Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Has security taken a back seat to productivity?

We told everyone to adopt AI, and they did. Almost anyone can now produce polished, professional work in seconds. The newest shortcut behind that speed is skills: small files that hand an AI agent a new ability. Skills are also where the risk now sits. One file can hold dozens of instructions and actions, so anything buried inside travels with it, and the agent follows all of it without asking. Most of those agents run unwatched, so the speed you gained is now exposure nobody in the business is measuring.

The Difference Between Hype and Documented Risk

How do security leaders separate legitimate AI security concerns from fear, uncertainty, and doubt? In this clip, Rik Ferguson explains why today's warnings about autonomous threats are different from past predictions. The evidence is already being documented, tested, and observed across the cybersecurity industry, making this a present challenge rather than a future possibility.

Financial Firm Stops Identity Attack in Under 2 Hours

Developing the full picture of an incident is essential for SOC teams responding to complex threats. A financial firm faced this challenge when attackers created legitimate accounts within their Google Workspace environment. While native alerts flagged the activity, investigators needed deeper context to determine scope and exposure. With Corelight, the team gained the network evidence and chronological activity timeline needed to scope the incident and restore full visibility.

Is "Assume Breach" No Longer Enough?

For more than a decade, security strategies have been shaped by the principle of "assume breach." But what if the next evolution of cybersecurity requires a different assumption? In this clip, Rik Ferguson discusses why organizations should begin building and testing security architectures based on the expectation that attackers will increasingly be autonomous and non-human, and why defenses must evolve accordingly.

The Vulnerability Tax: What CVE Response Costs at the Network Edge

Network edge vulnerabilities are accelerating. Cato’s cloud-native architecture reduces customers’ attack surface and shortens exposure to emerging vulnerabilities. The Cato CVE Exposure Calculator shows what that difference could mean for your organization. Another Known Exploited Vulnerability (KEV). Another emergency CAB. Another weekend spent upgrading firmware. You have to respond. The question is how much each response costs the business.

Episode 22 - The CTO's Case for AI: Fixing Bugs, Vibe Coding, and the Future of Dev Jobs

In this episode, host Richard Bejtlich sits down with Steve Smoot, Chief Technical Officer at Corelight, to explore how AI is reshaping the daily work of engineers and defenders alike. Steve traces his path from early employee to CTO and explains why the flexibility of Open NDR—where a simple ten-line Zeek or Spicy script can solve a customer's edge case without a full product release—remains a core advantage. The conversation digs into practical realities of working with large language models.

Ep. 76 - A Tale of Two SOCs: Invisible in One Network, Caught in 10 Minutes in the Other

CISA's own red team ran two critical-infrastructure assessments at once — and got opposite results. Host Tova Dvorin and SafeBreach offensive security engineer Adrian Culley break down advisory AA26-237A: how an ESC1 certificate template flaw and a default machine account quota chained into full domain compromise, why one SOC isolated three infected workstations in 10 minutes while the other never noticed, and the cloud identity gaps both organizations shared.

How Cato handled record-breaking traffic after Japan's return from the Obon holiday

On Monday, August 17, 2026, Cato recorded record-breaking post-Obon traffic across its Japan Points of Presence (PoPs) as employees returned to work together. At one of Cato’s Tokyo PoPs, traffic rose to more than 15 times its typical level for the same morning period on normal business days.