RSS
Threat Research
Ransomware
cybercrime
state-sponsored ransomware
victimization
Eeny, meeny, miny, moe? How ransomware operators choose victims
clickfix
Featured
GOLD FEATHER
human verification
infostealer
qilin
StealC
I am not a robot: ClickFix used to deploy StealC and Qilin
virtual machine
ISPs
Malicious use of virtual machine infrastructure
Microsoft Office
vulnerability
advisory
Microsoft Office vulnerability (CVE-2026-21509) in active exploitation
TamperedChef
EvilAI
Sophos X-Ops
TamperedChef serves bad ads, with infostealers as the main course
ATT&CK
Emulation
MITRE
MUSTANG PANDA
scattered spider
Game of clones: Sophos and The MITRE ATT&CK Enterprise 2025 Evaluations
Security Operations
active adversary
Active Adversary Report
Compromised Credentials
detection
dwell time
featured
impact
incident response
LOLBIN
MFA
Monitoring
RDP
Remote Ransomware
root cause
It takes two: The 2025 Sophos Active Adversary Report
election
Email
fraud
Phishing
Spam
Telegram
Phishing, BEC attackers target candidates in local election, among others