patch-management
Safeguard articles tagged "patch-management" — guides, analysis, and best practices for software supply chain and application security.
66 articles
Patch Lag Explains the Old Breaches. It Does Not Explain the New Ones.
Reviewing two decades of major incidents, the ones that defined early security were patch-adoption failures. A growing share of recent ones had no patch to apply, because the compromise was in the distribution chain itself. These need different defences.
WSUS and Configuration Manager: When Patch Infrastructure Itself Needs Patching
CVE-2025-59287 in WSUS and CVE-2024-43468 in Configuration Manager both scored CVSS 9.8 — critical bugs in the very tools organizations use to distribute trust across their fleet.
CISA Gave You Three Days: What the KEV Deadlines Say About Your Patch Process
Of the 103 vulnerabilities CISA added to the exploited catalogue since June, 75 carry a three-day remediation deadline. That is shorter than most release cycles, and it is an architecture requirement rather than a scheduling problem.
Your 30-Day Patch SLA Meets a 48-Hour Exploitation Window
88% of exploitation against vulnerabilities with a public PoC now happens within 48 hours. No organisation patches everything that fast. The fix is a smaller fast lane, selected automatically.
CVE-2025-31133 in runc: Patch Posture & SBOM Response
runc container-escape via /proc mount manipulation affects Docker, Kubernetes, and every CRI runtime. Defender playbook below.
CVE-2025-64446 in Fortinet FortiWeb: Patch Posture & SBOM Response
FortiWeb path traversal + RCE scored CVSS 9.1 and entered CISA KEV after months of targeted exploitation. Defender playbook for the WAF emergency.
The security hygiene checklist most engineering orgs still skip
22% of breaches start with stolen credentials, per Verizon's 2025 DBIR. A quarter-long hygiene checklist — patching, MFA, secrets, least privilege — closes most of that gap.
A patching playbook for critical open-source CVEs
Heartbleed, the OpenSSL punycode bug, and XZ Utils each broke a different assumption in incident response. Here's an SLA-driven playbook that survives all three.
Inside the OpenSSL punycode bug: why CVE-2022-3602 wasn't Heartbleed
OpenSSL pre-announced a 'critical' flaw in October 2022. It shipped as HIGH severity. Here's the buffer overflow, the downgrade, and the safe patch path.
A hardening checklist for modern Drupal deployments
Drupal 7's 2025 end-of-life left unsupported sites exposed; here's a concrete checklist for module vetting, access control, and patch cadence on Drupal 10/11.
The four pillars every enterprise security program needs
Identity, patching, segmentation, and logging aren't a checklist — they're the four controls that determine whether a breach stays contained or becomes Log4Shell.
Continuous vulnerability management: the discovery-to-verification lifecycle
CISA's new BOD 26-04 gives federal agencies as little as 3 days to remediate the highest-risk flaws — a preview of the SLA pressure every engineering org now faces.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.