Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (10491)Vulnerability Analysis (2437)AI Security (789)Application Security (543)Security (523)DevSecOps (511)Tool Comparison (454)Open Source Security (413)Compliance (318)Industry Analysis (311)AppSec (309)Container Security (285)Best Practices (264)Open Source (252)Cloud Security (246)Buyer's Guides (217)Software Supply Chain Security (182)Regulatory Compliance (144)Incident Analysis (141)Vulnerability Management (140)Security Guides (124)Concepts (116)Ranking (116)Product (101)Containers (100)Supply Chain Attacks (93)SBOM (77)Vulnerabilities (72)Threat Intelligence (66)Infrastructure Security (64)Supply Chain Security (55)Supply Chain (55)FAQ (50)Tools (50)SBOM & Compliance (41)Comparisons (32)Engineering (29)Licensing (26)Ransomware (24)Tutorials (24)Guides (22)SecOps (22)Kubernetes Security (22)Regulation (20)Vulnerability Guides (20)Industry Guides (19)Case Studies (18)Compliance & Regulations (18)Emerging Technology (17)Solutions (17)Risk Management (16)Tool Reviews (16)Agent Security (16)Vulnerability Response (16)Threat Research (16)Compliance & Frameworks (15)Identity Security (15)Cryptography (15)Security Concepts (15)Incident Response (15)Industry Events (14)Security Strategy (13)Frameworks (12)Dependency Security (11)Web Security (11)Data Breach (11)Security News (10)Career (10)Enterprise (9)Culture (9)Company (9)Strategy (8)Standards (8)Architecture (8)Zero-Day Exploits (7)Network Security (7)Secure Development (7)How-To Guide (7)Dependency Management (7)Industry Trends (7)Industry Insights (7)Vendor Comparison (6)Dev Practices (6)Developer Security (6)Security Operations (6)Research (6)Organizational Security (6)Industry (6)Breach Analysis (5)Code Security (5)Cryptocurrency Security (4)Offensive Security (4)Policy (4)Product Launch (4)Tool Comparisons (4)Mobile Security (4)Vulnerability Research (3)Hardware Security (3)Social Engineering (3)Policy & Compliance (3)Healthcare Security (3)Build Security (3)Startup Security (3)Governance (3)Regional Security (3)Analysis (3)Software Supply Chain (3)API Security (2)Security Culture (2)Release (2)DeFi Security (2)Zero-Day Analysis (2)Industry News (2)Security Management (2)SBOM Standards (2)Security Architecture (2)SBOM and Compliance (2)Threat Actors (2)Tools & Platforms (1)PKI Security (1)Threat Modeling (1)Threat Analysis (1)Architecture Security (1)Language Security (1)Incident Postmortem (1)Runtime Security (1)Product Update (1)SBOM & Standards (1)Healthcare (1)Lifecycle Management (1)Credential Attacks (1)Career Development (1)Business Continuity (1)Tools & Techniques (1)Data Security (1)Events (1)Privacy & Security (1)Technical (1)Privacy (1)Emerging Threats (1)Nation-State Threats (1)Browser Security (1)

Articles

RSS feed
Vulnerability Analysis

MOVEit Transfer (CVE-2023-34362): A Mass Exploitation Data-Theft Campaign

A factual look at the 2023 Cl0p ransomware group campaign exploiting a SQL injection vulnerability in Progress Software MOVEit Transfer to steal data from hundreds of organizations.

Sep 17, 20262 min read
Vulnerability Analysis

NotPetya (2017): A Supply Chain Wiper Disguised as Ransomware

A factual retrospective on the June 2017 NotPetya attack, distributed through a compromised update to Ukrainian accounting software M.E.Doc, which caused billions in damages worldwide.

Sep 17, 20262 min read
Vulnerability Analysis

Kaseya VSA (2021): A Supply Chain Ransomware Attack via MSP Tooling

A factual look at the July 2021 Kaseya VSA supply chain attack, in which REvil affiliates exploited a zero-day to deploy ransomware through managed service provider software to downstream customers.

Sep 17, 20262 min read
Vulnerability Analysis

Shellshock (CVE-2014-6271): The Bash Vulnerability That Hit CGI Scripts and Embedded Devices

A factual retrospective on Shellshock, the September 2014 Bash vulnerability that allowed remote code execution through crafted environment variables, affecting web servers and countless embedded devices.

Sep 17, 20262 min read
Vulnerability Analysis

The XZ Utils Backdoor (CVE-2024-3094): A Near-Miss Supply Chain Attack

A factual retrospective on the March 2024 discovery of a deliberately planted backdoor in XZ Utils, inserted over a multi-year social-engineering campaign against the open-source maintainer.

Sep 16, 20262 min read
Vulnerability Analysis

The 2017 Equifax Breach: Apache Struts CVE-2017-5638 and Patch Management Failure

A factual look at the 2017 Equifax data breach, traced to an unpatched Apache Struts remote code execution vulnerability, and its role in shaping enterprise vulnerability management practices.

Sep 16, 20262 min read
Vulnerability Analysis

WannaCry (2017): How EternalBlue and MS17-010 Enabled a Global Ransomware Worm

A factual retrospective on the May 2017 WannaCry ransomware outbreak, which spread using the EternalBlue exploit for the SMBv1 vulnerability patched as MS17-010.

Sep 16, 20262 min read
Vulnerability Analysis

The SolarWinds Orion Supply Chain Attack: What Actually Happened

A factual summary of the 2020 SolarWinds Orion compromise, in which attackers inserted malicious code into a legitimate software update, and what it means for build-pipeline integrity.

Sep 16, 20262 min read
Vulnerability Analysis

Log4Shell (CVE-2021-44228): The Log4j RCE and Its Supply Chain Lesson

A factual look at Log4Shell, the critical remote code execution vulnerability in Apache Log4j disclosed in December 2021, and why it became a defining supply chain security event.

Sep 16, 20262 min read

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.