DragonForce actors target SimpleHelp vulnerabilities to attack MSP, customers Security Operations β Sophos News By:gallagherseanm 27 May 2025 at 05:00 Ransomware actor exploited RMM to access multiple organizations; Sophos EDR blocked encryption on customerβs network
A familiar playbook with a twist: 3AM ransomware actors dropped virtual machine with vishing and Quick Assist Security Operations β Sophos News By:gallagherseanm 20 May 2025 at 12:30 Another adversary picks up the email bombing / vishing Storm-1811 playbook, doing thorough reconnaissance to target specific employees with fake help desk callβthis time, over the phone.
Lumma Stealer, coming and going Security Operations β Sophos News By:Angela Gunn 9 May 2025 at 04:12 The high-profile information stealer switches up its TTPs, but keeps the CAPTCHA tactic; we take a deep dive
NICKEL TAPESTRY expands fraudulent worker operations Security Operations β Sophos News By:Angela Gunn 8 May 2025 at 11:45 The North Korean IT worker scheme grows to include organizations in Europe and Asia and industries beyond the technology sector
Moving CVEs past one-nation control Security Operations β Sophos News By:Chester Wisniewski 17 April 2025 at 15:57 A near-miss episode of attempted defunding spotlights a need for a better way
Sophos Annual Threat Report appendix: Most frequently encountered malware and abused software Security Operations β Sophos News By:gallagherseanm 16 April 2025 at 05:00 These are the tools of the trade Sophos detected in use by cybercriminals over 2024
The Sophos Annual Threat Report: Cybercrime on Main Street 2025 Security Operations β Sophos News By:gallagherseanm 16 April 2025 at 05:00 Ransomware remains the biggest threat, but old and misconfigured network devices are making it too easy
It takes two: The 2025 Sophos Active Adversary Report Security Operations β Sophos News By:Angela Gunn 2 April 2025 at 05:01 The dawn of our fifth year deepens our understanding of the enemies at the gate, and some tensions inside it; plus, an anniversary gift from us to you
Qilin affiliates spear-phish MSP ScreenConnect admin, targeting customers downstream Security Operations β Sophos News By:gallagherseanm 1 April 2025 at 05:30 Attack matches three-year long pattern of ScreenConnect attacks tracked by Sophos MDR as STAC4365.
Stealing user credentials with evilginx Security Operations β Sophos News By:Angela Gunn 28 March 2025 at 02:29 A malevolent mutation of the widely used nginx web server facilitates Adversary-in-the-Middle action, but thereβs hope