Security
In-depth guides and analysis on security from the Safeguard engineering team.
100 articles
A LinkedIn Post Questioned Anthropic's Claude OSS Scanner License. Here Is What It Grants
Anthropic's opt-in OSS Scanner, built on its experience using Claude to find vulnerabilities, asks contributors to sign a contributor license agreement. What that agreement grants Anthropic, what it does not say, and ten questions to ask any AI vendor before you send code.
We Signed CISA's Secure by Design Pledge. Here Is Where We Stand on Each Goal
Safeguard now appears on CISA's list of Secure by Design Pledge signers. The pledge asks for measurable progress on seven security goals within a year. Here is what we already ship for each one, and what we have not done yet.
One Mailbox, Six Spellings: The Signup Bug in Almost Every Product
name+tag@, dotted Gmail, googlemail.com, a zero-width space. All reach one inbox, all pass a uniqueness check, and one common fix locks real users out of accounts they are entitled to.
Device Code Phishing Rose 15x. Checking the URL Does Not Help.
Device code phishing sends victims to a genuine Microsoft page to enter a genuine code. There is no fake domain and no credential to steal. Training built on spotting bad URLs has nothing to use.
CVE-2023-5752: Command Injection in pip via Mercurial Revisions
Installing a package from a Mercurial URL with a crafted revision let attackers inject hg config options. Here is how CVE-2023-5752 works and how to fix it.
eslint-plugin-unused-imports: Cleaner Code, Smaller Surface
eslint-plugin-unused-imports auto-removes dead imports that the base ESLint rule only warns about. Here is how to configure it correctly on ESLint 9.
CVE-2023-22102: The MySQL Connector/J Takeover Vulnerability
CVE-2023-22102 is a High-severity flaw in Oracle's MySQL Connector/J that can lead to connector takeover. Here is the root cause and how to remediate it.
Black Duck Competitors: The Top SCA Alternatives Compared
A fair look at the main Black Duck competitors in software composition analysis — Snyk, Mend, Sonatype, Endor Labs, and others — and which fits which job.
Application Data Security: How to Protect Data Across Its Lifecycle
Application data security is the set of controls that protect data as your application collects, processes, stores, and transmits it. Here is a practical model for getting it right.
Hacking Software: What It Is and How Defenders Use It Legally
Hacking software is the category of programs used to test and break into systems. Used with authorization, it is how security teams find their own weaknesses first.
NVD vs CVE: What's the Difference?
CVE is the list of vulnerability identifiers; the NVD is the enriched database built on top of it. They are related but run by different programs, and confusing them leads to real mistakes.
CVE Full Form Explained: What CVE Actually Stands For
The CVE full form is Common Vulnerabilities and Exposures, a public catalog of known security flaws. Here is what the term means, how the IDs work, and why it matters.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.