Uncategorized
Strengthening authentication with passkeys: A CISO playbook
Our passkey rollout took three tries. Here’s a playbook to make your implementation smoother. Categories: Security Operations Tags: CISO, playbook, toolkit, passkeys
Sophos Firewall v22 MR1 is now available
Check out the full release notes for more details and a list of fixes. Categories: Products & Services Tags: Firewall, network, v22
Microsoft addresses 163 CVEs, 88 advisories for April Patch Tuesday
Following a long-established pattern, the fourth month of the year is one of the cruelest Categories: X-ops, Threat Research Tags: Patch Tuesday
QEMU abused to evade detection and enable ransomware delivery
The use of hidden virtual machines (VMs) enables long-term access, credential harvesting, data exfiltration, and PayoutsKing ransomware deployment Categories: Threat Research Tags: virtual machine, QEMU, PayoutsKing, GOLD ENCOUNTER, CitrixBleed2
Secure by Design: Building cybersecurity into the foundation
An explainer of why this philosophy matters and how it reduces attack surface from the inside Categories: Sophos Insights, Products & Services Tags: Secure by Design, Thought Leadership
Adobe Reader zero-day vulnerability in active exploitation
Categories: Threat Research Tags: advisory, vulnerability, Adobe Reader
The vulnerability flood is here. Here’s what it means – and how to prepare
We can’t control the pace of AI-driven vulnerability discovery, but we can control how fast we respond. Categories: Sophos Insights Tags: LLM, AI, Exploit, vulnerability, Active Adversary, Pacific Rim
We let OpenClaw loose on an internal network. Here’s what it found
Following our article on the challenges posed by agentic AI, we gave OpenClaw access to one of our legacy networks Categories: Threat Research Tags: OpenClaw, LLM, AI, penetration testing, Red Team, CISO, Sophos X-Ops
Is compliance complexity outpacing IT capacity?
No matter the country, industry, or company size, IT and cybersecurity teams report a heavy regulatory load and worry about staying aligned with requirements Categories: Products & Services Tags: CISO, Compliance
Is compliance complexity outpacing IT capacity?
No matter the country, industry, or company size, IT and cybersecurity teams report a heavy regulatory load and worry about staying aligned with requirements Categories: Sophos Insights Tags: PRODUCTS & SERVICES, surveys, Compliance, GDPR compliance, regulatory compliance
