Oxford, UK
1985
  |  By Anthony Bradshaw
Active Directory defenses must combine identity fundamentals, telemetry, and rapid response as attackers reach the environment’s first breach attempt within a median of 11 hours.
  |  By Joe DeGon
In modern network environments, maintaining both operational efficiency and strong security controls requires careful design and planning. One of the more common challenges Sophos Professional Services encounters, especially during firewall upgrades or redesigns, is asymmetric routing.
On October 4, 2026, Citrix disclosed a high-severity (CVSS score of 8.7) memory overflow vulnerability (CVE-2026-88779) affecting Citrix NetScaler ADC and Citrix NetScaler Gateway deployments that are configured as either a SAML Service Provider (SP) or SAML Identity Provider (IdP). Successful exploitation can cause a denial of service (DoS) condition, potentially disrupting authentication services and remote access functionality.
  |  By Sophos
Sophos has been named a Leader in the IDC MarketScape for Worldwide Modern Endpoint Security for Enterprises 2026, recognizing the strength of our prevention-first approach and stopping AI-era threats as early as possible. Attackers using frontier AI models can now find vulnerabilities and generate exploits faster than organizations can patch them. And when malicious code is already running before an alert fires, detection alone is too late.
  |  By Sophos
Delivered through Sophos Fusion, Sophos CISO Advantage uses agentic AI with human judgement to give every organization, with or without a CISO, a security program it can measure, fund, and prove.
  |  By Sophos
Take control of your security outcomes. Sophos CISO Advantage is now generally available to the market, giving CISOs and security teams without a CISO the solution they need to build, manage, and improve a compliance-driven cybersecurity program. In July, we introduced Sophos CISO Advantage, explaining how it enables organizations and Managed Service Providers (MSPs) to understand cyber risk, prioritize what matters most, and demonstrate measurable improvement over time.
  |  By Jordon Olness
In August 2026, Sophos analysts began investigating a series of Managed Detection and Response (MDR) cases that involved ClickFix-style lures and resulted in the deployment of a Python-based tunneling implant. Instead of a typical ClickFix lure that instructs victims to open the Run dialog box, these lures direct users to open a Windows Terminal window. This ClickFix variation is known as ‘TerminalFix’. TerminalFix is not linked to a specific threat group or a single campaign.
  |  By Chris McCormack
Delivering over 30 of your top-requested features Sophos Firewall v23 brings many of your top-requested enhancements in one feature-packed release. From new AI-powered assistance and a modern REST API to streamlined rule management, stronger high-availability capabilities, expanded identity support, and simpler day-to-day administration, Sophos Firewall v23 is designed to make your firewall easier to manage, automate, and scale, while further strengthening its Secure by Design foundation.
  |  By Nash Borges
This article was first published on LinkedIn. Consider a cybersecurity alert for a potentially malicious PowerShell script that downloads and runs a file. An AI agent in a security operations center (SOC) can handle it by picking from a fixed set of actions: close the alert as benign, collect more evidence, or send it to an analyst. Before letting the agent act on such alerts, the SOC needs to know how often it picks correctly and whether its confidence helps identify its mistakes.
On September 27, 2026, Citrix disclosed eight vulnerabilities affecting NetScaler Application Delivery Controller (ADC) and NetScaler Gateway. Two of these vulnerabilities are critical (CVSS score of 9.5) and can allow an unauthenticated remote attacker to execute code: Citrix has observed exploitation against unmitigated NetScaler deployments, and the U.S.
  |  By Sophos
Get started with the new REST APIs in Sophos Firewall v23. Learn how to enable API access, authenticate requests with API keys, import the OpenAPI specification into Postman, and use the API to create and manage firewall objects. Ask questions and get expert answers in the Sophos Community.
  |  By Sophos
Every defence we rely on assumes there's time to check: verify the person on the call, vet the new hire, review the access request, patch the flaw. This video looks at how AI took that time away, in three parts. Built from the Sophos 2026 AI Security Report.
  |  By Sophos
Every defence we rely on assumes there's time to check: verify the person on the call, vet the new hire, review the access request, patch the flaw. This video looks at how AI took that time away, in three parts.
  |  By Sophos
You guide the strategy. You recommend the controls. You field the call when something goes wrong. You were always their CISO - now deliver it at scale with Sophos CISO Advantage.
  |  By Sophos
Available as a fully integrated add-on for Sophos MDR and Sophos XDR, Sophos ITDR provides a comprehensive security solution that addresses the growing and complex challenges of identity threats and is delivered through the Sophos Fusion platform.
  |  By Sophos
The Sophos Support Assistant answers your security and product questions directly within Sophos Fusion (formerly Sophos Central). It’s powered by Sophos documentation, knowledge base articles, user guides, and Community content, delivering relevant, up-to-date guidance to help you find answers and resolve issues faster. Learn how to access and use the Support Assistant. Ask questions and get expert answers in the Sophos Community.
  |  By Sophos
Detections that generate a new MDR Case trigger the Sophos MDR Operations Team to investigate and respond to identified threats in your environment. This workflow is examined, along with the importance of adding your MDR authorized contacts, and choosing the appropriate Threat Response Mode. The detection triage process is covered in a linked video. Ask questions and get expert answers in the Sophos Community.
  |  By Sophos
Take control of security outcomes with Sophos CISO Advantage.
  |  By Sophos
Sophos AI Defense is available as an add-on and is fully integrated with Sophos EDR, Sophos XDR, and Sophos MDR. The result is practical AI security: better visibility, faster investigation, and stronger protection against the real ways AI agents are being used in the enterprise. To learn more, visit Sophos.com/AI Defense.
  |  By Sophos
They call themselves The Gentlemen Behind the name is one of the most active ransomware operations of the past 12 months, linked to 683 victims and a playbook built around compromised credentials, legitimate tools, rapid privilege escalation, and aggressive defense evasion. In this video, Susie Evershed and Rafe Pilling break down the latest research from Sophos Counter Threat Unit (CTU), revealing how some affiliates can move from initial compromise to ransomware deployment in less than 24 hours.
  |  By Sophos
This white paper reveals the attack techniques most likely to drive highimpact incidents - and provides practical advice on how to stop them. By learning from realworld attacks, businesses can strengthen their resilience and meaningfully reduce their cyber risk.
  |  By Sophos
369 IT and cybersecurity leaders reveal the ransomware realities for financial services providers today. The report examines how the causes and consequences of ransomware attacks on financial services providers have evolved over time. This year's edition also sheds light on previously unexplored areas, including the organizational factors that left providers exposed and the human toll ransomware takes on IT and cybersecurity teams in the financial services sector.
  |  By Sophos
Security Operations Centers (SOCs) are essential for detecting and responding to cyber threats, but building the right model isn't one-size-fits-all. With talent shortages and rising threat complexity, many organizations are rethinking how to scale security operations. This guide breaks down the pros, cons, and trade-offs of in-house, hybrid, and outsourced SOC models. Find the SOC strategy that fits your needs, risk profile, and available resources.

Sophos unites unmatched threat intelligence, adaptive AI, and human expertise in an open platform to stop attacks before they strike — giving you the clarity and confidence to stay ahead of every threat.

Sophos delivers adaptive, AI-powered cybersecurity — backed by real experts — so organizations can stay secure, resilient, and free to grow without compromise.

Sophos advantage in cybersecurity:

  • Prevention: Sophos’ approach blocks more threats upfront to minimize risk and reduce investigation and response time.
  • Trust: The only vendor named Gartner® Customers’ choice for endpoint, firewalls, mobile threats, and MDR, with 600K+ customers worldwide.
  • Platform: Sophos products include 100+ integrations with other third-party solutions, plus services that are highly customizable to your needs.

Take Control of Every Threat