Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (711)AI Security (786)Vulnerability Analysis (711)Security (523)DevSecOps (497)Application Security (490)Tool Comparison (454)Open Source Security (412)Industry Analysis (310)AppSec (309)Compliance (304)Container Security (284)Open Source (252)Best Practices (252)Cloud Security (239)Buyer's Guides (216)Software Supply Chain Security (178)Incident Analysis (139)Regulatory Compliance (138)Vulnerability Management (136)Security Guides (124)Ranking (116)Concepts (116)Product (101)Containers (100)Supply Chain Attacks (93)SBOM (76)Vulnerabilities (72)Threat Intelligence (66)Supply Chain Security (55)Supply Chain (55)Infrastructure Security (52)Tools (50)FAQ (50)SBOM & Compliance (41)Comparisons (32)Licensing (26)Tutorials (24)Engineering (24)Ransomware (24)Guides (22)Kubernetes Security (22)SecOps (21)Vulnerability Guides (20)Regulation (20)Industry Guides (19)Compliance & Regulations (18)Case Studies (18)Emerging Technology (17)Solutions (17)Threat Research (16)Risk Management (16)Vulnerability Response (16)Tool Reviews (16)Agent Security (16)Compliance & Frameworks (15)Identity Security (15)Incident Response (15)Security Concepts (15)Cryptography (15)Industry Events (14)Security Strategy (13)Frameworks (12)Dependency Security (11)Data Breach (11)Web Security (11)Career (10)Security News (10)Enterprise (9)Company (9)Culture (9)Strategy (8)Architecture (8)Standards (8)Zero-Day Exploits (7)Industry Insights (7)How-To Guide (7)Network Security (7)Dependency Management (7)Industry Trends (7)Secure Development (7)Developer Security (6)Vendor Comparison (6)Dev Practices (6)Organizational Security (6)Security Operations (6)Industry (6)Research (6)Code Security (5)Breach Analysis (5)Tool Comparisons (4)Policy (4)Mobile Security (4)Cryptocurrency Security (4)Offensive Security (4)Product Launch (4)Software Supply Chain (3)Governance (3)Analysis (3)Hardware Security (3)Regional Security (3)Startup Security (3)Social Engineering (3)Build Security (3)Healthcare Security (3)Vulnerability Research (3)Policy & Compliance (3)Threat Actors (2)Industry News (2)Security Architecture (2)API Security (2)SBOM Standards (2)Zero-Day Analysis (2)Release (2)DeFi Security (2)Security Culture (2)SBOM and Compliance (2)Security Management (2)Runtime Security (1)Browser Security (1)Product Update (1)Architecture Security (1)PKI Security (1)Events (1)Privacy (1)Language Security (1)Tools & Platforms (1)Emerging Threats (1)Incident Postmortem (1)Career Development (1)Credential Attacks (1)Threat Analysis (1)Privacy & Security (1)Healthcare (1)Nation-State Threats (1)Lifecycle Management (1)Business Continuity (1)Threat Modeling (1)Tools & Techniques (1)SBOM & Standards (1)Technical (1)

Articles

RSS feed
Vulnerability Analysis

FortiGate SSL-VPN Zero-Day (CVE-2022-42475): How a Heap Overflow Gave Attackers the Keys

A heap-based buffer overflow in Fortinet's SSL-VPN was actively exploited before disclosure. State-sponsored actors used it to deploy custom implants on critical infrastructure.

Jan 19, 20266 min read
Vulnerability Analysis

GitHub Code Signing Bypass: When the Trust Anchor Fails

A vulnerability in GitHub's commit signature verification allowed attackers to forge signed commits. The flaw undermined the integrity guarantees that code signing is supposed to provide.

Jan 19, 20266 min read
Vulnerability Analysis

Log4Shell RCE in Apache Log4j (CVE-2021-44228)

A deep dive into CVE-2021-44228 (Log4Shell): the critical Log4j RCE vulnerability, its timeline, affected versions, and concrete remediation steps.

Jan 19, 20267 min read
Vulnerability Analysis

Apache Struts2 RCE behind the Equifax breach (CVE-2017-5638)

CVE-2017-5638, the Apache Struts2 RCE behind the Equifax breach, exposed 147.9M records. Here's the flaw, timeline, and how to remediate it.

Jan 19, 20267 min read
Vulnerability Analysis

Heartbleed OpenSSL memory disclosure (CVE-2014-0160)

Heartbleed (CVE-2014-0160) let attackers silently read server memory over TLS. Here's the impact, timeline, remediation, and how to detect lingering exposure today.

Jan 19, 20268 min read
Vulnerability Analysis

Sudo Baron Samedit heap overflow (CVE-2021-3156)

A decade-old sudo heap overflow, CVE-2021-3156 (Baron Samedit), let any local user gain root. Here's what's affected and how to fix it.

Jan 18, 20267 min read
Vulnerability Analysis

Spring4Shell RCE in Spring Framework (CVE-2022-22965)

A deep dive into CVE-2022-22965 (Spring4Shell): the critical Spring Framework RCE, its exploitation chain, timeline, and how to remediate it fast.

Jan 18, 20267 min read
Vulnerability Analysis

Log4j second RCE bypass (CVE-2021-45046)

The Log4j 2.15.0 patch for Log4Shell was incomplete. CVE-2021-45046 shows how attackers bypassed it to achieve remote code execution.

Jan 18, 20267 min read
Vulnerability Analysis

Struts2 OGNL injection RCE (CVE-2018-11776)

CVE-2018-11776 lets remote attackers achieve full RCE in Apache Struts2 via OGNL injection in URL namespaces. Impact, timeline, and fixes inside.

Jan 18, 20267 min read
Page 69 of 79

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.