
Sophos Counter Threat Unit Research Team
Sophos Counter Threat Unit™ (CTU) researchers are recognized authorities in the cybersecurity field, regularly contributing expert analysis to global media, publishing technical analyses for the security community, and presenting about emerging threats at leading security conferences. Backed by Sophos’ advanced security technologies and a broad network of intelligence contacts and partners, the CTU™ plays a critical role in identifying and tracking threat actors and analyzing anomalous activity, uncovering new attack techniques, threats, and major shifts in the threat landscape.
Content by Sophos Counter Threat Unit Research Team

Threat Research
AI
Dark Web
underground
AI in the underground: Curiosity, claims, and concerns
June 17, 2026

Threat Research
AI
EDR
Pointing a Cursor at evading detection
June 2, 2026

Threat Research
Ransomware
WantToCry
SMB
WantToCry ransomware remotely encrypts files
May 19, 2026

Threat Research
hacktivism
Iran
israel
Operation Epic Fury
Hacktivist campaigns increase as United States, Iran, and Israel conflict intensifies
March 3, 2026

Threat Research
advisory
vulnerability
SD-WAN
Cisco SD-WAN vulnerabilities (CVE-2026-20127, CVE-2022-20775) in active exploitation
February 26, 2026

Threat Research
EDR killer
infostealer
Ransomware
Threat Intelligence Executive Report – Volume 2025, Number 6
February 10, 2026

Threat Research
virtual machine
cybercrime
Ransomware
ISPs
Malicious use of virtual machine infrastructure
February 4, 2026

Threat Research
Ransomware
cybercrime
state-sponsored ransomware
victimization
Eeny, meeny, miny, moe? How ransomware operators choose victims
January 28, 2026

Threat Research
Microsoft Office
vulnerability
advisory
Microsoft Office vulnerability (CVE-2026-21509) in active exploitation
January 27, 2026