Product
Sophos EDR
- First Reported
- Sep 1, 2026
- Latest Reported
- Sep 1, 2026
Reported Context (1)
- attacker downloaded a vulnerable driver (xkpsm.sys) before leveraging an executable (x.exe) to target Sophos EDR endpoint processes. Existing countermeasures detected these attempts. Sophos Details GOLD SHERWOOD’s The Gentlemen Ransomware Playbook
CVE (1)
Malware (1)
Threat Actors (1)
MITRE ATT&CK (15)
Vendors (1)
Products (7)
Tools (13)
Countries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.