Blog

Guías de cumplimiento y seguridad

Guías prácticas y directas sobre ISO 27001, SOC 2 y cumplimiento de seguridad, y cómo automatizar lo que ralentiza a los equipos.

Security Advisory · August 30, 2026 · 11 min

Citrix NetScaler CVE-2026-8452: How a "Denial-of-Service" Bug Became Unauthenticated Root

It shipped as a bug that could crash your VPN. Six weeks later it was a bug that could hand an attacker root on the box guarding your entire network — no password required. This is CVE-2026-8452, the Citrix NetScaler flaw everyone underestimated. Here’s exactly what happened, and what to do before the web shell shows up.

Leer la guía →

Guide · August 30, 2026 · 9 min

The ACSC Essential Eight, Explained: The 8 Strategies, Maturity Levels 0–3, and How to Prove Them

The Essential Eight is Australia’s cyber-security baseline — mandatory for federal government and the de-facto standard everyone else is measured against. Here’s what the eight strategies actually require, how the Maturity Model works, and why proving them beats claiming them.

Leer la guía →

Guide · August 30, 2026 · 9 min

The Australian Privacy Principles (APPs), Explained: All 13 Principles, the NDB Scheme, and How to Comply

The Australian Privacy Principles are the backbone of the Privacy Act 1988 — Australia’s equivalent of GDPR. Here are the 13 principles, the mandatory breach-notification scheme, and how a GDPR-ready program carries most of the way.

Leer la guía →

Guide · August 30, 2026 · 8 min

APRA CPS 234, Explained: Information Security for Banks, Insurers & Super Funds

CPS 234 is APRA’s information-security standard — mandatory for banks, insurers and super funds. Here’s what it requires, the notification clock everyone forgets, and how ISO 27001 gets you most of the way.

Leer la guía →

Guide · August 18, 2026 · 13 min

The SOC 2 Journey, Explained: From Zero to Audit-Ready in 9 Steps

Every B2B software company hits the same wall: a buyer’s security team asks for your SOC 2 report, and the deal stalls without it. This is the whole journey — who needs it, what to pick, which criteria to scope, and every step from your first control to a public trust center — in nine steps and one four-minute video.

Leer la guía →

Guide · August 14, 2026 · 12 min

Zero Trust for Autonomous AI Agents: Identity, Network & Telemetry

Your AI agents can place orders, reroute fleets and issue refunds at machine speed. Most of them do it on a broad API key that never expires. That’s not an integration — it’s a standing breach waiting for one bad prompt. Zero Trust is how you give agents real power without handing over the keys.

Leer la guía →

Guide · August 14, 2026 · 12 min

What Is Red Teaming? How Attackers Really Break In — and How CATAAM Tests It

Your scanners are green. Your firewall is configured by the book. Your last pen test passed. So why do breaches still happen? Because a checklist proves you followed the rules — it doesn’t prove an adversary can’t get in. That’s what red teaming is for.

Leer la guía →

Security Advisory · August 13, 2026 · 11 min

A Self-Propagating npm Worm Is Stealing Every Secret It Can Find: Shai-Hulud / ChainDrop, Explained

On August 4, 2026, a self-propagating worm tore through the npm registry — hijacking maintainer accounts, weaponizing their publish tokens, and vacuuming up every credential it could reach across 400+ packages. It’s the software-supply-chain nightmare in its purest form: you didn’t have to be careless. You just had to run npm install.

Leer la guía →

Research · August 13, 2026 · 10 min

We Analyzed 1,307 Vulnerabilities in 60 Days: Two-Thirds Were RCE, and AI Tools Are the New Attack Surface

Between June 13 and August 12, 2026, CATAAM’s threat pipeline ingested and analyzed 1,307 vulnerability advisories from GitHub Security Advisories and CISA’s Known Exploited Vulnerabilities catalog. The pattern is stark: remote code execution dominates, threat-actor leverage is overwhelmingly high, and AI tooling has become its own distinct — and largely unguarded — attack surface.

Leer la guía →

Security Advisory · August 12, 2026 · 11 min

Langflow RCE (CVE-2026-9198): What Langflow Is, Who Got Hit, and How to Fix It

There’s a free tool thousands of teams use to build AI apps — Langflow. Right now, attackers are taking it over with a single web request and no password. Here’s the tool explained in plain English, how to tell if you’re exposed, and the exact steps to fix it.

Leer la guía →

Security Advisory · August 12, 2026 · 12 min

Cisco Secure Firewall CVE-2026-20349: What It Is, Who’s Exposed, and How to Patch (with Commands)

There’s a box at the edge of thousands of corporate networks that most people have never heard of — yet it decides who gets in. It’s the Cisco Secure Firewall, and in August 2026 attackers started knocking it offline. Here’s the device explained in plain English, how to tell if you’re exposed, and the exact commands to patch it.

Leer la guía →

Case Study · August 11, 2026 · 11 min

How a Logistics Company Passed SOC 2 with OKF and Claude — The Koorier Case Study

A 40-person last-mile carrier had its data, people, and processes scattered across a dozen vendors — the worst possible starting point for SOC 2. Here’s how Koorier turned that sprawl into a single OKF knowledge graph its whole team could query through Claude, while CATAAM’s ASM, iASM, and red-team exercises found the exposure a control checklist never would.

Leer la guía →

AI Security · August 5, 2026 · 8 min

No, an AI Didn’t “Escape the Lab” This Week — It Leaked Your API Keys

The scariest AI-security story of Black Hat 2026 isn’t a model that “went rogue.” It’s a boring credential-leak bug in the plumbing every AI agent is built on — and unlike the viral headlines, it has a tracking number, a severity score, and a patch.

Leer la guía →

OKF · August 5, 2026 · 7 min

OKF for Claude: Give Claude Your Real, Current Knowledge Graph over MCP

Pasting documents into a chat is lossy, stale, and unverifiable. OKF gives Claude something better: a live, linked, cryptographically signed knowledge graph it can traverse over the Model Context Protocol — so its answers come from your real, current data.

Leer la guía →

AI Security · August 4, 2026 · 11 min

The MCP CVE Wave Didn’t Crest — It Broke Wider: A Second SDK, the Vendors’ Own Servers, and the First Exploited-in-the-Wild Bug

In July we mapped the first Model Context Protocol CVE wave and argued it was becoming a category. Six weeks later the argument is settled. A second official SDK fell to the same bugs, the platform vendors shipped flawed servers of their own, and the first MCP-ecosystem flaw is now being exploited in the wild.

Leer la guía →

Threat Intelligence · August 4, 2026 · 7 min

Oracle E-Business Suite Under Attack (CVE-2026-46817): A CVSS 9.8 Payments Takeover, Read Through SOC 2 and ISO 27001

ERP is where procurement, payroll, and payments live — the crown jewels, wired to the internet and patched on a slow clock. CVE-2026-46817 turns Oracle Payments into an unauthenticated takeover. The security story is obvious; the compliance story is the one most teams miss.

Leer la guía →

AI Security · July 21, 2026 · 10 min

Exposed MCP Servers Are the New Unguarded Door: The July 2026 CVE Wave and How to Find Yours

The Model Context Protocol turns a language model into something that can act. In July 2026 the ecosystem shipped a dozen ways for a stranger to act through it — and the common thread wasn’t exotic. It was a server built for localhost, quietly put on the internet.

Leer la guía →

AI Governance · July 14, 2026 · 9 min

The Tool Nobody Reviewed: An MCP Zero-Day Read Through SOC 2 and ISO 42001

A company with a clean SOC 2 report shipped an AI agent to production. One of its tools was missing a single line of validation — and that line was the whole audit.

Leer la guía →

Engineering · July 7, 2026 · 5 min

One Connector, One Compliance Test: How We Built 428 Integrations

Most compliance tools treat integrations as a logo wall. We made each connector run a test. Here’s the engineering behind 428 vendor integrations — grounded in exactly what shipped.

Leer la guía →

AI Governance · July 1, 2026 · 7 min

Prompt Guard: Stop Secrets Leaking into ChatGPT & Claude — and Prove It for ISO 42001

Your team pastes API keys and source code into AI chatbots every day. Here’s an open-source, local-first way to stop it — and to turn each blocked leak into audit evidence.

Leer la guía →

AI Governance · July 1, 2026 · 6 min

Shadow AI: Your Employees Are Pasting Secrets into ChatGPT (How to Stop It in 2026)

Most “AI policy” documents are unenforced. The leak is already happening in the prompt box — here’s how to actually close it.

Leer la guía →

AI Governance · July 1, 2026 · 6 min

EU AI Act Article 12: Logging & Record-Keeping Requirements, Explained (2026)

Article 12 turns “trust us” into “show us the logs.” Here’s what it requires and how to produce the evidence without a six-month project.

Leer la guía →

AI Governance · July 1, 2026 · 7 min

What Is an AIMS? The ISO 42001 AI Management System, Explained

Everyone says “stand up an AIMS” — but what is it, actually? Here’s the AI Management System in plain terms, and the first control worth putting in force.

Leer la guía →

ISO 27001 · June 24, 2026 · 9 min

ISO 27001 Certification Checklist (2026): 12 Steps to Certified

Everything you need to take an organization from zero to ISO 27001 certified — as a checklist you can actually work through.

Leer la guía →

ISO 27001 · June 24, 2026 · 7 min

How Much Does ISO 27001 Certification Cost in 2026?

What ISO 27001 actually costs in 2026 — audit fees, tooling, training, and internal time — and where the real savings are.

Leer la guía →

ISO 27001 · June 24, 2026 · 8 min

ISO 27001 vs SOC 2: Which Should You Get First? (2026)

The honest comparison — what each proves, who demands them, and why you rarely have to choose.

Leer la guía →

OKF · June 27, 2026 · 6 min

What Is OKF (Open Knowledge Format)? Google’s Open Standard, Explained

The plain-English explainer on Open Knowledge Format — Google’s open standard for data that AI agents can actually read.

Leer la guía →

OKF · June 27, 2026 · 6 min

OKF in AI: Giving Agents Real, Current, Verifiable Context

How Open Knowledge Format gives AI agents grounded, current, verifiable context — and why that beats dumping documents.

Leer la guía →

OKF · June 27, 2026 · 5 min

OKF + Git: Version-Controlled Knowledge Graphs as Markdown

OKF is just Markdown — so it lives in Git natively. Diffable, reviewable, and auditable knowledge graphs.

Leer la guía →

OKF · June 27, 2026 · 6 min

OKF vs MCP: How Open Knowledge Format and the Model Context Protocol Work Together

OKF and MCP aren’t competitors — they’re a stack. The format your knowledge lives in, and the protocol an agent uses to reach it.

Leer la guía →

ISO 42001 · June 27, 2026 · 9 min

Get Your Organization ISO 42001-Ready: A 2026 Readiness Guide

What it takes to become ISO/IEC 42001-ready — the first international standard for AI management systems — as a checklist you can work through.

Leer la guía →

ISO 42001 · June 27, 2026 · 7 min

ISO 42001 vs ISO 27001: AI Governance and Information Security, Compared

The honest comparison — what each standard proves, how they overlap, and why teams building AI increasingly need both.

Leer la guía →

ISO 42001 · June 27, 2026 · 8 min

ISO 42001 Annex A Controls Explained: All 9 Objectives

The 38 Annex A controls, grouped under nine objectives — what each set covers and how to evidence it.

Leer la guía →

ISO 42001 · June 27, 2026 · 7 min

How Much Does ISO 42001 Certification Cost in 2026?

What ISO 42001 actually costs in 2026 — audit fees, tooling, and internal time — and where the real savings are.

Leer la guía →