Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Critical Care, Critical Risk: Inside the Cyber Threats Targeting Healthcare

The healthcare sector remains one of the most targeted industries for cyber attacks due to its critical role in national infrastructure and its extensive repositories of sensitive data containing personally identifiable information (PII). It’s widely assumed that threat actors target healthcare and related organizations because they are perceived as more likely to pay a ransom to restore critical systems and protect patient safety in the event of an attack.

Securing the AI Browser Revolution: How Cato Helps Mitigate Risks in OpenAI Atlas

The launch of OpenAI Atlas, an AI-powered browser that merges ChatGPT’s intelligence with a full web experience, marks a major leap in how people interact with the internet. Instead of typing queries or clicking through pages, users can now ask, act, and automate, delegating browsing tasks to AI agents capable of retrieving data, filling in forms, or performing actions on their behalf. For businesses, Atlas represents both opportunity and risk.

Purpose-Built for MSPs: Unlock New Market Opportunities with Arctic Wolf

In today’s evolving threat landscape, a stack of security tools isn’t enough. MSPs need a partner that helps them scale, differentiate, and deliver exceptional security outcomes. That’s why Arctic Wolf launched a purpose-built MSP program earlier this year, designed in close collaboration with our MSP partners to empower them to grow faster and more profitably.

The Compliance Gap: How Untracked User Lifecycle Changes Create SOC 2 Audit Failures

Forty-seven ghost accounts cost one SaaS company a $2M deal. Their SOC 2 auditor flagged a critical issue: former employees still had active system access, even those terminated six months earlier. The security team invested heavily in firewalls, encryption, and penetration tests. They failed on something more urgent: proving immediate access removal when people left.
Featured Post

Too Many Tools, Too Little Control: The Security Sprawl Problem

As Forrester expects the cost of cybercrime to reach $12 trillion by the end of 2025, enterprises are gearing up and investing heavily in cybersecurity. Yet, despite rising budgets, security leaders' confidence in detecting and recovering from incidents is declining. A key culprit is security tool sprawl, which quietly erodes visibility, speed, and trust in operations.

2025 Insider Risk Report Finds Most Organizations Struggle to Detect and Predict Insider Risks

The new 2025 Insider Risk Report, produced byCybersecurity Insiders in collaboration with Cogility, highlights that nearly all security leaders (93%) say insider threats are as difficult or harder to detect than external cyberattacks. Yet only 23% express strong confidence in stopping them before serious damage occurs. The report warns that most organizations remain reactive despite a surge in AI-driven risks and the increasing prevalence of decentralized workforces.

Emerging Threat: CVE-2025-64095 - Critical Unauthenticated File Upload Vulnerability in DNN (DotNetNuke)

CVE-2025-64095 is a critical unauthenticated file-upload vulnerability affecting DNN (DotNetNuke) versions prior to 10.1.1. The flaw exists in the platform’s default HTML editor provider, where upload validation and authorization checks were insufficient. Attackers can upload files and overwrite existing content without credentials, enabling page defacement, malicious script injection, and in some environments stored cross-site scripting (XSS).

Money20/20 2025 recap: Crypto is in its infrastructure era

Money20/20 has always been a window into what's next for money movement, and in 2025, crypto and stablecoins took center stage with a new energy and focus. This year, the discussions for crypto were all about infrastructure, collaboration, and building systems that last. Across sessions, one message kept surfacing: Crypto's future depends on collaboration. During our Money20/20 panel, Lee Bagan from Bridge put it best: "We're not asking if crypto can work within the system anymore.