Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (689)AI Security (786)Vulnerability Analysis (689)Security (523)DevSecOps (497)Application Security (490)Open Source Security (412)Industry Analysis (310)AppSec (309)Compliance (304)Container Security (284)Open Source (252)Best Practices (252)Cloud Security (239)Buyer's Guides (216)Software Supply Chain Security (178)Incident Analysis (139)Regulatory Compliance (138)Vulnerability Management (135)Security Guides (124)Concepts (116)Containers (100)Product (100)Supply Chain Attacks (93)SBOM (76)Vulnerabilities (72)Threat Intelligence (65)Supply Chain Security (55)Supply Chain (55)Infrastructure Security (52)FAQ (50)Tools (50)SBOM & Compliance (41)Comparisons (32)Licensing (26)Ransomware (24)Engineering (24)Tutorials (24)Guides (22)Kubernetes Security (22)SecOps (21)Regulation (20)Vulnerability Guides (20)Industry Guides (19)Compliance & Regulations (18)Case Studies (18)Solutions (17)Emerging Technology (17)Risk Management (16)Agent Security (16)Tool Reviews (16)Threat Research (16)Vulnerability Response (16)Identity Security (15)Compliance & Frameworks (15)Security Concepts (15)Cryptography (15)Incident Response (15)Industry Events (14)Security Strategy (13)Frameworks (12)Data Breach (11)Dependency Security (11)Web Security (11)Career (10)Security News (10)Culture (9)Enterprise (9)Company (9)Standards (8)Architecture (8)Strategy (8)Network Security (7)Zero-Day Exploits (7)Dependency Management (7)Industry Insights (7)How-To Guide (7)Secure Development (7)Industry Trends (7)Vendor Comparison (6)Dev Practices (6)Research (6)Security Operations (6)Industry (6)Developer Security (6)Organizational Security (6)Breach Analysis (5)Code Security (5)Offensive Security (4)Cryptocurrency Security (4)Tool Comparisons (4)Policy (4)Mobile Security (4)Tool Comparison (4)Product Launch (4)Social Engineering (3)Software Supply Chain (3)Build Security (3)Policy & Compliance (3)Healthcare Security (3)Hardware Security (3)Startup Security (3)Analysis (3)Vulnerability Research (3)Governance (3)Regional Security (3)Security Architecture (2)SBOM Standards (2)Release (2)Security Management (2)DeFi Security (2)SBOM and Compliance (2)Threat Actors (2)Security Culture (2)API Security (2)Zero-Day Analysis (2)Industry News (2)Career Development (1)Threat Modeling (1)SBOM & Standards (1)Privacy (1)Lifecycle Management (1)Credential Attacks (1)Technical (1)Incident Postmortem (1)Browser Security (1)Product Update (1)Runtime Security (1)Emerging Threats (1)PKI Security (1)Nation-State Threats (1)Architecture Security (1)Tools & Platforms (1)Language Security (1)Privacy & Security (1)Threat Analysis (1)Healthcare (1)Events (1)Tools & Techniques (1)Business Continuity (1)

Articles

RSS feed
Vulnerability Analysis

Zyxel Router Command Injection: CVE-2024-40891 Exploited in the Wild

Threat actors began mass-exploiting a Telnet-based command injection flaw in Zyxel CPE routers, with over 1,500 devices compromised in botnet campaigns. Zyxel initially refused to patch.

Mar 22, 20265 min read
Vulnerability Analysis

What Are Security Logging and Monitoring Failures

Equifax went undetected for 76 days, Marriott for four years. Here's what security logging and monitoring failures are, why they happen, and how to close the gap.

Mar 22, 20267 min read
Vulnerability Analysis

Use of Components with Known Vulnerabilities

Equifax lost 147M records to one unpatched library. Here's what "components with known vulnerabilities" means and how reachability analysis fixes the triage problem.

Mar 22, 20266 min read
Vulnerability Analysis

SonicWall SMA 1000 Zero-Day: CVE-2025-23006 Pre-Auth RCE

SonicWall disclosed CVE-2025-23006, a critical deserialization vulnerability in its SMA 1000 series gateways that was actively exploited as a zero-day before patches were available.

Mar 20, 20265 min read
Vulnerability Analysis

Citrix NetScaler CVE-2025 Vulnerabilities: Another Year, Another Gateway Crisis

Citrix NetScaler started 2025 with multiple critical CVEs affecting ADC and Gateway products. We break down the technical details and the recurring pattern.

Mar 19, 20266 min read
Vulnerability Analysis

Fortinet FortiGate Authentication Bypass: CVE-2024-55591 Explained

A critical authentication bypass in FortiOS and FortiProxy allowed attackers to gain super-admin privileges via crafted Node.js websocket requests. Here's what happened and how to protect your infrastructure.

Mar 19, 20265 min read
Vulnerability Analysis

Ivanti Connect Secure Zero-Day: CVE-2025-0282 Under Active Exploitation

A stack-based buffer overflow in Ivanti Connect Secure allowed unauthenticated remote code execution. Chinese threat actors exploited it before any patch existed.

Mar 19, 20265 min read
Vulnerability Analysis

Fortinet CVE-2024-21762 Deep Dive: Why SSL-VPN Keeps Producing Critical CVEs

The February 2024 FortiOS SSL-VPN remote code execution vulnerability continues a pattern of high-impact CVEs in edge appliances. A technical retrospective and structural analysis.

Mar 18, 20265 min read
Vulnerability Analysis

Palo Alto Expedition CVE-2024-9463: Command Injection in Migration Tool

Critical command injection vulnerabilities in Palo Alto Networks Expedition tool exposed firewall credentials and configurations, with CISA confirming active exploitation in November 2024.

Mar 14, 20266 min read
Page 57 of 77

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.