Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Don't Wait for a Crisis: Rehearse Your Zero-Day Response

How do you prepare for a zero-day attack before one impacts your organization? In this video, Daniel dos Santos explains why security teams should use past vulnerabilities and real-world attack scenarios to rehearse response plans. By testing decisions, controls, communications, and recovery actions—not just documentation—organizations can build confidence and improve readiness for future threats.

How a Network-First Strategy Buys Time for Patching

What can organizations do when a critical vulnerability can't be patched right away? In this video, Daniel dos Santos, VP of Research, explains how a network-first approach can reduce exploitability by restricting access to vulnerable services while remediation is underway. By limiting reachability, security teams can reduce risk and give patching teams the time they need to test and deploy fixes.

Networking: The Last Piece in the AI Puzzle

Artificial intelligence is revolutionizing the way we work, but it can also consume massive amounts of network resources. In this podcast, 11:11 Systems explores the critical networking foundation required to support AI workloads with the low latency, high bandwidth, and operational visibility they demand. Watch Jeff Robator, EVP Global Connectivity at 11:11 Systems, Anthony Lobretto, SVP Connectivity Services at 11:11 Systems, and Brad Gerlach, Product Marketing Manager at 11:11 Systems, as they discuss.

Cato CTRL Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan

SilverFox is expanding its toolkit. In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate applications for DLL sideloading, defense evasion, and layered recovery mechanisms to keep ValleyRAT running. We investigated an active campaign targeting a Japanese organization in the industrial manufacturing sector. The attack begins with an invoice-themed phishing lure and uses attacker-controlled content hosted through legitimate QQ and Tencent Cloud services.

The Hidden Cost of "Free": When Platform Incentives Become Lock-In

In enterprise software, “free” is rarely free. A free year can be a smart commercial incentive. It can also become a financial trap if the real cost, payment terms, and renewal baseline are unclear. When a platform deal looks almost too good to question, CFOs should question it first. Large multi-year incentives can look like a procurement win. They lower the apparent cost of entry, support a consolidation story, and create the impression of immediate savings.

How to Reduce Risk Without Shutting Down Operations

Discovering a vulnerable asset doesn't have to trigger panic. In this video, Daniel dos Santos explains how organizations can reduce risk while investigations are still underway by limiting reachability, tightening access controls, and using segmentation to restrict exposure—without disrupting critical business operations.