Entries in Sophos (142)

Wednesday
Apr112018

Sophos Ranked #1 in Malware Detection

MRG Effitas conducted a commissioned test comparing endpoint protection products’ ability to detect malware and potentially unwanted applications. Six different vendors, including Sophos, were reviewed in the test. This report will serve as an excellent proof point for Sophos. Some highlights of the report include:

Sophos ranked #1 at detecting malware. Sophos had an automatic block rate of 99.19% and a miss rate of 0.81%, half as much as next competitor. The percent of samples missed was over 11 times smaller than the average of the other vendors included in the study.

Sophos ranked #1 at detecting potentially unwanted applications (PUAs). Sophos detected 100% of the PUAs in the test, which is important as the sample contained a high number of cryptominers (aka coinminers) that are used in cryptojacking. Comparatively, four of the six vendors tested missed between 47% and 69% of PUAs.

Sophos’ false positive rate according to MRG Effitas was 0.05%, which is even more impressive when considering the corresponding best-in-class detection rates of in-the-wild malware and potentially unwanted applications.

You can read the report here.

You can download the report here.

Tuesday
Apr102018

Announcing Sophos Mobile 8.1 With Office 365 App Management

Hot on the heels of Sophos Mobile 8, we are pleased to announce that Sophos Mobile 8.1 is now available. New capabilities include support for devices running iOS 11.3, plus management and configuration of Office 365 applications on enrolled iOS and Android devices.

The new functionality means that admins can now use Sophos Mobile to manage and configure Office 365 apps on mobile devices. Admins will save time by using a single console, making policy creation and distribution very simple in the Sophos Mobile admin interface.

Office 365 app management features are available in both Sophos Central and when installed on premises. Customers will need an Office 365 license, but no other separate Microsoft license is required to enable app management.

Sophos Mobile 8.1 is available now for installation on the customer’s own premises with management in Sophos Central following on April 24, 2018.

To learn more as well as to find Sophos Mobile sales resources, please visit the Sophos Mobile product page.

Thursday
Apr052018

Important Sophos Security Advisory for Sophos Mobile and Sophos Mobile Control

Sophos

Technical Alert

Important Sophos Security Advisory for Sophos Mobile and Sophos Mobile Control

Date issued: 2018-03-26

Sophos has released a security update to Sophos Mobile and Sophos Mobile Control installed on premises. Customers running Sophos Mobile managed in Sophos Central or the hosted Sophos Mobile as a Service are not affected by this issue.

This update fixes a security bypass bug that could allow an unauthenticated user to access the administration console or the self-service portal.

This vulnerability was responsibly disclosed to Sophos on 2018-03-21. We are not aware of any attempts to exploit this bug in the wild.

We have assessed this update as critical and therefore advise you to install the update as soon as possible.

If you have Sophos Mobile or Sophos Mobile Control version 6.0 or later, please login to the Sophos License Portal, download the security patch for your version and apply immediately.

If you have Sophos Mobile Control 5.1 or earlier, you need to upgrade to the current version. For more information please read the article https://community.sophos.com/kb/128031.

For more information, please read this knowledge base article on our support site: https://community.sophos.com/kb/131867.

Note: We would like to make you aware of a vulnerability affecting Sophos Mobile customers running the product installed on premises. Customers running Sophos Mobile managed in Sophos Central or the hosted Sophos Mobile as a Service are not affected by this issue. We will send the following email to all affected customers indicating any required actions. Please don’t hesitate to reach out to your account or support representative if you have additional questions.

Monday
Jan152018

PR: Sophos Mobile 8 Launch Update

Timeline:

January 17, 2018 – Sophos Mobile as a server (SMaaS) upgrade to version 8

January 17, 2018 – Sophos Mobile 8 for installation on premises generally available to download

February 13, 2018 – Sophos Mobile 8 available in Sophos Central

February 26, 2018 – Announcement and public launch at Mobile World Congress 2018

Wednesday
Dec272017

Happy Holidays from Sophos

Thursday
Oct262017

Sorry if you missed the Sophos Rise Over Ransomeware event yesterday

There was a good turnout yesterday at the Cranberry/Pittsburgh event. Sophos presented a lot of good information to everyone that attended about the state of the Sophos products and the story behind the Synchronized Security Solution.

Wednesday
Oct252017

Sophos Launches New XG Firewall Version, Adds New Application Visibility And Deployment Options

This is a great article from CRN on the new release of the version 17 SFOS operating system. One of Sophos PAC members had quote in it which is sums up the positive direction that Sophos is taking towards their Synchronized Security capabilities for your network. Good job SAM! It is good to get the word out about one of the best good news stories in the security industry and the major reason for looking at Sophos then any other solution.

If you are not aware of the Sophos Synchronized Security Story you may want to take a look at the video below. Each new version of SFOS and the Sophos Central Products bring your network more security with each new component that you add to it.

See a quick video below to get a better view of what I am talking about:

Monday
Aug142017

Naked Security: Thousands of Android-spying apps in the wild: what to do about SonicSpy

By Bill Brenner, nakedsecurity.sophos.com

Well we always knew that Android was a security nightmare but SophosLabs has found three cases of SonicSpy-infused apps in Google Play:

Researchers from SophosLabs and elsewhere have found three cases of SonicSpy-infused apps in Google Play: Soniac, Hulk Messenger, and Troy Chat – messaging apps that hide their spying functionality and await orders from command-and-control servers.

Google booted the apps from its store after they were discovered. Researcher Chen Yu said the Google Play versions had “tiny installation numbers and existed for a very short time”. Though three were found on Google Play, SophosLabs has counted 3,240 SonicSpy apps in the wild. Some reports place the number at 4,000.

According to multiple reports, a single bad actor – probably based in Iraq – has released these apps into the wild since February.

To read more of this article: click here

Tuesday
Aug082017

Sophos Intercept X–Good News!

For those of you that have already jumped on to the bandwagon and have implemented Intercept in your Organization you have great news from Sophos Labs. The recent outbreak attacks that have been in the news of recent Ransomware attacks “WannaCry” and “Petya”, protected those machines that had Intercept X installed on them without any needed updates to recognize the attacks. This is another proof of concept behind the security that this products brings to your systems from this type of attack.

This product is only going to get better. Later this year you will get a incremental upgrade to the product that also contains some increased “Smarts” that will do an even better job of determining malware that is attacking our systems out there. If you don’t have Intercept X yet, maybe you should think about adding it to your systems.

Thursday
Jul272017

NakedSecurity:Privacy dust-up as Roomba maker mulls selling maps of users’ homes

Another example of how embracing technology and automation can come back and bite you! The more technology that has reach back to the manufacturer you have in your home, the more data that they will be able to acquire about your habits, likes and dislikes and your infrastructure. So… you can either continue to acquire the products that seem to make your life easier and/or more enjoyable or you can run back to your cave and pull the rock back in front of your door. Is there a happy medium? I don’t think so! I look at the number of services and devices that I use and it has become enormous.

Take a look at this article to give you another insight into what companies like iRobot have about you and your environment and how it could be used as a commodity sale to other companies.

Friday
Jul212017

Naked Security Post: Watch out for the Android malware that snoops on your phone

Android has a long history of being the one of the most hacked and infected phone devices and so if this is what your phone is running you may want to look at this article. Don’t forget that Sophos has a free anti-malware package available for both ios and android devices. For other free Sophos Tools take a look here.

Tuesday
Jul182017

Sophos Phish Threat Protection–Whitepaper

It is now surprise that Phishing attacks have caused issues with a whole lot of people. Whether it is from “The Microsoft Service Department” wanting to help you get rid of unwanted malware by signing on to your computer to get a quick look and run their special software… to the IRS scams with the caller wanting you to satisfy your unknown tax bill or there will be agents coming to take you away. They are coming at us from all directions. Some are subtle and most are real sneaky. How do we test our organization to see if we are prepared and educated to be aware of these attacks so that we are not succumbed by them? How do we get trained to understand what we should be wary of?

Sophos has an answer for you. Their brand new Phish Threat Protection service that allows you to setup campaigns to both train and test your employees. It is reasonably priced and is a good source for keeping your people on their toes. What is your weakest link in your organization? The People.

Take a look at this whitepaper: Don’t Take the Bait and learn more about protecting your company today.

Monday
Jul172017

Sophos Phish Threat Overview

The weakest link in a company's cyber-defenses? People! Sophos Phish Threat teaches end users to spot phony phishing messages with a series of simulated attack emails and easy-to-deploy training campaigns.

Sophos Phish Threat Overview from Sophos on Vimeo.

Friday
Jul142017

Sophos Intercept X vs. Petya/Petna/PetrWrap Ransomware

This short video showcases the signatureless protection capabilities of Sophos Intercept X. The Petya/Petna/PetrWrap outbreak that made headlines on June 27th, 2017 not only attempted to encrypt documents, it also infected the master boot record to encrypt the master file table and prevent users from using their machines.

Sophos Intercept X vs. Petya/Petna/PetrWrap Ransomware from Sophos on Vimeo.

Thursday
Jul132017

Naked Security Posts

News in brief: dark web sites attacked; radio station pwnd; Russian hacker jailed for nine years

Your daily round-up of some of the other stories in the news

Mark your calendar for the net neutrality Day of Action

Tomorrow - July 12 - is the Internet-Wide Day of Action, with big online names from Kickstarter and Vimeo to Reddit and Spotify banding together to express their objection to overturning rules that guarantee net neutrality

Two-factor via your mobile phone – should you stop using it?

Although SIM cards themselves are very secure, it's annoyingly easy for a crook to get hold of one for your number

Your gadget could save your life: smart device phones police

We write a lot about the privacy issues of connected things in your home - but one device might have saved lives

Russians told to log in to Pornhub using verified social media accounts

Russians need a passport to get a SIM card, a cell number to get a VK account, and the VK account to log into Pornhub. What's behind this new requirement?

News in brief: probe in Jupiter fly-by; footage of politician ‘not illegal’; Trump sued over Twitter block

Your daily round-up of some of the other stories in the news

Social engineering – explored and explained by our experts [VIDEO]

Join Sophos experts James Burchell and Greg Iddon as they explore, explain - and help you to fight back against - social engineering.

Researchers find chinks in the armour of satellite phone calls

Could the proof of concept the researchers describe be used to eavesdrop on actual satellite phone calls? It depends ...

How app developers are gaming Google Play to boost their rankings

Our researchers spotted some app developers who were gaming the Google Play store - here's what they uncovered in their investigation

So long, Windows Phone – it was nice knowing you

The end of support for Windows Phone 8.1 is pretty much the death knell for a platform that never took off but which was widely liked - not least for its security

Thursday
Jul132017

Sophos Phish Threat Product

Another reason that Sophos is such a great security solution company is this new product that helps you assess your vulnerabilities and help you train your employees on what they should be aware of to protect themselves and your company from Phishing attempts. Sophos says about this problem:

From our continuous assessment of the threat landscape, two things are abundantly clear: first, that email is one of the most problematic sources of infection; and second, it’s the ordinary, well-meaning people who often let poisonous emails into their organizations.

It’s easy to be tricked into clicking on a malicious email. So wouldn’t it be great to create a culture where the first instinct of each user was to think twice — even if just for a moment — before clicking on links, downloading attachments or running software that arrived via email? Think of how many threats could be neutralized before they even have a chance to make their way on to corporate networks.

So we’re excited to be able to help create that culture by announcing Sophos Phish Threat, a phishing attack simulator that’s powerful, thoughtful and very easy to use. You’ll be up and running in minutes, with campaigns to help your users learn to spot phishing links, dangerous attachments, and bogus scripts meant to cripple your organization before they have a chance to do harm.

Simply choose a campaign type, select one or more training modules, pick a simulated phishing message, and decide which users to test. Then sit back as the results roll in: top-notch reporting tells you how many messages have been sent out, who’s clicked, and, of those, who’s gone through the required modules. It couldn’t be easier.

Here’s a quick video overview of the product:

Getting Started With Sophos Phish Threat from Sophos on Vimeo.

Tuesday
Jul112017

Naked Security Posts

News in brief: NATO backs Kiev over cyber-attacks; China cracks down on VPNs; Somalia knocked offline

Your daily round-up of some of the other stories in the news

Tendulkar wants your number on Twitter, what do you do?

Indian cricket legend Sachin Tendulkar asked 17m Twitter followers to send him their friends' phone numbers - good intentions, bad idea!

FTC slaps $104m judgment on loan application firm

Blue Global wasn't a loan company, didn't safeguard data and sold leads to third parties for $200 each

Apps that are a matter of life, death and data win $75,000 prizes

Two start-ups have won a US government competition to design apps that help patients manage and control their data

When ex-workers attack (again): man used Trojan to cause havoc

Former staffer used a remote Trojan to trash client databases, steal credit cards and masquerade as another employee to make allegations about the company

More than 100m records potentially lost in huge telecoms breach

India's newest telecoms provider denies that subscriber records posted online were authentic, but users claim the data is real

Your gadget could save your life: smart speaker phones police

We write a lot about the privacy issues of smart speakers in your home - but one device might have saved lives in an alleged hostage situation

Tuesday
Jul112017

Did you ever wonder the difference between anti-malware and anti-virus software?

The short answer is that most anti-virus software packages also are taking care of anti-malware because they are different faces of the same issue. All viruses are malware so… The main difference between different companies products is how effective and how they do their recognition of the malware. We pick the combination of Sophos’s Endpoint Protection + Intercept X to give you the best one-two punch to protect your systems. When you combine these products with s Sophos Firewall you have a very effective start to your security needs.

Sophos Synchronized Security

Friday
Jul072017

Sophos Update: Differences between Machine and Deep Learning

Thursday
Jun292017

Naked Security Postings

Deconstructing Petya: how it spreads and how to fight back

It's been 24 hours since the outbreak first hit: here's what we know now about how Petya behaves

Anthem to pay record $115m to settle lawsuits over massive breach

Attackers grabbed data including names, birthdates, taxpayer IDs and more from Anthem patients - a toolkit for identity theft

New Petya ransomware: everything you wanted to know (but were afraid to ask)

Your questions about the new Petya ransomware answered - and your chance to ask us more.

From floppy disks to deep freeze: what’s the best way to store data?

Still got a Zip drive? What about a CD? Are you sure you'll be able to access the data stored on those? We take a look at what's being done to keep information safe for future generations

News in brief: Wimbledon adds AI; four arrested over support scams; Russia threatens to block Telegram

Your daily round-up of some of the other stories in the news

Beer + bitter former field engineer = hacked smart water meters

The story of Adam Flanagan, who's been jailed for hacking, is a reminder to companies to revoke access to networks when they sack a disgruntled employee