ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split
2026-09-15T08:51:32Z•d02bf6d763e5a1ec0c9d8e8c5689b61f75ba4bce8fa14d8edef4c252d07a1607
CVE-2026-83548CVE-2026-83549Cisco Firewall Management CenterCyclops BlinkDFIRGOLD SHERWOODMITRE ATT&CKPHP web-server rootkitSonicWall SMA1000active exploitationcybercrime AIransomwarethreat intelligence
What happened
Sophos RSS entries cover emerging and active cybersecurity threats, including Cyclops Blink activity targeting Cisco Firewall Management Center devices, a PHP web-server rootkit, ransomware tradecraft associated with GOLD SHERWOOD affiliates, underground criminal AI services, and active exploitation of two SonicWall SMA1000 vulnerabilities (CVE-2026-83548 and CVE-2026-83549). The collection also includes defensive guidance, ransomware sector research, and MITRE ATT&CK updates.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- d02bf6d763e5a1ec0c9d8e8c5689b61f75ba4bce8fa14d8edef4c252d07a1607
- Enrichment time
- 2026-09-15T08:51:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.