Topic hub

Security

Evaluating Security this quarter? This page brings together what changed, which companies are most active, what practitioners are asking and how to build a shortlist.

Threat research, identity, network and cloud security, and the new attack surface created by AI tools and agents.

What changed recently

Start with the news. These are the Security stories getting the most attention right now, so you know what has shifted before you talk to anyone.

Newest in the feed →
SecurityWhy it matters

Threat Actors Use Google Ads To Target Ledger Users

In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake…

Why it matters, from the Techarda editors: The lure chains trusted platforms (Google Ads, Google Cloud Storage, Vercel and Google Sites), so domain-reputation checks alone won't stop it. Worth sharing with anyone who supports crypto or hardware-wallet users, and a prompt to check how your own brand could be impersonated the same way.

Zscaler·via Zscaler ThreatLabz
Security

Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?

Rapid7·via Rapid7 Blog
Security

Two Things Every Cyber Asset Attack Surface Management (CAASM) Tool Needs to Get Right

Cyber Asset Attack Surface Management (CAASM) solved a significant problem. Security teams can now say with confidence what they own. But, two things separate a CAASM tool that stops there from one that actually moves the needle on risk. The first is what the inventory itself carries. The second is what it connects to. 1. An inventory needs to do more than list what exists A list of assets is…

Check Point Software·via Check Point Software Blog
Security

Agents can now set up your website’s security with Turnstile Spin

Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification.

Cloudflare·via Cloudflare Blog
Security

Darktrace / SECURE AI: Behavioral Security for the AI enterprise

Discover how Darktrace / SECURE AI applies behavioral security to AI usage, prompts, agents, and development to help organizations adopt AI securely.

Darktrace·via Darktrace Blog
Security

Wiz Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026

Forrester’s Proactive Security Platforms evaluation rated Wiz with top scores across eight areas, reflecting our commitment to securing the AI era

Wiz·via Wiz Blog
Security

How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers

External security researchers at Accomplish identified a vulnerability in Cloudflare Containers that could expose residual disk data from previous workloads. We explain how the issue worked, how we investigated it, and the steps we took to remediate it.

Cloudflare·via Cloudflare Blog
Security

When Business Email Compromise Starts Rewriting Reality

Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets. This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details…

Rapid7·via Rapid7 Blog

Companies to know in Security

Those stories keep returning to the same names. These are the companies we track in this category; each profile has its news, solutions and published reviews.

All companies →

Palo Alto Networks

Santa Clara, California, USA

Palo Alto Networks is a cybersecurity company offering network security, cloud security and security operations platforms. Its portfolio includes next-generation firewalls and Strata network security, Prisma SASE and Prisma Cloud, Cortex XSIAM, XDR and Cortex Cloud, and Unit 42 threat intelligence and incident response. Founded in 2005 by Nir Zuk, it is headquartered in Santa Clara, California, and listed on Nasdaq.

CrowdStrike

Austin, Texas, USA

CrowdStrike is an American cybersecurity company founded in 2011 by George Kurtz, Dmitri Alperovitch and Gregg Marston, and headquartered in Austin, Texas. Its cloud-native Falcon platform uses a single lightweight agent to provide endpoint protection, extended detection and response, identity protection, cloud security, next-gen SIEM and threat intelligence, with managed services. CrowdStrike is listed on Nasdaq (CRWD).

Microsoft

Redmond, Washington, USA

Microsoft is a global technology company whose enterprise portfolio spans the Azure cloud platform, Microsoft 365 productivity software, Dynamics 365 business applications, security products and developer tools such as GitHub. Founded in 1975 and headquartered in Redmond, Washington, Microsoft is one of the largest providers of cloud and AI services to businesses.

Fortinet

Sunnyvale, California, USA

Fortinet is a US cybersecurity company known for its FortiGate next-generation firewalls, built on its FortiOS operating system and custom security processors. Its Fortinet Security Fabric spans secure networking, SD-WAN, SASE, switching, wireless, endpoint and security operations. Founded in 2000 by Ken Xie and Michael Xie and headquartered in Sunnyvale, California, Fortinet is listed on Nasdaq.

Zscaler

San Jose, California, USA

Zscaler is a US cloud security company founded in 2007 by Jay Chaudhry and K. Kailash and headquartered in San Jose, California. Its Zero Trust Exchange platform delivers secure access to the internet, SaaS and private applications, including Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA) and Zscaler Digital Experience (ZDX). Zscaler is listed on Nasdaq.

Cisco

San Jose, California, USA

Cisco is a US networking and security company founded in 1984 and headquartered in San Jose, California. It sells enterprise, data centre and service provider networking (Catalyst, Nexus, Meraki, Silicon One), security products including firewalls and Cisco Security Cloud, Splunk observability and security analytics, and Webex collaboration. It completed its acquisition of Splunk in 2024.

Check Point Software

Tel Aviv, Israel

Check Point Software Technologies is an Israeli cybersecurity company founded in 1993 and headquartered in Tel Aviv. It sells network firewalls and the Quantum security gateway family, CloudGuard cloud security, Harmony workspace and email security, and the Infinity platform for unified management and threat prevention, serving enterprises, governments and service providers. It is listed on Nasdaq.

Okta

San Francisco, California, USA

Okta is an identity and access management company that provides cloud-based single sign-on, multi-factor authentication, lifecycle management and identity governance for workforces, and customer identity through Auth0. It serves enterprises, public sector organisations and developers securing access to applications and AI agents. Founded in 2009 by Todd McKinnon and Frederic Kerrest, Okta is headquartered in San Francisco and listed on Nasdaq.

SentinelOne

Mountain View, California, USA

SentinelOne is a US cybersecurity company headquartered in Mountain View, California, founded in 2013. Its Singularity Platform provides AI-driven endpoint protection, extended detection and response (XDR), cloud security, identity threat detection and AI SIEM, with Purple AI as a generative AI security analyst. SentinelOne serves enterprises and governments and is listed on the New York Stock Exchange.

Cloudflare

San Francisco, California, USA

Cloudflare is a US connectivity cloud company founded in 2009 and headquartered in San Francisco. It operates a global network providing CDN, DNS, DDoS protection, web application firewall, Zero Trust access and SASE services, and a developer platform including Workers serverless compute, R2 storage and Workers AI. Cloudflare has been listed on the New York Stock Exchange since 2019.

Wiz

New York City, New York, USA

Wiz is a cloud security company founded in 2020 by Assaf Rappaport, Ami Luttwak, Yinon Costica and Roy Reznik, headquartered in New York City with research and development in Israel. Its cloud-native application protection platform (CNAPP) covers cloud posture, vulnerabilities, identities, code and runtime threats using agentless scanning. Google completed its $32 billion acquisition of Wiz in March 2026, and Wiz is now part of Google Cloud.

Netskope

Santa Clara, California, USA

Netskope is a cybersecurity company that provides cloud-delivered Security Service Edge (SSE) and SASE through its Netskope One platform, combining secure web gateway, CASB, zero trust network access, data loss prevention, firewall and SD-WAN capabilities on its NewEdge private network. Founded in 2012 and headquartered in Santa Clara, California, Netskope listed on Nasdaq in 2025.

Proofpoint

Sunnyvale, California, USA

Proofpoint is a cybersecurity company headquartered in Sunnyvale, California, founded in 2002. It focuses on human-centric security, with products for email security, security awareness training, data loss prevention, insider threat management, identity threat defence and information archiving. Proofpoint was taken private by Thoma Bravo in 2021 and serves enterprises and government organisations worldwide.

Rapid7

Boston, Massachusetts, USA

Rapid7 is a US cybersecurity company headquartered in Boston, Massachusetts, founded in 2000. It sells the Command Platform for exposure management and threat detection and response, including InsightVM vulnerability management, InsightIDR SIEM/XDR, cloud security and managed detection and response services. Rapid7 also maintains the Metasploit penetration testing framework and is listed on Nasdaq.

Tenable

Columbia, Maryland, USA

Tenable is a US cybersecurity company founded in 2002 and headquartered in Columbia, Maryland. It is known for the Nessus vulnerability scanner and sells exposure management products, including the Tenable One platform, Tenable Vulnerability Management, Tenable Cloud Security, Tenable Identity Exposure and Tenable OT Security. Tenable is listed on Nasdaq and serves enterprises and government agencies.

Qualys

Foster City, California, USA

Qualys is a cloud-based cybersecurity and compliance company headquartered in Foster City, California, founded in 1999. Its Qualys Cloud Platform provides vulnerability management (VMDR), asset inventory, patch management, cloud security (TotalCloud), web application scanning, policy compliance and risk management through its Enterprise TruRisk Platform. Qualys is listed on Nasdaq.

CyberArk

Newton, Massachusetts, USA

CyberArk is an identity security company founded in Israel in 1999 by Udi Mokady and Alon N. Cohen, with headquarters in Newton, Massachusetts, and Petah Tikva, Israel. Its Identity Security Platform spans privileged access management, secrets management, machine identity security, endpoint privilege management and workforce identity. Palo Alto Networks completed its acquisition of CyberArk in 2026, and CyberArk was delisted from Nasdaq.

TrendAI

Tokyo, Japan

TrendAI is the enterprise cybersecurity business of Japan's Trend Micro Incorporated, which renamed the business from Trend Micro to TrendAI in March 2026. It sells the TrendAI Vision One platform, covering endpoint, cloud, network and email security, XDR and attack surface risk management. Its parent company, founded in 1988 and headquartered in Tokyo, is listed on the Tokyo Stock Exchange.

Sophos

Abingdon, Oxfordshire, England, UK

Sophos is a British cybersecurity company founded in 1985 and headquartered in Abingdon, Oxfordshire. It sells endpoint protection (Intercept X), firewalls, managed detection and response (MDR), and email and cloud security, managed through the Sophos Central platform, largely via channel partners to mid-sized organisations. Sophos has been owned by Thoma Bravo since 2020 and acquired Secureworks in 2025.

Darktrace

Cambridge, England, United Kingdom

Darktrace is a British cybersecurity company founded in 2013 and headquartered in Cambridge, England. It uses self-learning AI that models normal behaviour in each organisation to detect and respond to threats across networks, email, cloud, endpoints, identities and operational technology. Darktrace was listed on the London Stock Exchange from 2021 until private equity firm Thoma Bravo completed its acquisition in 2024.

What practitioners are asking

Vendor news only tells you half of it. This is what people working in Security are discussing and asking each other.

Open the space →

Build a shortlist

With the news, the companies and the open questions in view, the evaluation guide takes you through criteria and trade-offs to a shortlist you can defend.

More Security stories

If you want more background, here is more of the recent coverage.

All in the feed →
Security

A Decision Model Breaks Like Any Other Language Model: A First Look at Jev

A new kind of AI model returns decisions instead of text. We spent a day trying to change its mind. It cost about 50 cents. In this article Jev is a new kind of AI model that returns typed decisions instead of text, built for software to call rather than for people to read. We put it inside a realistic application and tried to change its verdict from the outside. →every configuration we tested…

Check Point Software·via Check Point Software Blog
Security

Scan for Good: Using AI to discover and fix high-priority exposures across public services and critical infrastructure

New initiative partners with under-resourced organizations to uncover, remediate exploitable risk at scale.

Wiz·via Wiz Blog
Security

Can We Control Every AI Agent Before It Becomes Our Next Privileged Insider?

AI agents are moving into the enterprise much faster than most security programs were designed to handle. They are no longer just answering questions or generating content. Agents can read email, access SaaS applications, query databases, invoke APIs, use MCP tools, modify records and execute business workflows. In other words, AI is moving from generating answers to taking actions. For CISOs and…

Check Point Software·via Check Point Software Blog
Security

Should you let AI shop for you this holiday season? Here’s what TrendLife found

Should you let AI shop for you? TrendLife tested six AI tools through the same set of realistic shopping tasks. Here's what we found: The post Should you let AI shop for you this holiday season? Here’s what TrendLife found appeared first on TrendLife Blog .

TrendAI·via TrendAI News
Security

CrowdStrike Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026

CrowdStrike·via CrowdStrike Blog
Security

Agent Hijacks: How Conversation History Poisoning Can Turn AI Agents Into Attackers

Darktrace researchers demonstrate how conversation history poisoning can hijack agentic harnesses, convincing AI agents to perform offensive cyber operations with little to no human interaction.

Darktrace·via Darktrace Blog
Security

CISA BOD 26-04 Timelines for Three Linux Kernel CVEs

Executive Summary CISA added three actively exploited Linux kernel vulnerabilities: CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog on September 18, 2026, triggering a 3-day remediation deadline that passed on September 21. Under CISA BOD 26-04, a 3-day window applies to CVE-2025-39682 across all assets, and for the other two, the deadline is 3 days […]

Qualys·via Qualys Blog
Security

How dynamic application security testing validates risk at runtime

Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give developers enough evidence to fix it? Dynamic application security testing (DAST) helps answer those questions by testing applications as an attacker encounters them. The IDC…

Rapid7·via Rapid7 Blog
Security

Workforce AI Security Policy Management Is Now Conversational

In this article The new Workforce AI MCP is Check Point’s own Model Context Protocol server for Workforce AI Security. Connect a compatible AI client and you can query, analyze, and manage your employee AI usage policy in natural language instead of working through filters, screens, and individual rule checks. →ask plain questions such as which rule applies to a given user and application, or…

Check Point Software·via Check Point Software Blog
Security

CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM

Overview On September 22, 2026, F5 published a security advisory for CVE-2026-94127 , a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted…

Rapid7·via Rapid7 Blog
Security

Detecting Rogue AI Agents: When Enterprise Agents Turn to Hacking

Darktrace researchers found that AI agents tasked with solving impossible challenges frequently resorted to hacking techniques. Learn how Darktrace detects and disrupts rogue agent behavior in real time.

Darktrace·via Darktrace Blog
Security

We just shipped support for the ugliest part of HTTP: Vary

Vary support is now available in Cache Rules on every plan. You can normalize known negotiation headers, pass exact values through to the origin when those small differences matter, or bypass cache when the variation is too unpredictable.

Cloudflare·via Cloudflare Blog
Security

Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616

As part of Check Point’s Frontier AI Readiness Program, we continue to release Jumbo hotfixes with security fixes and hardening improvements for our Firewall and Management products. This advisory addresses the active exploitation described below, and the immediate steps customers should take to protect affected systems. Check Point Research has identified active exploitation of two…

Check Point Software·via Check Point Software Blog
Security

Introducing Worker Previews: Isolated preview environments for every change your agent makes

Worker Previews gives every branch its own URL, configuration, state, and observability, so you and your agents can test changes in parallel without affecting production.

Cloudflare·via Cloudflare Blog
Security

Introducing Unit 42 Continuous Frontier AI Defense

Cybersecurity is in the middle of a generational shift. AI has disrupted a 30-year balance of power between defenders and adversaries. Armed with agentic AI tools and open-weight models stripped of safety … The post Introducing Unit 42 Continuous Frontier AI Defense appeared first on Palo Alto Networks Blog .

Palo Alto Networks·via Palo Alto Networks Blog
Security

Growing the WIN AI Ecosystem with Agent Integrations

WINning AI with AI: How the Wiz MCP for WIN partners accelerates a connected ecosystem

Wiz·via Wiz Blog