Tag

Sophos

All articles tagged with #sophos

cybersecurity1 year ago

"Ransomware Exploits Critical ConnectWise ScreenConnect Flaws"

Sophos X-Ops is tracking a wave of vulnerability exploitation targeting unpatched ConnectWise ScreenConnect installations, with attackers deploying malware to servers and workstations. ConnectWise has released a security advisory highlighting two critical vulnerabilities, urging immediate patching to version 23.9.8. Cloud-hosted implementations have received updates, but self-hosted instances remain at risk until manually upgraded. Sophos observed active exploitation in the wild, including attacks involving LockBit ransomware and other malware. Recommendations include confirming deployment type, scanning for unpatched instances, and implementing security measures. Sophos also provides detection and protection rules, as well as incident response guidance for organizations to mitigate risks and investigate potential incidents.

cybersecurity2 years ago

Beware of Fake ChatGPT Apps and AI Tools Distributing Malware

Fake ChatGPT apps are being created by developers to trick users into paying for expensive subscriptions, according to a report by cybersecurity firm Sophos. These apps, known as fleeceware, bombard users with ads until they sign up for a subscription, which can cost anywhere from $10 a month to $70 a year. Sophos has reported these apps to Apple and Google, and many have been removed from their respective app stores. To access ChatGPT without getting scammed, users can sign up for OpenAI's ChatGPT Plus for $20 a month or use Bing Chat, which has partnered with OpenAI to bring ChatGPT to its search engine.