Sophos X-Ops (incl. former Secureworks CTU)
sophos-xops · B · active
https://www.sophos.com/en-us/blog
Sophos cross-team threat research. Sophos acquired Secureworks in 2025 → former Secureworks CTU research now publishes here (the legacy `secureworks-ctu` source ID was removed 2026-05-08 to avoid duplication). The sophos.com domain occasionally serves a 503 to non-browser TLS fingerprints; if WebFetch fails, retry once before falling back to https://news.sophos.com/en-us/category/x-ops/ . (v2.55: rss_url verified, use `python3 tools/fetch_source.py feed https://www.sophos.com/en-us/blog/feed?id=blt6f15f4f7deaf4242 [N]`) | 2026-06-01: feed silent / prior 503 (rotation-priority unrecovered) | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → rss: python3 tools/fetch_source.py feed https://www.sophos.com/en-us/blog/feed?id=blt6f15f4f7deaf4242 5, clean dated entries; then WebFetch per-article /en-us/blog/{slug} for body.. AVOID: Don't WebFetch the sophos.com root first; it has 503'd on non-browser TLS fingerprints. The documented feed is the reliable entry; it has recovered from the 2026-06-01 silent/503 state noted in sources.json.. | 2026-07-05 admiralty audit: B, original vendor threat-research lab with first-hand telemetry; feed recovered and clean. Keep active.
Cited in 8 entries
Citation cadence
Citation days per ISO week (15 weeks of coverage span, total 7).
- Interlock ran Volatility3 and WinPmem against a live endpoint to harvest credentials, the responder's own memory-forensics toolkit used in place of a commodity dumper2026-08-10
- CVE-2026-18556 / CVE-2026-18577, N-able N-central: unauthenticated admin access to the RMM console, exploited in the wild, and the day-one fix was itself bypassable2026-08-03
- STAC4749 runs Teams helpdesk vishing from attacker-owned .top domains into certificate-pinned Golang implants and Chaos ransomware in under 17 hours2026-07-29
- CitrixBleed 2 (CVE-2025-5777) weaponised into a repeatable IAB kill chain ending in DragonForce ransomware (STAC3725)2026-07-10
- Sophos X-Ops: underground AI adoption is cautious but concrete, LLM-assisted packers, LLM C2 orchestration, NLP-triaged leak markets2026-06-19
- Sophos finds an attacker-built, AI-orchestrated EDR-evasion testing lab during incident response2026-06-03
- Sophos 2026 Active Adversary Report: identity is the dominant intrusion root cause2026-06-03
- Sophos: "Beagle" backdoor distributed via fake Claude AI site using DonutLoader + DLL sideloading on a signed G DATA AV updater2026-05-10