Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ungentlemanly behavior: Insights into a ransomware operation

They call themselves The Gentlemen Behind the name is one of the most active ransomware operations of the past 12 months, linked to 683 victims and a playbook built around compromised credentials, legitimate tools, rapid privilege escalation, and aggressive defense evasion. In this video, Susie Evershed and Rafe Pilling break down the latest research from Sophos Counter Threat Unit (CTU), revealing how some affiliates can move from initial compromise to ransomware deployment in less than 24 hours.
Featured Post

Increasingly Dangerous Threats, Not More Alerts, Are the New SOC Challenge

For years, security operations centres have operated under the same constraints of more alerts than analysts, more investigations than hours in the day, and more pressure than most teams can sustainably absorb. That imbalance is becoming dangerous as frontier models rapidly improve at finding vulnerabilities and turning them into exploits, while defenders are left dealing with the consequences in real time.

Sophos To Bring OpenAI GPT Cyber Models Into Managed Risk Offering, Helping Defenders Validate Exploit Paths

The company is building a new Exploit Path Verification (EPV) capability that will tell security teams which vulnerabilities an attacker can reach in their environment, turning long exposure lists into evidence-backed priorities.

Introducing App Store Threat Detection: Visibility Where Brand Monitoring Couldn't Reach

In January 2024, Craig Raw, the developer of the real Sparrow Wallet, a Bitcoin wallet app, warned that a fake version of his app was live on the Apple App Store. He reported it repeatedly, but the listing stayed up. By August 2025, three people had lost a combined $1.8 million to it: Jalen Delgado (about $120,000 in May 2025), James Ramirez (about $875,000 in July 2025), and Christopher Ellis (about $840,000 in August 2025). All three are now suing Apple. The complaint, Ramirez, et al. v.

Stop runtime threats with Workload Protection response actions

Modern threats increasingly unfold at runtime, where attackers exploit live workloads, spawn malicious processes, and move laterally across your environment. Detecting that activity is essential, but a signal only matters if you can stop it. When a threat appears, every step before a response gives an attacker more time to act. Datadog Workload Protection can now directly remediate threats with both automated and manual response.

7 AI Detection and Response Platforms for Enterprise Security Teams

The most difficult AI incidents do not necessarily begin with an obviously malicious prompt. An employee can ask an approved agent to summarize customer data. The agent retrieves the correct records, invokes an approved tool, generates the requested output, and then sends it somewhere it should never have gone. Every individual action may look legitimate in isolation. The incident only becomes visible when security can reconstruct the entire sequence and understand what the user intended, what the agent inferred, which systems it touched, and where the execution path diverged.