Resources
Insights
Guidance on compliance, threats and security engineering from the people who do the work.
May 5, 2026 · 4 min read
Software Supply Chain Attacks: From Poisoned Packages to Compromised Updates
When attackers compromise software before it reaches you, your own trusted update process delivers the attack. How supply chain attacks work, what landmark incidents taught the industry, and the defenses that apply to buyers and builders.
Read moreApril 7, 2026 · 4 min read
Phishing in the Age of AI: Deepfakes, Voice Cloning and Tailored Lures
The telltale signs people were trained to spot, such as bad grammar and generic greetings, are disappearing. How social engineering is changing, what recent cases show, and how organizations should adapt training and controls.
Read moreMarch 10, 2026 · 4 min read
Nation-State Targeting of the Defense Industrial Base
Defense contractors hold technology and access that foreign intelligence services want. Why the defense industrial base is targeted, the techniques public advisories describe, and the defenses that matter most.
Read moreFebruary 17, 2026 · 4 min read
Mobile Devices as an Attack Vector for Government Users
Phones carry email, messages, credentials and location for people who hold sensitive roles. How adversaries target mobile devices, what recent government guidance recommends, and practical protections for high-risk users.
Read moreFebruary 3, 2026 · 4 min read
Ransomware Playbooks: How Modern Attacks Unfold, Stage by Stage
Ransomware is rarely a single event. It is the final stage of an intrusion that may have lasted days or weeks. How modern ransomware operations work, where defenders can interrupt them, and how to prepare for the worst.
Read moreJanuary 6, 2026 · 4 min read
Edge Devices Under Attack: VPNs, Firewalls and Gateways
The devices that guard the perimeter have become a favorite target. Why VPNs, firewalls, routers and gateways are exploited so often, what recent advisories describe, and how to defend devices you often cannot inspect.
Read moreOctober 21, 2025 · 4 min read
Living off the Land: How Attackers Hide Using Your Own Tools
Some of the most capable threat actors bring almost no malware. They use the administration tools already on your systems. How living-off-the-land techniques work, why they evade traditional defenses, and how to detect them.
Read moreSeptember 16, 2025 · 5 min read
Pre-Positioning in Critical Infrastructure: What Public Advisories Tell Us
U.S. agencies have warned that state-sponsored actors are hiding inside critical infrastructure networks, not to steal data but to be ready to disrupt. What the advisories say, why it matters beyond infrastructure operators, and how to look for it.
Read more
Let's talk
Ready to strengthen your security posture?
Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.