ZeroHour

Search: “Huntress”

40 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Operational Resilience: IT Security Risks with Reduced Staffing | Huntress

Huntress blog advises security teams on managing change, risk, and incident response during reduced-staffing holiday periods.

The article discusses how holiday-period staffing reductions change organizational risk profiles around change management, monitoring, and incident response capability. It argues against blanket change freezes when critical vulnerabilities with high exploitation probability demand patching, and stresses retaining decision-making authority, escalation paths, and recovery knowledge. It concludes by promoting Huntress Managed Response, which lets the Huntress SOC take predefined containment actions on confirmed threats without customer intervention.

Huntress · 1d agoIndustry

Guide to Cybersecurity Budget Planning: How Much + How To | Huntress

Huntress publishes guidance on planning cybersecurity budgets and getting more value from security spend.

Huntress released a guide aimed at helping businesses plan their cybersecurity budgets without overspending. The content is promotional guidance on prioritizing security spend rather than incident reporting. No vulnerabilities, incidents, or threat activity are described.

Huntress · Aug 12, 2026Industry

Insights into Suspected DPRK Workers

Huntress details incidents involving suspected DPRK remote workers (Famous Chollima) in partner environments and shares detection indicators.

Huntress analyzed several incidents involving suspected North Korean remote workers, associated with the activity cluster known as Famous Chollima. The report describes indicators defenders can use to detect and prevent DPRK worker infiltration in customer environments. The scheme centers on operatives obtaining remote jobs at Western companies under assumed identities.

Huntress · 21d agoThreat actor in the wild

What Is Account Takeover Fraud? A Comprehensive Guide | Huntress

Huntress published an educational guide explaining account takeover (ATO) fraud, how attackers steal credentials, and steps to detect and prevent it.

Huntress released a comprehensive guide on account takeover fraud, which occurs when attackers steal login credentials to gain access to victim accounts. The article is educational rather than incident reporting, covering detection signals and prevention measures such as credential protection. No specific breach, actor, or vulnerability is described.

Huntress · 26d agoPhishing & fraud

The 12 Best Managed Detection & Response (MDR) Services, Compared and Priced

Buyer's guide compares 12 MDR services, naming Huntress best value, CrowdStrike Falcon Complete for response authority and Expel for transparency.

The article compares 12 managed detection and response providers across response authority, tool bundling and pricing, highlighting Huntress for published SMB pricing and CrowdStrike Falcon Complete for unilateral containment. It stresses the consolidation landscape: Sophos completed its acquisition of Secureworks in February 2025 for approximately $859 million, and Arctic Wolf closed its purchase of BlackBerry's Cylance endpoint assets the same month. It also warns that only full-response contract tiers isolate hosts and kill processes, while lower tiers only triage or guide.

GBHackersupdated · 7d agofirst · 7d agoIndustry 3 sources1

Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware

Huntress uncovered post-DEF CON phishing via X direct messages using a malicious Google Doc to deliver AMOS and NetSupport RAT malware.

Huntress uncovered a phishing campaign targeting attendees after Black Hat and DEF CON. Attackers used X direct messages pointing to a malicious Google Doc as the delivery vehicle. Payloads include AMOS, a macOS infostealer, and the NetSupport RAT, among other malware.

Huntress · 28d agoPhishing & fraud

PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE

PaperCut NG/MF hit by a pre-auth RCE zero-day under active exploitation; Huntress reproduced the chain and urged immediate patching.

Huntress reports active exploitation of a zero-day in PaperCut NG and PaperCut MF, and says it reproduced a pre-authentication remote code execution chain. The flaw allows unauthenticated attackers to execute code on exposed PaperCut servers. Huntress published urgent patching, exposure-reduction, and detection guidance. No CVE identifier was provided in the announcement.

Huntress · 19d agoExploit / PoC in the wild

Def Con Attendees Targeted by Persistent Phishing Campaign

Huntress reports a persistent and elaborate phishing campaign targeting attendees following the Def Con security conference.

A Huntress researcher documented being targeted by an elaborate and persistent phishing scam after attending Def Con. The campaign specifically went after conference attendees, suggesting deliberate targeting of the security community. Details of the social engineering approach and persistence were shared.

Infosecurity Magazine · 27d agoPhishing & fraud

Boardroom Battles 2026: ASD’s Cyber Priorities & AI Risk

Huntress analyzes the Australian Signals Directorate's 2026 board cyber priorities and frontier AI guidance on managing AI-era threats.

Huntress analyzed the Australian Signals Directorate's 2026 boardroom cyber priorities and its guidance on frontier AI risk. The piece argues that rapid AI adoption alone will not counter AI-era cyber threats and outlines what boards should focus on. No specific incident, vulnerability, or regulation change is described.

Huntress · 17d agoPolicy & legal

Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress

Huntress details modern phishing tactics including ClickFix, browser-in-the-browser, and OAuth consent phishing beyond basic credential harvesting.

Huntress describes a shift in phishing attacks beyond basic credential harvesting toward advanced tactics. Covered techniques include ClickFix social engineering, browser-in-the-browser (BitB) attacks, and OAuth consent phishing. The post recommends training users on these patterns through Huntress SAT simulations.

Huntress · 19d agoPhishing & fraud in the wild1

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Huntress says rogue ScreenConnect clients spread a four-stage VBScript chain delivering backdoors, privilege-escalation tools, or an XMRig miner to newly connected hosts.

Huntress identified three unrelated August 2026 incidents using a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund form to install rogue ScreenConnect clients. Each client repeatedly spawned wscript.exe to run 1.vbs through 4.vbs, which profiled the host, enumerated installed security products, and downloaded stage-specific payloads from Dropbox. Depending on detected state, payloads included a user-level ScreenConnect backdoor, UAC-bypass privilege escalation tooling, or tunneling utilities with an XMRig cryptocurrency miner. Infected clients re-infected newly connected hosts, creating worm-like propagation, and ConnectWise issued an advisory about affected file transfer behavior in ScreenConnect.

The Hacker News · 9d agoMalware in the wild

New View for Security Incident Investigations

Huntress launched a new view giving partners visibility into how its SOC investigates security incidents from first signal to resolution.

Huntress announced a new view into its security incident investigation workflow, showing partners how the Huntress SOC progresses cases from first signal to final resolution, including those closed as benign. The feature adds transparency into SOC triage and investigation decisions for managed detection and response customers.

Huntress · 23d agoTools

What Good Identity Hardening Looks Like

Huntress guidance defines mature identity hardening beyond baseline MFA, covering exception cleanup and detecting identity configuration drift before attackers do.

Huntress argues MFA is only a starting point and outlines what mature identity hardening actually looks like in practice. The guidance covers closing MFA exceptions and coverage gaps that create unauthenticated attack paths. It also stresses catching identity configuration drift before attackers can exploit it.

Huntress · 22d agoResearch

Back-to-back N-able bugs send admins on a patching spree

CVE-2026-86218, a CVSS 10.0 pre-auth RCE in N-able N-central, is being exploited in the wild; Hotfix 4 mitigates it immediately.

N-able disclosed CVE-2026-86218 on September 6, a pre-authentication remote code execution flaw with CVSS 10.0 in its N-central RMM platform, and both N-able and Huntress report it is being exploited in the wild. It follows Huntress's disclosure of an exploit chain combining CVE-2026-86206 and CVE-2026-86207 that bypasses access controls to create unauthorized administrative accounts, investigated after a September 4 compromise of a fully patched customer environment. N-able has applied mitigations to all hosted N-central instances; on-premises customers must upgrade to Hotfix 4 (build 2026.3.1.14) immediately.

CSO Online · 9d agoExploit / PoC in the wildCVE-2026-86218CVE-2026-86206CVE-2026-86207+2 CVEs

New Huntress Managed ITDR Dashboard: Faster Identity Investigations

Huntress redesigned its Managed ITDR dashboard, adding Rapid Identity Triage, Failed Login Characterization, and Quick SIEM search to speed identity investigations.

Huntress announced a redesigned Managed ITDR dashboard aimed at accelerating identity threat investigations. New capabilities include Rapid Identity Triage, Failed Login Characterization, and Quick SIEM search. The update is a vendor product change with no incident or vulnerability details attached.

Huntress · 20d agoTools

Attackers use rogue ScreenConnect clients to spread malware

Attackers deploy rogue ScreenConnect clients that spread VBScript malware to newly connected machines while ConnectWise patches a file-transfer flaw.

ConnectWise confirmed a file transfer flaw in ScreenConnect affecting both Cloud and On-Premise deployments, with a CVE identifier and official fix promised within the week; administrators can mitigate immediately by disabling TransferFiles (or TransferFilesInSession) in each role. Huntress documented incidents where social engineering installs rogue ScreenConnect clients that spawn Windows Script Host processes running four VBScript files (1.vbs-4.vbs), add a WindowsServiceHost registry Run key, and propagate to newly connected endpoints. Payloads enabled host profiling, persistence, additional ScreenConnect installs, tunneling, security-control changes, and cryptocurrency mining. ConnectWise has not confirmed a technical link between the flaw and this campaign.

Help Net Security · 9d agoExploit / PoC in the wild

Teach Yourself to Phish | Huntress

Huntress outlines the strategy behind phishing simulations to help organizations build resilience against real phishing threats.

Huntress published guidance on the strategy behind phishing simulation programs. The piece argues simulations should mirror real attacker behavior to train employees and measure organizational resilience. The content promotes Huntress's security awareness training offering.

Huntress · 19d agoIndustry

The 12 Best Endpoint Detection & Response (EDR) Solutions, Compared and Priced

An editorial scorecard ranks 12 EDR platforms, with CrowdStrike and SentinelOne tied at 8.6/10 and telemetry retention identified as the hidden cost driver.

An editorial comparison scores twelve EDR platforms on detection, response, analyst burden, pricing transparency, and coverage. CrowdStrike and SentinelOne tie at 8.6/10, with Microsoft Defender for Endpoint close behind at 8.5 and described as effectively free in Microsoft 365 E5 estates. The guide argues that telemetry retention, not per-endpoint price, drives real cost, with fully-priced quotes frequently diverging 2-3x from headline rates. Managed detection offerings, including Cynet's bundled 24/7 SOC, factor into the buyer-fit rankings.

GBHackers · 7d agoIndustry 2 sources

A Beginner’s Guide to Phishing Simulation Training for Employees | Huntress

Huntress published a beginner's guide to phishing simulation training that simulates real phishing attacks to protect organizations.

Huntress released a beginner's guide to phishing simulation training for employees. The guide covers the essentials of simulating real phishing attacks to improve organizational security awareness. It serves as educational content tied to Huntress's training products.

Huntress · 19d agoIndustry

Retail Cybersecurity in ANZ: Five Decisions That Keep Trading

Huntress outlines five key cybersecurity decisions for ANZ retail businesses to secure identities and maintain trading continuity against ransomware.

Huntress published guidance aimed at retailers in Australia and New Zealand, describing five decisions that help retail businesses stay trading through cyber incidents. The piece covers identity security, dependency management, and ransomware resilience. It is guidance content rather than a report of a specific incident.

Huntress · 20d agoIndustry

Huntress API Update: New Endpoints, Webhooks, and Automation

Huntress expanded its API from six read-only endpoints into an automation platform adding webhooks and Model Context Protocol support.

Huntress announced a major expansion of its API, growing from six read-only endpoints into a full integration and automation platform. New capabilities include webhook support, additional endpoints, and MCP (Model Context Protocol) support to enable AI-assisted automation. The update targets defenders building integrations and automated workflows around the Huntress managed detection and response platform.

Huntress · 16d agoTools

The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT

Huntress found tampered Exodus crypto wallet installers delivering a modular RAT that steals credentials rather than wallet funds.

Huntress analysts analyzed tampered installers for the Exodus cryptocurrency wallet that bundle a modular remote access trojan. The implant focuses on harvesting credentials instead of draining wallet balances, suggesting broader access theft. The case highlights installer tampering as a supply-chain-style delivery vector for credential-stealing tooling.

Huntress · 15d agoMalware in the wild

Credential Theft: How Attackers Steal & Use Stolen Credentials

Huntress explains how attackers steal credentials through phishing, AitM, infostealers, and dumping, then use them for lateral movement, BEC, and ransomware.

Huntress published an educational overview of credential theft, citing that roughly 70% of confirmed data breaches begin with stolen credentials. It details acquisition methods including phishing, adversary-in-the-middle attacks that capture MFA session tokens, infostealers (nearly a quarter of threats Huntress observed in 2025), Mimikatz-based credential dumping, credential stuffing, and password spraying. The piece then covers post-theft actions such as lateral movement, privilege escalation, account takeover, business email compromise, and ransomware, and closes with behavioral detection guidance and layered prevention strategies.

Huntress · 6d agoResearch

Securing Your Business: The Vital Role of Cyber Insurance | Huntress

Huntress explains cyber insurance coverage types, insurer security requirements, and the shift toward documented evidence of controls.

Huntress outlines first-party and third-party cyber insurance coverage, including business interruption, data recovery, extortion, privacy liability, and regulatory fines. Insurers now commonly require EDR, MFA, security awareness training, patching, tested backups, least-privilege access, and incident response plans. With ransomware accounting for 91% of insurance losses in H1 2025 and average US breach costs at $10.22 million, underwriters increasingly demand evidence packs rather than self-attestation.

Huntress · 15d agoIndustry

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Huntress details campaigns abusing Claude Artifacts, claude.ai/share links, and ChatGPT/Grok conversations to deliver SectopRAT, MacSync, and AMOS stealers.

Huntress SOC documented nine months of campaigns in which attackers weaponized trusted AI platform features—Claude Artifacts, public claude.ai/share links, and indexable ChatGPT/Grok conversations—to deliver malware. The July FakeAgent campaign hit more than 29 organizations via a malicious Claude Artifact posing as a Claude Desktop download page that redirected to SectopRAT. A claude.ai/share link disguised as an Apple Support guide tricked a victim into running a curl command that deployed the MacSync stealer, harvesting cookies, credentials, keychain secrets, Telegram sessions, and SSH/cloud keys, while SEO-poisoned ChatGPT and Grok conversations delivered the AMOS stealer via ClickFix-style instructions.

BleepingComputer · 5d agoPhishing & fraud in the wild

A Detection Engineer's Guide for Delegating Work to AI

Huntress argues detection engineers should only delegate security work to AI when outputs can be independently verified.

A Huntress detection engineer argues that the deciding factor for handing tasks to AI is whether the output can be checked, not whether the model is trusted. The piece frames human verification as the gate for delegating security engineering work to AI assistants. It is guidance/opinion aimed at defenders building detections with AI help.

Huntress · 28d agoAI safety & security

AD Rights Management Service (Part 2): Extraction, Offline Decryption, and the Unrotatable Key

Huntress research shows AD RMS SLC root key is unrotatable and never expires, so its compromise permanently exposes all RMS-protected documents.

Part 2 of Huntress's AD RMS series details server-side attacks: extracting the Server Licensor Certificate (SLC) private key and performing offline decryption of protected documents. The SLC key has no expiry or rotation mechanism, with a 255-year certificate validity (2002–2258), so whoever recovers it can decrypt every document the deployment ever protected, indefinitely. The author released SharpRMS, a unified tool combining the 2016 DisARMS client-side attacks with new server-side key extraction and decryption capabilities. The research frames the SLC as comparable to KRBTGT and the DPAPI domain backup key, though not equivalent to domain compromise.

Huntress · 6d agoResearch

10 Hacker Summer Camp Standouts at Black Hat and DEF CON

Huntress researchers recap standout talks, panels, and villages from this year's Black Hat and DEF CON conferences.

Huntress researchers and SOC analysts published a recap of highlights from Black Hat and DEF CON, covering panels, villages, and standout sessions from Hacker Summer Camp. The post is a community roundup rather than an incident, vulnerability, or research disclosure.

Huntress · Aug 14, 2026Industry

Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall

Academics linked Chinese vendor Geedge Networks' Tiangou Secure Gateway source code to one of the Great Firewall's three traffic filtering capabilities.

US researchers presenting at USENIX Security reconstructed Geedge Networks' Tiangou Secure Gateway firmware from over 100,000 leaked files, including Git repositories with commit history, and matched its filtering behavior to sections of China's Great Firewall. They found only 1 of 3 characterized DNS injectors matched Geedge code, noted the system relies on memory-unsafe C components and copied third-party code, and said its bugs could aid future circumvention tools. Geedge also exports censorship tools to Kazakhstan, Ethiopia, Pakistan, and Myanmar. The newsletter additionally rounds up multiple breaches.

Risky Business News · 26d agoResearch2

AI SIEM Search

Huntress launched AI Search for Managed SIEM, translating plain-English questions into ESQL log queries with schedulable custom alerts.

Huntress introduced AI Search in its Managed SIEM, letting users query logs in natural language instead of writing ESQL, KQL, or SPL. The feature generates a real ESQL query behind the scenes, exposes it for users to inspect and learn from, and allows saved searches to be scheduled as recurring alerts at hourly, daily, or weekly cadence. A planned next version will return summarized plain-language answers instead of raw logs.

Huntress · 9d agoTools

Akira Hits Safe Mode: Ransomware Rebooting Around EDR

Huntress documents an Akira ransomware affiliate rebooting endpoints into Windows Safe Mode to evade EDR and Defender, though Safe Mode broke the ransomware.

Huntress observed an Akira ransomware affiliate rebooting victim machines into Windows Safe Mode to disable EDR and Microsoft Defender before deploying ransomware. In an ironic twist, Safe Mode also prevented the ransomware from executing properly. The post walks through the full attack chain and the defensive lessons.

Huntress · Aug 12, 2026Ransomware in the wild

How Attackers Abuse VSS, and How Huntress Detects It

Huntress details how attackers abuse Windows Volume Shadow Copies for ransomware recovery sabotage and NTDS.dit credential theft, plus detection logic.

Huntress explains that attackers abuse VSS in three ways: deleting shadow copies to inhibit recovery before ransomware detonation, creating shadow copies to extract the NTDS.dit Active Directory database for offline credential theft, and manipulating shadow copy configuration. Because backup agents and RMM tools routinely create and delete shadow copies, raw events are too noisy to alert on alone. Huntress detections instead correlate VSS activity with lateral movement and credential harvesting over a time window, such as an observed sequence of PsExec spawning SYSTEM shells on a domain controller, vssadmin create shadow, a blocked deletion attempt, and DNS reconnaissance against another host.

Huntress · 2d agoResearch

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

CISA added CVE-2026-86218 (CVSS 10.0), a pre-auth RCE in N-able N-central, to KEV after N-able confirmed in-the-wild exploitation; patch by September 11.

CISA added CVE-2026-86218, a maximum-severity static code injection flaw enabling pre-authentication remote code execution in N-able N-central, to its Known Exploited Vulnerabilities catalog with a September 11, 2026 deadline for federal agencies. The flaw is fixed in N-central 2026.3 Hotfix 4 (released September 5), and N-able told customers it has been observed being exploited in the wild. Separately, Huntress is investigating the compromise of a fully patched customer N-central environment on September 4 and cannot yet confirm which flaw was used, while Rapid7-disclosed CVE-2026-86206 and CVE-2026-86207 can be chained by an unauthenticated attacker to create a rogue System Administrator account.

Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware

Huntress analysts trace one X direct message into separate Mac and Windows malware chains delivering AMOS infostealer and NetSupport Manager RAT.

Huntress SOC analysts dissected a malware campaign distributed via an X direct message styled as a Google Docs sidebar. macOS users were routed to the AMOS infostealer, while Windows users received NetSupport Manager remote access malware. The write-up details how a single message branched into two distinct delivery paths per operating system.

Huntress · 5d agoMalware in the wild

Education Under Attack: The Pattern Behind Recent University Breaches

Huntress finds four recent university breaches share one root cause, security misconfigurations, and outlines fixes for higher education.

Huntress analyzed four university breaches from 2026 and identified misconfiguration as the common root cause behind the incidents. The report describes the recurring attack pattern targeting higher education and offers remediation guidance to close the gap. Specific victim institutions, threat actor attribution, and breach volumes are not named in the announcement.

Huntress · Aug 13, 2026Threat actor in the wild

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

CISA added five actively exploited JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS flaws to its KEV catalog.

CISA added five actively exploited vulnerabilities to the KEV catalog: CVE-2026-42016 and CVE-2026-42018 in JFrog Artifactory, CVE-2026-84869 in ConnectWise ScreenConnect (CVSS 9.9), and CVE-2026-67277 and CVE-2026-86060 in MikroTik RouterOS. The Artifactory bugs are chained with CVE-2026-82329 to gain administrative control, deploy malicious Groovy plugins, and install Rust-based backdoors. CERT Polska dubbed the RouterOS chain 'MikroTrick'; FCEB agencies must patch between September 13 and 25, 2026.

The Hacker Newsupdated · 2d agofirst · 4d agoExploit / PoC in the wild 2 sourcesCVE-2026-42016CVE-2026-42018CVE-2026-84869+3 CVEs2· 1 read