Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The industry turned XDR and SIEM into categories. Sophos turned them into outcomes.

Sophos Next-Gen SIEM, now generally available as part of Sophos Fusion, brings security operations and compliance together through shared context. For years, the cybersecurity industry has blurred the lines between XDR and SIEM. As capabilities converged, organizations were left trying to connect separate security operations and compliance solutions, often moving the same data between different tools, workflows, and teams.

Digital Risk Protection in the Age of AI

Digital risk has expanded far beyond the traditional security perimeter. Brands now operate across social platforms, advertising ecosystems, messaging applications, collaboration tools, marketplaces, and dozens of other digital channels. Each represents an opportunity to connect with customers. Each also creates opportunities for abuse. A fraudulent advertisement can direct users to a spoofed login page. A fake social media account can support an executive impersonation campaign.

EMEA compliance just made sovereign cloud mandatory

For years, sovereign cloud was basically a data center pin on a map. A vendor would point at Frankfurt or Paris and call it a day. That pitch doesn’t work anymore, and it stopped working fast. Between late 2024 and late 2025, the EU passed three separate rules that turned sovereignty from a talking point into something organizations now have to prove, on a schedule, with documentation, to a specific regulator.

How identity sprawl is quietly expanding your attack surface

No city is designed to become complex. It starts with a simple plan with a handful of streets and a few neighborhoods. Then it grows. New districts appear, roads extend, bridges get built and temporary solutions slowly become permanent. As cities grow, complexity compounds, perhaps because that growth was never planned for. Identity environments follow the same pattern.

Why wild code is the next big challenge for CIOs

Tines co-founder and COO Thomas Kinsella recently joined Peter High on the Technovation podcast to talk about the evolution of Tines, the rise of "wild code," and why agents aren’t always the right tools for the job. The conversation covered a lot of ground — from the original problem that inspired Tines, to how teams should think about combining AI agents, deterministic automation, and humans in a single workflow. Here, we’ll share some of the highlights.

MFA for Retail: Smarter Authentication for Stores, E-commerce & Employees

A refund is an authentication event, so are a POS login, a loyalty-account change, and a technician connecting to a store remotely. Retailers have traditionally treated these moments as separate access problems, but they share the same underlying question: how much confidence should the business require before allowing an action to proceed?

How to Audit Data Access for HIPAA, PCI, and GDPR

When an auditor asks who can access protected health information, cardholder data, or EU personal data, and why, most security teams cannot answer with confidence right away. Access sprawls across cloud storage, SaaS applications, shared drives, and generative AI tools faster than manual reviews can track it. Permissions get granted for a single project and never revoked. A spreadsheet gets shared broadly and forgotten.

CVE-2026-76461: Active Exploitation of Cisco Secure Email Gateway Critical Zero-Day Vulnerability Immediate Mitigation Required

CVE-2026-76461 is a pre-authentication SQL injection vulnerability in the email parsing logic of Cisco Secure Email Gateway (AsyncOS). This vulnerability enables unauthenticated remote threat actors to execute arbitrary code as root by sending crafted, malicious emails. This grants threat actors full control over the operating system, allowing data exfiltration, email surveillance, persistent access, and potential network pivoting, all without user interaction or credentials.

PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting

CrowdStrike Counter Adversary Operations identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript (JS)-based information stealer PhantomRaven via npm, a platform on which developers can access open-source packages to build applications and software.