Safeguard
Tag

container-security

Safeguard articles tagged "container-security" — guides, analysis, and best practices for software supply chain and application security.

100 articles

Cloud Security

The Kubernetes Token Nobody Asked For

Every pod gets a token that authenticates to the API server, whether the application inside it ever calls the API or not. It sits there anyway, readable by anything that can read a file in the container, because the default is on.

Sep 18, 20265 min read
Software Supply Chain Security

A Tag Is Not a Version

You deployed myapp:1.4.2 in March and myapp:1.4.2 in September. Those are not necessarily the same image. Almost every tag you rely on is a mutable pointer that someone else can move without telling you.

Sep 17, 20265 min read
SBOM

The SBOM Your Customer Wants Is Not the One You Generated

An SBOM is a statement about a specific artifact. Generate it from the repository and you have an accurate document about something nobody runs, missing the base image where most of your published CVEs live.

Sep 17, 20266 min read
Container Security

An Egress Allowlist You Can Enforce, Not Just Record

A proxy the workload can decline to use is a log, not a control. Why environment-variable proxies and host firewall rules both fail for untrusted code, and the internal-network plus gateway-container shape that does not.

Sep 17, 20266 min read
Vulnerability Analysis

Four Artifactory CVEs in Sixteen Days: The Registry Is the Supply Chain

JFrog Artifactory had never appeared in CISA’s exploited-vulnerabilities catalogue. Between 27 August and 11 September 2026 it gained four entries, including unauthenticated administrative access under default configuration.

Sep 16, 20267 min read
Vulnerability Analysis

Docker symlink race condition escape (CVE-2018-15664)

A TOCTOU race in Docker's docker cp symlink resolution let malicious containers write to host files as root. Impact, CVSS, and fixes inside.

Aug 4, 20268 min read
Vulnerability Analysis

Docker Engine crafted image denial of service (CVE-2021-21285)

CVE-2021-21285 lets a crafted container image crash Docker Engine before 20.10.3. Affected versions, severity, timeline, and remediation steps.

Aug 4, 20267 min read
Vulnerability Analysis

Docker Engine remap-root UID mapping vulnerability (CVE-2021-21284)

CVE-2021-21284 let remapped-root containers escalate to real host root, defeating Docker's userns-remap isolation. Here's the full breakdown and fix.

Aug 4, 20266 min read
Vulnerability Analysis

Time-of-check to time-of-use (TOCTOU) race condition vulnerabilities

TOCTOU race conditions let attackers swap a resource between a security check and its use. Real CVEs, exploit mechanics, and prevention patterns explained.

Aug 2, 20267 min read
Containers

Kubernetes Security News Today: What to Watch and How to Respond

Keeping up with Kubernetes security news today means more than reading headlines. Here's how to triage a fresh CVE, what IngressNightmare taught us, and where to look first.

Aug 2, 20266 min read
Vulnerability Analysis

Kubernetes RBAC misconfiguration explained

RBAC misconfigurations like wildcard rules and default service account bindings have powered real cluster takeovers, from CVE-2018-1002105 to Siloscape.

Jul 29, 20266 min read
Vulnerability Analysis

Secrets leakage in Docker images explained

How credentials get baked into Docker image layers, real incidents that exposed them, and how to detect and stop secrets leakage in container images.

Jul 29, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.