Security
In-depth guides and analysis on security from the Safeguard engineering team.
521 articles
Define Agentic: What 'Agentic' Really Means for Security
To define agentic: it describes AI systems that plan and take actions toward a goal with limited human oversight. Here is what that autonomy means for security teams.
Container Security: Why Reachability Analysis Changes Everything
Stop chasing phantom vulnerabilities. Learn how reachability analysis reduces CVE noise by 80% and focuses remediation on what actually matters.
CVE-2023-5752: Command Injection in pip via Mercurial Revisions
Installing a package from a Mercurial URL with a crafted revision let attackers inject hg config options. Here is how CVE-2023-5752 works and how to fix it.
eslint-plugin-unused-imports: Cleaner Code, Smaller Surface
eslint-plugin-unused-imports auto-removes dead imports that the base ESLint rule only warns about. Here is how to configure it correctly on ESLint 9.
Application Data Security: How to Protect Data Across Its Lifecycle
Application data security is the set of controls that protect data as your application collects, processes, stores, and transmits it. Here is a practical model for getting it right.
Black Duck Competitors: The Top SCA Alternatives Compared
A fair look at the main Black Duck competitors in software composition analysis — Snyk, Mend, Sonatype, Endor Labs, and others — and which fits which job.
CVE-2023-22102: The MySQL Connector/J Takeover Vulnerability
CVE-2023-22102 is a High-severity flaw in Oracle's MySQL Connector/J that can lead to connector takeover. Here is the root cause and how to remediate it.
Hacking Software: What It Is and How Defenders Use It Legally
Hacking software is the category of programs used to test and break into systems. Used with authorization, it is how security teams find their own weaknesses first.
NVD vs CVE: What's the Difference?
CVE is the list of vulnerability identifiers; the NVD is the enriched database built on top of it. They are related but run by different programs, and confusing them leads to real mistakes.
CVE Full Form Explained: What CVE Actually Stands For
The CVE full form is Common Vulnerabilities and Exposures, a public catalog of known security flaws. Here is what the term means, how the IDs work, and why it matters.
Malicious Code Detection: How to Catch Threats in Your Supply Chain
Malicious code detection is the practice of identifying deliberately harmful code in your dependencies, containers, and repositories before it runs. Here is how modern detection actually works.
How to Choose Vulnerability Assessment Solutions That Actually Reduce Risk
Most vulnerability assessment solutions generate more findings than any team can fix. The right choice depends on what you're protecting — code, dependencies, containers, or infrastructure.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.