Blog
Guías de cumplimiento y seguridad
Guías prácticas y directas sobre ISO 27001, SOC 2 y cumplimiento de seguridad, y cómo automatizar lo que ralentiza a los equipos.
Security Advisory · August 30, 2026 · 11 min
Citrix NetScaler CVE-2026-8452: How a "Denial-of-Service" Bug Became Unauthenticated Root
It shipped as a bug that could crash your VPN. Six weeks later it was a bug that could hand an attacker root on the box guarding your entire network — no password required. This is CVE-2026-8452, the Citrix NetScaler flaw everyone underestimated. Here’s exactly what happened, and what to do before the web shell shows up.
Leer la guía →Guide · August 30, 2026 · 9 min
The ACSC Essential Eight, Explained: The 8 Strategies, Maturity Levels 0–3, and How to Prove Them
The Essential Eight is Australia’s cyber-security baseline — mandatory for federal government and the de-facto standard everyone else is measured against. Here’s what the eight strategies actually require, how the Maturity Model works, and why proving them beats claiming them.
Leer la guía →Guide · August 30, 2026 · 9 min
The Australian Privacy Principles (APPs), Explained: All 13 Principles, the NDB Scheme, and How to Comply
The Australian Privacy Principles are the backbone of the Privacy Act 1988 — Australia’s equivalent of GDPR. Here are the 13 principles, the mandatory breach-notification scheme, and how a GDPR-ready program carries most of the way.
Leer la guía →Guide · August 30, 2026 · 8 min
APRA CPS 234, Explained: Information Security for Banks, Insurers & Super Funds
CPS 234 is APRA’s information-security standard — mandatory for banks, insurers and super funds. Here’s what it requires, the notification clock everyone forgets, and how ISO 27001 gets you most of the way.
Leer la guía →Guide · August 18, 2026 · 13 min
The SOC 2 Journey, Explained: From Zero to Audit-Ready in 9 Steps
Every B2B software company hits the same wall: a buyer’s security team asks for your SOC 2 report, and the deal stalls without it. This is the whole journey — who needs it, what to pick, which criteria to scope, and every step from your first control to a public trust center — in nine steps and one four-minute video.
Leer la guía →Guide · August 14, 2026 · 12 min
Zero Trust for Autonomous AI Agents: Identity, Network & Telemetry
Your AI agents can place orders, reroute fleets and issue refunds at machine speed. Most of them do it on a broad API key that never expires. That’s not an integration — it’s a standing breach waiting for one bad prompt. Zero Trust is how you give agents real power without handing over the keys.
Leer la guía →Guide · August 14, 2026 · 12 min
What Is Red Teaming? How Attackers Really Break In — and How CATAAM Tests It
Your scanners are green. Your firewall is configured by the book. Your last pen test passed. So why do breaches still happen? Because a checklist proves you followed the rules — it doesn’t prove an adversary can’t get in. That’s what red teaming is for.
Leer la guía →Security Advisory · August 13, 2026 · 11 min
A Self-Propagating npm Worm Is Stealing Every Secret It Can Find: Shai-Hulud / ChainDrop, Explained
On August 4, 2026, a self-propagating worm tore through the npm registry — hijacking maintainer accounts, weaponizing their publish tokens, and vacuuming up every credential it could reach across 400+ packages. It’s the software-supply-chain nightmare in its purest form: you didn’t have to be careless. You just had to run npm install.
Leer la guía →Research · August 13, 2026 · 10 min
We Analyzed 1,307 Vulnerabilities in 60 Days: Two-Thirds Were RCE, and AI Tools Are the New Attack Surface
Between June 13 and August 12, 2026, CATAAM’s threat pipeline ingested and analyzed 1,307 vulnerability advisories from GitHub Security Advisories and CISA’s Known Exploited Vulnerabilities catalog. The pattern is stark: remote code execution dominates, threat-actor leverage is overwhelmingly high, and AI tooling has become its own distinct — and largely unguarded — attack surface.
Leer la guía →Security Advisory · August 12, 2026 · 11 min
Langflow RCE (CVE-2026-9198): What Langflow Is, Who Got Hit, and How to Fix It
There’s a free tool thousands of teams use to build AI apps — Langflow. Right now, attackers are taking it over with a single web request and no password. Here’s the tool explained in plain English, how to tell if you’re exposed, and the exact steps to fix it.
Leer la guía →Security Advisory · August 12, 2026 · 12 min
Cisco Secure Firewall CVE-2026-20349: What It Is, Who’s Exposed, and How to Patch (with Commands)
There’s a box at the edge of thousands of corporate networks that most people have never heard of — yet it decides who gets in. It’s the Cisco Secure Firewall, and in August 2026 attackers started knocking it offline. Here’s the device explained in plain English, how to tell if you’re exposed, and the exact commands to patch it.
Leer la guía →Case Study · August 11, 2026 · 11 min
How a Logistics Company Passed SOC 2 with OKF and Claude — The Koorier Case Study
A 40-person last-mile carrier had its data, people, and processes scattered across a dozen vendors — the worst possible starting point for SOC 2. Here’s how Koorier turned that sprawl into a single OKF knowledge graph its whole team could query through Claude, while CATAAM’s ASM, iASM, and red-team exercises found the exposure a control checklist never would.
Leer la guía →AI Security · August 5, 2026 · 8 min
No, an AI Didn’t “Escape the Lab” This Week — It Leaked Your API Keys
The scariest AI-security story of Black Hat 2026 isn’t a model that “went rogue.” It’s a boring credential-leak bug in the plumbing every AI agent is built on — and unlike the viral headlines, it has a tracking number, a severity score, and a patch.
Leer la guía →OKF · August 5, 2026 · 7 min
OKF for Claude: Give Claude Your Real, Current Knowledge Graph over MCP
Pasting documents into a chat is lossy, stale, and unverifiable. OKF gives Claude something better: a live, linked, cryptographically signed knowledge graph it can traverse over the Model Context Protocol — so its answers come from your real, current data.
Leer la guía →AI Security · August 4, 2026 · 11 min
The MCP CVE Wave Didn’t Crest — It Broke Wider: A Second SDK, the Vendors’ Own Servers, and the First Exploited-in-the-Wild Bug
In July we mapped the first Model Context Protocol CVE wave and argued it was becoming a category. Six weeks later the argument is settled. A second official SDK fell to the same bugs, the platform vendors shipped flawed servers of their own, and the first MCP-ecosystem flaw is now being exploited in the wild.
Leer la guía →Threat Intelligence · August 4, 2026 · 7 min
Oracle E-Business Suite Under Attack (CVE-2026-46817): A CVSS 9.8 Payments Takeover, Read Through SOC 2 and ISO 27001
ERP is where procurement, payroll, and payments live — the crown jewels, wired to the internet and patched on a slow clock. CVE-2026-46817 turns Oracle Payments into an unauthenticated takeover. The security story is obvious; the compliance story is the one most teams miss.
Leer la guía →AI Security · July 21, 2026 · 10 min
Exposed MCP Servers Are the New Unguarded Door: The July 2026 CVE Wave and How to Find Yours
The Model Context Protocol turns a language model into something that can act. In July 2026 the ecosystem shipped a dozen ways for a stranger to act through it — and the common thread wasn’t exotic. It was a server built for localhost, quietly put on the internet.
Leer la guía →AI Governance · July 14, 2026 · 9 min
The Tool Nobody Reviewed: An MCP Zero-Day Read Through SOC 2 and ISO 42001
A company with a clean SOC 2 report shipped an AI agent to production. One of its tools was missing a single line of validation — and that line was the whole audit.
Leer la guía →Engineering · July 7, 2026 · 5 min
One Connector, One Compliance Test: How We Built 428 Integrations
Most compliance tools treat integrations as a logo wall. We made each connector run a test. Here’s the engineering behind 428 vendor integrations — grounded in exactly what shipped.
Leer la guía →AI Governance · July 1, 2026 · 7 min
Prompt Guard: Stop Secrets Leaking into ChatGPT & Claude — and Prove It for ISO 42001
Your team pastes API keys and source code into AI chatbots every day. Here’s an open-source, local-first way to stop it — and to turn each blocked leak into audit evidence.
Leer la guía →AI Governance · July 1, 2026 · 6 min
Shadow AI: Your Employees Are Pasting Secrets into ChatGPT (How to Stop It in 2026)
Most “AI policy” documents are unenforced. The leak is already happening in the prompt box — here’s how to actually close it.
Leer la guía →AI Governance · July 1, 2026 · 6 min
EU AI Act Article 12: Logging & Record-Keeping Requirements, Explained (2026)
Article 12 turns “trust us” into “show us the logs.” Here’s what it requires and how to produce the evidence without a six-month project.
Leer la guía →AI Governance · July 1, 2026 · 7 min
What Is an AIMS? The ISO 42001 AI Management System, Explained
Everyone says “stand up an AIMS” — but what is it, actually? Here’s the AI Management System in plain terms, and the first control worth putting in force.
Leer la guía →ISO 27001 · June 24, 2026 · 9 min
ISO 27001 Certification Checklist (2026): 12 Steps to Certified
Everything you need to take an organization from zero to ISO 27001 certified — as a checklist you can actually work through.
Leer la guía →ISO 27001 · June 24, 2026 · 7 min
How Much Does ISO 27001 Certification Cost in 2026?
What ISO 27001 actually costs in 2026 — audit fees, tooling, training, and internal time — and where the real savings are.
Leer la guía →ISO 27001 · June 24, 2026 · 8 min
ISO 27001 vs SOC 2: Which Should You Get First? (2026)
The honest comparison — what each proves, who demands them, and why you rarely have to choose.
Leer la guía →OKF · June 27, 2026 · 6 min
What Is OKF (Open Knowledge Format)? Google’s Open Standard, Explained
The plain-English explainer on Open Knowledge Format — Google’s open standard for data that AI agents can actually read.
Leer la guía →OKF · June 27, 2026 · 6 min
OKF in AI: Giving Agents Real, Current, Verifiable Context
How Open Knowledge Format gives AI agents grounded, current, verifiable context — and why that beats dumping documents.
Leer la guía →OKF · June 27, 2026 · 5 min
OKF + Git: Version-Controlled Knowledge Graphs as Markdown
OKF is just Markdown — so it lives in Git natively. Diffable, reviewable, and auditable knowledge graphs.
Leer la guía →OKF · June 27, 2026 · 6 min
OKF vs MCP: How Open Knowledge Format and the Model Context Protocol Work Together
OKF and MCP aren’t competitors — they’re a stack. The format your knowledge lives in, and the protocol an agent uses to reach it.
Leer la guía →ISO 42001 · June 27, 2026 · 9 min
Get Your Organization ISO 42001-Ready: A 2026 Readiness Guide
What it takes to become ISO/IEC 42001-ready — the first international standard for AI management systems — as a checklist you can work through.
Leer la guía →ISO 42001 · June 27, 2026 · 7 min
ISO 42001 vs ISO 27001: AI Governance and Information Security, Compared
The honest comparison — what each standard proves, how they overlap, and why teams building AI increasingly need both.
Leer la guía →ISO 42001 · June 27, 2026 · 8 min
ISO 42001 Annex A Controls Explained: All 9 Objectives
The 38 Annex A controls, grouped under nine objectives — what each set covers and how to evidence it.
Leer la guía →ISO 42001 · June 27, 2026 · 7 min
How Much Does ISO 42001 Certification Cost in 2026?
What ISO 42001 actually costs in 2026 — audit fees, tooling, and internal time — and where the real savings are.
Leer la guía →