The latest vulnerability has the identifier CVE-2022-1040 and is rated as critical on the CVSS scale (9.8 points out of 10 possible).
The bug reportedly allows remote attackers to bypass authentication through the firewall’s user portal or web admin and then execute arbitrary code. The vulnerability was discovered by an anonymous researcher who reported it through the official bug bounty program and stated that the issue affects Sophos Firewall 18.5 MR3 (18.5.3) and earlier.
So far, little is known about attacks that exploit this [...]
The database, designed to improve the information security industry, provides metadata, labels and functions for files, and also allows interested parties to download available malware samples for further research.
“A publicly available dataset containing carefully selected samples and relevant metadata is expected to help accelerate research into the use of machine learning for malware detection”, – write Sophos and ReversingLabs [...]