Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Why You Should Back Up Your Terraform Configuration Code

SUMMARY – If you lose your.tf files, your Infrastructure as Code (IaC) stays up, but becomes entirely unmanaged.– Having a backup saves your team from weeks of manually reverse-engineering code to hit your RTO.– Your automated deployments rely entirely on the IaC—if the code vanishes, your CI/CD instantly stalls.– The Git commit history is the exact proof you need to pass strict audits like NIS2, SOC 2, and ISO 27001.– Setting up a dedicated Terraform backup means you c

DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE

Cato AI Labs has discovered two critical remote code execution (RCE) vulnerabilities in Cursor IDE, the popular development environment which, according to Cursor, is used by over half of the Fortune 500. Both RCE vulnerabilities, which we refer to as “DuneSlide,” achieved a 9.8 CVSS score, and involve breaking out of the IDE’s sandbox environment and were assigned CVE IDs CVE-2026-50548 and CVE-2026-50549.

Emerging Threat: (CVE-2026-55957) Apache Tomcat Authentication Bypass via JNDIRealm GSSAPI Binds

CVE-2026-55957 is a missing critical step in authentication in Apache Tomcat, present when the JNDIRealm is configured to authenticate binds using GSSAPI. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), based on network attack vector, low attack complexity, no privileges required, and no user interaction.

Why Low-And-Slow Attacks Look Normal

Low and slow attacks look normal because they are intentionally distributed into small, permissible actions that avoid detection thresholds. Each step appears legitimate on its own, which prevents detection systems from recognizing the overall progression. The issue is not that security teams lack telemetry. The issue is that traditional detection often evaluates activity in fragments. When each action stays below a rule or threshold, the broader pattern can remain invisible.

How to Meet EU Cyber Resilience Act (CRA) Requirements

In March 2026, attackers from the TeamPCP group compromised Trivy (CVE-2026-33634) — a widely-deployed open-source vulnerability scanner running in thousands of CI/CD pipelines — and turned it into a credential harvester. SSH keys, Kubernetes secrets, cloud tokens — secrets accessible to any pipeline that ran a compromised version — were exposed. The attacker retained access long enough to exfiltrate newly rotated secrets before the window closed.

LogRhythm SIEM July 2026 Release: Accelerating Investigations and Expanding Visibility

The LogRhythm SIEM July 2026 release adds new investigation workflow features, expands automation for administration and archiving, and broadens telemetry coverage across cloud, identity, collaboration, endpoint, and email environments. Organizations running on-premises and hybrid environments often need tight control over data to meet sovereignty and operational requirements.

Autonomous AI Accelerates Cyberattacks and Shrinks Response Time

The biggest challenge in cybersecurity is no longer just detecting threats. It's doing so before time runs out. Artificial intelligence is no longer confined to automating isolated tasks within an attack. It is enabling threats to operate as continuous systems that can adapt, coordinate, and evolve in real time, drastically reducing the time security teams have to react. This shift is doing more than simply increasing the volume of offensive activity.

What's New in New-Scale July 2026: AI Agents Need More Than Guardrails

Exabeam expands Behavior Intelligence to address risks introduced by agentic AI. This release introduces open-source projects for agent verification and telemetry, expanded AI observability with Anthropic Claude support, more than 50 new Agent Behavior Analytics (ABA) detections (bringing total to 90), Exabeam Nova Content Creator, and OWASP Agentic Top 10 coverage scoring in Outcomes Navigator, enabling teams to continuously verify, observe, analyze, and improve AI agent security.

What is CEN/TS 18099? A guide to the injection attack detection standard

For years, the dominant threat against remote identity verification was the presentation attack: someone holding a printed photo up to a camera, wearing a mask, or playing a pre-recorded video on a phone screen. The industry responded with increasingly sophisticated anti-spoofing technology and vision-based detection models, and the standards to test their effectiveness followed. But many of today’s most sophisticated fraudsters don’t bother with the camera at all.

How State Governments Can Navigate the Resource Crunch and Achieve Resiliency

The 2026 NASCIO-Deloitte Cybersecurity Study reveals a stark reality for CISOs in state governments: while cyber threats are growing in both sophistication and volume, the resources available to combat them are failing to keep pace. As foreign adversaries and cybercriminals weaponize AI to probe for vulnerabilities, state CISOs find themselves at a critical juncture, navigating expanding responsibilities amidst tightening budgets.