Other
AWS AppStream Cloudtrail Bypass
Credentials can be extracted from AppStream. When used, they obscure the sourceIP and userName of the initial user. The sourceIP appears as appstream.amazonaws.com.
Credentials can be extracted from AppStream. When used, they obscure the sourceIP and userName of the initial user. The sourceIP appears as appstream.amazonaws.com.
Group-IB Digital Risk Protection uncovers malicious campaign leveraging almost 900 scam pages with potential financial damage estimated at $280,000 over four-month span
A deep dive into the USB-borne Raspberry Robin malware and how Huntress Managed EDR and Managed Antivirus can detect and mitigate this threat.
Uncover the vulnerabilities crippling the airline industry and learn how to implement appropriate countermeasures
Tips from a Mac expert. Discover the best practices users and administrators can use to secure your Mac devices or your Mac fleet.
The automated scam-as-a-service program designed to steal your money and data is still going strong four years after launch
The blog post discusses the evolution of Huntress' data analysis in response to scaling challenges and how we transitioned to a custom detection engine.
With the FBI's takedown of Qakbot malware, we're sharing how the Huntress team developed our own Qakbot vaccine and our commitment to defend forward.
Dive into the basics of threat hunting and tactical malware analysis, and learn how these two practices go hand in hand in cybersecurity.
Secureworks researchers discovered an Azure AD application with an abandoned reply URL related to Microsoft Power Platform. An attacker could leverage this URL to redirect authorization codes, exchange them for access tokens, and call Power Platform API via a middle-tier service to obtain elevated privileges. Microsoft quickly addressed the issue by removing the identified abandoned reply URL from the Azure AD application.
Spoof extensions help cybercriminals target users on trading forums as 130 devices still infected at time of writing
Read expert insights on how to strengthen your cybersecurity strategy with asset inventory and attack surface reduction.
Discover the truth about macOS security. The Huntress Mac Guy answers common macOS security questions like why you should protect your Mac computers.
Actionable guide to hunting for the DLL side-loading threat by using Group-IB MXDR.
Get an inside look at how threat actors use phishing and social engineering tactics to target users and infiltrate organizations.
Learn why traditional antivirus falls short against today's cyber threats on its own and how Huntress offers proactive, effective protection.
Uncover the disruptive nature of Gigabud malware and take proactive measures to mitigate the associated risks
The Huntress team investigated a ransomware attack of a new INC Ransom threat actor group. Here is the activity we observed.
We’ve entered the era of identity security. Are you ready? Explore how to counter evolving threats and protect identities with confidence.
Discover how Huntress caught an attempted business email compromise (BEC) scam that would have cost the company more than $100,000 had it gone undetected.
Discover how today's businesses can conquer security challenges, strengthen defenses and evolve their security beyond traditional antivirus measures.
Huntress is tracking a new PaperCut vulnerability, CVE-2023-39143, which allows full remote code execution on unpatched servers.
Fighting cybercrime is more effective when we work together. Find out more about how you can work with Group-IB to document emerging threats.
A vulnerability in Power Platform could lead to unauthorized access to Custom Code functions used for custom connectors, thereby allowing cross-tenant information disclosure of secrets or other sensitive information if these were embedded in a Custom Code function. The issue occurred as a result of insufficient access control to Azure Function hosts, which are launched as part of the creation and operation of custom connectors in Microsoft’s Power Platform. An attacker who determined the hostna…
Analysis of a highly active hacktivist group with global reach
Dive into how Huntress caught a threat actor adding several legitimate email apps to maintain persistent access to a compromised Microsoft 365 environment.
Discover the key phases of the threat hunting process and how threat hunters structure their hunts to proactively seek out threats.
Is it worth switching to Microsoft Defender Antivirus? Spoiler alert: We think yes! Explore why Defender is a solid AV solution.
Explore how Huntress stopped a massive business email compromise (BEC) attack targeting multiple user accounts within a single organization.
This blog post provides a comprehensive overview of the importance, benefits and challenges of cyber insurance that every MSP should be aware of.