incident-response
Safeguard articles tagged "incident-response" — guides, analysis, and best practices for software supply chain and application security.
107 articles
Asana MCP Cross-Tenant Leak: A SaaS Connector Failure Mode
From May 1 to June 17, 2025, Asana's MCP server exposed records from one customer's workspace to another. The bug was a textbook authorization break wearing an AI label.
PHP Webshells: How Attackers Plant Them and How to Detect One
A PHP webshell is a malicious script that gives an attacker remote control of your server. Here is how they get planted, what they look like, and how to find them.
Malware Code Explained: How Malicious Code Works and How to Detect It
Malware code is any code written to run without the owner's informed consent and against their interest. Understanding its patterns is what makes it detectable.
A Defender's Template for Package Registry Incident Communications, Built from the 2025-2026 Response Postmortems
The npm Shai-Hulud, PyPI credential-leak, and tj-actions response postmortems published through 2025-2026 reveal a common communication shape. Here is the template, the timing, and the policy that turns the template into a fast response.
Cloudflare Workers KV June 12 2025 Outage: A GCP Dependency Story
A 2-hour, 28-minute Workers KV outage rolled into Access, Gateway, WARP, and Turnstile because the central store sat on GCP. Here is the dependency chain and the R2 re-architecture that followed.
SEC cybersecurity disclosure rules for public companies
The SEC's 2023 rules give public companies four business days to disclose material cyber incidents. Here's what triggers the clock, and how supply chain visibility keeps you compliant.
CISA's CI Fortify (May 2026): Planning Critical Infrastructure for Cyber Isolation and Recovery
On May 5, 2026, CISA launched CI Fortify, pushing critical infrastructure operators to plan for cyberattacks that sever their connections to the internet and telecom during a geopolitical crisis. We unpack the isolation and recovery objectives and what they demand of software supply chains.
AWS Hack: How Attackers Break Into AWS and How to Stop Them
Most AWS breaches don't start with a clever exploit. They start with a leaked key or a misconfigured bucket. Here is how an AWS hack actually unfolds and how to shut down each step.
Understanding zero-day vulnerabilities and incident response
A concrete look at zero-day vulnerabilities and incident response, using Log4Shell, MOVEit, and CISA KEV data to explain how fast defenders must move.
MTTR in DevOps: How to Measure and Actually Improve Recovery Time
MTTR is one of the four DORA metrics and the clearest signal of how resilient your delivery really is. Here is how to measure it honestly and drive it down.
EU Cybersecurity Reserve: Trusted Providers Under the Cyber Solidarity Act
The EU Cybersecurity Reserve under Regulation (EU) 2025/38 mobilises trusted private incident-response providers to support Member States facing significant cyber incidents.
Cloudflare R2 March 21, 2025 Outage: A Credential Rotation Postmortem
A missing --env flag during a Wrangler secret rotation took R2 writes to zero for 67 minutes. Here is the failure mode and the deployment guardrails that should have caught it.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.