Huntress
huntress.com
Imported from official source
Huntress — publications from its own official source.
- Type
- Company
- Scope
- US · national
- Website
- huntress.com
- Feed
- Atom
Publications 87
-
The First 24 Hours: What Happens When Ransomware Lands
Nazar Tymoshyk from UnderDefense shares his thoughts on what ransomware attacks look like during the all-important opening hours.
-
Companies Push AI Use But Skip Training and Official Policy
New data shows that many workers have employer-sponsored AI accounts and are encouraged to use them, yet 43% haven't been trained in AI.
-
Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses
The Huntress Tragic Quadrant ranks the cyber threats hitting businesses most, from RMM abuse to AiTM, ClickFix, using real SOC data.
-
Defender Exclusion Abuse: How Attackers Hide Malware from MDAV
See how attackers like GootKit and WhisperGate abuse Windows Defender exclusions to hide malware from AV scans — and how Huntress detects it.
-
Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers
Huntress SOC found a threat actor exploiting a file upload flaw in recreation management to breach 3 municipal servers and steal payment data.
-
Meet Athena: Huntress' Agentic SOC Analyst
Learn how Huntress' Athena brings agentic AI to the SOC, investigating signals end-to-end while human analysts own the final call.
-
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
Huntress researchers reveal how attackers are exploiting ChatGPT Custom GPTs to spread ClickFix lures and DLL-sideloaded malware. See the full breakdown.
-
Privilege Hygiene: Least Privilege Best Practices Guide
Learn what good privilege hygiene looks like, from local admin sprawl to accidental access, plus least privilege best practices you can start today.
-
Culture at Speed: Protecting What Makes Huntress Work
As Huntress scales past 800 teammates, Chief People Officer Kristin Dean reflects on protecting culture and not just letting it happen.
-
Managed or Modified: Choose How Huntress Hardens Microsoft 365
Managed ISPM now offers two deployment modes. Choose fully automated hardening or full control over which Microsoft 365 controls roll out, and when. See how it works.
-
The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint
Threat actors exploited Samsung MagicINFO to install AnyDesk, disable Defender, and compile a Monero miner directly on a victim endpoint. Learn the detection signals.
-
OAuth Token Theft Through Microsoft's Front Door
A sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. No phishing domain, no spoofed UI, no browser. Here's how to detect it.
Cybersecurity 2 versions -
Rogue RMM Abuse: How Attackers Exploit Remote Access Tools
The Huntress SOC uncovered phishing attacks that trick employees into installing rogue RMM tools like ScreenConnect for persistent access. Learn how to spot it.
-
DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer
DarkMe, an APT-linked VB6 RAT known for using zero day exploits, turned up in two Huntress incidents stripped down to a plain .pif infostealer malware.
2 versions -
Fighting AI Slop in Production Codebases: How Huntress Improved Fable 5.1’s API Recall
Three changes to the Huntress coding harnesses doubled Claude Fable 5.1’s API recall evaluation accuracy rate.
2 versions -
AI Attacks Move Faster. Huntress’ Agentic SOC Keeps Up
AI hasn't changed attacker tradecraft, just the speed. See how Huntress built Athena, an agentic SOC partner, to help analysts keep pace.
2 versions -
The Tale of Two INC Ransom Notes: A Ransomware Timeline | Huntress
Huntress analysts reconstructed a three-week INC ransomware attack from endpoint data, uncovering a 17-day lull despite missing process telemetry.
Cybersecurity 3 versions -
Operational Resilience: Turning Your IR Plan Into a Resilient Team
An incident response plan only works if it’s tested. Learn the 5 pillars of operational resilience and how to turn your plan into muscle memory before an attack hits.
Cybersecurity 3 versions -
Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM
Huntress has recently seen two incidents involving Settra, a ransomware variant that was first publicly reported in June 2026.
Cybersecurity 3 versions -
Operational Resilience: IT Security Risks with Reduced Staffing | Huntress
Reduced staffing during holidays changes more than headcount. Learn how operational resilience should shape your IT and security change decisions
Cybersecurity 3 versions -
Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware
A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.
Cybersecurity 3 versions -
How Attackers Abuse VSS, and How Huntress Detects It
Attackers exploit Volume Shadow Copy for credential theft and ransomware defense evasion. See how Huntress spots the difference from routine IT activity.
Cybersecurity 3 versions -
Credential Theft: How Attackers Steal & Use Stolen Credentials
Learn what credential theft is, how attackers steal credentials, and how to prevent credential-based attacks with identity-focused defenses from Huntress.
Cybersecurity 3 versions -
Best Practices for Good Endpoint Hardening | Huntress
Learn what endpoint hardening is, why it matters, and best practices to reduce attack surface, control access, & stop common intrusion paths.
Cybersecurity 3 versions -
35 Actionable Password Statistics for Businesses in 2026 | Huntress
The top password statistics might surprise you. Learn how common poor password hygiene is, plus tips to better protect your precious credentials.
Cybersecurity 3 versions -
The 20 Most Common Passwords Hackers Target in 2026
See this year's most common passwords, why they're so easy to crack, and how a stronger password (or passphrase) habit keeps your accounts protected.
Cybersecurity 3 versions -
AD Rights Management Service (Part 2): Extraction, Offline Decryption, and the Unrotatable Key
An AD RMS Service Group account exports the AD RMS Server Licensor Certificate private key. That 1172-byte key decrypts every document the deployment ever protected, offline, and keeps doing so aft...
Cybersecurity 3 versions -
Grand Theft Auto VI hype leads to malware
Threat actors are exploiting GTA6 hype with fake leaked downloads spread via SEO poisoning, packed with RATs, infostealers, and wiper ransomware. Here’s what Huntress found.
Cybersecurity 3 versions -
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
See how a browser-in-the-browser phishing attack led to rogue ScreenConnect persistence and evasion tactics Huntress caught in the act.
Cybersecurity 3 versions -
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.
Cybersecurity 3 versions -
AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance
Active Directory Rights Management Services still ships in Windows Server 2025, years after Microsoft began steering customers to the cloud, and it remains fully supported on-premises. Part 1 maps ...
Cybersecurity 3 versions -
AI SIEM Search
The new Huntress AI SIEM search feature lets you find answers in plain English, with no query language fluency required. Ask questions, get results, and skip the syntax.
-
Critical N-able N-central Vulnerability and Active Exploitation
UPDATE: Critical vulnerability in N-able N-central gives attackers unauthenticated, "god-mode" access to the RMM console.
Cybersecurity 3 versions -
Managed EDR: What It Is & How to Choose a Provider
Huntress breaks down what managed EDR is, how it differs from unmanaged, and what to look for when choosing a provider for your business.
Cybersecurity 3 versions -
Shadow AI in Financial Services | Risk & Governance
Shadow AI is spreading faster than governance in financial services. See the risks, why blocking AI backfires, and how to build policies that work.
-
CMMC Hit Pause, the FAR Council Hit Play
CMMC Phase 2 is paused, but the FAR CUI proposed rule pushes NIST 800-171 obligations past the defense industrial base. Here's what changed, what didn't, and the 32 requirements you can't defer.
Cybersecurity 3 versions -
Inside Knight Office, a New M365 AiTM Phishing Kit
An inside look at Knight Office, a newly discovered AiTM phishing kit featuring custom control panels, Cloudflare Turnstile, and M365 Token theft.
Cybersecurity 3 versions -
[object Object]
Cybersecurity 2 versions -
[object Object]
Cybersecurity 2 versions -
Hackers Frequently Target Healthcare and Finance Orgs
Healthcare organizations and banks handle highly personal information. But a new Huntress survey shows many threat actors frequently target these companies.
-
RMM Tools for MSPs: Features, Risks & How to Stay Secure
Four years after the Kaseya supply chain attack, a recent incident shows how threat actors still successfully target MSPs’ downstream customers through RMM software.
-
The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT
Exodus crypto wallet analysis by Huntress uncovered tampered installers hiding a modular RAT focused on stealing credentials, not coins.
-
Daisy-Chaining Trust: Investigating Faronics Deploy Abuse
Bad actors are abusing Faronics Deploy in phishing campaigns to run PowerShell, deploy ScreenConnect, and evade detection by using trusted tools.
-
Huntress API Update: New Endpoints, Webhooks, and Automation
The Huntress API has grown from six read-only endpoints into a full integration and automation platform. See what’s new, including webhooks and MCP support.
-
Boardroom Battles 2026: ASD’s Cyber Priorities & AI Risk
The Australian Signals Directorate’s 2026 board priorities and frontier AI guidance show why speed alone won’t stop AI-era cyber threats.
-
A Beginner’s Guide to Phishing Simulation Training for Employees | Huntress
Learn the essentials of phishing simulation training with our beginner's guide. Protect your organization by simulating real phishing attacks.
-
Teach Yourself to Phish | Huntress
Get ready for a phishing trip! Learn about the strategy behind phishing simulations and how it can help your organization build resilience against real phishing threats.
-
Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress
Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users with Huntress SAT.
-
Huntress Employee Spotlight: Meet Ben Bernstein
Meet Ben Bernstein, cybersecurity advisor and security badass, in this employee spotlight. See how he makes a difference every day.
-
PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE
UPDATED: PaperCut NG and PaperCut MF are under active exploitation. Huntress reproduced a pre-auth RCE chain and shares urgent patching, exposure, and detection guidance.