Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Scale Your Engineering Organization Without Losing Control

Growing engineering organizations all hit the same wall. More teams shipping software means more repositories, more permission requests, more onboarding cycles, and eventually one platform admin fielding every change. The platform that was supposed to accelerate delivery has now become the bottleneck. JFrog Projects is built to break that pattern.

Warning: Compromised Hotel Routers Send Users to Phishing Sites

Attackers are using compromised hotel Wi-Fi routers to redirect users to Microsoft 365 phishing sites, according to researchers at ReliaQuest. The attacks were observed in multiple U.S. cities, as well as across India and Saudi Arabia. These types of DNS poisoning attacks can send users to phishing sites with very little evidence that something suspicious has taken place.

Report: Scams Are Surging as Attackers Abuse Trusted Workflows

Threat actors are increasingly abusing trusted workflows to carry out attacks, according to a new report from Gen Digital. “ are not only sending malicious links or dropping malware,” the report says. “They are abusing context, sessions, workflows, brands, update systems, advertising platforms and delegated authority.

Unmasking the Invisible: How to Identify AI Tools, Hidden Devices, and Other Unknown Assets on Your Network

You cannot protect what you do not know exists. That statement has been true throughout the history of cybersecurity, but it has become even more important as organizations adopt new technologies and employees gain access to powerful AI tools. While many organizations focus on defending against external threats, they often overlook a growing problem much closer to home: devices, applications, and services operating within their environment that nobody knows about.

How Cloudflare detects MCP traffic and helps secure it

Most companies designed their resource permissions with a human user in mind. A senior engineer may be able to deploy to production, query a sensitive database, or revoke another user's access. Those privileges come with risk, but that risk has traditionally been bounded by two assumptions: the engineer will use human judgment, and the engineer can only act at human speed.

Secure all your internal vibe-coded applications - in one click

AI has enabled employees across every team to build applications faster than ever before. But that speed is also what's keeping every CISO up at night: any employee can build an application, deploy it to the public Internet, and accidentally expose internal work or company data. Today, we're launching new tools to make it easy to keep your applications hosted on Workers private.

Why AI Discovery Must Be the First Step in Enterprise AI Security

Every enterprise security leader is being asked the same question by their board: are we secure against AI risk? Most cannot answer it with confidence, and the reason is rarely a lack of tools. It is a lack of visibility. AI has spread through enterprises faster than almost any technology before it. Developers wire large language model APIs into internal tools. Business teams stand up copilots and chat assistants. Data science teams build retrieval pipelines against customer and financial data.

What is Managed Detection and Response (MDR)?

As technology grows at a rapid pace, many organizations have switched to new ways of working. Now, hybrid work environments are extremely common, with many organizations hiring employees who work remotely. And then there is the rapid growth of artificial intelligence (AI), which has further changed the way operations are carried out in organizations. Technology has significantly improved the efficiency and accuracy of work, but it has also increased the attack surface.