Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cyber Threat Intelligence for Insurance: The Supply Chain Risk Insurers Can't Ignore

A strong internal security score means little if the brokers, claims processors, and software vendors an insurer depends on are the weak link. This blog breaks down where insurance supply chain risk sits and what to do about it.

How Keeper Helps Enforce Zero Standing Privilege

Privileged accounts are standing invitations for attackers, with credentials to steal and permissions to misuse. When administrative rights are persistently active, whether or not they’re being used, privileged accounts significantly expand the attack surface. Zero Standing Privilege (ZSP) shrinks that risk by ensuring no user holds permanent elevated access.

Stop runtime threats with Workload Protection response actions

Modern threats increasingly unfold at runtime, where attackers exploit live workloads, spawn malicious processes, and move laterally across your environment. Detecting that activity is essential, but a signal only matters if you can stop it. When a threat appears, every step before a response gives an attacker more time to act. Datadog Workload Protection can now directly remediate threats with both automated and manual response.

Dissecting Attacks Is Only Valuable If It Informs Controls: What the Unit 42 agentic AI investigation should change in your control set, stage by stage.

The volume of published incident research involving agentic AI is increasing, and the analysis that follows each report tends to concentrate on the same attribute: speed. The recent investigation from Unit 42, the threat intelligence and incident response group at Palo Alto Networks, is a representative case.

Why slow fraud investigations cost more than you think: The ROI case for AI-assisted investigation

Fraud doesn’t wait for your investigation queue. Every minute an alert sits unresolved gives fraudsters more time to move the money. Yet at most financial institutions, a single case still takes an analyst 10 to 30 minutes to investigate — pulling transaction history, checking device and behavioral data, weighing risk signals and documenting a decision. Multiply that by hundreds or thousands of alerts a day, and slow investigation isn’t just an inconvenience.

From Social Media to Dark Web Forums: Monitoring Threats Across the Web

Cyber threats rarely start in hidden corners of the internet. Most begin in plain sight, on social media, before moving into Telegram channels and dark web forums. This blog looks at why organisations need visibility across the open and underground web, and how CYJAX connects the two into one picture of risk.

CVE-2026-0768: Critical RCE in Langflow AI Agent Builder

A critical remote code execution vulnerability has been identified in Langflow. The vulnerability was first reported to the vendor in mid-2025 and disclosed publicly as a zero-day in January 2026. Exploitation attempts rose sharply in late August 2026, moving from isolated probing to continuous, multi-source scanning within days.

Stop breaking SLAs: how to patch vulnerabilities before the fix even ships

You're almost out of time on an SLA on a critical dependency vulnerability, but you have no room in the current sprint for the manual testing needed to make sure you don't break production. Missing the remediation deadline itself is a finding in your next SOC 2 or ISO 27001 report, but the risk of exploitation is also growing with advancing AI models.

Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy

In addition to everyday users, Google's infrastructure is trusted by email security gateways, enterprise firewalls and automated URL detonation platforms. Threat actors know this.