Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (7863)AI Security (786)Vulnerability Analysis (577)Security (523)DevSecOps (497)Application Security (490)Open Source Security (412)AppSec (309)Compliance (304)Industry Analysis (295)Container Security (284)Open Source (252)Best Practices (252)Cloud Security (239)Buyer's Guides (216)Software Supply Chain Security (178)Incident Analysis (139)Regulatory Compliance (138)Vulnerability Management (135)Security Guides (124)Concepts (116)Containers (100)Supply Chain Attacks (93)SBOM (76)Vulnerabilities (72)Product (69)Threat Intelligence (65)Supply Chain Security (55)Supply Chain (55)Infrastructure Security (52)Tools (50)FAQ (50)SBOM & Compliance (41)Comparisons (32)Licensing (26)Tutorials (24)Ransomware (24)Engineering (24)Guides (22)Kubernetes Security (22)SecOps (21)Vulnerability Guides (20)Regulation (20)Industry Guides (19)Case Studies (18)Compliance & Regulations (18)Emerging Technology (17)Solutions (17)Threat Research (16)Risk Management (16)Vulnerability Response (16)Tool Reviews (16)Agent Security (16)Security Concepts (15)Cryptography (15)Identity Security (15)Incident Response (15)Compliance & Frameworks (15)Industry Events (14)Security Strategy (13)Frameworks (12)Dependency Security (11)Web Security (11)Data Breach (11)Career (10)Enterprise (9)Company (9)Culture (9)Architecture (8)Strategy (8)Standards (8)Industry Trends (7)How-To Guide (7)Secure Development (7)Industry Insights (7)Dependency Management (7)Zero-Day Exploits (7)Network Security (7)Research (6)Organizational Security (6)Vendor Comparison (6)Dev Practices (6)Industry (6)Security Operations (6)Developer Security (6)Code Security (5)Breach Analysis (5)Policy (4)Cryptocurrency Security (4)Tool Comparisons (4)Offensive Security (4)Mobile Security (4)Tool Comparison (4)Product Launch (4)Analysis (3)Social Engineering (3)Build Security (3)Startup Security (3)Policy & Compliance (3)Hardware Security (3)Governance (3)Software Supply Chain (3)Healthcare Security (3)Vulnerability Research (3)Regional Security (3)Threat Actors (2)Security Culture (2)Security Architecture (2)API Security (2)Zero-Day Analysis (2)SBOM Standards (2)Security Management (2)Release (2)Industry News (2)SBOM and Compliance (2)DeFi Security (2)Tools & Techniques (1)Healthcare (1)Emerging Threats (1)Tools & Platforms (1)Architecture Security (1)Lifecycle Management (1)Privacy (1)Product Update (1)Runtime Security (1)Technical (1)Nation-State Threats (1)Credential Attacks (1)Threat Analysis (1)Incident Postmortem (1)Career Development (1)Privacy & Security (1)Threat Modeling (1)Business Continuity (1)Browser Security (1)Events (1)PKI Security (1)Language Security (1)SBOM & Standards (1)

Articles

RSS feed
Application Security

Polymarket Lost ~$3M Without a Single Smart Contract Bug

On 25–26 June 2026 attackers compromised a third-party vendor and injected malicious code into Polymarket's website frontend, manipulating users into approving fraudulent transactions. Roughly $3M in crypto drained. The smart contracts were never touched. Your client-side dependency tree is production.

Jul 28, 20266 min read
Open Source Security

Python's .pth Files Are a Code Execution Primitive, and Attackers Noticed

The June 2026 PyPI worm wave used a *-setup.pth file to execute at interpreter startup — before your code, before your imports, on every single python invocation. It then fetched the Bun JavaScript runtime to run its payload. If your supply chain model stops at setup.py, it has a hole in it.

Jul 28, 20267 min read
Company

We're Opening Our Channel and White-Label Partner Program Worldwide

Resell it, distribute it, co-sell it, or put your own name on it. Safeguard's partner program is now open in every market outside India and the Middle East — here's how the eight tracks work, what the economics look like, and what we actually expect from a partner.

Jul 28, 20267 min read
Open Source Security

Seventeen Fake Payment SDKs, Six Minutes to Detection, and a Sandbox Check

On 7 July 2026, roughly 17 typosquatted payment-provider packages hit npm and PyPI — paysafe-checkout, paysafe-node, neteller and friends. They swept environment variables matching KEY, SECRET, TOKEN, PASS, AUTH and API, explicitly hunted AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN and NPM_TOKEN, and exited quietly if they thought they were in a sandbox.

Jul 28, 20266 min read
Open Source Security

npm v12 Disabled Install Scripts. Attackers Adapted in Three Days.

On 8 July 2026 npm v12 shipped with install scripts off by default — closing what GitHub called the ecosystem's largest code-execution surface. By 11 July, the jscrambler payload was executing on import instead. A study in why one-vector mitigations buy days, not years.

Jul 28, 20266 min read
Vulnerability Analysis

Java deserialization gadget chains explained

Java deserialization gadget chains turn trusted classpath libraries into RCE. Learn how they work, key CVEs like CVE-2015-4852, and how to detect them.

Jul 28, 20266 min read
DevSecOps

The AsyncAPI Hijack: When Trusted Publishing Becomes the Attack Path

On 14 July 2026 attackers used 37 pull requests against a pull_request_target workflow to steal the asyncapi-bot token, then let npm's OIDC trusted publisher automatically ship the malicious release. Four packages, 2.25 million weekly downloads, four hours live — and no code review was bypassed, because none was required.

Jul 28, 20266 min read
Open Source Security

The Jscrambler npm Compromise Went After Your AI Coding Assistant's Credentials

On 11 July 2026, five versions of the jscrambler package plus its webpack, gulp, grunt and metro plugins shipped malicious native binaries. The payload targeted crypto wallets and the credential stores of Claude Desktop, Cursor and Windsurf — and later versions fired on import, not install, defeating --ignore-scripts.

Jul 28, 20266 min read
AI Security

The Hugging Face Breach: What Changes When an AI Agent Runs the Intrusion

On 16 July 2026 Hugging Face disclosed that a malicious dataset gave an attacker code execution inside its data-processing pipeline, escalating to node-level access and internal cluster credentials over a single weekend — driven by an autonomous agent framework executing thousands of actions. Here's the anatomy, and what it means for anyone who treats a model registry as a trusted input.

Jul 28, 20266 min read
Page 32 of 874

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

Blog (Page 32) | Safeguard — Software Supply Chain Security Insights