2024-06-12 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Get to know Phishing Defense Coaching, the latest addition to Huntress SAT. This personalized feature helps teach learners how phishing simulations tricked them so they can better identify potential threats.
P0
2024-06-11 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
CVE-2024-37293 affects the AWS Deployment Framework's bootstrap process, potentially allowing privilege escalation if an actor has permissions to change CodeBuild projects or Lambda functions. The issue is fixed in version 4.0 and above. AWS recommends immediate upgrade and temporary mitigation by adding a permissions boundary to roles created by ADF in the management account.
P15
2024-06-11 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS addressed an issue with the Amazon EC2 VM Import Export Service where importing Windows VMs with custom Sysprep answer files resulted in an unprotected backup copy being created, potentially exposing sensitive data. The issue affected imports made before April 12, 2024, and could impact instances launched from affected AMIs.
P0
2024-06-08 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn what’s causing a surge in ransomware attacks on healthcare organizations and find out how new guidelines from HHS are addressing the problem.
P15
2024-06-06 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore the latest ransomware and BEC threats targeting healthcare today. And learn how to navigate emerging threats with insights from our 2024 Cyber Threat Report.
P15
2024-06-05 09:01 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Learn how to protect your devices against evolving iOS threats
P0
2024-06-04 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
As macOS adoption rises, so too do cyber threats against it. That’s why Huntress developed our Managed EDR for macOS, a security solution tailored to the unique challenges of macOS environments.
P0
2024-06-03 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Tenable Research discovered a vulnerability in Azure allowing attackers to bypass firewall rules based on Service Tags by forging requests from trusted services. It affects over 10 Azure services and enables access to internal/private Azure resources. Microsoft updated documentation to clarify Service Tags' security limitations.
P0
2024-05-30 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
[Mise à jour du 31 mai 2024] Des preuves de concept sont désormais disponibles publiquement sur Internet. De plus, l'éditeur indique avoir détecté des tentatives de compromission à partir du 7 avril 2024. **[Publication Initiale]** Une vulnérabilité a été découverte dans les produits Check Point....
P0
2024-05-30 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In the cybersecurity community, we may hear analysts say, “Oh, threat actors change their tactics…”, and at times, they may include the word “always” as part of that statement. However, the question at hand is, “Does the data really show that to be the case?” What are we truly seeing in real-world incidents?
P0
2024-05-28 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Researchers identified non-production AWS API endpoints that could be abused for defense evasion, including silent permission enumeration, accessing account data without logging, and partially bypassing CloudTrail. AWS has remediated specific issues but thousands of such endpoints may exist.
P0
2024-05-28 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Understand the impact of human error across healthcare, and discover how Huntress’ managed solutions can better defend your organization from social engineering scams.
P0
2024-05-27 07:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Amidst the GenAI revolution, how can you harness its potential to boost cybersecurity?
P0
2024-05-23 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Blowing the lid off of interesting adversary-in-the-middle tradecraft observed in the Huntress partner identities.
P0
2024-05-22 12:00 UTC
Government
NIST Cybersecurity Insights · Bill Fisher, Ryan Galluzzo · indexed 2026-08-15 20:45 UTC
Can you recall the last time you opened a bank account? It’s likely you walked into a local bank branch and spoke to a representative who asked for your driver’s license and social security card to verify your identity. Now imagine you want to create a bank account online. The process is likely similar—type in your social security number, take a picture of your driver’s license, and submit both to the bank via their webpage. Seems straightforward, right? Identity verification is important—it pr…
P0
2024-05-22 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore the interesting changes in the world of ransomware and more key findings from Huntress' 2024 Cyber Threat Report.
P15
2024-05-20 07:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Does the GDPR, designed to protect customer data, unintentionally create opportunities for cybercriminals to exploit it?
P0
2024-05-16 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A Microsoft employee accidentally published credentials via a git commit to a public repository. These credentials granted privileged access to an internal Azure Container Registry (ACR) used by Azure, which reportedly held container images utilized by multiple Azure projects, including Azure IoT Edge, Akri, and Apollo. The privileged access could have allowed an attacker to download private images as well as upload new images and (most importantly) overwrite existing ones. In theory, an attack…
P0
2024-05-14 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover how Huntress MDR can respond swiftly to cyber threats and give you the critical time advantage in your ongoing battle against attackers.
P0
2024-05-13 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how you can streamline incident response with Huntress Managed EDR's Active Remediation. Sleep soundly while we thwart threats on your behalf.
P0
2024-05-08 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Get to know Jeff Gill, Emmy award-winning storyteller and Huntress Security Awareness Training animator.
P0
2024-05-07 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Multiple vulnerabilities were uncovered in Azure Health Bot service, Microsoft's health chatbot platform. These could have potentially exposed sensitive user data and granted attackers extensive control, allowing unrestricted code execution as root on the bot backend, unrestricted access to authentication secrets & integration auth providers, unrestricted memory read in the bot backend, exposing sensitive secrets, allowing cross-tenant data access and unrestricted deletion of other tenants' pub…
P0
2024-05-06 14:01 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Fraudsters see potential in generative AI to defraud the gambling industry. Here’s how.
P0
2024-05-03 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Ransomware is spreading like wildfire. Learn about its growing threat to healthcare, its impact on patient care, and how Huntress managed solutions can better protect your organization from cyberattacks.
P15
2024-05-01 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has observed INC ransomware deployed in the past but recent activity indicates a possible continued shift in/or improvement of tactics employed by these threat actors.
P15
2024-04-30 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover the benefits of healthcare security awareness training and find out how Huntress can empower your organization with a culture of security.
P0
2024-04-29 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Microsoft Graph allowed attackers to conduct password-spray attacks without detection. The issue involved switching the 'common' authentication endpoint with that of an unrelated tenant, thereby avoiding the appearance of logon attempts in the victim's logs. This technique could allow attackers to validate user credentials through verbose error messages, but actual successful logons using these credentials would still be recorded in the victims' logs (regardless of endpoint).
P0
2024-04-26 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Microsoft Dynamics 365 Supply Chain Visibility allowed arbitrary takeover of Azure tenants via a malicious reply URL. Clicking a link could grant an attacker directory read access or full tenant control if clicked by a Global Admin, without requiring user consent.
P0
2024-04-25 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
Le 24 avril 2024, Cisco a publié trois avis de sécurité concernant des vulnérabilités affectant les équipements de sécurité ASA et FTD. Deux d'entre eux concernent les vulnérabilités CVE-2024-20353 et CVE-2024-20359 qui sont activement exploitées dans le cadre d'attaques ciblées. La vulnérabilité...
P5
2024-04-25 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
There's a new variant of LightSpy malware targeting macOS. Here, Huntress' macOS researchers dive into the macOS variant of the LightSpy malware, after gaps in recent reports stating that the LightSpy malware strictly targets iOS.
P0