Sophos X-Ops (incl. former Secureworks CTU)
sophos-xops · B · active
https://www.sophos.com/en-us/blog
Sophos cross-team threat research. Sophos acquired Secureworks in 2025 → former Secureworks CTU research now publishes here (the legacy `secureworks-ctu` source ID was removed 2026-05-08 to avoid duplication). The sophos.com domain occasionally serves a 503 to non-browser TLS fingerprints; if WebFetch fails, retry once before falling back to https://news.sophos.com/en-us/category/x-ops/ . (v2.55: rss_url verified — use `python3 tools/fetch_source.py feed https://www.sophos.com/en-us/blog/feed?id=blt6f15f4f7deaf4242 [N]`) | 2026-06-01: feed silent / prior 503 (rotation-priority unrecovered) | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → rss: python3 tools/fetch_source.py feed https://www.sophos.com/en-us/blog/feed?id=blt6f15f4f7deaf4242 5 — clean dated entries; then WebFetch per-article /en-us/blog/{slug} for body.. AVOID: Don't WebFetch the sophos.com root first — it has 503'd on non-browser TLS fingerprints. The documented feed is the reliable entry; it has recovered from the 2026-06-01 silent/503 state noted in sources.json.. | 2026-07-05 admiralty audit: B — original vendor threat-research lab with first-hand telemetry; feed recovered and clean. Keep active.
Cited in 10 entries
Citation cadence
Citation days per ISO week (14 weeks of coverage span, total 8).
- N-able N-central post-exploitation, unpacked: six remote-access tools pushed to managed endpoints, a Cloudflare tunnel renamed as a Microsoft updater, and an EDR-evasion driver staged from a remote-support directory2026-08-05
- STAC4749 runs Teams helpdesk vishing from attacker-owned .top domains into certificate-pinned Golang implants and Chaos ransomware in under 17 hours2026-07-29
- CitrixBleed 2 (CVE-2025-5777) weaponised into a repeatable IAB kill chain ending in DragonForce ransomware (STAC3725)2026-07-10
- Sophos X-Ops: underground AI adoption is cautious but concrete — LLM-assisted packers, LLM C2 orchestration, NLP-triaged leak markets2026-06-19
- Sophos finds an attacker-built, AI-orchestrated EDR-evasion testing lab during incident response2026-06-03
- Sophos 2026 Active Adversary Report: identity is the dominant intrusion root cause2026-06-03
- Sophos 2026 Active Adversary Report — identity the dominant intrusion root cause; Impacket and AnyDesk most-observed post-exploitation2026-06-01
- Sophos 2026 State of Identity Security — 71% of orgs breached via identity, 41% root-caused to non-human-identity mismanagement, Switzerland records highest incidence2026-05-11
- Public administration and government2026-05-11
- Sophos: "Beagle" backdoor distributed via fake Claude AI site using DonutLoader + DLL sideloading on a signed G DATA AV updater2026-05-10