2025-04-04 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress observed in-the-wild exploitation of CVE-2025-31161, an authentication bypass vulnerability in versions of CrushFTP and further post-exploitation leveraging MeshCentral and other malware.
P15
2025-04-04 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Poor credential hygiene and misconfigurations give hackers an easy way in. See real-world cyber hygiene failures, how attackers exploit them, and how Managed EDR stops them cold.
P0
2025-04-03 07:16 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Know exactly how cybercriminals are orchestrating attacks on Australia’s citizens and digital assets, and why are they a lucrative target?
P0
2025-04-03 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
**\[Mise à jour du 11 avril 2025\]** Le CERT-FR a connaissance d'une preuve de concept publique permettant de provoquer une exécution de code arbitraire à distance. **[Mise à jour du 04 avril 2025]** Le CERT-FR a connaissance d'une preuve de concept publique permettant de provoquer un arrêt du...
P0
2025-04-02 06:02 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Learn about technical details on the ransomware and Storage Software tool, how the criminals use the affiliate panel as well as information on the Hunters International ransomware group from its emergence to the end of the operation.
P15
2025-04-02 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors are enabling the built-in Windows Guest account to maintain persistence. Learn how they gain access and how to detect this activity.
P0
2025-04-01 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how and why Huntress uses ClickHouse for scalable EDR agent analytics, ensuring availability and stability for millions of endpoints while maintaining cost efficiency.
P0
2025-04-01 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An attacker with `run.services.update` and `iam.serviceAccounts.actAs` permissions but without explicit registry access could deploy new revisions of Cloud Run services that pulled private container images stored in the same GCP project. This was possible because Cloud Run uses a service agent with the necessary registry read permissions to retrieve these images, regardless of the caller’s access level. By updating a service revision and injecting malicious commands into the container's argumen…
P10
2025-03-31 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Doing nothing now can cost your business more than money. Learn why proactive cybersecurity steps keep your business resilient and save costs in the long term.
P0
2025-03-28 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how to lock down common endpoint vulnerabilities like weak passwords and unpatched software to secure your systems against threats like phishing and malware.
P0
2025-03-27 08:09 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Stripping down barriers of distance, language, and the unknown, Group-IB’s mission to fight cybercrime brings us to our latest frontier –Latin America. Join us as we uncover the region’s deceptive criminals and tactics.
P0
2025-03-26 09:03 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Scams like Classiscam automate fake websites to steal financial data, exploiting digitalization’s rise in developing countries, making fraud both effective and hard to detect. In this blog, we dissect the inner working of the scam and its prevalence in Central Asia.
P0
2025-03-26 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A publicly exposed GitHub token in CodeQL workflow artifacts could allow attackers to execute malicious code in repositories using CodeQL, potentially leading to source code exfiltration, secrets compromise, and supply chain attacks. The vulnerability stemmed from a debug artifact containing environment variables, which could be downloaded and exploited within a 1-2 second window.
P0
2025-03-25 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A bug in Entra ID restricted management administrative units allowed creating immutable users that couldn't be modified or disabled, even by Global Administrators. This could enable an attacker to protect a compromised account from containment. The issue was caused by a timing vulnerability when removing users from restricted AUs and required specific steps to remediate affected accounts.
P0
2025-03-24 12:47 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how hypothesis-driven threat hunting uncovered stealthy malware. Learn why having a dedicated in-house team or leveraging expert threat hunting services is crucial for modern cybersecurity.
P0
2025-03-24 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
When Celestial Stealer runs in the wild, it looks for Huntress’ own Jai Minton as a potential threat, and this shuts down the infostealer operation if his name is detected.
P20
2025-03-21 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS identified a security issue in the AWS CDK CLI versions 2.172.0-2.178.1 where temporary credentials from custom credential plugins could be printed to console output. This potentially exposes sensitive information to users with access to the console. The issue affects plugins that include an expiration property when returning temporary credentials.
P0
2025-03-20 09:09 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Following the arrest of the cybercriminal behind the aliases ALTDOS, DESORDEN, GHOSTR, and 0mid16B, Group-IB provides a deep dive into his activities, uncovering striking similarities and unmasking the cybercriminal that breached more than 90 instances of data leaks worldwide over the span of four years in operation.
P0
2025-03-14 16:03 UTC
Other
Black Lantern Security · Mark Gaddy · indexed 2026-09-07 17:30 UTC
The Aperio Eslide Manager application is vulnerable to reflected cross-site scripting (XSS), which primarily affects the Leica Web Viewer within the application.
P5
2025-03-13 08:11 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how the ClickFix social engineering attack exploits human psychology to bypass security. Learn how hackers use this tactic and how to protect against it.
P0
2025-03-10 07:14 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how SIM swapping fraud has evolved, how cybercriminals bypass security layers, and the best ways to protect yourself from SIM swap attacks. Learn key prevention tips now.
P0
2025-03-10 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Azure API Connections were found to allow any reader on a subscription to access backend resources through a proxy endpoint, potentially exposing secrets from Key Vaults, databases, and third-party services. This vulnerability affects various Azure services and external APIs, enabling privilege escalation and unauthorized access to sensitive information.
P10
2025-03-10 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore the inner workings of real-world cyberattacks and gain insight into the challenges faced by Huntress threat analysts. Discover the critical role of investigative techniques and their importance in uncovering and addressing these threats.
P0
2025-03-07 19:07 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
New data shows cybersecurity professionals are confident about their remote work safety. See the findings, plus security best practices for remote and hybrid work.
P0
2025-03-07 07:12 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Build resilience with a zero trust cybersecurity model. Leverage your existing infrastructure for stronger security. Get all essential insights to start now.
P0
2025-03-07 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Stopping malware isn’t about catching one-off alerts. It’s about finding and shutting down the persistence that keeps them in your systems. Here’s how Huntress found, fought, and drop-kicked malware that others missed.
P0
2025-03-06 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The Huntress SOC has an average response time of 8 minutes. That means we can investigate threats, send incident reports, and resolve alerts in record time, shutting down attackers before they have a chance to act.
P0
2025-03-04 10:10 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Get the (ABCs) Awareness, Behavior, and Culture of cybersecurity right - an organization's silent drivers of cyber protection.
P0
2025-03-04 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in AWS Temporary Elevated Access Management (TEAM) allows users to modify valid requests and spoof approvals due to improper input validation. This affects versions prior to 1.2.2 of TEAM for AWS IAM Identity Center. AWS has released a fix in version 1.2.2 and recommends customers upgrade to the latest release.
P0
2025-03-04 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore 2024's top cyber threats, including ransomware trends, advanced phishing tactics, and targeted industries. Stay ahead—download the Huntress 2025 Cyber Threat Report now!
P15