Tag Sophos

Critical RCE Vulnerabilities Identified in Sophos Firewall and SMA 100 Devices: Urgent Patches Released by Sophos and SonicWall

July 24, 2025
Network Security / Vulnerability

Sophos and SonicWall have issued a warning regarding serious security flaws in Sophos Firewall and Secure Mobile Access (SMA) 100 Series appliances, which could be exploited for remote code execution. The two critical vulnerabilities affecting Sophos Firewall are as follows:

  • CVE-2025-6704 (CVSS score: 9.8): An arbitrary file writing vulnerability within the Secure PDF eXchange (SPX) feature that can enable pre-auth remote code execution if specific SPX configurations are used alongside firewall operation in High Availability (HA) mode.
  • CVE-2025-7624 (CVSS score: 9.8): An SQL injection vulnerability in the legacy (transparent) SMTP proxy that can result in remote code execution, contingent on an active quarantining policy for Email and if SFOS has been upgraded from a version prior to 21.0 GA.

Sophos reports that CVE-2025-6704 affects approximately 0.05% of devices, while CVE-2025-7624 impacts up to 0.73% of devices. Both vulnerabilities have been addressed in a recent update, along with a high-severity command injection vulnerability.

Sophos and SonicWall Address Critical RCE Vulnerabilities in Firewalls and SMA 100 Devices On July 24, 2025, cybersecurity firms Sophos and SonicWall issued urgent security warnings regarding significant vulnerabilities discovered in the Sophos Firewall and Secure Mobile Access (SMA) 100 Series devices. The flaws present a critical risk, allowing potential…

Read More

Critical RCE Vulnerabilities Identified in Sophos Firewall and SMA 100 Devices: Urgent Patches Released by Sophos and SonicWall

July 24, 2025
Network Security / Vulnerability

Sophos and SonicWall have issued a warning regarding serious security flaws in Sophos Firewall and Secure Mobile Access (SMA) 100 Series appliances, which could be exploited for remote code execution. The two critical vulnerabilities affecting Sophos Firewall are as follows:

  • CVE-2025-6704 (CVSS score: 9.8): An arbitrary file writing vulnerability within the Secure PDF eXchange (SPX) feature that can enable pre-auth remote code execution if specific SPX configurations are used alongside firewall operation in High Availability (HA) mode.
  • CVE-2025-7624 (CVSS score: 9.8): An SQL injection vulnerability in the legacy (transparent) SMTP proxy that can result in remote code execution, contingent on an active quarantining policy for Email and if SFOS has been upgraded from a version prior to 21.0 GA.

Sophos reports that CVE-2025-6704 affects approximately 0.05% of devices, while CVE-2025-7624 impacts up to 0.73% of devices. Both vulnerabilities have been addressed in a recent update, along with a high-severity command injection vulnerability.

Scattered Spider Takes Advantage of VMware vSphere

Fraud Management & Cybercrime, Social Engineering Hacking Tactics Linked to Retail and Airline Breaches Akshaya Asokan (asokan_akshaya) • July 25, 2025 Image: Shutterstock A group of adolescent cybercriminals known as Scattered Spider has recently targeted VMware hypervisors, successfully infiltrating corporate environments through Active Directory. This emerging threat landscape has led…

Read MoreScattered Spider Takes Advantage of VMware vSphere

Cybercrime Alert: Internet Users Urged to Update Passwords Following Exposure of 16 Billion Logins

Recent cybersecurity research has raised alarms in the online community, urging users to update their passwords and enhance digital security measures. Analysts at Cybernews have identified an alarming 16 billion login records that may be accessible to cybercriminals, stemming from vulnerabilities associated with infostealing malware and various data leaks. The…

Read MoreCybercrime Alert: Internet Users Urged to Update Passwords Following Exposure of 16 Billion Logins

Chinese-Linked Hackers Attack Over 70 Global Organizations, Says SentinelLABS

A recent report from SentinelLABS reveals extensive cyber espionage operations linked to China, affecting more than 70 global organizations and cybersecurity firms from July 2024 to March 2025. The findings highlight the “PurpleHaze (also known as Vixen Panda)” and “ShadowPad” operations, underscoring the ongoing threat landscape. According to the cybersecurity…

Read MoreChinese-Linked Hackers Attack Over 70 Global Organizations, Says SentinelLABS

Ransomware Leader “Stern” Believed to Be Identified by German Authorities

Prominent Ransomware Figure Identified by German Authorities Recent investigations by the German Federal Criminal Police Office (BKA) have brought to light the activities of a significant player in the realm of cybercrime known as Stern. Widely recognized in the cybersecurity community, Stern’s operations are particularly tied to high-revenue ransomware schemes.…

Read MoreRansomware Leader “Stern” Believed to Be Identified by German Authorities

German Police Claim to Have Identified the Elusive Trickbot Ransomware Kingpin

Recent developments regarding the notorious Trickbot malware have shed light on the identity of one of its alleged key figures, Andrey Kovalev. Multiple cybersecurity researchers who have monitored Trickbot closely reported they were unaware of an announcement related to his identity. An anonymous account on the platform X recently claimed…

Read MoreGerman Police Claim to Have Identified the Elusive Trickbot Ransomware Kingpin

WatchGuard Appoints Former SentinelOne COO Srivatsan as Interim CEO

Endpoint Security, Governance & Risk Management, Managed Security Service Provider (MSSP) Vats Srivatsan Appointed Interim CEO at WatchGuard Following Prakash Panjwani’s Departure Michael Novinson (@MichaelNovinson) • May 8, 2025 Vats Srivatsan, interim CEO of WatchGuard (Image: WatchGuard) Vats Srivatsan, the former Chief Operating Officer of SentinelOne, has been appointed as…

Read MoreWatchGuard Appoints Former SentinelOne COO Srivatsan as Interim CEO