Investigating Unauthorized Access: Huntress QA Environment Incident | Huntress
ID: fcc43ebb-be77-543e-b185-61537496de71
STIX ID: report--fcc43ebb-be77-543e-b185-61537496de71
Feed Name: Huntress Blog
Huntress disclosed an incident in which an orphaned Windows VM in a segmented QA AWS environment was brute-forced via RDP using weak credentials (Administrator/abc123!!!), causing the VM to scan the internet; no customer data, billing information, production systems, or source code were accessed. The team investigated logs, terminated long-running VMs, validated no lateral movement or CI/CD access, rotated keys, rebuilt the QA environment with disabled RDP and per-run SSH keys, fixed provisioning bugs, and implemented tighter AWS roles, tagging for auto-termination, and security training and incident response processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
