Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

Sophos Rebuilds Firewall Security Around Evidence, Automation and Safer MFA

Sophos Rebuilds Firewall Security Around Evidence, Automation and Safer MFA
Photo by Tima Miroshnichenko on Pexels

Sophos has detailed a year of security improvements for its firewall platform, including stronger MFA enrollment, behavioral monitoring, visible hotfix status and upcoming scheduled firmware updates. The company is also developing fleet-scale forensic collection and using autonomous AI systems to test real firewall appliances for vulnerabilities.

Sophos is strengthening its firewall platform around a principle that network security vendors have historically struggled to deliver: customers should be able to verify that protective controls are working, not simply trust that they exist.

In a new Secure by Design update, the company described changes made after reviewing attacks against internet-facing edge devices. One important lesson concerned accounts that had never completed multifactor authentication enrollment. If an attacker guessed the password for an unused account, the attacker could potentially become the first person to register an authentication factor.

Closing the first-use authentication gap

Sophos redesigned that process so enrollment information is delivered through email instead of being displayed directly in the user portal. The codes expire after 24 hours, requiring someone to demonstrate control of the associated mailbox before completing enrollment. Dynamic login lockouts and MFA protection for SSH access are also under development.

The company has expanded behavioral detection across its XGS firewall appliances through the Sophos Linux Sensor. This capability looks for post-exploitation activity such as interactive shells, reverse shells and command-and-control traffic. Detection rules can be updated independently of full firmware releases, allowing protections to change more quickly when new attacker behavior is identified.

Making patch status visible

Sophos says more than 99 percent of customer firewalls receive its automatic hotfixes, but administrators previously had limited ways to confirm that a specific fix was present. Hotfix status is now visible through the firewall interface, logs, email notifications and centralized reporting. Scheduled firmware updates managed through Sophos Central are expected to become available in August 2026.

The company is also using an internal agentic vulnerability-hunting platform to test firewall source code and physical appliances inside an isolated laboratory. Engineers and red-team specialists supervise the models, while every action is recorded for review.

What administrators should do

  • Confirm that management and user portals are not unnecessarily exposed to the internet.
  • Review dormant and synchronized directory accounts.
  • Verify hotfix and firmware status across every deployed appliance.
  • Forward firewall logs to protected external storage.
  • Prepare procedures for collecting forensic evidence after a suspected compromise.

In my view, the most significant development is not any single control. It is the move toward measurable security. Firewalls are critical trust boundaries, and vendors should provide customers with patch evidence, useful telemetry and practical forensic capabilities. That level of transparency should become an expected purchasing requirement across the network security market.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path