Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cato CTRL Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan

SilverFox is expanding its toolkit. In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate applications for DLL sideloading, defense evasion, and layered recovery mechanisms to keep ValleyRAT running. We investigated an active campaign targeting a Japanese organization in the industrial manufacturing sector. The attack begins with an invoice-themed phishing lure and uses attacker-controlled content hosted through legitimate QQ and Tencent Cloud services.

2026 GenAI Code Security Report: AI Is Writing More of Your Code but Security Hasn't Caught Up

New GenAI code security research shows a stubborn truth: as AI is generating more of the code entering production, secure output is not improving at the same pace. The result is a GenAI code security challenge defined by scale, model choice, and the growing need for verification. AI coding has moved past experimentation. For many teams, it is now part of how software gets built every day. That’s the opportunity. It’s also the risk.

How to Add SAML Authentication to Legacy Applications: A Step-by-Step Guide

Many organizations still rely on legacy applications to run core business processes. But that comes with limitations. According to the Workforce Agility Report, 50% of CIOs said legacy applications hold back digital transformations. More importantly, they create major security gaps. Most legacy applications, such as Oracle EBS, PeopleSoft, SAP, and JD Edwards, use authentication methods that do not fit modern identity requirements.

Engineering the Datadog Agent for FedRAMP High Certification

Software that runs inside customer-managed infrastructure creates a particular challenge at the FedRAMP High baseline. It still has to meet the applicable security and compliance requirements, even though the vendor does not control the surrounding operating system, libraries, network configuration, or maintenance practices. For Datadog, that challenge centers on the Datadog Agent, which runs directly on customer-managed hosts to collect logs, metrics, traces, and security signals.

Atlanta's $17M Ransomware Attack: What Could Have Stopped It

In March 2018, the SamSam ransomware attack on the city of Atlanta became one of the most expensive ransomware incidents ever to hit a US local government. It remains a useful case study in what happens when an organization has no way to detect, stop or recover from ransomware in real time.

Securing the Agentic Enterprise

We're living through the biggest shift in how work gets done in a generation. In every industry, every company is becoming an agentic enterprise, meaning a business where humans and autonomous AI work side by side. What makes an agentic enterprise successful is its workflows: how it combines intelligence, both human and machine, with its proprietary data.

AI Agents and MCP: Security Implications

The Model Context Protocol has quietly become the connective tissue of enterprise agentic AI. MCP standardizes how AI agents discover, request, and invoke tools, data sources, and external systems, replacing the custom integration code that used to sit between every agent and every backend. ‍ That standardization is what made agents commercially viable at scale. It is also what turned MCP into one of the largest and least-understood attack surfaces in enterprise AI.

How to Quantify Cyber Risk for Board-Level Reporting

Quantifying cyber risk for the board means translating technical exposure into dollar-denominated financial risk that the audit committee, CFO, and directors can act on. Boards care about strategic business impact like operational downtime, regulatory penalties, and reputational damage. ‍ They do not care about patch rates, blocked emails, or firewall logs, which are the metrics cyber teams have historically brought to board meetings and which board members have historically ignored.

Arctic Wolf Named a Leader in the 2026 IDC MarketScape for Worldwide Managed Detection and Response Service for Midmarket

Midmarket security teams face the same adversaries as the largest enterprises, often with a fraction of the staff and budget. Alert volumes keep climbing, AI-driven threats are accelerating, and lean teams are expected to do more with fewer resources. What these organizations need is world-class AI-led security operations that are actually within reach.