Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (7863)AI Security (786)Vulnerability Analysis (577)Security (523)DevSecOps (497)Application Security (490)Open Source Security (412)AppSec (309)Compliance (304)Industry Analysis (295)Container Security (284)Open Source (252)Best Practices (252)Cloud Security (239)Buyer's Guides (216)Software Supply Chain Security (178)Incident Analysis (139)Regulatory Compliance (138)Vulnerability Management (135)Security Guides (124)Concepts (116)Containers (100)Supply Chain Attacks (93)SBOM (76)Vulnerabilities (72)Product (69)Threat Intelligence (65)Supply Chain Security (55)Supply Chain (55)Infrastructure Security (52)Tools (50)FAQ (50)SBOM & Compliance (41)Comparisons (32)Licensing (26)Tutorials (24)Ransomware (24)Engineering (24)Guides (22)Kubernetes Security (22)SecOps (21)Vulnerability Guides (20)Regulation (20)Industry Guides (19)Case Studies (18)Compliance & Regulations (18)Emerging Technology (17)Solutions (17)Threat Research (16)Risk Management (16)Vulnerability Response (16)Tool Reviews (16)Agent Security (16)Security Concepts (15)Cryptography (15)Identity Security (15)Incident Response (15)Compliance & Frameworks (15)Industry Events (14)Security Strategy (13)Frameworks (12)Dependency Security (11)Web Security (11)Data Breach (11)Career (10)Enterprise (9)Company (9)Culture (9)Architecture (8)Strategy (8)Standards (8)Industry Trends (7)How-To Guide (7)Secure Development (7)Industry Insights (7)Dependency Management (7)Zero-Day Exploits (7)Network Security (7)Research (6)Organizational Security (6)Vendor Comparison (6)Dev Practices (6)Industry (6)Security Operations (6)Developer Security (6)Code Security (5)Breach Analysis (5)Policy (4)Cryptocurrency Security (4)Tool Comparisons (4)Offensive Security (4)Mobile Security (4)Tool Comparison (4)Product Launch (4)Analysis (3)Social Engineering (3)Build Security (3)Startup Security (3)Policy & Compliance (3)Hardware Security (3)Governance (3)Software Supply Chain (3)Healthcare Security (3)Vulnerability Research (3)Regional Security (3)Threat Actors (2)Security Culture (2)Security Architecture (2)API Security (2)Zero-Day Analysis (2)SBOM Standards (2)Security Management (2)Release (2)Industry News (2)SBOM and Compliance (2)DeFi Security (2)Tools & Techniques (1)Healthcare (1)Emerging Threats (1)Tools & Platforms (1)Architecture Security (1)Lifecycle Management (1)Privacy (1)Product Update (1)Runtime Security (1)Technical (1)Nation-State Threats (1)Credential Attacks (1)Threat Analysis (1)Incident Postmortem (1)Career Development (1)Privacy & Security (1)Threat Modeling (1)Business Continuity (1)Browser Security (1)Events (1)PKI Security (1)Language Security (1)SBOM & Standards (1)

Articles

RSS feed
DevSecOps

Jenkins CLI Deserialization RCE via Commons-Collections G...

CVE-2015-8103: unauthenticated RCE in Jenkins CLI via a Commons-Collections deserialization gadget chain. Impact, timeline, and remediation.

Jul 25, 20269 min read
AI Security

AI Model Watermarking and Provenance

Watermarking and provenance are the two most confused terms in AI security. A practical breakdown of what each actually does, where the 2025 techniques break, and what to ship in the meantime.

Jul 25, 20267 min read
AppSec

Code Security Scan: How to Scan Your Code for Vulnerabilities

A code security scan analyzes your source and its dependencies for security flaws before they ship. Here is how the main scan types work, what tools to use, and how to wire scanning into CI without drowning in noise.

Jul 25, 20267 min read
Product Launch

Safeguard CLI v5: Faster, Smarter, More Extensible

Safeguard CLI v5 brings a rewritten scanning engine, plugin architecture, and native CI/CD integration. Here is what is new and how to upgrade.

Jul 25, 20266 min read
DevSecOps

Jenkins Script Security Sandbox Bypass Leading to RCE (CV...

CVE-2019-1003029 let attackers escape the Jenkins Script Security sandbox and execute arbitrary code via crafted Groovy pipeline scripts.

Jul 25, 20268 min read
DevSecOps

Jenkins Arbitrary File Read via Crafted CLI Command (CVE-...

CVE-2018-1999002 let attackers read arbitrary files from Jenkins masters via crafted requests to the Stapler framework, exposing secrets and credentials.

Jul 25, 20268 min read
DevSecOps

TeamCity Authentication Bypass Exploited by Nation-State ...

A critical TeamCity authentication bypass, CVE-2023-42793, let APT29 and North Korean hackers seize build servers for supply chain attacks.

Jul 25, 20267 min read
DevSecOps

TeamCity Authentication Bypass Enabling Admin Account Cre...

CVE-2024-27198 lets unauthenticated attackers bypass TeamCity login and create admin accounts, with active exploitation and ransomware activity observed.

Jul 25, 20267 min read
Open Source

angular.io Security: Keeping Your Angular App Safe in 2025

The docs at angular.io teach safe defaults, but recent CVEs in SSR, the HTTP client, and template sanitization show where the framework still needs your attention.

Jul 25, 20266 min read
Page 38 of 874

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.