Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Miasma: Red Hat Cloud Services npm Packages Hit by a Mini Shai-Hulud-Style Campaign

On June 1, 2026, multiple npm packages in the @redhat-cloud-services scope were published with malicious versions. Each tarball ships a 4.1 MB obfuscated JavaScript file added to package.json as a preinstall hook. The hook runs a multi-stage loader that ends in a Bun-executed credential stealer hitting AWS, Azure, GCP, HashiCorp Vault, Kubernetes, GitHub Actions OIDC, npm, Bitwarden, and 1Password.

Arctic Wolf Product Updates: May 2026

Security teams are being asked to operate at machine speed while still making decisions they can trust. Attackers move faster. Exposure changes continuously. Manual workflows struggle to keep up. Following the recent announcement of the Aurora Superintelligence Platform and Aurora Agentic SOC, Arctic Wolf continues to advance its portfolio with new capabilities that help teams see risk clearly, prioritize what matters, and act with confidence.

Automated vulnerability remediation: A governance, validation, and rollout guide for enterprise teams

Automated vulnerability remediation uses policy-driven workflows to execute approved remediation actions, including patch deployment, software updates, and configuration changes, consistently across managed assets. Within a broader vulnerability management program, it helps teams close the gap between identifying an exposure and safely resolving it at scale.

Why most DR deployments may not survive a real disaster

This report examines the disaster recovery (DR) readiness across the Acronis Cyber Protect Cloud platform, managing thousands of DR deployments across dozens of data centers worldwide. The analysis focuses on Q1 2026 (January – March) and reveals a clear gap between having DR configured and being truly ready for a disaster.

Secure Shadow AI at the Control Plane with Falcon for IT

CrowdStrike is introducing AI Discovery and Governance for CrowdStrike Falcon for IT, a new capability that helps organizations identify, assess, and govern AI technologies across enterprise environments. Enterprise IT infrastructure is the control plane for modern organizations. It determines how systems communicate, how identities authenticate, and how workloads execute across endpoints, servers, and clouds. This foundation supports the rapid implementation of AI across businesses.

Scaling Security Further: Introducing the New High-Performance Firebox Series

When we introduced the next generation of Firebox appliances last year, the goal was to simplify security while keeping pace with increasingly distributed environments. By combining performance, integrated security services, and cloud capabilities, we created a unified approach that helped organizations and MSPs protect networks without added complexity. But as customers continue to grow, so do their demands. Modernization is no longer enough; the real challenge is scaling effectively.

What is Remote Device Management? RDM Guide

The shift from traditional office setups to remote and hybrid work has changed how IT teams operate. Employees are no longer working from a single location. They use laptops, smartphones, tablets, and even rugged devices across homes, offices, and field environments. Managing all of this securely is not simple. IT teams now have to balance speed, security, and support without physical access to devices. When something breaks, they cannot walk up to a desk and fix it.

archTIS and Mattermost Partner to Deliver Secure Collaboration for Defence Operations

archTIS and Mattermost are pleased to announce a collaboration to deliver policy-enforced, data-centric security to secure operational collaboration for Defence Ministries, NATO Allies, and coalition partners worldwide. The collaboration combines Mattermost’s secure, mission-critical command-and-control surface with archTIS Trusted Data Integration (TDI) platform, to enable secure collaboration using dynamic policy orchestration via Attribute-Based Access Control (ABAC).

Reducing Time-to-Protect with Cato's Self-Evolving Vulnerability Protection Agent

TL;DR: In the age of frontier AI models, vulnerability discovery and exploit development are scaling faster than human defenders can manually respond. Security teams already face growing CVE volumes, shorter exploitation windows, and manual workflows for researching vulnerabilities, creating protections, validating them, and preparing them for deployment. As attackers weaponize vulnerabilities faster than organizations can patch them, time-to-protect is becoming a critical security metric.

K2view vs Tonic for synthetic data generation

If you've ever tried to share realistic production data with a QA team, a data science group, or an external vendor, you already know the problem: the data you need is also the data you're not allowed to move around freely. Synthetic data generation is the practical middle path when done correctly. It gives teams realistic datasets without the privacy risks, compliance concerns, and operational complexity associated with using production data directly.