Connect with us

Telecom

Sophos XDR Achieves its Best-Ever Results in the MITRE ATT&CK Enterprise 2025 Evaluation

Published

on

Kindly share this post

Sophos, a global leader of innovative security solutions for defeating cyberattacks, has announced its best-ever results in the MITRE ATT&CK Enterprise 2025 Evaluation.

Sophos XDR Achieves its Best-Ever Results in the MITRE ATT&CK Enterprise 2025 Evaluation

MITRE ATT&CK Enterprise 2025 Evaluation

Sophos XDR detected 100% of adversary behaviors (sub-steps)1 across two complex attack scenarios: Scattered Spider, which Sophos X-Ops tracks as GOLD HARVEST, a financially motivated cybercriminal collective, and Mustang Panda, which Sophos X-Ops tracks as BRONZE PRESIDENT, a People’s Republic of China (PRC) espionage group.

The Scattered Spider scenario included activity across Windows, Linux, and AWS cloud environments, and the Mustang Panda scenario focused on Windows only.

Further, Sophos achieved the highest-possible “Technique”-level rating for 86 out of 90 total sub-steps in the evaluation, by generating high-fidelity detections with details on execution, impact, and adversary behavior, providing clear who, what, when, where, how, and why insights.

Sophos XDR achieved:

  • 100% detection coverage1 for all 90 adversary sub-steps across two complex attack scenarios across Windows, Linux, and AWS cloud environments
  • Highest possible (“Technique”) ratings for 86 of 90 sub-steps, demonstrating deep visibility and actionable detections
  • Highest possible (“Technique”) ratings for 61 out of 62 of sub-steps in the Scattered Spider scenario involving identity abuse, cloud exploitation, and data exfiltration

“Scattered Spider and Mustang Panda represent distinct threat profiles that challenge defenders in very different ways,” said Simon Reed, chief research and scientific officer, Sophos. “Achieving full detection coverage against both validates the accuracy and depth of Sophos’ analytics and demonstrates how the company’s AI-native XDR platform converts complex telemetry into clear, actionable intelligence, helping security teams detect, understand, and stop advanced attacks with confidence.

“Sophos’ consistently strong performance in these rigorous evaluations underscores the power and precision of our threat detection and response capabilities, and our commitment to stopping the world’s most sophisticated cyberthreats.

Advertisement

“Over the five years that Sophos has participated in ATT&CK Evaluations, we have continually invested in strengthening our platform, and that investment has translated into stronger results year after year – both in the evaluations, and in the security outcomes we deliver for our customers.”

These results demonstrate the power of the Sophos XDR platform to defend against sophisticated cyber threats. Every day, Sophos processes 223+ terabytes of telemetry in Sophos Central, generating 34+ million detections and automatically blocking 11+ million threats.

This scale of customer insights ensures that Sophos’ detections are being tested and improved to provide continuous protection while delivering stronger outcomes for organizations worldwide.

Understanding The Threat Actors

Sophos X-Ops has tracked GOLD HARVEST (Scattered Spider) since 2022, observing a loosely affiliated cybercriminal collective driven by both financial motives and a desire to elevate their reputations on underground forums.

Advertisement

Despite several arrests, operators and associates continue to launch high-profile attacks across the U.K. and U.S., at times partnering with major Russian-speaking ransomware groups.

Their sophisticated social engineering capabilities enable them to compromise even well-defended organizations, underscoring the importance of strong behavioral detections within modern security operations.

In parallel, Sophos X-Ops has monitored BRONZE PRESIDENT (Mustang Panda) for many years.

This long-running PRC espionage group conducts intelligence-led operations that align closely with priorities of China’s Ministry of State Security. Recent targeting includes activity against Tibetan communities surrounding the Dalai Lama’s 90th birthday, as well as intrusions on Thai government and military offices during periods of heightened regional tension.

BRONZE PRESIDENT remains one of the most active and persistent state-aligned threat actors operating today.

Advertisement

MITRE ATT&CK Evaluations are among the world’s most rigorous independent security tests.

They emulate the tactics, techniques, and procedures (TTPs) used by real-world adversaries to assess each participating vendor’s ability to detect, analyze, and articulate threats in alignment with the MITRE ATT&CK Framework.

These evaluations continually strengthen Sophos’ capabilities for the benefit of the organizations it protects. This was the seventh round of MITRE’s “Enterprise” ATT&CK Evaluation, a product-focused assessment designed to help organizations better understand how security operations solutions like Sophos EDR and Sophos XDR can help them defend against sophisticated, multi-stage attacks.

When evaluating EDR or XDR solutions, Sophos recommends reviewing MITRE ATT&CK Evaluations alongside other independent proof points.

Advertisement

Kindly share this post

Ugo Onwuaso is an ICT enthusiast. He believes technology should be used for general good. He holds a Master of Public Administration (MPA) degree from the Lagos state University. Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

Telecom

Clydestone Ghana Sues MTN Over Mobile Money

Published

on

Kindly share this post

Clydestone Ghana Plc has filed a writ of summons and statement of claim against MTN Ghana, MTN Group Limited and Mobile Money Fintech Limited, alleging unauthorized use of its intellectual property.

The company announced the court action at the Ghana Stock Exchange, confirming proceedings in the Commercial Division of the High Court of Ghana.

The case relates to work commissioned in 2007 that Clydestone alleges was later used without authorisation or compensation.

Clydestone said the claim involves proprietary intellectual property, confidential commercial information and operational methodology developed during the engagement. The company is seeking declarations, damages and equitable remedies.

In a statement, Clydestone said MTN Ghana engaged it in 2007 to develop a commercial and operational framework for a mobile money business.

Advertisement

“The work was developed and delivered by the company’s founder and Group CEO, Paul Jacquaye, and included a full mobile money ecosystem covering the commercial model, operational architecture, implementation methodology and business case.”

Clydestone said the work was commissioned on the understanding that a non-disclosure agreement and memorandum of understanding would be signed.

It alleges these agreements were not finalised despite repeated requests.

The company further alleges MTN Ghana later used its proprietary work and methodology without authorisation or compensation, including in MTN Mobile Money Ghana and other markets.

Clydestone said the alleged use has continued since the launch of MTN Mobile Money Ghana in 2009.

Advertisement

“The wrongful use of that work has been ongoing since 2009. What has changed is the availability of independently verifiable information that documents its scale and commercial significance,” the company said.

It cited the GSMA State of the Industry Report on Mobile Money 2026 and MTN Ghana’s 2025 annual report as evidence of the platform’s scale.

According to Clydestone, the reports show approximately 19.3 million active users and annual revenue of about GHS 6.0 billion ($516m).

The company said it reviewed its records following these publications and concluded there were sufficient grounds to initiate legal proceedings.

It added that it has received no payment or acknowledgement for the work since December 2007, and that pre-action correspondence in 2026 received no substantive response.

Advertisement

“The Board of Directors has unanimously authorised the commencement of these proceedings,” the company said.

Jacquaye said: “This case is about accountability for commissioned intellectual property.

“When independent publications in 2025 and 2026 revealed the scale of the mobile money business, we reviewed all documentation relating to the original engagement and concluded these proceedings were necessary.”

MTN Group Limited, named as a defendant, had not commented at the time of publication.

 

Advertisement

Kindly share this post
Continue Reading

Telecom

Operators Divert Rollout Equipment to Fix Sabotaged Delta Assets Amid Spares Shortage

Published

on

Kindly share this post

In a development that underscores the fragile state of Nigeria’s telecommunications grid, an incident of infrastructure vandalism in Delta State has severely disrupted network connectivity, leaving thousands of subscribers stranded.

Operators Divert Rollout Equipment to Fix Sabotaged Delta Assets Amid Spares Shortage

The breach, where a robber attacked the sites, occurred at an IHS-managed telecom node in the ASB region on July 8, 2026, immediately knocking 33 base stations offline across 2G, 3G, and 4G spectrums.

The situation in the region escalated drastically by morning when a separate fibre-optic cable cut severed primary transmission lines. Because the compromised node serves as a critical fibre convergence point, the secondary fibre cut triggered a cascading failure.

This secondary disruption ballooned the number of dark sites from 33 to 103, temporarily paralysing digital communications, banking, and commerce in the affected communities.

Industry sources reveal that the financial and logistical toll of such incidents is becoming unsustainable for Mobile Network Operators (MNOs).

Advertisement

Currently, network providers are utilising 20 per cent more spare parts than initially budgeted for the fiscal year.

This unpredictable depletion of technical reserves has stripped operators of their supply buffers, making inventory management and financial forecasting increasingly difficult for telecom executives.

Consequently, engineering teams have been forced to cannibalise materials originally designated for network expansion and new site rollouts just to perform emergency restorations on the damaged sites.

This diversion of resources significantly delays the rollout of new infrastructure, stifling the nation’s broader broadband penetration targets and stalling anticipated revenue generation for the telecom companies.

The Nigerian Communications Commission (NCC) recently noted an average of 1,744 weekly attacks on telecom infrastructure nationwide, including over 1,100 fibre cuts.

Advertisement

As operators endure protracted back-and-forth negotiations with insurance firms to cover these sudden hardware losses, stakeholders are intensifying calls for the strict enforcement of the Federal Government’s recent designation of telecom assets as Critical National Information Infrastructure (CNII) to safeguard Quality of Service (QoS).

Kindly share this post
Continue Reading

Telecom

Fact-Check: Elon Musk’s “Tesla Pi Phone” is Internet Rumor

Published

on

Kindly share this post

Viral rumors about a “Tesla Pi Phone” a  new phone, being developed by Elon Musk,  CEO and largest shareholder of Tesla and SpaceX, are entirely fake.

Fact-Check:  Elon Musk’s "Tesla Pi Phone" is Internet Rumor

AI Generated Tesla Pi Phone and Elon Musk

Instead, the tech giant said on Monday it has filed an application with the US Federal Communications Commission for permission to deploy the constellation by 2028.

It said the system would provide voice, messaging, data and emergency services.

A quick fact-check revealed that Tesla Inc. has never manufactured, developed, or released a smartphone.

Videos and articles claiming a release (often priced between $150 and $800 with solar charging or satellite-only connections) rely on AI-generated concept art and recycled internet hoaxes dating back to 2021.

Musk has only mentioned a phone in hypothetical remarks, stating Tesla would build one only if major app stores completely blocked or censored essential apps like X (formerly Twitter).

Advertisement

On Monday however, his company said that “Amazon looks forward to delivering on the promise of D2D [direct-to-device] connectivity, including to the millions of people living, travelling and working in places beyond the reach of existing networks today,”

The filing is the first step from Amazon into satellite mobile connections, which has until now been dominated by SpaceX’s Starlink service.

Musk’s group has signed partnerships with existing operators such as T-Mobile US and the UK’s Virgin Media O2 to provide phone services for customers where their conventional networks do not reach.

Starlink operates across more than 150 countries, offering high-speed internet connections through its constellation of satellites.

 

Advertisement

 

Kindly share this post
Continue Reading

Trending