2024-03-13 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
“Double extortion” attacks, often perpetrated by ransomware threat actors, include data exfiltration prior to file encryption. Huntress analysts have observed various means of data exfiltration, but recently observed the use of a legitimate backup application seen by others to be associated with a Noberus/ALPHV ransomware affiliate.
P15
2024-03-04 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Over the past year, the Huntress team has posted a number of blog posts related to remote monitoring and management (RMM) tools being installed or abused by threat actors.
P0
2024-02-08 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In addition to social engineering attacks, threat actors target organizations' attack surface, looking for exposed services and applications to gain access into an infrastructure. Microsoft SQL database servers have long been a target for attackers.
P0
2023-12-14 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress analysts recently observed a novel set of tactics, techniques, and procedures used by a threat actor for data collection and exfiltration.
P0
2023-11-28 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors frequently make use of native utilities during incidents. However, this blog post discusses a rarely-observed means of data exfiltration.
P0
2023-11-09 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has uncovered a series of unauthorized access, revealing a threat actor using ScreenConnect to infiltrate multiple healthcare organizations.
P0
2023-11-08 07:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Take a deep dive into the operations of one of the most active players in the Ransomware-as-a-Service market.
P15
2023-11-02 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Amazon Managed Workflows for Apache Airflow (MWAA) and the Task instance details page in the Google Composer UI were not patched against CVE-2023-29247 (Stored XSS). This meant that post-authentication, a threat actor could have exploited this to store their JavaScript payload in the victim's managed Apache Airflow instance and run JavaScript on behalf of the victim (who could be an admin or another user with higher permissions than the threat actor, thereby leading to privilege escalation). Wi…
P15
2023-08-17 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Get an inside look at how threat actors use phishing and social engineering tactics to target users and infiltrate organizations.
P0
2023-08-11 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The Huntress team investigated a ransomware attack of a new INC Ransom threat actor group. Here is the activity we observed.
P15
2023-08-03 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Dive into how Huntress caught a threat actor adding several legitimate email apps to maintain persistent access to a compromised Microsoft 365 environment.
P0
2023-06-08 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore the recent disclosures concerning Volt Typhoon, a threat actor engaged in the widespread exploitation of external-facing services and network appliances.
P0
2023-05-18 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Threat actors in possession of IAM active credentials that had the power to update S3 bucket policies could have bypassed GuardDuty’s S3 detections and silently updated permissions for S3 resources, resulting in a bucket configuration that allowed anonymous data access. This gap in GuardDuty’s alert coverage occurred only when S3’s Block Public Access was not enabled on the account or the bucket, and when KMS-based server-side bucket encryption was not in use. In order to trigger on opening pub…
P0
2023-04-21 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Google users can find and install third-party OAuth applications from Google Marketplace that are integrated with Google Workspace. Each OAuth application client in Google is associated with a GCP project. A bug in the way a GCP project enters a "pending deletion" state when deleted, could have allowed threat actors to make a malicious application invisible and unremovable from the user's account. If an attacker had managed to install an application in an account (e.g., through a phishing attac…
P0
2022-08-16 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
We unravel an investigation that details one way threat actors are able to gather cleartext passwords via NPPSPY.
P0
2021-10-22 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress discovered threat actors abusing a blind SQL injection vulnerability in BillQuick Web Suite. Follow our analysis and latest findings in this blog.
P0
2021-04-05 08:45 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
The analysis of phishing campaigns carried out by a new threat actor
P0
2020-05-14 14:09 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
The success of enterprise ransomware attacks has motivated more and more threat actors to join the game.
P15
2019-05-29 07:08 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
How the hacker group MuddyWater attacked a Turkish manufacturer of military electronics
P0
2018-09-05 11:51 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB has exposed the attacks committed by Silence cybercriminal group.
P0
2017-12-11 12:12 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB has uncovered a hacker group attacking banks in the USA and Russia
P0
2017-08-02 12:29 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB reveals the identity of alleged members of the Islamic hacker group United Islamic Cyber Force
P0