Skip to content
Threat Feed

Vendor

Sophos

6 briefs RSS
high advisory

Privilege Escalation Vulnerability in Sophos Endpoint Products for macOS

A local privilege escalation vulnerability, tracked as CVE-2026-18367, affects multiple Sophos endpoint security products on macOS, potentially allowing authenticated local users to gain elevated system privileges.

Intercept X Endpoint +1 vulnerability privilege-escalation macos
1t 1c
high advisory

Local Privilege Escalation in Sophos Endpoint

A local privilege escalation vulnerability in Sophos Endpoint allows an authenticated local attacker to execute arbitrary code with administrative privileges.

Endpoint privilege-escalation windows security-advisory
1t
high advisory

Process Created with an Elevated Token via Token Theft

This rule detects the creation of a process running as SYSTEM while impersonating the token context of a Windows core binary, which adversaries may leverage to escalate privileges and bypass access controls through token theft.

privilege-escalation token-theft windows
2r 1t
medium advisory

Potential Evasion via Windows Filtering Platform Blocking Security Software

Adversaries may add malicious Windows Filtering Platform (WFP) rules to prevent endpoint security solutions from sending telemetry data, impairing defenses, which this rule detects by identifying multiple WFP block events where the process name is associated with endpoint security software.

Windows Filtering Platform +2 defense-evasion windows-filtering-platform endpoint-security
2r 2t
high advisory

Suspicious Registry Hive Access via RegBack

This rule detects attempts to access registry backup hives (SAM, SECURITY, SYSTEM) via RegBack on Windows systems, which can contain or enable access to credential material.

Endpoint Defense +6 credential-access regback windows
2r 1t
medium advisory

LSASS Loading Suspicious DLL

Detection of LSASS loading an unsigned or untrusted DLL, which can indicate credential access attempts by malicious actors targeting sensitive information stored in the LSASS process.

Windows credential-access lsass dll-injection
2r 2t 9i