The Dangers of Storing Unencrypted Passwords
ID: 0e19a4a5-e621-5bcf-b676-50b95c45254f
STIX ID: report--0e19a4a5-e621-5bcf-b676-50b95c45254f
Feed Name: Huntress Blog
Threat Score
Huntress SOC investigated a SonicWall VPN compromise that enabled Akira ransomware execution and the placement of rogue systems without EDR coverage; attackers located plaintext Huntress recovery codes on an engineer's desktop, used them to log into the Huntress portal from 104.238.221.69 to suppress alerts and uninstall agents, and exported a certificate PFX—demonstrating MFA bypass, credential theft, and attempts to disable detection and persist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
