Vulnerability Management
In-depth guides and analysis on vulnerability management from the Safeguard engineering team.
135 articles
Supply Chain IoC Catalog
A practical catalog of indicators of compromise for software supply chain attacks, with detection queries and false-positive notes.
Cisco ASA Firepower Zero-Day Trends, 2024 Edition
Six zero-days against ASA and FTD in 2024, two tied to ArcaneDoor. We chart the trend, the CVSS distribution, and the patch-to-exploit gap.
A Framework for Security Patch Prioritization
You cannot patch everything immediately. Here is a risk-based framework for deciding which patches to apply first when your vulnerability backlog exceeds your capacity.
Static Analysis False-Positive Reduction
A technique-by-technique tour of how modern static analyzers cut false positives, from CodeQL's path pruning to Infer's bi-abduction.
NuGet Package Vulnerabilities Dashboard
Listing every CVE in your NuGet dependency tree is easy. Turning it into a dashboard someone can act on is the work. A practical design.
Dependabot Noise Reduction Techniques For 2026
Dependabot is useful when tuned and a productivity tax when not. Here are the noise reduction techniques that actually work in modern monorepos.
Fuzzing Open Source for Supply Chain Findings
How modern coverage-guided fuzzing finds real vulnerabilities in open-source dependencies, and how to fold it into a supply-chain security program.
Mean Time to Remediation Benchmarks: How Fast Should You Be Patching?
MTTR is the most important vulnerability management metric. But what is a good MTTR? Industry benchmarks, realistic targets, and strategies for improvement.
bundler-audit Production Setup
A practical guide to running bundler-audit in production CI pipelines, including advisory database updates, exception handling, and integration with remediation workflows.
SLO-Driven Vulnerability Management Program
Service-level objectives turn vulnerability management from heroics into a measurable program. Here is how to define SLOs that survive contact with reality.
Symbolic Execution for Dependency Analysis
Symbolic execution explores program paths without concrete inputs. For supply-chain work, it answers reachability questions that fuzzing cannot.
False Positive Rates in Container Scanning: Why Your Scanner Lies to You
Container scanners produce mountains of findings. A significant percentage are false positives. Here is how to measure and manage the noise.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.