<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Sophos Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Sophos.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Pay up or not? Ransomware surge has victims facing tough choices</title><link>https://arstechnica.com/security/2026/07/pay-up-or-not-ransomware-surge-has-victims-facing-tough-choices</link><guid isPermaLink="false">cst-2850</guid><description>Sophos research shows that nearly half of targeted companies pay ransoms, with median demands increasing. The UK government is advancing legislation to prohibit public sector bodies and critical national infrastructure, including the NHS, councils, and schools, from making ransom payments as attackers grow more sophisticated in targeting vulnerable organizations.</description><pubDate>Mon, 20 Jul 2026 14:00:50 GMT</pubDate></item><item><title>AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers</title><link>https://thehackernews.com/2026/07/ai-coding-agents-found-triggering.html</link><guid isPermaLink="false">cst-2186</guid><description>Sophos analyzed its endpoint detection data and found that AI coding agents like Claude Code, Cursor, and OpenAI Codex trigger security rules designed to catch attacker behavior. The agents perform legitimate development tasks such as decrypting browser credentials and querying credential stores, but these actions match patterns that behavioral detection engines flag as malicious.</description><pubDate>Wed, 08 Jul 2026 17:02:12 GMT</pubDate></item><item><title>You do surprise me.exe: An unexpected executable in Hola Browser</title><link>https://sophos.com/en-us/blog/you-do-surprise-me-exe-an-unexpected-executable-in-hola-browser</link><guid isPermaLink="false">cst-2089</guid><description>Sophos X-Ops discovered an unexpected executable hidden within Hola Browser during certification testing. The finding suggests a supply chain compromise where an unwanted component was bundled with the application.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Why AMOS matters: The macOS malware stealing data at scale</title><link>https://sophos.com/en-us/blog/why-amos-matters-the-macos-malware-stealing-data-at-scale</link><guid isPermaLink="false">cst-2093</guid><description>Sophos X-Ops has analyzed Atomic macOS Stealer (AMOS), a malware that extracts data at scale on macOS systems. The analysis covers the stealer's technical capabilities and operational scope.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate></item><item><title>Donuts and Beagles: Fake Claude site spreads backdoor</title><link>https://sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor</link><guid isPermaLink="false">cst-2096</guid><description>A fake website impersonating Anthropic's Claude AI platform is distributing malware through DLL sideloading attacks that establish a backdoor on infected systems. The campaign uses malvertising to direct users to the fraudulent site, where downloads are weaponized with the Beagle backdoor and DONUT malware.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Supply chain attacks hit Checkmarx and Bitwarden developer tools</title><link>https://sophos.com/en-us/blog/supply-chain-attacks-hit-checkmarx-and-bitwarden-developer-tools</link><guid isPermaLink="false">cst-2098</guid><description>Two separate supply chain attacks were discovered on the same day using the same command-and-control domain, targeting developer tools from Checkmarx and Bitwarden. The incidents were identified through threat research, indicating coordinated or opportunistic exploitation of development infrastructure. These attacks represent a broader pattern of threat actors targeting software supply chains to distribute malware or gain access to downstream users.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate></item><item><title>StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms</title><link>https://volexity.com/blog/2024/08/02/stormbamboo-compromises-isp-to-abuse-insecure-software-update-mechanisms</link><guid isPermaLink="false">cst-2112</guid><description>StormBamboo, a Chinese-linked threat actor, compromised an internet service provider's DNS infrastructure to redirect software update requests to malware-hosting servers. The attacks targeted applications with insecure update mechanisms that use HTTP and lack signature validation, allowing attackers to distribute malware families including MACMA and POCOSTICK to Windows and macOS systems across victim organizations.</description><pubDate>Fri, 02 Aug 2024 12:05:13 GMT</pubDate></item></channel></rss>