Actors abuse Faronics Deploy in phishing campaigns to run PowerShell and deploy ScreenConnect while evading detection with trusted tools.
Huntress investigated attacks in which threat actors abuse Faronics Deploy, a legitimate remote management tool, as part of phishing-driven intrusions. The chain uses the trusted deployment tool to launch PowerShell commands and deploy ScreenConnect for remote access. Leveraging signed, legitimate software helps the actors blend in and evade detection.
PaperCut warns of active zero-day exploitation chaining CVE-2026-81578 and CVE-2026-82078 for pre-auth remote code execution in NG/MF print management.
PaperCut Software confirmed attackers are chaining two vulnerabilities in PaperCut NG and MF: CVE-2026-81578, an improper access control flaw in the web management interface allowing unauthenticated configuration changes, and CVE-2026-82078, unsafe dynamic class loading in database connection utilities enabling arbitrary Java bytecode execution. Huntress reproduced a pre-authentication remote configuration takeover and full RCE chain against PaperCut NG 25.0.11.75758 and observed limited exploitation at two customers, including post-exploitation whoami and ver commands. The vendor released Emergency Patch Release 2 with additional hardening and urged restricting Application Server web access to trusted IPs. In 2023, Clop and LockBit affiliates abused CVE-2023-27350 and CVE-2023-27351 in the same software.
Huntress expanded its API from six read-only endpoints into an automation platform adding webhooks and Model Context Protocol support.
Huntress announced a major expansion of its API, growing from six read-only endpoints into a full integration and automation platform. New capabilities include webhook support, additional endpoints, and MCP (Model Context Protocol) support to enable AI-assisted automation. The update targets defenders building integrations and automated workflows around the Huntress managed detection and response platform.
Huntress analyzes the Australian Signals Directorate's 2026 board cyber priorities and frontier AI guidance on managing AI-era threats.
Huntress analyzed the Australian Signals Directorate's 2026 boardroom cyber priorities and its guidance on frontier AI risk. The piece argues that rapid AI adoption alone will not counter AI-era cyber threats and outlines what boards should focus on. No specific incident, vulnerability, or regulation change is described.
PaperCut warns of active exploitation of CVE-2026-82078 and CVE-2026-81578 in NG/MF print management software used by universities, corporations, and governments.
PaperCut issued an emergency advisory saying vulnerabilities in PaperCut NG and MF, tracked as CVE-2026-82078 and CVE-2026-81578 with severity scores above 8.8, are under active exploitation with confirmed customer incidents. Huntress reported at least two customers impacted, and an initial patch was revised with input from Huntress and watchTowr researchers. PaperCut software is widely deployed at universities, corporations, and governments managing printers from Canon, Epson, Xerox, and Brother, and the vendor urged removing server web interfaces from the public internet. Previous PaperCut flaws were used by ransomware gangs like Bl00dy and Clop, and CISA has warned the education sector is particularly exposed.
Huntress outlines the strategy behind phishing simulations to help organizations build resilience against real phishing threats.
Huntress published guidance on the strategy behind phishing simulation programs. The piece argues simulations should mirror real attacker behavior to train employees and measure organizational resilience. The content promotes Huntress's security awareness training offering.
Huntress published a beginner's guide to phishing simulation training that simulates real phishing attacks to protect organizations.
Huntress released a beginner's guide to phishing simulation training for employees. The guide covers the essentials of simulating real phishing attacks to improve organizational security awareness. It serves as educational content tied to Huntress's training products.
Huntress details modern phishing tactics including ClickFix, browser-in-the-browser, and OAuth consent phishing beyond basic credential harvesting.
Huntress describes a shift in phishing attacks beyond basic credential harvesting toward advanced tactics. Covered techniques include ClickFix social engineering, browser-in-the-browser (BitB) attacks, and OAuth consent phishing. The post recommends training users on these patterns through Huntress SAT simulations.
Huntress publishes an employee spotlight on cybersecurity advisor Ben Bernstein.
Huntress featured Ben Bernstein, a cybersecurity advisor at the company, in an employee spotlight article. The piece is promotional HR content with no security incidents, vulnerabilities, or research findings.
PaperCut NG/MF hit by a pre-auth RCE zero-day under active exploitation; Huntress reproduced the chain and urged immediate patching.
Huntress reports active exploitation of a zero-day in PaperCut NG and PaperCut MF, and says it reproduced a pre-authentication remote code execution chain. The flaw allows unauthenticated attackers to execute code on exposed PaperCut servers. Huntress published urgent patching, exposure-reduction, and detection guidance. No CVE identifier was provided in the announcement.
Huntress links suspected North Korean remote workers to sales, marketing, and healthcare jobs using stolen identities, VPNs, proxies, and KVM hardware.
Huntress investigations identified suspected DPRK remote workers hired beyond IT in sales, marketing, and healthcare/financial organizations, sometimes actually performing the work they were hired for. Fraudulent documents included passports from the same city issued one day apart, ID cards with identical validity dates, and electricity bills built from the same online template with matching typos. A financial-services case found a PiKVM and Guermok USB capture card on a new hire's laptop within hours of delivery, suggesting a laptop farm, and another hire used a police mugshot with the photo digitally swapped. Researchers urge rigorous background checks and identity verification at the interview stage.
Huntress redesigned its Managed ITDR dashboard, adding Rapid Identity Triage, Failed Login Characterization, and Quick SIEM search to speed identity investigations.
Huntress announced a redesigned Managed ITDR dashboard aimed at accelerating identity threat investigations. New capabilities include Rapid Identity Triage, Failed Login Characterization, and Quick SIEM search. The update is a vendor product change with no incident or vulnerability details attached.
Huntress outlines five key cybersecurity decisions for ANZ retail businesses to secure identities and maintain trading continuity against ransomware.
Huntress published guidance aimed at retailers in Australia and New Zealand, describing five decisions that help retail businesses stay trading through cyber incidents. The piece covers identity security, dependency management, and ransomware resilience. It is guidance content rather than a report of a specific incident.
Huntress explains how threat actors abuse trusted AI platforms as an attack surface for malware delivery and data theft.
Huntress's post describes threat actors targeting the AI attack surface, abusing trusted AI tools and platforms to deliver malware and steal data. Using legitimate AI services helps attacker activity blend into normal traffic and evade detection. The article frames AI platforms as an increasingly exploited part of the enterprise attack surface that defenders should monitor.
Huntress details incidents involving suspected DPRK remote workers (Famous Chollima) in partner environments and shares detection indicators.
Huntress analyzed several incidents involving suspected North Korean remote workers, associated with the activity cluster known as Famous Chollima. The report describes indicators defenders can use to detect and prevent DPRK worker infiltration in customer environments. The scheme centers on operatives obtaining remote jobs at Western companies under assumed identities.
A hacker or insider leaked GTA VI gameplay footage before launch, triggering Take-Two DMCA subpoenas against Discord, Google, Microsoft and X.
The persona "CyberLeek" published stolen Grand Theft Auto VI gameplay footage and a manifesto, in what experts call a familiar data extortion playbook with monetization via watermarks, crypto wallets and a memecoin. Take-Two Interactive obtained DMCA subpoenas against Discord, Microsoft and X, and sent copyright notices to Google, treating the case like an insider threat investigation. GTA VI is projected to earn $3.3–5.2 billion in launch-week sales, raising financial and reputational stakes. Related leak websites went offline after the subpoenas.
Huntress guidance defines mature identity hardening beyond baseline MFA, covering exception cleanup and detecting identity configuration drift before attackers do.
Huntress argues MFA is only a starting point and outlines what mature identity hardening actually looks like in practice. The guidance covers closing MFA exceptions and coverage gaps that create unauthenticated attack paths. It also stresses catching identity configuration drift before attackers can exploit it.
Huntress launched a new view giving partners visibility into how its SOC investigates security incidents from first signal to resolution.
Huntress announced a new view into its security incident investigation workflow, showing partners how the Huntress SOC progresses cases from first signal to final resolution, including those closed as benign. The feature adds transparency into SOC triage and investigation decisions for managed detection and response customers.
Huntress published an educational guide explaining account takeover (ATO) fraud, how attackers steal credentials, and steps to detect and prevent it.
Huntress released a comprehensive guide on account takeover fraud, which occurs when attackers steal login credentials to gain access to victim accounts. The article is educational rather than incident reporting, covering detection signals and prevention measures such as credential protection. No specific breach, actor, or vulnerability is described.
Huntress reports RMM tool abuse jumped 277% and now appears in nearly 40% of its investigations as attackers leverage trusted remote access software.
Huntress observed a 277% increase in remote monitoring and management (RMM) tool abuse, with such abuse now present in nearly 40% of its investigations. Attackers exploit legitimate, trusted remote access tools to gain access and persistence, complicating detection because the software is expected on endpoints. The write-up explains common abuse patterns and defenses against them.
Huntress reports a persistent and elaborate phishing campaign targeting attendees following the Def Con security conference.
A Huntress researcher documented being targeted by an elaborate and persistent phishing scam after attending Def Con. The campaign specifically went after conference attendees, suggesting deliberate targeting of the security community. Details of the social engineering approach and persistence were shared.
Huntress uncovered post-DEF CON phishing via X direct messages using a malicious Google Doc to deliver AMOS and NetSupport RAT malware.
Huntress uncovered a phishing campaign targeting attendees after Black Hat and DEF CON. Attackers used X direct messages pointing to a malicious Google Doc as the delivery vehicle. Payloads include AMOS, a macOS infostealer, and the NetSupport RAT, among other malware.
Huntress argues detection engineers should only delegate security work to AI when outputs can be independently verified.
A Huntress detection engineer argues that the deciding factor for handing tasks to AI is whether the output can be checked, not whether the model is trusted. The piece frames human verification as the gate for delegating security engineering work to AI assistants. It is guidance/opinion aimed at defenders building detections with AI help.
An Akira affiliate rebooted a compromised host into Safe Mode to bypass EDR, but constrained memory crashed the encryptor before encryption completed.
Huntress reports an Akira affiliate gained access on August 4 via an MFA-less SonicWall VPN, enumerated Active Directory, archived file shares with WinRAR, and exfiltrated data to an attacker S3 bucket. The attacker rebooted the host into Safe Mode with Networking and preloaded AnyDesk into the Safe Mode service registry, disabling EDR and Defender's real-time protection for roughly ten minutes. The encryptor failed about 13 seconds after launch with out-of-virtual-memory errors caused by Safe Mode's stripped-down environment, and Defender later removed akira.exe after reboot. Huntress says this is the first observed Safe Mode abuse by Akira, following precedents by Snatch and AvosLocker, and provides detection guidance.
Huntress dissects MacSync Stealer, a macOS infostealer delivered through fake Claude Code download pages in Google search results.
Huntress SOC analysts published a reverse-engineering analysis of MacSync Stealer, a macOS infostealer distributed through fraudulent Claude Code download pages surfaced via web searches. Users searching for Anthropic's Claude coding tool are redirected to fake download pages that install the stealer, abusing developer trust in popular AI tooling. The writeup covers the analysis of the sample and its delivery chain.
Huntress researchers recap standout talks, panels, and villages from this year's Black Hat and DEF CON conferences.
Huntress researchers and SOC analysts published a recap of highlights from Black Hat and DEF CON, covering panels, villages, and standout sessions from Hacker Summer Camp. The post is a community roundup rather than an incident, vulnerability, or research disclosure.
Huntress finds four recent university breaches share one root cause, security misconfigurations, and outlines fixes for higher education.
Huntress analyzed four university breaches from 2026 and identified misconfiguration as the common root cause behind the incidents. The report describes the recurring attack pattern targeting higher education and offers remediation guidance to close the gap. Specific victim institutions, threat actor attribution, and breach volumes are not named in the announcement.
Huntress documented an Akira ransomware affiliate attack that failed after its anti-EDR tool crashed legitimate software and stopped encryption before completion.
Infosecurity Magazine reports on Huntress research into a failed Akira ransomware affiliate attack. The affiliate attempted EDR evasion using an anti-EDR tool, but the tool interfered with legitimate software on the client's system. The interference crashed the ransomware before encryption completed, sabotaging the attack; no completed encryption was reported.
Huntress publishes guidance on planning cybersecurity budgets and getting more value from security spend.
Huntress released a guide aimed at helping businesses plan their cybersecurity budgets without overspending. The content is promotional guidance on prioritizing security spend rather than incident reporting. No vulnerabilities, incidents, or threat activity are described.
Huntress documents an Akira ransomware affiliate rebooting endpoints into Windows Safe Mode to evade EDR and Defender, though Safe Mode broke the ransomware.
Huntress observed an Akira ransomware affiliate rebooting victim machines into Windows Safe Mode to disable EDR and Microsoft Defender before deploying ransomware. In an ironic twist, Safe Mode also prevented the ransomware from executing properly. The post walks through the full attack chain and the defensive lessons.
Unsafe Reflection RCE in PaperCut NG/MF, Chained with Auth Bypass in Attacks
CVE-2026-82078 is an unsafe dynamic class loading flaw (unsafe reflection, CWE-470) in the database connection utilities of PaperCut NG and PaperCut MF: the software instantiates a database driver class based on a configurable driver name without validating it against an allowlist of approved drivers. An attacker who can manipulate system configuration parameters can point that setting at classes of their choosing, causing the server to execute arbitrary Java bytecode residing on the application classpath in the security context of the PaperCut server process. On its own the issue is rated 9.4 (Critical) with high privileges required, but when chained with the companion authentication bypass CVE-2026-81578 it yields unauthenticated remote code execution on the print-management server. All PaperCut NG and MF deployments are in scope; affected version ranges were not specified in the available data, so administrators should consult PaperCut's advisory for fixed versions. The flaw is confirmed exploited in the wild as a zero-day: it was added to CISA's KEV catalog on 2026-08-31, and public reporting describes an AI-orchestrated campaign that compromised PaperCut servers at roughly 395 organizations (~440 servers), with EPSS currently at 1.7% (76th percentile).
Missing Authentication for Critical Function in PaperCut NG/MF Web Interface
CVE-2026-81578 is an improper access control flaw (CWE-305) in the web management interface of PaperCut MF and PaperCut NG in which administrative requests from unauthenticated remote users trigger backend actions before access validation completes. An attacker can invoke administrative functions without logging in, allowing modification of certain system configurations. When chained with CVE-2026-82078 (unsafe dynamic class loading), the flaw has been used to achieve unauthenticated code execution. Any organization running PaperCut NG/MF, particularly servers whose web management interface is reachable from the internet or untrusted networks, is affected. The vulnerability was added to CISA KEV on 2026-08-31 and is being exploited in the wild as part of an AI-orchestrated campaign that compromised roughly 395–440 organizations.
Pre-Auth Static Code Injection RCE in N-able N-central (Exploited in the Wild)
CVE-2026-86218 is a static code injection flaw (CWE-96) in N-able's N-central on-premises remote monitoring and management (RMM) platform, carrying a maximum CVSS 4.0 score of 10.0. An unauthenticated, remote attacker triggers it by sending crafted network input to the N-central server that is improperly neutralized and persisted into application-managed code, which the server then executes — no privileges (PR:N) or user interaction (UI:N) are required. Successful exploitation yields full server compromise with high impact on confidentiality, integrity, and availability, and because N-central acts as the management hub for downstream customer endpoints, compromise can expose the entire managed estate. Any organization running an affected N-central release (before 2026.3.1.14) — primarily MSPs and corporate IT departments using N-able RMM — is affected. The flaw is confirmed exploited in the wild: N-able patched it as a zero-day, CISA added it to the KEV catalog on 2026-09-08, and it is the fourth N-central hotfix in five weeks, though no public PoC is known and ransomware use is unknown.
· N-able N-central before 2026.3.1.14 KEV PoC large
Authentication bypass in N-able N-central internal APIs before 2026.3 HF 3
CVE-2026-86207 is an authentication bypass (CWE-305) in N-able's N-central remote monitoring and management (RMM) platform that allows unauthorized access to APIs that are supposed to be internal-only. It is triggered over the network by sending requests to these internal API endpoints under specific conditions (the CVSS vector indicates some attack prerequisites and a low-privilege foothold are required). An attacker who exploits it gains highly privileged access to the N-central server's data and functions, with high impact on confidentiality, integrity and availability of the server itself. Organizations running any N-central release before version 2026.3 Hotfix 3 are affected — primarily managed service providers hosting N-central for their own operations. There is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation risk at just 0.7%; note that the recent news headlines about actively exploited 'unauthenticated RCE' flaws in N-central describe separate vulnerabilities in the same product, which is why multiple hotfixes have shipped in quick succession.
· N-able N-central all versions before 2026.3 HF 3 (Hotfix 3)moderate
Access Control Filter Bypass in N-able N-central Exposes Internal APIs
N-able N-central contains a flaw in the access-control filter that protects its internal API (CWE-791, incomplete filtering), allowing requests to bypass the filter and reach internal APIs without authorization. The issue is exploitable over the network with no privileges and no user interaction, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). An attacker gains unauthorized, low-impact access to internal APIs (VC:L); the vector indicates no integrity or availability impact and no evidence of code execution from this flaw. Any organization running an affected N-central release — a remote monitoring and management (RMM) platform operated by managed service providers — is affected, and the fix is available in N-central 2026.3 HF3 and 2026.4. The flaw is not on the CISA KEV list and has no known public PoC or confirmed in-the-wild exploitation, though it was disclosed in the same patching cycle as actively exploited N-central unauthenticated RCE flaws.
· N-able N-central Releases prior to 2026.3 HF3; fixed in 2026.3 HF3 and 2026.4large
Argument-Injection Flaw in MikroTik RouterOS SSH Login Enables Privilege Escalation
CVE-2026-86060 is an argument-injection flaw (CWE-88) in MikroTik RouterOS's SSH login path: when a login supplies a username beginning with a prohibited character, the RouterOS login helper mishandles the argument, allowing the trusted RouterOS policy mask to be changed and privileges to be escalated. An unauthenticated attacker only needs the ability to reach the router's SSH service, since exploitation happens during the SSH login process itself. By altering the policy mask the attacker gains elevated rights on the device, and news reports indicate attackers have used this technique — including logins with usernames such as '-2' — as part of chains that take over routers without needing a password. Any RouterOS deployment running versions before the fixes (6.49.21 Long-term, 7.23.4 Long-term, 7.24.2 Stable) with SSH enabled or reachable is affected, with internet-exposed SSH at highest risk. Multiple outlets report the RouterOS flaws are being actively exploited in the wild, although no public proof-of-concept is known and the flaw is not yet in CISA KEV.
· MikroTik RouterOS v6 (Long-term channel) versions prior to 6.49.21 (fixed in 6.49.21) · MikroTik RouterOS v7 (Long-term channel) versions prior to 7.23.4 (fixed in 7.23.4) KEV PoC ×2mass
Authenticated OS Command Injection RCE in SonicWall SMA1000 Appliance Console
CVE-2026-83549 is a post-authentication OS command injection flaw (CWE-78) in the Appliance Management Console (AMC) of SonicWall SMA1000 appliances. An attacker who authenticates to the AMC with administrator privileges can, under specific conditions, inject arbitrary operating system commands and achieve remote code execution on the appliance. Only organizations running SMA1000-series appliances, including the SMA 6210, SMA 7210, and SMA 8200v models cited in the data, are affected. CISA added the flaw to the KEV catalog on 2026-09-02, and news reports describe active exploitation, possibly chained with companion zero-day CVE-2026-83548, with reverse shells and cryptocurrency miners observed; no public proof-of-concept is known. EPSS assigns an 8.5% probability of exploitation within 30 days (95th percentile).
· SonicWall SMA1000 series appliances - Appliance Management Console (AMC) · SonicWall SMA 6210 (SMA1000 series firmware) KEVmoderate
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line.
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds.…
Unauthenticated SSH Session Bypass Enables File Writes in MikroTik RouterOS
CVE-2026-67279 is an authentication-ordering flaw (CWE-841) in the SSH server of MikroTik RouterOS: after a client-requested SSH rekey, the server enters the connection protocol even though user authentication was never attempted. An unauthenticated SSH client can therefore open a session channel and send an exec request, and on affected builds the server dispatches the command without any credentials. This lets the attacker create, overwrite, and reconstruct files in the RouterOS managed file namespace, including support files that contain configuration and diagnostic data. Any MikroTik device running RouterOS builds older than the fixed releases is affected, although remote exploitation requires the SSH service to be reachable by the attacker. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and EPSS estimates a 0.4% probability of exploitation in the next 30 days, so no exploitation is currently known.
· MikroTik RouterOS (Long-term branch, v6) prior to 6.49.21 · MikroTik RouterOS (Long-term branch, v7) prior to 7.23.4mass
X.509 Signature Forgery Enables TLS Impersonation in MikroTik RouterOS 7.x
MikroTik RouterOS 7.x improperly verifies RSA/PKCS#1 v1.5 signatures when validating X.509 certificate chains, accepting malformed signatures (CWE-347, Improper Verification of Cryptographic Signature). Because the RouterOS trust store includes a root CA whose public key uses the small exponent e=3, an attacker who can control or redirect one of the router's outbound TLS connections (for example via a network man-in-the-middle position, DNS hijacking, or a compromised upstream path) can forge an intermediate CA signed with the root's public key, without ever holding its private key, and mint trusted certificates for arbitrary hostnames. This lets the attacker impersonate TLS servers the router connects to, with low confidentiality and integrity impact per the CVSS 4.0 score of 6.3 (medium), which reflects the network vector, no privileges required, but a high attack requirement of holding such a network position. Any deployment running RouterOS 7.x before 7.23.4 (Long-term) or 7.24.2 (Stable) is affected, spanning home/SOHO, enterprise, and ISP/WISP infrastructure; the 6.x branch is not listed as affected. No public proof-of-concept is known, the issue is not in CISA's KEV, and EPSS gives a 0.2% probability of exploitation within 30 days, although related headlines note other MikroTik flaws have recently been chained to hack routers.
· MikroTik RouterOS 7.x before 7.23.4 (Long-term) and before 7.24.2 (Stable); the 6.x branch is not affectedmass
Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.