Safeguard
Tag

mfa

Safeguard articles tagged "mfa" — guides, analysis, and best practices for software supply chain and application security.

19 articles

Security

We Signed CISA's Secure by Design Pledge. Here Is Where We Stand on Each Goal

Safeguard now appears on CISA's list of Secure by Design Pledge signers. The pledge asks for measurable progress on seven security goals within a year. Here is what we already ship for each one, and what we have not done yet.

Oct 10, 20268 min read
Compliance

Your Cyber Insurance Application Can Void the Claim You Will Need It For

The application said MFA was enforced everywhere. The compromised account did not have it. The policy did not fail you. The application did, months earlier, answered quickly under a renewal deadline.

Sep 18, 20265 min read
Application Security

Which of Your Second Factors Can Be Relayed by Someone in the Middle

A code read off a screen and typed into a page can be typed into the wrong page. A key bound to an origin cannot produce anything usable for a site that is not yours. That is the whole distinction.

Sep 18, 20265 min read
Application Security

Account Recovery Is the Weakest Authentication You Have

You require strong passwords and enforce MFA, then built a flow that lets someone with inbox access bypass all of it. Recovery exists to let in someone who cannot satisfy the normal requirements, so every control above it is capped by how well it is built.

Sep 18, 20266 min read
Vulnerability Analysis

The 2024 Snowflake Customer Attacks: A Breach With No Platform Vulnerability

A factual account of the 2024 campaign against Snowflake customer accounts, which used credentials harvested by infostealer malware against accounts lacking multi-factor authentication, with no vulnerability in Snowflake itself.

Sep 17, 20263 min read
Vulnerability Analysis

Colonial Pipeline (2021): A Single Compromised VPN Password

A factual retrospective on the May 2021 Colonial Pipeline ransomware attack, traced to a single compromised VPN account password with no multi-factor authentication, and its effect on U.S. critical infrastructure fuel supply.

Sep 17, 20262 min read
Security

Phishing Tools: How Attackers Operate and How to Defend

A defender's overview of phishing tools — the kit categories attackers use, the techniques that make modern campaigns effective, and the controls that actually blunt them.

Jul 22, 20266 min read
Best Practices

The security hygiene checklist most engineering orgs still skip

22% of breaches start with stolen credentials, per Verizon's 2025 DBIR. A quarter-long hygiene checklist — patching, MFA, secrets, least privilege — closes most of that gap.

Jul 14, 20266 min read
Security Guides

OWASP A07: Identification and Authentication Failures — A Deep-Dive Guide

Identification and Authentication Failures rank #7 in the OWASP Top 10 (2021). A deep dive into credential stuffing, session handling, real CVEs, and 2026 fixes.

Jul 5, 20266 min read
Security

Cyber Hygiene: The Everyday Habits That Stop Most Breaches

Cyber hygiene is the routine set of practices that keep systems healthy and hard to compromise. Get the basics right and you close the door on the majority of real-world attacks.

Jun 24, 20267 min read
Compliance

NYDFS Part 500: The November 2025 Deadlines, One Year On

The Second Amendment to NYDFS Part 500 added universal MFA and an asset inventory mandate on November 1, 2025. The April 2026 certification reveals where covered entities stand.

May 6, 20266 min read
Vulnerability Analysis

What is Phishing

Phishing drives more breaches than any other attack vector. Here's how it works, how it hits software supply chains, and how to defend against it.

Mar 26, 20268 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.