Sorry

This feed does not validate.

In addition, interoperability with the widest range of feed readers could be improved by implementing the following recommendations.

Source: https://feeds.feedburner.com/sophos/dgdY

  1. <?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
  2. xmlns:content="http://purl.org/rss/1.0/modules/content/"
  3. xmlns:wfw="http://wellformedweb.org/CommentAPI/"
  4. xmlns:dc="http://purl.org/dc/elements/1.1/"
  5. xmlns:atom="http://www.w3.org/2005/Atom"
  6. xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  7. xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
  8. xmlns:georss="http://www.georss.org/georss"
  9. xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#"
  10. xmlns:media="http://search.yahoo.com/mrss/"
  11. >
  12.  
  13. <channel>
  14. <title>Sophos News</title>
  15. <atom:link href="https://news.sophos.com/en-us/feed/" rel="self" type="application/rss+xml" />
  16. <link>https://news.sophos.com/en-us/</link>
  17. <description>The Sophos Blog</description>
  18. <lastBuildDate>Thu, 19 Dec 2024 17:11:17 +0000</lastBuildDate>
  19. <language>en-US</language>
  20. <sy:updatePeriod>
  21. hourly </sy:updatePeriod>
  22. <sy:updateFrequency>
  23. 1 </sy:updateFrequency>
  24. <generator>https://wordpress.org/?v=6.7.1</generator>
  25.  
  26. <image>
  27. <url>https://news.sophos.com/wp-content/uploads/2020/01/cropped-sophos.png?w=32</url>
  28. <title>Sophos News</title>
  29. <link>https://news.sophos.com/en-us/</link>
  30. <width>32</width>
  31. <height>32</height>
  32. </image>
  33. <site xmlns="com-wordpress:feed-additions:1">166161023</site> <item>
  34. <title>Phishing platform Rockstar 2FA trips, and “FlowerStorm” picks up the pieces</title>
  35. <link>https://news.sophos.com/en-us/2024/12/19/phishing-platform-rockstar-2fa-trips-and-flowerstorm-picks-up-the-pieces/</link>
  36. <comments>https://news.sophos.com/en-us/2024/12/19/phishing-platform-rockstar-2fa-trips-and-flowerstorm-picks-up-the-pieces/?noamp=mobile#respond</comments>
  37. <dc:creator><![CDATA[gallagherseanm]]></dc:creator>
  38. <pubDate>Thu, 19 Dec 2024 15:11:48 +0000</pubDate>
  39. <category><![CDATA[Security Operations]]></category>
  40. <category><![CDATA[Threat Research]]></category>
  41. <category><![CDATA[CloudFlare]]></category>
  42. <category><![CDATA[featured]]></category>
  43. <category><![CDATA[FlowerStorm]]></category>
  44. <category><![CDATA[legitimate service abuse]]></category>
  45. <category><![CDATA[Phishing]]></category>
  46. <category><![CDATA[phishing-as-a-service]]></category>
  47. <category><![CDATA[Rockstar]]></category>
  48. <category><![CDATA[Rockstar2FA]]></category>
  49. <category><![CDATA[Sophos MDR]]></category>
  50. <guid isPermaLink="false">https://news.sophos.com/en-us/?p=958944</guid>
  51.  
  52. <description><![CDATA[A sudden disruption of a major phishing-as-a-service provider leads to the rise of another…that looks very familiar ]]></description>
  53. <wfw:commentRss>https://news.sophos.com/en-us/2024/12/19/phishing-platform-rockstar-2fa-trips-and-flowerstorm-picks-up-the-pieces/feed/</wfw:commentRss>
  54. <slash:comments>0</slash:comments>
  55. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_1469287178.jpg?w=230&#38;h=130&#38;crop=1" medium="image" alt="" />
  56. <post-id xmlns="com-wordpress:feed-additions:1">958944</post-id>
  57. <media:thumbnail url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_1469287178.jpg" alt="" />
  58. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_1469287178.jpg" medium="image" alt="">
  59. <media:title type="html">A,Wooden,Acoustic,Guitar,At,Night.,With,Spotlight,For,Your</media:title>
  60. </media:content>
  61.  
  62. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/rockstar-decoy.png" medium="image" alt="A screenshot of a Rockstar2FA &#034;decoy&#034; page, a fake auto dealer site.">
  63. <media:title type="html">A screenshot of a Rockstar2FA &#034;decoy&#034; page, a fake auto dealer site.</media:title>
  64. </media:content>
  65.  
  66. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/Rockstar-backend-server-comms.jpg" medium="image" alt="Screen shots of the developer view of Chrome showing web requests sent from a Rockstar2FA phishing portal. ">
  67. <media:title type="html">Screen shots of the developer view of Chrome showing web requests sent from a Rockstar2FA phishing portal. </media:title>
  68. </media:content>
  69.  
  70. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/RockstarTLDs.png" medium="image" alt="A pie chart showing the distribution of top-level domains the 10 most heavily used domain names were registered with. A third were .ru, a fifth were .com. ">
  71. <media:title type="html">A pie chart showing the distribution of top-level domains the 10 most heavily used domain names were registered with. A third were .ru, a fifth were .com. </media:title>
  72. </media:content>
  73.  
  74. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/FlowerStorm-detects-by-TLD.jpg" medium="image" alt="A bar chart showing the distribution of TLDs and number of URLs detected per month for Rockstar2FA. The number of .ru domains decreased significantly over time.">
  75. <media:title type="html">A bar chart showing the distribution of TLDs and number of URLs detected per month for Rockstar2FA. The number of .ru domains decreased significantly over time.</media:title>
  76. </media:content>
  77.  
  78. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/Rockstarerror522.png" medium="image" alt="A screenshot of a failed connection error for a Rockstar decoy page.">
  79. <media:title type="html">A screenshot of a failed connection error for a Rockstar decoy page.</media:title>
  80. </media:content>
  81.  
  82. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/RockstarOutlookanimate.png" medium="image" alt="A screenshot of an animated Office365 logo for Outlook used by Rockstar&#039;s phishing portal pages.">
  83. <media:title type="html">A screenshot of an animated Office365 logo for Outlook used by Rockstar&#039;s phishing portal pages.</media:title>
  84. </media:content>
  85.  
  86. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/Failed_connection_Rockstar_backend.png" medium="image" alt="A screenshot of a Chrome developer view of a Rockstar pages.dev phishing portal failing to connect to a backend server.">
  87. <media:title type="html">A screenshot of a Chrome developer view of a Rockstar pages.dev phishing portal failing to connect to a backend server.</media:title>
  88. </media:content>
  89.  
  90. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/FlowerStormphishnext-php.png" medium="image" alt="A screenshot of data abouit and ">
  91. <media:title type="html">A screenshot of data abouit and </media:title>
  92. </media:content>
  93.  
  94. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/FlowerStormEntraID-log.png" medium="image" alt="Figure 9: the EnteraID log for a sign-in by the adversary-in-the-middle script on the phishing service’s back-end server.">
  95. <media:title type="html">Figure 9: the EnteraID log for a sign-in by the adversary-in-the-middle script on the phishing service’s back-end server.</media:title>
  96. </media:content>
  97.  
  98. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/Flowerstorm-same-host-authenticate.png" medium="image" alt="Figure 10: the HTTP header data for a phishing page’s backend server communications on a separate host">
  99. <media:title type="html">Figure 10: the HTTP header data for a phishing page’s backend server communications on a separate host</media:title>
  100. </media:content>
  101.  
  102. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/FlowerstormDeveloperViewPhishportal.png" medium="image" alt="Figure 11: A developer browser view of the phishing page protectivewearsupplies[.]doclawfederal[.]com/wQBPg/">
  103. <media:title type="html">Figure 11: A developer browser view of the phishing page protectivewearsupplies[.]doclawfederal[.]com/wQBPg/</media:title>
  104. </media:content>
  105.  
  106. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/rockstardom.png" medium="image" alt="Figure12: The document object model of a Rockstar2FA phishing page ">
  107. <media:title type="html">Figure12: The document object model of a Rockstar2FA phishing page </media:title>
  108. </media:content>
  109.  
  110. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/OldFlowerDom.png" medium="image" alt="Figure 13: The DOM of an older FlowerStorm phishing page (from June 2024)">
  111. <media:title type="html">Figure 13: The DOM of an older FlowerStorm phishing page (from June 2024)</media:title>
  112. </media:content>
  113.  
  114. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/NewFlowerDom.png" medium="image" alt="Figure 14: The DOM of a newer FlowerStorm phishing page; the algorithm generating the title and function names uses a combination of two botanical-themed words">
  115. <media:title type="html">Figure 14: The DOM of a newer FlowerStorm phishing page; the algorithm generating the title and function names uses a combination of two botanical-themed words</media:title>
  116. </media:content>
  117.  
  118. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/RS_vs_FS_detects.jpg" medium="image" alt="Figure 15: A chart plotting daily page detections for Rockstar2FA and FlowerStorm through the end of November 2024 ">
  119. <media:title type="html">Figure 15: A chart plotting daily page detections for Rockstar2FA and FlowerStorm through the end of November 2024 </media:title>
  120. </media:content>
  121.  
  122. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/FlowerStormTargeting.png" medium="image" alt="Figure 16: The ten countries most targeted by attackers using FlowerStorm, based on Sophos detections">
  123. <media:title type="html">Figure 16: The ten countries most targeted by attackers using FlowerStorm, based on Sophos detections</media:title>
  124. </media:content>
  125.  
  126. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/FSindustrytargeting.png" medium="image" alt="Figure 17: The ten business sectors most targeted by attackers using FlowerStorm">
  127. <media:title type="html">Figure 17: The ten business sectors most targeted by attackers using FlowerStorm</media:title>
  128. </media:content>
  129. </item>
  130. <item>
  131. <title>Sophos ranked #1 overall for Firewall, MDR, and EDR in the G2 Winter 2025 Reports</title>
  132. <link>https://news.sophos.com/en-us/2024/12/18/sophos-ranked-1-overall-for-firewall-mdr-and-edr-in-the-g2-winter-2025-reports/</link>
  133. <comments>https://news.sophos.com/en-us/2024/12/18/sophos-ranked-1-overall-for-firewall-mdr-and-edr-in-the-g2-winter-2025-reports/?noamp=mobile#respond</comments>
  134. <dc:creator><![CDATA[rajansanhotra]]></dc:creator>
  135. <pubDate>Wed, 18 Dec 2024 10:21:54 +0000</pubDate>
  136. <category><![CDATA[Products & Services]]></category>
  137. <category><![CDATA[EDR]]></category>
  138. <category><![CDATA[Endpoint]]></category>
  139. <category><![CDATA[Firewall]]></category>
  140. <category><![CDATA[G2]]></category>
  141. <category><![CDATA[MDR]]></category>
  142. <category><![CDATA[Sophos EDR]]></category>
  143. <category><![CDATA[Sophos Endpoint]]></category>
  144. <category><![CDATA[Sophos Firewall]]></category>
  145. <category><![CDATA[Sophos MDR]]></category>
  146. <category><![CDATA[Sophos XDR]]></category>
  147. <category><![CDATA[XDR]]></category>
  148. <guid isPermaLink="false">https://news.sophos.com/en-us/?p=958917</guid>
  149.  
  150. <description><![CDATA[Sophos was also ranked the #1 solution in 36 individual reports spanning the Antivirus, EDR, Endpoint Protection Suites, XDR, Firewall, and MDR markets.]]></description>
  151. <wfw:commentRss>https://news.sophos.com/en-us/2024/12/18/sophos-ranked-1-overall-for-firewall-mdr-and-edr-in-the-g2-winter-2025-reports/feed/</wfw:commentRss>
  152. <slash:comments>0</slash:comments>
  153. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/Sophos-ranked-1-overall-for-Firewall-MDR-and-EDR-in-the-G2-Winter-2025-Reports-1.png?w=230&#38;h=130&#38;crop=1" medium="image" alt="Sophos ranked #1 overall for Firewall, MDR, and EDR in the G2 Winter 2025 Reports" />
  154. <post-id xmlns="com-wordpress:feed-additions:1">958917</post-id>
  155. <media:thumbnail url="https://news.sophos.com/wp-content/uploads/2024/12/Sophos-ranked-1-overall-for-Firewall-MDR-and-EDR-in-the-G2-Winter-2025-Reports-1.png" alt="Sophos ranked #1 overall for Firewall, MDR, and EDR in the G2 Winter 2025 Reports" />
  156. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/Sophos-ranked-1-overall-for-Firewall-MDR-and-EDR-in-the-G2-Winter-2025-Reports-1.png" medium="image" alt="Sophos ranked #1 overall for Firewall, MDR, and EDR in the G2 Winter 2025 Reports">
  157. <media:title type="html">Sophos ranked #1 overall for Firewall, MDR, and EDR in the G2 Winter 2025 Reports</media:title>
  158. </media:content>
  159. </item>
  160. <item>
  161. <title>Year in Review 2024: The major headlines and moments from Sophos this year</title>
  162. <link>https://news.sophos.com/en-us/2024/12/17/year-in-review-2024-the-major-headlines-and-moments-from-sophos-this-year/</link>
  163. <comments>https://news.sophos.com/en-us/2024/12/17/year-in-review-2024-the-major-headlines-and-moments-from-sophos-this-year/?noamp=mobile#respond</comments>
  164. <dc:creator><![CDATA[Doug Aamoth]]></dc:creator>
  165. <pubDate>Tue, 17 Dec 2024 13:00:15 +0000</pubDate>
  166. <category><![CDATA[Products & Services]]></category>
  167. <category><![CDATA[Sophos Endpoint]]></category>
  168. <category><![CDATA[Sophos MDR]]></category>
  169. <category><![CDATA[Sophos X-Ops]]></category>
  170. <category><![CDATA[Sophos XDR]]></category>
  171. <guid isPermaLink="false">https://news.sophos.com/en-us/?p=958865</guid>
  172.  
  173. <description><![CDATA[From cyber attacks across the geopolitical landscapes, to product updates that help small businesses, Sophos was there in 2024.]]></description>
  174. <wfw:commentRss>https://news.sophos.com/en-us/2024/12/17/year-in-review-2024-the-major-headlines-and-moments-from-sophos-this-year/feed/</wfw:commentRss>
  175. <slash:comments>0</slash:comments>
  176. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/sophos-wews-blog-banner-year-in-review-1200x628px-01.png?w=230&#38;h=130&#38;crop=1" medium="image" alt="sophos-wews-blog-banner-year-in-review-1200x628px-01" />
  177. <post-id xmlns="com-wordpress:feed-additions:1">958865</post-id>
  178. <media:thumbnail url="https://news.sophos.com/wp-content/uploads/2024/12/sophos-wews-blog-banner-year-in-review-1200x628px-01.png" alt="sophos-wews-blog-banner-year-in-review-1200x628px-01" />
  179. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/sophos-wews-blog-banner-year-in-review-1200x628px-01.png" medium="image" alt="sophos-wews-blog-banner-year-in-review-1200x628px-01">
  180. <media:title type="html">sophos-wews-blog-banner-year-in-review-1200x628px-01</media:title>
  181. </media:content>
  182. </item>
  183. <item>
  184. <title>DeepSpeed: a tuning tool for large language models</title>
  185. <link>https://news.sophos.com/en-us/2024/12/13/deepspeed-a-tuning-tool-for-large-language-models/</link>
  186. <comments>https://news.sophos.com/en-us/2024/12/13/deepspeed-a-tuning-tool-for-large-language-models/?noamp=mobile#respond</comments>
  187. <dc:creator><![CDATA[gallagherseanm]]></dc:creator>
  188. <pubDate>Fri, 13 Dec 2024 11:30:50 +0000</pubDate>
  189. <category><![CDATA[AI Research]]></category>
  190. <category><![CDATA[deepspeed]]></category>
  191. <category><![CDATA[featured]]></category>
  192. <category><![CDATA[LLM]]></category>
  193. <category><![CDATA[LLM tuning]]></category>
  194. <guid isPermaLink="false">https://news.sophos.com/en-us/?p=958840</guid>
  195.  
  196. <description><![CDATA[SophosAI’s framework for upgrading the performance of LLMs for cybersecurity tasks (or any other specific task) is now open source. ]]></description>
  197. <wfw:commentRss>https://news.sophos.com/en-us/2024/12/13/deepspeed-a-tuning-tool-for-large-language-models/feed/</wfw:commentRss>
  198. <slash:comments>0</slash:comments>
  199. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_asset-generation-6dc4f763-f8a7-4dff-a56b-92736d8c8d6c-1_edited-e1734048709973.jpeg?w=230&#38;h=130&#38;crop=1" medium="image" alt="" />
  200. <post-id xmlns="com-wordpress:feed-additions:1">958840</post-id>
  201. <media:thumbnail url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_asset-generation-6dc4f763-f8a7-4dff-a56b-92736d8c8d6c-1_edited-e1734048709973.jpeg" alt="" />
  202. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_asset-generation-6dc4f763-f8a7-4dff-a56b-92736d8c8d6c-1_edited-e1734048709973.jpeg" medium="image" alt="">
  203. <media:title type="html">shutterstock_asset-generation-6dc4f763-f8a7-4dff-a56b-92736d8c8d6c-1_edited</media:title>
  204. </media:content>
  205.  
  206. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/Slide1.jpeg" medium="image" alt="" />
  207. </item>
  208. <item>
  209. <title>The Bite from Inside: The Sophos Active Adversary Report</title>
  210. <link>https://news.sophos.com/en-us/2024/12/12/active-adversary-report-2024-12/</link>
  211. <comments>https://news.sophos.com/en-us/2024/12/12/active-adversary-report-2024-12/?noamp=mobile#respond</comments>
  212. <dc:creator><![CDATA[Angela Gunn]]></dc:creator>
  213. <pubDate>Thu, 12 Dec 2024 14:00:56 +0000</pubDate>
  214. <category><![CDATA[Security Operations]]></category>
  215. <category><![CDATA[Threat Research]]></category>
  216. <category><![CDATA[active adversary]]></category>
  217. <category><![CDATA[Active Adversary Report]]></category>
  218. <category><![CDATA[featured]]></category>
  219. <category><![CDATA[incident response]]></category>
  220. <category><![CDATA[IR]]></category>
  221. <category><![CDATA[LoLBINs]]></category>
  222. <category><![CDATA[MDR]]></category>
  223. <category><![CDATA[RDP]]></category>
  224. <guid isPermaLink="false">https://news.sophos.com/en-us/?p=958790</guid>
  225.  
  226. <description><![CDATA[A sea change in available data fuels fresh insights from the first half of 2024]]></description>
  227. <wfw:commentRss>https://news.sophos.com/en-us/2024/12/12/active-adversary-report-2024-12/feed/</wfw:commentRss>
  228. <slash:comments>0</slash:comments>
  229. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_2154147129.jpg?w=230&#38;h=130&#38;crop=1" medium="image" alt="Active Adversary Report" />
  230. <post-id xmlns="com-wordpress:feed-additions:1">958790</post-id>
  231. <media:thumbnail url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_2154147129.jpg" alt="Active Adversary Report" />
  232. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_2154147129.jpg" medium="image" alt="Active Adversary Report">
  233. <media:title type="html">Active Adversary Report</media:title>
  234. </media:content>
  235.  
  236. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/aar2412-01.png" medium="image" alt="A bar chart showing an increase in LOLbins in the span between 2021 and the first half of 2024; the totals increased from just over 100 to nearly 190">
  237. <media:title type="html">A bar chart showing an increase in LOLbins in the span between 2021 and the first half of 2024; the totals increased from just over 100 to nearly 190</media:title>
  238. </media:content>
  239.  
  240. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/aar2412-02.png" medium="image" alt="A stacked bar chart showing the relationship between artifact and LOLbin counts between 2021 and the first half of 2024, as described in text">
  241. <media:title type="html">A stacked bar chart showing the relationship between artifact and LOLbin counts between 2021 and the first half of 2024, as described in text</media:title>
  242. </media:content>
  243.  
  244. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/aar2412-03.png" medium="image" alt="A bar chart showing the prevalence of the top 29 LOLbins noted in the first half of 2024, ranging from RDP at just under 90 percent to findstr.exe at 10 percent">
  245. <media:title type="html">A bar chart showing the prevalence of the top 29 LOLbins noted in the first half of 2024, ranging from RDP at just under 90 percent to findstr.exe at 10 percent</media:title>
  246. </media:content>
  247.  
  248. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/aar2412-04.png" medium="image" alt="A table showing the changes in prevalence of the top 29 1H24 LOLbins between 2023 and the first half of the year; all but five of the listed LOLbins increased in frequency of usage">
  249. <media:title type="html">A table showing the changes in prevalence of the top 29 1H24 LOLbins between 2023 and the first half of the year; all but five of the listed LOLbins increased in frequency of usage</media:title>
  250. </media:content>
  251.  
  252. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/aar2412-05.png" medium="image" alt="A table showing RDP usage in attacks in 2022, 2023, and the first half of 2024">
  253. <media:title type="html">A table showing RDP usage in attacks in 2022, 2023, and the first half of 2024</media:title>
  254. </media:content>
  255.  
  256. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/aar2412-06.png" medium="image" alt="Five funnel-shaped charts showing the prevalence of ransomware attributions between 2020 and the first half of 2024; in this format they resemble different types of trees as described in text">
  257. <media:title type="html">Five funnel-shaped charts showing the prevalence of ransomware attributions between 2020 and the first half of 2024; in this format they resemble different types of trees as described in text</media:title>
  258. </media:content>
  259.  
  260. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/aar2412-07.png" medium="image" alt="A table showing the root causes of 1H24 cases for the entire report, for IR&#039;s portion of the data, and for MDR&#039;s portion of the data">
  261. <media:title type="html">A table showing the root causes of 1H24 cases for the entire report, for IR&#039;s portion of the data, and for MDR&#039;s portion of the data</media:title>
  262. </media:content>
  263.  
  264. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/aar2412-08.png" medium="image" alt="A table showing changes in artifact prevalence in AAR cases from 2021 to the first half of 2024">
  265. <media:title type="html">A table showing changes in artifact prevalence in AAR cases from 2021 to the first half of 2024</media:title>
  266. </media:content>
  267.  
  268. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/aar2412-a1.png" medium="image" alt="A world map showing locations in which cases appearing in this report occurred">
  269. <media:title type="html">A world map showing locations in which cases appearing in this report occurred</media:title>
  270. </media:content>
  271. </item>
  272. <item>
  273. <title>Sophos excels in the 2024 MITRE ATT&#038;CK® Evaluations: Enterprise</title>
  274. <link>https://news.sophos.com/en-us/2024/12/11/sophos-excels-in-the-2024-mitre-attck-evaluations-enterprise/</link>
  275. <comments>https://news.sophos.com/en-us/2024/12/11/sophos-excels-in-the-2024-mitre-attck-evaluations-enterprise/?noamp=mobile#respond</comments>
  276. <dc:creator><![CDATA[rajansanhotra]]></dc:creator>
  277. <pubDate>Wed, 11 Dec 2024 15:55:55 +0000</pubDate>
  278. <category><![CDATA[Products & Services]]></category>
  279. <category><![CDATA[Security Operations]]></category>
  280. <category><![CDATA[featured]]></category>
  281. <category><![CDATA[MITRE ATT&CK]]></category>
  282. <category><![CDATA[Sophos EDR]]></category>
  283. <category><![CDATA[Sophos Endpoint]]></category>
  284. <category><![CDATA[Sophos XDR]]></category>
  285. <guid isPermaLink="false">https://news.sophos.com/en-us/?p=958700</guid>
  286.  
  287. <description><![CDATA[Results from the latest ATT&#38;CK Evaluations for endpoint detection and response solutions.]]></description>
  288. <wfw:commentRss>https://news.sophos.com/en-us/2024/12/11/sophos-excels-in-the-2024-mitre-attck-evaluations-enterprise/feed/</wfw:commentRss>
  289. <slash:comments>0</slash:comments>
  290. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/Sophos-excels-in-the-2024-MITRE-ATTCK®-Evaluations-Enterprise-3.png?w=230&#38;h=130&#38;crop=1" medium="image" alt="Sophos excels in the 2024 MITRE ATT&amp;CK® Evaluations Enterprise" />
  291. <post-id xmlns="com-wordpress:feed-additions:1">958700</post-id>
  292. <media:thumbnail url="https://news.sophos.com/wp-content/uploads/2024/12/Sophos-excels-in-the-2024-MITRE-ATTCK®-Evaluations-Enterprise-3.png" alt="Sophos excels in the 2024 MITRE ATT&#38;CK® Evaluations Enterprise" />
  293. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/Sophos-excels-in-the-2024-MITRE-ATTCK®-Evaluations-Enterprise-3.png" medium="image" alt="Sophos excels in the 2024 MITRE ATT&#38;CK® Evaluations Enterprise">
  294. <media:title type="html">Sophos excels in the 2024 MITRE ATT&#38;CK® Evaluations Enterprise</media:title>
  295. </media:content>
  296.  
  297. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/Evaluation-particpants.png" medium="image" alt="MITRE ATT&#038;CK® Evaluation participants">
  298. <media:title type="html">MITRE ATT&#038;CK® Evaluation participants</media:title>
  299. </media:content>
  300.  
  301. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/vendor-performance.png" medium="image" alt="MITRE ATT&#038;CK Evaluation vendor performance">
  302. <media:title type="html">MITRE ATT&#038;CK Evaluation vendor performance</media:title>
  303. </media:content>
  304. </item>
  305. <item>
  306. <title>Keeping it real: Sophos and the 2024 MITRE ATT&#038;CK Evaluations: Enterprise</title>
  307. <link>https://news.sophos.com/en-us/2024/12/11/keeping-it-real-sophos-and-the-2024-mitre-attck-evaluations-enterprise/</link>
  308. <comments>https://news.sophos.com/en-us/2024/12/11/keeping-it-real-sophos-and-the-2024-mitre-attck-evaluations-enterprise/?noamp=mobile#comments</comments>
  309. <dc:creator><![CDATA[Michael Wood]]></dc:creator>
  310. <pubDate>Wed, 11 Dec 2024 15:35:22 +0000</pubDate>
  311. <category><![CDATA[Threat Research]]></category>
  312. <category><![CDATA[featured]]></category>
  313. <category><![CDATA[MITRE]]></category>
  314. <category><![CDATA[MITRE ATT&CK]]></category>
  315. <category><![CDATA[Ransomware]]></category>
  316. <category><![CDATA[Sophos X-Ops]]></category>
  317. <guid isPermaLink="false">https://news.sophos.com/en-us/?p=958764</guid>
  318.  
  319. <description><![CDATA[Sophos X-Ops looks at the realism of this year’s MITRE ATT&#38;CK Evaluations]]></description>
  320. <wfw:commentRss>https://news.sophos.com/en-us/2024/12/11/keeping-it-real-sophos-and-the-2024-mitre-attck-evaluations-enterprise/feed/</wfw:commentRss>
  321. <slash:comments>1</slash:comments>
  322. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_2229463409.jpg?w=230&#38;h=130&#38;crop=1" medium="image" alt="White Grey Virtual reality Headset isolated on white background" />
  323. <post-id xmlns="com-wordpress:feed-additions:1">958764</post-id>
  324. <media:thumbnail url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_2229463409.jpg" alt="White Grey Virtual reality Headset isolated on white background" />
  325. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_2229463409.jpg" medium="image" alt="White Grey Virtual reality Headset isolated on white background">
  326. <media:title type="html">White,Grey,Virtual,Reality,Headset,Isolated,On,White,Background</media:title>
  327. </media:content>
  328.  
  329. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/image1.png" medium="image" alt="A screenshot of a dashboard showing commands which establish persistence via &#039;ZoomHelperTool.plist&#039;">
  330. <media:title type="html">A screenshot of a dashboard showing commands which establish persistence via &#039;ZoomHelperTool.plist&#039;</media:title>
  331. </media:content>
  332.  
  333. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/image2.png" medium="image" alt="A screenshot of disassembled code">
  334. <media:title type="html">A screenshot of disassembled code</media:title>
  335. </media:content>
  336.  
  337. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/image3.png" medium="image" alt="A screenshot of disassembled code">
  338. <media:title type="html">A screenshot of disassembled code</media:title>
  339. </media:content>
  340.  
  341. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/image4.jpeg" medium="image" alt="A screenshot of a command window showing a symlink for msverload.dll">
  342. <media:title type="html">A screenshot of a command window showing a symlink for msverload.dll</media:title>
  343. </media:content>
  344.  
  345. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/image5.png" medium="image" alt="A screenshot of disassembled code">
  346. <media:title type="html">A screenshot of disassembled code</media:title>
  347. </media:content>
  348.  
  349. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/image6.png" medium="image" alt="A screenshot of a dashboard, showing detection of exfiltration">
  350. <media:title type="html">A screenshot of a dashboard, showing detection of exfiltration</media:title>
  351. </media:content>
  352.  
  353. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/image7.png" medium="image" alt="A screenshot of disassembled code">
  354. <media:title type="html">A screenshot of disassembled code</media:title>
  355. </media:content>
  356.  
  357. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/image8.png" medium="image" alt="A screenshot of a dashboard, with a list of commands to resize shadowstorage">
  358. <media:title type="html">A screenshot of a dashboard, with a list of commands to resize shadowstorage</media:title>
  359. </media:content>
  360.  
  361. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/image9.png" medium="image" alt="A screenshot of a dashboard, showing a list of executed net stop commands for various services">
  362. <media:title type="html">A screenshot of a dashboard, showing a list of executed net stop commands for various services</media:title>
  363. </media:content>
  364.  
  365. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/image10.png" medium="image" alt="A screenshot of a dashboard showing that cmd.exe was executed during an RDP session">
  366. <media:title type="html">A screenshot of a dashboard showing that cmd.exe was executed during an RDP session</media:title>
  367. </media:content>
  368.  
  369. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/image11.png" medium="image" alt="A screenshot of disassembled code">
  370. <media:title type="html">A screenshot of disassembled code</media:title>
  371. </media:content>
  372.  
  373. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/image12.png" medium="image" alt="A screenshot of text (&#039;thumbprint information&#039;) from CryptoGuard">
  374. <media:title type="html">A screenshot of text (&#039;thumbprint information&#039;) from CryptoGuard</media:title>
  375. </media:content>
  376. </item>
  377. <item>
  378. <title>December Patch Tuesday arrives bearing 71 gifts</title>
  379. <link>https://news.sophos.com/en-us/2024/12/11/december-patch-tuesday-arrives-bearing-71-gifts/</link>
  380. <comments>https://news.sophos.com/en-us/2024/12/11/december-patch-tuesday-arrives-bearing-71-gifts/?noamp=mobile#respond</comments>
  381. <dc:creator><![CDATA[Angela Gunn]]></dc:creator>
  382. <pubDate>Wed, 11 Dec 2024 08:00:38 +0000</pubDate>
  383. <category><![CDATA[Threat Research]]></category>
  384. <category><![CDATA[featured]]></category>
  385. <category><![CDATA[Microsoft]]></category>
  386. <category><![CDATA[Patch Tuesday]]></category>
  387. <category><![CDATA[RDP]]></category>
  388. <category><![CDATA[Windows]]></category>
  389. <guid isPermaLink="false">https://news.sophos.com/en-us/?p=958752</guid>
  390.  
  391. <description><![CDATA[Seventeen Critical-severity CVEs ready to deck your halls; also, new blog guidance for Windows Server admins]]></description>
  392. <wfw:commentRss>https://news.sophos.com/en-us/2024/12/11/december-patch-tuesday-arrives-bearing-71-gifts/feed/</wfw:commentRss>
  393. <slash:comments>0</slash:comments>
  394. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_517169110.jpg?w=230&#38;h=130&#38;crop=1" medium="image" alt="martes de parches" />
  395. <post-id xmlns="com-wordpress:feed-additions:1">958752</post-id>
  396. <media:thumbnail url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_517169110.jpg" alt="martes de parches" />
  397. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/shutterstock_517169110.jpg" medium="image" alt="martes de parches">
  398. <media:title type="html">martes de parches</media:title>
  399. </media:content>
  400.  
  401. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/pt2412-01.png" medium="image" alt="A bar chart showing the severities of the issues addressed in the December 2024 Patch Tuesday release, sorted by impact. Information duplicated in text.">
  402. <media:title type="html">A bar chart showing the severities of the issues addressed in the December 2024 Patch Tuesday release, sorted by impact. Information duplicated in text.</media:title>
  403. </media:content>
  404.  
  405. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/pt2412-02.png" medium="image" alt="A bar chart showing the severeities of all patches in the December 2024 release, sorted by product family. Information also covered in text.">
  406. <media:title type="html">A bar chart showing the severeities of all patches in the December 2024 release, sorted by product family. Information also covered in text.</media:title>
  407. </media:content>
  408.  
  409. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/pt2412-03.png" medium="image" alt="A bar chart showing the cumulative totals for all Patch Tuesday releases in 2024. Highlights covered in text.">
  410. <media:title type="html">A bar chart showing the cumulative totals for all Patch Tuesday releases in 2024. Highlights covered in text.</media:title>
  411. </media:content>
  412.  
  413. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/pt2412-04.png" medium="image" alt="A bar chart showing the patch counts for each month from January 202-December 2024; highlights covered in text">
  414. <media:title type="html">A bar chart showing the patch counts for each month from January 202-December 2024; highlights covered in text</media:title>
  415. </media:content>
  416. </item>
  417. <item>
  418. <title>Network security best practices for the holidays</title>
  419. <link>https://news.sophos.com/en-us/2024/12/10/network-security-best-practices-for-the-holidays/</link>
  420. <comments>https://news.sophos.com/en-us/2024/12/10/network-security-best-practices-for-the-holidays/?noamp=mobile#respond</comments>
  421. <dc:creator><![CDATA[Chris McCormack]]></dc:creator>
  422. <pubDate>Tue, 10 Dec 2024 20:19:47 +0000</pubDate>
  423. <category><![CDATA[Products & Services]]></category>
  424. <category><![CDATA[Firewall]]></category>
  425. <category><![CDATA[network]]></category>
  426. <guid isPermaLink="false">https://news.sophos.com/en-us/?p=958738</guid>
  427.  
  428. <description><![CDATA[Tips to better protect your network while you take some well-deserved time off.]]></description>
  429. <wfw:commentRss>https://news.sophos.com/en-us/2024/12/10/network-security-best-practices-for-the-holidays/feed/</wfw:commentRss>
  430. <slash:comments>0</slash:comments>
  431. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/Shutterstock_768302194.jpg?w=230&#38;h=130&#38;crop=1" medium="image" alt="Shutterstock_768302194" />
  432. <post-id xmlns="com-wordpress:feed-additions:1">958738</post-id>
  433. <media:thumbnail url="https://news.sophos.com/wp-content/uploads/2024/12/Shutterstock_768302194.jpg" alt="Shutterstock_768302194" />
  434. <media:content url="https://news.sophos.com/wp-content/uploads/2024/12/Shutterstock_768302194.jpg" medium="image" alt="Shutterstock_768302194">
  435. <media:title type="html">Shutterstock_768302194</media:title>
  436. </media:content>
  437. </item>
  438. <item>
  439. <title>Sophos AI to present on how to defang malicious AI models at Black Hat Europe</title>
  440. <link>https://news.sophos.com/en-us/2024/12/10/sophos-ai-to-present-on-how-to-defang-malicious-ai-models-at-black-hat-europe/</link>
  441. <comments>https://news.sophos.com/en-us/2024/12/10/sophos-ai-to-present-on-how-to-defang-malicious-ai-models-at-black-hat-europe/?noamp=mobile#respond</comments>
  442. <dc:creator><![CDATA[gallagherseanm]]></dc:creator>
  443. <pubDate>Tue, 10 Dec 2024 15:35:16 +0000</pubDate>
  444. <category><![CDATA[AI Research]]></category>
  445. <category><![CDATA[AI Trojans]]></category>
  446. <category><![CDATA[featured]]></category>
  447. <category><![CDATA[LLM]]></category>
  448. <guid isPermaLink="false">https://news.sophos.com/en-us/?p=958735</guid>
  449.  
  450. <description><![CDATA[“LLMbotomy” research reveals how Trojans can be injected into Large Language Models, and how to disarm them.]]></description>
  451. <wfw:commentRss>https://news.sophos.com/en-us/2024/12/10/sophos-ai-to-present-on-how-to-defang-malicious-ai-models-at-black-hat-europe/feed/</wfw:commentRss>
  452. <slash:comments>0</slash:comments>
  453. <media:content url="https://news.sophos.com/wp-content/uploads/2022/02/shutterstock_389760973.jpg?w=230&#38;h=130&#38;crop=1" medium="image" alt="" />
  454. <post-id xmlns="com-wordpress:feed-additions:1">958735</post-id>
  455. <media:thumbnail url="https://news.sophos.com/wp-content/uploads/2022/02/shutterstock_389760973.jpg" alt="" />
  456. <media:content url="https://news.sophos.com/wp-content/uploads/2022/02/shutterstock_389760973.jpg" medium="image" alt="">
  457. <media:title type="html">Flat,Line,Design,Website,Banner,Of,Learning,Process,,Brain,Process,</media:title>
  458. </media:content>
  459. </item>
  460. </channel>
  461. </rss>
  462.  
Copyright © 2002-9 Sam Ruby, Mark Pilgrim, Joseph Walton, and Phil Ringnalda