Roger Neal
rogredhat.bsky.social
Roger Neal
@rogredhat.bsky.social
Thoughts & posts are my own. GRRC Member, Didcot Town Football Club Trustee, Photographer & Technology Manager at Sophos.
Game of clones: Sophos and the MITRE ATT&CK Enterprise 2025 Evaluations news.sophos.com/en-us/2025/1...
Game of clones: Sophos and the MITRE ATT&CK Enterprise 2025 Evaluations
Winter is coming – so it must be time for Sophos X-Ops’ report on this year’s MITRE ATT&CK Enterprise Evaluations
news.sophos.com
December 16, 2025 at 5:24 PM
Sophos XDR delivers 100% detection coverage in the latest MITRE ATT&CK® Evaluations for Enterprise EDR and XDR Solutions. These evaluations are among the world’s most rigorous assessing how EDR & XDR products, detect & report the complex tactics of advanced threats

news.sophos.com/en-us/2025/1...
Sophos achieves its best-ever results in the MITRE ATT&CK Enterprise 2025 Evaluation
A major milestone: Sophos XDR delivers 100% detection coverage in the latest ATT&CK Evaluation.
news.sophos.com
December 10, 2025 at 8:41 PM
Another vulnerability in a firewall and VPN. Patch and Patch fast! www.techradar.com/pro/security...
SonicWall tells customers to patch SonicOS flaw allowing hackers to crash firewalls
A high-severity flaw was found in SonicWall OS SSLVPN
www.techradar.com
November 21, 2025 at 8:59 PM
@sophossecurity.bsky.social Sophos MDR has achieved Microsoft Verified: SMB Solution status through the Microsoft Intelligent Security Association (MISA)!

Cyberattacks don’t discriminate by size. But protection hasn’t always been equal.

Read more: bit.ly/4oM0x7N
Sophos Recognized with Microsoft Verified Small and Medium Business (SMB) Solution Status
Sophos achieves Microsoft Verified SMB Solution status, integrating Sophos MDR with Microsoft Defender for Business and Defender for Endpoint.
bit.ly
November 18, 2025 at 8:08 PM
Announcing the latest evolution of our Security Operations portfolio news.sophos.com/en-us/2025/1...
Announcing the latest evolution of our Security Operations portfolio
New innovations in identity protection, expanded security services, and advancements in AI, and threat detection and response to strengthen cybersecurity outcomes
news.sophos.com
October 21, 2025 at 12:44 PM
Getting salty with LLMs: SophosAI unveils new defense against jailbreaking at CAMLIS 2025 news.sophos.com/en-us/2025/1...
Getting salty with LLMs: SophosAI unveils new defense against jailbreaking at CAMLIS 2025
On October 22-24, SophosAI will present research on ‘LLM salting’ (a novel countermeasure against jailbreaks) and command line classification at CAMLIS 2025
news.sophos.com
October 21, 2025 at 10:29 AM
Patch your CISCO kit ASAP
Urgent: Cisco warns of active exploitation of critical zero-day vulnerabilities in ASA and FTD software. Immediate patching required to prevent potential system compromise. #CyberSecurity #CiscoVulnerability #ZeroDay Link: thedailytechfeed.com/critical-zer...
September 26, 2025 at 4:49 PM
Reposted by Roger Neal
Ransomware Groups Still Exploiting SonicWall Firewall Vulnerability Despite Patch #AkiraRansomware #CVE202440766 #SonicOS730
Ransomware Groups Still Exploiting SonicWall Firewall Vulnerability Despite Patch
  More than a year after SonicWall released a patch for CVE-2024-40766, a critical vulnerability affecting its next-generation firewalls, attackers linked to the Akira ransomware-as-a-service operation continue to exploit the flaw to breach organizations. Similar to incidents in September 2024 and earlier this year, affiliates of the Akira group are behind the latest wave of attacks. The spike observed in July 2025 was partly due to organizations upgrading from Gen 6 to Gen 7 SonicWall firewalls without resetting local user passwords as recommended by SonicWall. Attackers have also expanded their techniques. According to Rapid7’s Incident Response team, there has been “an uptick in intrusions involving SonicWall appliances” since early August 2025. Their findings indicate that the Akira group may be chaining together three different security weaknesses to gain access and deploy ransomware. CVE-2024-40766, which remains unpatched in some environments. A misconfiguration in the SSLVPN Default Users Group setting. SonicWall explains: “This setting automatically adds every successfully authenticated LDAP user to a predefined local group, regardless of their actual membership in Active Directory. If that default group has access to sensitive services – such as SSL VPN, administrative interfaces, or unrestricted network zones – then any compromised AD account, even one with no legitimate need for those services, will instantly inherit those permissions.”“This effectively bypasses intended AD group-based access controls, giving attackers a direct path into the network perimeter as soon as they obtain valid credentials.” Abuse of the Virtual Office Portal feature in SonicWall appliances, which attackers are using to configure MFA/TOTP on already compromised accounts. The Australian Cyber Security Centre (ACSC) has also issued warnings about increased Akira activity targeting Australian entities via CVE-2024-40766. According to Rapid7, the attackers’ method remains consistent: they gain entry through the SSLVPN component, escalate privileges to elevated or service accounts, exfiltrate sensitive data from file servers and network shares, disable or delete backups, and finally execute ransomware at the hypervisor layer. Recommended Mitigations Organizations relying on SonicWall firewalls are advised to: * Rotate passwords on all SonicWall local accounts and delete unused ones. * Enforce MFA/TOTP for SSLVPN services. * Set the Default LDAP User Group to “None.” * Restrict Virtual Office Portal access to trusted local networks and closely monitor usage. * Ensure all appliances run the latest firmware updates. SonicWall recently highlighted that SonicOS 7.3.0 introduces additional protections against brute-force attacks and enhanced MFA controls, providing stronger defense against ransomware intrusions.
dlvr.it
September 14, 2025 at 6:11 PM
Just chilling
September 10, 2025 at 8:31 AM
@sophossecurity.bsky.social has won all 6 security categories that it was nominated for in the 2025 CRN Annual Report Card Awards.

Sophos recognized as industry-best in 6 security categories: Managed Detection & Response (MDR), Endpoint Security, Network Security, Data Security & Cloud Security.
August 22, 2025 at 9:33 AM
Reposted by Roger Neal
With @sophossecurity.bsky.social Sophos Firewall & Taegis MDR or XDR, analysts can trigger an automated response. A key benefit of the Sophos platform: enabling information and telemetry sharing between products to facilitate an automated response to active attacks. news.sophos.com/en-us/2025/0...
Taegis MDR/XDR now work with Sophos Firewall’s Active Threat Response
Response times go from hours or days to seconds.
news.sophos.com
August 20, 2025 at 3:33 PM
With @sophossecurity.bsky.social Sophos Firewall & Taegis MDR or XDR, analysts can trigger an automated response. A key benefit of the Sophos platform: enabling information and telemetry sharing between products to facilitate an automated response to active attacks. news.sophos.com/en-us/2025/0...
Taegis MDR/XDR now work with Sophos Firewall’s Active Threat Response
Response times go from hours or days to seconds.
news.sophos.com
August 20, 2025 at 3:33 PM
Reposted by Roger Neal
Cisco Security Under Siege: Critical Vulnerabilities Expose Firewalls, Routers, and Identity Systems to Code Execution Threats

Rising Cybersecurity Alarm for Cisco Users Cisco, a global leader in networking and security solutions, is grappling with multiple high-risk vulnerabilities across its…
Cisco Security Under Siege: Critical Vulnerabilities Expose Firewalls, Routers, and Identity Systems to Code Execution Threats
Rising Cybersecurity Alarm for Cisco Users Cisco, a global leader in networking and security solutions, is grappling with multiple high-risk vulnerabilities across its flagship products that could enable attackers to execute arbitrary code remotely. These flaws impact critical platforms such as Cisco Secure Firewall Management Center (FMC), Firepower 2100 Series, ASA and FTD software, Identity Services Engine (ISE), and both IOS and IOS XE network operating systems.
undercodenews.com
August 15, 2025 at 6:49 AM
Reposted by Roger Neal
🟡 Heavy metal star Ozzy Osbourne has died, just weeks after reuniting with his Black Sabbath bandmates and performing a huge farewell concert for fans.⁠

In a statement, his family said he died "surrounded by love".⁠

news.sky.com/story/ozzy-o...
Ozzy Osbourne dies just weeks after farewell show
The heavy metal star reunited with his Black Sabbath bandmates on stage at Villa Park earlier in July.
news.sky.com
July 22, 2025 at 6:16 PM
Reposted by Roger Neal
SharePoint ‘ToolShell’ vulnerabilities being exploited in the wild news.sophos.com/en-us/2025/0... Customers running on-premises SharePoint instances are advised to apply the official patches from Microsoft ASAP & follow the recommendations for mitigation or turn offline until they can be patched.
SharePoint ‘ToolShell’ vulnerabilities being exploited in the wild
Sophos X-Ops sees exploitation across multiple customer estates
news.sophos.com
July 21, 2025 at 3:22 PM
SharePoint ‘ToolShell’ vulnerabilities being exploited in the wild news.sophos.com/en-us/2025/0... Customers running on-premises SharePoint instances are advised to apply the official patches from Microsoft ASAP & follow the recommendations for mitigation or turn offline until they can be patched.
SharePoint ‘ToolShell’ vulnerabilities being exploited in the wild
Sophos X-Ops sees exploitation across multiple customer estates
news.sophos.com
July 21, 2025 at 3:22 PM
Sunset at Chichester harbour
July 10, 2025 at 8:46 PM
So @beenetworkgm.bsky.social what’s going on with the teams to/from Altrincham? Timetable seems to have gone to pot with double trams disappearing or suddenly delayed? The sardines are getting very fed up with singles during busy times..
July 7, 2025 at 9:10 PM
Reposted by Roger Neal
Microsoft's June 2025 Patch Tuesday brings critical security fixes for Windows 11 (KB5060842 & KB5060999), patching 66 vulnerabilities including an exploited zero-day. Enterprises should prioritize updating, especially for DirectAccess fixes. Details: Read More
June 10, 2025 at 5:53 PM
Come on you Spurs #COYS @tottenhamhotspur.com
May 21, 2025 at 6:46 PM
Hurry up Human and empty the shopping I’m hungry…
May 17, 2025 at 5:31 PM
Reposted by Roger Neal
🚨 New CISA Vulnerability Alert 🚨

CRITICAL: Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

CVE-2025-32756

Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability - CyberAlerts
View detailed information about CVE-2025-32756 on CyberAlerts
cyberalerts.io
May 14, 2025 at 5:30 PM