
Sophos Report: In 56% of Sophos IR and MDR Cases, Adversaries Logged In, Instead of Breaking In
Sophos, a global leader of innovative security solutions for defeating cyberattacks, today released the 2025 Sophos Active Adversary Report, which details attacker behavior and techniques from over 400 Managed Detection and Response (MDR) and Incident Response (IR) cases in 2024. The report found that the primary way attackers gained initial access to networks (56% of all cases across MDR and IR) was by exploiting external remote services, which includes edge devices such as firewalls and VPNs, by leveraging valid accounts.
The combination of external remote services and valid accounts aligns with the top root causes of attacks. For the second year in row, compromised credentials were the number one root cause of attacks (41% of cases). This was followed by exploited vulnerabilities (21.79%) and brute force attacks (21.07%).
Understanding The Speed of AttacksWhen analyzing MDR and IR investigations, the Sophos X-Ops team looked specifically at ransomware, data exfiltration, and data extortion cases to identify how fast attackers progressed through the stages of an attack within an organization. In those three types of cases, the median time between the start of an attack and exfiltration was only 72.98 hours (3.04 days). Furthermore, there was only a median of 2.7 hours from exfiltration to attack detection.
'Passive security is no longer enough. While prevention is essential, rapid response is critical. Organizations must actively monitor networks and act swiftly against observed telemetry. Coordinated attacks by motivated adversaries require a coordinated defense. For many organizations, that means combining business-specific knowledge with expert-led detection and response. Our report confirms that organizations with proactive monitoring detect attacks faster and experience better outcomes,' said John Shier, field CISO.
Other Key Findings from the 2025 Sophos Active Adversary Report:Attackers Can Take Control of a System in Just 11 Hours: The median time between attackers' initial action and their first (often successful) attempt to breach Active Directory (AD) - arguably one of the most important assets in any Windows network – was just 11 hours. If successful, attackers can more easily take control of the organization. Top Ransomware Groups in Sophos Cases: Akira was the most frequently encountered ransomware group in 2024, followed by Fog and LockBit (despite a multi-government takedown of LockBit earlier in the year).Dwell Time is Down to Just 2 Days: Overall, dwell time – the time from the start of an attack to when it is detected – decreased from 4 days to just 2 in 2024, largely due to the addition of MDR cases to the dataset.Dwell Time in IR Cases: Dwell time remained stable at 4 days for ransomware attacks and 11.5 days for non-ransomware cases. Dwell Time in MDR Cases: In MDR investigations, dwell time was only 3 days for ransomware cases and just 1 day for non-ransomware cases, suggesting MDR teams are able to more quickly detect and respond to attacks.Ransomware Groups Work Overnight: In 2024, 83% of ransomware binaries were dropped outside of the targets' local business hours.
Remote Desktop Protocol Continues to Dominate: RDP was involved in 84% of MDR/IR cases, making it the most frequently abused Microsoft tool.
To shore up their defenses, Sophos recommends that companies do the following:Close exposed RDP portsUse phishing-resistant multifactor authentication (MFA) wherever possiblePatch vulnerable systems in a timely manner, with a particular focus on internet-facing devices and servicesDeploy EDR or MDR and ensure it is proactively monitored 24/7 Establish a comprehensive incident response plan and test it regularly through simulations or tabletop exercises
Read the full It Takes Two: The 2025 Sophos Active Adversary Report on Sophos.com.
© 2000 - 2025 Al Bawaba (www.albawaba.com)
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Al Bawaba
2 days ago
- Al Bawaba
Lg's 10 Million-selling Cutting-edge Oled and Qned Tv Lineup Set to Redefine Home Entertainment in the Gcc
LG Electronics (LG), a global leader in consumer electronics and home entertainment, is thrilled to announce the upcoming launch of its groundbreaking 2025 OLED and QNED TV lineup across the region. Building on a legacy of innovation and a proven track record of success, LG is poised to elevate the home entertainment experience for consumers throughout the GCC. The regional launch follows hot on the heels of LG's recent incredible milestone of selling over 10 million OLED units in Europe – a testament to the technology's superior picture quality, design, and overall viewing experience – an achievement that underscores the trust and confidence consumers worldwide place in LG OLED TVs as the gold standard in premium home entertainment. LG has for the past 12 years consistently delivered unstoppable world's first OLED innovations, including the curved; 4K; Ultra Slim Wallpaper; 8K; Rollable; 4K 120hz Wireless; 4K Wireless and Transparent; True Wireless 4K; and three-times brighter AI-powered OLED TVs. Not to mention being the first brand to surpass the 10-million-mark of OLED sales in Europe. Featuring the M5, G5, C5, and B5 series, LG's 2025 OLED models are designed to deliver an exceptional viewing experience. Renowned for their perfect blacks, vibrant colors, and infinite contrast, creating images that are remarkably lifelike, LG OLED TVs take picture quality to the next level with the advanced α (Alpha) AI processors, ensuring stunning visuals regardless of the content source. Additionally, all four models boast "Perfect Black" and "Perfect Color" certifications, guaranteeing an immersive viewing experience in any lighting conditions. The complementary new webOS 25 platform, powered by the Alpha AI Processor, offers a personalized and intuitive user experience, where features like AI Picture/Sound Wizard, AI Brightness Control, AI Voice ID, AI Chatbot, and AI Search use Large Language Models (LLMs) to tailor the TV to individual preferences. Gamers, too, will appreciate the industry's first 4K 165Hz Variable Refresh Rate (VRR) on the G5 series, certified by NVIDIA® G-SYNC® and AMD FreeSync Premium, which ensures smooth, tear-free gaming with minimal input lag. And for those averse to cable clutter, the OLED M5 is the world's first OLED TV capable of wirelessly transferring audio and video, with its Zero Connect box allowing for seamless wireless transmission at up to 144Hz, providing greater flexibility in the living space without unsightly wires. But it's not just cutting-edge OLED TVs breaking new ground for LG, which is also redefining the premium LCD TV segment with its 2025 QNED evo lineup. These TVs combine advanced color solutions with cutting-edge Mini LED technology, powered by the α AI processor, and certified by Intertek as delivering rich, true-to-life colors in both bright and dark environments. Better still, AI Object Enhancer and Dynamic Tone Mapping Pro refine light control, enhance contrast, and enrich faces, bodies, and key scene elements for immersive visuals, while virtual 9.1.2 surround sound from AI Sound Pro delivers unmatched depth and spatial clarity through the TV's built-in speakers. LG is committed to pushing the boundaries of TV technology, delivering products that resonate with its customers the world over, with the 2025 OLED and QNED lineup reflecting a promise of visually-arresting perfection.


Al Bawaba
3 days ago
- Al Bawaba
Tourism spending in the Middle East is projected to reach US$350 billion by 2030, according to a new travel industry report
A new report compiled by Tourism Economics on behalf of Arabian Travel Market (ATM) predicts that by 2030, total tourism spend in the Middle East will be 50% higher than in 2024, generating expenditure of nearly US$350 ATM Travel Trends Report 2025 reveals insights into the trends and transformations redefining the travel sector in the Middle East and worldwide, including the surge of business travel, the growth of the luxury segment, and the boom in regional sports tourism. The report highlights exceptional growth in Middle East travel spending, projected to exceed 2019 levels by 54% this year and anticipates an annual growth rate of over 7% from 2025 to Curtis, Exhibition Director ME, Arabian Travel Market, said: 'The report's findings confirm that travel growth in the Middle East is incredibly strong, with annual growth averaging more than 7% through 2030. Bold national visions, game-changing developments, and enhanced connectivity are some of the key factors driving this momentum.'Underscoring the Middle East's strong position in global tourism, inbound travel from outside the region is set to grow by 13% annually up to 2030 and outbound business travel forecast to surge at 9% per source markets make up 50% of all leisure travel to the Middle East, with India and the United Kingdom the top two inbound international leisure source markets. China is also a critical market, ranking third by value with leisure spend expected to increase by 130% by 2030. Furthermore, tourism nights by visitors from Asia Pacific and Africa, are expected to increase by over 100% between now and outbound travel, Saudi Arabia and Egypt dominate regional flows, while Thailand and the United Kingdom lead as preferred long-haul four largest airlines in the region – Emirates, Etihad Airways, Qatar Airways and Saudia – have placed nearly 780 aircraft orders with Boeing and Airbus, representing major expansions to their existing fleets. This significant investment underscores the region's strategic focus on becoming a global aviation hub and meeting rising passenger demand over the coming Middle East's rise as a global hub for business events is another key highlight of the report, which states that spending on Middle East business travel will grow 1.5 times faster than the global average through to 2030. The region's strategic location at the centre of Asia, Africa, and Europe supports business and leisure travel, with the latter on a particularly strong trajectory for sector plays a vital role in developing the region's reputation for hosting major events. It is expected to experience the second-fastest rate of business travel growth among all global regions, underscoring the increased potential for combining business and leisure travel, or 'bleisure'.Curtis commented: 'At ATM 2025, we recognised the industry's hunger for innovation in travel technology as well as the rising demand for business travel across the region. In response, we launched two dynamic new zones, IBTM@ATM and the Innovation Zone, designed to empower our growing audience to shape the future of travel with the speed and scale our exciting industry demands.'The region is also witnessing unprecedented growth in luxury and lifestyle tourism, attracting a new generation of high-net-worth travellers, drawn to exceptional Middle East hospitality, curated experiences and premium cultural events. According to the report global spending on luxury leisure hospitality is expected to continue growing briskly reaching over US$390 billion by 2028.'Travellers drawn to the Middle East tend to spend more on travel overall, nearly 60% habitually spending on luxury experiences while travelling compared to under 40% among travellers who favour other destinations,' added the more than 170 luxury hotel properties in the Middle East, nearly 100 are situated Abu Dhabi and Dubai, with 22 currently in development. With several luxury properties in the pipeline among Saudi Arabia's Giga projects, the region will continue to serve as a preferred destination for luxury and leisure in the footsteps of the Qatar 2022 World Cup and Dubai Expo 2020, the Middle East region has a proven track record for successfully hosting high-profile entertainment and sports events. According to the ATM Travel Trends report, the strong appetite for sports tourism in the region will lead to a potential growth rate of 63% in the coming years, with the 2034 FIFA World Cup in Saudi Arabia set to continue this to the report, golf, motorsports, football, cycling, and esports are all benefiting from heightened visibility and investment in the region. This surge in sporting and entertainment events is significantly boosting the travel industry, driving increased demand for hotel stays, flights, and related services, creating a ripple effect that supports broader tourism growth. ATM is the leading international travel and tourism event held annually in Dubai. It plays a vital role in shaping the future of global travel. Held at the Dubai World Trade Centre, the 2025 edition welcomed over 55,000 industry professionals from 166 countries, achieving year-on-year growth of 16%. The next edition will take place from 4-7 May 2026.


Al Bawaba
5 days ago
- Al Bawaba
Tinder sparks debate after new 'Height' filter feature
Published June 2nd, 2025 - 09:38 GMT ALBAWABA - Popular dating platform Tinder recently sparked mixed reactions on social media after launching a new feature allowing users to filter their height preferences, which adds to the already present superficial factors its users suffer from. The new feature first gained traction on social media after a user shared a screenshot of it on Reddit. After it went viral, a Tinder spokesperson stated that the feature was rolled out as a global test and was only available to select users, such as Gold and Premium subscribers. Tinder is implementing a height filter for change will allow women to generally filter out men below their preferred height. Follow: @AFpost — AF Post (@AFpost) May 30, 2025 This naturally sparked a wide variety of reactions from shorter men and women alike who found the new feature offensive and degrading. Others demanded a "weight filter" since the popular dating platform incorporated height into its scene. A woman wrote on X (formerly known as Twitter), "As someone who is 5'1, I don't have a height preference. But you know who does? The men over 6'0 specifically seeking out short women." Another added, "men and women alike are derangingly obsessed with men's heights in theory, but it doesn't really translate irl?" According to Tech Crunch, Tinder's Vice President, Philip Price Fry, said in a statement, "We're always listening to what matters most to our Tinder users — and testing the paid height preference is a great example of how we're building with urgency, clarity, and focus." He added, "This is part of a broader effort to help people connect more intentionally on Tinder. Our new product principles guide every decision, and this one speaks directly to a few: prioritizing user outcomes, moving fast, and learning quickly. Not every test becomes a permanent feature, but every test helps us learn how we can deliver smarter, more relevant experiences and push the category forward." © 2000 - 2025 Al Bawaba (