Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (2437)Vulnerability Analysis (2437)AI Security (789)Application Security (543)Security (523)DevSecOps (511)Tool Comparison (454)Open Source Security (413)Compliance (318)Industry Analysis (311)AppSec (309)Container Security (285)Best Practices (264)Open Source (252)Cloud Security (246)Buyer's Guides (217)Software Supply Chain Security (182)Regulatory Compliance (144)Incident Analysis (141)Vulnerability Management (140)Security Guides (124)Concepts (116)Ranking (116)Product (101)Containers (100)Supply Chain Attacks (93)SBOM (77)Vulnerabilities (72)Threat Intelligence (66)Infrastructure Security (64)Supply Chain Security (55)Supply Chain (55)FAQ (50)Tools (50)SBOM & Compliance (41)Comparisons (32)Engineering (29)Licensing (26)Ransomware (24)Tutorials (24)Guides (22)SecOps (22)Kubernetes Security (22)Regulation (20)Vulnerability Guides (20)Industry Guides (19)Case Studies (18)Compliance & Regulations (18)Emerging Technology (17)Solutions (17)Risk Management (16)Tool Reviews (16)Agent Security (16)Vulnerability Response (16)Threat Research (16)Compliance & Frameworks (15)Identity Security (15)Cryptography (15)Security Concepts (15)Incident Response (15)Industry Events (14)Security Strategy (13)Frameworks (12)Dependency Security (11)Web Security (11)Data Breach (11)Security News (10)Career (10)Enterprise (9)Culture (9)Company (9)Strategy (8)Standards (8)Architecture (8)Zero-Day Exploits (7)Network Security (7)Secure Development (7)How-To Guide (7)Dependency Management (7)Industry Trends (7)Industry Insights (7)Vendor Comparison (6)Dev Practices (6)Developer Security (6)Security Operations (6)Research (6)Organizational Security (6)Industry (6)Breach Analysis (5)Code Security (5)Cryptocurrency Security (4)Offensive Security (4)Policy (4)Product Launch (4)Tool Comparisons (4)Mobile Security (4)Vulnerability Research (3)Hardware Security (3)Social Engineering (3)Policy & Compliance (3)Healthcare Security (3)Build Security (3)Startup Security (3)Governance (3)Regional Security (3)Analysis (3)Software Supply Chain (3)API Security (2)Security Culture (2)Release (2)DeFi Security (2)Zero-Day Analysis (2)Industry News (2)Security Management (2)SBOM Standards (2)Security Architecture (2)SBOM and Compliance (2)Threat Actors (2)Tools & Platforms (1)PKI Security (1)Threat Modeling (1)Threat Analysis (1)Architecture Security (1)Language Security (1)Incident Postmortem (1)Runtime Security (1)Product Update (1)SBOM & Standards (1)Healthcare (1)Lifecycle Management (1)Credential Attacks (1)Career Development (1)Business Continuity (1)Tools & Techniques (1)Data Security (1)Events (1)Privacy & Security (1)Technical (1)Privacy (1)Emerging Threats (1)Nation-State Threats (1)Browser Security (1)

Articles

RSS feed
Vulnerability Analysis

SharePoint and Exchange Produce Four More Confirmed-Exploited CVEs

Beyond the five-CVE cluster covered earlier, four more SharePoint and Exchange vulnerabilities were confirmed exploited across the year — including a 2023 Exchange bug confirmed nearly three years later.

Sep 16, 20264 min read
Vulnerability Analysis

WSUS and Configuration Manager: When Patch Infrastructure Itself Needs Patching

CVE-2025-59287 in WSUS and CVE-2024-43468 in Configuration Manager both scored CVSS 9.8 — critical bugs in the very tools organizations use to distribute trust across their fleet.

Sep 16, 20264 min read
Vulnerability Analysis

Eleven Microsoft CVEs From 2008 to 2013, All Confirmed Exploited This Past Year

A Windows buffer overflow from 2008, IE bugs from 2010, an Office flaw from 2009 — eleven old Microsoft vulnerabilities entered CISA's KEV catalogue, several on the exact same day.

Sep 16, 20264 min read
Vulnerability Analysis

CISA Gave You Three Days: What the KEV Deadlines Say About Your Patch Process

Of the 103 vulnerabilities CISA added to the exploited catalogue since June, 75 carry a three-day remediation deadline. That is shorter than most release cycles, and it is an architecture requirement rather than a scheduling problem.

Sep 16, 20266 min read
Vulnerability Analysis

A CVSS 10.0 That Only Reads Files: GitLab CVE-2026-85706

An unauthenticated attacker reads arbitrary files from a GitLab server. There is no code execution, and it still scores 10.0 — because on a source host a read primitive is a credential incident.

Sep 16, 20266 min read
Vulnerability Analysis

Four Artifactory CVEs in Sixteen Days: The Registry Is the Supply Chain

JFrog Artifactory had never appeared in CISA’s exploited-vulnerabilities catalogue. Between 27 August and 11 September 2026 it gained four entries, including unauthenticated administrative access under default configuration.

Sep 16, 20267 min read
Vulnerability Analysis

Apple Patched a Network-Exploitable Auth Bug Across Five Concurrent macOS Releases

CVE-2026-65400, an authentication issue Apple fixed with 'improved state management,' was backported across Golden Gate, Sequoia, Sonoma and two Tahoe releases at once.

Sep 16, 20264 min read
Vulnerability Analysis

Arista's SD-WAN Orchestrator Had a Perfect-10 Privileged-Access Bug

CVE-2026-16812 gives a remote attacker access to privileged internal functionality on Arista's on-premises VeloCloud Orchestrator — the single console managing an entire SD-WAN fleet.

Sep 16, 20264 min read
Vulnerability Analysis

Zimbra's Optional SNMP Monitoring Feature Became a Remote Code Execution Path

CVE-2026-73570 requires the optional zimbra-snmp package and SNMP notifications enabled — exactly the configuration a more security-conscious mail admin was likely to have set up.

Sep 16, 20264 min read

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.