The Hugging Face Incident: A CISO Wake-Up Call for the Agentic Era 2026-07-31 True Dr. Guy Waizel True Cato CTRL™ Threat Brief: AsyncAPI Supply Chain Attack Delivers Miasma Malware Through Trusted npm Packages 2026-07-20 True Tal Biran True The Agentic Attacker: One Objective, One Prompt, Forty Minutes, Domain Admin – Game Over 2026-07-15 True Tal Biran True DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE 2026-07-01 True Tal Biran True Cato CTRL™ Threat Research: Operation Poisson – Analyzing a Cybercriminal’s Entire Operation 2026-06-16 True Tal Biran True From CVE Disclosure to Agentic Protection in 45 Minutes. Why it Matters Now. 2026-06-11 True Tal Biran True Cato CTRL™ Threat Research: From Fiscal Lures to Remote Access, A Previously Undocumented NinjaOne RMM Abuse Chain 2026-06-10 True Tal Biran True Cato CTRL Threat Research: Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware 2026-05-13 True Tal Biran True Threat Brief: CVE-2026-41940: Critical cPanel & WHM Authentication Bypass Actively Exploited in the Wild 2026-05-02 True Tim Chen True Cato CTRL™ Threat Brief: Middle East Escalation and Summary of Notable Iranian-Linked CVEs 2026-03-15 True Dr. Guy Waizel True Cato CTRL™ Threat Research: New MongoDB Vulnerability Allows Instant Remote Server Takedown (CVE-2026-25611) 2026-03-04 True Vitaly Simonovich True Cato CTRL™ Threat Research: Vulnerability Discovered in Open WebUI Enables Account Takeover and Remote Code Execution (CVE-2025-64496) 2026-01-05 True Vitaly Simonovich True Cyberattack on the Sun: Threat Actors Manipulate Solar Panel Systems; Agentic AI Increases the Risk 2025-12-15 True Dr. Guy Waizel True Cato CTRL™ Threat Brief: “React2Shell” Vulnerability Targeting React Server Components 2025-12-09 True Dr. Guy Waizel True The Dark Side of Black Friday: When Ransomware Attacks Join the Shopping Rush 2025-11-24 True Omri Albalak True Cato CTRL™ Threat Research: Two Vulnerabilities in Anthropic’s MCP SDK Enable OAuth Token Theft and Supply Chain Attacks 2025-11-13 True Dr. Guy Waizel True Cato Networks Statement on Salesforce-Salesloft Drift Incident 2025-09-03 True Aviram Katzenstein True Cato CTRL™ Threat Brief: “ToolShell” Exploit Targeting Microsoft SharePoint Vulnerabilities 2025-07-24 True Guy Waizel True Cato CTRL™ Threat Research: Analyzing LAMEHUG – First Known LLM-Powered Malware with Links to APT28 (Fancy Bear) 2025-07-23 True Vitaly Simonovich True Cato CTRL™ Threat Research: Investigation of RMM Tools Leveraged by Ransomware Gangs in Real-World Incidents 2025-07-21 True Guy Waizel True Cato CTRL™ Threat Actor Profile: IntelBroker 2025-07-16 True Vitaly Simonovich True Cato CTRL™ Threat Research: Overview of BloodHound and Associated Collectors Including ShadowHound, SharpHound, and SoapHound 2025-07-08 True Dolev Moshe Attiya True Cato CTRL™ Threat Research: PoC Attack Targeting Atlassian’s Model Context Protocol (MCP) Introduces New “Living off AI” Risk 2025-06-19 True Guy Waizel True Breaking down ‘EchoLeak’, the First Zero-Click AI Vulnerability Enabling Data Exfiltration from Microsoft 365 Copilot 2025-05-31 True Itay Ravia True 2025 Cato CTRL™ Threat Report: Top 4 AI Predictions for the Year Ahead 2025-03-18 True Etay Maor True Cato CTRL Threat Research: Advanced Behavioral Analysis of IoT and OT Devices for IoC Collection 2025-02-26 True Oz Soprin True Cato CTRL Threat Research: Unmasking Hellcat – Not Your Average Ransomware Gang 2025-01-28 True Etay Maor True When Public Prompts Turn Into Local Shells: ‘CurXecute’ – RCE in Cursor via MCP Auto‑Start 2025-01-08 True Ofir Abu True Cato CTRL Threat Research: ProKYC Selling Deepfake Tool for Account Fraud Attacks 2024-10-09 True Etay Maor True Cato CTRL Threat Actor Profile: Yashechka 2024-08-26 True Etay Maor True Highlights from Q2 2024 Cato CTRL SASE Threat Report 2024-08-13 True Etay Maor True A Brief History of Graduality 2024-07-19 True Vadim Freger True Cato CTRL Issues New SASE Threat Report 2024-05-07 True Etay Maor True WANTED: Brilliant AI Experts Needed for Cyber Criminal Ring 2024-03-04 True Etay Maor True When Patch Tuesday becomes Patch Monday – Friday 2024-03-01 True Vadim Freger True How to steal intellectual property from GPTs 2024-01-29 True Vitaly Simonovich True Atlassian Confluence Server and Data Center Remote Code Execution (CVE-2023-22527) – Cato’s Analysis and Mitigation 2024-01-25 True Vadim Freger True How Long Before Governments Ban Use of Security Appliances? 2023-12-07 True Eyal Webber Zvik True Cisco IOS XE Privilege Escalation (CVE-2023-20198) – Cato’s analysis and mitigation 2023-11-02 True Vadim Freger True Cato Protects Against Atlassian Confluence Server Exploits (CVE-2023-22515) 2023-10-06 True Matan Mittelman True New Critical Vulnerability Underscores the Need for Virtual Patching 2022-12-20 True Etay Maor True The OpenSSL Vulnerability: A Cato Networks Labs Update 2022-11-03 True Dave Greenfield True Spring4Shell Might Grab Headlines, But Log4j Exploits Swamped Enterprises, Finds Cato Threat Report 2022-07-28 True Etay Maor True Cato Patches Vulnerabilities in Java Spring Framework in Record Time 2022-03-31 True Dima Solomonov True Analysis of Phishing Kill Chain Identifies Emerging Technique That Exploits Trust in Your Collaboration Platforms 2022-01-25 True Zohar Buber True Log4J – A Look into Threat Actors Exploitation Attempts 2021-12-13 True Dolev Moshe Attiya True Cato Networks Rapid Response to The Apache Log4J Remote Code Execution Vulnerability 2021-12-12 True Eyal Webber Zvik True What Makes for a Great IPS: A Security Leader’s Perspective 2021-11-16 True Avishay Zawoznik True How to Detect DNS Tunneling in the Network? 2021-11-02 True Zohar Buber True Attackers are Zeroing in On Trust with New Device ID Twist 2021-08-15 True Dima Solomonov True