endpoint-security
Safeguard articles tagged "endpoint-security" — guides, analysis, and best practices for software supply chain and application security.
11 articles
LastPass (2022): Two Linked Intrusions and a Developer Home Machine
A factual retrospective on the 2022 LastPass breaches, where attackers used data from a first incident to target a DevOps engineer personal computer, ultimately obtaining encrypted customer vault backups.
When the Security Console Becomes the Distribution Path: Apex One and Workspace ONE UEM
A directory traversal bug in Trend Micro Apex One and a four-year-old SSRF flaw in Omnissa Workspace ONE UEM both use management-plane trust against the fleets these tools are meant to protect.
Three Adobe Acrobat and Reader Bugs, From a 2009 Overflow to This Year's Prototype Pollution
A heap overflow first exploited in 2009, a use-after-free from 2020, and a fresh prototype pollution bug — all three confirmed exploited against Adobe Acrobat and Reader within weeks of each other.
Nine Apple Memory-Safety Bugs Confirmed Exploited Across iOS, macOS, and Safari
Use-after-free, memory corruption, integer overflow — nine Apple vulnerabilities spanning nearly a decade of disclosure dates were confirmed exploited across the company's full platform range.
Microsoft Defender Had Three of Its Own Vulnerabilities Confirmed Exploited
Security software is software first: two local privilege-escalation bugs and a denial-of-service flaw in Microsoft Defender itself were confirmed exploited in the wild.
Apple Patched a Network-Exploitable Auth Bug Across Five Concurrent macOS Releases
CVE-2026-65400, an authentication issue Apple fixed with 'improved state management,' was backported across Golden Gate, Sequoia, Sonoma and two Tahoe releases at once.
Homebrew Formula Security for Engineering Teams
Every brew install runs Ruby you didn't read on a laptop that holds your SSH keys and cloud credentials. How formulae, taps, casks and bottles actually differ in risk.
How Can You Prevent the Download of Malicious Code?
You prevent the download of malicious code with layered controls: verified sources, dependency scanning, browser and endpoint protection, and least-privilege execution.
Wiz vs. CrowdStrike: agentless CNAPP vs. endpoint-driven ...
Wiz's agentless CNAPP and CrowdStrike's endpoint agents both secure runtime, but neither closes the software supply chain gap Safeguard is built for.
What is EDR (Endpoint Detection and Response)
What EDR actually detects, how it differs from antivirus, XDR, and MDR, and why supply chain attacks like XZ Utils and 3CX slip past it entirely.
How to set up endpoint detection and response (EDR)
A step-by-step guide to setting up EDR across your fleet: choosing a platform, deploying agents, tuning policies, and verifying coverage before an incident tests it for you.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.