Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

CISOs need decision-grade risk intelligence, not another workflow

In large enterprises, the hardest security decisions are rarely made in the SOC. They are made in board meetings, budget reviews, audit discussions, customer escalations. The most dire are often represented in the moments when leaders have to decide what matters now, what can wait, and what risk the business is actually taking on. The real GRC problem is no longer how to manage more work. It is how to help the business make better decisions with higher confidence. CISOs do not need another workflow.

Cato CTRL Threat Research: From Fiscal Lures to Remote Access, A Previously Undocumented NinjaOne RMM Abuse Chain

Cato CTRL researchers recently identified an undocumented, active phishing campaign targeting Brazilian organizations with fake business-document lures, downloading a NinjaOne Remote Monitoring and Management (RMM) agent. The use of NinjaOne is particularly significant, underscoring how attackers no longer need exotic malware to penetrate an enterprise. Familiar business workflows and software is enough.

Grounding the AI SOC: The Context Graph Problem

See how Torq harnesses AI in your SOC to detect, prioritize, and respond to threats faster. Request a Demo David Melamed is Head of Emerging Technologies at Torq. He joined through Torq’s acquisition of Jit, which he co-founded and led as CTO since 2020, building agentic security on a production Context Graph. A cloud security veteran with 20+ years of experience, David previously held senior technical roles at Cisco (via the CloudLock acquisition) and MyHeritage.

The Governance Gap: What IDC's 2026 Data Reveals About AI and the Software Supply Chain

In a landscape where executive teams demand immediate AI integration, engineering and security leaders find themselves navigating a complex operational balancing act. To explore how organizations can accelerate delivery pipelines without introducing fatal security risks, JFrog recently hosted a virtual panel discussion titled “Agentic Software Delivery in 2026.

Our AI Agent Now Has a Security Conscience: Introducing the JFrog Plugin for Claude Code

AI coding agents are changing the pace of software development. With tools like Claude Code, developers can move from idea to implementation faster than ever, generating code, exploring unfamiliar repositories, refactoring services, and turning plain-language intent into working software. That speed is powerful. But speed without governance = risk. It also creates a new challenge: how can you govern what an AI agent builds, suggests, and pulls in from the internet?

How DSPM Detects Insider Threats Using Data Lineage

Most insider risk programs stall at the same place: they can see what data exists, but not what users are doing with it. Data security posture management (DSPM) tools catalog sensitive files, flag misconfigured permissions, and surface overexposed repositories. What they often cannot communicate is whether that overexposed file was accessed, copied, renamed, and uploaded to a personal cloud account by an employee who put in their resignation last week.

Should penetration testing be performed in staging or production?

One of the most common questions organisations ask when planning a security assessment is whether penetration testing should be performed against a staging environment or a live production system. At first glance, staging appears to be the safer option. It provides an environment where testing can be conducted without affecting real users, customer data, or operational services.

What's new in Tines: June 2026 edition

In the previous edition, we introduced Apps, a customizable, interactive front end for your Tines workflows. This month, get to know Apps a little better. Once your app is live, monitor performance and catch issues early in the analytics tab. Track total and unique views, endpoint invocations, success and failure rates, and route breakdowns. We built more version control for clean app iterations. You can now save restore points while making changes and unpublish an app and return it to a draft state.

Why Ongoing Cybersecurity Monitoring Is Essential for Medical Device Compliance

Healthcare organizations today rely heavily on connected medical devices to improve patient outcomes, streamline clinical workflows, and support real-time decision-making. From infusion pumps and imaging systems to wearable monitoring technologies, these devices have become a critical part of modern healthcare delivery. However, as connectivity increases, so does exposure to cybersecurity risks that can affect device functionality, patient safety, and regulatory compliance.

What Integrated Lab Management Teaches Us About Systematic Risk Reduction

Risk in laboratory environments doesn't usually announce itself. It accumulates in the gaps - between process steps, between systems that don't communicate, between the way a procedure is documented and the way it's actually being performed on a busy Tuesday afternoon. Individual failures are often small enough to be invisible until they combine with other small failures to produce an outcome that prompts a formal investigation.