Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (523)AI Security (786)Vulnerability Analysis (689)Security (523)DevSecOps (497)Application Security (490)Open Source Security (412)Industry Analysis (310)AppSec (309)Compliance (304)Container Security (284)Open Source (252)Best Practices (252)Cloud Security (239)Buyer's Guides (216)Software Supply Chain Security (178)Incident Analysis (139)Regulatory Compliance (138)Vulnerability Management (135)Security Guides (124)Concepts (116)Containers (100)Product (100)Supply Chain Attacks (93)SBOM (76)Vulnerabilities (72)Threat Intelligence (65)Supply Chain Security (55)Supply Chain (55)Infrastructure Security (52)FAQ (50)Tools (50)SBOM & Compliance (41)Comparisons (32)Licensing (26)Ransomware (24)Engineering (24)Tutorials (24)Guides (22)Kubernetes Security (22)SecOps (21)Regulation (20)Vulnerability Guides (20)Industry Guides (19)Compliance & Regulations (18)Case Studies (18)Solutions (17)Emerging Technology (17)Risk Management (16)Agent Security (16)Tool Reviews (16)Threat Research (16)Vulnerability Response (16)Identity Security (15)Compliance & Frameworks (15)Security Concepts (15)Cryptography (15)Incident Response (15)Industry Events (14)Security Strategy (13)Frameworks (12)Data Breach (11)Dependency Security (11)Web Security (11)Career (10)Security News (10)Culture (9)Enterprise (9)Company (9)Standards (8)Architecture (8)Strategy (8)Network Security (7)Zero-Day Exploits (7)Dependency Management (7)Industry Insights (7)How-To Guide (7)Secure Development (7)Industry Trends (7)Vendor Comparison (6)Dev Practices (6)Research (6)Security Operations (6)Industry (6)Developer Security (6)Organizational Security (6)Breach Analysis (5)Code Security (5)Offensive Security (4)Cryptocurrency Security (4)Tool Comparisons (4)Policy (4)Mobile Security (4)Tool Comparison (4)Product Launch (4)Social Engineering (3)Software Supply Chain (3)Build Security (3)Policy & Compliance (3)Healthcare Security (3)Hardware Security (3)Startup Security (3)Analysis (3)Vulnerability Research (3)Governance (3)Regional Security (3)Security Architecture (2)SBOM Standards (2)Release (2)Security Management (2)DeFi Security (2)SBOM and Compliance (2)Threat Actors (2)Security Culture (2)API Security (2)Zero-Day Analysis (2)Industry News (2)Career Development (1)Threat Modeling (1)SBOM & Standards (1)Privacy (1)Lifecycle Management (1)Credential Attacks (1)Technical (1)Incident Postmortem (1)Browser Security (1)Product Update (1)Runtime Security (1)Emerging Threats (1)PKI Security (1)Nation-State Threats (1)Architecture Security (1)Tools & Platforms (1)Language Security (1)Privacy & Security (1)Threat Analysis (1)Healthcare (1)Events (1)Tools & Techniques (1)Business Continuity (1)

Articles

RSS feed
Security

Ethical Hacking Workshop: How to Read and Learn Online

Looking to read an ethical hacking workshop online? Here is how to learn ethical hacking legally and safely, what a good curriculum covers, and how it connects to defending real software.

Mar 22, 20266 min read
Security

XXE Attack Demo: Understanding and Defending Against XML External Entities

An XXE attack demo makes the vulnerability click: an XML parser that trusts external entities can be tricked into reading files or making requests. Here is how it works and how to shut it down.

Mar 22, 20265 min read
Security

How Can Malicious Code Do Damage? A Practical Security Guide

Malicious code does damage by abusing the permissions of the process it runs in, then spreading, stealing, or destroying. Here is how each mechanism works and how to blunt it.

Mar 22, 20266 min read
Security

CVE Management for SMEs: A Practical Security Guide

A practical CVE guide for SMEs: what a CVE is, how small and medium teams should triage them without a full security department, and where to focus.

Mar 22, 20266 min read
Security

The Bootstrap Freelancer Theme: A Security Review Before You Ship It

The Bootstrap Freelancer theme is a popular free portfolio template, but shipping it unchanged pulls in front-end dependencies you need to check first.

Mar 22, 20266 min read
Security

Java Deserialization Vulnerabilities: How They Work and How to Stop Them

A practical explanation of the Java deserialization vulnerability class: why untrusted object deserialization leads to remote code execution, and how to defend against it.

Mar 22, 20266 min read
Security

Nginx 1.14.2: Which Vulnerabilities Affect It and How to Upgrade

Nginx/1.14.2 is an end-of-life release carrying the resolver heap overwrite, HTTP/2 DoS flaws, and a request-smuggling bug. Here is what applies and the upgrade path.

Mar 22, 20265 min read
Security

JSON Patch Security: Prototype Pollution and Safe Usage

JSON Patch (RFC 6902) is a compact format for applying partial updates, but implementations like fast-json-patch have had prototype-pollution flaws. Here is how to use it safely.

Mar 21, 20265 min read
Security

Input Validation in Cyber Security: Why It Matters and How to Do It

Input validation is a foundational cyber security control that rejects malformed data at the boundary, cutting off entire classes of injection attacks before they start.

Mar 21, 20265 min read
Page 57 of 59

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.