Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cato CTRL Threat Research: Operation Poisson - Analyzing a Cybercriminal's Entire Operation

Cato CTRL recently analyzed an operator’s command-and-control (C2) server’s entire 33 days operation, including the steps he took to preserve access after the takedown. 339 commands. Four French victims. Between March 30 and May 1, 2026, Cato CTRL studied every command issued by a French-speaking threat actor (“Poisson”) against one French automotive small business and four French individuals.

Let's Talk Security: Leading Healthcare Security Through Constant Change

Healthcare CISOs are navigating one of the most complex security environments. In this conversation, Barry Mainz will be joined by David Finkelstein, CISO, St. Luke’s University Health Network, a seasoned healthcare security leader with experience spanning cyber, operations, and military service, to discuss what it takes to build a modern healthcare cybersecurity program that is resilient today and ready for tomorrow.

9 of the Best Managed IT Services for Focused Cybersecurity Frameworks

Do you know there are between 2,200 and 2,700 impactful cyberattacks every day out of the hundreds of millions of automated attempts? The vast amount of high-potential attacks means that any business or organization needs focused cybersecurity frameworks to proactively deal with the threat. But where do you even begin? Like anything, there are many IT and cybersecurity delivery services for businesses of all sizes, needs, and, of course, budgets.

From CVE Disclosure to Agentic Protection in 45 Minutes. Why it Matters Now.

A CVE lands in the morning. Hours later, attackers are exploiting it in the wild. The patch is not ready, the change window is days away, and the clock is already running. None of this is new. What changed is that vulnerability exploitation is now the most common path into organizations.

Cato Expands the Power of the Platform with New Technology Ecosystem

Modern IT and security teams no longer evaluate platforms in isolation. They ask how a platform fits into the architecture they run, the workflows they trust, and the outcomes they need to improve. Enterprise stacks are not isolated; they are interdependent. Identity shapes access, endpoint posture influences policy, while SIEM tools drive investigations and rely on shared data and context. AI tools introduce new layers and patterns of usage, risk, and data movement across the network.

The Hidden Path From a Household Gadget to Your Personal Data

Most people think about cybersecurity in terms of computers and smartphones. When they hear about data breaches, identity theft, or compromised accounts, they picture hackers targeting laptops, email inboxes, or financial institutions. Few people imagine that a device mounted quietly on a wall could become part of the story.

Cato CTRL Threat Research: From Fiscal Lures to Remote Access, A Previously Undocumented NinjaOne RMM Abuse Chain

Cato CTRL researchers recently identified an undocumented, active phishing campaign targeting Brazilian organizations with fake business-document lures, downloading a NinjaOne Remote Monitoring and Management (RMM) agent. The use of NinjaOne is particularly significant, underscoring how attackers no longer need exotic malware to penetrate an enterprise. Familiar business workflows and software is enough.

Why Segmentation is Crucial for Cybersecurity in Today's World

This video delves into the importance of segmentation in cybersecurity and why it matters more than ever. As attacks become more sophisticated, they don't just stop at entry but rather succeed through lateral movement. An expert explains how effective segmentation limits this movement, contains the blast radius, and buys you the most critical resource in combating cyber threats—TIME. In a world where machine speed exploits are on the rise, machine speed containment is key. Discover how immediate and well-designed segmentation can provide the much-needed AI defense to protect what truly matters.

Black Hat Asia 2026: Everything from cat feeders to solar farms

There is a saying you will hear from veterans in the Black Hat Network Operations Center (NOC): “Threat hunting on the Black Hat network is like trying to find a needle in a stack of needles." With dozens of training classes running live exploit chains, capture-the-flag traffic, and researchers probing every corner of the internet, our Corelight sensors generate a rich set of Zeek logs, many of which can look suspicious in varying degrees.

Three processes slowing down network security in 2026

Network security stacks are stronger than ever: visibility is high, threat detection is improving, and AI adoption is widespread, with 99% of SOCs using it in some capacity. But despite these advances, network security teams face many of the same operational challenges as before. Incidents still escalate. Responses are slow. Analysts remain overwhelmed and burnt out. The issue isn’t detection – it’s what happens next.