Huntress

huntress.com

Imported from official source

Huntress — publications from its own official source.

Type
Company
Scope
US · national
Website
huntress.com
Feed
Atom

Publications 87

  1. The First 24 Hours: What Happens When Ransomware Lands

    Nazar Tymoshyk from UnderDefense shares his thoughts on what ransomware attacks look like during the all-important opening hours.

  2. Companies Push AI Use But Skip Training and Official Policy

    New data shows that many workers have employer-sponsored AI accounts and are encouraged to use them, yet 43% haven't been trained in AI.

    AI
  3. Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses

    The Huntress Tragic Quadrant ranks the cyber threats hitting businesses most, from RMM abuse to AiTM, ClickFix, using real SOC data.

  4. Defender Exclusion Abuse: How Attackers Hide Malware from MDAV

    See how attackers like GootKit and WhisperGate abuse Windows Defender exclusions to hide malware from AV scans — and how Huntress detects it.

  5. Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers

    Huntress SOC found a threat actor exploiting a file upload flaw in recreation management to breach 3 municipal servers and steal payment data.

  6. Meet Athena: Huntress' Agentic SOC Analyst

    Learn how Huntress' Athena brings agentic AI to the SOC, investigating signals end-to-end while human analysts own the final call.

  7. Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix

    Huntress researchers reveal how attackers are exploiting ChatGPT Custom GPTs to spread ClickFix lures and DLL-sideloaded malware. See the full breakdown.

  8. Privilege Hygiene: Least Privilege Best Practices Guide

    Learn what good privilege hygiene looks like, from local admin sprawl to accidental access, plus least privilege best practices you can start today.

  9. Culture at Speed: Protecting What Makes Huntress Work

    As Huntress scales past 800 teammates, Chief People Officer Kristin Dean reflects on protecting culture and not just letting it happen.

  10. Managed or Modified: Choose How Huntress Hardens Microsoft 365

    Managed ISPM now offers two deployment modes. Choose fully automated hardening or full control over which Microsoft 365 controls roll out, and when. See how it works.

  11. The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint

    Threat actors exploited Samsung MagicINFO to install AnyDesk, disable Defender, and compile a Monero miner directly on a victim endpoint. Learn the detection signals.

  12. OAuth Token Theft Through Microsoft's Front Door

    A sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. No phishing domain, no spoofed UI, no browser. Here's how to detect it.

    Cybersecurity 2 versions
  13. Rogue RMM Abuse: How Attackers Exploit Remote Access Tools

    The Huntress SOC uncovered phishing attacks that trick employees into installing rogue RMM tools like ScreenConnect for persistent access. Learn how to spot it.

  14. DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer

    DarkMe, an APT-linked VB6 RAT known for using zero day exploits, turned up in two Huntress incidents stripped down to a plain .pif infostealer malware.

    2 versions
  15. Fighting AI Slop in Production Codebases: How Huntress Improved Fable 5.1’s API Recall

    Three changes to the Huntress coding harnesses doubled Claude Fable 5.1’s API recall evaluation accuracy rate.

    2 versions
  16. AI Attacks Move Faster. Huntress’ Agentic SOC Keeps Up

    AI hasn't changed attacker tradecraft, just the speed. See how Huntress built Athena, an agentic SOC partner, to help analysts keep pace.

    2 versions
  17. The Tale of Two INC Ransom Notes: A Ransomware Timeline | Huntress

    Huntress analysts reconstructed a three-week INC ransomware attack from endpoint data, uncovering a 17-day lull despite missing process telemetry.

    Cybersecurity 3 versions
  18. Operational Resilience: Turning Your IR Plan Into a Resilient Team

    An incident response plan only works if it’s tested. Learn the 5 pillars of operational resilience and how to turn your plan into muscle memory before an attack hits.

    Cybersecurity 3 versions
  19. Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM

    Huntress has recently seen two incidents involving Settra, a ransomware variant that was first publicly reported in June 2026.

    Cybersecurity 3 versions
  20. Operational Resilience: IT Security Risks with Reduced Staffing | Huntress

    Reduced staffing during holidays changes more than headcount. Learn how operational resilience should shape your IT and security change decisions

    Cybersecurity 3 versions
  21. Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware

    A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.

    Cybersecurity 3 versions
  22. How Attackers Abuse VSS, and How Huntress Detects It

    Attackers exploit Volume Shadow Copy for credential theft and ransomware defense evasion. See how Huntress spots the difference from routine IT activity.

    Cybersecurity 3 versions
  23. Credential Theft: How Attackers Steal & Use Stolen Credentials

    Learn what credential theft is, how attackers steal credentials, and how to prevent credential-based attacks with identity-focused defenses from Huntress.

    Cybersecurity 3 versions
  24. Best Practices for Good Endpoint Hardening | Huntress

    Learn what endpoint hardening is, why it matters, and best practices to reduce attack surface, control access, & stop common intrusion paths.

    Cybersecurity 3 versions
  25. 35 Actionable Password Statistics for Businesses in 2026 | Huntress

    The top password statistics might surprise you. Learn how common poor password hygiene is, plus tips to better protect your precious credentials.

    Cybersecurity 3 versions
  26. The 20 Most Common Passwords Hackers Target in 2026

    See this year's most common passwords, why they're so easy to crack, and how a stronger password (or passphrase) habit keeps your accounts protected.

    Cybersecurity 3 versions
  27. AD Rights Management Service (Part 2): Extraction, Offline Decryption, and the Unrotatable Key

    An AD RMS Service Group account exports the AD RMS Server Licensor Certificate private key. That 1172-byte key decrypts every document the deployment ever protected, offline, and keeps doing so aft...

    Cybersecurity 3 versions
  28. Grand Theft Auto VI hype leads to malware

    Threat actors are exploiting GTA6 hype with fake leaked downloads spread via SEO poisoning, packed with RATs, infostealers, and wiper ransomware. Here’s what Huntress found.

    Cybersecurity 3 versions
  29. Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

    See how a browser-in-the-browser phishing attack led to rogue ScreenConnect persistence and evasion tactics Huntress caught in the act.

    Cybersecurity 3 versions
  30. Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity

    Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.

    Cybersecurity 3 versions
  31. AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance

    Active Directory Rights Management Services still ships in Windows Server 2025, years after Microsoft began steering customers to the cloud, and it remains fully supported on-premises. Part 1 maps ...

    Cybersecurity 3 versions
  32. AI SIEM Search

    The new Huntress AI SIEM search feature lets you find answers in plain English, with no query language fluency required. Ask questions, get results, and skip the syntax.

    AI Cybersecurity 3 versions
  33. Critical N-able N-central Vulnerability and Active Exploitation

    UPDATE: Critical vulnerability in N-able N-central gives attackers unauthenticated, "god-mode" access to the RMM console.

    Cybersecurity 3 versions
  34. Managed EDR: What It Is & How to Choose a Provider

    Huntress breaks down what managed EDR is, how it differs from unmanaged, and what to look for when choosing a provider for your business.

    Cybersecurity 3 versions
  35. Shadow AI in Financial Services | Risk & Governance

    Shadow AI is spreading faster than governance in financial services. See the risks, why blocking AI backfires, and how to build policies that work.

    AI Finance 3 versions
  36. CMMC Hit Pause, the FAR Council Hit Play

    CMMC Phase 2 is paused, but the FAR CUI proposed rule pushes NIST 800-171 obligations past the defense industrial base. Here's what changed, what didn't, and the 32 requirements you can't defer.

    Cybersecurity 3 versions
  37. Inside Knight Office, a New M365 AiTM Phishing Kit

    An inside look at Knight Office, a newly discovered AiTM phishing kit featuring custom control panels, Cloudflare Turnstile, and M365 Token theft.

    Cybersecurity 3 versions
  38. [object Object]

    Cybersecurity 2 versions
  39. [object Object]

    Cybersecurity 2 versions
  40. Hackers Frequently Target Healthcare and Finance Orgs

    Healthcare organizations and banks handle highly personal information. But a new Huntress survey shows many threat actors frequently target these companies.

  41. RMM Tools for MSPs: Features, Risks & How to Stay Secure

    Four years after the Kaseya supply chain attack, a recent incident shows how threat actors still successfully target MSPs’ downstream customers through RMM software.

  42. The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT

    Exodus crypto wallet analysis by Huntress uncovered tampered installers hiding a modular RAT focused on stealing credentials, not coins.

  43. Daisy-Chaining Trust: Investigating Faronics Deploy Abuse

    Bad actors are abusing Faronics Deploy in phishing campaigns to run PowerShell, deploy ScreenConnect, and evade detection by using trusted tools.

  44. Huntress API Update: New Endpoints, Webhooks, and Automation

    The Huntress API has grown from six read-only endpoints into a full integration and automation platform. See what’s new, including webhooks and MCP support.

  45. Boardroom Battles 2026: ASD’s Cyber Priorities & AI Risk

    The Australian Signals Directorate’s 2026 board priorities and frontier AI guidance show why speed alone won’t stop AI-era cyber threats.

  46. A Beginner’s Guide to Phishing Simulation Training for Employees | Huntress

    Learn the essentials of phishing simulation training with our beginner's guide. Protect your organization by simulating real phishing attacks.

  47. Teach Yourself to Phish | Huntress

    Get ready for a phishing trip! Learn about the strategy behind phishing simulations and how it can help your organization build resilience against real phishing threats.

  48. Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress

    Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users with Huntress SAT.

  49. Huntress Employee Spotlight: Meet Ben Bernstein

    Meet Ben Bernstein, cybersecurity advisor and security badass, in this employee spotlight. See how he makes a difference every day.

  50. PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE

    UPDATED: PaperCut NG and PaperCut MF are under active exploitation. Huntress reproduced a pre-auth RCE chain and shares urgent patching, exposure, and detection guidance.

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.