Sophos

Microsoft Patches 63 Vulnerabilities in November Patch Tuesday Including Critical RCE and Privilege Escalation Flaws

Microsoft’s November Patch Tuesday addresses 63 vulnerabilities across 13 product families, including: Windows (38) Office (12), 365 (11), Excel (7), Visual Studio (4) Dynamics 365 (3), Azure (1), Configuration Manager (1) and more.

Locking it down: A new technique to prevent LLM jailbreaks

A new technique called LLM salting has been introduced to counteract jailbreak attacks on LLMs such as LLaMA-2-7B and Vicuna-7B. These attacks exploit the reuse of precomputed adversarial prompts across similar model deployments.
September 18, 2025

GOLD SALEM’s Warlock operation joins busy ransomware landscape

GOLD SALEM, also known as the Warlock Group, is an emerging ransomware threat actor active since March. The group has targeted a wide range of organizations across North America, Europe, and South America, deploying its Warlock ransomware.

Velociraptor incident response tool abused for remote access

Threat actors have been observed abusing the legitimate Velociraptor digital forensics and incident response (DFIR) tool to establish remote access and execute further malicious payloads.

Shared secret: EDR killer in the kill chain

A new wave of sophisticated EDR killer tools, often packed with HeartCrypt, is being deployed by multiple ransomware groups to disable endpoint defenses and facilitate ransomware execution.
July 29, 2025

GOLD BLADE Remote DLL Sideloading Attack Deploys RedLoader

A new campaign by the GOLD BLADE threat group leverages remote DLL sideloading technique to deploy RedLoader malware. This attack chain combines malicious LNK files and WebDAV-based delivery mechanisms to evade detection and establish persistence.

DragonForce actors target SimpleHelp vulnerabilities to attack MSP, customers

A recent targeted ransomware attack leveraged vulnerabilities in SimpleHelp remote monitoring and management (RMM) software to compromise a Managed Service Provider (MSP) and its clients.

A familiar playbook with a twist: 3AM ransomware actors dropped virtual machine with vishing and Quick Assist

This campaign, observed between November 2024 and January 2025, involved over 55 attempted attacks and at least 15 confirmed incidents. Initial access was achieved through email bombing and vishing, exploiting Microsoft Quick Assist.

Finding Minhook in a sideloading attack – and Sweden too

A sideloading campaign active from late 2023 to early 2024 targeted organisations in East Asia and later Sweden, delivering Cobalt Strike payloads via legitimate Windows executables and malicious DLLs.

Qilin affiliates spear-phish MSP ScreenConnect admin, targeting customers downstream

In January 2025, a phishing email targeting an MSP administrator led to a ransomware attack, with the Qilin ransomware group gaining access to the administrator's credentials and attacking the MSP's customers.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags