Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cato SMB FlexPool: Scale Managed SASE with Less Friction

As an SMB managed SASE business grows, the real challenge is often operational: how to add customers and respond to changing needs without adding licensing friction. Cato SMB FlexPool helps eligible MSPs and service providers managed committed capacity at the partner level, supporting faster growth, better utilization, and control of the managed service experience. Contact your Cato channel representative to discuss SMB FlexPool eligibility and pool sizing.

Demo - Agent Action Control

Netskope Skylight Agent Action Control is an inline security capability within the Netskope Skylight AI Security suite designed to evaluate, govern, and enforce real-time controls over the actions performed by autonomous AI agents. Rather than simply blocking or allowing an entire AI application or coding assistant, it intercepts attempted agent operations—such as code pushes, database modifications, or API calls—before they execute.

'Set menu or à la carte?' Customizing the Identity Manager UI

A “set menu” or “à la carte” design? Drawing on nearly 12 years of experience using Identity Manager by One Identity, Andrew Edney, a lead consultant at iC Consult, gives a lightning-quick breakdown of useful UI customization options using Designer, including changes to overview forms and updating navigation with features like custom filtering.

Research - From Square Root to /root: Escalating Privileges in Azure Containers with Python in Excel

Isolation is not the same thing as security. Ron Ben Yizhak from SafeBreach Labs presented this research at Black Hat USA and DEF CON: when Microsoft shipped Python in Excel, the code didn't run on a machine. It ran in an isolated container in Azure. So he asked the obvious question. How isolated is it, really? An isolated environment still has an attack surface. It just moves. See how Ron: If your teams are evaluating cloud-executed code features, this one is worth the full read—the methodology matters as much as the findings.

Tanium Scan Engine 7.0, "Better, Faster, Stronger": Tanium Tech Talks #170

Vulnerability and compliance scans just got faster with Tanium's new scan engine. Today we're digging into Tanium Scan Engine 7.0, a rebuild of Comply scanning that moves enumeration onto Tanium Index instead of scanning live every time. The result: faster scans, lower resource usage, and one less dependency to worry about (goodbye, JRE!!).

Why Developer Endpoints Are the New Secrets Battleground

Secrets migrated from private repos to developer endpoints. Attackers no longer hack access. They log in with stolen credentials and move laterally. Dan Nguyen-Huu, Partner at Decibel Partners, explains what the shift means for defenders and where innovation is headed. "The endpoint is largely going to become one of the big new battlegrounds. I think there's also going to be new innovation on the endpoint as it pertains to new companies, maybe trying to think about DLP in a different way.".