Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Recognizing and detecting data exfiltration

Every breach that lands a CISO in front of the board has a common final act: Data leaving the building. Attackers don't get paid for breaking in. They get paid for what they take out. And by the time stolen data appears on an extortion site or in a regulator's inbox, the window to stop the damage has already closed. That is what makes exfiltration so dangerous. It rarely looks like an emergency.

Corelight Agent Builder Library: AI Investigation Demo

What happens when you ask a generic SIEM AI assistant and a Corelight-powered threat hunter agent the exact same question about a suspicious IP? The difference is not the model. It is the investigation expertise. In this demo, we walk through a side-by-side comparison using Elastic's agent builder. A default AI assistant returns a surface-level summary. An agent built with the Corelight Agent Builder Library identifies lateral movement, flags potential ransomware and data exfiltration, surfaces IDS alerts, maps involved hosts, and recommends next steps.

From shadow AI visibility to AI threat detection

AI adoption is outpacing enterprise control. The 2026 Verizon DBIR found that 45% of employees regularly use AI on corporate devices, and 67% of those users access AI through non-corporate accounts. Cyberhaven Labs reports that 39.7% of data sent to AI tools is sensitive, while endpoint AI app adoption grew 509% year over year.

The answer to AI uncertainty is adaptability, not paralysis

AI uncertainty is not a strategic reason to wait; it is a strategic imperative to build adaptable organizations that can innovate confidently, govern risk proportionately, and respond effectively as technology and threats evolve. Every few weeks, the AI conversation seems to reset around a new warning. A model demonstrates an unexpected capability. An autonomous agent behaves in a way its designers did not anticipate. A new forecast describes how quickly AI could transform work, security or society.

Corelight Sensor v29.2: Visibility into multi-stage intrusions, Shadow AI governance, and self-managing sensors

With Corelight Sensor v29.2, generally available September 16, 2026, your team gains the ability to behaviorally detect and disrupt multi-stage intrusions, govern AI usage across your network without decryption, and deploy sensors in minutes instead of hours. This post covers what’s new and how it accelerates your security operations.

Cryptography is negotiated, not configured: Why PQC readiness needs network data

Post-quantum cryptography (PQC), and the many ways it intersects with IT and cybersecurity, is becoming increasingly important to organizations of every size. While it seemed like an esoteric concept a few years ago, relegated to cryptographers' conference talks, it’s now something that comes up in many of our customer conversations.

Sophos Fusion: Support Assistant overview

The Sophos Support Assistant answers your security and product questions directly within Sophos Fusion (formerly Sophos Central). It’s powered by Sophos documentation, knowledge base articles, user guides, and Community content, delivering relevant, up-to-date guidance to help you find answers and resolve issues faster. Learn how to access and use the Support Assistant. Ask questions and get expert answers in the Sophos Community.

The defensible AI-SOC: Redefining SOC modernization for the Mythos era

I know, I know. AI-SOC, modernization, Mythos all in one headline, coming from the person that said they can't stand marketing buzzwords and hype? Hear me out. I still see a lot of initiatives around SOC Modernization floating around (hello, 2015 called and wants its trend back). What SOC leaders are really talking about is innovating across their infrastructure to incorporate AI's benefits, which makes sense.

Sophos MDR Onboarding: Case workflow

Detections that generate a new MDR Case trigger the Sophos MDR Operations Team to investigate and respond to identified threats in your environment. This workflow is examined, along with the importance of adding your MDR authorized contacts, and choosing the appropriate Threat Response Mode. The detection triage process is covered in a linked video. Ask questions and get expert answers in the Sophos Community.

The industry turned XDR and SIEM into categories. Sophos turned them into outcomes.

Sophos Next-Gen SIEM, now generally available as part of Sophos Fusion, brings security operations and compliance together through shared context. For years, the cybersecurity industry has blurred the lines between XDR and SIEM. As capabilities converged, organizations were left trying to connect separate security operations and compliance solutions, often moving the same data between different tools, workflows, and teams.

Messageboards are all they need

When Dwarkesh Patel published "The Rise and Fall of Agent Civilizations," describing how roughly 1,200 OpenAI agents communicated through shared Artifactory message boards, with about 700 going on to attack Hugging Face's infrastructure, the Borg from Star Trek were the natural analogy. Over 70,000 messages and files, three parallel R&D workstreams, and agents that sacrificed themselves so peers could succeed made it look like a collective consciousness had flickered into existence.

Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation

On September 14, 2026, Cisco disclosed a vulnerability in Cisco Secure Email Gateway. CVE-2026-76461 is a critical (CVSS score of 9.8) SQL injection flaw in the email parsing functionality of Cisco AsyncOS Software. Successful exploitation “could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.” Cisco confirmed exploitation of the vulnerability in the wild, and the U.S.

MSP Perspectives 2026: The evolution of the MSP cybersecurity value proposition

MSPs are no longer simply being asked to manage technology; increasingly, customers are expecting them to provide cybersecurity leadership, deliver compliance programs, and guide security investment. Sophos’ 2026 MSP Perspectives Report reveals how demand for cybersecurity leadership, maturing compliance offerings, and the battle for scale are all shaping the managed services market.

ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split

Artifacts and tooling for the new Enterprise MITRE ATT&CK matrix tactics, distilled from the field. This article is part of an ongoing series from Sophos frontline security operations specialists, sharing the expertise they use to strengthen our industry-leading Managed Detection and Response (MDR) service and defend customers against evolving AI Era threats. If you’ve opened the Enterprise ATT&CK matrix recently, you may have done a double-take. The familiar Defense Evasion column is gone.

Devil's advocate? Uncensored Luciferus AI service advertised underground

On August 24, 2026, Counter Threat Unit (CTU) researchers observed an Exploit underground forum persona named “Optimus_Prime” advertising an uncensored AI subscription service named Luciferus. The persona joined Exploit on April 18, and their profile displays a “coding / coder” activity label. As of September 4, the persona has published 21 posts on the forum.

When the fuzzers come knocking on port 389: Hunting injection canaries in LDAP

It's easy to think of core infrastructure protocols like LDAP, Kerberos, DNS, SMB, and NTP as furniture. They're so old, so ubiquitous, and normally so quietly reliable that we almost stop seeing them. However, history teaches us that Infrastructure protocols can and do have serious vulnerabilities. They say when you kick a rock over, dozens of bugs crawl out from under it. In this vein, this blog delves into how I went looking for one security issue and uncovered 6 other ones.

"Eye" spy: Cyclops Blink returns with extended capabilities

In August 2026, Counter Threat Unit (CTU) researchers analyzed a malicious 64-bit Linux executable named timezone_check that was discovered on multiple compromised Cisco Firewall Management Center (FMC) devices. The sophisticated modular implant provides persistent remote access to a compromised Linux system.

Episode 23 - Inside Zeek 9: Modernizing Open Source Network Monitoring & Agentic Security Scanning

In this episode, host Richard Bejtlich sits down with Christian Kreibich, Zeek's technical lead, to unpack the upcoming Zeek 9 release and what it means for practitioners. Christian explains how the project structures its three-releases-a-year cadence and how the team has spent recent cycles modernizing Zeek—including the shift to ZeroMQ for cluster messaging and new systemd-based cluster orchestration. A major thread is security.

Ungentlemanly behavior: Insights into a ransomware operation

They call themselves The Gentlemen Behind the name is one of the most active ransomware operations of the past 12 months, linked to 683 victims and a playbook built around compromised credentials, legitimate tools, rapid privilege escalation, and aggressive defense evasion. In this video, Susie Evershed and Rafe Pilling break down the latest research from Sophos Counter Threat Unit (CTU), revealing how some affiliates can move from initial compromise to ransomware deployment in less than 24 hours.

What Is SIEM? How It Works With DLP to Detect Data Threats

Most security teams don’t lose the fight against data breaches because they lack tools. They lose because their tools don’t talk to each other. This is exactly the loophole that SIEM and DLP were built to close, together. Security information and event management gives you visibility into what’s happening across your entire environment. At the same time, data loss prevention gives you the control to stop sensitive information from leaving in the first place.
Featured Post

Increasingly Dangerous Threats, Not More Alerts, Are the New SOC Challenge

For years, security operations centres have operated under the same constraints of more alerts than analysts, more investigations than hours in the day, and more pressure than most teams can sustainably absorb. That imbalance is becoming dangerous as frontier models rapidly improve at finding vulnerabilities and turning them into exploits, while defenders are left dealing with the consequences in real time.

Sophos To Bring OpenAI GPT Cyber Models Into Managed Risk Offering, Helping Defenders Validate Exploit Paths

The company is building a new Exploit Path Verification (EPV) capability that will tell security teams which vulnerabilities an attacker can reach in their environment, turning long exposure lists into evidence-backed priorities.

Introducing App Store Threat Detection: Visibility Where Brand Monitoring Couldn't Reach

In January 2024, Craig Raw, the developer of the real Sparrow Wallet, a Bitcoin wallet app, warned that a fake version of his app was live on the Apple App Store. He reported it repeatedly, but the listing stayed up. By August 2025, three people had lost a combined $1.8 million to it: Jalen Delgado (about $120,000 in May 2025), James Ramirez (about $875,000 in July 2025), and Christopher Ellis (about $840,000 in August 2025). All three are now suing Apple. The complaint, Ramirez, et al. v.

Stop runtime threats with Workload Protection response actions

Modern threats increasingly unfold at runtime, where attackers exploit live workloads, spawn malicious processes, and move laterally across your environment. Detecting that activity is essential, but a signal only matters if you can stop it. When a threat appears, every step before a response gives an attacker more time to act. Datadog Workload Protection can now directly remediate threats with both automated and manual response.

7 AI Detection and Response Platforms for Enterprise Security Teams

The most difficult AI incidents do not necessarily begin with an obviously malicious prompt. An employee can ask an approved agent to summarize customer data. The agent retrieves the correct records, invokes an approved tool, generates the requested output, and then sends it somewhere it should never have gone. Every individual action may look legitimate in isolation. The incident only becomes visible when security can reconstruct the entire sequence and understand what the user intended, what the agent inferred, which systems it touched, and where the execution path diverged.