Safeguard
Tag

least-privilege

Safeguard articles tagged "least-privilege" — guides, analysis, and best practices for software supply chain and application security.

57 articles

Cloud Security

One Shared Deploy Credential Is Forty Pipelines' Worth of Blast Radius

Set up once, when there was one service. Forty pipelines later, every one of them still uses it, and it can deploy to production, which means it can read the secrets and infrastructure of everything it touches.

Sep 18, 20266 min read
Cloud Security

The Kubernetes Token Nobody Asked For

Every pod gets a token that authenticates to the API server, whether the application inside it ever calls the API or not. It sits there anyway, readable by anything that can read a file in the container, because the default is on.

Sep 18, 20265 min read
Infrastructure Security

Nobody Notices When a Scheduled Job Stops Running

They run at three in the morning with broad credentials, unattended, and failure produces nothing because the output was always invisible. A retention job that silently stops means you are keeping data you promised to delete.

Sep 18, 20265 min read
Compliance

Nobody Decided That Everyone Should Have Production Access

It was obviously right at eight people and nothing has forced a decision since. At some point the number who can read every customer's data stops being one you would say out loud, and nothing breaks to tell you.

Sep 18, 20265 min read
Application Security

Your Application Connects as a User That Can Do Everything

A SQL injection is limited by what the connected user may do, and so is a compromised application process. In most deployments the answer is everything, because that is what the framework quickstart produced.

Sep 18, 20266 min read
Compliance

Your Quarterly Access Review Revoked Nothing

Managers approve everything because the task as presented cannot be done well: uninterpretable entitlement names, no usage data, and a default that costs nothing while the alternative breaks a colleague's Friday.

Sep 17, 20266 min read
AI Security

Every AI Coding Tool Has the Same Vulnerability, and It Isn't a Bug

Sandbox escapes in Claude Code, critical CVEs in Cursor, a 10.0 in Gemini CLI, prompt injection in Copilot. Different vendors, one shared cause: the agent must hold elevated access to be useful.

Aug 7, 20266 min read
AI Security

How to authorize and scope permissions for autonomous AI ...

A practical, step-by-step guide to AI agent authorization: scoping permissions, using OAuth for machine identities, and verifying least-privilege boundaries hold in production.

Aug 5, 20268 min read
Cloud Security

AWS IAM: common vulnerabilities and fixes

Rhino Security Labs catalogs 21+ IAM privilege-escalation paths to full admin — most start with one over-scoped policy nobody remembers writing.

Jul 16, 20266 min read
Best Practices

Ransomware defense strategy for engineering teams

Ransomware hit 44% of breaches in Verizon's 2025 DBIR, up from 32% a year prior. Here's the backup, access, and detection playbook that actually stops it.

Jul 15, 20266 min read
Best Practices

The security hygiene checklist most engineering orgs still skip

22% of breaches start with stolen credentials, per Verizon's 2025 DBIR. A quarter-long hygiene checklist — patching, MFA, secrets, least privilege — closes most of that gap.

Jul 14, 20266 min read
Cloud Security

Common AWS IAM privilege-escalation paths and how to design least privilege

Rhino Security Labs cataloged 21 distinct AWS IAM privilege-escalation methods in 2018 — most still work today, and most are invisible to a manifest scan.

Jul 14, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.