Roger Neal
rogredhat.bsky.social
Roger Neal
@rogredhat.bsky.social
Thoughts & posts are my own. GRRC Member, Didcot Town Football Club Trustee, Photographer & Technology Manager at Sophos.
Announcing the latest evolution of our Security Operations portfolio news.sophos.com/en-us/2025/1...
Announcing the latest evolution of our Security Operations portfolio
New innovations in identity protection, expanded security services, and advancements in AI, and threat detection and response to strengthen cybersecurity outcomes
news.sophos.com
October 21, 2025 at 12:44 PM
Getting salty with LLMs: SophosAI unveils new defense against jailbreaking at CAMLIS 2025 news.sophos.com/en-us/2025/1...
Getting salty with LLMs: SophosAI unveils new defense against jailbreaking at CAMLIS 2025
On October 22-24, SophosAI will present research on ‘LLM salting’ (a novel countermeasure against jailbreaks) and command line classification at CAMLIS 2025
news.sophos.com
October 21, 2025 at 10:29 AM
Patch your CISCO kit ASAP
Urgent: Cisco warns of active exploitation of critical zero-day vulnerabilities in ASA and FTD software. Immediate patching required to prevent potential system compromise. #CyberSecurity #CiscoVulnerability #ZeroDay Link: thedailytechfeed.com/critical-zer...
September 26, 2025 at 4:49 PM
Reposted by Roger Neal
Ransomware Groups Still Exploiting SonicWall Firewall Vulnerability Despite Patch #AkiraRansomware #CVE202440766 #SonicOS730
Ransomware Groups Still Exploiting SonicWall Firewall Vulnerability Despite Patch
  More than a year after SonicWall released a patch for CVE-2024-40766, a critical vulnerability affecting its next-generation firewalls, attackers linked to the Akira ransomware-as-a-service operation continue to exploit the flaw to breach organizations. Similar to incidents in September 2024 and earlier this year, affiliates of the Akira group are behind the latest wave of attacks. The spike observed in July 2025 was partly due to organizations upgrading from Gen 6 to Gen 7 SonicWall firewalls without resetting local user passwords as recommended by SonicWall. Attackers have also expanded their techniques. According to Rapid7’s Incident Response team, there has been “an uptick in intrusions involving SonicWall appliances” since early August 2025. Their findings indicate that the Akira group may be chaining together three different security weaknesses to gain access and deploy ransomware. CVE-2024-40766, which remains unpatched in some environments. A misconfiguration in the SSLVPN Default Users Group setting. SonicWall explains: “This setting automatically adds every successfully authenticated LDAP user to a predefined local group, regardless of their actual membership in Active Directory. If that default group has access to sensitive services – such as SSL VPN, administrative interfaces, or unrestricted network zones – then any compromised AD account, even one with no legitimate need for those services, will instantly inherit those permissions.”“This effectively bypasses intended AD group-based access controls, giving attackers a direct path into the network perimeter as soon as they obtain valid credentials.” Abuse of the Virtual Office Portal feature in SonicWall appliances, which attackers are using to configure MFA/TOTP on already compromised accounts. The Australian Cyber Security Centre (ACSC) has also issued warnings about increased Akira activity targeting Australian entities via CVE-2024-40766. According to Rapid7, the attackers’ method remains consistent: they gain entry through the SSLVPN component, escalate privileges to elevated or service accounts, exfiltrate sensitive data from file servers and network shares, disable or delete backups, and finally execute ransomware at the hypervisor layer. Recommended Mitigations Organizations relying on SonicWall firewalls are advised to: * Rotate passwords on all SonicWall local accounts and delete unused ones. * Enforce MFA/TOTP for SSLVPN services. * Set the Default LDAP User Group to “None.” * Restrict Virtual Office Portal access to trusted local networks and closely monitor usage. * Ensure all appliances run the latest firmware updates. SonicWall recently highlighted that SonicOS 7.3.0 introduces additional protections against brute-force attacks and enhanced MFA controls, providing stronger defense against ransomware intrusions.
dlvr.it
September 14, 2025 at 6:11 PM
Just chilling
September 10, 2025 at 8:31 AM
@sophossecurity.bsky.social has won all 6 security categories that it was nominated for in the 2025 CRN Annual Report Card Awards.

Sophos recognized as industry-best in 6 security categories: Managed Detection & Response (MDR), Endpoint Security, Network Security, Data Security & Cloud Security.
August 22, 2025 at 9:33 AM
Reposted by Roger Neal
With @sophossecurity.bsky.social Sophos Firewall & Taegis MDR or XDR, analysts can trigger an automated response. A key benefit of the Sophos platform: enabling information and telemetry sharing between products to facilitate an automated response to active attacks. news.sophos.com/en-us/2025/0...
Taegis MDR/XDR now work with Sophos Firewall’s Active Threat Response
Response times go from hours or days to seconds.
news.sophos.com
August 20, 2025 at 3:33 PM
With @sophossecurity.bsky.social Sophos Firewall & Taegis MDR or XDR, analysts can trigger an automated response. A key benefit of the Sophos platform: enabling information and telemetry sharing between products to facilitate an automated response to active attacks. news.sophos.com/en-us/2025/0...
Taegis MDR/XDR now work with Sophos Firewall’s Active Threat Response
Response times go from hours or days to seconds.
news.sophos.com
August 20, 2025 at 3:33 PM
Reposted by Roger Neal
Cisco Security Under Siege: Critical Vulnerabilities Expose Firewalls, Routers, and Identity Systems to Code Execution Threats

Rising Cybersecurity Alarm for Cisco Users Cisco, a global leader in networking and security solutions, is grappling with multiple high-risk vulnerabilities across its…
Cisco Security Under Siege: Critical Vulnerabilities Expose Firewalls, Routers, and Identity Systems to Code Execution Threats
Rising Cybersecurity Alarm for Cisco Users Cisco, a global leader in networking and security solutions, is grappling with multiple high-risk vulnerabilities across its flagship products that could enable attackers to execute arbitrary code remotely. These flaws impact critical platforms such as Cisco Secure Firewall Management Center (FMC), Firepower 2100 Series, ASA and FTD software, Identity Services Engine (ISE), and both IOS and IOS XE network operating systems.
undercodenews.com
August 15, 2025 at 6:49 AM
Reposted by Roger Neal
🟡 Heavy metal star Ozzy Osbourne has died, just weeks after reuniting with his Black Sabbath bandmates and performing a huge farewell concert for fans.⁠

In a statement, his family said he died "surrounded by love".⁠

news.sky.com/story/ozzy-o...
Ozzy Osbourne dies just weeks after farewell show
The heavy metal star reunited with his Black Sabbath bandmates on stage at Villa Park earlier in July.
news.sky.com
July 22, 2025 at 6:16 PM
Reposted by Roger Neal
SharePoint ‘ToolShell’ vulnerabilities being exploited in the wild news.sophos.com/en-us/2025/0... Customers running on-premises SharePoint instances are advised to apply the official patches from Microsoft ASAP & follow the recommendations for mitigation or turn offline until they can be patched.
SharePoint ‘ToolShell’ vulnerabilities being exploited in the wild
Sophos X-Ops sees exploitation across multiple customer estates
news.sophos.com
July 21, 2025 at 3:22 PM
SharePoint ‘ToolShell’ vulnerabilities being exploited in the wild news.sophos.com/en-us/2025/0... Customers running on-premises SharePoint instances are advised to apply the official patches from Microsoft ASAP & follow the recommendations for mitigation or turn offline until they can be patched.
SharePoint ‘ToolShell’ vulnerabilities being exploited in the wild
Sophos X-Ops sees exploitation across multiple customer estates
news.sophos.com
July 21, 2025 at 3:22 PM
Sunset at Chichester harbour
July 10, 2025 at 8:46 PM
So @beenetworkgm.bsky.social what’s going on with the teams to/from Altrincham? Timetable seems to have gone to pot with double trams disappearing or suddenly delayed? The sardines are getting very fed up with singles during busy times..
July 7, 2025 at 9:10 PM
Reposted by Roger Neal
Microsoft's June 2025 Patch Tuesday brings critical security fixes for Windows 11 (KB5060842 & KB5060999), patching 66 vulnerabilities including an exploited zero-day. Enterprises should prioritize updating, especially for DirectAccess fixes. Details: Read More
June 10, 2025 at 5:53 PM
Come on you Spurs #COYS @tottenhamhotspur.com
May 21, 2025 at 6:46 PM
Hurry up Human and empty the shopping I’m hungry…
May 17, 2025 at 5:31 PM
Reposted by Roger Neal
🚨 New CISA Vulnerability Alert 🚨

CRITICAL: Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

CVE-2025-32756

Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability - CyberAlerts
View detailed information about CVE-2025-32756 on CyberAlerts
cyberalerts.io
May 14, 2025 at 5:30 PM
Reposted by Roger Neal
~Sophos~
Microsoft released 71 patches for May Patch Tuesday, including 6 critical & 5 actively exploited vulns.
-
IOCs: CVE-2025-30397, CVE-2025-32701, CVE-2025-32706
-
#Microsoft #PatchTuesday #ThreatIntel #Vulnerabilities
Microsoft primes 71 fixes for May Patch Tuesday
news.sophos.com
May 14, 2025 at 5:36 PM
Woke up to a lovely M&S email saying we’ve lost customer data.. but it’s not been shared. Lovely to know they can 100% trust the threat actors not to sell it on. Seriously..

www.bleepingcomputer.com/news/securit...
M&S says customer data stolen in cyberattack, forces password resets
Marks and Spencer (M&S) confirms that customer data was stolen in a cyberattack last month, when ransomware was used to encrypt servers.
www.bleepingcomputer.com
May 14, 2025 at 5:20 AM
Yet another dose of Microsoft patch and patch quickly..
May 14, 2025 at 5:13 AM
With the increased use of Bring Your Own Compromised Driver or malicious use of the EDR's setup program by threat actors. This @sophossecurity.bsky.social article "Putting the dampener on tamperers" is well worth a read. #cybersecurity #infosec news.sophos.com/en-us/2025/0...
Putting the dampener on tamperers
Taking a dive into Sophos Tamper Protection
news.sophos.com
May 9, 2025 at 7:53 AM