2025-05-07 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has verified Samsung’s MagicINFO 9 Server (version 21.1050.0) is vulnerable to a publicly available proof-of-concept (PoC). Understand why MagicINFO 9 Server shouldn’t be internet-facing until a patch is applied.
P0
2025-05-06 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Across the larger cybersecurity community, an often-used adage is that “threat actors always change their tactics.” However, when we really start to look at and track incident data, we begin to see that while some changes may be necessitated based on infrastructures and other challenges the threat actor may encounter, there are times when tactics remain consistent across incidents. Recent investigations into exploitation activity for CVE-2025-31151 and CVE-2025-30406 show similar TTPs across di…
P5
2025-05-06 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A critical vulnerability in AZNFS-mount utility, preinstalled on Azure HPC/AI images, allowed unprivileged users to escalate privileges to root on Linux machines. The flaw existed in versions up to 2.0.10 and involved a SUID binary. Azure classified it as low severity but fixed it in version 2.0.11.
P10
2025-05-05 12:00 UTC
Government
NIST Cybersecurity Insights · Daniel Eliot · indexed 2026-08-15 20:45 UTC
This week we’re celebrating National Small Business Week—which recognizes and celebrates the small and medium-sized business (SMB) community’s significant contributions to the nation. SMBs are a substantial and critical part of the U.S. and global economic and cybersecurity infrastructure. According to the U.S. Small Business Administration’s Office of Advocacy, [1] there are 34.8 million SMBs in the United States (making up 99% of all U.S. businesses). Of those, 81.7% are non-employer firms wi…
P0
2025-05-05 08:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
P0
2025-05-02 17:38 UTC
Other
Black Lantern Security · Paul Mueller · indexed 2026-09-07 17:30 UTC
This article was originally posted to blog.liquidsec.net on June 1, 2021.
P0
2025-05-01 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore how criminal justice principles can improve detection engineering by distinguishing true threats from false positives. And learn how concepts like burden of proof and intent enhance cybersecurity defense strategies.
P0
2025-04-30 06:00 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog on RansomHub provides an overview into how this Ransomware-as-a-Service (RaaS) group operates, including its extortion tactics, affiliate recruitment strategies, and the features of its affiliate panel.
P15
2025-04-29 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress Managed SIEM makes threat detection and response faster and more accessible. Learn about new features, real-world success stories, and how it enhances cybersecurity and compliance.
P0
2025-04-29 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Research uncovered security flaws in default AWS service roles, granting overly broad permissions like full S3 access. This allows privilege escalation, cross-service access, and potential account compromise across services like SageMaker, Glue, and EMR. Attackers could exploit these roles to manipulate critical assets and move laterally within AWS environments. AWS has since updated default policies and documentation to mitigate risks.
P10
2025-04-28 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress Managed ITDR with Rogue Apps proactively protects against identity threats, including malicious OAuth apps. Learn about the surge in identity-based attacks and how to defend your business effectively.
P0
2025-04-28 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
Le 24 avril 2025, SAP a publié un bulletin de sécurité relatif à la vulnérabilité CVE-2025-31324 qui permet l'exécution de code arbitraire à distance pour un utilisateur non authentifié. Cette vulnérabilité est provoquée par un contournement de la politique de sécurité qui permet de télécharger...
P5
2025-04-24 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Protect your business from malware attacks by fostering a security-first culture. Learn how to defend against cyber threats, establish strategies, and train employees to spot malware before it strikes.
P0
2025-04-24 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
As with many tactics within the MITRE ATT&CK framework, credential theft consists of a number of different techniques. Showing what many of them look like on an endpoint helps other security professionals understand what to look for and how to detect and respond to similar activity.
P0
2025-04-23 07:05 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover the latest phishing campaign targeting a major toll road service provider, where cybercriminals use sophisticated evasion techniques to bypass security detections. This in-depth blog reveals how threat actors exploit legitimate platforms and deploy cloaking methods to disguise malicious links, allowing them to evade detection by security solutions. Discover how these sophisticated tactics create highly convincing phishing pages designed to steal victims’ card information, and how to sa…
P0
2025-04-22 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this month’s Tradecraft Tuesday, we talked about how threat actors are finetuning their macOS malware in order to maintain persistent access and avoid detection by Apple’s security features.
P0
2025-04-22 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Tenable discovered a privilege escalation vulnerability in Google Cloud Platform's Cloud Composer service, dubbed ConfusedComposer. It allowed users with composer.environments.update permission to escalate privileges to the default Cloud Build service account by injecting malicious PyPI packages. This could grant broad permissions across the victim's GCP project.
P10
2025-04-18 13:20 UTC
Other
Black Lantern Security · Micheal Reski · indexed 2026-09-07 17:30 UTC
Scanning the Internet with BBOT
P0
2025-04-18 08:04 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Our new LLM-powered chatbot is designed for efficiency and security. Discover how Group-IB AI Assistant enhances threat intelligence workflows and provides security teams with instant insights — without compromising privacy.
P0
2025-04-17 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In a highly interconnected world, remote monitoring and management (RMM) tools are critical to reducing cost and increasing efficiencies. However, these tools pose challenges and even significant risk if not properly managed.
P0
2025-04-16 07:02 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
P0
2025-04-16 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
App Allowlisting is a good preventative software tool, but it's not enough. Learn why a layered security approach with detection and response is crucial to protect against today's cyber threats.
P0
2025-04-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Varonis Threat Labs discovered a vulnerability in Azure SQL Server allowing privileged users to create malicious firewall rules that can delete Azure resources when triggered by admin actions. The exploit involves manipulating rule names via TSQL to inject destructive commands, potentially leading to large-scale data loss in affected Azure accounts.
P0
2025-04-14 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has observed in the wild exploitation against CVE-2025-30406, a weakness due to hardcoded cryptographic keys.
P25
2025-04-11 08:50 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
For modern CISOs, cyber risk management and reduction are nonstop challenges. But this blog offers exactly what you need to build a strategy that empowers you to manage and mitigate threats—cutting through the noise of an otherwise demanding role.
P0
2025-04-11 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
Fortinet a publié le 10 avril 2025 un billet de blogue [1] indiquant l'utilisation d'une technique de post-exploitation qui permet une atteinte à la confidentialité des données de l'ensemble du système des équipements Fortigate affectés. Cette technique repose sur l'utilisation d'un lien...
P0
2025-04-10 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover how a seemingly simple brute force attack led to the uncovering of a suspected ransomware-as-a-service operation. This ecosystem appears to be leveraged by initial access brokers, driving an illicit and complex network of cybercrime.
P15
2025-04-09 06:04 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
P0
2025-04-09 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors are now exploiting both endpoints and identities in the latest cyberattacks. Learn about the rise of identity-based threats and why a combined EDR and ITDR approach is crucial for your cybersecurity.
P0
2025-04-09 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A path traversal vulnerability in AWS SSM Agent's ValidatePluginId function allows attackers to create directories and execute scripts in unintended locations on the filesystem. This could lead to privilege escalation or other malicious activities, as files may be written to or executed from sensitive areas of the system with root privileges.
P10