ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split

2026-09-14T20:51:31Z•9b5bc0ba689ae1f0eb0cf168125bf9e8d5f74d87bf2510a60d917525f08424f7
CVE-2026-83548CVE-2026-83549AI-enabled cybercrimeCisco FMCCyclops BlinkDFIRGOLD SHERWOODLuciferusMITRE ATT&CKPHP web shellSonicWall SMA1000Sophosactive exploitationdefense impairmenteducation sectorransomwarethreat intelligenceweb server rootkit

What happened

Sophos news feed covering emerging cyber threats and defensive research, including a newly described MITRE ATT&CK tactic split, underground uncensored AI services, Cyclops Blink malware targeting Cisco FMC devices, a PHP web-server rootkit, active exploitation of SonicWall SMA1000 vulnerabilities, and ransomware tradecraft associated with GOLD SHERWOOD. The most urgent item is active exploitation of CVE-2026-83548 and CVE-2026-83549.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
9b5bc0ba689ae1f0eb0cf168125bf9e8d5f74d87bf2510a60d917525f08424f7
Enrichment time
2026-09-14T20:51:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.