Category: Sophos SecOps

Providing Solutions

Rapid Response: The Ngrok Incident Guide

Ngrok is a legitimate remote-access tool. It is regularly abused by attackers, who use its capabilities and reputation to maneuver while bypassing network protections. This incident guide shows Security Operations Centers (SOCs) and response teams how to detect and respond to the suspicious presence or use of ngrok on the network.

Analyzing CVE-2022-0778: When Square Root Results in a Denial of Service

How could a humble SSL certificate entirely gridlock a system? Walk with us through the math