Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split

Artifacts and tooling for the new Enterprise MITRE ATT&CK matrix tactics, distilled from the field. This article is part of an ongoing series from Sophos frontline security operations specialists, sharing the expertise they use to strengthen our industry-leading Managed Detection and Response (MDR) service and defend customers against evolving AI Era threats. If you’ve opened the Enterprise ATT&CK matrix recently, you may have done a double-take. The familiar Defense Evasion column is gone.

Devil's advocate? Uncensored Luciferus AI service advertised underground

On August 24, 2026, Counter Threat Unit (CTU) researchers observed an Exploit underground forum persona named “Optimus_Prime” advertising an uncensored AI subscription service named Luciferus. The persona joined Exploit on April 18, and their profile displays a “coding / coder” activity label. As of September 4, the persona has published 21 posts on the forum.

Cybersecurity is Getting Faster at the Wrong Thing

Reaction remains cybersecurity’s default posture. Rather than question that approach, the industry has focused on making it faster. The instinct is understandable. Cybersecurity has always been about understanding threats. What has changed is their sheer scale, and the growing gap between what organisations can see and what they can realistically act on. Somewhere along the way, we started calling faster detection, richer analysis and AI-powered response proactive security.

CVE-2026-84869: ConnectWise ScreenConnect Client Vulnerability Critical Remote Session File Transfer Exploitation Risk

A critical security weakness (CVE-2026-84869) has been identified in the ConnectWise ScreenConnect client (prior to version 26.6.5), where missing authorization controls and improper privilege management allow file transfers and execution through active remote sessions without host confirmation.

The EU Cyber Resilience Act Has Global Implications - Who Needs to Prepare and How?

The European Union has made great strides to enhance cybersecurity over the past few years, with a comprehensive framework of core legislative acts designed to protect critical infrastructure. The EU Cyber Resilience Act, originally published as Regulation (EU) 2024/2847 on 20 November 2024, and entered into force on 10 December 2024, shifts the burden of proof so that manufacturers must now show their software is secure, not just claim it.

Keeper Security Named a Leader in the 2026 GigaOm Radar Report for Enterprise Password Management

GigaOm has recognized Keeper Security in the Enduring Innovators quadrant of its 2026 Radar Report for Enterprise Password Management. This marks the fifth consecutive year that Keeper has been named a Leader in GigaOm’s evaluation of the enterprise password management market. The report recognizes Keeper’s continued innovation, architectural depth and ability to help organizations secure more than just passwords.

Australian Privacy Principles: A compliance guide for small businesses

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Noodle RAT: A Recipe for Cross Platform Espionage

Noodle RAT—also known as ANGRYREBEL or Nood RAT—is a modular remote access trojan (RAT) with dual versions for Windows and Linux, actively used by Chinese-speaking threat actors since at least mid-2016. It was previously misclassified as variants of Gh0st RAT or Rekoobe but is now recognized as a unique backdoor family.

Introducing Guardian Agents: Meet Blue Agent, Your AI Security Analyst

AI agents are moving into production faster than security teams can govern them. And unlike traditional applications, agents continuously make decisions, invoke tools, access data, and take actions. Every one of those interactions creates security context that needs to be understood. At enterprise scale, asking analysts to manually evaluate every finding becomes impossible.