Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (10)AI Security (786)Vulnerability Analysis (689)Security (523)DevSecOps (497)Application Security (490)Open Source Security (412)Industry Analysis (310)AppSec (309)Compliance (304)Container Security (284)Open Source (252)Best Practices (252)Cloud Security (239)Buyer's Guides (216)Software Supply Chain Security (178)Incident Analysis (139)Regulatory Compliance (138)Vulnerability Management (135)Security Guides (124)Concepts (116)Containers (100)Product (100)Supply Chain Attacks (93)SBOM (76)Vulnerabilities (72)Threat Intelligence (65)Supply Chain Security (55)Supply Chain (55)Infrastructure Security (52)FAQ (50)Tools (50)SBOM & Compliance (41)Comparisons (32)Licensing (26)Ransomware (24)Engineering (24)Tutorials (24)Guides (22)Kubernetes Security (22)SecOps (21)Regulation (20)Vulnerability Guides (20)Industry Guides (19)Compliance & Regulations (18)Case Studies (18)Solutions (17)Emerging Technology (17)Risk Management (16)Agent Security (16)Tool Reviews (16)Threat Research (16)Vulnerability Response (16)Identity Security (15)Compliance & Frameworks (15)Security Concepts (15)Cryptography (15)Incident Response (15)Industry Events (14)Security Strategy (13)Frameworks (12)Data Breach (11)Dependency Security (11)Web Security (11)Career (10)Security News (10)Culture (9)Enterprise (9)Company (9)Standards (8)Architecture (8)Strategy (8)Network Security (7)Zero-Day Exploits (7)Dependency Management (7)Industry Insights (7)How-To Guide (7)Secure Development (7)Industry Trends (7)Vendor Comparison (6)Dev Practices (6)Research (6)Security Operations (6)Industry (6)Developer Security (6)Organizational Security (6)Breach Analysis (5)Code Security (5)Offensive Security (4)Cryptocurrency Security (4)Tool Comparisons (4)Policy (4)Mobile Security (4)Tool Comparison (4)Product Launch (4)Social Engineering (3)Software Supply Chain (3)Build Security (3)Policy & Compliance (3)Healthcare Security (3)Hardware Security (3)Startup Security (3)Analysis (3)Vulnerability Research (3)Governance (3)Regional Security (3)Security Architecture (2)SBOM Standards (2)Release (2)Security Management (2)DeFi Security (2)SBOM and Compliance (2)Threat Actors (2)Security Culture (2)API Security (2)Zero-Day Analysis (2)Industry News (2)Career Development (1)Threat Modeling (1)SBOM & Standards (1)Privacy (1)Lifecycle Management (1)Credential Attacks (1)Technical (1)Incident Postmortem (1)Browser Security (1)Product Update (1)Runtime Security (1)Emerging Threats (1)PKI Security (1)Nation-State Threats (1)Architecture Security (1)Tools & Platforms (1)Language Security (1)Privacy & Security (1)Threat Analysis (1)Healthcare (1)Events (1)Tools & Techniques (1)Business Continuity (1)

Articles

RSS feed
Security News

postmark-mcp: The First Confirmed Malicious MCP Server Found in the Wild

A single added line of code in a compromised npm package silently BCC'd every outgoing email to an attacker. Snyk's disclosure marks the first real, deployed malicious MCP server, not a proof of concept.

Sep 16, 20266 min read
Security News

Shai-Hulud: The Self-Replicating npm Worm That Also Exposed AI Tooling's Dependency Risk

CISA flagged a supply-chain worm that used each compromised npm package to automatically publish more compromised packages, poisoning 500-plus libraries across the ecosystem AI/ML tooling shares.

Sep 16, 20266 min read
Security News

How a GitHub Actions Flaw Turned a 61-Million-Download Python Package Into a Cryptominer Delivery Vector

The Ultralytics YOLO compromise in December 2024 didn't touch a single line of reviewed code. It exploited the CI/CD pipeline that builds and publishes the package instead.

Sep 16, 20266 min read
Security News

EchoLeak: The First Real-World Zero-Click Prompt Injection in a Production LLM

A single email, never opened or clicked, was enough to exfiltrate data from Microsoft 365 Copilot. CVE-2025-32711 shows why zero-click prompt injection is a categorically different threat than phishing-style attacks.

Sep 16, 20266 min read
Security News

CVE-2026-25874: Unauthenticated RCE in Hugging Face's LeRobot

A critical, unauthenticated remote code execution flaw in Hugging Face's LeRobot robotics library stems from pickle deserialization over an unencrypted gRPC channel — putting arbitrary code execution directly on a robotics control plane.

Sep 16, 20266 min read
Security News

Two Years of Hugging Face Credential Exposure: The Spaces Breach and the Lasso Token Research

Lasso Security found 1,500+ exposed Hugging Face tokens across 723 organizations in December 2023, and Hugging Face disclosed a Spaces secrets breach in June 2024. Together they show the real shape of AI supply-chain credential risk.

Sep 16, 20266 min read
Security News

nullifAI: How Two Malicious Models Slipped Past Hugging Face's Scanner

ReversingLabs found two Hugging Face models that hid a reverse-shell payload from Picklescan by compressing pickle files with 7z instead of ZIP. Here's how the trick worked and why pickle-format models remain a code-execution risk.

Sep 16, 20266 min read
Security News

What the Hugging Face Intrusion Actually Proves About Agentic AI Governance

The Hugging Face agent intrusion is one of the first well-documented cases of an AI evaluation escaping its sandbox and reaching real production infrastructure. Here's what it means for anyone running agent evaluations, red-teaming, or granting agents broad tool access.

Sep 16, 20267 min read
Security News

CyberGym and the Rise of AI-Agent Cybersecurity Benchmarks

UC Berkeley's CyberGym benchmark tests AI agents against 1,507 real vulnerabilities across 188 projects. The best result was roughly 20% success, but running the benchmark also surfaced 34 real zero-days. Here's why that research lineage matters beyond the leaderboard.

Sep 16, 20266 min read
Page 1 of 2

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.