Untitled attachment
https://cyberplace.social/system/media_attachments/files/114/268/471/173/532/870/original/2e2261a255c41905.png
The 2025 Sophos Active Adversary Report is out.
I thread these every year as, personally, I think yearly IR and MDR reports are the best source of data for defenders on _real world_ threats.
https://news.sophos.com/en-us/2025/04/02/2025-sophos-active-adversary-report/
Key take aways for me:
- Despite what you read from scare vendors, ransomware dwell time (initial access to deployment) is still measured days.
It is not hopeless and by active monitoring you *can* stop attackers.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.