shadow-it
Safeguard articles tagged "shadow-it" — guides, analysis, and best practices for software supply chain and application security.
6 articles
Every SaaS Tool Nobody Approved Still Has Access
Someone signed up with a company card, connected it with broad OAuth scopes, used it for a quarter, and stopped. The subscription lapsed. The integration did not. Adopting a tool costs nothing; removing one requires someone to remember it exists.
The Notebook Nobody Reviewed Is Running on a Schedule
It pulls customer records, holds a password in cell four, installs packages at runtime, and has run nightly for eighteen months. The format hides both the state and the data, and nothing gated the moment it became infrastructure.
cPanel, Gogs, and Adminer: When Convenience Tools Become the Attack Path
Three unrelated self-hosted admin tools — a hosting control panel, a Git server, and a database manager — each had a confirmed-exploited vulnerability targeting the same convenience-over-process tradeoff.
You Cannot Defend an MCP Server You Do Not Know You Are Running
Tool poisoning is the most impactful client-side MCP vulnerability, and the defensive research is solid. All of it assumes you know which MCP servers you connect to. Almost nobody does.
Know your cloud environment: a practical asset inventory methodology
Gartner projects that through 2025, 99% of cloud security failures will be the customer's fault — almost always because an asset nobody tracked got misconfigured.
Why asset inventory should come before AppSec tooling
Only 17% of organizations can inventory 95%+ of their assets, and 69% have been breached through one they didn't know existed — start with the map, not the scanner.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.