Cracks in the Foundation: Intrusions of FOUNDATION Accounting Software | Huntress
ID: e79962e2-3c81-5457-b263-28d853004d56
STIX ID: report--e79962e2-3c81-5457-b263-28d853004d56
Feed Name: Huntress Blog
Huntress discovered an active campaign targeting FOUNDATION Accounting Software where publicly exposed MSSQL instances (commonly on TCP/4243) were brute-forced using default 'sa'/'dba' credentials; attackers enabled xp_cmdshell to execute OS commands, with ~33 confirmed exposed hosts and evidence of large-scale brute force activity (one host observed with ~35,000 attempts). Recommended mitigations include rotating database credentials, removing public exposure of the application, and disabling xp_cmdshell where appropriate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
