Safeguard
Tag

scanning

Safeguard articles tagged "scanning" — guides, analysis, and best practices for software supply chain and application security.

11 articles

Application Security

A Scanner's Scope Guard Belongs in Code, Not in a Config File

The difference between a security test and an unauthorised attack is permission on the target. If that boundary is a setting, then a typo, a redirect or a merged config is all it takes to cross it.

Aug 16, 20264 min read
Application Security

Your DAST Scan Has Six Timeouts and No Deadline

Per-phase timeouts add up. Six phases capped at ten minutes each is a sixty-minute scan wearing a ten-minute label — and the phase that mattered gets whatever is left.

Aug 16, 20265 min read
AppSec

Skill Scanner: How It Works and What to Use

What a skill scanner does, why AI agent skills and voice-assistant skills need scanning, and how to evaluate one for your pipeline.

Jul 2, 20266 min read
Security

How to Choose a Vulnerability Assessment Solution

A vulnerability assessment solution finds, ranks, and tracks weaknesses across your systems. Here is what separates a useful one from a report generator.

Jun 28, 20265 min read
Threat Intelligence

SonicWall SonicOS Scanning Surge in May 2026: The CVE-2026-0400 Early-Warning Pattern

GreyNoise recorded ~597,000 SonicWall SonicOS scanning sessions on May 12, 2026, roughly 46x baseline. The pattern echoes the recon waves that preceded CVE-2026-0400's disclosure. Here is how to read the signal.

May 20, 202611 min read
Security

How to Check Website Vulnerability: A Practical Guide

To check website vulnerability properly you combine automated scanning of the running app with dependency analysis of what it's built from. Here's a workflow that covers both.

Apr 30, 20266 min read
AppSec

Website Vulnerability Scanners: How They Work and What They Miss

How a website vulnerability scanner crawls, fuzzes, and fingerprints your app, plus the whole classes of flaws it structurally cannot find on its own.

Apr 25, 20266 min read
Security

How to Check a Website for Vulnerabilities: A Practical Guide

A hands-on walkthrough of how to check a website for vulnerabilities, from passive header checks to authenticated dynamic scanning, and how to read the results.

Mar 29, 20265 min read
DevSecOps

Gitleaks Secret Scanning Recipes for 2026

Practical Gitleaks configurations and workflows for 2026, including pre-commit setup, monorepo tuning, custom rules, and how to avoid the false-positive treadmill.

Mar 25, 20265 min read
AI Security

Griffin AI vs Claude Batch API for Scanning

Claude's Batch API gives you 50% off for async workloads. Griffin AI uses it internally. The question is whether your team should use the Batch API directly or consume it through Griffin.

Feb 26, 20262 min read
DevSecOps

Container Security Scanning in 2024: Benchmarks, Tools, and What Actually Matters

Container image scanning tools vary widely in detection rates, false positive rates, and coverage. Here is a practical assessment of the container security scanning landscape in 2024.

Feb 23, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

scanning — Safeguard Blog