" ITREALMS: Sophos
Showing posts with label Sophos. Show all posts
Showing posts with label Sophos. Show all posts

Monday, August 11, 2025

Sophos, Halcyon team-up intelligence-sharing against ransomware - ITREALMS

ITREALMS ... making leadership SENSE with digital news!

Global leader of innovative security solutions for defeating cyberattacks, Sophos, has announced a strategic threat intelligence sharing partnership with Halcyon, the leading anti-ransomware solution provider, reports ITREALMS.
Sophos, Halcyon team up intelligence-sharing against ransomware - ITREALMS
This collaboration brings together two of the most experienced teams in ransomware defense to accelerate detection, enhance protection, and improve response capabilities for more than 300,000 organizations worldwide.

Tuesday, July 22, 2025

Sophos is leader in 2025 Gartner Magic Quadrant for Endpoint Protection Platforms - ITREALMS

Sponsored@ITREALMS ... making leadership SENSE with digital news!

Sophos, a global leader of innovative security solutions for defeating cyberattacks, today announced that it has been named a Leader in the 2025 Gartner Magic Quadrant for Endpoint Protection Platforms (EPP), marking the 16th consecutive time the company has received this recognition. 
Sophos has been recognized in the Gartner Magic Quadrant for Endpoint Protection Platforms (EPP) since the inaugural publication for this category in 2007.

Tuesday, July 08, 2025

Sophos managed risk expands capabilities with IASM - ITREALMS

ITREALMS ... making leadership SENSE with digital news!


Global leader of innovative security solutions for defeating cyber-attacks, Sophos, has announced the expansion of its managed risk capabilities with the introduction of Internal Attack Surface Management (IASM) powered by Tenable, reports ITREALMS.
Sophos  managed risk expands capabilities with IASM - ITREALMS
Many organizations face critical blind spots in their cyber defenses. In fact, the Sophos State of Ransomware 2025 report found 40% of organizations impacted by ransomware in the last year reported falling victim due to an exposure they were unaware of.

Tuesday, December 17, 2024

Sophos XDR Excels in MITRE ATT&CK Evaluations: Enterprise - ITREALMS

Sponsored@ITREALMS ... making leadership SENSE with digital news!
…100% of Sophos XDR detections for adversary activities targeting Windows and Linux devices provide rich analytic coverage and achieve the highest possible ratings.
Sophos, a global leader of innovative security solutions for defeating cyberattacks, has announced its strong results in the 2024 MITRE ATT&CK Evaluations: Enterprise.
According to the report, Sophos XDR detected 100% of the adversary behaviours in attack scenarios targeting Windows and Linux platforms, mimicking malware strains from ruthless ransomware-as-a-service gangs LockBit and CL0P.

Wednesday, May 08, 2024

State of Ransomware: 97% of firms partner law enforcement, Sophos - ITREALMS

ITREALMS ... making leadership SENSE with digital news!


Sophos, a global leader of innovative security solutions that defeat cyberattacks, today released additional findings from its annual “State of Ransomware 2024” survey. According to the report, among organizations surveyed, 97% of those hit by ransomware over the past year engaged with law enforcement and/or official government bodies for help with the attack.
In addition, more than half (59%) of those organizations that did engage with law enforcement found the process easy or somewhat easy. Only 10% of those surveyed said the process was  very difficult.

Friday, February 09, 2024

Sophos: Global leader in IDC MarketScape for endpoint security - ITREALMS

ITREALMS ... making leadership SENSE with digital news!

Sophos, a global leader in innovating and delivering cybersecurity as a service, has announced its recognition as a Leader in the IDC MarketScape: Worldwide Modern Endpoint Security for Midsize Businesses 2024 Vendor Assessment, which evaluates the solutions and business strategies of 16 modern endpoint security (MES) vendors.
Sophos: Global leader in IDC MarketScape for endpoint security - ITREALMS
Sophos Endpoint defends more than 300,000 organizations worldwide against advanced attacks with anti-ransomware, anti-exploitation, behavioral analysis, and other technologies that stop threats before they escalate. In the report, IDC applauds Sophos Endpoint for including “a more expansive set of protection technologies (host-based firewall and IDS/IPS, device control, DLP, and encryption) as standard features in its endpoint security offering.” In addition, “in the discipline of systematically strengthening customers’ security posture, Sophos has a strong set of features in customer security advisory recently enhanced with an account health-checking feature (detecting and remediating security configuration drift).” The report also praises Sophos for adding “several new capabilities: adaptive attack protection, critical attack warning and data protection and recovery” to further mitigate risks.

Wednesday, September 20, 2023

Sophos reveals Sha Zhu Pan scammers steal $1m with fake cryptocurrency trading pools - ITREALMS

ITREALMS ... making leadership SENSE with digital news!

A global leader in innovating and delivering cybersecurity as a service, Sophos, has released findings on a major shā zhū pán (pig butchering) operation utilizing fake trading pools of cryptocurrency (liquidity pools) to steal more than $1 million, reports ITREALMS.
Sophos reveals Sha Zhu Pan scammers steal $1m with fake cryptocurrency trading pools - ITREALMS
The report, “Latest Evolution of ‘Pig Butchering’ Scam Lures Victim in Fake Mining Scheme,” details the story of one of the scammed victims in the pools, named *Frank, and how he lost $22,000 in one week after “someone” pretending to be “Vivian” on the dating app MeetMe contacted him.

Tuesday, August 29, 2023

First half of 2023: Dwell time on attacks shrinks says Sophos - ITREALMS

ITREALMS ... making leadership SENSE with digital news!

Global leader in innovating and delivering cybersecurity as a service, Sophos has released its Active Adversary Report for Tech Leaders 2023, an in-depth look at attacker behaviors and tools during the first half of 2023, reports 
ITREALMS.
First half of 2023: Dwell time on attacks shrinks says Sophos - ITREALMS
According to the report available to ITREALMS, after analyzing Sophos Incident Response (IR) cases from January to July 2023, Sophos X-Ops found that median attacker dwell time; the time from when an attack starts to when it’s detected—shrunk from 10 to eight days for all attacks, and to five days for ransomware attacks. In 2022, the median dwell time decreased from 15 to 10 days.

Tuesday, May 30, 2023

Sophos: Fake ChatGPT apps scamming users - ITREALMS

ITREALMS ... making leadership SENSE with digital news!

A global leader in innovating and delivering cybersecurity as a service, Sophos, has uncovered multiple apps masquerading as legitimate, ChatGPT-based chatbots to overcharge users and bring in thousands of dollars a month, reports 
ITREALMS.
Sophos: Fake ChatGPT apps scamming users - ITREALMS
This is coming as detailed in Sophos X-Ops' latest report, “’FleeceGPT’ Mobile Apps Target AI-Curious to Rake in Cash,” these apps have popped up in both the Google Play and Apple App Store, and, because the free versions have near-zero functionality and constant ads, they coerce unsuspecting users into signing up for a subscription that can cost hundreds of dollars a year.

Tuesday, April 11, 2023

Sophos elevates Joe Levy, appoints Bill Robbins - ITREALMS

ITREALMS ... making leadership SENSE with digital news!

Sophos, a global leader in innovating and delivering cybersecurity as a service, today announced the promotion of Joe Levy to president of the Sophos Technology Group (STG). Sophos also appointed Bill Robbins president, Worldwide Field Operations.
Sophos elevates Joe Levy,  appoints Bill Robbins - ITREALMS
Levy is currently Sophos’ chief technology officer and chief product officer, and will retain these titles and the organizational structure of STG.

Monday, February 13, 2023

Sophos investigates two cyber fraud operations: Reveals scammers expanding their crypto-Romance - ITREALMS

ITREALMS ... making leadership SENSE with digital news!

Sophos, a global leader in innovating and delivering cybersecurity as a service, today released details of two expansive, still operational, pig butchering or sha zhu pan rings (elaborate and lengthy financial fraud scams that can cost victims thousands of dollars) that scammers are operating from Asia.
Sophos investigates two cyber fraud operations: Reveals scammers expanding their crypto-Romance - ITREALMS
One of the rings, based in Hong Kong, involves a fake gold trading marketplace, while the other, based in Cambodia and with ties to Chinese organized crime, netted the scammers $500,000 in cryptocurrency in just one month.

Saturday, September 25, 2021

Sophos accelerates growth of MSP Connect - ITREALMS

ITREALMS ... making leadership SENSE with digital news!

Global leader in next-generation cybersecurity, Sophos has accelerated worldwide growth of Managed Service Providers MSP Connect, the firm's award-winning programme to help MSPs increase customer management efficiencies, unlock new business opportunities and boost revenue, reports ITREALMS.
Scott Barlow, Sophos' VP global MSP and cloud alliances
The growth, ITREALMS gathered was fueled by the increased demand for Sophos’ next-generation cybersecurity solutions and services that protect against ransomware and other cyberthreats.

Wednesday, November 13, 2019

Sophos report showcases 2020 cyberthreat impacts - ITREALMS

Leader in cloud-enabled next-generation cybersecurity, Sophos has launched its 2020 Threat Report providing insights into the rapidly evolving cyberthreats landscape, reports ITREALMS.

The latest report, 
ITREALMS gathered, was produced by SophosLabs researchers, and explored changes in the threat landscape over the past 12 months, uncovering trends likely to impact cybersecurity in 2020.

“The threat landscape continues to evolve – and the speed and extent of that evolution is both accelerating and unpredictable. The only certainty we have is what is happening right now, so in our 2020 Threat Report we look at how current trends might impact the world over the coming year. We highlight how adversaries are becoming ever stealthier, better at exploiting mistakes, hiding their activities and evading detection technologies, and more, in the cloud, through mobile apps and inside networks. The 2020 Threat Report is not so much a map as a series of signposts to help defenders better understand what they could face in the months ahead, and how to prepare,” said John Shier, senior security advisor, Sophos.

The SophosLabs 2020 Threat Report, which is also summarized in a SophosLabs Uncut article, focuses on six areas where researchers noted particular developments during this past year. Among those expected to have significant impact on the cyberthreat landscape into 2020 and beyond are the following:

Ransomware attackers continue to raise the stakes with automated active attacks that turn organizations’ trusted management tools against them, evade security controls and disable back ups in order to cause maximum impact in the shortest possible time.

Unwanted apps are edging closer to malware. In a year that brought the subscription-abusing Android Fleeceware apps, and ever more stealthy and aggressive adware, the Threat Report highlights how these and other potentially unwanted apps (PUA), like browser plug-ins, are becoming brokers for delivering and executing malware and fileless attacks.

The greatest vulnerability for cloud computing is misconfiguration by operators. As cloud systems become more complex and more flexible, operator error is a growing risk. Combined with a general lack of visibility, this makes cloud computing environments a ready made target for cyberattackers.

Machine learning designed to defeat malware finds itself under attack. 2019 was the year when the potential of attacks against machine learning security systems were highlighted. Research showed how machine learning detection models could possibly be tricked, and how machine learning could be applied to offensive activity to generate highly convincing fake content for social engineering. At the same time, defenders are applying machine learning to language as a way to detect malicious emails and URLs. This advanced game of cat and mouse is expected to become more prevalent in the future.

Other areas covered in the 2020 Threat Report include the danger of failing to spot cybercriminal reconnaissance hidden in the wider noise of internet scanning, the continuing attack surface of the Remote Desktop Protocol (RDP), and the further advancement of automated active attacks (AAA).

Nenye Dom/Editor

*JOIN our alert's group | Share stories with us | Advert placement: WhatsApp | SMS: +2348033592762 *Twitter: @ITREALMS *Email: itrealms.dsa@gmail.com*

Wednesday, October 23, 2019

Now access Sophos Cloud Optic @Amazon marketplace - ITREALMS

Global leader in network and endpoint security, Sophos, has declared that its cloud optic is now accessible on Amazon Web Services (AWS) marketplace, reports ITREALMS.

As a new agentless software-as-a-service (SaaS) offering, Cloud Optix automatically discovers cloud assets, detects cloud security vulnerabilities and misconfigurations, and provides threat response for AWS customers.



Recognized as a channel-first, channel-best leader in providing innovative solutions like Cloud Optix, Sophos has also been named AWS Partner Network (APN) Technology Partner of the Year. It tops the list of APN partners for its dedication to helping AWS customers build, market and grow successful cloud businesses.



“Sophos research shows that cybercriminals are relentlessly trying to attack cloud servers, using automation to scan for weaknesses like open cloud buckets, and launching attacks within minutes of assets going live in the cloud,” said Dan Schiappa, chief product officer, Sophos. “Organizations are at risk of a security breach if they can’t see and properly secure what they’re putting into the cloud. Cloud Optix continuously monitors cloud assets, configurations and network traffic patterns to prevent provisioning of vulnerable infrastructure.”



More than 200,000 active AWS Marketplace customers can now easily access and set up Cloud Optix on a per-host, per-hour basis for flexible scaling, with no minimum term contract.



Automatically discovering cloud assets in minutes, Cloud Optix provides a full topology view of cloud infrastructure, leverages artificial intelligence to highlight and mitigate threat exposure, and integrates with native AWS APIs.



It provides teams with a single view of security posture across multiple cloud environments, including AWS, and enables organizations to accurately visualize and secure cloud infrastructure continuously, and confidently.





Cloud Optix is now available on AWS Marketplace. Visit Sophos.com to learn more about Sophos security for AWS. Partners can also leverage Cloud Optix on AWS Marketplace through the AWS Consulting Partner Private Offers program.



*JOIN our alert's group | Share stories with us | Advert placement: WhatsApp | SMS: +2348033592762 *Twitter: @ITREALMS *Email: itrealms.dsa@gmail.com*

Tuesday, May 07, 2019

Ransomware: Sophos raises alarm over MegaCortex threats - ITREALMS

ITREALMS:  
Global leader in endpoint and network security, Sophos, has raised alarm over new ransomware threats by MegaCortex, reports ITREALMS.

Ransomware, ITREALMS gathered, is a type of malicious software or malware, designed to deny access to a computer system or data until a ransom is paid. Ransomware typically spreads through phishing emails or by unknowingly visiting an infected website.

Raising the alarm at the weekend, SophosLabs Uncut release made available to ITREALMS, gave detailed malware analysis of the new ransomware called MegaCortex.

Explaining this, Sophos research team noted that MegaCortex was a relatively little-seen malware that suddenly spiked in volume on May 1.

"Sophos has seen MegaCortex detections in the US, Canada, Argentina, Italy, the Netherlands, France, Ireland, Hong Kong, Indonesia, and Australia.

“The ransomware has manual components similar to Ryuk and BitPaymer, but the adversaries behind MegaCortex use more automated tools to carry out the attack – this is unique.

“Up until now, Sophos has seen automated attacks, manual attacks and blended attacks, which typically lean more towards using manual hacking techniques to move laterally; with MegaCortex, Sophos is seeing heavier use of automation coupled with the manual component.

“This new formula is designed to spread the infection to more victims, more quickly.

As indicated in the SophosLabs Uncut article, MegaCortex Ransomware Wants to be TheOne, there is no explicit value for the ransom demand in the ransom note.

The attackers invite victims to email them on either of two free mail.com email addresses and send along a file that the ransomware drops on the victim’s hard drive to request decryption “services.”
The ransom note also promises the cybercriminals “will include a guarantee that your company will never be inconvenienced by us,” if the victims pay the ransom, and continues, “You will also receive a consultation on how to improve your companies cyber security.”

Also, Sophos made some recommendations to businesses:

“It appears that there's a strong correlation between the presence of MegaCortex, and a pre-existing, ongoing infection on the victims' networks with both Emotet and Qbot. If IT managers are seeing alerts about Emotet or Qbot infections, those should take a high priority. Both of those bots can be used to distribute other malware, and it's possible that's how the MegaCortex infections got their start.

“Sophos has not seen any indication so far that Remote Desktop Protocol (RDP) has been abused to break into networks, but we know that holes in enterprise firewalls that allow people to connect to RDP remain relatively common. We strongly discourage this practice and suggest that any IT admin who wishes to do this put the RDP machine behind a Virtual Private Network (VPN).

“As the attack seems to indicate that an administrative password was abused by the criminals, we also recommend the widespread adoption of two-factor authentication wherever possible

“Keeping regular backups of your most important and current data on an offline storage device is the best way to avoid having to pay a ransom.

“Use anti-ransomware protection, such as Sophos Intercept X, to block MegaCortex and future ransomware

Sophos' Senior Security Advisor, John Shier, said they suspect this script kiddie/living-off-the-land ‘mega bundle’ and a good example of what we've lately been calling cybercriminal pen-testing.

“The MegaCortex attackers have taken the blended threat approach and turned it up to 11, by increasing the automated component to target more victims. Once they have your admin credentials, there's no stopping them. Launching the attack from your own domain controller is a great way for the attackers to inherit all the authority they need to impact everything in an organization.

“Organizations need to pay attention to basic security controls and perform security assessments, before the criminals do, to prevent attackers like these from slipping through” he said.

Remmy Nweke/DoP

*JOIN our alert's group | Share stories with us | Advert placement: WhatsApp | SMS: +2348033592762 *Twitter: @ITREALMS *Email: itrealms.dsa@gmail.com*


Pix: Sophos' Senior Security Advisor, John Shier.