XG Firewall

Mentioned 2 times across 1 podcast this week

This Week's Pulse

Sophos announced a 10% price increase for its XG Firewall hardware and subscriptions, effective July 1, 2026. This follows the May 6 release of Sophos Firewall Config Studio v2.5, a tool aimed at streamlining firewall management.

Despite the new features, the XG Firewall continues to face scrutiny regarding its legacy architecture. On Darknet Diaries, speaker_3 noted, "The Sophos has a firewall called the XG Firewall... it's running a version of Linux in it. It has a UI that's running on the front of it so that you can manage it."

The technical debt remains a focal point for critics. Craig Jones explained on Darknet Diaries that "the Cyberoam code is the predecessor to the XG Firewall code... they were using some of that still to find additional vulnerabilities." This history is particularly relevant as the device remains on the CISA Known Exploited Vulnerabilities catalog.

Users are now forced to weigh the benefits of the updated Sophos Firewall Config Studio against the rising cost of ownership and the persistent security concerns listed by CISA. The coming weeks will show if enterprise customers accept the price hike or look for alternatives that lack the Cyberoam-era baggage.

Where it's discussed

174: Pacific Rim

Darknet Diaries

speaker_3neutralfrom “Sophos and Cyberoam Security Intrusions

A Sophos product that was the subject of a security incident involving a SQL injection vulnerability.

So the s- Sophos has a firewall called the XG Firewall. At, at this point it was just called the XG Firewall, and the f- firewall has its own operating system. It's r- it's running a version of Linux in it. It has a UI that's running on the front of it so that

Craig Jonesneutralfrom “Sophos Firewall Security Breach Analysis

A Sophos product that succeeded Cyberoam and was also targeted by threat actors.

Well, it turns out that the Cyberoam code is the predecessor to the XG Firewall code. So Cyberoam was the company that Sophos bought, and their product became the XG Firewall. So when back in 2018, we're talking about how the threat actors had stolen the sourc