Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (2437)Vulnerability Analysis (2437)AI Security (786)Security (523)DevSecOps (497)Application Security (490)Tool Comparison (454)Open Source Security (412)Industry Analysis (310)AppSec (309)Compliance (304)Container Security (284)Best Practices (252)Open Source (252)Cloud Security (239)Buyer's Guides (216)Software Supply Chain Security (178)Incident Analysis (139)Regulatory Compliance (138)Vulnerability Management (136)Security Guides (124)Ranking (116)Concepts (116)Product (101)Containers (100)Supply Chain Attacks (93)SBOM (76)Vulnerabilities (72)Threat Intelligence (66)Supply Chain (55)Supply Chain Security (55)Infrastructure Security (52)Tools (50)FAQ (50)SBOM & Compliance (41)Comparisons (32)Licensing (26)Engineering (24)Ransomware (24)Tutorials (24)Kubernetes Security (22)Guides (22)SecOps (21)Regulation (20)Vulnerability Guides (20)Industry Guides (19)Case Studies (18)Compliance & Regulations (18)Emerging Technology (17)Solutions (17)Agent Security (16)Vulnerability Response (16)Tool Reviews (16)Risk Management (16)Threat Research (16)Security Concepts (15)Compliance & Frameworks (15)Identity Security (15)Incident Response (15)Cryptography (15)Industry Events (14)Security Strategy (13)Frameworks (12)Data Breach (11)Dependency Security (11)Web Security (11)Career (10)Security News (10)Culture (9)Enterprise (9)Company (9)Architecture (8)Strategy (8)Standards (8)Industry Insights (7)Network Security (7)Industry Trends (7)How-To Guide (7)Dependency Management (7)Secure Development (7)Zero-Day Exploits (7)Industry (6)Security Operations (6)Vendor Comparison (6)Organizational Security (6)Dev Practices (6)Research (6)Developer Security (6)Breach Analysis (5)Code Security (5)Offensive Security (4)Product Launch (4)Tool Comparisons (4)Policy (4)Mobile Security (4)Cryptocurrency Security (4)Startup Security (3)Healthcare Security (3)Governance (3)Software Supply Chain (3)Analysis (3)Vulnerability Research (3)Hardware Security (3)Regional Security (3)Build Security (3)Policy & Compliance (3)Social Engineering (3)Industry News (2)Security Culture (2)Zero-Day Analysis (2)SBOM Standards (2)Security Architecture (2)DeFi Security (2)SBOM and Compliance (2)API Security (2)Security Management (2)Threat Actors (2)Release (2)Incident Postmortem (1)Architecture Security (1)Career Development (1)Privacy & Security (1)Emerging Threats (1)Threat Modeling (1)Business Continuity (1)Nation-State Threats (1)Runtime Security (1)Tools & Platforms (1)Product Update (1)Language Security (1)Privacy (1)PKI Security (1)Healthcare (1)Technical (1)Threat Analysis (1)SBOM & Standards (1)Tools & Techniques (1)Lifecycle Management (1)Browser Security (1)Credential Attacks (1)Events (1)

Articles

RSS feed
Vulnerability Analysis

Follina (CVE-2022-30190): The Microsoft Zero-Day That Bypassed Macro Protections

A Word document, no macros enabled, and full remote code execution. Follina exploited the Microsoft Support Diagnostic Tool via ms-msdt protocol handlers, rendering years of macro-blocking defenses irrelevant.

Jan 10, 20267 min read
Vulnerability Analysis

Confluence Zero-Day (CVE-2022-26134): Atlassian's OGNL Injection Crisis

An unauthenticated RCE zero-day in Confluence Server was being actively exploited before Atlassian even knew about it. The vulnerability affected virtually every on-premise Confluence installation.

Jan 9, 20265 min read
Vulnerability Analysis

Log4Shell Five Years Later: What CVE-2021-44228 Taught Us About Transitive Risk

Five years after Log4Shell, the technical details still matter, but the lasting lessons are about transitive dependencies, SBOM accuracy, and the long tail of unpatched internal tooling.

Jan 9, 20265 min read
Vulnerability Analysis

Kubernetes API server privilege escalation via aggregated API (CVE-2018-1002105)

A critical flaw in Kubernetes' aggregated API let unauthenticated users gain full admin privileges. Here's how it worked and how to fix it.

Jan 9, 20267 min read
Vulnerability Analysis

Red Hat JBoss Vulnerability Exploitation: The Persistent Threat of Java Middleware

JBoss application servers have been a recurring target for attackers. From deserialization flaws to exposed management interfaces, the middleware layer remains a critical attack surface.

Jan 9, 20266 min read
Vulnerability Analysis

runc container escape via file descriptor overwrite (CVE-2019-5736)

CVE-2019-5736 let malicious containers overwrite the host runc binary and gain root — here's the mechanism, affected versions, and how to remediate it.

Jan 9, 20267 min read
Vulnerability Analysis

Linux cgroups release_agent container escape (CVE-2022-0492)

CVE-2022-0492 lets containers with CAP_SYS_ADMIN escape via cgroup v1's release_agent. Impact, timeline, and concrete remediation steps inside.

Jan 9, 20267 min read
Vulnerability Analysis

containerd-shim abstract Unix socket container escape (CVE-2020-15257)

CVE-2020-15257 let containers sharing a host network namespace abuse containerd-shim's abstract socket API. Here's the impact, fix, and remediation path.

Jan 9, 20267 min read
Vulnerability Analysis

Windows MSHTML Spoofing CVE-2024-43573 Explained

CVE-2024-43573 is a zero-day MSHTML spoofing flaw patched by Microsoft in October 2024. Here is the chain, detection, and why MSHTML keeps biting.

Jan 9, 20267 min read

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.