{"id":119140,"date":"2025-02-19T16:29:53","date_gmt":"2025-02-19T14:29:53","guid":{"rendered":"https:\/\/www.catonetworks.com\/blog\/highlights-aus-dem-cato-ctrl-sase-threat-report-fur-q3-2024\/"},"modified":"2026-08-31T10:17:15","modified_gmt":"2026-08-31T07:17:15","slug":"highlights-from-q3-2024-cato-ctrl-sase-threat-report","status":"publish","type":"post","link":"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/","title":{"rendered":"Highlights aus dem Cato CTRL SASE Threat Report f\u00fcr Q3 2024\u00a0"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-introduction-nbsp-nbsp\"><strong>Introduction\u00a0<\/strong>\u00a0<\/h2>\n\n<p class=\"wp-block-paragraph\">Today, we published the <a href=\"https:\/\/www.catonetworks.com\/resources\/the-cato-ctrl-sase-threat-report-q3-2024\/\">Q3 2024 Cato CTRL SASE Threat Report<\/a>, which summarizes findings from Cato CTRL\u2019s analysis of 1.46 trillion network flows across more than 2,500 customers globally between July and September 2024.\u00a0\u00a0<\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-key-findings-nbsp\"><strong>Key Findings<\/strong>\u00a0<\/h2>\n\n<h3 class=\"wp-block-heading\" id=\"h-threat-actors-recruiting-pen-testers-for-ransomware-affiliate-programs-nbsp-nbsp\"><strong>Threat actors recruiting pen testers for ransomware affiliate programs\u00a0<\/strong>\u00a0<\/h3>\n\n<p class=\"wp-block-paragraph\">In closely monitoring discussions on the RAMP forum, Cato CTRL has observed threat actors seeking pen testers to join various ransomware affiliate programs including Apos, Lynx and Rabbit Hole.\u00a0\u00a0\u00a0<\/p>\n\n<p class=\"wp-block-paragraph\">Any good developer knows that software needs to be tested before deploying in production environments. This is also true for ransomware gangs. They want to ensure that their ransomware can be deployed successfully against organizations.\u00a0\u00a0\u00a0<\/p>\n\n<h3 class=\"wp-block-heading\" id=\"h-shadow-ai-lurks-in-the-background-for-organizations-nbsp-nbsp\"><strong>Shadow AI lurks in the background for organizations\u00a0<\/strong>\u00a0<\/h3>\n\n<p class=\"wp-block-paragraph\">Shadow AI refers to the unauthorized or unsanctioned use of AI applications and tools within an organization without the knowledge or approval of IT departments or security teams. This phenomenon typically involves employees or departments adopting AI solutions independently and bypassing formal vetting processes and governance controls.\u00a0\u00a0<\/p>\n\n<p class=\"wp-block-paragraph\">Out of the hundreds of AI applications that Cato CTRL monitors, Cato CTRL tracked 10 AI applications used by organizations (Bodygram, Craiyon, Otter.ai, Writesonic, Poe, HIX.AI, Fireflies.ai, PeekYou, Character.AI and Luma AI) and observed various security risks. The top concern is data privacy.\u00a0\u00a0\u00a0<\/p>\n<a href=\"https:\/\/www.catonetworks.com\/resources\/the-cato-ctrl-sase-threat-report-q3-2024\/\" class=\"blog-box-link\">\nQ3 2024 Cato CTRL SASE Threat Report | Download the report  <span class=\"chevron-wrap\"><\/span><\/a>\n\n<h3 class=\"wp-block-heading\" id=\"h-tls-attack-attempts-reveal-tls-inspection-not-utilized-enough-nbsp\"><strong>TLS attack attempts reveal TLS inspection not utilized enough<\/strong>\u00a0<\/h3>\n\n<p class=\"wp-block-paragraph\">TLS inspection allows organizations to decrypt, inspect and re-encrypt traffic. However, TLS inspection can break applications and access to some domains. As such, many organizations choose to forgo TLS inspection entirely or bypass inspection for a large portion of their traffic.\u00a0 \u00a0<\/p>\n\n<p class=\"wp-block-paragraph\">Cato CTRL found that only 45% of participating organizations enable TLS inspection. Even then, only 3% of organizations inspected all relevant TLS-encrypted sessions. This leaves the door open for threat actors to utilize TLS traffic and remain undetected. Organizations must inspect TLS sessions to protect themselves. In Q3 2024, Cato CTRL found that 60% of attempts to exploit CVEs were blocked in TLS traffic. CVEs included Log4j, SolarWinds and ConnectWise.\u00a0\u00a0 \u00a0<\/p>\n\n<p class=\"wp-block-paragraph\">When TLS inspection is enabled, organizations are better protected. In Q3 2024, Cato CTRL found that organizations who enabled TLS inspection blocked 52% more malicious traffic than organizations without TLS inspection.\u00a0<\/p>\n\n<h2 class=\"wp-block-heading\" id=\"h-security-best-practices-nbsp\"><strong>Security Best Practices<\/strong>\u00a0<\/h2>\n\n<p class=\"wp-block-paragraph\">Based on our key findings, Cato CTRL recommends that organizations take the following actions:\u00a0<\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>Ransomware: <\/strong>Organizations should engage in red team exercises and pen testing to identify vulnerabilities in their infrastructure before ransomware gangs exploit them.\u00a0<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li><strong>Shadow AI: <\/strong>Visibility into which AI tools and applications are being used, by whom and for what purposes is important for organizations to effectively manage data privacy risks.\u00a0<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li><strong>TLS Inspection: <\/strong>Threat actors often use encrypted communication channels to evade detection and exploit vulnerabilities in applications that utilize TLS. Enabling TLS inspection is crucial for effectively monitoring this traffic.\u00a0<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\" id=\"h-resources-nbsp\"><strong>Resources<\/strong>\u00a0<\/h2>\n\n<ul class=\"wp-block-list\">\n<li>Download the <a href=\"https:\/\/www.catonetworks.com\/resources\/the-cato-ctrl-sase-threat-report-q1-2024\/\">Q1 2024 Cato CTRL SASE Threat Report<\/a>.<\/li>\n\n\n\n<li>Download the <a href=\"https:\/\/www.catonetworks.com\/resources\/the-cato-ctrl-sase-threat-report-q2-2024\/\">Q2 2024 Cato CTRL SASE Threat Report<\/a>.<\/li>\n\n\n\n<li>Download the <a href=\"https:\/\/www.catonetworks.com\/resources\/the-cato-ctrl-sase-threat-report-q3-2024\/\">Q3 2024 Cato CTRL SASE Threat Report<\/a>.<\/li>\n\n\n\n<li>Read the <a href=\"https:\/\/www.catonetworks.com\/news\/new-threat-report-from-cato-reveals-ransomware-gangs\/\">press release<\/a>.<\/li>\n\n\n\n<li>Visit the <a href=\"https:\/\/www.catonetworks.com\/cato-ctrl\/\">Cato CTRL page<\/a> to learn more about Cato\u2019s threat intelligence team.<\/li>\n\n\n\n<li>Learn more about Safe TLS Inspection <a href=\"https:\/\/www.catonetworks.com\/blog\/how-cato-is-transforming-encrypted-traffic-security\/\">announced today<\/a>, which is Cato\u2019s groundbreaking solution that enables organizations to safely and easily inspect encrypted traffic.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction\u00a0\u00a0 Today, we published the Q3 2024 Cato CTRL SASE Threat Report, which summarizes findings from Cato CTRL\u2019s analysis of 1.46 trillion network flows across more than 2,500 customers globally between July and September 2024.\u00a0\u00a0 Key Findings\u00a0 Threat actors recruiting pen testers for ransomware affiliate programs\u00a0\u00a0 In closely monitoring discussions on the RAMP forum, Cato&#8230;<\/p>\n","protected":false},"author":39,"featured_media":113265,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1621],"tags":[],"coauthors":[1008],"class_list":["post-119140","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cato-ctrl"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.3 (Yoast SEO v28.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Highlights aus dem Cato CTRL SASE Threat Report f\u00fcr Q3 2024| Cato Networks<\/title>\n<meta name=\"description\" content=\"Der Q3 2024 Cato CTRL SASE Threat Report ist jetzt verf\u00fcgbar und fasst die Ergebnisse der Analyse von 1,46 Billionen Netzwerkfl\u00fcssen durch Cato CTRL zusammen, die zwischen Juli und September 2024 bei \u00fcber 2.500 Kunden weltweit durchgef\u00fchrt wurde.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/\" \/>\n<meta property=\"og:locale\" content=\"de_DE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Highlights aus dem Cato CTRL SASE Threat Report f\u00fcr Q3 2024\u00a0\" \/>\n<meta property=\"og:description\" content=\"Der Q3 2024 Cato CTRL SASE Threat Report ist jetzt verf\u00fcgbar und fasst die Ergebnisse der Analyse von 1,46 Billionen Netzwerkfl\u00fcssen durch Cato CTRL zusammen, die zwischen Juli und September 2024 bei \u00fcber 2.500 Kunden weltweit durchgef\u00fchrt wurde.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/\" \/>\n<meta property=\"og:site_name\" content=\"Cato Networks\" \/>\n<meta property=\"article:published_time\" content=\"2025-02-19T14:29:53+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-31T07:17:15+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.catonetworks.com\/wp-content\/uploads\/2024\/11\/Cato-CTRL-SASE-Threat-Report-blog-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"794\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Etay Maor\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Verfasst von\" \/>\n\t<meta name=\"twitter:data1\" content=\"Etay Maor\" \/>\n\t<meta name=\"twitter:label2\" content=\"Gesch\u00e4tzte Lesezeit\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 Minuten\" \/>\n\t<meta name=\"twitter:label3\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data3\" content=\"Etay Maor\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Highlights aus dem Cato CTRL SASE Threat Report f\u00fcr Q3 2024| Cato Networks","description":"Der Q3 2024 Cato CTRL SASE Threat Report ist jetzt verf\u00fcgbar und fasst die Ergebnisse der Analyse von 1,46 Billionen Netzwerkfl\u00fcssen durch Cato CTRL zusammen, die zwischen Juli und September 2024 bei \u00fcber 2.500 Kunden weltweit durchgef\u00fchrt wurde.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/","og_locale":"de_DE","og_type":"article","og_title":"Highlights aus dem Cato CTRL SASE Threat Report f\u00fcr Q3 2024\u00a0","og_description":"Der Q3 2024 Cato CTRL SASE Threat Report ist jetzt verf\u00fcgbar und fasst die Ergebnisse der Analyse von 1,46 Billionen Netzwerkfl\u00fcssen durch Cato CTRL zusammen, die zwischen Juli und September 2024 bei \u00fcber 2.500 Kunden weltweit durchgef\u00fchrt wurde.","og_url":"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/","og_site_name":"Cato Networks","article_published_time":"2025-02-19T14:29:53+00:00","article_modified_time":"2026-08-31T07:17:15+00:00","og_image":[{"width":1200,"height":794,"url":"https:\/\/www.catonetworks.com\/wp-content\/uploads\/2024\/11\/Cato-CTRL-SASE-Threat-Report-blog-1.png","type":"image\/png"}],"author":"Etay Maor","twitter_card":"summary_large_image","twitter_misc":{"Verfasst von":"Etay Maor","Gesch\u00e4tzte Lesezeit":"3 Minuten","Written by":"Etay Maor"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/#article","isPartOf":{"@id":"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/"},"author":{"name":"Etay Maor","@id":"https:\/\/www.catonetworks.com\/de\/#\/schema\/person\/b4f917cd1b547601ddc92f680f45df40"},"headline":"Highlights aus dem Cato CTRL SASE Threat Report f\u00fcr Q3 2024\u00a0","datePublished":"2025-02-19T14:29:53+00:00","dateModified":"2026-08-31T07:17:15+00:00","mainEntityOfPage":{"@id":"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/"},"wordCount":548,"publisher":{"@id":"https:\/\/www.catonetworks.com\/de\/#organization"},"image":{"@id":"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/#primaryimage"},"thumbnailUrl":"https:\/\/www.catonetworks.com\/wp-content\/uploads\/2024\/11\/Cato-CTRL-SASE-Threat-Report-blog-1.png","articleSection":["Cato CTRL"],"inLanguage":"de-DE"},{"@type":"WebPage","@id":"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/","url":"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/","name":"Highlights aus dem Cato CTRL SASE Threat Report f\u00fcr Q3 2024| Cato Networks","isPartOf":{"@id":"https:\/\/www.catonetworks.com\/de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/#primaryimage"},"image":{"@id":"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/#primaryimage"},"thumbnailUrl":"https:\/\/www.catonetworks.com\/wp-content\/uploads\/2024\/11\/Cato-CTRL-SASE-Threat-Report-blog-1.png","datePublished":"2025-02-19T14:29:53+00:00","dateModified":"2026-08-31T07:17:15+00:00","description":"Der Q3 2024 Cato CTRL SASE Threat Report ist jetzt verf\u00fcgbar und fasst die Ergebnisse der Analyse von 1,46 Billionen Netzwerkfl\u00fcssen durch Cato CTRL zusammen, die zwischen Juli und September 2024 bei \u00fcber 2.500 Kunden weltweit durchgef\u00fchrt wurde.","breadcrumb":{"@id":"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/#breadcrumb"},"inLanguage":"de-DE","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/"]}]},{"@type":"ImageObject","inLanguage":"de-DE","@id":"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/#primaryimage","url":"https:\/\/www.catonetworks.com\/wp-content\/uploads\/2024\/11\/Cato-CTRL-SASE-Threat-Report-blog-1.png","contentUrl":"https:\/\/www.catonetworks.com\/wp-content\/uploads\/2024\/11\/Cato-CTRL-SASE-Threat-Report-blog-1.png","width":1200,"height":794,"caption":"Cato CTRL SASE Threat Report-blog"},{"@type":"BreadcrumbList","@id":"https:\/\/www.catonetworks.com\/de\/blog\/highlights-from-q3-2024-cato-ctrl-sase-threat-report\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.catonetworks.com\/de\/"},{"@type":"ListItem","position":2,"name":"Highlights aus dem Cato CTRL SASE Threat Report f\u00fcr Q3 2024\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/www.catonetworks.com\/de\/#website","url":"https:\/\/www.catonetworks.com\/de\/","name":"Cato Networks","description":"","publisher":{"@id":"https:\/\/www.catonetworks.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.catonetworks.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"de-DE"},{"@type":"Organization","@id":"https:\/\/www.catonetworks.com\/de\/#organization","name":"Cato Networks","url":"https:\/\/www.catonetworks.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"de-DE","@id":"https:\/\/www.catonetworks.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/www.catonetworks.com\/wp-content\/uploads\/2022\/08\/1559077757990.jpg","contentUrl":"https:\/\/www.catonetworks.com\/wp-content\/uploads\/2022\/08\/1559077757990.jpg","width":200,"height":200,"caption":"Cato Networks"},"image":{"@id":"https:\/\/www.catonetworks.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/cato-networks\/"]},{"@type":"Person","@id":"https:\/\/www.catonetworks.com\/de\/#\/schema\/person\/b4f917cd1b547601ddc92f680f45df40","name":"Etay Maor","image":{"@type":"ImageObject","inLanguage":"de-DE","@id":"https:\/\/secure.gravatar.com\/avatar\/0d24de5cafe1728ec90e8da24737d9efc25748bc2045ee2bec3f22371f95fe14?s=96&d=mm&r=g27d49c81edd0b47590c7b73a88aeb32d","url":"https:\/\/secure.gravatar.com\/avatar\/0d24de5cafe1728ec90e8da24737d9efc25748bc2045ee2bec3f22371f95fe14?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0d24de5cafe1728ec90e8da24737d9efc25748bc2045ee2bec3f22371f95fe14?s=96&d=mm&r=g","caption":"Etay Maor"},"description":"Etay Maor is the vice president of threat intelligence at Cato Networks, a founding member of Cato CTRL, and an industry-recognized cybersecurity researcher. Prior to joining Cato in 2021, Etay was the chief security officer for IntSights (acquired by Rapid7), where he led strategic cybersecurity research and security services. Etay has also held senior security positions at Trusteer (acquired by IBM), where he created and led breach response training and security research, and RSA Security\u2019s Cyber Threats Research Labs, where he managed malware research and intelligence teams. Etay is an adjunct professor at Boston College and is part of the Call for Paper (CFP) committees for the RSA Conference and Qubits Conference. Etay holds a Master\u2019s degree in Counterterrorism and Cyber-Terrorism and a Bachelor's degree in Computer Science from IDC Herzliya.","url":"https:\/\/www.catonetworks.com\/de\/blog\/author\/etay-maor\/"}]}},"_links":{"self":[{"href":"https:\/\/www.catonetworks.com\/de\/wp-json\/wp\/v2\/posts\/119140","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.catonetworks.com\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.catonetworks.com\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.catonetworks.com\/de\/wp-json\/wp\/v2\/users\/39"}],"replies":[{"embeddable":true,"href":"https:\/\/www.catonetworks.com\/de\/wp-json\/wp\/v2\/comments?post=119140"}],"version-history":[{"count":1,"href":"https:\/\/www.catonetworks.com\/de\/wp-json\/wp\/v2\/posts\/119140\/revisions"}],"predecessor-version":[{"id":169253,"href":"https:\/\/www.catonetworks.com\/de\/wp-json\/wp\/v2\/posts\/119140\/revisions\/169253"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.catonetworks.com\/de\/wp-json\/wp\/v2\/media\/113265"}],"wp:attachment":[{"href":"https:\/\/www.catonetworks.com\/de\/wp-json\/wp\/v2\/media?parent=119140"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.catonetworks.com\/de\/wp-json\/wp\/v2\/categories?post=119140"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.catonetworks.com\/de\/wp-json\/wp\/v2\/tags?post=119140"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.catonetworks.com\/de\/wp-json\/wp\/v2\/coauthors?post=119140"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}