Safeguard
Tag

email-security

Safeguard articles tagged "email-security" — guides, analysis, and best practices for software supply chain and application security.

12 articles

Regulatory Compliance

Every Notification Is a Permanent Copy of Your Customer's Data

Email is the one channel where you hand data to a third party as a matter of routine and nobody counts it as a data flow. The inbox is not deleted, is forwarded, is searchable by whoever holds it, and is scanned.

Sep 18, 20265 min read
Application Security

Inbound Email Is an Unauthenticated API You Forgot You Built

Reply to a notification and it appears in the ticket. Forward a document and it imports. The From header is a string the sender chooses, and it is what most implementations key on.

Sep 18, 20265 min read
Infrastructure Security

The Domains You Registered Defensively Can Send Mail As You

You configured SPF, DKIM and DMARC on the domain you send from. The eleven others you own have no email authentication at all, and the ones closest to your real name are the most useful to an attacker.

Sep 18, 20265 min read
Vulnerability Analysis

SmarterMail's Triple Threat: Three Unauthenticated Roads to Full Compromise

In eleven days, SmarterMail picked up three confirmed-exploited CVEs, all unauthenticated, all tied to known ransomware use — file upload, password-reset bypass, and an API missing authentication.

Sep 16, 20265 min read
Vulnerability Analysis

Zimbra's Optional SNMP Monitoring Feature Became a Remote Code Execution Path

CVE-2026-73570 requires the optional zimbra-snmp package and SNMP notifications enabled — exactly the configuration a more security-conscious mail admin was likely to have set up.

Sep 16, 20264 min read
Security

Phishing Tools: How Attackers Operate and How to Defend

A defender's overview of phishing tools — the kit categories attackers use, the techniques that make modern campaigns effective, and the controls that actually blunt them.

Jul 22, 20266 min read
Application Security

Preventing SMTP injection vulnerabilities in email-sending code

A crafted From address turned PHPMailer into a remote code execution bug in 2016 — here's how header injection works and how to stop it.

Jul 13, 20266 min read
Open Source

Nodemailer npm: A Security Review and Safe Usage Guide

Nodemailer is the default way to send email from Node.js. It is well maintained, but email is a classic injection surface. Here is a security review and how to use it safely.

Apr 8, 20266 min read
Vulnerability Analysis

CVE-2024-45519 Zimbra Unauth RCE Breakdown

A technical breakdown of CVE-2024-45519, the unauthenticated RCE in Zimbra's postjournal service, how it was exploited in the wild, and what defenders should take away.

Feb 25, 20267 min read
Incident Analysis

Microsoft Breached by Midnight Blizzard: Russian Hackers Read Executive Emails

In January 2024, Microsoft disclosed that the Russian state-sponsored group Midnight Blizzard had been reading emails of senior executives and security team members since November 2023, using a password spray attack against a legacy test account.

Feb 11, 20267 min read
Industry Analysis

How to set up SPF, DKIM, and DMARC for email security

A step-by-step guide to setting up SPF, DKIM, and DMARC records to stop email spoofing and secure your domain sending reputation.

Feb 7, 20268 min read
Social Engineering

Email Security and Supply Chain Phishing Attacks

Phishing remains the top initial access vector for supply chain attacks. Targeted emails against developers, maintainers, and DevOps engineers open the door to code injection, credential theft, and pipeline compromise.

Jan 23, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.