Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (10491)Vulnerability Analysis (2437)AI Security (789)Application Security (543)Security (523)DevSecOps (511)Tool Comparison (454)Open Source Security (413)Compliance (318)Industry Analysis (311)AppSec (309)Container Security (285)Best Practices (264)Open Source (252)Cloud Security (246)Buyer's Guides (217)Software Supply Chain Security (182)Regulatory Compliance (144)Incident Analysis (141)Vulnerability Management (140)Security Guides (124)Concepts (116)Ranking (116)Product (101)Containers (100)Supply Chain Attacks (93)SBOM (77)Vulnerabilities (72)Threat Intelligence (66)Infrastructure Security (64)Supply Chain Security (55)Supply Chain (55)FAQ (50)Tools (50)SBOM & Compliance (41)Comparisons (32)Engineering (29)Licensing (26)Ransomware (24)Tutorials (24)Guides (22)SecOps (22)Kubernetes Security (22)Regulation (20)Vulnerability Guides (20)Industry Guides (19)Case Studies (18)Compliance & Regulations (18)Emerging Technology (17)Solutions (17)Risk Management (16)Tool Reviews (16)Agent Security (16)Vulnerability Response (16)Threat Research (16)Compliance & Frameworks (15)Identity Security (15)Cryptography (15)Security Concepts (15)Incident Response (15)Industry Events (14)Security Strategy (13)Frameworks (12)Dependency Security (11)Web Security (11)Data Breach (11)Security News (10)Career (10)Enterprise (9)Culture (9)Company (9)Strategy (8)Standards (8)Architecture (8)Zero-Day Exploits (7)Network Security (7)Secure Development (7)How-To Guide (7)Dependency Management (7)Industry Trends (7)Industry Insights (7)Vendor Comparison (6)Dev Practices (6)Developer Security (6)Security Operations (6)Research (6)Organizational Security (6)Industry (6)Breach Analysis (5)Code Security (5)Cryptocurrency Security (4)Offensive Security (4)Policy (4)Product Launch (4)Tool Comparisons (4)Mobile Security (4)Vulnerability Research (3)Hardware Security (3)Social Engineering (3)Policy & Compliance (3)Healthcare Security (3)Build Security (3)Startup Security (3)Governance (3)Regional Security (3)Analysis (3)Software Supply Chain (3)API Security (2)Security Culture (2)Release (2)DeFi Security (2)Zero-Day Analysis (2)Industry News (2)Security Management (2)SBOM Standards (2)Security Architecture (2)SBOM and Compliance (2)Threat Actors (2)Tools & Platforms (1)PKI Security (1)Threat Modeling (1)Threat Analysis (1)Architecture Security (1)Language Security (1)Incident Postmortem (1)Runtime Security (1)Product Update (1)SBOM & Standards (1)Healthcare (1)Lifecycle Management (1)Credential Attacks (1)Career Development (1)Business Continuity (1)Tools & Techniques (1)Data Security (1)Events (1)Privacy & Security (1)Technical (1)Privacy (1)Emerging Threats (1)Nation-State Threats (1)Browser Security (1)

Articles

RSS feed
Vulnerability Analysis

Follina (CVE-2022-30190): The Office Attack That Needed No Macros

A factual look at Follina, a 2022 Windows vulnerability abusing the MSDT protocol handler, which allowed code execution from a Word document without macros and therefore bypassed the standard defensive advice.

Sep 17, 20262 min read
Vulnerability Analysis

Citrix Bleed (CVE-2023-4966): Stolen Sessions That Walked Past MFA

A factual look at Citrix Bleed, a 2023 buffer over-read in NetScaler appliances that leaked valid session tokens, allowing attackers to hijack authenticated sessions without credentials or a second factor.

Sep 17, 20262 min read
Vulnerability Analysis

Patch Lag Explains the Old Breaches. It Does Not Explain the New Ones.

Reviewing two decades of major incidents, the ones that defined early security were patch-adoption failures. A growing share of recent ones had no patch to apply, because the compromise was in the distribution chain itself. These need different defences.

Sep 17, 20264 min read
Vulnerability Analysis

polyfill.io (2024): What Happens When a CDN Domain Changes Hands

A factual account of the 2024 polyfill.io incident, in which a widely embedded JavaScript CDN domain was acquired and began serving malicious code to a large number of websites.

Sep 17, 20262 min read
Vulnerability Analysis

Target (2013): How an HVAC Vendor Became the Path to 40 Million Cards

A factual retrospective on the 2013 Target breach, in which attackers used credentials stolen from a third-party refrigeration contractor to reach the retail network and deploy point-of-sale malware.

Sep 17, 20262 min read
Vulnerability Analysis

SQL Slammer (2003): 376 Bytes That Saturated the Internet in Minutes

A factual retrospective on the January 2003 SQL Slammer worm, which exploited a patched buffer overflow in Microsoft SQL Server and doubled in size every 8.5 seconds, disrupting internet infrastructure globally.

Sep 17, 20262 min read
Vulnerability Analysis

Spring4Shell (CVE-2022-22965): Class Loader Manipulation in Spring Framework

A factual look at Spring4Shell, the March 2022 remote code execution vulnerability in Spring Framework, including why its real-world impact was narrower than the initial Log4Shell comparisons suggested.

Sep 17, 20262 min read
Vulnerability Analysis

Stuxnet (2010): Four Zero-Days Aimed at Industrial Controllers

A factual retrospective on Stuxnet, the malware discovered in 2010 that targeted Siemens PLCs controlling uranium enrichment centrifuges, and why it reset expectations about targeted attacks on physical systems.

Sep 17, 20262 min read
Vulnerability Analysis

Spectre and Meltdown (2018): When the Vulnerability Was in the CPU

A factual explanation of the Spectre and Meltdown speculative execution side-channel vulnerabilities disclosed in January 2018, which affected processors from multiple vendors and could not be fully fixed in software.

Sep 17, 20262 min read

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.