News

Latest news about B2B cyber security >>> PR agencies: add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

Cyber ​​insurance: The quality of defense determines the premium

Insurance against cybercrime is now standard protection for companies. But the insurance conditions depend on your own defense quality. The Sophos report on cyber insurance shows that those who have insurance are more likely to pay criminals ransom. In the new report "The Critical Role of Frontline Cyber ​​Defenses in Cyber ​​Insurance Adoption", Sophos has examined the connections between defense quality, insurability and insurance conditions for companies. 95 percent of organizations that purchased a cyber insurance policy in the last year say the quality of their organization's cyber defenses directly impacts their insurance terms. For 60 percent, the quality influences…

Read more

Cybercrime: The end goal is always clear – money!
Cybercrime: The end goal is always clear: money!

Cybercrime is a money-making business. It is subject to trends, picks up on current developments and is constantly changing. So the insight and outlook is always just a snapshot or a trend, such as the adoption of vulnerable signed drivers and tactics of state groups. The reuse of existing attack techniques and the emergence of new attacks are common in the threat landscape. Cyber ​​criminals often continue to use successful tools and techniques and will continue to do so until they no longer work. Says John Shier, Field CTO Commercial at Sophos. Cyber ​​criminals are extremely…

Read more

MOVEit zero-day gap: The countdown is on
MOVEit zero-day gap: The countdown is on

Last week, Progress Software reported a critical security vulnerability (CVE-2023-34362) in its MOVEit Transfer product and related MOVEit cloud solutions. The APT group CLOP, which also issued an ultimatum until June 14.06, carried out mass attacks and data theft on the software that is often used around the world. As the name suggests, MOVEit Transfer is a system that allows for easy storage and sharing of files across a team, department, company, or even a supply chain. The software is also used by the AOK, for example. In the current…

Read more

ChatGPT Fake Apps: Expensive subscriptions for zero features
SophosNews

A Sophos report uncovers the rip-off through expensive ChatGPT imitations: The fraud apps continue to thrive due to gaps in the app store guidelines from the current interest in the latest version of the AI-supported language model and benefit with sometimes horrendous subscriptions. Fees . Sophos X-Ops has uncovered various apps on the official Apple and Google stores posing as legitimate ChatGPT-based chatbots, scamming users with obfuscated, often extortionate, fees, and raking in thousands of dollars a month for scammers. Fleeceware: Expensive apps with tons of advertising The report “FleeceGPT Mobile Apps Target…

Read more

Data encryption by ransomware at an all-time high
Data encryption by ransomware at an all-time high

In its new State of Ransomware 2023 report, Sophos proves that data encryption by ransomware with 76 (international) had never reached such a high level. An evaluation also shows that paying the ransom only doubles the recovery costs. Sophos has published its new global study "State of Ransomware 2023", according to which cybercriminals in Germany succeed in encrypting data in 71 percent (internationally 76 percent) of ransomware attacks on organizations. From an international perspective, it is the highest rate of data encryption by ransomware since Sophos first published the annual ransomware report in 2020. ransom payment…

Read more

Welcome Distrust: Cybersecurity and ChatGPT
Welcome Distrust: Cybersecurity and ChatGPT

So far, organizations have had their biggest weakness in the fight against cybercrime well under control: employees have been successfully trained and sensitized. But with AI-generated social engineering scams comes a new wave. Until the technology is mature, humans have to play the watchdog, says Chester Wisniewski, Field CTO Applied Research at Sophos and makes three predictions for the future. Organizations have grappled with one of their most critical cybersecurity components: their people. They counter the "human weakness" with continuous training and now often trust that users, for example, avoid potential phishing attacks due to linguistic irregularities...

Read more

Report: Cyber ​​criminals use 500 tools and tactics
Report: Cyber ​​criminals use 500 tools and tactics

In its Active Adversary Report, Sophos describes how and with what cybercriminals carried out the most attacks in 2022. The shocking result: they used more than 500 different tools and tactics. This is how ransomware stays on the rise. Sophos has released its Active Adversary Playbook for Business Leaders. The report provides an in-depth look at the changing behaviors and attack techniques attackers will employ in 2022. Data from more than 150 Sophos Incident Response cases was analyzed for this report. Sophos researchers identified more than 500 unique tools and techniques, including 118 "Living off...

Read more

ChatGPT 4: The lawyer who knows how to lie perfectly
ChatGPT 4: The lawyer who knows how to lie perfectly

The update for ChatGPT to version 4 was eagerly awaited and, according to the manufacturer Open AI, is said to represent the “most advanced” AI technology and even passed a bar exam with top marks in a test. However, the only thing that ChatGPT can recreate are lies that are hardly recognizable in the factual texts, according to Sophos security expert Chester Wisniewski in an interview. How does a representative of the IT security industry see the rapid development in chat AI and how does he classify the resulting opportunities and possible disadvantages? Chester Wisniewski, Principal Researcher at Sophos, has...

Read more

Companies: 93 percent have problems with security tasks
Companies: 93 percent have problems with security tasks

New global study by Sophos confirms: 93 percent of companies have problems with basic security tasks. The risk is also high: 75 percent (65 percent in DACH) of those surveyed have difficulty identifying the causes of an incident. Sophos has released the new study “The State of Cybersecurity 2023: The Business Impact of Adversaries on Defenders”. The latest international study found that 93 percent of organizations worldwide find it difficult to perform basic security tasks, such as threat hunting. Understanding how an attack occurs Challenges also include…

Read more

AI Report: Dreamteam ChatGPT and Cybersecurity
AI Report: Dreamteam ChatGPT and Cybersecurity

The ChatGPT AI model can more easily filter malicious activity in XDR telemetry, improve spam filters, and simplify analysis of "Living Off the Land Binaries" -- "LOLBins" for short. Sophos has recently published this in a new report. The topic is the GPT-3 language model, which is behind the well-known ChatGPT framework, and how the cybersecurity industry can use the model to defend against attackers. The current report "GPT for You and Me: Applying AI Language Processing to Cyber ​​Defenses" describes projects developed by Sophos X-Ops that use the extensive language models of GPT-3. The goal is…

Read more