NEW#0001
Sophos3 days ago6 min▣LLM reportcritical A Linux rootkit targets BIG-IP APM via CVE-2025-53521, injecting a fileless PHP web shell into Apache memory and providing a local socket backdoor.
The implant hooks Apache's APR module loader to inject a web shell into PHP file memory mappings, bypassing disk-based detection. It also creates a local UNIX socket backdoor to /bin/bash. The malware uses RC4 for string obfuscation and custom ELF loading to execute before the host process main().
#0002
Sophos8 days ago6 min▣LLM reportcritical SonicWall disclosed two vulnerabilities in SMA1000 appliances on September 1, 2026, both confirmed as exploited in the wild. CVE-2026-83548 is a critical unauthenticated SSRF flaw (CVSS 10.0) in the Appliance Work Place interface. CVE-2026-83549 is a high-severity OS command injection vulnerability (CVSS 7.8) in the Appliance Management Console that requires authenticated admin access to achieve remote code execution. Affected models include 6210, 7210, and 8200v.
#0003
Sophos10 days ago15 min▣LLM reportcritical GOLD SHERWOOD operates The Gentlemen ransomware-as-a-service scheme using a repeatable post-exploitation playbook. Affiliates gain initial access by exploiting FortiGate firewall vulnerabilities or abusing stolen VPN credentials, then rapidly escalate privileges, deploy BYOVD-based EDR killers, exfiltrate data via cloud storage tools, and deploy Go-based ransomware binaries. Median dwell time is approximately two days, with some intrusions completing in under 24 hours. The attackers stage tools in C:\PerfLogs, use native Windows utilities for privilege escalation, and adaptively switch between Rclone, Restic, and MinIO Client for data exfiltration.
#0004
Sophos15 days ago7 min▣LLM reporthigh The Sophos State of Ransomware in Education 2026 report surveyed 226 education providers hit by ransomware in the last 12 months. Identity-based attack vectors initiated 85% of attacks. Despite widespread MFA adoption and firewall detections, education providers struggled to translate detection into prevention, with encryption rates in lower education doubling year-over-year. Recovery costs and timelines continue to climb while ransom demands trend downward.
#0005
Sophos23 days ago4 min▣LLM reportlow The provided article text is a brief abstract stating that Sophos MDR casework over the course of a year identified a pattern of attackers impersonating AI brands to distribute malware. No technical details, indicators of compromise, malware families, or attack chain information are included in the supplied content.
#0006
Sophos24 days ago3 min▣LLM reportmedium Microsoft released patches for 423 CVEs in the August Patch Tuesday update. The release did not include any security updates for Microsoft Edge. The author notes a change in the distribution of CWE categories represented in this month's vulnerabilities.
#0007
Sophos25 days ago3 min▣LLM reportmedium This research details how NetNTLMv1 authentication can still be leveraged by attackers in modern environments. Improvements in attack tooling have reduced the cost and complexity of cracking NetNTLMv1 hashes without requiring specialized GPU hardware.
#0008
Sophos30 days ago3 min▣LLM reportmedium The ClickFix campaign abuses the Deno JavaScript runtime as a delivery mechanism for infostealer malware. The article was published by Sophos Counter Threat Unit Research Team but the full content was not provided for detailed analysis.
#0009
Sophos30 days ago4 min▣LLM reportmedium The article discusses how threat actors are abusing alternative runtime environments such as Deno to evade security defenders. The full article content was not provided in the source text, limiting detailed technical analysis.
#0010
Sophosabout 1 month ago3 min▣LLM reportmedium The article title indicates that exploitation of N-able N-central results in the deployment of Remote Monitoring and Management (RMM) tools. No further technical details, IOCs, or attack chain descriptions are provided in the article text.
#0011
Sophosabout 1 month ago2 min▣LLM reportmedium The article title references the Interlock ransomware gang and suggests a volatile situation, but the full article body was not provided for analysis. No technical details, IOCs, TTPs, or detection guidance can be extracted from the title and author attribution alone.
#0012
Sophos3 months ago5 min▣LLM reporthigh During a routine certification test, Sophos X-Ops discovered an undeclared XMRig-based crypto-miner bundled with Hola Browser version 1.251.91.0. The incident was attributed to a supply chain compromise affecting the browser's distribution pipeline, which has since been remediated by the vendor.
#0013
Sophos3 months ago5 min▣LLM reporthigh Sophos researchers uncovered a threat actor utilizing AI-native development tools, specifically the Cursor IDE and Claude Opus, to build and iteratively test a post-exploitation framework designed to evade major EDR solutions. The framework automates the ingestion of public security research to generate and refine custom Rust and Go payloads, ultimately supporting ransomware and data theft operations.
#0014
Sophos4 months ago4 min▣LLM reporthigh GitHub experienced an internal security incident where threat actor TeamPCP (UNC6780) compromised an employee's device using a malicious Visual Studio Code extension. The attacker harvested local developer secrets to clone approximately 3,800 internal repositories, which were subsequently listed for sale on a cybercrime forum.
#0015
Sophos4 months ago6 min▣LLM reporthigh WantToCry is a remote ransomware operation that targets internet-exposed SMB services using brute-force authentication. Instead of deploying local malware, attackers exfiltrate files, encrypt them on their own infrastructure, and write the encrypted versions back to the victim's network via authenticated SMB sessions, effectively bypassing traditional process-based EDR detections.
#0016
Sophos4 months ago7 min▣LLM reporthigh Sophos MDR investigated a macOS infostealer infection attributed to an AMOS (Atomic macOS) variant. The attack leverages ClickFix social engineering to trick users into running a malicious Terminal command, which initiates a multi-stage infection chain. The malware captures the user's system password via a spoofed prompt, evades analysis by checking for virtualized environments, and exfiltrates sensitive data like Keychain and browser credentials before establishing persistence via a LaunchDaemon.
#0017
Sophos4 months ago5 min▣LLM reportcritical Microsoft's May 2026 Patch Tuesday release addresses 132 CVEs, including 29 Critical vulnerabilities and 14 with a CVSS score of 9.0 or higher. Key threats include a critical authentication bypass in the Microsoft SSO Plugin for Jira & Confluence, unauthorized RCEs in Windows Netlogon and DNS Client, and multiple Office RCEs exploitable via the Preview Pane.
#0018
Sophos4 months ago5 min▣LLM reportmedium AI agents deployed in enterprise environments are highly susceptible to indirect prompt injection attacks, enabling data theft and unauthorized actions. Security teams must adopt an 'assume breach' architecture for LLMs, focusing on blast radius reduction through agent sandboxing, credential isolation, egress restrictions, and human-in-the-loop governance.
#0019
Sophos4 months ago6 min▣LLM reporthigh A malvertising campaign is leveraging a fake Claude AI website to distribute a malicious MSI installer. The infection chain employs DLL sideloading via a legitimate G DATA executable to execute DonutLoader, which ultimately deploys a novel backdoor dubbed 'Beagle' for remote command execution and file manipulation.
#0020
Sophos4 months ago3 min▣LLM reporthigh CVE-2026-31431, dubbed 'Copy Fail', is a high-severity (CVSS 7.8) local privilege escalation vulnerability in the Linux kernel affecting distributions released since 2017. A reliable public PoC is available, allowing unprivileged local users to achieve root access by corrupting the kernel's in-memory page cache of privileged binaries. Immediate patching is recommended, particularly for multi-tenant and containerized environments.