December 19, 2024 Phishing platform Rockstar 2FA trips, and “FlowerStorm” picks up the pieces A sudden disruption of a major phishing-as-a-service provider leads to the rise of another…that looks very familiar Security Operations Threat Research
December 12, 2024 The Bite from Inside: The Sophos Active Adversary Report A sea change in available data fuels fresh insights from the first half of 2024 Security OperationsThreat Research
December 11, 2024 Keeping it real: Sophos and the 2024 MITRE ATT&CK Evaluations: Enterprise Sophos X-Ops looks at the realism of this year’s MITRE ATT&CK Evaluations Threat Research
December 30, 2024 Prioritizing patching: A deep dive into frameworks and tools – Part 2: Alternative frameworks In the second of a two-part series on tools and frameworks designed to help with remediation prioritization, we explore some alternatives to CVSS Threat Research
December 27, 2024 Prioritizing patching: A deep dive into frameworks and tools – Part 1: CVSS In the first of a two-part series exploring tools and frameworks which can help organizations with remediation prioritization, Sophos X-Ops takes a look at the Common Vulnerability Scoring System (CVSS) Threat Research
December 11, 2024 December Patch Tuesday arrives bearing 71 gifts Seventeen Critical-severity CVEs ready to deck your halls; also, new blog guidance for Windows Server admins Threat Research
November 20, 2024 Sophos MDR blocks and tracks activity from probable Iranian state actor “MuddyWater” Security OperationsThreat Research
November 13, 2024 November Patch Tuesday loads up everyone’s plate Fourteen product families affected as 2024 passes an unfortunate milestone Threat Research
November 08, 2024 VEEAM exploit seen used again with a new ransomware: “Frag” Security OperationsThreat Research
November 06, 2024 Bengal cat lovers in Australia get psspsspss’d in Google-driven Gootloader campaign The Internet is full of cats—and in this case, malware-delivering fake cat websites used for very targeted search engine optimization. Security OperationsThreat Research
October 16, 2024 From QR to compromise: The growing “quishing” threat Attackers leverage QR codes in PDF email attachments to spearphish corporate credentials from mobile devices Threat Research
October 09, 2024 October Patch Tuesday harvest hauls in 117 CVEs Bumper crop of Windows vulns leads the way; 15 product groups represented Threat Research