logo

Secure by Design in practice: a year of progress on Sophos Firewall

ID: a60488d4-6b9f-5964-8558-f0ad3891800f

STIX ID: report--a60488d4-6b9f-5964-8558-f0ad3891800f

Feed Name: Sophos Blogs

Threat Score
65/100

Date Published: 2026-07-29

Date Updated: 2026-07-30

...
...

In response to the FortiBleed credential dump and related brute-force/stuffing activity against edge devices, Sophos details its firewall hardening and detections (v22 architectural changes, Sophos Linux Sensor, traceable telemetry, hotfix visibility, scheduled updates), fixes to MFA onboarding to mitigate trust-on-first-use enrollment, and investments in telemetry and fleet forensics to enable rapid characterization of future campaigns. The company reports no evidence of exploitation of Sophos devices in this campaign, describes an internal AI-enabled vulnerability-hunting platform, maps progress to NCSC forensic guidance, and commits to delivering remote forensic capture and expanded attack-facing telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.