Safeguard
Tag

network-security

Safeguard articles tagged "network-security" — guides, analysis, and best practices for software supply chain and application security.

33 articles

Container Security

An Egress Allowlist You Can Enforce, Not Just Record

A proxy the workload can decline to use is a log, not a control. Why environment-variable proxies and host firewall rules both fail for untrusted code, and the internal-network plus gateway-container shape that does not.

Sep 17, 20266 min read
Vulnerability Analysis

WatchGuard Firebox's IKEv2 VPN Bug Hit Twice, and One Is Tied to Ransomware

Two nearly identical out-of-bounds write vulnerabilities in Firebox's iked process, both CVSS 9.8, both unauthenticated remote code execution, one confirmed for ransomware.

Sep 16, 20264 min read
Vulnerability Analysis

F5, Check Point, Versa, and Arista: Four Vendors, One Edge Infrastructure Problem

A BIG-IP APM buffer overflow, a ransomware-linked Check Point VPN authentication bypass, a Versa Concerto proxy misconfiguration, and an Arista EOS tunnel decapsulation flaw all failed at the same job: enforcing a boundary.

Sep 16, 20265 min read
Vulnerability Analysis

Cisco's Catalyst SD-WAN Line Produced Seven Confirmed-Exploited CVEs in a Year

From a perfect-10 peering authentication bypass to CLI privilege escalation, seven distinct vulnerabilities across Cisco's SD-WAN Controller, Manager, and underlying software were confirmed exploited.

Sep 16, 20264 min read
Security

Snyk Broker: How the On-Premise Connector Secures Access

Snyk Broker is the proxy that lets a SaaS scanner reach your on-prem Git without opening inbound ports. Here is how it works and what to lock down.

Jul 19, 20266 min read
Application Security

DNS attack techniques and defenses

Cache poisoning, tunneling, and NXDOMAIN floods all abuse the same trust: DNS was built to be fast and open, not authenticated.

Jul 12, 20266 min read
Best Practices

Open-source penetration testing tools: a comparison guide

Nine open-source pentest tools, one decision problem: Nmap finds hosts, Metasploit exploits them, but neither replaces the other. Here's when to reach for each.

Jul 8, 20267 min read
Application Security

The security cost of long-lived HTTP connections

Keep-alive and HTTP/2 multiplexing cut handshake overhead but hold server resources open per connection — Slowloris and 2023's Rapid Reset attacks both exploited exactly that tradeoff.

Jul 8, 20266 min read
Vulnerability Management

HTTP/2 Rapid Reset: inside CVE-2023-44487

A single HTTP/2 feature let attackers hit 398 million requests per second. Here's how Rapid Reset (CVE-2023-44487) broke nearly every major web server at once.

Jul 8, 20266 min read
AppSec

Network Hacking Tools Attackers Use — and How Defenders Answer

A defender's field guide to the network hacking tools attackers reach for — reconnaissance, sniffing, exploitation, credential attacks — and the detection and control that answers each class.

Jun 29, 20268 min read
AI Security

AI in Network Security: Where It Actually Helps Today

AI in network security earns its keep in anomaly detection and alert triage today, not in autonomous response — here's the honest split between what's proven and what's still marketing.

Apr 22, 20265 min read
Security

DNS Vulnerabilities: The Attacks That Target the Internet's Address Book

A DNS vulnerability lets an attacker forge, intercept, or redirect the name lookups your systems depend on. Here are the main classes and how to defend against them.

Apr 18, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.