Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Dark Caracal Reloaded: New Malware, Same Hunting Grounds

Arctic Wolf Labs exposes Dark Caracal’s evolving tradecraft, linking 249 samples to two operational build profiles and a resilient Ethereum-based C2 architecture targeting Latin America. In June 2026, Arctic Wolf Labs investigated a targeted intrusion affecting a communications organization in Venezuela.

How Many Cyber Risk Scenarios Should You Model?

Scenario libraries grow. A program starts with ransomware and a data breach, adds a third-party failure after a supplier incident, splits ransomware into encryption and extortion variants, adds a cloud outage, and two years later holds forty entries nobody has revisited. ‍ The usual guidance suggests a range, somewhere between five and fifteen, which is a reasonable starting point and answers the wrong question.

Agent Incident Response: Containment Is the Easy Part

Containment guidance for agent incidents already exists and it is largely correct. Revoke the tokens, freeze the orchestration tier, cut egress, set the vector store to read-only. Those steps take minutes and any competent team will find them. ‍ The difficulty sits either side of containment. Deciding what kind of incident this is takes longer than stopping it, establishing what the agent did before you stopped it takes longer still, and both depend on preparation that has to exist beforehand.

WatchGuard Recognized as 2026 CRN Annual Report Card Winner for Network Security

WatchGuard Technologies, a global leader in unified cybersecurity, has been recognized as a 2026 CRN Annual Report Card (ARC) Award winner in the Security: Network Security—SMB category by CRN, a brand of The Channel Company. The recognition is based on direct feedback from solution providers across North America, who evaluated technology vendors on product innovation, support, partnership, and managed and cloud services. WatchGuard achieved an overall score of 92.8, ranking first in the category.

Fewer lockouts, less manual work: What's new for 1Password EPM admins

As a company grows, more employees join, but the size of the IT team overseeing critical systems often doesn’t grow at the same pace. Admins have to be intentional about prioritizing their efforts to meet the needs of a growing organization. That’s why we’re excited to announce several releases aimed at helping admins optimize their organization’s use of 1Password in two important areas: reducing lockouts and automating provisioning at scale.

AI Assurance: The Third Head of Your AI Governance Watchdog

In July 2026, two AI stories broke that appeared unrelated on the surface. But were they really? The first was an AI product's shared conversation links, meant for specific people, turning up in Google searches, some holding sensitive personal and company data. The second was a frontier AI lab's own model escaping a security sandbox during an internal evaluation and spending four and a half days inside three companies' systems. One involved ordinary users making a common mistake.

Zombie APIs Are Costing You More Than You Think: A Risk Quantification Guide

Zombie APIs are API versions or endpoints that were once known and documented, but were never properly retired. A team ships v2 of an API, tells everyone to migrate, and assumes v1 is dead. In reality, v1 is still running on a server somewhere, still accepting requests, and still connected to production data. This is different from unmanaged APIs, which were never documented in the first place. Zombie APIs were documented once.

Aikido Security achieves ISO 42001:2023 certification for AI governance

Aikido Security has achieved ISO 42001:2023 certification, the international standard for AI management systems, a step few security vendors have taken so far. The certification confirms that Aikido runs a structured, continuously improving governance system for managing the risks introduced by its AI-enabled features, across our entire platform.

Aikido launches agentic pentesting for Android apps

TL;DR: Aikido now pentests Android apps. The same agents that test your web apps and APIs can now work through your APK, log into the app, and reason through it, alongside the backend it talks to, in a single assessment. Findings come back with reproduction steps and are ready for an AutoFix, the same as any other Aikido pentest. Aikido has been running autonomous pentests against web apps and APIs since November 2025.