Safeguard
Topic

Security

In-depth guides and analysis on security from the Safeguard engineering team.

521 articles

Security

Apache Struts 2 Vulnerability History: The RCE Flaws You Must Patch

Apache Struts 2 vulnerabilities have caused some of the largest breaches on record. Here is the CVE lineage, why the same flaw keeps recurring, and how to detect it.

Feb 19, 20255 min read
Security

Software Development Life Cycle Security: Building Security Into Every SDLC Phase

Software development life cycle security means every phase carries a security activity, not a scan bolted on at the end. Here is what belongs in each stage of the SDLC.

Feb 19, 20257 min read
Security

What Is IaC in Cyber Security? Risks, Scanning, and Best Practices

Infrastructure as Code turns your cloud setup into version-controlled files, which is powerful and dangerous in equal measure. Here is what IaC means for security teams.

Feb 18, 20256 min read
Security

What Is a Cross-Site Request Forgery Vulnerability?

A cross-site request forgery vulnerability tricks a logged-in user's browser into sending unwanted requests. Here is how it works and how to shut it down.

Feb 18, 20256 min read
Security

What Is Malicious Code in Cyber Security? Types, Detection, and Defense

Malicious code is any software written to harm a system or its users. Here is how the main families work, where they hide in modern supply chains, and how to catch them.

Feb 18, 20257 min read
Security

What Is a Product Security Assessment? A Practical Guide

A product security assessment is a structured evaluation of a product's design, code, dependencies, and deployment for exploitable weakness. Here is how to run one that finds real risk.

Feb 18, 20256 min read
Security

typescript-plugin-css-modules: A Dev Dependency Security Guide

typescript-plugin-css-modules gives you typed CSS Modules imports. Here is what it does, why build-time dev tooling is part of your supply chain, and how to keep it safe.

Feb 18, 20255 min read
Security

Website Vulnerability Assessment: A Practical How-To Guide

A website vulnerability assessment systematically finds and ranks the security weaknesses in a web app. Here is the process, the tools, and the pitfalls.

Feb 14, 20255 min read
Security

Flask-CORS Security: The 2024 CVEs and How to Configure It Safely

Flask-CORS is easy to enable and easy to misconfigure. A look at the 2024 path-matching CVEs and the configuration mistakes that actually open your API.

Feb 14, 20256 min read
Security

Hacking Tools Explained: What Every Defender Should Understand

A hacking tool is only as good or bad as its operator. Here is how defenders should think about the tools attackers use, and how to turn them into a defensive advantage.

Feb 14, 20255 min read
Security

How Secure Code Reviews Catch Bugs Before Attackers Do

Code reviews are one of the cheapest security controls you have, but only if they look for the right things. Here is how to run secure code reviews that actually find vulnerabilities.

Feb 14, 20256 min read
Security

CVE-2022-31630: The PHP GD imageloadfont() Out-of-Bounds Read Explained

CVE-2022-31630 is an out-of-bounds read in PHP's GD extension triggered through imageloadfont(). Here are the affected versions, real impact, and the fix.

Feb 14, 20255 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

Security (Page 40) — Supply Chain Security Blog | Safeguard