logo

Huntress Blog

ID: e1b4d979-e6a5-5eef-9f0d-273f751e82e1

STIX ID: identity--e1b4d979-e6a5-5eef-9f0d-273f751e82e1

Feed Type: rss

Earliest post: 2016-04-06

Latest post: 2026-08-27

Threat research, incident response insights, and practical defensive guidance from the Huntress team — focused on real-world attacks, persistence mechanisms, and strategies to protect SMBs and enterprises.

01/01/2020
08/28/2026
Title Date Published Describes IncidentAuthorVisible
What Good Identity Hardening Looks Like2026-08-25TrueTrue
RMM Abuse: How Attackers Exploit Remote Access Tools | Huntress 2026-08-21TrueTrue
Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware2026-08-19TrueTrue
MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer2026-08-17TrueTrue
10 Hacker Summer Camp Standouts at Black Hat and DEF CON2026-08-14TrueTrue
Education Under Attack: The Pattern Behind Recent University Breaches2026-08-13TrueTrue
Fake Refund Scam Hits Shopify Shop App Users2026-08-13TrueTrue
Akira Hits Safe Mode: Ransomware Rebooting Around EDR2026-08-12TrueTrue
Five Years, 88,000 Backdoors, and a Pair of Handcuffs: Inside the Global Manhunt That Ended in an Arrest2026-08-10TrueTrue
From Screen Share to Root Access: Breaking Down CVE-2026-43760 and CVE-2026-65400 on macOS2026-08-07TrueTrue
Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam2026-08-06TrueTrue
Inside an Oracle Database SQL Injection Attack | Huntress 2026-08-05TrueTrue
Bank of America Phishing Email Delivers ScreenConnect Malware2026-08-04TrueTrue
Why App Control Fails Most Teams and How Managed ESPM Fixes It 2026-08-03TrueTrue
Critical N-able N-central Vulnerability and Active Exploitation2026-08-03TrueTrue
Device Code Phishing Keeps Evolving. Here’s What to Watch For2026-07-31TrueTrue
Reverse Engineering the Six Stages of MacSync Stealer and RAT 2026-07-29TrueTrue
Credential Stuffing Campaign Hits SonicWall | Huntress SOC Tracking2026-07-28TrueTrue
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT2026-07-22TrueTrue
How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant2026-07-22TrueTrue
What Are Initial Access Brokers?2026-07-21TrueTrue
Every Ransomware Attack Has a Backstory2026-07-15TrueTrue
5 Modern Threats You Need to Watch2026-07-14TrueTrue
Threat Actors Achieve Persistence After SQL Injection2026-07-13TrueTrue
CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware | Huntress2026-07-09TrueTrue
Conditional Access Misconfigurations Exposed 55 Orgs with MFA On2026-07-09TrueTrue
AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration | Huntress2026-07-08TrueTrue
Meta Phishers Abuse Business Account Manager Service | Huntress2026-07-07TrueTrue
How the RaaS Business Model Actually Works2026-07-01TrueTrue
No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack2026-06-30TrueTrue
The Hacker's 2026 Playbook: Dark Web Tactics Targeting You2026-06-29TrueTrue
Defence Impairment Olympics2026-06-29TrueTrue
From Code to Coverage (Part 6): What netlogon.log Sees That Event 1644 Never Will2026-06-24TrueTrue
We Need to Talk About Device Code Phishing2026-06-22TrueTrue
Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress2026-06-22TrueTrue
Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress2026-06-18TrueTrue
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack2026-06-16TrueTrue
The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed2026-06-15TrueTrue
Akira, LimeWire, and the Sour Taste of Data Exfiltration2026-06-12TrueTrue
Inside Kali365, a Device Code Phishing Ecosystem | Huntress2026-06-11TrueTrue
Deceptive Installers: How Fake Apps Target macOS 2026-06-10TrueTrue
Inside .NET Loader Analysis: From Malspam to In-Memory Loader 2026-06-03TrueTrue
Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix2026-06-02TrueTrue
Unpatched NTLM Leakage in Windows search: URI Handler, Same Bug, No CVE, No Fix2026-06-02TrueTrue
Your Profile Is a Dossier. Here's Who's Reading It.2026-05-28TrueTrue
From Cookies to Keys: The Threat of Session Hijacking2026-05-26TrueTrue
The Gentleman Ransomware | Defense Evasion TTPs Uncovered | Huntress2026-05-21TrueTrue
Inside the RaaS Ecosystem: Operators, Affiliates & Attack Tradecraft | Huntress2026-05-20TrueTrue
Exposed RDP: The Misconfiguration Attackers Keep Exploiting2026-05-19TrueTrue
Threat Actor Defense Evasion: How Attackers Disable AV & EDR 2026-05-18TrueTrue

1–50 of 330