Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (7863)AI Security (786)Vulnerability Analysis (577)Security (523)DevSecOps (497)Application Security (490)Open Source Security (412)AppSec (309)Compliance (304)Industry Analysis (295)Container Security (284)Open Source (252)Best Practices (252)Cloud Security (239)Buyer's Guides (216)Software Supply Chain Security (178)Incident Analysis (139)Regulatory Compliance (138)Vulnerability Management (135)Security Guides (124)Concepts (116)Containers (100)Supply Chain Attacks (93)SBOM (76)Vulnerabilities (72)Product (69)Threat Intelligence (65)Supply Chain Security (55)Supply Chain (55)Infrastructure Security (52)Tools (50)FAQ (50)SBOM & Compliance (41)Comparisons (32)Licensing (26)Tutorials (24)Ransomware (24)Engineering (24)Guides (22)Kubernetes Security (22)SecOps (21)Vulnerability Guides (20)Regulation (20)Industry Guides (19)Case Studies (18)Compliance & Regulations (18)Emerging Technology (17)Solutions (17)Threat Research (16)Risk Management (16)Vulnerability Response (16)Tool Reviews (16)Agent Security (16)Security Concepts (15)Cryptography (15)Identity Security (15)Incident Response (15)Compliance & Frameworks (15)Industry Events (14)Security Strategy (13)Frameworks (12)Dependency Security (11)Web Security (11)Data Breach (11)Career (10)Enterprise (9)Company (9)Culture (9)Architecture (8)Strategy (8)Standards (8)Industry Trends (7)How-To Guide (7)Secure Development (7)Industry Insights (7)Dependency Management (7)Zero-Day Exploits (7)Network Security (7)Research (6)Organizational Security (6)Vendor Comparison (6)Dev Practices (6)Industry (6)Security Operations (6)Developer Security (6)Code Security (5)Breach Analysis (5)Policy (4)Cryptocurrency Security (4)Tool Comparisons (4)Offensive Security (4)Mobile Security (4)Tool Comparison (4)Product Launch (4)Analysis (3)Social Engineering (3)Build Security (3)Startup Security (3)Policy & Compliance (3)Hardware Security (3)Governance (3)Software Supply Chain (3)Healthcare Security (3)Vulnerability Research (3)Regional Security (3)Threat Actors (2)Security Culture (2)Security Architecture (2)API Security (2)Zero-Day Analysis (2)SBOM Standards (2)Security Management (2)Release (2)Industry News (2)SBOM and Compliance (2)DeFi Security (2)Tools & Techniques (1)Healthcare (1)Emerging Threats (1)Tools & Platforms (1)Architecture Security (1)Lifecycle Management (1)Privacy (1)Product Update (1)Runtime Security (1)Technical (1)Nation-State Threats (1)Credential Attacks (1)Threat Analysis (1)Incident Postmortem (1)Career Development (1)Privacy & Security (1)Threat Modeling (1)Business Continuity (1)Browser Security (1)Events (1)PKI Security (1)Language Security (1)SBOM & Standards (1)

Articles

RSS feed
AppSec

VAPT Tools: The Vulnerability Assessment and Penetration Testing Toolkit

VAPT tools are the software used to run vulnerability assessment and penetration testing. Here is what belongs in the toolkit, how the categories differ, and how to pick the right tool for the job.

Jul 28, 20266 min read
AppSec

Code Security Scanners: Choosing One for Your Stack

The right code security scanner depends less on which vendor's marketing sounds best and more on language coverage, false-positive rate, and whether it fits into the workflow developers already use.

Jul 28, 20265 min read
Concepts

What Is a Build Artifact?

A build artifact is the packaged output your build process produces from source code. Here is why artifacts are a critical supply chain checkpoint and how to verify their provenance.

Jul 28, 20266 min read
Open Source Security

node-tar Arbitrary File Write via Symlink Extraction (CVE...

CVE-2021-32803 allows crafted symlinks in tar archives to make node-tar write files outside the extraction directory via malicious npm packages.

Jul 28, 20267 min read
Vulnerability Analysis

Python Pickle deserialization risk explained

Pickle deserialization lets attacker-controlled data execute arbitrary code on load. Here's how the exploit works, real CVEs, and how to fix it.

Jul 28, 20267 min read
Software Supply Chain Security

Every Supply Chain Attack of June and July 2026 Was After the Same Thing

Nine incidents in eight weeks: a PyPI worm, typosquatted payment SDKs, jscrambler, AsyncAPI, Hugging Face, Polymarket, Nx Console, Medtronic, AdaptHealth. Nine different vectors, one prize — credentials sitting in developer environments and build pipelines. If you fix one thing this quarter, fix that.

Jul 28, 20268 min read
Compliance

Medtronic and AdaptHealth: The Third Party Was the Vulnerability

3.8 million people notified by Medtronic. PII, PHI and insurance billing credentials exfiltrated at AdaptHealth after social engineering against a third-party contractor. Neither breach needed a software vulnerability — both needed a trusted outsider with a session.

Jul 28, 20266 min read
DevSecOps

Eighteen Minutes: The Nx Console Extension Compromise and the IDE Blind Spot

A poisoned VS Code extension was live for eighteen minutes. In that window, auto-update pushed it into every developer environment with Nx Console installed — including a GitHub employee's device, leading to exfiltration of internal GitHub repositories. Your IDE extensions have no SBOM, no review, and a direct push channel to your engineers.

Jul 28, 20266 min read
Open Source Security

node-tar Second Bypass Enabling Arbitrary File Write (CVE...

CVE-2021-32804 let crafted tar archives bypass node-tar path sanitization, enabling arbitrary file writes during npm package extraction.

Jul 28, 20267 min read
Page 31 of 874

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

Blog (Page 31) | Safeguard — Software Supply Chain Security Insights