guid>
      <pubDate>Thu, 19 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Deserialization Chains: Griffin AI vs Mythos]]></title>
      <description><![CDATA[CWE-502 deserialisation chains are the canonical stress test for AI bug hunters. Why Griffin AI's grounded synthesis finds real chains and Mythos-class scanners hallucinate them.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-deserialization-chains</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-deserialization-chains</guid>
      <pubDate>Thu, 19 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Triage Backlog Reduction: Griffin AI vs Mythos]]></title>
      <description><![CDATA[A shrinking triage queue is the clearest sign a security programme is working. We explain why Griffin AI shrinks queues and Mythos-class tools grow them.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-triage-backlog-reduction</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-triage-backlog-reduction</guid>
      <pubDate>Thu, 19 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Fine-Tuned Open Weights for SecOps]]></title>
      <description><![CDATA[Fine-tuning an open-weight model sounds like a shortcut to a custom SecOps copilot. In practice, it is one step of a much longer journey.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-open-weight-fine-tuning-for-secops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-open-weight-fine-tuning-for-secops</guid>
      <pubDate>Thu, 19 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Rust Build Scripts: A Supply Chain Risk Profile]]></title>
      <description><![CDATA[Why build.rs is the highest-leverage attack surface in the Rust ecosystem, with concrete examples from 2023 and 2024 incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-supply-chain-build-scripts-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-supply-chain-build-scripts-risk</guid>
      <pubDate>Thu, 19 Feb 2026 11:51:30 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Aqua vs Sysdig Buyer Comparison 2026]]></title>
      <description><![CDATA[Two specialist platforms that converged into CNAPP from different starting points. Container provenance, runtime forensics, eBPF coverage, and the cases where each tool earns its keep.]]></description>
      <link>https://safeguard.sh/resources/blog/aqua-vs-sysdig-buyer-comparison-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aqua-vs-sysdig-buyer-comparison-2026</guid>
      <pubDate>Thu, 19 Feb 2026 11:15:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[npm Lifecycle Scripts: The Hidden Attack Surface in Your Node.js Supply Chain]]></title>
      <description><![CDATA[npm lifecycle scripts execute arbitrary code during package installation. This design choice creates one of the largest and least-understood attack surfaces in modern software development.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-lifecycle-scripts-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-lifecycle-scripts-security-risks</guid>
      <pubDate>Thu, 19 Feb 2026 10:31:03 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Asset Management AI: How AI Is Reshaping Security Asset Inventory]]></title>
      <description><![CDATA[Asset management AI turns a stale spreadsheet of assets into a living, correlated inventory. Here is what it actually does for security teams and where it falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/asset-management-ai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/asset-management-ai</guid>
      <pubDate>Thu, 19 Feb 2026 10:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[AI-Powered Security Companies: A Buyer's Map]]></title>
      <description><![CDATA[Nearly every security vendor now claims to be an ai security company — here's how to tell genuine AI-powered security from a rebadged feature, and what to actually evaluate before you buy.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-powered-security-companies-a-buyers-map</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-powered-security-companies-a-buyers-map</guid>
      <pubDate>Thu, 19 Feb 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Buy, Build, or Hybrid: Supply Chain Security in 2026]]></title>
      <description><![CDATA[The build-it-yourself era of supply chain security is ending. The full-stack vendor era has not arrived. The right architecture in 2026 is hybrid — and the decisions are different than they look.]]></description>
      <link>https://safeguard.sh/resources/blog/buy-build-hybrid-supply-chain-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buy-build-hybrid-supply-chain-security-2026</guid>
      <pubDate>Thu, 19 Feb 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Defense Contractor IL7 Deployment Walkthrough]]></title>
      <description><![CDATA[An anonymized account of how a US defense prime deployed Safeguard in an IL7 classified environment supporting a DoD mission system.]]></description>
      <link>https://safeguard.sh/resources/blog/customer-story-defense-contractor-il7-deployment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/customer-story-defense-contractor-il7-deployment</guid>
      <pubDate>Thu, 19 Feb 2026 10:00:00 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Getting Started: Safeguard Kubernetes Admission]]></title>
      <description><![CDATA[Deploy the Safeguard admission controller to block images with unresolved critical vulnerabilities before they run in your cluster.]]></description>
      <link>https://safeguard.sh/resources/blog/getting-started-safeguard-kubernetes-admission</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/getting-started-safeguard-kubernetes-admission</guid>
      <pubDate>Thu, 19 Feb 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 Annex A Controls That Touch Your Build Pipeline]]></title>
      <description><![CDATA[ISO 27001:2022 has 93 Annex A controls, and about a dozen land squarely on CI/CD. Here's the control-by-control map from clause number to pipeline artifact.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-annex-a-controls-that-touch-your-build-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-annex-a-controls-that-touch-your-build-pipeline</guid>
      <pubDate>Thu, 19 Feb 2026 09:10:37 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Elena Kovacs)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Vulnerability Management Software: What Actually Matters]]></title>
      <description><![CDATA[Most enterprise vulnerability management software is judged on scanner coverage, but the deployments that work are won on deduplication, prioritization, and ownership routing. Here is an evaluation framework grounded in how programs actually fail.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-vulnerability-management-software-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-vulnerability-management-software-guide</guid>
      <pubDate>Thu, 19 Feb 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[How to scan container images for vulnerabilities with Trivy]]></title>
      <description><![CDATA[Learn how to scan container images with Trivy: install it, run your first scan, filter by severity, and gate builds automatically in CI/CD pipelines.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-scan-container-images-for-vulnerabilities-with-trivy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-scan-container-images-for-vulnerabilities-with-trivy</guid>
      <pubDate>Thu, 19 Feb 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Is Snyk Free? Free Tier Limits, Pricing, and Alternatives]]></title>
      <description><![CDATA[Is Snyk free? Yes, with monthly test limits that commercial teams outgrow fast. Here are the actual free-tier caps, paid pricing, and when alternatives make sense.]]></description>
      <link>https://safeguard.sh/resources/blog/is-snyk-free-pricing-and-limits</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/is-snyk-free-pricing-and-limits</guid>
      <pubDate>Thu, 19 Feb 2026 09:00:00 GMT</pubDate>
      <category>Industry</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Multi-Cloud Software Supply Chain Abstractions]]></title>
      <description><![CDATA[Running supply chain controls across AWS, Azure, and GCP means picking the right abstractions. Here is which ones hold up and which ones you will regret.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-cloud-software-supply-chain-abstractions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-cloud-software-supply-chain-abstractions</guid>
      <pubDate>Thu, 19 Feb 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Top 10 Riskiest Transitive Dependencies 2026]]></title>
      <description><![CDATA[The Safeguard Research team built a risk index for transitive dependencies and ranked the ten categories that concentrate the most risk in modern stacks.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-research-top-10-riskiest-transitive-deps-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-research-top-10-riskiest-transitive-deps-2026</guid>
      <pubDate>Thu, 19 Feb 2026 09:00:00 GMT</pubDate>
      <category>Research</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Prisma Cloud Container Security: Palo Alto's Cloud Native Play]]></title>
      <description><![CDATA[A review of Prisma Cloud's container and cloud workload security features, covering image scanning, runtime protection, compliance, and the Twistlock heritage.]]></description>
      <link>https://safeguard.sh/resources/blog/prisma-cloud-container-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prisma-cloud-container-security-review</guid>
      <pubDate>Thu, 19 Feb 2026 07:50:10 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2022-31129: The Day.js ReDoS Vulnerability, Explained]]></title>
      <description><![CDATA[CVE-2022-31129 is a regular expression denial of service in Day.js's custom parse format handling. Here's what triggered it, why it's still showing up in scans, and how it was fixed.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2022-31129-the-day-js-redos-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2022-31129-the-day-js-redos-explained</guid>
      <pubDate>Thu, 19 Feb 2026 06:29:43 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to implement Kubernetes Pod Security Standards]]></title>
      <description><![CDATA[A step-by-step guide to implementing Kubernetes Pod Security Standards, from auditing pods to enforcing restricted mode and migrating off PSP.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-implement-kubernetes-pod-security-standards</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-implement-kubernetes-pod-security-standards</guid>
      <pubDate>Thu, 19 Feb 2026 06:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Symmetric vs Asymmetric Encryption, Explained]]></title>
      <description><![CDATA[What makes an encryption algorithm symmetric is a single shared key for both encryption and decryption; asymmetric algorithms use a mathematically linked public/private key pair instead — and the difference decides which one you should reach for.]]></description>
      <link>https://safeguard.sh/resources/blog/symmetric-vs-asymmetric-encryption-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/symmetric-vs-asymmetric-encryption-explained</guid>
      <pubDate>Thu, 19 Feb 2026 05:09:16 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 Meets SSDF: A Practical Mapping]]></title>
      <description><![CDATA[SOC 2 auditors are starting to ask about secure development practices. Here's how to map NIST SSDF tasks onto SOC 2 Trust Services Criteria without duplicating work.]]></description>
      <link>https://safeguard.sh/resources/blog/soc2-meets-ssdf-mapping-practical</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc2-meets-ssdf-mapping-practical</guid>
      <pubDate>Thu, 19 Feb 2026 03:48:50 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to set up mutual TLS (mTLS) between microservices]]></title>
      <description><![CDATA[A step-by-step guide to configuring mTLS across microservices with Istio — from CA setup and PeerAuthentication policies to certificate rotation and verification.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-mutual-tls-mtls-between-microservices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-mutual-tls-mtls-between-microservices</guid>
      <pubDate>Thu, 19 Feb 2026 03:00:00 GMT</pubDate>
      <category>Identity Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Single-Maintainer Bus Factor Risk in OSS]]></title>
      <description><![CDATA[A single person maintaining critical infrastructure is one medical emergency, burnout, or coercion event away from a supply chain crisis. The bus factor is not a theoretical metric.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-single-maintainer-bus-factor-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-single-maintainer-bus-factor-risk</guid>
      <pubDate>Thu, 19 Feb 2026 02:28:23 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Okta 2022-2023 Incidents: Supply Chain Lessons]]></title>
      <description><![CDATA[A retrospective on Okta's string of security incidents from 2022 through 2023 and what they teach us about identity providers as critical supply chain dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/okta-2022-2023-incidents-supply-chain-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/okta-2022-2023-incidents-supply-chain-lessons</guid>
      <pubDate>Thu, 19 Feb 2026 01:07:56 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AWS Lambda Layers: Supply Chain Risks]]></title>
      <description><![CDATA[Lambda layers feel like a convenience but they are a supply chain attack surface that most teams do not treat as code. Here is how they get abused and what to do about it.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-lambda-layers-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-lambda-layers-supply-chain-risks</guid>
      <pubDate>Wed, 18 Feb 2026 23:47:30 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Node.js Permission Model: Restricting What Your Code Can Do]]></title>
      <description><![CDATA[Node.js finally has an experimental permission model. It is a significant step toward containing supply chain attacks, but it has important limitations.]]></description>
      <link>https://safeguard.sh/resources/blog/nodejs-permission-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nodejs-permission-model</guid>
      <pubDate>Wed, 18 Feb 2026 22:27:03 GMT</pubDate>
      <category>Secure Development</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Security Posture Management: A No-Nonsense Guide]]></title>
      <description><![CDATA[What CSPM actually does, where it falls short, and how to get real value from posture management instead of drowning in alerts.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-security-posture-management-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-security-posture-management-guide</guid>
      <pubDate>Wed, 18 Feb 2026 21:06:36 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Where Technical Debt Meets Security Debt]]></title>
      <description><![CDATA[Technical debt and security debt are deeply intertwined. Untangling them requires understanding how shortcuts in code quality create openings for attackers.]]></description>
      <link>https://safeguard.sh/resources/blog/technical-debt-security-debt-intersection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/technical-debt-security-debt-intersection</guid>
      <pubDate>Wed, 18 Feb 2026 19:46:10 GMT</pubDate>
      <category>Risk Management</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[GitHub's Supply Chain Security Features]]></title>
      <description><![CDATA[A comprehensive look at GitHub's evolving supply chain security toolkit, from Dependabot to code scanning, and how these features are reshaping how developers manage dependency risk.]]></description>
      <link>https://safeguard.sh/resources/blog/github-supply-chain-security-features</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-supply-chain-security-features</guid>
      <pubDate>Wed, 18 Feb 2026 18:25:43 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Ruby Gem Reserved Names Policy]]></title>
      <description><![CDATA[How RubyGems.org handles reserved gem names, what protections exist for trademark holders, and where the policy creates friction for legitimate namespace claims.]]></description>
      <link>https://safeguard.sh/resources/blog/ruby-gem-reserved-names-policy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ruby-gem-reserved-names-policy</guid>
      <pubDate>Wed, 18 Feb 2026 17:05:16 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vault Supply Chain Integration Patterns]]></title>
      <description><![CDATA[HashiCorp Vault is a Swiss Army knife for secrets, but most teams use it as a glorified key-value store. A walkthrough of the integration patterns that make Vault actually useful in a CI/CD supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/hashicorp-vault-supply-chain-integration-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hashicorp-vault-supply-chain-integration-patterns</guid>
      <pubDate>Wed, 18 Feb 2026 15:44:49 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[ESSCM: Enterprise SBOM Management at Scale]]></title>
      <description><![CDATA[Managing SBOMs across hundreds of products requires more than file storage. ESSCM brings lifecycle management, versioning, and queryability to your software inventory.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-esscm-enterprise-sbom-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-esscm-enterprise-sbom-management</guid>
      <pubDate>Wed, 18 Feb 2026 14:24:23 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to Set Up Tailwind CSS with Vue 3 Safely]]></title>
      <description><![CDATA[Getting Tailwind CSS working in a Vue 3 project takes a few minutes. Keeping the toolchain secure and your bundle clean is what separates a throwaway demo from production.]]></description>
      <link>https://safeguard.sh/resources/blog/tailwind-vue-3</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tailwind-vue-3</guid>
      <pubDate>Wed, 18 Feb 2026 14:05:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Security Testing for Data Pipelines: A Practical Guide]]></title>
      <description><![CDATA[Data pipelines ingest, transform, and move sensitive information across systems. Here is how to identify and address the security risks that traditional application testing misses.]]></description>
      <link>https://safeguard.sh/resources/blog/security-testing-data-pipelines</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-testing-data-pipelines</guid>
      <pubDate>Wed, 18 Feb 2026 13:03:56 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Leakage Testing Methods For Security Benchmarks]]></title>
      <description><![CDATA[A benchmark that the model has seen in training is a benchmark of memorisation. Specific leakage-testing methods separate generalisation from recall.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-benchmark-leakage-testing-methods</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-benchmark-leakage-testing-methods</guid>
      <pubDate>Wed, 18 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Claude Desktop MCP for Security]]></title>
      <description><![CDATA[Claude Desktop's MCP support makes it a capable security tool. Griffin AI builds on that foundation rather than competing with it.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-claude-desktop-mcp-integration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-claude-desktop-mcp-integration</guid>
      <pubDate>Wed, 18 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Mythos: Architecture Deep Dive]]></title>
      <description><![CDATA[An architectural comparison of Griffin AI's engine-grounded reasoning stack against the pure-LLM pattern that Mythos-class products rely on.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-architecture-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-architecture-deep-dive</guid>
      <pubDate>Wed, 18 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Hugging Face's Guardian-Plus-Picklescan Stack: How the Model Hub Scanning Posture Evolved Through 2025-2026]]></title>
      <description><![CDATA[Following NullifAI and the broken-pickle bypass campaigns, Hugging Face layered Protect AI's Guardian on top of Picklescan, ClamAV, and secrets scanning across 1.5 million public models. Here is the defender view of the new pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/huggingface-protectai-guardian-scanning-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/huggingface-protectai-guardian-scanning-2026</guid>
      <pubDate>Wed, 18 Feb 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[MCP Transport Layer Security Options]]></title>
      <description><![CDATA[MCP supports stdio, streamable HTTP, and a handful of experimental transports. Each has distinct security properties, and the choice of transport constrains every other security decision you make about the deployment.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-transport-layer-security-options</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-transport-layer-security-options</guid>
      <pubDate>Wed, 18 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Multi-Modal AI Supply Chain Considerations]]></title>
      <description><![CDATA[Multi-modal models bring image, audio, and video into the AI supply chain. Each modality introduces provenance and integrity challenges that text-only pipelines never had to face.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-modal-ai-supply-chain-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-modal-ai-supply-chain-considerations</guid>
      <pubDate>Wed, 18 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Two Years of Item 1.05: What the Notable 8-K Filings Tell Us]]></title>
      <description><![CDATA[From UnitedHealth to AT&T to Snowflake's downstream effects, two years of Item 1.05 filings reveal patterns in materiality, vendor incidents, and update cadence.]]></description>
      <link>https://safeguard.sh/resources/blog/sec-cyber-disclosure-2026-notable-form-8k-filings</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sec-cyber-disclosure-2026-notable-form-8k-filings</guid>
      <pubDate>Wed, 18 Feb 2026 12:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[IAST vs RASP: A Decision Tree for 2026]]></title>
      <description><![CDATA[When to deploy IAST, when to deploy RASP, and when to skip both. A pragmatic decision tree based on application architecture, threat model, and operational maturity.]]></description>
      <link>https://safeguard.sh/resources/blog/iast-vs-rasp-decision-tree-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iast-vs-rasp-decision-tree-2026</guid>
      <pubDate>Wed, 18 Feb 2026 11:45:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[NIST NVD Slowdown: What the Vulnerability Enrichment Backlog Means for Security Teams]]></title>
      <description><![CDATA[NIST's National Vulnerability Database nearly stopped enriching CVEs in early 2024, creating a growing backlog that left security teams without the severity scores and metadata they depend on.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-nvd-slowdown-vulnerability-enrichment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-nvd-slowdown-vulnerability-enrichment</guid>
      <pubDate>Wed, 18 Feb 2026 11:43:29 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to Run a Rocky Linux Container Scan Correctly]]></title>
      <description><![CDATA[A Rocky Linux container scan only produces accurate results when your scanner reads Rocky's own advisory feed instead of guessing from RHEL or CentOS data.]]></description>
      <link>https://safeguard.sh/resources/blog/rocky-linux-container-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rocky-linux-container-scan</guid>
      <pubDate>Wed, 18 Feb 2026 11:40:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SaaS Container Security: Protecting Multi-Tenant Workloads]]></title>
      <description><![CDATA[SaaS container security is the set of controls that keep containerized, multi-tenant applications isolated, patched, and hardened from build through runtime. Here is the practical playbook.]]></description>
      <link>https://safeguard.sh/resources/blog/saas-container-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/saas-container-security</guid>
      <pubDate>Wed, 18 Feb 2026 11:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Heroku OAuth Token Leak Postmortem and Lessons]]></title>
      <description><![CDATA[A retrospective on the Heroku OAuth token incident, what the public timeline revealed about supply chain trust assumptions, and the durable lessons for platform teams.]]></description>
      <link>https://safeguard.sh/resources/blog/heroku-oauth-token-leak-postmortem-and-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/heroku-oauth-token-leak-postmortem-and-lessons</guid>
      <pubDate>Wed, 18 Feb 2026 11:15:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Consulting: What to Actually Expect]]></title>
      <description><![CDATA[Application security consulting services range from a two-week penetration test to a multi-year embedded program, and knowing which one you're buying changes what you should expect to get out of it.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-consulting-what-to-expect</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-consulting-what-to-expect</guid>
      <pubDate>Wed, 18 Feb 2026 11:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Account Recovery: A Security Model Review]]></title>
      <description><![CDATA[Account recovery is where most identity systems leak security, and PyPI is no exception. A close look at how recovery works today, where the edges are, and what enterprise publishers should plan around.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-account-recovery-security-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-account-recovery-security-model</guid>
      <pubDate>Wed, 18 Feb 2026 10:23:03 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Fix 'Could Not Find or Load Main Class org.gradle.wrapper.GradleWrapperMain']]></title>
      <description><![CDATA[The 'could not find or load main class org.gradle.wrapper.GradleWrapperMain' error almost always means gradle-wrapper.jar is missing from your checkout. Here is why it happens and how to fix it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/could-not-find-or-load-main-class-org-gradle-wrapper-gradlewrappermain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/could-not-find-or-load-main-class-org-gradle-wrapper-gradlewrappermain</guid>
      <pubDate>Wed, 18 Feb 2026 10:15:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[AI-Generated Dockerfile Vulnerability Patterns]]></title>
      <description><![CDATA[LLM-generated Dockerfiles repeat the same six or seven mistakes. Here is the pattern catalog and how to catch them before they ship.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-generated-dockerfile-vulnerability-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-generated-dockerfile-vulnerability-patterns</guid>
      <pubDate>Wed, 18 Feb 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Testing Services: A Buyer's Guide]]></title>
      <description><![CDATA[A practical framework for evaluating application security testing services in 2026, from what should be included by default to the questions that separate a real program from a checkbox audit.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-testing-services-buyers-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-testing-services-buyers-guide</guid>
      <pubDate>Wed, 18 Feb 2026 10:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Blocking Malicious Packages at the Proxy Level With Artifactory]]></title>
      <description><![CDATA[Once a compromised dependency reaches a laptop or CI runner, you are doing incident response. Blocked at the Artifactory proxy, it is a log line. Here is the configuration that makes that happen.]]></description>
      <link>https://safeguard.sh/resources/blog/block-malicious-packages-artifactory-proxy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/block-malicious-packages-artifactory-proxy</guid>
      <pubDate>Wed, 18 Feb 2026 10:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Supply Chain Security Across AWS, Azure, and GCP]]></title>
      <description><![CDATA[Each major cloud provider approaches supply chain security differently. Here's a practical comparison and what it means for multi-cloud organizations.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-supply-chain-security-aws-azure-gcp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-supply-chain-security-aws-azure-gcp</guid>
      <pubDate>Wed, 18 Feb 2026 10:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[npm Slopsquat: The Hallucinated Package Risk in 2026]]></title>
      <description><![CDATA[Slopsquatting is the practice of registering package names that LLMs hallucinate, turning AI coding assistants into an accidental distribution channel.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-slopsquat-hallucinated-package-risk-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-slopsquat-hallucinated-package-risk-2026</guid>
      <pubDate>Wed, 18 Feb 2026 10:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard February 2026 Release Notes]]></title>
      <description><![CDATA[February 2026 at Safeguard: Lion behavioral baselines, Eagle base image advisories, Griffin reachability for Rust, and a new workflow editor.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-changelog-february-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-changelog-february-2026</guid>
      <pubDate>Wed, 18 Feb 2026 10:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Web Application Security Testing Tools in 2026]]></title>
      <description><![CDATA[A category map of web application security testing tools in 2026, from SAST and DAST to API scanners, and how to pick a stack that matches your architecture.]]></description>
      <link>https://safeguard.sh/resources/blog/web-application-security-testing-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-application-security-testing-tools-2026</guid>
      <pubDate>Wed, 18 Feb 2026 10:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[YAML Deserialization Attacks: The Config File That Runs Code]]></title>
      <description><![CDATA[YAML's type system allows object instantiation during parsing. In many languages, this means a YAML file can execute arbitrary code.]]></description>
      <link>https://safeguard.sh/resources/blog/yaml-deserialization-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/yaml-deserialization-attacks</guid>
      <pubDate>Wed, 18 Feb 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Security Compliance: Mapping Controls to Frameworks]]></title>
      <description><![CDATA[Chasing SOC 2, ISO 27001, and PCI DSS as separate projects triples your audit workload. Build one control set, map it to every framework, and collect evidence once.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-security-compliance-mapping-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-security-compliance-mapping-controls</guid>
      <pubDate>Wed, 18 Feb 2026 09:30:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What Is SSDLC? The Secure Software Development Lifecycle]]></title>
      <description><![CDATA[SSDLC builds security work into every phase of delivery instead of auditing at the end. Here is what changes at each phase, which frameworks define it, and how to adopt it without stalling releases.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-ssdlc-secure-development-lifecycle</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-ssdlc-secure-development-lifecycle</guid>
      <pubDate>Wed, 18 Feb 2026 09:02:36 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Software: A Category-by-Category Guide]]></title>
      <description><![CDATA[A map of the application security software market by category — SAST, DAST, SCA, ASPM, and more — so buyers can tell which tool solves which problem.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-software-category-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-software-category-guide</guid>
      <pubDate>Wed, 18 Feb 2026 09:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Cyber Security Software: An Evaluation Guide]]></title>
      <description><![CDATA[A practical framework for evaluating enterprise cyber security software beyond feature checklists — coverage, integration depth, false-positive rates, and what 'enterprise-grade' should actually mean in a contract.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-cyber-security-software-evaluation-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-cyber-security-software-evaluation-guide</guid>
      <pubDate>Wed, 18 Feb 2026 09:00:00 GMT</pubDate>
      <category>Enterprise</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to set up SAST scanning in a GitHub Actions pipeline]]></title>
      <description><![CDATA[A step-by-step guide to setting up SAST scanning in GitHub Actions with CodeQL and Semgrep, including config, gating, and troubleshooting tips.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-sast-scanning-in-a-github-actions-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-sast-scanning-in-a-github-actions-pipeline</guid>
      <pubDate>Wed, 18 Feb 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[IaC Scanning Tools for Terraform and Beyond]]></title>
      <description><![CDATA[IaC scanning tools catch misconfigured cloud resources before they're ever applied — the question is which ones actually understand Terraform's module graph instead of just its syntax.]]></description>
      <link>https://safeguard.sh/resources/blog/iac-scanning-tools-for-terraform-and-beyond</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iac-scanning-tools-for-terraform-and-beyond</guid>
      <pubDate>Wed, 18 Feb 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[NIST SSDF Audit: What Auditors Actually Check]]></title>
      <description><![CDATA[A practical walkthrough of what NIST Secure Software Development Framework audits look like in 2026, where evidence gaps show up, and how to prepare without burning out engineering.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-ssdf-secure-software-development-framework-audit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-ssdf-secure-software-development-framework-audit</guid>
      <pubDate>Wed, 18 Feb 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Runtime Application Security Protection (RASP), Explained]]></title>
      <description><![CDATA[Runtime application security protection instruments your app from the inside so it can block attacks in production, not just flag them in a report.]]></description>
      <link>https://safeguard.sh/resources/blog/runtime-application-security-protection-rasp-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runtime-application-security-protection-rasp-explained</guid>
      <pubDate>Wed, 18 Feb 2026 09:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Signing Container Images: Cosign, Notary, and Why It Matters]]></title>
      <description><![CDATA[Signing container images cryptographically proves an image came from a trusted build and hasn't been tampered with since — here's how Cosign and Notary do it, and why registries alone can't guarantee that.]]></description>
      <link>https://safeguard.sh/resources/blog/signing-container-images-cosign-and-notary-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/signing-container-images-cosign-and-notary-explained</guid>
      <pubDate>Wed, 18 Feb 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Snyk Competitors: A 2026 Market Map]]></title>
      <description><![CDATA[Snyk popularized developer-first SCA, but the competitive field has broadened into full AppSec platforms. Here's who's actually competing for the same budget in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-competitors-a-2026-market-map</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-competitors-a-2026-market-map</guid>
      <pubDate>Wed, 18 Feb 2026 09:00:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[SCA Security Tools: A Practical Shortlist]]></title>
      <description><![CDATA[A working shortlist of SCA security tools, what actually differentiates them beyond CVE counts, and how to pick an sca solution that fits your ecosystem.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-security-tools-a-shortlist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-security-tools-a-shortlist</guid>
      <pubDate>Wed, 18 Feb 2026 08:15:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[CI/CD Security Tools, Organized by Pipeline Stage]]></title>
      <description><![CDATA[A stage-by-stage map of CI/CD security tools — from pre-commit hooks to runtime protection — so you know which control belongs where instead of bolting everything onto one gate.]]></description>
      <link>https://safeguard.sh/resources/blog/ci-cd-security-tools-by-pipeline-stage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ci-cd-security-tools-by-pipeline-stage</guid>
      <pubDate>Wed, 18 Feb 2026 08:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is a Docker Container? A Practical Explanation]]></title>
      <description><![CDATA[A Docker container is a lightweight, isolated unit that packages an app with everything it needs to run — here's what that actually means under the hood and why it matters for security.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-docker-container-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-docker-container-explained</guid>
      <pubDate>Wed, 18 Feb 2026 07:42:09 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Are Dependencies in Software?]]></title>
      <description><![CDATA[A plain-English definition of software dependencies, how direct and transitive dependencies differ, and why most projects ship far more third-party code than code their own team wrote.]]></description>
      <link>https://safeguard.sh/resources/blog/what-are-dependencies-in-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-are-dependencies-in-software</guid>
      <pubDate>Wed, 18 Feb 2026 06:21:43 GMT</pubDate>
      <category>Dev Practices</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[How to set up DAST scanning in a CI/CD pipeline]]></title>
      <description><![CDATA[A practical guide to building a DAST scanning CI/CD pipeline with OWASP ZAP — setup, integration, rule tuning, and troubleshooting for real deployments.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-dast-scanning-in-a-cicd-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-dast-scanning-in-a-cicd-pipeline</guid>
      <pubDate>Wed, 18 Feb 2026 06:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[jQuery 3.5.1 Vulnerabilities: What Was Actually Fixed]]></title>
      <description><![CDATA[jQuery 3.5.1 closed a second cross-site scripting hole in the htmlPrefilter regex that 3.5.0 had only partially patched — here's exactly what changed and why old jQuery bundles still trip scanners.]]></description>
      <link>https://safeguard.sh/resources/blog/jquery-3-5-1-vulnerabilities-what-was-fixed</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jquery-3-5-1-vulnerabilities-what-was-fixed</guid>
      <pubDate>Wed, 18 Feb 2026 05:01:16 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[WAF vs RASP]]></title>
      <description><![CDATA[WAF vs RASP: how edge filtering and runtime protection differ, why Log4Shell exposed WAF blind spots, and when security teams need both layers.]]></description>
      <link>https://safeguard.sh/resources/blog/waf-vs-rasp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/waf-vs-rasp</guid>
      <pubDate>Wed, 18 Feb 2026 04:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Licenses: Choosing One for Your Repo]]></title>
      <description><![CDATA[A practical walkthrough of the license options GitHub surfaces when you create a repo, and how to pick one that matches what you actually want people to do with your code.]]></description>
      <link>https://safeguard.sh/resources/blog/github-licenses-choosing-one-for-your-repo</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-licenses-choosing-one-for-your-repo</guid>
      <pubDate>Wed, 18 Feb 2026 03:40:49 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to rotate SSH keys safely]]></title>
      <description><![CDATA[A step-by-step guide to rotating SSH keys without downtime: inventory existing keys, generate new pairs, cut over safely, revoke old keys, and verify nothing was missed.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-rotate-ssh-keys-safely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-rotate-ssh-keys-safely</guid>
      <pubDate>Wed, 18 Feb 2026 03:00:00 GMT</pubDate>
      <category>Identity Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Azure Functions Supply Chain Security]]></title>
      <description><![CDATA[Azure Functions hide a surprising amount of supply chain risk — Oryx builds, run-from-package, extension bundles, and the way deployment slots interact with identity.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-functions-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-functions-supply-chain-security</guid>
      <pubDate>Wed, 18 Feb 2026 02:20:23 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Encryption]]></title>
      <description><![CDATA[Encryption converts readable data into ciphertext using algorithms and keys. Here's how AES, RSA, and TLS actually work — and where implementations fail.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-encryption</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-encryption</guid>
      <pubDate>Wed, 18 Feb 2026 01:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Security Architecture Review Process: A Practical Framework]]></title>
      <description><![CDATA[Architecture reviews catch security issues before code is written. Most organizations skip them or do them poorly. Here is a process that works.]]></description>
      <link>https://safeguard.sh/resources/blog/security-architecture-review-process</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-architecture-review-process</guid>
      <pubDate>Wed, 18 Feb 2026 00:59:56 GMT</pubDate>
      <category>Security Operations</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[How to configure GitHub branch protection rules]]></title>
      <description><![CDATA[A practical guide to configuring GitHub branch protection rules — required reviews, status checks, and security settings that keep your main branch safe.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-configure-github-branch-protection-rules</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-configure-github-branch-protection-rules</guid>
      <pubDate>Wed, 18 Feb 2026 00:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[.NET Trimming Security Implications: What Gets Cut and Why It Matters]]></title>
      <description><![CDATA[IL trimming reduces .NET application size but can silently remove security-relevant code paths. Here is what you need to watch for.]]></description>
      <link>https://safeguard.sh/resources/blog/dotnet-trimming-security-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dotnet-trimming-security-implications</guid>
      <pubDate>Tue, 17 Feb 2026 23:39:29 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Chocolatey Package Security on Windows: What You Need to Know]]></title>
      <description><![CDATA[Chocolatey is the de facto package manager for Windows automation. Its trust model and security features deserve more scrutiny than most teams give them.]]></description>
      <link>https://safeguard.sh/resources/blog/chocolatey-package-security-windows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chocolatey-package-security-windows</guid>
      <pubDate>Tue, 17 Feb 2026 22:19:02 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[XXE Attacks Explained: XML External Entity Injection]]></title>
      <description><![CDATA[How an XXE attack turns a trusting XML parser into a file-reading, request-forging liability, with a concrete Java example and the parser flags that shut it down.]]></description>
      <link>https://safeguard.sh/resources/blog/xxe-attack-xml-external-entity-injection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xxe-attack-xml-external-entity-injection</guid>
      <pubDate>Tue, 17 Feb 2026 20:58:36 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[XSS Attack Explained: How Cross-Site Scripting Works]]></title>
      <description><![CDATA[An XSS attack lets an attacker run their JavaScript in your users' browsers. Here is how cross-site scripting works, the three types, and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/xss-attack-explained-cross-site-scripting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xss-attack-explained-cross-site-scripting</guid>
      <pubDate>Tue, 17 Feb 2026 19:38:09 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Does SCA Stand For, and Why Does It Matter Now?]]></title>
      <description><![CDATA[SCA stands for software composition analysis, and it matters more in 2024 than it did five years ago because open source now makes up the majority of most codebases.]]></description>
      <link>https://safeguard.sh/resources/blog/what-does-sca-stand-for-and-why-it-matters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-does-sca-stand-for-and-why-it-matters</guid>
      <pubDate>Tue, 17 Feb 2026 18:17:42 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Energy Sector Software Security and NERC CIP Compliance]]></title>
      <description><![CDATA[Power utilities and energy companies must secure software supply chains while meeting NERC CIP requirements. Here's a practical approach.]]></description>
      <link>https://safeguard.sh/resources/blog/energy-sector-software-security-nerc-cip</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/energy-sector-software-security-nerc-cip</guid>
      <pubDate>Tue, 17 Feb 2026 16:57:16 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Flutter and Dart Dependency Security: A Practical Guide]]></title>
      <description><![CDATA[Flutter apps pull dozens of Dart packages from pub.dev. Most teams never audit them. Here is how to manage dependency security in the Flutter ecosystem without slowing down development.]]></description>
      <link>https://safeguard.sh/resources/blog/flutter-dart-dependency-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/flutter-dart-dependency-security-guide</guid>
      <pubDate>Tue, 17 Feb 2026 15:36:49 GMT</pubDate>
      <category>Developer Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Endor Labs SCA Review: Reachability Analysis Changes the Game]]></title>
      <description><![CDATA[A review of Endor Labs and its reachability-based approach to software composition analysis, examining how call graph analysis reduces vulnerability noise.]]></description>
      <link>https://safeguard.sh/resources/blog/endor-labs-sca-platform-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/endor-labs-sca-platform-review</guid>
      <pubDate>Tue, 17 Feb 2026 14:16:22 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CISA Secure Software Development Attestation: What Vendors Must Know]]></title>
      <description><![CDATA[CISA now requires software vendors selling to the US government to attest to secure development practices. Here's what the form demands and how to prepare.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-secure-software-development-attestation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-secure-software-development-attestation</guid>
      <pubDate>Tue, 17 Feb 2026 12:55:56 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs OpenAI Function Calling: Scoping]]></title>
      <description><![CDATA[Function calling gives models the ability to act. Acting safely on behalf of a specific user, in a specific context, within specific policy is a different problem.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-openai-function-calling-scoping</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-openai-function-calling-scoping</guid>
      <pubDate>Tue, 17 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[LLM Selection Cost-Quality Tradeoff For Security]]></title>
      <description><![CDATA[LLM selection is ultimately a cost-quality optimisation under workflow constraints. The curve is not smooth, and the right point on it depends on where errors land in your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-selection-cost-quality-tradeoff-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-selection-cost-quality-tradeoff-security</guid>
      <pubDate>Tue, 17 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Apache Struts 2 Vulnerabilities: A History Worth Knowing]]></title>
      <description><![CDATA[Apache Struts 2 has produced some of the most damaging vulnerabilities in web application history, including the flaw behind the Equifax breach. Here's what happened and why it keeps happening.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-struts-2-vulnerabilities-a-history</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-struts-2-vulnerabilities-a-history</guid>
      <pubDate>Tue, 17 Feb 2026 11:35:29 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is AppSec, and Who Owns It on a Modern Team?]]></title>
      <description><![CDATA[AppSec covers every security decision made about how software is designed, built, and shipped — but ownership is more distributed than most org charts admit.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-appsec-and-who-owns-it</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-appsec-and-who-owns-it</guid>
      <pubDate>Tue, 17 Feb 2026 10:15:02 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[AI Cyber Solutions: What Actually Works in Security]]></title>
      <description><![CDATA[AI cyber solutions are most useful where they reduce analyst toil: triaging alerts, prioritizing vulnerabilities, and drafting remediation. Here is what to trust and what to question.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-cyber-solutions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-cyber-solutions</guid>
      <pubDate>Tue, 17 Feb 2026 10:15:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Software Licenses Explained: A Practical Guide for Engineering Teams]]></title>
      <description><![CDATA[Software licenses fall into a few clear buckets — permissive, copyleft, and proprietary — and knowing which is which decides what you can legally ship. Here is the map, without the legalese.]]></description>
      <link>https://safeguard.sh/resources/blog/software-licenses-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-licenses-explained</guid>
      <pubDate>Tue, 17 Feb 2026 10:15:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is TLS/SSL]]></title>
      <description><![CDATA[TLS/SSL encrypts data in transit, but outdated versions and unpatched libraries like Heartbleed-era OpenSSL still expose real risk today.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-tlsssl</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-tlsssl</guid>
      <pubDate>Tue, 17 Feb 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Snyk AppRisk: What It Actually Covers]]></title>
      <description><![CDATA[Snyk AppRisk aggregates findings across Snyk's scanners into a single application-level risk view — here's what it covers, and what it doesn't replace.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-apprisk-what-it-covers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-apprisk-what-it-covers</guid>
      <pubDate>Tue, 17 Feb 2026 09:45:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Choosing an Application Security Framework]]></title>
      <description><![CDATA[SAMM, BSIMM, NIST SSDF, and ASVS answer different questions. Here is how to pick the one that fits your team and turn it into policy your pipeline can actually enforce.]]></description>
      <link>https://safeguard.sh/resources/blog/choosing-an-application-security-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/choosing-an-application-security-framework</guid>
      <pubDate>Tue, 17 Feb 2026 09:30:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise Cloud Security: Architecture and Program Design]]></title>
      <description><![CDATA[Enterprise cloud security fails when it is treated as a tool purchase instead of an architecture. Here is how to design the layers, the ownership model, and the program around them.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-cloud-security-architecture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-cloud-security-architecture</guid>
      <pubDate>Tue, 17 Feb 2026 09:30:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Snyk's Market Trajectory Under Peter McKay]]></title>
      <description><![CDATA[Peter McKay has led Snyk as CEO since 2020, steering it from a developer-first open-source scanning tool into a broad, AI-integrated application security platform through a string of acquisitions and a sustained enterprise push.]]></description>
      <link>https://safeguard.sh/resources/blog/peter-mckay-and-snyks-market-trajectory</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/peter-mckay-and-snyks-market-trajectory</guid>
      <pubDate>Tue, 17 Feb 2026 09:30:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[UA-Parser-JS October 2021: A Deep Dive on the Attack]]></title>
      <description><![CDATA[The ua-parser-js compromise of October 2021 paired credential theft with cryptominer and password stealer payloads. A close look at what happened and why.]]></description>
      <link>https://safeguard.sh/resources/blog/ua-parser-js-october-2021-attack-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ua-parser-js-october-2021-attack-deep-dive</guid>
      <pubDate>Tue, 17 Feb 2026 09:30:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[API Security Solutions and Application Security Services: How They Differ]]></title>
      <description><![CDATA[API security solutions focus narrowly on API traffic and contracts; application security services cover the whole app. Here's where the two overlap and where teams need both.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-solutions-and-application-security-services</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-solutions-and-application-security-services</guid>
      <pubDate>Tue, 17 Feb 2026 09:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Black Basta Ransomware Leak Lessons Learned]]></title>
      <description><![CDATA[The Black Basta chat leak gave defenders a rare inside view of how a ransomware program operates. Here are the durable engineering lessons to take from it.]]></description>
      <link>https://safeguard.sh/resources/blog/blackbasta-ransomware-leak-lessons-learned</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/blackbasta-ransomware-leak-lessons-learned</guid>
      <pubDate>Tue, 17 Feb 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to set up signed commits with GPG]]></title>
      <description><![CDATA[A step-by-step guide to set up GPG signed commits in Git: generate a key, configure Git, publish it to GitHub, verify signatures, and fix common errors.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-signed-commits-with-gpg</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-signed-commits-with-gpg</guid>
      <pubDate>Tue, 17 Feb 2026 09:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[NuGet Package Signing Status in 2026]]></title>
      <description><![CDATA[NuGet package signing has quietly become one of the stricter supply chain stories in mainstream ecosystems. Here is what .NET teams actually need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-package-signing-microsoft-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-package-signing-microsoft-2026</guid>
      <pubDate>Tue, 17 Feb 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[.NET 8 Supply Chain Improvements]]></title>
      <description><![CDATA[.NET 8 quietly shipped several supply chain improvements worth knowing — NuGet audit, signed packages, SBOM tooling, and better source-link coverage.]]></description>
      <link>https://safeguard.sh/resources/blog/dotnet-8-supply-chain-improvements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dotnet-8-supply-chain-improvements</guid>
      <pubDate>Tue, 17 Feb 2026 08:54:36 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The DevSecOps Metrics That Actually Predict Breaches]]></title>
      <description><![CDATA[Finding counts and scan totals are vanity metrics. The numbers that correlate with real incidents measure exposure time, coverage gaps, and gate bypasses.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-metrics-that-predict-breaches</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-metrics-that-predict-breaches</guid>
      <pubDate>Tue, 17 Feb 2026 08:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CISA KEV Catalog Growth: A 2024 Q1 Analysis]]></title>
      <description><![CDATA[CISA added 40+ CVEs to the Known Exploited Vulnerabilities catalog in Q1 2024. We break down the vendor mix, the edge-device bias, and what to prioritize.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-kev-catalog-growth-analysis-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-kev-catalog-growth-analysis-2024</guid>
      <pubDate>Tue, 17 Feb 2026 07:34:09 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is a VPN]]></title>
      <description><![CDATA[A plain-English breakdown of what a VPN is, how it encrypts traffic, and why VPN gateways have become one of the most exploited attack surfaces in enterprise networks.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-vpn</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-vpn</guid>
      <pubDate>Tue, 17 Feb 2026 07:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes CVE-2024-3177: Bypassing Mountable Secrets Policy]]></title>
      <description><![CDATA[A medium-severity Kubernetes vulnerability allowed pods to access secrets they should not have been able to mount, undermining RBAC-based secret isolation in multi-tenant clusters.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-vulnerability-cve-2024-3177</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-vulnerability-cve-2024-3177</guid>
      <pubDate>Tue, 17 Feb 2026 06:13:42 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to implement software supply chain security with SLSA]]></title>
      <description><![CDATA[A step-by-step guide to implement SLSA supply chain security: map risk, generate signed provenance, and enforce verification before deploy.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-implement-software-supply-chain-security-with-slsa</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-implement-software-supply-chain-security-with-slsa</guid>
      <pubDate>Tue, 17 Feb 2026 06:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What is a Software Attestation]]></title>
      <description><![CDATA[A software attestation is a signed, machine-readable claim about an artifact — who built it, what it contains, which checks it passed — that a machine can verify before trusting it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-software-attestation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-software-attestation</guid>
      <pubDate>Tue, 17 Feb 2026 04:53:15 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Aisha Bello)</author>
    </item>
    <item>
      <title><![CDATA[What is EDR (Endpoint Detection and Response)]]></title>
      <description><![CDATA[What EDR actually detects, how it differs from antivirus, XDR, and MDR, and why supply chain attacks like XZ Utils and 3CX slip past it entirely.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-edr-endpoint-detection-and-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-edr-endpoint-detection-and-response</guid>
      <pubDate>Tue, 17 Feb 2026 04:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[BianLian's Pivot: From Ransomware Encryption to Pure Data Extortion]]></title>
      <description><![CDATA[BianLian abandoned encryption entirely in favor of data theft and extortion. This shift reveals where ransomware economics are heading — and why traditional defenses are lagging behind.]]></description>
      <link>https://safeguard.sh/resources/blog/bianlian-ransomware-data-extortion-evolution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bianlian-ransomware-data-extortion-evolution</guid>
      <pubDate>Tue, 17 Feb 2026 03:32:49 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to set up Kubernetes RBAC]]></title>
      <description><![CDATA[A step-by-step kubernetes RBAC setup guide covering Roles, RoleBindings, service accounts, least-privilege patterns, and how to verify and troubleshoot access.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-kubernetes-rbac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-kubernetes-rbac</guid>
      <pubDate>Tue, 17 Feb 2026 03:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[VM to Container: Supply Chain Implications of the Migration]]></title>
      <description><![CDATA[What changes in your software supply chain when you move from virtual machines to containers, and how to adapt governance, scanning, and provenance accordingly.]]></description>
      <link>https://safeguard.sh/resources/blog/vm-to-container-supply-chain-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vm-to-container-supply-chain-implications</guid>
      <pubDate>Tue, 17 Feb 2026 02:12:22 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is SIEM]]></title>
      <description><![CDATA[SIEM explained: how it works, what data feeds it, how it differs from SOAR/XDR, and where reachability-based supply chain security fills its blind spots.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-siem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-siem</guid>
      <pubDate>Tue, 17 Feb 2026 01:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Tekton Pipelines Hardening Guide]]></title>
      <description><![CDATA[A practical hardening guide for Tekton Pipelines covering TaskRun isolation, step image provenance, workspace secrets, and the CVE history that shaped the current defaults.]]></description>
      <link>https://safeguard.sh/resources/blog/tekton-pipelines-hardening-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tekton-pipelines-hardening-guide</guid>
      <pubDate>Tue, 17 Feb 2026 00:51:55 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to encrypt Kubernetes secrets at rest]]></title>
      <description><![CDATA[A step-by-step guide to encrypting Kubernetes secrets at rest: choosing a KMS provider, configuring etcd encryption, re-encrypting existing secrets, and verifying it worked.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-encrypt-kubernetes-secrets-at-rest</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-encrypt-kubernetes-secrets-at-rest</guid>
      <pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Publish an npm Package With Provenance]]></title>
      <description><![CDATA[A step-by-step tutorial for publishing npm packages with provenance attestations so your consumers can cryptographically verify the build source.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-publish-npm-package-with-provenance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-publish-npm-package-with-provenance</guid>
      <pubDate>Mon, 16 Feb 2026 23:31:29 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CI/CD Compromise Investigation Steps]]></title>
      <description><![CDATA[A step-by-step investigation playbook for suspected CI/CD pipeline compromise, from runner forensics to secrets rotation.]]></description>
      <link>https://safeguard.sh/resources/blog/ci-cd-compromise-investigation-steps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ci-cd-compromise-investigation-steps</guid>
      <pubDate>Mon, 16 Feb 2026 22:11:02 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Certificate Pinning for Software Updates: When and How to Pin]]></title>
      <description><![CDATA[Certificate pinning can protect your update channel from MITM attacks, but it introduces operational complexity. Here is when pinning makes sense and how to do it safely.]]></description>
      <link>https://safeguard.sh/resources/blog/certificate-pinning-software-updates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/certificate-pinning-software-updates</guid>
      <pubDate>Mon, 16 Feb 2026 20:50:35 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Security KPI Frameworks: Measuring What Matters Without Drowning in Metrics]]></title>
      <description><![CDATA[Most security metrics measure activity, not outcomes. Here is how to build a KPI framework that tells leadership whether the security program is actually reducing risk.]]></description>
      <link>https://safeguard.sh/resources/blog/security-kpi-frameworks-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-kpi-frameworks-guide</guid>
      <pubDate>Mon, 16 Feb 2026 19:30:09 GMT</pubDate>
      <category>Security Management</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Mobile Application Security Testing: Beyond the OWASP Mobile Top 10]]></title>
      <description><![CDATA[Mobile apps have unique security challenges that web-focused tools miss entirely. Here is a practical testing methodology for iOS and Android.]]></description>
      <link>https://safeguard.sh/resources/blog/mobile-application-security-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mobile-application-security-testing</guid>
      <pubDate>Mon, 16 Feb 2026 18:09:42 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[GPLv3 License: What Changed From GPLv2]]></title>
      <description><![CDATA[GPLv3 added patent protection and anti-tivoization clauses that GPLv2 never had. Here's what actually changed and why it still matters for dependency compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/gpl-v3-license-what-changed-from-gplv2</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gpl-v3-license-what-changed-from-gplv2</guid>
      <pubDate>Mon, 16 Feb 2026 16:49:15 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The AGPL-3.0 License, Explained]]></title>
      <description><![CDATA[AGPL-3.0 is the GNU Affero General Public License v3.0 — GPLv3 with one added clause that closes the SaaS loophole, requiring source disclosure even when software is only used over a network, never distributed.]]></description>
      <link>https://safeguard.sh/resources/blog/agpl-3-0-license-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agpl-3-0-license-explained</guid>
      <pubDate>Mon, 16 Feb 2026 15:28:49 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Secrets Encryption Providers Reviewed]]></title>
      <description><![CDATA[etcd encryption at rest finally works out of the box. The question is which provider you use, and the trade-offs have sharpened in 2024.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-secrets-encryption-providers-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-secrets-encryption-providers-review</guid>
      <pubDate>Mon, 16 Feb 2026 14:08:22 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Fintech Software Supply Chain Regulatory Map]]></title>
      <description><![CDATA[A practical tour through the tangle of regulations, supervisory letters, and industry standards that now govern how fintech firms build, buy, and operate software.]]></description>
      <link>https://safeguard.sh/resources/blog/fintech-software-supply-chain-regulatory-map</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fintech-software-supply-chain-regulatory-map</guid>
      <pubDate>Mon, 16 Feb 2026 12:47:55 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Unbounded Output Space And Security Contracts]]></title>
      <description><![CDATA[A function whose output space is finite and enumerable can be secured by testing. A function whose output space is every string of tokens up to some length cannot. That difference quietly invalidates most classical security contracts.]]></description>
      <link>https://safeguard.sh/resources/blog/frontier-model-limit-unbounded-output-space</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/frontier-model-limit-unbounded-output-space</guid>
      <pubDate>Mon, 16 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Bring-Your-Own-Model: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Model lock-in is the quiet liability of pure-LLM vendors. Safeguard's bring-your-own-model story gives enterprises the option Mythos-class competitors cannot match.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-bring-your-own-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-bring-your-own-model</guid>
      <pubDate>Mon, 16 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Vertex AI Safety for Enterprise]]></title>
      <description><![CDATA[Vertex AI Safety is Google's approach to enterprise AI controls. For security-specific workflows, Griffin AI adds grounding the Safety layer doesn't.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-vertex-ai-safety-for-enterprise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-vertex-ai-safety-for-enterprise</guid>
      <pubDate>Mon, 16 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is RASP]]></title>
      <description><![CDATA[RASP runs inside an application and blocks attacks in real time, from the inside out. Here's how it works, how it differs from a WAF, and where it fits.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-rasp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-rasp</guid>
      <pubDate>Mon, 16 Feb 2026 11:27:28 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Crates.io Security Audit Results: The State of Rust Package Security]]></title>
      <description><![CDATA[Security audits of the Rust crate ecosystem reveal patterns of unsafe code, build script risks, and supply chain vulnerabilities. Here is what the data shows.]]></description>
      <link>https://safeguard.sh/resources/blog/crates-io-security-audit-results</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/crates-io-security-audit-results</guid>
      <pubDate>Mon, 16 Feb 2026 10:07:02 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[FAQ: How Much Does Supply Chain Security Cost?]]></title>
      <description><![CDATA[Real numbers for supply chain security in 2026 — tool spend, headcount, hidden costs, SMB vs enterprise ranges, and where teams over- and under-invest.]]></description>
      <link>https://safeguard.sh/resources/blog/faq-how-much-does-supply-chain-security-cost-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/faq-how-much-does-supply-chain-security-cost-2026</guid>
      <pubDate>Mon, 16 Feb 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[KubeCon NA 2025: Supply Chain Security Themes]]></title>
      <description><![CDATA[KubeCon + CloudNativeCon NA 2025 put supply chain security at the center of the cloud-native conversation. Here is what mattered for platform teams.]]></description>
      <link>https://safeguard.sh/resources/blog/kubecon-na-2025-supply-chain-security-themes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubecon-na-2025-supply-chain-security-themes</guid>
      <pubDate>Mon, 16 Feb 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is SOAR]]></title>
      <description><![CDATA[SOAR explained: what Security Orchestration, Automation, and Response actually does, how it differs from SIEM, and where it fits in supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-soar</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-soar</guid>
      <pubDate>Mon, 16 Feb 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Board-Level Supply Chain Security Reporting]]></title>
      <description><![CDATA[A practical template for reporting software supply chain risk to the board, including the three slides that work, the language that does not, and common traps.]]></description>
      <link>https://safeguard.sh/resources/blog/board-level-supply-chain-security-reporting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/board-level-supply-chain-security-reporting</guid>
      <pubDate>Mon, 16 Feb 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to set up AWS CloudTrail logging]]></title>
      <description><![CDATA[A step-by-step guide to setting up AWS CloudTrail logging, enabling it across all regions, validating log integrity, and building a solid audit logging setup.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-aws-cloudtrail-logging</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-aws-cloudtrail-logging</guid>
      <pubDate>Mon, 16 Feb 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[K8s RBAC Blast Radius in Supply Chain Attacks]]></title>
      <description><![CDATA[How Kubernetes RBAC determines what a supply chain attack can actually do once a compromised workload runs, and the RBAC patterns that meaningfully reduce blast radius.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-rbac-blast-radius-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-rbac-blast-radius-supply-chain</guid>
      <pubDate>Mon, 16 Feb 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Capacitor and Ionic Hybrid App Security: A Practical Guide]]></title>
      <description><![CDATA[Capacitor-based hybrid apps blend web technologies with native device access. This combination creates a unique attack surface that requires specific security strategies.]]></description>
      <link>https://safeguard.sh/resources/blog/capacitor-ionic-hybrid-app-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/capacitor-ionic-hybrid-app-security</guid>
      <pubDate>Mon, 16 Feb 2026 08:46:35 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Abandoned Package Takeover: When Maintainers Walk Away]]></title>
      <description><![CDATA[Abandoned packages are ticking time bombs in the supply chain. When maintainers disappear, attackers can take over package names and push malicious updates to millions of downstream projects.]]></description>
      <link>https://safeguard.sh/resources/blog/abandoned-package-takeover-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/abandoned-package-takeover-risks</guid>
      <pubDate>Mon, 16 Feb 2026 07:26:08 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What is an Intrusion Detection System (IDS)]]></title>
      <description><![CDATA[An IDS detects malicious network or host activity after it happens. Learn what an IDS is, how it differs from an IPS, and why supply chain attacks need more.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-an-intrusion-detection-system-ids</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-an-intrusion-detection-system-ids</guid>
      <pubDate>Mon, 16 Feb 2026 07:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What Does SAST Stand For, Exactly?]]></title>
      <description><![CDATA[SAST stands for static application security testing — analyzing source code for vulnerabilities without ever running the program, which is what separates it from every dynamic testing approach.]]></description>
      <link>https://safeguard.sh/resources/blog/what-does-sast-stand-for</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-does-sast-stand-for</guid>
      <pubDate>Mon, 16 Feb 2026 06:05:42 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Software Liability in 2024: The Shift From Caveat Emptor to Vendor Accountability]]></title>
      <description><![CDATA[Governments worldwide are moving to hold software vendors liable for security failures. Here is what the shifting liability landscape means for software producers and consumers.]]></description>
      <link>https://safeguard.sh/resources/blog/software-liability-shifting-landscape-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-liability-shifting-landscape-2024</guid>
      <pubDate>Mon, 16 Feb 2026 04:45:15 GMT</pubDate>
      <category>Policy & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is an Intrusion Prevention System (IPS)]]></title>
      <description><![CDATA[An IPS blocks malicious traffic inline in real time, but it can't stop supply chain attacks hidden inside trusted code and dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-an-intrusion-prevention-system-ips</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-an-intrusion-prevention-system-ips</guid>
      <pubDate>Mon, 16 Feb 2026 04:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Security Debt: Measuring and Paying It Down]]></title>
      <description><![CDATA[Security debt is the gap between the risk you're carrying and the risk you've decided to carry. Here's how to measure it in vuln-days and pay it down without a heroic quarter.]]></description>
      <link>https://safeguard.sh/resources/blog/security-debt-measuring-and-paying-it-down</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-debt-measuring-and-paying-it-down</guid>
      <pubDate>Mon, 16 Feb 2026 03:24:48 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Jonas Meyer)</author>
    </item>
    <item>
      <title><![CDATA[How to set up secrets scanning in git repositories]]></title>
      <description><![CDATA[A step-by-step guide to secrets scanning in git repositories using gitleaks and trufflehog, covering pre-commit hooks, CI enforcement, and history audits.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-secrets-scanning-in-git-repositories</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-secrets-scanning-in-git-repositories</guid>
      <pubDate>Mon, 16 Feb 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Securing Software Update Mechanisms]]></title>
      <description><![CDATA[Software updates are a double-edged sword: they deliver patches but also provide a trusted channel attackers can exploit. Securing the update mechanism itself is essential to supply chain integrity.]]></description>
      <link>https://safeguard.sh/resources/blog/software-update-mechanism-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-update-mechanism-security</guid>
      <pubDate>Mon, 16 Feb 2026 02:04:22 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is Network Segmentation]]></title>
      <description><![CDATA[Network segmentation limits breach blast radius by isolating systems into enforced zones. Learn the types, common mistakes, and how to implement it in hybrid clouds.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-network-segmentation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-network-segmentation</guid>
      <pubDate>Mon, 16 Feb 2026 01:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Argo CD GitOps Security Guide]]></title>
      <description><![CDATA[Securing Argo CD deployments with RBAC, SSO integration, secret management, and network policies for production Kubernetes clusters.]]></description>
      <link>https://safeguard.sh/resources/blog/argo-cd-gitops-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/argo-cd-gitops-security-guide</guid>
      <pubDate>Mon, 16 Feb 2026 00:43:55 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[How to Generate an SBOM in a GitLab CI Pipeline]]></title>
      <description><![CDATA[A working .gitlab-ci.yml for SBOM generation with Syft: CycloneDX report artifacts, a Grype scan stage, and Cosign attestations pushed next to the image.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-generate-an-sbom-in-a-gitlab-ci-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-generate-an-sbom-in-a-gitlab-ci-pipeline</guid>
      <pubDate>Sun, 15 Feb 2026 23:23:28 GMT</pubDate>
      <category>Guides</category>
      <author>hi@safeguard.sh (Priya Raman)</author>
    </item>
    <item>
      <title><![CDATA[Introducing Safeguard: Software Supply Chain Security, Done Right]]></title>
      <description><![CDATA[Today we are launching Safeguard, a platform purpose-built for managing the security of your software supply chain from SBOM generation to vulnerability response.]]></description>
      <link>https://safeguard.sh/resources/blog/introducing-safeguard-software-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/introducing-safeguard-software-supply-chain-security</guid>
      <pubDate>Sun, 15 Feb 2026 22:03:02 GMT</pubDate>
      <category>Company</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[LockBit Takedown: Inside Operation Cronos]]></title>
      <description><![CDATA[Operation Cronos seized LockBit's leak site in February 2024. We unpack the NCA-led takedown, the decryptor release, and LockBit's rapid rebuild.]]></description>
      <link>https://safeguard.sh/resources/blog/lockbit-takedown-operation-cronos-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lockbit-takedown-operation-cronos-analysis</guid>
      <pubDate>Sun, 15 Feb 2026 20:42:35 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Lazarus Group Software Supply Chain Campaigns]]></title>
      <description><![CDATA[A field analyst's look at how North Korea's Lazarus Group has turned software supply chains into a strategic weapon, from 3CX to npm.]]></description>
      <link>https://safeguard.sh/resources/blog/lazarus-group-software-supply-chain-campaigns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lazarus-group-software-supply-chain-campaigns</guid>
      <pubDate>Sun, 15 Feb 2026 19:22:08 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Set Up Sigstore in Your Build Pipeline]]></title>
      <description><![CDATA[Wire Sigstore into GitHub Actions end-to-end: OIDC identity, Cosign signing, Rekor transparency, and policy-controller enforcement — with working snippets.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-sigstore-in-your-build-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-sigstore-in-your-build-pipeline</guid>
      <pubDate>Sun, 15 Feb 2026 18:01:41 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AWS SAM Template Security Considerations]]></title>
      <description><![CDATA[SAM templates look simple and that is exactly the problem. The defaults are generous, the transforms are opaque, and the resulting stacks are often more privileged than anyone intended.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-sam-template-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-sam-template-security-considerations</guid>
      <pubDate>Sun, 15 Feb 2026 16:41:15 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Multi-Cloud Security Posture Management for Supply Chains]]></title>
      <description><![CDATA[Running workloads across AWS, Azure, and GCP multiplies your attack surface. This guide covers cloud security posture management with a supply chain lens.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-cloud-security-posture-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-cloud-security-posture-management</guid>
      <pubDate>Sun, 15 Feb 2026 15:20:48 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Building a Software Vendor Security Scorecard]]></title>
      <description><![CDATA[Not all vendors are equal when it comes to security. Here is how to build a scorecard that objectively evaluates vendor security practices and informs procurement decisions.]]></description>
      <link>https://safeguard.sh/resources/blog/software-vendor-security-scorecard</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-vendor-security-scorecard</guid>
      <pubDate>Sun, 15 Feb 2026 14:00:21 GMT</pubDate>
      <category>Risk Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Building a Security Champions Program]]></title>
      <description><![CDATA[A step-by-step guide to launching a security champions program that scales your security team's influence across engineering without hiring a dozen new AppSec engineers.]]></description>
      <link>https://safeguard.sh/resources/blog/security-champions-program-building-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-champions-program-building-guide</guid>
      <pubDate>Sun, 15 Feb 2026 12:39:55 GMT</pubDate>
      <category>How-To Guide</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[EU AI Act Enforcement: Year One Review]]></title>
      <description><![CDATA[The first enforcement window under the EU AI Act has closed. The actual pattern of enforcement looks different from the one vendors and advocacy groups predicted.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-trend-eu-ai-act-enforcement-first-year</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-trend-eu-ai-act-enforcement-first-year</guid>
      <pubDate>Sun, 15 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Patch Minimality: Griffin AI vs Mythos]]></title>
      <description><![CDATA[A minimal patch is easier to review, safer to merge, and cheaper to roll back. Griffin AI enforces minimality; Mythos-class tools treat it as optional.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-patch-minimality</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-patch-minimality</guid>
      <pubDate>Sun, 15 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Rate-Limiting Patterns]]></title>
      <description><![CDATA[A practical look at rate-limiting patterns for Model Context Protocol servers, covering per-tool quotas, token budgets, burst control, and abuse-resistant designs.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-rate-limiting-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-rate-limiting-patterns</guid>
      <pubDate>Sun, 15 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Earthly Reproducible Builds and Security]]></title>
      <description><![CDATA[How Earthly's reproducible, containerized build system eliminates environment drift and strengthens build integrity for security-conscious teams.]]></description>
      <link>https://safeguard.sh/resources/blog/earthly-reproducible-builds-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/earthly-reproducible-builds-security</guid>
      <pubDate>Sun, 15 Feb 2026 11:19:28 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[SLSA Level 3 Implementation Blueprint 2026]]></title>
      <description><![CDATA[A practical blueprint for reaching SLSA Level 3 in 2026: hosted builders, provenance generation, verification gates, and the operational habits that hold the line.]]></description>
      <link>https://safeguard.sh/resources/blog/slsa-level-3-implementation-blueprint-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slsa-level-3-implementation-blueprint-2026</guid>
      <pubDate>Sun, 15 Feb 2026 11:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Securing MCP Servers in the Enterprise: A Practical Guide]]></title>
      <description><![CDATA[MCP servers connect AI agents to your infrastructure. Here's how to secure them without killing the productivity gains.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-mcp-servers-enterprise-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-mcp-servers-enterprise-guide</guid>
      <pubDate>Sun, 15 Feb 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is Multi-Factor Authentication (MFA)]]></title>
      <description><![CDATA[MFA blocks over 99% of credential-based attacks, but Uber, Cisco, and Twilio breaches show how push-bombing and AiTM phishing still get around it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-multi-factor-authentication-mfa</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-multi-factor-authentication-mfa</guid>
      <pubDate>Sun, 15 Feb 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2023-4807: The OpenSSL POLY1305 Flaw on Windows]]></title>
      <description><![CDATA[A cryptographic MAC that silently trashes CPU registers: why CVE-2023-4807 only bites Windows builds of OpenSSL, what it can actually do, and which releases fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2023-4807-openssl-poly1305-windows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2023-4807-openssl-poly1305-windows</guid>
      <pubDate>Sun, 15 Feb 2026 09:59:01 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to configure OWASP ZAP for automated scanning]]></title>
      <description><![CDATA[A step-by-step guide to configuring OWASP ZAP for automated scanning in CI/CD, from Docker setup through baseline and API scans to pipeline gating.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-configure-owasp-zap-for-automated-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-configure-owasp-zap-for-automated-scanning</guid>
      <pubDate>Sun, 15 Feb 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CISA's Memory-Safe Languages Roadmap: What It Means for Software Development]]></title>
      <description><![CDATA[CISA publishes a roadmap urging the industry to transition to memory-safe programming languages, targeting the root cause of roughly 70% of critical vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-memory-safe-languages-roadmap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-memory-safe-languages-roadmap</guid>
      <pubDate>Sun, 15 Feb 2026 08:38:35 GMT</pubDate>
      <category>Compliance & Frameworks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NIST Cybersecurity Framework 2.0: What Changed and Why It Matters]]></title>
      <description><![CDATA[NIST CSF 2.0 introduces a new Govern function and expands supply chain risk management. Here's what security teams need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-cybersecurity-framework-2-0-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-cybersecurity-framework-2-0-guide</guid>
      <pubDate>Sun, 15 Feb 2026 07:18:08 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Single Sign-On (SSO)]]></title>
      <description><![CDATA[SSO lets users log in once to access many apps — but it also concentrates identity into one high-value target. Here's how it works and its real risks.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-single-sign-on-sso</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-single-sign-on-sso</guid>
      <pubDate>Sun, 15 Feb 2026 07:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to set up software composition analysis (SCA)]]></title>
      <description><![CDATA[A practical, step-by-step guide to setting up software composition analysis: choosing a tool, setting policy, and integrating scans into CI/CD.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-software-composition-analysis-sca</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-software-composition-analysis-sca</guid>
      <pubDate>Sun, 15 Feb 2026 06:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[NuGet Package Signing: Enterprise Rollout]]></title>
      <description><![CDATA[Rolling NuGet package signing enforcement across a large .NET estate is a policy and tooling problem, not a cryptography problem. Here is how it actually goes.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-package-signing-enterprise-rollout</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-package-signing-enterprise-rollout</guid>
      <pubDate>Sun, 15 Feb 2026 05:57:41 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Poetry and Python Supply Chain Security]]></title>
      <description><![CDATA[Poetry's lockfile is an asset. Its dependency resolver is a tradeoff. Here is how to run Poetry safely in a world of typosquats, dependency confusion, and unmaintained installers.]]></description>
      <link>https://safeguard.sh/resources/blog/python-poetry-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-poetry-supply-chain-security</guid>
      <pubDate>Sun, 15 Feb 2026 04:37:14 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is a Security Operations Center (SOC)]]></title>
      <description><![CDATA[A clear breakdown of what a Security Operations Center (SOC) is, how it's staffed, the tools it runs, and how it differs from a NOC or CSIRT.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-security-operations-center-soc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-security-operations-center-soc</guid>
      <pubDate>Sun, 15 Feb 2026 04:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[PDF Supply Chain Attack Vectors: When Documents Become Weapons]]></title>
      <description><![CDATA[PDFs are trusted by default in most organizations. That trust makes them a potent vector for supply chain attacks. Here is how the attacks work.]]></description>
      <link>https://safeguard.sh/resources/blog/pdf-supply-chain-attack-vectors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pdf-supply-chain-attack-vectors</guid>
      <pubDate>Sun, 15 Feb 2026 03:16:48 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to enable MFA on an AWS root account]]></title>
      <description><![CDATA[A step-by-step guide to enabling MFA on your AWS root account, covering virtual MFA device setup, verification commands, troubleshooting, and ongoing security best practices.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-enable-mfa-on-an-aws-root-account</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-enable-mfa-on-an-aws-root-account</guid>
      <pubDate>Sun, 15 Feb 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Change Healthcare Breach: The Worst Healthcare Data Breach in U.S. History]]></title>
      <description><![CDATA[In February 2024, a ransomware attack on Change Healthcare paralyzed the U.S. healthcare payment system for weeks and ultimately exposed the personal health data of over 100 million Americans, making it the largest healthcare data breach ever recorded.]]></description>
      <link>https://safeguard.sh/resources/blog/unitedhealth-change-healthcare-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/unitedhealth-change-healthcare-breach</guid>
      <pubDate>Sun, 15 Feb 2026 01:56:21 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is Incident Response]]></title>
      <description><![CDATA[What incident response actually means, its four NIST phases, and why supply chain attacks like Log4Shell and SolarWinds break traditional response assumptions.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-incident-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-incident-response</guid>
      <pubDate>Sun, 15 Feb 2026 01:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Change Healthcare Ransomware Attack: The Breach That Disrupted American Healthcare]]></title>
      <description><![CDATA[The BlackCat/ALPHV ransomware attack on Change Healthcare caused the largest healthcare IT disruption in U.S. history, affecting pharmacies, hospitals, and insurance claims processing nationwide.]]></description>
      <link>https://safeguard.sh/resources/blog/change-healthcare-ransomware-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/change-healthcare-ransomware-attack</guid>
      <pubDate>Sun, 15 Feb 2026 00:35:54 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AI Models in Your Supply Chain: The Security Risks Nobody Talks About]]></title>
      <description><![CDATA[AI/ML models are the new open source libraries. Here's why your supply chain security strategy needs to account for model provenance, poisoning, and compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-supply-chain-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-supply-chain-security-risks</guid>
      <pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[How to set up centralized logging with the ELK stack]]></title>
      <description><![CDATA[A hands-on guide to setting up ELK stack centralized logging: installing Elasticsearch, Logstash, and Kibana, shipping logs with Beats, and building SIEM-style alerts.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-centralized-logging-with-the-elk-stack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-centralized-logging-with-the-elk-stack</guid>
      <pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Operation Cronos: How Law Enforcement Dismantled LockBit Ransomware]]></title>
      <description><![CDATA[A coordinated international operation seized LockBit's infrastructure, arrested affiliates, and obtained decryption keys. But did it actually stop the world's most prolific ransomware gang?]]></description>
      <link>https://safeguard.sh/resources/blog/lockbit-ransomware-takedown-operation-cronos</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lockbit-ransomware-takedown-operation-cronos</guid>
      <pubDate>Sat, 14 Feb 2026 23:15:28 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Security Awareness Training That Developers Don't Hate]]></title>
      <description><![CDATA[Traditional security training is boring and ineffective. Here is how to build a training program developers actually engage with and learn from.]]></description>
      <link>https://safeguard.sh/resources/blog/security-awareness-training-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-awareness-training-developers</guid>
      <pubDate>Sat, 14 Feb 2026 21:55:01 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Confusion in Private Registries: The Attack That Keeps Working]]></title>
      <description><![CDATA[Dependency confusion exploits the gap between public and private package registries. Despite widespread awareness, organizations keep falling for it.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-confusion-private-registries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-confusion-private-registries</guid>
      <pubDate>Sat, 14 Feb 2026 20:34:34 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What Is the NIST Cybersecurity Framework?]]></title>
      <description><![CDATA[The NIST Cybersecurity Framework is a voluntary set of standards organized around five (now six) functions — here's what it actually is and how organizations use it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-nist-cybersecurity-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-nist-cybersecurity-framework</guid>
      <pubDate>Sat, 14 Feb 2026 19:14:08 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[jQuery 1.10.2 Vulnerabilities: Should You Still Worry?]]></title>
      <description><![CDATA[jQuery 1.10.2, released in 2013, predates the fixes for three well-documented CVEs — CVE-2015-9251, CVE-2019-11358, and CVE-2020-11022/11023 — which means yes, it's genuinely still worth worrying about.]]></description>
      <link>https://safeguard.sh/resources/blog/jquery-1-10-2-vulnerabilities-should-you-still-worry</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jquery-1-10-2-vulnerabilities-should-you-still-worry</guid>
      <pubDate>Sat, 14 Feb 2026 17:53:41 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Shopify's Supply Chain Security Program]]></title>
      <description><![CDATA[How Shopify built a supply chain security program that protects millions of merchants while maintaining the development velocity that e-commerce demands.]]></description>
      <link>https://safeguard.sh/resources/blog/shopify-supply-chain-security-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shopify-supply-chain-security-program</guid>
      <pubDate>Sat, 14 Feb 2026 16:33:14 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[SBOMs for Microservices Architecture: Managing Complexity at Scale]]></title>
      <description><![CDATA[When your application is 50 services with 50 dependency trees, SBOM management stops being simple. Here's how to handle it.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-microservices-architecture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-microservices-architecture</guid>
      <pubDate>Sat, 14 Feb 2026 15:12:48 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Apache 2 License: A Quick Reference]]></title>
      <description><![CDATA[The Apache 2 license is a permissive open source license that allows commercial use, modification, and redistribution, with an explicit patent grant most permissive licenses lack.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-2-license-quick-reference</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-2-license-quick-reference</guid>
      <pubDate>Sat, 14 Feb 2026 13:52:21 GMT</pubDate>
      <category>Licensing</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Follina and the MSDT Lesson: What CVE-2022-30190 Taught About Trusted Handlers]]></title>
      <description><![CDATA[Follina exploited a Microsoft Support Diagnostic Tool URI handler that nobody thought about. The technical mechanics, the rapid exploitation, and the lasting defense lessons.]]></description>
      <link>https://safeguard.sh/resources/blog/follina-msdt-cve-2022-30190-defense-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/follina-msdt-cve-2022-30190-defense-lessons</guid>
      <pubDate>Sat, 14 Feb 2026 13:45:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Nginx 1.20.1 Vulnerabilities: What to Patch]]></title>
      <description><![CDATA[Nginx 1.20.1 fixed a real, exploitable DNS resolver bug — if you're still running an older 1.20.x or 1.19.x build, here's what the fix addressed and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/nginx-1-20-1-vulnerabilities-what-to-patch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nginx-1-20-1-vulnerabilities-what-to-patch</guid>
      <pubDate>Sat, 14 Feb 2026 12:31:54 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Framework Routing Awareness: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Every HTTP vulnerability begins at a route. Griffin AI models routing; Mythos-class tools guess it. That difference shapes every downstream finding.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-framework-routing-awareness</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-framework-routing-awareness</guid>
      <pubDate>Sat, 14 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[PCI DSS 4.0 Alignment: Griffin AI vs Mythos]]></title>
      <description><![CDATA[PCI DSS 4.0 raised the evidence bar for software security, supplier management, and continuous assurance. Griffin AI meets the new requirements with persisted records. Mythos-class pure-LLM tools leave QSAs asking for artifacts.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-pci-dss-4-alignment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-pci-dss-4-alignment</guid>
      <pubDate>Sat, 14 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[gVisor Runtime Security Deep Dive]]></title>
      <description><![CDATA[gVisor intercepts syscalls in userspace and implements a minimal kernel in Go. It is a genuinely different approach, with genuinely different trade-offs.]]></description>
      <link>https://safeguard.sh/resources/blog/gvisor-runtime-security-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gvisor-runtime-security-deep-dive</guid>
      <pubDate>Sat, 14 Feb 2026 11:11:27 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Getting Started: Safeguard GitHub Actions Gate]]></title>
      <description><![CDATA[Set up the Safeguard GitHub Action to block risky pull requests on dependency vulnerabilities, license violations, and policy breaches before merge.]]></description>
      <link>https://safeguard.sh/resources/blog/getting-started-safeguard-github-actions-gate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/getting-started-safeguard-github-actions-gate</guid>
      <pubDate>Sat, 14 Feb 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is a Data Breach]]></title>
      <description><![CDATA[A data breach is unauthorized access to sensitive data. See real causes like MOVEit and Log4Shell, average costs, and how to prevent one.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-data-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-data-breach</guid>
      <pubDate>Sat, 14 Feb 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Fortinet FortiOS CVE-2024-21762: Exploitation Patterns]]></title>
      <description><![CDATA[CVE-2024-21762 gave attackers pre-auth RCE on FortiGate SSL VPN. We trace the exploitation patterns, scanner behavior, and who got hit first.]]></description>
      <link>https://safeguard.sh/resources/blog/fortinet-fortios-cve-2024-21762-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fortinet-fortios-cve-2024-21762-exploitation</guid>
      <pubDate>Sat, 14 Feb 2026 09:51:01 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GCP Artifact Analysis API for Vulnerability Triage]]></title>
      <description><![CDATA[GCP's Artifact Analysis API is the most direct way to get scan results into your triage tooling. Here is how to use it without drowning your team.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-artifact-analysis-api-vulnerability-triage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-artifact-analysis-api-vulnerability-triage</guid>
      <pubDate>Sat, 14 Feb 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to configure Falco for runtime security monitoring]]></title>
      <description><![CDATA[A practical walkthrough to configure Falco runtime security in Kubernetes: install, customize rules, route alerts, tune noise, and verify detection end-to-end.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-configure-falco-for-runtime-security-monitoring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-configure-falco-for-runtime-security-monitoring</guid>
      <pubDate>Sat, 14 Feb 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Multi-Tenant Isolation for FedRAMP HIGH]]></title>
      <description><![CDATA[How Safeguard achieves hard multi-tenant isolation in a platform that meets FedRAMP HIGH — the boundaries, the proofs, and the trade-offs we accepted.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-multi-tenant-isolation-architecture-fedramp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-multi-tenant-isolation-architecture-fedramp</guid>
      <pubDate>Sat, 14 Feb 2026 09:00:00 GMT</pubDate>
      <category>Architecture</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Security KPIs for Engineering Leaders]]></title>
      <description><![CDATA[If you cannot measure your supply chain security posture, you cannot invest in it. Here are the KPIs that separate real programs from the theater.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-kpis-for-engineering-leaders</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-kpis-for-engineering-leaders</guid>
      <pubDate>Sat, 14 Feb 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Incident Notification Laws: A Global Overview]]></title>
      <description><![CDATA[Governments worldwide are mandating supply chain incident disclosure. Here is what organizations need to know about notification requirements across major jurisdictions.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-incident-notification-laws</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-incident-notification-laws</guid>
      <pubDate>Sat, 14 Feb 2026 08:30:34 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[The OWASP Top 10 for Large Language Model Applications: A Field Guide]]></title>
      <description><![CDATA[A working breakdown of the OWASP Top 10 for Large Language Model Applications — what each risk actually looks like in production and how teams are testing for it.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-large-language-model-applications-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-large-language-model-applications-guide</guid>
      <pubDate>Sat, 14 Feb 2026 08:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[NYDFS Cybersecurity Regulation: Software Security Requirements for Financial Firms]]></title>
      <description><![CDATA[New York's DFS cybersecurity regulation sets a high bar for financial institutions. Here's how the 2023 amendments affect software supply chain practices.]]></description>
      <link>https://safeguard.sh/resources/blog/nydfs-cybersecurity-regulation-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nydfs-cybersecurity-regulation-software</guid>
      <pubDate>Sat, 14 Feb 2026 07:10:07 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is a Bug Bounty Program]]></title>
      <description><![CDATA[A bug bounty program pays researchers to find and report vulnerabilities before attackers do. Here's how they work, what they cost, and their limits.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-bug-bounty-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-bug-bounty-program</guid>
      <pubDate>Sat, 14 Feb 2026 07:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to implement zero trust network architecture]]></title>
      <description><![CDATA[A practical, step-by-step guide to implement zero trust network architecture: identity, microsegmentation, posture checks, policy-as-code, and verification.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-implement-zero-trust-network-architecture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-implement-zero-trust-network-architecture</guid>
      <pubDate>Sat, 14 Feb 2026 06:00:00 GMT</pubDate>
      <category>Identity Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[XML External Entity (XXE) Prevention: Disabling the Features That Attack You]]></title>
      <description><![CDATA[XXE attacks exploit XML parser features that most applications never need. Here is how to disable them across every major language and framework.]]></description>
      <link>https://safeguard.sh/resources/blog/xml-external-entity-xxe-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xml-external-entity-xxe-prevention</guid>
      <pubDate>Sat, 14 Feb 2026 05:49:41 GMT</pubDate>
      <category>Code Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Semgrep vs CodeQL: Static Analysis for Security Teams]]></title>
      <description><![CDATA[A deep comparison of Semgrep and CodeQL for static application security testing, covering rule writing, performance, language support, and practical deployment considerations.]]></description>
      <link>https://safeguard.sh/resources/blog/semgrep-codeql-sast-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/semgrep-codeql-sast-comparison</guid>
      <pubDate>Sat, 14 Feb 2026 04:29:14 GMT</pubDate>
      <category>Tool Comparisons</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is Responsible Disclosure]]></title>
      <description><![CDATA[What responsible disclosure means, how 45-90 day timelines work in practice, and how coordinated CVE reporting like Log4Shell actually played out.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-responsible-disclosure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-responsible-disclosure</guid>
      <pubDate>Sat, 14 Feb 2026 04:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to Enforce Cosign Signatures in Kubernetes Admission]]></title>
      <description><![CDATA[A hands-on tutorial for blocking unsigned container images at the Kubernetes admission layer using Cosign, Sigstore policy-controller, and keyless verification.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-enforce-cosign-signatures-in-kubernetes-admission</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-enforce-cosign-signatures-in-kubernetes-admission</guid>
      <pubDate>Sat, 14 Feb 2026 03:08:47 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to set up AWS Secrets Manager with automatic rotation]]></title>
      <description><![CDATA[A practical guide to setting up AWS Secrets Manager with automatic rotation via Lambda, including verification steps and a comparison to Parameter Store.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-aws-secrets-manager-with-automatic-rotation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-aws-secrets-manager-with-automatic-rotation</guid>
      <pubDate>Sat, 14 Feb 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Why We Built Safeguard]]></title>
      <description><![CDATA[The software supply chain is broken. We started Safeguard because existing tools treated SBOM as a checkbox exercise instead of a security discipline.]]></description>
      <link>https://safeguard.sh/resources/blog/why-we-built-safeguard</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-we-built-safeguard</guid>
      <pubDate>Sat, 14 Feb 2026 01:48:21 GMT</pubDate>
      <category>Company</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Fuzz Testing (Fuzzing)]]></title>
      <description><![CDATA[Fuzz testing bombards software with malformed inputs to surface crashes and memory bugs. Here's how fuzzers work, what they've found, and where they fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-fuzz-testing-fuzzing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-fuzz-testing-fuzzing</guid>
      <pubDate>Sat, 14 Feb 2026 01:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Media and Entertainment Software Supply Chain Security]]></title>
      <description><![CDATA[Streaming platforms, studios, and media companies depend on complex software stacks. Here's how the entertainment industry should approach supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/media-entertainment-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/media-entertainment-software-supply-chain</guid>
      <pubDate>Sat, 14 Feb 2026 00:27:54 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to configure Azure AD Conditional Access policies]]></title>
      <description><![CDATA[A step-by-step guide to configure Azure AD conditional access policies safely — MFA enforcement, device compliance, report-only piloting, and troubleshooting tips.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-configure-azure-ad-conditional-access-policies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-configure-azure-ad-conditional-access-policies</guid>
      <pubDate>Sat, 14 Feb 2026 00:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[.NET NuGet Package Security]]></title>
      <description><![CDATA[Securing your .NET supply chain with NuGet package signing, lock files, and vulnerability scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/dotnet-nuget-package-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dotnet-nuget-package-security</guid>
      <pubDate>Fri, 13 Feb 2026 23:07:27 GMT</pubDate>
      <category>Dependency Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Azure Managed Identities and the Supply Chain]]></title>
      <description><![CDATA[Managed identities are the credential primitive that fixes most supply chain risk in Azure — but only if you use them the way the service actually intends.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-managed-identities-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-managed-identities-supply-chain</guid>
      <pubDate>Fri, 13 Feb 2026 21:47:01 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is IAST]]></title>
      <description><![CDATA[IAST instruments a running application from the inside to find vulnerabilities with very low false positives. Here's how it works and how it compares to SAST and DAST.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-iast</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-iast</guid>
      <pubDate>Fri, 13 Feb 2026 20:26:34 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Notable CVEs of 2022: A Practitioner's Roundup]]></title>
      <description><![CDATA[CVE-2022-31160 and a run of recursion-based denial-of-service bugs made 2022 a year defined less by exotic exploits and more by parsers that never expected deeply nested input.]]></description>
      <link>https://safeguard.sh/resources/blog/notable-cves-2022-a-practitioners-roundup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/notable-cves-2022-a-practitioners-roundup</guid>
      <pubDate>Fri, 13 Feb 2026 19:06:07 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Bank of America Breach via Infosys McCamish Exposes 57,000 Customers]]></title>
      <description><![CDATA[In February 2024, Bank of America disclosed that a ransomware attack on its service provider Infosys McCamish Systems had compromised the personal and financial data of over 57,000 customers, highlighting the cascading risk of vendor supply chain attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/bank-of-america-infosys-mccamish-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bank-of-america-infosys-mccamish-breach</guid>
      <pubDate>Fri, 13 Feb 2026 17:45:40 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Service Worker Security Risks: The Persistent Threat in Your Browser]]></title>
      <description><![CDATA[Service workers intercept network requests, cache content, and run in the background. When compromised, they become a persistent foothold in the browser.]]></description>
      <link>https://safeguard.sh/resources/blog/service-worker-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/service-worker-security-risks</guid>
      <pubDate>Fri, 13 Feb 2026 16:25:14 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Multi-Stage Docker Builds: The Security Implications Nobody Talks About]]></title>
      <description><![CDATA[Multi-stage builds reduce image size, but they also introduce security considerations around build secrets, layer caching, and dependency leakage.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-stage-docker-builds-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-stage-docker-builds-security</guid>
      <pubDate>Fri, 13 Feb 2026 15:04:47 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Compliance as Code: Implementation Guide for Security Teams]]></title>
      <description><![CDATA[Compliance as code transforms audit requirements into automated checks. This guide covers frameworks, tooling, and practical implementation for security teams.]]></description>
      <link>https://safeguard.sh/resources/blog/compliance-as-code-implementation-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/compliance-as-code-implementation-guide</guid>
      <pubDate>Fri, 13 Feb 2026 13:44:20 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[npm Package Visibility Audit Techniques]]></title>
      <description><![CDATA[Public when it should have been private. Private when it should have been archived. The state of npm package visibility across an organization is almost always worse than the team thinks.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-package-visibility-audit-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-package-visibility-audit-techniques</guid>
      <pubDate>Fri, 13 Feb 2026 12:23:54 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SLSA Provenance Consumption: Griffin AI vs Mythos]]></title>
      <description><![CDATA[SLSA provenance is the cryptographic receipt of a build. Griffin AI verifies it, parses it, and uses it as typed evidence. Mythos-class tools describe it and forget to check the signature.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-slsa-provenance-consumption</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-slsa-provenance-consumption</guid>
      <pubDate>Fri, 13 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[go mod tidy: The Security Implications]]></title>
      <description><![CDATA[Running go mod tidy feels like harmless housekeeping, but the command can silently pull new code, update checksums, and reshape your dependency graph in ways that have real security consequences.]]></description>
      <link>https://safeguard.sh/resources/blog/go-mod-tidy-security-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-mod-tidy-security-implications</guid>
      <pubDate>Fri, 13 Feb 2026 11:03:27 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Copilot Code Review Security: What It Misses]]></title>
      <description><![CDATA[Copilot's code review is useful. It is also not a security review, and treating it as one is how vulnerabilities ship. Here is what it actually catches.]]></description>
      <link>https://safeguard.sh/resources/blog/copilot-code-review-security-limitations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/copilot-code-review-security-limitations</guid>
      <pubDate>Fri, 13 Feb 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Threat Intelligence]]></title>
      <description><![CDATA[Threat intelligence turns raw indicators into actionable defense. Here's what it actually is, its four types, and how it applies to software supply chains.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-threat-intelligence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-threat-intelligence</guid>
      <pubDate>Fri, 13 Feb 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[SBOMs for AI/ML Models: Why Machine Learning Needs a Bill of Materials]]></title>
      <description><![CDATA[As AI models become critical infrastructure, the need for transparency about their components, training data, and dependencies grows urgent. Emerging standards are beginning to address this gap.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-ai-ml-models-emerging-standards</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-ai-ml-models-emerging-standards</guid>
      <pubDate>Fri, 13 Feb 2026 09:43:00 GMT</pubDate>
      <category>SBOM & Standards</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[How to harden a Linux server]]></title>
      <description><![CDATA[A step-by-step guide to harden Linux server security: SSH hardening, firewalls, patching, CIS benchmark alignment, and verification for production systems.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-harden-a-linux-server</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-harden-a-linux-server</guid>
      <pubDate>Fri, 13 Feb 2026 09:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[LockBit Takedown: What Came After]]></title>
      <description><![CDATA[Operation Cronos disrupted LockBit's infrastructure but not the underlying affiliate economy. Here is what actually changed and what defenders should take from it into 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/lockbit-operational-takedown-aftermath</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lockbit-operational-takedown-aftermath</guid>
      <pubDate>Fri, 13 Feb 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Gold Expands to 6,000+ Artifacts]]></title>
      <description><![CDATA[The Gold Registry crossed 6,000 curated zero-CVE packages and images across ten ecosystems in February 2026 — and is now at 500K+. Here is what was in the original milestone, how it is built, and how to use it.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-gold-registry-expansion-6000-artifacts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-gold-registry-expansion-6000-artifacts</guid>
      <pubDate>Fri, 13 Feb 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Remix Framework Security Deep Dive]]></title>
      <description><![CDATA[Remix's server-first architecture and loader/action primitives make for a distinctive security model. The framework encourages good patterns, but the places where it leaves choices to the developer are where I find the interesting bugs.]]></description>
      <link>https://safeguard.sh/resources/blog/remix-framework-security-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/remix-framework-security-deep-dive</guid>
      <pubDate>Fri, 13 Feb 2026 08:22:34 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Building vs Buying Security Tools: Making the Right Call]]></title>
      <description><![CDATA[Every security team faces the build-vs-buy decision. Here is a framework for deciding when to build custom tools and when to buy off the shelf.]]></description>
      <link>https://safeguard.sh/resources/blog/building-vs-buying-security-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-vs-buying-security-tools</guid>
      <pubDate>Fri, 13 Feb 2026 07:02:07 GMT</pubDate>
      <category>Security Strategy</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is a Honeypot]]></title>
      <description><![CDATA[A honeypot is a decoy system or credential built to lure attackers so defenders can detect, delay, and study intrusions before real assets are touched.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-honeypot</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-honeypot</guid>
      <pubDate>Fri, 13 Feb 2026 07:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How to scan Terraform for misconfigurations with Checkov]]></title>
      <description><![CDATA[A hands-on guide to running Checkov against Terraform, triaging findings, writing custom policies, and blocking IaC misconfigurations before they merge.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-scan-terraform-for-misconfigurations-with-checkov</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-scan-terraform-for-misconfigurations-with-checkov</guid>
      <pubDate>Fri, 13 Feb 2026 06:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[CWE Full Form: What It Actually Stands For]]></title>
      <description><![CDATA[CWE stands for Common Weakness Enumeration — a community-maintained taxonomy of software and hardware weakness types that CVEs, SAST tools, and OWASP guidance all reference back to.]]></description>
      <link>https://safeguard.sh/resources/blog/cwe-full-form-what-it-stands-for</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cwe-full-form-what-it-stands-for</guid>
      <pubDate>Fri, 13 Feb 2026 05:41:40 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[SCA Meaning and Full Form: Software Composition Analysis Explained]]></title>
      <description><![CDATA[SCA stands for Software Composition Analysis — the practice of scanning your dependencies for known vulnerabilities and license risk. Here's the full form and how it actually works.]]></description>
      <link>https://safeguard.sh/resources/blog/sca-meaning-full-form-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sca-meaning-full-form-explained</guid>
      <pubDate>Fri, 13 Feb 2026 04:21:14 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What is MITRE ATT&CK]]></title>
      <description><![CDATA[MITRE ATT&CK catalogs real attacker behavior into 14 tactics and 200+ techniques. Here's how it works, how it differs from CVE/CWE, and how to use it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-mitre-attck</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-mitre-attck</guid>
      <pubDate>Fri, 13 Feb 2026 04:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Green Software and Security: When Sustainability Meets Supply Chain Risk]]></title>
      <description><![CDATA[The push for sustainable software is changing how we build and deploy applications. Security teams need to understand where green initiatives create new risks.]]></description>
      <link>https://safeguard.sh/resources/blog/green-software-security-sustainability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/green-software-security-sustainability</guid>
      <pubDate>Fri, 13 Feb 2026 03:00:47 GMT</pubDate>
      <category>Industry Trends</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to encrypt a Terraform state file]]></title>
      <description><![CDATA[A step-by-step guide to encrypting a Terraform state file using an S3 backend, KMS keys, and IAM controls to keep infrastructure secrets safe.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-encrypt-a-terraform-state-file</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-encrypt-a-terraform-state-file</guid>
      <pubDate>Fri, 13 Feb 2026 03:00:00 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Government Contractor SBOM Compliance: Meeting Federal Requirements]]></title>
      <description><![CDATA[Federal agencies are mandating SBOMs from their software suppliers. If you sell software to the government, here's what compliance looks like.]]></description>
      <link>https://safeguard.sh/resources/blog/government-contractor-sbom-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/government-contractor-sbom-compliance</guid>
      <pubDate>Fri, 13 Feb 2026 01:40:20 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is a Kill Chain]]></title>
      <description><![CDATA[What is a cyber kill chain? A staged breakdown of how attacks unfold, from Lockheed Martin's 7 stages to why supply chain attacks break the model.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-kill-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-kill-chain</guid>
      <pubDate>Fri, 13 Feb 2026 01:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Software Updates in Air-Gapped Environments: Security Without Connectivity]]></title>
      <description><![CDATA[Air-gapped environments protect critical infrastructure by eliminating network connectivity. But software still needs updates. Bridging this gap without introducing the risks you isolated against is the challenge.]]></description>
      <link>https://safeguard.sh/resources/blog/air-gapped-environment-software-updates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/air-gapped-environment-software-updates</guid>
      <pubDate>Fri, 13 Feb 2026 00:19:53 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[debug/chalk npm Compromise Sept 2025: Deep Dive]]></title>
      <description><![CDATA[A phishing campaign against a prolific npm maintainer poisoned chalk, debug, and several other packages with a Web3 hijacker. Here is the full breakdown.]]></description>
      <link>https://safeguard.sh/resources/blog/debug-chalk-npm-compromise-sept-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/debug-chalk-npm-compromise-sept-2025</guid>
      <pubDate>Fri, 13 Feb 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Annual Vendor Security Review Cadence]]></title>
      <description><![CDATA[A complete timeline and workflow for running the annual vendor security review cycle, staffed sustainably, with clear deliverables and audit-ready evidence.]]></description>
      <link>https://safeguard.sh/resources/blog/annual-vendor-security-review-cadence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/annual-vendor-security-review-cadence</guid>
      <pubDate>Thu, 12 Feb 2026 22:59:27 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Secure Development Environment Setup: A Practical Guide]]></title>
      <description><![CDATA[Setting up a secure development environment involves more than installing an IDE. From OS hardening to credential management, here is a comprehensive checklist for security-conscious teams.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-development-environment-setup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-development-environment-setup</guid>
      <pubDate>Thu, 12 Feb 2026 21:39:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Privilege Escalation in Web Applications: Attacks and Defenses]]></title>
      <description><![CDATA[Privilege escalation vulnerabilities let attackers elevate their access level within an application. This guide covers both vertical and horizontal escalation techniques, real-world patterns, and concrete defenses.]]></description>
      <link>https://safeguard.sh/resources/blog/privilege-escalation-web-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/privilege-escalation-web-applications</guid>
      <pubDate>Thu, 12 Feb 2026 20:18:33 GMT</pubDate>
      <category>Web Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[South Korea's Cybersecurity Regulations and Software Supply Chain Requirements]]></title>
      <description><![CDATA[South Korea is strengthening cybersecurity regulations with new supply chain security frameworks. Here's the landscape for software vendors.]]></description>
      <link>https://safeguard.sh/resources/blog/south-korea-cybersecurity-regulations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/south-korea-cybersecurity-regulations</guid>
      <pubDate>Thu, 12 Feb 2026 18:58:07 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AnyDesk Production Systems Compromised: Code Signing Certificates Stolen]]></title>
      <description><![CDATA[AnyDesk confirmed a breach of their production systems in late January 2024, forcing revocation of code signing certificates and a mandatory password reset for all users.]]></description>
      <link>https://safeguard.sh/resources/blog/anydesk-production-systems-compromised</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anydesk-production-systems-compromised</guid>
      <pubDate>Thu, 12 Feb 2026 17:37:40 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Cloudflare's Thanksgiving 2023 Breach: How Okta Credentials Led to a Nation-State Intrusion]]></title>
      <description><![CDATA[Cloudflare disclosed that a nation-state actor used credentials stolen from the October 2023 Okta breach to access their Atlassian systems. Their transparent post-mortem set a new standard.]]></description>
      <link>https://safeguard.sh/resources/blog/cloudflare-thanksgiving-2023-breach-okta</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloudflare-thanksgiving-2023-breach-okta</guid>
      <pubDate>Thu, 12 Feb 2026 16:17:13 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Secure Boot UEFI and Software Supply Chain Links]]></title>
      <description><![CDATA[How UEFI Secure Boot, shim, and Microsoft third-party UEFI CA connect to software supply chain risk in OS and firmware update pipelines.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-boot-uefi-software-supply-chain-links</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-boot-uefi-software-supply-chain-links</guid>
      <pubDate>Thu, 12 Feb 2026 14:56:47 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The Spring Shell Vulnerability: What Happened]]></title>
      <description><![CDATA[Spring4Shell (CVE-2022-22965) let attackers achieve remote code execution through Spring's data-binding mechanism — here's what made it exploitable and what actually needed patching.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-shell-vulnerability-what-happened</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-shell-vulnerability-what-happened</guid>
      <pubDate>Thu, 12 Feb 2026 13:36:20 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Renovate Bot Configuration Recipes for 2026]]></title>
      <description><![CDATA[Renovate is the more powerful dependency-update bot, and its config surface is large. Here are the recipes worth knowing and the defaults worth overriding.]]></description>
      <link>https://safeguard.sh/resources/blog/renovate-bot-config-recipes-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/renovate-bot-config-recipes-2026</guid>
      <pubDate>Thu, 12 Feb 2026 13:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Notable CVEs of 2023: A Practitioner's Roundup]]></title>
      <description><![CDATA[From an OpenSSL IV-truncation flaw to a critical Babel code-execution bug, 2023's CVE crop is a good reminder that severity and blast radius don't always line up.]]></description>
      <link>https://safeguard.sh/resources/blog/notable-cves-2023-a-practitioners-roundup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/notable-cves-2023-a-practitioners-roundup</guid>
      <pubDate>Thu, 12 Feb 2026 12:15:53 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Cursor IDE Security Model: What Enterprises Need to Know]]></title>
      <description><![CDATA[Cursor's 2026 security model introduces privacy modes, indexing controls, and agent sandboxes. Here is the enterprise-ready view of what works.]]></description>
      <link>https://safeguard.sh/resources/blog/cursor-ide-security-model-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cursor-ide-security-model-2026</guid>
      <pubDate>Thu, 12 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Regression Gates: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Every release risks making the model worse. Griffin AI's regression gates block bad builds before they ship. Mythos-class tools rarely describe a gate process at all.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-regression-gates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-regression-gates</guid>
      <pubDate>Thu, 12 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[XSS Variants: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Stored, reflected, DOM, mutation, and template-injection XSS each live in a different part of the application and demand a different analysis. Griffin's engine understands template contexts, framework escaping rules, and client-side sinks; Mythos reads HTML and hopes. The difference shows up the moment you leave textbook territory.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-xss-variants</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-xss-variants</guid>
      <pubDate>Thu, 12 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Reka Multimodal for Security]]></title>
      <description><![CDATA[Reka's multimodal models are interesting for specific security workflows. The question is whether multimodal is the binding constraint, and usually it isn't.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-reka-multimodal-security-use</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-reka-multimodal-security-use</guid>
      <pubDate>Thu, 12 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[YAML Deserialization Attacks and How to Prevent Them]]></title>
      <description><![CDATA[YAML looks innocent but its deserialization features have led to remote code execution in countless applications. Here is why and how to stay safe.]]></description>
      <link>https://safeguard.sh/resources/blog/yaml-deserialization-attacks-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/yaml-deserialization-attacks-prevention</guid>
      <pubDate>Thu, 12 Feb 2026 10:55:26 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Solutions: Platform or Point Tools?]]></title>
      <description><![CDATA[The platform-versus-point-tool decision is really a question about who does the correlation work: your vendor or your engineers. A framework for making the call with real numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-solutions-platform-vs-point</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-solutions-platform-vs-point</guid>
      <pubDate>Thu, 12 Feb 2026 10:15:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SaaS Vendor's EU CRA Readiness Sprint]]></title>
      <description><![CDATA[An anonymized account of how a mid-sized European SaaS vendor prepared for the EU Cyber Resilience Act using a focused 12-week Safeguard readiness sprint.]]></description>
      <link>https://safeguard.sh/resources/blog/customer-story-saas-vendor-cra-readiness-sprint</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/customer-story-saas-vendor-cra-readiness-sprint</guid>
      <pubDate>Thu, 12 Feb 2026 10:00:00 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Security Management: From Policy to Pipeline]]></title>
      <description><![CDATA[A policy document nobody enforces is theater. Here is how to turn open source rules into pipeline checks that developers can live with.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-security-management-policy-to-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-security-management-policy-to-pipeline</guid>
      <pubDate>Thu, 12 Feb 2026 10:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The End of CVSS-Only Prioritization]]></title>
      <description><![CDATA[A single static severity score cannot tell you which vulnerability to fix first. Modern prioritization is a function of reachability, exploitability, and business context — and CVSS is only one input.]]></description>
      <link>https://safeguard.sh/resources/blog/the-end-of-cvss-only-prioritization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-end-of-cvss-only-prioritization</guid>
      <pubDate>Thu, 12 Feb 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Attack Path Analysis]]></title>
      <description><![CDATA[Attack path analysis maps how vulnerabilities and misconfigurations chain together into real exploit routes, cutting 10,000+ findings down to the handful that matter.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-attack-path-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-attack-path-analysis</guid>
      <pubDate>Thu, 12 Feb 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[SBOMs for Defense Contractors: Aligning with CMMC and DoD Requirements]]></title>
      <description><![CDATA[Defense contractors face unique SBOM challenges. This guide covers CMMC alignment, DFARS clauses, and practical steps to meet DoD software supply chain requirements.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-defense-contractors-cmmc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-defense-contractors-cmmc</guid>
      <pubDate>Thu, 12 Feb 2026 09:35:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[JFrog Xray Alternatives: A 2026 Buyer's Guide]]></title>
      <description><![CDATA[Where JFrog Xray fits, where it falls short, and which alternatives actually deserve a seat at the evaluation table in 2026 for SCA, container scanning, and policy enforcement.]]></description>
      <link>https://safeguard.sh/resources/blog/jfrog-xray-alternatives-buyer-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jfrog-xray-alternatives-buyer-guide-2026</guid>
      <pubDate>Thu, 12 Feb 2026 09:30:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Platforms vs Point Tools in 2026]]></title>
      <description><![CDATA[When a consolidated application security platform actually beats a stack of best-of-breed point tools, and when it doesn't — a buyer's framework for 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-platforms-vs-point-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-platforms-vs-point-tools-2026</guid>
      <pubDate>Thu, 12 Feb 2026 09:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[EU Cyber Resilience Act: Your SBOM Obligations]]></title>
      <description><![CDATA[The EU Cyber Resilience Act makes SBOMs a legal requirement for products with digital elements sold in Europe. Here is what the regulation actually demands, when the deadlines hit, and how to prepare.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cyber-resilience-act-sbom-obligations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cyber-resilience-act-sbom-obligations</guid>
      <pubDate>Thu, 12 Feb 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to implement network segmentation in a data center]]></title>
      <description><![CDATA[A step-by-step guide to network segmentation best practices in the data center: mapping traffic, VLANs, microsegmentation, least-privilege rules, and verification.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-implement-network-segmentation-in-a-data-center</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-implement-network-segmentation-in-a-data-center</guid>
      <pubDate>Thu, 12 Feb 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Kyverno ImageValidatingPolicy 2026: A Production Walkthrough]]></title>
      <description><![CDATA[Kyverno 1.18 ships ImageValidatingPolicy as the new policy type for cosign signature, attestation, and SBOM verification. We migrated a 60-cluster fleet and graded the new model.]]></description>
      <link>https://safeguard.sh/resources/blog/kyverno-image-validating-policy-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kyverno-image-validating-policy-2026</guid>
      <pubDate>Thu, 12 Feb 2026 09:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Maven Central Sigstore Migration Status]]></title>
      <description><![CDATA[Maven Central's move from GPG to Sigstore is genuinely underway in 2026. Here is where the transition actually stands and what Java shops should do now.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-central-sigstore-migration-status</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-central-sigstore-migration-status</guid>
      <pubDate>Thu, 12 Feb 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Security: Malware Campaigns and How to Defend]]></title>
      <description><![CDATA[The Python Package Index has become a first-class malware channel — from the ctx hijack to the ultralytics pipeline compromise. Here are the campaigns worth studying and the defenses that work.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-security-malware-campaigns-defenses</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-security-malware-campaigns-defenses</guid>
      <pubDate>Thu, 12 Feb 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[AI Code Assistant Package Hallucination Study]]></title>
      <description><![CDATA[The Safeguard Research team measured how often AI coding assistants hallucinate non-existent packages, how sticky those hallucinations are, and what defenders should do.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-research-ai-code-assistant-package-hallucination-study</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-research-ai-code-assistant-package-hallucination-study</guid>
      <pubDate>Thu, 12 Feb 2026 09:00:00 GMT</pubDate>
      <category>Research</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Sify Technology and US Enterprise Reach: What We're Evaluating]]></title>
      <description><![CDATA[A closer look at the enterprise accounts, verticals, and delivery capabilities that make Sify Technology (USA) an interesting partner for Safeguard.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-sify-technology-us-enterprise-reach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-sify-technology-us-enterprise-reach</guid>
      <pubDate>Thu, 12 Feb 2026 09:00:00 GMT</pubDate>
      <category>Company</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vite and Turbopack: Security Considerations for Next-Gen Build Tools]]></title>
      <description><![CDATA[Vite and Turbopack represent the next generation of JavaScript build tools. Their architectures introduce new security considerations alongside their performance improvements.]]></description>
      <link>https://safeguard.sh/resources/blog/vite-turbopack-build-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vite-turbopack-build-security</guid>
      <pubDate>Thu, 12 Feb 2026 08:14:33 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best Container Security Tools in 2026]]></title>
      <description><![CDATA[Image scanners, runtime sensors, and Kubernetes posture tools each catch different failures. Here is how the leading options compare in 2026 — and how to pick a stack without buying three overlapping scanners.]]></description>
      <link>https://safeguard.sh/resources/blog/best-container-security-tools-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-container-security-tools-2026</guid>
      <pubDate>Thu, 12 Feb 2026 08:00:00 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Log4Shell (Log4j Vulnerability) Explained]]></title>
      <description><![CDATA[A deep dive into Log4Shell (CVE-2021-44228): how the critical Log4j2 RCE flaw worked, its timeline, affected versions, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/log4shell-log4j-vulnerability-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4shell-log4j-vulnerability-explained</guid>
      <pubDate>Thu, 12 Feb 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[SBOM for Fintech Startups: Compliance and Security from Day One]]></title>
      <description><![CDATA[Fintech startups face intense regulatory scrutiny from the start. SBOMs are not just good practice — they are becoming a regulatory expectation that investors and partners demand.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-fintech-startups</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-fintech-startups</guid>
      <pubDate>Thu, 12 Feb 2026 06:54:06 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[How to set up a bastion host for secure SSH access]]></title>
      <description><![CDATA[A step-by-step guide to set up bastion host SSH access on AWS, with ProxyJump configs, security group rules, and a verification checklist for hardened jump box access.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-a-bastion-host-for-secure-ssh-access</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-a-bastion-host-for-secure-ssh-access</guid>
      <pubDate>Thu, 12 Feb 2026 06:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Midnight Blizzard and the Microsoft Email Breach]]></title>
      <description><![CDATA[Russia's SVR-linked Midnight Blizzard sat inside Microsoft's corporate email for weeks. Here is what the January 2024 disclosure revealed about identity supply chains.]]></description>
      <link>https://safeguard.sh/resources/blog/midnight-blizzard-microsoft-email-breach-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/midnight-blizzard-microsoft-email-breach-analysis</guid>
      <pubDate>Thu, 12 Feb 2026 05:33:40 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Auditing AI-Generated Code: A Practical Security Guide]]></title>
      <description><![CDATA[AI code generation tools are producing millions of lines of code daily. Here is a practical framework for auditing AI-generated code for security vulnerabilities and supply chain risks.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-code-generation-security-audit-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-code-generation-security-audit-guide</guid>
      <pubDate>Thu, 12 Feb 2026 04:13:13 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What Was the Heartbleed Bug]]></title>
      <description><![CDATA[A deep dive into CVE-2014-0160 (Heartbleed): the OpenSSL heartbeat flaw, its severity, exploitation timeline, and how to remediate it today.]]></description>
      <link>https://safeguard.sh/resources/blog/what-was-the-heartbleed-bug</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-was-the-heartbleed-bug</guid>
      <pubDate>Thu, 12 Feb 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to configure AWS Config for continuous compliance mon...]]></title>
      <description><![CDATA[A step-by-step guide to configure AWS Config compliance monitoring: rules setup, conformance packs, alerting, remediation, and multi-account aggregation.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-configure-aws-config-for-continuous-compliance-monitoring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-configure-aws-config-for-continuous-compliance-monitoring</guid>
      <pubDate>Thu, 12 Feb 2026 03:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[SBOM API Integration Patterns for Development Teams]]></title>
      <description><![CDATA[SBOMs locked in files are static inventory. SBOMs exposed through APIs become live infrastructure. Here's how to build the integration layer.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-api-integration-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-api-integration-patterns</guid>
      <pubDate>Thu, 12 Feb 2026 02:52:46 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[libwebp and CVE-2023-4863: The Full Story]]></title>
      <description><![CDATA[A heap buffer overflow in libwebp's lossless decoder, exploited in the wild before a patch existed, turned out to affect far more software than the browser it was first reported in.]]></description>
      <link>https://safeguard.sh/resources/blog/libwebp-cve-2023-4863-the-full-story</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/libwebp-cve-2023-4863-the-full-story</guid>
      <pubDate>Thu, 12 Feb 2026 01:32:20 GMT</pubDate>
      <category>Vulnerabilities</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[What Was the Shellshock Vulnerability]]></title>
      <description><![CDATA[Shellshock (CVE-2014-6271) let attackers run code on millions of Bash-based systems via a single crafted header. Here's the full breakdown and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/what-was-the-shellshock-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-was-the-shellshock-vulnerability</guid>
      <pubDate>Thu, 12 Feb 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Trello API Scraping Exposes 15 Million User Accounts]]></title>
      <description><![CDATA[In January 2024, a threat actor used an insecure Trello API endpoint to scrape and correlate email addresses with Trello account data for over 15 million users, then posted the dataset on a hacking forum.]]></description>
      <link>https://safeguard.sh/resources/blog/trello-15-million-accounts-exposed</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trello-15-million-accounts-exposed</guid>
      <pubDate>Thu, 12 Feb 2026 00:11:53 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to meet SOC 2 audit logging requirements]]></title>
      <description><![CDATA[A step-by-step guide to meeting SOC 2 audit logging requirements: what to log, retention, access controls, alerting, and how to verify your controls before an audit.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-meet-soc-2-audit-logging-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-meet-soc-2-audit-logging-requirements</guid>
      <pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Netflix's Open-Source Security Approach]]></title>
      <description><![CDATA[How Netflix manages security across hundreds of open-source projects and thousands of internal dependencies while maintaining the velocity that streaming demands.]]></description>
      <link>https://safeguard.sh/resources/blog/netflix-open-source-security-approach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/netflix-open-source-security-approach</guid>
      <pubDate>Wed, 11 Feb 2026 22:51:26 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[npm audit vs pnpm audit vs yarn audit]]></title>
      <description><![CDATA[Three audit tools, three philosophies, three blind spots. A ground-level comparison of how npm, pnpm, and yarn surface vulnerabilities, and where each one leaves you exposed.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-audit-vs-pnpm-audit-vs-yarn-audit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-audit-vs-pnpm-audit-vs-yarn-audit</guid>
      <pubDate>Wed, 11 Feb 2026 21:31:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[React Application Security Guide]]></title>
      <description><![CDATA[Securing React applications from XSS, dependency vulnerabilities, and common frontend attack patterns.]]></description>
      <link>https://safeguard.sh/resources/blog/react-application-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-application-security-guide</guid>
      <pubDate>Wed, 11 Feb 2026 20:10:33 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Manufacturing OT Software Supply Chain: Securing the Factory Floor]]></title>
      <description><![CDATA[Manufacturing OT systems depend on software supply chains that most security teams don't monitor. Here's how to extend supply chain security to the factory floor.]]></description>
      <link>https://safeguard.sh/resources/blog/manufacturing-ot-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/manufacturing-ot-software-supply-chain</guid>
      <pubDate>Wed, 11 Feb 2026 18:50:06 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Microsoft Breached by Midnight Blizzard: Russian Hackers Read Executive Emails]]></title>
      <description><![CDATA[In January 2024, Microsoft disclosed that the Russian state-sponsored group Midnight Blizzard had been reading emails of senior executives and security team members since November 2023, using a password spray attack against a legacy test account.]]></description>
      <link>https://safeguard.sh/resources/blog/microsoft-midnight-blizzard-email-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microsoft-midnight-blizzard-email-breach</guid>
      <pubDate>Wed, 11 Feb 2026 17:29:39 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Midnight Blizzard Breaches Microsoft: What the Exchange Online Attack Means for Everyone]]></title>
      <description><![CDATA[Russian state actors compromised Microsoft executive email accounts through a password spray attack on a legacy test tenant. The breach exposed how identity misconfigurations cascade.]]></description>
      <link>https://safeguard.sh/resources/blog/midnight-blizzard-microsoft-exchange-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/midnight-blizzard-microsoft-exchange-breach</guid>
      <pubDate>Wed, 11 Feb 2026 16:09:13 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Veracode SCA: Mature Application Security Meets Dependency Scanning]]></title>
      <description><![CDATA[An overview of Veracode's SCA capabilities within their broader application security platform, covering vulnerability prioritization, agent-based scanning, and enterprise features.]]></description>
      <link>https://safeguard.sh/resources/blog/veracode-sca-platform-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/veracode-sca-platform-overview</guid>
      <pubDate>Wed, 11 Feb 2026 14:48:46 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Container-Specific Vulnerability Management Tools, Compared]]></title>
      <description><![CDATA[A field guide to container-specific vulnerability management tools: what Trivy, Grype, Clair, Docker Scout, and Anchore actually catch, and where each falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/container-specific-vulnerability-management-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-specific-vulnerability-management-tools</guid>
      <pubDate>Wed, 11 Feb 2026 14:15:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[npm chai: A Security Review and Safe Usage Guide]]></title>
      <description><![CDATA[Chai is a staple assertion library for JavaScript testing. Here is an honest look at the security profile of the npm chai package and how to keep it out of your production bundle.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-chai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-chai</guid>
      <pubDate>Wed, 11 Feb 2026 14:05:00 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Detect Typosquatting in Package Installs]]></title>
      <description><![CDATA[Build a pre-install guard that catches typosquatted npm, PyPI, and RubyGems dependencies using Levenshtein distance, download-count heuristics, and registry APIs.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-detect-typosquatting-in-package-installs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-detect-typosquatting-in-package-installs</guid>
      <pubDate>Wed, 11 Feb 2026 13:28:19 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Software Component Lifecycle Management]]></title>
      <description><![CDATA[Components do not stay secure forever. This guide covers managing the full lifecycle of software dependencies -- from adoption through deprecation -- with a focus on security and operational continuity.]]></description>
      <link>https://safeguard.sh/resources/blog/software-component-lifecycle-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-component-lifecycle-management</guid>
      <pubDate>Wed, 11 Feb 2026 12:07:53 GMT</pubDate>
      <category>Lifecycle Management</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[GuardDuty Extended Threat Detection: What Defenders Actually Get]]></title>
      <description><![CDATA[GuardDuty's extended threat detection correlates findings across signals into attack sequences. We dig into where it helps, where it misses, and how to wire it into supply chain incident response.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-guardduty-extended-threat-detection-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-guardduty-extended-threat-detection-2026</guid>
      <pubDate>Wed, 11 Feb 2026 12:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise AI Incident Response Playbooks]]></title>
      <description><![CDATA[AI incidents are not the same shape as traditional security incidents. The playbooks need to be specific to how AI systems actually fail.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-ai-incident-response-playbooks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-ai-incident-response-playbooks</guid>
      <pubDate>Wed, 11 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Gemma for Lightweight Scanning]]></title>
      <description><![CDATA[Gemma is built for efficiency. Can a small open-weight model replace Griffin AI for lightweight scanning workflows, or does the engine still matter?]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-gemma-for-lightweight-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-gemma-for-lightweight-scanning</guid>
      <pubDate>Wed, 11 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Engineer-Hour Savings: Griffin AI vs Mythos]]></title>
      <description><![CDATA[The real cost of a scanner is not the subscription. It is the engineer hours lost to false positives, bad remediations, and noisy queues. We do the math.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-engineer-hour-savings</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-engineer-hour-savings</guid>
      <pubDate>Wed, 11 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Novel Bug Class Detection: Griffin AI vs Mythos]]></title>
      <description><![CDATA[What happens when the bug does not match any known CWE? A study of how grounded and pure-LLM scanners perform on genuinely novel vulnerability patterns.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-novel-bug-class-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-novel-bug-class-detection</guid>
      <pubDate>Wed, 11 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to Security Audit an Open Source Project Before Adoption]]></title>
      <description><![CDATA[Adopting an open source dependency is a trust decision. This guide provides a structured methodology for evaluating the security posture of open source projects before adding them to your supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-project-security-audit-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-project-security-audit-guide</guid>
      <pubDate>Wed, 11 Feb 2026 10:47:26 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The Real Security Concerns About AI in 2026]]></title>
      <description><![CDATA[The most grounded concerns about AI are not sci-fi scenarios; they are prompt injection, data leakage, supply chain risk in models, and opaque decisions. Here is how each one actually shows up.]]></description>
      <link>https://safeguard.sh/resources/blog/concerns-about-ai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/concerns-about-ai</guid>
      <pubDate>Wed, 11 Feb 2026 10:40:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[How to Scan a Website for Vulnerabilities Free: Tools and Method]]></title>
      <description><![CDATA[You can scan a website for vulnerabilities free with ZAP, Nuclei, testssl.sh, and a few hosted checkers — if you follow a method instead of pushing buttons. Here is the workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/scan-website-for-vulnerabilities-free</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scan-website-for-vulnerabilities-free</guid>
      <pubDate>Wed, 11 Feb 2026 10:40:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Prompt Injection Defense Architectures in 2026]]></title>
      <description><![CDATA[Prompt injection remains the LLM01 entry on the OWASP LLM Top 10 for a reason. A pragmatic look at the defense architectures that hold up in production this year.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-defense-architectures-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-defense-architectures-2026</guid>
      <pubDate>Wed, 11 Feb 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is EternalBlue]]></title>
      <description><![CDATA[EternalBlue (CVE-2017-0144) turned a patched SMBv1 flaw into WannaCry and NotPetya. Here is the exploit, timeline, and remediation, explained.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-eternalblue</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-eternalblue</guid>
      <pubDate>Wed, 11 Feb 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Healthcare Supply Chain Security Baseline for 2026]]></title>
      <description><![CDATA[What hospitals and payers should actually require from their software vendors in 2026: HIPAA-aligned controls, SBOM expectations, and the threats now hitting clinical environments.]]></description>
      <link>https://safeguard.sh/resources/blog/healthcare-supply-chain-security-baseline-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/healthcare-supply-chain-security-baseline-2026</guid>
      <pubDate>Wed, 11 Feb 2026 09:30:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Open Source License Management: Tools and Workflow]]></title>
      <description><![CDATA[A practical breakdown of how mature engineering teams do license management open source style: scanning dependency trees, classifying license risk, and building a workflow that does not slow releases down.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-license-management-tools-and-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-license-management-tools-and-workflow</guid>
      <pubDate>Wed, 11 Feb 2026 09:30:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[OSS Container Security: What Changes With Open-Source Base Images]]></title>
      <description><![CDATA[Open-source base images change your patch cadence, your license exposure, and your provenance story — here's what OSS container security actually adds on top of standard image hardening.]]></description>
      <link>https://safeguard.sh/resources/blog/oss-container-security-what-changes-with-open-source-bases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oss-container-security-what-changes-with-open-source-bases</guid>
      <pubDate>Wed, 11 Feb 2026 09:30:00 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis for Rust and Cargo in 2026]]></title>
      <description><![CDATA[How reachability analysis cuts noise for Rust services: cargo features, conditional compilation, RustSec advisories, and the tools that handle Rust well.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-rust-cargo-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-rust-cargo-2026</guid>
      <pubDate>Wed, 11 Feb 2026 09:30:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Bun Runtime Security Considerations: Speed vs. Safety Trade-offs]]></title>
      <description><![CDATA[Bun prioritizes performance over Node.js compatibility. But some of those performance choices have security implications worth understanding.]]></description>
      <link>https://safeguard.sh/resources/blog/bun-runtime-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bun-runtime-security-considerations</guid>
      <pubDate>Wed, 11 Feb 2026 09:26:59 GMT</pubDate>
      <category>Secure Development</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx vs Fortify: A Practical Comparison]]></title>
      <description><![CDATA[Checkmarx and Fortify solve the same SAST problem with different architectures — here's how they actually differ on accuracy, deployment, and total cost.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-vs-fortify-a-practical-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-vs-fortify-a-practical-comparison</guid>
      <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Container Breakout Class Vulnerabilities 2024-2025]]></title>
      <description><![CDATA[A look at the container breakout vulnerabilities disclosed in 2024 and 2025, what they actually required to exploit, and what that pattern tells us about the defense model.]]></description>
      <link>https://safeguard.sh/resources/blog/container-breakout-class-vulnerabilities-2024-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-breakout-class-vulnerabilities-2024-2025</guid>
      <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[DevOps Metrics That Security Teams Should Watch Too]]></title>
      <description><![CDATA[Deploy frequency and lead time aren't just engineering KPIs — read alongside vulnerability data, they tell security teams exactly where risk is accumulating.]]></description>
      <link>https://safeguard.sh/resources/blog/devops-metrics-that-security-teams-should-watch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devops-metrics-that-security-teams-should-watch</guid>
      <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[EU Cyber Resilience Act Enforcement Timeline 2026]]></title>
      <description><![CDATA[The EU Cyber Resilience Act is already biting in 2026. Here is the enforcement timeline manufacturers, integrators, and open source stewards need to internalize now.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cyber-resilience-act-enforcement-timeline-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cyber-resilience-act-enforcement-timeline-2026</guid>
      <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to implement GDPR technical and organizational measures]]></title>
      <description><![CDATA[A practical, engineering-first walkthrough for GDPR technical measures implementation: encryption, access control, minimization, and verification steps.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-implement-gdpr-technical-and-organizational-measures</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-implement-gdpr-technical-and-organizational-measures</guid>
      <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Admission Controller Policy Patterns in 2026]]></title>
      <description><![CDATA[A field guide to the admission control patterns that survived contact with production clusters: validating webhooks, image policy, mutating defaults, and what to skip.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-admission-controller-policy-patterns-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-admission-controller-policy-patterns-2026</guid>
      <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Vulnerability Management Tools, Compared]]></title>
      <description><![CDATA[OSV-Scanner, Trivy, Grype, and Dependency-Check all find known CVEs for free, but they differ sharply in language coverage, database freshness, and how far they get you toward an actual fix.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-vulnerability-management-tools-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-vulnerability-management-tools-compared</guid>
      <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[The Snyk Tool: What It Does, and What It Doesn't]]></title>
      <description><![CDATA[The Snyk tool covers SCA, container, and IaC scanning well, but its SAST depth and enterprise pricing are the two things buyers most often get wrong going in.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-tool-what-it-does-and-doesnt-do</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-tool-what-it-does-and-doesnt-do</guid>
      <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[OpenVEX vs. CycloneDX VEX: Which to Pick]]></title>
      <description><![CDATA[A direct comparison of OpenVEX and CycloneDX VEX in 2026, covering spec differences, tooling support, and the operational tradeoffs that actually affect your choice.]]></description>
      <link>https://safeguard.sh/resources/blog/vex-openvex-vs-cyclonedx-vex-which-to-pick</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vex-openvex-vs-cyclonedx-vex-which-to-pick</guid>
      <pubDate>Wed, 11 Feb 2026 09:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Container Security Vulnerabilities: How to Find and Fix Them]]></title>
      <description><![CDATA[The container security vulnerabilities that actually get exploited, where they hide across the image lifecycle, and a practical order for fixing them without rebuilding everything at once.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-vulnerabilities</guid>
      <pubDate>Wed, 11 Feb 2026 08:45:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Marcus Chen)</author>
    </item>
    <item>
      <title><![CDATA[Infrastructure as Code Security Tools, Compared]]></title>
      <description><![CDATA[Infrastructure as code security tools catch misconfigured cloud resources before they're ever provisioned — here's how the main options differ and where each one fits.]]></description>
      <link>https://safeguard.sh/resources/blog/infrastructure-as-code-security-tools-compared</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/infrastructure-as-code-security-tools-compared</guid>
      <pubDate>Wed, 11 Feb 2026 08:30:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability SLA Compliance Tracking That Actually Works]]></title>
      <description><![CDATA[Most organizations define vulnerability SLAs and then fail to meet them. The problem is not motivation. It is measurement and process.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-sla-compliance-tracking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-sla-compliance-tracking</guid>
      <pubDate>Wed, 11 Feb 2026 08:06:33 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Testing Software: A Category Map]]></title>
      <description><![CDATA[A clear map of the application security testing software categories — SAST, DAST, IAST, SCA, and the platforms that bundle them — and when each one actually applies.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-testing-software-category-map</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-testing-software-category-map</guid>
      <pubDate>Wed, 11 Feb 2026 08:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm Provenance Statements: What They Prove and What They Don't]]></title>
      <description><![CDATA[npm provenance ties a package to the commit and CI run that built it. That's genuinely useful — and narrower than most teams assume. Here's the exact boundary.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-provenance-statements-what-they-prove-and-what-they-don-t</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-provenance-statements-what-they-prove-and-what-they-don-t</guid>
      <pubDate>Wed, 11 Feb 2026 08:00:00 GMT</pubDate>
      <category>Engineering</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[The SolarWinds Supply Chain Attack Explained]]></title>
      <description><![CDATA[How Russian intelligence hijacked SolarWinds' build system to backdoor Orion updates for 18,000 customers, and what security teams must do now.]]></description>
      <link>https://safeguard.sh/resources/blog/the-solarwinds-supply-chain-attack-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-solarwinds-supply-chain-attack-explained</guid>
      <pubDate>Wed, 11 Feb 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Platform Engineering and Security: Building Guardrails, Not Gates]]></title>
      <description><![CDATA[Platform engineering teams are becoming the stewards of developer experience. Here's how to make supply chain security a built-in capability, not a bolt-on burden.]]></description>
      <link>https://safeguard.sh/resources/blog/platform-engineering-security-integration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/platform-engineering-security-integration</guid>
      <pubDate>Wed, 11 Feb 2026 06:46:06 GMT</pubDate>
      <category>Industry Trends</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to set up a vulnerability management program]]></title>
      <description><![CDATA[A step-by-step guide to setting up a vulnerability management program: scanning schedules, risk-based triage, patch management, and metrics that hold up in an audit.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-a-vulnerability-management-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-a-vulnerability-management-program</guid>
      <pubDate>Wed, 11 Feb 2026 06:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Express and Node.js Security Hardening]]></title>
      <description><![CDATA[Practical security hardening for Express.js applications covering middleware, input validation, and production deployment.]]></description>
      <link>https://safeguard.sh/resources/blog/express-nodejs-security-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/express-nodejs-security-hardening</guid>
      <pubDate>Wed, 11 Feb 2026 05:25:39 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[AWS ECR Image Scanning: A Deep Dive Into What It Catches and What It Misses]]></title>
      <description><![CDATA[ECR offers both basic and enhanced scanning. The difference between them determines whether your container security is real or performative.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-ecr-image-scanning-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-ecr-image-scanning-deep-dive</guid>
      <pubDate>Wed, 11 Feb 2026 04:05:13 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[The XZ Utils Backdoor Explained]]></title>
      <description><![CDATA[A trusted maintainer, years of quiet social engineering, and one hidden SSH backdoor: how CVE-2024-3094 nearly compromised the global Linux supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/the-xz-utils-backdoor-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-xz-utils-backdoor-explained</guid>
      <pubDate>Wed, 11 Feb 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to configure Nessus for vulnerability scanning]]></title>
      <description><![CDATA[A step-by-step guide to installing Nessus, building scan policies, defining safe targets, and validating results — plus where supply chain risk starts beyond the network scan.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-configure-nessus-for-vulnerability-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-configure-nessus-for-vulnerability-scanning</guid>
      <pubDate>Wed, 11 Feb 2026 03:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Akira Ransomware: Exploiting VPN Vulnerabilities for Supply Chain Entry]]></title>
      <description><![CDATA[Akira ransomware systematically exploited Cisco VPN vulnerabilities as its primary entry vector, targeting organizations through the network infrastructure they trusted most.]]></description>
      <link>https://safeguard.sh/resources/blog/akira-ransomware-supply-chain-entry</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/akira-ransomware-supply-chain-entry</guid>
      <pubDate>Wed, 11 Feb 2026 02:44:46 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is Security Testing]]></title>
      <description><![CDATA[Security testing is how teams find exploitable weaknesses before attackers do. Here's the main types — SAST, DAST, IAST, SCA, fuzzing, pentesting — and how they fit together.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-security-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-security-testing</guid>
      <pubDate>Wed, 11 Feb 2026 01:24:19 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[The Shai-Hulud npm Supply Chain Attack Explained]]></title>
      <description><![CDATA[How the Shai-Hulud worm turned compromised npm maintainer tokens into a self-replicating supply chain attack, and how to detect and remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/the-shai-hulud-npm-supply-chain-attack-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-shai-hulud-npm-supply-chain-attack-explained</guid>
      <pubDate>Wed, 11 Feb 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Ivanti Connect Secure Zero-Day: CVE-2024-21887 and CVE-2023-46805 Exploited in the Wild]]></title>
      <description><![CDATA[Two chained zero-days in Ivanti Connect Secure VPN appliances gave attackers unauthenticated remote code execution. Here's what happened and why perimeter devices remain a favorite target.]]></description>
      <link>https://safeguard.sh/resources/blog/ivanti-connect-secure-cve-2024-21887-zero-day</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ivanti-connect-secure-cve-2024-21887-zero-day</guid>
      <pubDate>Wed, 11 Feb 2026 00:03:52 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[VMware ESXi CVE-2024-37085 Auth Bypass by Ransomware]]></title>
      <description><![CDATA[CVE-2024-37085 abuses ESXi's AD domain join to grant admin via a specially named group. Exploitation by Akira and Black Basta, detection, and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-37085-vmware-esxi-auth-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-37085-vmware-esxi-auth-bypass</guid>
      <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to set up a CI/CD pipeline security gate]]></title>
      <description><![CDATA[A practical, step-by-step guide to building a CI/CD pipeline security gate that scans, enforces vulnerability thresholds, and blocks risky builds without slowing developers down.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-a-cicd-pipeline-security-gate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-a-cicd-pipeline-security-gate</guid>
      <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Gradle Plugin Security Risks: The Code That Runs Before Your Code]]></title>
      <description><![CDATA[Gradle plugins execute during your build with full access to your environment. Most teams never audit them. Here is why that is dangerous.]]></description>
      <link>https://safeguard.sh/resources/blog/gradle-plugin-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gradle-plugin-security-risks</guid>
      <pubDate>Tue, 10 Feb 2026 22:43:26 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Ansible Galaxy Security Risks: The Infrastructure Supply Chain You Forgot About]]></title>
      <description><![CDATA[Ansible Galaxy roles and collections execute with root privileges on your infrastructure. Most teams apply zero security scrutiny to them.]]></description>
      <link>https://safeguard.sh/resources/blog/ansible-galaxy-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ansible-galaxy-security-risks</guid>
      <pubDate>Tue, 10 Feb 2026 21:22:59 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[npm Registry Governance and the Security of node_modules]]></title>
      <description><![CDATA[The npm registry serves billions of downloads per week. Its governance decisions directly impact the security of every Node.js application on the planet.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-registry-governance-and-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-registry-governance-and-security</guid>
      <pubDate>Tue, 10 Feb 2026 20:02:32 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[IAST vs RASP: Runtime Protection Approaches Compared]]></title>
      <description><![CDATA[Interactive Application Security Testing and Runtime Application Self-Protection both operate at runtime, but they serve different purposes. Here is how they compare and when to use each.]]></description>
      <link>https://safeguard.sh/resources/blog/iast-rasp-runtime-protection-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iast-rasp-runtime-protection-comparison</guid>
      <pubDate>Tue, 10 Feb 2026 18:42:06 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[HTTP Request Smuggling: A Practical Guide]]></title>
      <description><![CDATA[HTTP request smuggling exploits disagreements between frontend and backend servers about where one request ends and the next begins. This guide covers CL.TE, TE.CL, and TE.TE variants with detection and defense strategies.]]></description>
      <link>https://safeguard.sh/resources/blog/http-request-smuggling-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/http-request-smuggling-guide</guid>
      <pubDate>Tue, 10 Feb 2026 17:21:39 GMT</pubDate>
      <category>Web Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AI Code Review for Security: How Effective Is It Really?]]></title>
      <description><![CDATA[AI-powered code review tools promise to catch vulnerabilities faster than humans. We tested the claims against reality.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-code-review-security-effectiveness</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-code-review-security-effectiveness</guid>
      <pubDate>Tue, 10 Feb 2026 16:01:12 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to Write a Security Advisory That Actually Helps]]></title>
      <description><![CDATA[Most security advisories are either too vague to be actionable or too detailed to be safe. Here is how to write advisories that help defenders without enabling attackers.]]></description>
      <link>https://safeguard.sh/resources/blog/security-advisory-writing-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-advisory-writing-guide</guid>
      <pubDate>Tue, 10 Feb 2026 14:40:46 GMT</pubDate>
      <category>Security Strategy</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Apache OFBiz CVE-2023-51467: Authentication Bypass in Enterprise Resource Planning]]></title>
      <description><![CDATA[CVE-2023-51467 bypassed a previous patch for an authentication flaw in Apache OFBiz, granting unauthenticated access to ERP functionality. A patch bypass that exposed critical business data.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-ofbiz-cve-2023-51467-auth-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-ofbiz-cve-2023-51467-auth-bypass</guid>
      <pubDate>Tue, 10 Feb 2026 13:20:19 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[How to Choose a Container Scanning Tool That Actually Helps]]></title>
      <description><![CDATA[A practitioner's guide to picking a container scanning tool: what it should detect, where it fits in the pipeline, and how to avoid drowning in false positives.]]></description>
      <link>https://safeguard.sh/resources/blog/container-scanning-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-scanning-tool</guid>
      <pubDate>Tue, 10 Feb 2026 13:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Benchmark Contamination Concerns In Security Evals]]></title>
      <description><![CDATA[When the test set is in the training set, the benchmark is broken. Security eval contamination is widespread and the mitigations are specific.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-benchmark-contamination-concerns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-benchmark-contamination-concerns</guid>
      <pubDate>Tue, 10 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Claude Agent Skills for Security]]></title>
      <description><![CDATA[Anthropic's Claude Agent Skills let you package tools and context for Claude. Here's how that primitive compares to Griffin's security-specific workflow scaffolding.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-claude-agent-skills-for-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-claude-agent-skills-for-security</guid>
      <pubDate>Tue, 10 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Mythos: The Security Platform Comparison]]></title>
      <description><![CDATA[A senior engineer's side-by-side look at Griffin AI and Mythos — why engine-grounded reasoning beats pure-LLM security intuition when the audit clock starts.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-security-platform-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-security-platform-comparison</guid>
      <pubDate>Tue, 10 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[ISO/IEC 42001: AI Management Systems Reach Adoption Critical Mass]]></title>
      <description><![CDATA[ISO/IEC 42001:2023 went from new-standard status to enterprise compliance benchmark in 2025, with major SaaS vendors certifying and the EU AI Act referencing it as a harmonized pathway.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-iec-42001-ai-management-adoption-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-iec-42001-ai-management-adoption-2025</guid>
      <pubDate>Tue, 10 Feb 2026 12:00:00 GMT</pubDate>
      <category>Standards</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[UK Cyber Security and Resilience Bill: What Changed November 2025]]></title>
      <description><![CDATA[The UK government published the draft Cyber Security and Resilience Bill on 12 November 2025, bringing over 900 managed service providers and data centres above 1MW into NIS scope.]]></description>
      <link>https://safeguard.sh/resources/blog/uk-cyber-security-resilience-bill-november-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uk-cyber-security-resilience-bill-november-2025</guid>
      <pubDate>Tue, 10 Feb 2026 12:00:00 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[npm Team Access Model Hardening]]></title>
      <description><![CDATA[Npm's team-based permissions are more expressive than most organizations use. A walkthrough of the access model and the configurations that actually reduce blast radius.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-team-access-model-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-team-access-model-hardening</guid>
      <pubDate>Tue, 10 Feb 2026 11:59:52 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security in 2023: Year in Review]]></title>
      <description><![CDATA[From the MOVEit mass exploitation to AI model risks, 2023 proved that supply chain attacks are accelerating in both sophistication and scale. Here's what we learned.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-2023-year-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-2023-year-review</guid>
      <pubDate>Tue, 10 Feb 2026 10:39:26 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[AI Security Solutions: A Buyer's Guide for 2026]]></title>
      <description><![CDATA[AI security solutions now span two very different categories — securing AI systems and using AI to secure everything else — and buyers who conflate them end up with the wrong tool.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-solutions-buyers-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-solutions-buyers-guide-2026</guid>
      <pubDate>Tue, 10 Feb 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[FAQ: Building an AppSec Program From Scratch]]></title>
      <description><![CDATA[How to stand up an application security program from zero in 2026 — headcount, tooling, first 90 days, metrics, and the traps that waste the first year.]]></description>
      <link>https://safeguard.sh/resources/blog/faq-building-appsec-program-from-scratch-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/faq-building-appsec-program-from-scratch-2026</guid>
      <pubDate>Tue, 10 Feb 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Maven Central Malicious Publishing Trends 2025]]></title>
      <description><![CDATA[Maven Central has historically been the quietest major registry for malware, but 2025 saw a measurable uptick in malicious artifacts and namespace abuse.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-central-malicious-publishing-trends-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-central-malicious-publishing-trends-2025</guid>
      <pubDate>Tue, 10 Feb 2026 10:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The event-stream npm Attack Explained]]></title>
      <description><![CDATA[In 2018, a hijacked npm maintainer account turned event-stream into a supply chain weapon against crypto wallets. Here's the full CVE-style breakdown.]]></description>
      <link>https://safeguard.sh/resources/blog/the-event-stream-npm-attack-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-event-stream-npm-attack-explained</guid>
      <pubDate>Tue, 10 Feb 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Disclosure Policy Template]]></title>
      <description><![CDATA[A practical template for creating a vulnerability disclosure policy, with guidance on safe harbor provisions, response timelines, and researcher relationships.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-disclosure-policy-template</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-disclosure-policy-template</guid>
      <pubDate>Tue, 10 Feb 2026 09:18:59 GMT</pubDate>
      <category>Organizational Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Best AI Tool for Resume: What to Check Before You Trust One]]></title>
      <description><![CDATA[The best AI tool for resume building is the one that improves your document without quietly harvesting the personal data on it. Here is how to judge these tools on privacy and security, not just polish.]]></description>
      <link>https://safeguard.sh/resources/blog/best-ai-tool-for-resume</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-ai-tool-for-resume</guid>
      <pubDate>Tue, 10 Feb 2026 09:15:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Azure ACR Image Signing with Notation Policy]]></title>
      <description><![CDATA[Azure Container Registry plus Notation gives you signing, trust policy, and AKS enforcement without bolting on Sigstore. Here is how the pieces actually fit together.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-acr-image-signing-notation-policy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-acr-image-signing-notation-policy</guid>
      <pubDate>Tue, 10 Feb 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[FIN7 Supply Chain Social Engineering (2024)]]></title>
      <description><![CDATA[FIN7 built tooling that made its social engineering feel like a SaaS product. Here is how its 2024 tradecraft blended malvertising, fake tools, and credential theft into a supply chain attack.]]></description>
      <link>https://safeguard.sh/resources/blog/fin7-supply-chain-social-engineering-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fin7-supply-chain-social-engineering-2024</guid>
      <pubDate>Tue, 10 Feb 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to secure Jenkins pipelines]]></title>
      <description><![CDATA[A step-by-step guide to secure Jenkins pipelines: hardening the controller, fixing credentials management, RBAC setup, agent isolation, and supply chain verification.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-secure-jenkins-pipelines</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-secure-jenkins-pipelines</guid>
      <pubDate>Tue, 10 Feb 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Reproducible Builds: Why Bother in 2026?]]></title>
      <description><![CDATA[Reproducible builds used to feel academic. After a decade of supply chain attacks, they are the shortest path from an SBOM to a verifiable artifact. Here is the case.]]></description>
      <link>https://safeguard.sh/resources/blog/reproducible-builds-why-bother-in-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reproducible-builds-why-bother-in-2026</guid>
      <pubDate>Tue, 10 Feb 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Introducing Griffin AI v2: Context-Aware Security Intelligence]]></title>
      <description><![CDATA[Griffin AI v2 brings multi-step reasoning, remediation generation, and deep organizational context to Safeguard's AI engine.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-griffin-ai-v2-release</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-griffin-ai-v2-release</guid>
      <pubDate>Tue, 10 Feb 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 Cloud Compliance: A Practical Primer]]></title>
      <description><![CDATA[SOC 2 cloud compliance means proving your cloud-hosted controls actually operate the way you say they do — here's what auditors check and how a cloud compliance platform shortens the path to a report.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-cloud-compliance-a-practical-primer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-cloud-compliance-a-practical-primer</guid>
      <pubDate>Tue, 10 Feb 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How Attackers Use JavaScript: Common Client-Side Attack Techniques]]></title>
      <description><![CDATA[Using JavaScript for hacking rarely means writing exotic exploits — it means abusing the same DOM APIs, event handlers, and third-party scripts every legitimate site relies on.]]></description>
      <link>https://safeguard.sh/resources/blog/how-attackers-use-javascript-client-side-attack-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-attackers-use-javascript-client-side-attack-techniques</guid>
      <pubDate>Tue, 10 Feb 2026 08:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Xfinity Breach via Citrix Bleed Exposes 35.9 Million Customers]]></title>
      <description><![CDATA[In December 2023, Comcast's Xfinity division disclosed that attackers exploiting the Citrix Bleed vulnerability had accessed personal data of 35.9 million customers, including usernames, hashed passwords, and partial Social Security numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/xfinity-citrix-bleed-35-million</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xfinity-citrix-bleed-35-million</guid>
      <pubDate>Tue, 10 Feb 2026 07:58:32 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[The Codecov Supply Chain Attack Explained]]></title>
      <description><![CDATA[A breakdown of the 2021 Codecov breach: how the Bash Uploader was compromised, what CI secrets were exposed, and the remediation steps teams need now.]]></description>
      <link>https://safeguard.sh/resources/blog/the-codecov-supply-chain-attack-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-codecov-supply-chain-attack-explained</guid>
      <pubDate>Tue, 10 Feb 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[VF Corporation Ransomware Attack Disrupts Vans, North Face, and Timberland]]></title>
      <description><![CDATA[In December 2023, VF Corporation, parent company of Vans, The North Face, and Timberland, suffered a ransomware attack that disrupted order fulfillment and exposed personal data of 35.5 million customers during the critical holiday shopping season.]]></description>
      <link>https://safeguard.sh/resources/blog/vans-vf-corporation-ransomware</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vans-vf-corporation-ransomware</guid>
      <pubDate>Tue, 10 Feb 2026 06:38:05 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[How to implement OAuth 2.0 securely]]></title>
      <description><![CDATA[A step-by-step guide to implementing OAuth 2.0 securely: PKCE, redirect URI validation, token storage, and the vulnerabilities to avoid.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-implement-oauth-20-securely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-implement-oauth-20-securely</guid>
      <pubDate>Tue, 10 Feb 2026 06:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Building a Security Automation Playbook Library for Supply Chain Defense]]></title>
      <description><![CDATA[Security automation playbooks codify response procedures into executable workflows. A well-designed playbook library turns supply chain incidents from fire drills into routine operations.]]></description>
      <link>https://safeguard.sh/resources/blog/security-automation-playbook-library</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-automation-playbook-library</guid>
      <pubDate>Tue, 10 Feb 2026 05:17:39 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[The Kaseya VSA Ransomware Attack Explained]]></title>
      <description><![CDATA[A deep dive into the 2021 Kaseya VSA supply chain ransomware attack: the CVE chain, CVSS/KEV context, full timeline, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/the-kaseya-vsa-ransomware-attack-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-kaseya-vsa-ransomware-attack-explained</guid>
      <pubDate>Tue, 10 Feb 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Red Team Supply Chain Attack Simulation]]></title>
      <description><![CDATA[How red teams can simulate real-world supply chain attacks to test organizational defenses—from dependency confusion to build pipeline compromise.]]></description>
      <link>https://safeguard.sh/resources/blog/red-team-supply-chain-attack-simulation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/red-team-supply-chain-attack-simulation</guid>
      <pubDate>Tue, 10 Feb 2026 03:57:12 GMT</pubDate>
      <category>Offensive Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[How to set up API rate limiting]]></title>
      <description><![CDATA[A practical, step-by-step guide to setting up API rate limiting — gateway and app-layer configs, algorithm choices, per-endpoint tuning, and how to verify it actually blocks abuse.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-api-rate-limiting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-api-rate-limiting</guid>
      <pubDate>Tue, 10 Feb 2026 03:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SEC Cyber Disclosure Rules: What Public Companies Must Do Now]]></title>
      <description><![CDATA[The SEC's new cybersecurity disclosure rules require public companies to report material incidents within four days. Here's the operational impact.]]></description>
      <link>https://safeguard.sh/resources/blog/sec-cyber-disclosure-rules-impact</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sec-cyber-disclosure-rules-impact</guid>
      <pubDate>Tue, 10 Feb 2026 02:36:45 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Autonomous Security Remediation: The Promise and Peril of Self-Healing Software]]></title>
      <description><![CDATA[Automated vulnerability patching sounds ideal until you consider what happens when the automation gets it wrong. Here's a realistic look at autonomous remediation.]]></description>
      <link>https://safeguard.sh/resources/blog/autonomous-security-remediation-future</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/autonomous-security-remediation-future</guid>
      <pubDate>Tue, 10 Feb 2026 01:16:19 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What is Spring4Shell]]></title>
      <description><![CDATA[Spring4Shell (CVE-2022-22965) let attackers gain unauthenticated RCE on Java apps via Spring data binding. Here's the full breakdown and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-spring4shell</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-spring4shell</guid>
      <pubDate>Tue, 10 Feb 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[JFrog Artifactory Hardening Guide]]></title>
      <description><![CDATA[Artifactory is the most common artifact repository in enterprise. It is also a default-permissive system where misconfigurations compound. A concrete hardening guide.]]></description>
      <link>https://safeguard.sh/resources/blog/jfrog-artifactory-hardening-guide-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jfrog-artifactory-hardening-guide-2023</guid>
      <pubDate>Mon, 09 Feb 2026 23:55:52 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Puppet Forge Supply Chain Security: Trusting Your Configuration Management]]></title>
      <description><![CDATA[Puppet modules from the Forge run with root-level access on your servers. The supply chain security of these modules deserves the same scrutiny as any dependency.]]></description>
      <link>https://safeguard.sh/resources/blog/puppet-forge-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/puppet-forge-supply-chain-security</guid>
      <pubDate>Mon, 09 Feb 2026 22:35:25 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[API Gateway Security Patterns That Actually Work]]></title>
      <description><![CDATA[API gateways sit between the internet and your services. Getting the security patterns right here multiplies your defense across every API behind them.]]></description>
      <link>https://safeguard.sh/resources/blog/api-gateway-security-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-gateway-security-patterns</guid>
      <pubDate>Mon, 09 Feb 2026 21:14:59 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Container Runtime Security Comparison: runc, gVisor, Kata, and Firecracker]]></title>
      <description><![CDATA[Your container runtime determines the strength of your isolation boundary. Here is an honest comparison of runc, gVisor, Kata Containers, and Firecracker from a security perspective.]]></description>
      <link>https://safeguard.sh/resources/blog/container-runtime-comparison-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-runtime-comparison-security</guid>
      <pubDate>Mon, 09 Feb 2026 19:54:32 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Education Sector Software Security: Protecting Students and Data]]></title>
      <description><![CDATA[Schools and universities rely on hundreds of software applications with limited security staff. Here's how education institutions can manage software supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/education-sector-software-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/education-sector-software-security</guid>
      <pubDate>Mon, 09 Feb 2026 18:34:05 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Post-Install Hooks Across Package Managers: A Comparative Security Analysis]]></title>
      <description><![CDATA[Every package ecosystem handles install-time code execution differently. Some are permissive, some restrictive, and the differences matter for supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/post-install-hooks-across-package-managers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/post-install-hooks-across-package-managers</guid>
      <pubDate>Mon, 09 Feb 2026 17:13:39 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Log4j Two Years Later: Are We Actually Safer?]]></title>
      <description><![CDATA[Two years after Log4Shell shook the internet, many organizations still have vulnerable Log4j instances. The vulnerability changed how we think about supply chain security—but did it change how we act?]]></description>
      <link>https://safeguard.sh/resources/blog/log4j-two-years-later-are-we-safer</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4j-two-years-later-are-we-safer</guid>
      <pubDate>Mon, 09 Feb 2026 15:53:12 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[WAF Bypass Techniques and What They Mean for Supply Chain Security]]></title>
      <description><![CDATA[Web Application Firewalls are a critical defense layer, but they are routinely bypassed. Understanding bypass techniques helps you build defense in depth rather than relying on a single control.]]></description>
      <link>https://safeguard.sh/resources/blog/web-application-firewall-bypass-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web-application-firewall-bypass-techniques</guid>
      <pubDate>Mon, 09 Feb 2026 14:32:45 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Norton Healthcare Ransomware Breach Exposes 2.5 Million Patient Records]]></title>
      <description><![CDATA[In December 2023, Norton Healthcare disclosed that a May ransomware attack by the ALPHV/BlackCat group had compromised personal and medical data of 2.5 million patients, revealing the devastating impact of ransomware on healthcare.]]></description>
      <link>https://safeguard.sh/resources/blog/norton-healthcare-ransomware-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/norton-healthcare-ransomware-breach</guid>
      <pubDate>Mon, 09 Feb 2026 13:12:18 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs GPT-5: Context Grounding]]></title>
      <description><![CDATA[A million-token context window is a tool, not a solution. Context grounding for security requires architecture, not just capacity.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-gpt-5-context-grounding</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-gpt-5-context-grounding</guid>
      <pubDate>Mon, 09 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NIS2 in Spain: The Delayed Transposition and Commission Reasoned Opinion]]></title>
      <description><![CDATA[Spain's draft NIS2 law was approved by the Council of Ministers on 14 January 2025, but had not been published in the BOE by January 2026, triggering Commission action.]]></description>
      <link>https://safeguard.sh/resources/blog/nis2-spain-transposition-delay-reasoned-opinion</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nis2-spain-transposition-delay-reasoned-opinion</guid>
      <pubDate>Mon, 09 Feb 2026 12:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Evaluating Security-Specific Reasoning Models]]></title>
      <description><![CDATA[Reasoning models have arrived in security tooling. Evaluating them requires different methodology from evaluating classification or generation models. Here is what good evaluation looks like.]]></description>
      <link>https://safeguard.sh/resources/blog/security-specific-reasoning-model-evaluation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-specific-reasoning-model-evaluation</guid>
      <pubDate>Mon, 09 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Multi-Cloud Container Security: Building a Unified Strategy]]></title>
      <description><![CDATA[How to maintain consistent container security across AWS, Azure, and GCP without drowning in tool sprawl and fragmented visibility.]]></description>
      <link>https://safeguard.sh/resources/blog/multi-cloud-container-security-strategy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/multi-cloud-container-security-strategy</guid>
      <pubDate>Mon, 09 Feb 2026 11:51:52 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The email-validator Python Library: Usage and Security Guide]]></title>
      <description><![CDATA[How the email-validator Python package works, why regex-only validation is a trap, and the deliverability checks that quietly protect your signup flow.]]></description>
      <link>https://safeguard.sh/resources/blog/email-validator-python</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/email-validator-python</guid>
      <pubDate>Mon, 09 Feb 2026 11:45:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Dark AI: How Attackers Weaponize Generative Models]]></title>
      <description><![CDATA[Dark AI refers to generative models turned to malicious ends, from phishing at scale to malware assistance. Here is what defenders need to understand and do.]]></description>
      <link>https://safeguard.sh/resources/blog/dark-ai</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dark-ai</guid>
      <pubDate>Mon, 09 Feb 2026 11:40:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[DAST, SAST, IAST, and SCA: How They Actually Compose Into a Program]]></title>
      <description><![CDATA[DAST, SAST, IAST, and SCA each catch a different slice of application risk. Here's how they overlap, where each one is blind, and how to combine them without duplicating effort.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-sast-iast-and-sca-how-they-compose</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-sast-iast-and-sca-how-they-compose</guid>
      <pubDate>Mon, 09 Feb 2026 11:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Firmware Analysis and Reverse Engineering for Security Teams]]></title>
      <description><![CDATA[Firmware is the forgotten attack surface. Here are the techniques security teams use to uncover hidden vulnerabilities in embedded software.]]></description>
      <link>https://safeguard.sh/resources/blog/firmware-analysis-reverse-engineering-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/firmware-analysis-reverse-engineering-security</guid>
      <pubDate>Mon, 09 Feb 2026 10:31:25 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Getting Started with Safeguard MCP + ChatGPT]]></title>
      <description><![CDATA[Expose the Safeguard MCP server to ChatGPT so the assistant can run live dependency scans and pull advisory data instead of guessing.]]></description>
      <link>https://safeguard.sh/resources/blog/getting-started-safeguard-mcp-with-chatgpt</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/getting-started-safeguard-mcp-with-chatgpt</guid>
      <pubDate>Mon, 09 Feb 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[RSA Conference 2026: Supply Chain Themes]]></title>
      <description><![CDATA[RSA Conference 2026 centered on AI governance, software supply chain regulation, and vendor consolidation. Here is the analyst view of what mattered.]]></description>
      <link>https://safeguard.sh/resources/blog/rsa-conference-2026-supply-chain-themes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rsa-conference-2026-supply-chain-themes</guid>
      <pubDate>Mon, 09 Feb 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The left-pad npm Incident Explained]]></title>
      <description><![CDATA[No CVE, no CVSS — just one unpublished package that broke the internet's build pipelines. Here's what left-pad still teaches security teams.]]></description>
      <link>https://safeguard.sh/resources/blog/the-left-pad-npm-incident-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-left-pad-npm-incident-explained</guid>
      <pubDate>Mon, 09 Feb 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Agile Data Security Platforms: What the Label Actually Means]]></title>
      <description><![CDATA[An agile data security platform is marketing shorthand for tools that adapt security controls as fast as data moves — here's what actually separates a real one from the label.]]></description>
      <link>https://safeguard.sh/resources/blog/agile-data-security-platforms-what-the-label-means</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agile-data-security-platforms-what-the-label-means</guid>
      <pubDate>Mon, 09 Feb 2026 09:30:00 GMT</pubDate>
      <category>Enterprise</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Security Observability and Telemetry: Seeing What Matters]]></title>
      <description><![CDATA[Traditional security monitoring drowns you in alerts. Security observability flips the model — providing context-rich telemetry that makes threats visible without the noise.]]></description>
      <link>https://safeguard.sh/resources/blog/security-observability-telemetry-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-observability-telemetry-guide</guid>
      <pubDate>Mon, 09 Feb 2026 09:10:58 GMT</pubDate>
      <category>Security Operations</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Hiring Software Supply Chain Security Engineers]]></title>
      <description><![CDATA[What to screen for, how to structure interviews, and the signals that distinguish real supply chain security engineers from adjacent AppSec talent in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/hiring-software-supply-chain-security-engineers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hiring-software-supply-chain-security-engineers</guid>
      <pubDate>Mon, 09 Feb 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to automate TLS certificates with Let's Encrypt]]></title>
      <description><![CDATA[A step-by-step guide to automating TLS certificates with Let's Encrypt using certbot and cert-manager, plus verification steps so renewals never silently fail.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-automate-tls-certificates-with-lets-encrypt</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-automate-tls-certificates-with-lets-encrypt</guid>
      <pubDate>Mon, 09 Feb 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Best SBOM Generators Ranked by Accuracy 2026]]></title>
      <description><![CDATA[Syft, Trivy, cdxgen, and Microsoft sbom-tool measured against known dependency ground truth across four ecosystems. The accuracy spread is wider than you think.]]></description>
      <link>https://safeguard.sh/resources/blog/best-sbom-generators-ranked-by-accuracy-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-sbom-generators-ranked-by-accuracy-2026</guid>
      <pubDate>Mon, 09 Feb 2026 08:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Aisha Bello)</author>
    </item>
    <item>
      <title><![CDATA[Apache Struts CVE-2023-50164: Critical File Upload RCE Echoes Equifax-Era Nightmares]]></title>
      <description><![CDATA[A critical path traversal vulnerability in Apache Struts allowed RCE through file upload manipulation. The disclosure triggered flashbacks to the 2017 Equifax breach caused by a similar Struts flaw.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-struts-cve-2023-50164-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-struts-cve-2023-50164-rce</guid>
      <pubDate>Mon, 09 Feb 2026 07:50:32 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The clawdhub Malicious AI Agent Skills Campaign Explained]]></title>
      <description><![CDATA[A coordinated supply-chain campaign poisoned 1,184+ ClawHub AI agent skills, stealing crypto wallets and SSH keys via CVE-2026-25253.]]></description>
      <link>https://safeguard.sh/resources/blog/the-clawdhub-malicious-ai-agent-skills-campaign-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-clawdhub-malicious-ai-agent-skills-campaign-explained</guid>
      <pubDate>Mon, 09 Feb 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[OpenShift Security Context Constraints: A Guide]]></title>
      <description><![CDATA[SCCs predate Pod Security Admission by a decade and are more powerful. That power is also why OpenShift newcomers find them confusing.]]></description>
      <link>https://safeguard.sh/resources/blog/openshift-security-context-constraints-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openshift-security-context-constraints-guide</guid>
      <pubDate>Mon, 09 Feb 2026 06:30:05 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to build a disaster recovery and backup strategy]]></title>
      <description><![CDATA[A step-by-step guide to building a disaster recovery backup strategy: RTO/RPO planning, backup architecture, automation, a DR plan checklist, and testing.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-build-a-disaster-recovery-and-backup-strategy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-build-a-disaster-recovery-and-backup-strategy</guid>
      <pubDate>Mon, 09 Feb 2026 06:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to Verify a PyPI Package Before Install]]></title>
      <description><![CDATA[A practical pre-install verification workflow for PyPI packages covering sigstore attestations, maintainer checks, and sdist auditing.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-verify-pypi-package-before-install</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-verify-pypi-package-before-install</guid>
      <pubDate>Mon, 09 Feb 2026 05:09:38 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is a Software License]]></title>
      <description><![CDATA[A software license governs how open source code can be used, modified, and redistributed — and license conflicts now carry real contract-law risk, as the Vizio GPL case shows.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-software-license</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-software-license</guid>
      <pubDate>Mon, 09 Feb 2026 04:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Purple Team Exercises for Supply Chain Security]]></title>
      <description><![CDATA[Purple team exercises combine offensive and defensive perspectives to test supply chain defenses. Here is how to structure exercises that improve both detection capabilities and attack understanding.]]></description>
      <link>https://safeguard.sh/resources/blog/purple-team-supply-chain-exercises</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/purple-team-supply-chain-exercises</guid>
      <pubDate>Mon, 09 Feb 2026 03:49:12 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[How to set up an incident response plan]]></title>
      <description><![CDATA[A practical guide to building an incident response plan for software supply chain security, with a ready-to-use playbook template and concrete detection steps.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-an-incident-response-plan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-an-incident-response-plan</guid>
      <pubDate>Mon, 09 Feb 2026 03:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Deserialization Attacks in Java and Python]]></title>
      <description><![CDATA[Insecure deserialization turns data parsing into code execution. This guide covers deserialization attacks in Java and Python, the gadget chain concept, and practical defenses for both ecosystems.]]></description>
      <link>https://safeguard.sh/resources/blog/deserialization-attacks-java-python</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/deserialization-attacks-java-python</guid>
      <pubDate>Mon, 09 Feb 2026 02:28:45 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Managing Security Debt: A Practical Guide]]></title>
      <description><![CDATA[Security debt is inevitable, but it does not have to be unmanageable. Learn how to quantify, prioritize, and systematically pay down your organization's security debt.]]></description>
      <link>https://safeguard.sh/resources/blog/managing-security-debt-practical-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/managing-security-debt-practical-guide</guid>
      <pubDate>Mon, 09 Feb 2026 01:08:18 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is Open Source Software]]></title>
      <description><![CDATA[Open source software now sits in 96% of codebases. Here's what OSS actually is, how licensing works, and where the real security risk hides.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-open-source-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-open-source-software</guid>
      <pubDate>Mon, 09 Feb 2026 01:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[How to configure SIEM alerting rules]]></title>
      <description><![CDATA[A step-by-step guide to configure SIEM alerting rules: from use case development through Splunk alert configuration to detection rule tuning.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-configure-siem-alerting-rules</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-configure-siem-alerting-rules</guid>
      <pubDate>Mon, 09 Feb 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[xrpl.js npm Backdoor April 2025 Incident Analysis]]></title>
      <description><![CDATA[A stolen Ripple-adjacent npm token pushed key-stealing versions of xrpl.js. Timeline, payload structure, and what XRPL integrators should do next.]]></description>
      <link>https://safeguard.sh/resources/blog/xrpl-js-npm-backdoor-april-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xrpl-js-npm-backdoor-april-2025</guid>
      <pubDate>Mon, 09 Feb 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Dependency Health Metrics That Actually Matter]]></title>
      <description><![CDATA[Star counts and download numbers tell you popularity, not health. The metrics that predict dependency risk are harder to measure and more important to track.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-dependency-health-metrics</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-dependency-health-metrics</guid>
      <pubDate>Sun, 08 Feb 2026 23:47:51 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Monorepo Security: Dependency Management at Scale]]></title>
      <description><![CDATA[Monorepos centralize code but create unique security challenges. Learn how to manage shared dependencies, enforce security policies, and maintain SBOMs across a monorepo architecture.]]></description>
      <link>https://safeguard.sh/resources/blog/monorepo-security-dependency-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/monorepo-security-dependency-management</guid>
      <pubDate>Sun, 08 Feb 2026 22:27:25 GMT</pubDate>
      <category>Architecture</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Federal SBOM Mandate: Compliance Deadlines and What They Mean for Vendors]]></title>
      <description><![CDATA[Federal agencies are tightening SBOM requirements for software suppliers. Here's what vendors need to know about compliance deadlines, attestation requirements, and practical implementation.]]></description>
      <link>https://safeguard.sh/resources/blog/federal-sbom-mandate-compliance-deadline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/federal-sbom-mandate-compliance-deadline</guid>
      <pubDate>Sun, 08 Feb 2026 21:06:58 GMT</pubDate>
      <category>Compliance & Regulations</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[npm Scripts Sandboxing Techniques]]></title>
      <description><![CDATA[Postinstall scripts have been the supply-chain attacker's favorite tool for a decade. Here are the sandboxing techniques that actually work, ranked from cheap to serious.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-scripts-sandboxing-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-scripts-sandboxing-techniques</guid>
      <pubDate>Sun, 08 Feb 2026 19:46:31 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SOX IT Controls and Software Supply Chain]]></title>
      <description><![CDATA[SOX ITGCs are being rewritten around open-source software and build integrity as PCAOB and SEC scrutiny extends ICFR into the developer toolchain for the first time.]]></description>
      <link>https://safeguard.sh/resources/blog/sox-it-controls-software-supply-chain-intersection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sox-it-controls-software-supply-chain-intersection</guid>
      <pubDate>Sun, 08 Feb 2026 18:26:05 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Dollar Tree Third-Party Breach Impacts Nearly 2 Million Employees]]></title>
      <description><![CDATA[In November 2023, Dollar Tree disclosed that a breach at its third-party service provider Zeroed-In Technologies exposed the personal data of nearly 2 million current and former employees, highlighting the persistent risk of third-party supply chain compromises.]]></description>
      <link>https://safeguard.sh/resources/blog/dollar-tree-third-party-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dollar-tree-third-party-breach</guid>
      <pubDate>Sun, 08 Feb 2026 17:05:38 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[How to Audit npm Postinstall Scripts Safely]]></title>
      <description><![CDATA[Inspect every lifecycle script in your node_modules tree, disable dangerous ones by default, and catch malicious postinstall hooks before they execute.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-audit-npm-postinstall-scripts-safely</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-audit-npm-postinstall-scripts-safely</guid>
      <pubDate>Sun, 08 Feb 2026 15:45:11 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Chainguard Images: The Zero-CVE Container Base Image Revolution]]></title>
      <description><![CDATA[Chainguard ships container images with zero known CVEs. That sounds like marketing until you understand how they build them. Here is the technical reality behind the claim.]]></description>
      <link>https://safeguard.sh/resources/blog/chainguard-images-minimal-containers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chainguard-images-minimal-containers</guid>
      <pubDate>Sun, 08 Feb 2026 14:24:45 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[AI Model Supply Chain Risks: Hugging Face and the New Attack Surface]]></title>
      <description><![CDATA[As organizations download pre-trained models from Hugging Face and other model hubs, the AI supply chain introduces risks that traditional software security tools don't address.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-model-supply-chain-hugging-face-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-model-supply-chain-hugging-face-risks</guid>
      <pubDate>Sun, 08 Feb 2026 13:04:18 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Tool-Call Privilege Escalation In Practice]]></title>
      <description><![CDATA[When an agent can call tools, the permission boundary is no longer between the user and the system. It is between the model's current beliefs and everything the model can reach. That is a much harder boundary to defend.]]></description>
      <link>https://safeguard.sh/resources/blog/frontier-model-limit-tool-call-privilege-escalation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/frontier-model-limit-tool-call-privilege-escalation</guid>
      <pubDate>Sun, 08 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Gemini Function Calling: Security]]></title>
      <description><![CDATA[Gemini's function calling is strong and flexible. Griffin AI's tool layer is narrow and opinionated. For security workflows, the opinionated approach wins.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-function-calling-for-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-function-calling-for-security</guid>
      <pubDate>Sun, 08 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[RBAC & Scoping: Griffin AI vs Mythos]]></title>
      <description><![CDATA[An AI that reads your security data needs the same access controls as a human analyst. Most pure-LLM vendors stop at the role name. Safeguard enforces the scope.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-rbac-and-scoping</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-rbac-and-scoping</guid>
      <pubDate>Sun, 08 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Multi-Tenant Isolation]]></title>
      <description><![CDATA[Practical guidance on isolating tenants on shared Model Context Protocol servers, covering identity, data, compute, and observability boundaries at production scale.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-multi-tenant-isolation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-multi-tenant-isolation</guid>
      <pubDate>Sun, 08 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Security Considerations When Migrating from Monolith to Microservices]]></title>
      <description><![CDATA[Decomposing a monolith into microservices changes the attack surface fundamentally. The security model that worked for the monolith will not work for the distributed system.]]></description>
      <link>https://safeguard.sh/resources/blog/monolith-to-microservices-security-migration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/monolith-to-microservices-security-migration</guid>
      <pubDate>Sun, 08 Feb 2026 11:43:51 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Legacy Software and Supply Chain Risks]]></title>
      <description><![CDATA[Legacy systems are supply chain time bombs—running outdated dependencies, unsupported frameworks, and unmaintained libraries. Here's how to manage the risk.]]></description>
      <link>https://safeguard.sh/resources/blog/legacy-software-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/legacy-software-supply-chain-risks</guid>
      <pubDate>Sun, 08 Feb 2026 10:23:25 GMT</pubDate>
      <category>Risk Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[AI Model Weights: Signing, Attestation, Provenance]]></title>
      <description><![CDATA[Model weights are binaries with the privilege of code and the review of documents. Here is what signing, attestation, and provenance should actually look like.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-model-weights-signing-attestation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-model-weights-signing-attestation</guid>
      <pubDate>Sun, 08 Feb 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GitLab OIDC Token Theft: Workflow Research]]></title>
      <description><![CDATA[GitLab CI OIDC tokens are becoming the keys to cloud kingdoms. Recent research shows how workflow misconfigurations leak them in surprising ways.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-oidc-token-theft-workflow-research</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-oidc-token-theft-workflow-research</guid>
      <pubDate>Sun, 08 Feb 2026 10:00:00 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Enrichment and Vulnerability Correlation: Turning Inventory into Intelligence]]></title>
      <description><![CDATA[A raw SBOM is a parts list. An enriched SBOM is a risk assessment. Here's how to bridge the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-enrichment-vulnerability-correlation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-enrichment-vulnerability-correlation</guid>
      <pubDate>Sun, 08 Feb 2026 10:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is a Package Manager]]></title>
      <description><![CDATA[Package managers like npm and pip automate dependency resolution — and have been the entry point for incidents from event-stream to the xz-utils backdoor.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-package-manager</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-package-manager</guid>
      <pubDate>Sun, 08 Feb 2026 10:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Express.js Security Middleware: An Audit]]></title>
      <description><![CDATA[Express remains the default Node.js framework at most shops, and its middleware ecosystem is a thirteen-year accumulation of packages, some abandoned, some indispensable. This is a pragmatic audit of what belongs in a 2023 Express stack.]]></description>
      <link>https://safeguard.sh/resources/blog/express-js-security-middleware-audit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/express-js-security-middleware-audit</guid>
      <pubDate>Sun, 08 Feb 2026 09:02:58 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to set up AWS Organizations Service Control Policies]]></title>
      <description><![CDATA[A practical, command-by-command guide to AWS Organizations SCP setup — from enabling policy types to real guardrail examples, rollout, and troubleshooting.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-aws-organizations-service-control-policies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-aws-organizations-service-control-policies</guid>
      <pubDate>Sun, 08 Feb 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Policy Evaluation Engine]]></title>
      <description><![CDATA[How Safeguard's policy engine evaluates thousands of rules per artifact with predictable latency — the compiler, the cache layer, and the decision trail.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-policy-evaluation-engine-architecture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-policy-evaluation-engine-architecture</guid>
      <pubDate>Sun, 08 Feb 2026 09:00:00 GMT</pubDate>
      <category>Architecture</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Healthcare Software Security: HIPAA, SBOMs, and Patient Safety]]></title>
      <description><![CDATA[Medical devices and healthcare IT systems depend on software with hidden vulnerabilities. Here's how SBOMs and supply chain security intersect with HIPAA.]]></description>
      <link>https://safeguard.sh/resources/blog/healthcare-software-security-hipaa-sbom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/healthcare-software-security-hipaa-sbom</guid>
      <pubDate>Sun, 08 Feb 2026 07:42:31 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is npm Security]]></title>
      <description><![CDATA[A concrete look at npm security: real 2025 supply chain attacks on chalk and debug, the Shai-Hulud worm, and how teams actually defend the npm dependency tree.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-npm-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-npm-security</guid>
      <pubDate>Sun, 08 Feb 2026 07:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[MongoDB Atlas Breach: Customer Metadata Exposed in Corporate Systems Attack]]></title>
      <description><![CDATA[MongoDB disclosed unauthorized access to its corporate systems in December 2023, exposing customer metadata and contact information while Atlas cluster data remained secure.]]></description>
      <link>https://safeguard.sh/resources/blog/mongodb-atlas-breach-customer-data</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mongodb-atlas-breach-customer-data</guid>
      <pubDate>Sun, 08 Feb 2026 06:22:04 GMT</pubDate>
      <category>Incident Response</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SonarQube Security Scanning: Code Quality Meets Application Security]]></title>
      <description><![CDATA[A review of SonarQube's security scanning capabilities, examining how its code quality heritage shapes its approach to vulnerability detection and taint analysis.]]></description>
      <link>https://safeguard.sh/resources/blog/sonarqube-security-scanning-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sonarqube-security-scanning-review</guid>
      <pubDate>Sun, 08 Feb 2026 05:01:38 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What is PyPI Security]]></title>
      <description><![CDATA[PyPI security stops typosquats, dependency confusion, and poisoned CI builds before pip install ever runs your code.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-pypi-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-pypi-security</guid>
      <pubDate>Sun, 08 Feb 2026 04:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[API Key Rotation Automation: A Practical Implementation Guide]]></title>
      <description><![CDATA[Manual key rotation does not happen. Automated rotation does. Here is how to implement zero-downtime API key rotation for the services and credentials that matter most.]]></description>
      <link>https://safeguard.sh/resources/blog/api-key-rotation-automation-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-key-rotation-automation-guide</guid>
      <pubDate>Sun, 08 Feb 2026 03:41:11 GMT</pubDate>
      <category>Security Operations</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[How to set up OPA Gatekeeper for Kubernetes admission con...]]></title>
      <description><![CDATA[A step-by-step guide to OPA Gatekeeper Kubernetes admission control: install, write constraint templates, roll out safely, and verify enforcement.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-opa-gatekeeper-for-kubernetes-admission-control</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-opa-gatekeeper-for-kubernetes-admission-control</guid>
      <pubDate>Sun, 08 Feb 2026 03:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Snap Store and Flatpak Security Models Compared]]></title>
      <description><![CDATA[Universal Linux packaging formats promise sandboxed applications. Their security models differ significantly, and neither delivers the isolation most users assume.]]></description>
      <link>https://safeguard.sh/resources/blog/snap-store-flatpak-security-models</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snap-store-flatpak-security-models</guid>
      <pubDate>Sun, 08 Feb 2026 02:20:44 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Apache Web Server Hardening Guide for Production Environments]]></title>
      <description><![CDATA[Apache httpd still serves millions of websites. Its default configuration exposes information, accepts weak TLS, and enables features you probably do not need.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-web-server-hardening-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-web-server-hardening-guide</guid>
      <pubDate>Sun, 08 Feb 2026 01:00:18 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is Maven Security]]></title>
      <description><![CDATA[Maven security covers vulnerable dependencies, malicious plugins, and build-time risks in Java projects -- from Log4Shell to transitive dependency sprawl.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-maven-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-maven-security</guid>
      <pubDate>Sun, 08 Feb 2026 01:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[How to configure DNSSEC]]></title>
      <description><![CDATA[A practical, command-by-command guide to configure DNSSEC on managed and self-hosted DNS, verify the chain of trust, and prevent DNS spoofing across your supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-configure-dnssec</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-configure-dnssec</guid>
      <pubDate>Sun, 08 Feb 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Travis CI Security Best Practices]]></title>
      <description><![CDATA[Security hardening for Travis CI pipelines covering secret management, build isolation, and migration considerations for teams still on the platform.]]></description>
      <link>https://safeguard.sh/resources/blog/travis-ci-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/travis-ci-security-best-practices</guid>
      <pubDate>Sat, 07 Feb 2026 23:39:51 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Boeing Hit by LockBit Ransomware: 43GB of Sensitive Data Leaked]]></title>
      <description><![CDATA[In November 2023, the LockBit ransomware gang published 43 gigabytes of Boeing's internal data after the aerospace giant refused to pay ransom, exposing the persistent vulnerability of manufacturing supply chains to ransomware.]]></description>
      <link>https://safeguard.sh/resources/blog/boeing-lockbit-ransomware-data-leak</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/boeing-lockbit-ransomware-data-leak</guid>
      <pubDate>Sat, 07 Feb 2026 22:19:24 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Rust Cargo Dependency Security Guide]]></title>
      <description><![CDATA[How to secure your Rust supply chain with Cargo.lock, crate auditing, and build script controls.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-cargo-dependency-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-cargo-dependency-security-guide</guid>
      <pubDate>Sat, 07 Feb 2026 20:58:58 GMT</pubDate>
      <category>Dependency Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Singapore's Cybersecurity Act and Software Supply Chain Obligations]]></title>
      <description><![CDATA[Singapore's regulatory approach to cybersecurity is maturing fast, with supply chain security becoming a central pillar. Here's what's changing.]]></description>
      <link>https://safeguard.sh/resources/blog/singapore-cybersecurity-act-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/singapore-cybersecurity-act-supply-chain</guid>
      <pubDate>Sat, 07 Feb 2026 19:38:31 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[govulncheck in Production Integration]]></title>
      <description><![CDATA[govulncheck is the best vulnerability scanner the Go ecosystem has ever had, but turning it from a demo into a production gate takes more than adding a CI step.]]></description>
      <link>https://safeguard.sh/resources/blog/govulncheck-production-integration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/govulncheck-production-integration</guid>
      <pubDate>Sat, 07 Feb 2026 18:18:04 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[OAuth Token Security Throughout the Lifecycle]]></title>
      <description><![CDATA[OAuth tokens grant access to APIs, services, and user data. Their security across creation, storage, use, and revocation determines your application risk posture.]]></description>
      <link>https://safeguard.sh/resources/blog/oauth-token-security-lifecycle</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oauth-token-security-lifecycle</guid>
      <pubDate>Sat, 07 Feb 2026 16:57:38 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The LLM Supply Chain: Risks Hiding in Foundation Models]]></title>
      <description><![CDATA[Large language models have their own supply chains: training data, fine-tuning datasets, model weights, and serving infrastructure. Each layer introduces risk.]]></description>
      <link>https://safeguard.sh/resources/blog/large-language-model-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/large-language-model-supply-chain-risks</guid>
      <pubDate>Sat, 07 Feb 2026 15:37:11 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Java Module System Security Features: What JPMS Actually Delivers]]></title>
      <description><![CDATA[The Java Platform Module System promised stronger encapsulation and security boundaries. Here is what it actually delivers and where the gaps remain.]]></description>
      <link>https://safeguard.sh/resources/blog/java-module-system-security-features</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-module-system-security-features</guid>
      <pubDate>Sat, 07 Feb 2026 14:16:44 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Citrix Bleed CVE-2023-4966: Session Token Theft That Bypassed Every Authentication Control]]></title>
      <description><![CDATA[Citrix Bleed allowed attackers to steal session tokens from NetScaler ADC, bypassing MFA and all authentication controls. LockBit ransomware used it to devastating effect.]]></description>
      <link>https://safeguard.sh/resources/blog/citrix-bleed-cve-2023-4966-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/citrix-bleed-cve-2023-4966-exploitation</guid>
      <pubDate>Sat, 07 Feb 2026 12:56:17 GMT</pubDate>
      <category>Zero-Day Exploits</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[AI-BOM Adoption: State of the Art in 2026]]></title>
      <description><![CDATA[The AI Bill of Materials went from concept paper to procurement requirement in under two years. Here is what the current state of the art actually looks like.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-trend-ai-bom-adoption-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-trend-ai-bom-adoption-2026</guid>
      <pubDate>Sat, 07 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Fix Explanation Quality: Griffin AI vs Mythos]]></title>
      <description><![CDATA[A remediation PR explanation is either evidence or storytelling. Griffin AI attaches taint paths and disproof attempts; Mythos-class tools attach plausible prose.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-fix-explanation-quality</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-fix-explanation-quality</guid>
      <pubDate>Sat, 07 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Apache ActiveMQ CVE-2023-46604: Ransomware Groups Exploit Critical RCE]]></title>
      <description><![CDATA[A critical remote code execution flaw in Apache ActiveMQ was rapidly weaponized by ransomware operators, with exploitation beginning before many organizations could patch.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-activemq-cve-2023-46604-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-activemq-cve-2023-46604-rce</guid>
      <pubDate>Sat, 07 Feb 2026 11:35:51 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Deno's Permission-Based Security Model: What It Gets Right and Where It Falls Short]]></title>
      <description><![CDATA[Deno was built with security as a first-class concern, requiring explicit permissions for file, network, and environment access. Here is an honest assessment of what that model delivers in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/deno-runtime-security-model-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/deno-runtime-security-model-analysis</guid>
      <pubDate>Sat, 07 Feb 2026 10:15:24 GMT</pubDate>
      <category>Developer Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What is a Monorepo]]></title>
      <description><![CDATA[A monorepo houses many projects in one repository. Learn how Google, Meta, and Microsoft use them, and the blast-radius risks security teams must manage.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-monorepo</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-monorepo</guid>
      <pubDate>Sat, 07 Feb 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best Kubernetes Admission Controllers for Supply Chain Security]]></title>
      <description><![CDATA[Kyverno, OPA Gatekeeper, Sigstore policy-controller, Ratify, or plain CEL? A field guide to admission controllers that actually block unsigned and vulnerable images.]]></description>
      <link>https://safeguard.sh/resources/blog/best-kubernetes-admission-controllers-for-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-kubernetes-admission-controllers-for-supply-chain-security</guid>
      <pubDate>Sat, 07 Feb 2026 09:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Priya Raman)</author>
    </item>
    <item>
      <title><![CDATA[Go Module Checksum Database In Depth]]></title>
      <description><![CDATA[The Go checksum database is one of the most successful supply chain controls in any mainstream ecosystem. Here is how it actually works and where it still has edges.]]></description>
      <link>https://safeguard.sh/resources/blog/go-module-checksum-database-in-depth</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-module-checksum-database-in-depth</guid>
      <pubDate>Sat, 07 Feb 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to set up SPF, DKIM, and DMARC for email security]]></title>
      <description><![CDATA[A step-by-step guide to setting up SPF, DKIM, and DMARC records to stop email spoofing and secure your domain sending reputation.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-spf-dkim-and-dmarc-for-email-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-spf-dkim-and-dmarc-for-email-security</guid>
      <pubDate>Sat, 07 Feb 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[CI/CD Credential Theft Prevention]]></title>
      <description><![CDATA[CI/CD pipelines are treasure troves of secrets -- cloud credentials, API keys, signing certificates. Preventing credential theft from build environments is critical to supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/ci-cd-credential-theft-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ci-cd-credential-theft-prevention</guid>
      <pubDate>Sat, 07 Feb 2026 08:54:57 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SBOMs in the Automotive Industry: Navigating Software-Defined Vehicles]]></title>
      <description><![CDATA[Modern vehicles contain over 100 million lines of code. The automotive industry is waking up to software supply chain security, and SBOMs are central to the response.]]></description>
      <link>https://safeguard.sh/resources/blog/software-bill-of-materials-automotive-industry</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-bill-of-materials-automotive-industry</guid>
      <pubDate>Sat, 07 Feb 2026 07:34:31 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What is Static Code Analysis]]></title>
      <description><![CDATA[Static code analysis scans source code for flaws before it runs. Here's how SAST works, what it catches, and where it falls short without reachability context.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-static-code-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-static-code-analysis</guid>
      <pubDate>Sat, 07 Feb 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Executive Order 14028 at the Two-Year Mark]]></title>
      <description><![CDATA[Two years after Executive Order 14028 on federal cybersecurity, the operational impact is clearer. What actually changed, what stalled, and what is coming in year three.]]></description>
      <link>https://safeguard.sh/resources/blog/executive-order-14028-year-two-checkpoint</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/executive-order-14028-year-two-checkpoint</guid>
      <pubDate>Sat, 07 Feb 2026 06:14:04 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to implement least privilege for GCP service accounts]]></title>
      <description><![CDATA[A step-by-step guide to auditing, scoping, and enforcing least privilege service accounts GCP-wide — including key rotation and IAM audit workflows.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-implement-least-privilege-for-gcp-service-accounts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-implement-least-privilege-for-gcp-service-accounts</guid>
      <pubDate>Sat, 07 Feb 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems Yanked Gems: Security Risks of Removed Ruby Packages]]></title>
      <description><![CDATA[When a Ruby gem is yanked from RubyGems.org, it creates security risks for projects that depended on it. Understanding the yanking mechanism is critical for Ruby supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-yanked-gems-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-yanked-gems-security</guid>
      <pubDate>Sat, 07 Feb 2026 04:53:37 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What is Dynamic Code Analysis]]></title>
      <description><![CDATA[Dynamic code analysis tests running applications to catch exploitable vulnerabilities that static scans and manifest files alone can easily miss.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-dynamic-code-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-dynamic-code-analysis</guid>
      <pubDate>Sat, 07 Feb 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[React Native Security Considerations for Mobile Supply Chains]]></title>
      <description><![CDATA[React Native introduces unique security challenges at the intersection of JavaScript and native mobile code. Understanding these risks is essential for securing cross-platform mobile applications.]]></description>
      <link>https://safeguard.sh/resources/blog/react-native-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/react-native-security-considerations</guid>
      <pubDate>Sat, 07 Feb 2026 03:33:11 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to set up cloud security posture management (CSPM)]]></title>
      <description><![CDATA[A practical, step-by-step guide to setting up cloud security posture management: inventory, tool selection, policy tuning, alerting, remediation, and verification.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-cloud-security-posture-management-cspm</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-cloud-security-posture-management-cspm</guid>
      <pubDate>Sat, 07 Feb 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Pulumi and Crossplane Security: IaC Beyond Terraform]]></title>
      <description><![CDATA[Security considerations for Pulumi and Crossplane as infrastructure-as-code alternatives, including unique risks and hardening strategies.]]></description>
      <link>https://safeguard.sh/resources/blog/pulumi-crossplane-iac-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pulumi-crossplane-iac-security</guid>
      <pubDate>Sat, 07 Feb 2026 02:12:44 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What is Threat Detection]]></title>
      <description><![CDATA[Threat detection means spotting active attacks before they succeed. See real dwell-time data, CVE examples, and detection metrics that matter.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-threat-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-threat-detection</guid>
      <pubDate>Sat, 07 Feb 2026 01:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Hijacking Prevention: A Comprehensive Guide]]></title>
      <description><![CDATA[Dependency hijacking encompasses multiple attack techniques that redirect dependency resolution to attacker-controlled packages. This guide covers all major hijacking vectors and their countermeasures.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-hijacking-prevention-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-hijacking-prevention-guide</guid>
      <pubDate>Sat, 07 Feb 2026 00:52:17 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[How to configure network ACLs in AWS VPC]]></title>
      <description><![CDATA[A step-by-step guide to configure AWS NACLs correctly — creating rules, associating subnets, and verifying traffic — for real defense-in-depth in your VPC.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-configure-network-acls-in-aws-vpc</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-configure-network-acls-in-aws-vpc</guid>
      <pubDate>Sat, 07 Feb 2026 00:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Deno Security Model Advantages: Runtime Permissions Done Right]]></title>
      <description><![CDATA[Deno requires explicit permission grants for file, network, and environment access. This capability-based model changes the supply chain risk equation.]]></description>
      <link>https://safeguard.sh/resources/blog/deno-security-model-advantages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/deno-security-model-advantages</guid>
      <pubDate>Fri, 06 Feb 2026 23:31:51 GMT</pubDate>
      <category>Secure Development</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Container Escape Techniques in 2023: What's Changed and What Hasn't]]></title>
      <description><![CDATA[Container escapes remain a real threat in multi-tenant environments. A look at the latest techniques, CVEs, and defenses as container security matures in 2023.]]></description>
      <link>https://safeguard.sh/resources/blog/container-escape-techniques-2023-update</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-escape-techniques-2023-update</guid>
      <pubDate>Fri, 06 Feb 2026 22:11:24 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[CMMC 2.0 and Software Supply Chain Security: A Practical Guide]]></title>
      <description><![CDATA[CMMC 2.0 is reshaping defense contracting requirements. Here's how software supply chain security maps to the new maturity model.]]></description>
      <link>https://safeguard.sh/resources/blog/cmmc-2-0-software-supply-chain-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cmmc-2-0-software-supply-chain-guide</guid>
      <pubDate>Fri, 06 Feb 2026 20:50:57 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Wiz Cloud Security Platform: Agentless Done at Scale]]></title>
      <description><![CDATA[An overview of Wiz's cloud security platform, covering its agentless architecture, graph-based risk analysis, and how it changed expectations for cloud security tooling.]]></description>
      <link>https://safeguard.sh/resources/blog/wiz-cloud-security-platform-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wiz-cloud-security-platform-overview</guid>
      <pubDate>Fri, 06 Feb 2026 19:30:30 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Cloudflare's Supply Chain Security Model]]></title>
      <description><![CDATA[How Cloudflare secures the software supply chain for infrastructure that sits between the internet and millions of websites, with lessons on Rust adoption and edge computing security.]]></description>
      <link>https://safeguard.sh/resources/blog/cloudflare-supply-chain-security-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloudflare-supply-chain-security-model</guid>
      <pubDate>Fri, 06 Feb 2026 18:10:04 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[API Security Testing Against the OWASP API Top 10: A Hands-On Guide]]></title>
      <description><![CDATA[APIs are now the primary attack surface for most applications. Here is how to test for the OWASP API Security Top 10 risks systematically.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-testing-owasp-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-testing-owasp-guide</guid>
      <pubDate>Fri, 06 Feb 2026 16:49:37 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Mr. Cooper Mortgage Breach Exposes 14.7 Million Customers]]></title>
      <description><![CDATA[In November 2023, mortgage giant Mr. Cooper disclosed a cyberattack that compromised the personal and financial data of 14.7 million current and former customers, making it one of the largest financial services breaches of the year.]]></description>
      <link>https://safeguard.sh/resources/blog/mr-cooper-mortgage-data-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mr-cooper-mortgage-data-breach</guid>
      <pubDate>Fri, 06 Feb 2026 15:29:10 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CISA's Secure by Default: Shifting Responsibility to Software Manufacturers]]></title>
      <description><![CDATA[CISA's Secure by Design guidance pushes software vendors to ship secure defaults and take ownership of customer security outcomes, fundamentally changing the security responsibility model.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-secure-by-default-guidance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-secure-by-default-guidance</guid>
      <pubDate>Fri, 06 Feb 2026 14:08:44 GMT</pubDate>
      <category>Compliance & Regulations</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[PyPI 2FA Enrollment: Enterprise Rollout]]></title>
      <description><![CDATA[PyPI's 2FA mandate isn't just a personal-account concern anymore — enterprises publishing Python libraries have real rollout work to do. A playbook from the front lines.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-2fa-enrollment-enterprise-rollout</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-2fa-enrollment-enterprise-rollout</guid>
      <pubDate>Fri, 06 Feb 2026 12:48:17 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Dynamic Dispatch: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Dynamic dispatch hides real exploits behind indirection. Griffin AI models the dispatch; Mythos-class tools guess. That gap changes outcomes.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-dynamic-dispatch-handling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-dynamic-dispatch-handling</guid>
      <pubDate>Fri, 06 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Building a Software Supply Chain Risk Register]]></title>
      <description><![CDATA[A risk register is the backbone of supply chain risk management. Here is a practical template for identifying, scoring, tracking, and mitigating software supply chain risks.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-risk-register-template</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-risk-register-template</guid>
      <pubDate>Fri, 06 Feb 2026 11:27:50 GMT</pubDate>
      <category>Risk Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Dagger CI/CD Security Benefits]]></title>
      <description><![CDATA[How Dagger's containerized pipeline model improves CI/CD security with hermetic builds, portability, and reduced platform dependency.]]></description>
      <link>https://safeguard.sh/resources/blog/dagger-ci-cd-security-benefits</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dagger-ci-cd-security-benefits</guid>
      <pubDate>Fri, 06 Feb 2026 10:07:24 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is a Security Champion Program]]></title>
      <description><![CDATA[A security champion program embeds trained developers in each engineering team to triage vulnerabilities locally. Here's how to structure, staff, and measure one.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-security-champion-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-security-champion-program</guid>
      <pubDate>Fri, 06 Feb 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[What Is Patch Management?]]></title>
      <description><![CDATA[Patch management is the process of finding, testing, and deploying software updates that fix bugs and security flaws. Learn the lifecycle, prioritization, and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-patch-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-patch-management</guid>
      <pubDate>Fri, 06 Feb 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[How an AI-Based Security System Works in Modern Application Security]]></title>
      <description><![CDATA[An AI-based security system uses machine learning to detect threats and prioritize risk at a scale humans cannot match. Here is what it does well, and where it needs guardrails.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-based-security-system</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-based-security-system</guid>
      <pubDate>Fri, 06 Feb 2026 09:50:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Fargate/ECS Container Supply Chain Pitfalls]]></title>
      <description><![CDATA[The parts of container supply chain that break differently on AWS Fargate and ECS compared to Kubernetes, and what to do about each one in production.]]></description>
      <link>https://safeguard.sh/resources/blog/fargate-ecs-container-supply-chain-pitfalls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fargate-ecs-container-supply-chain-pitfalls</guid>
      <pubDate>Fri, 06 Feb 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Gamaredon Ukraine Targeting Supply Chain 2025]]></title>
      <description><![CDATA[Gamaredon's 2025 operations against Ukraine have leaned harder into software and MSP supply chain pivots. Here is the tradecraft defenders need to recognize.]]></description>
      <link>https://safeguard.sh/resources/blog/gamaredon-ukraine-targeting-supply-chain-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gamaredon-ukraine-targeting-supply-chain-2025</guid>
      <pubDate>Fri, 06 Feb 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to scope a penetration test and define rules of engag...]]></title>
      <description><![CDATA[A practical guide to scoping a pentest and writing penetration testing rules of engagement, covering targets, timing, methodology, and legal sign-off.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-scope-a-penetration-test-and-define-rules-of-engagement</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-scope-a-penetration-test-and-define-rules-of-engagement</guid>
      <pubDate>Fri, 06 Feb 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Lazarus Group: 3CX and Software Builds]]></title>
      <description><![CDATA[Lazarus turned a developer's personal machine into a corporate build-system compromise. Here is how that cascade actually worked and what it teaches about build-system trust.]]></description>
      <link>https://safeguard.sh/resources/blog/lazarus-group-3cx-and-software-builds</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lazarus-group-3cx-and-software-builds</guid>
      <pubDate>Fri, 06 Feb 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Secure Defaults for Internal Developer Platforms]]></title>
      <description><![CDATA[An IDP that makes the secure path the easy path wins. One that requires engineers to opt into security loses. Here is how to ship defaults that actually stick.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-defaults-for-internal-developer-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-defaults-for-internal-developer-platforms</guid>
      <pubDate>Fri, 06 Feb 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[F5 BIG-IP CVE-2023-46747: Authentication Bypass Puts Network Infrastructure at Risk]]></title>
      <description><![CDATA[A critical authentication bypass in F5 BIG-IP allowed unauthenticated attackers to gain administrative access. The vulnerability affected the management interface of devices protecting enterprise networks.]]></description>
      <link>https://safeguard.sh/resources/blog/f5-big-ip-cve-2023-46747-authentication-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/f5-big-ip-cve-2023-46747-authentication-bypass</guid>
      <pubDate>Fri, 06 Feb 2026 08:46:57 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Building a DevSecOps Culture: Beyond Tools and into Teams]]></title>
      <description><![CDATA[DevSecOps is a culture shift, not a tooling decision. Practical strategies for building security into development teams without creating friction or resentment.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-culture-building-security-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-culture-building-security-teams</guid>
      <pubDate>Fri, 06 Feb 2026 07:26:30 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is Secure by Design]]></title>
      <description><![CDATA[Secure by Design turns CISA's 2023 guidance and pledge into concrete practice: memory-safe code, no default passwords, and verifiable SBOMs over marketing claims.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-secure-by-design</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-secure-by-design</guid>
      <pubDate>Fri, 06 Feb 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[A History of Browser Sandbox Escapes and What They Teach Us]]></title>
      <description><![CDATA[Browser sandboxes are the last line of defense against web-based attacks. When they fail, everything is exposed. Here is what the major escapes reveal.]]></description>
      <link>https://safeguard.sh/resources/blog/browser-sandbox-escape-history</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/browser-sandbox-escape-history</guid>
      <pubDate>Fri, 06 Feb 2026 06:06:04 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to implement password policy best practices]]></title>
      <description><![CDATA[A step-by-step guide to implement password policy best practices: aligning with NIST guidelines, dropping outdated complexity rules, and rolling out passwordless authentication.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-implement-password-policy-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-implement-password-policy-best-practices</guid>
      <pubDate>Fri, 06 Feb 2026 06:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Confidential Computing: A New Trust Model for Software Supply Chains]]></title>
      <description><![CDATA[Confidential computing protects data in use through hardware-based enclaves. It could fundamentally change how we think about supply chain trust.]]></description>
      <link>https://safeguard.sh/resources/blog/confidential-computing-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/confidential-computing-supply-chain</guid>
      <pubDate>Fri, 06 Feb 2026 04:45:37 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is Secure by Default]]></title>
      <description><![CDATA[Secure by default means software ships in its safest state out of the box. See real breaches, standards, and pledges driving this shift.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-secure-by-default</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-secure-by-default</guid>
      <pubDate>Fri, 06 Feb 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Southeast Asia's Software Supply Chain Security Gap]]></title>
      <description><![CDATA[Southeast Asia's booming tech sector is building fast but securing slowly. Supply chain attacks targeting the region are increasing, and most organizations lack basic visibility into their dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/southeast-asia-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/southeast-asia-supply-chain-security</guid>
      <pubDate>Fri, 06 Feb 2026 03:25:10 GMT</pubDate>
      <category>Regional Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to set up endpoint detection and response (EDR)]]></title>
      <description><![CDATA[A step-by-step guide to setting up EDR across your fleet: choosing a platform, deploying agents, tuning policies, and verifying coverage before an incident tests it for you.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-set-up-endpoint-detection-and-response-edr</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-set-up-endpoint-detection-and-response-edr</guid>
      <pubDate>Fri, 06 Feb 2026 03:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Trivy vs Grype: Container Scanning Head-to-Head]]></title>
      <description><![CDATA[Compare Trivy and Grype on vulnerability database sources, scan speed, OS coverage, SBOM integration, and CI ergonomics to pick the right open source container scanner.]]></description>
      <link>https://safeguard.sh/resources/blog/trivy-vs-grype-container-scanning-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trivy-vs-grype-container-scanning-2023</guid>
      <pubDate>Fri, 06 Feb 2026 02:04:43 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is a Vulnerability Disclosure Program]]></title>
      <description><![CDATA[What a vulnerability disclosure program actually is, how it differs from a bug bounty, and what CISA, ISO, and the EU CRA now require of it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-vulnerability-disclosure-program</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-vulnerability-disclosure-program</guid>
      <pubDate>Fri, 06 Feb 2026 01:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Okta's Support System Breach: Identity Provider Under Fire Again]]></title>
      <description><![CDATA[Okta disclosed that attackers used stolen credentials to access its customer support system, downloading HAR files containing session tokens for multiple customers.]]></description>
      <link>https://safeguard.sh/resources/blog/okta-support-system-breach-october-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/okta-support-system-breach-october-2023</guid>
      <pubDate>Fri, 06 Feb 2026 00:44:17 GMT</pubDate>
      <category>Incident Response</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[CUPS CVE-2024-47176: Network RCE via IPP]]></title>
      <description><![CDATA[CVE-2024-47176 in cups-browsed lets attackers add rogue printers over UDP 631 and chain to RCE. Exploit flow, detection, and Linux distro impact.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-47176-cups-network-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-47176-cups-network-rce</guid>
      <pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Rust memory safety vulnerabilities despite the borrow che...]]></title>
      <description><![CDATA[The borrow checker doesn't stop everything. Here's how rust unsafe code vulnerabilities slip past Rust's safety guarantees and reach production.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-memory-safety-vulnerabilities-despite-the-borrow-checker-what-unsafe-blocks-still-allow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-memory-safety-vulnerabilities-despite-the-borrow-checker-what-unsafe-blocks-still-allow</guid>
      <pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CISO Quarterly Reporting Template: What the Board Actually Needs to See]]></title>
      <description><![CDATA[Most CISO board reports contain too many technical details and not enough business context. Here is a reporting template that communicates security posture in terms boards understand.]]></description>
      <link>https://safeguard.sh/resources/blog/ciso-quarterly-reporting-template</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ciso-quarterly-reporting-template</guid>
      <pubDate>Thu, 05 Feb 2026 23:23:50 GMT</pubDate>
      <category>Security Strategy</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[RSA Conference 2023 Supply Chain Track: Field Notes]]></title>
      <description><![CDATA[Five takeaways from the supply chain sessions at RSA Conference 2023, from SBOM adoption skepticism to attestation tooling and federal procurement pressure.]]></description>
      <link>https://safeguard.sh/resources/blog/rsa-conference-2023-supply-chain-track-notes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rsa-conference-2023-supply-chain-track-notes</guid>
      <pubDate>Thu, 05 Feb 2026 22:03:23 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Uber's Security Transformation Post-Breach]]></title>
      <description><![CDATA[How Uber rebuilt its security program after the 2016 data breach and the 2022 Lapsus$ compromise, with hard-won lessons about security culture and supply chain controls.]]></description>
      <link>https://safeguard.sh/resources/blog/uber-security-transformation-post-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uber-security-transformation-post-breach</guid>
      <pubDate>Thu, 05 Feb 2026 20:42:57 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[SBOMs for Embedded Systems: Firmware Transparency]]></title>
      <description><![CDATA[Embedded devices run for decades and rarely get patched. SBOMs bring transparency to firmware that the IoT industry desperately needs.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-embedded-systems</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-embedded-systems</guid>
      <pubDate>Thu, 05 Feb 2026 19:22:30 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Cisco IOS XE CVE-2023-20198: The Zero-Day That Compromised Tens of Thousands of Network Devices]]></title>
      <description><![CDATA[CVE-2023-20198 in Cisco IOS XE allowed unauthenticated attackers to create admin accounts on network devices. Over 40,000 devices were compromised before Cisco shipped a fix.]]></description>
      <link>https://safeguard.sh/resources/blog/cisco-ios-xe-webui-cve-2023-20198-implant</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisco-ios-xe-webui-cve-2023-20198-implant</guid>
      <pubDate>Thu, 05 Feb 2026 18:02:03 GMT</pubDate>
      <category>Zero-Day Exploits</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cisco IOS XE CVE-2023-20198: Tens of Thousands of Devices Implanted]]></title>
      <description><![CDATA[A critical zero-day in Cisco IOS XE's web UI allowed unauthenticated attackers to create admin accounts and deploy implants on over 40,000 devices worldwide.]]></description>
      <link>https://safeguard.sh/resources/blog/cisco-ios-xe-cve-2023-20198-implant</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisco-ios-xe-cve-2023-20198-implant</guid>
      <pubDate>Thu, 05 Feb 2026 16:41:37 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[TypeScript Security Best Practices]]></title>
      <description><![CDATA[How TypeScript's type system helps catch security bugs at compile time, and what it cannot protect you from.]]></description>
      <link>https://safeguard.sh/resources/blog/typescript-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/typescript-security-best-practices</guid>
      <pubDate>Thu, 05 Feb 2026 15:21:10 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How to Enable Dependency Review on GitHub PRs]]></title>
      <description><![CDATA[A step-by-step tutorial for turning on GitHub Dependency Review, enforcing license and severity policies, and getting fast feedback on every pull request.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-enable-github-dependency-review-on-prs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-enable-github-dependency-review-on-prs</guid>
      <pubDate>Thu, 05 Feb 2026 14:00:43 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Scratch vs Distroless: Choosing the Right Minimal Container Image]]></title>
      <description><![CDATA[Both scratch and distroless promise minimal attack surface. The right choice depends on your runtime, your debugging needs, and your tolerance for complexity.]]></description>
      <link>https://safeguard.sh/resources/blog/scratch-vs-distroless-minimal-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scratch-vs-distroless-minimal-images</guid>
      <pubDate>Thu, 05 Feb 2026 12:40:16 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[ISO 27001 Mapping: Griffin AI vs Mythos]]></title>
      <description><![CDATA[ISO 27001 Annex A has 93 controls in the 2022 revision, each needing documented evidence. Griffin AI emits records that map cleanly. Mythos-class pure-LLM tools force control owners to narrate.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-iso-27001-mapping</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-iso-27001-mapping</guid>
      <pubDate>Thu, 05 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[VEX Integration: Griffin AI vs Mythos]]></title>
      <description><![CDATA[VEX is how you turn a vulnerability list into an actionable work queue. Griffin AI ingests VEX documents as structured statements that filter findings at policy time. Mythos-class tools read them as advisory prose and lose the filtering entirely.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-vex-integration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-vex-integration</guid>
      <pubDate>Thu, 05 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[LLM Output Filtering as a Security Control]]></title>
      <description><![CDATA[Output filters are the last line before the user and the tool call. We cover when they work, when they fail, and how to measure them honestly in production.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-output-filtering-as-security-control</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-output-filtering-as-security-control</guid>
      <pubDate>Thu, 05 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Progressive Web App Security: The Risks Hiding in the Browser]]></title>
      <description><![CDATA[PWAs blur the line between websites and applications. Their security model is browser-based, which introduces different risks than native applications.]]></description>
      <link>https://safeguard.sh/resources/blog/progressive-web-app-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/progressive-web-app-security-guide</guid>
      <pubDate>Thu, 05 Feb 2026 11:19:50 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Federal Agency FedRAMP Evidence Pack in 30 Days]]></title>
      <description><![CDATA[An anonymized look at how a US federal civilian agency assembled a complete FedRAMP High supply chain evidence pack in 30 days using Safeguard.]]></description>
      <link>https://safeguard.sh/resources/blog/customer-story-federal-agency-fedramp-evidence-pack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/customer-story-federal-agency-fedramp-evidence-pack</guid>
      <pubDate>Thu, 05 Feb 2026 10:00:00 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[LLM Jailbreak as a Supply Chain Risk in 2026]]></title>
      <description><![CDATA[A jailbreak in a model you ship downstream is a supply chain incident, not a trivia item. Here is how to reason about it and where the defensive controls belong.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-jailbreak-as-supply-chain-risk-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-jailbreak-as-supply-chain-risk-2026</guid>
      <pubDate>Thu, 05 Feb 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM as a Product, Not a Checkbox]]></title>
      <description><![CDATA[Most SBOMs are generated, filed, and forgotten. Treating them as compliance artifacts rather than operational products is why they have not paid off — and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-as-a-product-not-a-checkbox-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-as-a-product-not-a-checkbox-2026</guid>
      <pubDate>Thu, 05 Feb 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Management Automation in 2026: Beyond Scanning]]></title>
      <description><![CDATA[Modern vulnerability management is shifting from periodic scanning to continuous, automated triage and remediation. Here's what that looks like in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-management-automation-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-management-automation-2026</guid>
      <pubDate>Thu, 05 Feb 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What is Risk-Based Vulnerability Prioritization]]></title>
      <description><![CDATA[CVSS alone can't sort 40,000 CVEs a year. Learn how reachability, EPSS, and KEV data cut real risk from noise.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-risk-based-vulnerability-prioritization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-risk-based-vulnerability-prioritization</guid>
      <pubDate>Thu, 05 Feb 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Insecure Deserialization: Why Untrusted Data Should Never Become Objects]]></title>
      <description><![CDATA[Deserialization vulnerabilities turn data into code execution. Here is how they work, which languages are most affected, and how to defend against them.]]></description>
      <link>https://safeguard.sh/resources/blog/insecure-deserialization-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/insecure-deserialization-prevention</guid>
      <pubDate>Thu, 05 Feb 2026 09:59:23 GMT</pubDate>
      <category>Code Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[AWS ECR Signing Policies with Notation]]></title>
      <description><![CDATA[ECR now supports Notation-based image signing and trust policy enforcement. Here is how to design signing policies that survive scale and auditors.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-ecr-signing-policies-notation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-ecr-signing-policies-notation</guid>
      <pubDate>Thu, 05 Feb 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cargo supply chain attacks: typosquatting and malicious c...]]></title>
      <description><![CDATA[Crates.io typosquatting tricks Rust developers into pulling malicious crates instead of trusted ones. Here's how these attacks work — and how to spot them before you build.]]></description>
      <link>https://safeguard.sh/resources/blog/cargo-supply-chain-attacks-typosquatting-and-malicious-crates-on-cratesio</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cargo-supply-chain-attacks-typosquatting-and-malicious-crates-on-cratesio</guid>
      <pubDate>Thu, 05 Feb 2026 09:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Abandoned Dependency Risk Study]]></title>
      <description><![CDATA[The Safeguard Research team measured how much abandonment exists in real dependency graphs, how it correlates with risk, and what to do about it.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-research-abandoned-dependency-risk-study</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-research-abandoned-dependency-risk-study</guid>
      <pubDate>Thu, 05 Feb 2026 09:00:00 GMT</pubDate>
      <category>Research</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Incident Response Tabletop Exercises: A Practical Guide for Supply Chain Scenarios]]></title>
      <description><![CDATA[Your incident response plan is untested until people have walked through it under pressure. Here is how to design and run tabletop exercises that actually prepare your team for supply chain compromises.]]></description>
      <link>https://safeguard.sh/resources/blog/incident-response-tabletop-exercises-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/incident-response-tabletop-exercises-guide</guid>
      <pubDate>Thu, 05 Feb 2026 08:38:56 GMT</pubDate>
      <category>Incident Response</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[curl CVE-2023-38545: The Worst curl Vulnerability in Years]]></title>
      <description><![CDATA[A heap buffer overflow in curl's SOCKS5 proxy handshake earned a severity rating of HIGH from curl's creator Daniel Stenberg, who called it the worst curl flaw in a long time.]]></description>
      <link>https://safeguard.sh/resources/blog/curl-cve-2023-38545-heap-buffer-overflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/curl-cve-2023-38545-heap-buffer-overflow</guid>
      <pubDate>Thu, 05 Feb 2026 07:18:30 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Using cargo-audit and the RustSec Advisory Database to ca...]]></title>
      <description><![CDATA[A hands-on cargo-audit tutorial: scan Rust dependencies against the RustSec advisory database, interpret results, and block vulnerable crates before they ship.]]></description>
      <link>https://safeguard.sh/resources/blog/using-cargo-audit-and-the-rustsec-advisory-database-to-catch-vulnerable-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/using-cargo-audit-and-the-rustsec-advisory-database-to-catch-vulnerable-dependencies</guid>
      <pubDate>Thu, 05 Feb 2026 06:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[HTTP/2 Rapid Reset: The Largest DDoS Attacks in Internet History]]></title>
      <description><![CDATA[CVE-2023-44487 exploits a design flaw in HTTP/2 to amplify DDoS attacks, enabling record-breaking attacks peaking at 398 million requests per second.]]></description>
      <link>https://safeguard.sh/resources/blog/http2-rapid-reset-cve-2023-44487-ddos</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/http2-rapid-reset-cve-2023-44487-ddos</guid>
      <pubDate>Thu, 05 Feb 2026 05:58:03 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Scattered Spider: The Social Engineering Group That Outmaneuvered Enterprise Security]]></title>
      <description><![CDATA[Scattered Spider combined aggressive social engineering with deep knowledge of enterprise IT to breach MGM Resorts, Caesars Entertainment, and dozens of other organizations.]]></description>
      <link>https://safeguard.sh/resources/blog/scattered-spider-social-engineering-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scattered-spider-social-engineering-attacks</guid>
      <pubDate>Thu, 05 Feb 2026 04:37:36 GMT</pubDate>
      <category>Threat Actors</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is a False Positive in Security Scanning]]></title>
      <description><![CDATA[False positives waste security team hours flagging vulnerabilities that aren't actually exploitable. Here's how to spot, measure, and reduce them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-false-positive-in-security-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-false-positive-in-security-scanning</guid>
      <pubDate>Thu, 05 Feb 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Open Source vs Commercial SCA Tools: An Honest Comparison]]></title>
      <description><![CDATA[Free SCA tools have gotten remarkably good. Commercial tools still offer advantages. Here is when each makes sense for your organization.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-vs-commercial-sca</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-vs-commercial-sca</guid>
      <pubDate>Thu, 05 Feb 2026 03:17:10 GMT</pubDate>
      <category>Security Strategy</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Auditing unsafe Rust FFI boundaries for memory corruption...]]></title>
      <description><![CDATA[A step-by-step rust ffi security audit: map unsafe boundaries, fuzz with cargo-fuzz, run Miri and sanitizers, and verify ownership to catch memory corruption before shipping.]]></description>
      <link>https://safeguard.sh/resources/blog/auditing-unsafe-rust-ffi-boundaries-for-memory-corruption-bugs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/auditing-unsafe-rust-ffi-boundaries-for-memory-corruption-bugs</guid>
      <pubDate>Thu, 05 Feb 2026 03:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cloud-Native Application Protection: Beyond the Buzzword]]></title>
      <description><![CDATA[CNAPP promises unified cloud security. Here is what it actually delivers, where it falls short, and how to evaluate platforms honestly.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-native-application-protection-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-native-application-protection-guide</guid>
      <pubDate>Thu, 05 Feb 2026 01:56:43 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Noise Reduction in AppSec Tooling]]></title>
      <description><![CDATA[Most AppSec scans return thousands of findings, but under 5% are ever reachable in production. Here's how noise reduction actually works.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-noise-reduction-in-appsec-tooling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-noise-reduction-in-appsec-tooling</guid>
      <pubDate>Thu, 05 Feb 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Package Registry Mirroring: Security Benefits and Hidden Risks]]></title>
      <description><![CDATA[Mirroring npm, PyPI, or Maven Central locally reduces dependency on external infrastructure. But mirrors introduce their own security considerations that most teams overlook.]]></description>
      <link>https://safeguard.sh/resources/blog/package-registry-mirroring-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/package-registry-mirroring-security</guid>
      <pubDate>Thu, 05 Feb 2026 00:36:16 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Cargo.lock integrity and reproducible builds as a supply ...]]></title>
      <description><![CDATA[Cargo.lock pins your dependency tree, but only reproducible builds prove the binary you ship matches the source you reviewed and approved.]]></description>
      <link>https://safeguard.sh/resources/blog/cargolock-integrity-and-reproducible-builds-as-a-supply-chain-defense</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cargolock-integrity-and-reproducible-builds-as-a-supply-chain-defense</guid>
      <pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Solana web3.js npm Backdoor: Dec 2024 Post-Mortem]]></title>
      <description><![CDATA[A phished maintainer token pushed a private-key-stealing backdoor into @solana/web3.js 1.95.6/1.95.7. Full mechanics and post-incident recommendations.]]></description>
      <link>https://safeguard.sh/resources/blog/solana-web3-js-npm-backdoor-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/solana-web3-js-npm-backdoor-2024</guid>
      <pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Python setuptools Security Considerations]]></title>
      <description><![CDATA[setuptools is the default Python packaging backend and its security properties matter for anyone who builds, installs, or runs Python code. Here is what to watch.]]></description>
      <link>https://safeguard.sh/resources/blog/python-setuptools-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-setuptools-security-considerations</guid>
      <pubDate>Wed, 04 Feb 2026 23:15:50 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Zero Trust for Developer Workstations: Rethinking Endpoint Security]]></title>
      <description><![CDATA[Developer workstations have elevated access to source code, build systems, and deployment pipelines. Zero Trust principles applied to these endpoints significantly reduce supply chain attack surface.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-trust-developer-workstations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-trust-developer-workstations</guid>
      <pubDate>Wed, 04 Feb 2026 21:55:23 GMT</pubDate>
      <category>Network Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSF Scorecard v5: Raising the Bar for Open Source Security]]></title>
      <description><![CDATA[The latest release of OpenSSF Scorecard introduces new checks and improved accuracy, helping organizations make data-driven decisions about open source dependency risk.]]></description>
      <link>https://safeguard.sh/resources/blog/openssf-scorecard-v5-release</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssf-scorecard-v5-release</guid>
      <pubDate>Wed, 04 Feb 2026 20:34:56 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Authorization Vulnerabilities: Prevention and Best Practices]]></title>
      <description><![CDATA[Authorization flaws let authenticated users access resources and perform actions beyond their intended permissions. Learn the most common authorization vulnerabilities and how to build robust access control systems.]]></description>
      <link>https://safeguard.sh/resources/blog/authorization-vulnerabilities-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/authorization-vulnerabilities-prevention</guid>
      <pubDate>Wed, 04 Feb 2026 19:14:29 GMT</pubDate>
      <category>Web Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[When Observability Meets Security: The Convergence That Changes Everything]]></title>
      <description><![CDATA[Observability and security have operated in silos for too long. Their convergence creates capabilities that neither could achieve alone.]]></description>
      <link>https://safeguard.sh/resources/blog/observability-security-convergence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/observability-security-convergence</guid>
      <pubDate>Wed, 04 Feb 2026 17:54:03 GMT</pubDate>
      <category>Industry Trends</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[JetBrains TeamCity CVE-2023-42793: When Your Build Server Becomes the Attack Vector]]></title>
      <description><![CDATA[A critical authentication bypass in TeamCity allowed unauthenticated attackers to gain admin access to CI/CD servers. State-sponsored groups exploited it to compromise software supply chains.]]></description>
      <link>https://safeguard.sh/resources/blog/jetbrains-teamcity-cve-2023-42793-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jetbrains-teamcity-cve-2023-42793-exploitation</guid>
      <pubDate>Wed, 04 Feb 2026 16:33:36 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[OWASP Top 10 for LLM Applications: A First Look]]></title>
      <description><![CDATA[OWASP published its first Top 10 for LLM Applications on August 1, 2023. Here is what it covers, where it overreaches, and how to use it on real systems.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-for-llm-applications-first-look</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-for-llm-applications-first-look</guid>
      <pubDate>Wed, 04 Feb 2026 15:13:09 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[JSON Parsing Library Vulnerabilities You Should Know About]]></title>
      <description><![CDATA[JSON is the lingua franca of APIs, but the libraries that parse it have had serious security issues. Here is what to watch for in your stack.]]></description>
      <link>https://safeguard.sh/resources/blog/json-parsing-library-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/json-parsing-library-vulnerabilities</guid>
      <pubDate>Wed, 04 Feb 2026 13:52:43 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Webpack vs Rollup vs esbuild: A Security Comparison]]></title>
      <description><![CDATA[Choosing a bundler is usually about speed and features. Here is how Webpack, Rollup, and esbuild compare on the dimension that matters most for supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/webpack-rollup-esbuild-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webpack-rollup-esbuild-security</guid>
      <pubDate>Wed, 04 Feb 2026 12:32:16 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[ToxicSkills: When Claude Skills Become a Malware Distribution Channel]]></title>
      <description><![CDATA[Snyk's ToxicSkills research found prompt injection in 36% of Claude skills tested and 1,467 malicious payloads. The SKILL.md trust model is the structural issue.]]></description>
      <link>https://safeguard.sh/resources/blog/claude-skills-toxicskills-malicious-payloads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/claude-skills-toxicskills-malicious-payloads</guid>
      <pubDate>Wed, 04 Feb 2026 12:00:00 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Inflection Pi for Security Assistance]]></title>
      <description><![CDATA[]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-inflection-pi-for-security-assistance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-inflection-pi-for-security-assistance</guid>
      <pubDate>Wed, 04 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Path Traversal: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Path traversal is the vulnerability class that punishes lazy analysis. Framework-specific path normalisation, OS-dependent separators, symbolic link resolution, and archive extraction all hide exploitable gaps behind code that looks defensive. Griffin's engine resolves path operations with actual semantics; Mythos reads the variable name and calls it a day.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-path-traversal-cases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-path-traversal-cases</guid>
      <pubDate>Wed, 04 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Refusal Rate Analysis: Griffin AI vs Mythos]]></title>
      <description><![CDATA[A security AI that refuses too often is useless. One that refuses too rarely is dangerous. Griffin AI publishes calibrated refusal benchmarks; Mythos does not.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-refusal-rate-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-refusal-rate-analysis</guid>
      <pubDate>Wed, 04 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[IBM Cloud Code Engine: A Supply Chain Defender's Walkthrough]]></title>
      <description><![CDATA[Code Engine abstracts away Kubernetes for Knative-style serverless workloads on IBM Cloud. The supply chain story is different from what most defenders bring from AWS or GCP.]]></description>
      <link>https://safeguard.sh/resources/blog/ibm-cloud-code-engine-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ibm-cloud-code-engine-supply-chain-2026</guid>
      <pubDate>Wed, 04 Feb 2026 12:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Inside PyPI Project Quarantine: How the Reversible Takedown Workflow Has Performed Since Launch]]></title>
      <description><![CDATA[PyPI's Project Quarantine status, introduced in August 2024 and used roughly 140 times in its first year, replaces irreversible deletions with a reversible hidden state. Here is how the workflow operates and how to consume the signal.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-project-quarantine-operations-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-project-quarantine-operations-2026</guid>
      <pubDate>Wed, 04 Feb 2026 12:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SEC Form 8-K Item 1.05: Two Years of Enforcement Lessons]]></title>
      <description><![CDATA[Two years into mandatory cybersecurity incident disclosure, the SEC has issued comment letter sweeps and settled enforcement actions. Here is what filers got wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/sec-form-8k-item-105-enforcement-actions-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sec-form-8k-item-105-enforcement-actions-2026</guid>
      <pubDate>Wed, 04 Feb 2026 12:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx SCA: Application Security from a SAST Pioneer]]></title>
      <description><![CDATA[A review of Checkmarx SCA covering its integration with the broader Checkmarx AST platform, vulnerability detection, and exploitability analysis capabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-sca-platform-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-sca-platform-review</guid>
      <pubDate>Wed, 04 Feb 2026 11:11:49 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Wiz vs Prisma Cloud in 2026]]></title>
      <description><![CDATA[Two CNAPPs at the top of every shortlist, and they are not interchangeable. A detailed look at agentless coverage, runtime depth, pricing pressure, and deployment realities.]]></description>
      <link>https://safeguard.sh/resources/blog/wiz-vs-prisma-cloud-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wiz-vs-prisma-cloud-2026</guid>
      <pubDate>Wed, 04 Feb 2026 10:30:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Container Runtime Showdown: runc vs crun vs gVisor in 2026]]></title>
      <description><![CDATA[A practical comparison of runc, crun, and gVisor across performance, isolation, and operational fit, with concrete guidance on when each runtime earns its place in production.]]></description>
      <link>https://safeguard.sh/resources/blog/container-runtime-runc-vs-crun-vs-gvisor-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-runtime-runc-vs-crun-vs-gvisor-2026</guid>
      <pubDate>Wed, 04 Feb 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Event-Stream npm 2018: Package Trust Lessons That Still Apply]]></title>
      <description><![CDATA[The event-stream npm incident remains the cleanest case study in maintainer-handoff risk. What it taught the ecosystem, and what we still ignore in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/event-stream-npm-2018-package-trust-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/event-stream-npm-2018-package-trust-lessons</guid>
      <pubDate>Wed, 04 Feb 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[FAQ: CycloneDX vs SPDX — Which to Use?]]></title>
      <description><![CDATA[Practical answers to the most common CycloneDX vs SPDX questions: differences, tooling, regulatory preference, VEX support, and when to emit both.]]></description>
      <link>https://safeguard.sh/resources/blog/faq-sbom-format-choice-cyclonedx-vs-spdx</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/faq-sbom-format-choice-cyclonedx-vs-spdx</guid>
      <pubDate>Wed, 04 Feb 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Getting Started with Safeguard MCP + Claude Desktop]]></title>
      <description><![CDATA[Connect the Safeguard MCP server to Claude Desktop so your AI assistant can scan dependencies, read SBOMs, and suggest fixes grounded in real advisory data.]]></description>
      <link>https://safeguard.sh/resources/blog/getting-started-safeguard-mcp-with-claude-desktop</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/getting-started-safeguard-mcp-with-claude-desktop</guid>
      <pubDate>Wed, 04 Feb 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Leaky Vessels: The runc Container Escape Class (2024)]]></title>
      <description><![CDATA[Leaky Vessels bundled four CVEs that let container processes escape into the host. Two years later the class is still mispatched and misunderstood.]]></description>
      <link>https://safeguard.sh/resources/blog/leaky-vessels-runc-container-escape-class-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/leaky-vessels-runc-container-escape-class-2024</guid>
      <pubDate>Wed, 04 Feb 2026 10:00:00 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Progress WS_FTP CVE-2023-40044: Another File Transfer Platform Falls to Pre-Auth RCE]]></title>
      <description><![CDATA[A critical deserialization vulnerability in Progress WS_FTP Server allowed unauthenticated RCE. Coming after MOVEit, it proved that file transfer platforms remain a systemic weak point.]]></description>
      <link>https://safeguard.sh/resources/blog/progress-ws-ftp-cve-2023-40044-critical</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/progress-ws-ftp-cve-2023-40044-critical</guid>
      <pubDate>Wed, 04 Feb 2026 09:51:23 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Firecracker vs Cloud Hypervisor vs Kata Containers: 2026 Buyer Guide]]></title>
      <description><![CDATA[A practical comparison of Firecracker, Cloud Hypervisor, and Kata Containers across boot time, memory overhead, security boundary, and operational fit for serverless and multi-tenant workloads.]]></description>
      <link>https://safeguard.sh/resources/blog/firecracker-vs-cloud-hypervisor-vs-kata-buyer-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/firecracker-vs-cloud-hypervisor-vs-kata-buyer-guide-2026</guid>
      <pubDate>Wed, 04 Feb 2026 09:30:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[How to Set Your Git Username and Email (and Why It Matters for Security)]]></title>
      <description><![CDATA[Your Git username and email stamp every commit you make. Here is how to configure them correctly across global and per-repo scopes, and why they matter for trust and audit.]]></description>
      <link>https://safeguard.sh/resources/blog/git-username-and-email</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-username-and-email</guid>
      <pubDate>Wed, 04 Feb 2026 09:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Advanced Security vs Snyk vs Safeguard 2026]]></title>
      <description><![CDATA[A side-by-side evaluation of GHAS, Snyk, and Safeguard across SCA depth, reachability, SBOM, policy gating, and the operational realities of running each at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/github-advanced-security-vs-snyk-vs-safeguard-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-advanced-security-vs-snyk-vs-safeguard-2026</guid>
      <pubDate>Wed, 04 Feb 2026 09:30:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Implementing the ISO 27001:2022 Revision in 2026]]></title>
      <description><![CDATA[The transition window to the 2022 revision of ISO 27001 closed in October 2025. Here is what we have learned from helping organizations implement it cleanly.]]></description>
      <link>https://safeguard.sh/resources/blog/iso-27001-2022-revision-implementation-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iso-27001-2022-revision-implementation-2026</guid>
      <pubDate>Wed, 04 Feb 2026 09:30:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Sigstore Rekor Transparency Log Deep Dive 2026]]></title>
      <description><![CDATA[How Rekor actually works in 2026, the trade-offs of the current Merkle tree design, witness diversity, and the operational realities of verifying inclusion at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/sigstore-rekor-transparency-log-deep-dive-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sigstore-rekor-transparency-log-deep-dive-2026</guid>
      <pubDate>Wed, 04 Feb 2026 09:30:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Case study: crates.io maintainer account takeover and mal...]]></title>
      <description><![CDATA[How a compromised maintainer credential becomes a crates.io account takeover and a malicious crate version in the Rust software supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/case-study-cratesio-maintainer-account-takeover-and-malicious-crate-versions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/case-study-cratesio-maintainer-account-takeover-and-malicious-crate-versions</guid>
      <pubDate>Wed, 04 Feb 2026 09:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[RASP vs IAST: Which to Deploy in 2026]]></title>
      <description><![CDATA[A practical comparison of Runtime Application Self-Protection and Interactive Application Security Testing for 2026, with deployment guidance based on real-world tradeoffs.]]></description>
      <link>https://safeguard.sh/resources/blog/rasp-vs-iast-which-to-deploy-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rasp-vs-iast-which-to-deploy-2026</guid>
      <pubDate>Wed, 04 Feb 2026 09:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Lion 2.0: Multi-Jurisdiction Compliance]]></title>
      <description><![CDATA[Lion 2.0 is Safeguard's compliance model. The 2.0 release adds multi-jurisdiction mapping, control-level evidence, and a new export for audit packages.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-lion-2-0-release-compliance-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-lion-2-0-release-compliance-model</guid>
      <pubDate>Wed, 04 Feb 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Ingestion at Scale: An Architecture Guide]]></title>
      <description><![CDATA[A pragmatic architecture for ingesting, normalizing, and querying hundreds of thousands of SBOMs across an enterprise or agency, without drowning in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-ingestion-at-scale-architecture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-ingestion-at-scale-architecture</guid>
      <pubDate>Wed, 04 Feb 2026 09:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SEC Cyber Incident Disclosure Rule: Year Two]]></title>
      <description><![CDATA[Two years into Item 1.05 of Form 8-K, the SEC has clarified materiality, enforcement posture, and how Regulation S-K Item 106 cybersecurity narratives will be judged.]]></description>
      <link>https://safeguard.sh/resources/blog/sec-cybersecurity-incident-disclosure-rule-year-two</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sec-cybersecurity-incident-disclosure-rule-year-two</guid>
      <pubDate>Wed, 04 Feb 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Designing a Vulnerability Triage Workflow That Works]]></title>
      <description><![CDATA[Most vulnerability triage processes are broken. Here is how to design a workflow that reduces noise, routes issues to the right owners, and actually gets things fixed.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-triage-workflow-design</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-triage-workflow-design</guid>
      <pubDate>Wed, 04 Feb 2026 08:30:56 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Does GitHub Copilot Use Your Code? IP and Licensing Questions Answered]]></title>
      <description><![CDATA[Does GitHub Copilot steal your code, or just learn patterns from it? The honest answer depends on which setting you're using, what plan you're on, and whether the suggestion it hands back matches code it was trained on.]]></description>
      <link>https://safeguard.sh/resources/blog/does-github-copilot-use-your-code-ip-and-licensing-questions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/does-github-copilot-use-your-code-ip-and-licensing-questions</guid>
      <pubDate>Wed, 04 Feb 2026 08:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Securing LLM Applications: The OWASP Top 10 for Large Language Models]]></title>
      <description><![CDATA[OWASP released its Top 10 for LLM Applications in August 2023, providing the first standardized framework for understanding and mitigating risks in AI-powered software.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-llm-applications-owasp-top-10</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-llm-applications-owasp-top-10</guid>
      <pubDate>Wed, 04 Feb 2026 07:10:29 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What is Binary Composition Analysis]]></title>
      <description><![CDATA[Binary composition analysis identifies open source components inside compiled artifacts—no source code needed. Here's how it works and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-binary-composition-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-binary-composition-analysis</guid>
      <pubDate>Wed, 04 Feb 2026 07:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Go module proxy security: how GOPROXY and sum.golang.org ...]]></title>
      <description><![CDATA[How GOPROXY and sum.golang.org protect Go builds with caching and checksum verification, and where trust-on-first-use gaps let malicious modules slip through.]]></description>
      <link>https://safeguard.sh/resources/blog/go-module-proxy-security-how-goproxy-and-sumgolangorg-protect-and-can-fail-integrity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-module-proxy-security-how-goproxy-and-sumgolangorg-protect-and-can-fail-integrity</guid>
      <pubDate>Wed, 04 Feb 2026 06:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Storage and Distribution Infrastructure]]></title>
      <description><![CDATA[Generating SBOMs is solved. Storing, versioning, and distributing them at scale is the next engineering challenge.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-storage-distribution-infrastructure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-storage-distribution-infrastructure</guid>
      <pubDate>Wed, 04 Feb 2026 05:50:03 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Spring Boot Security and Dependency Management]]></title>
      <description><![CDATA[Securing Spring Boot applications with dependency management BOMs, vulnerability scanning, and hardened configurations.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-boot-security-dependency-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-boot-security-dependency-management</guid>
      <pubDate>Wed, 04 Feb 2026 04:29:36 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is License Scanning]]></title>
      <description><![CDATA[License scanning finds every open source license in your dependency tree before it becomes a legal or compliance problem — here's how it works and why it changed in 2024.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-license-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-license-scanning</guid>
      <pubDate>Wed, 04 Feb 2026 04:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[AI Hallucinations Meet Package Confusion: A New Class of Supply Chain Attack]]></title>
      <description><![CDATA[When LLMs hallucinate package names that don't exist, attackers can register them. This supply chain attack vector is already being exploited in the wild.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-hallucination-package-confusion-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-hallucination-package-confusion-attacks</guid>
      <pubDate>Wed, 04 Feb 2026 03:09:09 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Typosquatting and malicious Go modules published to pkg.g...]]></title>
      <description><![CDATA[How malicious Go modules exploit pkg.go.dev's open publishing model, real typosquatting attacks like steelpoor/tlsproxy, and why Go's module proxy makes cleanup so hard.]]></description>
      <link>https://safeguard.sh/resources/blog/typosquatting-and-malicious-go-modules-published-to-pkggodev</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/typosquatting-and-malicious-go-modules-published-to-pkggodev</guid>
      <pubDate>Wed, 04 Feb 2026 03:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[SBOM for the Gaming Industry: Why Game Studios Need Software Transparency]]></title>
      <description><![CDATA[Game studios ship millions of lines of code with complex dependency chains across engines, middleware, and third-party SDKs. SBOMs are not just a compliance tool — they are an operational necessity.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-gaming-industry</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-gaming-industry</guid>
      <pubDate>Wed, 04 Feb 2026 01:48:42 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is a Private Package Registry]]></title>
      <description><![CDATA[A private package registry controls who can publish and pull internal and third-party code — but only if it's configured to block, not just cache, public fallback resolution.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-private-package-registry</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-private-package-registry</guid>
      <pubDate>Wed, 04 Feb 2026 01:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Tooling Landscape in 2023: What Actually Works]]></title>
      <description><![CDATA[The SBOM tooling ecosystem has matured significantly, but choosing the right tools still requires understanding the tradeoffs between formats, generators, and analysis platforms.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-tooling-landscape-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-tooling-landscape-2023</guid>
      <pubDate>Wed, 04 Feb 2026 00:28:16 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[State of Vulnerability Management 2026 Report]]></title>
      <description><![CDATA[Where vulnerability management actually stands in 2026: KEV-driven prioritization, reachability, SLAs that hold, and the tools teams are consolidating onto.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-vulnerability-management-2026-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-vulnerability-management-2026-report</guid>
      <pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Python Packaging Authority and the Security of pip install]]></title>
      <description><![CDATA[Every pip install is a trust decision. The Python Packaging Authority has spent years hardening the ecosystem, but the attack surface remains vast and the threat actors are persistent.]]></description>
      <link>https://safeguard.sh/resources/blog/python-packaging-authority-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-packaging-authority-security</guid>
      <pubDate>Tue, 03 Feb 2026 23:07:49 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Microsoft's Secure Supply Chain Practices]]></title>
      <description><![CDATA[How Microsoft rebuilt its security posture after years of high-profile incidents, implementing supply chain controls that now protect one of the world's largest software ecosystems.]]></description>
      <link>https://safeguard.sh/resources/blog/microsoft-secure-supply-chain-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microsoft-secure-supply-chain-practices</guid>
      <pubDate>Tue, 03 Feb 2026 21:47:22 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MGM Resorts and Caesars Hit by Scattered Spider: Social Engineering at Scale]]></title>
      <description><![CDATA[In September 2023, the Scattered Spider hacking group crippled MGM Resorts and extorted Caesars Entertainment through phone-based social engineering, exposing how human vulnerabilities can bypass even the most expensive security stacks.]]></description>
      <link>https://safeguard.sh/resources/blog/mgm-resorts-caesars-scattered-spider-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mgm-resorts-caesars-scattered-spider-2023</guid>
      <pubDate>Tue, 03 Feb 2026 20:26:56 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Electron App Supply Chain Security Posture]]></title>
      <description><![CDATA[Electron apps ship Chromium, Node.js, and your entire npm tree to a user's desktop, running with the privileges of the logged-in user. The supply chain implications are severe enough that they deserve their own category of threat model.]]></description>
      <link>https://safeguard.sh/resources/blog/electron-app-supply-chain-security-posture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/electron-app-supply-chain-security-posture</guid>
      <pubDate>Tue, 03 Feb 2026 19:06:29 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Dependabot Security Updates: Behavior Deep Dive]]></title>
      <description><![CDATA[A hands-on look at how Dependabot security updates behave in 2023 - PR grouping, semver strategy, transitive coverage, and alternatives when it misses a fix.]]></description>
      <link>https://safeguard.sh/resources/blog/dependabot-security-updates-behavior-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependabot-security-updates-behavior-2023</guid>
      <pubDate>Tue, 03 Feb 2026 17:46:02 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Building a Supply Chain Security Metrics Dashboard That Drives Action]]></title>
      <description><![CDATA[Most security dashboards display data nobody acts on. Here is how to build supply chain metrics that actually drive security improvement.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-metrics-dashboard</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-metrics-dashboard</guid>
      <pubDate>Tue, 03 Feb 2026 16:25:36 GMT</pubDate>
      <category>Security Operations</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Packages Security Features: What You Get and What You Do Not]]></title>
      <description><![CDATA[GitHub Packages integrates tightly with GitHub Actions and repositories. Its security features are convenient but have gaps that teams need to understand.]]></description>
      <link>https://safeguard.sh/resources/blog/github-packages-security-features</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-packages-security-features</guid>
      <pubDate>Tue, 03 Feb 2026 15:05:09 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Dart/Flutter Dependency Security: Securing the Mobile Supply Chain]]></title>
      <description><![CDATA[Flutter's pub ecosystem is growing fast. The security tooling has not kept pace. Here is what you need to know about securing Dart dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/dart-flutter-dependency-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dart-flutter-dependency-security</guid>
      <pubDate>Tue, 03 Feb 2026 13:44:42 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Canada's Cybersecurity Strategy and the Push for SBOM Adoption]]></title>
      <description><![CDATA[Canada is integrating software supply chain security into its national cyber strategy. Here's where SBOMs fit in and what's coming next.]]></description>
      <link>https://safeguard.sh/resources/blog/canada-cyber-security-strategy-sbom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/canada-cyber-security-strategy-sbom</guid>
      <pubDate>Tue, 03 Feb 2026 12:24:16 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise LLM Budget Management Patterns]]></title>
      <description><![CDATA[LLM spend forecasting is where finance teams meet AI engineering for the first time. The patterns that produce predictability are specific.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-llm-budget-management-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-llm-budget-management-patterns</guid>
      <pubDate>Tue, 03 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs DeepSeek Coder for Security Review]]></title>
      <description><![CDATA[DeepSeek Coder has become a favourite for code-focused workloads. This is how it compares to Griffin AI when the job is security review, not code generation.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-deepseek-coder-for-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-deepseek-coder-for-security-review</guid>
      <pubDate>Tue, 03 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Exploit Path Synthesis: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Finding a bug is not the same as proving it is exploitable. How Griffin AI synthesises concrete exploit paths and why pure-LLM scanners rarely get past the sketch stage.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-exploit-path-synthesis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-exploit-path-synthesis</guid>
      <pubDate>Tue, 03 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Throughput At Scale: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Engine work parallelises cleanly. Model calls do not. We explain why Griffin AI's throughput scales with CPU while Mythos-class tools bottleneck on rate limits.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-throughput-at-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-throughput-at-scale</guid>
      <pubDate>Tue, 03 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[API Security Through the Supply Chain Lens]]></title>
      <description><![CDATA[APIs are both an attack surface and a supply chain dependency. This guide examines API security risks from authentication to third-party integrations.]]></description>
      <link>https://safeguard.sh/resources/blog/api-security-supply-chain-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/api-security-supply-chain-considerations</guid>
      <pubDate>Tue, 03 Feb 2026 11:03:49 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Dependabot Security Update Policies for 2026]]></title>
      <description><![CDATA[A pragmatic guide to configuring Dependabot for security updates: which knobs matter, which defaults are wrong, and how to avoid drowning teams in PRs.]]></description>
      <link>https://safeguard.sh/resources/blog/dependabot-security-update-policies-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependabot-security-update-policies-2026</guid>
      <pubDate>Tue, 03 Feb 2026 11:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[RAG Pipeline Supply Chain Attacks: Vector DBs and More]]></title>
      <description><![CDATA[RAG pipelines have six or seven supply chain surfaces, and most teams are only watching one. Here is how the attacks actually look in production.]]></description>
      <link>https://safeguard.sh/resources/blog/rag-pipeline-supply-chain-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rag-pipeline-supply-chain-attacks</guid>
      <pubDate>Tue, 03 Feb 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Artifact Repository Security]]></title>
      <description><![CDATA[Artifact repositories are prime attack targets — one poisoned package reaches every downstream consumer. Here's what actually secures them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-artifact-repository-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-artifact-repository-security</guid>
      <pubDate>Tue, 03 Feb 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Automated Zero-Day Discovery: How AI Is Changing Vulnerability Research]]></title>
      <description><![CDATA[AI-powered fuzzing and code analysis are accelerating zero-day discovery. Here's what that means for defenders.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-day-discovery-automated-approaches</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-day-discovery-automated-approaches</guid>
      <pubDate>Tue, 03 Feb 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[gRPC Security Considerations: Protecting High-Performance Service Communication]]></title>
      <description><![CDATA[gRPC's binary protocol and HTTP/2 transport make it fast. They also make it harder to inspect, monitor, and secure than REST APIs. Here is what you need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/grpc-security-considerations-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/grpc-security-considerations-guide</guid>
      <pubDate>Tue, 03 Feb 2026 09:43:22 GMT</pubDate>
      <category>API Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[PwnKit Five Years On: Why CVE-2021-4034 Still Lives in Production]]></title>
      <description><![CDATA[PwnKit was a trivial local privilege escalation in polkit that affected nearly every Linux distribution for over a decade. The technical details and the residual risk in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/polkit-pwnkit-cve-2021-4034-impact-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/polkit-pwnkit-cve-2021-4034-impact-review</guid>
      <pubDate>Tue, 03 Feb 2026 09:15:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Goroutine leaks and data races as denial-of-service and s...]]></title>
      <description><![CDATA[Goroutine leaks and data races aren't just bugs — they're exploitable DoS and logic-corruption vectors. Here's how they work, real incidents, and how Safeguard catches them.]]></description>
      <link>https://safeguard.sh/resources/blog/goroutine-leaks-and-data-races-as-denial-of-service-and-security-vectors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/goroutine-leaks-and-data-races-as-denial-of-service-and-security-vectors</guid>
      <pubDate>Tue, 03 Feb 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[OCI + CNCF Image Supply Chain: 2026 Snapshot]]></title>
      <description><![CDATA[Where the OCI and CNCF image supply chain ecosystem actually sits in 2026, what has stabilized, what is still contested, and what to deploy now versus later.]]></description>
      <link>https://safeguard.sh/resources/blog/ocid-cncf-image-supply-chain-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ocid-cncf-image-supply-chain-2026</guid>
      <pubDate>Tue, 03 Feb 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SLSA v1.0: Software Provenance Attestation Goes Mainstream]]></title>
      <description><![CDATA[The SLSA framework reached v1.0 in April 2023, providing a practical framework for software supply chain integrity that's already being adopted by major package registries.]]></description>
      <link>https://safeguard.sh/resources/blog/software-provenance-attestation-slsa-v1</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-provenance-attestation-slsa-v1</guid>
      <pubDate>Tue, 03 Feb 2026 08:22:55 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Edge Computing and the Distributed Supply Chain Security Challenge]]></title>
      <description><![CDATA[As compute moves to the edge, software supply chain security must adapt to environments with limited visibility, constrained resources, and vast attack surfaces.]]></description>
      <link>https://safeguard.sh/resources/blog/edge-computing-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/edge-computing-software-supply-chain</guid>
      <pubDate>Tue, 03 Feb 2026 07:02:29 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What is Reproducible Builds]]></title>
      <description><![CDATA[Reproducible builds let anyone recompile source code and cryptographically verify the binary matches — closing the gap attackers exploit when they compromise build systems, not source code.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-reproducible-builds</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-reproducible-builds</guid>
      <pubDate>Tue, 03 Feb 2026 07:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Scanning Go codebases for known vulnerabilities with govu...]]></title>
      <description><![CDATA[A practical govulncheck tutorial for scanning Go codebases for known vulnerabilities, auditing dependencies, and wiring checks into your CI pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/scanning-go-codebases-for-known-vulnerabilities-with-govulncheck</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scanning-go-codebases-for-known-vulnerabilities-with-govulncheck</guid>
      <pubDate>Tue, 03 Feb 2026 06:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cloud Marketplace Security: What AWS and Azure Listings Actually Verify]]></title>
      <description><![CDATA[Buying software through AWS Marketplace or Azure Marketplace feels safe. But what security verification actually happens before a listing goes live?]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-marketplace-security-aws-azure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-marketplace-security-aws-azure</guid>
      <pubDate>Tue, 03 Feb 2026 05:42:02 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Build System Poisoning Techniques: How Attackers Corrupt Your Pipeline]]></title>
      <description><![CDATA[Build systems transform source code into deployable artifacts. When attackers poison the build, every artifact is compromised. Here is how it happens.]]></description>
      <link>https://safeguard.sh/resources/blog/build-system-poisoning-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/build-system-poisoning-techniques</guid>
      <pubDate>Tue, 03 Feb 2026 04:21:35 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is a Trust Boundary]]></title>
      <description><![CDATA[A trust boundary is where data crosses into a higher-privilege context and must be verified. Learn where they hide and how breaches like Log4Shell exploited them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-trust-boundary</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-trust-boundary</guid>
      <pubDate>Tue, 03 Feb 2026 04:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Massive PyPI Malware Campaign Targets Developers with Credential Stealers]]></title>
      <description><![CDATA[A sustained campaign flooded PyPI with hundreds of malicious packages using typosquatting and dependency confusion to steal credentials and cryptocurrency from developers.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-malware-campaign-targeting-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-malware-campaign-targeting-developers</guid>
      <pubDate>Tue, 03 Feb 2026 03:01:09 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Anatomy of a Go module supply chain compromise: lessons f...]]></title>
      <description><![CDATA[Real incidents like the xz-utils backdoor reveal the anatomy of a go module supply chain compromise: maintainer trust, init() execution, and immutable proxy caching.]]></description>
      <link>https://safeguard.sh/resources/blog/anatomy-of-a-go-module-supply-chain-compromise-lessons-from-real-world-incidents</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anatomy-of-a-go-module-supply-chain-compromise-lessons-from-real-world-incidents</guid>
      <pubDate>Tue, 03 Feb 2026 03:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[DAST Tool Comparison for Enterprise: What Matters Beyond Feature Lists]]></title>
      <description><![CDATA[Enterprise DAST tools differ in how they handle modern application architectures, API testing, and CI/CD integration. Here is what to evaluate when choosing a DAST solution.]]></description>
      <link>https://safeguard.sh/resources/blog/dast-tool-comparison-enterprise-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dast-tool-comparison-enterprise-2023</guid>
      <pubDate>Tue, 03 Feb 2026 01:40:42 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Cache Poisoning Attacks: How They Work and How to Prevent Them]]></title>
      <description><![CDATA[Cache poisoning attacks manipulate web caches to serve malicious content to other users. This guide covers web cache poisoning, DNS cache poisoning, and practical defenses for modern applications.]]></description>
      <link>https://safeguard.sh/resources/blog/cache-poisoning-attacks-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cache-poisoning-attacks-prevention</guid>
      <pubDate>Tue, 03 Feb 2026 00:20:15 GMT</pubDate>
      <category>Web Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[RubyGems supply chain attacks: gem typosquatting and hija...]]></title>
      <description><![CDATA[A look at RubyGems typosquatting and maintainer takeovers: how malicious Ruby gems slip into the supply chain, and what actually stops them.]]></description>
      <link>https://safeguard.sh/resources/blog/rubygems-supply-chain-attacks-gem-typosquatting-and-hijacked-maintainers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rubygems-supply-chain-attacks-gem-typosquatting-and-hijacked-maintainers</guid>
      <pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Pipenv Security Posture Review]]></title>
      <description><![CDATA[Pipenv is still in production at many companies. Here is an honest look at its security model, its maintenance status, and when it is time to migrate away.]]></description>
      <link>https://safeguard.sh/resources/blog/pipenv-security-posture-review-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pipenv-security-posture-review-2023</guid>
      <pubDate>Mon, 02 Feb 2026 22:59:49 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Secure Package Publishing Checklist for Open Source Maintainers]]></title>
      <description><![CDATA[Publishing a package to a public registry makes your code part of thousands of supply chains. This checklist covers the security controls that responsible maintainers implement before and during publication.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-package-publishing-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-package-publishing-checklist</guid>
      <pubDate>Mon, 02 Feb 2026 21:39:22 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[The Ransomware Payment Ban Debate: Arguments, Evidence, and Unintended Consequences]]></title>
      <description><![CDATA[Should governments ban ransomware payments? The debate intensified through 2023 as attacks escalated, with strong arguments on both sides and no clear consensus.]]></description>
      <link>https://safeguard.sh/resources/blog/ransomware-payment-ban-debate-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ransomware-payment-ban-debate-analysis</guid>
      <pubDate>Mon, 02 Feb 2026 20:18:55 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Changelog and Security Disclosure Best Practices]]></title>
      <description><![CDATA[How you communicate security changes in your changelog affects both your users' safety and your project's trustworthiness. Here is how to get it right.]]></description>
      <link>https://safeguard.sh/resources/blog/changelog-security-disclosure-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/changelog-security-disclosure-practices</guid>
      <pubDate>Mon, 02 Feb 2026 18:58:28 GMT</pubDate>
      <category>Security Strategy</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Runtime SBOM vs. Build-Time SBOM: Which Do You Actually Need?]]></title>
      <description><![CDATA[Build-time SBOMs capture what goes into your software; runtime SBOMs capture what actually runs. Understanding the difference is critical for accurate vulnerability management.]]></description>
      <link>https://safeguard.sh/resources/blog/runtime-sbom-vs-build-time-sbom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runtime-sbom-vs-build-time-sbom</guid>
      <pubDate>Mon, 02 Feb 2026 17:38:02 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Bitbucket Pipelines Security Guide]]></title>
      <description><![CDATA[Securing Bitbucket Pipelines with secure variables, deployment permissions, and pipeline hardening.]]></description>
      <link>https://safeguard.sh/resources/blog/bitbucket-pipelines-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bitbucket-pipelines-security-guide</guid>
      <pubDate>Mon, 02 Feb 2026 16:17:35 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Security Incident Communication Guide]]></title>
      <description><![CDATA[How to communicate during and after a security incident without making things worse. Templates, timelines, and principles for crisis communication.]]></description>
      <link>https://safeguard.sh/resources/blog/security-incident-communication-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-incident-communication-guide</guid>
      <pubDate>Mon, 02 Feb 2026 14:57:08 GMT</pubDate>
      <category>Organizational Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Socket.dev: Detecting Supply Chain Attacks Before They Hit]]></title>
      <description><![CDATA[A review of Socket.dev's approach to supply chain security, focusing on behavior analysis of npm packages, install script detection, and typosquatting prevention.]]></description>
      <link>https://safeguard.sh/resources/blog/socket-dev-supply-chain-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/socket-dev-supply-chain-detection</guid>
      <pubDate>Mon, 02 Feb 2026 13:36:42 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[WinRAR Zero-Day CVE-2023-38831: Weaponized Archives in the Wild]]></title>
      <description><![CDATA[A WinRAR vulnerability exploited since April 2023 allowed attackers to execute arbitrary code when users opened seemingly harmless files inside ZIP archives.]]></description>
      <link>https://safeguard.sh/resources/blog/winrar-cve-2023-38831-zero-day-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/winrar-cve-2023-38831-zero-day-exploitation</guid>
      <pubDate>Mon, 02 Feb 2026 12:16:15 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[SEvenLLM Design And Coverage]]></title>
      <description><![CDATA[SEvenLLM set out to measure how well LLMs handle Security Event analysis, the unglamorous day-to-day work of SOCs and IR teams. A design review of what the benchmark covers, how it was built, and where the coverage maps or does not map to real operations.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-benchmark-sevenllm-design</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-benchmark-sevenllm-design</guid>
      <pubDate>Mon, 02 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Claude Haiku for Bulk Scanning]]></title>
      <description><![CDATA[Claude Haiku is the cost-efficient model Griffin uses for high-volume scan interpretation. Here's how raw Haiku compares to Haiku inside Griffin's bulk pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-claude-haiku-for-bulk-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-claude-haiku-for-bulk-scanning</guid>
      <pubDate>Mon, 02 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Japan's Approach to Cybersecurity and Software Supply Chain Security]]></title>
      <description><![CDATA[Japan is rapidly building cybersecurity policy around software supply chain risk. Here's what the regulatory landscape looks like and where it's headed.]]></description>
      <link>https://safeguard.sh/resources/blog/japan-cybersecurity-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/japan-cybersecurity-software-supply-chain</guid>
      <pubDate>Mon, 02 Feb 2026 10:55:48 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[DEF CON 33 Software Supply Chain Sessions Recap]]></title>
      <description><![CDATA[DEF CON 33 brought hacker-energy attention to package ecosystems, CI/CD abuse, and AppSec Village. Here is what supply chain defenders should take home.]]></description>
      <link>https://safeguard.sh/resources/blog/defcon-33-recap-software-supply-chain-sessions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/defcon-33-recap-software-supply-chain-sessions</guid>
      <pubDate>Mon, 02 Feb 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[PyPI mexalz Malware Campaign Deep Dive]]></title>
      <description><![CDATA[Researchers tracked a PyPI campaign publishing malicious packages under the mexalz and related account names, targeting Python developers with infostealers.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-mexalz-malware-campaign-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-mexalz-malware-campaign-deep-dive</guid>
      <pubDate>Mon, 02 Feb 2026 10:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Taint Analysis]]></title>
      <description><![CDATA[Taint analysis traces untrusted input from source to sink to catch injection flaws. Learn how it works, what it misses, and how reachability analysis fixes the noise.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-taint-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-taint-analysis</guid>
      <pubDate>Mon, 02 Feb 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[pip Install Hooks Security: The Python Packaging Backdoor]]></title>
      <description><![CDATA[Python's setup.py runs arbitrary code during package installation. Despite efforts to move to declarative metadata, the risk persists.]]></description>
      <link>https://safeguard.sh/resources/blog/pip-install-hooks-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pip-install-hooks-security</guid>
      <pubDate>Mon, 02 Feb 2026 09:35:22 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Bundler dependency pinning and Gemfile.lock as a supply c...]]></title>
      <description><![CDATA[A step-by-step guide to Gemfile.lock security: pin gems deliberately, enforce ruby lockfile integrity with checksums, and lock down bundle install in CI/CD.]]></description>
      <link>https://safeguard.sh/resources/blog/bundler-dependency-pinning-and-gemfilelock-as-a-supply-chain-control</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bundler-dependency-pinning-and-gemfilelock-as-a-supply-chain-control</guid>
      <pubDate>Mon, 02 Feb 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Dev Container Security Posture (incl. Dotfiles)]]></title>
      <description><![CDATA[Dev containers promise reproducibility and isolation. They also pull in a long tail of scripts, dotfiles, and feature repos that most teams never audit. Here is how to fix that.]]></description>
      <link>https://safeguard.sh/resources/blog/dev-container-security-posture-dotfiles</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dev-container-security-posture-dotfiles</guid>
      <pubDate>Mon, 02 Feb 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Measuring AppSec Program Effectiveness in 2026]]></title>
      <description><![CDATA[The metrics that actually distinguish high-functioning application security programs from theater, with concrete formulas and reporting cadences for 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/measuring-appsec-program-effectiveness-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/measuring-appsec-program-effectiveness-2026</guid>
      <pubDate>Mon, 02 Feb 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[RansomHub Ransomware and EDR Bypass (2024)]]></title>
      <description><![CDATA[RansomHub absorbed affiliates displaced by BlackCat and ran one of the most prolific extortion operations of 2024. Here is what made its tradecraft effective and how to counter it.]]></description>
      <link>https://safeguard.sh/resources/blog/ransomhub-ransomware-edr-bypass-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ransomhub-ransomware-edr-bypass-2024</guid>
      <pubDate>Mon, 02 Feb 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Rust crates.io Supply Chain Controls in 2026]]></title>
      <description><![CDATA[crates.io has gained real supply chain features over the past two years. Here is an honest read on what works, what is still immature, and where to invest.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-crates-io-supply-chain-controls-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-crates-io-supply-chain-controls-2026</guid>
      <pubDate>Mon, 02 Feb 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Explores Partnership With Sify Technology (USA)]]></title>
      <description><![CDATA[Safeguard is in early discussions with Sify Technology (USA) to evaluate a joint motion across network services, managed security, and enterprise reach.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-exploring-partnership-sify-technology-usa</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-exploring-partnership-sify-technology-usa</guid>
      <pubDate>Mon, 02 Feb 2026 09:00:00 GMT</pubDate>
      <category>Company</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin Agent Loop: Design Decisions]]></title>
      <description><![CDATA[The design rationale behind Griffin, Safeguard's triage agent — how the loop is structured, why we bounded reasoning depth, and how tool calls stay auditable.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-griffin-agent-loop-design</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-griffin-agent-loop-design</guid>
      <pubDate>Mon, 02 Feb 2026 09:00:00 GMT</pubDate>
      <category>Architecture</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Salt Typhoon Telecom Supply Chain Campaign 2024]]></title>
      <description><![CDATA[Salt Typhoon's 2024 intrusions into U.S. telecoms reframed supply chain risk as a routing and lawful-intercept problem. Here is what the campaign looked like from a defender's seat.]]></description>
      <link>https://safeguard.sh/resources/blog/salt-typhoon-telecom-supply-chain-campaign-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/salt-typhoon-telecom-supply-chain-campaign-2024</guid>
      <pubDate>Mon, 02 Feb 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Threat Hunting in the Software Supply Chain]]></title>
      <description><![CDATA[Proactive threat hunting techniques adapted for software supply chain security—because waiting for alerts isn't enough when adversaries hide in your dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/threat-hunting-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/threat-hunting-software-supply-chain</guid>
      <pubDate>Mon, 02 Feb 2026 08:14:55 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is Abstract Syntax Tree (AST) Analysis]]></title>
      <description><![CDATA[AST analysis parses code into a tree to catch what regex scanning misses — here's how it works, its limits, and how reachability fixes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-abstract-syntax-tree-ast-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-abstract-syntax-tree-ast-analysis</guid>
      <pubDate>Mon, 02 Feb 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Network Policies Deep Dive: From Zero Trust to Microsegmentation]]></title>
      <description><![CDATA[By default, every pod can talk to every other pod. Network policies change that, but most implementations are incomplete. Here is how to build real microsegmentation in Kubernetes.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-network-policies-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-network-policies-deep-dive</guid>
      <pubDate>Mon, 02 Feb 2026 06:54:28 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Ruby deserialization vulnerabilities: Marshal.load, YAML....]]></title>
      <description><![CDATA[A decade of Ruby CVEs — from CVE-2013-0156 to CVE-2022-32224 — shows how Marshal.load and YAML.load turn untrusted input into remote code execution.]]></description>
      <link>https://safeguard.sh/resources/blog/ruby-deserialization-vulnerabilities-marshalload-yamlload-and-unsafe-object-loading</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ruby-deserialization-vulnerabilities-marshalload-yamlload-and-unsafe-object-loading</guid>
      <pubDate>Mon, 02 Feb 2026 06:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[DevSecOps Toolchain Integration Patterns That Actually Work]]></title>
      <description><![CDATA[Most DevSecOps tool integrations fail because they are bolted on rather than designed in. Here are integration patterns that provide security value without breaking the developer experience.]]></description>
      <link>https://safeguard.sh/resources/blog/devsecops-toolchain-integration-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devsecops-toolchain-integration-patterns</guid>
      <pubDate>Mon, 02 Feb 2026 05:34:02 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Security Champions With a Supply Chain Focus]]></title>
      <description><![CDATA[Designing and running a security champions program specifically for supply chain risks, including recruitment, training, cadences, and measurable impact.]]></description>
      <link>https://safeguard.sh/resources/blog/security-champions-program-supply-chain-focus</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-champions-program-supply-chain-focus</guid>
      <pubDate>Mon, 02 Feb 2026 04:13:35 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Semantic Code Analysis]]></title>
      <description><![CDATA[Semantic code analysis traces how data actually flows through code to find real vulnerabilities — cutting false positives that plague pattern-matching SAST tools.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-semantic-code-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-semantic-code-analysis</guid>
      <pubDate>Mon, 02 Feb 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Auditing Ruby dependencies for known CVEs with bundler-audit]]></title>
      <description><![CDATA[A step-by-step bundler-audit tutorial for scanning Ruby gems against known CVEs, patching vulnerable dependencies, and enforcing the check in CI.]]></description>
      <link>https://safeguard.sh/resources/blog/auditing-ruby-dependencies-for-known-cves-with-bundler-audit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/auditing-ruby-dependencies-for-known-cves-with-bundler-audit</guid>
      <pubDate>Mon, 02 Feb 2026 03:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Remediation SLAs: Best Practices for Real Teams]]></title>
      <description><![CDATA[Setting vulnerability remediation deadlines is easy. Actually meeting them is hard. This guide covers practical SLA frameworks that balance security urgency with engineering reality.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-remediation-sla-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-remediation-sla-best-practices</guid>
      <pubDate>Mon, 02 Feb 2026 02:53:08 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Dependabot and the State of Automated Dependency Security]]></title>
      <description><![CDATA[Dependabot has become the default for dependency updates, but its limitations highlight why automated scanning alone isn't enough for supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/github-dependabot-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-dependabot-supply-chain-security</guid>
      <pubDate>Mon, 02 Feb 2026 01:32:41 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is a Security Gate]]></title>
      <description><![CDATA[A security gate blocks a build or deploy the moment it fails a policy check. Here's what gates actually check, where to place them, and why most fail.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-security-gate</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-security-gate</guid>
      <pubDate>Mon, 02 Feb 2026 01:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Africa's Digital Transformation: Security Challenges at Scale]]></title>
      <description><![CDATA[Africa is leapfrogging traditional IT infrastructure with mobile-first, cloud-native solutions. But the cybersecurity foundations are lagging dangerously behind the pace of adoption.]]></description>
      <link>https://safeguard.sh/resources/blog/africa-digital-transformation-security-challenges</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/africa-digital-transformation-security-challenges</guid>
      <pubDate>Mon, 02 Feb 2026 00:12:15 GMT</pubDate>
      <category>Regional Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Case study: RubyGems account takeover incidents and their...]]></title>
      <description><![CDATA[A look at real RubyGems account takeover incidents, including the rest-client hijack, and what they reveal about Ruby supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/case-study-rubygems-account-takeover-incidents-and-their-downstream-impact</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/case-study-rubygems-account-takeover-incidents-and-their-downstream-impact</guid>
      <pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[SonicWall SMA 1000 CVE-2025-23006 Pre-Auth RCE]]></title>
      <description><![CDATA[CVE-2025-23006 is a pre-auth deserialization RCE in SonicWall SMA 1000. Exploit chain, detection signals, and appliance hardening.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2025-23006-sonicwall-sma-1000-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2025-23006-sonicwall-sma-1000-rce</guid>
      <pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Terraform Provider Verification: Securing Your Infrastructure as Code Supply Chain]]></title>
      <description><![CDATA[Terraform providers are plugins that execute with full access to your infrastructure credentials. Verifying their integrity is not optional.]]></description>
      <link>https://safeguard.sh/resources/blog/terraform-provider-verification-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/terraform-provider-verification-guide</guid>
      <pubDate>Sun, 01 Feb 2026 22:51:48 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Ingress Security Configuration: Getting It Right]]></title>
      <description><![CDATA[Ingress controllers are the front door to your Kubernetes cluster. Misconfigurations here expose everything behind them.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-ingress-security-configuration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-ingress-security-configuration</guid>
      <pubDate>Sun, 01 Feb 2026 21:31:21 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Google Cloud Build Supply Chain Security: From Source to Deploy]]></title>
      <description><![CDATA[How to secure your Cloud Build pipelines with SLSA provenance, Binary Authorization, and artifact verification for end-to-end supply chain integrity.]]></description>
      <link>https://safeguard.sh/resources/blog/google-cloud-build-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/google-cloud-build-supply-chain-security</guid>
      <pubDate>Sun, 01 Feb 2026 20:10:55 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes 1.27 Security Highlights]]></title>
      <description><![CDATA[Kubernetes 1.27 graduated seccomp default, introduced in-place pod resize, and cleaned up admission. Here is what actually matters for cluster security.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-1-27-security-highlights</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-1-27-security-highlights</guid>
      <pubDate>Sun, 01 Feb 2026 18:50:28 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[npm Lockfile v3 Security Improvements]]></title>
      <description><![CDATA[Lockfile v3 is more than a format bump. It quietly fixed a class of integrity bugs that plagued v1 and v2, and the difference matters more than most teams realize.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-lockfile-v3-security-improvements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-lockfile-v3-security-improvements</guid>
      <pubDate>Sun, 01 Feb 2026 17:30:01 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[LLM Prompt Injection: The New Supply Chain Attack Vector]]></title>
      <description><![CDATA[Prompt injection attacks against large language models represent a dangerous new frontier in software supply chain security. Here's what defenders need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-prompt-injection-supply-chain-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-prompt-injection-supply-chain-risk</guid>
      <pubDate>Sun, 01 Feb 2026 16:09:35 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Ivanti EPMM Zero-Day CVE-2023-35078: Norwegian Government Breach]]></title>
      <description><![CDATA[A critical authentication bypass in Ivanti's Endpoint Manager Mobile was exploited to breach Norwegian government agencies, earning a perfect CVSS 10.0 score.]]></description>
      <link>https://safeguard.sh/resources/blog/ivanti-epmm-cve-2023-35078-zero-day</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ivanti-epmm-cve-2023-35078-zero-day</guid>
      <pubDate>Sun, 01 Feb 2026 14:49:08 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Internal Package Naming Best Practices to Prevent Dependency Confusion]]></title>
      <description><![CDATA[The wrong naming convention for internal packages makes dependency confusion attacks trivial. Here is how to name packages so attackers cannot substitute them.]]></description>
      <link>https://safeguard.sh/resources/blog/internal-package-naming-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/internal-package-naming-best-practices</guid>
      <pubDate>Sun, 01 Feb 2026 13:28:41 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[The Hidden Risk of Abandoned Open Source Projects]]></title>
      <description><![CDATA[Abandoned open source projects do not disappear. They continue to be installed, depended upon, and deployed in production. They just stop getting security patches.]]></description>
      <link>https://safeguard.sh/resources/blog/abandoned-open-source-project-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/abandoned-open-source-project-risks</guid>
      <pubDate>Sun, 01 Feb 2026 12:08:15 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Audit Log Completeness: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Audit logs are where enterprise AI either proves its seriousness or exposes its improvisation. The gap between Griffin AI and Mythos-class products is visible in the first day of a real audit.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-audit-log-completeness</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-audit-log-completeness</guid>
      <pubDate>Sun, 01 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs OpenAI o1 for Security Reasoning]]></title>
      <description><![CDATA[Deep reasoning models are transformative for hard logical problems. Security reasoning is only partially a logic problem—the rest is grounding, policy, and workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-openai-o1-reasoning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-openai-o1-reasoning</guid>
      <pubDate>Sun, 01 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Small-Model Distillation For Security Workflows]]></title>
      <description><![CDATA[Distillation compresses the capability of a large model into a small one for a narrow task. For high-volume security workflows, it is often the difference between a working pipeline and an unaffordable one.]]></description>
      <link>https://safeguard.sh/resources/blog/small-model-distillation-for-security-workflows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/small-model-distillation-for-security-workflows</guid>
      <pubDate>Sun, 01 Feb 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[How to Generate SBOMs From Maven Projects]]></title>
      <description><![CDATA[Produce accurate CycloneDX SBOMs from Maven builds using the official plugin, handle multi-module reactors, and ship attested SBOMs alongside your JARs.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-generate-sboms-from-maven-projects-cli</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-generate-sboms-from-maven-projects-cli</guid>
      <pubDate>Sun, 01 Feb 2026 10:47:48 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The Software Transparency Act of 2026: What It Means for the Industry]]></title>
      <description><![CDATA[Proposed legislation would require SBOMs for all critical infrastructure software. Here's a detailed analysis of the bill and its implications.]]></description>
      <link>https://safeguard.sh/resources/blog/software-transparency-act-2026-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-transparency-act-2026-analysis</guid>
      <pubDate>Sun, 01 Feb 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is Risk Scoring]]></title>
      <description><![CDATA[Vulnerability risk scoring ranks flaws by real exploitability and exposure, not just CVSS severity. Here's how it works and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-risk-scoring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-risk-scoring</guid>
      <pubDate>Sun, 01 Feb 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Template Injection (SSTI) Prevention Guide]]></title>
      <description><![CDATA[Server-Side Template Injection turns template engines into code execution engines. This guide covers SSTI in Jinja2, Twig, Freemarker, and other engines, with detection techniques and layered defenses.]]></description>
      <link>https://safeguard.sh/resources/blog/template-injection-ssti-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/template-injection-ssti-prevention</guid>
      <pubDate>Sun, 01 Feb 2026 09:27:21 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[GCP Cloud Build + Workload Identity Federation]]></title>
      <description><![CDATA[Workload Identity Federation is the right way to give Cloud Build and external CI access to GCP. Here is the architecture, the traps, and the rollout plan.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-cloud-build-workload-identity-federation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-cloud-build-workload-identity-federation</guid>
      <pubDate>Sun, 01 Feb 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Hex.pm package registry security and Elixir supply chain ...]]></title>
      <description><![CDATA[Hex.pm blocks install-time scripts npm allows, but Elixir dependency risk still hides in native builds, Erlang CVEs, and thin registry-side vetting. Here's what to watch.]]></description>
      <link>https://safeguard.sh/resources/blog/hexpm-package-registry-security-and-elixir-supply-chain-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hexpm-package-registry-security-and-elixir-supply-chain-risk</guid>
      <pubDate>Sun, 01 Feb 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Game Day Exercises for Supply Chain Incidents: Practicing Before the Real Thing]]></title>
      <description><![CDATA[Game day exercises simulate supply chain attacks and failures, testing your team's response procedures before a real incident hits. Here is how to plan and run effective supply chain game days.]]></description>
      <link>https://safeguard.sh/resources/blog/game-day-exercises-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/game-day-exercises-supply-chain</guid>
      <pubDate>Sun, 01 Feb 2026 08:06:54 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is Vulnerability Triage]]></title>
      <description><![CDATA[Vulnerability triage ranks scanner findings by real exploitability and exposure, not raw CVSS score, turning an unmanageable backlog into a short, defensible fix list.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-vulnerability-triage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-vulnerability-triage</guid>
      <pubDate>Sun, 01 Feb 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Pharmaceutical Software Validation and Supply Chain Security]]></title>
      <description><![CDATA[Pharma companies must validate software used in drug manufacturing and clinical trials. Software supply chain security is now part of that equation.]]></description>
      <link>https://safeguard.sh/resources/blog/pharmaceutical-software-validation-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pharmaceutical-software-validation-supply-chain</guid>
      <pubDate>Sun, 01 Feb 2026 06:46:28 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Mix dependency management and mix.lock integrity in Elixi...]]></title>
      <description><![CDATA[A practical guide to mix.lock integrity: pinning Elixir dependencies, verifying lockfile hashes, and preventing supply chain tampering in mix.exs projects.]]></description>
      <link>https://safeguard.sh/resources/blog/mix-dependency-management-and-mixlock-integrity-in-elixir-projects</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mix-dependency-management-and-mixlock-integrity-in-elixir-projects</guid>
      <pubDate>Sun, 01 Feb 2026 06:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[OSV Schema: The Open Source Vulnerability Database Format Explained]]></title>
      <description><![CDATA[OSV provides a standardized format for vulnerability data that is purpose-built for open-source ecosystems. Here is how it works and why it is better than NVD for dependency scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/osv-schema-vulnerability-database-format</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/osv-schema-vulnerability-database-format</guid>
      <pubDate>Sun, 01 Feb 2026 05:26:01 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[npm Tightens Unpublish Rules: What It Means for Supply Chain Security]]></title>
      <description><![CDATA[npm's updated unpublish policy addresses the left-pad problem while balancing maintainer rights, but the supply chain implications go deeper than most realize.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-unpublish-policy-changes-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-unpublish-policy-changes-2023</guid>
      <pubDate>Sun, 01 Feb 2026 04:05:34 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is a Golden Image]]></title>
      <description><![CDATA[A golden image is the hardened template every server and container is cloned from — powerful for consistency, dangerous when it goes stale. Here's how to secure it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-golden-image</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-golden-image</guid>
      <pubDate>Sun, 01 Feb 2026 04:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Erlang/OTP atom exhaustion and deserialization risks in E...]]></title>
      <description><![CDATA[How the elixir atom exhaustion vulnerability lets attackers crash BEAM nodes via unsafe binary_to_term calls, and how Safeguard catches the pattern before it ships.]]></description>
      <link>https://safeguard.sh/resources/blog/erlangotp-atom-exhaustion-and-deserialization-risks-in-elixir-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/erlangotp-atom-exhaustion-and-deserialization-risks-in-elixir-applications</guid>
      <pubDate>Sun, 01 Feb 2026 03:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Vulnerability Rewards: Can Bug Bounties Save Open Source?]]></title>
      <description><![CDATA[Google expanded its OSS vulnerability rewards program in 2023, paying researchers to find bugs in critical open source projects. It's a promising model, but not a silver bullet.]]></description>
      <link>https://safeguard.sh/resources/blog/oss-vulnerability-rewards-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oss-vulnerability-rewards-programs</guid>
      <pubDate>Sun, 01 Feb 2026 02:45:08 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Kotlin detekt Security Rules: Catching Vulnerabilities in Kotlin Code]]></title>
      <description><![CDATA[detekt is Kotlin's primary static analysis tool. Its security-relevant rules catch patterns that lead to vulnerabilities in Android and server-side Kotlin.]]></description>
      <link>https://safeguard.sh/resources/blog/kotlin-detekt-security-rules</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kotlin-detekt-security-rules</guid>
      <pubDate>Sun, 01 Feb 2026 01:24:41 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is Image Signing]]></title>
      <description><![CDATA[Container image signing binds a cryptographic signature to an image's digest so you can prove what's running is what was actually built — not just scanned.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-image-signing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-image-signing</guid>
      <pubDate>Sun, 01 Feb 2026 01:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Distroless Container Images: Stripping the Attack Surface to Nothing]]></title>
      <description><![CDATA[Distroless images remove the shell, package manager, and everything else an attacker needs post-exploitation. Here is how to use them, what breaks, and whether the security tradeoff is worth it.]]></description>
      <link>https://safeguard.sh/resources/blog/distroless-container-images-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/distroless-container-images-security</guid>
      <pubDate>Sun, 01 Feb 2026 00:04:14 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Auditing Elixir and Phoenix apps with mix_audit and Sobelow]]></title>
      <description><![CDATA[A hands-on mix_audit Sobelow tutorial for scanning Elixir and Phoenix apps: dependency audits, static analysis, CI wiring, and triage tips.]]></description>
      <link>https://safeguard.sh/resources/blog/auditing-elixir-and-phoenix-apps-with-mixaudit-and-sobelow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/auditing-elixir-and-phoenix-apps-with-mixaudit-and-sobelow</guid>
      <pubDate>Sun, 01 Feb 2026 00:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Ledger Connect Kit Attack: What Devs Missed]]></title>
      <description><![CDATA[A phishing-obtained GitHub token published a wallet drainer as @ledgerhq/connect-kit in Dec 2023. What the incident tells us about Web3 supply chain trust.]]></description>
      <link>https://safeguard.sh/resources/blog/ledger-connect-kit-supply-chain-attack-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ledger-connect-kit-supply-chain-attack-2023</guid>
      <pubDate>Sun, 01 Feb 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Zenbleed: AMD CPU Vulnerability Leaks Data Across Processes (CVE-2023-20593)]]></title>
      <description><![CDATA[A speculative execution bug in AMD Zen 2 processors allows attackers to steal sensitive data at 30KB per core per second, affecting cloud environments and shared infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/zenbleed-amd-cpu-vulnerability-cve-2023-20593</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zenbleed-amd-cpu-vulnerability-cve-2023-20593</guid>
      <pubDate>Sat, 31 Jan 2026 22:43:48 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Python Wheel Security Verification: What You Are Missing]]></title>
      <description><![CDATA[Python wheels are the standard packaging format, but their security verification story has significant gaps that most developers never consider.]]></description>
      <link>https://safeguard.sh/resources/blog/python-wheel-security-verification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-wheel-security-verification</guid>
      <pubDate>Sat, 31 Jan 2026 21:23:21 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Security Challenges in Polyglot Repositories]]></title>
      <description><![CDATA[Repositories containing multiple programming languages multiply the security tooling, configuration, and expertise required. These challenges are manageable with the right approach.]]></description>
      <link>https://safeguard.sh/resources/blog/polyglot-repository-security-challenges</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/polyglot-repository-security-challenges</guid>
      <pubDate>Sat, 31 Jan 2026 20:02:54 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Golang Module Security and Verification]]></title>
      <description><![CDATA[Securing your Go module supply chain with checksum databases, GOPROXY, and vendor directories.]]></description>
      <link>https://safeguard.sh/resources/blog/golang-module-security-verification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/golang-module-security-verification</guid>
      <pubDate>Sat, 31 Jan 2026 18:42:28 GMT</pubDate>
      <category>Dependency Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Automated Security Testing in CI/CD Pipelines]]></title>
      <description><![CDATA[A hands-on guide to embedding SAST, SCA, secret scanning, and container analysis into your CI/CD pipeline without making builds unbearably slow.]]></description>
      <link>https://safeguard.sh/resources/blog/automated-security-testing-in-ci-cd</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automated-security-testing-in-ci-cd</guid>
      <pubDate>Sat, 31 Jan 2026 17:22:01 GMT</pubDate>
      <category>How-To Guide</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[IAST Explained: Why Instrumented Security Testing Catches What Others Miss]]></title>
      <description><![CDATA[IAST combines the precision of SAST with the realism of DAST. Here is how it works, where it fits, and what it actually costs to deploy.]]></description>
      <link>https://safeguard.sh/resources/blog/interactive-application-security-testing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/interactive-application-security-testing</guid>
      <pubDate>Sat, 31 Jan 2026 16:01:34 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Reproducible Builds in the Go Ecosystem]]></title>
      <description><![CDATA[Go's toolchain makes reproducible builds unusually tractable. Here is how to reach bit-for-bit builds across machines in 2023, and where the rough edges remain.]]></description>
      <link>https://safeguard.sh/resources/blog/reproducible-builds-go-ecosystem-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reproducible-builds-go-ecosystem-2023</guid>
      <pubDate>Sat, 31 Jan 2026 14:41:07 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CI/CD Secret Sprawl: How Pipeline Credentials Become Your Biggest Risk]]></title>
      <description><![CDATA[Your CI/CD pipeline has more credentials than your production environment. Secret sprawl across pipelines creates a massive attack surface that most teams cannot even inventory.]]></description>
      <link>https://safeguard.sh/resources/blog/ci-cd-secret-sprawl-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ci-cd-secret-sprawl-management</guid>
      <pubDate>Sat, 31 Jan 2026 13:20:41 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Aqua Security Platform Review: Cloud Native Security Done Right]]></title>
      <description><![CDATA[An in-depth review of the Aqua Security platform covering container security, runtime protection, Kubernetes scanning, and how it fits into a modern DevSecOps workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/aqua-security-platform-review-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aqua-security-platform-review-2023</guid>
      <pubDate>Sat, 31 Jan 2026 12:00:14 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Training Data Opacity As A Trust Limit]]></title>
      <description><![CDATA[You cannot audit what you cannot see. Frontier model training corpora are effectively opaque to their users, and that opacity is not incidental. It shapes what kinds of trust you can extend to the outputs.]]></description>
      <link>https://safeguard.sh/resources/blog/frontier-model-limit-training-data-opacity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/frontier-model-limit-training-data-opacity</guid>
      <pubDate>Sat, 31 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Gemini Long Context for Codebases]]></title>
      <description><![CDATA[Gemini's million-token context window is a genuinely new capability. For security analysis of large codebases, is it enough on its own?]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-long-context-for-codebases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-long-context-for-codebases</guid>
      <pubDate>Sat, 31 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Human Review Burden: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Auto-remediation only scales if human review stays cheap. Griffin AI's grounded PRs keep reviewer time low; Mythos-class PRs push the cost back to humans.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-human-review-burden</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-human-review-burden</guid>
      <pubDate>Sat, 31 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[WebAssembly Security: New Capabilities, New Supply Chain Questions]]></title>
      <description><![CDATA[WebAssembly is expanding beyond the browser into server-side and edge workloads. The security model and supply chain implications deserve closer scrutiny.]]></description>
      <link>https://safeguard.sh/resources/blog/wasm-webassembly-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wasm-webassembly-security-considerations</guid>
      <pubDate>Sat, 31 Jan 2026 10:39:47 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Admission Control (Kubernetes)]]></title>
      <description><![CDATA[Admission control is the last checkpoint in Kubernetes before an object is written to etcd — here's how webhooks, PSA, and policy engines enforce it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-admission-control-kubernetes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-admission-control-kubernetes</guid>
      <pubDate>Sat, 31 Jan 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[How to Structure an SBOM Review Process]]></title>
      <description><![CDATA[Build a repeatable SBOM review workflow that catches license risks, stale dependencies, and unexpected components before they ship to customers.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-structure-an-sbom-review-process</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-structure-an-sbom-review-process</guid>
      <pubDate>Sat, 31 Jan 2026 09:19:21 GMT</pubDate>
      <category>SBOM & Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[NuGet supply chain attacks: typosquatting and dependency ...]]></title>
      <description><![CDATA[NuGet typosquatting and dependency confusion let attackers plant malicious packages in .NET builds. Here's how real campaigns worked and how to stop them.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-supply-chain-attacks-typosquatting-and-dependency-confusion-in-net</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-supply-chain-attacks-typosquatting-and-dependency-confusion-in-net</guid>
      <pubDate>Sat, 31 Jan 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Risk Scoring Algorithms: How They Work and Where They Fail]]></title>
      <description><![CDATA[Risk scoring turns complex supply chain data into actionable numbers. But the algorithms behind these scores have assumptions and blind spots that security teams must understand.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-risk-scoring-algorithms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-risk-scoring-algorithms</guid>
      <pubDate>Sat, 31 Jan 2026 07:58:54 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Runtime Protection]]></title>
      <description><![CDATA[Runtime protection catches what pre-deployment scanning can't — live attacks like the XZ Utils backdoor and Log4Shell exploitation, detected only in production.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-runtime-protection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-runtime-protection</guid>
      <pubDate>Sat, 31 Jan 2026 07:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Citrix NetScaler Zero-Day CVE-2023-3519: Mass Exploitation in the Wild]]></title>
      <description><![CDATA[CVE-2023-3519 allowed unauthenticated remote code execution on Citrix NetScaler ADC and Gateway devices, leading to widespread exploitation and CISA emergency directives.]]></description>
      <link>https://safeguard.sh/resources/blog/citrix-netscaler-cve-2023-3519-zero-day</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/citrix-netscaler-cve-2023-3519-zero-day</guid>
      <pubDate>Sat, 31 Jan 2026 06:38:27 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Aerospace and Defense Software Supply Chain Security]]></title>
      <description><![CDATA[Aerospace and defense organizations face nation-state threats targeting software supply chains. Here's how to build resilience in high-assurance environments.]]></description>
      <link>https://safeguard.sh/resources/blog/aerospace-defense-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aerospace-defense-software-supply-chain</guid>
      <pubDate>Sat, 31 Jan 2026 05:18:01 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What is Drift Detection]]></title>
      <description><![CDATA[Drift detection catches unauthorized config changes in real time. See how it works, why it fails in most orgs, and real breaches it could have stopped.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-drift-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-drift-detection</guid>
      <pubDate>Sat, 31 Jan 2026 04:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Svelte and SvelteKit Security Best Practices for Production Apps]]></title>
      <description><![CDATA[Svelte's compile-time approach reduces runtime attack surface, but SvelteKit introduces server-side considerations that require deliberate security attention. A practical guide.]]></description>
      <link>https://safeguard.sh/resources/blog/svelte-sveltekit-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/svelte-sveltekit-security-best-practices</guid>
      <pubDate>Sat, 31 Jan 2026 03:57:34 GMT</pubDate>
      <category>Developer Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[NuGet package signing, source mapping, and verifying pack...]]></title>
      <description><![CDATA[A practical guide to NuGet package signing, source mapping, and provenance verification for .NET teams — with commands, config, and a troubleshooting checklist.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-package-signing-source-mapping-and-verifying-package-provenance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-package-signing-source-mapping-and-verifying-package-provenance</guid>
      <pubDate>Sat, 31 Jan 2026 03:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Security Debt: Tracking and Remediation Strategies]]></title>
      <description><![CDATA[Security debt accumulates silently—unpatched dependencies, skipped reviews, deferred upgrades. Here's how to measure it and pay it down systematically.]]></description>
      <link>https://safeguard.sh/resources/blog/security-debt-tracking-remediation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-debt-tracking-remediation</guid>
      <pubDate>Sat, 31 Jan 2026 02:37:07 GMT</pubDate>
      <category>Risk Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[ITAR and EAR Export Controls: What Software Teams Need to Know]]></title>
      <description><![CDATA[Export control regulations affect software development more than most teams realize. Here's how ITAR and EAR intersect with software supply chains.]]></description>
      <link>https://safeguard.sh/resources/blog/itar-ear-export-control-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/itar-ear-export-control-software</guid>
      <pubDate>Sat, 31 Jan 2026 01:16:41 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is Posture Management]]></title>
      <description><![CDATA[Security posture management explained: what it covers, how it differs from vulnerability management, and why misconfiguration still drives most cloud breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-posture-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-posture-management</guid>
      <pubDate>Sat, 31 Jan 2026 01:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Finding vulnerable .NET dependencies with dotnet list pac...]]></title>
      <description><![CDATA[A step-by-step guide to scanning C# projects for vulnerable NuGet packages using dotnet list package --vulnerable, plus how to fix and monitor them continuously.]]></description>
      <link>https://safeguard.sh/resources/blog/finding-vulnerable-net-dependencies-with-dotnet-list-package-vulnerable</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/finding-vulnerable-net-dependencies-with-dotnet-list-package-vulnerable</guid>
      <pubDate>Sat, 31 Jan 2026 00:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Economics of Vulnerability Bounties: Who Wins and Who Loses]]></title>
      <description><![CDATA[Bug bounty programs are a billion-dollar market. But the economics do not work equally well for everyone. A look at who benefits, who gets shortchanged, and what the numbers actually say.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-bounty-economics-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-bounty-economics-analysis</guid>
      <pubDate>Fri, 30 Jan 2026 23:56:14 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Zimbra Collaboration CVE-2023-37580: XSS Zero-Day Exploited by Four Nation-State Groups]]></title>
      <description><![CDATA[A reflected XSS vulnerability in Zimbra Collaboration was exploited by four distinct threat groups targeting government organizations worldwide. The campaign showed how even 'low severity' bugs enable espionage.]]></description>
      <link>https://safeguard.sh/resources/blog/zimbra-collaboration-cve-2023-37580-xss</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zimbra-collaboration-cve-2023-37580-xss</guid>
      <pubDate>Fri, 30 Jan 2026 22:35:47 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Rate Limiting in Package Registries: Balancing Security and Developer Experience]]></title>
      <description><![CDATA[Docker Hub's rate limits broke builds worldwide. Rate limiting is necessary for registry security, but getting it wrong disrupts entire engineering organizations.]]></description>
      <link>https://safeguard.sh/resources/blog/rate-limiting-package-registries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rate-limiting-package-registries</guid>
      <pubDate>Fri, 30 Jan 2026 21:15:20 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Load Balancer Security Considerations for Modern Architectures]]></title>
      <description><![CDATA[Load balancers terminate TLS, distribute traffic, and make routing decisions. Their security configuration affects every service behind them.]]></description>
      <link>https://safeguard.sh/resources/blog/load-balancer-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/load-balancer-security-considerations</guid>
      <pubDate>Fri, 30 Jan 2026 19:54:54 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[JumpCloud Supply Chain Attack: North Korea's Lazarus Group Strikes Again]]></title>
      <description><![CDATA[How North Korean threat actors compromised JumpCloud's infrastructure to target cryptocurrency firms through a sophisticated supply chain attack in July 2023.]]></description>
      <link>https://safeguard.sh/resources/blog/jumpcloud-supply-chain-attack-north-korea</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jumpcloud-supply-chain-attack-north-korea</guid>
      <pubDate>Fri, 30 Jan 2026 18:34:27 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Chaining: Real-World Examples and Defense Strategies]]></title>
      <description><![CDATA[Individual vulnerabilities rarely tell the full story. This deep dive examines how attackers chain low-severity bugs into devastating exploits and how defenders can break the chain.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-chaining-real-world-examples</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-chaining-real-world-examples</guid>
      <pubDate>Fri, 30 Jan 2026 17:14:00 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Stripe's Dependency Security Practices]]></title>
      <description><![CDATA[How Stripe secures its software dependencies while processing billions of dollars in payments, with a focus on Ruby ecosystem hardening and dependency isolation.]]></description>
      <link>https://safeguard.sh/resources/blog/stripe-dependency-security-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/stripe-dependency-security-practices</guid>
      <pubDate>Fri, 30 Jan 2026 15:53:34 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Renovate vs Dependabot: Enterprise Rollout Playbook for 2026]]></title>
      <description><![CDATA[How to choose between Renovate and Dependabot for enterprise dependency automation in 2026, with rollout patterns, failure modes, and migration paths.]]></description>
      <link>https://safeguard.sh/resources/blog/renovate-vs-dependabot-enterprise-rollout-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/renovate-vs-dependabot-enterprise-rollout-2026</guid>
      <pubDate>Fri, 30 Jan 2026 15:20:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[Digital Twins and Supply Chain Security: Securing the Virtual Mirror]]></title>
      <description><![CDATA[Digital twins replicate physical systems in software. When the software supply chain of a digital twin is compromised, the consequences extend to the physical world.]]></description>
      <link>https://safeguard.sh/resources/blog/digital-twin-security-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/digital-twin-security-supply-chain</guid>
      <pubDate>Fri, 30 Jan 2026 14:33:07 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Cloud-Native SBOM Generation Strategies That Actually Work]]></title>
      <description><![CDATA[Practical strategies for generating and managing Software Bills of Materials in cloud-native environments, beyond the compliance checkbox.]]></description>
      <link>https://safeguard.sh/resources/blog/cloud-native-sbom-generation-strategies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloud-native-sbom-generation-strategies</guid>
      <pubDate>Fri, 30 Jan 2026 13:12:40 GMT</pubDate>
      <category>Software Supply Chain</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Agent Security: Enterprise Adoption Patterns]]></title>
      <description><![CDATA[Enterprise agent deployments have moved past pilot phase. The security patterns that have survived contact with production look different from the ones the industry was selling a year ago.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-trend-agent-security-enterprise-adoption</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-trend-agent-security-enterprise-adoption</guid>
      <pubDate>Fri, 30 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Claude Code Coding Agent: Security Posture Review]]></title>
      <description><![CDATA[A working review of Claude Code's security posture, sandboxing model, and the practical controls enterprises need to deploy it safely at scale.]]></description>
      <link>https://safeguard.sh/resources/blog/claude-code-coding-agent-security-posture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/claude-code-coding-agent-security-posture</guid>
      <pubDate>Fri, 30 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Cross-Package Analysis: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Real exploits cross package boundaries. Griffin AI's graph follows them; Mythos-class tools often stop at the file they are reading.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cross-package-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cross-package-analysis</guid>
      <pubDate>Fri, 30 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Nonprofit Organization Cybersecurity: A Practical Guide]]></title>
      <description><![CDATA[Nonprofits handle donor data and sensitive beneficiary information with limited budgets. Here's a realistic guide to managing software security on nonprofit resources.]]></description>
      <link>https://safeguard.sh/resources/blog/nonprofit-organization-cybersecurity-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nonprofit-organization-cybersecurity-guide</guid>
      <pubDate>Fri, 30 Jan 2026 11:52:14 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SSH Key Management for Organizations: Beyond the Basics]]></title>
      <description><![CDATA[SSH keys provide access to your most critical infrastructure. Most organizations manage them poorly. Here is how to do it right.]]></description>
      <link>https://safeguard.sh/resources/blog/ssh-key-management-organizations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ssh-key-management-organizations</guid>
      <pubDate>Fri, 30 Jan 2026 10:31:47 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[CISO FAQ: Software Supply Chain Security 2026]]></title>
      <description><![CDATA[The questions CISOs actually ask about software supply chain security in 2026: scope, budget, reporting lines, SBOMs, AI code, and where to start.]]></description>
      <link>https://safeguard.sh/resources/blog/faq-software-supply-chain-security-for-cisos-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/faq-software-supply-chain-security-for-cisos-2026</guid>
      <pubDate>Fri, 30 Jan 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Getting Started with Safeguard CLI: Your First Scan]]></title>
      <description><![CDATA[Install the Safeguard CLI, authenticate, and run your first dependency and SBOM scan in under ten minutes. Covers config, output formats, and CI wiring.]]></description>
      <link>https://safeguard.sh/resources/blog/getting-started-safeguard-cli-first-scan</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/getting-started-safeguard-cli-first-scan</guid>
      <pubDate>Fri, 30 Jan 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Exposure Management]]></title>
      <description><![CDATA[Exposure management goes beyond CVE lists — it's the continuous, evidence-backed way to find and fix what attackers can actually exploit today.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-exposure-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-exposure-management</guid>
      <pubDate>Fri, 30 Jan 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Advanced Security: CodeQL, Dependabot, and Secret Scanning in Practice]]></title>
      <description><![CDATA[A review of GitHub Advanced Security covering CodeQL SAST, Dependabot SCA, secret scanning, and how the integrated security experience works for development teams.]]></description>
      <link>https://safeguard.sh/resources/blog/github-advanced-security-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-advanced-security-review</guid>
      <pubDate>Fri, 30 Jan 2026 09:11:20 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Case study: a malicious NuGet package compromise and its ...]]></title>
      <description><![CDATA[Inside the Moq/SponsorLink malicious NuGet package incident: what shipped, who was exposed, and how to harden your .NET build pipeline against the next one.]]></description>
      <link>https://safeguard.sh/resources/blog/case-study-a-malicious-nuget-package-compromise-and-its-blast-radius</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/case-study-a-malicious-nuget-package-compromise-and-its-blast-radius</guid>
      <pubDate>Fri, 30 Jan 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Sigstore Policy Controller for K8s in Production]]></title>
      <description><![CDATA[How the Sigstore Policy Controller actually runs in production, what it does better than Kyverno, and the operational pitfalls nobody mentions in the quickstart.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-supply-chain-sigstore-policy-controller</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-supply-chain-sigstore-policy-controller</guid>
      <pubDate>Fri, 30 Jan 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Scattered Spider: Identity as Supply Chain 2024-25]]></title>
      <description><![CDATA[Scattered Spider showed that help-desk processes, SaaS federation, and MSPs are the new software supply chain. Here is how to think about it and what to actually change.]]></description>
      <link>https://safeguard.sh/resources/blog/scattered-spider-identity-supply-chain-2024-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scattered-spider-identity-supply-chain-2024-2025</guid>
      <pubDate>Fri, 30 Jan 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CircleCI Security Configuration Guide]]></title>
      <description><![CDATA[Practical steps to secure your CircleCI pipelines, from context management and OIDC to orb vetting and runner isolation.]]></description>
      <link>https://safeguard.sh/resources/blog/circleci-security-configuration-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/circleci-security-configuration-guide</guid>
      <pubDate>Fri, 30 Jan 2026 07:50:53 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is Continuous Threat Exposure Management (CTEM)]]></title>
      <description><![CDATA[CTEM is Gartner's five-stage framework for continuously scoping, discovering, prioritizing, and validating exposures instead of relying on periodic scans.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-continuous-threat-exposure-management-ctem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-continuous-threat-exposure-management-ctem</guid>
      <pubDate>Fri, 30 Jan 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Starjacking Attacks on Package Registries: Exploiting Repository Trust]]></title>
      <description><![CDATA[Starjacking exploits the trust developers place in GitHub stars and repository metadata. Attackers link malicious packages to popular repositories to appear legitimate. Here is how it works.]]></description>
      <link>https://safeguard.sh/resources/blog/starjacking-attacks-package-registries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/starjacking-attacks-package-registries</guid>
      <pubDate>Fri, 30 Jan 2026 06:30:27 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[CocoaPods supply chain security and Podfile.lock integrit...]]></title>
      <description><![CDATA[A 2024 CocoaPods Trunk server flaw let attackers hijack orphaned pods and exposed a deeper gap: Podfile.lock never verified dependency integrity in the first place.]]></description>
      <link>https://safeguard.sh/resources/blog/cocoapods-supply-chain-security-and-podfilelock-integrity-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cocoapods-supply-chain-security-and-podfilelock-integrity-risks</guid>
      <pubDate>Fri, 30 Jan 2026 06:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[NuGet Package Tampering Detection: Securing the .NET Supply Chain]]></title>
      <description><![CDATA[NuGet packages can be tampered with at multiple points in the supply chain. Here is how to detect and prevent package tampering in your .NET projects.]]></description>
      <link>https://safeguard.sh/resources/blog/nuget-package-tampering-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nuget-package-tampering-detection</guid>
      <pubDate>Fri, 30 Jan 2026 05:10:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is Attack Surface Reduction]]></title>
      <description><![CDATA[Attack surface reduction means shrinking every entry point attackers can use—code, network, and identity. Here's how to define, measure, and act on it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-attack-surface-reduction</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-attack-surface-reduction</guid>
      <pubDate>Fri, 30 Jan 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Electron ContextBridge Security: Building Safe Desktop Apps]]></title>
      <description><![CDATA[Electron's ContextBridge is the secure boundary between web content and Node.js APIs. This guide covers how to use it correctly, common mistakes that create RCE vulnerabilities, and security best practices for Electron applications.]]></description>
      <link>https://safeguard.sh/resources/blog/electron-contextbridge-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/electron-contextbridge-security</guid>
      <pubDate>Fri, 30 Jan 2026 03:49:33 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Swift Package Manager dependency resolution and pinning s...]]></title>
      <description><![CDATA[SPM trusts mutable git tags, not signed artifacts. Here's how dependency resolution, Package.resolved integrity, and pinning gaps expose Swift apps to supply chain attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/swift-package-manager-dependency-resolution-and-pinning-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/swift-package-manager-dependency-resolution-and-pinning-security</guid>
      <pubDate>Fri, 30 Jan 2026 03:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Clop Ransomware and the MOVEit Campaign: Mass Exploitation at Scale]]></title>
      <description><![CDATA[Clop's exploitation of MOVEit Transfer compromised over 2,500 organizations in one campaign, demonstrating a shift from traditional ransomware to mass vulnerability exploitation.]]></description>
      <link>https://safeguard.sh/resources/blog/clop-ransomware-moveit-campaign-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/clop-ransomware-moveit-campaign-analysis</guid>
      <pubDate>Fri, 30 Jan 2026 02:29:07 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Domain Squatting and Package Registry Attacks]]></title>
      <description><![CDATA[Typosquatting and domain squatting in package registries trick developers into installing malicious packages. The attack is trivially easy to execute and remarkably effective.]]></description>
      <link>https://safeguard.sh/resources/blog/domain-squatting-package-registries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/domain-squatting-package-registries</guid>
      <pubDate>Fri, 30 Jan 2026 01:08:40 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What is a Security Baseline]]></title>
      <description><![CDATA[A security baseline is the minimum, testable set of controls every system or repo must meet — here's how it differs from policy, and how to build one for your supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-security-baseline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-security-baseline</guid>
      <pubDate>Fri, 30 Jan 2026 01:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[iOS app supply chain risk from third-party SDKs and ad li...]]></title>
      <description><![CDATA[Third-party SDKs and ad libraries run inside your iOS app with your app's permissions. Here's how ios sdk supply chain risk hides in plain sight — and what Safeguard does about it.]]></description>
      <link>https://safeguard.sh/resources/blog/ios-app-supply-chain-risk-from-third-party-sdks-and-ad-libraries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ios-app-supply-chain-risk-from-third-party-sdks-and-ad-libraries</guid>
      <pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[State of SBOM Adoption Across Industries 2026]]></title>
      <description><![CDATA[How SBOM adoption differs across finance, healthcare, public sector, manufacturing, and tech in 2026, where the real operational usage is, and where it stalls.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-sbom-adoption-across-industries-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-sbom-adoption-across-industries-2026</guid>
      <pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Kotlin Gradle Dependency Verification]]></title>
      <description><![CDATA[Implement dependency verification in Kotlin Gradle projects with checksums, PGP signatures, and repository filtering.]]></description>
      <link>https://safeguard.sh/resources/blog/kotlin-gradle-dependency-verification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kotlin-gradle-dependency-verification</guid>
      <pubDate>Thu, 29 Jan 2026 23:48:13 GMT</pubDate>
      <category>Dependency Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Automated SBOM Drift Detection: When Your Bill of Materials Goes Stale]]></title>
      <description><![CDATA[An SBOM that does not match what is actually deployed is worse than no SBOM at all. Here is how to detect and prevent SBOM drift automatically.]]></description>
      <link>https://safeguard.sh/resources/blog/automated-sbom-drift-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automated-sbom-drift-detection</guid>
      <pubDate>Thu, 29 Jan 2026 22:27:47 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Harness CI/CD Security Features]]></title>
      <description><![CDATA[Leveraging Harness platform security capabilities including governance policies, secret management, and pipeline security controls.]]></description>
      <link>https://safeguard.sh/resources/blog/harness-ci-cd-security-features</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/harness-ci-cd-security-features</guid>
      <pubDate>Thu, 29 Jan 2026 21:07:20 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MOVEit Vulnerability Mass Exploitation: A Field Analysis]]></title>
      <description><![CDATA[Inside the Cl0p ransomware gang's zero-day attack on Progress MOVEit Transfer, the CVE-2023-34362 timeline, and the supply chain lessons it exposed.]]></description>
      <link>https://safeguard.sh/resources/blog/moveit-vulnerability-mass-exploitation-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/moveit-vulnerability-mass-exploitation-analysis</guid>
      <pubDate>Thu, 29 Jan 2026 19:46:53 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Runtime Application Self-Protection (RASP): A Practical Guide]]></title>
      <description><![CDATA[RASP embeds security directly into the application runtime, detecting and blocking attacks from inside the app. It's powerful, controversial, and misunderstood. Here's what actually works.]]></description>
      <link>https://safeguard.sh/resources/blog/runtime-application-self-protection-rasp-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runtime-application-self-protection-rasp-guide</guid>
      <pubDate>Thu, 29 Jan 2026 18:26:27 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Microsegmentation for Software Supply Chain Security]]></title>
      <description><![CDATA[Microsegmentation limits lateral movement after a breach. Applied to software supply chains, it contains the blast radius when a dependency, build tool, or vendor is compromised.]]></description>
      <link>https://safeguard.sh/resources/blog/microsegmentation-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microsegmentation-supply-chain-security</guid>
      <pubDate>Thu, 29 Jan 2026 17:06:00 GMT</pubDate>
      <category>Security Architecture</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SpotBugs Security Detectors for Java: A Practical Guide]]></title>
      <description><![CDATA[SpotBugs with Find Security Bugs is the most effective free security analysis tool for Java. Here is how to get real results from it.]]></description>
      <link>https://safeguard.sh/resources/blog/spotbugs-security-detectors-java</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spotbugs-security-detectors-java</guid>
      <pubDate>Thu, 29 Jan 2026 15:45:33 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Microsoft Teams Vulnerability: External Tenant Attacks and the Collaboration Security Gap]]></title>
      <description><![CDATA[Researchers demonstrated that Microsoft Teams' default configuration allowed external attackers to deliver malware directly to employees, bypassing email security controls entirely.]]></description>
      <link>https://safeguard.sh/resources/blog/microsoft-teams-vulnerability-giftofspeed</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microsoft-teams-vulnerability-giftofspeed</guid>
      <pubDate>Thu, 29 Jan 2026 14:25:06 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Automotive Cybersecurity: UNECE WP.29 and Software Supply Chain Security]]></title>
      <description><![CDATA[Connected vehicles depend on millions of lines of code. UNECE WP.29 regulations now require automotive manufacturers to manage software supply chain risks.]]></description>
      <link>https://safeguard.sh/resources/blog/automotive-cybersecurity-unece-wp29</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automotive-cybersecurity-unece-wp29</guid>
      <pubDate>Thu, 29 Jan 2026 13:04:40 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[AI-BOM Awareness: Griffin AI vs Mythos]]></title>
      <description><![CDATA[AI-BOM is how you describe an AI system's supply chain — models, datasets, prompts, inference environments. Griffin AI ingests it as structured inventory. Mythos-class tools try to talk about AI while remaining blind to the AI systems they describe.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-ai-bom-awareness</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-ai-bom-awareness</guid>
      <pubDate>Thu, 29 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 Type II Evidence: Griffin AI vs Mythos]]></title>
      <description><![CDATA[A SOC 2 Type II auditor samples a control population across a reporting period. Griffin AI creates that population as a natural output. Mythos-class pure-LLM tools leave you reconstructing it.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-soc2-type2-evidence</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-soc2-type2-evidence</guid>
      <pubDate>Thu, 29 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CycloneDX v1.5: New Features and What They Mean for Your SBOM Program]]></title>
      <description><![CDATA[CycloneDX v1.5 introduced formulation, machine learning BOMs, and expanded evidence. Here is what changed and how to take advantage of it.]]></description>
      <link>https://safeguard.sh/resources/blog/cyclonedx-v1-5-new-features-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyclonedx-v1-5-new-features-guide</guid>
      <pubDate>Thu, 29 Jan 2026 11:44:13 GMT</pubDate>
      <category>SBOM Standards</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Renovate 2026: Security-Only Mode and OSV Alerts Tested]]></title>
      <description><![CDATA[Renovate's 2026 security presets, OSV-based vulnerability alerts, and 14-day minimum release age combine into a defensible auto-update posture. We tested it on a 240-repo org.]]></description>
      <link>https://safeguard.sh/resources/blog/renovate-2026-security-mode-field-test</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/renovate-2026-security-mode-field-test</guid>
      <pubDate>Thu, 29 Jan 2026 11:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Why Choose Wolfi Linux: A Buyer Rationale for 2026]]></title>
      <description><![CDATA[A clear-eyed look at Wolfi's value as a container base image distribution: glibc-based design, security defaults, build provenance, and where it does not fit.]]></description>
      <link>https://safeguard.sh/resources/blog/wolfi-linux-buyer-rationale-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wolfi-linux-buyer-rationale-2026</guid>
      <pubDate>Thu, 29 Jan 2026 11:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Quantum Computing and the Coming Cryptography Crisis in Supply Chains]]></title>
      <description><![CDATA[Quantum computers threaten the cryptographic foundations of software supply chains. The time to prepare is now, not when quantum advantage arrives.]]></description>
      <link>https://safeguard.sh/resources/blog/quantum-computing-cryptography-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/quantum-computing-cryptography-supply-chain</guid>
      <pubDate>Thu, 29 Jan 2026 10:23:46 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AI Model Weight Tampering Detection Techniques]]></title>
      <description><![CDATA[Weight-level tampering leaves cryptographic and statistical fingerprints. Here is what current research says about detecting a modified checkpoint before it reaches inference.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-model-weight-tampering-detection-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-model-weight-tampering-detection-techniques</guid>
      <pubDate>Thu, 29 Jan 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[FinTech Cuts CVE Noise 80% With Reachability]]></title>
      <description><![CDATA[An anonymized story of how a high-growth payments FinTech slashed vulnerability backlog noise by 80% using Safeguard's reachability analysis.]]></description>
      <link>https://safeguard.sh/resources/blog/customer-story-fintech-80-percent-cve-noise-cut</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/customer-story-fintech-80-percent-cve-noise-cut</guid>
      <pubDate>Thu, 29 Jan 2026 10:00:00 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Sandboxing LLM Agent Code Execution: Patterns]]></title>
      <description><![CDATA[If your agent can execute code, something it reads from the internet can execute code. Pick your sandbox before the agent picks one for you.]]></description>
      <link>https://safeguard.sh/resources/blog/llm-agent-code-execution-sandboxing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/llm-agent-code-execution-sandboxing</guid>
      <pubDate>Thu, 29 Jan 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Case for Autonomous Remediation Now]]></title>
      <description><![CDATA[Manual patching is a losing race against the rate of new vulnerabilities. Autonomous remediation is not a future technology — it is the only workflow that keeps pace with modern supply chains.]]></description>
      <link>https://safeguard.sh/resources/blog/the-case-for-autonomous-remediation-now</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-case-for-autonomous-remediation-now</guid>
      <pubDate>Thu, 29 Jan 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Third-Party Risk Management]]></title>
      <description><![CDATA[Third-party risk management explained: what it covers, why SolarWinds and MOVEit made it board-level, and how modern TPRM differs from supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-third-party-risk-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-third-party-risk-management</guid>
      <pubDate>Thu, 29 Jan 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Progress MOVEit: Second Critical Vulnerability Discovered Amid Breach Fallout]]></title>
      <description><![CDATA[While organizations were still reeling from the first MOVEit zero-day, a second critical vulnerability was found — raising questions about the product's security.]]></description>
      <link>https://safeguard.sh/resources/blog/progress-moveit-second-vulnerability-discovered</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/progress-moveit-second-vulnerability-discovered</guid>
      <pubDate>Thu, 29 Jan 2026 09:03:20 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[AI BOM Spec Comparison: CycloneDX ML-BOM in 2026]]></title>
      <description><![CDATA[AI bills of materials moved from proposal to procurement requirement. A practical comparison of CycloneDX ML-BOM, SPDX 3.0 AI profile, and what to ship in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-bom-spec-comparison-cyclonedx-ml-bom-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-bom-spec-comparison-cyclonedx-ml-bom-2026</guid>
      <pubDate>Thu, 29 Jan 2026 09:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Noise Reduction: Findings]]></title>
      <description><![CDATA[The Safeguard Research team ran reachability analysis across a large corpus of real codebases. This is what we learned about which CVEs actually matter.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-research-reachability-noise-reduction-findings</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-research-reachability-noise-reduction-findings</guid>
      <pubDate>Thu, 29 Jan 2026 09:00:00 GMT</pubDate>
      <category>Research</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Flask Application Security: A Deep Dive]]></title>
      <description><![CDATA[Flask gives you room to make mistakes. This is a long look at the patterns that keep Flask apps safe in 2023, covering sessions, extensions, Werkzeug, and Jinja.]]></description>
      <link>https://safeguard.sh/resources/blog/flask-application-security-deep-dive-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/flask-application-security-deep-dive-2023</guid>
      <pubDate>Thu, 29 Jan 2026 07:42:53 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Vendor Risk Management]]></title>
      <description><![CDATA[Vendor risk management now means tracking code-level supply chain risk, not just SOC 2 reports—here's what it covers, how to tier vendors, and what regulations require it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-vendor-risk-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-vendor-risk-management</guid>
      <pubDate>Thu, 29 Jan 2026 07:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Server-Side Request Forgery (SSRF): The Vulnerability That Unlocks Cloud Metadata]]></title>
      <description><![CDATA[SSRF lets attackers reach internal services through your application. In cloud environments, that often means access to instance metadata and IAM credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/server-side-request-forgery-ssrf-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/server-side-request-forgery-ssrf-guide</guid>
      <pubDate>Thu, 29 Jan 2026 06:22:26 GMT</pubDate>
      <category>Code Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Gradle build script injection and plugin supply chain att...]]></title>
      <description><![CDATA[How attackers hijack Gradle plugins, typosquat the Plugin Portal, and inject code into build.gradle files to run with full CI trust — and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/gradle-build-script-injection-and-plugin-supply-chain-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gradle-build-script-injection-and-plugin-supply-chain-attacks</guid>
      <pubDate>Thu, 29 Jan 2026 06:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Barracuda ESG Zero-Day CVE-2023-2868: When Patching Isn't Enough]]></title>
      <description><![CDATA[Barracuda told customers to physically replace compromised Email Security Gateway appliances. The vulnerability had been exploited since October 2022.]]></description>
      <link>https://safeguard.sh/resources/blog/barracuda-esg-zero-day-cve-2023-2868</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/barracuda-esg-zero-day-cve-2023-2868</guid>
      <pubDate>Thu, 29 Jan 2026 05:02:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Are Secure Coding Standards]]></title>
      <description><![CDATA[Secure coding standards are enforceable rules — like OWASP and CERT — that stop specific CWEs before code ships. Here's what they cover and how to enforce them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-are-secure-coding-standards</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-are-secure-coding-standards</guid>
      <pubDate>Thu, 29 Jan 2026 04:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Security Maturity Benchmarking: How to Measure Against Your Peers]]></title>
      <description><![CDATA[Security maturity models provide structure, but benchmarking against peers provides context. Here is how to build a meaningful security maturity benchmark without falling into common traps.]]></description>
      <link>https://safeguard.sh/resources/blog/security-maturity-benchmarking-peers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-maturity-benchmarking-peers</guid>
      <pubDate>Thu, 29 Jan 2026 03:41:33 GMT</pubDate>
      <category>Security Strategy</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Maven Central dependency confusion and namespace collisio...]]></title>
      <description><![CDATA[How Maven's groupId system and multi-repo resolution let attackers slip malicious packages into Java builds — and how to close the internal vs public repo gap.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-central-dependency-confusion-and-namespace-collision-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-central-dependency-confusion-and-namespace-collision-attacks</guid>
      <pubDate>Thu, 29 Jan 2026 03:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOMs for Mobile Applications: iOS and Android]]></title>
      <description><![CDATA[Mobile apps ship to millions of devices and can't be patched silently. Here's how to build SBOM practices for iOS and Android development.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-mobile-applications-ios-android</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-mobile-applications-ios-android</guid>
      <pubDate>Thu, 29 Jan 2026 02:21:06 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[DNS Security and Software Distribution: The Foundation Nobody Secures]]></title>
      <description><![CDATA[Every software download, package install, and API call starts with a DNS query. DNS compromise redirects your supply chain at the most fundamental level — and most organizations have no visibility.]]></description>
      <link>https://safeguard.sh/resources/blog/dns-security-software-distribution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dns-security-software-distribution</guid>
      <pubDate>Thu, 29 Jan 2026 01:00:40 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is the CERT Secure Coding Standard]]></title>
      <description><![CDATA[CERT secure coding standards give C, C++, and Java developers rule-by-rule guidance — with IDs, risk scores, and fix patterns — for avoiding exploitable bugs.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-cert-secure-coding-standard</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-cert-secure-coding-standard</guid>
      <pubDate>Thu, 29 Jan 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[ScreenConnect CVE-2024-57727 Path Traversal Detailed]]></title>
      <description><![CDATA[CVE-2024-57727 is a path traversal in ConnectWise ScreenConnect enabling arbitrary file read on self-hosted instances. Chain, detection, and patching.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-57727-screenconnect-path-traversal</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-57727-screenconnect-path-traversal</guid>
      <pubDate>Thu, 29 Jan 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Scanning Kotlin and Android projects with OWASP Dependenc...]]></title>
      <description><![CDATA[A step-by-step guide to scanning Kotlin and Android projects with OWASP Dependency-Check: Gradle plugin setup, CI automation, triage, and suppressions.]]></description>
      <link>https://safeguard.sh/resources/blog/scanning-kotlin-and-android-projects-with-owasp-dependency-check</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scanning-kotlin-and-android-projects-with-owasp-dependency-check</guid>
      <pubDate>Thu, 29 Jan 2026 00:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Dependabot: A Head-to-Head Comparison]]></title>
      <description><![CDATA[Evaluate Snyk and Dependabot on vulnerability detection, ecosystem coverage, CI integration, pricing, and remediation to pick the right SCA tool for your team.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-dependabot-head-to-head-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-dependabot-head-to-head-2023</guid>
      <pubDate>Wed, 28 Jan 2026 23:40:13 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[JetBrains Plugin Security Verification: Protecting Your IDE]]></title>
      <description><![CDATA[IDE plugins run with the same privileges as your IDE. A malicious IntelliJ plugin has access to your source code, credentials, and development environment.]]></description>
      <link>https://safeguard.sh/resources/blog/jetbrains-plugin-security-verification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jetbrains-plugin-security-verification</guid>
      <pubDate>Wed, 28 Jan 2026 22:19:46 GMT</pubDate>
      <category>Developer Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[FortiGate CVE-2023-27997: Critical Heap Overflow in SSL VPN]]></title>
      <description><![CDATA[A pre-authentication heap overflow in FortiOS SSL VPN allowed remote code execution on hundreds of thousands of internet-facing firewalls.]]></description>
      <link>https://safeguard.sh/resources/blog/fortinet-fortigate-cve-2023-27997-heap-overflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fortinet-fortigate-cve-2023-27997-heap-overflow</guid>
      <pubDate>Wed, 28 Jan 2026 20:59:19 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Container Base Image Selection: A Security-First Decision Framework]]></title>
      <description><![CDATA[Your base image choice determines your container security baseline. Most teams pick based on size or familiarity, not security properties.]]></description>
      <link>https://safeguard.sh/resources/blog/container-base-image-selection-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-base-image-selection-guide</guid>
      <pubDate>Wed, 28 Jan 2026 19:38:53 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[JFrog Xray: Vulnerability Scanning Built Into Your Artifact Pipeline]]></title>
      <description><![CDATA[A review of JFrog Xray for vulnerability scanning and license compliance, covering its deep integration with Artifactory, impact analysis, and binary-level scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/jfrog-xray-vulnerability-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jfrog-xray-vulnerability-scanning</guid>
      <pubDate>Wed, 28 Jan 2026 18:18:26 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SWIFT CSCF: Software Security Requirements for Financial Messaging]]></title>
      <description><![CDATA[SWIFT's Customer Security Controls Framework sets mandatory security baselines for financial institutions. Here's the software supply chain angle.]]></description>
      <link>https://safeguard.sh/resources/blog/swift-cscf-software-security-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/swift-cscf-software-security-requirements</guid>
      <pubDate>Wed, 28 Jan 2026 16:57:59 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[MOVEit Breach Impact Assessment: The Cl0p Campaign's Fallout]]></title>
      <description><![CDATA[The MOVEit breach became one of the largest data theft incidents in history. Here's an assessment of the damage and what organizations should learn.]]></description>
      <link>https://safeguard.sh/resources/blog/moveit-breach-impact-assessment-cl0p</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/moveit-breach-impact-assessment-cl0p</guid>
      <pubDate>Wed, 28 Jan 2026 15:37:33 GMT</pubDate>
      <category>Incident Response</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Spotify's Dependency Management at Scale]]></title>
      <description><![CDATA[Inside Spotify's approach to managing thousands of dependencies across hundreds of microservices, balancing developer autonomy with supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/spotify-dependency-management-at-scale</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spotify-dependency-management-at-scale</guid>
      <pubDate>Wed, 28 Jan 2026 14:17:06 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[CVE-2025-15467 in OpenSSL CMS: Patch Posture & SBOM Response]]></title>
      <description><![CDATA[OpenSSL CMS pre-auth stack buffer overflow scored CVSS 9.8. Mail servers, web servers, and anything that processes S/MIME need the fix. Defender playbook below.]]></description>
      <link>https://safeguard.sh/resources/blog/openssl-cve-2025-15467-patch-response</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssl-cve-2025-15467-patch-response</guid>
      <pubDate>Wed, 28 Jan 2026 14:00:00 GMT</pubDate>
      <category>Vulnerability Response</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vendor Lock-In in Security Tooling: The Hidden Cost of Integration]]></title>
      <description><![CDATA[Deep integration with a security vendor creates efficiency but also dependency. Here is how to evaluate lock-in risk in your security tooling decisions.]]></description>
      <link>https://safeguard.sh/resources/blog/vendor-lock-in-security-tooling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vendor-lock-in-security-tooling</guid>
      <pubDate>Wed, 28 Jan 2026 12:56:39 GMT</pubDate>
      <category>Security Strategy</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AWS Signer with Notation: Designing a Trust Policy That Survives Contact]]></title>
      <description><![CDATA[AWS Signer integrates with Notation for OCI image signing. The hard part is not signing — it is the trust policy that decides what gets to run. We walk through one that holds up.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-signer-notation-trust-policy-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-signer-notation-trust-policy-2026</guid>
      <pubDate>Wed, 28 Jan 2026 12:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Citation Accuracy: Griffin AI vs Mythos]]></title>
      <description><![CDATA[An AI security tool that cites the wrong advisory is worse than one that says nothing. Griffin AI benchmarks citation accuracy at 0.89 similarity; Mythos does not.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-citation-accuracy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-citation-accuracy</guid>
      <pubDate>Wed, 28 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SSRF Detection: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Server-side request forgery is a test of how well your scanner understands the boundary between trusted and untrusted URLs. Griffin's engine resolves URL construction through string builders, template engines, and HTTP client configuration; Mythos reads the code and guesses. On modern applications that is the difference between a finding you can ship and a finding you cannot defend.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-ssrf-detection</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-ssrf-detection</guid>
      <pubDate>Wed, 28 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Capability Declaration Audit]]></title>
      <description><![CDATA[An MCP server tells the world what it can do through its capability declaration. Auditing those declarations catches drift, tool poisoning, and misconfiguration before an agent gets talked into using the wrong one.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-capability-declaration-audit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-capability-declaration-audit</guid>
      <pubDate>Wed, 28 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CISSP, CEH, OSCP: How Security Certifications Address Supply Chain Risks]]></title>
      <description><![CDATA[Major security certifications are updating their content to cover supply chain threats. Here is what CISSP, CEH, and OSCP teach about supply chain security — and what they miss.]]></description>
      <link>https://safeguard.sh/resources/blog/cissp-ceh-oscp-supply-chain-certifications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cissp-ceh-oscp-supply-chain-certifications</guid>
      <pubDate>Wed, 28 Jan 2026 11:36:13 GMT</pubDate>
      <category>Career Development</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[IAST vs DAST Decision Guide 2026]]></title>
      <description><![CDATA[When to choose IAST, when to choose DAST, and when to run both. A decision framework for 2026 with concrete coverage, cost, and integration tradeoffs.]]></description>
      <link>https://safeguard.sh/resources/blog/iast-vs-dast-decision-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iast-vs-dast-decision-guide-2026</guid>
      <pubDate>Wed, 28 Jan 2026 11:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Jira and Docker: Integrating Security Workflows]]></title>
      <description><![CDATA[Jira docker integration for security teams usually means auto-filing tickets from container scan findings — here's how to wire it without flooding the backlog with noise.]]></description>
      <link>https://safeguard.sh/resources/blog/jira-and-docker-integrating-security-workflows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jira-and-docker-integrating-security-workflows</guid>
      <pubDate>Wed, 28 Jan 2026 10:30:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Anchore Syft: The Go-To Open Source SBOM Generator]]></title>
      <description><![CDATA[A thorough review of Anchore's Syft SBOM generation tool, covering supported formats, language ecosystems, container scanning, and integration patterns.]]></description>
      <link>https://safeguard.sh/resources/blog/anchore-syft-sbom-generation-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anchore-syft-sbom-generation-review</guid>
      <pubDate>Wed, 28 Jan 2026 10:15:46 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Black Hat USA 2025: Supply Chain Security Recap]]></title>
      <description><![CDATA[Black Hat USA 2025 highlighted AI-generated code risks, build system attacks, and the maturation of SBOM tooling. Here is what mattered for supply chain teams.]]></description>
      <link>https://safeguard.sh/resources/blog/black-hat-usa-2025-supply-chain-security-recap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/black-hat-usa-2025-supply-chain-security-recap</guid>
      <pubDate>Wed, 28 Jan 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard January 2026 Release Notes]]></title>
      <description><![CDATA[January 2026 release notes from Safeguard: Lion runtime attestations, Griffin cache sharing, self-healing workflows, and runner fleet mode.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-changelog-january-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-changelog-january-2026</guid>
      <pubDate>Wed, 28 Jan 2026 10:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Input Validation]]></title>
      <description><![CDATA[Input validation stops malicious data at the door. See the CVEs — Equifax, Log4Shell, MOVEit — that prove why skipping it, or doing it wrong, is so costly.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-input-validation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-input-validation</guid>
      <pubDate>Wed, 28 Jan 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Air-Gapped Vulnerability Management]]></title>
      <description><![CDATA[No internet means no live CVE feeds, no SaaS scanners, and no auto-updates — but the vulnerabilities still arrive. How to run a real vulnerability management program inside a disconnected environment.]]></description>
      <link>https://safeguard.sh/resources/blog/air-gapped-vulnerability-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/air-gapped-vulnerability-management</guid>
      <pubDate>Wed, 28 Jan 2026 09:30:00 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[CISA Secure by Design Pledge: Signatories in 2026]]></title>
      <description><![CDATA[CISA's Secure by Design Pledge has crossed 300 signatories. Here is what the 2026 cohort is committing to, what regulators expect in return, and how to prove it.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-secure-by-design-pledge-signatories-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-secure-by-design-pledge-signatories-2026</guid>
      <pubDate>Wed, 28 Jan 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[FDA Premarket Cybersecurity SBOM in 2026]]></title>
      <description><![CDATA[What the FDA's 2026 premarket cybersecurity guidance actually requires for SBOMs, how reviewers evaluate them, and the patterns that cause 510(k) submissions to stall.]]></description>
      <link>https://safeguard.sh/resources/blog/fda-premarket-cybersecurity-sbom-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fda-premarket-cybersecurity-sbom-2026</guid>
      <pubDate>Wed, 28 Jan 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Trusted Publishing Common Pitfalls]]></title>
      <description><![CDATA[PyPI trusted publishing removed a whole class of token leaks, but teams keep tripping over the same half-dozen configuration mistakes. Here is what to watch for.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-trusted-publishing-common-pitfalls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-trusted-publishing-common-pitfalls</guid>
      <pubDate>Wed, 28 Jan 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Gold Build Pipeline: How It Works]]></title>
      <description><![CDATA[A walkthrough of the Gold Build pipeline that produces reproducible, attested, policy-verified container images and binaries for Safeguard customers.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-gold-build-pipeline-how-it-works</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-gold-build-pipeline-how-it-works</guid>
      <pubDate>Wed, 28 Jan 2026 09:00:00 GMT</pubDate>
      <category>Architecture</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Review in Pull Request Workflows]]></title>
      <description><![CDATA[An SBOM that arrives after merge is a compliance artifact. An SBOM that shows up in the PR is a security control. Here is how to wire it up without killing velocity.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-in-pull-request-workflows-practical</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-in-pull-request-workflows-practical</guid>
      <pubDate>Wed, 28 Jan 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Third-party library risk in Android apps: permissions, SD...]]></title>
      <description><![CDATA[Every Android app runs dozens of third-party SDKs with full app permissions. Here's how android third-party library risk turns into real data leaks — and how Safeguard catches it first.]]></description>
      <link>https://safeguard.sh/resources/blog/third-party-library-risk-in-android-apps-permissions-sdks-and-data-leakage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/third-party-library-risk-in-android-apps-permissions-sdks-and-data-leakage</guid>
      <pubDate>Wed, 28 Jan 2026 09:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[WireGuard for Development Infrastructure: Fast, Simple, and Secure Tunneling]]></title>
      <description><![CDATA[WireGuard's simplicity and performance make it well-suited for securing development infrastructure. Here is how to deploy it for build servers, artifact repositories, and developer access.]]></description>
      <link>https://safeguard.sh/resources/blog/wireguard-development-infrastructure</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/wireguard-development-infrastructure</guid>
      <pubDate>Wed, 28 Jan 2026 08:55:19 GMT</pubDate>
      <category>Network Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Security Posture Assessment: A Step-by-Step Method]]></title>
      <description><![CDATA[A security posture assessment turns 'are we secure?' into a measured, repeatable answer. Here is a six-phase method — from asset inventory to a scored, prioritized gap list you can act on.]]></description>
      <link>https://safeguard.sh/resources/blog/security-posture-assessment-method</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-posture-assessment-method</guid>
      <pubDate>Wed, 28 Jan 2026 08:30:00 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[EU Cyber Resilience Act: Impact on Software Developers and Open Source]]></title>
      <description><![CDATA[The EU's Cyber Resilience Act will impose mandatory cybersecurity requirements on all software sold in Europe. Here's what developers need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/eu-cyber-resilience-act-impact-on-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eu-cyber-resilience-act-impact-on-developers</guid>
      <pubDate>Wed, 28 Jan 2026 07:34:53 GMT</pubDate>
      <category>Compliance & Regulations</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is Output Encoding]]></title>
      <description><![CDATA[Output encoding neutralizes untrusted data before it reaches a browser or database -- the last line of defense against XSS, and most teams still get it wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-output-encoding</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-output-encoding</guid>
      <pubDate>Wed, 28 Jan 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Authentication Bypass: Common Patterns Attackers Exploit]]></title>
      <description><![CDATA[Authentication bypass vulnerabilities let attackers access protected resources without valid credentials. This guide covers the most common bypass patterns found in modern web applications and how to prevent each one.]]></description>
      <link>https://safeguard.sh/resources/blog/authentication-bypass-common-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/authentication-bypass-common-patterns</guid>
      <pubDate>Wed, 28 Jan 2026 06:14:26 GMT</pubDate>
      <category>Web Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Django ORM SQL injection edge cases beyond parameterized ...]]></title>
      <description><![CDATA[Django's ORM parameterizes queries by default, but .raw(), .extra(), and annotate() calls create real SQL injection risk. Here's what to check.]]></description>
      <link>https://safeguard.sh/resources/blog/django-orm-sql-injection-edge-cases-beyond-parameterized-queries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/django-orm-sql-injection-edge-cases-beyond-parameterized-queries</guid>
      <pubDate>Wed, 28 Jan 2026 06:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[ChatGPT Plugins and the New Plugin Supply Chain Attack Surface]]></title>
      <description><![CDATA[AI plugins connect LLMs to external services, creating a supply chain of trust that most users never examine. The risks are significant.]]></description>
      <link>https://safeguard.sh/resources/blog/chatgpt-plugins-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chatgpt-plugins-supply-chain-risks</guid>
      <pubDate>Wed, 28 Jan 2026 04:53:59 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What is Input Sanitization]]></title>
      <description><![CDATA[Input sanitization stops attacker-controlled data from executing as code. Learn how it works, how it differs from validation, and where it fails.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-input-sanitization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-input-sanitization</guid>
      <pubDate>Wed, 28 Jan 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[npm Install Script Security: The Code That Runs Before Your Code]]></title>
      <description><![CDATA[npm install scripts execute arbitrary code during package installation. They are the most exploited vector in JavaScript supply chain attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-install-script-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-install-script-security</guid>
      <pubDate>Wed, 28 Jan 2026 03:33:32 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[PyPI typosquatting and malicious Python packages targetin...]]></title>
      <description><![CDATA[PyPI typosquatting lets attackers slip malicious Python packages into your build with one typo. Real attacks, why PyPI is exposed, and how to stay safe.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-typosquatting-and-malicious-python-packages-targeting-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-typosquatting-and-malicious-python-packages-targeting-developers</guid>
      <pubDate>Wed, 28 Jan 2026 03:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[MOVEit Transfer CVE-2023-34362: The Zero-Day That Hit Thousands]]></title>
      <description><![CDATA[The MOVEit Transfer SQL injection zero-day exploited by Cl0p ransomware gang became 2023's most impactful vulnerability. Here's the full technical analysis.]]></description>
      <link>https://safeguard.sh/resources/blog/moveit-transfer-cve-2023-34362-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/moveit-transfer-cve-2023-34362-analysis</guid>
      <pubDate>Wed, 28 Jan 2026 02:13:06 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What Are Parameterized Queries]]></title>
      <description><![CDATA[Parameterized queries stop SQL injection by binding user input as data instead of parsing it as SQL — here's how they work, and where they still fail.]]></description>
      <link>https://safeguard.sh/resources/blog/what-are-parameterized-queries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-are-parameterized-queries</guid>
      <pubDate>Wed, 28 Jan 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Securing Your Private Package Registry]]></title>
      <description><![CDATA[Private package registries are high-value targets for supply chain attackers. Here is how to lock them down, from access controls to dependency confusion prevention.]]></description>
      <link>https://safeguard.sh/resources/blog/private-package-registry-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/private-package-registry-security</guid>
      <pubDate>Wed, 28 Jan 2026 00:52:39 GMT</pubDate>
      <category>How-To Guide</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Django SECRET_KEY exposure and settings.py secret managem...]]></title>
      <description><![CDATA[A Django SECRET_KEY exposure can silently unravel session security, CSRF protection, and signed tokens. Here's how to find, fix, and prevent it for good.]]></description>
      <link>https://safeguard.sh/resources/blog/django-secretkey-exposure-and-settingspy-secret-management-mistakes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/django-secretkey-exposure-and-settingspy-secret-management-mistakes</guid>
      <pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Rspack npm Account Takeover: 2024 Incident Analysis]]></title>
      <description><![CDATA[Compromised npm tokens pushed crypto-miner versions of @rspack/core and @rspack/cli in December 2024. Timeline, payload, and what downstream teams missed.]]></description>
      <link>https://safeguard.sh/resources/blog/rspack-npm-account-takeover-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rspack-npm-account-takeover-2024</guid>
      <pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Security Implications of Package Bundlers]]></title>
      <description><![CDATA[Bundlers transform your code and dependencies into production artifacts. The security implications of this transformation are significant and widely overlooked.]]></description>
      <link>https://safeguard.sh/resources/blog/security-implications-package-bundlers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-implications-package-bundlers</guid>
      <pubDate>Tue, 27 Jan 2026 23:32:12 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[TLS Library Comparison: OpenSSL vs BoringSSL vs LibreSSL vs rustls]]></title>
      <description><![CDATA[Your TLS library choice has massive security implications. Here is an honest comparison of the major options and what each trade-off means.]]></description>
      <link>https://safeguard.sh/resources/blog/tls-library-comparison-openssl-boringssl</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tls-library-comparison-openssl-boringssl</guid>
      <pubDate>Tue, 27 Jan 2026 22:11:46 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Legal Tech Software Security and Compliance Considerations]]></title>
      <description><![CDATA[Law firms and legal tech companies handle privileged data through increasingly complex software. Here's how to manage the software supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/legal-tech-software-security-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/legal-tech-software-security-compliance</guid>
      <pubDate>Tue, 27 Jan 2026 20:51:19 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[HIPAA and Software Supply Chain Compliance for Health Tech]]></title>
      <description><![CDATA[HIPAA's Security Rule requires safeguards that extend to software dependencies. Here's what health tech developers and vendors need to address.]]></description>
      <link>https://safeguard.sh/resources/blog/hipaa-software-supply-chain-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hipaa-software-supply-chain-compliance</guid>
      <pubDate>Tue, 27 Jan 2026 19:30:52 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Developer-Focused Security Awareness for Supply Chain]]></title>
      <description><![CDATA[A supply-chain-specific developer awareness curriculum that replaces generic phishing drills with content engineers actually need, measured by behavior change.]]></description>
      <link>https://safeguard.sh/resources/blog/security-awareness-training-developer-focused-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-awareness-training-developer-focused-supply-chain</guid>
      <pubDate>Tue, 27 Jan 2026 18:10:26 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Validation and Quality Checks: Ensuring Your SBOMs Are Actually Useful]]></title>
      <description><![CDATA[A syntactically valid SBOM can still be useless. Here's how to validate structure, completeness, and accuracy to produce SBOMs worth trusting.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-validation-quality-checks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-validation-quality-checks</guid>
      <pubDate>Tue, 27 Jan 2026 16:49:59 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Swift Security Analysis Tools: The Current Landscape]]></title>
      <description><![CDATA[Swift's type safety helps, but it does not eliminate all security bugs. Here is the current tooling landscape for finding vulnerabilities in Swift code.]]></description>
      <link>https://safeguard.sh/resources/blog/swift-security-analysis-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/swift-security-analysis-tools</guid>
      <pubDate>Tue, 27 Jan 2026 15:29:32 GMT</pubDate>
      <category>Secure Development</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Malware Detection Techniques for Package Registries]]></title>
      <description><![CDATA[Malicious packages on npm, PyPI, and other registries are surging. Here are the techniques researchers and tools use to detect them.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-malware-detection-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-malware-detection-techniques</guid>
      <pubDate>Tue, 27 Jan 2026 14:09:06 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[GCP Binary Authorization: Enforcing Container Trust at Deploy Time]]></title>
      <description><![CDATA[A practical walkthrough of Binary Authorization on GKE, from attestor setup to break-glass procedures and CI/CD integration.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-binary-authorization-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-binary-authorization-guide</guid>
      <pubDate>Tue, 27 Jan 2026 12:48:39 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs AI21 Jurassic for Security Workflows]]></title>
      <description><![CDATA[]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-ai21-jurassic-security-workflows</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-ai21-jurassic-security-workflows</guid>
      <pubDate>Tue, 27 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cache Hit Optimisation: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Prompt caching and engine memoisation combine to make Griffin AI scans repeat-cheap. Pure-LLM tools recompute the same reasoning on every run.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cache-hit-optimisation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cache-hit-optimisation</guid>
      <pubDate>Tue, 27 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Inside the Apache Foundation's Security Practices]]></title>
      <description><![CDATA[The Apache Software Foundation oversees 350+ projects including some of the most widely deployed software on earth. Their security practices set the standard for foundation-governed open source.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-foundation-security-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-foundation-security-practices</guid>
      <pubDate>Tue, 27 Jan 2026 11:28:12 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Serverless Security: Supply Chain Risks in Lambda, Cloud Functions, and Azure Functions]]></title>
      <description><![CDATA[Serverless architectures shift the attack surface from infrastructure to application dependencies. This guide covers the unique supply chain risks of serverless and how to address them.]]></description>
      <link>https://safeguard.sh/resources/blog/serverless-security-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/serverless-security-supply-chain-risks</guid>
      <pubDate>Tue, 27 Jan 2026 10:07:45 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What is the Principle of Least Functionality]]></title>
      <description><![CDATA[The principle of least functionality (NIST CM-7) means shipping only the ports, services, and code a system needs—nothing extra "just in case."]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-the-principle-of-least-functionality</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-the-principle-of-least-functionality</guid>
      <pubDate>Tue, 27 Jan 2026 10:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Azure DevOps Supply Chain Hardening Guide]]></title>
      <description><![CDATA[A senior engineer's 2026 playbook for hardening Azure DevOps against the supply chain attacks that actually happen: extensions, service connections, and template injection.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-devops-supply-chain-hardening-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-devops-supply-chain-hardening-guide</guid>
      <pubDate>Tue, 27 Jan 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Container Security Solutions vs Platforms: What You're Actually Buying]]></title>
      <description><![CDATA[Container security solutions and container security platforms get marketed almost interchangeably — here's the actual difference in scope and what each one leaves you to build yourself.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-solutions-vs-platforms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-solutions-vs-platforms</guid>
      <pubDate>Tue, 27 Jan 2026 09:00:00 GMT</pubDate>
      <category>Containers</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[DevOps Pipeline Tools: A Buyer's Map by Stage]]></title>
      <description><![CDATA[DevOps pipeline tools cluster around six stages of the software lifecycle — mapping a shortlist to the stage it actually serves prevents the most common buying mistake: overlap without coverage.]]></description>
      <link>https://safeguard.sh/resources/blog/devops-pipeline-tools-a-buyers-map</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devops-pipeline-tools-a-buyers-map</guid>
      <pubDate>Tue, 27 Jan 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Pinning Python dependencies: requirements.txt vs Poetry a...]]></title>
      <description><![CDATA[A practical guide to python dependency pinning with requirements.txt, pip-tools, and Poetry — locked, hash-verified builds instead of moving-target dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/pinning-python-dependencies-requirementstxt-vs-poetry-and-pip-tools-lock-files</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pinning-python-dependencies-requirementstxt-vs-poetry-and-pip-tools-lock-files</guid>
      <pubDate>Tue, 27 Jan 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[NIST SSDF v1.1: Practical Adoption Notes]]></title>
      <description><![CDATA[NIST SP 800-218 became the de facto baseline for federal software attestation in 2023. Here is how to adopt SSDF v1.1 without drowning in paperwork.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-ssdf-v1-1-practical-adoption</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-ssdf-v1-1-practical-adoption</guid>
      <pubDate>Tue, 27 Jan 2026 08:47:19 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Malware Analysis Techniques for Suspicious npm Packages]]></title>
      <description><![CDATA[When an npm package looks suspicious, you need a systematic approach to determine if it is malicious. These analysis techniques separate noise from genuine threats.]]></description>
      <link>https://safeguard.sh/resources/blog/malware-analysis-npm-packages-techniques</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malware-analysis-npm-packages-techniques</guid>
      <pubDate>Tue, 27 Jan 2026 07:26:52 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Defense in Depth]]></title>
      <description><![CDATA[Defense in depth stacks independent security layers—source, build, dependencies, artifacts, runtime—so no single failure causes a breach.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-defense-in-depth</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-defense-in-depth</guid>
      <pubDate>Tue, 27 Jan 2026 07:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Low-Code/No-Code Platforms: The Shadow Supply Chain in Your Organization]]></title>
      <description><![CDATA[Citizen developers are building applications on low-code platforms faster than security teams can assess them. The supply chain risks are real and growing.]]></description>
      <link>https://safeguard.sh/resources/blog/low-code-no-code-platform-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/low-code-no-code-platform-security-risks</guid>
      <pubDate>Tue, 27 Jan 2026 06:06:25 GMT</pubDate>
      <category>Industry Trends</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Django CSRF protection and common session security miscon...]]></title>
      <description><![CDATA[Django's CSRF defaults are solid, but wildcards, exempted webhooks, and reordered middleware quietly undo them. Here's where django csrf misconfiguration actually happens.]]></description>
      <link>https://safeguard.sh/resources/blog/django-csrf-protection-and-common-session-security-misconfigurations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/django-csrf-protection-and-common-session-security-misconfigurations</guid>
      <pubDate>Tue, 27 Jan 2026 06:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Google Assured Open Source Software: Curated Security for Enterprise Dependencies]]></title>
      <description><![CDATA[Google's Assured OSS service provides enterprise-grade security guarantees for open source packages. It's a compelling model, but it raises questions about who controls the open source supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/google-assured-open-source-software-service</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/google-assured-open-source-software-service</guid>
      <pubDate>Tue, 27 Jan 2026 04:45:59 GMT</pubDate>
      <category>Tools & Platforms</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What is Security by Obscurity]]></title>
      <description><![CDATA[Security by obscurity means hiding a system instead of securing it. Here's why that bet fails, with real breaches, real CVEs, and what to build instead.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-security-by-obscurity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-security-by-obscurity</guid>
      <pubDate>Tue, 27 Jan 2026 04:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Double Extortion Ransomware: How Data Theft Changed the Game]]></title>
      <description><![CDATA[Double extortion transformed ransomware from a reversible nuisance into an irreversible data breach. The evolution from encryption-only to data theft fundamentally changed the threat model.]]></description>
      <link>https://safeguard.sh/resources/blog/double-extortion-ransomware-evolution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/double-extortion-ransomware-evolution</guid>
      <pubDate>Tue, 27 Jan 2026 03:25:32 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Auditing Python dependencies with pip-audit and Safety]]></title>
      <description><![CDATA[A hands-on pip-audit tutorial covering Python dependency scanning, Safety CLI comparisons, and a workflow for catching PyPI vulnerabilities before release.]]></description>
      <link>https://safeguard.sh/resources/blog/auditing-python-dependencies-with-pip-audit-and-safety</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/auditing-python-dependencies-with-pip-audit-and-safety</guid>
      <pubDate>Tue, 27 Jan 2026 03:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Django Security and Supply Chain Guide]]></title>
      <description><![CDATA[Securing Django applications with built-in security features, dependency management, and supply chain protections.]]></description>
      <link>https://safeguard.sh/resources/blog/django-security-supply-chain-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/django-security-supply-chain-guide</guid>
      <pubDate>Tue, 27 Jan 2026 02:05:05 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is a Trust Store]]></title>
      <description><![CDATA[Trust stores decide which signatures your systems believe. Here's how they work, why they matter for supply chain security, and how to audit them.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-trust-store</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-trust-store</guid>
      <pubDate>Tue, 27 Jan 2026 01:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Subresource Integrity Failures: When CDN Trust Goes Wrong]]></title>
      <description><![CDATA[SRI protects against CDN compromises and supply chain attacks on client-side scripts. Most web applications do not use it. Here is what they are missing.]]></description>
      <link>https://safeguard.sh/resources/blog/subresource-integrity-failures-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/subresource-integrity-failures-guide</guid>
      <pubDate>Tue, 27 Jan 2026 00:44:39 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Rails mass assignment vulnerabilities and the strong para...]]></title>
      <description><![CDATA[How a 2012 GitHub hack exposed Rails' mass assignment flaw, why attr_accessible failed, and how strong parameters became the lasting fix.]]></description>
      <link>https://safeguard.sh/resources/blog/rails-mass-assignment-vulnerabilities-and-the-strong-parameters-fix</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rails-mass-assignment-vulnerabilities-and-the-strong-parameters-fix</guid>
      <pubDate>Tue, 27 Jan 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Artifactory Security Best Practices for Enterprise Teams]]></title>
      <description><![CDATA[JFrog Artifactory is a universal artifact manager. Getting its security right requires understanding its permission model, Xray integration, and access token management.]]></description>
      <link>https://safeguard.sh/resources/blog/artifactory-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/artifactory-security-best-practices</guid>
      <pubDate>Mon, 26 Jan 2026 23:24:12 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Requirements for Financial Services: What You Need to Know]]></title>
      <description><![CDATA[Financial regulators are tightening software transparency requirements. Here's what banks, fintechs, and financial institutions need to know about SBOMs.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-requirements-financial-services</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-requirements-financial-services</guid>
      <pubDate>Mon, 26 Jan 2026 22:03:45 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Container Vulnerability Scanning: Comparing the Top Tools in 2023]]></title>
      <description><![CDATA[Not all container scanners are equal. We compared Trivy, Grype, Snyk Container, and others on accuracy, speed, and coverage.]]></description>
      <link>https://safeguard.sh/resources/blog/container-vulnerability-scanning-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-vulnerability-scanning-comparison</guid>
      <pubDate>Mon, 26 Jan 2026 20:43:18 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Sonatype: A Head-to-Head SCA Comparison]]></title>
      <description><![CDATA[We break down the real differences between Snyk and Sonatype for software composition analysis, covering vulnerability detection, developer experience, and pricing.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-sonatype-comparison-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-sonatype-comparison-2023</guid>
      <pubDate>Mon, 26 Jan 2026 19:22:52 GMT</pubDate>
      <category>Tool Comparisons</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Elixir and Hex Package Security: Protecting the BEAM Ecosystem]]></title>
      <description><![CDATA[Elixir's Hex package manager serves a smaller but growing ecosystem. Smaller does not mean safer — here is what Elixir teams need to know about dependency security.]]></description>
      <link>https://safeguard.sh/resources/blog/elixir-hex-package-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/elixir-hex-package-security</guid>
      <pubDate>Mon, 26 Jan 2026 18:02:25 GMT</pubDate>
      <category>Developer Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[SBOMs for SaaS Products: What Customers Are Starting to Demand]]></title>
      <description><![CDATA[SBOMs were originally for on-premises software. Now SaaS customers are asking for them too. Here is what that means and how to respond.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-saas-products</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-saas-products</guid>
      <pubDate>Mon, 26 Jan 2026 16:41:58 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Environment Variable Injection in CI/CD Pipelines]]></title>
      <description><![CDATA[Environment variables in CI/CD systems carry secrets, configuration, and control flow. When attackers can inject or modify them, everything breaks.]]></description>
      <link>https://safeguard.sh/resources/blog/environment-variable-injection-ci-cd</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/environment-variable-injection-ci-cd</guid>
      <pubDate>Mon, 26 Jan 2026 15:21:32 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How Google Secures Its Software Supply Chain]]></title>
      <description><![CDATA[An inside look at Google's multi-layered approach to supply chain security, from Binary Authorization to SLSA, and what other organizations can adapt from their model.]]></description>
      <link>https://safeguard.sh/resources/blog/how-google-secures-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-google-secures-software-supply-chain</guid>
      <pubDate>Mon, 26 Jan 2026 14:01:05 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[MSI Breach: Intel Boot Guard Keys Leaked After Ransomware Attack]]></title>
      <description><![CDATA[The Money Message ransomware gang breached MSI and leaked Intel Boot Guard private keys, undermining firmware security for millions of devices.]]></description>
      <link>https://safeguard.sh/resources/blog/msi-breach-intel-boot-guard-keys-leaked</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/msi-breach-intel-boot-guard-keys-leaked</guid>
      <pubDate>Mon, 26 Jan 2026 12:40:38 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise RAG Security Rollout Antipatterns]]></title>
      <description><![CDATA[Retrieval-augmented generation systems are where enterprise AI meets enterprise data, and where most security rollouts stumble. A catalog of the antipatterns we keep seeing.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-rag-security-rollout-antipatterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-rag-security-rollout-antipatterns</guid>
      <pubDate>Mon, 26 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CWE Classification Accuracy: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Getting the CWE right is not a taxonomic hobby. It drives remediation, compliance mapping, and detection engineering. Here is how grounded and pure-LLM scanners compare.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cwe-classification-accuracy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cwe-classification-accuracy</guid>
      <pubDate>Mon, 26 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Qwen for Code Security]]></title>
      <description><![CDATA[Qwen's open-weight models have strong code benchmarks. We dig into how they compare to Griffin AI when the workflow is real code security, not just leetcode.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-qwen-for-code-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-qwen-for-code-security</guid>
      <pubDate>Mon, 26 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Business Logic Vulnerabilities: The Flaws Scanners Cannot Find]]></title>
      <description><![CDATA[Business logic vulnerabilities bypass every automated scanner because they are not coding errors. They are design errors. Here is how to identify and prevent them.]]></description>
      <link>https://safeguard.sh/resources/blog/business-logic-vulnerabilities-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/business-logic-vulnerabilities-guide</guid>
      <pubDate>Mon, 26 Jan 2026 11:20:12 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SLSA v1.0: Supply-chain Levels for Software Artifacts Reaches Maturity]]></title>
      <description><![CDATA[SLSA v1.0 simplifies the framework and makes it practical to adopt. Here's what changed and how to implement it.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-levels-for-software-artifacts-slsa-v1</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-levels-for-software-artifacts-slsa-v1</guid>
      <pubDate>Mon, 26 Jan 2026 09:59:45 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Cilium Tetragon Runtime Security with eBPF]]></title>
      <description><![CDATA[A practical look at Cilium Tetragon for Kubernetes runtime security, what eBPF gives you that audit logs do not, and where Tetragon fits in a real stack.]]></description>
      <link>https://safeguard.sh/resources/blog/cilium-tetragon-runtime-security-ebpf</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cilium-tetragon-runtime-security-ebpf</guid>
      <pubDate>Mon, 26 Jan 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Build a Software Supply Chain Program in 90 Days]]></title>
      <description><![CDATA[A pragmatic, phase-by-phase blueprint for standing up a credible software supply chain security program inside a single fiscal quarter without boiling the ocean.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-build-a-software-supply-chain-program-90-days</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-build-a-software-supply-chain-program-90-days</guid>
      <pubDate>Mon, 26 Jan 2026 09:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Rails YAML deserialization RCE history and CVE-2013-0156 ...]]></title>
      <description><![CDATA[A deep dive into CVE-2013-0156, the Rails YAML deserialization RCE that let attackers execute code via crafted requests, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/rails-yaml-deserialization-rce-history-and-cve-2013-0156-lessons</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rails-yaml-deserialization-rce-history-and-cve-2013-0156-lessons</guid>
      <pubDate>Mon, 26 Jan 2026 09:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Security Implications of Semantic Versioning]]></title>
      <description><![CDATA[Semver promises predictability in dependency management. In practice, it creates a trust model with serious security implications that most developers do not consider.]]></description>
      <link>https://safeguard.sh/resources/blog/semantic-versioning-security-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/semantic-versioning-security-implications</guid>
      <pubDate>Mon, 26 Jan 2026 08:39:18 GMT</pubDate>
      <category>Dependency Management</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CISA KEV Catalog: One Year Analysis of Known Exploited Vulnerabilities]]></title>
      <description><![CDATA[After one year, the CISA KEV catalog has reshaped how organizations prioritize patching. Here's what the data tells us about real-world exploitation.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-kev-catalog-one-year-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-kev-catalog-one-year-analysis</guid>
      <pubDate>Mon, 26 Jan 2026 07:18:52 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is a Man-in-the-Browser Attack]]></title>
      <description><![CDATA[Man-in-the-browser malware rewrites transactions inside a victim's own browser, bypassing TLS and OTP 2FA -- here's how it works and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-man-in-the-browser-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-man-in-the-browser-attack</guid>
      <pubDate>Mon, 26 Jan 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Auditing Rails applications' Gemfile for vulnerable depen...]]></title>
      <description><![CDATA[A practical guide to auditing your Rails Gemfile and Gemfile.lock for vulnerable dependencies using bundler-audit, from triage through CI automation.]]></description>
      <link>https://safeguard.sh/resources/blog/auditing-rails-applications-gemfile-for-vulnerable-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/auditing-rails-applications-gemfile-for-vulnerable-dependencies</guid>
      <pubDate>Mon, 26 Jan 2026 06:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Post-Breach Supply Chain Hardening: Lessons from Real Incidents]]></title>
      <description><![CDATA[After a supply chain breach, the remediation window is your best opportunity to implement controls that should have existed before the incident. This guide covers what to harden and in what order.]]></description>
      <link>https://safeguard.sh/resources/blog/post-breach-supply-chain-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/post-breach-supply-chain-hardening</guid>
      <pubDate>Mon, 26 Jan 2026 05:58:25 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[CISA Secure by Design Principles: What They Mean for Software Teams]]></title>
      <description><![CDATA[CISA's Secure by Design initiative shifts security responsibility from users to manufacturers. Here's what it means for how you build software.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-secure-by-design-principles</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-secure-by-design-principles</guid>
      <pubDate>Mon, 26 Jan 2026 04:37:58 GMT</pubDate>
      <category>Compliance & Regulations</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[What is Credential Rotation]]></title>
      <description><![CDATA[Credential rotation limits how long a leaked API key, password, or token stays valid. Here's how it works, how often to do it, and why automation matters.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-credential-rotation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-credential-rotation</guid>
      <pubDate>Mon, 26 Jan 2026 04:00:00 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[PaperCut CVE-2023-27350: When Print Management Software Becomes a Ransomware Gateway]]></title>
      <description><![CDATA[CVE-2023-27350 in PaperCut NG/MF allowed unauthenticated RCE through the print management server. Cl0p and LockBit ransomware groups jumped on it within days.]]></description>
      <link>https://safeguard.sh/resources/blog/papercut-cve-2023-27350-rce-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/papercut-cve-2023-27350-rce-exploitation</guid>
      <pubDate>Mon, 26 Jan 2026 03:17:31 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Rails Active Record SQL injection via raw queries and str...]]></title>
      <description><![CDATA[A concrete look at how raw SQL and string interpolation reopen rails active record sql injection risk, from CVE-2012-2695 to modern where-clause and order-by exploits.]]></description>
      <link>https://safeguard.sh/resources/blog/rails-active-record-sql-injection-via-raw-queries-and-string-interpolation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rails-active-record-sql-injection-via-raw-queries-and-string-interpolation</guid>
      <pubDate>Mon, 26 Jan 2026 03:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Pin GitHub Actions to SHAs Correctly]]></title>
      <description><![CDATA[A hands-on guide to pinning every third-party GitHub Action to a full commit SHA, automating updates with Dependabot, and avoiding the common pitfalls.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-pin-github-actions-to-shas-correctly</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-pin-github-actions-to-shas-correctly</guid>
      <pubDate>Mon, 26 Jan 2026 01:57:05 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Just-in-Time Access]]></title>
      <description><![CDATA[Just-in-time access grants time-bound, task-scoped permissions instead of standing privileges -- here's how it works, its benefits, and how to implement it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-just-in-time-access</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-just-in-time-access</guid>
      <pubDate>Mon, 26 Jan 2026 01:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[GitLab CI/CD Security Configuration]]></title>
      <description><![CDATA[Hardening GitLab CI/CD pipelines with protected variables, secure runners, and built-in security scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-cicd-security-configuration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-cicd-security-configuration</guid>
      <pubDate>Mon, 26 Jan 2026 00:36:38 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[FastAPI and Pydantic dependency injection security pitfalls]]></title>
      <description><![CDATA[FastAPI's Depends() and Pydantic's type validation look airtight but hide real bypass patterns — caching bugs, extra="allow" mass assignment, and leaked test overrides.]]></description>
      <link>https://safeguard.sh/resources/blog/fastapi-and-pydantic-dependency-injection-security-pitfalls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fastapi-and-pydantic-dependency-injection-security-pitfalls</guid>
      <pubDate>Mon, 26 Jan 2026 00:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Intelligence (OSINT) for Supply Chain Security]]></title>
      <description><![CDATA[How OSINT techniques can uncover supply chain threats hiding in plain sight—from compromised packages to suspicious maintainer activity.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-intelligence-osint-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-intelligence-osint-supply-chain</guid>
      <pubDate>Sun, 25 Jan 2026 23:16:11 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[npm Manifest Confusion: The Hidden Vulnerability in Every Node.js Project]]></title>
      <description><![CDATA[A fundamental flaw in npm's package handling allowed published package metadata to differ from actual package contents, undermining trust in the entire ecosystem.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-manifest-confusion-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-manifest-confusion-vulnerability</guid>
      <pubDate>Sun, 25 Jan 2026 21:55:45 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Maven Plugin Verification: Trusting Your Build-Time Dependencies]]></title>
      <description><![CDATA[Maven plugins execute during your build with full system access. Verifying them is harder than verifying runtime dependencies, and most teams skip it.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-plugin-verification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-plugin-verification</guid>
      <pubDate>Sun, 25 Jan 2026 20:35:18 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Choosing Between SCA Tools in 2023]]></title>
      <description><![CDATA[A no-nonsense comparison of software composition analysis tools to help you pick the right one for your team's needs, budget, and workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/choosing-between-sca-tools-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/choosing-between-sca-tools-2023</guid>
      <pubDate>Sun, 25 Jan 2026 19:14:51 GMT</pubDate>
      <category>Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[A Taxonomy of Open Source Supply Chain Attacks]]></title>
      <description><![CDATA[Supply chain attacks on open source come in distinct flavors. Understanding the taxonomy helps defenders prioritize controls and recognize threats before they reach production.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-supply-chain-attack-taxonomy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-supply-chain-attack-taxonomy</guid>
      <pubDate>Sun, 25 Jan 2026 17:54:25 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Black Duck SCA: The Enterprise Stalwart of Open Source Security]]></title>
      <description><![CDATA[A review of Synopsys Black Duck for software composition analysis, covering its strengths in license compliance, vulnerability detection, and enterprise governance.]]></description>
      <link>https://safeguard.sh/resources/blog/black-duck-software-composition-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/black-duck-software-composition-analysis</guid>
      <pubDate>Sun, 25 Jan 2026 16:33:58 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Software Escrow and Supply Chain Continuity Planning]]></title>
      <description><![CDATA[What happens when a critical vendor disappears? Software escrow arrangements protect your business continuity, but most organizations get the implementation wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/software-escrow-supply-chain-continuity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-escrow-supply-chain-continuity</guid>
      <pubDate>Sun, 25 Jan 2026 15:13:31 GMT</pubDate>
      <category>Risk Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[The Shared Responsibility Model for Software Supply Chain Security]]></title>
      <description><![CDATA[Cloud providers defined the shared responsibility model for infrastructure. Software supply chains need the same clarity about who is responsible for what.]]></description>
      <link>https://safeguard.sh/resources/blog/shared-responsibility-model-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shared-responsibility-model-supply-chain</guid>
      <pubDate>Sun, 25 Jan 2026 13:53:05 GMT</pubDate>
      <category>Risk Management</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Calico Network Policy Best Practices for Production Kubernetes]]></title>
      <description><![CDATA[Calico is the most widely deployed Kubernetes network plugin. Its policy model is powerful but has gotchas that trip up even experienced teams.]]></description>
      <link>https://safeguard.sh/resources/blog/calico-network-policy-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/calico-network-policy-best-practices</guid>
      <pubDate>Sun, 25 Jan 2026 12:32:38 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SecBench Methodology Reviewed]]></title>
      <description><![CDATA[SecBench positioned itself as a comprehensive cybersecurity knowledge and reasoning benchmark for LLMs. A methodology review of its construction, scoring, and the gaps that separate the advertised coverage from what the benchmark actually exercises.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-benchmark-secbench-methodology</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-benchmark-secbench-methodology</guid>
      <pubDate>Sun, 25 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Claude Sonnet for Remediation]]></title>
      <description><![CDATA[Claude Sonnet is the workhorse model Griffin leans on for remediation. Here's how raw Sonnet compares to Sonnet inside Griffin's remediation pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-claude-sonnet-for-remediation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-claude-sonnet-for-remediation</guid>
      <pubDate>Sun, 25 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Data Residency Controls: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Data residency is no longer a procurement checkbox. It is an architectural property that most pure-LLM vendors cannot deliver without major rework.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-data-residency-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-data-residency-controls</guid>
      <pubDate>Sun, 25 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Software Heritage and the Case for Source Code Preservation]]></title>
      <description><![CDATA[Software Heritage archives the world's source code. Here is why that matters for supply chain security, reproducibility, and long-term software integrity.]]></description>
      <link>https://safeguard.sh/resources/blog/software-heritage-archive-preservation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-heritage-archive-preservation</guid>
      <pubDate>Sun, 25 Jan 2026 11:12:11 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CISA SBOM Mandate Enforcement Begins: What Federal Contractors Need to Know]]></title>
      <description><![CDATA[CISA is moving from SBOM guidance to enforcement in 2026. Here's what the mandate requires and how to prepare.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-sbom-mandate-enforcement-begins</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-sbom-mandate-enforcement-begins</guid>
      <pubDate>Sun, 25 Jan 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Getting Started with Safeguard IDE Extension (VS Code)]]></title>
      <description><![CDATA[A step-by-step walkthrough for installing, configuring, and using the Safeguard VS Code extension to catch supply chain issues before you commit.]]></description>
      <link>https://safeguard.sh/resources/blog/getting-started-safeguard-ide-extension-vscode</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/getting-started-safeguard-ide-extension-vscode</guid>
      <pubDate>Sun, 25 Jan 2026 10:00:00 GMT</pubDate>
      <category>Tutorials</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software Attestation in Practice: From Theory to Implementation]]></title>
      <description><![CDATA[Software attestation is moving from academic concept to practical requirement. Here's how to implement it in your build pipelines today.]]></description>
      <link>https://safeguard.sh/resources/blog/software-attestation-in-practice</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-attestation-in-practice</guid>
      <pubDate>Sun, 25 Jan 2026 09:51:44 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Async Python request smuggling risks in Starlette and Uvi...]]></title>
      <description><![CDATA[Starlette request smuggling exploits parsing gaps between proxies and Uvicorn/h11. Learn the CL.TE mechanics, a real CVE, and how Safeguard closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/async-python-request-smuggling-risks-in-starlette-and-uvicorn</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/async-python-request-smuggling-risks-in-starlette-and-uvicorn</guid>
      <pubDate>Sun, 25 Jan 2026 09:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Post-Install Hooks in Package Managers: The Universal Backdoor Mechanism]]></title>
      <description><![CDATA[Almost every package manager supports post-install hooks that run arbitrary code. This is the most abused feature in supply chain attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/post-install-hooks-package-managers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/post-install-hooks-package-managers</guid>
      <pubDate>Sun, 25 Jan 2026 08:31:18 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Measuring Security Program Effectiveness]]></title>
      <description><![CDATA[Beyond vulnerability counts: practical metrics and measurement frameworks that actually tell you whether your security program is working.]]></description>
      <link>https://safeguard.sh/resources/blog/measuring-security-program-effectiveness</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/measuring-security-program-effectiveness</guid>
      <pubDate>Sun, 25 Jan 2026 07:10:51 GMT</pubDate>
      <category>Organizational Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is a Security Compliance Framework]]></title>
      <description><![CDATA[A concrete breakdown of what security compliance frameworks are, which ones software companies actually need, and how long certification really takes.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-security-compliance-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-security-compliance-framework</guid>
      <pubDate>Sun, 25 Jan 2026 07:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Common OAuth2 and JWT implementation mistakes in FastAPI ...]]></title>
      <description><![CDATA[A practical walkthrough of the FastAPI JWT security mistakes that lead to broken authentication, plus concrete fixes for OAuth2 flows and token validation.]]></description>
      <link>https://safeguard.sh/resources/blog/common-oauth2-and-jwt-implementation-mistakes-in-fastapi-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/common-oauth2-and-jwt-implementation-mistakes-in-fastapi-applications</guid>
      <pubDate>Sun, 25 Jan 2026 06:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[3CX Desktop App: Anatomy of a Cascading Breach]]></title>
      <description><![CDATA[How a Trading Technologies installer from 2022 poisoned the 3CX build pipeline in 2023, producing the first publicly confirmed cascading supply chain attack.]]></description>
      <link>https://safeguard.sh/resources/blog/3cx-desktop-app-cascading-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/3cx-desktop-app-cascading-breach</guid>
      <pubDate>Sun, 25 Jan 2026 05:50:24 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Chaos Engineering for Supply Chain Resilience: Breaking Your Build to Make It Stronger]]></title>
      <description><![CDATA[Chaos engineering principles applied to the software supply chain reveal hidden dependencies, single points of failure, and degradation paths that only surface under stress.]]></description>
      <link>https://safeguard.sh/resources/blog/chaos-engineering-supply-chain-resilience</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chaos-engineering-supply-chain-resilience</guid>
      <pubDate>Sun, 25 Jan 2026 04:29:58 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What is a CI/CD Pipeline]]></title>
      <description><![CDATA[A CI/CD pipeline automates code from commit to deployment—but SolarWinds, Codecov, and CircleCI show it's also a top supply-chain attack target.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-cicd-pipeline</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-cicd-pipeline</guid>
      <pubDate>Sun, 25 Jan 2026 04:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Modern Command Injection Prevention: Beyond the Basics]]></title>
      <description><![CDATA[Command injection remains in the OWASP Top 10 because developers keep making the same mistakes with new tools. Here is a modern prevention guide covering containers, serverless, and CI/CD.]]></description>
      <link>https://safeguard.sh/resources/blog/command-injection-prevention-modern</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/command-injection-prevention-modern</guid>
      <pubDate>Sun, 25 Jan 2026 03:09:31 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[PyPI malware campaigns targeting machine learning and dat...]]></title>
      <description><![CDATA[PyPI malware ML packages have hit PyTorch and Ultralytics YOLO via dependency confusion and CI/CD compromise. What happened, and how to defend your ML supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-malware-campaigns-targeting-machine-learning-and-data-science-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-malware-campaigns-targeting-machine-learning-and-data-science-packages</guid>
      <pubDate>Sun, 25 Jan 2026 03:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Startup Security at Growth Stage: Building Enterprise-Grade Programs]]></title>
      <description><![CDATA[Post-Series B, your startup is becoming an enterprise. Security programs that worked for 30 engineers will not work for 300. Here is how to build security that scales with your ambitions.]]></description>
      <link>https://safeguard.sh/resources/blog/startup-security-growth-stage-enterprise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/startup-security-growth-stage-enterprise</guid>
      <pubDate>Sun, 25 Jan 2026 01:49:04 GMT</pubDate>
      <category>Startup Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Running Containers in Rootless Mode: A Practical Security Guide]]></title>
      <description><![CDATA[Root in the container often means root on the host. Rootless mode breaks that assumption. Here is how to run Docker and Podman without root and why it matters more than you think.]]></description>
      <link>https://safeguard.sh/resources/blog/container-rootless-mode-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-rootless-mode-security-guide</guid>
      <pubDate>Sun, 25 Jan 2026 00:28:38 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Windows LDAP LSASS CVE-2024-49113 (LDAPNightmare)]]></title>
      <description><![CDATA[CVE-2024-49113 crashes LSASS over LDAP referrals and pairs with CVE-2024-49112 for RCE. Exploit chain, detection, and domain controller hardening.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-49113-windows-ldap-lsass-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-49113-windows-ldap-lsass-rce</guid>
      <pubDate>Sun, 25 Jan 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[npm supply chain attacks via malicious postinstall scripts]]></title>
      <description><![CDATA[How a single postinstall hook in a compromised npm package can run malware at install time, real incidents from 2018-2025, and how to defend against it.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-supply-chain-attacks-via-malicious-postinstall-scripts</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-supply-chain-attacks-via-malicious-postinstall-scripts</guid>
      <pubDate>Sun, 25 Jan 2026 00:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[State of Software Supply Chain Security 2026]]></title>
      <description><![CDATA[A senior-engineer view of where software supply chain security stands in 2026: what's changed, what's stuck, and where budgets, regulations, and attacker tactics converge.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-software-supply-chain-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-software-supply-chain-security-2026</guid>
      <pubDate>Sun, 25 Jan 2026 00:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[3CX Attack Lessons: What Every Software Vendor Must Do Differently]]></title>
      <description><![CDATA[The 3CX supply chain attack exposed critical gaps in how software vendors protect their build pipelines. Here are the concrete lessons.]]></description>
      <link>https://safeguard.sh/resources/blog/3cx-attack-lessons-for-software-vendors</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/3cx-attack-lessons-for-software-vendors</guid>
      <pubDate>Sat, 24 Jan 2026 23:08:11 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[3CX Supply Chain Attack: A Deep Dive into the North Korean Compromise]]></title>
      <description><![CDATA[The 3CX supply chain attack was a multi-stage operation linked to North Korea's Lazarus Group. Here's the full technical breakdown.]]></description>
      <link>https://safeguard.sh/resources/blog/3cx-supply-chain-attack-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/3cx-supply-chain-attack-analysis</guid>
      <pubDate>Sat, 24 Jan 2026 21:47:44 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[The March 2023 PyPI Malware Wave]]></title>
      <description><![CDATA[PyPI paused new user registration for most of May 20-23 after a March wave of typosquats and info-stealers flooded the index. Here is what happened and why.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-malware-wave-march-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-malware-wave-march-2023</guid>
      <pubDate>Sat, 24 Jan 2026 20:27:18 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[FISMA and Federal Software Security: Supply Chain Requirements Explained]]></title>
      <description><![CDATA[FISMA's authorization framework creates strict requirements for software in federal systems. Here's how supply chain security fits into the ATO process.]]></description>
      <link>https://safeguard.sh/resources/blog/fisma-federal-software-security-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fisma-federal-software-security-requirements</guid>
      <pubDate>Sat, 24 Jan 2026 19:06:51 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Azure Container Registry Security: Locking Down Your Image Pipeline]]></title>
      <description><![CDATA[How to secure Azure Container Registry with network isolation, content trust, and Microsoft Defender for Containers integration.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-container-registry-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-container-registry-security</guid>
      <pubDate>Sat, 24 Jan 2026 17:46:24 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[OpenAI ChatGPT Data Breach March 2023: What Was Exposed]]></title>
      <description><![CDATA[A bug in ChatGPT exposed user chat histories and payment information. Here's what happened and what it means for AI service security.]]></description>
      <link>https://safeguard.sh/resources/blog/openai-chatgpt-data-breach-march-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openai-chatgpt-data-breach-march-2023</guid>
      <pubDate>Sat, 24 Jan 2026 16:25:57 GMT</pubDate>
      <category>Incident Response</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Threat Modeling the Software Supply Chain]]></title>
      <description><![CDATA[Traditional threat modeling focuses on your code. Supply chain threat modeling extends to every tool, dependency, and process that touches your software. Here is how to do it systematically.]]></description>
      <link>https://safeguard.sh/resources/blog/threat-modeling-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/threat-modeling-software-supply-chain</guid>
      <pubDate>Sat, 24 Jan 2026 15:05:31 GMT</pubDate>
      <category>Threat Modeling</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Quantifying Security Debt: Methods That Actually Work]]></title>
      <description><![CDATA[Everyone talks about security debt. Almost nobody measures it. Here are practical methods for putting numbers on the security shortcuts your organization has accumulated.]]></description>
      <link>https://safeguard.sh/resources/blog/security-debt-quantification-methods</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-debt-quantification-methods</guid>
      <pubDate>Sat, 24 Jan 2026 13:45:04 GMT</pubDate>
      <category>Security Management</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GitLab CI Security Scanning Setup]]></title>
      <description><![CDATA[Step-by-step guide to enabling SAST, DAST, dependency scanning, and container scanning in GitLab CI pipelines.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-ci-security-scanning-setup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-ci-security-scanning-setup</guid>
      <pubDate>Sat, 24 Jan 2026 12:24:37 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Domain-Adapted LLMs For Vulnerability Detection in 2026]]></title>
      <description><![CDATA[Domain adaptation has quietly become the default for LLM-assisted vulnerability detection. A look at what works in 2026, what does not, and what teams should plan for next.]]></description>
      <link>https://safeguard.sh/resources/blog/domain-adapted-llm-vulnerability-detection-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/domain-adapted-llm-vulnerability-detection-2026</guid>
      <pubDate>Sat, 24 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs GPT-4o: Security Limits Exposed]]></title>
      <description><![CDATA[GPT-4o is an excellent general-purpose model. Security workflows are a specialty, and specialty work exposes the limits of general intelligence.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-gpt-4o-security-limits</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-gpt-4o-security-limits</guid>
      <pubDate>Sat, 24 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Regression Testing on Fixes: Griffin AI vs Mythos]]></title>
      <description><![CDATA[A remediation PR is only useful if it does not break anything else. Griffin AI runs targeted regression before opening; Mythos-class tools usually do not.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-regression-testing-on-fixes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-regression-testing-on-fixes</guid>
      <pubDate>Sat, 24 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AI-Generated Code Security Risks: Copilot, ChatGPT, and the New Attack Surface]]></title>
      <description><![CDATA[AI code assistants are writing a growing share of production code. The security implications are significant and largely unaddressed.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-generated-code-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-generated-code-security-risks</guid>
      <pubDate>Sat, 24 Jan 2026 11:04:11 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Prompt Injection as a Supply Chain Risk in 2026]]></title>
      <description><![CDATA[Prompt injection stopped being an LLM curiosity the moment agents started committing code. It is now a software supply chain risk and should be modeled as one.]]></description>
      <link>https://safeguard.sh/resources/blog/prompt-injection-supply-chain-risk-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prompt-injection-supply-chain-risk-2026</guid>
      <pubDate>Sat, 24 Jan 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Go Module Checksum Database: How It Secures Your Dependencies]]></title>
      <description><![CDATA[Go checksum database is one of the most underappreciated supply chain security features in any language ecosystem. Here is how it works and where it falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/go-module-checksum-database-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-module-checksum-database-security</guid>
      <pubDate>Sat, 24 Jan 2026 09:43:44 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Actions: SHA-Pin Tags or Get Burned]]></title>
      <description><![CDATA[Tag-pinning Actions feels fine until a maintainer gets compromised. Here is why SHA-pinning is the only serious option in 2026 and how to operationalize it.]]></description>
      <link>https://safeguard.sh/resources/blog/github-actions-pinning-sha-vs-tag</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-actions-pinning-sha-vs-tag</guid>
      <pubDate>Sat, 24 Jan 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[NestJS dependency injection and module configuration secu...]]></title>
      <description><![CDATA[NestJS's dependency injection container silently governs data isolation and supply-chain trust. Here's how scope, module, and factory misconfigurations turn into real security failures.]]></description>
      <link>https://safeguard.sh/resources/blog/nestjs-dependency-injection-and-module-configuration-security-pitfalls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nestjs-dependency-injection-and-module-configuration-security-pitfalls</guid>
      <pubDate>Sat, 24 Jan 2026 09:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Eagle 3.0 Release: Classifier Update]]></title>
      <description><![CDATA[Eagle 3.0 is the classification model behind Safeguard's package, image, and secret detection. Here is what changed, what moved, and what it means for alerts.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-eagle-3-0-release-malware-classifier</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-eagle-3-0-release-malware-classifier</guid>
      <pubDate>Sat, 24 Jan 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cross-Language Dependency Analysis: Bridging npm, pip, Maven, and Beyond]]></title>
      <description><![CDATA[Modern applications use multiple languages and package ecosystems. Analyzing dependencies across these boundaries requires techniques that single-ecosystem tools cannot provide.]]></description>
      <link>https://safeguard.sh/resources/blog/cross-language-dependency-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cross-language-dependency-analysis</guid>
      <pubDate>Sat, 24 Jan 2026 08:23:17 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Dynamic Application Security Testing: A Practitioner's Guide to DAST Done Right]]></title>
      <description><![CDATA[DAST finds what source code analysis cannot. Here is how to set it up, tune it, and actually get value from it in a modern CI/CD pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/dynamic-application-security-testing-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dynamic-application-security-testing-guide</guid>
      <pubDate>Sat, 24 Jan 2026 07:02:51 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[AI Cybersecurity Glossary: Key Machine Learning & Security Terms]]></title>
      <description><![CDATA[A defender's glossary of AI security terms — prompt injection, model poisoning, AI-BOM, adversarial ML — with dated, real-world incidents behind each one.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-cybersecurity-glossary-key-machine-learning-security-terms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-cybersecurity-glossary-key-machine-learning-security-terms</guid>
      <pubDate>Sat, 24 Jan 2026 07:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[package-lock.json integrity checks and the npm audit work...]]></title>
      <description><![CDATA[A step-by-step guide to verifying package-lock.json integrity, running npm audit correctly, and scanning Node.js dependencies for tampering and vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/package-lockjson-integrity-checks-and-the-npm-audit-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/package-lockjson-integrity-checks-and-the-npm-audit-workflow</guid>
      <pubDate>Sat, 24 Jan 2026 06:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Cross-Functional Security Collaboration]]></title>
      <description><![CDATA[Security isn't just the security team's problem. Building effective collaboration between security, engineering, product, and operations is essential for supply chain defense.]]></description>
      <link>https://safeguard.sh/resources/blog/cross-functional-security-collaboration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cross-functional-security-collaboration</guid>
      <pubDate>Sat, 24 Jan 2026 05:42:24 GMT</pubDate>
      <category>Security Culture</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Understanding EPSS: Exploit Prediction Scoring System Explained]]></title>
      <description><![CDATA[EPSS offers a data-driven approach to vulnerability prioritization. Learn how it works, how it compares to CVSS, and why your team should care.]]></description>
      <link>https://safeguard.sh/resources/blog/understanding-epss-exploit-prediction-scoring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/understanding-epss-exploit-prediction-scoring</guid>
      <pubDate>Sat, 24 Jan 2026 04:21:57 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Navigating AI for Source Code Analysis]]></title>
      <description><![CDATA[AI source code analysis pairs LLMs with static analysis to cut false positives and speed triage -- but reachability data still decides what's real.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-navigating-ai-for-source-code-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-navigating-ai-for-source-code-analysis</guid>
      <pubDate>Sat, 24 Jan 2026 04:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Ruby Brakeman Security Scanner: Rails-Aware Vulnerability Detection]]></title>
      <description><![CDATA[Brakeman understands Rails conventions and catches security issues that generic scanners miss. Here is how to use it effectively.]]></description>
      <link>https://safeguard.sh/resources/blog/ruby-brakeman-security-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ruby-brakeman-security-scanner</guid>
      <pubDate>Sat, 24 Jan 2026 03:01:31 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Prototype pollution vulnerabilities in Node.js and NestJS...]]></title>
      <description><![CDATA[How prototype pollution reaches NestJS apps through lodash, qs, tough-cookie, and dotenv-expand — and how Safeguard catches it before it merges.]]></description>
      <link>https://safeguard.sh/resources/blog/prototype-pollution-vulnerabilities-in-nodejs-and-nestjs-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/prototype-pollution-vulnerabilities-in-nodejs-and-nestjs-applications</guid>
      <pubDate>Sat, 24 Jan 2026 03:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Web3 Smart Contract Dependencies: A Supply Chain Security Blind Spot]]></title>
      <description><![CDATA[Smart contracts import code from unaudited libraries, creating supply chain risks that have already led to billions in losses. The Web3 ecosystem needs better tooling.]]></description>
      <link>https://safeguard.sh/resources/blog/web3-smart-contract-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/web3-smart-contract-supply-chain-security</guid>
      <pubDate>Sat, 24 Jan 2026 01:41:04 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[State of Open Source Security Report Overview]]></title>
      <description><![CDATA[Open source vulnerabilities tripled in six years, but 70-85% aren't even reachable. A data-driven look at the real state of open source security in 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-open-source-security-report-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-open-source-security-report-overview</guid>
      <pubDate>Sat, 24 Jan 2026 01:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Chrome Extension Manifest V3: What It Means for Browser Supply Chain Security]]></title>
      <description><![CDATA[Chrome's Manifest V3 restricts extension capabilities in the name of security. The changes help, but they do not solve the browser extension supply chain problem.]]></description>
      <link>https://safeguard.sh/resources/blog/chrome-extension-manifest-v3-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chrome-extension-manifest-v3-security</guid>
      <pubDate>Sat, 24 Jan 2026 00:20:37 GMT</pubDate>
      <category>Browser Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Go Modules Checksum Database: Five Years In]]></title>
      <description><![CDATA[sum.golang.org went public in August 2019. After four years of production, here is what the Go checksum database got right and what it did not.]]></description>
      <link>https://safeguard.sh/resources/blog/go-modules-checksum-database-five-years-in</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/go-modules-checksum-database-five-years-in</guid>
      <pubDate>Fri, 23 Jan 2026 23:00:10 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Service Mesh mTLS Configuration: Getting Mutual TLS Right]]></title>
      <description><![CDATA[Service meshes promise automatic mTLS. The reality involves permissive modes, certificate management complexity, and gaps that attackers can exploit.]]></description>
      <link>https://safeguard.sh/resources/blog/service-mesh-mtls-configuration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/service-mesh-mtls-configuration</guid>
      <pubDate>Fri, 23 Jan 2026 21:39:44 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[DDoS Protection for Software Distribution Infrastructure]]></title>
      <description><![CDATA[Package registries, artifact repositories, and update servers are high-value DDoS targets. Taking them down disrupts entire software supply chains.]]></description>
      <link>https://safeguard.sh/resources/blog/ddos-protection-software-distribution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ddos-protection-software-distribution</guid>
      <pubDate>Fri, 23 Jan 2026 20:19:17 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[BuildKit and Buildah: Building Containers Without Giving Away the Keys]]></title>
      <description><![CDATA[Container build tools have direct access to your source code, secrets, and registries. BuildKit and Buildah offer security features that most teams ignore. Here is what to use and why.]]></description>
      <link>https://safeguard.sh/resources/blog/buildkit-buildah-secure-container-builds</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/buildkit-buildah-secure-container-builds</guid>
      <pubDate>Fri, 23 Jan 2026 18:58:50 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Security Code Review Best Practices]]></title>
      <description><![CDATA[How to make code reviews an effective security checkpoint without turning every PR into a week-long security audit.]]></description>
      <link>https://safeguard.sh/resources/blog/security-code-review-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-code-review-best-practices</guid>
      <pubDate>Fri, 23 Jan 2026 17:38:24 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Private RSA Key Exposed in Public Repository]]></title>
      <description><![CDATA[GitHub's accidental exposure of its private RSA SSH host key in a public repository forced an emergency rotation affecting millions of developers.]]></description>
      <link>https://safeguard.sh/resources/blog/github-private-rsa-key-exposed-in-repository</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-private-rsa-key-exposed-in-repository</guid>
      <pubDate>Fri, 23 Jan 2026 16:17:57 GMT</pubDate>
      <category>Incident Response</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Code Signing Certificates and Software Supply Chain Integrity]]></title>
      <description><![CDATA[Code signing is a critical trust anchor in the software supply chain. This guide covers how it works, how it fails, and how to implement it correctly.]]></description>
      <link>https://safeguard.sh/resources/blog/code-signing-certificates-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/code-signing-certificates-supply-chain</guid>
      <pubDate>Fri, 23 Jan 2026 14:57:30 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Java Maven and Gradle Dependency Security]]></title>
      <description><![CDATA[How to secure your Java dependency chain across Maven and Gradle builds, from signature verification to repository management.]]></description>
      <link>https://safeguard.sh/resources/blog/java-maven-gradle-dependency-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/java-maven-gradle-dependency-security</guid>
      <pubDate>Fri, 23 Jan 2026 13:37:04 GMT</pubDate>
      <category>Dependency Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Git Credential Security for Organizations: Locking Down Source Access]]></title>
      <description><![CDATA[Git credentials are the keys to your source code. Here is how organizations should manage them to prevent unauthorized access and credential theft.]]></description>
      <link>https://safeguard.sh/resources/blog/git-credential-security-organizations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-credential-security-organizations</guid>
      <pubDate>Fri, 23 Jan 2026 12:16:37 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Instruction/Data Conflation: Why Prompt Injection Persists]]></title>
      <description><![CDATA[Prompt injection is not a vulnerability that will be patched. It is what happens when a system cannot distinguish the instructions it is supposed to follow from the data it is supposed to process.]]></description>
      <link>https://safeguard.sh/resources/blog/frontier-model-limit-instruction-data-conflation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/frontier-model-limit-instruction-data-conflation</guid>
      <pubDate>Fri, 23 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Gemini Code Assist: Security]]></title>
      <description><![CDATA[Gemini Code Assist makes developers faster. But faster is not safer. Here's how Griffin AI layers a security engine onto the same developer workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-code-assist-for-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-code-assist-for-security</guid>
      <pubDate>Fri, 23 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SPDX Coverage: Griffin AI vs Mythos]]></title>
      <description><![CDATA[SPDX is the format auditors ask for, the format regulators reference, and the format most enterprise procurement teams standardize on. Griffin AI treats it as a first-class graph. Mythos-class tools treat it as a long document.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-spdx-coverage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-spdx-coverage</guid>
      <pubDate>Fri, 23 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Fortinet FortiProxy CVE-2023-25610: Buffer Underwrite in Network Security Infrastructure]]></title>
      <description><![CDATA[CVE-2023-25610 allowed unauthenticated RCE on FortiOS and FortiProxy through a buffer underwrite vulnerability. Another critical flaw in perimeter security appliances.]]></description>
      <link>https://safeguard.sh/resources/blog/fortinet-fortiproxy-cve-2023-25610</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fortinet-fortiproxy-cve-2023-25610</guid>
      <pubDate>Fri, 23 Jan 2026 10:56:10 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[State of Cloud Security Report Overview]]></title>
      <description><![CDATA[This year's cloud security reports point to the same conclusion: detection isn't the bottleneck anymore — identity sprawl, supply chain risk, and slow remediation are.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-cloud-security-report-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-cloud-security-report-overview</guid>
      <pubDate>Fri, 23 Jan 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Email Security and Supply Chain Phishing Attacks]]></title>
      <description><![CDATA[Phishing remains the top initial access vector for supply chain attacks. Targeted emails against developers, maintainers, and DevOps engineers open the door to code injection, credential theft, and pipeline compromise.]]></description>
      <link>https://safeguard.sh/resources/blog/email-security-supply-chain-phishing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/email-security-supply-chain-phishing</guid>
      <pubDate>Fri, 23 Jan 2026 09:35:43 GMT</pubDate>
      <category>Social Engineering</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Clop/Cl0p Supply Chain Exploitation Patterns]]></title>
      <description><![CDATA[Clop has industrialized third-party file-transfer exploitation. Here is how the group operates, what it keeps repeating, and how defenders can stop repeating their own mistakes.]]></description>
      <link>https://safeguard.sh/resources/blog/clop-cl0p-supply-chain-exploitation-patterns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/clop-cl0p-supply-chain-exploitation-patterns</guid>
      <pubDate>Fri, 23 Jan 2026 09:00:00 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[npm dependency confusion attacks against private package ...]]></title>
      <description><![CDATA[How npm dependency confusion lets attackers hijack internal package names on public registries — and why private npm registry security gaps still leave teams exposed.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-dependency-confusion-attacks-against-private-package-namespaces</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-dependency-confusion-attacks-against-private-package-namespaces</guid>
      <pubDate>Fri, 23 Jan 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Knowledge Graph Architecture]]></title>
      <description><![CDATA[How Safeguard's knowledge graph unifies components, vulnerabilities, policies, and runtime evidence into a single queryable substrate that powers every product surface.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-knowledge-graph-architecture-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-knowledge-graph-architecture-deep-dive</guid>
      <pubDate>Fri, 23 Jan 2026 09:00:00 GMT</pubDate>
      <category>Architecture</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Automating Typosquatting Detection for Package Registries]]></title>
      <description><![CDATA[Typosquatting remains one of the most effective supply chain attacks. Automated detection using string distance algorithms, behavioral analysis, and registry monitoring can catch malicious packages before they reach your builds.]]></description>
      <link>https://safeguard.sh/resources/blog/typosquatting-detection-automation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/typosquatting-detection-automation</guid>
      <pubDate>Fri, 23 Jan 2026 08:15:17 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[State of Agentic AI Adoption Report Overview]]></title>
      <description><![CDATA[Safeguard's State of Agentic AI Adoption Report finds 71% of enterprises now run agents with production access, outpacing identity, SBOM, and reachability controls.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-agentic-ai-adoption-report-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-agentic-ai-adoption-report-overview</guid>
      <pubDate>Fri, 23 Jan 2026 07:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[PWA Service Worker Attack Surface: What Security Teams Overlook]]></title>
      <description><![CDATA[Service workers give Progressive Web Apps powerful offline and caching capabilities, but they also create a persistent attack surface that outlives the browser tab. Understanding this surface is critical.]]></description>
      <link>https://safeguard.sh/resources/blog/pwa-service-worker-attack-surface</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pwa-service-worker-attack-surface</guid>
      <pubDate>Fri, 23 Jan 2026 06:54:50 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Maven Dependency Resolution Attacks: Exploiting Java's Build System]]></title>
      <description><![CDATA[Maven's dependency resolution mechanism can be exploited through repository poisoning, dependency confusion, and POM manipulation. Here is what Java teams need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-dependency-resolution-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-dependency-resolution-attacks</guid>
      <pubDate>Fri, 23 Jan 2026 05:34:23 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes RBAC Security Best Practices for Supply Chain Protection]]></title>
      <description><![CDATA[Misconfigured Kubernetes RBAC is a common path to supply chain compromise. Here's how to lock down permissions in your clusters.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-rbac-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-rbac-security-best-practices</guid>
      <pubDate>Fri, 23 Jan 2026 04:13:57 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Inside the Agentic Development Supply Chain Report]]></title>
      <description><![CDATA[Safeguard's research team analyzed 42,000+ repositories with agentic commit activity, finding new dependency, MCP server, and SBOM gaps introduced by AI coding agents.]]></description>
      <link>https://safeguard.sh/resources/blog/inside-the-agentic-development-supply-chain-report</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/inside-the-agentic-development-supply-chain-report</guid>
      <pubDate>Fri, 23 Jan 2026 04:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Compromised npm packages in the React and Next.js build p...]]></title>
      <description><![CDATA[A react npm supply chain incident case study: how a phishing attack on a single maintainer compromised chalk, debug, and other build-pipeline dependencies.]]></description>
      <link>https://safeguard.sh/resources/blog/compromised-npm-packages-in-the-react-and-nextjs-build-pipeline-incident-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/compromised-npm-packages-in-the-react-and-nextjs-build-pipeline-incident-analysis</guid>
      <pubDate>Fri, 23 Jan 2026 03:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Australia's Critical Infrastructure Security Act and Software Supply Chain Risk]]></title>
      <description><![CDATA[Australia's SOCI Act imposes strict cybersecurity obligations on critical infrastructure. Here's what software suppliers need to understand.]]></description>
      <link>https://safeguard.sh/resources/blog/australia-critical-infrastructure-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/australia-critical-infrastructure-security</guid>
      <pubDate>Fri, 23 Jan 2026 02:53:30 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Setting Up Continuous Dependency Monitoring From Scratch]]></title>
      <description><![CDATA[Point-in-time dependency scans miss vulnerabilities disclosed between scans. Here is how to set up continuous monitoring that catches new threats as they emerge.]]></description>
      <link>https://safeguard.sh/resources/blog/continuous-dependency-monitoring-setup</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/continuous-dependency-monitoring-setup</guid>
      <pubDate>Fri, 23 Jan 2026 01:33:03 GMT</pubDate>
      <category>Dependency Management</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[AI Agent Security: 6 Risks Beyond Traditional Controls]]></title>
      <description><![CDATA[Gartner projects a third of enterprise apps will run agentic AI by 2028. Here are six AI agent security risks traditional controls miss.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-agent-security-6-risks-beyond-traditional-controls</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-agent-security-6-risks-beyond-traditional-controls</guid>
      <pubDate>Fri, 23 Jan 2026 01:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[GitLab Ultimate Security Features: Built-In Security Done Pragmatically]]></title>
      <description><![CDATA[A review of GitLab Ultimate's security scanning features covering SAST, DAST, dependency scanning, container scanning, and how integrated security compares to best-of-breed tools.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-ultimate-security-features-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-ultimate-security-features-review</guid>
      <pubDate>Fri, 23 Jan 2026 00:12:37 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Polyfill.io CDN Supply Chain Attack: 100K+ Sites]]></title>
      <description><![CDATA[After a domain handover, polyfill.io began serving malware to more than 100,000 sites. Here is the attack chain and what the incident teaches us.]]></description>
      <link>https://safeguard.sh/resources/blog/polyfill-io-cdn-supply-chain-attack-june-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/polyfill-io-cdn-supply-chain-attack-june-2024</guid>
      <pubDate>Fri, 23 Jan 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Swift CocoaPods and SPM Security]]></title>
      <description><![CDATA[Securing iOS and macOS dependencies with Swift Package Manager and CocoaPods, including checksum verification and source control.]]></description>
      <link>https://safeguard.sh/resources/blog/swift-cocoapods-spm-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/swift-cocoapods-spm-security</guid>
      <pubDate>Thu, 22 Jan 2026 22:52:10 GMT</pubDate>
      <category>Dependency Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Spinnaker Deployment Security]]></title>
      <description><![CDATA[Securing Spinnaker's multi-cloud deployment pipelines with authentication, authorization, pipeline constraints, and artifact verification.]]></description>
      <link>https://safeguard.sh/resources/blog/spinnaker-deployment-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spinnaker-deployment-security</guid>
      <pubDate>Thu, 22 Jan 2026 21:31:43 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Securing GCP Artifact Registry: A Complete Guide]]></title>
      <description><![CDATA[How to configure GCP Artifact Registry for security-first container and package management, from IAM policies to vulnerability scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-artifact-registry-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-artifact-registry-security-guide</guid>
      <pubDate>Thu, 22 Jan 2026 20:11:17 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Requirements for Medical Devices: FDA's New Mandate]]></title>
      <description><![CDATA[The FDA now requires software bill of materials for medical device submissions. Here's what manufacturers need to know about compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-requirements-for-medical-devices-fda</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-requirements-for-medical-devices-fda</guid>
      <pubDate>Thu, 22 Jan 2026 18:50:50 GMT</pubDate>
      <category>Compliance & Regulations</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[gosec: Static Analysis for Go Security]]></title>
      <description><![CDATA[gosec is the standard security linter for Go. Here is what it catches, what it misses, and how to integrate it effectively into your workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/gosec-static-analysis-go-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gosec-static-analysis-go-security</guid>
      <pubDate>Thu, 22 Jan 2026 17:30:23 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Jira Service Management CVE-2023-22501: Broken Authentication Exposes Enterprise Workflows]]></title>
      <description><![CDATA[A critical authentication vulnerability in Jira Service Management allowed attackers to impersonate users and gain access to sensitive service desk instances. The flaw bypassed email verification controls.]]></description>
      <link>https://safeguard.sh/resources/blog/jira-service-management-cve-2023-22501</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jira-service-management-cve-2023-22501</guid>
      <pubDate>Thu, 22 Jan 2026 16:09:56 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Deploying Falco for Runtime Security in 2026]]></title>
      <description><![CDATA[A pragmatic deployment guide for Falco 0.41 in production Kubernetes: driver selection, rule tuning, alert routing, and the operational debt teams underestimate.]]></description>
      <link>https://safeguard.sh/resources/blog/falco-runtime-security-deploy-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/falco-runtime-security-deploy-2026</guid>
      <pubDate>Thu, 22 Jan 2026 15:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Sharing and Distribution Best Practices]]></title>
      <description><![CDATA[Generating SBOMs is only half the battle. Sharing them securely and effectively with stakeholders requires careful planning and tooling.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-sharing-and-distribution-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-sharing-and-distribution-best-practices</guid>
      <pubDate>Thu, 22 Jan 2026 14:49:30 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[FastAPI Authentication Best Practices in 2026]]></title>
      <description><![CDATA[Practical, opinionated guidance on authentication in FastAPI: token formats, dependency patterns, refresh flows, and the mistakes we still see in production code reviews.]]></description>
      <link>https://safeguard.sh/resources/blog/fastapi-authentication-best-practices-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fastapi-authentication-best-practices-2026</guid>
      <pubDate>Thu, 22 Jan 2026 14:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Financial Services Supply Chain Controls for 2026]]></title>
      <description><![CDATA[What banks, broker-dealers, and insurers should require from their software vendors in 2026: DORA, NYDFS Part 500, OCC guidance, and the operational resilience controls that actually hold up.]]></description>
      <link>https://safeguard.sh/resources/blog/financial-services-supply-chain-controls-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/financial-services-supply-chain-controls-2026</guid>
      <pubDate>Thu, 22 Jan 2026 14:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Daniel Chen)</author>
    </item>
    <item>
      <title><![CDATA[Detecting Model Supply Chain Poisoning in 2026]]></title>
      <description><![CDATA[Poisoning attacks against the model supply chain have moved from research to incident reports. What detection looks like when the attack surface includes weights.]]></description>
      <link>https://safeguard.sh/resources/blog/model-supply-chain-poisoning-detection-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/model-supply-chain-poisoning-detection-2026</guid>
      <pubDate>Thu, 22 Jan 2026 14:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Codecov Bash Uploader 2021: A Supply Chain Retrospective]]></title>
      <description><![CDATA[The Codecov bash uploader compromise was the quiet supply chain attack that exposed how CI secrets flow through every customer's pipeline. A five-year look back.]]></description>
      <link>https://safeguard.sh/resources/blog/codecov-bash-uploader-2021-supply-chain-retrospective</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/codecov-bash-uploader-2021-supply-chain-retrospective</guid>
      <pubDate>Thu, 22 Jan 2026 13:30:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Defense in Depth for the Software Supply Chain]]></title>
      <description><![CDATA[No single control stops supply chain attacks. Defense in depth — layered controls across the entire software lifecycle — is the only strategy that works against sophisticated adversaries.]]></description>
      <link>https://safeguard.sh/resources/blog/defense-in-depth-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/defense-in-depth-software-supply-chain</guid>
      <pubDate>Thu, 22 Jan 2026 13:29:03 GMT</pubDate>
      <category>Security Architecture</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Android APK Supply Chain Verification: Beyond Play Protect]]></title>
      <description><![CDATA[Google Play Protect scans for malware, but it does not verify supply chain integrity. Here is how to verify that the APKs on your devices are what you expect.]]></description>
      <link>https://safeguard.sh/resources/blog/android-apk-supply-chain-verification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/android-apk-supply-chain-verification</guid>
      <pubDate>Thu, 22 Jan 2026 12:08:36 GMT</pubDate>
      <category>Mobile Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Aflac and the Scattered Spider Insurance Pivot: June 2025]]></title>
      <description><![CDATA[In June 2025 Scattered Spider pivoted from UK retail to US insurance, hitting Erie Insurance, Philadelphia Insurance, and Aflac inside a week. Aflac later confirmed 22.6 million people affected. We unpack the campaign.]]></description>
      <link>https://safeguard.sh/resources/blog/aflac-insurance-scattered-spider-june-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aflac-insurance-scattered-spider-june-2025</guid>
      <pubDate>Thu, 22 Jan 2026 12:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MCP Ecosystem Maturation: Where It's Going]]></title>
      <description><![CDATA[The Model Context Protocol went from a single-vendor proposal to a multi-implementation standard in under eighteen months. The security implications are still being worked out in public.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-trend-mcp-ecosystem-maturation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-trend-mcp-ecosystem-maturation</guid>
      <pubDate>Thu, 22 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[FedRAMP HIGH Posture: Griffin AI vs Mythos]]></title>
      <description><![CDATA[FedRAMP HIGH demands 421 controls with documented, continuous evidence. Griffin AI produces control-mapped records every day. Mythos-class pure-LLM tools cannot fill a 3PAO evidence package.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-fedramp-high-posture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-fedramp-high-posture</guid>
      <pubDate>Thu, 22 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Taint Propagation: Griffin AI vs Mythos Approaches]]></title>
      <description><![CDATA[Taint tells you whether attacker data actually reaches a sink. Griffin AI propagates it; Mythos-class tools infer it. The difference shows up fast.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-taint-propagation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-taint-propagation</guid>
      <pubDate>Thu, 22 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MCP Server Discovery Protocol Security]]></title>
      <description><![CDATA[MCP server discovery turns a client connection string into a live capability graph. The protocol mechanics that make this convenient also widen the blast radius when discovery is spoofed, tampered with, or silently reshaped mid-session.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-discovery-protocol-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-discovery-protocol-security</guid>
      <pubDate>Thu, 22 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Anthropic mcp-server-git: Three CVEs That Chain to RCE via Prompt Injection]]></title>
      <description><![CDATA[Three flaws in Anthropic's official Git MCP server let prompt injection in a README compromise the developer's machine. The chain shows how MCP servers leak authority.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-server-git-cve-chain-anthropic-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-server-git-cve-chain-anthropic-2026</guid>
      <pubDate>Thu, 22 Jan 2026 12:00:00 GMT</pubDate>
      <category>Agent Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[npm Mandatory 2FA for Publishing: How the November 2025 Rollout Hardened the Registry]]></title>
      <description><![CDATA[After the Shai-Hulud worm compromised more than 500 npm packages in September 2025, GitHub published a revised timeline forcing FIDO 2FA, 90-day token caps, and disabled token publishing by default. Here is the defender view.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-mandatory-2fa-publishing-rollout-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-mandatory-2fa-publishing-rollout-2026</guid>
      <pubDate>Thu, 22 Jan 2026 12:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Artificial Intelligence and Cyber Security: Risks and Benefits]]></title>
      <description><![CDATA[A balanced look at what artificial intelligence and cyber security actually means in practice today, the concrete benefits teams are seeing and the new risks AI introduces into the same systems.]]></description>
      <link>https://safeguard.sh/resources/blog/artificial-intelligence-cyber-security-risks-and-benefits</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/artificial-intelligence-cyber-security-risks-and-benefits</guid>
      <pubDate>Thu, 22 Jan 2026 11:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Reachability Analysis for Go Modules in 2026]]></title>
      <description><![CDATA[Go's static linking, vendoring, and govulncheck make reachability analysis tractable. Here is what works, what does not, and the false-positive numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/reachability-analysis-go-modules-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reachability-analysis-go-modules-2026</guid>
      <pubDate>Thu, 22 Jan 2026 11:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Marina Petrov)</author>
    </item>
    <item>
      <title><![CDATA[Alpine APK Security Model: Small Footprint, Big Trust Decisions]]></title>
      <description><![CDATA[Alpine Linux is the default choice for minimal containers. Its APK package manager has a different security model than apt or dnf, and the tradeoffs matter.]]></description>
      <link>https://safeguard.sh/resources/blog/alpine-apk-security-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/alpine-apk-security-model</guid>
      <pubDate>Thu, 22 Jan 2026 10:48:10 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Spring4Shell Retrospective: What CVE-2022-22965 Actually Cost the Industry]]></title>
      <description><![CDATA[Spring4Shell was hyped as the next Log4Shell and turned out to be neither as broad nor as harmless as the early coverage suggested. A 2026 look back at the real numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/spring4shell-cve-2022-22965-retrospective-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring4shell-cve-2022-22965-retrospective-2026</guid>
      <pubDate>Thu, 22 Jan 2026 10:30:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Container Security Best Practices Checklist 2026]]></title>
      <description><![CDATA[A practical container security checklist for 2026 covering base images, runtime controls, registry hygiene, and signing, with specific thresholds defenders can adopt.]]></description>
      <link>https://safeguard.sh/resources/blog/container-security-best-practices-checklist-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-security-best-practices-checklist-2026</guid>
      <pubDate>Thu, 22 Jan 2026 10:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[A Healthcare System's Self-Healing Container Rollout]]></title>
      <description><![CDATA[An anonymized account of how a regional North American healthcare system deployed Safeguard's self-healing container base images across 600+ workloads.]]></description>
      <link>https://safeguard.sh/resources/blog/customer-story-healthcare-system-self-healing-containers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/customer-story-healthcare-system-self-healing-containers</guid>
      <pubDate>Thu, 22 Jan 2026 10:00:00 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Git Hooks as Supply Chain Controls in 2026]]></title>
      <description><![CDATA[Server-side and client-side git hooks are an underused control surface for supply chain risk. Here is what to enforce, where to enforce it, and what to leave alone.]]></description>
      <link>https://safeguard.sh/resources/blog/git-hooks-supply-chain-controls-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/git-hooks-supply-chain-controls-2026</guid>
      <pubDate>Thu, 22 Jan 2026 10:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Hugging Face Pickle Backdoor Research 2025]]></title>
      <description><![CDATA[Pickle-serialized model files remain a live attack surface on Hugging Face. Here is what 2025 research disclosed about persistent backdoors and what defenders should do about it.]]></description>
      <link>https://safeguard.sh/resources/blog/huggingface-pickle-backdoor-research-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/huggingface-pickle-backdoor-research-2025</guid>
      <pubDate>Thu, 22 Jan 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Distribution Patterns: TEA, VEX, and the Last Mile in 2026]]></title>
      <description><![CDATA[How SBOMs actually move between producers and consumers in 2026, what TEA and VEX are solving, and the distribution patterns that hold up in production.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-distribution-patterns-tea-vex-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-distribution-patterns-tea-vex-2026</guid>
      <pubDate>Thu, 22 Jan 2026 10:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[SOC 2 Type II for SaaS Startups in 2026]]></title>
      <description><![CDATA[What a SOC 2 Type II audit actually requires in 2026, where supply chain controls now sit in the Trust Services Criteria, and how to scope a defensible first report.]]></description>
      <link>https://safeguard.sh/resources/blog/soc-2-type-ii-for-saas-startups-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/soc-2-type-ii-for-saas-startups-2026</guid>
      <pubDate>Thu, 22 Jan 2026 10:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Next-Generation Software Composition Analysis: Beyond Dependency Lists]]></title>
      <description><![CDATA[Traditional SCA tools tell you what's in your software. Next-gen SCA tells you what matters. Here's how the category is evolving.]]></description>
      <link>https://safeguard.sh/resources/blog/software-composition-analysis-next-generation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-composition-analysis-next-generation</guid>
      <pubDate>Thu, 22 Jan 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Swift Static Analysis Tools for Security 2026]]></title>
      <description><![CDATA[A 2026 survey of static analysis tools for Swift focused on security findings: what works, what does not, and where the iOS and server-side gaps remain.]]></description>
      <link>https://safeguard.sh/resources/blog/swift-static-analysis-tools-for-security-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/swift-static-analysis-tools-for-security-2026</guid>
      <pubDate>Thu, 22 Jan 2026 10:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Aisha Rahman)</author>
    </item>
    <item>
      <title><![CDATA[The Hidden Cost of AI Code in Financial Services]]></title>
      <description><![CDATA[Banks and fintechs are shipping AI-generated code faster than they can vet it. The bill for that speed is starting to come due.]]></description>
      <link>https://safeguard.sh/resources/blog/the-hidden-cost-of-ai-code-in-financial-services</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/the-hidden-cost-of-ai-code-in-financial-services</guid>
      <pubDate>Thu, 22 Jan 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Why Scanning Alone Doesn't Work Anymore]]></title>
      <description><![CDATA[Scanners generate findings. Programs produce outcomes. After a decade of dashboards and CVE counts, it is time to admit the gap between the two is the actual security problem.]]></description>
      <link>https://safeguard.sh/resources/blog/why-scanning-alone-does-not-work-anymore-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-scanning-alone-does-not-work-anymore-2026</guid>
      <pubDate>Thu, 22 Jan 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Top AI Cybersecurity Companies to Watch in 2026]]></title>
      <description><![CDATA[The top AI cybersecurity companies of 2026 span three distinct plays — AI-assisted detection, AI-native SOC automation, and AI-augmented AppSec — and the distinction matters when you're evaluating vendors.]]></description>
      <link>https://safeguard.sh/resources/blog/top-ai-cybersecurity-companies-to-watch-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/top-ai-cybersecurity-companies-to-watch-2026</guid>
      <pubDate>Thu, 22 Jan 2026 09:30:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SBOMs for Serverless Applications: What Changes and What Doesn't]]></title>
      <description><![CDATA[Serverless doesn't mean dependency-free. Here's how to generate and manage SBOMs for Lambda functions, Azure Functions, and Cloud Functions.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-for-serverless-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-for-serverless-applications</guid>
      <pubDate>Thu, 22 Jan 2026 09:27:43 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Product Security Assessments: What They Actually Cover]]></title>
      <description><![CDATA[A product security assessment looks at more than code, it evaluates the whole shipped product: architecture, dependencies, deployment configuration, and the data it touches.]]></description>
      <link>https://safeguard.sh/resources/blog/product-security-assessments-what-they-cover</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/product-security-assessments-what-they-cover</guid>
      <pubDate>Thu, 22 Jan 2026 09:15:00 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Checkmarx vs SonarQube: An Honest Comparison]]></title>
      <description><![CDATA[Checkmarx and SonarQube get compared constantly, but they're not really solving the same problem — one is a dedicated security SAST platform, the other is a code-quality tool with a security add-on.]]></description>
      <link>https://safeguard.sh/resources/blog/checkmarx-vs-sonarqube-honest-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/checkmarx-vs-sonarqube-honest-comparison</guid>
      <pubDate>Thu, 22 Jan 2026 09:10:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[AWS CodeBuild/CodePipeline Hardening in 2026]]></title>
      <description><![CDATA[CodeBuild and CodePipeline still carry the biggest AWS supply chain blast radius per dollar. Here is how to harden them in 2026 without rewriting to a different CI.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-codebuild-codepipeline-hardening-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-codebuild-codepipeline-hardening-2026</guid>
      <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cosign for Container Signing: A Production Setup]]></title>
      <description><![CDATA[A working production setup for Cosign image signing across CI, registries, and Kubernetes admission, including the parts that break at scale and how to recover.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-signing-with-cosign-production</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-signing-with-cosign-production</guid>
      <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Maven and Gradle dependency supply chain attacks in the J...]]></title>
      <description><![CDATA[How attackers exploit Maven Central and the Gradle Plugin Portal — dependency confusion, malicious artifacts, and plugin takeovers — and how to defend Java builds.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-and-gradle-dependency-supply-chain-attacks-in-the-java-ecosystem</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-and-gradle-dependency-supply-chain-attacks-in-the-java-ecosystem</guid>
      <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Network Security Automation: What to Automate First]]></title>
      <description><![CDATA[Network security automation pays off fastest on the repetitive, high-volume tasks — not on the judgment calls teams are tempted to automate first.]]></description>
      <link>https://safeguard.sh/resources/blog/network-security-automation-what-to-automate-first</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/network-security-automation-what-to-automate-first</guid>
      <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
      <category>SecOps</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[npm Provenance Statements in Practice (2026)]]></title>
      <description><![CDATA[A practical look at npm provenance in 2026: what statements prove, how to publish them from CI, and where they quietly fail when teams treat them as magic.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-provenance-statements-practical-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-provenance-statements-practical-2026</guid>
      <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[OSS Malware Trends Q1 2026 (Safeguard Research)]]></title>
      <description><![CDATA[The Safeguard Research team analyzed first-quarter 2026 malicious package telemetry across npm, PyPI, RubyGems, and crates.io. Here is what the data shows.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-research-oss-malware-trends-q1-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-research-oss-malware-trends-q1-2026</guid>
      <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
      <category>Research</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Tech-D Cybersecurity: A Joint Opportunity Under Review]]></title>
      <description><![CDATA[A deeper look at the commercial and technical thesis behind Safeguard's exploratory partnership discussions with Tech-D Cybersecurity Ltd.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-tech-d-cybersecurity-joint-opportunity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-tech-d-cybersecurity-joint-opportunity</guid>
      <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
      <category>Company</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Snyk vs Veracode 2026 Buyer Guide]]></title>
      <description><![CDATA[A hands-on comparison of Snyk and Veracode in 2026: developer experience, scan accuracy, SCA depth, SAST tradeoffs, and where each tool actually earns its license cost.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-vs-veracode-2026-buyer-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-vs-veracode-2026-buyer-guide</guid>
      <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[What Is KICS? Checkmarx's Open Source IaC Scanner Explained]]></title>
      <description><![CDATA[Checkmarx KICS is a free, open source static analysis tool for infrastructure-as-code that scans Terraform, CloudFormation, Kubernetes manifests, and more for misconfigurations before they're ever deployed.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-kics-checkmarx-open-source-iac-scanner</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-kics-checkmarx-open-source-iac-scanner</guid>
      <pubDate>Thu, 22 Jan 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Missing Rate Limiting: The OWASP API Security Risk Explained]]></title>
      <description><![CDATA[A no rate limiting vulnerability sits quietly in most APIs until it enables brute force, credential stuffing, or resource exhaustion; here is how to spot it and fix it before it does.]]></description>
      <link>https://safeguard.sh/resources/blog/missing-rate-limiting-owasp-api-security-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/missing-rate-limiting-owasp-api-security-risk</guid>
      <pubDate>Thu, 22 Jan 2026 08:45:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Cross-Site Scripting (XSS) Prevention: Context-Aware Encoding and Modern Defenses]]></title>
      <description><![CDATA[XSS remains a top web vulnerability because output encoding is context-dependent. Here is how to get it right across HTML, JavaScript, URL, and CSS contexts.]]></description>
      <link>https://safeguard.sh/resources/blog/cross-site-scripting-xss-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cross-site-scripting-xss-prevention</guid>
      <pubDate>Thu, 22 Jan 2026 08:07:16 GMT</pubDate>
      <category>Code Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Docker MCP Server: Setup and Security Considerations]]></title>
      <description><![CDATA[Running a docker mcp server puts an AI agent's tool access inside a container boundary, which helps containment but doesn't remove the need to scope credentials and network access carefully.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-mcp-server-setup-and-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-mcp-server-setup-and-security</guid>
      <pubDate>Thu, 22 Jan 2026 08:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[What Is a CTF in Cybersecurity? A Beginner's Guide]]></title>
      <description><![CDATA[A CTF in cyber security is a hands-on competition where you solve security puzzles to capture hidden flags — the fastest, most practical way for beginners to learn real offensive and defensive skills.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-ctf-in-cybersecurity-beginners-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-ctf-in-cybersecurity-beginners-guide</guid>
      <pubDate>Thu, 22 Jan 2026 08:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Executive Guide to Operationalizing AI Governance]]></title>
      <description><![CDATA[A 2026 look at why AI governance policies keep failing in practice—and the five-pillar operating model executives are using to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/executive-guide-to-operationalizing-ai-governance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/executive-guide-to-operationalizing-ai-governance</guid>
      <pubDate>Thu, 22 Jan 2026 07:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CDN Poisoning Attacks: How Cached Content Becomes a Weapon]]></title>
      <description><![CDATA[CDN cache poisoning turns your performance infrastructure into an attack vector. When the cache serves malicious content to every user, the blast radius is massive and immediate.]]></description>
      <link>https://safeguard.sh/resources/blog/cdn-poisoning-attacks-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cdn-poisoning-attacks-prevention</guid>
      <pubDate>Thu, 22 Jan 2026 06:46:50 GMT</pubDate>
      <category>Web Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Spring Boot Actuator endpoint exposure and information di...]]></title>
      <description><![CDATA[Exposed Spring Boot actuator endpoints leak env variables, heap dumps, and credentials via a single unauthenticated request — here's why it keeps happening and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-boot-actuator-endpoint-exposure-and-information-disclosure-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-boot-actuator-endpoint-exposure-and-information-disclosure-risks</guid>
      <pubDate>Thu, 22 Jan 2026 06:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Mandatory 2FA for Critical Packages: A Turning Point for Python Security]]></title>
      <description><![CDATA[PyPI's decision to require two-factor authentication for critical package maintainers marks a significant step toward securing the Python supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-mandatory-2fa-for-critical-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-mandatory-2fa-for-critical-packages</guid>
      <pubDate>Thu, 22 Jan 2026 05:26:23 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Cybersecurity Budget Planning: A Practical Guide for Security Leaders]]></title>
      <description><![CDATA[Budget season is every security leader's least favorite time. Here is how to build a cybersecurity budget that gets approved and actually protects the organization.]]></description>
      <link>https://safeguard.sh/resources/blog/cybersecurity-budget-planning-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cybersecurity-budget-planning-guide</guid>
      <pubDate>Thu, 22 Jan 2026 04:05:56 GMT</pubDate>
      <category>Security Strategy</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[A Tale of Two Scanners: Siloed Scanning vs AI-Powered Correlation]]></title>
      <description><![CDATA[Siloed scanners flood teams with disconnected alerts. Here's why AI powered vulnerability correlation is becoming the industry's answer to alert fatigue.]]></description>
      <link>https://safeguard.sh/resources/blog/a-tale-of-two-scanners-siloed-scanning-vs-ai-powered-correlation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/a-tale-of-two-scanners-siloed-scanning-vs-ai-powered-correlation</guid>
      <pubDate>Thu, 22 Jan 2026 04:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Log4Shell (CVE-2021-44228) and the supply chain lessons o...]]></title>
      <description><![CDATA[A Log4Shell CVE-2021-44228 analysis covering the JNDI lookup flaw, CVSS 10.0 severity, KEV status, patch timeline, remediation steps, and the transitive dependency lessons it taught.]]></description>
      <link>https://safeguard.sh/resources/blog/log4shell-cve-2021-44228-and-the-supply-chain-lessons-of-transitive-java-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4shell-cve-2021-44228-and-the-supply-chain-lessons-of-transitive-java-dependencies</guid>
      <pubDate>Thu, 22 Jan 2026 03:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[GoAnywhere MFT Zero-Day (CVE-2023-0669): Clop Ransomware's File Transfer Rampage]]></title>
      <description><![CDATA[The Clop ransomware gang exploited a pre-auth RCE in GoAnywhere MFT to breach over 130 organizations. The campaign foreshadowed their devastating MOVEit attack months later.]]></description>
      <link>https://safeguard.sh/resources/blog/goanywhere-mft-cve-2023-0669-clop</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/goanywhere-mft-cve-2023-0669-clop</guid>
      <pubDate>Thu, 22 Jan 2026 02:45:30 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[VPN Security for Remote Development Teams: Beyond the Basics]]></title>
      <description><![CDATA[Remote development teams depend on VPNs, but misconfigured VPNs create supply chain risks. Split tunneling, credential management, and endpoint security all affect build pipeline integrity.]]></description>
      <link>https://safeguard.sh/resources/blog/vpn-security-remote-development-teams</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vpn-security-remote-development-teams</guid>
      <pubDate>Thu, 22 Jan 2026 01:25:03 GMT</pubDate>
      <category>Network Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Agent Security Buyer's Guide Overview]]></title>
      <description><![CDATA[As AI agents gain production write-access across the enterprise, security teams need a rigorous buyer's guide to separate real agent security platforms from repackaged AppSec dashboards.]]></description>
      <link>https://safeguard.sh/resources/blog/agent-security-buyers-guide-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/agent-security-buyers-guide-overview</guid>
      <pubDate>Thu, 22 Jan 2026 01:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Session Management Security: A Complete Guide]]></title>
      <description><![CDATA[Session management vulnerabilities enable account takeover, privilege escalation, and data theft. This guide covers session ID generation, storage, lifecycle, and the attacks that exploit weak session handling.]]></description>
      <link>https://safeguard.sh/resources/blog/session-management-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/session-management-security-guide</guid>
      <pubDate>Thu, 22 Jan 2026 00:04:36 GMT</pubDate>
      <category>Web Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Spring4Shell (CVE-2022-22965): root cause and remote code...]]></title>
      <description><![CDATA[Spring4Shell (CVE-2022-22965) let attackers manipulate Java class loaders via Spring data binding to achieve RCE on Tomcat-deployed apps. Root cause, timeline, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/spring4shell-cve-2022-22965-root-cause-and-remote-code-execution-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring4shell-cve-2022-22965-root-cause-and-remote-code-execution-analysis</guid>
      <pubDate>Thu, 22 Jan 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[ESLint Supply Chain Attack: Malicious npm Packages Targeting Developers]]></title>
      <description><![CDATA[Attackers published malicious packages impersonating ESLint on npm, exploiting developer trust in the popular linting tool to steal credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/eslint-supply-chain-attack-npm-packages</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eslint-supply-chain-attack-npm-packages</guid>
      <pubDate>Wed, 21 Jan 2026 22:44:09 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Fork Maintenance and Your Security Responsibilities]]></title>
      <description><![CDATA[Forking an open source project means inheriting its security obligations. Here is what organizations need to know before and after forking a dependency.]]></description>
      <link>https://safeguard.sh/resources/blog/fork-maintenance-security-responsibilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fork-maintenance-security-responsibilities</guid>
      <pubDate>Wed, 21 Jan 2026 21:23:43 GMT</pubDate>
      <category>Dependency Management</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Pinning vs. Ranges: The Tradeoffs]]></title>
      <description><![CDATA[Should you pin exact dependency versions or use ranges? The answer is more nuanced than most teams think, and getting it wrong has real security implications.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-pinning-vs-ranges-tradeoffs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-pinning-vs-ranges-tradeoffs</guid>
      <pubDate>Wed, 21 Jan 2026 20:03:16 GMT</pubDate>
      <category>Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GitHub RSA SSH Key Rotation Incident: Why It Mattered]]></title>
      <description><![CDATA[GitHub rotated its RSA SSH host key after accidental exposure. A small mistake with major supply chain implications for every Git-based workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/github-rsa-ssh-key-rotation-incident</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-rsa-ssh-key-rotation-incident</guid>
      <pubDate>Wed, 21 Jan 2026 18:42:49 GMT</pubDate>
      <category>Incident Response</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Dependabot vs Renovate: Which Dependency Update Bot Should You Use?]]></title>
      <description><![CDATA[A practical guide comparing Dependabot and Renovate for automated dependency updates, covering configuration flexibility, ecosystem support, and team workflows.]]></description>
      <link>https://safeguard.sh/resources/blog/dependabot-renovate-comparison-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependabot-renovate-comparison-guide</guid>
      <pubDate>Wed, 21 Jan 2026 17:22:23 GMT</pubDate>
      <category>Tool Comparisons</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Royal Ransomware: Why Healthcare Became the Primary Target]]></title>
      <description><![CDATA[Royal ransomware emerged from the ashes of Conti to become one of the most aggressive operations targeting healthcare organizations in 2022 and 2023.]]></description>
      <link>https://safeguard.sh/resources/blog/royal-ransomware-healthcare-targeting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/royal-ransomware-healthcare-targeting</guid>
      <pubDate>Wed, 21 Jan 2026 16:01:56 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Cryptographic Library Selection Guide: Choosing Wisely for Your Stack]]></title>
      <description><![CDATA[Picking the wrong crypto library means either rolling your own crypto or using a library with a poor security track record. Here is how to choose.]]></description>
      <link>https://safeguard.sh/resources/blog/cryptographic-library-selection-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cryptographic-library-selection-guide</guid>
      <pubDate>Wed, 21 Jan 2026 14:41:29 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Securing AI/ML Pipelines: The Supply Chain You're Not Watching]]></title>
      <description><![CDATA[AI/ML pipelines introduce unique supply chain risks from training data to model distribution. Most organizations have zero visibility into this attack surface.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-ai-ml-pipelines-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-ai-ml-pipelines-supply-chain</guid>
      <pubDate>Wed, 21 Jan 2026 13:21:03 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[T-Mobile API Breach: 37 Million Records Stolen Through an Unsecured API]]></title>
      <description><![CDATA[In January 2023, T-Mobile disclosed that an attacker exploited an API to steal personal data of 37 million customers. It was their ninth major breach in five years.]]></description>
      <link>https://safeguard.sh/resources/blog/t-mobile-breach-2022-api-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/t-mobile-breach-2022-api-exploitation</guid>
      <pubDate>Wed, 21 Jan 2026 12:00:36 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Adversarial Resistance: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Griffin AI reports 98-100% hold rate against adversarial probes. Most Mythos-class tools have never published an adversarial number at all.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-adversarial-resistance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-adversarial-resistance</guid>
      <pubDate>Wed, 21 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[ISA-TR62443-2-2-2025: Security Protection Schemes for IACS]]></title>
      <description><![CDATA[The ISA released TR62443-2-2-2025 in December 2025, giving industrial operators actionable guidance for designing and validating a Security Protection Scheme. Here is what changed in OT defender practice.]]></description>
      <link>https://safeguard.sh/resources/blog/iec-62443-2-2-2025-security-protection-schemes-iacs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/iec-62443-2-2-2025-security-protection-schemes-iacs</guid>
      <pubDate>Wed, 21 Jan 2026 12:00:00 GMT</pubDate>
      <category>Standards</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[OpenShift Pipelines with Sigstore: A Production Integration Guide]]></title>
      <description><![CDATA[OpenShift Pipelines (Tekton) plus Sigstore gives you keyless signing inside a regulated cluster. The integration patterns are subtle. We map the ones that survive audit.]]></description>
      <link>https://safeguard.sh/resources/blog/openshift-pipelines-sigstore-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openshift-pipelines-sigstore-2026</guid>
      <pubDate>Wed, 21 Jan 2026 12:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SBOM Format Conversion: Tools and Techniques]]></title>
      <description><![CDATA[Your supplier sends SPDX, your platform expects CycloneDX. Here's how to convert between SBOM formats without losing critical data.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-format-conversion-tools</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-format-conversion-tools</guid>
      <pubDate>Wed, 21 Jan 2026 10:40:09 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[MCP vs Skills vs Hooks vs Rules Explained]]></title>
      <description><![CDATA[MCP, Skills, hooks, and rules extend AI coding agents in very different ways — two execute code, two only steer behavior. Here's how each one breaks.]]></description>
      <link>https://safeguard.sh/resources/blog/mcp-vs-skills-vs-hooks-vs-rules-explained</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mcp-vs-skills-vs-hooks-vs-rules-explained</guid>
      <pubDate>Wed, 21 Jan 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[ChatGPT and AI Security Implications for Software Supply Chains]]></title>
      <description><![CDATA[The explosion of AI tools like ChatGPT is reshaping how developers write code — and introducing new supply chain risks that most teams aren't thinking about.]]></description>
      <link>https://safeguard.sh/resources/blog/chatgpt-ai-security-implications-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/chatgpt-ai-security-implications-supply-chain</guid>
      <pubDate>Wed, 21 Jan 2026 09:19:43 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Auditing Spring Boot dependencies with OWASP Dependency-C...]]></title>
      <description><![CDATA[A step-by-step spring boot dependency audit using OWASP Dependency-Check and Snyk, from Maven setup to CI automation and finding reconciliation.]]></description>
      <link>https://safeguard.sh/resources/blog/auditing-spring-boot-dependencies-with-owasp-dependency-check-and-snyk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/auditing-spring-boot-dependencies-with-owasp-dependency-check-and-snyk</guid>
      <pubDate>Wed, 21 Jan 2026 09:00:00 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[CISA Secure by Design Pledge: Practical Impact]]></title>
      <description><![CDATA[An engineer's assessment of what the CISA Secure by Design Pledge actually changed inside product teams, what it did not, and where the 2026 expectations are landing.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-secure-by-design-pledge-practical-impact</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-secure-by-design-pledge-practical-impact</guid>
      <pubDate>Wed, 21 Jan 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Azure Defender for Containers: Getting Real Security Value]]></title>
      <description><![CDATA[How to configure and operationalize Microsoft Defender for Containers for ACR scanning, AKS runtime protection, and CI/CD integration.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-defender-for-containers-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-defender-for-containers-guide</guid>
      <pubDate>Wed, 21 Jan 2026 07:59:16 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Vulnerability Remediation]]></title>
      <description><![CDATA[Vulnerability remediation means fixing a flaw at its source, not just detecting it. Learn the workflow, real MTTR benchmarks, and prioritization.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-vulnerability-remediation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-vulnerability-remediation</guid>
      <pubDate>Wed, 21 Jan 2026 07:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CCPA/CPRA and Software Security: What Developers Must Know]]></title>
      <description><![CDATA[California's privacy laws impose security obligations on software that handles consumer data. Here's how CCPA and CPRA intersect with supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/ccpa-cpra-software-security-requirements</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ccpa-cpra-software-security-requirements</guid>
      <pubDate>Wed, 21 Jan 2026 06:38:49 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Spring Security misconfigurations and default credential ...]]></title>
      <description><![CDATA[Default credentials, exposed Actuator endpoints, and missed filter rules: how spring security misconfiguration quietly exposes Java apps to breach.]]></description>
      <link>https://safeguard.sh/resources/blog/spring-security-misconfigurations-and-default-credential-exposure-in-java-apps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring-security-misconfigurations-and-default-credential-exposure-in-java-apps</guid>
      <pubDate>Wed, 21 Jan 2026 06:00:00 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Sensitive Data Exposure Prevention: Protecting Data at Rest, in Transit, and in Use]]></title>
      <description><![CDATA[Data exposure is not just about encryption. It is about knowing where your sensitive data lives, how it moves, and who can access it at every stage.]]></description>
      <link>https://safeguard.sh/resources/blog/sensitive-data-exposure-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sensitive-data-exposure-prevention</guid>
      <pubDate>Wed, 21 Jan 2026 05:18:22 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Auto-Remediation (AI-Powered Fixes)]]></title>
      <description><![CDATA[Auto-remediation uses AI to generate and PR real fixes for vulnerabilities — not just flag them. Here's how it decides what's safe to auto-fix.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-auto-remediation-ai-powered-fixes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-auto-remediation-ai-powered-fixes</guid>
      <pubDate>Wed, 21 Jan 2026 04:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Blue-Green Deployment Security]]></title>
      <description><![CDATA[Security considerations for blue-green deployment strategies including environment parity, rollback integrity, and data migration safety.]]></description>
      <link>https://safeguard.sh/resources/blog/blue-green-deployment-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/blue-green-deployment-security</guid>
      <pubDate>Wed, 21 Jan 2026 03:57:56 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How to enable and configure Amazon ECR image scanning for...]]></title>
      <description><![CDATA[A step-by-step guide to enabling AWS ECR image scanning, from basic vs. enhanced scanning and scan-on-push to CI/CD gating, finding triage, and troubleshooting.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-enable-and-configure-amazon-ecr-image-scanning-for-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-enable-and-configure-amazon-ecr-image-scanning-for-vulnerabilities</guid>
      <pubDate>Wed, 21 Jan 2026 03:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Nexus Repository Security Hardening: Beyond the Defaults]]></title>
      <description><![CDATA[Sonatype Nexus is everywhere. Its default configuration is permissive. Here is how to lock it down for enterprise use.]]></description>
      <link>https://safeguard.sh/resources/blog/nexus-repository-security-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nexus-repository-security-hardening</guid>
      <pubDate>Wed, 21 Jan 2026 02:37:29 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CSP Bypass Techniques and Prevention: Beyond the Basics]]></title>
      <description><![CDATA[Content Security Policy is the strongest browser-side defense against XSS. But most CSP deployments are bypassable. Here is why, and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/csp-bypass-techniques-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/csp-bypass-techniques-prevention</guid>
      <pubDate>Wed, 21 Jan 2026 01:17:02 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[What is a Fix PR (Automated Fix Pull Request)]]></title>
      <description><![CDATA[Fix PRs auto-generate code changes for known CVEs, but without reachability analysis they can flood queues with noise or reintroduce risk on merge.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-fix-pr-automated-fix-pull-request</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-fix-pr-automated-fix-pull-request</guid>
      <pubDate>Wed, 21 Jan 2026 01:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Best practices for implementing least-privilege IAM polic...]]></title>
      <description><![CDATA[A practical guide to designing least-privilege IAM policies in AWS: permission boundaries, policy patterns, and habits that keep access tight as teams scale.]]></description>
      <link>https://safeguard.sh/resources/blog/best-practices-for-implementing-least-privilege-iam-policies-in-aws</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-practices-for-implementing-least-privilege-iam-policies-in-aws</guid>
      <pubDate>Wed, 21 Jan 2026 00:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Veeam Backup CVE-2024-40711 Unauth RCE Walkthrough]]></title>
      <description><![CDATA[CVE-2024-40711 is a critical unauth RCE in Veeam Backup & Replication. Deserialization flaw, exploit chain, and ransomware operator abuse.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-40711-veeam-backup-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-40711-veeam-backup-rce</guid>
      <pubDate>Wed, 21 Jan 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Container Image Hardening Checklist]]></title>
      <description><![CDATA[A comprehensive checklist for hardening your container images, from base image selection to runtime protections, with practical Dockerfile examples.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-hardening-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-hardening-checklist</guid>
      <pubDate>Tue, 20 Jan 2026 23:56:36 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSL Project Governance: Security Lessons from Heartbleed and Beyond]]></title>
      <description><![CDATA[OpenSSL's transformation from a two-person project securing half the internet to a properly governed foundation offers a blueprint for open source security governance.]]></description>
      <link>https://safeguard.sh/resources/blog/openssl-project-governance-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssl-project-governance-security</guid>
      <pubDate>Tue, 20 Jan 2026 22:36:09 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[CircleCI Credential Rotation: The Mass-Reset Event]]></title>
      <description><![CDATA[CircleCI told every customer to rotate every secret on January 4, 2023. Here is what actually happened and why the scope was total.]]></description>
      <link>https://safeguard.sh/resources/blog/circleci-credential-rotation-mass-event-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/circleci-credential-rotation-mass-event-2023</guid>
      <pubDate>Tue, 20 Jan 2026 21:15:42 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Vue.js Security Best Practices]]></title>
      <description><![CDATA[Securing Vue.js applications from template injection, XSS through v-html, and third-party plugin risks.]]></description>
      <link>https://safeguard.sh/resources/blog/vue-js-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vue-js-security-best-practices</guid>
      <pubDate>Tue, 20 Jan 2026 19:55:16 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Vendor Concentration Risk in Software: When One Vendor Failure Breaks Everything]]></title>
      <description><![CDATA[Depending on too few vendors creates systemic risk. The CrowdStrike outage proved it. Here is how to assess and manage vendor concentration in your software stack.]]></description>
      <link>https://safeguard.sh/resources/blog/vendor-concentration-risk-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vendor-concentration-risk-software</guid>
      <pubDate>Tue, 20 Jan 2026 18:34:49 GMT</pubDate>
      <category>Security Strategy</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Symlink Attacks in Package Managers: Following Links to Trouble]]></title>
      <description><![CDATA[Symbolic links in package archives can redirect file operations to unintended locations. Here is how this old trick still works against modern tools.]]></description>
      <link>https://safeguard.sh/resources/blog/symlink-attacks-package-managers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/symlink-attacks-package-managers</guid>
      <pubDate>Tue, 20 Jan 2026 17:14:22 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[PHPStan Security Analysis: Static Typing as a Security Tool for PHP]]></title>
      <description><![CDATA[PHPStan brings static analysis to PHP. Its type checking catches entire classes of bugs that lead to security vulnerabilities in PHP applications.]]></description>
      <link>https://safeguard.sh/resources/blog/phpstan-security-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/phpstan-security-analysis</guid>
      <pubDate>Tue, 20 Jan 2026 15:53:55 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Race Condition Vulnerabilities in Web Applications]]></title>
      <description><![CDATA[Race conditions in web applications lead to double-spending, privilege escalation, and data corruption. This guide covers the most common patterns, detection techniques, and practical defenses.]]></description>
      <link>https://safeguard.sh/resources/blog/race-condition-vulnerabilities-web-apps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/race-condition-vulnerabilities-web-apps</guid>
      <pubDate>Tue, 20 Jan 2026 14:33:29 GMT</pubDate>
      <category>Web Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[CircleCI Security Incident January 2023: What Happened and What We Learned]]></title>
      <description><![CDATA[CircleCI's January 2023 breach exposed secrets for thousands of organizations. Here's how the attack unfolded and what it means for CI/CD security.]]></description>
      <link>https://safeguard.sh/resources/blog/circleci-security-incident-january-2023</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/circleci-security-incident-january-2023</guid>
      <pubDate>Tue, 20 Jan 2026 13:13:02 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Cloudflare Code Orange Fail Small: What the Resilience Plan Actually Changes]]></title>
      <description><![CDATA[After November and December 2025 outages, Cloudflare declared Code Orange and shipped a Health Mediated Deployment system, break-glass dependency audits, and graceful-degradation rewrites.]]></description>
      <link>https://safeguard.sh/resources/blog/cloudflare-code-orange-fail-small-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloudflare-code-orange-fail-small-2026</guid>
      <pubDate>Tue, 20 Jan 2026 12:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Aman Khan)</author>
    </item>
    <item>
      <title><![CDATA[Deserialization Vulnerabilities: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Unsafe deserialization looks obvious on a slide and impossible on a real codebase. Sinks are language-specific, gadgets live in third-party libraries, and the tainted byte can arrive wrapped in six layers of framework ceremony. Griffin's engine-plus-LLM design handles each of those concerns separately; Mythos-style pure-LLM scanners blur them into pattern-matching.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-deserialization-vulns</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-deserialization-vulns</guid>
      <pubDate>Tue, 20 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Germany's NIS2 Transposition: BSI Act in Force December 2025]]></title>
      <description><![CDATA[Germany's NIS2 implementing law took effect 6 December 2025 with no transition period, expanding regulated entities from 4,500 to roughly 29,000 and giving the BSI direct sanction powers.]]></description>
      <link>https://safeguard.sh/resources/blog/nis2-germany-bsi-act-december-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nis2-germany-bsi-act-december-2025</guid>
      <pubDate>Tue, 20 Jan 2026 12:00:00 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Slack GitHub Repository Theft: Stolen Tokens and the Risks of Third-Party Integrations]]></title>
      <description><![CDATA[In December 2022, Slack disclosed that stolen employee tokens were used to access private GitHub repositories. The breach highlighted the risks of token-based authentication in CI/CD pipelines.]]></description>
      <link>https://safeguard.sh/resources/blog/slack-github-repository-theft-2022</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/slack-github-repository-theft-2022</guid>
      <pubDate>Tue, 20 Jan 2026 11:52:35 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Release Management Security Checklist]]></title>
      <description><![CDATA[A pre-release security checklist that covers dependency verification, vulnerability scanning, SBOM generation, and artifact integrity for every production release.]]></description>
      <link>https://safeguard.sh/resources/blog/release-management-security-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/release-management-security-checklist</guid>
      <pubDate>Tue, 20 Jan 2026 10:32:09 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[AI Agent Security Risks: Why Autonomous Systems Are the Next Supply Chain Frontier]]></title>
      <description><![CDATA[AI agents are consuming APIs, installing packages, and executing code autonomously. The security implications are massive and largely unaddressed.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-agent-security-risks-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-agent-security-risks-2026</guid>
      <pubDate>Tue, 20 Jan 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[The npm 'everything' Package Attack (2024) Analyzed]]></title>
      <description><![CDATA[In January 2024 a developer published npm packages that depended on every public npm package, triggering a denial-of-service style incident across the registry.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-everything-package-attack-2024-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-everything-package-attack-2024-analysis</guid>
      <pubDate>Tue, 20 Jan 2026 10:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[What is Snyk Code (SAST Tool Category Overview)]]></title>
      <description><![CDATA[Snyk Code explained: what it is, how its SAST engine works, its limits, category competitors, and where reachability closes the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-snyk-code-sast-tool-category-overview</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-snyk-code-sast-tool-category-overview</guid>
      <pubDate>Tue, 20 Jan 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Responsible Disclosure in Open Source: The Messy Reality]]></title>
      <description><![CDATA[Responsible disclosure sounds simple in theory. In practice, coordinating vulnerability disclosure across open source projects with no budgets, no SLAs, and no obligation to respond is an exercise in patience and diplomacy.]]></description>
      <link>https://safeguard.sh/resources/blog/responsible-disclosure-open-source</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/responsible-disclosure-open-source</guid>
      <pubDate>Tue, 20 Jan 2026 09:11:42 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Automating secret rotation with AWS Secrets Manager]]></title>
      <description><![CDATA[A step-by-step guide to configuring AWS Secrets Manager rotation for RDS credentials, deploying the rotation Lambda function, and verifying it actually works.]]></description>
      <link>https://safeguard.sh/resources/blog/automating-secret-rotation-with-aws-secrets-manager</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automating-secret-rotation-with-aws-secrets-manager</guid>
      <pubDate>Tue, 20 Jan 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The Gartner Magic Quadrant for Application Security Testing, 2026 Edition]]></title>
      <description><![CDATA[What the Magic Quadrant for Application Security Testing actually measures, how leaders end up in that top-right quadrant, and why the report is one input into a buying decision, not the decision itself.]]></description>
      <link>https://safeguard.sh/resources/blog/gartner-magic-quadrant-for-application-security-testing-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gartner-magic-quadrant-for-application-security-testing-2026</guid>
      <pubDate>Tue, 20 Jan 2026 09:00:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Pre-commit Hook Security Gotchas You'll Hit]]></title>
      <description><![CDATA[Pre-commit hooks feel like a free security win until you ship them at scale. Here are the failure modes, trust boundaries, and escape hatches that bite.]]></description>
      <link>https://safeguard.sh/resources/blog/pre-commit-hooks-security-gotchas</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pre-commit-hooks-security-gotchas</guid>
      <pubDate>Tue, 20 Jan 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security in 2022: The Year Everything Changed]]></title>
      <description><![CDATA[From LastPass to Log4j's aftermath to new regulations, 2022 was the year supply chain security went from niche concern to board-level priority.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-2022-year-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-2022-year-review</guid>
      <pubDate>Tue, 20 Jan 2026 07:51:15 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What is a Vulnerability Database]]></title>
      <description><![CDATA[CVE, NVD, OSV, GHSA, KEV — vulnerability databases power every scanner's severity score. Here's how they're built, enriched, and where they fall short.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-vulnerability-database</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-vulnerability-database</guid>
      <pubDate>Tue, 20 Jan 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[GLBA and Financial Software Security: Safeguards Rule Deep Dive]]></title>
      <description><![CDATA[The GLBA Safeguards Rule now requires specific cybersecurity controls for financial institutions. Here's how it affects software supply chains.]]></description>
      <link>https://safeguard.sh/resources/blog/glba-financial-software-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/glba-financial-software-security</guid>
      <pubDate>Tue, 20 Jan 2026 06:30:49 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Hardening Amazon EKS clusters against common attack paths]]></title>
      <description><![CDATA[A step-by-step guide to EKS security best practices: lock down IAM, enforce pod security standards, segment networks, and verify every control.]]></description>
      <link>https://safeguard.sh/resources/blog/hardening-amazon-eks-clusters-against-common-attack-paths</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hardening-amazon-eks-clusters-against-common-attack-paths</guid>
      <pubDate>Tue, 20 Jan 2026 06:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Software Vendor Risk Scoring Methodology]]></title>
      <description><![CDATA[A practical framework for scoring and ranking software vendor risk based on supply chain security posture, vulnerability history, and development practices.]]></description>
      <link>https://safeguard.sh/resources/blog/software-vendor-risk-scoring-methodology</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-vendor-risk-scoring-methodology</guid>
      <pubDate>Tue, 20 Jan 2026 05:10:22 GMT</pubDate>
      <category>Risk Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[What is a CI/CD Secrets Leak]]></title>
      <description><![CDATA[A CI/CD secrets leak exposes real credentials through build logs, forks, or compromised Actions. Here's how it happens and how to stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-cicd-secrets-leak</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-cicd-secrets-leak</guid>
      <pubDate>Tue, 20 Jan 2026 04:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Funding, Sustainability, and Security]]></title>
      <description><![CDATA[The software industry runs on open source maintained by unpaid volunteers. Until we fix the funding problem, we can't fix the security problem.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-funding-sustainability-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-funding-sustainability-security</guid>
      <pubDate>Tue, 20 Jan 2026 03:49:55 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Signing container images with AWS Signer for supply chain...]]></title>
      <description><![CDATA[A practical walkthrough for signing container images with AWS Signer, verifying them in ECR and EKS, and closing supply chain gaps with cryptographic trust.]]></description>
      <link>https://safeguard.sh/resources/blog/signing-container-images-with-aws-signer-for-supply-chain-integrity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/signing-container-images-with-aws-signer-for-supply-chain-integrity</guid>
      <pubDate>Tue, 20 Jan 2026 03:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Security Budget Justification Guide]]></title>
      <description><![CDATA[How to build a compelling business case for security investment, with frameworks for quantifying risk, communicating with executives, and defending your security budget.]]></description>
      <link>https://safeguard.sh/resources/blog/security-budget-justification-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-budget-justification-guide</guid>
      <pubDate>Tue, 20 Jan 2026 02:29:29 GMT</pubDate>
      <category>Organizational Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Lessons from SolarWinds: Two Years Later]]></title>
      <description><![CDATA[Two years after the SolarWinds breach reshaped cybersecurity, we examine what the industry actually learned and what organizations still get wrong about supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/lessons-from-solarwinds-two-years-later</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lessons-from-solarwinds-two-years-later</guid>
      <pubDate>Tue, 20 Jan 2026 01:09:02 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[What is Software Supply Chain Risk Scoring]]></title>
      <description><![CDATA[CVSS alone can't tell you what to fix first. Here's how supply chain risk scoring blends exploitability, reachability, and provenance into one actionable number.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-software-supply-chain-risk-scoring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-software-supply-chain-risk-scoring</guid>
      <pubDate>Tue, 20 Jan 2026 01:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[From DevOps to DevSecOps: A Practical Shift-Left Guide]]></title>
      <description><![CDATA[Shift-left security doesn't mean dumping security tools on developers. Here's a practical guide to integrating security into your development workflow without killing velocity.]]></description>
      <link>https://safeguard.sh/resources/blog/devops-devsecops-shift-left</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/devops-devsecops-shift-left</guid>
      <pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Securing AWS CodePipeline and CodeBuild against supply ch...]]></title>
      <description><![CDATA[CodePipeline and CodeBuild sit where code, secrets, and compute converge unattended — here's where supply chain attacks actually enter and how to close the gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-aws-codepipeline-and-codebuild-against-supply-chain-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-aws-codepipeline-and-codebuild-against-supply-chain-attacks</guid>
      <pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Single Points of Failure in Software Supply Chains]]></title>
      <description><![CDATA[Your software supply chain has single points of failure that would take down your entire operation. Most organizations have never mapped them.]]></description>
      <link>https://safeguard.sh/resources/blog/single-points-of-failure-supply-chains</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/single-points-of-failure-supply-chains</guid>
      <pubDate>Mon, 19 Jan 2026 23:48:35 GMT</pubDate>
      <category>Risk Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Log4j One Year Later: What We Learned and What We Didn't Fix]]></title>
      <description><![CDATA[A year after Log4Shell shook the internet, many organizations still had vulnerable instances. Here's what the anniversary revealed about our industry.]]></description>
      <link>https://safeguard.sh/resources/blog/log4j-one-year-later-lessons-learned</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4j-one-year-later-lessons-learned</guid>
      <pubDate>Mon, 19 Jan 2026 22:28:08 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Repository Security Settings Guide]]></title>
      <description><![CDATA[Configure GitHub repository security settings for branch protection, secret scanning, dependency alerts, and code scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/github-repository-security-settings-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-repository-security-settings-guide</guid>
      <pubDate>Mon, 19 Jan 2026 21:07:42 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Cilium Network Security in Kubernetes: Beyond Basic Network Policies]]></title>
      <description><![CDATA[Cilium uses eBPF to provide network security that standard Kubernetes NetworkPolicies cannot match. Here is what it adds and how to configure it.]]></description>
      <link>https://safeguard.sh/resources/blog/cilium-network-security-kubernetes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cilium-network-security-kubernetes</guid>
      <pubDate>Mon, 19 Jan 2026 19:47:15 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[FortiGate SSL-VPN Zero-Day (CVE-2022-42475): How a Heap Overflow Gave Attackers the Keys]]></title>
      <description><![CDATA[A heap-based buffer overflow in Fortinet's SSL-VPN was actively exploited before disclosure. State-sponsored actors used it to deploy custom implants on critical infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/fortinet-fortigate-ssl-vpn-cve-2022-42475</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fortinet-fortigate-ssl-vpn-cve-2022-42475</guid>
      <pubDate>Mon, 19 Jan 2026 18:26:48 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The End-of-Year Dependency Audit Ritual]]></title>
      <description><![CDATA[Most dependency audits get done in a panic after a CVE lands. A planned year-end audit is cheaper, more thorough, and produces a backlog you can actually work through in Q1.]]></description>
      <link>https://safeguard.sh/resources/blog/end-of-year-dependency-audit-ritual-2022</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/end-of-year-dependency-audit-ritual-2022</guid>
      <pubDate>Mon, 19 Jan 2026 17:06:22 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Startup Security at Series A: Scaling Without Breaking]]></title>
      <description><![CDATA[You have raised Series A, hired 20 engineers, and landed your first enterprise customers. Your seed-stage security shortcuts are starting to crack. Here is how to scale security alongside your product.]]></description>
      <link>https://safeguard.sh/resources/blog/startup-security-series-a-scaling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/startup-security-series-a-scaling</guid>
      <pubDate>Mon, 19 Jan 2026 15:45:55 GMT</pubDate>
      <category>Startup Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Cargo Build Script Security: What build.rs Can Do to Your Machine]]></title>
      <description><![CDATA[Rust build scripts run arbitrary code during compilation. Here is what they can access and how to evaluate the risk in your dependency tree.]]></description>
      <link>https://safeguard.sh/resources/blog/cargo-build-script-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cargo-build-script-security</guid>
      <pubDate>Mon, 19 Jan 2026 14:25:28 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Pod Security Standards: From PodSecurityPolicy to the New Admission Controller]]></title>
      <description><![CDATA[PodSecurityPolicy is dead. Pod Security Standards replaced it. Here is what changed, what the three levels mean, and how to migrate without breaking your clusters.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-pod-security-standards</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-pod-security-standards</guid>
      <pubDate>Mon, 19 Jan 2026 13:05:02 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Cohere Command for SecOps]]></title>
      <description><![CDATA[]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-cohere-command-for-secops</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-cohere-command-for-secops</guid>
      <pubDate>Mon, 19 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The Disproof Step: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Most AI bug hunters skip the hardest step: trying to kill their own findings. Here is why Griffin AI's disproof pass is the single biggest lever on false-positive rate.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-disproof-step</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-disproof-step</guid>
      <pubDate>Mon, 19 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Model Tiering Strategy: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Opus for reasoning, Sonnet for drafting, Haiku for scale. We break down when each tier earns its keep and why single-model architectures cannot compete.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-model-tiering-strategy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-model-tiering-strategy</guid>
      <pubDate>Mon, 19 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[FOSSA Review: Open Source License Compliance at Enterprise Scale]]></title>
      <description><![CDATA[A review of FOSSA for open source license compliance and vulnerability management, covering license detection, policy automation, and enterprise integration patterns.]]></description>
      <link>https://safeguard.sh/resources/blog/fossa-open-source-compliance-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fossa-open-source-compliance-review</guid>
      <pubDate>Mon, 19 Jan 2026 11:44:35 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Code Signing Bypass: When the Trust Anchor Fails]]></title>
      <description><![CDATA[A vulnerability in GitHub's commit signature verification allowed attackers to forge signed commits. The flaw undermined the integrity guarantees that code signing is supposed to provide.]]></description>
      <link>https://safeguard.sh/resources/blog/github-code-signing-bypass-vulnerability</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-code-signing-bypass-vulnerability</guid>
      <pubDate>Mon, 19 Jan 2026 10:24:08 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[What is a Malicious Commit / Compromised Maintainer Account]]></title>
      <description><![CDATA[When an attacker steals a maintainer's credentials, every user of that package inherits the compromise. Here's how it happens and how to catch it.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-a-malicious-commit-compromised-maintainer-account</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-a-malicious-commit-compromised-maintainer-account</guid>
      <pubDate>Mon, 19 Jan 2026 10:00:00 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Malware Campaigns Surge in Q4 2022: A Roundup of the Worst Offenders]]></title>
      <description><![CDATA[Python's package registry saw an explosion of malicious packages in late 2022, from credential stealers to reverse shells. Here's what we found.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-malware-campaigns-q4-2022</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-malware-campaigns-q4-2022</guid>
      <pubDate>Mon, 19 Jan 2026 09:03:42 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Distroless vs. Chainguard vs. Wolfi: Real Differences]]></title>
      <description><![CDATA[A working engineer's comparison of Google Distroless, Chainguard Images, and Wolfi as base images, covering what actually breaks in production and what does not.]]></description>
      <link>https://safeguard.sh/resources/blog/distroless-vs-chainguard-vs-wolfi-base-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/distroless-vs-chainguard-vs-wolfi-base-images</guid>
      <pubDate>Mon, 19 Jan 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Generating and exporting a software bill of materials in AWS]]></title>
      <description><![CDATA[A practical walkthrough for generating and exporting an AWS SBOM using Inspector and ECR -- plus troubleshooting tips and how Safeguard helps.]]></description>
      <link>https://safeguard.sh/resources/blog/generating-and-exporting-a-software-bill-of-materials-in-aws</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/generating-and-exporting-a-software-bill-of-materials-in-aws</guid>
      <pubDate>Mon, 19 Jan 2026 09:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Property-Based Testing for Security: Defining Invariants That Must Never Break]]></title>
      <description><![CDATA[Property-based testing defines invariants about program behavior and generates thousands of test cases automatically. For security code, the right properties can catch vulnerabilities that example-based tests miss.]]></description>
      <link>https://safeguard.sh/resources/blog/property-based-testing-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/property-based-testing-security</guid>
      <pubDate>Mon, 19 Jan 2026 07:43:15 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Log4Shell RCE in Apache Log4j (CVE-2021-44228)]]></title>
      <description><![CDATA[A deep dive into CVE-2021-44228 (Log4Shell): the critical Log4j RCE vulnerability, its timeline, affected versions, and concrete remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/log4shell-rce-in-apache-log4j-cve-2021-44228</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4shell-rce-in-apache-log4j-cve-2021-44228</guid>
      <pubDate>Mon, 19 Jan 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[LDAP Injection Prevention Guide]]></title>
      <description><![CDATA[LDAP injection attacks manipulate directory service queries to bypass authentication, extract sensitive data, and enumerate user accounts. This guide covers attack techniques and practical defenses for applications using LDAP.]]></description>
      <link>https://safeguard.sh/resources/blog/ldap-injection-prevention-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ldap-injection-prevention-guide</guid>
      <pubDate>Mon, 19 Jan 2026 06:22:48 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Using AWS IAM Access Analyzer to find unused and external...]]></title>
      <description><![CDATA[How AWS IAM Access Analyzer surfaces unused permissions and external access risk across your AWS accounts, and where native findings need extra context to prioritize.]]></description>
      <link>https://safeguard.sh/resources/blog/using-aws-iam-access-analyzer-to-find-unused-and-external-access</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/using-aws-iam-access-analyzer-to-find-unused-and-external-access</guid>
      <pubDate>Mon, 19 Jan 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Graph Analysis: Finding Hidden Transitive Risks]]></title>
      <description><![CDATA[Your project has 50 direct dependencies. It actually depends on 1,200 packages. Transitive dependency analysis is how you find the risks hiding three layers deep.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-graph-analysis-transitive-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-graph-analysis-transitive-risks</guid>
      <pubDate>Mon, 19 Jan 2026 05:02:21 GMT</pubDate>
      <category>Software Supply Chain</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Apache Struts2 RCE behind the Equifax breach (CVE-2017-5638)]]></title>
      <description><![CDATA[CVE-2017-5638, the Apache Struts2 RCE behind the Equifax breach, exposed 147.9M records. Here's the flaw, timeline, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-struts2-rce-behind-the-equifax-breach-cve-2017-5638</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-struts2-rce-behind-the-equifax-breach-cve-2017-5638</guid>
      <pubDate>Mon, 19 Jan 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Incident Response Playbook for Supply Chain Attacks]]></title>
      <description><![CDATA[Supply chain attacks break your standard IR playbook. The compromise originates outside your perimeter, affects trusted software, and the blast radius is unknown. Here's how to adapt.]]></description>
      <link>https://safeguard.sh/resources/blog/incident-response-playbook-supply-chain-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/incident-response-playbook-supply-chain-attacks</guid>
      <pubDate>Mon, 19 Jan 2026 03:41:55 GMT</pubDate>
      <category>Incident Response</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[How AWS STS temporary credentials reduce long-lived key risk]]></title>
      <description><![CDATA[Long-lived AWS keys sit in code and CI logs for years. AWS STS temporary credentials expire automatically, shrinking the window attackers have to exploit a leak.]]></description>
      <link>https://safeguard.sh/resources/blog/how-aws-sts-temporary-credentials-reduce-long-lived-key-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-aws-sts-temporary-credentials-reduce-long-lived-key-risk</guid>
      <pubDate>Mon, 19 Jan 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[5G Networks and the Software Supply Chain Risks Nobody Talks About]]></title>
      <description><![CDATA[5G networks are software-defined infrastructure built on open-source components. The supply chain implications are enormous and under-discussed.]]></description>
      <link>https://safeguard.sh/resources/blog/5g-network-software-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/5g-network-software-supply-chain-risks</guid>
      <pubDate>Mon, 19 Jan 2026 02:21:28 GMT</pubDate>
      <category>Emerging Technology</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Penetration Testing the Software Supply Chain]]></title>
      <description><![CDATA[Traditional pentests focus on the application. Supply chain pentesting targets the build pipeline, dependency resolution, and distribution mechanisms. Here is how to approach it.]]></description>
      <link>https://safeguard.sh/resources/blog/penetration-testing-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/penetration-testing-software-supply-chain</guid>
      <pubDate>Mon, 19 Jan 2026 01:01:01 GMT</pubDate>
      <category>Offensive Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Heartbleed OpenSSL memory disclosure (CVE-2014-0160)]]></title>
      <description><![CDATA[Heartbleed (CVE-2014-0160) let attackers silently read server memory over TLS. Here's the impact, timeline, remediation, and how to detect lingering exposure today.]]></description>
      <link>https://safeguard.sh/resources/blog/heartbleed-openssl-memory-disclosure-cve-2014-0160</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/heartbleed-openssl-memory-disclosure-cve-2014-0160</guid>
      <pubDate>Mon, 19 Jan 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Continuous container vulnerability scanning with Amazon I...]]></title>
      <description><![CDATA[How Amazon Inspector's continuous container scanning actually works, where Inspector vs Trivy differs, and the ECR blind spots teams need to cover.]]></description>
      <link>https://safeguard.sh/resources/blog/continuous-container-vulnerability-scanning-with-amazon-inspector</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/continuous-container-vulnerability-scanning-with-amazon-inspector</guid>
      <pubDate>Mon, 19 Jan 2026 00:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Lottie Player npm Supply Chain Attack Explained]]></title>
      <description><![CDATA[A leaked maintainer token published three trojanized versions of @lottiefiles/lottie-player to npm, targeting wallet drains. Here is the mechanics.]]></description>
      <link>https://safeguard.sh/resources/blog/lottie-player-npm-supply-chain-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lottie-player-npm-supply-chain-attack</guid>
      <pubDate>Mon, 19 Jan 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[LastPass Second Breach: Encrypted Vaults Stolen Using Data from First Attack]]></title>
      <description><![CDATA[LastPass revealed that the August breach enabled a second attack that exfiltrated encrypted customer vaults. The full scope of the damage was devastating.]]></description>
      <link>https://safeguard.sh/resources/blog/lastpass-second-breach-encrypted-vaults</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lastpass-second-breach-encrypted-vaults</guid>
      <pubDate>Sun, 18 Jan 2026 23:40:35 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Correlation Across Package Ecosystems]]></title>
      <description><![CDATA[The same vulnerability often appears under different identifiers across npm, PyPI, Maven, and other ecosystems. Here is how to correlate vulnerabilities across ecosystems and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-correlation-across-ecosystems</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-correlation-across-ecosystems</guid>
      <pubDate>Sun, 18 Jan 2026 22:20:08 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Startup Security Budget Allocation: Where to Spend First]]></title>
      <description><![CDATA[Startups can't afford to do everything at once. Here's how to allocate your security budget for maximum impact, including software supply chain basics.]]></description>
      <link>https://safeguard.sh/resources/blog/startup-security-budget-allocation-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/startup-security-budget-allocation-guide</guid>
      <pubDate>Sun, 18 Jan 2026 20:59:41 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[The Open Source Maintainer Burnout Crisis and Its Security Consequences]]></title>
      <description><![CDATA[Burned-out maintainers abandon projects, accept risky PRs without review, and hand off keys to strangers. The burnout crisis is a supply chain security crisis.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-maintainer-burnout-crisis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-maintainer-burnout-crisis</guid>
      <pubDate>Sun, 18 Jan 2026 19:39:15 GMT</pubDate>
      <category>Open Source</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Docker Desktop WSL2 Security Changes in 2022]]></title>
      <description><![CDATA[Docker Desktop's WSL2 backend reshaped container security on Windows. Here is what changed in 2022 and the defects that forced those changes.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-desktop-wsl2-security-changes-2022</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-desktop-wsl2-security-changes-2022</guid>
      <pubDate>Sun, 18 Jan 2026 18:18:48 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Python Package Security Best Practices]]></title>
      <description><![CDATA[Practical techniques for securing your Python supply chain, from pip and PyPI to virtual environments and hash verification.]]></description>
      <link>https://safeguard.sh/resources/blog/python-package-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/python-package-security-best-practices</guid>
      <pubDate>Sun, 18 Jan 2026 16:58:21 GMT</pubDate>
      <category>Dependency Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AWS ECR Container Scanning: Beyond the Defaults]]></title>
      <description><![CDATA[A deep dive into ECR scanning options, from basic Clair scanning to enhanced Inspector integration, and what most teams get wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-ecr-container-scanning-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-ecr-container-scanning-guide</guid>
      <pubDate>Sun, 18 Jan 2026 15:37:55 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Scaling a Security Champions Network]]></title>
      <description><![CDATA[Security teams can't be everywhere. A well-structured security champions network extends security expertise into every development team without bottlenecking delivery.]]></description>
      <link>https://safeguard.sh/resources/blog/security-champions-network-scaling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-champions-network-scaling</guid>
      <pubDate>Sun, 18 Jan 2026 14:17:28 GMT</pubDate>
      <category>Security Culture</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Browser Extension Supply Chain Attacks: The Overlooked Threat Vector]]></title>
      <description><![CDATA[Browser extensions have become a prime target for supply chain attackers. With access to browsing data, credentials, and session tokens, a compromised extension is a skeleton key to your organization.]]></description>
      <link>https://safeguard.sh/resources/blog/browser-extension-supply-chain-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/browser-extension-supply-chain-attacks</guid>
      <pubDate>Sun, 18 Jan 2026 12:57:01 GMT</pubDate>
      <category>Threat Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[AI Safety Eval Datasets as Supply Chain]]></title>
      <description><![CDATA[The datasets you use to evaluate model safety are themselves a supply chain, and almost nobody is treating them that way. A senior engineer's audit of how eval corpora get poisoned, contaminated, and silently drifted.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-safety-eval-datasets-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-safety-eval-datasets-supply-chain</guid>
      <pubDate>Sun, 18 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise AI Agent Deployment Lessons, 2026]]></title>
      <description><![CDATA[Lessons learned from a year of enterprise AI agent deployments: what worked, what failed, and what we would do differently starting now.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-ai-agent-deployment-lessons-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-ai-agent-deployment-lessons-2026</guid>
      <pubDate>Sun, 18 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Mistral Large for Remediation]]></title>
      <description><![CDATA[Mistral Large is a strong reasoning model, but remediation is more than generating a diff. We look at what Griffin AI adds for production fix workflows.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mistral-large-for-remediation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mistral-large-for-remediation</guid>
      <pubDate>Sun, 18 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SSO & SCIM: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Enterprise identity is not a paywall. It is the substrate on which every other security control depends, and it is where Mythos-class vendors quietly fall behind.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-enterprise-sso-scim</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-enterprise-sso-scim</guid>
      <pubDate>Sun, 18 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Podman vs Docker Security: What Actually Changes When You Drop the Daemon]]></title>
      <description><![CDATA[Podman is daemonless, rootless by default, and fork-exec instead of client-server. Here is what those architectural differences mean for container security in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/podman-vs-docker-security-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/podman-vs-docker-security-comparison</guid>
      <pubDate>Sun, 18 Jan 2026 11:36:34 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[WAF Rule Writing Best Practices: From Alert Fatigue to Actionable Protection]]></title>
      <description><![CDATA[Most WAF deployments drown in false positives because the rules were never tuned. Here is how to write rules that protect without blocking legitimate traffic.]]></description>
      <link>https://safeguard.sh/resources/blog/waf-rule-writing-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/waf-rule-writing-best-practices</guid>
      <pubDate>Sun, 18 Jan 2026 10:16:08 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[The MCP Threat Model: What Actually Matters in 2026]]></title>
      <description><![CDATA[Most MCP threat models confuse protocol risk with deployment risk. Here is what the real attack surface looks like after a year of production incidents.]]></description>
      <link>https://safeguard.sh/resources/blog/model-context-protocol-threat-model-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/model-context-protocol-threat-model-2026</guid>
      <pubDate>Sun, 18 Jan 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Sudo Baron Samedit heap overflow (CVE-2021-3156)]]></title>
      <description><![CDATA[A decade-old sudo heap overflow, CVE-2021-3156 (Baron Samedit), let any local user gain root. Here's what's affected and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/sudo-baron-samedit-heap-overflow-cve-2021-3156</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sudo-baron-samedit-heap-overflow-cve-2021-3156</guid>
      <pubDate>Sun, 18 Jan 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Inside Safeguard's Reachability Engine]]></title>
      <description><![CDATA[A deep look at how Safeguard's reachability engine combines call graph construction, symbolic analysis, and runtime evidence to reduce vulnerability noise by an order of magnitude.]]></description>
      <link>https://safeguard.sh/resources/blog/inside-safeguard-reachability-engine-architecture</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/inside-safeguard-reachability-engine-architecture</guid>
      <pubDate>Sun, 18 Jan 2026 09:00:00 GMT</pubDate>
      <category>Architecture</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Forensics: Investigation Techniques After a Compromise]]></title>
      <description><![CDATA[When a supply chain compromise is confirmed or suspected, forensic investigation must trace the attack path through dependencies, build systems, and artifacts. This guide covers the methodology.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-forensics-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-forensics-guide</guid>
      <pubDate>Sun, 18 Jan 2026 08:55:41 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Rust Adoption in Security-Critical Software: Where We Stand]]></title>
      <description><![CDATA[Rust promises memory safety without garbage collection. Here is an honest look at where adoption stands and what it means for supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-adoption-security-critical-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-adoption-security-critical-software</guid>
      <pubDate>Sun, 18 Jan 2026 07:35:14 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Spring4Shell RCE in Spring Framework (CVE-2022-22965)]]></title>
      <description><![CDATA[A deep dive into CVE-2022-22965 (Spring4Shell): the critical Spring Framework RCE, its exploitation chain, timeline, and how to remediate it fast.]]></description>
      <link>https://safeguard.sh/resources/blog/spring4shell-rce-in-spring-framework-cve-2022-22965</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spring4shell-rce-in-spring-framework-cve-2022-22965</guid>
      <pubDate>Sun, 18 Jan 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Runtime vs Static Container Analysis: Complementary, Not Competing]]></title>
      <description><![CDATA[Static scanning finds known vulnerabilities. Runtime analysis finds actual exploitation. Using only one gives you half the picture.]]></description>
      <link>https://safeguard.sh/resources/blog/runtime-vs-static-container-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runtime-vs-static-container-analysis</guid>
      <pubDate>Sun, 18 Jan 2026 06:14:48 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Configuring automatic key rotation in AWS KMS]]></title>
      <description><![CDATA[A practical, step-by-step guide to configuring AWS KMS key rotation for customer managed keys, including custom rotation periods, multi-Region keys, and monitoring.]]></description>
      <link>https://safeguard.sh/resources/blog/configuring-automatic-key-rotation-in-aws-kms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/configuring-automatic-key-rotation-in-aws-kms</guid>
      <pubDate>Sun, 18 Jan 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Coordination Across the Open Source Ecosystem]]></title>
      <description><![CDATA[When a vulnerability affects a library used by thousands of projects, coordinating the fix is harder than writing the patch. The coordination problem is open source security's biggest operational challenge.]]></description>
      <link>https://safeguard.sh/resources/blog/vulnerability-coordination-open-source</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vulnerability-coordination-open-source</guid>
      <pubDate>Sun, 18 Jan 2026 04:54:21 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Log4j second RCE bypass (CVE-2021-45046)]]></title>
      <description><![CDATA[The Log4j 2.15.0 patch for Log4Shell was incomplete. CVE-2021-45046 shows how attackers bypassed it to achieve remote code execution.]]></description>
      <link>https://safeguard.sh/resources/blog/log4j-second-rce-bypass-cve-2021-45046</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4j-second-rce-bypass-cve-2021-45046</guid>
      <pubDate>Sun, 18 Jan 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Taming Static Analysis: A Practical Guide to False Positive Reduction]]></title>
      <description><![CDATA[False positives kill SAST adoption faster than anything else. Here is how to cut through the noise without missing real vulnerabilities.]]></description>
      <link>https://safeguard.sh/resources/blog/static-analysis-false-positive-reduction</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/static-analysis-false-positive-reduction</guid>
      <pubDate>Sun, 18 Jan 2026 03:33:54 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Automating Vulnerability Remediation: A Practical Guide]]></title>
      <description><![CDATA[Stop drowning in CVE backlogs. Learn how to build automated remediation workflows that fix vulnerabilities faster without burning out your engineering team.]]></description>
      <link>https://safeguard.sh/resources/blog/automating-vulnerability-remediation-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automating-vulnerability-remediation-guide</guid>
      <pubDate>Sun, 18 Jan 2026 02:13:28 GMT</pubDate>
      <category>How-To Guide</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Struts2 OGNL injection RCE (CVE-2018-11776)]]></title>
      <description><![CDATA[CVE-2018-11776 lets remote attackers achieve full RCE in Apache Struts2 via OGNL injection in URL namespaces. Impact, timeline, and fixes inside.]]></description>
      <link>https://safeguard.sh/resources/blog/struts2-ognl-injection-rce-cve-2018-11776</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/struts2-ognl-injection-rce-cve-2018-11776</guid>
      <pubDate>Sun, 18 Jan 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Software Update Signing and Verification: Getting It Right]]></title>
      <description><![CDATA[Signed updates are table stakes for software distribution. But the signing and verification process has pitfalls that undermine the entire security model.]]></description>
      <link>https://safeguard.sh/resources/blog/software-update-signing-verification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-update-signing-verification</guid>
      <pubDate>Sun, 18 Jan 2026 00:53:01 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Detecting malware and runtime threats in ECR and EKS with...]]></title>
      <description><![CDATA[How GuardDuty ECR malware protection and EKS runtime monitoring catch cryptominers and malicious images, where the coverage gaps are, and how Safeguard closes them.]]></description>
      <link>https://safeguard.sh/resources/blog/detecting-malware-and-runtime-threats-in-ecr-and-eks-with-guardduty</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/detecting-malware-and-runtime-threats-in-ecr-and-eks-with-guardduty</guid>
      <pubDate>Sun, 18 Jan 2026 00:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Container Image Signing with Cosign: A Practical Deep Dive]]></title>
      <description><![CDATA[Cosign makes signing and verifying container images straightforward. Here's everything you need to know to implement it in your pipeline.]]></description>
      <link>https://safeguard.sh/resources/blog/container-image-signing-with-cosign</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-image-signing-with-cosign</guid>
      <pubDate>Sat, 17 Jan 2026 23:32:34 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Jenkins Pipeline Security Hardening]]></title>
      <description><![CDATA[How to lock down Jenkins pipelines against credential theft, script injection, and unauthorized access with practical hardening steps.]]></description>
      <link>https://safeguard.sh/resources/blog/jenkins-pipeline-security-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/jenkins-pipeline-security-hardening</guid>
      <pubDate>Sat, 17 Jan 2026 22:12:08 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Namespace Squatting: How Attackers Exploit Python's Flat Package Namespace]]></title>
      <description><![CDATA[Python's package registry has no namespace protection. Attackers exploit this with typosquatting, namespace confusion, and abandoned name reclamation. Here is how to protect your Python supply chain.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-namespace-squatting-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-namespace-squatting-prevention</guid>
      <pubDate>Sat, 17 Jan 2026 20:51:41 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Brand Protection on Package Registries: Defending Your Namespace]]></title>
      <description><![CDATA[Attackers impersonate legitimate organizations on package registries through name squatting, logo theft, and metadata manipulation. Here is how to protect your brand and your users.]]></description>
      <link>https://safeguard.sh/resources/blog/brand-protection-package-registries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/brand-protection-package-registries</guid>
      <pubDate>Sat, 17 Jan 2026 19:31:14 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Browser Extension Permission Models and Supply Chain Risk]]></title>
      <description><![CDATA[Browser extensions operate with broad permissions and auto-update silently. Here is how the extension permission model creates supply chain risks and what organizations can do about it.]]></description>
      <link>https://safeguard.sh/resources/blog/browser-extension-permission-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/browser-extension-permission-model</guid>
      <pubDate>Sat, 17 Jan 2026 18:10:47 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Browser Extension Attacks and the Supply Chain]]></title>
      <description><![CDATA[Browser extensions run with elevated privileges and update automatically. When attackers compromise or acquire popular extensions, they gain access to millions of users instantly.]]></description>
      <link>https://safeguard.sh/resources/blog/browser-supply-chain-extension-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/browser-supply-chain-extension-attacks</guid>
      <pubDate>Sat, 17 Jan 2026 16:50:21 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Dropbox Breach: Phishing Attack Exposes 130 Private GitHub Repositories]]></title>
      <description><![CDATA[Attackers phished Dropbox employees by impersonating CircleCI, gaining access to 130 private GitHub repos containing internal code and credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/dropbox-phishing-attack-github-repositories</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dropbox-phishing-attack-github-repositories</guid>
      <pubDate>Sat, 17 Jan 2026 15:29:54 GMT</pubDate>
      <category>Incident Response</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Makefile Injection Attacks: When Build Automation Becomes a Weapon]]></title>
      <description><![CDATA[Makefiles execute shell commands by design. When those commands incorporate untrusted input, the results are predictably dangerous.]]></description>
      <link>https://safeguard.sh/resources/blog/makefile-injection-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/makefile-injection-attacks</guid>
      <pubDate>Sat, 17 Jan 2026 14:09:27 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSL CVE-2022-3602: The Critical That Wasn't (But Still Matters)]]></title>
      <description><![CDATA[OpenSSL pre-announced a critical vulnerability that was later downgraded to high severity. The incident revealed as much about our processes as the bug itself.]]></description>
      <link>https://safeguard.sh/resources/blog/openssl-critical-vulnerability-cve-2022-3602</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssl-critical-vulnerability-cve-2022-3602</guid>
      <pubDate>Sat, 17 Jan 2026 12:49:01 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SWE-Bench With Security Extensions: Field Review]]></title>
      <description><![CDATA[SWE-bench became the default benchmark for measuring AI coding agents, but the security extensions that were bolted on afterwards deserve their own scrutiny. A field review of what they measure, where they break, and whether you should trust the numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-benchmark-swe-bench-security-extensions</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-benchmark-swe-bench-security-extensions</guid>
      <pubDate>Sat, 17 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Claude Opus for Triage]]></title>
      <description><![CDATA[Griffin uses Claude Opus as its deepest reasoning engine. Here's what triage looks like with Opus alone versus Opus running inside Griffin's eval harness.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-claude-opus-for-triage</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-claude-opus-for-triage</guid>
      <pubDate>Sat, 17 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Auto-Fix Compile Rates: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Griffin AI's auto-fixes compile clean 73 percent of the time and pass with minor edits 87 percent. Mythos-class pure-LLM patches rarely show those numbers for a reason.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-auto-fix-compile-rates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-auto-fix-compile-rates</guid>
      <pubDate>Sat, 17 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Real Estate and PropTech Security Considerations]]></title>
      <description><![CDATA[PropTech platforms handle wire transfers, personal data, and property records. Software supply chain security is essential as real estate goes digital.]]></description>
      <link>https://safeguard.sh/resources/blog/real-estate-proptech-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/real-estate-proptech-security-considerations</guid>
      <pubDate>Sat, 17 Jan 2026 11:28:34 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Build Reproducibility: A Verification Guide]]></title>
      <description><![CDATA[If you cannot reproduce a build bit-for-bit, you cannot verify it was not tampered with. This guide covers deterministic builds, reproducibility verification, and why it matters for supply chain trust.]]></description>
      <link>https://safeguard.sh/resources/blog/build-reproducibility-verification-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/build-reproducibility-verification-guide</guid>
      <pubDate>Sat, 17 Jan 2026 10:08:07 GMT</pubDate>
      <category>Build Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[PHP-FPM/Nginx path disclosure RCE (CVE-2019-11043)]]></title>
      <description><![CDATA[CVE-2019-11043 let attackers gain unauthenticated RCE on PHP-FPM/Nginx stacks via a PATH_INFO underflow. Here's the impact, timeline, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/php-fpmnginx-path-disclosure-rce-cve-2019-11043</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-fpmnginx-path-disclosure-rce-cve-2019-11043</guid>
      <pubDate>Sat, 17 Jan 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Setting up OIDC federation between GitHub Actions and AWS...]]></title>
      <description><![CDATA[A step-by-step guide to setting up AWS OIDC GitHub Actions federation, from IAM provider setup to scoped trust policies, so CI/CD pipelines never need long-lived AWS keys.]]></description>
      <link>https://safeguard.sh/resources/blog/setting-up-oidc-federation-between-github-actions-and-aws-iam</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/setting-up-oidc-federation-between-github-actions-and-aws-iam</guid>
      <pubDate>Sat, 17 Jan 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Security Impact Analysis for Dependency Updates]]></title>
      <description><![CDATA[Updating a dependency is not just a version bump. Here is how to assess the security impact of dependency changes before they reach production.]]></description>
      <link>https://safeguard.sh/resources/blog/security-impact-analysis-dependency-updates</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-impact-analysis-dependency-updates</guid>
      <pubDate>Sat, 17 Jan 2026 08:47:41 GMT</pubDate>
      <category>Dependency Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Tekton Pipeline Security Guide]]></title>
      <description><![CDATA[Securing Tekton CI/CD pipelines on Kubernetes with task isolation, supply chain verification, and least-privilege service accounts.]]></description>
      <link>https://safeguard.sh/resources/blog/tekton-pipeline-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tekton-pipeline-security-guide</guid>
      <pubDate>Sat, 17 Jan 2026 07:27:14 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Ghostcat Apache Tomcat AJP file read/RCE (CVE-2020-1938)]]></title>
      <description><![CDATA[CVE-2020-1938 'Ghostcat' exposes Apache Tomcat's AJP connector to file read and RCE. Here's the ghostcat tomcat AJP vulnerability impact and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/ghostcat-apache-tomcat-ajp-file-readrce-cve-2020-1938</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ghostcat-apache-tomcat-ajp-file-readrce-cve-2020-1938</guid>
      <pubDate>Sat, 17 Jan 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Prevention in 2022: Why It Still Happens and How to Stop It]]></title>
      <description><![CDATA[SQL injection has been the top web vulnerability for over two decades. Modern frameworks help, but they do not make it impossible. Here is what still goes wrong.]]></description>
      <link>https://safeguard.sh/resources/blog/sql-injection-prevention-modern-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sql-injection-prevention-modern-guide</guid>
      <pubDate>Sat, 17 Jan 2026 06:06:47 GMT</pubDate>
      <category>Code Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Common AWS IAM misconfigurations that lead to breaches]]></title>
      <description><![CDATA[Capital One and Code Spaces both fell to AWS IAM misconfigurations, not novel exploits. Here's how overly permissive policies and privilege escalation paths cause real breaches.]]></description>
      <link>https://safeguard.sh/resources/blog/common-aws-iam-misconfigurations-that-lead-to-breaches</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/common-aws-iam-misconfigurations-that-lead-to-breaches</guid>
      <pubDate>Sat, 17 Jan 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Mend.io (WhiteSource): The Renamed SCA Veteran]]></title>
      <description><![CDATA[A review of Mend.io, formerly WhiteSource, covering its SCA capabilities, Renovate integration, automated remediation, and position in the crowded dependency scanning market.]]></description>
      <link>https://safeguard.sh/resources/blog/mend-io-whitesource-sca-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mend-io-whitesource-sca-review</guid>
      <pubDate>Sat, 17 Jan 2026 04:46:20 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[ProxyLogon Microsoft Exchange RCE chain (CVE-2021-26855)]]></title>
      <description><![CDATA[A deep dive into ProxyLogon (CVE-2021-26855 and chain): the unauthenticated Exchange RCE that enabled HAFNIUM and mass ransomware attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/proxylogon-microsoft-exchange-rce-chain-cve-2021-26855</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/proxylogon-microsoft-exchange-rce-chain-cve-2021-26855</guid>
      <pubDate>Sat, 17 Jan 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Policy Template for Enterprises]]></title>
      <description><![CDATA[A practical template for crafting an enterprise open-source usage policy that balances developer freedom with security and compliance requirements.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-policy-template-enterprises</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-policy-template-enterprises</guid>
      <pubDate>Sat, 17 Jan 2026 03:25:54 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Best practices for rotating secrets stored in Azure Key V...]]></title>
      <description><![CDATA[A practical, step-by-step guide to Azure Key Vault secret rotation best practices, covering rotation policies, automation, and expiration alerts.]]></description>
      <link>https://safeguard.sh/resources/blog/best-practices-for-rotating-secrets-stored-in-azure-key-vault</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-practices-for-rotating-secrets-stored-in-azure-key-vault</guid>
      <pubDate>Sat, 17 Jan 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The SBOM Maturity Model: A Practical Roadmap for Enterprise Adoption]]></title>
      <description><![CDATA[Most organizations are still at SBOM Level 0. Here's a five-level maturity model to guide your journey from no SBOMs to full supply chain transparency.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-maturity-model-for-enterprises</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-maturity-model-for-enterprises</guid>
      <pubDate>Sat, 17 Jan 2026 02:05:27 GMT</pubDate>
      <category>Compliance & Regulations</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[PrintNightmare Windows Print Spooler RCE (CVE-2021-34527)]]></title>
      <description><![CDATA[A critical Print Spooler flaw (CVE-2021-34527) enabled unauthenticated SYSTEM-level RCE on nearly every Windows host. Here's what happened and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/printnightmare-windows-print-spooler-rce-cve-2021-34527</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/printnightmare-windows-print-spooler-rce-cve-2021-34527</guid>
      <pubDate>Sat, 17 Jan 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Package Lock Files and Their Security Implications]]></title>
      <description><![CDATA[Lock files are your first line of defense against dependency drift. This guide explains how package-lock.json, yarn.lock, and similar files protect your builds from supply chain manipulation.]]></description>
      <link>https://safeguard.sh/resources/blog/package-lock-files-security-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/package-lock-files-security-implications</guid>
      <pubDate>Sat, 17 Jan 2026 00:45:00 GMT</pubDate>
      <category>Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[WinRAR CVE-2025-0411 Mark-of-the-Web Bypass]]></title>
      <description><![CDATA[CVE-2025-0411 lets WinRAR archives bypass Windows Mark-of-the-Web when extracted. Here is the flaw, the observed campaigns, and the patching path.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2025-0411-winrar-mark-of-the-web-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2025-0411-winrar-mark-of-the-web-bypass</guid>
      <pubDate>Sat, 17 Jan 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Scanning Azure Container Registry images for vulnerabilities]]></title>
      <description><![CDATA[A step-by-step guide to enabling Azure Container Registry vulnerability scanning with Microsoft Defender for Containers, plus troubleshooting and gating deployments on scan results.]]></description>
      <link>https://safeguard.sh/resources/blog/scanning-azure-container-registry-images-for-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scanning-azure-container-registry-images-for-vulnerabilities</guid>
      <pubDate>Sat, 17 Jan 2026 00:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[LockBit 3.0: The Evolution of the World's Most Prolific Ransomware Operation]]></title>
      <description><![CDATA[LockBit 3.0 introduced bug bounties, new extortion tactics, and industrial-scale operations that made it the dominant ransomware group through 2022 and 2023.]]></description>
      <link>https://safeguard.sh/resources/blog/lockbit-3-0-ransomware-evolution</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lockbit-3-0-ransomware-evolution</guid>
      <pubDate>Fri, 16 Jan 2026 23:24:34 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Text4Shell (CVE-2022-42889): Apache Commons Text and the Haunting Echo of Log4Shell]]></title>
      <description><![CDATA[A critical RCE vulnerability in Apache Commons Text drew immediate comparisons to Log4Shell. While less severe in practice, it highlighted how deeply embedded utility libraries create systemic risk.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-commons-text-text4shell-cve-2022-42889</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-commons-text-text4shell-cve-2022-42889</guid>
      <pubDate>Fri, 16 Jan 2026 22:04:07 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[VS Code Extension Marketplace Security: The IDE Supply Chain]]></title>
      <description><![CDATA[VS Code extensions run with the same privileges as your editor — which means full access to your source code, terminal, and credentials. The marketplace security model does not prevent malicious extensions.]]></description>
      <link>https://safeguard.sh/resources/blog/vscode-extension-marketplace-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vscode-extension-marketplace-security</guid>
      <pubDate>Fri, 16 Jan 2026 20:43:40 GMT</pubDate>
      <category>Developer Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Business Continuity Planning for Supply Chain Attacks]]></title>
      <description><![CDATA[When a critical dependency is compromised or disappears, can your business keep running? Most organizations haven't answered this question honestly.]]></description>
      <link>https://safeguard.sh/resources/blog/business-continuity-supply-chain-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/business-continuity-supply-chain-attacks</guid>
      <pubDate>Fri, 16 Jan 2026 19:23:14 GMT</pubDate>
      <category>Business Continuity</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Sigstore Reaches GA: Free Software Signing for Everyone]]></title>
      <description><![CDATA[Sigstore's general availability in October 2022 made cryptographic signing accessible to every developer. Here's why this is a watershed moment.]]></description>
      <link>https://safeguard.sh/resources/blog/sigstore-general-availability-software-signing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sigstore-general-availability-software-signing</guid>
      <pubDate>Fri, 16 Jan 2026 18:02:47 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Bandit for Python Security Linting: Getting Real Value From Static Analysis]]></title>
      <description><![CDATA[Bandit scans Python code for security issues. Here is how to configure it so it catches real bugs without burying your team in false positives.]]></description>
      <link>https://safeguard.sh/resources/blog/bandit-python-security-linting</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bandit-python-security-linting</guid>
      <pubDate>Fri, 16 Jan 2026 16:42:20 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Azure DevOps Pipeline Security Hardening: A Practical Guide]]></title>
      <description><![CDATA[How to lock down your Azure DevOps pipelines against supply chain attacks, credential leaks, and unauthorized deployments.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-devops-pipeline-security-hardening</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-devops-pipeline-security-hardening</guid>
      <pubDate>Fri, 16 Jan 2026 15:21:54 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Setting Up Pre-Commit Security Hooks]]></title>
      <description><![CDATA[Catch secrets, vulnerable patterns, and misconfigurations before they reach your repository with pre-commit hooks that developers will actually keep enabled.]]></description>
      <link>https://safeguard.sh/resources/blog/pre-commit-security-hooks-setup-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pre-commit-security-hooks-setup-guide</guid>
      <pubDate>Fri, 16 Jan 2026 14:01:27 GMT</pubDate>
      <category>How-To Guide</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[iOS Sideloading Security Implications for Enterprise Environments]]></title>
      <description><![CDATA[Regulatory pressure is forcing Apple to allow sideloading. For enterprise security teams, this changes the iOS threat model fundamentally.]]></description>
      <link>https://safeguard.sh/resources/blog/ios-sideloading-security-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ios-sideloading-security-implications</guid>
      <pubDate>Fri, 16 Jan 2026 12:41:00 GMT</pubDate>
      <category>Mobile Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Fine-Tuning Security LLMs vs Grounding: Which Wins]]></title>
      <description><![CDATA[Fine-tuning teaches a model to be a security expert. Grounding lets a general model act like one by reading the right sources. The right answer is usually both, but the proportions matter.]]></description>
      <link>https://safeguard.sh/resources/blog/fine-tuning-security-llm-vs-grounding-approach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/fine-tuning-security-llm-vs-grounding-approach</guid>
      <pubDate>Fri, 16 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[EU CRA Readiness: Griffin AI vs Mythos]]></title>
      <description><![CDATA[The EU Cyber Resilience Act wants mandatory vulnerability handling, SBOM delivery, and documented due diligence. Griffin AI produces those artifacts continuously. Mythos-class tools produce conversations about them.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-eu-cra-readiness</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-eu-cra-readiness</guid>
      <pubDate>Fri, 16 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs OpenAI Codex for Security]]></title>
      <description><![CDATA[Codex-style coding agents are powerful for writing features. Security remediation needs a different shape of system—one that grounds frontier reasoning in SBOM, policy, and reachability context.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-openai-codex-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-openai-codex-security</guid>
      <pubDate>Fri, 16 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Debian Repository Security: A Practical Hardening Guide]]></title>
      <description><![CDATA[Debian APT is powerful but riddled with trust assumptions. Here is how to lock it down for production environments.]]></description>
      <link>https://safeguard.sh/resources/blog/debian-repository-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/debian-repository-security-guide</guid>
      <pubDate>Fri, 16 Jan 2026 11:20:33 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Tern: Container SBOM Generation Through Layer Analysis]]></title>
      <description><![CDATA[A review of Tern, the open source tool that generates SBOMs by inspecting container image layers, including its strengths, limitations, and where it fits in your toolchain.]]></description>
      <link>https://safeguard.sh/resources/blog/tern-sbom-container-analysis-tool</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tern-sbom-container-analysis-tool</guid>
      <pubDate>Fri, 16 Jan 2026 10:00:07 GMT</pubDate>
      <category>Tool Reviews</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[F5 BIG-IP iControl REST RCE (CVE-2022-1388)]]></title>
      <description><![CDATA[A critical iControl REST auth bypass let attackers gain root RCE on BIG-IP within days of disclosure. Impact, KEV status, timeline, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/f5-big-ip-icontrol-rest-rce-cve-2022-1388</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/f5-big-ip-icontrol-rest-rce-cve-2022-1388</guid>
      <pubDate>Fri, 16 Jan 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Secrets Management in CI Pipelines: 2026 Guide]]></title>
      <description><![CDATA[Rotating tokens, OIDC federation, and scoped runners are table stakes in 2026. Here is how senior engineers design CI secrets that do not leak on bad days.]]></description>
      <link>https://safeguard.sh/resources/blog/secrets-management-in-ci-pipelines-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secrets-management-in-ci-pipelines-2026</guid>
      <pubDate>Fri, 16 Jan 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Using Azure AD Workload Identity Federation to remove sec...]]></title>
      <description><![CDATA[How Azure Workload Identity Federation lets AKS and CI workloads swap Azure AD access tokens without ever storing a client secret—and how to migrate safely.]]></description>
      <link>https://safeguard.sh/resources/blog/using-azure-ad-workload-identity-federation-to-remove-secrets-from-workloads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/using-azure-ad-workload-identity-federation-to-remove-secrets-from-workloads</guid>
      <pubDate>Fri, 16 Jan 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[OPA Gatekeeper for Kubernetes: Writing Policies That Actually Work]]></title>
      <description><![CDATA[Gatekeeper brings OPA's policy engine to Kubernetes. The learning curve is steep but the flexibility is unmatched. Here is how to write, test, and deploy Rego policies that enforce real security.]]></description>
      <link>https://safeguard.sh/resources/blog/opa-gatekeeper-kubernetes-policies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/opa-gatekeeper-kubernetes-policies</guid>
      <pubDate>Fri, 16 Jan 2026 08:39:40 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Security ROI Calculation Methods That Actually Work]]></title>
      <description><![CDATA[Calculating security ROI is notoriously difficult because you are measuring things that did not happen. Here are methods that produce credible numbers.]]></description>
      <link>https://safeguard.sh/resources/blog/security-roi-calculation-methods</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-roi-calculation-methods</guid>
      <pubDate>Fri, 16 Jan 2026 07:19:13 GMT</pubDate>
      <category>Security Strategy</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[libwebp heap buffer overflow zero-day (CVE-2023-4863)]]></title>
      <description><![CDATA[A heap buffer overflow in libwebp, actively exploited in a zero-click iOS spyware chain, exposed browsers, Electron apps, and containers alike.]]></description>
      <link>https://safeguard.sh/resources/blog/libwebp-heap-buffer-overflow-zero-day-cve-2023-4863</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/libwebp-heap-buffer-overflow-zero-day-cve-2023-4863</guid>
      <pubDate>Fri, 16 Jan 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Designing least-privilege custom roles with Azure RBAC]]></title>
      <description><![CDATA[A practical guide to designing least-privilege custom roles in Azure RBAC, covering over-permissioning pitfalls, scoping, and audit strategies.]]></description>
      <link>https://safeguard.sh/resources/blog/designing-least-privilege-custom-roles-with-azure-rbac</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/designing-least-privilege-custom-roles-with-azure-rbac</guid>
      <pubDate>Fri, 16 Jan 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[GDPR and Software Supply Chain Obligations You Can't Ignore]]></title>
      <description><![CDATA[GDPR's security requirements extend deep into software supply chains. Here's where data protection law meets dependency management.]]></description>
      <link>https://safeguard.sh/resources/blog/gdpr-software-supply-chain-obligations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gdpr-software-supply-chain-obligations</guid>
      <pubDate>Fri, 16 Jan 2026 05:58:47 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[CISA Self-Attestation Form: What Software Producers Need to Know]]></title>
      <description><![CDATA[OMB M-22-18 requires software producers selling to the federal government to self-attest to secure development practices. Here's what's required.]]></description>
      <link>https://safeguard.sh/resources/blog/cisa-self-attestation-form-secure-software</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cisa-self-attestation-form-secure-software</guid>
      <pubDate>Fri, 16 Jan 2026 04:38:20 GMT</pubDate>
      <category>Compliance & Regulations</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[HTTP/2 Rapid Reset DDoS technique (CVE-2023-44487)]]></title>
      <description><![CDATA[CVE-2023-44487 (HTTP/2 Rapid Reset) fueled record DDoS attacks by abusing stream resets. Here's the impact, timeline, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/http2-rapid-reset-ddos-technique-cve-2023-44487</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/http2-rapid-reset-ddos-technique-cve-2023-44487</guid>
      <pubDate>Fri, 16 Jan 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Package Manager Security: npm, pip, and Maven Compared]]></title>
      <description><![CDATA[Each package manager has its own security model, attack surface, and best practices. This guide compares npm, pip, and Maven from a supply chain security perspective.]]></description>
      <link>https://safeguard.sh/resources/blog/package-manager-security-npm-pip-maven</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/package-manager-security-npm-pip-maven</guid>
      <pubDate>Fri, 16 Jan 2026 03:17:53 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Generating SBOMs from Container Images: A Practical Guide]]></title>
      <description><![CDATA[Container images are opaque by default. Here's how to crack them open with SBOMs to see exactly what's running in production.]]></description>
      <link>https://safeguard.sh/resources/blog/generating-sbom-from-container-images</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/generating-sbom-from-container-images</guid>
      <pubDate>Fri, 16 Jan 2026 01:57:27 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[XZ Utils backdoor discovery (CVE-2024-3094)]]></title>
      <description><![CDATA[A deep dive into CVE-2024-3094, the XZ Utils backdoor: affected versions, CVSS/EPSS context, full attack timeline, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/xz-utils-backdoor-discovery-cve-2024-3094</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xz-utils-backdoor-discovery-cve-2024-3094</guid>
      <pubDate>Fri, 16 Jan 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Telecommunications Supply Chain Security: Protecting Critical Infrastructure]]></title>
      <description><![CDATA[Telecom networks are critical infrastructure that depend on complex software supply chains. Here's how carriers and equipment providers should approach security.]]></description>
      <link>https://safeguard.sh/resources/blog/telecommunications-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/telecommunications-supply-chain-security</guid>
      <pubDate>Fri, 16 Jan 2026 00:37:00 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Securing Azure DevOps pipelines against supply chain comp...]]></title>
      <description><![CDATA[Pipelines now hold more privilege than the apps they build. Here's how Azure DevOps pipeline security actually breaks down—and how to close the gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-azure-devops-pipelines-against-supply-chain-compromise</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-azure-devops-pipelines-against-supply-chain-compromise</guid>
      <pubDate>Fri, 16 Jan 2026 00:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[PHP Composer Dependency Security]]></title>
      <description><![CDATA[Securing PHP applications through Composer lockfiles, Packagist verification, and automated vulnerability scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/php-composer-dependency-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/php-composer-dependency-security</guid>
      <pubDate>Thu, 15 Jan 2026 23:16:33 GMT</pubDate>
      <category>Dependency Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Network Segmentation for Development Environments: Isolating the Build Pipeline]]></title>
      <description><![CDATA[Development environments are often the weakest link in network security. Proper segmentation isolates build systems from production and prevents lateral movement from compromised developer machines.]]></description>
      <link>https://safeguard.sh/resources/blog/network-segmentation-development-environments</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/network-segmentation-development-environments</guid>
      <pubDate>Thu, 15 Jan 2026 21:56:07 GMT</pubDate>
      <category>Network Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Cookie Security for Modern Web Applications]]></title>
      <description><![CDATA[Cookie misconfigurations remain one of the most common web vulnerabilities. From SameSite to cookie prefixes, here is how to configure cookies that resist session hijacking and CSRF attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/cookie-security-modern-web-apps</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cookie-security-modern-web-apps</guid>
      <pubDate>Thu, 15 Jan 2026 20:35:40 GMT</pubDate>
      <category>Web Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Trusted Computing and TPM in the Software Supply Chain]]></title>
      <description><![CDATA[Trusted Platform Modules provide a hardware root of trust for verifying software integrity. Understanding how TPMs fit into supply chain security helps build tamper-resistant systems.]]></description>
      <link>https://safeguard.sh/resources/blog/trusted-computing-tpm-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trusted-computing-tpm-software-supply-chain</guid>
      <pubDate>Thu, 15 Jan 2026 19:15:13 GMT</pubDate>
      <category>Hardware Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Developer Productivity vs. Security: Finding the Real Balance]]></title>
      <description><![CDATA[The security-productivity tension is real but often exaggerated. Most friction comes from bad tooling and poor processes, not from security itself. Here is how to fix the actual problems.]]></description>
      <link>https://safeguard.sh/resources/blog/developer-productivity-security-balance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/developer-productivity-security-balance</guid>
      <pubDate>Thu, 15 Jan 2026 17:54:46 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[npm Registry Security Gets Serious: 2022's Major Improvements]]></title>
      <description><![CDATA[From mandatory MFA for top packages to enhanced login verification, npm made significant security improvements in 2022. Here's what changed.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-registry-security-improvements-2022</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-registry-security-improvements-2022</guid>
      <pubDate>Thu, 15 Jan 2026 16:34:20 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[ProxyNotShell CVE-2022-41040: Microsoft Exchange Under Fire Again]]></title>
      <description><![CDATA[ProxyNotShell chained two Exchange vulnerabilities for authenticated RCE, exploited in the wild for weeks before Microsoft delivered a patch. Exchange admins were running out of patience.]]></description>
      <link>https://safeguard.sh/resources/blog/microsoft-exchange-proxynotshell-cve-2022-41040</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microsoft-exchange-proxynotshell-cve-2022-41040</guid>
      <pubDate>Thu, 15 Jan 2026 15:13:53 GMT</pubDate>
      <category>Zero-Day Exploits</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[OSS Review Toolkit (ORT): Automating License Compliance at Scale]]></title>
      <description><![CDATA[The OSS Review Toolkit handles license scanning, vulnerability detection, and compliance policy enforcement. Here's how to put it to work.]]></description>
      <link>https://safeguard.sh/resources/blog/oss-review-toolkit-ort-license-compliance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/oss-review-toolkit-ort-license-compliance</guid>
      <pubDate>Thu, 15 Jan 2026 13:53:26 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Migrating Dependencies for Security: A Step-by-Step Guide]]></title>
      <description><![CDATA[When a dependency becomes a security liability, migration is the only real fix. Here is a structured approach to dependency migration that minimizes risk and disruption.]]></description>
      <link>https://safeguard.sh/resources/blog/migrating-dependencies-security-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/migrating-dependencies-security-guide</guid>
      <pubDate>Thu, 15 Jan 2026 12:33:00 GMT</pubDate>
      <category>Dependency Management</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Anthropic MCP Security Model: A Deep Dive]]></title>
      <description><![CDATA[Anthropic's Model Context Protocol introduces a new trust boundary between agents and tools. Here is how the security model actually works in practice.]]></description>
      <link>https://safeguard.sh/resources/blog/anthropic-mcp-security-model-deep-dive</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/anthropic-mcp-security-model-deep-dive</guid>
      <pubDate>Thu, 15 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CRA Product Classes: Implementing Regulation 2025/2392 Technical Descriptions]]></title>
      <description><![CDATA[Commission Implementing Regulation (EU) 2025/2392 was signed on 28 November 2025, setting the technical descriptions for important and critical CRA product categories.]]></description>
      <link>https://safeguard.sh/resources/blog/cra-implementing-regulation-2025-2392-product-classes</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cra-implementing-regulation-2025-2392-product-classes</guid>
      <pubDate>Thu, 15 Jan 2026 12:00:00 GMT</pubDate>
      <category>Regulation</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[CycloneDX ML-BOM in 1.7: Implementation Guide]]></title>
      <description><![CDATA[CycloneDX 1.7 was published in October 2025 and adopted by the General Assembly in December. We unpack what the ML-BOM capability means in practice for AI inventory.]]></description>
      <link>https://safeguard.sh/resources/blog/cyclonedx-ml-bom-1-7-implementation-guide-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cyclonedx-ml-bom-1-7-implementation-guide-2026</guid>
      <pubDate>Thu, 15 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Context Window As A Security Limit]]></title>
      <description><![CDATA[The context window is usually marketed as a capability parameter. In a security setting, it behaves like a budget, a forgetting function, and an attack surface all at once.]]></description>
      <link>https://safeguard.sh/resources/blog/frontier-model-limit-context-window-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/frontier-model-limit-context-window-security</guid>
      <pubDate>Thu, 15 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GCP Artifact Registry Vulnerability Scanning: Integrating the Findings]]></title>
      <description><![CDATA[Artifact Analysis on Artifact Registry produces a steady stream of findings. The discipline is in what you do with them. We map the workflows that actually reduce risk.]]></description>
      <link>https://safeguard.sh/resources/blog/gcp-artifact-registry-vulnerability-scanning-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gcp-artifact-registry-vulnerability-scanning-2026</guid>
      <pubDate>Thu, 15 Jan 2026 12:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Gemini Ultra for Security Reasoning]]></title>
      <description><![CDATA[Gemini Ultra sets a high bar on complex reasoning benchmarks. But security reasoning is not benchmark reasoning. Here's how Griffin AI's engine-first approach changes the outcome.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-ultra-reasoning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-gemini-ultra-reasoning</guid>
      <pubDate>Thu, 15 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CycloneDX Support: Griffin AI vs Mythos]]></title>
      <description><![CDATA[CycloneDX is not a text format to be summarized — it's a typed graph with dozens of semantically-rich fields. Griffin AI consumes it as a graph. Mythos-class tools consume it as tokens. That difference decides every downstream finding.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cyclonedx-support</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-cyclonedx-support</guid>
      <pubDate>Thu, 15 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Database Extensions as Supply Chain Risk: The Overlooked Attack Surface]]></title>
      <description><![CDATA[PostgreSQL extensions, MySQL plugins, and database add-ons run with database-level privileges. A compromised extension has direct access to your data. Most organizations never audit them.]]></description>
      <link>https://safeguard.sh/resources/blog/database-extension-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/database-extension-supply-chain-risks</guid>
      <pubDate>Thu, 15 Jan 2026 11:12:33 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[How a Fortune 500 Bank Ran Its SBOM Program]]></title>
      <description><![CDATA[An anonymized look at how a Fortune 500 financial services firm operationalized an enterprise SBOM program using Safeguard across 4,200 applications.]]></description>
      <link>https://safeguard.sh/resources/blog/customer-story-fortune-500-bank-sbom-program-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/customer-story-fortune-500-bank-sbom-program-2026</guid>
      <pubDate>Thu, 15 Jan 2026 10:00:00 GMT</pubDate>
      <category>Case Studies</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSH forwarded ssh-agent RCE (CVE-2023-38408)]]></title>
      <description><![CDATA[CVE-2023-38408 lets a malicious SSH server hijack a forwarded ssh-agent to run code on the client. Impact, affected versions, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/openssh-forwarded-ssh-agent-rce-cve-2023-38408</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssh-forwarded-ssh-agent-rce-cve-2023-38408</guid>
      <pubDate>Thu, 15 Jan 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[5 Software Supply Chain Security Trends Defining 2026]]></title>
      <description><![CDATA[From AI-generated code risks to regulatory enforcement, these are the supply chain security trends that will shape the year ahead.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-trends-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-trends-2026</guid>
      <pubDate>Thu, 15 Jan 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[The Open Source Software Security Act of 2022: What It Means for Developers]]></title>
      <description><![CDATA[The U.S. Senate introduced legislation directing CISA to secure open source software used by the federal government. Here's what the bill contains.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-software-security-act-2022</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-software-security-act-2022</guid>
      <pubDate>Thu, 15 Jan 2026 09:52:06 GMT</pubDate>
      <category>Compliance & Regulations</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Checklist: Best Practices for 2026]]></title>
      <description><![CDATA[An application security best practices checklist for 2026: what to enforce at design, dependency, pipeline, and runtime layers, updated for the new OWASP Top 10 categories.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-checklist-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-checklist-2026</guid>
      <pubDate>Thu, 15 Jan 2026 09:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[How Microsoft Defender for Containers protects AKS and AC...]]></title>
      <description><![CDATA[Defender for Containers scans ACR images and monitors AKS clusters in real time — but it can't see what happens before a build reaches the registry. Here's what it covers and what it misses.]]></description>
      <link>https://safeguard.sh/resources/blog/how-microsoft-defender-for-containers-protects-aks-and-acr-workloads</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-microsoft-defender-for-containers-protects-aks-and-acr-workloads</guid>
      <pubDate>Thu, 15 Jan 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Snyk's Market Position: An Independent Read Going Into 2026]]></title>
      <description><![CDATA[Snyk's market position going into 2026 rests on developer-first SCA and container scanning, with SAST and DAST as comparatively newer additions.]]></description>
      <link>https://safeguard.sh/resources/blog/snyk-market-position-independent-read</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/snyk-market-position-independent-read</guid>
      <pubDate>Thu, 15 Jan 2026 09:00:00 GMT</pubDate>
      <category>Comparisons</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Compression Library Vulnerabilities: From zlib to the xz Backdoor]]></title>
      <description><![CDATA[Compression libraries are everywhere and trusted implicitly. The xz backdoor proved that trust can be weaponized. Here is the full picture.]]></description>
      <link>https://safeguard.sh/resources/blog/compression-library-vulnerabilities-zlib-xz</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/compression-library-vulnerabilities-zlib-xz</guid>
      <pubDate>Thu, 15 Jan 2026 08:31:40 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Application Security Companies: An Evaluation Checklist]]></title>
      <description><![CDATA[A concrete checklist for evaluating application security companies in 2026 — coverage, false-positive handling, integration depth, and the questions vendor demos are designed to dodge.]]></description>
      <link>https://safeguard.sh/resources/blog/application-security-companies-evaluation-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/application-security-companies-evaluation-checklist</guid>
      <pubDate>Thu, 15 Jan 2026 08:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Building an SBOM Program from Scratch: A Practical Guide]]></title>
      <description><![CDATA[Standing up an SBOM program is more than picking a tool. This guide covers organizational buy-in, tooling selection, automation, and scaling from your first BOM to enterprise-wide adoption.]]></description>
      <link>https://safeguard.sh/resources/blog/building-sbom-program-from-scratch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-sbom-program-from-scratch</guid>
      <pubDate>Thu, 15 Jan 2026 07:11:13 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSH agent forwarding RCE (CVE-2016-10009)]]></title>
      <description><![CDATA[A malicious or compromised SSH server could abuse forwarded ssh-agent connections to load arbitrary PKCS#11 modules and run code on the client.]]></description>
      <link>https://safeguard.sh/resources/blog/openssh-agent-forwarding-rce-cve-2016-10009</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssh-agent-forwarding-rce-cve-2016-10009</guid>
      <pubDate>Thu, 15 Jan 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Choosing between Key Vault access policies and RBAC permi...]]></title>
      <description><![CDATA[Access policies or RBAC? A concrete breakdown of Azure Key Vault's two permission models, when each still makes sense, and how to migrate safely.]]></description>
      <link>https://safeguard.sh/resources/blog/choosing-between-key-vault-access-policies-and-rbac-permission-model</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/choosing-between-key-vault-access-policies-and-rbac-permission-model</guid>
      <pubDate>Thu, 15 Jan 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Admission Controllers for Supply Chain Policy]]></title>
      <description><![CDATA[Admission controllers are the only Kubernetes enforcement point that sees every workload before it runs. That makes them the right place to enforce image provenance, signing, and SBOM policies.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-admission-controllers-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-admission-controllers-supply-chain</guid>
      <pubDate>Thu, 15 Jan 2026 05:50:46 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SOX Compliance in Software Development: The Supply Chain Angle]]></title>
      <description><![CDATA[Sarbanes-Oxley requirements for internal controls extend into software development and supply chain integrity. Here's the connection most teams miss.]]></description>
      <link>https://safeguard.sh/resources/blog/sox-compliance-software-development</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sox-compliance-software-development</guid>
      <pubDate>Thu, 15 Jan 2026 04:30:20 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Shellshock Bash environment variable RCE (CVE-2014-6271)]]></title>
      <description><![CDATA[A 2014 parsing flaw in Bash's function-export handling let attackers run arbitrary commands via environment variables — and it's still exploited today.]]></description>
      <link>https://safeguard.sh/resources/blog/shellshock-bash-environment-variable-rce-cve-2014-6271</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shellshock-bash-environment-variable-rce-cve-2014-6271</guid>
      <pubDate>Thu, 15 Jan 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[GoSec Static Analysis for Go: Practical Security Scanning]]></title>
      <description><![CDATA[GoSec finds security issues in Go source code. Here is how to get the most out of it without fighting false positives all day.]]></description>
      <link>https://safeguard.sh/resources/blog/gosec-static-analysis-for-go</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gosec-static-analysis-for-go</guid>
      <pubDate>Thu, 15 Jan 2026 03:09:53 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Best practices for using Azure Managed Identity instead o...]]></title>
      <description><![CDATA[A step-by-step guide to Azure Managed Identity best practices: system vs user assigned identities, least-privilege roles, and secretless authentication.]]></description>
      <link>https://safeguard.sh/resources/blog/best-practices-for-using-azure-managed-identity-instead-of-secrets</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-practices-for-using-azure-managed-identity-instead-of-secrets</guid>
      <pubDate>Thu, 15 Jan 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Uber's 2022 Breach: How an 18-Year-Old Social Engineered Past MFA]]></title>
      <description><![CDATA[An attacker bombarded an Uber contractor with MFA push notifications until they accepted. What followed was a full compromise of internal systems.]]></description>
      <link>https://safeguard.sh/resources/blog/uber-breach-2022-social-engineering-attack</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/uber-breach-2022-social-engineering-attack</guid>
      <pubDate>Thu, 15 Jan 2026 01:49:26 GMT</pubDate>
      <category>Incident Response</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[EternalBlue SMBv1 RCE (CVE-2017-0144)]]></title>
      <description><![CDATA[EternalBlue (CVE-2017-0144) turned a Windows SMBv1 flaw into WannaCry and NotPetya. Here's the risk context, timeline, and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/eternalblue-smbv1-rce-cve-2017-0144</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eternalblue-smbv1-rce-cve-2017-0144</guid>
      <pubDate>Thu, 15 Jan 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Software Transparency and the EU Cyber Resilience Act]]></title>
      <description><![CDATA[The EU Cyber Resilience Act is rewriting the rules for software sold in Europe. Mandatory vulnerability handling, SBOM requirements, and security-by-design obligations are coming for every vendor.]]></description>
      <link>https://safeguard.sh/resources/blog/software-transparency-eu-cyber-resilience-act</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-transparency-eu-cyber-resilience-act</guid>
      <pubDate>Thu, 15 Jan 2026 00:28:59 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Signing container images and generating SBOMs in Azure pi...]]></title>
      <description><![CDATA[A practical walkthrough for Azure container image signing with Notation and ACR content trust, plus generating SBOMs inside Azure DevOps pipelines.]]></description>
      <link>https://safeguard.sh/resources/blog/signing-container-images-and-generating-sboms-in-azure-pipelines</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/signing-container-images-and-generating-sboms-in-azure-pipelines</guid>
      <pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Priya Mehta)</author>
    </item>
    <item>
      <title><![CDATA[Retail and E-Commerce Software Supply Chain Security]]></title>
      <description><![CDATA[E-commerce platforms process millions in transactions daily using open-source components. Here's how retail organizations should manage software supply chain risk.]]></description>
      <link>https://safeguard.sh/resources/blog/retail-ecommerce-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/retail-ecommerce-software-supply-chain</guid>
      <pubDate>Wed, 14 Jan 2026 23:08:33 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Trivy vs Grype: Open Source Vulnerability Scanners Compared]]></title>
      <description><![CDATA[A practical comparison of Trivy and Grype for vulnerability scanning, covering detection accuracy, performance, SBOM support, and real-world usage patterns.]]></description>
      <link>https://safeguard.sh/resources/blog/trivy-grype-vulnerability-scanner-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trivy-grype-vulnerability-scanner-comparison</guid>
      <pubDate>Wed, 14 Jan 2026 21:48:06 GMT</pubDate>
      <category>Tool Comparisons</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SPDX Specification: A Practical Guide for Security Teams]]></title>
      <description><![CDATA[SPDX is the ISO-standardized SBOM format. Here's how to use it effectively for security, not just license compliance.]]></description>
      <link>https://safeguard.sh/resources/blog/spdx-specification-practical-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/spdx-specification-practical-guide</guid>
      <pubDate>Wed, 14 Jan 2026 20:27:39 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Harbor Registry Security Configuration: A Complete Hardening Guide]]></title>
      <description><![CDATA[Harbor is the most popular open-source container registry. Its security features are powerful but require deliberate configuration to be effective.]]></description>
      <link>https://safeguard.sh/resources/blog/harbor-registry-security-configuration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/harbor-registry-security-configuration</guid>
      <pubDate>Wed, 14 Jan 2026 19:07:13 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CORS Misconfiguration Exploitation: The Silent API Exposure]]></title>
      <description><![CDATA[CORS misconfigurations are one of the most common web security issues. They silently expose your APIs to cross-origin data theft.]]></description>
      <link>https://safeguard.sh/resources/blog/cors-misconfiguration-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cors-misconfiguration-exploitation</guid>
      <pubDate>Wed, 14 Jan 2026 17:46:46 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Angular Application Security Checklist]]></title>
      <description><![CDATA[A practical security checklist for Angular applications covering XSS prevention, dependency management, and secure configuration.]]></description>
      <link>https://safeguard.sh/resources/blog/angular-application-security-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/angular-application-security-checklist</guid>
      <pubDate>Wed, 14 Jan 2026 16:26:19 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Canary Deployments and Security Monitoring]]></title>
      <description><![CDATA[Using canary deployment strategies to catch security regressions before they reach all users, with monitoring patterns for security-relevant metrics.]]></description>
      <link>https://safeguard.sh/resources/blog/canary-deployments-security-monitoring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/canary-deployments-security-monitoring</guid>
      <pubDate>Wed, 14 Jan 2026 15:05:53 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Software Escrow Agreements: Security Implications You Should Negotiate]]></title>
      <description><![CDATA[Software escrow protects you if a vendor goes under. But the security details in the agreement determine whether the escrow is actually usable.]]></description>
      <link>https://safeguard.sh/resources/blog/software-escrow-agreements-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-escrow-agreements-security</guid>
      <pubDate>Wed, 14 Jan 2026 13:45:26 GMT</pubDate>
      <category>Security Strategy</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Rust Supply Chain Security: How crates.io Stacks Up Against npm and PyPI]]></title>
      <description><![CDATA[Rust's crates.io registry has design advantages for supply chain security, but it's not immune. Here's an honest assessment of the Rust ecosystem.]]></description>
      <link>https://safeguard.sh/resources/blog/rust-supply-chain-security-crates-io</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/rust-supply-chain-security-crates-io</guid>
      <pubDate>Wed, 14 Jan 2026 12:24:59 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Training Data Provenance: The Regulatory Wave]]></title>
      <description><![CDATA[Regulators across three continents are converging on a single demand: show where your training data came from. The engineering implications are larger than most labs have admitted.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-trend-training-data-provenance-regulation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-trend-training-data-provenance-regulation</guid>
      <pubDate>Wed, 14 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Call Graph Depth Compared: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Shallow call graphs miss real exploits; deep graphs surface them. We examine how Griffin AI and Mythos-class tools differ on depth, and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-call-graph-depth</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-call-graph-depth</guid>
      <pubDate>Wed, 14 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Path Traversal in Dependency Installation: Writing Files Where They Should Not Go]]></title>
      <description><![CDATA[Package archives can contain path traversal sequences that write files outside the expected directory. Most developers never check for this.]]></description>
      <link>https://safeguard.sh/resources/blog/path-traversal-dependency-installation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/path-traversal-dependency-installation</guid>
      <pubDate>Wed, 14 Jan 2026 11:04:33 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[BlueKeep RDP wormable RCE (CVE-2019-0708)]]></title>
      <description><![CDATA[A deep dive into CVE-2019-0708 (BlueKeep), the wormable, pre-auth RDP RCE affecting legacy Windows — impact, timeline, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/bluekeep-rdp-wormable-rce-cve-2019-0708</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bluekeep-rdp-wormable-rce-cve-2019-0708</guid>
      <pubDate>Wed, 14 Jan 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[What Is Access Control?]]></title>
      <description><![CDATA[Access control decides who can reach a resource and what they can do with it. Learn the common models, how enforcement works, and why least privilege is the guiding rule.]]></description>
      <link>https://safeguard.sh/resources/blog/what-is-access-control</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-is-access-control</guid>
      <pubDate>Wed, 14 Jan 2026 10:00:00 GMT</pubDate>
      <category>Concepts</category>
      <author>hi@safeguard.sh (Daniel Osei)</author>
    </item>
    <item>
      <title><![CDATA[Security Misconfiguration Checklist: The Low-Hanging Fruit Attackers Love]]></title>
      <description><![CDATA[Misconfigurations are the easiest vulnerabilities to find and exploit. Here is a practical checklist for web servers, frameworks, cloud services, and databases.]]></description>
      <link>https://safeguard.sh/resources/blog/security-misconfiguration-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-misconfiguration-checklist</guid>
      <pubDate>Wed, 14 Jan 2026 09:44:06 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[AppSec Solutions: A Market Map for 2026]]></title>
      <description><![CDATA[The appsec solutions market has consolidated around a handful of shapes — code-first platforms, cloud-native suites, and point scanners — and picking the right shape matters more than picking a brand.]]></description>
      <link>https://safeguard.sh/resources/blog/appsec-solutions-market-map-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/appsec-solutions-market-map-2026</guid>
      <pubDate>Wed, 14 Jan 2026 09:30:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[Configuring soft delete and purge protection for Azure Ke...]]></title>
      <description><![CDATA[A step-by-step guide to enabling Key Vault soft delete and purge protection, recovering deleted secrets, and applying backup practices to prevent permanent data loss.]]></description>
      <link>https://safeguard.sh/resources/blog/configuring-soft-delete-and-purge-protection-for-azure-key-vault</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/configuring-soft-delete-and-purge-protection-for-azure-key-vault</guid>
      <pubDate>Wed, 14 Jan 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[EO 14028 Two Years In: What Actually Shipped]]></title>
      <description><![CDATA[A clear-eyed look at what parts of Executive Order 14028 actually made it into production across federal agencies, vendors, and the SBOM ecosystem by 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/eo-14028-two-years-in-what-shipped</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eo-14028-two-years-in-what-shipped</guid>
      <pubDate>Wed, 14 Jan 2026 09:00:00 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Pre-Commit Hooks Security Recipes for 2026]]></title>
      <description><![CDATA[Practical pre-commit framework recipes that catch secrets, malicious packages, and risky changes before they reach your remote, without slowing developers down.]]></description>
      <link>https://safeguard.sh/resources/blog/pre-commit-hooks-security-recipes-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pre-commit-hooks-security-recipes-2026</guid>
      <pubDate>Wed, 14 Jan 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SAST Tools: A Shortlist Worth Evaluating]]></title>
      <description><![CDATA[A working sast tools list should separate what free sast tools handle well from what only becomes worthwhile once you're paying for language coverage, tuning, and CI/CD depth.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-tools-a-shortlist-worth-evaluating</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-tools-a-shortlist-worth-evaluating</guid>
      <pubDate>Wed, 14 Jan 2026 09:00:00 GMT</pubDate>
      <category>AppSec</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[The OWASP Top 10: A Quick Reference for 2026]]></title>
      <description><![CDATA[A working reference to the OWASP Top10 categories, what each one covers in plain terms, and which scanner type actually catches it.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-quick-reference-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-quick-reference-2026</guid>
      <pubDate>Wed, 14 Jan 2026 08:30:00 GMT</pubDate>
      <category>Security Concepts</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Linux Kernel Supply Chain Security: How the World's Largest Project Protects Itself]]></title>
      <description><![CDATA[The Linux kernel is the most critical open source project on earth. Its supply chain security practices offer lessons for every project, but also reveal challenges that scale creates.]]></description>
      <link>https://safeguard.sh/resources/blog/linux-kernel-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/linux-kernel-supply-chain-security</guid>
      <pubDate>Wed, 14 Jan 2026 08:23:39 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SSRF Exploitation in Cloud Environments]]></title>
      <description><![CDATA[Server-Side Request Forgery is especially dangerous in cloud environments where metadata services expose credentials and configuration. This guide covers SSRF exploitation techniques and defenses specific to AWS, GCP, and Azure.]]></description>
      <link>https://safeguard.sh/resources/blog/ssrf-exploitation-cloud-environments</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ssrf-exploitation-cloud-environments</guid>
      <pubDate>Wed, 14 Jan 2026 07:03:12 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[CurveBall Windows CryptoAPI spoofing flaw (CVE-2020-0601)]]></title>
      <description><![CDATA[CVE-2020-0601 (CurveBall) let attackers spoof trusted certificates via a Windows CryptoAPI flaw. Impact, timeline, and remediation steps inside.]]></description>
      <link>https://safeguard.sh/resources/blog/curveball-windows-cryptoapi-spoofing-flaw-cve-2020-0601</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/curveball-windows-cryptoapi-spoofing-flaw-cve-2020-0601</guid>
      <pubDate>Wed, 14 Jan 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Enforcing container compliance with Azure Policy]]></title>
      <description><![CDATA[How Azure Policy enforces container compliance on AKS—registry restriction, regulatory mapping, and where admission-time policy alone falls short.]]></description>
      <link>https://safeguard.sh/resources/blog/enforcing-container-compliance-with-azure-policy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enforcing-container-compliance-with-azure-policy</guid>
      <pubDate>Wed, 14 Jan 2026 06:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The State of Software Supply Chain Attacks: Mid-2022 Report]]></title>
      <description><![CDATA[By mid-2022, supply chain attacks had surged 742% over the previous three years. Here's the data, the trends, and what defenders need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-attacks-state-of-2022</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-attacks-state-of-2022</guid>
      <pubDate>Wed, 14 Jan 2026 05:42:46 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[SLSA vs SSDF vs S2C2F: Framework Comparison]]></title>
      <description><![CDATA[Three supply chain integrity frameworks. Three different authors. Three different audiences. A practical comparison of SLSA, NIST SSDF, and Microsoft S2C2F for teams picking one.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-integrity-framework-comparison-2022</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-integrity-framework-comparison-2022</guid>
      <pubDate>Wed, 14 Jan 2026 04:22:19 GMT</pubDate>
      <category>Regulatory Compliance</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Log4j JDBC Appender RCE (CVE-2021-44832)]]></title>
      <description><![CDATA[CVE-2021-44832 lets attackers with logging-config write access achieve RCE via Log4j2's JDBC Appender — and Log4Shell fixes alone don't stop it.]]></description>
      <link>https://safeguard.sh/resources/blog/log4j-jdbc-appender-rce-cve-2021-44832</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4j-jdbc-appender-rce-cve-2021-44832</guid>
      <pubDate>Wed, 14 Jan 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Build Artifact Integrity Verification: From Source to Deployment]]></title>
      <description><![CDATA[If you cannot verify that your deployed artifact matches your reviewed source code, your entire code review process is security theater. Here is how to close that gap.]]></description>
      <link>https://safeguard.sh/resources/blog/build-artifact-integrity-verification</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/build-artifact-integrity-verification</guid>
      <pubDate>Wed, 14 Jan 2026 03:01:52 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Using Privileged Identity Management for just-in-time Azu...]]></title>
      <description><![CDATA[A practical guide to using Azure conditional access PIM for just-in-time role activation, reducing standing privileges and strengthening least-privilege access.]]></description>
      <link>https://safeguard.sh/resources/blog/using-privileged-identity-management-for-just-in-time-azure-role-activation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/using-privileged-identity-management-for-just-in-time-azure-role-activation</guid>
      <pubDate>Wed, 14 Jan 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[LastPass Breach: How a Compromised Developer Environment Exposed Millions]]></title>
      <description><![CDATA[LastPass disclosed that an attacker accessed their development environment for four days. The full impact wouldn't be known for months.]]></description>
      <link>https://safeguard.sh/resources/blog/lastpass-security-breach-developer-environment</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lastpass-security-breach-developer-environment</guid>
      <pubDate>Wed, 14 Jan 2026 01:41:26 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Text4Shell Apache Commons Text RCE (CVE-2022-42889)]]></title>
      <description><![CDATA[A deep dive into CVE-2022-42889 (Text4Shell): the Apache Commons Text RCE, its narrower real-world exploitability versus Log4Shell, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/text4shell-apache-commons-text-rce-cve-2022-42889</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/text4shell-apache-commons-text-rce-cve-2022-42889</guid>
      <pubDate>Wed, 14 Jan 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Plex Data Breach: 20 Million Users Forced to Reset Passwords]]></title>
      <description><![CDATA[A breach of Plex's systems exposed usernames, emails, and hashed passwords for approximately 20 million users, forcing the streaming platform to trigger a mass password reset.]]></description>
      <link>https://safeguard.sh/resources/blog/plex-data-breach-august-2022</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/plex-data-breach-august-2022</guid>
      <pubDate>Wed, 14 Jan 2026 00:20:59 GMT</pubDate>
      <category>Data Breach</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Preventing and detecting Azure service principal credenti...]]></title>
      <description><![CDATA[How Azure service principal secrets leak through repos, pipelines, and IaC state files — and the detection, scoping, and rotation practices that stop a leak from becoming a breach.]]></description>
      <link>https://safeguard.sh/resources/blog/preventing-and-detecting-azure-service-principal-credential-leaks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/preventing-and-detecting-azure-service-principal-credential-leaks</guid>
      <pubDate>Wed, 14 Jan 2026 00:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[tj-actions/changed-files Compromise: What Happened]]></title>
      <description><![CDATA[A March 2025 GitHub Action compromise rewrote every tagged version to leak secrets. Here is the timeline, attack chain, and what repos need to change.]]></description>
      <link>https://safeguard.sh/resources/blog/tj-actions-changed-files-compromise-march-2025</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tj-actions-changed-files-compromise-march-2025</guid>
      <pubDate>Wed, 14 Jan 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[GitLab Critical RCE (CVE-2022-2884): Remote Code Execution via GitHub Import]]></title>
      <description><![CDATA[A critical vulnerability in GitLab's GitHub import feature allowed authenticated attackers to execute arbitrary code on the server. The flaw highlighted risks in platform migration features.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-critical-vulnerability-cve-2022-2884</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-critical-vulnerability-cve-2022-2884</guid>
      <pubDate>Tue, 13 Jan 2026 23:00:32 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Setting Up Dependency Scanning on GitHub]]></title>
      <description><![CDATA[A hands-on walkthrough for configuring automated dependency scanning in your GitHub repositories, from Dependabot alerts to custom CI workflows.]]></description>
      <link>https://safeguard.sh/resources/blog/setting-up-dependency-scanning-github</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/setting-up-dependency-scanning-github</guid>
      <pubDate>Tue, 13 Jan 2026 21:40:06 GMT</pubDate>
      <category>How-To Guide</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Infrastructure as Code Security: Scanning Terraform, CloudFormation, and Kubernetes Manifests]]></title>
      <description><![CDATA[IaC scanning catches misconfigurations before they reach production. This guide covers tools, techniques, and integration patterns for Terraform, CloudFormation, and Kubernetes.]]></description>
      <link>https://safeguard.sh/resources/blog/infrastructure-as-code-security-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/infrastructure-as-code-security-scanning</guid>
      <pubDate>Tue, 13 Jan 2026 20:19:39 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Building a Security Team from Scratch]]></title>
      <description><![CDATA[A practical guide to hiring your first security engineers, defining roles, and building a security function that scales with your organization.]]></description>
      <link>https://safeguard.sh/resources/blog/building-security-team-from-scratch</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/building-security-team-from-scratch</guid>
      <pubDate>Tue, 13 Jan 2026 18:59:12 GMT</pubDate>
      <category>Organizational Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Malicious GitHub Commits: The Overlooked Supply Chain Attack Vector]]></title>
      <description><![CDATA[Attackers can impersonate any committer on GitHub, inject malicious code through PRs, and exploit lax review processes. Here's the risk.]]></description>
      <link>https://safeguard.sh/resources/blog/malicious-github-commits-supply-chain-risk</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/malicious-github-commits-supply-chain-risk</guid>
      <pubDate>Tue, 13 Jan 2026 17:38:45 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Software Supply Chain Security in Banking: A Practical Guide]]></title>
      <description><![CDATA[Banks face unique software supply chain risks. This guide covers real threats, regulatory expectations, and what security teams should actually be doing.]]></description>
      <link>https://safeguard.sh/resources/blog/software-supply-chain-security-banking</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-supply-chain-security-banking</guid>
      <pubDate>Tue, 13 Jan 2026 16:18:19 GMT</pubDate>
      <category>Industry Guides</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Supply Chain Security for Government Agencies]]></title>
      <description><![CDATA[Government agencies face unique software supply chain threats. Here's how federal and state organizations can protect critical infrastructure from compromise.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-security-for-government-agencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-security-for-government-agencies</guid>
      <pubDate>Tue, 13 Jan 2026 14:57:52 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Security Bounty Programs: Do They Actually Work?]]></title>
      <description><![CDATA[Bug bounty programs for open source projects promise market-driven vulnerability discovery. The reality is more complicated, with perverse incentives, quality problems, and funding gaps.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-security-bounty-programs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-security-bounty-programs</guid>
      <pubDate>Tue, 13 Jan 2026 13:37:25 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Securing GitHub Actions: Hardening Your CI/CD Supply Chain]]></title>
      <description><![CDATA[GitHub Actions is a powerful CI/CD platform — and a significant attack surface. Here's how to lock it down against supply chain threats.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-github-actions-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-github-actions-supply-chain</guid>
      <pubDate>Tue, 13 Jan 2026 12:16:59 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Eval Methodology: Griffin AI vs Mythos]]></title>
      <description><![CDATA[A benchmark number is only as good as the methodology that produced it. Here is how Griffin AI builds its harness and why most Mythos-class tools cannot be audited.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-eval-methodology</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-eval-methodology</guid>
      <pubDate>Tue, 13 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[SQL Injection Chains: Griffin AI vs Mythos]]></title>
      <description><![CDATA[SQL injection stopped being a single-line bug years ago. Modern chains stitch a tainted parameter through ORMs, caches, background jobs, and downstream services. Griffin AI's engine-plus-LLM architecture follows the taint across those hops; Mythos-class pure-LLM scanners summarise one file at a time and lose the thread.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-sql-injection-chains</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-sql-injection-chains</guid>
      <pubDate>Tue, 13 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Security Metrics That Matter: A CISO Guide]]></title>
      <description><![CDATA[Stop reporting vanity metrics. Here are the security measurements that actually inform decisions, demonstrate program effectiveness, and earn board-level credibility.]]></description>
      <link>https://safeguard.sh/resources/blog/security-metrics-that-matter-ciso-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-metrics-that-matter-ciso-guide</guid>
      <pubDate>Tue, 13 Jan 2026 10:56:32 GMT</pubDate>
      <category>Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Trojan Source Unicode bidi-override attack (CVE-2021-42574)]]></title>
      <description><![CDATA[CVE-2021-42574 (Trojan Source) lets Unicode bidi control characters hide malicious logic in plain sight during code review. Here's the full breakdown and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/trojan-source-unicode-bidi-override-attack-cve-2021-42574</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trojan-source-unicode-bidi-override-attack-cve-2021-42574</guid>
      <pubDate>Tue, 13 Jan 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[eBPF for Security Monitoring: What It Can and Cannot Do]]></title>
      <description><![CDATA[eBPF is being called the future of security observability. It is genuinely powerful, but it is not a magic bullet for runtime security.]]></description>
      <link>https://safeguard.sh/resources/blog/ebpf-security-monitoring-applications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ebpf-security-monitoring-applications</guid>
      <pubDate>Tue, 13 Jan 2026 09:36:05 GMT</pubDate>
      <category>Runtime Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Best Free Security Tools for Bootstrapped Startups in 2026]]></title>
      <description><![CDATA[A zero-budget security stack that actually covers the top risks: SCA, secrets scanning, SAST, container scanning, and DAST — plus what each free tool won't do.]]></description>
      <link>https://safeguard.sh/resources/blog/best-free-security-tools-bootstrapped-startups-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-free-security-tools-bootstrapped-startups-2026</guid>
      <pubDate>Tue, 13 Jan 2026 09:30:00 GMT</pubDate>
      <category>Tools</category>
      <author>hi@safeguard.sh (Safeguard Team)</author>
    </item>
    <item>
      <title><![CDATA[K8s Admission Controllers for Supply Chain Policy]]></title>
      <description><![CDATA[How to design Kubernetes admission controllers that enforce supply chain policy without turning every deploy into a 30-minute argument with the cluster.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-admission-controller-supply-chain-policy</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-admission-controller-supply-chain-policy</guid>
      <pubDate>Tue, 13 Jan 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Security best practices for Azure Container Apps and secr...]]></title>
      <description><![CDATA[A step-by-step guide to Azure Container Apps security best practices: managed identity, Key Vault-backed secrets, network ingress, and supply chain hardening.]]></description>
      <link>https://safeguard.sh/resources/blog/security-best-practices-for-azure-container-apps-and-secrets-handling</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-best-practices-for-azure-container-apps-and-secrets-handling</guid>
      <pubDate>Tue, 13 Jan 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Trivy for SBOM Generation and Vulnerability Scanning]]></title>
      <description><![CDATA[Trivy combines SBOM generation with vulnerability scanning in a single tool. Here's how to use both capabilities effectively.]]></description>
      <link>https://safeguard.sh/resources/blog/trivy-sbom-generation-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/trivy-sbom-generation-scanning</guid>
      <pubDate>Tue, 13 Jan 2026 08:15:39 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSL punycode buffer overflow pair (CVE-2022-3602 / CVE-2022-3786)]]></title>
      <description><![CDATA[A deep dive into CVE-2022-3602 and CVE-2022-3786, the OpenSSL punycode buffer overflow pair once dubbed "Heartbleed 2.0" — impact, timeline, and fixes.]]></description>
      <link>https://safeguard.sh/resources/blog/openssl-punycode-buffer-overflow-pair-cve-2022-3602-cve-2022-3786</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssl-punycode-buffer-overflow-pair-cve-2022-3602-cve-2022-3786</guid>
      <pubDate>Tue, 13 Jan 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Safeguard Research Team)</author>
    </item>
    <item>
      <title><![CDATA[Docker Image Layer Security Analysis: What Lurks Beneath Your Containers]]></title>
      <description><![CDATA[Every Docker image is a stack of layers, and each one can introduce vulnerabilities. Learn how to dissect image layers for security risks and what tools actually help.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-image-layer-security-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-image-layer-security-analysis</guid>
      <pubDate>Tue, 13 Jan 2026 06:55:12 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Zimbra CVE-2022-37042: Authentication Bypass in a Widely Used Email Platform]]></title>
      <description><![CDATA[CVE-2022-37042 allowed unauthenticated attackers to upload web shells to Zimbra email servers. Over 1,000 servers were compromised before most admins knew about it.]]></description>
      <link>https://safeguard.sh/resources/blog/zimbra-cve-2022-37042-authentication-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zimbra-cve-2022-37042-authentication-bypass</guid>
      <pubDate>Tue, 13 Jan 2026 05:34:45 GMT</pubDate>
      <category>Zero-Day Exploits</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[pip Install Hooks Security Risks: Code Execution During Package Installation]]></title>
      <description><![CDATA[Running pip install can execute arbitrary code on your machine before you ever import the package. Here is how install hooks create risk.]]></description>
      <link>https://safeguard.sh/resources/blog/pip-install-hooks-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pip-install-hooks-security-risks</guid>
      <pubDate>Tue, 13 Jan 2026 04:14:19 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Outlook NTLM hash leak zero-day (CVE-2023-23397)]]></title>
      <description><![CDATA[A zero-click Outlook flaw let attackers steal NTLM hashes via crafted calendar reminders — exploited by APT28 for a year before patching. Here's what to do.]]></description>
      <link>https://safeguard.sh/resources/blog/outlook-ntlm-hash-leak-zero-day-cve-2023-23397</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/outlook-ntlm-hash-leak-zero-day-cve-2023-23397</guid>
      <pubDate>Tue, 13 Jan 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Docker Security Best Practices for Developers]]></title>
      <description><![CDATA[Practical Docker security from image building to runtime, covering multi-stage builds, user namespaces, and image scanning.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-security-best-practices-developers</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-security-best-practices-developers</guid>
      <pubDate>Tue, 13 Jan 2026 02:53:52 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[0ktapus: The Phishing Campaign That Hit Cloudflare, Twilio, and 130+ Organizations]]></title>
      <description><![CDATA[A single phishing campaign compromised over 130 companies including Cloudflare and Twilio. Here's how the 0ktapus attack chain worked.]]></description>
      <link>https://safeguard.sh/resources/blog/cloudflare-twilio-0ktapus-phishing-campaign</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cloudflare-twilio-0ktapus-phishing-campaign</guid>
      <pubDate>Tue, 13 Jan 2026 01:33:25 GMT</pubDate>
      <category>Incident Response</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[MOVEit Transfer SQL injection mass-exploitation (CVE-2023-34362)]]></title>
      <description><![CDATA[CVE-2023-34362, the MOVEit Transfer SQL injection exploited by Cl0p, hit 2,600+ organizations. Impact, timeline, and remediation steps inside.]]></description>
      <link>https://safeguard.sh/resources/blog/moveit-transfer-sql-injection-mass-exploitation-cve-2023-34362</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/moveit-transfer-sql-injection-mass-exploitation-cve-2023-34362</guid>
      <pubDate>Tue, 13 Jan 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Startup Security at Seed Stage: What to Prioritize When Resources Are Scarce]]></title>
      <description><![CDATA[You have five engineers, zero security staff, and a product to ship. Here is the minimum viable security program that protects your startup without killing your velocity.]]></description>
      <link>https://safeguard.sh/resources/blog/startup-security-seed-stage-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/startup-security-seed-stage-guide</guid>
      <pubDate>Tue, 13 Jan 2026 00:12:58 GMT</pubDate>
      <category>Startup Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Apache OFBiz CVE-2024-38856 Pre-Auth RCE Analysis]]></title>
      <description><![CDATA[CVE-2024-38856 is an unauthenticated RCE in Apache OFBiz that bypasses authentication via screen rendering. Exploit chain, detection, and patching.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-38856-apache-ofbiz-pre-auth-rce</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-38856-apache-ofbiz-pre-auth-rce</guid>
      <pubDate>Tue, 13 Jan 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Hardening Google Kubernetes Engine clusters against attacks]]></title>
      <description><![CDATA[A step-by-step guide to GKE security best practices: private clusters, Workload Identity, Shielded Nodes, Binary Authorization, and verification checks for real audits.]]></description>
      <link>https://safeguard.sh/resources/blog/hardening-google-kubernetes-engine-clusters-against-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hardening-google-kubernetes-engine-clusters-against-attacks</guid>
      <pubDate>Tue, 13 Jan 2026 00:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[NoSQL Injection and MongoDB: Prevention Guide]]></title>
      <description><![CDATA[NoSQL injection attacks exploit the query languages of non-relational databases to bypass authentication, extract data, and modify records. This guide focuses on MongoDB injection with defenses applicable to all NoSQL databases.]]></description>
      <link>https://safeguard.sh/resources/blog/nosql-injection-mongodb-prevention</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nosql-injection-mongodb-prevention</guid>
      <pubDate>Mon, 12 Jan 2026 22:52:32 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Mutation Testing for Security Validation: Testing Your Tests]]></title>
      <description><![CDATA[Mutation testing measures whether your security tests actually catch bugs by introducing small changes to code and checking if tests fail. Here is how to apply it to security-critical code.]]></description>
      <link>https://safeguard.sh/resources/blog/mutation-testing-security-validation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mutation-testing-security-validation</guid>
      <pubDate>Mon, 12 Jan 2026 21:32:05 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Reproducible Builds: The Gold Standard for Supply Chain Integrity]]></title>
      <description><![CDATA[If you can't rebuild a binary from source and get the same result, you can't verify that the binary matches the source. Reproducible builds close this fundamental trust gap.]]></description>
      <link>https://safeguard.sh/resources/blog/reproducible-builds-supply-chain-integrity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/reproducible-builds-supply-chain-integrity</guid>
      <pubDate>Mon, 12 Jan 2026 20:11:38 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Zero Trust Architecture for the Software Supply Chain]]></title>
      <description><![CDATA[Zero trust isn't just for networks. Applying zero trust principles to your software supply chain fundamentally changes how you manage dependency risk.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-trust-architecture-software-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-trust-architecture-software-supply-chain</guid>
      <pubDate>Mon, 12 Jan 2026 18:51:12 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[AWS Inspector V2 Container Scanning: What Changed and Why It Matters]]></title>
      <description><![CDATA[A deep look at Amazon Inspector v2 for container scanning, its improvements over v1, and how to get the most out of it.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-inspector-v2-container-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-inspector-v2-container-scanning</guid>
      <pubDate>Mon, 12 Jan 2026 17:30:45 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Microservices Security Architecture: A Supply Chain Perspective]]></title>
      <description><![CDATA[Microservices multiply your dependency surface. This guide covers service mesh security, inter-service authentication, and dependency management across distributed architectures.]]></description>
      <link>https://safeguard.sh/resources/blog/microservices-security-architecture-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/microservices-security-architecture-guide</guid>
      <pubDate>Mon, 12 Jan 2026 16:10:18 GMT</pubDate>
      <category>Architecture</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Twitter Data Breach: 5.4 Million Accounts Exposed Through an API Vulnerability]]></title>
      <description><![CDATA[An API vulnerability in Twitter allowed attackers to link phone numbers and email addresses to Twitter accounts, ultimately exposing data from 5.4 million users — and possibly over 200 million email-account pairs.]]></description>
      <link>https://safeguard.sh/resources/blog/twitter-54-million-data-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/twitter-54-million-data-breach</guid>
      <pubDate>Mon, 12 Jan 2026 14:49:52 GMT</pubDate>
      <category>Data Breach</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Clippy Rust Security Lints: Catching What the Borrow Checker Misses]]></title>
      <description><![CDATA[Rust's compiler catches memory safety bugs. Clippy catches everything else -- including security anti-patterns the borrow checker does not care about.]]></description>
      <link>https://safeguard.sh/resources/blog/clippy-rust-security-lints</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/clippy-rust-security-lints</guid>
      <pubDate>Mon, 12 Jan 2026 13:29:25 GMT</pubDate>
      <category>Secure Development</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Brazil's LGPD and Its Implications for Software Security]]></title>
      <description><![CDATA[Brazil's data protection law creates obligations for software security and supply chain transparency. Here's what developers and vendors should know.]]></description>
      <link>https://safeguard.sh/resources/blog/brazil-lgpd-software-security-implications</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/brazil-lgpd-software-security-implications</guid>
      <pubDate>Mon, 12 Jan 2026 12:08:58 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Hypothesis Quality: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Two AI bug hunters can both generate hypotheses. Only one can defend them. A field study of grounded versus ungrounded hypothesis generation in zero-day discovery.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-hypothesis-quality</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-hypothesis-quality</guid>
      <pubDate>Mon, 12 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Zero-Knowledge Proofs for Supply Chain Attestation]]></title>
      <description><![CDATA[Where zk-SNARKs, STARKs, and Bulletproofs actually fit in software supply chain attestation, and where conventional signatures remain the correct choice.]]></description>
      <link>https://safeguard.sh/resources/blog/zero-knowledge-proofs-supply-chain-attestation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/zero-knowledge-proofs-supply-chain-attestation</guid>
      <pubDate>Mon, 12 Jan 2026 12:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[VEX Explained: How Vulnerability Exploitability Exchange Cuts Through Alert Noise]]></title>
      <description><![CDATA[VEX documents let software producers tell consumers which vulnerabilities actually affect their products. Here's how VEX works and why it matters.]]></description>
      <link>https://safeguard.sh/resources/blog/vex-vulnerability-exploitability-exchange-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/vex-vulnerability-exploitability-exchange-guide</guid>
      <pubDate>Mon, 12 Jan 2026 10:48:32 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Vulnerability Scanning for AI Models: A New Frontier]]></title>
      <description><![CDATA[AI models ship with dependencies, use vulnerable libraries, and introduce novel attack surfaces. Traditional scanning is not enough.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-model-vulnerability-scanning</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-model-vulnerability-scanning</guid>
      <pubDate>Mon, 12 Jan 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Q4 2025 Release Recap]]></title>
      <description><![CDATA[A full recap of Q4 2025 at Safeguard: Griffin for Java and .NET, Eagle attestations, Lion serverless, Gold policy-aware remediation, and more.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-changelog-q4-2025-recap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-changelog-q4-2025-recap</guid>
      <pubDate>Mon, 12 Jan 2026 10:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Securing Claude Code MCP Server Deployments]]></title>
      <description><![CDATA[Claude Code MCP servers run with the privileges of the developer who invoked them. That makes deployment posture the entire security model.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-claude-code-mcp-server-deployments</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-claude-code-mcp-server-deployments</guid>
      <pubDate>Mon, 12 Jan 2026 10:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[systeminformation npm package command injection (CVE-2021-21315)]]></title>
      <description><![CDATA[A critical command injection flaw in the systeminformation npm package (CVE-2021-21315) let attackers run OS commands via unsanitized shell calls. Here's the full breakdown.]]></description>
      <link>https://safeguard.sh/resources/blog/systeminformation-npm-package-command-injection-cve-2021-21315</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/systeminformation-npm-package-command-injection-cve-2021-21315</guid>
      <pubDate>Mon, 12 Jan 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[XML Parsing Security: XXE, Billion Laughs, and Beyond]]></title>
      <description><![CDATA[XML's feature richness is its security weakness. XXE, entity expansion, and XSLT injection continue to plague applications that process XML.]]></description>
      <link>https://safeguard.sh/resources/blog/xml-parsing-security-xxe-billion-laughs</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/xml-parsing-security-xxe-billion-laughs</guid>
      <pubDate>Mon, 12 Jan 2026 10:00:00 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Atlassian Questions for Confluence CVE-2022-26138: A Hardcoded Password That Gave Away the Keys]]></title>
      <description><![CDATA[CVE-2022-26138 exposed a hardcoded password in the Questions for Confluence app, granting unauthenticated access to Confluence data. A preventable disaster.]]></description>
      <link>https://safeguard.sh/resources/blog/atlassian-questions-for-confluence-cve-2022-26138</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/atlassian-questions-for-confluence-cve-2022-26138</guid>
      <pubDate>Mon, 12 Jan 2026 09:28:05 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Explores Partnership With Tech-D Cybersecurity]]></title>
      <description><![CDATA[Safeguard is in early-stage discussions with Tech-D Cybersecurity Ltd to explore co-selling, joint delivery, and shared services opportunities.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-exploring-partnership-tech-d-cybersecurity</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-exploring-partnership-tech-d-cybersecurity</guid>
      <pubDate>Mon, 12 Jan 2026 09:00:00 GMT</pubDate>
      <category>Company</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Using GCP Workload Identity Federation for keyless CI/CD ...]]></title>
      <description><![CDATA[GCP Workload Identity Federation lets CI/CD pipelines authenticate with short-lived tokens instead of service account keys. Here's how it works and how to migrate.]]></description>
      <link>https://safeguard.sh/resources/blog/using-gcp-workload-identity-federation-for-keyless-cicd-authentication</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/using-gcp-workload-identity-federation-for-keyless-cicd-authentication</guid>
      <pubDate>Mon, 12 Jan 2026 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The Open Source Software Bill of Rights]]></title>
      <description><![CDATA[As governments and enterprises demand more from open source maintainers, the community pushes back with a framework of rights. The tension between accountability and sustainability is shaping the future of open source.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-software-bill-of-rights</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-software-bill-of-rights</guid>
      <pubDate>Mon, 12 Jan 2026 08:07:38 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[lodash prototype pollution via zipObjectDeep (CVE-2020-8203)]]></title>
      <description><![CDATA[CVE-2020-8203 lets attackers pollute Object.prototype via lodash's zipObjectDeep. Learn affected versions, CVSS/EPSS context, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/lodash-prototype-pollution-via-zipobjectdeep-cve-2020-8203</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lodash-prototype-pollution-via-zipobjectdeep-cve-2020-8203</guid>
      <pubDate>Mon, 12 Jan 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Bug Bounty Programs with a Supply Chain Focus]]></title>
      <description><![CDATA[Traditional bug bounty programs miss supply chain vulnerabilities. Here's how to design a bounty program that incentivizes researchers to hunt in your dependency chain.]]></description>
      <link>https://safeguard.sh/resources/blog/bug-bounty-programs-supply-chain-focus</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/bug-bounty-programs-supply-chain-focus</guid>
      <pubDate>Mon, 12 Jan 2026 06:47:11 GMT</pubDate>
      <category>Offensive Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Automating secret rotation in Google Cloud Secret Manager]]></title>
      <description><![CDATA[A practical guide to automating GCP Secret Manager rotation—covering versioning, Cloud Functions, Cloud Scheduler, and rotating database credentials safely.]]></description>
      <link>https://safeguard.sh/resources/blog/automating-secret-rotation-in-google-cloud-secret-manager</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/automating-secret-rotation-in-google-cloud-secret-manager</guid>
      <pubDate>Mon, 12 Jan 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[NIST CSF Updates Put Supply Chain Risk Management Front and Center]]></title>
      <description><![CDATA[NIST's 2022 updates to the Cybersecurity Framework signal a major shift: supply chain risk management is no longer optional — it's a core pillar.]]></description>
      <link>https://safeguard.sh/resources/blog/nist-csf-update-supply-chain-risk-management</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nist-csf-update-supply-chain-risk-management</guid>
      <pubDate>Mon, 12 Jan 2026 05:26:45 GMT</pubDate>
      <category>Compliance & Regulations</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[GitHub Actions Security Best Practices in 2022]]></title>
      <description><![CDATA[A practical guide to hardening your GitHub Actions workflows against supply chain attacks, secret leaks, and privilege escalation.]]></description>
      <link>https://safeguard.sh/resources/blog/github-actions-security-best-practices-2022</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-actions-security-best-practices-2022</guid>
      <pubDate>Mon, 12 Jan 2026 04:06:18 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[lodash defaultsDeep prototype pollution (CVE-2019-10744)]]></title>
      <description><![CDATA[A critical prototype pollution flaw in lodash's defaultsDeep (CVE-2019-10744) lets attackers corrupt Object.prototype. Here's the impact and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/lodash-defaultsdeep-prototype-pollution-cve-2019-10744</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lodash-defaultsdeep-prototype-pollution-cve-2019-10744</guid>
      <pubDate>Mon, 12 Jan 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Applying least-privilege principles to GCP IAM roles]]></title>
      <description><![CDATA[Predefined roles, custom roles, IAM Recommender, and service account hygiene: a practical guide to applying GCP IAM least privilege without breaking production.]]></description>
      <link>https://safeguard.sh/resources/blog/applying-least-privilege-principles-to-gcp-iam-roles</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/applying-least-privilege-principles-to-gcp-iam-roles</guid>
      <pubDate>Mon, 12 Jan 2026 03:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Azure AD Token Theft Campaigns: A 2022 Retrospective]]></title>
      <description><![CDATA[Token theft is the quiet successor to credential phishing, and 2022 turned it into an industry. Here is what the year's Azure AD campaigns actually looked like.]]></description>
      <link>https://safeguard.sh/resources/blog/azure-ad-token-theft-retrospective-2022</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/azure-ad-token-theft-retrospective-2022</guid>
      <pubDate>Mon, 12 Jan 2026 02:45:51 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Notary v2 Content Trust: A Practical Implementation Guide]]></title>
      <description><![CDATA[Docker Content Trust never gained traction. Notary v2, now called Notation, is the replacement. Here is how to implement it and what has changed.]]></description>
      <link>https://safeguard.sh/resources/blog/notary-v2-content-trust-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/notary-v2-content-trust-guide</guid>
      <pubDate>Mon, 12 Jan 2026 01:25:25 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[lodash template code injection (CVE-2021-23337)]]></title>
      <description><![CDATA[CVE-2021-23337 lets attackers inject code via lodash's template function. Here's the impact, affected versions, CVSS/EPSS context, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/lodash-template-code-injection-cve-2021-23337</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/lodash-template-code-injection-cve-2021-23337</guid>
      <pubDate>Mon, 12 Jan 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[NGINX Security Configuration Guide for Production Deployments]]></title>
      <description><![CDATA[NGINX powers a third of the internet. Its default configuration is optimized for getting started, not for production security. Here is the gap.]]></description>
      <link>https://safeguard.sh/resources/blog/nginx-security-configuration-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/nginx-security-configuration-guide</guid>
      <pubDate>Mon, 12 Jan 2026 00:04:58 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Enforcing signed and attested container images with Binar...]]></title>
      <description><![CDATA[A step-by-step guide to enforcing signed, attested container images in GKE with Binary Authorization — from attestor setup to policy enforcement and troubleshooting.]]></description>
      <link>https://safeguard.sh/resources/blog/enforcing-signed-and-attested-container-images-with-binary-authorization</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enforcing-signed-and-attested-container-images-with-binary-authorization</guid>
      <pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[JavaScript Dependency Security: The Complete Guide]]></title>
      <description><![CDATA[A thorough walkthrough of securing your JavaScript dependency tree, from lockfile hygiene to automated auditing and runtime protections.]]></description>
      <link>https://safeguard.sh/resources/blog/javascript-dependency-security-complete-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/javascript-dependency-security-complete-guide</guid>
      <pubDate>Sun, 11 Jan 2026 22:44:31 GMT</pubDate>
      <category>Dependency Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[BlackCat/ALPHV Ransomware: Rust-Based Innovation and Supply Chain Exploitation]]></title>
      <description><![CDATA[BlackCat (ALPHV) brought Rust programming, triple extortion, and supply chain targeting to the ransomware-as-a-service model, raising the bar for both attackers and defenders.]]></description>
      <link>https://safeguard.sh/resources/blog/blackcat-alphv-ransomware-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/blackcat-alphv-ransomware-supply-chain</guid>
      <pubDate>Sun, 11 Jan 2026 21:24:05 GMT</pubDate>
      <category>Ransomware</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Protocol Buffer Security Considerations Beyond Serialization]]></title>
      <description><![CDATA[Protobuf is everywhere in modern infrastructure. Its security implications go beyond just serialization format choice. Here is what to watch.]]></description>
      <link>https://safeguard.sh/resources/blog/protocol-buffer-security-considerations</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/protocol-buffer-security-considerations</guid>
      <pubDate>Sun, 11 Jan 2026 20:03:38 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Memory Safety Bugs in C/C++ Dependencies: The Hidden Risk in Your Software Supply Chain]]></title>
      <description><![CDATA[C and C++ libraries still power critical infrastructure everywhere. Their memory safety issues are your problem whether you write C or not.]]></description>
      <link>https://safeguard.sh/resources/blog/memory-safety-bugs-c-cpp-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/memory-safety-bugs-c-cpp-dependencies</guid>
      <pubDate>Sun, 11 Jan 2026 18:43:11 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SAST vs DAST vs IAST: Which Application Security Testing Approach Fits Your Pipeline?]]></title>
      <description><![CDATA[A practical comparison of SAST, DAST, and IAST — when to use each, where they overlap, and why most teams need more than one.]]></description>
      <link>https://safeguard.sh/resources/blog/sast-vs-dast-vs-iast-comparison</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sast-vs-dast-vs-iast-comparison</guid>
      <pubDate>Sun, 11 Jan 2026 17:22:45 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[CDN Supply Chain Security Risks You Should Know]]></title>
      <description><![CDATA[Content delivery networks serve billions of software assets daily. When a CDN is compromised, the blast radius is enormous. Here's what CDN supply chain risks look like and how to defend against them.]]></description>
      <link>https://safeguard.sh/resources/blog/cdn-supply-chain-security-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cdn-supply-chain-security-risks</guid>
      <pubDate>Sun, 11 Jan 2026 16:02:18 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[WebAssembly Security: A Deep Dive into the Sandbox Model]]></title>
      <description><![CDATA[WebAssembly promises near-native performance with a strong security sandbox. But the sandbox model has nuances that developers and security teams must understand to avoid dangerous assumptions.]]></description>
      <link>https://safeguard.sh/resources/blog/webassembly-security-sandbox-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/webassembly-security-sandbox-analysis</guid>
      <pubDate>Sun, 11 Jan 2026 14:41:51 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Retbleed: The Spectre Variant That Haunts Modern CPUs (CVE-2022-29900)]]></title>
      <description><![CDATA[Retbleed exploits return instructions to bypass Spectre mitigations on AMD and Intel processors. Here's what it means for your infrastructure.]]></description>
      <link>https://safeguard.sh/resources/blog/retbleed-spectre-variant-cve-2022-29900-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/retbleed-spectre-variant-cve-2022-29900-analysis</guid>
      <pubDate>Sun, 11 Jan 2026 13:21:24 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[npm Lockfile Injection Attacks: How Tampered package-lock.json Files Compromise Builds]]></title>
      <description><![CDATA[Lockfile injection is a subtle supply chain attack where malicious changes to package-lock.json redirect dependency resolution to attacker-controlled packages. Here is how it works and how to detect it.]]></description>
      <link>https://safeguard.sh/resources/blog/npm-lockfile-injection-attacks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/npm-lockfile-injection-attacks</guid>
      <pubDate>Sun, 11 Jan 2026 12:00:58 GMT</pubDate>
      <category>Software Supply Chain Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Air-Gapped Environments: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Air-gapped AI is not a feature flag. It is an architectural commitment, and it separates serious enterprise products from consumer-grade assistants.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-air-gapped-environments</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-air-gapped-environments</guid>
      <pubDate>Sun, 11 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Per-Scan Token Cost: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Tiered models and a deterministic engine cut token consumption to the moments that need reasoning. Pure-LLM tools pay full price for every trivial check.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-per-scan-token-cost</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-per-scan-token-cost</guid>
      <pubDate>Sun, 11 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs xAI Grok for Security]]></title>
      <description><![CDATA[]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-xai-grok-for-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-xai-grok-for-security</guid>
      <pubDate>Sun, 11 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[How to Create Your First SBOM]]></title>
      <description><![CDATA[A practical, step-by-step guide to generating your first Software Bill of Materials using open-source tools and integrating it into your development workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/how-to-create-your-first-sbom</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-to-create-your-first-sbom</guid>
      <pubDate>Sun, 11 Jan 2026 10:40:31 GMT</pubDate>
      <category>How-To Guide</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Alibaba fastjson deserialization RCE (CVE-2022-25845)]]></title>
      <description><![CDATA[A critical AutoType-bypass RCE in Alibaba fastjson (CVSS 9.8, EPSS ~99th pct) hits any app parsing untrusted JSON. Here's how to detect and fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/alibaba-fastjson-deserialization-rce-cve-2022-25845</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/alibaba-fastjson-deserialization-rce-cve-2022-25845</guid>
      <pubDate>Sun, 11 Jan 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Dark Web Monitoring for Supply Chain Threats]]></title>
      <description><![CDATA[Software supply chain credentials, stolen signing keys, and zero-day exploits for build tools are traded on dark web forums. Monitoring these channels provides early warning of supply chain attacks.]]></description>
      <link>https://safeguard.sh/resources/blog/dark-web-monitoring-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dark-web-monitoring-supply-chain</guid>
      <pubDate>Sun, 11 Jan 2026 09:20:04 GMT</pubDate>
      <category>Threat Intelligence</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Managing and securing GCP service account keys]]></title>
      <description><![CDATA[A practical, step-by-step guide to GCP service account key security: disable key creation, adopt impersonation, rotate remaining keys, and monitor for misuse.]]></description>
      <link>https://safeguard.sh/resources/blog/managing-and-securing-gcp-service-account-keys</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/managing-and-securing-gcp-service-account-keys</guid>
      <pubDate>Sun, 11 Jan 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Docker Scout for Container Security Analysis: A Practical Guide]]></title>
      <description><![CDATA[Docker Scout brings vulnerability scanning directly into the Docker CLI. Here is what it actually catches, where it falls short, and how to integrate it into your workflow.]]></description>
      <link>https://safeguard.sh/resources/blog/docker-scout-container-analysis-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/docker-scout-container-analysis-guide</guid>
      <pubDate>Sun, 11 Jan 2026 07:59:38 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Struts2 REST plugin XStream deserialization RCE (CVE-2017-9805)]]></title>
      <description><![CDATA[CVE-2017-9805 lets attackers RCE Struts2 REST APIs via unsafe XStream XML deserialization. Learn impact, affected versions, and remediation steps.]]></description>
      <link>https://safeguard.sh/resources/blog/struts2-rest-plugin-xstream-deserialization-rce-cve-2017-9805</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/struts2-rest-plugin-xstream-deserialization-rce-cve-2017-9805</guid>
      <pubDate>Sun, 11 Jan 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Governance: Building an Enterprise Framework]]></title>
      <description><![CDATA[Ad-hoc open source usage creates legal, security, and operational risk. This guide walks through building a governance framework that enables developers while managing risk.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-governance-enterprise-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-governance-enterprise-framework</guid>
      <pubDate>Sun, 11 Jan 2026 06:39:11 GMT</pubDate>
      <category>Governance</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[What Software Delivery Shield does for end-to-end supply ...]]></title>
      <description><![CDATA[A breakdown of what Google Cloud's Software Delivery Shield actually does — SLSA provenance, SBOM generation, Binary Authorization — and where its coverage gaps still leave supply chains exposed.]]></description>
      <link>https://safeguard.sh/resources/blog/what-software-delivery-shield-does-for-end-to-end-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/what-software-delivery-shield-does-for-end-to-end-supply-chain-security</guid>
      <pubDate>Sun, 11 Jan 2026 06:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[India's CERT-In Cybersecurity Directives: Six-Hour Reporting and Beyond]]></title>
      <description><![CDATA[India's CERT-In directives mandate six-hour incident reporting and strict logging requirements. Here's what organizations operating in India need to know.]]></description>
      <link>https://safeguard.sh/resources/blog/india-cert-in-cyber-security-directives</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/india-cert-in-cyber-security-directives</guid>
      <pubDate>Sun, 11 Jan 2026 05:18:44 GMT</pubDate>
      <category>Compliance</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Apache Commons Collections deserialization gadget RCE (CVE-2015-7501)]]></title>
      <description><![CDATA[A decade-old Apache Commons Collections deserialization gadget chain still enables unauthenticated RCE across legacy Java middleware. Here's how to find and fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/apache-commons-collections-deserialization-gadget-rce-cve-2015-7501</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/apache-commons-collections-deserialization-gadget-rce-cve-2015-7501</guid>
      <pubDate>Sun, 11 Jan 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Dependency Update Strategies for Large Codebases]]></title>
      <description><![CDATA[At scale, keeping dependencies current is not a weekend chore — it is an engineering discipline. The wrong update strategy creates either a mountain of tech debt or a pipeline permanently broken by cascading upgrades.]]></description>
      <link>https://safeguard.sh/resources/blog/dependency-update-strategies-for-large-codebases</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dependency-update-strategies-for-large-codebases</guid>
      <pubDate>Sun, 11 Jan 2026 03:58:18 GMT</pubDate>
      <category>Software Supply Chain</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Generating SBOMs and provenance with GCP Artifact Analysis]]></title>
      <description><![CDATA[A step-by-step guide to GCP SBOM generation using Artifact Analysis: scan container images, export SPDX/CycloneDX SBOMs, and attach SLSA provenance attestations.]]></description>
      <link>https://safeguard.sh/resources/blog/generating-sboms-and-provenance-with-gcp-artifact-analysis</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/generating-sboms-and-provenance-with-gcp-artifact-analysis</guid>
      <pubDate>Sun, 11 Jan 2026 03:00:00 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[The GitHub Codespaces Security Model, Examined]]></title>
      <description><![CDATA[GitHub Codespaces has gone GA and is about to become the dev environment standard. Here is a close read of its security model — including what it does not solve.]]></description>
      <link>https://safeguard.sh/resources/blog/github-codespaces-security-model-2022</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/github-codespaces-security-model-2022</guid>
      <pubDate>Sun, 11 Jan 2026 02:37:51 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Terraform Security Scanning: What to Scan, When, and How]]></title>
      <description><![CDATA[A practical guide to integrating security scanning into your Terraform workflow without destroying developer productivity.]]></description>
      <link>https://safeguard.sh/resources/blog/terraform-security-scanning-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/terraform-security-scanning-best-practices</guid>
      <pubDate>Sun, 11 Jan 2026 01:17:24 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[GitLab ExifTool RCE (CVE-2021-22205)]]></title>
      <description><![CDATA[CVE-2021-22205 let attackers RCE self-managed GitLab via a malicious ExifTool-parsed upload — no auth required. Here's the timeline and fix.]]></description>
      <link>https://safeguard.sh/resources/blog/gitlab-exiftool-rce-cve-2021-22205</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/gitlab-exiftool-rce-cve-2021-22205</guid>
      <pubDate>Sun, 11 Jan 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Best practices for managing encryption keys with Google C...]]></title>
      <description><![CDATA[A step-by-step guide to Cloud KMS best practices: key hierarchy, IAM scoping, envelope encryption, automated rotation, HSM protection levels, and audit logging.]]></description>
      <link>https://safeguard.sh/resources/blog/best-practices-for-managing-encryption-keys-with-google-cloud-kms</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/best-practices-for-managing-encryption-keys-with-google-cloud-kms</guid>
      <pubDate>Sun, 11 Jan 2026 00:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Secrets Management: Preventing Credential Leaks in Your Software Supply Chain]]></title>
      <description><![CDATA[Hardcoded credentials remain the most common source of breaches. Despite a decade of tooling improvements, secrets keep leaking through source code, container images, CI logs, and dependency configurations. Here is how to actually fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/secrets-management-preventing-credential-leaks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secrets-management-preventing-credential-leaks</guid>
      <pubDate>Sat, 10 Jan 2026 23:56:57 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Managing End-of-Life Software Dependencies]]></title>
      <description><![CDATA[Every dependency eventually reaches end of life. Here is a practical framework for identifying, tracking, and migrating away from EOL software before it becomes a security liability.]]></description>
      <link>https://safeguard.sh/resources/blog/managing-eol-software-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/managing-eol-software-dependencies</guid>
      <pubDate>Sat, 10 Jan 2026 22:36:31 GMT</pubDate>
      <category>Dependency Management</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Ruby Gems Supply Chain Security]]></title>
      <description><![CDATA[Protecting your Ruby applications from gem-based supply chain attacks with Bundler security features, gem signing, and auditing.]]></description>
      <link>https://safeguard.sh/resources/blog/ruby-gems-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ruby-gems-supply-chain-security</guid>
      <pubDate>Sat, 10 Jan 2026 21:16:04 GMT</pubDate>
      <category>Dependency Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[ESLint Security Rules Configuration: A Practical Guide]]></title>
      <description><![CDATA[ESLint can catch security issues before they reach production. Here is how to configure security-focused rules that actually help without drowning you in noise.]]></description>
      <link>https://safeguard.sh/resources/blog/eslint-security-rules-configuration</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/eslint-security-rules-configuration</guid>
      <pubDate>Sat, 10 Jan 2026 19:55:37 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Environment Variable Injection in CI/CD: The Invisible Attack Surface]]></title>
      <description><![CDATA[CI/CD pipelines trust environment variables implicitly. Injecting or modifying them can hijack builds, steal secrets, and compromise deployments.]]></description>
      <link>https://safeguard.sh/resources/blog/environment-variable-injection-cicd</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/environment-variable-injection-cicd</guid>
      <pubDate>Sat, 10 Jan 2026 18:35:11 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Securing Terraform Infrastructure as Code: A Practitioner's Guide]]></title>
      <description><![CDATA[Your Terraform code defines your production infrastructure. If an attacker compromises your HCL files, state files, or provider plugins, they do not just get access — they get the keys to rebuild your entire environment on their terms.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-terraform-infrastructure-as-code</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-terraform-infrastructure-as-code</guid>
      <pubDate>Sat, 10 Jan 2026 17:14:44 GMT</pubDate>
      <category>Infrastructure Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Building a Supply Chain Risk Appetite Framework]]></title>
      <description><![CDATA[Every organization accepts some supply chain risk. The question is whether that acceptance is deliberate and documented or accidental and invisible.]]></description>
      <link>https://safeguard.sh/resources/blog/supply-chain-risk-appetite-framework</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/supply-chain-risk-appetite-framework</guid>
      <pubDate>Sat, 10 Jan 2026 15:54:17 GMT</pubDate>
      <category>Risk Management</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Flux CD GitOps Security Practices]]></title>
      <description><![CDATA[Hardening Flux CD deployments with multi-tenancy, RBAC, secret encryption, and image verification for secure GitOps workflows.]]></description>
      <link>https://safeguard.sh/resources/blog/flux-cd-gitops-security-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/flux-cd-gitops-security-practices</guid>
      <pubDate>Sat, 10 Jan 2026 14:33:51 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Shifting Left Without Slowing Down]]></title>
      <description><![CDATA[How to integrate security earlier in the development lifecycle without turning your CI pipeline into a bottleneck that developers hate.]]></description>
      <link>https://safeguard.sh/resources/blog/shifting-left-without-slowing-down</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shifting-left-without-slowing-down</guid>
      <pubDate>Sat, 10 Jan 2026 13:13:24 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Enterprise AI Security Rollout: The Governance Gap]]></title>
      <description><![CDATA[Most enterprises rolled out AI-for-security tools faster than their governance processes could keep up. The resulting gap is where most of the pain from 2025 deployments lives.]]></description>
      <link>https://safeguard.sh/resources/blog/enterprise-ai-security-rollout-governance-gap</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/enterprise-ai-security-rollout-governance-gap</guid>
      <pubDate>Sat, 10 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Llama 3 for Security Workflows]]></title>
      <description><![CDATA[Llama 3 is a powerful open-weight foundation model, but security workflows demand more than raw inference. Here is how Griffin AI compares.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-llama-3-for-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-llama-3-for-security</guid>
      <pubDate>Sat, 10 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Remediation PR Quality: Griffin AI vs Mythos]]></title>
      <description><![CDATA[Griffin AI produces draft PRs with taint paths, exploit hypotheses, and disproof attempts. Mythos-class pure-LLM tools skip those anchors, and PR quality suffers.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-remediation-pr-quality</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-remediation-pr-quality</guid>
      <pubDate>Sat, 10 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[CPE Naming Convention and the Vulnerability Matching Problem]]></title>
      <description><![CDATA[CPE is the backbone of NVD vulnerability matching, and it is deeply flawed. Understanding its limitations is essential for accurate vulnerability management.]]></description>
      <link>https://safeguard.sh/resources/blog/cpe-naming-convention-vulnerability-matching</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cpe-naming-convention-vulnerability-matching</guid>
      <pubDate>Sat, 10 Jan 2026 11:52:57 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[The OWASP Top 10 (2021) Through a Supply Chain Security Lens]]></title>
      <description><![CDATA[The 2021 OWASP Top 10 added supply chain risks for the first time. Here is what each category means when your code is mostly someone else's code.]]></description>
      <link>https://safeguard.sh/resources/blog/owasp-top-10-2021-supply-chain-perspective</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/owasp-top-10-2021-supply-chain-perspective</guid>
      <pubDate>Sat, 10 Jan 2026 10:32:31 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[OpenSSL BN_mod_sqrt infinite loop DoS (CVE-2022-0778)]]></title>
      <description><![CDATA[CVE-2022-0778 lets attackers hang OpenSSL with a single malformed certificate. Here's the impact, affected versions, and how to remediate fast.]]></description>
      <link>https://safeguard.sh/resources/blog/openssl-bnmodsqrt-infinite-loop-dos-cve-2022-0778</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/openssl-bnmodsqrt-infinite-loop-dos-cve-2022-0778</guid>
      <pubDate>Sat, 10 Jan 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The State of SBOM Adoption in 2026: Progress, Gaps, and Reality]]></title>
      <description><![CDATA[SBOM adoption has grown rapidly, but maturity varies wildly. Here's where the industry actually stands heading into 2026.]]></description>
      <link>https://safeguard.sh/resources/blog/state-of-sbom-adoption-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/state-of-sbom-adoption-2026</guid>
      <pubDate>Sat, 10 Jan 2026 10:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[The Log4Shell Response Playbook Six Months In]]></title>
      <description><![CDATA[Six months after CVE-2021-44228 broke the internet, here is what worked, what didn't, and the response patterns security teams should keep as muscle memory.]]></description>
      <link>https://safeguard.sh/resources/blog/log4shell-response-playbook-six-months-in</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4shell-response-playbook-six-months-in</guid>
      <pubDate>Sat, 10 Jan 2026 09:12:04 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Safeguard Griffin 3.0 GA: What's New]]></title>
      <description><![CDATA[Griffin 3.0 is now generally available. Here is what changed in the reasoning and remediation model, how it behaves in practice, and the defaults you should know.]]></description>
      <link>https://safeguard.sh/resources/blog/safeguard-griffin-3-0-ga-release-announcement</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/safeguard-griffin-3-0-ga-release-announcement</guid>
      <pubDate>Sat, 10 Jan 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Using GCP organization policy constraints to enforce secu...]]></title>
      <description><![CDATA[GCP organization policy security constraints turn security intent into enforceable guardrails across your resource hierarchy, closing gaps IAM alone cannot.]]></description>
      <link>https://safeguard.sh/resources/blog/using-gcp-organization-policy-constraints-to-enforce-security-guardrails</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/using-gcp-organization-policy-constraints-to-enforce-security-guardrails</guid>
      <pubDate>Sat, 10 Jan 2026 09:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Mobile App Store Security Bypass: How Malicious Apps Evade Review]]></title>
      <description><![CDATA[App store review processes catch most malware. But the bypass techniques that work reveal systematic gaps in mobile supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/mobile-app-store-security-bypass</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/mobile-app-store-security-bypass</guid>
      <pubDate>Sat, 10 Jan 2026 07:51:37 GMT</pubDate>
      <category>Mobile Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Dirty COW Linux kernel privilege escalation (CVE-2016-5195)]]></title>
      <description><![CDATA[Dirty COW (CVE-2016-5195) let local attackers hijack a kernel race condition for root. Nine years old, still found in fleets — here's how to find and fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/dirty-cow-linux-kernel-privilege-escalation-cve-2016-5195</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dirty-cow-linux-kernel-privilege-escalation-cve-2016-5195</guid>
      <pubDate>Sat, 10 Jan 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Linux Distribution Package Signing: How It Actually Works]]></title>
      <description><![CDATA[Package signing is the backbone of Linux software distribution security. Most teams trust it blindly without understanding the verification chain they depend on.]]></description>
      <link>https://safeguard.sh/resources/blog/linux-distribution-package-signing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/linux-distribution-package-signing</guid>
      <pubDate>Sat, 10 Jan 2026 06:31:10 GMT</pubDate>
      <category>Supply Chain Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[How Container Threat Detection identifies runtime attacks...]]></title>
      <description><![CDATA[How Container Threat Detection GCP watches GKE kernels for reverse shells, added binaries, and privilege escalation—and why runtime signals catch what image scanning can't.]]></description>
      <link>https://safeguard.sh/resources/blog/how-container-threat-detection-identifies-runtime-attacks-in-gke</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/how-container-threat-detection-identifies-runtime-attacks-in-gke</guid>
      <pubDate>Sat, 10 Jan 2026 06:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Electron App Supply Chain Security: Desktop Apps Built on Web Dependencies]]></title>
      <description><![CDATA[Electron apps ship a full Chromium browser and Node.js runtime to the desktop. That means every web supply chain risk becomes a desktop attack surface — with elevated privileges.]]></description>
      <link>https://safeguard.sh/resources/blog/electron-app-supply-chain-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/electron-app-supply-chain-security</guid>
      <pubDate>Sat, 10 Jan 2026 05:10:44 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Dirty Pipe Linux kernel arbitrary write (CVE-2022-0847)]]></title>
      <description><![CDATA[Dirty Pipe (CVE-2022-0847) lets local attackers overwrite read-only files via a pipe buffer flaw, enabling fast, reliable root escalation on Linux and Android.]]></description>
      <link>https://safeguard.sh/resources/blog/dirty-pipe-linux-kernel-arbitrary-write-cve-2022-0847</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/dirty-pipe-linux-kernel-arbitrary-write-cve-2022-0847</guid>
      <pubDate>Sat, 10 Jan 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Follina (CVE-2022-30190): The Microsoft Zero-Day That Bypassed Macro Protections]]></title>
      <description><![CDATA[A Word document, no macros enabled, and full remote code execution. Follina exploited the Microsoft Support Diagnostic Tool via ms-msdt protocol handlers, rendering years of macro-blocking defenses irrelevant.]]></description>
      <link>https://safeguard.sh/resources/blog/follina-cve-2022-30190-microsoft-zero-day</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/follina-cve-2022-30190-microsoft-zero-day</guid>
      <pubDate>Sat, 10 Jan 2026 03:50:17 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Securing Cloud Build pipelines and generating SLSA proven...]]></title>
      <description><![CDATA[How to secure Cloud Build supply chain security with least-privilege service accounts and SLSA provenance so tampered builds never reach production.]]></description>
      <link>https://safeguard.sh/resources/blog/securing-cloud-build-pipelines-and-generating-slsa-provenance</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/securing-cloud-build-pipelines-and-generating-slsa-provenance</guid>
      <pubDate>Sat, 10 Jan 2026 03:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Container Runtime Security Monitoring: Catching What Scanners Miss]]></title>
      <description><![CDATA[Image scanning finds known vulnerabilities before deployment. Runtime monitoring catches actual exploitation, zero-days, and behavioral anomalies after deployment. You need both.]]></description>
      <link>https://safeguard.sh/resources/blog/container-runtime-security-monitoring</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/container-runtime-security-monitoring</guid>
      <pubDate>Sat, 10 Jan 2026 02:29:50 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[TLS Configuration Security Audit: What to Check and How]]></title>
      <description><![CDATA[A misconfigured TLS setup can be worse than no encryption at all because it creates false confidence. Here is how to audit your TLS configuration properly.]]></description>
      <link>https://safeguard.sh/resources/blog/tls-configuration-security-audit</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/tls-configuration-security-audit</guid>
      <pubDate>Sat, 10 Jan 2026 01:09:24 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Using VPC Service Controls to prevent secret exfiltration...]]></title>
      <description><![CDATA[VPC Service Controls create a hard perimeter around Secret Manager, blocking exfiltration even when credentials are compromised or IAM is misconfigured.]]></description>
      <link>https://safeguard.sh/resources/blog/using-vpc-service-controls-to-prevent-secret-exfiltration-in-gcp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/using-vpc-service-controls-to-prevent-secret-exfiltration-in-gcp</guid>
      <pubDate>Sat, 10 Jan 2026 00:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[AWS Supply Chain Security Best Practices You Should Adopt Today]]></title>
      <description><![CDATA[A practical guide to securing your software supply chain on AWS, from ECR image provenance to CodePipeline hardening.]]></description>
      <link>https://safeguard.sh/resources/blog/aws-supply-chain-security-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/aws-supply-chain-security-best-practices</guid>
      <pubDate>Fri, 09 Jan 2026 23:48:57 GMT</pubDate>
      <category>Cloud Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes Supply Chain Policy Engines: Enforcing What Gets Deployed]]></title>
      <description><![CDATA[Scanning for vulnerabilities means nothing if you cannot enforce the results. Supply chain policy engines in Kubernetes turn security findings into hard deployment gates.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-supply-chain-policy-engine</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-supply-chain-policy-engine</guid>
      <pubDate>Fri, 09 Jan 2026 22:28:30 GMT</pubDate>
      <category>Kubernetes Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Software-Defined Perimeters for Supply Chain Security]]></title>
      <description><![CDATA[Software-Defined Perimeters can isolate build systems, artifact repositories, and deployment pipelines from unauthorized access. Here is how SDP applies to supply chain security.]]></description>
      <link>https://safeguard.sh/resources/blog/software-defined-perimeter-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-defined-perimeter-supply-chain</guid>
      <pubDate>Fri, 09 Jan 2026 21:08:04 GMT</pubDate>
      <category>Network Security</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Security Headers Implementation Checklist: Hardening Your Web Application]]></title>
      <description><![CDATA[HTTP security headers are your first line of defense against XSS, clickjacking, and data injection attacks. Here is a practical implementation checklist with correct configurations.]]></description>
      <link>https://safeguard.sh/resources/blog/security-headers-implementation-checklist</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/security-headers-implementation-checklist</guid>
      <pubDate>Fri, 09 Jan 2026 19:47:37 GMT</pubDate>
      <category>Web Security</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[SBOM 101: A Complete Beginner's Guide to Software Bill of Materials]]></title>
      <description><![CDATA[Everything you need to know about Software Bills of Materials -- what they are, why they matter, and how to start generating them for your projects.]]></description>
      <link>https://safeguard.sh/resources/blog/sbom-101-complete-beginners-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/sbom-101-complete-beginners-guide</guid>
      <pubDate>Fri, 09 Jan 2026 18:27:10 GMT</pubDate>
      <category>SBOM</category>
      <author>hi@safeguard.sh (Yukti Singhal)</author>
    </item>
    <item>
      <title><![CDATA[Hardware Supply Chain Trust Boundaries]]></title>
      <description><![CDATA[Hardware travels through dozens of hands before reaching your data center. Understanding and enforcing trust boundaries across the hardware supply chain is essential for building secure systems.]]></description>
      <link>https://safeguard.sh/resources/blog/hardware-supply-chain-trust-boundaries</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/hardware-supply-chain-trust-boundaries</guid>
      <pubDate>Fri, 09 Jan 2026 17:06:44 GMT</pubDate>
      <category>Hardware Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Confluence Zero-Day (CVE-2022-26134): Atlassian's OGNL Injection Crisis]]></title>
      <description><![CDATA[An unauthenticated RCE zero-day in Confluence Server was being actively exploited before Atlassian even knew about it. The vulnerability affected virtually every on-premise Confluence installation.]]></description>
      <link>https://safeguard.sh/resources/blog/confluence-cve-2022-26134-atlassian-zero-day</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/confluence-cve-2022-26134-atlassian-zero-day</guid>
      <pubDate>Fri, 09 Jan 2026 15:46:17 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (James)</author>
    </item>
    <item>
      <title><![CDATA[Software Provenance Tracking: From Source to Production]]></title>
      <description><![CDATA[Software provenance answers the question: where did this code come from, who built it, and can I trust it? In 2022, provenance tracking moved from academic concept to practical necessity.]]></description>
      <link>https://safeguard.sh/resources/blog/software-provenance-tracking-best-practices</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/software-provenance-tracking-best-practices</guid>
      <pubDate>Fri, 09 Jan 2026 14:25:50 GMT</pubDate>
      <category>DevSecOps</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Evaluating Open Source Alternatives Through a Security Lens]]></title>
      <description><![CDATA[When choosing between open source packages that provide the same functionality, security factors should weigh as heavily as features. Here is a practical evaluation framework.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-alternative-evaluation-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-alternative-evaluation-security</guid>
      <pubDate>Fri, 09 Jan 2026 13:05:23 GMT</pubDate>
      <category>Dependency Management</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[CyberSecEval Reviewed: What It Measures]]></title>
      <description><![CDATA[A working engineer's review of CyberSecEval, the Meta-originated benchmark that has quietly become the default sniff test for AI-for-security claims. What it actually measures, what it misses, and how to read its scores without fooling yourself.]]></description>
      <link>https://safeguard.sh/resources/blog/ai-security-benchmark-cybersecevval-review</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ai-security-benchmark-cybersecevval-review</guid>
      <pubDate>Fri, 09 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SSDF Attestation: Griffin AI vs Mythos]]></title>
      <description><![CDATA[The NIST SSDF attestation form asks structured questions with structured answers. A chat transcript is not an answer. We explain how Griffin AI produces the evidence auditors expect, and why Mythos-class tools struggle.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-ssdf-attestation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-mythos-ssdf-attestation</guid>
      <pubDate>Fri, 09 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Griffin AI vs Raw Claude for Security Workflow]]></title>
      <description><![CDATA[Griffin AI runs on Anthropic's Claude models under the hood. Here's what the engine context, eval harness, and workflow scaffolding actually buy you over calling Claude directly.]]></description>
      <link>https://safeguard.sh/resources/blog/griffin-ai-vs-raw-claude-security-workflow</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/griffin-ai-vs-raw-claude-security-workflow</guid>
      <pubDate>Fri, 09 Jan 2026 12:00:00 GMT</pubDate>
      <category>AI Security</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Synnovis NHS Qilin Ransomware: Pathology Supply Chain Lessons]]></title>
      <description><![CDATA[Eighteen months after Qilin encrypted Synnovis, the pathology provider finally finished notifying NHS trusts. We unpack how a single supplier paralysed London hospitals and how defenders can prepare.]]></description>
      <link>https://safeguard.sh/resources/blog/synnovis-nhs-qilin-ransomware-pathology-supply-chain</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/synnovis-nhs-qilin-ransomware-pathology-supply-chain</guid>
      <pubDate>Fri, 09 Jan 2026 12:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Shield Health Group Data Breach: 2 Million Patient Records Exposed]]></title>
      <description><![CDATA[A breach at Shield Health Group, a Massachusetts medical imaging provider, exposed personal and medical data of approximately 2 million patients — highlighting the healthcare sector's persistent vulnerability.]]></description>
      <link>https://safeguard.sh/resources/blog/shield-health-group-data-breach</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/shield-health-group-data-breach</guid>
      <pubDate>Fri, 09 Jan 2026 11:44:57 GMT</pubDate>
      <category>Healthcare Security</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[Log4Shell Five Years Later: What CVE-2021-44228 Taught Us About Transitive Risk]]></title>
      <description><![CDATA[Five years after Log4Shell, the technical details still matter, but the lasting lessons are about transitive dependencies, SBOM accuracy, and the long tail of unpatched internal tooling.]]></description>
      <link>https://safeguard.sh/resources/blog/log4shell-cve-2021-44228-five-years-later-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/log4shell-cve-2021-44228-five-years-later-2026</guid>
      <pubDate>Fri, 09 Jan 2026 11:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[SolarWinds Sunburst: Five Years of Lessons in 2026]]></title>
      <description><![CDATA[Half a decade after Sunburst, the build system compromise still defines how we think about software supply chain risk. A look at what stuck and what did not.]]></description>
      <link>https://safeguard.sh/resources/blog/solarwinds-sunburst-five-years-of-lessons-2026</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/solarwinds-sunburst-five-years-of-lessons-2026</guid>
      <pubDate>Fri, 09 Jan 2026 11:00:00 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Broken Access Control: The Number One Web Vulnerability and How to Fix It]]></title>
      <description><![CDATA[Access control moved to the top of the OWASP Top 10 in 2021. Here is why it is so hard to get right and what a solid authorization architecture looks like.]]></description>
      <link>https://safeguard.sh/resources/blog/broken-access-control-prevention-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/broken-access-control-prevention-guide</guid>
      <pubDate>Fri, 09 Jan 2026 10:24:30 GMT</pubDate>
      <category>Application Security</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Kubernetes API server privilege escalation via aggregated API (CVE-2018-1002105)]]></title>
      <description><![CDATA[A critical flaw in Kubernetes' aggregated API let unauthenticated users gain full admin privileges. Here's how it worked and how to fix it.]]></description>
      <link>https://safeguard.sh/resources/blog/kubernetes-api-server-privilege-escalation-via-aggregated-api-cve-2018-1002105</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/kubernetes-api-server-privilege-escalation-via-aggregated-api-cve-2018-1002105</guid>
      <pubDate>Fri, 09 Jan 2026 10:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[General Motors Credential Stuffing Attack: Loyalty Points Theft at Scale]]></title>
      <description><![CDATA[Attackers used credential stuffing to compromise GM customer accounts, stealing reward points and personal data — a reminder that password reuse remains one of the most exploitable habits in cybersecurity.]]></description>
      <link>https://safeguard.sh/resources/blog/general-motors-credential-stuffing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/general-motors-credential-stuffing</guid>
      <pubDate>Fri, 09 Jan 2026 09:04:03 GMT</pubDate>
      <category>Credential Attacks</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Comparing security models of GKE Autopilot versus Standar...]]></title>
      <description><![CDATA[GKE Autopilot security vs Standard clusters draw the shared-responsibility line very differently. Here's what changes for pod security and hardening.]]></description>
      <link>https://safeguard.sh/resources/blog/comparing-security-models-of-gke-autopilot-versus-standard-clusters</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/comparing-security-models-of-gke-autopilot-versus-standard-clusters</guid>
      <pubDate>Fri, 09 Jan 2026 09:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Red Hat JBoss Vulnerability Exploitation: The Persistent Threat of Java Middleware]]></title>
      <description><![CDATA[JBoss application servers have been a recurring target for attackers. From deserialization flaws to exposed management interfaces, the middleware layer remains a critical attack surface.]]></description>
      <link>https://safeguard.sh/resources/blog/red-hat-jboss-vulnerability-exploitation</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/red-hat-jboss-vulnerability-exploitation</guid>
      <pubDate>Fri, 09 Jan 2026 07:43:37 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Bob)</author>
    </item>
    <item>
      <title><![CDATA[runc container escape via file descriptor overwrite (CVE-2019-5736)]]></title>
      <description><![CDATA[CVE-2019-5736 let malicious containers overwrite the host runc binary and gain root — here's the mechanism, affected versions, and how to remediate it.]]></description>
      <link>https://safeguard.sh/resources/blog/runc-container-escape-via-file-descriptor-overwrite-cve-2019-5736</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/runc-container-escape-via-file-descriptor-overwrite-cve-2019-5736</guid>
      <pubDate>Fri, 09 Jan 2026 07:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Open Source Funding Models and Their Impact on Security]]></title>
      <description><![CDATA[The way open source projects get funded directly shapes their security outcomes. From corporate sponsorship to bounty programs, each model creates different incentives and blind spots.]]></description>
      <link>https://safeguard.sh/resources/blog/open-source-funding-models-security</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/open-source-funding-models-security</guid>
      <pubDate>Fri, 09 Jan 2026 06:23:10 GMT</pubDate>
      <category>Open Source Security</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Implementing keyless container image signing with Cosign ...]]></title>
      <description><![CDATA[A hands-on guide to Cosign keyless signing GCP setups with Sigstore, Workload Identity Federation, and Cloud Build — sign and verify images with no key management.]]></description>
      <link>https://safeguard.sh/resources/blog/implementing-keyless-container-image-signing-with-cosign-and-sigstore-on-gcp</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/implementing-keyless-container-image-signing-with-cosign-and-sigstore-on-gcp</guid>
      <pubDate>Fri, 09 Jan 2026 06:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[PyPI Supply Chain Attacks: The ctx Package Compromise]]></title>
      <description><![CDATA[The ctx package on PyPI was hijacked to steal environment variables from developer machines. The attack exploited an expired domain to take over a maintainer account — a novel and repeatable technique.]]></description>
      <link>https://safeguard.sh/resources/blog/pypi-supply-chain-attacks-ctx-package</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/pypi-supply-chain-attacks-ctx-package</guid>
      <pubDate>Fri, 09 Jan 2026 05:02:43 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Linux cgroups release_agent container escape (CVE-2022-0492)]]></title>
      <description><![CDATA[CVE-2022-0492 lets containers with CAP_SYS_ADMIN escape via cgroup v1's release_agent. Impact, timeline, and concrete remediation steps inside.]]></description>
      <link>https://safeguard.sh/resources/blog/linux-cgroups-releaseagent-container-escape-cve-2022-0492</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/linux-cgroups-releaseagent-container-escape-cve-2022-0492</guid>
      <pubDate>Fri, 09 Jan 2026 04:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Secure Coding Practices: A Developer's Guide]]></title>
      <description><![CDATA[Practical secure coding habits every developer should build, covering input validation, authentication, dependency management, and more.]]></description>
      <link>https://safeguard.sh/resources/blog/secure-coding-practices-developers-guide</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/secure-coding-practices-developers-guide</guid>
      <pubDate>Fri, 09 Jan 2026 03:42:17 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Alex)</author>
    </item>
    <item>
      <title><![CDATA[Managing secrets securely with OCI Vault]]></title>
      <description><![CDATA[A step-by-step guide to OCI Vault secrets management: provisioning, rotation, IAM policies, pipeline integration, and best practices for securing credentials.]]></description>
      <link>https://safeguard.sh/resources/blog/managing-secrets-securely-with-oci-vault</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/managing-secrets-securely-with-oci-vault</guid>
      <pubDate>Fri, 09 Jan 2026 03:00:00 GMT</pubDate>
      <category>Industry Analysis</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Image Parsing Vulnerabilities in Dependencies: The Pixel-Level Threat]]></title>
      <description><![CDATA[Every application that processes images depends on parsing libraries with a long history of memory corruption bugs. Here is what is at stake.]]></description>
      <link>https://safeguard.sh/resources/blog/image-parsing-vulnerabilities-dependencies</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/image-parsing-vulnerabilities-dependencies</guid>
      <pubDate>Fri, 09 Jan 2026 02:21:50 GMT</pubDate>
      <category>Vulnerability Management</category>
      <author>hi@safeguard.sh (Michael)</author>
    </item>
    <item>
      <title><![CDATA[Why Dependency Pinning Alone Is Not Enough]]></title>
      <description><![CDATA[Pinning dependencies feels like a complete answer to supply chain risk. It is not — and the gap between pinning and real integrity matters more in 2022 than ever.]]></description>
      <link>https://safeguard.sh/resources/blog/why-dependency-pinning-alone-is-not-enough</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/why-dependency-pinning-alone-is-not-enough</guid>
      <pubDate>Fri, 09 Jan 2026 01:01:23 GMT</pubDate>
      <category>Best Practices</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[containerd-shim abstract Unix socket container escape (CVE-2020-15257)]]></title>
      <description><![CDATA[CVE-2020-15257 let containers sharing a host network namespace abuse containerd-shim's abstract socket API. Here's the impact, fix, and remediation path.]]></description>
      <link>https://safeguard.sh/resources/blog/containerd-shim-abstract-unix-socket-container-escape-cve-2020-15257</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/containerd-shim-abstract-unix-socket-container-escape-cve-2020-15257</guid>
      <pubDate>Fri, 09 Jan 2026 01:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Vikram Iyer)</author>
    </item>
    <item>
      <title><![CDATA[Windows MSHTML Spoofing CVE-2024-43573 Explained]]></title>
      <description><![CDATA[CVE-2024-43573 is a zero-day MSHTML spoofing flaw patched by Microsoft in October 2024. Here is the chain, detection, and why MSHTML keeps biting.]]></description>
      <link>https://safeguard.sh/resources/blog/cve-2024-43573-windows-mshtml-spoofing</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/cve-2024-43573-windows-mshtml-spoofing</guid>
      <pubDate>Fri, 09 Jan 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Scanning Oracle Cloud Infrastructure Registry images for ...]]></title>
      <description><![CDATA[A step-by-step guide to OCIR vulnerability scanning: enabling OCI's Vulnerability Scanning Service, triggering push-time scans, triaging CVEs, and signing verified images.]]></description>
      <link>https://safeguard.sh/resources/blog/scanning-oracle-cloud-infrastructure-registry-images-for-vulnerabilities</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/scanning-oracle-cloud-infrastructure-registry-images-for-vulnerabilities</guid>
      <pubDate>Fri, 09 Jan 2026 00:00:00 GMT</pubDate>
      <category>Container Security</category>
      <author>hi@safeguard.sh (Karan Patel)</author>
    </item>
    <item>
      <title><![CDATA[Ultralytics PyPI Compromise: Dec 2024 Post-Mortem]]></title>
      <description><![CDATA[How a GitHub Actions cache poisoning attack pushed a crypto miner into Ultralytics 8.3.41 on PyPI, and what engineering teams should actually change.]]></description>
      <link>https://safeguard.sh/resources/blog/ultralytics-pypi-compromise-december-2024</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/ultralytics-pypi-compromise-december-2024</guid>
      <pubDate>Fri, 09 Jan 2026 00:00:00 GMT</pubDate>
      <category>Incident Analysis</category>
      <author>hi@safeguard.sh (Shadab Khan)</author>
    </item>
    <item>
      <title><![CDATA[Maven Central Supply Chain Risks: Securing the Java Ecosystem]]></title>
      <description><![CDATA[Maven Central is the backbone of the Java ecosystem, serving billions of artifact downloads annually. Its unique trust model and dependency resolution create supply chain risks that Java teams must understand.]]></description>
      <link>https://safeguard.sh/resources/blog/maven-central-supply-chain-risks</link>
      <guid isPermaLink="true">https://safeguard.sh/resources/blog/maven-central-supply-chain-risks</guid>
      <pubDate>Thu, 08 Jan 2026 23:40:57 GMT</pubDate>
      <category>Supply Chain Attacks</category>
      <author>hi@safeguard.sh (Nayan Dey)</author>
    </item>
    <item>
      <title><![CDATA[Zyxel Firewall CVE-2022-30525: Unauthenticated Command Injection in Your Perimeter Defense]]></title>
      <description><![CDATA[CVE-2022-30525 gave attackers unauthenticated OS command injection on Zyxel firewalls. The irony of a firewall being the weakest point in your network security.]]></description>
      <link>https://safeguard.sh/resources/blog/zyxel-firewall-cve-2022-30525-rce</link>
      <guid isPermaLink="true">https://safeguard.sh