Safeguard
Tag

ai-security

Safeguard articles tagged "ai-security" — guides, analysis, and best practices for software supply chain and application security.

593 articles

AI Security

Indirect Prompt Injection Stopped Being a Demo. Google Is Measuring It at Web Scale.

Malicious injected instructions are now tracked across billions of crawled pages a month, every AI browser tested at Black Hat proved vulnerable, and one framework bug turned a prompt into RCE.

Aug 12, 20266 min read
Vulnerability Management

66,000 CVEs: The Year Enumeration Stopped Being a Strategy

2026 is forecast to close near 66,000 CVEs, driven partly by AI-assisted discovery. At that volume reading the list is not a job anyone can do — and most programmes are still built around reading it.

Aug 11, 20266 min read
Vulnerability Analysis

CVE-2026-9198: Two Endpoints, No Password, Full Remote Code Execution

Langflow's auto-login endpoint mints a superuser token for anyone who asks. Its code-validation endpoint runs Python through exec(). Chained, that is unauthenticated RCE at CVSS 9.8.

Aug 10, 20266 min read
AI Security

You Cannot Defend an MCP Server You Do Not Know You Are Running

Tool poisoning is the most impactful client-side MCP vulnerability, and the defensive research is solid. All of it assumes you know which MCP servers you connect to. Almost nobody does.

Aug 7, 20266 min read
AI Security

Every AI Coding Tool Has the Same Vulnerability, and It Isn't a Bug

Sandbox escapes in Claude Code, critical CVEs in Cursor, a 10.0 in Gemini CLI, prompt injection in Copilot. Different vendors, one shared cause: the agent must hold elevated access to be useful.

Aug 7, 20266 min read
AI Security

2,130 AI-Related CVEs and Counting: The Surge Is Structural, Not a Blip

AI-related CVEs rose 34.6% year over year and more than 200% since 2023. The interesting question is what kind of vulnerabilities they are — because most of them are not model flaws at all.

Aug 7, 20266 min read
Industry Analysis

Five Numbers From the CrowdStrike 2026 Threat Hunting Report That Should Change Your Roadmap

87% of software registry threats were malicious npm packages. 88% of exploitation with a public PoC happened inside 48 hours. Device code phishing rose 15x. Five numbers, five pieces of work.

Aug 6, 20266 min read
AI Security

What agentic AI security means and why traditional AppSec...

Traditional AppSec was built for static code, not decision-making agents. Here's what agentic AI security actually covers—and why autonomous agents need a new defense model.

Aug 5, 20268 min read
AI Security

Identity and access management for non-human AI agents

AI agents now hold production credentials the way employees do, except most are never offboarded. Here's how AI agent identity and access management closes that gap.

Aug 5, 20267 min read
AI Security

How to authorize and scope permissions for autonomous AI ...

A practical, step-by-step guide to AI agent authorization: scoping permissions, using OAuth for machine identities, and verifying least-privilege boundaries hold in production.

Aug 5, 20268 min read
AI Security

Security risks of multi-agent AI systems collaborating au...

Multi-agent AI systems introduce security risks classic AppSec misses: agent-to-agent exploits, swarm failures, and orchestration trust gaps.

Aug 5, 20267 min read
AI Security

Security implications of AI browser agents that click, br...

AI browser agents click, browse, and pay with your credentials -- and prompt injection attacks like EchoLeak and CometJacking prove they can be hijacked to do it.

Aug 5, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

ai-security — Safeguard Blog