2023-06-01 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Our team is tracking in-the-wild exploitation of a zero-day vulnerability against Progress' MOVEit Transfer web application that allows for escalated privileges and unauthorized access.
P40
2023-05-31 07:58 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
APT Dark Pink is back with 5 victims in new countries.
P0
2023-05-30 09:00 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Security misconfiguration, excessive data exposure, and injections top three API vulnerability types for financial and tech firms
P0
2023-05-30 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has recently seen an uptick in compromised TeamViewer accounts being used to install the XMRig cryptocurrency miner. Dive into the analysis here.
P0
2023-05-24 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability discovered in GCP's Cloud SQL service allowed customer administrator accounts to create triggers in the tempdb database and use those to gain sysadmin privileges in the instance. This could be abused to result in complete control of the database engine and access to the host OS. An attacker could have listed and accessed files in the host OS, including any secrets on the machine, as well as gaining access to service agents. However, it is unclear from the report if this level of…
P10
2023-05-23 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Is RMM the same as MDM? Learn the key differences between RMM and MDM for macOS management and how Huntress works with both to keep your endpoints secure.
P0
2023-05-18 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Threat actors in possession of IAM active credentials that had the power to update S3 bucket policies could have bypassed GuardDuty’s S3 detections and silently updated permissions for S3 resources, resulting in a bucket configuration that allowed anonymous data access. This gap in GuardDuty’s alert coverage occurred only when S3’s Block Public Access was not enabled on the account or the bucket, and when KMS-based server-side bucket encryption was not in use. In order to trigger on opening pub…
P0
2023-05-17 07:57 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Bridewell and Group-IB expose the APT’s unknown infrastructure
P0
2023-05-16 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has raised $60M in Series C funding, led by Sapphire Ventures with participation from existing investors Forgepoint Capital and JMI Equity.
P0
2023-05-15 08:20 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
All you need to know about Qilin ransomware and its operations targeting critical sectors.
P15
2023-05-09 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Need some CyberChef tips? You've come to the right blog.
P0
2023-05-04 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Azure API Management is an API gateway service meant to help organizations to create, manage, secure, and monitor APIs across all of their environments. Researchers found three high severity vulnerabilities in the service, two of which are SSRF (Server Side Request Forgery) vulnerabilities, and the third is a path traversal bug. The SSRF issues affected the Azure API Management CORS proxy (which handles schema retrieval) and hosting proxy (which routes API requests to the correct server). An at…
P0
2023-05-02 08:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
New and modified malware detonation capabilities in Group-IB’s Managed XDR and Business Email Protection solutions for precise threat detection and analysis
P0
2023-05-02 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Watch the webinar recording for an overview of the Huntress platform for our community—and how our human analysts make all the difference.
P0
2023-04-25 04:19 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB Digital Risk Protection discovers more than 3,200 fake Facebook profiles in ongoing phishing campaign that sees scammers impersonate Meta support staff
P0
2023-04-25 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An AWS-recommended IAM policy that enforced MFA on access keys could have been bypassed due to a change implemented by AWS in November 2022 that allowed IAM users to assign multiple MFA devices to their account. Prior to this change, an attacker that had compromised credentials could not create and assign a new MFA device to bypass the MFA requirement as they would need to first deactivate the user’s existing MFA device. Organisations using SSO which enforces MFA, either via an external IdP or …
P0
2023-04-25 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
It would take hours to cover everything endpoint security can do, but this blog covers it in a few aspects: a high-level overview, a deeper dive and how detection engineers can leverage it.
P0
2023-04-21 03:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
How to investigate phishing campaigns
P0
2023-04-21 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Google users can find and install third-party OAuth applications from Google Marketplace that are integrated with Google Workspace. Each OAuth application client in Google is associated with a GCP project. A bug in the way a GCP project enters a "pending deletion" state when deleted, could have allowed threat actors to make a malicious application invisible and unremovable from the user's account. If an attacker had managed to install an application in an account (e.g., through a phishing attac…
P0
2023-04-21 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Our team is tracking in-the-wild exploitation of zero-day vulnerabilities against PaperCut MF/NG which allow for unauthenticated remote code execution due to an authentication bypass.
P50
2023-04-19 12:00 UTC
Government
UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC
Report informing readers about the threat to UK industry and society from commercial cyber tools and services.
P0
2023-04-19 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Asset Key Thief was a Google Cloud privilege escalation vulnerability that enabled principals with the "Cloud Asset Viewer" role (or other roles with the `cloudasset.assets.searchAllResources` permission) on the Cloud Asset Inventory API, at the Project, Folder, or Organization level to view and exfiltrate any user-managed Service Account private key under a project within the same Google Cloud environment that had been created or rotated up to a maximum of 12 hours ago. Access to Service Accou…
P10
2023-04-19 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
ApsaraDB and AnalyticDB contained several vulnerabilities in their PostgreSQL offerings which ultimately allowed unauthorized access to other tenants' databases and the ability to perform a supply-chain attack on both services, which in turn would have allowed remote code execution (RCE) as well. Both services implemented multi-tenancy through a shared K8s cluster, but contained several bugs related to tenant isolation which an attacker could chain together to achieve the above impact. In Apsar…
P25
2023-04-18 07:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB analysts discovered the new MuddyWater infrastructure while researching the pro-state group’s use of the legitimate SimpleHelp tool.
P0
2023-04-13 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is bringing the hunt to Australia and New Zealand! Hear from the Regional Director of Huntress ANZ what this expansion means.
P0
2023-04-11 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Your security tools are just as likely to be attacked as anything else. This blog dives into traitorware and how it's used to live off the land.
P0
2023-04-06 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is SOC2, GDPR and CCPA Compliant. Read what this means for us—and for our partners.
P0
2023-04-04 17:24 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB uncovers a new stealthy ransomware strain
P15
2023-04-04 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
We're so excited to say we're now securing more than two million endpoints!
P0
2023-04-03 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
The API action ListObservabilityConfigurationsForAccount did not properly validate the "AccountId" parameter that was passed to it. As a result, any account ID could be provided and the API would return the information for that account. This would leak minor information about the observability configuration for App Runner in the account.
P0