mfa
Safeguard articles tagged "mfa" — guides, analysis, and best practices for software supply chain and application security.
19 articles
We Signed CISA's Secure by Design Pledge. Here Is Where We Stand on Each Goal
Safeguard now appears on CISA's list of Secure by Design Pledge signers. The pledge asks for measurable progress on seven security goals within a year. Here is what we already ship for each one, and what we have not done yet.
Your Cyber Insurance Application Can Void the Claim You Will Need It For
The application said MFA was enforced everywhere. The compromised account did not have it. The policy did not fail you. The application did, months earlier, answered quickly under a renewal deadline.
Which of Your Second Factors Can Be Relayed by Someone in the Middle
A code read off a screen and typed into a page can be typed into the wrong page. A key bound to an origin cannot produce anything usable for a site that is not yours. That is the whole distinction.
Account Recovery Is the Weakest Authentication You Have
You require strong passwords and enforce MFA, then built a flow that lets someone with inbox access bypass all of it. Recovery exists to let in someone who cannot satisfy the normal requirements, so every control above it is capped by how well it is built.
The 2024 Snowflake Customer Attacks: A Breach With No Platform Vulnerability
A factual account of the 2024 campaign against Snowflake customer accounts, which used credentials harvested by infostealer malware against accounts lacking multi-factor authentication, with no vulnerability in Snowflake itself.
Colonial Pipeline (2021): A Single Compromised VPN Password
A factual retrospective on the May 2021 Colonial Pipeline ransomware attack, traced to a single compromised VPN account password with no multi-factor authentication, and its effect on U.S. critical infrastructure fuel supply.
Phishing Tools: How Attackers Operate and How to Defend
A defender's overview of phishing tools — the kit categories attackers use, the techniques that make modern campaigns effective, and the controls that actually blunt them.
The security hygiene checklist most engineering orgs still skip
22% of breaches start with stolen credentials, per Verizon's 2025 DBIR. A quarter-long hygiene checklist — patching, MFA, secrets, least privilege — closes most of that gap.
OWASP A07: Identification and Authentication Failures — A Deep-Dive Guide
Identification and Authentication Failures rank #7 in the OWASP Top 10 (2021). A deep dive into credential stuffing, session handling, real CVEs, and 2026 fixes.
Cyber Hygiene: The Everyday Habits That Stop Most Breaches
Cyber hygiene is the routine set of practices that keep systems healthy and hard to compromise. Get the basics right and you close the door on the majority of real-world attacks.
NYDFS Part 500: The November 2025 Deadlines, One Year On
The Second Amendment to NYDFS Part 500 added universal MFA and an asset inventory mandate on November 1, 2025. The April 2026 certification reveals where covered entities stand.
What is Phishing
Phishing drives more breaches than any other attack vector. Here's how it works, how it hits software supply chains, and how to defend against it.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.