Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Understanding Asymmetric Routing Risks in Modern Firewall Deployments

In modern network environments, maintaining both operational efficiency and strong security controls requires careful design and planning. One of the more common challenges Sophos Professional Services encounters, especially during firewall upgrades or redesigns, is asymmetric routing.

Citrix NetScaler vulnerability (CVE-2026-88779) in active exploitation

On October 4, 2026, Citrix disclosed a high-severity (CVSS score of 8.7) memory overflow vulnerability (CVE-2026-88779) affecting Citrix NetScaler ADC and Citrix NetScaler Gateway deployments that are configured as either a SAML Service Provider (SP) or SAML Identity Provider (IdP). Successful exploitation can cause a denial of service (DoS) condition, potentially disrupting authentication services and remote access functionality.

Sophos Named a Leader in the IDC MarketScape for Worldwide Modern Endpoint Security for Enterprises 2026

Sophos has been named a Leader in the IDC MarketScape for Worldwide Modern Endpoint Security for Enterprises 2026, recognizing the strength of our prevention-first approach and stopping AI-era threats as early as possible. Attackers using frontier AI models can now find vulnerabilities and generate exploits faster than organizations can patch them. And when malicious code is already running before an alert fires, detection alone is too late.

Sophos Launches CISO Advantage, Bringing CISO-Level Security Strategy Within Reach of Every Organization

Delivered through Sophos Fusion, Sophos CISO Advantage uses agentic AI with human judgement to give every organization, with or without a CISO, a security program it can measure, fund, and prove.

Sophos CISO Advantage is now generally available

Take control of your security outcomes. Sophos CISO Advantage is now generally available to the market, giving CISOs and security teams without a CISO the solution they need to build, manage, and improve a compliance-driven cybersecurity program. In July, we introduced Sophos CISO Advantage, explaining how it enables organizations and Managed Service Providers (MSPs) to understand cyber risk, prioritize what matters most, and demonstrate measurable improvement over time.

TerminalFix and Lorem Ipsum Loader enable covert tunneling

In August 2026, Sophos analysts began investigating a series of Managed Detection and Response (MDR) cases that involved ClickFix-style lures and resulted in the deployment of a Python-based tunneling implant. Instead of a typical ClickFix lure that instructs victims to open the Run dialog box, these lures direct users to open a Windows Terminal window. This ClickFix variation is known as ‘TerminalFix’. TerminalFix is not linked to a specific threat group or a single campaign.

Sophos Firewall v23 is now in early access

Delivering over 30 of your top-requested features Sophos Firewall v23 brings many of your top-requested enhancements in one feature-packed release. From new AI-powered assistance and a modern REST API to streamlined rule management, stronger high-availability capabilities, expanded identity support, and simpler day-to-day administration, Sophos Firewall v23 is designed to make your firewall easier to manage, automate, and scale, while further strengthening its Secure by Design foundation.

Jev's Paradox: The hidden cost of cheap AI decisions

This article was first published on LinkedIn. Consider a cybersecurity alert for a potentially malicious PowerShell script that downloads and runs a file. An AI agent in a security operations center (SOC) can handle it by picking from a fixed set of actions: close the alert as benign, collect more evidence, or send it to an analyst. Before letting the agent act on such alerts, the SOC needs to know how often it picks correctly and whether its confidence helps identify its mistakes.