least-privilege
Safeguard articles tagged "least-privilege" — guides, analysis, and best practices for software supply chain and application security.
57 articles
One Shared Deploy Credential Is Forty Pipelines' Worth of Blast Radius
Set up once, when there was one service. Forty pipelines later, every one of them still uses it, and it can deploy to production, which means it can read the secrets and infrastructure of everything it touches.
The Kubernetes Token Nobody Asked For
Every pod gets a token that authenticates to the API server, whether the application inside it ever calls the API or not. It sits there anyway, readable by anything that can read a file in the container, because the default is on.
Nobody Notices When a Scheduled Job Stops Running
They run at three in the morning with broad credentials, unattended, and failure produces nothing because the output was always invisible. A retention job that silently stops means you are keeping data you promised to delete.
Nobody Decided That Everyone Should Have Production Access
It was obviously right at eight people and nothing has forced a decision since. At some point the number who can read every customer's data stops being one you would say out loud, and nothing breaks to tell you.
Your Application Connects as a User That Can Do Everything
A SQL injection is limited by what the connected user may do, and so is a compromised application process. In most deployments the answer is everything, because that is what the framework quickstart produced.
Your Quarterly Access Review Revoked Nothing
Managers approve everything because the task as presented cannot be done well: uninterpretable entitlement names, no usage data, and a default that costs nothing while the alternative breaks a colleague's Friday.
Every AI Coding Tool Has the Same Vulnerability, and It Isn't a Bug
Sandbox escapes in Claude Code, critical CVEs in Cursor, a 10.0 in Gemini CLI, prompt injection in Copilot. Different vendors, one shared cause: the agent must hold elevated access to be useful.
How to authorize and scope permissions for autonomous AI ...
A practical, step-by-step guide to AI agent authorization: scoping permissions, using OAuth for machine identities, and verifying least-privilege boundaries hold in production.
AWS IAM: common vulnerabilities and fixes
Rhino Security Labs catalogs 21+ IAM privilege-escalation paths to full admin — most start with one over-scoped policy nobody remembers writing.
Ransomware defense strategy for engineering teams
Ransomware hit 44% of breaches in Verizon's 2025 DBIR, up from 32% a year prior. Here's the backup, access, and detection playbook that actually stops it.
The security hygiene checklist most engineering orgs still skip
22% of breaches start with stolen credentials, per Verizon's 2025 DBIR. A quarter-long hygiene checklist — patching, MFA, secrets, least privilege — closes most of that gap.
Common AWS IAM privilege-escalation paths and how to design least privilege
Rhino Security Labs cataloged 21 distinct AWS IAM privilege-escalation methods in 2018 — most still work today, and most are invisible to a manifest scan.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.