Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (8627)AI Security (786)Vulnerability Analysis (716)Security (523)DevSecOps (497)Application Security (490)Tool Comparison (454)Open Source Security (412)Industry Analysis (310)AppSec (309)Compliance (304)Container Security (284)Open Source (252)Best Practices (252)Cloud Security (239)Buyer's Guides (216)Software Supply Chain Security (178)Incident Analysis (139)Regulatory Compliance (138)Vulnerability Management (136)Security Guides (124)Ranking (116)Concepts (116)Product (101)Containers (100)Supply Chain Attacks (93)SBOM (76)Vulnerabilities (72)Threat Intelligence (66)Supply Chain Security (55)Supply Chain (55)Infrastructure Security (52)Tools (50)FAQ (50)SBOM & Compliance (41)Comparisons (32)Licensing (26)Tutorials (24)Engineering (24)Ransomware (24)Guides (22)Kubernetes Security (22)SecOps (21)Vulnerability Guides (20)Regulation (20)Industry Guides (19)Compliance & Regulations (18)Case Studies (18)Emerging Technology (17)Solutions (17)Threat Research (16)Risk Management (16)Vulnerability Response (16)Tool Reviews (16)Agent Security (16)Compliance & Frameworks (15)Identity Security (15)Incident Response (15)Security Concepts (15)Cryptography (15)Industry Events (14)Security Strategy (13)Frameworks (12)Dependency Security (11)Data Breach (11)Web Security (11)Career (10)Security News (10)Enterprise (9)Company (9)Culture (9)Strategy (8)Architecture (8)Standards (8)Zero-Day Exploits (7)Industry Insights (7)How-To Guide (7)Network Security (7)Dependency Management (7)Industry Trends (7)Secure Development (7)Developer Security (6)Vendor Comparison (6)Dev Practices (6)Organizational Security (6)Security Operations (6)Industry (6)Research (6)Code Security (5)Breach Analysis (5)Tool Comparisons (4)Policy (4)Mobile Security (4)Cryptocurrency Security (4)Offensive Security (4)Product Launch (4)Software Supply Chain (3)Governance (3)Analysis (3)Hardware Security (3)Regional Security (3)Startup Security (3)Social Engineering (3)Build Security (3)Healthcare Security (3)Vulnerability Research (3)Policy & Compliance (3)Threat Actors (2)Industry News (2)Security Architecture (2)API Security (2)SBOM Standards (2)Zero-Day Analysis (2)Release (2)DeFi Security (2)Security Culture (2)SBOM and Compliance (2)Security Management (2)Runtime Security (1)Browser Security (1)Product Update (1)Architecture Security (1)PKI Security (1)Events (1)Privacy (1)Language Security (1)Tools & Platforms (1)Emerging Threats (1)Incident Postmortem (1)Career Development (1)Credential Attacks (1)Threat Analysis (1)Privacy & Security (1)Healthcare (1)Nation-State Threats (1)Lifecycle Management (1)Business Continuity (1)Threat Modeling (1)Tools & Techniques (1)SBOM & Standards (1)Technical (1)

Articles

RSS feed
Vulnerability Analysis

Samsung's Year: A Signage Server Bug and a Codec Library Hit Twice for Spyware

Three confirmed-exploited Samsung vulnerabilities span an enterprise digital signage server and a mobile image codec library hit twice in five months, one tied to commercial-grade Android spyware.

Sep 16, 20265 min read
Vulnerability Analysis

A 2016 SKYSEA Client View Bug Was Confirmed Exploited Nine Years Later

CVE-2016-7836, a critical authentication flaw in a Japanese endpoint management console, sat disclosed for nearly a decade before CISA confirmed active exploitation in October 2025.

Sep 16, 20265 min read
Vulnerability Analysis

GeoServer's WMS Endpoint Adds Another XXE to Its Exploitation History

CVE-2025-58360 lets attackers define external XML entities through GeoServer's GetMap operation — the latest confirmed-exploited bug in a geospatial server long favored by less security-mature operators.

Sep 16, 20264 min read
Vulnerability Analysis

F5, Check Point, Versa, and Arista: Four Vendors, One Edge Infrastructure Problem

A BIG-IP APM buffer overflow, a ransomware-linked Check Point VPN authentication bypass, a Versa Concerto proxy misconfiguration, and an Arista EOS tunnel decapsulation flaw all failed at the same job: enforcing a boundary.

Sep 16, 20265 min read
Vulnerability Analysis

Langflow and Marimo: When the AI Platform's Core Feature Is the Vulnerability

Three confirmed-exploited CVEs across Langflow and Marimo show what happens when a code-execution-by-design platform ships an authentication gap on the endpoint meant to guard it.

Sep 16, 20265 min read
Vulnerability Analysis

Two PAN-OS Vulnerabilities Target Palo Alto's Front Doors: GlobalProtect and Captive Portal

A root-privilege buffer overflow in the User-ID Authentication Portal and a GlobalProtect authentication bypass confirmed for ransomware use, both hitting PAN-OS's remote-access surface within weeks of each other.

Sep 16, 20264 min read
Vulnerability Analysis

Android Framework and Qualcomm Chipsets: Four CVEs Across the Mobile Stack

Three Android Framework privilege-escalation bugs and a Qualcomm chipset memory corruption flaw, confirmed exploited across the software and silicon layers of the Android ecosystem.

Sep 16, 20265 min read
Vulnerability Analysis

From a 2010 Firefox Bug to a 2025 Vite Dev-Server Flaw: Four Unrelated Products, One Lesson

An industrial controller authentication bypass, an EoL cellular gateway RCE, a fifteen-year-old browser bug, and a Vite dev-server exposure — none related, all confirmed exploited.

Sep 16, 20266 min read
Vulnerability Analysis

How a Non-Atomic Credential Rotation Let Attackers Take Over 76 Trivy Action Tags

A compromised-credential attack on Aquasecurity's Trivy scanner force-pushed malware into version tags across trivy-action and setup-trivy, exploiting the gap left by an earlier, incomplete rotation.

Sep 16, 20265 min read
Page 76 of 959

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.