|
By Sophos
The company is building a new Exploit Path Verification (EPV) capability that will tell security teams which vulnerabilities an attacker can reach in their environment, turning long exposure lists into evidence-backed priorities.
|
By Sophos
Malicious email is the leading attack method, and recovery costs now average $2.26 million.
|
By Nate Drier
Outdated protocols, forgotten configurations, and legacy dependencies continue to create opportunities for attackers in modern environments. This research explores how NetNTLMv1 can still be leveraged today and how improvements in attack tooling are reducing the cost and complexity of exploiting it.
Counter Threat Unit (CTU) researchers investigated a June 2026 campaign in which threat actors used the Deno JavaScript runtime as a core execution mechanism within a ClickFix-driven intrusion chain. On June 3 and June 4, compromised WordPress sites served Cloudflare-themed ClickFix lures that prompted users to execute a clipboard-delivered PowerShell command. This command initiated an MSI-based staging process that installed Deno and enabled retrieval and execution of remote JavaScript.
|
By Sophos
A dedicated channel partnership brings frontier AI to the channel and service providers through Sophos Fusion, powering new security services partners can build on.
|
By Sophos
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defense system that prevents, detects, investigates, and responds at AI speed.
|
By Mitch Pronschinske
The State of Ransomware 2026: Payments are dropping but encryption is climbing Insights from 2,158 IT and cybersecurity leaders across 17 countries whose organizations were hit by ransomware in the past year. This year's data has a few eyebrow-raising departures from the patterns of past State of Ransomware reports. Exploited vulnerabilities lost their three-year grip on the top root-cause spot. Median ransom demands and payments both dropped, yet the average recovery bill still climbed.
On July 14, 2026, SonicWall disclosed two vulnerabilities in SonicWall SMA1000 appliances. Models 6210, 7210, and 8200v are affected. CVE-2026-15409 is a critical (CVSS score of 10.0) unauthenticated server-side request forgery (SSRF) flaw that allows an attacker to force the appliance to make requests to unintended destinations.
|
By Raja Patel
The stack had a good run. Defense systems are the future. Introducing Sophos Fusion, the industry’s most complete AI-Native Cybersecurity Defense System. Something shifted in late 2025 that I don't think our industry has fully reckoned with yet.
|
By Chris McCormack
Sophos Firewall v22 MR2 is now available AI app control, PQC detection, enhanced Chromebook support, and more. Sophos Firewall v22 bolstered Secure by Design, taking it to a whole new level with major updates to the architecture and new features like the Health Check to help identify high-risk configurations. Sophos Firewall v22 MR1 added several enhancements, including a new set of NDR detections for active threats.
|
By Sophos
The Sophos Support Assistant answers your security and product questions directly within Sophos Fusion (formerly Sophos Central). It’s powered by Sophos documentation, knowledge base articles, user guides, and Community content, delivering relevant, up-to-date guidance to help you find answers and resolve issues faster. Learn how to access and use the Support Assistant. Ask questions and get expert answers in the Sophos Community.
|
By Sophos
Detections that generate a new MDR Case trigger the Sophos MDR Operations Team to investigate and respond to identified threats in your environment. This workflow is examined, along with the importance of adding your MDR authorized contacts, and choosing the appropriate Threat Response Mode. The detection triage process is covered in a linked video. Ask questions and get expert answers in the Sophos Community.
|
By Sophos
Take control of security outcomes with Sophos CISO Advantage.
|
By Sophos
Sophos AI Defense is available as an add-on and is fully integrated with Sophos EDR, Sophos XDR, and Sophos MDR. The result is practical AI security: better visibility, faster investigation, and stronger protection against the real ways AI agents are being used in the enterprise. To learn more, visit Sophos.com/AI Defense.
|
By Sophos
They call themselves The Gentlemen Behind the name is one of the most active ransomware operations of the past 12 months, linked to 683 victims and a playbook built around compromised credentials, legitimate tools, rapid privilege escalation, and aggressive defense evasion. In this video, Susie Evershed and Rafe Pilling break down the latest research from Sophos Counter Threat Unit (CTU), revealing how some affiliates can move from initial compromise to ransomware deployment in less than 24 hours.
|
By Sophos
Sophos XDR/MDR and third-party solutions trigger automated responses to isolate compromised devices across networks, preventing lateral movement and speeding up remediation.
|
By Sophos
AI speed. Human judgment. Fully managed. Sophos MDR: the world's largest agentic SOC. Speak with an expert.
|
By Sophos
Sophos Fusion isn't another platform. It's an AI-native cyber defense system that connects security controls, intelligence, data, services, and human expertise into one coordinated defense. Watch Raja Patel explain the foundation of Sophos Fusion and how it's built for the AI era.
|
By Sophos
A step-by-step tutorial showing you how to define your Sophos Managed Detection and Response (MDR) authorized contacts and threat response mode in Sophos Central. As a Sophos MDR customer, assigning authorized contacts lets you fully utilize the service. This instructs the Sophos MDR Operations team who to contact and how to take action during an active threat. You're prompted to take these steps in Sophos Central after activating a new Sophos MDR license, and you can modify this information at any time.
|
By Sophos
A criminal talked commercial AI models past their guardrails. Then stood up a "company" of AI agents that engineered, tested and refined malware. It began when Sophos analysts found a folder named "test" on an endpoint nobody recognised. Inside was the front end of a machine: Cobalt Strike profiles, a Telegram command channel, a hidden Sliver server behind Cloudflare and scripts written with the help of AI.
|
By Sophos
This white paper reveals the attack techniques most likely to drive highimpact incidents - and provides practical advice on how to stop them. By learning from realworld attacks, businesses can strengthen their resilience and meaningfully reduce their cyber risk.
|
By Sophos
369 IT and cybersecurity leaders reveal the ransomware realities for financial services providers today. The report examines how the causes and consequences of ransomware attacks on financial services providers have evolved over time. This year's edition also sheds light on previously unexplored areas, including the organizational factors that left providers exposed and the human toll ransomware takes on IT and cybersecurity teams in the financial services sector.
|
By Sophos
Security Operations Centers (SOCs) are essential for detecting and responding to cyber threats, but building the right model isn't one-size-fits-all. With talent shortages and rising threat complexity, many organizations are rethinking how to scale security operations. This guide breaks down the pros, cons, and trade-offs of in-house, hybrid, and outsourced SOC models. Find the SOC strategy that fits your needs, risk profile, and available resources.
- September 2026 (7)
- August 2026 (8)
- July 2026 (20)
- June 2026 (6)
- May 2026 (25)
- April 2026 (17)
- March 2026 (17)
- February 2026 (6)
- January 2026 (10)
Sophos unites unmatched threat intelligence, adaptive AI, and human expertise in an open platform to stop attacks before they strike — giving you the clarity and confidence to stay ahead of every threat.
Sophos delivers adaptive, AI-powered cybersecurity — backed by real experts — so organizations can stay secure, resilient, and free to grow without compromise.
Sophos advantage in cybersecurity:
- Prevention: Sophos’ approach blocks more threats upfront to minimize risk and reduce investigation and response time.
- Trust: The only vendor named Gartner® Customers’ choice for endpoint, firewalls, mobile threats, and MDR, with 600K+ customers worldwide.
- Platform: Sophos products include 100+ integrations with other third-party solutions, plus services that are highly customizable to your needs.
Take Control of Every Threat