ai-security
Safeguard articles tagged "ai-security" — guides, analysis, and best practices for software supply chain and application security.
593 articles
Guardrails for Autonomous Code-Fixing Agents
AI agents can now open pull requests that patch vulnerabilities on their own. Without guardrails — scoped permissions, test gates, human merge approval — they can also break builds and introduce new flaws at machine speed.
The OWASP AI Top 10 Explained: LLM Risks for 2025 and Beyond
The OWASP AI Top 10 is the community list of the most critical security risks in LLM applications, led by prompt injection. Here is what each entry means and how to defend against it.
What Is AI-Powered Cybersecurity? A Practical Security Guide
AI-powered cybersecurity means using machine learning and language models to detect, triage, and remediate threats faster than rule-based tooling alone. Here is where it genuinely helps and where the hype outruns reality.
NIST SP 800-218A: SSDF Practices for Generative AI Models
NIST finalized SP 800-218A on July 26, 2024, augmenting the Secure Software Development Framework with practices specific to generative AI and dual-use foundation models.
Enterprise AI Center Of Excellence Blueprint
An AI Center of Excellence is not a committee. It is the function that makes AI adoption coherent across business units. The blueprint is specific.
Griffin AI vs Open Weights: Supply Chain Risks
Open-weight models give you total deployment control. They also give you a new supply chain to secure. The tradeoff is worth being explicit about.
AI Code Assistants and Security: The Hidden Risks in 2025
AI coding assistants are generating millions of lines of production code. But they also introduce dependency hallucinations, insecure patterns, and supply chain risks that security teams need to address.
Regression Gate Design Patterns For Security LLMs
A release gate that fails on regression is the most important operational control for AI-for-security tools. The design patterns are specific and worth copying.
Small Language Models: Security Use-Case Fit
Small language models aren't a worse version of large ones. For specific security workflows, they're the right tool — if you know which workflows.
Zero-Day Triage Without Drowning Engineers
A zero-day discovery pipeline is only as useful as the triage process around it. Here is what triage looks like when the pipeline gives engineers something they can defend.
Claude MCP Tool Poisoning Threat Model 2026
A senior engineer's threat model for Claude MCP tool poisoning in 2026, covering malicious servers, description hijacking, and the authorization patterns that actually help.
Hugging Face Token Exposure 2024 Analysis
Researchers found thousands of valid Hugging Face API tokens in public code and models. Analysis of the 2024 exposures and what they mean for ML supply chain.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.