Blog

Guides de conformité et de sécurité

Des guides pratiques et sans superflu sur ISO 27001, SOC 2 et la conformité en sécurité — et comment automatiser ce qui ralentit les équipes.

Guide · August 30, 2026 · 9 min

The ACSC Essential Eight, Explained: The 8 Strategies, Maturity Levels 0–3, and How to Prove Them

The Essential Eight is Australia’s cyber-security baseline — mandatory for federal government and the de-facto standard everyone else is measured against. Here’s what the eight strategies actually require, how the Maturity Model works, and why proving them beats claiming them.

Lire le guide →

Guide · August 30, 2026 · 9 min

The Australian Privacy Principles (APPs), Explained: All 13 Principles, the NDB Scheme, and How to Comply

The Australian Privacy Principles are the backbone of the Privacy Act 1988 — Australia’s equivalent of GDPR. Here are the 13 principles, the mandatory breach-notification scheme, and how a GDPR-ready program carries most of the way.

Lire le guide →

Guide · August 30, 2026 · 8 min

APRA CPS 234, Explained: Information Security for Banks, Insurers & Super Funds

CPS 234 is APRA’s information-security standard — mandatory for banks, insurers and super funds. Here’s what it requires, the notification clock everyone forgets, and how ISO 27001 gets you most of the way.

Lire le guide →

Guide · August 18, 2026 · 13 min

The SOC 2 Journey, Explained: From Zero to Audit-Ready in 9 Steps

Every B2B software company hits the same wall: a buyer’s security team asks for your SOC 2 report, and the deal stalls without it. This is the whole journey — who needs it, what to pick, which criteria to scope, and every step from your first control to a public trust center — in nine steps and one four-minute video.

Lire le guide →

Guide · August 14, 2026 · 12 min

Zero Trust for Autonomous AI Agents: Identity, Network & Telemetry

Your AI agents can place orders, reroute fleets and issue refunds at machine speed. Most of them do it on a broad API key that never expires. That’s not an integration — it’s a standing breach waiting for one bad prompt. Zero Trust is how you give agents real power without handing over the keys.

Lire le guide →

Guide · August 14, 2026 · 12 min

What Is Red Teaming? How Attackers Really Break In — and How CATAAM Tests It

Your scanners are green. Your firewall is configured by the book. Your last pen test passed. So why do breaches still happen? Because a checklist proves you followed the rules — it doesn’t prove an adversary can’t get in. That’s what red teaming is for.

Lire le guide →

Security Advisory · August 13, 2026 · 11 min

A Self-Propagating npm Worm Is Stealing Every Secret It Can Find: Shai-Hulud / ChainDrop, Explained

On August 4, 2026, a self-propagating worm tore through the npm registry — hijacking maintainer accounts, weaponizing their publish tokens, and vacuuming up every credential it could reach across 400+ packages. It’s the software-supply-chain nightmare in its purest form: you didn’t have to be careless. You just had to run npm install.

Lire le guide →

Research · August 13, 2026 · 10 min

We Analyzed 1,307 Vulnerabilities in 60 Days: Two-Thirds Were RCE, and AI Tools Are the New Attack Surface

Between June 13 and August 12, 2026, CATAAM’s threat pipeline ingested and analyzed 1,307 vulnerability advisories from GitHub Security Advisories and CISA’s Known Exploited Vulnerabilities catalog. The pattern is stark: remote code execution dominates, threat-actor leverage is overwhelmingly high, and AI tooling has become its own distinct — and largely unguarded — attack surface.

Lire le guide →

Security Advisory · August 12, 2026 · 11 min

Langflow RCE (CVE-2026-9198): What Langflow Is, Who Got Hit, and How to Fix It

There’s a free tool thousands of teams use to build AI apps — Langflow. Right now, attackers are taking it over with a single web request and no password. Here’s the tool explained in plain English, how to tell if you’re exposed, and the exact steps to fix it.

Lire le guide →

Security Advisory · August 12, 2026 · 12 min

Cisco Secure Firewall CVE-2026-20349: What It Is, Who’s Exposed, and How to Patch (with Commands)

There’s a box at the edge of thousands of corporate networks that most people have never heard of — yet it decides who gets in. It’s the Cisco Secure Firewall, and in August 2026 attackers started knocking it offline. Here’s the device explained in plain English, how to tell if you’re exposed, and the exact commands to patch it.

Lire le guide →

Case Study · August 11, 2026 · 11 min

How a Logistics Company Passed SOC 2 with OKF and Claude — The Koorier Case Study

A 40-person last-mile carrier had its data, people, and processes scattered across a dozen vendors — the worst possible starting point for SOC 2. Here’s how Koorier turned that sprawl into a single OKF knowledge graph its whole team could query through Claude, while CATAAM’s ASM, iASM, and red-team exercises found the exposure a control checklist never would.

Lire le guide →

AI Security · August 5, 2026 · 8 min

No, an AI Didn’t “Escape the Lab” This Week — It Leaked Your API Keys

The scariest AI-security story of Black Hat 2026 isn’t a model that “went rogue.” It’s a boring credential-leak bug in the plumbing every AI agent is built on — and unlike the viral headlines, it has a tracking number, a severity score, and a patch.

Lire le guide →

OKF · August 5, 2026 · 7 min

OKF for Claude: Give Claude Your Real, Current Knowledge Graph over MCP

Pasting documents into a chat is lossy, stale, and unverifiable. OKF gives Claude something better: a live, linked, cryptographically signed knowledge graph it can traverse over the Model Context Protocol — so its answers come from your real, current data.

Lire le guide →

AI Security · August 4, 2026 · 11 min

The MCP CVE Wave Didn’t Crest — It Broke Wider: A Second SDK, the Vendors’ Own Servers, and the First Exploited-in-the-Wild Bug

In July we mapped the first Model Context Protocol CVE wave and argued it was becoming a category. Six weeks later the argument is settled. A second official SDK fell to the same bugs, the platform vendors shipped flawed servers of their own, and the first MCP-ecosystem flaw is now being exploited in the wild.

Lire le guide →

Threat Intelligence · August 4, 2026 · 7 min

Oracle E-Business Suite Under Attack (CVE-2026-46817): A CVSS 9.8 Payments Takeover, Read Through SOC 2 and ISO 27001

ERP is where procurement, payroll, and payments live — the crown jewels, wired to the internet and patched on a slow clock. CVE-2026-46817 turns Oracle Payments into an unauthenticated takeover. The security story is obvious; the compliance story is the one most teams miss.

Lire le guide →

AI Security · July 21, 2026 · 10 min

Exposed MCP Servers Are the New Unguarded Door: The July 2026 CVE Wave and How to Find Yours

The Model Context Protocol turns a language model into something that can act. In July 2026 the ecosystem shipped a dozen ways for a stranger to act through it — and the common thread wasn’t exotic. It was a server built for localhost, quietly put on the internet.

Lire le guide →

AI Governance · July 14, 2026 · 9 min

The Tool Nobody Reviewed: An MCP Zero-Day Read Through SOC 2 and ISO 42001

A company with a clean SOC 2 report shipped an AI agent to production. One of its tools was missing a single line of validation — and that line was the whole audit.

Lire le guide →

Engineering · July 7, 2026 · 5 min

One Connector, One Compliance Test: How We Built 428 Integrations

Most compliance tools treat integrations as a logo wall. We made each connector run a test. Here’s the engineering behind 428 vendor integrations — grounded in exactly what shipped.

Lire le guide →

AI Governance · July 1, 2026 · 7 min

Prompt Guard: Stop Secrets Leaking into ChatGPT & Claude — and Prove It for ISO 42001

Your team pastes API keys and source code into AI chatbots every day. Here’s an open-source, local-first way to stop it — and to turn each blocked leak into audit evidence.

Lire le guide →

AI Governance · July 1, 2026 · 6 min

Shadow AI: Your Employees Are Pasting Secrets into ChatGPT (How to Stop It in 2026)

Most “AI policy” documents are unenforced. The leak is already happening in the prompt box — here’s how to actually close it.

Lire le guide →

AI Governance · July 1, 2026 · 6 min

EU AI Act Article 12: Logging & Record-Keeping Requirements, Explained (2026)

Article 12 turns “trust us” into “show us the logs.” Here’s what it requires and how to produce the evidence without a six-month project.

Lire le guide →

AI Governance · July 1, 2026 · 7 min

What Is an AIMS? The ISO 42001 AI Management System, Explained

Everyone says “stand up an AIMS” — but what is it, actually? Here’s the AI Management System in plain terms, and the first control worth putting in force.

Lire le guide →

ISO 27001 · June 24, 2026 · 9 min

ISO 27001 Certification Checklist (2026): 12 Steps to Certified

Everything you need to take an organization from zero to ISO 27001 certified — as a checklist you can actually work through.

Lire le guide →

ISO 27001 · June 24, 2026 · 7 min

How Much Does ISO 27001 Certification Cost in 2026?

What ISO 27001 actually costs in 2026 — audit fees, tooling, training, and internal time — and where the real savings are.

Lire le guide →

ISO 27001 · June 24, 2026 · 8 min

ISO 27001 vs SOC 2: Which Should You Get First? (2026)

The honest comparison — what each proves, who demands them, and why you rarely have to choose.

Lire le guide →

OKF · June 27, 2026 · 6 min

What Is OKF (Open Knowledge Format)? Google’s Open Standard, Explained

The plain-English explainer on Open Knowledge Format — Google’s open standard for data that AI agents can actually read.

Lire le guide →

OKF · June 27, 2026 · 6 min

OKF in AI: Giving Agents Real, Current, Verifiable Context

How Open Knowledge Format gives AI agents grounded, current, verifiable context — and why that beats dumping documents.

Lire le guide →

OKF · June 27, 2026 · 5 min

OKF + Git: Version-Controlled Knowledge Graphs as Markdown

OKF is just Markdown — so it lives in Git natively. Diffable, reviewable, and auditable knowledge graphs.

Lire le guide →

OKF · June 27, 2026 · 6 min

OKF vs MCP: How Open Knowledge Format and the Model Context Protocol Work Together

OKF and MCP aren’t competitors — they’re a stack. The format your knowledge lives in, and the protocol an agent uses to reach it.

Lire le guide →

ISO 42001 · June 27, 2026 · 9 min

Get Your Organization ISO 42001-Ready: A 2026 Readiness Guide

What it takes to become ISO/IEC 42001-ready — the first international standard for AI management systems — as a checklist you can work through.

Lire le guide →

ISO 42001 · June 27, 2026 · 7 min

ISO 42001 vs ISO 27001: AI Governance and Information Security, Compared

The honest comparison — what each standard proves, how they overlap, and why teams building AI increasingly need both.

Lire le guide →

ISO 42001 · June 27, 2026 · 8 min

ISO 42001 Annex A Controls Explained: All 9 Objectives

The 38 Annex A controls, grouped under nine objectives — what each set covers and how to evidence it.

Lire le guide →

ISO 42001 · June 27, 2026 · 7 min

How Much Does ISO 42001 Certification Cost in 2026?

What ISO 42001 actually costs in 2026 — audit fees, tooling, and internal time — and where the real savings are.

Lire le guide →