web-security
Safeguard articles tagged "web-security" — guides, analysis, and best practices for software supply chain and application security.
153 articles
Authenticated DAST: Getting Past the Login Without Wrecking the App
Most of an application is behind a session, so an unauthenticated scan tests the login page and the marketing footer. Getting in is the easy half — staying in, and not clicking Delete Account, is the rest.
Fingerprinting AI-Built Web Apps From the Outside
A DAST scan has no repository and no commit history — only what the server sends a browser. That is enough to identify the builder that generated an app, and nowhere near enough to name the model.
Cross-site scripting (XSS) explained for developers
XSS has topped vulnerability lists for two decades. Here's how reflected, stored, and DOM-based XSS actually work, real incidents, and how to fix them.
Directory listing exposure risks explained
Directory listing vulnerabilities expose raw file trees via one misconfigured Apache, Nginx, or IIS directive. Here's how they happen and how to fix them.
Subresource integrity bypass explained
SRI hashes can't stop what happens before the hash is made. How polyfill.io, British Airways, and event-stream exposed real gaps in browser integrity checks.
CRLF injection and HTTP response splitting explained
CRLF injection lets attackers forge HTTP headers and split responses. Here's how it works, real CVEs behind it, and how to detect and stop it.
angular.io Security: Keeping Your Angular App Safe in 2025
The docs at angular.io teach safe defaults, but recent CVEs in SSR, the HTTP client, and template sanitization show where the framework still needs your attention.
Best DAST tools for web application security testing
A practical comparison of DAST tools -- from OWASP ZAP to Invicti -- covering real strengths, limitations, and what Safeguard adds beyond runtime scanning.
Security Headers: A Practical Hardening Guide
Which HTTP security headers actually matter, what each one defends against, and copy-ready configuration to harden a site without breaking it.
ZAP Scanner: How OWASP ZAP Works and When to Use It
ZAP is the most widely used free DAST scanner. Here is how its spider, passive, and active engines work, where it fits in CI, and its honest limits.
The ZAP Security Testing Tool: A Practical Guide
How the ZAP security testing tool works as a free DAST scanner: passive and active scanning, the spider and AJAX spider, and how to run it in CI without noise.
CORS Misconfiguration Vulnerabilities
CORS misconfiguration vulnerabilities let attackers steal authenticated API data with a single reflected Origin header. Here's how they happen and how to catch them before release.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.