Safeguard
Topic

Cloud Security

In-depth guides and analysis on cloud security from the Safeguard engineering team.

100 articles

Cloud Security

One Shared Deploy Credential Is Forty Pipelines' Worth of Blast Radius

Set up once, when there was one service. Forty pipelines later, every one of them still uses it, and it can deploy to production, which means it can read the secrets and infrastructure of everything it touches.

Sep 18, 20266 min read
Cloud Security

Your Terraform State Is a Secrets Store With a Build Artefact's Access Control

The database password, the generated private key, the API token an output exposed. You did not put them there directly. Terraform did, because it needs the full attributes of everything it manages to plan the next change.

Sep 18, 20265 min read
Cloud Security

The Kubernetes Token Nobody Asked For

Every pod gets a token that authenticates to the API server, whether the application inside it ever calls the API or not. It sits there anyway, readable by anything that can read a file in the container, because the default is on.

Sep 18, 20265 min read
Cloud Security

Your Free Tier Is Compute You Hand to Strangers

That is the point of it, and it is also a standing offer to everyone who wants compute, a clean network position or storage for a purpose you did not intend. The abuse is rarely sophisticated.

Sep 18, 20265 min read
Cloud Security

Encryption at Rest Protects Against Roughly One Thing

It is on every security page, it is true, and it covers someone taking the physical disk. Every other way your data gets read happens through a path where it is already decrypted, because the encryption is transparent by design.

Sep 18, 20265 min read
Cloud Security

Autoscaling Turned the Attack Into an Invoice

Every request was served, no alerts fired, the dashboards stayed green. The properties that made your infrastructure resilient are what made the attack work, and the only symptom arrives weeks later on a bill.

Sep 18, 20266 min read
Cloud Security

A Presigned URL Is a Capability You Minted Without Thinking About It

Anyone holding the string can do what it permits, with no identity check, until it expires. Every mistake is a variation of one thing: handing out more capability than intended, for longer than intended.

Sep 18, 20265 min read
Cloud Security

Comparing confidential VM offerings across major cloud pr...

A practical comparison of confidential virtual machines across Azure, AWS Nitro Enclaves, GCP confidential compute, and more -- real strengths, real limitations, no marketing gloss.

Aug 2, 20268 min read
Cloud Security

Cloudflare November 18 2025 Outage: A Bot Management Feature File Doubled in Size

A ClickHouse permissions change caused Cloudflare's Bot Management feature file to balloon past a hard-coded proxy limit, taking the core network down for two hours and ten minutes.

Jul 24, 20267 min read
Cloud Security

Best cloud workload protection platforms (CWPP)

An honest, no-hype comparison of leading cloud workload protection platforms — evaluation criteria, real vendor tradeoffs, and where supply chain security fits in.

Jul 19, 20268 min read
Cloud Security

Catching Terraform Misconfigurations Before They Ever Reach Apply

Trivy replaced tfsec in 2023 and Checkov ships thousands of policies — here's how to wire open-source Terraform scanners into CI/CD before terraform apply runs.

Jul 16, 20266 min read
Cloud Security

Insecure defaults in Azure ARM templates: a pre-deployment scanning guide

Azure Resource Manager templates don't enforce TLS 1.2 or block public blob access by default — here's how to catch it before terraform apply's Azure cousin ever runs.

Jul 16, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.