SecurityHow-to

ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split

From the source: Sophos News

Artifacts and tooling for the new Enterprise MITRE ATT&CK matrix tactics, distilled from the field.

Read the full story on Sophos News
Originally published by Sophos News on 14 Sept 2026. Techarda links to the original rather than republishing it. Read the full article →

Have you worked with this?

The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.

Start the discussion

More from Sophos

Recent updates from Sophos, so you can tell whether this is a one-off or part of a pattern.

All Sophos news →
Security

The industry turned XDR and SIEM into categories. Sophos turned them into outcomes.

Sophos Next-Gen SIEM, now generally available as part of Sophos Fusion, brings security operations and compliance together through shared context.

Sophos·via Sophos News
Security

Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation

Sophos·via Sophos News
Security

Messageboards are all they need

This article was first published on LinkedIn.

Sophos·via Sophos News

More in Security

What other companies in Security are doing. The category page shows who’s active, side by side.

Compare companies in Security →
SecurityWhy it matters

Threat Actors Use Google Ads To Target Ledger Users

In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake…

Zscaler·via Zscaler ThreatLabz
Security

Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?

Rapid7·via Rapid7 Blog
Security

Two Things Every Cyber Asset Attack Surface Management (CAASM) Tool Needs to Get Right

Cyber Asset Attack Surface Management (CAASM) solved a significant problem. Security teams can now say with confidence what they own. But, two things separate a CAASM tool that stops there from one that actually moves the needle on risk. The first is what the inventory itself carries. The second is what it connects to. 1. An inventory needs to do more than list what exists A list of assets is…

Check Point Software·via Check Point Software Blog
Security

Agents can now set up your website’s security with Turnstile Spin

Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification.

Cloudflare·via Cloudflare Blog