ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split

2026-09-15T08:51:32Z•d02bf6d763e5a1ec0c9d8e8c5689b61f75ba4bce8fa14d8edef4c252d07a1607
CVE-2026-83548CVE-2026-83549Cisco Firewall Management CenterCyclops BlinkDFIRGOLD SHERWOODMITRE ATT&CKPHP web-server rootkitSonicWall SMA1000active exploitationcybercrime AIransomwarethreat intelligence

What happened

Sophos RSS entries cover emerging and active cybersecurity threats, including Cyclops Blink activity targeting Cisco Firewall Management Center devices, a PHP web-server rootkit, ransomware tradecraft associated with GOLD SHERWOOD affiliates, underground criminal AI services, and active exploitation of two SonicWall SMA1000 vulnerabilities (CVE-2026-83548 and CVE-2026-83549). The collection also includes defensive guidance, ransomware sector research, and MITRE ATT&CK updates.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
d02bf6d763e5a1ec0c9d8e8c5689b61f75ba4bce8fa14d8edef4c252d07a1607
Enrichment time
2026-09-15T08:51:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.