2024-03-05 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has launched Huntress Security Awareness Training (SAT), a new and improved SAT solution tailored to the needs of underserved and resource-strapped organizations. It features memorable, story-driven episodes, making it easier for users to retain knowledge. And since it’s fully managed by Huntress, admins will enjoy it too. Most importantly, Huntress SAT was developed with one overall goal—elevate the security of your small- and medium-sized business (SMB).
P0
2024-03-04 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Over the past year, the Huntress team has posted a number of blog posts related to remote monitoring and management (RMM) tools being installed or abused by threat actors.
P0
2024-03-01 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In an era where cyber threats like SocGholish are becoming increasingly sophisticated, understanding and combating these attacks is crucial for digital safety. This post delves into leveraging Huntress for effectively handling SocGholish threats, outlining a step-by-step approach for IT professionals.
P0
2024-02-29 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The publication of the first blog post led a Huntress SOC analyst to identify and escalate a second, similar incident. A deeper investigation into the activity made it clear that the Huntress SOC had obviated several Trigona ransomware attacks, protecting customers from the impact of a ransomware infection.
P15
2024-02-28 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
This blog post provides a detailed look at the TTPs of a ransomware affiliate operator. In this case, the endpoint had been moved to another infrastructure (as illustrated by various command lines, and confirmed by the partner), so while Huntress SOC analysts reported the activity to the partner, no Huntress customer was impacted by the ransomware deployment.
P15
2024-02-23 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Adversaries have been VERY busy in the wake of the ScreenConnect vulnerabilities (CVE-2024-1709 & CVE-2024-1708). Here’s all the post-exploitation details, tradecraft, and tactics we’ve observed so far!
P5
2024-02-23 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress Guide: Review this guide on how to tell which ScreenConnect Server autoruns are found on your endpoint so you can quickly find and remove them.
P0
2024-02-21 07:58 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB discovers new information stealer targeting Vietnam with rare functionality to filter out Facebook accounts with advertising credits
P0
2024-02-21 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
This blog discusses the Huntress Team's analysis efforts of the two vulnerabilities and software weaknesses in ConnectWise ScreenConnect (CVE-2024-1708 and CVE-2024-1709) and the technical details behind this attack.
P5
2024-02-20 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Stay secure with Huntress! Learn about critical vulnerabilities tied to ConnectWise, including CWE-288 authentication bypass. Patch now to version 23.9.8 for protection.
P15
2024-02-19 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has validated the vulnerabilities referred to in the latest February 19 ConnectWise ScreenConnect advisory. For on-premise users, it is our strongest recommendation to patch and update to ScreenConnect version 23.9.8 immediately.
P0
2024-02-16 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Endpoint detection and response (EDR) is an essential endpoint security solution, but without the right time, resources, and knowledge to remediate threats, your EDR can quickly become a nuisance.
P0
2024-02-15 08:02 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB uncovers the first iOS Trojan harvesting facial recognition data used for unauthorized access to bank accounts. The GoldDigger family grows
P0
2024-02-15 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
\[Mise à jour du 15 mars 2024\] Ajout de précision concernant les défi-réponses NTLM \[Mise à jour du 22 février 2024\] Ajout de recommandations et de précisions sur le fonctionnement de la vulnérabilité. La vulnérabilité CVE-2024-21413 permet à un attaquant de contourner les mesures de sécurité...
P5
2024-02-15 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Healthcare organizations are facing cyber threats at an alarming rate, and as the U.S. Department of Health and Human Services (HHS) introduces new measures for cybersecurity, it’s also time for small- and mid-sized organizations to be proactive in their defense.
P0
2024-02-14 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Evidence of a pre-existing exploit was rendered when the Huntress agent was added to an endpoint. Within minutes, and in part through the use of previously published threat intelligence, analysts were able to identify the issue and make recommendations to the customer to remediate the root cause.
P0
2024-02-13 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
When the ASR service is enabled, it uses an Automation Account with a System-Assigned Managed Identity to manage Site Recovery extensions on VMs. However, the Runbook (a set of scripts for managing extensions) executed by the Automation Account had its job output visible to users, and this output mistakenly included a cleartext Management-scoped Access Token for the System-Assigned Managed Identity, which possesses the Contributor role over the entire Azure subscription. Therefore, lower-privil…
P10
2024-02-09 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
\[Mise à jour du 19 mars 2024\] Le CERT-FR a connaissance de codes d'exploitation publics et de nouvelles tentatives d'exploitation. Le 8 février 2024, Fortinet a publié l'avis de sécurité concernant la vulnérabilité critique CVE-2024-21762 affectant le VPN SSL de FortiOS. Cette vulnérabilité...
P5
2024-02-08 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In addition to social engineering attacks, threat actors target organizations' attack surface, looking for exposed services and applications to gain access into an infrastructure. Microsoft SQL database servers have long been a target for attackers.
P0
2024-02-06 06:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
ResumeLooters gang infects websites with XSS scripts and SQL injections to vacuum up job seekers' personal data and CVs
P0
2024-02-06 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Three privilege escalation and denial-of-service vulnerabilities were discovered in Azure HDinsight, related to their usage of Apache Oozie and Ambari. The root cause of at least one of these vulnerabilities is a flaw in Apache Oozie itself, leading to regex denial-of-service (ReDoS). The other two vulnerabilities could allow an authenticated attacker with HDI cluster access to gain cluster administrator privileges and perform any resource service management operation. The vulnerabilities were …
P15
2024-02-06 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Tips and tricks to hunt down RMM abuse. Remote access tools for persistence. Are RMMs really just command and control? January’s Tradecraft Tuesday was wild. Here’s the recap.
P0
2024-02-05 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
\[Mise à jour du 27 février 2024\] Le 29 janvier 2024 l'ANSSI a été alertée par le BSI que l'éditeur AnyDesk Software GmbH a été victime d'une fuite de données. Le code source des applications développées par l'éditeur ainsi que des certificats et clés privées pourraient avoir été dérobés. De...
P0
2024-02-02 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is tracking concerns regarding the AnyDesk remote control software and provider.
P0
2024-01-31 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Legit Security found a zero-click vulnerability in Azure Pipelines that allows an attacker to access secrets and internal information and perform actions in elevated permissions in the context of a pipeline workflow. This could allow attackers to move laterally in the organization and initiate supply chain attacks. When a pipeline is triggered by a "pipeline resource trigger," it shows in the platform as "Automatically Triggered For …" Instead of running in fork default permissions, preventing …
P0
2024-01-24 12:00 UTC
Government
UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC
An NCSC assessment focusing on how AI will impact the efficacy of cyber operations and the implications for the cyber threat over the next two years.
P0
2024-01-24 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
The system:authenticated group in Kubernetes is a special group that includes all authenticated entities, including human users and service accounts. Anyone who successfully authenticates to the Kubernetes API server, regardless of the authentication method used, will be automatically included in this unique group. Thus, it will share the same roles and permissions of the group. This misunderstanding then creates a significant security loophole when administrators unknowingly bind this group wi…
P0
2024-01-18 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An Indirect Prompt Injection attack can cause the LLM to return markdown tags. This allows an adversary who’s data makes it into the chat context (e.g via an uploaded file) to achieve data exfiltration of the victim’s data by rendering hyperlinks.
P0
2024-01-17 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress analysts continue to observe access to endpoints via legacy TeamViewer installations, and/or compromised TeamViewer credentials.
P15
2024-01-16 07:58 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Inferno Drainer may have shut down in November 2023, but users of the devastating scam-as-a-service platform still pose a risk as they look for other avenues.
P0