Sophos's Counter Threat Unit found the advertisement on August 24. The cheapest tier answered a direct request for a Python remote access trojan with source code, and the service runs on a local model no provider can patch.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+30
- Incentives55
- Confidence60
Eclypsium tracked 158 infrastructure advisories between August 25 and September 17. The exploited maximum-severity flaws it highlights are authentication bypasses in Cisco's Firewall Management Center and Identity Services Engine.
Reality
- Evidence62
- Adoption72
- Hype gap+14
- Incentives65
- Confidence58
Sophos found the timezone_check implant on compromised Cisco Firewall Management Center devices in August 2026 and assessed it likely Sandworm's work. Generic SysV persistence replaces the firmware trick and widens the appliances it can run on.
Reality
- Evidence63
- Adoption38
- Hype gap+12
- Incentives55
- Confidence58
Sophos CTU reviewed 15 intrusions by GOLD SHERWOOD affiliates and found the same route each time: a working credential on a Fortinet SSL VPN with no MFA, then RDP into domain controllers within hours.
Reality
- Evidence64
- Adoption76
- Hype gap+12
- Incentives70
- Confidence58
Sophos says a June 2026 campaign used winget to install the Deno runtime on victim machines, then used deno.exe to fetch, run and persist remote JavaScript ending in a Python infostealer.
Reality
- Evidence70
- Adoption63
- Hype gap+6
- Incentives62
- Confidence65
Attackers installed a legitimate JavaScript and TypeScript runtime on victim hosts to run payloads in memory. The middle of the chain barely varied, which is where detection work belongs.
Reality
- Evidence62
- Adoption41
- Hype gap+12
- Incentives58
- Confidence55