Safeguard
Tag

attack-surface

Safeguard articles tagged "attack-surface" — guides, analysis, and best practices for software supply chain and application security.

20 articles

Infrastructure Security

Your Staging Environment Is on the Internet and Nobody Chose That

Less hardening, unfinished code, no monitoring, real credentials, and often production's network reachability. An attacker choosing between your two environments will frequently prefer this one.

Sep 18, 20265 min read
Infrastructure Security

Your Health and Metrics Endpoints Describe Your System to Anyone Who Asks

Nobody designed them. A framework, a platform team or a monitoring integration added them, they were configured once, and they are the endpoints that describe your architecture most accurately.

Sep 18, 20265 min read
Best Practices

The Asset Nobody Owns Is the One That Sits for a Year

The DNS record pointing at a dead vendor, the service account nobody can justify, the repository failing every scan. Each has a fix that takes an afternoon, and each waits a year because finding an owner has no owner either.

Sep 18, 20266 min read
Application Security

Your API Inventory Is Smaller Than Your API

The spec says one number, the gateway serves a larger one, and the difference is your unprotected surface: undecommissioned v1 routes, framework-generated handlers, and the debug endpoint added during an incident.

Sep 18, 20266 min read
Infrastructure Security

A Half-Deleted Service Is More Dangerous Than a Running One

Services are launched with a checklist and switched off with a Slack message. The container goes, the credentials stay, and nobody patches or monitors something everyone believes is gone.

Sep 17, 20266 min read
Infrastructure Security

The Subdomain You Forgot Is Someone Else's Now

A CNAME outlives the vendor account it pointed at, the platform frees the hostname, and anyone can claim it. The damage is rarely the defaced page: it is parent-domain cookies, OAuth redirects and a CSP that trusts subdomains.

Sep 17, 20266 min read
Application Security

Fingerprinting AI-Built Web Apps From the Outside

A DAST scan has no repository and no commit history — only what the server sends a browser. That is enough to identify the builder that generated an app, and nowhere near enough to name the model.

Aug 13, 20265 min read
Containers

Docker Scratch Image: The Security Case for Empty Bases

A Docker scratch image starts from nothing, and that emptiness is the point: no shell, no package manager, and almost no CVEs for a scanner to find.

Jul 18, 20265 min read
Application Security

How to Discover Shadow and Undocumented APIs Before Attackers Do

A single undocumented API endpoint exposed 10 million Optus records in 2022. Here's how to find shadow APIs in production and assess their real exposure.

Jul 10, 20266 min read
Container Security

Multi-Stage Docker Builds: A Security Pattern, Not Just a Size Trick

Multi-stage builds are pitched as a way to shrink images. Their bigger payoff is security: build secrets, compilers, and toolchains that never reach production. Here is how to use them right.

Jul 8, 20265 min read
Container Security

Using jlink to Build Minimal, Lower-Attack-Surface Java Docker Images

jlink has shipped with every JDK since Java 9 in 2017, yet most Spring Boot images still ship a full 300MB+ JDK. Here's how to fix that.

Jul 8, 20266 min read
Container Security

Distroless vs Alpine: Which Base Image Is More Secure?

Alpine is tiny and familiar; distroless is tinier and shell-free. The right choice depends on what you value more — debuggability or a minimal attack surface. Here is the honest tradeoff.

Jul 5, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.