Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cato CTRL Threat Brief: AsyncAPI Supply Chain Attack Delivers Miasma Malware Through Trusted npm Packages

On July 14, 2026, attackers compromised release processes connected to the AsyncAPI open- source project and published malicious versions of four widely used npm packages with a combined reach of approximately 2.9 million weekly downloads.

Kovrr's Insurance Data Insights: Connecting Cyber Exposure to Coverage

‍ ‍Cyber insurance has become a standard line item in enterprise risk management, and for good reason. The financial consequences of a significant cyber event, whether a ransomware attack that halts operations for weeks or a data breach that triggers regulatory scrutiny and third-party liability, can far exceed what any operational budget was sized to absorb. Insurance exists to handle that tail. Most organizations recognize this benefit and carry a policy.

The Security Risks of AI Agents in the Enterprise

AI agents introduce a category of security risk that traditional application security, identity management, and even standard AI security programs were not designed to handle. Unlike a generative model that only produces text, an agent takes autonomous action against real systems, chains API calls together to accomplish goals, and often holds permissions broad enough to touch data across multiple business systems.

Governing non-human identities with Identity Manager 10.0

Most organizations today have more non-human identities than human identities. These NHIs often hold privileged access, operate continuously and are difficult to track. Get a handle on every identity in your environment with Identity Manager by One Identity.

Avast One: One App for Security, Privacy & Performance

Your digital life is complicated enough — your protection shouldn't be. Avast One is an all-in-one app that brings together everything you need to stay safe, private, and running smoothly online. No more juggling separate apps, overlapping tools, or rigid bundles. Just one clean dashboard, one smart app, and full control over what protects you.

The First Hour of a Zero-Day: Why Preparation Must Start Before Disclosure

The window between vulnerability disclosure and exploitation is shrinking. As exploit development accelerates, organizations can no longer afford to wait for a vulnerability to be disclosed or a patch to become available before taking action. Daniel dos Santos, VP of Research, explains why effective zero-day response depends on preparation that happens before an incident occurs.

Where Security Breaks First in the AI Era

Most security programs were built for a slower clock. But as AI-assisted and autonomous attackers accelerate the pace of attacks, manual approval gates can become the point where defenders fall behind. This short video explores why security teams need to reexamine the processes, decision points, and response workflows that may slow them down when speed matters most.

Who's Winning the AI Security Race: Attackers or Defenders?

Defenders have gained early access to powerful AI tools, creating an opportunity to improve security outcomes and strengthen cyber resilience. But as these capabilities become more widely available, that advantage may not last. Rik Ferguson, VP of Security Intelligence at Forescout, shares his perspective on what security teams should be doing now to prepare.