Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (10491)Vulnerability Analysis (2437)AI Security (789)Application Security (543)Security (523)DevSecOps (511)Tool Comparison (454)Open Source Security (413)Compliance (318)Industry Analysis (311)AppSec (309)Container Security (285)Best Practices (264)Open Source (252)Cloud Security (246)Buyer's Guides (217)Software Supply Chain Security (182)Regulatory Compliance (144)Incident Analysis (141)Vulnerability Management (140)Security Guides (124)Concepts (116)Ranking (116)Product (101)Containers (100)Supply Chain Attacks (93)SBOM (77)Vulnerabilities (72)Threat Intelligence (66)Infrastructure Security (64)Supply Chain Security (55)Supply Chain (55)FAQ (50)Tools (50)SBOM & Compliance (41)Comparisons (32)Engineering (29)Licensing (26)Ransomware (24)Tutorials (24)Guides (22)SecOps (22)Kubernetes Security (22)Regulation (20)Vulnerability Guides (20)Industry Guides (19)Case Studies (18)Compliance & Regulations (18)Emerging Technology (17)Solutions (17)Risk Management (16)Tool Reviews (16)Agent Security (16)Vulnerability Response (16)Threat Research (16)Compliance & Frameworks (15)Identity Security (15)Cryptography (15)Security Concepts (15)Incident Response (15)Industry Events (14)Security Strategy (13)Frameworks (12)Dependency Security (11)Web Security (11)Data Breach (11)Security News (10)Career (10)Enterprise (9)Culture (9)Company (9)Strategy (8)Standards (8)Architecture (8)Zero-Day Exploits (7)Network Security (7)Secure Development (7)How-To Guide (7)Dependency Management (7)Industry Trends (7)Industry Insights (7)Vendor Comparison (6)Dev Practices (6)Developer Security (6)Security Operations (6)Research (6)Organizational Security (6)Industry (6)Breach Analysis (5)Code Security (5)Cryptocurrency Security (4)Offensive Security (4)Policy (4)Product Launch (4)Tool Comparisons (4)Mobile Security (4)Vulnerability Research (3)Hardware Security (3)Social Engineering (3)Policy & Compliance (3)Healthcare Security (3)Build Security (3)Startup Security (3)Governance (3)Regional Security (3)Analysis (3)Software Supply Chain (3)API Security (2)Security Culture (2)Release (2)DeFi Security (2)Zero-Day Analysis (2)Industry News (2)Security Management (2)SBOM Standards (2)Security Architecture (2)SBOM and Compliance (2)Threat Actors (2)Tools & Platforms (1)PKI Security (1)Threat Modeling (1)Threat Analysis (1)Architecture Security (1)Language Security (1)Incident Postmortem (1)Runtime Security (1)Product Update (1)SBOM & Standards (1)Healthcare (1)Lifecycle Management (1)Credential Attacks (1)Career Development (1)Business Continuity (1)Tools & Techniques (1)Data Security (1)Events (1)Privacy & Security (1)Technical (1)Privacy (1)Emerging Threats (1)Nation-State Threats (1)Browser Security (1)

Articles

RSS feed
AI Security

LLM-assisted vulnerability autofixing: approaches and how to validate the patches

At DARPA's AIxCC finals in August 2025, AI systems patched 68% of vulnerabilities they found — up from 25% at semifinals. Here's how the approaches differ and why validation still matters most.

Jul 8, 20267 min read
AI Security

Why static scanners miss malicious AI agent skills

In April 2025, Invariant Labs showed a malicious MCP tool description could exfiltrate an SSH key — with zero suspicious code for a static scanner to flag.

Jul 8, 20266 min read
Application Security

LDAP injection: a technical primer and defense guide

LDAP injection is CWE-90, dates to the same root cause as SQL injection, and still shipped in production software as recently as CVE-2023-0476.

Jul 8, 20266 min read
Kubernetes Security

Designing Least-Privilege Kubernetes RBAC: A Practical Guide

CVE-2018-1002105 (CVSS 9.8) let an unauthenticated request reach cluster-admin through pod exec endpoints — most RBAC breaches since trace back to the same handful of over-broad bindings.

Jul 8, 20267 min read
Application Security

Secure JWT handling: algorithm confusion, expiry, and storage done right

A single unchecked `alg` header turned jsonwebtoken into a forgeable token in CVE-2015-9235 — here's how to close every hole RFC 8725 warns about.

Jul 8, 20266 min read
Application Security

Wiring dependency and SAST scanning into your JavaScript CLI workflow

npm audit has shipped for free since npm 6 in 2018, yet most JavaScript teams still find out about vulnerable dependencies in a Slack alert, not a failed commit.

Jul 8, 20267 min read
Best Practices

Getting AES right in Java: JCA/JCE mistakes that break your encryption

Call `Cipher.getInstance("AES")` in Java and you silently get ECB mode — no warning, no error, just plaintext patterns leaking through.

Jul 8, 20267 min read
Application Security

Java SecurityManager is gone: a practical migration guide

JEP 411 deprecated the Security Manager in JDK 17; JEP 486 disabled it outright in JDK 24, released March 18, 2025. Here's how to migrate before it's removed for good.

Jul 8, 20267 min read
Best Practices

Defensive Java: coding patterns that stop NullPointerExceptions from becoming outages

NPE has been Java's most common runtime exception since JDK 1.0 in 1996 — Optional, JSpecify annotations, and static analysis can turn most of them into compile-time errors.

Jul 8, 20267 min read

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.