Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Sophos: Why Your Firewall May Be Your Biggest Security Risk

Sophos
09/21/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


weakest component or its weakest device. So with that said I'm going to hand the time over and introduce you to my good friend Anurag Singh who is going to talk through some information as to how Sophos is helping to lower risk especially as it relates to your edge devices and those things that are exposed to the internet. So with that time I'm going to hand that over to Anurag. Is your firewall reducing a cyber security risk or introducing it? Is your firewall defending your network like it is supposed to or acting like a Trojan horse and inviting attackers in silently? That's what we'll try and figure out together in the next 10 minutes. Are you guys ready for this ride? Okay, let's do it. We are going to be methodical about this. We are going to first state a problem or establish a problem. We are going to then validate if it is a real problem or I'm just making it up to sell a product, right? How are we going to validate it? Using publicly available information. Then we are going to talk about the solution and then we'll also validate the solution. If that solution has been out there in the field for a couple of years, so we have a way of validating if it's actually solving the problem or not. Good? Okay, let's dive in. So if you pick any LLM model of your choice, Chad, GPT, Grog, Gemini, whichever one you use every day, just ask this simple question. What are the top five initial access methods that threat actors have been using to gain access into your network in last three years? So what it's going to do, it's going to go out and read reports, yearly reports released by vendors like us. Like we release active adversary report, Palo Alto releases one, CrowdStrike releases one, Microsoft, Google Mandiant, Verizon, tons of other sources. Like almost all these companies around, they all release these reports. They have insights in those. One of those things is, how are the attackers getting in? Or in other words, initial access methods. So what you'll see in this, the top one, exploitation of internet facing application. Guess what? Your edge device or your firewall is internet facing. It has a WAN public IP, meaning someone sitting on the internet can scan the public IP and see what it is responding to. Meaning if you have remote access VPN service enabled, user portal enabled, the UI access for the firewall enabled or SSH access of the firewall enabled, they are going to get a response. And if there's a vulnerability in there, they're going to try and exploit it and get in the network. Not just once, it shows up again at number five, exposed remote services. So if your firewall has RDP SSH enabled or remote services like VPN enabled, so if a problem shows up twice in top five, I think it's pretty safe to say using public data that we have validated the problem. What do you guys agree? Sounds good? Okay. Let's use more information to validate this further. This is another, if this LLM that you are using, if you ask another question, okay attacker gained access to the firewall, what are they going to do next? So this is some of the recent exploits of firewall vendors and their VPN service. In general, the goal is they gain initial access, then they would try and gain root access of your firewall. From there, still username, passwords, credentials, firewall config. Essentially use that as foothold in your network and from there, slowly move laterally inside the network. These are some other sources, specific ones like Verizon Data Breach, Mendian, Sophos, Coalition, CyberThreat Index, CrowdStrike, they're all talking about key findings 2326. How are the attackers getting in? Exploitation of vulnerabilities, credential abuse, internet facing application, external remote services, remote access services. So specific reports validate that as well. Okay, so here specifically now, we are going to talk about Sophos firewall vulnerability first. So in our firewall in 2020, a specific vulnerability was found by international APT groups and they used it to exploit vulnerability and gain access to some of our customers. That is how this whole thing started when we realized that this is a big problem and we need to address it. So to establish the problem, what are we saying? The firewalls are the problem? No, we still need the firewalls. We cannot get rid of the firewalls. Are we saying that the vendors are bad? No, wherever there's a hardware and software, the vulnerabilities will always exist. So what we need to improve upon or what is the problem is vulnerability management. So the problem statement is better vulnerability management in firewalls. In this case, it ran for like four or five years and we had to involve FBI and even few people got charged for this, right? From there, other news about other vendors, similar big breaches, multiple firewalls being used as an entry point into the attack or networks. It has got to the point where in last one week, National Cyber Security Center of UK, which is equivalent to US CISA, came out and said, we need better logging on networking devices. We need tamper-proof logging on networking devices because there are so many breaches happening because of networking devices or through networking devices. We need better logging and make sure attackers are not able to delete those logs. Then, other than the company that is under attack and maybe the MDR company that is there to defend them, who else is very interested in understanding if attackers are getting into your environment, how are they getting in? Any guesses? Cyber insurance companies because like any insurance company, they don't want to pay out, right? So if they can dig deeper and figure out how the attackers getting in, if they can add a clause or force your hand to fix that, then they will definitely do that. So this is a company called Coalition based out of Massachusetts that released a report within last year saying that out of every 10 ransom payments that they had to release for their customers, six were because of compromised VPN or firewall. So about 60% happened because of firewall. This is another vendor saying 90% of ransomware incidents happen because of firewall exploits. Maybe we can dispute the number, maybe this number is too high, but you cannot dispute that it's in top five and it's happening a lot. So I believe we have done enough to validate the problem. The problem is validated at this point. Would you guys agree? Okay. So the problem was already bad, it was in top five. It's going to get worse because now there are frontier AI models available that will speed up the number of vulnerabilities identified and very quickly even a non-technical person can give a couple of prompts that, hey, write a code to exploit this vulnerability and it will write it. It doesn't even have to be high or critical vulnerability. It will say, find three or four medium or low vulnerabilities, chain them together and get me access of this network. And it's literally doing it. So the problem is only going to get worse. So let's talk about solution. What is the solution? I'm sure you have heard secure by design before, right? Every company, every cybersecurity company talks about secure by design, secure by design. In this case, I'm going to demonstrate that we are walking the talk. We are not just talking about it, we are actually implementing it in our product. So the solution, what is the solution? The first solution is automated hot fixes. So let me ask you this question. I'm sure you're familiar with or you might manage some sort of endpoint or antivirus on your devices, right? Have you recently upgraded your antivirus or endpoint in the last two, three years? No, because they're all cloud managed and the vendor, whoever is providing the endpoint, they automatically upgrade it for you. So if there's a vulnerability, you don't have to worry about it. They just find it, fix it, patch it. But for the firewall, that's not the case. Endpoint is sitting inside your network. It has a private IP. Firewall is out. It has public IP, but endpoint has better vulnerability management than the firewall. Why is that? That's the question we are trying to address and fix. So in our firewall, we added automated patching. So an example of automatic patching would be, let's say there is a vulnerability in our syslog database, in our firewall where we keep our logs. How would it look like? We will upgrade the logging database and only restart the logging daemon, the logging service, not the whole firewall. So we're not changing your version. You're not rebooting the whole firewall, bringing downtime. Just a few seconds for one service. That's it. It is enabled by default, so you don't have to opt in, but you do have a choice of opting out if you don't like it. Does this address the whole problem? No, it doesn't, because we are relying on the fact that some security researcher will find the vulnerability and report it to us. What if it's a nation-state actor? They'll find the vulnerability and they will keep it to themselves because they want to use it to gain access into the country that they don't like and their infrastructure. So for that, what we did at the crux of it, any firewall is just a custom Linux box, right? Whichever firewall you're thinking of or you might be using is a custom Linux box. Vendors like Sophos, Trend, and many others, they do provide endpoint agent for Linux and Windows servers and other kinds of servers. Why not put that endpoint agent in the Linux server that is the firewall? So that is exactly what we did here with system integrity monitoring. We took our Linux endpoint agent and we put it into our firewall OS and started monitoring it, like doing EDR monitoring for it. Unauthorized access, file modification, privilege escalation, any vulnerable library being exploited, all that is being monitored for free. Even if you don't have our MDR service, if you have our Sophos firewall, it will be monitored for free. So those are the two main features, two solutions to secure your security device. In addition to that, we do other things, for example, hardening the hardware itself. For example, the operating system is compartmentalized, modularized, so if attackers gain access to one part of the OS, it's not easy to get to the other part. In addition to that, we have cloud management, which means you can simply disable the WAN access of the firewall, SSH and UI, and simply access it from our cloud management. Any questions here? This is the most important slide. Okay, sounds good. So in addition to that, in our firewall UI, this is not about the device of the security itself, but this is, as a customer, you don't have to become an expert in our firewall. What we did is we created one page called health check, and all the important features are listed here, and we are showing whether it's on, turned on, or off, and we are matching it against CIS benchmark. So you can see if your important settings are enabled, disabled, and whichever ones are not enabled, you can quickly click on it, get to that feature, and turn it on. So that's the solution. So we established the problem, we validated the problem, we talked about the solution, now it's time to validate the solution. So how do we validate the solution? Again, the same LLM model, any one of your choice, go in and ask this question, give me a list of devices or networks that have been breached in last two years because of the exploitation of Sophos firewall vulnerability. You will find nothing. Change that to five years, you'll find stuff because of the CV that we talked about earlier. Change it to any other firewall vendor name, and you'll find a big list. So that's how we know that our solution is working, and you can validate it to yourself. So how did we get to this point? So that CV 2020 that I showed you, we have dubbed it as Project Pacific Rim. We don't really have enough time to talk about it, but there's ton of blogs, videos, information that we have published transparently. You can go and read about it, but essentially that became a necessity for us, so this innovation came out of necessity of auto-patching, monitoring the OS, hardening the firewall itself. So I want you to walk away from here with this message. Demand a better firewall, right? If you do it yourself, ask it to yourself. If you have an IT team, ask them. Have a better firewall that does auto-patching for you, just like your endpoint does, that does OS monitoring, just like you do endpoint DDR XTR monitoring, and has a hardened OS. Thank you for your time. Have fun at Black Hat. Take care, guys. A round of applause for Anurag. Thank you very much, Anurag. Appreciate you spending your time here, and thank you all for joining us here.

TL;DR

  • Firewall exploitation ranks in the top five initial access methods across major threat intelligence reports, with Coalition data showing 60% of ransomware payments linked to compromised VPN or firewall devices.
  • Sophos developed automated hotfixes that patch individual firewall services without rebooting the device, bringing endpoint-style vulnerability management to internet-facing edge devices for the first time.
  • A built-in Linux endpoint agent now monitors the Sophos Firewall OS for unauthorized access, file modification, and privilege escalation — included free with the firewall, no MDR subscription required.
  • AI-assisted exploitation is lowering the attacker skill threshold: frontier models can chain medium and low-severity vulnerabilities to gain network access, making proactive firewall hardening more urgent than ever.

Firewalls as an Attack Vector

Recorded live at Black Hat 2026, this session with Sophos product expert Anurag Singh opens with a provocative question: is your firewall reducing cyber risk or actively introducing it? Singh builds his case using publicly available threat intelligence — including reports from Sophos, CrowdStrike, Verizon, Google Mandiant, and Coalition — to demonstrate that exploitation of internet-facing applications and exposed remote services consistently rank in the top five initial access methods used by threat actors. Because firewalls sit on public IP addresses with services like VPN, SSH, and management UIs exposed, they are prime targets. Coalition's research found that 60% of ransom payments they covered were tied to compromised VPN or firewall devices, underscoring the scale of the problem. Singh also flags that AI-assisted exploitation is accelerating the threat: frontier models can now chain medium and low-severity vulnerabilities together to gain network access, lowering the bar for attackers significantly.

Sophos's Response: Automated Patching and OS Monitoring

Singh traces Sophos's innovation directly to a 2020 vulnerability exploited by international APT groups — internally dubbed Project Pacific Rim — which led to FBI involvement and criminal charges. That incident forced a rethink of firewall vulnerability management. The core insight: endpoint agents receive automatic, cloud-managed patches without user intervention, yet firewalls — which are more exposed — historically required manual firmware upgrades. Sophos addressed this gap with automated hotfixes that patch individual services (such as the logging daemon) without rebooting the device, minimizing downtime and enabled by default. Complementing this, Sophos embedded its Linux endpoint agent directly into the firewall OS as a system integrity monitoring layer, providing EDR-style detection of unauthorized access, file modification, privilege escalation, and vulnerable library exploitation — included at no additional cost with Sophos Firewall, even without an MDR subscription.

Hardening, Cloud Management, and Validation

Beyond patching and monitoring, Sophos has compartmentalized the firewall OS so that a breach of one component does not automatically expose others. Cloud management enables administrators to disable WAN-facing SSH and UI access entirely, reducing the attack surface without losing remote manageability. A single health check page in the firewall UI maps active settings against CIS benchmarks, giving administrators a clear view of which security controls are enabled or disabled and allowing one-click remediation. Singh validates the solution's effectiveness by challenging the audience to query any LLM for Sophos firewall breaches in the past two years — asserting the results will be empty — while the same query against other firewall vendors returns a substantial list. The session closes with a call to action: demand that firewalls meet the same automated vulnerability management standards already expected of endpoint security tools.

Chapters

0:00 - Introduction and Framing
0:38 - The Core Problem: Firewalls as Entry Points
2:00 - Validating the Threat with Public Data
4:35 - Project Pacific Rim and the 2020 CVE
7:39 - AI Accelerating Firewall Exploitation
8:21 - Solution: Automated Hotfixes and OS Monitoring
11:35 - Hardening, Cloud Management, and Health Checks
12:56 - Validating the Solution and Call to Action

Key Quotes

0:38 "Is your firewall reducing a cyber security risk or introducing it? Is your firewall defending your network like it is supposed to or acting like a Trojan horse and inviting attackers in silently? ..."
7:05 "Out of every 10 ransom payments that they had to release for their customers, six were because of compromised VPN or firewall. So about 60% happened because of firewall."
7:39 "The problem was already bad, it was in top five. It's going to get worse because now there are frontier AI models available that will speed up the number of vulnerabilities identified and very quickly even a non-technical person can give a couple of prompts."
9:13 "Endpoint is sitting inside your network. It has a private IP. Firewall is out. It has public IP, but endpoint has better vulnerability management than the firewall. Why is that? That's the question we are trying to address and fix."
13:59 "Demand a better firewall. Have a better firewall that does auto-patching for you, just like your endpoint does, that does OS monitoring, just like you do endpoint DDR XTR monitoring, and has a hardened OS."

FAQ

Does automated hotfix patching require a reboot or cause downtime?

No. Sophos's automated hotfixes patch individual services — for example, restarting only the logging daemon if a logging database vulnerability is found — without rebooting the entire firewall. The process takes only a few seconds and does not change the firmware version. It is enabled by default but can be opted out of.

Do I need a Sophos MDR subscription to get OS-level firewall monitoring?

No. System integrity monitoring — which embeds a Linux endpoint agent into the Sophos Firewall OS to detect unauthorized access, file modification, and privilege escalation — is included at no additional cost with Sophos Firewall, regardless of whether you have an MDR subscription.


Categories:
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Network Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Network Security
  • Vulnerability Management
  • Data Protection
  • Security Operations
  • Technical Deep Dive
  • Demo
  • Firewall security
  • Edge device vulnerability management
  • Initial access techniques
  • Automated patch management
  • OS integrity monitoring
  • Network hardening
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Sophos: Why Your Firewall May Be Your Biggest Security Risk

              Industry Events (Sponsor Hosted)

              • Sep
                23

                Invisible Data: The Key to Effective Protection Strategies

                09/23/202601:00 PM ET
                • Sep
                  29

                  Embracing AI Adoption While Ensuring Robust Security Measures

                  09/29/202612:00 PM ET
                  • Oct
                    15

                    Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                    10/15/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/23/2026
                      01:00 PM
                      09/23/2026
                      Invisible Data: The Key to Effective Protection Strategies
                      https://www.truthinit.com/index.php/channel/2087/invisible-data-the-key-to-effective-protection-strategies/
                    • 09/29/2026
                      12:00 PM
                      09/29/2026
                      Embracing AI Adoption While Ensuring Robust Security Measures
                      https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Enhanced Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-enhanced-visibility-and-control-in-your-operations/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version