Dissecting a PHP web server rootkit
Sophos X-Ops takes a deep dive into an insidious piece of malware
Sophos X-Ops takes a deep dive into an insidious piece of malware
Analysis of 15 intrusions revealed tradecraft used by GOLD SHERWOOD affiliates
Sophos joins organizations worldwide in supporting a coordinated and responsible approach to cyber defense.
Insights from 226 IT and cybersecurity leaders across the education sector in 17 countries whose organizations were hit by ransomware in the past year.
Sophos is the only vendor recognized as a Leader across all five of these core cybersecurity markets.
A year of MDR casework shows attackers repeatedly exploiting demand for AI tools
421 CVEs, a relatively small set of Edge patches, and two spicy stragglers
Outdated protocols, forgotten configurations, and legacy dependencies continue to create opportunities for attackers in modern environments. This research explores how NetNTLMv1 can still be leveraged today and how improvements in attack tooling are reducing the cost and complexity of exploiting it.
Outdated protocols, forgotten configurations, and legacy dependencies continue to create opportunities for attackers in modern environments. This research explores how NetNTLMv1 can still be leveraged today and how improvements in attack tooling are reducing the cost and complexity of exploiting it.
Attack TTPs combine fileless execution, wide LOLBin use
Lures on compromised WordPress sites led to installation of Deno and a Python-based infostealer
Sophos to bring OpenAI’s frontier models to the channel and managed service providers in newly announced partnership
New Generative AI category is now available in DNS filtering policy and reporting.
After compromising systems via CVE-2026-18577, threat actors use the additional RMM tools and network tunnels to establish persistent remote access
Multiple legitimate DFIR tools abused by GOLD EMBRACE double-extortion specialists
The follow-up to the Hugging Face breach is a disclosure from Anthropic
Data scientists from the Sophos AI team will present two research talks at BSides Las Vegas
One year on from our last Secure by Design update, we’re changing the format: deeper, per-product updates. First up: the firewall.
Attackers used Microsoft Teams vishing, custom malware, and remote access tools to facilitate ransomware deployment