Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Atlanta's $17M Ransomware Attack: What Could Have Stopped It

In March 2018, the SamSam ransomware attack on the city of Atlanta became one of the most expensive ransomware incidents ever to hit a US local government. It remains a useful case study in what happens when an organization has no way to detect, stop or recover from ransomware in real time.

Engineering the Datadog Agent for FedRAMP High Certification

Software that runs inside customer-managed infrastructure creates a particular challenge at the FedRAMP High baseline. It still has to meet the applicable security and compliance requirements, even though the vendor does not control the surrounding operating system, libraries, network configuration, or maintenance practices. For Datadog, that challenge centers on the Datadog Agent, which runs directly on customer-managed hosts to collect logs, metrics, traces, and security signals.

How to Add SAML Authentication to Legacy Applications: A Step-by-Step Guide

Many organizations still rely on legacy applications to run core business processes. But that comes with limitations. According to the Workforce Agility Report, 50% of CIOs said legacy applications hold back digital transformations. More importantly, they create major security gaps. Most legacy applications, such as Oracle EBS, PeopleSoft, SAP, and JD Edwards, use authentication methods that do not fit modern identity requirements.

2026 GenAI Code Security Report: AI Is Writing More of Your Code but Security Hasn't Caught Up

New GenAI code security research shows a stubborn truth: as AI is generating more of the code entering production, secure output is not improving at the same pace. The result is a GenAI code security challenge defined by scale, model choice, and the growing need for verification. AI coding has moved past experimentation. For many teams, it is now part of how software gets built every day. That’s the opportunity. It’s also the risk.

Cato CTRL Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan

SilverFox is expanding its toolkit. In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate applications for DLL sideloading, defense evasion, and layered recovery mechanisms to keep ValleyRAT running. We investigated an active campaign targeting a Japanese organization in the industrial manufacturing sector. The attack begins with an invoice-themed phishing lure and uses attacker-controlled content hosted through legitimate QQ and Tencent Cloud services.

Sensitive Data Is More Than PII: The Blind Spot in Enterprise AI Security

A user asks an enterprise AI assistant a normal question: “Why did we lose the Acme deal?” The agent does what agents do. It retrieves CRM notes, pricing history, discount approvals, sales leadership comments, and a couple of internal strategy docs, then combines them into one clear answer: “Acme received a 28% discount exception, well above our standard enterprise pricing.

What information do you need to scope a penetration test?

Accurate scoping is one of the most important stages of a penetration testing engagement. It determines what will be assessed, how much testing effort is required, and whether the final results will provide meaningful assurance against the risks an organisation is trying to understand. A scope that is too narrow may exclude important systems, user roles, or integrations.

7 Essential Business Security Tips You Need to Follow

As a business owner, you'll know just how important protecting your company is. It could be the target of more than a few potential hackers and other criminals trying to get at your data, steal your inventory, and much more. It can be one of the more unfortunate parts of running a company. But, that doesn't mean it has to be one of the more overwhelming. Quite a few business security tips could have a noticeable impact, especially when you want to do more than just installing some alarms, CCTV cameras, and locks. It's just a matter of knowing what you're doing.

Why Cybersecurity Is Becoming Critical for Crypto Market Infrastructure

Digital asset markets have developed quickly, but their long-term growth depends on more than trading volume or market interest. As crypto becomes more connected to institutional finance, payment systems, fintech platforms, and treasury operations, the infrastructure behind these markets is coming under greater scrutiny. Speed and liquidity matter, but so do security, resilience, access control, and operational transparency.