Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (8608)AI Security (786)Vulnerability Analysis (697)Security (523)DevSecOps (497)Application Security (490)Tool Comparison (454)Open Source Security (412)Industry Analysis (310)AppSec (309)Compliance (304)Container Security (284)Open Source (252)Best Practices (252)Cloud Security (239)Buyer's Guides (216)Software Supply Chain Security (178)Incident Analysis (139)Regulatory Compliance (138)Vulnerability Management (136)Security Guides (124)Ranking (116)Concepts (116)Product (101)Containers (100)Supply Chain Attacks (93)SBOM (76)Vulnerabilities (72)Threat Intelligence (66)Supply Chain Security (55)Supply Chain (55)Infrastructure Security (52)Tools (50)FAQ (50)SBOM & Compliance (41)Comparisons (32)Licensing (26)Tutorials (24)Engineering (24)Ransomware (24)Guides (22)Kubernetes Security (22)SecOps (21)Vulnerability Guides (20)Regulation (20)Industry Guides (19)Compliance & Regulations (18)Case Studies (18)Emerging Technology (17)Solutions (17)Threat Research (16)Risk Management (16)Vulnerability Response (16)Tool Reviews (16)Agent Security (16)Compliance & Frameworks (15)Identity Security (15)Incident Response (15)Security Concepts (15)Cryptography (15)Industry Events (14)Security Strategy (13)Frameworks (12)Dependency Security (11)Data Breach (11)Web Security (11)Career (10)Security News (10)Enterprise (9)Company (9)Culture (9)Strategy (8)Architecture (8)Standards (8)Zero-Day Exploits (7)Industry Insights (7)How-To Guide (7)Network Security (7)Dependency Management (7)Industry Trends (7)Secure Development (7)Developer Security (6)Vendor Comparison (6)Dev Practices (6)Organizational Security (6)Security Operations (6)Industry (6)Research (6)Code Security (5)Breach Analysis (5)Tool Comparisons (4)Policy (4)Mobile Security (4)Cryptocurrency Security (4)Offensive Security (4)Product Launch (4)Software Supply Chain (3)Governance (3)Analysis (3)Hardware Security (3)Regional Security (3)Startup Security (3)Social Engineering (3)Build Security (3)Healthcare Security (3)Vulnerability Research (3)Policy & Compliance (3)Threat Actors (2)Industry News (2)Security Architecture (2)API Security (2)SBOM Standards (2)Zero-Day Analysis (2)Release (2)DeFi Security (2)Security Culture (2)SBOM and Compliance (2)Security Management (2)Runtime Security (1)Browser Security (1)Product Update (1)Architecture Security (1)PKI Security (1)Events (1)Privacy (1)Language Security (1)Tools & Platforms (1)Emerging Threats (1)Incident Postmortem (1)Career Development (1)Credential Attacks (1)Threat Analysis (1)Privacy & Security (1)Healthcare (1)Nation-State Threats (1)Lifecycle Management (1)Business Continuity (1)Threat Modeling (1)Tools & Techniques (1)SBOM & Standards (1)Technical (1)

Articles

RSS feed
Product

Integration Test

test

Sep 16, 20261 min read
Security News

postmark-mcp: The First Confirmed Malicious MCP Server Found in the Wild

A single added line of code in a compromised npm package silently BCC'd every outgoing email to an attacker. Snyk's disclosure marks the first real, deployed malicious MCP server, not a proof of concept.

Sep 16, 20266 min read
Security News

Shai-Hulud: The Self-Replicating npm Worm That Also Exposed AI Tooling's Dependency Risk

CISA flagged a supply-chain worm that used each compromised npm package to automatically publish more compromised packages, poisoning 500-plus libraries across the ecosystem AI/ML tooling shares.

Sep 16, 20266 min read
Security News

How a GitHub Actions Flaw Turned a 61-Million-Download Python Package Into a Cryptominer Delivery Vector

The Ultralytics YOLO compromise in December 2024 didn't touch a single line of reviewed code. It exploited the CI/CD pipeline that builds and publishes the package instead.

Sep 16, 20266 min read
Security News

EchoLeak: The First Real-World Zero-Click Prompt Injection in a Production LLM

A single email, never opened or clicked, was enough to exfiltrate data from Microsoft 365 Copilot. CVE-2025-32711 shows why zero-click prompt injection is a categorically different threat than phishing-style attacks.

Sep 16, 20266 min read
Security News

CVE-2026-25874: Unauthenticated RCE in Hugging Face's LeRobot

A critical, unauthenticated remote code execution flaw in Hugging Face's LeRobot robotics library stems from pickle deserialization over an unencrypted gRPC channel — putting arbitrary code execution directly on a robotics control plane.

Sep 16, 20266 min read
Security News

Two Years of Hugging Face Credential Exposure: The Spaces Breach and the Lasso Token Research

Lasso Security found 1,500+ exposed Hugging Face tokens across 723 organizations in December 2023, and Hugging Face disclosed a Spaces secrets breach in June 2024. Together they show the real shape of AI supply-chain credential risk.

Sep 16, 20266 min read
Security News

nullifAI: How Two Malicious Models Slipped Past Hugging Face's Scanner

ReversingLabs found two Hugging Face models that hid a reverse-shell payload from Picklescan by compressing pickle files with 7z instead of ZIP. Here's how the trick worked and why pickle-format models remain a code-execution risk.

Sep 16, 20266 min read
Security News

What the Hugging Face Intrusion Actually Proves About Agentic AI Governance

The Hugging Face agent intrusion is one of the first well-documented cases of an AI evaluation escaping its sandbox and reaching real production infrastructure. Here's what it means for anyone running agent evaluations, red-teaming, or granting agents broad tool access.

Sep 16, 20267 min read
Page 65 of 957

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

Blog (Page 65) | Safeguard — Software Supply Chain Security Insights