Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How we replaced our host vulnerability scanner with the Datadog Agent

A year ago, Datadog’s cloud environment had grown to support tens of thousands of users across the globe. As our host fleet expanded alongside that user growth, we saw that our original system for vulnerability scanning was becoming less effective at reaching and assessing every host.

Gemini Never Left the Sandbox. The Sandbox Had a Door.

In short, in May 2026 a Gemini model under evaluation by the AI security firm Irregular reached the systems of three real companies, and the incident has been reported as a breakout. By Google’s own account it was nothing of the kind. The test environment had internet access it was not meant to have, the fictional target shared its name with a real company, and the model found public information online, guessed one password and found two more in public code repositories.

Why Your Collaboration Foundation Matters Most When Adopting AI Tools

Is your leadership team pushing to roll out new AI tools, but your users are still struggling with basic issues like working on large/complex files or collaborating effectively? Then you’re starting off with an ineffective AI adoption plan. AI is becoming an increasingly important collaboration tool, so it’s critical to include it as part of your foundation. You can even think of AI as being your first collaborator.

Building an evidence-grounded agentic security operations harness on Cloudflare

Security alerts rarely arrive one at a time. A single alert can cause a spike across the environment, requiring a human analyst to decide which alerts are related and what they mean. When multiple arrive at the same time, it can quickly overwhelm even a seasoned security analyst. Enter the alert paradox. Now, our built-in, multi-AI-agent security operations harness can handle more of this work at Cloudflare scale.

Emerging Threat: (CVE-2026-21589) Atlassian Data Center Arbitrary File Access via Path Traversal

CVE-2026-21589 is an arbitrary file access flaw affecting most of Atlassian’s self-hosted Data Center product line. CISA classifies it as CWE-552, files or directories accessible to external parties. An unauthenticated remote attacker can read specific files inside the web application root directory. The vulnerability carries a CVSS v4.0 base score of 9.3 (Critical). Attack vector is network, attack complexity is low, and neither privileges nor user interaction are required.

Warning: Attackers Are Tricking Employees Into Sharing Malicious Calendar Invites

Researchers at Fortra are tracking a new variant of calendar phishing in which threat actors trick employees into sharing meeting links internally. The attackers pose as prospective customers and contact non-sales employees, asking to be directed to a sales representative in order to discuss a business opportunity. The attacker then sends the employee a meeting link to forward to a sales contact. The attack takes place as follows.

Certificate monitoring with TLS, chain, and post-quantum readiness

Most customers start CertKit with SSL host monitoring. On day one, you point CertKit at the systems you already run and get every certificate and when it expires. You start with confidence that you have everything under control. Then, you automate, letting CertKit take over the certificates as they need to be renewed. Each renewal is the last time you ever have to worry about that certificate.