attack-surface
Safeguard articles tagged "attack-surface" — guides, analysis, and best practices for software supply chain and application security.
20 articles
Your Staging Environment Is on the Internet and Nobody Chose That
Less hardening, unfinished code, no monitoring, real credentials, and often production's network reachability. An attacker choosing between your two environments will frequently prefer this one.
Your Health and Metrics Endpoints Describe Your System to Anyone Who Asks
Nobody designed them. A framework, a platform team or a monitoring integration added them, they were configured once, and they are the endpoints that describe your architecture most accurately.
The Asset Nobody Owns Is the One That Sits for a Year
The DNS record pointing at a dead vendor, the service account nobody can justify, the repository failing every scan. Each has a fix that takes an afternoon, and each waits a year because finding an owner has no owner either.
Your API Inventory Is Smaller Than Your API
The spec says one number, the gateway serves a larger one, and the difference is your unprotected surface: undecommissioned v1 routes, framework-generated handlers, and the debug endpoint added during an incident.
A Half-Deleted Service Is More Dangerous Than a Running One
Services are launched with a checklist and switched off with a Slack message. The container goes, the credentials stay, and nobody patches or monitors something everyone believes is gone.
The Subdomain You Forgot Is Someone Else's Now
A CNAME outlives the vendor account it pointed at, the platform frees the hostname, and anyone can claim it. The damage is rarely the defaced page: it is parent-domain cookies, OAuth redirects and a CSP that trusts subdomains.
Fingerprinting AI-Built Web Apps From the Outside
A DAST scan has no repository and no commit history — only what the server sends a browser. That is enough to identify the builder that generated an app, and nowhere near enough to name the model.
Docker Scratch Image: The Security Case for Empty Bases
A Docker scratch image starts from nothing, and that emptiness is the point: no shell, no package manager, and almost no CVEs for a scanner to find.
How to Discover Shadow and Undocumented APIs Before Attackers Do
A single undocumented API endpoint exposed 10 million Optus records in 2022. Here's how to find shadow APIs in production and assess their real exposure.
Multi-Stage Docker Builds: A Security Pattern, Not Just a Size Trick
Multi-stage builds are pitched as a way to shrink images. Their bigger payoff is security: build secrets, compilers, and toolchains that never reach production. Here is how to use them right.
Using jlink to Build Minimal, Lower-Attack-Surface Java Docker Images
jlink has shipped with every JDK since Java 9 in 2017, yet most Spring Boot images still ship a full 300MB+ JDK. Here's how to fix that.
Distroless vs Alpine: Which Base Image Is More Secure?
Alpine is tiny and familiar; distroless is tinier and shell-free. The right choice depends on what you value more — debuggability or a minimal attack surface. Here is the honest tradeoff.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.