RSS
Sophos Insights
LLM
AI
Exploit
vulnerability
Active Adversary
Pacific Rim
The vulnerability flood is here. Here’s what it means – and how to prepare
We can't control the pace of AI-driven vulnerability discovery, but we can control how fast we respond.
Threat Research
advisory
Adobe Reader
Adobe Reader zero-day vulnerability in active exploitation
Oracle
Oracle vulnerability (CVE-2026-21992) impacts core products
SD-WAN
Cisco SD-WAN vulnerabilities (CVE-2026-20127, CVE-2022-20775) in active exploitation
Microsoft Office
Microsoft Office vulnerability (CVE-2026-21509) in active exploitation
Featured
react2shell
React2Shell flaw (CVE-2025-55182) exploited for remote code execution
Windows Server Update Services
WSUS
Windows Server Update Services (WSUS) vulnerability abused to harvest sensitive data
Naked Security
Patch Tuesday
Zero-day
Microsoft Patch Tuesday: 74 CVEs plus 2 “Exploit Detected” advisories
Firefox
security fix
Firefox fixes a flurry of flaws in the first of two releases this month
Apple
triangulation
Apple ships that recent “Rapid Response” spyware patch to everyone, fixes a second zero-day