2026-07-07
- threat intel
ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit
Elastic Security Labs discovered REF6045, a Mexican banking fraud operation that uses fake CAPTCHA pages to trick victims into installing SCMBANKER, a PowerShell toolkit designed for operator-assisted fraud. The human-controlled operation monitors infected machines to intercept banking sessions, manipulate credentials, and facilitate takeovers through techniques including screen locking, vishing overlays, clipboard manipulation, and remote access tool deployment. The operation's infrastructure exposed multiple OPSEC failures that revealed targeting of Mexican banks, fintechs, payment processors, and cryptocurrency exchanges.
Why it matters: Banks, fintechs, payment processors, and cryptocurrency exchanges operating in Mexico face immediate risk from this active banking fraud toolkit; security teams should implement detection for SCMBANKER PowerShell signatures, monitor for fake CAPTCHA delivery domains, and alert on bitsadmin downloads from suspicious servers.
- breaches incidents
Accenture confirms breach after hacker offers stolen data for sale
Accenture confirmed a security breach after a threat actor claimed to possess 35 GB of stolen source code and other data from the company. The attacker publicly offered the stolen information for sale. Accenture has not yet disclosed additional details about the scope, timeline, or remediation efforts.
Why it matters: Accenture customers and partners need to assess exposure of their data that may have been accessed during this breach, and security teams should monitor for any disclosed credentials or intellectual property that could be weaponized against their organization.
- threat intel
Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
Researchers analyzed a cybercrime campaign deploying Vidar Stealer through a combination of novel evasion techniques, including a Go-compiled loader framework and DLL sideloading via a spoofed MpClient.dll. The attackers leveraged code signing abuse to enhance legitimacy and bypass security controls.
Why it matters: Organizations need to monitor for Vidar Stealer campaigns using these evasion tactics, as the Go loader and DLL sideloading techniques represent an evolving threat that may evade traditional endpoint detection methods.
- ai security
Deepfake CSAM lawsuit against xAI, Grok expands
A class-action lawsuit against xAI's Grok tool has been expanded to include two additional plaintiffs alleging the AI model was used to generate nonconsensual deepfake child sexual abuse material (CSAM) based on their images. The complaint details cases where minors' photos were exploited through Grok to create thousands of illegal images that were shared online, and adds Stability AI as a defendant for releasing Stable Diffusion 1.0 with insufficient safeguards despite knowing its training data contained CSAM. The lawsuit claims both companies failed to implement adequate content moderation and disclosure practices that would have aided law enforcement investigations.
Why it matters: Security and compliance teams at AI companies and platforms face immediate liability exposure and regulatory pressure to audit training datasets, implement robust safeguards against CSAM generation, and establish clear reporting procedures to law enforcement. Organizations deploying or fine-tuning foundation models must verify their content moderation capabilities and document their guardrail decisions, as inadequate protections can result in significant legal liability and reputational harm.
- threat intel
Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese threat actors known as UAT-7810 are developing LONGLEASH malware to compromise internet-facing networking devices, particularly unpatched Ruckus routers, to expand their Operational Relay Box (ORB) botnet infrastructure. The group is actively iterating on malware capabilities to target networking hardware and establish persistent access across victim networks.
Why it matters: Network administrators and organizations using Ruckus routers face direct compromise risk from UAT-7810's expanding infrastructure; patching exposed routers and monitoring for ORB network indicators should be immediate priorities.
- vulnerabilities
OMB M-26-14: Why federal agencies must fix asset visibility first
OMB Memorandum M-26-14 replaces the previous logging directive with a five-level maturity model that ties logging progress to asset visibility, requiring federal agencies to demonstrate 70-95% IT, OT, and IoT asset capture across increasingly stringent timelines. The directive organizes logging around continuous event monitoring and threat hunting, with overall maturity calculated using a lowest-watermark approach where incomplete inventory visibility caps an agency's entire rating regardless of other achievements. Agencies must close asset-inventory gaps immediately to meet strict deadlines, with level 1 maturity due 120 days after CISA publishes the logging reference architecture.
Why it matters: Federal agencies and their vendors must prioritize asset discovery now; incomplete inventory visibility will prevent any agency from advancing past level 1 maturity and delaying remediation creates compounding compliance risk under the lowest-watermark scoring model.
- threat intel
More Odd DNS Records: NIMLOC
DNS resource record type 32 (NIMLOC) is historically assigned to obsolete protocols but continues to appear in network logs, particularly from macOS systems broadcasting NetBIOS name announcements on port 137. The record type was originally designated for Nimrod routing architecture but is now primarily associated with legacy NetBIOS traffic, a protocol largely replaced by modern DNS and SMB implementations on contemporary networks.
Why it matters: Security practitioners monitoring DNS logs should recognize NIMLOC queries as benign legacy NetBIOS traffic from macOS systems rather than indicators of compromise, avoiding false positives while remaining alert to unexpected sources of these outdated protocol broadcasts.
- vulnerabilitiesCVE-2026-20896
Critical Gitea Flaw Under Active Exploitation, Researchers Warn
A critical vulnerability in Gitea (CVE-2026-20896) allows attackers to bypass authentication by manipulating a single HTTP header, granting access to repositories and secrets. Researchers have confirmed the flaw is under active exploitation in the wild.
Why it matters: Organizations running Gitea instances are at immediate risk of unauthorized repository access and credential theft; patching or disabling the affected authentication mechanism should be prioritized today.
- threat intel
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
RedWing is a new Android malware operation being offered as a rental service on Telegram that enables attackers to take control of victim devices, extract banking credentials, and intercept one-time authentication codes. Zimperium's zLabs attributes the malware to a variant of Oblivion, a subscription-based malware tool priced at $300 per month.
Why it matters: Mobile banking customers and financial institutions face escalating fraud risk as malware-as-a-service (MaaS) offerings lower barriers to entry for cybercriminals and increase the attack surface against authentication mechanisms that protect online accounts.
- ransomware
Hacked, leaked, and held for ransom: The worst breaches of 2026 so far
2026 has seen several significant security incidents including a major breach affecting the Department of Government Efficiency (DOGE), compromises to critical energy and water infrastructure systems, and unauthorized access to an FBI surveillance system. These incidents represent a range of targets from government agencies to essential services infrastructure. The article highlights the most damaging breaches and incidents of the year to date.
Why it matters: Security practitioners need to assess exposure across federal agencies, critical infrastructure operators, and law enforcement systems, and review their own incident response protocols for comparable attack vectors targeting sensitive government and infrastructure assets.
- vulnerabilities
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
Varonis discovered a critical vulnerability in Google Dialogflow CX that could have allowed an attacker with edit rights on one Code Block-enabled agent to compromise other agents within the same Google Cloud project. An exploited flaw would have enabled attackers to read live conversations, steal user data, and inject malicious messages into chatbot interactions.
Why it matters: Organizations using Dialogflow CX with Code Block agents in shared Google Cloud projects face exposure to data theft and conversation manipulation until the patch is applied; practitioners should verify their deployment model and prioritize patching.
- government policy
Supreme Court allows Texas app law requiring age verification to take effect
The Supreme Court declined to block the Texas App Store Accountability Act, allowing the law requiring age verification in app stores to take effect while litigation continues. A student advocacy organization and tech trade group had sought an emergency stay of the law pending lower court proceedings.
Why it matters: App developers, app stores, and platforms operating in Texas must implement age verification mechanisms or face legal exposure under this new state law, and the Supreme Court's decision indicates a higher bar for emergency relief against state digital regulation.
- ai security
Britain plans to build autonomous AI 'Cyber Shield' to defend nation
Britain is developing an autonomous artificial intelligence system called Cyber Shield to defend critical infrastructure and networks against large-scale, rapid cyberattacks. The National Cyber Security Centre (NCSC) describes the threat landscape as evolving toward machine-speed attacks at greater scale, which reduces human response windows. The AI-driven capability aims to enable faster detection and response than traditional security approaches.
Why it matters: UK government agencies, critical infrastructure operators, and enterprises should track this initiative as it signals policy direction on AI-assisted defense, potential future procurement requirements, and evolving incident response expectations for critical assets.
- vulnerabilities
'GitLost' Flaw Leaks Private Data from GitHub's Agentic Workflows
A vulnerability in GitHub's Agentic Workflows allows unauthenticated attackers to craft a malicious GitHub Issue in a public repository to extract data from private repositories within the same organization. The flaw, dubbed GitLost, enables silent data exfiltration without requiring authentication or explicit permissions.
Why it matters: Development teams using GitHub's Agentic Workflows may have sensitive code and credentials exposed in private repositories; practitioners should audit workflow configurations and consider disabling or restricting agentic features until GitHub patches this vulnerability.
- threat intel
Spain arrests suspected member of pro-Russian hacktivist groups
Spanish National Police arrested a suspect believed to be an active member of CyberArmy of Russia Reborn (CARR) and Z-Pentest, both pro-Russian hacktivist groups. The arrest represents law enforcement action against individuals allegedly involved in coordinated hacking activities aligned with Russian interests.
Why it matters: Organizations targeted by pro-Russian hacktivist groups should assess their exposure to credential theft, data exfiltration, and service disruption; law enforcement gains traction against these actors, but operational capability persists.
- threat intel
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A phishing campaign targeting Microsoft 365 accounts has exploited the Microsoft device-code authentication flow using collaboration-themed lures. Rather than employing fake login pages, the attackers directed victims to the legitimate Microsoft device login process, potentially making the attack more credible to users.
Why it matters: M365 users and administrators need to recognize device-code phishing techniques as a threat vector, since these attacks bypass traditional password page detection and can lead to account compromise.
- breaches incidents
Major Japanese telco says cyberattack exposed 12 million emails
A major Japanese telecommunications company disclosed that a cyberattack compromised an email system serving multiple internet service providers, affecting approximately 12 million email addresses. The affected system managed customer email accounts, webmail services, and email storage across five Japanese ISPs.
Why it matters: ISP and email customers across Japan face potential credential and personal data exposure; practitioners should assess whether their organization uses services from the affected telco or ISPs and implement credential monitoring.
- cloud saas
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
Researchers at Noma Security identified a vulnerability in GitHub Agentic Workflows where a public issue in a repository can be crafted to trick the workflow agent into leaking contents from private repositories. The attack requires only the ability to open an issue on a public repository and relies on the organization having granted the agent read access across its repositories.
Why it matters: Organizations using GitHub Agentic Workflows with broad repository access are at risk of private repository data exposure through public issue manipulation; practitioners should review workflow permissions and access controls immediately.
- threat intel
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
ActiveState has identified attack patterns in GitHub Actions that bypass conventional CI security scanners, demonstrating that passing a security scan does not ensure pipeline security. The article discusses governance strategies to better protect CI/CD workflows from these evasion techniques.
Why it matters: Development and security teams need to understand these GitHub Actions attack vectors to prevent CI/CD pipeline compromises that could lead to supply chain attacks affecting downstream users and customers.
- vulnerabilities
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
Mandiant researchers identified a configuration drift vulnerability in Microsoft ADFS environments where manually rotated certificates leave active signing keys exposed in Machine DPAPI, separate from the database records. When AutoCertificateRollover is disabled and administrators perform manual certificate rotation without updating the WID configuration database, attackers can extract the active signing key and forge valid SAML tokens for any user. This technique bypasses traditional detection methods because it avoids interaction with monitored components like LSASS and the live ADFS service process.
Why it matters: Enterprises with manually rotated ADFS certificates and disabled AutoCertificateRollover are at immediate risk of forged SAML token attacks that bypass MFA and conditional access controls, allowing attackers to impersonate any user in Microsoft 365 and Entra ID environments.
- identity access
Barracuda adds PAM and identity protection with Evo Security acquisition
Barracuda Networks acquired Evo Security to expand its BarracudaONE platform with privileged access management, access control, identity protection, and identity threat detection capabilities. The acquisition consolidates identity security functions into a unified platform as the identity and access management market experiences double-digit growth.
Why it matters: Security teams evaluating identity and access solutions should track Barracuda's expanded platform capabilities, as integrated PAM and threat detection could affect your organization's architecture and vendor consolidation strategy.
- cloud saas
CyberProof Agentic MXDR Service brings AI agents to managed detection and response
CyberProof announced a new managed detection and response service that integrates AI agents with human security experts and automated threat intelligence, hunting, and exposure management capabilities. The service aims to replace manual security operations workflows with AI-driven systems while keeping human analysts in decision-making roles.
Why it matters: Security operations teams considering MXDR providers should evaluate whether agentic AI integration improves detection speed and reduces manual triage work, as adoption of these tools is becoming standard in the market.
- vulnerabilities
Picus Autonomous Exposure Validation Platform validates real-world CVE exploitability
Picus Security released an Autonomous Exposure Validation Platform designed to assess whether published CVEs can actually exploit an organization's environment. The platform addresses the challenge of rapid CVE weaponization, with approximately 132 new CVEs published daily and adversaries creating exploits within hours of disclosure.
Why it matters: Security teams need to rapidly determine CVE exposure and exploitability against their controls; this platform helps prioritize patching among the high volume of daily disclosures.
- threat intel
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
Federal prosecutors used a persistent Windows device identifier to link a 19-year-old suspect named Peter Stokes to a Scattered Spider attack on a luxury jewelry retailer in May 2025. Microsoft records traced the device ID from the attacker's persistence account to online accounts associated with the suspect. The connection was revealed in an unsealed federal complaint.
Why it matters: Defenders and forensic teams should understand that Windows device IDs can serve as persistent identifiers connecting threat actors across intrusions and online accounts, making them valuable for attribution and investigation.
- vulnerabilities
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
Researchers disclosed a critical session isolation vulnerability in Writer, an enterprise AI platform, that has been patched. The flaw, termed WriteOut, could allow attackers to leak session tokens and achieve cross-tenant compromise with minimal effort.
Why it matters: Organizations using Writer AI face potential unauthorized access to other tenants' sessions and data if they have not yet patched; security teams should verify the patch status immediately.
- government policy
CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws
The Cybersecurity and Infrastructure Security Agency (CISA) is reportedly using Anthropic's Mythos tool to scan government software for vulnerabilities. CISA's Attack Surface Evaluation team, which conducts digital defense assessments and simulated exercises, is leading these audits.
Why it matters: Government IT teams and software vendors should understand that CISA is actively scanning systems with AI-powered tools and may report findings through established disclosure channels, affecting patch priorities and remediation timelines.
- breaches incidents
Hacktivists call out Trump by hacking and defacing US Army websites
Hacktivists compromised two U.S. Army websites and replaced content with political messages targeting President Trump. The Army subsequently remediated the affected sites.
Why it matters: U.S. government web infrastructure operators need to assess whether these compromises represent broader vulnerabilities in their security posture and implement additional defensive measures.
- government policy
UK cyber pledge draws only a handful of top firms despite ministerial appeal
The UK government's cyber pledge initiative has attracted limited participation from major corporations, despite appeals from officials. Notable signatories include Aviva, London Stock Exchange Group, and Marks & Spencer, along with smaller cybersecurity consulting firms.
Why it matters: UK businesses and policymakers should understand the uptake challenges of voluntary cybersecurity commitments; low participation may indicate gaps in incentive structures or perceived burden on large organizations.
- ai security
Commvault measures cyber recovery readiness with AI attack simulations
Commvault has launched Minutes to Recovery, a simulation platform that uses AI-driven attack scenarios to test organizations' cyber resilience and recovery capabilities. Participants role-play as attackers and defenders to measure their organization's response times, reflecting a threat landscape where the time from vulnerability discovery to active exploitation has compressed to 29 minutes in 2025.
Why it matters: Security teams and incident responders should evaluate their recovery capabilities against realistic, accelerated attack timelines; the 29-minute window means detection and response must be faster than ever before.
- breaches incidents
Bojangles sued again by workers over Russian hacker data breach. NC judge weighs in
Bojangles faces renewed class-action litigation from workers over a 2024 data breach attributed to Russian-linked group Hunters International. A North Carolina judge is reviewing standing and negligence claims in the case, which has progressed through multiple court proceedings with varying outcomes for plaintiffs.
Why it matters: Employees affected by the breach should track this litigation for potential compensation, and restaurants and other retailers need to understand emerging standards for negligence liability and breach notification following the court's ruling.
- breaches incidents
Jacksonville, Texas, keeps some city systems offline after cyber incident
Jacksonville, Texas detected suspicious network activity on July 3 and took some city systems offline in response to a confirmed cybersecurity incident. As of Monday, multiple online services remained unavailable while officials continued investigating the breach.
Why it matters: City residents and businesses depending on municipal services face disruptions, and IT teams should monitor whether this incident involved ransomware or data exfiltration requiring incident response coordination.
- threat intel
Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks
Iran-linked threat actors are deploying a modular command and control (C&C) framework to conduct cyberattacks, using compromised IT service providers as intermediaries to access high-value targets in Israel. The modular design of the malware enables attackers to customize their payload and tactics for specific targets.
Why it matters: Organizations using IT service providers, particularly those in Israel or with Israeli operations, face elevated risk from nation-state actors leveraging supply chain compromises; practitioners should assess third-party provider security controls and network segmentation to limit lateral movement impact.
- threat intel
Webinar tomorrow: Why modern email attacks require a new approach to defense
A webinar scheduled for tomorrow will discuss how behavioral artificial intelligence (AI) can help organizations detect sophisticated phishing, business email compromise, and account takeover attacks while reducing alert fatigue through automated investigation and response workflows.
Why it matters: Security teams managing email threats need to understand new detection approaches that can handle evolving attack tactics while maintaining operational efficiency.
- vulnerabilities
New Januscape Linux flaw allows VM escape on Intel, AMD devices
A 16-year-old Linux kernel vulnerability tracked as Januscape enables attackers to escape virtual machines and execute arbitrary code on the host system. The flaw affects both Intel and AMD devices running vulnerable Linux kernel versions.
Why it matters: Infrastructure teams running Linux VMs on Intel or AMD hardware need to patch immediately, as successful exploitation grants attackers direct access to the hypervisor and other co-hosted systems.
- vulnerabilitiesCVE-2025-1352CVE-2025-1376
Siemens SINEC OS
Siemens has released version 4.0 of SINEC OS to address multiple vulnerabilities in the RUGGEDCOM RST2428P industrial switch, including memory corruption, denial of service, and access control issues. The vulnerabilities affect versions prior to 4.0 and are tracked across numerous CVEs with CVSS scores ranging from low to critical. Siemens recommends immediate update to version 4.0 or later.
Why it matters: Organizations operating critical infrastructure (manufacturing, energy, healthcare, transportation) using RUGGEDCOM RST2428P devices must update to SINEC OS 4.0 to prevent remote exploitation and denial of service attacks on industrial network segments.
- vulnerabilitiesCVE-2026-42953CVE-2026-42958
Labcenter Proteus 9
Labcenter Electronics has disclosed three high-severity vulnerabilities in Proteus 9 version 9.1_SP4_Build_42914: an out-of-bounds write, stack-based buffer overflow, and use-after-free flaw. All three flaws carry CVSS scores of 7.8 to 8.4 and can lead to arbitrary code execution when parsing specially crafted files. The vendor recommends upgrading to version 9.2_SP0.
Why it matters: Organizations using Proteus 9 in critical infrastructure sectors (communications, manufacturing, defense, energy, healthcare, transportation, water systems) face code execution risk from local exploitation; immediate patching to version 9.2_SP0 is required.
- vulnerabilitiesCVE-2026-42945
Hitachi Energy e-mesh EMS
Hitachi Energy has disclosed a heap-based buffer overflow vulnerability (CVE-2026-42945) in its e-mesh EMS product versions 4.1.6, 4.4.2, and 4.7.0, caused by an NGINX module flaw. The vulnerability, with a CVSS 3.1 score of 8.1, could allow unauthenticated attackers to cause denial of service or execute arbitrary code by sending crafted HTTP requests, particularly on systems without Address Space Layout Randomization (ASLR) enabled. Hitachi Energy recommends applying hotfixes to update NGINX to version 1.30.2 or later, and has provided interim mitigations including configuration changes and operating system upgrades.
Why it matters: Energy sector organizations operating e-mesh EMS 4.1.6, 4.4.2, or 4.7.0 globally should immediately apply NGINX hotfixes or implement mitigations to prevent denial of service or code execution against critical infrastructure.
- vulnerabilitiesCVE-2026-12352CVE-2026-12948
Digi International PortServer TS, Digi One SP IA
Digi International PortServer TS and Digi One SP series devices contain two vulnerabilities in firmware versions prior to 2025: an authentication bypass (CVE-2026-12352) that allows unauthenticated access to restricted resources, and a stored cross-site scripting (XSS) flaw (CVE-2026-12948) in the web management interface. Digi recommends upgrading to Digi Connect EZ models or applying mitigations including enabling HTTPS, disabling unused web servers, and restricting network access.
Why it matters: Organizations deploying these serial console and device management appliances in critical manufacturing, communications, transportation, and IT environments worldwide face immediate risk of unauthorized access and credential theft; administrators should prioritize firmware updates or apply compensating controls such as HTTPS enablement and network segmentation to limit exposure.
- vulnerabilitiesCVE-2026-48192
Siemens Mendix Studio Pro
A file parsing vulnerability in Siemens Mendix Studio Pro versions before 11.12 could allow arbitrary code execution when a user opens a specially crafted malicious project file during the build process. Siemens has released patches for some affected versions (10.24.21 and 11.6.7) and recommends immediate updates where available. The vulnerability has a CVSS score of 5.4 and affects multiple Mendix Studio Pro versions across the 10.x and 11.x release lines.
Why it matters: Development teams and organizations using Mendix Studio Pro should immediately update to patched versions (10.24.21 or 11.6.7+) to prevent potential code execution attacks that could compromise development environments and systems in critical manufacturing and energy sectors.
- vulnerabilitiesCVE-2026-20744CVE-2026-42952
Hydro-Québec Le Circuit Electrique charging station backend
Hydro-Québec's Le Circuit Electrique charging station backend contains three critical vulnerabilities affecting versions prior to June 2026, including improper authentication on websocket endpoints, lack of throttling on authentication attempts, and insufficient session management. These flaws could enable privilege escalation, denial-of-service attacks, and backend overwhelm via malicious OCPP (Open Charge Point Protocol) clients. Hydro-Québec has mitigated the risks by disabling OCPP on most stations and implementing authentication systems on remaining affected infrastructure.
Why it matters: Electric vehicle charging infrastructure operators in Canada and those managing OCPP-dependent systems should verify their station versions and confirm remediation status with Hydro-Québec, as unauthenticated network access to charging backends creates both operational availability and potential supply chain risks.
- ransomware
Savi’s app aims to protect consumers from realistic AI scams like kidnappers demanding ransom
Savi, a startup focused on protecting consumers from AI-generated scams such as deepfake kidnapping extortion, has raised $7 million in seed funding and is launching its mobile app for iPhone and Android.
Why it matters: Consumers and their families face increasing risk from synthetic media scams targeting emotional vulnerabilities; practitioners should monitor this emerging threat category and understand detection limitations as AI generation quality improves.
- government policy
Cyber Shield: The path to an agentic AI future for cyber defence
The United Kingdom is developing a sovereign artificial intelligence (AI) initiative aimed at scaling cyber defence capabilities at the national level. This effort positions the UK to build independent, AI-driven defense systems without reliance on external vendors or infrastructure.
Why it matters: Government security leaders and defence contractors should monitor this initiative to understand emerging UK cyber strategy and potential procurement opportunities for sovereign AI defense platforms.
- industry
CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker
Tarah Wheeler, CISO at TPO Group, a cybersecurity consultancy firm serving high-stakes organizations, is featured in an interview about her career and leadership perspective. The article highlights her professional journey and insights as a security executive.
Why it matters: Security leaders seeking insights into CISO career paths and industry perspectives may find relevant experience and advice applicable to their own organizational challenges.
- ai security
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
The article discusses how artificial intelligence integration into software development pipelines has introduced new complexity to supply chain security beyond traditional dependency management concerns. It references past incidents like SolarWinds, Log4Shell, and XZ Utils to highlight how software supply chain risks extend beyond visible code components.
Why it matters: Development teams and security practitioners need to understand how AI-generated code in build pipelines creates new attack surfaces and vendor dependencies that existing supply chain security practices may not adequately address.
- ai security
Radware updates Agentic AI Protection with AI governance and compliance capabilities
Radware has released updates to its Agentic AI Protection platform, adding compliance reporting, improved visibility into agent ecosystems, and support for developer-hosted AI agents like Anthropic Claude Code. The enhancements address enterprise demand for governance, transparency, and accountability as organizations scale AI agent deployments.
Why it matters: Security and compliance teams deploying AI agents need to evaluate whether Radware's governance and compliance capabilities meet your organization's regulatory requirements and control requirements for agent-based AI systems.
- research
Google Is Suing Chinese Scammers Who Are Using Gemini
Google filed a lawsuit against Outsider Enterprise, a Chinese scam operation that uses Telegram to offer phishing-as-a-service. The group provided instructions on leveraging Google's Gemini AI to create fraudulent websites mimicking Google, YouTube, and government agencies like New York's E-ZPass, with nearly 300 scam templates available. Google coordinated with major carriers to block malicious text messages and notes that its on-device scam detection in Google Messages blocks approximately 10 billion spam texts monthly.
Why it matters: Practitioners managing brand protection and anti-phishing defenses should monitor the accessibility of AI tools for scam creation and consider how carrier-level blocking and client-side detection integrate into layered defenses against mass phishing campaigns.
- industry
Unveiling Silent Push 6.0: MCP Server, Bulk Enrichment, New Modules and More
Silent Push released version 6.0 featuring an MCP (Model Context Protocol) server for AI tool integration, bulk enrichment capabilities for up to 100 domains or IPs, rebuilt TLP Amber reports with new API access, and reorganization into four functional modules: Defend, Insight, Reconnaissance, and Advanced Attribution.
Why it matters: Security practitioners using AI tools or conducting threat intelligence research can now integrate Silent Push directly into their workflows and process multiple indicators simultaneously, improving investigation efficiency.
- threat intelCVE-2020-22653CVE-2020-22658
UAT-7810 continues building ORB networks using new malware
Cisco Talos is tracking UAT-7810, a China-nexus APT actor that builds and maintains Operational Relay Box (ORB) networks for use by secondary threat actors. UAT-7810 has developed and deployed new malware variants including LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST, targeting Linux and embedded devices across multiple architectures. The group exploits known vulnerabilities in Ruckus wireless routers and ASUS AiCloud routers from infrastructure in Eastern Europe and Hong Kong.
Why it matters: Organizations using Ruckus wireless routers and ASUS AiCloud devices should immediately verify patches for CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492, as unpatched devices are actively being compromised to serve as ORB infrastructure for subsequent attacks against high-value targets by secondary threat actors.
- vulnerabilitiesCVE-2026-53359
Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems
A 16-year-old vulnerability in Linux's KVM hypervisor, dubbed Januscape, allows attackers to escape virtual machines and execute code on the underlying host system on both Intel and AMD processors. The flaw represents a critical privilege escalation path from guest to host in virtualized environments.
Why it matters: Organizations running Linux KVM hypervisors with untrusted guest workloads face host compromise; practitioners should prioritize patching and assessing whether guest isolation assumptions remain valid.
- threat intel
The Security Loop: Continuously Improving Preemptive Defense
Silent Push describes a continuous security improvement methodology where security teams use threat intelligence to map related infrastructure, understand wider threat context, and feed learnings back into detection systems. Rather than treating each alert as an isolated incident, teams use this cycle to progressively improve detection, response, and prevention capabilities.
Why it matters: Security practitioners should evaluate whether their incident response processes systematically convert findings into detection improvements and infrastructure blocking, as continuous learning cycles can reduce detection time for related threats.
- ai security
Using Preemptive Cyber Defense Data in AI Agents and Workflows
Silent Push demonstrates how AI agents can enhance preemptive cyber defense by enriching indicators, identifying related infrastructure, and feeding intelligence into SOAR and SIEM systems. The approach enables security teams to detect and monitor emerging attacker infrastructure before it becomes active, scaling threat hunting and making it more proactive.
Why it matters: Security teams evaluating AI-assisted threat detection should consider how agent-based enrichment and infrastructure clustering can accelerate identification of attacker campaigns before exploitation occurs.
- cloud saas
Microsoft to enable Windows settings backup by default for orgs
Microsoft will automatically enable the Windows settings backup and restore feature for organizations using Microsoft Entra-joined or hybrid-joined systems when they upgrade to Windows 11 26H2. This change streamlines configuration management for enterprise deployments by making the backup capability opt-out rather than opt-in.
Why it matters: Enterprise IT administrators managing Windows 11 deployments need to review backup policies and ensure this default behavior aligns with their security and data residency requirements, particularly regarding where settings are stored.
- industry
Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security
The company Keyfactor announced a funding round exceeding $1 billion to advance its machine identity, public key infrastructure (PKI), and cryptographic security platform. The investment is intended to support product development for emerging threats from artificial intelligence and post-quantum computing.
Why it matters: Security leaders evaluating PKI and machine identity solutions should monitor Keyfactor's roadmap as the company expands capabilities for post-quantum cryptography and AI-driven threat scenarios that may affect certificate and key management strategies.
- threat intel
Silent Push and NYSE Discuss Preemptive Cyber Defense
Silent Push and the New York Stock Exchange discussed approaches to preemptive cyber defense and how threat intelligence can shift from reactive to proactive. The discussion focused on Indicators of Future Attack (IOFA), which identify adversary infrastructure and behavior patterns before attacks are launched, allowing security teams to block threats proactively rather than respond after detection.
Why it matters: Financial services and critical infrastructure operators need to understand evolving threat intelligence methodologies to stay ahead of sophisticated adversaries targeting high-value assets.
- vulnerabilitiesCVE-2024-42009
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
A suspected China-aligned threat group is exploiting patched critical vulnerabilities in Roundcube webmail software at U.S. and Canadian university physics and engineering departments to steal credentials. The campaign leverages flaws including CVE-2024-42009, a critical vulnerability with a CVSS score of 9.3 in the open-source email solution.
Why it matters: Universities and organizations running unpatched Roundcube instances need to patch immediately; academic researchers and their email accounts are actively targeted for credential theft by state-aligned attackers.
- threat intel
The 5 Stages to Common Finance Fraud Attacks—and How to Stop Them
Financial institutions face coordinated fraud attacks that progress through five stages: credential harvesting, AI-generated phishing, executive impersonation, account takeover, and money movement. Organizations can disrupt these chains by implementing phishing-resistant authentication, domain monitoring, out-of-band payment verification, and cross-system behavioral correlation rather than relying on perimeter defenses alone.
Why it matters: Finance teams and security practitioners need to shift from infrastructure-focused defense to identity and behavioral controls, as attackers now target human trust and approval workflows; implementing the staged controls described could prevent wire fraud before credentials are even validated.
- vulnerabilities
BeyondTrust warns of critical flaws in remote access software
BeyondTrust has disclosed two critical vulnerabilities in its Remote Support and Privileged Remote Access products that could allow attackers to circumvent authentication mechanisms. The company is urging customers to apply patches immediately to address these flaws.
Why it matters: Organizations using BeyondTrust remote access solutions face immediate risk of unauthorized access; patching is required today to prevent exploitation.
- cloud saas
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
Microsoft is testing a Cloud Rebuild recovery feature for Windows 11 through its Insider Preview program in the Experimental channel. This feature allows users to recover their systems using cloud-based resources rather than traditional local recovery methods. The company is gathering feedback from testers before a broader release.
Why it matters: Organizations managing Windows 11 deployments should monitor this feature as it may change recovery procedures and introduce dependencies on cloud connectivity for incident response and system restoration.
- vulnerabilitiesCVE-2026-11405
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
CERT/CC disclosed that multiple versions of Tenda router firmware contain an undocumented authentication backdoor allowing attackers to bypass password verification and gain administrative access to the web management interface. The vulnerability, tracked as CVE-2026-11405, affects Chinese network device manufacturer Tenda's firmware releases.
Why it matters: Organizations and home users running affected Tenda routers face unauthorized admin access and network compromise; patch or replace affected devices immediately if in use.
- ai security
Researchers make the case for a cybersecurity AI scientist
Researchers at the Chinese Academy of Sciences have proposed the concept of a Cybersecurity AI Scientist to automate security research tasks. The paper describes AI agents that could autonomously conduct vulnerability discovery, penetration testing, and attack chain analysis, addressing the traditional bottleneck of manual, expert-driven security research.
Why it matters: Security teams and researchers should monitor developments in AI-driven vulnerability research capabilities, as autonomous agents could accelerate both attack discovery and defense, affecting threat modeling and research prioritization decisions.
- ai security
Review: Building Machine Learning Systems with a Feature Store
This article reviews Jim Dowling's O'Reilly book on building machine learning systems using a feature store approach, based on a course taught at KTH Stockholm. The book addresses the practical challenge of moving from model training on clean data to deploying and maintaining models in production environments with fresh data streams.
Why it matters: Security practitioners developing or deploying machine learning systems should understand feature store architecture and data pipeline management, as these components directly impact model reliability, data integrity, and the security posture of ML systems in production.
- ai security
Your company already adopted AI and nobody is governing access
Enterprises are adopting AI tools and integrations without formal governance, creating unmanaged security exposures across multiple vectors. Organizations lack visibility into unreviewed OAuth connections, inherited user permissions in AI agents, and improperly stored credentials that can be exploited. The risks span from standing OAuth grants to agent credentials and copilot permission inheritance.
Why it matters: Security teams need immediate visibility and control over shadow AI deployments and integrations; unvetted AI tool adoption connected to critical systems like Google Workspace represents a direct attack surface for credential theft and lateral movement.
- vulnerabilitiesCVE-2026-40138
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
BeyondTrust released patches for two critical authentication bypass vulnerabilities in its Remote Support and Privileged Remote Access products that could allow unauthenticated attackers to compromise affected devices. The flaws, including CVE-2026-40138 with a CVSS score of 9.2, require immediate patching to prevent unauthorized access and device takeover.
Why it matters: Organizations running BeyondTrust Remote Support or Privileged Remote Access need to apply these patches immediately, as unauthenticated remote attackers can exploit these flaws to gain full device control without credentials.
- industry
Apple Container: Open-source tool for Linux containers on the Mac
Apple has released an open-source container tool called Container that runs Linux containers as lightweight virtual machines on Apple silicon Macs. The tool is written in Swift, optimized for Apple hardware, and supports OCI-compatible images from standard registries.
Why it matters: Developers using Apple silicon need to evaluate this tool as a potential alternative to existing container solutions, particularly for local development workflows that require Linux containerization on macOS.
- ai security
Microsoft wants to keep your AI agents from going rogue
Microsoft introduced Microsoft Execution Containers (MXC), a policy-driven execution layer that enables developers to define runtime constraints for AI agents on Windows and Windows Subsystem for Linux (WSL). The SDK abstracts away low-level isolation details, allowing the operating system to enforce application constraints at runtime. This early preview feature aims to prevent AI agents from performing unauthorized actions.
Why it matters: Security and platform teams need to evaluate MXC as a native isolation mechanism for AI workloads, reducing reliance on custom security implementations and limiting the blast radius of compromised or misbehaving agents in production environments.
- ai security
Power shortages could slow AI data center expansion
NTT Data reports that rapid AI adoption is driving data center expansion while simultaneously creating infrastructure constraints around power availability, equipment, land, and permitting. Access to reliable electricity is becoming a critical factor determining where new data centers will be built, when capacity comes online, and the pace of AI project deployment. These infrastructure limitations may significantly slow the rate at which organizations can scale AI workloads.
Why it matters: Organizations planning AI infrastructure investments need to account for power availability and permitting timelines as potential bottlenecks to deployment schedules and regional expansion strategies.
- industry
Cybersecurity jobs available right now: July 7, 2026
This article lists cybersecurity job openings available as of July 7, 2026, including an Application Security Lead position at Gett focused on integrating security into the software development lifecycle and cloud infrastructure, and a Cybersecurity Analyst role at Cynet Security in the United States.
Why it matters: Security practitioners should review available positions to identify career advancement opportunities and understand current market demand for specialized roles like application security and cloud security expertise.
- research
2607_agents_vs_telemetry
An X-Ops analysis examines how artificial intelligence (AI) coding agents trigger endpoint detection and response (EDR) rules that were originally designed to catch adversarial activity. The research highlights potential blind spots in security monitoring systems when legitimate AI tools behave similarly to malicious actors.
Why it matters: Security practitioners need to understand how AI agents interact with EDR systems to avoid false positives, improve detection tuning, and ensure monitoring rules distinguish between autonomous development tools and genuine threats.
- threat intel
Use Case Deep Dive: Your EDR Fired on an IP. Here’s How to Know if it’s Part of Something Bigger.
Silent Push is hosting a webinar on July 18, 2026 demonstrating how to investigate Endpoint Detection and Response (EDR) alerts by enriching IP data, analyzing traffic origins, and identifying command and control (C2) infrastructure clusters. The session will cover techniques for determining whether a single flagged IP represents an isolated event or part of a larger attack campaign.
Why it matters: Security operations teams need practical methods to triage EDR alerts and distinguish isolated threats from coordinated campaigns to prioritize escalation and incident response actions.
- industry
Integrations of the Month
Silent Push announced three new integrations designed to incorporate preemptive threat data into existing security tools: Splunk SIEM/SOAR for automatic enrichment during log ingestion, Tines for building automated workflows without code, and an ITSM integration for incident response context. The integrations focus on making Indicators of Future Attack (IOFAs) actionable within existing security stacks rather than requiring separate consoles or manual analysis steps.
Why it matters: Security teams using Splunk, Tines, or ITSM tools can now automatically enrich alerts and block pre-weaponized infrastructure before it reaches their environment, reducing analyst context-switching and enabling faster detection of staging activity by threat actors.
- threat intel
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
Check Point Research identified Cavern Manticore, an Iran-linked advanced persistent threat group targeting Israeli government and IT organizations, operating a modular command-and-control framework built on .NET with multiple compilation formats. The framework uses uncommon binary formats (Mixed-Mode C++/CLI and Native AOT) to evade analysis tools and implements modular post-exploitation components for reconnaissance, data access, and lateral movement. Initial compromises were achieved through abuse of legitimate remote monitoring and management software already present in victim environments.
Why it matters: Israeli government, IT providers, and organizations using remote monitoring and management tools need to audit RMM deployment privileges and monitor for suspicious module loading; defenders should implement .NET runtime monitoring and recognize that low VirusTotal detection rates do not indicate safety when uncommon compilation formats are involved.
- vulnerabilitiesCVE-2026-46242CVE-2026-46817
6th July – Threat Intelligence Report
A threat intelligence bulletin reports multiple significant incidents across sectors: ransomware attacks affecting financial, defense, manufacturing, and insurance organizations; artificial intelligence threats including LLM-generated ransomware, unsafe coding agents, and phishing domain hijacking; and critical vulnerabilities in Oracle, Linux, Citrix, and Progress products with active exploitation observed.
Why it matters: Organizations using Oracle E-Business Suite, Linux, Citrix NetScaler, or Kemp LoadMaster need immediate patches for actively exploited critical flaws; financial institutions, defense contractors, and manufacturers should review ransomware incident response given recent attacks; security teams should monitor for browser-based ransomware and AI-generated phishing domains targeting their users.
- threat intel
Community Bootcamp: Live Scan - Inspect a suspicious URL right now
Silent Push is hosting a community bootcamp session focused on Live Scan, a tool for analyzing suspicious URLs. Participants can bring their own URLs for inspection or observe demonstrations during the online event scheduled for August 18, 2026.
Why it matters: Security practitioners can learn URL analysis techniques and threat detection methods applicable to phishing investigations and malware identification.
- threat intel
The Silent Push Difference
Silent Push claims to identify and track attacker infrastructure by scanning the global IPv4 and IPv6 address space daily to detect indicators of future attacks rather than post-breach indicators of compromise. The company positions its approach as proactive threat hunting based on analyzing how adversaries build and manage their infrastructure to generate digital fingerprints of attacker behavior.
Why it matters: Security teams evaluating threat intelligence capabilities should assess whether this vendor's claimed coverage of 98% of untracked attacker infrastructure and proactive indicators of future attacks deliver measurable detection advantages over traditional indicator-based approaches.
- threat intel
What is Traffic Origin?
Silent Push has introduced Traffic Origin, a security capability designed to identify the upstream source and control signals of network connections rather than relying solely on IP geolocation. The tool aims to shift security operations from reactive threat detection to proactive validation by revealing the true origin of traffic before it is weaponized.
Why it matters: Security teams can reduce dwell time and prevent compromise by identifying and blocking malicious traffic at its source based on upstream control signals, rather than waiting for infrastructure to be actively exploited.
- threat intel
Staying "Left of Boom" with Preemptive Cyber Defense
A senior threat researcher discusses proactive cyber defense techniques that focus on identifying attacker infrastructure before it becomes weaponized. The approach emphasizes tracking both static and change data in DNS and infrastructure to detect emerging campaigns and allow organizations to act ahead of threats.
Why it matters: Security teams and threat hunters can reduce response time and impact by implementing infrastructure fingerprinting and change monitoring strategies to catch adversary preparations early.
- vulnerabilitiesCVE-2026-48276CVE-2026-48277
It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)
Adobe released a security advisory on June 30 addressing multiple critical vulnerabilities in ColdFusion 2025 (Update 9 and below) and ColdFusion 2023 (Update 20 and below), including several arbitrary code execution flaws, privilege escalation issues, and file system access vulnerabilities. The analysis highlights that several vulnerabilities involve the Remote Development Services (RDS) feature, which requires being explicitly enabled and having authentication disabled to be exploited, and researchers note difficulty in mapping all disclosed CVEs to specific vulnerability details.
Why it matters: Organizations running vulnerable ColdFusion versions must apply updates immediately; those with RDS enabled and authentication disabled face immediate arbitrary code execution risk and should prioritize patching or disabling RDS until updates are deployed.
- threat intel
Context Engineering | Compaction & Agent Memory for Automated Malware Analysis
SentinelLABS evaluated OpenAI's native compaction feature, a context-management pattern that compresses prior conversation history into a denser working state for long-running agent tasks. Testing the approach on automated malware analysis, the team found compaction reduced input tokens by approximately 86% while maintaining evaluation scores, demonstrating significant cost and efficiency improvements for security workflows. Compaction is now standard infrastructure in multiple AI frameworks including those from Anthropic and Google, addressing the fundamental challenge that context accumulates faster than it remains relevant during extended agent operations.
Why it matters: Security teams building automated malware analysis or other long-running agent workflows can reduce operational costs and token consumption substantially by implementing context compaction, allowing more efficient use of AI-driven analysis tools without degrading output quality.
- ai security
Build AI Security Agents with Wiz MCP
Wiz announced a new capability called AI Agents that enables security professionals to build AI-driven security workflows using trusted security context and Wiz AI Skills. The announcement positions Wiz's platform as a foundation for automating security tasks through AI agents that can access and act on cloud security data.
Why it matters: Security teams evaluating AI-assisted tooling should understand Wiz's agent framework as a potential way to automate vulnerability management and threat response workflows, but need to test integration, accuracy, and governance controls before adopting in production environments.
- government policy
Breaking Down the White House’s Actions on Post-Quantum Cryptography Readiness
The White House has released guidance or taken action to advance U.S. readiness for post-quantum cryptography (PQC) migration. The directive signals federal commitment to preparing systems and infrastructure for quantum-resistant encryption standards. This represents a concrete step toward protecting sensitive government communications and data from future quantum computing threats.
Why it matters: Federal agencies and contractors handling sensitive data must begin assessing their cryptographic inventory and migration timelines; organizations in critical infrastructure, defense, and finance should track and prepare for similar mandates affecting their supply chains.
- ransomware
Vect and TeamPCP partner for ransomware campaigns
Security researchers have identified a partnership between Vect and TeamPCP threat actors who are leveraging credentials obtained from supply chain compromises to conduct large-scale ransomware campaigns. The coordination between these groups enables them to deploy ransomware more effectively across multiple victims by exploiting initial access gained through compromised suppliers and vendors.
Why it matters: Organizations using third-party software or services face direct risk if their vendors are targeted; practitioners should assess supply chain attack vectors and credential exposure in their environments, particularly for vendors handling sensitive systems.
- ai security
Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3
Elastic's InfoSec team built an automated security operations center using native Elastic tools that triages security alerts in under 3 minutes instead of the traditional 30-minute manual process. The system uses deterministic ES|QL queries to close obvious false positives at no cost, then routes genuinely ambiguous cases to specialized AI agents across endpoint, cloud, and SaaS domains, with a final review agent documenting conclusions in Kibana cases. The approach prioritizes query-based investigation over AI inference for well-understood patterns, reducing both cost and token consumption while allowing analysts to focus on alerts requiring human judgment.
Why it matters: Security teams managing high alert volumes need to accelerate triage without adding headcount; this architecture demonstrates how to reduce investigation time by 90 percent while controlling AI inference costs and maintaining data privacy through documented zero-retention model providers.
- ransomware
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
Researchers demonstrated a practical ransomware attack that operates entirely within a web browser on Android devices using the File System Access API, bypassing traditional malware defenses. The attack leverages social engineering through a fake image-enhancement workflow to trick users into granting file system permissions, enabling attackers to encrypt photos and other files. The research highlights how large language models like DeepSeek, with lower refusal rates for harmful requests than competitors, can convert malicious concepts into working attack code more easily than other AI platforms.
Why it matters: Android users and organizations supporting mobile workers face a new attack vector that circumvents app-based malware detection, requiring security awareness training and browser permission policy reviews to prevent social engineering exploitation of legitimate APIs.
- threat intel
Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool
Insikt Group identified new infrastructure used by TAG-182, an Iran-linked threat cluster, to distribute MarkiRAT malware through fake Android applications disguised as VPNs and media tools targeting Iranians both domestically and abroad. The malware samples share technical similarities with previously attributed Ferocious Kitten activity, suggesting a possible operational connection. Following Iran's internet restoration in May 2026, surveillance operations using these tools are expected to intensify as Iranian authorities seek to monitor perceived dissidents.
Why it matters: Security teams protecting Iranian diaspora populations, civil society organizations, and anyone using Iranian-based services should identify and block MarkiRAT indicators of compromise and educate users to avoid fake VPN and media applications from untrusted sources, as this represents active state-sponsored surveillance targeting a specific geographic and political population.
- vulnerabilitiesCVE-2025-12101CVE-2025-5777
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
Citrix has publicly disclosed CVE-2026-8451, a memory overread vulnerability in NetScaler devices that allows unauthenticated access to sensitive information. This marks another instance in a recurring pattern of memory disclosure vulnerabilities affecting NetScaler appliances, which the researcher refers to as part of the broader CitrixBleed class of issues. The vulnerability demonstrates ongoing memory management weaknesses in a critical appliance used for load balancing, SSL termination, and remote access across enterprise networks.
Why it matters: Organizations running Citrix NetScaler appliances face immediate risk of credential and sensitive data exposure from unauthenticated attackers, requiring urgent assessment of affected devices and deployment of patches or compensating controls.
- ai security
Start Secure in the AI Era: Accelerating AI Threat Readiness with WizOS
WizOS addresses the challenge of rapidly accelerating timelines between vulnerability discovery and exploitation by promoting a minimal and secure component-based building approach. The article discusses how this methodology supports organizations in strengthening their vulnerability response posture in the context of AI-driven threats.
Why it matters: Security teams need to understand frameworks that reduce attack surface and accelerate patching cycles, as zero-day windows continue to compress and AI-enabled exploitation techniques emerge.
- ransomware
Your Business Continuity Plan Was Built for Accidents. Ransomware Is Not an Accident.
Business continuity and disaster recovery (BC/DR) plans are designed for natural outages and accidents, but ransomware attackers deliberately target backup systems and data to maximize damage and extract ransom. Organizations often conflate BC/DR readiness with ransomware resilience, missing the critical need for defense-specific protections. Effective ransomware preparedness requires strategies beyond traditional continuity planning, such as immutable backups, segmented networks, and incident response procedures tailored to extortion threats.
Why it matters: Organizations relying on standard BC/DR plans without ransomware-specific defenses face material risk of prolonged recovery, data loss, and ransom pressure; practitioners should audit backup isolation, access controls, and response procedures designed explicitly for ransomware scenarios.
- cloud saas
Microsoft 365 Hardening and Huntress Managed ISPM
Most Microsoft 365 environments lack more than half of the recommended security controls despite having security tools deployed. Huntress Managed ISPM is positioned as a solution to address this control gap in Microsoft 365 deployments.
Why it matters: Microsoft 365 administrators and security teams need to audit their control implementation, as underdeployed security configurations leave environments vulnerable to compromise.
- threat intel
Train, triage, repeat: The AI agent changing how we fight phishing
Red Canary has developed an AI agent that combines machine learning, rules engines, similarity analysis, and large language models to classify phishing emails with 94% accuracy. The system demonstrates how hybrid AI approaches can enhance security operations center capabilities by automating phishing triage at scale.
Why it matters: Security teams handling high email volumes can reduce manual phishing classification workload and improve detection consistency, freeing analysts to focus on higher-risk threats and investigation.
- ransomware
What's Trending: Top Cyber Attacker Techniques, March - May 2026
A threat report covering March through May 2026 finds that ClickFix (a social engineering delivery technique) has become the dominant initial access method, driving 14.9% of spearphishing attacks and nearly 28% of defense-evasion activity while reaching macOS for the first time. The malware leaderboard underwent near-complete turnover for a second consecutive period, with defenders advised to focus on attacker behavior patterns rather than malware family names. Ransomware operators like Qilin continue exploiting unpatched internet-facing firewalls and VPNs using a consistent playbook.
Why it matters: Security teams need to shift detection focus from malware names to behavioral patterns, especially ClickFix social engineering and exploitation of unpatched edge infrastructure, since the report shows attackers are rotating malware families rapidly while techniques remain consistent, and AI is accelerating social engineering at scale.
- threat intel
The Hacker's 2026 Playbook: Dark Web Tactics Targeting You
Cybercriminals are rapidly compromising Microsoft 365 accounts using techniques that circumvent traditional security awareness training, including a method called ConsentFix. These attacks exploit common user behaviors and normal workflows to gain unauthorized access in minimal time.
Why it matters: Organizations using Microsoft 365 face immediate risk from account takeover attacks; security teams need to understand these emerging bypass techniques and adjust defenses and training accordingly.
- cloud saas
Bridging the Visibility Gap: A Unified Security Operating Model for Hybrid Cloud Teams
A vendor has released the Sensor Workload Scanner to general availability, extending its risk prioritization capabilities to on-premises environments alongside cloud infrastructure. The tool aims to help organizations identify critical attack paths across hybrid cloud deployments through unified visibility.
Why it matters: Practitioners managing hybrid cloud environments need to evaluate whether this unified scanning approach reduces the operational burden of maintaining separate visibility tools and improves prioritization of remediation efforts across disparate infrastructure.
- ransomware
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
A threat campaign leverages Bumblebee malware and AdaptixC2 command-and-control infrastructure to deliver Akira ransomware through Bing search results. The intrusions were first reported in July 2025 and subsequently observed again in August 2025 by Swisscom B2B CSIRT analysts.
Why it matters: Organizations relying on search-based malware distribution are at risk; practitioners should monitor for Bumblebee and AdaptixC2 indicators and implement detection controls for Akira ransomware deployments.
- cloud saas
The Borderless Attack Surface: Securing Public Sector Hybrid Environments
A discussion of how cloud-native application protection platform (CNAPP) telemetry can be integrated with risk assessment practices to improve security outcomes in public sector hybrid cloud environments through coordinated cross-functional efforts.
Why it matters: Public sector IT teams managing hybrid infrastructure need practical frameworks to prioritize cloud security findings and allocate resources effectively across their organizations.
- vulnerabilities
The Red Agent POV: Exploiting Broken Object-Level Authorization in an Airline GraphQL API
A red team exercise demonstrated how broken object-level authorization in a GraphQL API allowed unauthorized access to an airline's booking database. The attacker bypassed backend resolvers to expose sensitive data within fifteen minutes.
Why it matters: Airlines and any organization using GraphQL APIs need to audit object-level authorization controls immediately, as this vulnerability exposes customer booking information and personal data to unauthorized access.
- threat intel
Defence Impairment Olympics
Huntress documented a credential dumping attack in which threat actors disabled Windows Defender, terminated monitoring tools, and deployed Mimikatz to extract credentials. The attack demonstrates a coordinated approach to evade defenses and establish persistence within compromised environments.
Why it matters: Security operations teams need to detect and respond to Defender disablement and monitoring tool termination as early indicators of active credential theft, as these techniques precede lateral movement and data exfiltration.
These Recent Insider Threat Allegations
No article content was provided to summarize.
Why it matters: Practitioners need complete information to assess insider threat risk and determine if remediation actions are required.
- ransomware
$2.5 Billion in Damage, Zero Ransom Demand: Russia's New Playbook
The JLR ransomware attack resulted in an estimated $2.5 billion in damages and factory shutdowns across five countries, yet no ransom demand was issued by the threat actors. The incident suggests a shift in tactics from traditional financially-motivated ransomware operations toward objectives aligned with geopolitical or strategic interests.
Why it matters: Security teams managing manufacturing and supply chain operations should assess whether recent attacks targeting their environments represent financially-motivated ransomware or state-sponsored disruption campaigns, as detection and response strategies differ significantly.
- ransomware
The Questions Your Board Should Be Asking About Ransomware Risk: What Unclear Answers Mean
A brief article asserts that boards unable to obtain clear answers about ransomware resilience, recovery readiness, and supply chain exposure face a material risk. The lack of clear responses from management indicates potential gaps in the organization's ransomware preparedness and visibility.
Why it matters: Board members and security leaders need to ensure they can articulate ransomware risk metrics to the board; inability to answer these questions suggests gaps in incident response planning, backup strategies, and vendor risk assessment that could delay recovery or increase breach impact.
- ransomware
How One Letter Hid a Ransomware Army
Qilin ransomware exploited a one-letter filename to evade Windows Defender and Carbon Black endpoint detection and response (EDR) protections, spreading to 30 endpoints in a customer environment before being stopped by Halcyon. The attack did not result in any file encryption. This incident demonstrates how simple obfuscation techniques can circumvent mainstream security tools.
Why it matters: Organizations relying on Windows Defender or Carbon Black EDR face exposure to Qilin ransomware through a basic evasion method; practitioners should review EDR alert tuning and consider behavioral detection rules that do not depend on filename analysis.
- ransomware
OceanAir Federal Credit Union Closed the Gap Between Cyber Insurance and Ransomware Resilience
OceanAir Federal Credit Union used Halcyon to assess its ransomware risk exposure and address gaps between its existing security tools and its ransomware resilience capabilities. The credit union improved its defensive posture by implementing specialized ransomware protection alongside its general-purpose security infrastructure.
Why it matters: Credit unions and financial institutions need to understand their ransomware exposure and evaluate whether current security investments actually protect against modern attacks; this case demonstrates the value of dedicated ransomware resilience tools beyond standard defenses.
- ransomware
Imagine a World Where Ransomware Cannot Encrypt Your Files. That World Now Exists.
A technology called File Resilience claims to block ransomware at the kernel level during execution without requiring threat databases. The approach relies on behavioral detection rather than signature-based identification.
Why it matters: Security teams should evaluate whether kernel-level behavioral defenses offer practical advantages over existing ransomware protections in their environment.
- cloud saas
MCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension
Amazon Q's VS Code extension automatically loaded Model Context Protocol (MCP) servers from workspace files without user consent, allowing attackers to execute arbitrary code and access cloud environments. Researchers demonstrated how a malicious workspace configuration could lead to full compromise of AWS credentials and cloud resources. This attack bypassed typical user interaction requirements by exploiting the automatic initialization process.
Why it matters: Developers using Amazon Q in VS Code are exposed to code execution and credential theft if they open a malicious workspace, making this critical for practitioners managing developer toolchains and AWS security.
- breaches incidents
What’s the Average Cost of a Data Breach in 2025? | Huntress
Huntress published analysis on the average cost of data breaches in 2025, examining how industry sector and geographic location influence breach expenses. The report provides context on financial impact and protective measures against breaches.
Why it matters: Security practitioners need current cost data to justify breach prevention investments and understand financial risk exposure for their organization and industry vertical.
- regulatory
How to Spot a Client in the DoD Industrial Base That Handles CUI
The article provides guidance for managed service providers and managed security service providers to identify whether their clients are Department of Defense contractors that handle Controlled Unclassified Information (CUI). This helps service providers understand their clients' regulatory obligations and security requirements.
Why it matters: MSPs and MSSPs need to identify DoD contractors handling CUI to ensure they implement appropriate security controls, comply with DFARS requirements, and avoid liability for failing to protect sensitive government information.
- cloud saas
Uncovering Hidden Attack Paths in Cloud Environments Using Runtime Signals
Wiz has integrated runtime signals into its Security Graph platform to identify hidden attack paths in cloud environments. This enhancement provides security teams with more comprehensive visibility into potential risk pathways within their cloud infrastructure.
Why it matters: Cloud security practitioners need to evaluate whether this additional layer of runtime visibility can help them identify and prioritize lateral movement risks that static tools might miss.
- threat intel
The 36 Most Common Cyberattacks (2026) | Huntress
This article provides an overview of thirty-six prevalent cyberattack types and methods used by threat actors to compromise systems and networks. It includes guidance on reducing exposure to these common attack vectors.
Why it matters: Security teams and practitioners need to understand attack methodologies and prioritize defenses against the most frequently observed threats in their environments.
- breaches incidents
27 Biggest Data Breaches in History: Famous Examples
This article provides an overview of major data breaches from the past two decades, documenting notable incidents and their circumstances. The piece aims to help organizations understand historical breach patterns and improve their defensive posture.
Why it matters: Security practitioners should review historical breach case studies to identify common attack vectors and weaknesses that may exist in their own environments, enabling better prioritization of defenses.
- ransomware
Evaluating Mexico’s New Cybersecurity Plan
Mexico unveiled a new National Cybersecurity Plan (2025-2030) to address identified threats including organized crime, geopolitical activity, and artificial intelligence concerns across federal, state, and local institutions. Historical analysis shows ransomware, financial malware, fraud, and hacktivism have been primary threats to Mexican government, healthcare, and financial sectors, with Mexico remaining a target for state-sponsored actors due to its supply chain integration with the United States and underdeveloped cybergovernance. The plan represents a policy shift with political backing, though organizations in Mexico must enhance threat detection, incident response capabilities, and staff training to manage evolving risks.
Why it matters: Organizations operating in Mexico, supply chain partners, and those involved in the 2026 FIFA World Cup infrastructure should strengthen threat visibility, incident response planning, and ransomware defenses now, as the country remains a high-priority target for organized crime, state-sponsored actors, and cybercrime-as-a-service operators leveraging dark web forums and cryptocurrency networks.
- threat intel
Where Expertise Meets Algorithm: The Insikt Group® Intelligence Edge
Recorded Future's Insikt Group combines human expertise with automated data analysis to identify threats and adversary operations. The team uses infrastructure detection, victim identification through network traffic analysis, and multi-source validation across over one million data sources to uncover threat actor activities. This hybrid approach enables analysts to detect malicious infrastructure and ongoing compromises faster than traditional methods while providing context that automated systems alone would miss.
Why it matters: Security teams relying on manual threat analysis or single-source detection tools may miss adversary activity that cross-source correlation and expert contextualization would surface, particularly in near real-time detection of active intrusions and infrastructure pivoting.
- ai security
How AI Is Rewriting the SecOps Playbook
The article discusses how adversaries are accelerating their attack timelines from days to minutes, requiring security operations teams to fundamentally shift their approach toward speed and automation. Modern defenders must adopt continuous decision-making processes rather than traditional investigation-then-response models to keep pace with machine-speed threats.
Why it matters: Security operations teams need to evaluate their current detection and response capabilities today to ensure they can handle the compressed attack timelines that adversaries now employ.
- threat intel
From Code to Coverage (Part 6): What netlogon.log Sees That Event 1644 Never Will
A researcher demonstrates that the ldapnomnom tool bypasses Windows audit Event 1644 by using LDAP Ping operations, which leaves no traces in standard event logs. The article explains where defenders can detect these activities in netlogon.log when standard LDAP audit events fail to capture the behavior.
Why it matters: Defenders relying solely on Event 1644 for LDAP attack detection will miss ldapnomnom exploitation; understanding netlogon.log coverage is critical for detecting this active evasion technique.
- ransomware
Why Halcyon? A SOC Operator's Answer.
An article discusses the architectural differences between Halcyon and competing security platforms like CrowdStrike, SentinelOne, and Microsoft Defender from the perspective of a field CISO evaluating endpoint protection options during ransomware incidents.
Why it matters: Security operations teams selecting endpoint detection and response tools need to understand the specific architectural tradeoffs between vendors to ensure their platform can maintain visibility and containment capabilities during active ransomware attacks.
- ransomware
Why Ransomware Deletes Your Backups Before You Know You've Been Hit
Ransomware operators target backup systems in 96% of attacks and successfully destroy them in 76% of cases. Understanding how attackers locate and eliminate backups before encryption is critical for designing effective ransomware defense strategies.
Why it matters: Organizations relying on backups as their primary recovery strategy face a severe gap in resilience: attackers are systematically destroying backups before victims detect the intrusion, leaving no recovery path once encryption begins.
- threat intel
macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox
SentinelLabs has identified macOS.Gaslight, a Rust-based macOS implant attributed to North Korean threat actors that uses Telegram Bot API for command-and-control communications. The implant's notable capability is an embedded payload of fabricated system messages designed to deceive LLM-assisted security analysis tools into aborting their analysis. Communications are hardened with AES-GCM encryption, certificate pinning, and the implant self-redacts sensitive tokens from its runtime output.
Why it matters: macOS users and security teams running LLM-assisted malware analysis pipelines face a novel evasion technique; defenders need to validate analysis results independently and monitor for DPRK-aligned macOS activity using Apple's XProtect signatures BONZAI and AIRPIPE.
- ai security
AI Threat Readiness Pillar 4: Detect and contain threats in real-time
This article discusses operationalizing AI-powered threat detection and response capabilities to counter AI-driven attacks. It provides guidance on implementing real-time threat detection and containment strategies leveraging artificial intelligence (AI) tools.
Why it matters: Security teams need practical guidance on deploying AI-powered detection systems to identify and respond to increasingly sophisticated AI-driven threats before they cause damage.
- threat intel
The Purchase Scam Tactic Headed for the World Cup | Recorded Future
Recorded Future researchers identified a purchase scam tactic that compromises legitimate websites to redirect organic search traffic rather than relying on paid ads or creating fake domains. The technique avoids detection by standard search monitoring and is already being used in World Cup-themed fraud with potential to scale across event-driven scams through 2026.
Why it matters: E-commerce teams and security operations centers should monitor for compromised legitimate sites redirecting to fraudulent checkouts, as this tactic bypasses traditional detection methods and could affect customers during high-traffic sporting events.
- vulnerabilities
From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI
Elastic developed a generative AI agent using Elastic Agent Builder that automatically drafts complete CVE security advisories from vulnerability reports in minutes, eliminating manual work. The agent uses retrieval-augmented generation (RAG) against indexed MITRE CWE and CAPEC catalogues in Elasticsearch to ensure accurate classifications and prevent AI hallucinations. The solution has already been deployed in production and generates standardized advisory text with CWE classification, CAPEC methodology, CVSS scoring, and mitigation guidance.
Why it matters: Security teams managing vulnerability disclosure workflows can accelerate advisory drafting from hours to minutes while reducing errors in CWE and CAPEC assignments that affect downstream national vulnerability databases like NVD.
- cloud saas
Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows
Wiz announced a new Runtime Sensor for Windows environments designed to provide real-time threat detection while maintaining performance through a memory-safe architecture. The tool is intended to help organizations secure Windows deployments in cloud infrastructure without incurring significant performance overhead.
Why it matters: Security teams managing Windows workloads in cloud environments need efficient runtime protection options; this release provides an additional detection and response capability for Windows-based cloud infrastructure.
- threat intel
We Need to Talk About Device Code Phishing
Huntress researchers presented analysis of device code phishing attacks during a June Tradecraft Tuesday session, examining variations of the technique and its appeal to threat actors. Device code phishing leverages the device authorization flow to trick users into granting attackers access to cloud accounts and data.
Why it matters: Security teams need to understand device code phishing because threat actors are increasingly using this method to bypass traditional defenses and gain initial access to cloud environments; practitioners should implement controls to detect and block suspicious device code authentication attempts.
- threat intel
Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress
Modern phishing attacks have evolved beyond simple credential harvesting to include techniques such as ClickFix, BitB (Browser-in-the-Browser), and OAuth consent phishing. These tactics exploit user behavior in more sophisticated ways than traditional methods. Organizations need to update user awareness training to address these emerging threat vectors.
Why it matters: Security teams must train employees to recognize advanced phishing techniques that bypass traditional defenses; failure to do so leaves organizations vulnerable to account compromise and data theft.
- ransomware
An update on FortiBleed — what’s happening with victim orgs
FortiBleed exposed Fortinet firewall administrator credentials at scale after an attacker gained access to tens of thousands of devices, exported configurations, and cracked password hashes using rented GPU compute resources. The attacker's infrastructure left evidence in an open directory, revealing that approximately 1,000 organizations were directly compromised, though credential theft occurred across tens of thousands of devices, with stolen FortiVPN credentials now being resold on underground forums. Many victim organizations show evidence of configuration exports in their logs over the past month from multiple IP addresses.
Why it matters: Fortinet firewall administrators and security teams managing Fortigate devices need to immediately review System event logs for unauthorized config exports, verify whether their devices were compromised, rotate administrative credentials, and investigate whether dormant backdoor accounts from prior ransomware campaigns are present in their infrastructure.
- threat intel
Lost in relocation: analysis of a new loader distributing CASTLESTEALER
Elastic Security Labs identified OXLOADER, a previously undocumented Windows loader distributing the CASTLESTEALER infostealer through malicious Google Ads campaigns impersonating Node.js. The loader employs multiple obfuscation techniques including control-flow flattening, self-modifying code, and abuse of the Windows .reloc section to evade detection across static engines and sandboxes. Evidence suggests the threat actor is financially motivated and Russian-speaking, with the campaign targeting US-based users through a fake installation wizard delivered via Storj's legitimate file-sharing service.
Why it matters: US-based users and organizations are exposed to a low-detection loader actively delivering infostealer malware via search ads; practitioners should monitor for OXLOADER signatures and suspicious Node.js download redirects, and consider implementing malvertising defenses and UAC elevation controls.
- cloud saas
Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap
Azure AD Graph Activity Logs are now available for ingestion into Elastic and other security platforms, closing a decade-long visibility gap where adversary reconnaissance tools operated undetected. The legacy Azure AD Graph API (graph.windows.net) remained inaccessible to defenders as a log stream until early 2026, while threat actors continued using it via tools like ROADtools and AADInternals. The article provides guidance on ingesting these logs, hunting for malicious activity, and detecting five common attack patterns including suspicious user-agents and API version abuse.
Why it matters: Azure AD and Entra ID administrators need to enable and monitor Azure AD Graph Activity Logs immediately to detect reconnaissance activity from compromised accounts or external attackers that was previously invisible to SOCs.
- threat intel
Intelligence Insights: June 2026
ClearFake maintains the top position in threat rankings for June 2026, while Kali365 appears as a new entry in this month's Intelligence Insights report. The brief update highlights shifts in threat actor prominence without providing additional technical details.
Why it matters: Security teams should monitor which threats are trending to prioritize detection and response resources against the most active or impactful threat actors.
- government policy
The President’s Executive Actions on AI Have a Lot to Say on Cybersecurity
A presidential executive order on artificial intelligence (AI) addresses cybersecurity applications beyond frontier model development, including accelerated cyber defense capabilities and automated risk remediation. The order takes a broad approach to AI governance with implications for security infrastructure and operational practices.
Why it matters: Security practitioners should understand how new federal AI policy directives may affect enterprise cybersecurity strategies, budget priorities, and compliance requirements for AI-assisted defense tools.
- breaches incidents
Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress
Klue, a competitive intelligence platform, experienced a security breach that exposed Salesforce data from multiple vendors and customers, including Huntress. The incident affected an undetermined number of organizations that relied on Klue's services. Details about the breach scope and remediation efforts remain limited.
Why it matters: Security vendors and Salesforce users need to assess whether their data was exposed in the Klue breach and review Salesforce instances for unauthorized access or data exfiltration.
- threat intel
The dual-use dilemma: Rethinking detection for remote access tool abuse
Remote management and monitoring (RMM) tools are frequently abused by adversaries for unauthorized access and malicious purposes. The article provides technical detection and prevention guidance for organizations to identify and mitigate RMM tool abuse. This addresses a significant challenge in distinguishing legitimate administrative use from malicious activity.
Why it matters: Security teams need practical detection methods to identify RMM abuse before attackers establish persistent access, since these tools are often legitimate in enterprise environments and difficult to distinguish from normal operations.
- cloud saas
The Red Agent POV: How it Reasoned its Way to SSRF
A red team agent discovered a multi-step attack sequence that exploited a Server-Side Request Forgery (SSRF) vulnerability to achieve local file read access against a Google Cloud Platform Cloud Run application programming interface. The agent's reasoning approach identified how vulnerabilities could be chained together to escalate privileges and access sensitive data.
Why it matters: Cloud and SaaS security teams operating GCP Cloud Run environments need to understand SSRF exploitation chains and implement proper input validation, network segmentation, and file access controls to prevent unauthorized local file access.
- ai security
Introducing the Red Agent POV Series
This article introduces a content series that examines how an AI-powered red agent tool identifies complex security vulnerabilities in live environments. The series provides an insider perspective on the attacker's methodology and approach to discovering exploitable weaknesses.
Why it matters: Security practitioners should understand how AI-driven attack simulation works to better defend against real-world threats and improve their own vulnerability discovery processes.
- vulnerabilities
FortiBleed — 75k Fortinet firewalls have admin passwords cracked
Approximately 75,000 Fortinet firewall admin passwords were exposed in a recent data leak discovered by Hunt Intelligence Inc, with the plaintext credentials extracted from device configuration exports. The compromised devices represent roughly 50% of all internet-facing Fortinet firewalls, and most remain online and accessible. The source and method of the breach remain unclear, though it may involve known CVEs or a previously unknown vulnerability.
Why it matters: Organizations with internet-exposed FortiGate management interfaces face immediate risk of unauthorized remote access to their networks and firewall configuration changes, necessitating urgent credential rotation, device audits for backdoors or unauthorized logins, and potential device replacement if compromise is suspected.
- identity access
Why Your Organization Needs ISPM
Huntress has released a managed Identity and Security Posture Management (ISPM) offering designed to identify and remediate identity security gaps in Microsoft 365 environments. The product emphasizes that organizations need more than visibility into identity risks to achieve effective hardening.
Why it matters: Security teams responsible for Microsoft 365 environments need to evaluate whether their current identity management approach leaves gaps that attackers could exploit, and whether managed ISPM services fit their remediation strategy.
- threat intel
From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker
A threat actor is distributing a Rust-based clipboard hijacker disguised as cryptocurrency trading bots and game prediction tools across multiple platforms, including fake GitHub and SourceForge repositories, a YouTube channel with AI-generated content, and compromised news sites. The operation uses coordinated fake accounts, inflated engagement metrics, and manipulated VirusTotal reputation signals to create a false appearance of legitimacy and trustworthiness. Once installed, the malware monitors the clipboard for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses, generating illicit cryptocurrency transactions.
Why it matters: Cryptocurrency traders and crash-game gamblers are at immediate risk of wallet hijacking and financial loss; security practitioners should monitor for this malware across detection systems and educate users that reputation signals on GitHub, YouTube, and VirusTotal can be artificially manipulated to bypass trust-based decisions.
- threat intel
Klue Integration Abused in Salesforce Data Theft
Attackers compromised the Klue integration in Salesforce to exfiltrate customer relationship management (CRM) data by abusing OAuth tokens and automated REST API queries. The activity follows a pattern seen in prior Salesforce third-party compromises affecting Salesloft, Drift, and Gainsight throughout 2025 and 2026. A Telegram account claiming to be ShinyHunters took responsibility, though attribution remains unconfirmed.
Why it matters: Organizations using Klue or similar Salesforce integrations face immediate risk of CRM data exposure; practitioners should revoke OAuth tokens, rotate credentials, and restrict API access to allowlisted infrastructure while hunting for suspicious Salesforce API activity.
- threat intel
AI in the underground: Curiosity, claims, and concerns
Security researchers examined how artificial intelligence is being discussed in cybercriminal communities and found that threat actors express mixed attitudes ranging from curiosity to skepticism about AI's actual utility for conducting cyberattacks. The findings highlight a disconnect between public concerns about AI-enabled cybercrime and the more nuanced views emerging in underground forums where criminals debate AI's practical applicability. While some actors see potential in AI tools, others question whether these technologies deliver promised advantages over existing techniques.
Why it matters: Security teams should understand that not all threat actors are adopting AI at scale; skepticism in criminal communities may create a window to understand adoption barriers and emerging AI-based threats before they mature.
- government policy
State Digital Surveillance Risk Landscape
Insikt Group assesses that 31 countries pose high or very high digital surveillance risks to foreign nationals and business travelers, exploiting telecommunications infrastructure, commercial spyware, and AI-powered tools with minimal legal oversight. An additional 55 countries present medium risk through less sophisticated surveillance targeting political opposition and dissent. Organizations should implement mitigation measures appropriate to the surveillance risk level of each jurisdiction, from standard security hygiene in low-risk areas to sterile devices in high-risk locations.
Why it matters: Business travelers and organizations operating internationally face risks including data breaches, IP theft, and physical threats in high-surveillance jurisdictions; security teams must assess destination country surveillance risk profiles and implement corresponding device and data protection strategies.
- threat intel
5 Things I Show Every SOC Team When We Wire GreyNoise Into Their SOAR
GreyNoise, a threat intelligence platform, can be integrated into Security Orchestration, Automation and Response (SOAR) systems to improve incident response playbook efficiency. The article outlines five ways this integration helps security teams make better decisions during automated response workflows.
Why it matters: SOC teams using SOAR platforms can reduce alert fatigue and improve response accuracy by incorporating GreyNoise threat data to contextualize and prioritize security incidents faster.
- threat intel
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack
A ClickFix attack campaign deploys Potemkin loader and RMMProject remote access trojan (RAT) to compromise systems, resulting in browser credential theft, unauthorized remote desktop access, and lateral movement across multiple hosts. The attack demonstrates the evolving sophistication of ClickFix social engineering tactics in delivering multi-stage malware payloads.
Why it matters: Organizations and users are at risk from ClickFix phishing attacks that bypass initial defenses and establish persistent remote access; practitioners should monitor for Potemkin and RMMProject indicators and strengthen endpoint detection, browser security, and network segmentation to prevent lateral movement.
- cloud saas
Wiz Exposure Management Dashboard: Your CTEM Command Center
Wiz has released an exposure management dashboard designed to help organizations implement continuous threat exposure management (CTEM) practices. The tool aims to provide visibility and control over vulnerabilities in an environment where artificial intelligence can exploit weaknesses at accelerated speeds.
Why it matters: Security teams need centralized exposure visibility to prioritize and remediate vulnerabilities before AI-driven attacks can exploit them, making this relevant to practitioners managing risk in high-threat environments.
- ransomware
The Intelligence No One Else Has: Inside Recorded Future’s Proprietary Collection Engine
Recorded Future collects and analyzes threat intelligence across four data source types: technical intelligence from internet-scale network monitoring, malware behavioral analysis from sandbox detonation of over 1.5 million samples daily, intelligence from underground criminal forums and marketplaces, and aggregated detections across customer organizations. The vendor positions this multi-source approach as enabling faster threat identification and response compared to organizations relying on public disclosures or general trends.
Why it matters: Security teams evaluating threat intelligence platforms should assess whether their current vendor provides visibility into active exploitation patterns, malware behavior, adversary communications, and cross-organization threat correlations; gaps in any of these sources may delay detection and incident response.
- threat intel
The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed
A compromised terminal server was leveraged as a phishing staging infrastructure to distribute a fraudulent Boots survey to approximately 8.9 million recipients, with malicious payloads hosted on a hacked Bolivian government website.
Why it matters: Organizations and individuals targeted by this survey campaign risk credential theft and system compromise; security teams should monitor for Boots-themed phishing and block access to the identified hosting infrastructure.
- vulnerabilitiesCVE-2026-20253
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)
Splunk published CVE-2026-20253, a pre-authentication remote code execution vulnerability in the PostgreSQL Sidecar Service with a CVSS score of 9.8. The vulnerability affects Splunk Enterprise version 10 and above, with Splunk Enterprise on AWS being vulnerable by default, while on-premises Windows installations require the sidecar to be explicitly enabled. The researchers analyzed the vulnerable service listening on local ports and confirmed the exposure in default deployments.
Why it matters: Organizations running Splunk Enterprise on AWS with version 10 or higher face immediate remote code execution risk without authentication; security teams should verify their Splunk deployment type and version, then apply patches or disable the PostgreSQL Sidecar Service if not needed.
- government policy
Navigating the New Federal Logging Mandate | OMB Memorandum M-26-14
The White House has issued Memorandum M-26-14, which establishes an adaptive framework requiring federal agencies to implement logging practices based on risk assessment and prioritization. This guidance shifts from prescriptive rules to agency-level decision-making on logging requirements.
Why it matters: Federal contractors, agencies, and service providers supporting federal systems must understand these new logging requirements to maintain compliance and security standards.
- ransomware
Akira, LimeWire, and the Sour Taste of Data Exfiltration
An Akira ransomware affiliate exploited a LimeWire-owned website as a data exfiltration vector in an attack. The investigation revealed how the attacker leveraged the legitimate web property to move stolen data off victim systems.
Why it matters: Organizations using or connected to LimeWire services face operational risk from compromised infrastructure; security teams need to audit for similar abuse of trusted third-party domains for exfiltration.
- vulnerabilitiesCVE-2026-50751
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)
Check Point released hotfixes on June 8, 2026, for CVE-2026-50751, a CVSS 9.3 authentication bypass vulnerability in IKEv1 VPN code affecting Mobile Access, SSL VPN, Remote Access VPN, and Spark Firewall products. The vulnerability stems from a logic flaw in certificate validation during IKEv1 key exchange that allows clients to bypass authentication checks, and has been exploited in the wild since May 7, 2026, affecting dozens of targeted organizations including at least one incident linked to Qilin ransomware affiliates. Exploitation requires legacy Remote Access clients, IKEv1 protocol enabled, and absence of mandatory machine certificate authentication.
Why it matters: Organizations running affected Check Point versions (R80.20.X through R82.10) with IKEv1 VPN enabled must patch immediately, as this authentication bypass is actively exploited and listed in CISA KEV, creating direct perimeter compromise risk for remote access infrastructure.
- ai security
AI Threat Readiness Pillar 3: Perform AI Code Analysis Natively in Wiz
Wiz has published guidance on operationalizing AI-powered code analysis as part of its AI threat readiness framework. The content focuses on integrating native code analysis capabilities to address security challenges in AI-driven development environments.
Why it matters: Security practitioners need to understand how to implement AI-native code analysis tools to identify vulnerabilities in AI-generated and AI-assisted code before deployment.
- threat intel
When the Music Stops: How the ROC Caught a Triple DLL Sideloading Attack Hidden in an Audio File
Halcyon's Response Operations Center (ROC) identified and blocked a triple DLL sideloading attack concealed within a malicious audio file. The attack evaded detection by 61 of 70 security engines, demonstrating an evasion technique that combines file format obfuscation with DLL sideloading exploitation.
Why it matters: Security teams rely on detection engines to catch malware delivery mechanisms; this attack shows that audio files can serve as effective vectors for sophisticated payload delivery and that standard detection signatures may miss advanced evasion techniques using DLL sideloading.
- vulnerabilities
CIOs Are Terrified of Mythos. Should They Be?
Project Glasswing identified thousands of vulnerabilities in software, with less than 1% patched immediately upon disclosure. A Field CISO discusses what security leaders should realistically prioritize regarding vulnerability management and patching strategies.
Why it matters: CIOs and security teams need to understand the practical implications of large-scale vulnerability discovery and the gap between disclosure and patching, as this affects prioritization decisions and risk management posture.
- threat intel
Congratulations, You're Human. Now Here's Your Malware.
ClickFix is a social engineering campaign that tricks users into executing malicious commands by convincing them they are human during security checks. Halcyon detected and blocked the same campaign across three customer environments within a single week, highlighting its active circulation among threat actors.
Why it matters: Security teams need to educate users on ClickFix social engineering tactics and implement detection rules immediately, as the campaign is actively spreading across multiple organizations.
- threat intel
Inside Kali365, a Device Code Phishing Ecosystem | Huntress
Huntress identified Kali365, a Microsoft 365 focused phishing toolkit, that leverages device code flows to steal authentication tokens and maintain persistent access despite multi-factor authentication (MFA) or password resets. The attack chain originates from Tencent Cloud infrastructure and targets organizations relying on Microsoft cloud services. The toolkit represents an evolving threat that bypasses common account recovery mechanisms.
Why it matters: Microsoft 365 users are at immediate risk from device code phishing attacks that circumvent MFA and password resets, requiring security teams to implement detection for anomalous device code flows and token theft indicators.
- vulnerabilitiesCVE-2025-67644CVE-2026-27022
From SQLi to RCE – Exploiting LangGraph’s Checkpointer
Check Point Research identified three vulnerabilities in LangGraph, an open-source AI agent framework with over 50 million monthly downloads, affecting its SQLite and Redis checkpointers. Two vulnerabilities chain together to enable remote code execution through SQL injection and unsafe msgpack deserialization, while a third introduces SQL injection to the Redis checkpointer. LangChain has released patches for all three issues.
Why it matters: Teams self-hosting LangGraph with SQLite or Redis checkpointers that expose get_state_history() with user-controlled filters face remote code execution risk and must update to patched versions immediately; LangSmith Deployment (managed cloud) users are not affected.
- threat intel
How threat hunting evolves at scale
Organizations can evolve informal threat hunting practices into mature, scalable programs by addressing friction points, implementing structural strategies, and deploying appropriate tooling. The article outlines a practical roadmap for managing this transition at scale.
Why it matters: Security operations teams need to understand how to mature threat hunting capabilities to detect threats more effectively and allocate resources efficiently as detection demands grow.
- ai security
LABScon25 Replay | Keynote: Steps to an Ecology of Cyber
A keynote from SentinelLABS VP Juan Andrés Guerrero-Saade argues that cybersecurity is transitioning from an experimental era toward a more standardized and automated future enabled by large language models. He frames LLMs as a source of cheap, scalable evaluative power that can mechanize routine analysis and reduce dependence on scarce human expertise. The talk advocates for systems where human expertise and AI work together through standardized, automated approaches rather than defending legacy product categories and workflows.
Why it matters: Security leaders and practitioners should understand how LLMs and mechanized intelligence may reshape defensive operations, reduce analysis costs, and change skill requirements as automation becomes embedded rather than bolted onto existing systems.
- threat intel
Cyber-Enabled Maritime Sanctions Evasion
Iranian and Russian shadow fleet vessels are using cyber-enabled infrastructure consisting of over 36 fraudulent websites that impersonate maritime registries, administrations, and certification organizations to generate false documents and evade sanctions. The infrastructure is organized into three clusters with varying attribution, including links to an Indian web development company and Syrian nationals, and operates as a service-provider model offering reusable digital infrastructure and forged credentials to multiple sanctions evasion networks. This cyber-enabled approach blends traditional sanctions evasion tactics with automated document generation and layered infrastructure, significantly complicating detection and regulatory compliance enforcement.
Why it matters: Shipping and maritime companies face increased due diligence failures and regulatory exposure from sanctions evasion networks using sophisticated fraudulent online infrastructure; compliance teams must integrate independent verification and cyber threat intelligence into workflows to detect and report impersonated government maritime organizations and suspicious vessel documentation.
- ransomware
Recorded Future Launches Impact and Metrics Dashboard
Recorded Future has launched an Impact and Metrics Dashboard that automatically aggregates data from customer environments, alerts, integrations, and analyst activity to surface business-aligned security metrics without manual reporting. The dashboard tracks platform-wide risk reduction, threat prioritization, detection coverage, digital risk protection, credential monitoring, and analyst efficiency, addressing the challenge of translating security outcomes into language that boards and CFOs understand.
Why it matters: Security leaders responsible for demonstrating ROI and risk reduction to executive stakeholders can now measure and report the value of their threat intelligence program using pre-built, organization-specific metrics rather than manual quarterly reporting.
- threat intel
Deceptive Installers: How Fake Apps Target macOS
Malicious installers masquerading as legitimate macOS applications are being used to deliver infostealers that target sensitive data including passwords, cookies, and cryptocurrency wallets. These deceptive packages exploit user trust in familiar software distribution methods to compromise systems and exfiltrate credentials and financial assets.
Why it matters: macOS users and security teams need to implement application verification practices and monitor for suspicious installer behavior, as these attacks directly threaten personal credentials and financial accounts.
- vulnerabilitiesCVE-2026-10520CVE-2026-10523
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)
Ivanti released an advisory for two critical vulnerabilities in its Sentry product: CVE-2026-10520, a pre-authenticated OS command injection flaw allowing unauthenticated remote code execution with CVSS 10.0, and CVE-2026-10523, an authentication bypass enabling creation of arbitrary administrative accounts. Both vulnerabilities affect Ivanti Sentry versions before R10.5.2, R10.6.2, and R10.7.1.
Why it matters: Organizations running vulnerable Ivanti Sentry versions face immediate risk of complete system compromise through unauthenticated remote code execution and administrative account creation, requiring urgent patching or network segmentation to prevent in-the-wild exploitation.
- government policy
China's Noncombatant Evacuation Operations: 2005–2025
Insikt Group analyzed 37 Chinese noncombatant evacuation operations (NEOs) conducted between 2005 and 2025 across 28 countries, finding that China consistently mobilized state-owned enterprises, private companies, and civil society organizations to support these efforts. At least 65% of these operations involved civilian resources providing ground coordination, transportation, communications, and relief assistance. The research demonstrates China's capacity to leverage diverse national instruments to protect overseas interests and personnel across Africa, the Middle East, Asia, and other regions.
Why it matters: Defense and intelligence practitioners should understand China's evolving capability to rapidly mobilize civilian infrastructure for overseas operations, as this capability enables expedited crisis response and extends China's operational reach, with implications for regional stability and competition in contested areas.
- government policy
2026 FIFA World Cup: What Public Safety Officials Need to Know
The 2026 FIFA World Cup across the United States, Canada, and Mexico will present coordinated physical and cyber security challenges spanning infrastructure protection, cybercriminal fraud schemes, hacktivism, and politically motivated disruption. Public safety officials must prepare for threats including credential harvesting, fraudulent merchandise sites, crowd management at soft targets, and influence operations designed to exploit the event's global visibility. Effective response requires coordination across cybersecurity, law enforcement, communications, and third-party risk management teams.
Why it matters: Security practitioners, law enforcement, and event planners must develop integrated threat response plans now; cybercriminals are already launching credential harvesting and fraud campaigns, while state and non-state actors may use the event for operational or influence objectives.
- ai security
AI Threat Readiness Pillar 2: Accelerate Patching and Response
Wiz has published guidance on operationalizing patching and response processes to address threats in AI environments. The resource focuses on establishing ownership, remediation workflows, and incident response capabilities aligned with the evolving AI threat landscape.
Why it matters: Security teams managing AI deployments need practical processes for patch management and incident response; this guidance helps organizations establish repeatable remediation workflows to reduce exposure from AI-related vulnerabilities.
- research
Gartner Security Summit 2026: Huntress 5 Key Takeaways
Gartner Security & Risk Management Summit 2026 highlighted three major themes: resilience, identity, and practical artificial intelligence (AI) applications. The article identifies five key takeaways for security leaders to consider.
Why it matters: Security practitioners should review the summit's takeaways to understand industry consensus on emerging priorities and potentially inform their own strategic planning and resource allocation.
- government policy
Russia’s Defense-Based Economy Risks Forcing Putin to Fight Wars
Russia's economy has become heavily militarized since the 2022 Ukraine invasion, with defense spending reaching 7.2% of GDP and 32% of the federal budget by 2025. Western sanctions have concentrated elite patronage flows through defense contracts, creating a structural incentive for Putin to maintain high military spending. Analysts assess that Putin may pursue conflicts abroad to sustain defense expenditures and the patronage networks necessary for domestic political stability, potentially targeting non-NATO states near Russia such as Moldova.
Why it matters: Organizations and governments in Europe, particularly those with Russian exposure or operations in non-NATO states bordering Russia, face an unpredictable and elevated cyber, physical, and economic threat environment as long as sanctions prevent Russian elites from diversifying wealth sources beyond the defense sector.
- identity access
Investigating suspicious AI workflows in Microsoft Entra Agent ID: Assistive agents
Microsoft Entra has identified suspicious AI workflow activity involving assistive agents that may operate outside intended boundaries. Security teams should investigate whether these autonomous agents are being misused within their identity environments.
Why it matters: Organizations using Microsoft Entra and AI agents face potential unauthorized actions taken by these assistants; practitioners should audit agent configurations and permissions to prevent account compromise or policy violations.
- cloud saas
Introducing Wiz Cloud Cost: Powering Cost Management and Optimization with Context
Wiz has released a cloud cost management tool that combines cloud and AI cost visibility across AWS, Azure, and GCP environments. The platform aims to help teams identify and eliminate waste to improve spending efficiency.
Why it matters: Cloud infrastructure teams need visibility into spending patterns and waste across multi-cloud environments to control costs and optimize budgets in real time.
- vulnerabilitiesCVE-2008-4250CVE-2009-1537
May 2026 CVE Landscape
In May 2026, Insikt Group identified 41 high-impact vulnerabilities requiring prioritized remediation, representing an 11% increase from April. These vulnerabilities affected 20 vendors, with 21 included in CISA's Known Exploited Vulnerabilities catalog, 19 detected via honeypot data, and one reported by a vendor. Notably, 12 vulnerabilities enabled remote code execution, public proof-of-concept exploits were available for 32 of them, and five were first disclosed between 2008 and 2010, demonstrating continued exploitation of long-standing weaknesses.
Why it matters: Vulnerability management teams should immediately triage the 41 high-risk CVEs listed, prioritize the 22 actively exploited vulnerabilities, and focus on patching remote code execution flaws affecting Microsoft, Palo Alto Networks, Cisco, and other enterprise vendors; the prevalence of years-old unpatched vulnerabilities underscores the urgency of basic patch management compliance.
- regulatory
Why Huntress Doesn’t Need FedRAMP
Huntress has implemented Sensitive Data Mode to provide logical data separation, allowing defense contractors to achieve CMMC (Cybersecurity Maturity Model Certification) compliance without requiring FedRAMP authorization. This approach offers a more cost-effective and faster alternative to using FedRAMP-authorized cloud services for contractors handling sensitive defense data.
Why it matters: Defense contractors and their IT providers need to understand CMMC compliance pathways; this highlights an alternative to expensive FedRAMP authorization that could reduce costs and implementation timelines while maintaining required security controls.
- threat intel
ReliaQuest's Agentic AI Uncovers New China-Linked Cluster OP-512
ReliaQuest's AI platform identified OP-512, a previously undocumented China-linked threat cluster targeting legacy Internet Information Services (IIS) servers through a custom web shell framework with cryptographic protections that evade signature-based detection. OP-512 represents at least the fourth China-linked cluster publicly documented targeting IIS servers in the past year, with a focus on espionage and long-term access maintenance. Organizations running end-of-life .NET frameworks on internet-facing servers face elevated risk and should prioritize migration or network segmentation.
Why it matters: Organizations operating internet-facing IIS servers with legacy .NET frameworks require immediate assessment and remediation planning, as OP-512 and similar clusters are actively targeting this infrastructure for state-sponsored espionage with tools designed to bypass existing defenses.
- threat intel
Why Holistic Sourcing Wins: The Numbers Behind the Recorded Future Advantage
Recorded Future published marketing content about the value of comprehensive threat intelligence sourcing across multiple domains rather than relying on narrow, siloed data sources. The company claims its Intelligence Graph monitors over one million sources spanning technical, criminal, collective, and open-source domains to detect threats that fragmented approaches would miss.
Why it matters: Security teams evaluating threat intelligence platforms should understand that source breadth affects detection capability, particularly for nation-state activity, criminal infrastructure, and credential exposure monitoring.
- threat intel
VerdantBamboo: Just Another BRICKSTORM in the Firewall
Volexity discovered that a Chinese threat actor tracked as VerdantBamboo had compromised an Egnyte Storage Sync appliance using the BRICKSTORM malware, with the initial compromise dating back at least 18 months. The actor used the compromised appliance to access the victim's Microsoft 365 environment while evading security controls, and later regained access via stolen firewall credentials to deploy additional malware. Investigation revealed the victim organization had been compromised through a breach of their managed services provider, whose pfSense firewall had also been infected with BRICKSTORM for at least 18 months.
Why it matters: Organizations using Egnyte Storage Sync, pfSense firewalls, and MSP-managed infrastructure face persistent risk from VerdantBamboo; practitioners should investigate long-term network anomalies, review firewall and VPN access logs, and audit MSP security postures to detect similar implants.
- ai security
AI Threat Readiness Pillar 1: Reduce Critical Exposures & Scan with AI
This article discusses the first pillar of an AI Threat Readiness Framework, focusing on reducing critical exposures and using AI for scanning purposes. The piece appears to position a security vendor's capabilities within this framework.
Why it matters: Security teams need to understand best practices for identifying and reducing critical exposures in AI environments to prevent exploitation and guide tool selection decisions.
- breaches incidents
You do surprise me.exe: An unexpected executable in Hola Browser
Sophos X-Ops discovered an unexpected executable hidden within Hola Browser during certification testing. The finding suggests a supply chain compromise where an unwanted component was bundled with the application.
Why it matters: Users of Hola Browser face the risk of running unauthorized code on their systems; practitioners should evaluate whether this application is present in their environments and assess the exposure.
Remembering Sir Alex Younger
This article is a tribute to Sir Alex Younger, former chief of MI6, who joined the Recorded Future board of directors in 2020 and contributed to the company's intelligence practices and strategy until his recent death. The piece reflects on his character, his approach to learning and collaboration, and his influence on the organization's work in threat intelligence and building alliances against adversaries.
Why it matters: Security practitioners should recognize that trusted intelligence leaders and collaborative approaches across public and private sectors strengthen collective defense capabilities against state and criminal adversaries.
- industry
4 Ways GreyNoise Improves SOC Outcomes
GreyNoise offers capabilities designed to help security operations centers reduce alert fatigue, prioritize targeted threats, and detect compromised infrastructure. The vendor provides tooling for alert triage and threat identification across operational environments.
Why it matters: SOC teams need to evaluate whether GreyNoise's threat intelligence and alert filtering capabilities reduce noise and improve detection efficiency in their specific environment and alert sources.
- threat intel
Inside .NET Loader Analysis: From Malspam to In-Memory Loader
A malspam campaign using Google DoubleClick delivers a multi-stage .NET loader that employs evasion techniques to bypass detection and disable Windows telemetry before establishing persistence. The five-stage infection chain demonstrates sophisticated obfuscation and anti-forensic methods to conceal the payload delivery mechanism.
Why it matters: Organizations and security teams need to understand this attack pattern to detect malspam-delivered loaders, as the telemetry-blinding tactics will reduce visibility into endpoint activity and complicate incident response and threat hunting.
- threat intel
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
Check Point Research documented a large-scale operation impersonating legitimate open-source and security tools such as Ghidra, dnSpy, and SpiderFoot through professionally designed fake websites. These sites use hidden JavaScript to redirect users through a Traffic Distribution System (TDS) that filters based on geography, device type, and browser fingerprints before sending selected users to malware delivery infrastructure. The ecosystem has delivered multiple malware families including RemusStealer, AnimateClipper, and SessionGate, with over 5,000 submissions observed suggesting substantial reach.
Why it matters: Security researchers and malware analysts are directly targeted by impersonated reverse-engineering tools, creating risk of credential theft and system compromise; practitioners should verify tool authenticity and implement awareness training on search result spoofing.
- vulnerabilities
The Patch Gap Is Structural. Here Is What That Means for Your SOC.
AI-driven vulnerability discovery is expected to outpace the ability to patch systems, indicating the patch gap is a fundamental structural issue rather than an operational one. This widening gap between vulnerability identification and remediation will require security operations centers (SOCs) to adapt their strategies and prioritization approaches.
Why it matters: SOC teams need to understand that patching backlogs are inherent to the scaling problem, not fixable through process improvements alone, and must prioritize which vulnerabilities to address based on risk and exploitability rather than attempting comprehensive coverage.
- vulnerabilities
Unpatched NTLM Leakage in Windows search: URI Handler, Same Bug, No CVE, No Fix
An unpatched NTLM credential leakage vulnerability exists in Windows Explorer's search handler that mirrors a previously patched flaw in Snipping Tool. The issue has not been assigned a CVE identifier and remains unfixed, creating a potential security gap for organizations relying on CVE-based patch management.
Why it matters: Windows users and security teams need to know that CVE-based patching strategies miss vulnerabilities without CVE assignments, leaving credential exposure unaddressed until Microsoft acts.
- threat intel
LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine
ESET researchers presented technical evidence at LABScon 25 demonstrating that Gamaredon actively facilitated Turla's access to high-value Ukrainian targets between February and June 2025. Gamaredon's tools, including PteroGraphin and PteroOdd, were used to deploy Turla's Kazuar backdoor and restore access after compromise. The presentation reveals how Russian cyberespionage groups divide operational labor, with Gamaredon establishing initial access through spearphishing while Turla deploys advanced espionage platforms for post-compromise objectives.
Why it matters: Ukrainian military and government defenders, as well as threat hunters tracking Russian state-aligned activity, need to understand this operational collaboration pattern to better detect and respond to access brokering chains where lightweight initial access tools precede deployment of sophisticated backdoors.
- threat intel
Pointing a Cursor at evading detection
A research analysis examines how artificial intelligence accelerated tool development and testing processes, while human decision-making and workflow management remained central to the overall effort. The study highlights the complementary roles of AI capabilities and human expertise in security tool creation.
Why it matters: Security practitioners should understand how AI is reshaping threat tool development timelines and testing methodologies, as faster adversary iteration may compress the window for detection and response.
- threat intel
Iran Expands Handala Brand to Physical Threats
Iran's Ministry of Intelligence has expanded the Handala brand to coordinate cyber operations, influence campaigns, and physical threat activities targeting US and Israeli interests. The organization now operates multiple personas under the Handala umbrella that solicit individuals to conduct physical attacks and espionage in exchange for payment. This consolidated branding and coordination of cyber, physical, and influence operations likely amplifies the scope and impact of Iranian intelligence activities.
Why it matters: US and Israeli government personnel, law enforcement, military, intelligence agencies, and critical infrastructure operators in energy, transportation, and research sectors face elevated recruitment and targeting risks from coordinated Handala-affiliated actors offering financial incentives for physical attacks and espionage.
- threat intel
From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence
Elastic Security now natively integrates Google Threat Intelligence, enabling real-time matching of malicious IPs, domains, URLs, and file hashes against security telemetry with threat scores and verdicts. The integration requires only an API key and two data streams with no additional infrastructure, and can enrich ambiguous indicators through AI-driven workflows that query VirusTotal and correlate findings with existing telemetry. This approach treats threat intelligence as an operational tool for detection, hunting, and investigation rather than as static reference data.
Why it matters: Security operations teams can now reduce detection latency and improve alert prioritization by automatically correlating Google's curated threat intelligence against their environment, enabling faster response to known malicious indicators and more confident decision-making on indicator confidence scores.
- industry
Red Canary CFP tracker: June 2026
Red Canary publishes a monthly roundup of security conferences and call for papers submission deadlines for June 2026. This curated list helps security professionals identify upcoming speaking and training opportunities in the industry.
Why it matters: Security practitioners looking to present research, network with peers, or stay current with industry events should review the deadline dates to plan submissions and attendance accordingly.
- cloud saas
Eliminate Critical API Attack Paths with Wiz API SPM
Wiz has released API Security Posture Management (SPM) to general availability, a tool that helps organizations discover APIs in their environments, evaluate them for security vulnerabilities, and prioritize fixes to prevent API-based breaches.
Why it matters: Security teams managing API sprawl need to assess and remediate API attack surface to reduce breach risk from increasingly targeted API exploits.
- threat intel
Miasma: Supply Chain Attack Targeting RedHat npm Packages
A supply chain attack targets RedHat npm (Node Package Manager) packages using malware derived from Mini Shai-Hulud. Organizations using affected npm packages may have their systems compromised through malicious code injection into the dependency chain.
Why it matters: Development teams and security practitioners using RedHat npm packages need to audit dependencies immediately and apply mitigations to prevent malicious code execution in their build and runtime environments.
- vulnerabilities
Microsoft’s stance on zero day exploits is a dumpster fire of their own making
A researcher going by Nightmare Eclipse has published proof of concept exploits for Microsoft vulnerabilities, claiming difficulty in responsible disclosure. Microsoft responded by disabling their MSRC account, removing exploits from GitHub, and characterizing the activity as potentially criminal. The situation highlights tensions between coordinated disclosure frameworks and researcher access to reporting mechanisms, complicated by Microsoft's historical hiring of security researchers who have publicly disclosed exploits.
Why it matters: Security practitioners need to understand the current state of responsible disclosure channels and the practical risks of reporting to vendors who may restrict access or pursue legal action rather than remediation.
- research
State of Post Quantum Cryptography
This story discusses post-quantum cryptography (PQC) adoption trends and statistics based on customer data and other sources. It provides insights into current PQC implementation rates and readiness levels across organizations.
Why it matters: Security practitioners need to understand PQC adoption trends to assess their organization's quantum-safe migration timeline and competitive positioning in cryptographic readiness.
- research
Grading on a curve: How to assess a pentest
The article discusses a practical approach to penetration testing that moves away from detecting every adversary action, instead focusing on a more realistic and optimized assessment methodology for defenders.
Why it matters: Security practitioners need efficient testing methodologies to prioritize defensive efforts and understand that perfect detection is impractical; this grading approach helps teams assess pentest results more effectively.
- threat intel
Your Profile Is a Dossier. Here's Who's Reading It.
Social media profiles serve as readily available sources of personal information that attackers exploit to develop targeted attack strategies. This article examines how threat actors leverage publicly visible data to construct attack playbooks and offers recommendations for limiting the information attackers can gather from your online presence.
Why it matters: All users of social media platforms face exposure to reconnaissance attacks that harvest public profile data for social engineering, credential targeting, and personalized phishing campaigns; practitioners should audit their own and their organization's public presence to reduce information available to attackers.
- cloud saas
Evidence at the Moment of Attack. Answers at AI Speed.
Wiz has released Sensor Forensics in general availability, a product that automatically captures forensic data when threats are detected and uses artificial intelligence to help security operations and incident response teams investigate faster. The tool aims to preserve evidence at the point of detection to reduce investigation time.
Why it matters: SOC and IR teams need faster investigation capabilities; this tool may reduce mean time to respond by automating forensic collection and AI-powered analysis.
- regulatory
Before Your MSP Chases CMMC, Take an Honest Look at Your Operations
The article advises managed service providers (MSPs) to conduct thorough internal audits of their operations before pursuing Cybersecurity Maturity Model Certification (CMMC) compliance for Department of Defense contracts. CMMC should be approached as a comprehensive operating model rather than a checklist, with particular attention to access controls and data handling practices. MSPs need to ensure their internal processes can withstand the scrutiny required for defense work.
Why it matters: MSPs bidding on DoD contracts must understand that CMMC compliance requires substantive operational changes, not just documentation; inadequate preparation risks failed audits and lost contract opportunities.
- threat intel
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
Wiz CIRT and Wiz Research have identified a threat actor called JINX-0164 that uses LinkedIn social engineering and custom macOS malware to compromise cryptocurrency organizations' software development infrastructure through CI/CD (continuous integration/continuous delivery) hijacking.
Why it matters: Cryptocurrency developers and organizations with macOS-based development environments are exposed to supply chain attacks that could compromise software releases and internal systems; practitioners should review access controls and monitor CI/CD pipelines for unauthorized changes.
- ai security
Defending at Machine-Speed: Building AI Threat Readiness with Wiz
Wiz has released guidance on adopting an AI Operating Model to enhance organizational readiness against AI-related threats. The approach aims to help security teams integrate AI-driven capabilities into their defensive strategies and incident response processes.
Why it matters: Security practitioners should evaluate whether AI-augmented threat detection and response tools align with their current tooling and workflows, as adoption of such models may impact staffing, budget, and operational priorities.
- research
State of SDLC Security 2026: How Risk Scales in Modern Development
A report examines how security risks evolve across the software development lifecycle as modern development practices, automation, and AI tools scale. The analysis draws from real-world environments to understand the interplay between code, developer tooling, and application security.
Why it matters: Security practitioners need to understand how SDLC risk profiles are changing to prioritize investments in tooling, process controls, and developer training that match current threat landscapes.
- ransomware
AI Threat Landscape Digest March-April 2026
During March and April 2026, artificial intelligence transitioned from experimental to widespread operational use in cyberattacks by criminal actors, ransomware groups, and state-sponsored operations. Attackers are weaponizing commercial AI models like Claude and GPT-4.1 as persistent tools in extended campaigns, while AI provider credentials are being harvested at scale to maintain access. A documented breach of nine Mexican government agencies demonstrates how attackers orchestrate dual AI workflows, with Claude Code performing interactive exploitation and GPT-4.1 conducting automated intelligence analysis to guide successive attack phases.
Why it matters: Security teams and defenders must recognize that AI is now an active operational weapon in real campaigns, not a theoretical threat; immediate focus on detecting AI-orchestrated workflows, monitoring for harvested API credentials in logs, and understanding how attackers chain multiple AI models together will be critical to detecting and containing attacks in your environment.
- identity access
From Cookies to Keys: The Threat of Session Hijacking
Session hijacking involves attackers stealing session tokens or cookies to impersonate legitimate users without compromising credentials directly. This technique allows attackers to bypass authentication controls and gain unauthorized access to systems and data, creating a significant risk for enterprise environments.
Why it matters: Security teams need to understand session hijacking as a vector that circumvents password-based defenses; practitioners should implement token protection, secure session handling, and continuous authentication monitoring to detect unauthorized access patterns.
- threat intel
Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace
Tycoon 2FA is a prolific phishing-as-a-service platform that performs adversary-in-the-middle attacks to bypass multi-factor authentication and steal authenticated session tokens from Microsoft 365 and Google Workspace. The kit operates as a reverse proxy that captures real-time authentication flows, including MFA challenges, and intercepts post-MFA session tokens before they reach the victim's browser. Despite a March 2026 takedown that seized over 300 domains, operators have adapted and continue deploying variants that use WebSocket-based proxying and OAuth device code abuse, employing sophisticated evasion techniques to avoid researcher detection.
Why it matters: Microsoft 365 and Google Workspace administrators and security teams need to detect and block Tycoon 2FA campaigns immediately, as the kit bypasses standard MFA protections and remains the top malware trend; organizations should implement conditional access policies, detect unusual token usage patterns, and monitor for phishing emails with embedded attachments containing login replicas.
- threat intel
Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict
Nimbus Manticore, an Iranian IRGC-affiliated threat actor, resurfaced during escalated US-Iran military tensions in early 2026 with enhanced capabilities including a new backdoor called MiniFast and novel delivery techniques. The group conducted phishing campaigns targeting aviation and software sector employees across the United States, Europe, and the Middle East, employing methods such as SEO poisoning, AppDomain hijacking, and abuse of legitimate Zoom installers. The malware development appeared to incorporate AI-assisted practices, enabling rapid tool adaptation and sustained operational activity.
Why it matters: Organizations in defense, aviation, and telecommunications sectors in the US, Europe, and Middle East should review phishing controls and monitor for AppDomain hijacking and SEO-poisoned search results, as this threat actor actively targets these industries during geopolitical escalation.
- threat intel
The Coverage Gap: Why Your Blocklist Is Missing 119,000 Malicious IPs Today
GreyNoise analyzed 119,842 malicious IP addresses against 11 major threat intelligence feeds and found that these feeds covered only an average of 2% of the malicious IPs, highlighting significant gaps in static blocklist coverage. The research underscores that relying solely on blocklists leaves organizations exposed to the majority of known malicious infrastructure. This limitation suggests practitioners need layered defenses beyond traditional blocklist-based approaches.
Why it matters: Security teams relying on threat feeds and blocklists for network defense are exposed to over 98% of tracked malicious IPs that go undetected, requiring evaluation of supplementary detection methods and threat intelligence sources.
- threat intel
PHANTOMPULSE: anatomy of a hijackable blockchain-C2 RAT
Elastic Security Labs analyzed PHANTOMPULSE, a remote access trojan (RAT) used by intrusion set REF6598 that resolves its command and control (C2) infrastructure through Ethereum blockchain transactions, implements three process injection techniques, and bypasses endpoint defenses including User Account Control (UAC), AMSI, Windows Defender Language Protection (WLDP), and Event Tracing for Windows (ETW) using a shared hardware breakpoint primitive. The malware exhibits strong fingerprints of artificial intelligence (AI)-assisted development, including structured step numbering, verbose diagnostic output, and function-tracing patterns typical of large language model (LLM) code generation. The analysis identified a critical weakness: the blockchain C2 resolver lacks sender verification, allowing defenders to override the C2 address by posting a single transaction.
Why it matters: Windows defenders need to understand that this implant uses blockchain for C2 resilience and employs multiple defense-evasion techniques simultaneously; the lack of sender verification on the blockchain resolver creates an immediate sinkhole opportunity for incident responders.
- cloud saas
Claude Enterprise Meets the Security Graph: Wiz Integrates with Anthropic's Compliance API
Wiz has integrated with Anthropic's compliance API to allow security and compliance teams to monitor Claude activity within the Wiz platform, expanding existing security workflows to cover AI systems.
Why it matters: Security practitioners managing Claude Enterprise deployments need this integration to maintain visibility and compliance oversight of AI tool usage alongside their existing infrastructure monitoring.
- cloud saas
How Huntress Uses Managed SIEM to Detect Threats Faster
Huntress has implemented a Managed Security Information and Event Management (SIEM) approach to accelerate threat detection and improve hunting capabilities across endpoints, identities, and infrastructure. The company's strategy combines centralized log analysis with managed services to enhance visibility and response capabilities for security teams.
Why it matters: Practitioners evaluating detection and response platforms should understand how managed SIEM integration can reduce investigation time and improve threat visibility across hybrid environments.
- ransomware
The Gentleman Ransomware | Defense Evasion TTPs Uncovered | Huntress
Huntress researchers documented two incidents involving The Gentlemen ransomware that employed defense evasion techniques, including clearing logs and attempting to add antivirus exclusions to avoid detection. These tactics suggest the threat actors are actively working to obstruct forensic analysis and security tools during attacks.
Why it matters: Organizations running Windows systems should review endpoint logging and antivirus configurations to detect unauthorized exclusion attempts, and ensure log retention policies prevent attackers from covering their tracks post-compromise.
- vulnerabilities
The Vulnerability Flood Is Now a Board Conversation. Here's How to Lead It.
The disclosure of approximately 50,000 software vulnerabilities annually represents a growing challenge, though fewer than 1% are actively weaponized by threat actors. AI-assisted discovery tools accelerate the identification of vulnerabilities and compress the window between disclosure and exploitation from days to minutes, but the core prioritization problem remains unchanged; most organizations struggle with manual triage processes that cannot keep pace with discovery volume rather than with finding vulnerabilities themselves.
Why it matters: Security leaders and boards must distinguish between a fundamental transformation of the threat landscape versus an acceleration of existing challenges; organizations need intelligence-led prioritization capabilities operating at threat speed, and should audit their vulnerability posture across internal systems and third-party components rather than focusing solely on perimeter and endpoint defenses.
- vulnerabilitiesCVE-2026-0400
A New SonicWall Scanning Spike Echoes the Pattern That Preceded CVE-2026-0400
Security researchers at GreyNoise have detected a new spike in scanning activity targeting SonicWall devices that follows a similar pattern to activity preceding a prior vulnerability (CVE-2026-0400). The researchers are documenting the activity and providing guidance on indicators defenders should monitor.
Why it matters: Network defenders relying on SonicWall appliances need to investigate scanning patterns immediately, as historical precedent suggests this activity may precede active exploitation of a vulnerability.
- ransomware
Inside the RaaS Ecosystem: Operators, Affiliates & Attack Tradecraft | Huntress
Ransomware-as-a-Service (RaaS) operations involve complex relationships between operators and affiliates, where affiliates handle initial access, persistence, and data exfiltration before operators deploy ransomware. Understanding these distinct roles and tradecraft helps defenders identify and disrupt attacks at multiple stages.
Why it matters: Security teams need to recognize that ransomware attacks involve multiple actors with different responsibilities; detecting affiliate activity in early phases (access, persistence, exfiltration) can stop attacks before encryption occurs.
- breaches incidents
GitHub internal repositories breached
A malicious Visual Studio Code (VS Code) extension resulted in cloned private repositories from GitHub, with the stolen data reportedly being offered for sale on criminal forums. The incident highlights supply chain risks through developer tools and the potential exposure of sensitive code repositories.
Why it matters: Organizations using compromised VS Code extensions face immediate risk of private repository theft and intellectual property exposure, requiring urgent review of extension installations and repository access logs.
- threat intel
durabletask: TeamPCP's Latest PyPi Compromise
A malicious version of the durabletask package was discovered on the Python Package Index (PyPI), following tactics consistent with TeamPCP. The compromise targeted developers using this dependency management platform. This represents another instance of supply chain threats through package repository manipulation.
Why it matters: Developers and organizations using durabletask or similar PyPI packages face immediate risk of compromise through dependency installation; practitioners should audit package versions and implement package verification controls.
- cloud saas
Introducing Runtime Threat Detection for Google Cloud Run
Wiz has released general availability of its Runtime Sensor for Google Cloud Run, enabling real-time threat detection and response capabilities for serverless container workloads. This security tool provides runtime visibility and threat monitoring for containers deployed on Google's serverless platform.
Why it matters: DevSecOps teams running containerized applications on Google Cloud Run can now detect and respond to threats in production environments, reducing exposure from malicious activity targeting serverless infrastructure.
- vulnerabilitiesCVE-2024-12802
VPN Exploitation When Patched Doesn't Mean Protected
CVE-2024-12802 is an authentication bypass vulnerability in SonicWall SSL VPN appliances that reduces security to single-factor authentication and bypasses MFA. On Gen6 devices, the firmware patch alone does not remediate the vulnerability; six additional manual reconfiguration steps are required, yet standard patch management workflows do not verify these steps, leaving devices appearing patched while remaining exploitable. ReliaQuest identified in-the-wild exploitation of this vulnerability between February and March 2026, where threat actors brute-forced VPN credentials and deployed ransomware staging tools within 30 minutes of initial access.
Why it matters: Organizations running SonicWall Gen6 SSL VPN appliances are at immediate risk if they patched based on firmware version alone without completing six manual remediation steps; practitioners should verify all required configuration changes and implement detection for the sess="CLI" session type to identify brute-force attacks early before ransomware actors gain network access.
- threat intel
The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave
TeamPCP has conducted a multi-ecosystem supply chain compromise targeting GitHub, NPM, and Visual Studio Code (VSCode) environments. The attack aims to steal credentials and establish persistence across these development platforms. This represents a coordinated effort to infiltrate multiple layers of the software development toolchain.
Why it matters: Developers and organizations using GitHub, NPM, and VSCode are at immediate risk of credential theft and unauthorized access to their repositories and systems. Teams should audit package dependencies, review access logs, and rotate credentials if exposed through these compromised ecosystems.
- cloud saas
Exposed RDP: The Misconfiguration Attackers Keep Exploiting
Remote Desktop Protocol (RDP) misconfigurations remain a common attack vector because many organizations fail to detect or restrict exposed RDP services. The article highlights real-world cases where exposed RDP was identified before causing serious damage, underscoring the persistent risk despite awareness efforts.
Why it matters: Security teams and infrastructure owners need to audit and restrict RDP exposure immediately, as attackers actively exploit this misconfiguration to gain initial access and lateral movement within networks.
- ransomware
WantToCry ransomware remotely encrypts files
WantToCry ransomware can remotely encrypt files on systems accessible via Server Message Block (SMB) services. Brute-force attacks targeting SMB are often precursors to this ransomware deployment.
Why it matters: Organizations with exposed SMB services face direct encryption risk from WantToCry; monitor for brute-force attempts on SMB as an early warning indicator and enforce strong authentication and network segmentation to prevent remote access exploitation.
- ransomware
At Mythos Speed: A Defender's Playbook for the AI Vulnerability Surge in 2026
Frontier AI models are dramatically accelerating vulnerability discovery, making it cheap and accessible, while defenders struggle to prioritize among the thousands of disclosed CVEs. In 2025, approximately 50,000 CVEs were disclosed but only 446 were actively exploited in the wild, highlighting that the bottleneck for defenders is not finding vulnerabilities but rapidly triaging and acting on the ones that matter. Threat intelligence paired with agentic processing can help defenders match attacker speed by prioritizing vulnerabilities based on active exploitation, threat actor association, and continuous risk scoring.
Why it matters: Security teams need to shift from manual triage to machine-speed threat intelligence to identify the less than 1% of vulnerabilities that attackers actively weaponize, ensuring limited remediation resources focus on real threats before adversaries exploit them.
- threat intel
Threat Actor Defense Evasion: How Attackers Disable AV & EDR
Threat actors employ various techniques to disable antivirus and endpoint detection and response (EDR) solutions, including exploiting vulnerable drivers, tampering with security configurations, and modifying firewall rules. These evasion tactics allow attackers to operate undetected on compromised systems. Understanding these methods is critical for defensive teams to maintain visibility and protect their environments.
Why it matters: Security operations and incident response teams need to detect and prevent AV/EDR disablement attacks, as successful evasion directly undermines visibility into endpoint compromise and enables attackers to operate freely.
- ai security
From Cryptographic Blind Spots to Post-Quantum Agility: Introducing Wiz for PQC Readiness
Wiz has introduced a tool for post-quantum cryptography (PQC) readiness that provides visibility into cryptographic assets across code, cloud, and runtime environments. The tool leverages the Wiz Security Graph to identify risks and prioritize migration efforts while helping organizations prepare for harvest now, decrypt later attacks.
Why it matters: Security practitioners need to assess and plan cryptographic transitions now to prevent adversaries from storing encrypted data today for decryption after quantum computers become capable of breaking current encryption standards.
- cloud saas
19 Cloud Security Challenges and How to Mitigate Risk | Huntress
This article discusses 19 common cloud security challenges that modern businesses face and provides mitigation strategies. It addresses the security risks and exposures associated with cloud environments that affect organizations and their personnel.
Why it matters: Cloud practitioners and security teams need to understand prevalent cloud security gaps to prioritize remediation efforts that protect their organization's cloud infrastructure and data.
- identity access
Most Common Passwords to Compromise Security in 2026
An article discusses commonly used passwords that pose security risks to individuals and organizations, along with recommendations for strengthening password practices.
Why it matters: All users and defenders need to avoid weak passwords and implement better password hygiene, as commonly used passwords are among the easiest attack vectors for unauthorized access.
- identity access
What Is Single Sign-On? The Practical Guide | Huntress
This article provides an overview of single sign-on (SSO) technology, explaining its function in authentication and access management, as well as guidance on implementing SSO within an organization.
Why it matters: Security practitioners should understand SSO mechanisms to properly configure identity solutions and reduce attack surface from multiple credential management points.
- identity access
Strong Stack. Strong Team. Real Security Resilience.
This is promotional content about building a security stack and program designed to reduce alert fatigue, enhance identity security, and improve incident response capabilities.
Why it matters: Security teams should evaluate whether their current stack and processes are generating excessive noise and whether identity-focused defenses align with their organization's actual risk profile and response speed.
- regulatory
13 Cybersecurity Frameworks for 2026 and How to Choose What's Best for You
This article provides an overview of 13 cybersecurity frameworks and guidance for organizations to select the appropriate framework based on their specific needs and use cases. The piece aims to help security leaders understand different framework options available in 2026.
Why it matters: Security practitioners need to evaluate and select frameworks aligned with their organization's risk profile, industry, and compliance requirements to establish effective security governance.
- ransomware
LABScon25 Replay | Breach Alpha: Trading on Cyber Fallout
Researchers Mick Baccio and Scott Roberts presented analysis on whether public indicators of cybersecurity breaches can predict stock market reactions before formal disclosure. Using AI-assisted data collection and time-series modeling, they tested a trading hypothesis based on casino operator ransomware incidents and other material breaches, ultimately concluding that market responses to cyber events are too inconsistent to reliably inform trading strategies.
Why it matters: Security practitioners and investors should understand how breach disclosure timing and investor perception influence market outcomes, and recognize that simplistic models of cyber-event trading face significant limitations in real-world conditions.
- vulnerabilities
Panic at the Distro
Three critical Linux kernel vulnerabilities—CopyFail, Dirty Frag, and Fragnesia—allow unprivileged users to escalate privileges to root access. Security teams need to identify and patch affected systems to close this privilege escalation pathway.
Why it matters: Linux system administrators and security teams must prioritize patching these kernel vulnerabilities on any systems where unprivileged users have access, as they enable direct privilege escalation to root.
- ransomware
Help-Desk Lures Drop KongTuke's Evolved ModeloRAT
KongTuke, a financially motivated initial access broker, has shifted from web-based delivery methods to impersonating help-desk staff in external Microsoft Teams chats to distribute ModeloRAT, a remote access trojan with redundant command-and-control infrastructure and layered persistence mechanisms. The group achieves persistent access within five minutes of victims executing a single PowerShell command, and rotates through multiple Microsoft 365 tenants and persistence triggers to evade defensive measures. This represents the first known use of a collaboration platform by KongTuke for initial access and signals a broader trend of threat actors moving social engineering tactics from email and web vectors to Teams and similar platforms.
Why it matters: Security teams and Microsoft 365 administrators need to restrict external Teams federation and hunt for portable Python installations to detect KongTuke activity, as help-desk impersonation via Teams now represents a low-friction initial-access channel comparable to email that many organizations have not yet adequately controlled.
- regulatory
CMMC Final Rule: A Guide for DoD Subcontractors
The Department of Defense (DoD) has finalized the Cybersecurity Maturity Model Certification (CMMC) rule, establishing a November 2026 deadline for DoD subcontractors to achieve Level 2 compliance. Security vendors are offering tools and monitoring services to help organizations meet these requirements.
Why it matters: DoD subcontractors must act now to assess their current maturity level and plan remediation efforts to meet the November 2026 deadline, avoiding contract suspension or loss of work.
- threat intel
Why AMOS matters: The macOS malware stealing data at scale
Sophos X-Ops has analyzed Atomic macOS Stealer (AMOS), a malware that extracts data at scale on macOS systems. The analysis covers the stealer's technical capabilities and operational scope.
Why it matters: macOS users and organizations relying on Apple devices face data exfiltration risks from AMOS; security teams should understand the malware's functionality to detect and respond to infections.
- threat intel
Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defense
Artificial intelligence combined with threat intelligence creates new defensive capabilities by enabling real-time, scaled mapping of adversary tactics and techniques (TTPs) against an organization's actual infrastructure, exposure, and defensive gaps. Traditional AI applications in cybersecurity focus on automation and acceleration of existing workflows, but the convergence of AI reasoning with threat intelligence produces qualitatively different capabilities that begin to address the structural asymmetry between defenders and attackers. This integration allows defenders to efficiently prioritize scarce resources by connecting attacker behaviors to actual organizational exposure rather than treating threat intelligence as disconnected feeds.
Why it matters: Security teams and practitioners should evaluate how AI-augmented threat intelligence mapping can reduce analyst toil and shift from reactive to proactive risk prioritization, addressing the fundamental resource constraints that have historically favored attackers.
- vulnerabilities
NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals
NIST's National Vulnerability Database changed its enrichment policy on April 15, 2026 to prioritize only CVEs appearing in the CISA Known Exploited Vulnerabilities catalog, federal software, or software designated critical under Executive Order 14028, marking roughly 15-20% of anticipated CVE volume while leaving the remainder unenriched without CVSS scores or product mappings. Vulnerability management teams that depend on NVD CVSS scores may face operational gaps as the backlog grows. Recorded Future argues that effective vulnerability prioritization should rely on attacker behavior signals and the weaponization lifecycle rather than institutional CVSS scoring delays.
Why it matters: Security teams using CVSS scores from NVD as primary vulnerability prioritization inputs will lose enrichment data on 80-85% of incoming CVEs, requiring alternative risk scoring methods that track exploit availability, proof-of-concept development, and active attacker use to maintain effective patch prioritization.
- identity access
How Huntress Managed ITDR's New Incident Report Timeline | Huntress
Huntress has released a feature within its Managed Identity Threat Detection and Response (ITDR) platform called Incident Report Timeline, which provides chronological documentation of security incidents. This capability is designed to help security teams review and respond to incidents with greater clarity and context.
Why it matters: Security teams using Huntress Managed ITDR can now better investigate and respond to identity-based threats through improved incident visibility, reducing time-to-response for attacks targeting identity infrastructure.
- cloud saas
Beyond Findings: Connecting Exploitable Risk to Cloud Context with Wiz and HackerOne
Wiz and HackerOne have partnered to integrate vulnerability and risk data, allowing security teams to view exploitable risks within their broader cloud environment context. This integration aims to help practitioners correlate findings from bug bounty programs with their actual cloud infrastructure and asset inventory.
Why it matters: Security teams managing cloud environments need to prioritize which vulnerabilities pose the highest risk; this integration helps connect external vulnerability reports to internal cloud assets and context for faster remediation decisions.
- vulnerabilities
Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP
Researchers have identified a page-cache corruption vulnerability in the Linux kernel's Dirty Frag family that allows unprivileged local attackers to escalate privileges to root level. The vulnerability exploits issues in how the kernel handles fragmented data structures in memory. This represents a significant local privilege escalation pathway that affects Linux systems across multiple distributions.
Why it matters: Linux users and administrators need to patch affected systems immediately, as any local unprivileged user can exploit this to gain root access and fully compromise the machine.
- vulnerabilities
May’s Patch Tuesday hauls out 132 CVEs
Microsoft's May Patch Tuesday release addressed 132 Common Vulnerabilities and Exposures (CVEs), with additional advisories bringing the total count to approximately 300 across the month. Many of the addressed vulnerabilities had patches or mitigations already in place prior to the official release.
Why it matters: Security teams must prioritize testing and deploying the 132 CVE patches to reduce organizational attack surface, particularly any marked as critical or actively exploited.
- vulnerabilitiesCVE-2025-54957
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
Researchers demonstrated a zero-click exploit chain for the Google Pixel 10 that achieves root access through two vulnerabilities: an updated Dolby decoder exploit (CVE-2025-54957) and a critical flaw in the VPU driver that allows unmapped kernel memory access. The VPU driver's mmap handler fails to bound memory mappings to the hardware register region, enabling arbitrary kernel memory access and modification from userspace.
Why it matters: Pixel 10 users with December 2025 or earlier security patch levels are exposed to unauthenticated complete device compromise via network or local triggers, and device manufacturers and security teams need to prioritize patching the VPU driver vulnerability immediately as it represents a straightforward path to kernel code execution.
- threat intel
Attackers Don't Take Holidays, But They Know You Do
Security research analyzing April alert data indicates attackers coordinate increased activity ahead of holiday weekends when defense teams are reduced. The ROC STAR Report documents timing patterns, tools, and tactics exploited during these periods.
Why it matters: Security operations teams should staff and monitor more aggressively before holiday breaks, since adversaries time attacks to exploit reduced coverage and delayed response.
- industry
Huntress × Acrisure Cyber Insurance Program
Huntress and Acrisure have launched a joint cyber insurance program that offers streamlined coverage with a zero deductible for Technology Errors and Omissions or Cyber policies when customers use Huntress' Managed Endpoint Detection and Response (EDR) and Managed Identity Threat Detection and Response (ITDR) services. The program combines insurance benefits with managed security services to reduce policyholder out-of-pocket costs.
Why it matters: Security practitioners and managed service providers can reduce insurance deductibles to zero by deploying the specified detection and response tools, lowering total cost of ownership for cyber coverage.
- cloud saas
Introducing Wiz Audit History: Track Every Change Across your Environment
Wiz has released Audit History as a generally available feature that tracks configuration changes and findings across cloud environments in a unified timeline. The capability is designed to support incident response investigations and compliance documentation requirements.
Why it matters: Cloud security and compliance teams need audit visibility to investigate incidents faster and demonstrate change control to auditors; this tool centralizes that tracking across multiple cloud platforms.
- threat intel
ClickFix Evolves with PySoxy Proxying
ReliaQuest researchers observed a ClickFix campaign that evolved beyond one-time user execution to establish persistent access using scheduled tasks and PySoxy, an open-source Python SOCKS5 proxy tool. After a user executed a malicious PowerShell command from a compromised website, the attacker deployed a PowerShell-based command-and-control channel, domain reconnaissance, and a secondary encrypted proxy path through PySoxy, creating a durable intrusion that continued attempting to re-execute even after initial outbound connections were blocked. This represents the first observed combination of ClickFix with PySoxy, demonstrating how attackers are layering older open-source tools to establish redundant access paths that are harder to detect and contain.
Why it matters: Security teams investigating ClickFix incidents must treat cases with persistence mechanisms or secondary tools as active compromises requiring full containment, not isolated execution events, since blocking one C2 connection will not stop scheduled tasks from continuously re-attempting callback and maintaining attacker access.
- threat intel
Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
Malicious npm packages linked to the Mini Shai-Hulud supply chain campaign have compromised TanStack and additional developer tooling packages. The attack targets high-value dependencies that could expose downstream projects to compromise through software supply chain pollution.
Why it matters: Development teams relying on affected npm packages face immediate risk of code injection and malware distribution to their applications and users; practitioners should audit dependencies and update to verified clean versions.
- ai security
Inside the lethal trifecta: Blast radius reduction in AI agent deployments
This article discusses practical security measures that organizations can implement immediately to mitigate risks in AI agent deployments, focusing on reducing the potential impact of AI-related incidents.
Why it matters: Security teams and AI practitioners need concrete, actionable steps to limit blast radius when deploying AI agents, as misconfigured or compromised agents can spread damage across connected systems and data.
- cloud saas
Elastic Security MCP App: Interactive security operations inside your AI Tools
Elastic released a Model Context Protocol (MCP) app that integrates security operations directly into AI tools like Claude, VS Code, and Cursor, enabling security operations center analysts to perform triage, threat hunting, case management, and detection rule tuning without leaving the chat interface. The app provides six interactive dashboards that map to core security workflows and sync all actions back to Elasticsearch and Kibana, allowing analysts to maintain full context and workflow continuity across platforms.
Why it matters: SOC analysts and security engineers using Claude, VS Code, or other compatible AI tools can now perform interactive security investigations within their preferred AI environment while maintaining data consistency with their Elastic deployment, reducing context switching and improving operational efficiency.
- threat intel
How EvilTokens Turbocharges Old School Phishing with AI
EvilTokens is an attack campaign that exploits legitimate device code authentication flows using AI to conduct phishing at scale against 344 organizations, bypassing the need for stolen passwords or malware. Device code phishing leverages standard OAuth and similar protocols where users are asked to visit a URL and enter a code, creating an opportunity for attackers to intercept or manipulate the flow. The campaign demonstrates how AI techniques amplify traditional phishing methods by automating targeting, personalization, or execution across large victim sets.
Why it matters: Security teams and identity administrators need to review device code authentication implementations and user training, as this attack bypasses credential-based defenses and affects any organization using OAuth, SAML, or similar federated authentication flows.
- ransomwareCVE-2025-55182
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
EtherRAT malware, initially discovered in December 2025 targeting Linux servers via CVE-2025-55182, evolved to include a Windows variant by March 2026. Recent findings indicate that EtherRAT and TukTuk command and control infrastructure have been repurposed or connected to The Gentleman ransomware operations.
Why it matters: Organizations running Linux and Windows servers need to assess whether they were targeted by EtherRAT campaigns and patch CVE-2025-55182, as compromised systems may now face ransomware deployment by The Gentleman threat group.
- cloud saas
Wiz at Wiz: Reducing Risk through Service Ownership
Wiz security has implemented a Service Catalog approach to connect cloud risks with the teams responsible for owning and managing those services. This strategy aims to shift cloud security accountability from a centralized security function to distributed service owners who can take direct action on identified risks.
Why it matters: Security and engineering teams need practical ways to assign cloud risk remediation responsibility; service ownership models can accelerate risk reduction by making accountability clear and distributing the workload.
- vulnerabilitiesCVE-2026-31431
Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
Linux kernel vulnerabilities Copy Fail (CVE-2026-31431), Copy Fail 2, and DirtyFrag enable local privilege escalation through page cache corruption bugs exploitable via legitimate kernel interfaces like AF_ALG socket and splice() syscalls. Copy Fail has been observed in active exploitation and added to CISA's Known Exploited Vulnerabilities catalog, while DirtyFrag extends the attack surface to the networking stack with multiple exploitation paths that bypass some existing mitigations.
Why it matters: Linux system administrators and security teams must detect and patch these vulnerabilities immediately: attackers can escalate from unprivileged local access to root using short, reliable proof-of-concept code across major distributions (Ubuntu, RHEL, Amazon Linux, SUSE), and detection requires monitoring syscall primitives (AF_ALG socket, splice, unshare) rather than specific exploit signatures since multiple public reimplementations already exist.
- ai security
A Framework for AI Threat Readiness
A new framework with four pillars has been developed to address the challenge of AI models autonomously discovering and exploiting zero-day vulnerabilities. The framework is designed to improve the speed of patching, threat analysis, and incident response capabilities.
Why it matters: Security teams need a structured approach to defend against AI-driven vulnerability discovery threats, requiring immediate adoption of faster patching and response processes to limit exposure windows.
- cloud saas
See and Secure Everything at the Edge with Wiz and Akamai
Wiz and Akamai have integrated their platforms to provide unified visibility of edge configurations within the Wiz Security Graph. This integration allows security teams to assess risk across edge infrastructure and runtime environments in a consolidated view.
Why it matters: Practitioners managing edge infrastructure need this integration to identify misconfigurations and security gaps in Akamai deployments without switching between tools.
- industry
Working in London at the World’s Largest Intelligence Company
Recorded Future, a cybersecurity intelligence company with over 1,000 employees globally, has expanded its London office to house more than 100 cross-functional staff members across multiple departments including research, sales, and global services. The office has grown from a small converted attic operation in 2018 to a modern high-rise location, reflecting the company's expansion from serving dozens of regional customers to approximately 700. The company emphasizes a collaborative culture with team-building activities and inclusive workplace practices.
Why it matters: Security practitioners and potential employees evaluating threat intelligence vendors should note Recorded Future's significant regional growth in EMEA, which may affect service availability, team continuity, and the maturity of their intelligence offerings in that market.
- cloud saas
Detecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare Response
A security practitioner describes using Traefik reverse proxy logs ingested into Elastic Security to detect web server probing and fuzzing activity through statistical analysis of HTTP 404 response codes. When suspicious patterns are identified, an automated workflow blocks the offending source IP addresses at the Cloudflare edge using the Cloudflare API, providing perimeter defense without requiring local tools like Fail2Ban.
Why it matters: Practitioners running self-hosted services behind reverse proxies need automated defenses against reconnaissance scanning; this approach reduces attack surface by blocking threats at the edge rather than consuming local bandwidth and offers a reusable detection framework applicable to other attack patterns.
- threat intel
Threat Actors Weaponize Tiflux RMMs in Malspam Attacks
Security researchers identified a malspam campaign that distributes a weaponized installer for Tiflux, a commercial remote monitoring and management tool. Threat actors are abusing the legitimate RMM software as a delivery mechanism in mass phishing attacks to compromise target systems.
Why it matters: Organizations and security teams need to monitor for Tiflux installer emails and block suspicious distribution sources, as RMM tools provide attackers with broad system access if installed through malicious channels.
- industry
Meet Andrea Colon, Restoring Peace of Mind in a Paranoid Digital World
Huntress Account Executive Andrea Colon discusses the psychological impact of cyberbreaches on small business owners and Huntress's approach to helping affected organizations recover and regain confidence in their security posture.
Why it matters: Small business leaders and their security teams need to understand both the technical and emotional recovery dimensions of incidents to build resilience and trust in their defenses.
- cloud saas
Build Fast, Build Secure: Wiz findings are now in Lovable
Wiz, a cloud security platform, has integrated its capabilities into Lovable, a development environment that enables developers to identify and remediate security risks during the application building process. The integration allows developers to address security issues in real time as they write code, rather than discovering them later in the development cycle.
Why it matters: Developers using Lovable can now detect and fix security vulnerabilities during development, reducing the likelihood of shipping insecure code and decreasing remediation costs for security teams.
- industry
It's Time to Go After Achieving Zero Code Criticals
Wiz has introduced a badge or certification program to help organizations achieve and maintain zero critical code vulnerabilities. The initiative appears designed to track and recognize companies that eliminate critical-severity issues in their codebase.
Why it matters: Development and security teams need to understand whether this is a practical vulnerability management milestone or a marketing construct that could distract from comprehensive risk reduction beyond critical severity ratings.
- ransomware
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
SentinelLABS discovered PCPJack, a credential theft worm that targets exposed cloud infrastructure including Docker, Kubernetes, Redis, and MongoDB, while removing artifacts from the TeamPCP threat actor group. The framework harvests credentials from cloud services, containers, developer tools, and financial applications, then spreads to additional hosts via a dropper script that downloads Python-based modules from attacker-controlled infrastructure. Unlike typical cloud malware, PCPJack does not deploy cryptominers, instead suggesting monetization through credential fraud, spam campaigns, extortion, or resale of stolen access.
Why it matters: Cloud infrastructure teams and developers must audit exposed Docker, Kubernetes, and database services for credential theft and apply network restrictions immediately, as this active worm actively spreads across environments and is associated with significant supply chain attack activity.
- threat intel
Donuts and Beagles: Fake Claude site spreads backdoor
A fake website impersonating Anthropic's Claude AI platform is distributing malware through DLL sideloading attacks that establish a backdoor on infected systems. The campaign uses malvertising to direct users to the fraudulent site, where downloads are weaponized with the Beagle backdoor and DONUT malware.
Why it matters: Organizations and developers using Claude or searching for AI tools are at risk of downloading backdoored software that could compromise credentials and system access; practitioners should warn users against unofficial Claude sites and monitor for suspicious DLL sideloading activity.
- threat intel
Quantum Risk Explained
Quantum computing is advancing from theoretical research toward practical commercial deployment, creating security risks for current encryption and authentication systems. Cryptographically relevant quantum computers (CRQCs) could break public-key algorithms like RSA and ECC that protect internet communications, identity systems, and software supply chains. The threat is already present through harvest now, decrypt later activities, where adversaries collect encrypted data today to decrypt once quantum capabilities mature, and regulatory mandates are pushing organizations to adopt post-quantum cryptography by the mid-2020s to avoid compressed timelines and higher costs.
Why it matters: All organizations holding sensitive data, managing authentication, or relying on digital signatures face long-term exposure from harvest now, decrypt later attacks and eventual CRQC emergence; practitioners should begin post-quantum cryptography migration planning now to meet regulatory deadlines and avoid costly emergency transitions.
- threat intel
TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook
Elastic Security Labs identified TCLBANKER, a Brazilian banking trojan that represents a significant evolution of the MAVERICK/SORVEPOTEL malware family. The malware uses a loader with extensive anti-analysis capabilities to deploy a banking trojan targeting 59 Brazilian financial institutions and a worm module that spreads via compromised WhatsApp and Outlook accounts. The infrastructure is hosted on Cloudflare Workers and shows signs of early-stage operations with debug artifacts and incomplete phishing pages.
Why it matters: Brazilian financial institution customers and organizations supporting them need to monitor for MSI installers bundled in ZIP files and educate users about WhatsApp and email messages from contacts, as the malware hijacks authenticated sessions to propagate to victims' contact lists.
- threat intel
The Jenkins Threat Landscape
An analysis examines how Jenkins usage patterns, plugin adoption, and configuration choices create vulnerabilities in the attack surface. The report provides insights into common deployment practices and security misconfigurations that expose instances to compromise.
Why it matters: DevOps teams and CI/CD pipeline operators must understand their Jenkins deployment patterns and plugin risks to identify and remediate misconfigurations before attackers exploit them.
- ot ics
LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experience
Joe FitzPatrick presents research on undocumented connectivity features in imported networked devices, particularly highlighting cellular radios discovered in U.S. highway solar inverters and the widespread reliance on foreign-manufactured hardware by small businesses and infrastructure operators. He argues that current safeguards like import bans and FCC regulations are ineffective at managing supply chain risks and recommends alternatives including right-to-repair policies with offline use guarantees, hardware bills of materials, and comprehensive privacy legislation. The talk examines how devices default to connecting to foreign entities and the practical challenges of using such hardware without establishing external connections.
Why it matters: Security practitioners and infrastructure operators need to understand that critical systems depend on imported hardware with undocumented connectivity features, creating supply chain exposure that import restrictions alone cannot mitigate, and should advocate for transparency mechanisms like hardware bills of materials and offline-capable designs.
- vulnerabilitiesCVE-2026-0300
Critical Buffer Overflow Vulnerability in PAN-OS Exploited in-the-Wild
A critical buffer overflow vulnerability (CVE-2026-0300) in Palo Alto Networks PAN-OS User-ID Authentication Portal enables unauthenticated remote code execution with root privileges and is being exploited in active attacks.
Why it matters: Organizations running vulnerable PAN-OS deployments face immediate compromise risk; security teams must patch or apply mitigations without delay to prevent unauthorized system takeover.
- threat intel
Threat Activity Enablers: The Backbone of Today’s Threat Landscape
The article introduces threat activity enablers (TAEs), infrastructure providers that knowingly support malicious cyber operations including ransomware, botnets, and state-sponsored activity. TAEs operate through obfuscation tactics such as shell companies, rapid rebranding, and direct control of IP resources to evade accountability and maintain resilient malicious infrastructure. Security teams can identify and track high-risk TAE networks using threat density scoring to move from reactive threat response to proactive infrastructure risk management.
Why it matters: Infrastructure and network defenders need to track TAE networks and patterns to identify which providers actively harbor threat actors, enabling them to apply intelligence across prevention, detection, and exposure mitigation rather than responding to individual threats after the fact.
- industry
Recorded Future Named a Leader in the 2026 Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies. And there’s more.
Recorded Future has been recognized as a Leader in Gartner's inaugural Magic Quadrant for Cyberthreat Intelligence Technologies, evaluated among 17 vendors in the market. The company is introducing a simplified product structure with four new solutions focused on cyber operations, digital risk protection, third-party risk, and payment fraud detection, built on a unified intelligence platform that integrates with tools like CrowdStrike Falcon and Google SecOps.
Why it matters: Security teams evaluating threat intelligence platforms need to understand the competitive positioning and feature sets available; Recorded Future's new modular approach and integrations may affect purchasing decisions and how existing customers access threat intelligence services.
- ransomware
How EvilAI Tried to Speed Run a Triple Ransomware Attack
Halcyon detected and blocked EvilAI, an AI-powered malware campaign, across three customer environments spanning different industries before encryption or data exfiltration could occur. The campaign attempted coordinated ransomware attacks simultaneously across multiple targets. No successful compromise or damage was reported.
Why it matters: Organizations across multiple sectors face active threats from AI-enhanced ransomware campaigns; practitioners should review detection controls and incident response capabilities to identify similar coordinated attack patterns.
- cloud saas
Introducing Penetration Test Findings: Unified Offensive Security in Wiz
Wiz has introduced a new feature that consolidates penetration test findings from multiple sources, including bug bounties, manual audits, and its Wiz Red Agent tool, into a unified dashboard. The feature provides contextual information to help security teams analyze and prioritize offensive security results in one place.
Why it matters: Security teams using Wiz can now reduce fragmentation across pen-testing workflows and improve visibility into vulnerabilities discovered through multiple assessment methods, enabling faster remediation prioritization.
- ot ics
Hacking Embodied AI
Humanoid and quadruped robots are increasingly deployed in manufacturing, critical infrastructure, and military operations, but security has lagged behind rapid adoption. Researchers demonstrated that commercially available robots can be compromised via Bluetooth, exfiltrate data to remote servers, and spread compromises across robot fleets wirelessly. Organizations deploying embodied AI must treat robots as cyber-physical endpoints with comprehensive security controls, network isolation, and fleet continuity plans.
Why it matters: Security teams and procurement officers responsible for operational technology and critical infrastructure deployments need immediate visibility into embodied AI security posture, as robot fleets lack foundational controls and can create cascading compromise across physical and digital systems.
- threat intel
Your UEBA is lying to you: Why entity record quality decides everything
User and entity behavior analytics (UEBA) systems depend critically on the quality of entity records representing users, hosts, and services, yet most implementations get this foundation wrong from the start. The article examines two common failure modes: treating all instances of a username as a single entity (creating noise from shared accounts), and requiring identity provider integration only (leaving most environments invisible). A third approach using host-scoped identity with proper governance can balance meaningful signal detection against false positives.
Why it matters: Security analysts and UEBA platform operators need to audit entity record quality because poor entity models degrade detection accuracy, waste investigation time on false positives, or blind visibility entirely, undermining the effectiveness of downstream anomaly detection and risk scoring regardless of algorithm sophistication.
- ai security
AI-generated hunting leads: The hunt starts before you ask the question
Elastic has developed AI-generated threat hunting leads that automatically identify patterns and anomalies in security telemetry by analyzing contextual entity data rather than waiting for human analysts to form hypotheses. The system uses an entity store that tracks user, host, and service characteristics over time, combining attributes, lifecycle events, behavioral signals, and risk scores to surface suspicious patterns that would be difficult for analysts to discover manually. This approach aims to shift security operations from reactive alerting to proactive, environment-specific threat hunting.
Why it matters: Security analysts and threat hunters should evaluate whether AI-assisted lead generation can reduce the time spent on hypothesis formation and help surface compromises during the critical window before attackers achieve objectives.
- identity access
Know who to watch before the incident finds you
Elastic Security v9.4 introduces Entity Analytics Watchlists, a feature that allows security teams to create weighted lists of users, hosts, and services to inject organizational context directly into the platform's risk scoring pipeline. The capability bridges the gap between what security teams know about their environment and what their SIEM can operationalize, without requiring engineering configuration or custom queries. Watchlist membership compounds with alert activity, asset criticality, and behavioral signals to produce prioritized risk scores.
Why it matters: Security teams and insider threat programs need to operationalize existing organizational knowledge about high-risk entities: this feature enables faster detection and prioritization of anomalies involving departing employees, privileged admins, and other elevated-risk targets without manual engineering overhead.
- cloud saas
Elastic Workflows GA: automation where your security data already lives
Elastic has released Workflows as generally available in version 9.4, providing native automation capabilities built directly into the Elastic platform for security, observability, and search use cases. The automation layer executes based on alerts or schedules, querying Elasticsearch, enriching data with threat intelligence, creating cases, and calling external APIs without requiring separate platforms or data movement. Version 9.4 adds 25 case management automation steps, human-in-the-loop primitives, natural language workflow authoring via AI, and expanded flow-control features for production-ready security automation.
Why it matters: Security teams using Elastic can now automate alert triage and case management at scale without custom integrations, reducing manual handoffs and enabling faster response to security events.
- threat intel
Practical Package Security: The Unofficial Guide
This article provides practical security guidance for managing package dependencies and reducing exposure from compromised or malicious packages. It covers strategies for attack surface reduction, runtime protection, package validation, and early detection of compromises.
Why it matters: Development teams and security practitioners need to implement package management controls to prevent supply chain attacks that could introduce malicious code into production systems.
- identity access
dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025
Researchers discovered dMSA Ouroboros, a credential extraction technique that exploits delegated permissions in fully patched Windows Server 2025 domains. The attack is self-sustaining and persists despite standard remediation attempts, requiring only standard permissions to execute.
Why it matters: Active Directory administrators and identity teams need to understand this attack vector because it bypasses typical security controls and remediation processes, allowing attackers to maintain persistent credential access in core infrastructure.
- cloud saas
Meet Wiz for M365: Bringing SaaS into the Security Graph
Wiz announced a new product offering called Wiz for M365 that integrates Microsoft 365 security into its unified security platform. The tool aims to provide consolidated visibility and context across SaaS and cloud environments through a single security graph.
Why it matters: Security teams managing Microsoft 365 environments can now use Wiz to centralize visibility across their SaaS and cloud infrastructure, reducing the complexity of monitoring multiple disconnected security tools.
- cloud saas
From Foundation to Force: Your Guide to Operationalizing Wiz at Scale
This article provides guidance on implementing Wiz, a cloud security platform, across key operational phases including development, detection and response, and program maturity stages. The content focuses on establishing and scaling a security program using Wiz capabilities.
Why it matters: Security practitioners deploying Wiz need a structured operationalization approach to maximize the platform's value across development environments, threat detection workflows, and security program maturity.
- cloud saas
One agent, the right skills: Elastic Security 9.4 brings domain expertise on demand to every SOC workflow
Elastic Security 9.4 introduces an AI agent architecture that uses specialized skills to handle different security operations workflows, including detection rule writing, alert triage, and threat hunting. Rather than using a single monolithic prompt, the system activates task-specific skills with tailored instructions, tools, and domain context only when needed, allowing analysts to manage multiple investigations through one conversation interface.
Why it matters: SOC teams can consolidate fragmented workflows and reduce context-switching overhead, enabling faster investigation and response to threats like credential-harvesting campaigns and service account anomalies.
- cloud saas
Elastic Conversational Entity Analytics: threat hunting in a single conversation
Elastic has introduced Conversational Entity Analytics, an AI agent skill within Agent Builder that allows threat hunters to investigate users, hosts, and services through natural language questions rather than navigating multiple screens and dashboards. The feature delivers entity risk scores, profiles, and analytics inline within a chat interface, keeping investigation context in one place while maintaining connection to the underlying Entity Analytics data in Kibana.
Why it matters: Security teams and threat hunters need to evaluate whether conversational AI integration into their SIEM workflows can improve investigation efficiency and reduce time spent pivoting between multiple interfaces during entity-focused threat hunts.
- ai security
From plain English to production rule: AI-native Elasticsearch ES|QL detection in Elastic Security
Elastic Security has added AI-powered detection rule creation that allows analysts to describe threats in plain English and automatically generates validated Elasticsearch Query Language (ES|QL) rules with MITRE ATT&CK mappings and severity recommendations. The capability is built directly into the rule creation workflow, eliminating the need to learn query syntax or leave the platform. This addresses the growing gap between attack speed and detection engineering capacity by reducing the friction required to write and deploy new detection rules.
Why it matters: Detection engineering teams need to match the pace of AI-augmented attackers; this capability accelerates rule creation for Enterprise license customers, reducing backlog and coverage gaps that adversaries can exploit.
- ransomware
The Ransom Is the Smallest Line Item
Ransomware incidents impose costs far beyond the ransom payment itself, including financial losses, regulatory penalties, and reputational damage. Organizations that address ransomware primarily as a technology problem miss the broader business and compliance implications that boards should oversee.
Why it matters: Board members and senior leaders need to understand that ransomware risk spans finance, legal, and operations: the ransom is often the least expensive component, and failure to address incident response holistically can result in material financial and regulatory exposure.
- threat intel
Social Engineering Leveled Up. Has Your Security Program?
Social engineering attacks have evolved to include device code phishing and AI-generated lures that can bypass multi-factor authentication (MFA) and evade detection. Security programs need to update their cyber resilience strategies to address these emerging tactics before attackers exploit organizational blind spots.
Why it matters: Security leaders and defenders need to reassess anti-phishing and user awareness controls today, as traditional MFA protections may not stop device code and AI-enhanced social engineering attacks from reaching employees.
- vulnerabilitiesCVE-2026-31431
Copy Fail: Universal Linux Local Privilege Escalation Vulnerability
A Linux kernel vulnerability identified as CVE-2026-31431, named Copy Fail, enables unprivileged local users to escalate privileges to root through relatively straightforward exploitation. The flaw affects universal Linux distributions and poses a direct path to complete system compromise for attackers with local access.
Why it matters: Any Linux system with local users is at risk; practitioners should immediately assess whether unprivileged accounts exist in their environments and prioritize patching this kernel vulnerability to prevent privilege escalation attacks.
- government policy
The Iran War: What You Need to Know
Insikt Group published a scenario analysis examining potential outcomes of the Iran conflict over the next 6-12 months, ranging from ceasefire to regional war and nuclear crisis, with business implications for each scenario. Iranian hardliners are driving strategic deadlock, oil exports have been cut by approximately 70% through blockade, and maritime tensions are escalating with vessel seizures and mine-laying in the Strait of Hormuz. The analysis covers geopolitical, cyber, and influence operations dimensions affecting organizations in the US, Israel, Gulf states, and those exposed to energy, shipping, and critical infrastructure sectors.
Why it matters: Organizations in the US, Israel, and Gulf states with exposure to energy markets, maritime shipping, and critical infrastructure should review the scenario analysis and 0-90 day priority actions to assess targeting risk from Iranian state-sponsored actors and prepare for potential regional escalation impacts.
- threat intel
DFIR: From alert to root cause using Osquery without leaving Elastic Security
Elastic Security integrates Osquery to enable modern Digital Forensics and Incident Response (DFIR) workflows that shift from post-incident disk imaging to real-time, query-driven investigation across live endpoints. The platform eliminates context-switching by allowing investigators to move from alert detection through forensic analysis without leaving the Elastic interface. Osquery exposes OS artifacts as queryable tables, enabling rapid hypothesis testing and investigation pivots across ephemeral infrastructure at scale.
Why it matters: Security teams investigating incidents in dynamic cloud and containerized environments can reduce investigation time and catch attackers operating on minute-level timelines by performing live forensic queries directly within their existing Elastic Security platform rather than manually collecting full disk images or switching between multiple tools.
- regulatory
How Public Sector Organizations Protect Their Communities Without Breaking the Budget
The article discusses cost-effective security strategies that public sector organizations can implement to protect their communities and constituents. It examines budget constraints and practical approaches for maintaining adequate security posture within financial limitations.
Why it matters: Public sector security practitioners need to optimize limited budgets while maintaining effective community protection, making this relevant for evaluating cost-efficient security investments.
- cloud saas
Red Agent and Claude Opus: Securing Production Targets at Scale
Wiz and Anthropic have partnered to deliver continuous AI-powered risk assessment capabilities to enterprise customers at scale. The integration combines Wiz's cloud security platform with Claude Opus, Anthropic's large language model, to automate vulnerability and risk detection across production environments.
Why it matters: Security teams using Wiz for cloud security can now leverage advanced AI models to accelerate threat detection and remediation at scale, reducing manual assessment overhead and improving coverage of complex environments.
- ransomware
Why We Built the World's First Ransomware Operations Center
Halcyon has established a Ransomware Operations Center (ROC), a dedicated team focused on ransomware response and defense. The ROC is offered as an included service for all Halcyon customers.
Why it matters: Organizations using Halcyon gain access to specialized ransomware response expertise, reducing time to detection and containment if an attack occurs.
- ai security
The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2)
GitHub Actions integrations with AI systems can introduce security risks including permission bypasses and prompt injection attacks through CI/CD pipelines. The article explores vulnerabilities that emerge when AI-powered components interact with workflow automation systems and examines mitigation strategies.
Why it matters: DevOps and platform engineering teams using AI-enhanced GitHub Actions should evaluate whether their CI/CD pipelines are exposed to prompt injection or privilege escalation before deploying such integrations into production.
- threat intel
ClickFix Removes Your Background but Leaves the Malware
Huntress researchers identified BackgroundFix, a new social engineering variant of the ClickFix malware campaign that uses a fake Windows background removal tool to distribute CastleLoader, which then deploys NetSupport RAT and CastleStealer malware. The attack chain allows threat actors to gain remote access and steal sensitive data from compromised systems. This represents an evolution of the ClickFix tactics that have been exploited throughout 2024.
Why it matters: Organizations and end users are at risk of inadvertent malware installation through seemingly legitimate Windows utilities, leading to potential data theft and unauthorized remote access that could compromise credentials, intellectual property, and system integrity.
- industry
Building with AI: Here's What No Briefing Will Tell You
Executives managing AI initiatives without hands-on development experience face a comprehension gap that formal briefings cannot address. Proprietary data's competitive advantage is shrinking as AI accelerates development cycles, making a competitor's ability to reconstruct datasets the primary limiting factor. Organizations must prioritize protecting and developing engineers with strong judgment skills as these become the differentiating factor in an AI-leveled competitive landscape.
Why it matters: Technology leaders and security professionals should understand that AI commoditization shifts competitive risk from data protection alone to talent retention and organizational knowledge preservation, requiring strategic focus on engineer development and judgment-critical roles.
- government policy
Risk Scenarios for the US’s Strategic Pivot
The United States is implementing a more militarized security strategy in the Western Hemisphere, including military strikes against cartels, sanctions enforcement, and the Shield of the Americas initiative. This shift toward force-driven counternarcotics and great power competition creates three potential regional scenarios: US-aligned authoritarian partnerships, criminal expansion with governance collapse, or a strategic realignment toward BRICS. All scenarios increase risks of political instability, regulatory fragmentation, cybercrime, critical infrastructure targeting, and surveillance expansion.
Why it matters: Security practitioners and organizations operating in Latin America, the Caribbean, or with regional supply chains face elevated exposure to kinetic conflicts, sanctions disruption, surveillance intensification, cybercrime expansion tied to cartel financing, and critical infrastructure attacks as US military operations intensify and regional governance structures destabilize.
- threat intel
Komari Red: The Monitoring Tool with a Built-in Reverse Shell
Threat actors have exploited Komari, a legitimate monitoring agent, to deploy a SYSTEM-level backdoor, leveraging GitHub in the process. Defenders can use this discovery to identify and hunt for malicious Komari instances within their environments.
Why it matters: Organizations using Komari or managing systems where it may have been installed need to immediately verify the integrity of their monitoring agents and check for unauthorized SYSTEM-level access, as this represents a complete compromise vector.
- ai security
Key Takeaways from the 2026 State of AI in the Cloud Report
A new report examines how artificial intelligence adoption, increased autonomy in AI systems, and evolving attacker tactics are transforming cloud security landscapes. The analysis highlights emerging trends in how organizations deploy AI workloads and the corresponding security challenges that arise.
Why it matters: Cloud and security practitioners need to understand how AI deployment patterns and attacker innovation are reshaping their threat models and defense requirements in cloud environments.
- vulnerabilitiesCVE-2026-41940
The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)
cPanel & WHM, which manages over 70 million domains, contains an authentication bypass vulnerability (CVE-2026-41940) affecting all currently supported versions. The flaw in session loading and saving mechanisms has been exploited in the wild as a zero-day, and cPanel has released patches across multiple version tracks (110.0.x through 136.0.x) to address the issue.
Why it matters: Hosting providers and system administrators using cPanel & WHM must immediately patch affected systems, as this authentication bypass provides administrative access to the management plane and has already been exploited by threat actors.
- threat intel
Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware
Security researchers identified malicious npm packages associated with a supply chain campaign targeting SAP environments, distributing credential-stealing malware. The campaign, termed Mini Shai Hulud, represents an evolution of previous supply chain attack tactics focusing on development dependency chains.
Why it matters: SAP customers and developers who use npm packages in their build pipelines face direct risk of credential compromise and lateral movement into production environments; practitioners should audit npm dependencies and implement package verification controls immediately.
- ai security
Wiz Code Week Recap: Securing AI Native Development
Wiz held Code Week, a discussion about security practices for AI-native development environments. The event focused on helping application security teams gain visibility and implement guardrails for agentic software development and modern supply chain risks.
Why it matters: Application security practitioners need to understand emerging best practices for securing AI agents and modern development pipelines to prevent supply chain compromise and agentic system misuse.
- cloud saas
Modern Defensible Architecture: Resilience for the Australian Federal Government
Wiz provides cloud security capabilities to Australian federal government agencies for implementing Modern Defensible Architecture (MDA) through real-time context analysis, zero trust enforcement, and comprehensive cloud visibility across their infrastructure.
Why it matters: Australian government practitioners need to evaluate cloud security tooling that supports MDA compliance and zero trust deployment across federal agency environments.
- research
Project Swarm: Join the Collective. Defend the Edge
GreyNoise has launched Project Swarm, a research initiative that converts its deception platform from a proprietary sensor network into a shared intelligence platform accessible to the security community. This approach aims to enable collaborative edge defense through distributed data collection and analysis.
Why it matters: Security practitioners should evaluate whether participating in the collective intelligence network provides actionable threat data and operational benefits for their defensive posture compared to proprietary alternatives.
- threat intel
CI/CD pipeline abuse: the problem no one is watching
Attackers are increasingly targeting CI/CD pipelines rather than production systems directly, compromising developer credentials and modifying workflow files to exfiltrate secrets at scale. The article details specific attack patterns including the GhostAction campaign (327 users, 3,325 stolen secrets), the Shai-Hulud npm worm (46,000 malicious packages), and automated scanning for misconfigurations like the pull_request_target trigger. A new open-source tool, cicd-abuse-detector, has been released to identify suspicious pipeline modifications across GitHub Actions, GitLab CI, and Azure DevOps using regex patterns and language model analysis.
Why it matters: Organizations using CI/CD platforms need to immediately review workflow permissions and developer credential access, as a single compromised workflow can exfiltrate cloud credentials, API tokens, and signing keys simultaneously, enabling lateral movement to production and downstream supply chain attacks.
- vulnerabilitiesCVE-2026-3854
Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)
A critical remote code execution vulnerability (CVE-2026-3854) was discovered in GitHub's internal git infrastructure by Wiz Research, affecting both GitHub.com and GitHub Enterprise Server. The flaw enables attackers to execute arbitrary code on affected systems.
Why it matters: GitHub users and enterprise customers running GitHub Enterprise Server must assess whether this vulnerability has been exploited and apply available patches immediately, as remote code execution represents direct compromise of code repositories and deployment infrastructure.
- threat intel
Lazarus Doesn't Need AGI
An unauthorized access to Claude Mythos occurred through a third-party contractor shortly after its announcement, likely through endpoint enumeration based on Anthropic's naming patterns. The incident exposes a broader supply chain security problem where controlled-access model releases have porous boundaries by design, as multiple contractors and partners introduce uneven security practices across the access ecosystem. The structural vulnerability matters less for immediate AI safety concerns and more because state actors like North Korea depend heavily on cyber-enabled theft and could weaponize AI model access to automate and accelerate existing intrusion operations against cryptocurrency exchanges and similar targets.
Why it matters: Security practitioners managing third-party vendor access, AI model deployments, and supply chain risk should recognize that contractual controls differ from operational reality, and that threat actors focused on financial theft (rather than advanced AI dominance) will exploit any productivity gains from early model access to scale existing attack patterns.
- threat intel
The Money Mule Solution: What Every Scam Has in Common
Scams represent a significant global financial problem worth hundreds of billions annually, and unlike breach-based fraud, they rely on convincing victims to send money themselves. A key vulnerability in scam operations is the money mule account, which serves as the exit point for funds and represents a more actionable target for intervention before transactions occur. Regulatory pressure is increasing globally, with jurisdictions like the UK mandating reimbursement for authorized push payment fraud, prompting financial institutions to adopt proactive approaches to address scam vulnerabilities.
Why it matters: Financial institutions and fraud prevention teams need to prioritize mule account identification and disruption to reduce scam losses and meet emerging regulatory requirements that penalize institutions for insufficient anti-scam measures.
- identity access
Unified EDR + ITDR: Closing the Identity Gap Before Attacks Spread
Huntress has integrated endpoint detection and response (EDR) with identity threat detection and response (ITDR) capabilities to correlate endpoint compromise events with cloud identity risks. The unified approach aims to prevent attackers from reusing stolen credentials by linking endpoint telemetry to identity events for coordinated response.
Why it matters: Security practitioners managing both endpoint and cloud identity security need integrated detection to stop infostealer attacks at the credential compromise stage before lateral movement occurs.
- ransomware
Ransomware and Cyber Extortion in Q1 2026
Ransomware activity in Q1 2026 reached 2,638 posts on data-leak sites, up 22% from the prior year, with established groups like Akira and Qilin maintaining high victim volumes while newer actors like The Gentlemen surged into the top tier. Identity-first intrusions and SaaS-targeted attacks by groups such as ShinyHunters demonstrated that significant enterprise impact can occur without traditional encryption deployment. The threat landscape fragmented further, with some newer leak sites using questionable or fabricated claims to extort organizations.
Why it matters: Organizations must focus on detecting and disrupting common ransomware behaviors, such as exposed VPN and RDP access, trusted admin tool abuse, and lateral movement techniques, rather than tracking individual group rankings, as both established and emerging actors continue to drive widespread operational pressure.
- vulnerabilities
NIST NVD Update: What it Means For Vulnerability Management
The National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) is moving away from static Common Vulnerability Enumeration (CVE) scoring toward risk-based prioritization methods. This change reflects a broader industry recognition that vulnerability management should account for contextual threat factors beyond fixed severity scores. Vulnerability managers will need to adapt their prioritization strategies to incorporate dynamic risk assessments.
Why it matters: Vulnerability managers and security teams need to understand this shift to avoid over-relying on legacy static scores when making patching and remediation decisions.
- breaches incidents
Supply chain attacks hit Checkmarx and Bitwarden developer tools
Two separate supply chain attacks were discovered on the same day using the same command-and-control domain, targeting developer tools from Checkmarx and Bitwarden. The incidents were identified through threat research, indicating coordinated or opportunistic exploitation of development infrastructure. These attacks represent a broader pattern of threat actors targeting software supply chains to distribute malware or gain access to downstream users.
Why it matters: Development teams and organizations using Checkmarx or Bitwarden are potentially exposed to compromised tools; practitioners should verify the integrity of recent downloads and check for suspicious activity in their pipelines and deployments.
- threat intel
From Overwhelmed to Autonomous: Rethinking Threat Intelligence in 2026
Modern security organizations struggle not with lack of threat intelligence but with the speed gap between rapid machine-driven attacks and slower human-dependent response workflows. The article argues that traditional threat intelligence models that merely inform decisions are insufficient, and that security teams must shift toward intelligence-driven autonomous systems that continuously correlate signals and trigger actions in real time. Fragmentation across cyber, fraud, and third-party risk functions further compounds the problem, requiring unified, intelligence-led approaches to match attacker velocity.
Why it matters: Security leaders and practitioners need to evaluate whether their current tools and workflows can execute response actions at machine speed; delays in translating intelligence to action represent material business risk and board visibility gaps.
- threat intel
fast16 | Mystery Shadow Brokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet
SentinelLABS discovered fast16, a cyber sabotage framework with origins dating to 2005 that targeted high-precision calculation software by tampering with code execution in memory to produce inaccurate results across facilities. The framework predates Stuxnet by five years and represents the earliest known instance of sophisticated malware using an embedded Lua virtual machine on Windows. References to fast16 were found in the Shadow Brokers' leaked NSA materials, indicating connections to state-sponsored cyber operations.
Why it matters: Organizations running high-precision computing workloads in physics, cryptography, and nuclear research should assess whether legacy systems may have been compromised by this 2005 framework or its descendants, as the attack method targeting calculation integrity could remain undetected without direct forensic investigation.
- cloud saas
Microsoft Vibing — capturing screenshots and voice samples without governance
Microsoft Vibing is an executable distributed through the Microsoft Store that captures user screenshots, clipboard contents, microphone audio, and window metadata, then sends this data to a Microsoft Azure endpoint without explicit user consent or in-app disclosure. The application was developed by Microsoft Research Asia employees but misrepresented as a community or open-source project to bypass internal security and privacy governance reviews. The software auto-starts on Windows login, encodes captured data with machine GUIDs for tracking, and uses WebSocket connections that can evade some proxy configurations.
Why it matters: Windows users and IT teams managing endpoints need to audit whether Vibing is installed and remove it immediately, as it exfiltrates sensitive data including screenshots, audio, and system identifiers to Microsoft infrastructure without proper consent mechanisms or documented data handling policies.
- research
Cyber Hygiene Best Practices: Essential Security Checklist
An article outlines cyber hygiene best practices including strong passwords, multi-factor authentication (MFA), patching, and security training. The piece appears to serve as a general security checklist for organizations.
Why it matters: Security practitioners should review foundational controls to ensure their organization's baseline defenses are implemented and maintained across all staff.
- identity access
What Is Multi-Factor Authentication (MFA)? | How MFA Secures Businesses | Huntress
Multi-factor authentication (MFA) is a security mechanism that combines passwords with additional verification factors to protect against unauthorized access. The article explains that passwords alone are insufficient and that MFA provides an important additional layer of defense for organizations.
Why it matters: Security practitioners need to understand MFA implementation and deployment to reduce credential-based attack surface, especially as password compromises remain common across organizations of all sizes.
- ransomware
Today, trust is the superpower that makes innovation possible
A Recorded Future executive argues that trust has become essential for digital innovation and business growth in an increasingly fragmented security landscape. The article emphasizes that organizations must prioritize threat intelligence, speed of response, and cross-sector collaboration rather than attempting to eliminate risk entirely. The piece highlights Latin America as a region experiencing rapid digital growth but facing significant security gaps, with 452 ransomware incidents tracked in 2025 despite limited cybersecurity infrastructure.
Why it matters: Practitioners should understand that trust and collaborative threat intelligence are now business enablers: organizations lagging in cross-sector information sharing and rapid response capabilities face competitive and economic disadvantages, particularly those operating in or serving Latin American markets where incident rates are high but coordinated defense mechanisms remain underdeveloped.
- threat intel
Critical minerals and cyber operations
Critical minerals and rare earth elements (REEs) have become strategic dependencies rather than commodities, with China controlling much of global processing and refining capacity. As competition for these resources intensifies across land, Arctic regions, and seabeds, cyber threat actors including state-sponsored groups and criminal organizations are increasingly targeting mining organizations to gain competitive advantage. The convergence of geopolitical resource competition and cyber operations is expected to drive growing cyber activity targeting critical mineral supply chains.
Why it matters: Mining operators, energy companies, and infrastructure providers dependent on critical minerals face elevated risk from state-backed and criminal cyber operations seeking to disrupt supply chains or steal strategic advantage; practitioners should implement enhanced monitoring and incident response capabilities for their critical mineral operations and suppliers.
- threat intel
LABScon25 Replay | Are Your Chinese Cameras Spying For You Or On You?
Researchers Marc Rogers and Silas Cutler analyzed ultra-cheap Chinese smart home cameras and video doorbells sold globally under rotating brand names, revealing they share identical hardware platforms, contain hardcoded root passwords, and route user data through servers in China and Hong Kong despite claims of local processing. The devices are distributed through shell companies designed to evade regulatory oversight, with minimal security updates and rapid hardware iterations resembling malware distribution patterns. The investigation demonstrates a widespread, vulnerable Internet of Things (IoT) surface accessible to remote configuration from overseas actors.
Why it matters: Organizations and consumers deploying these devices face data exfiltration and remote compromise risks; security teams should audit smart home camera deployments, restrict network access, and evaluate supply chain transparency as part of IoT governance.
- ransomware
What Cybersecurity Leaders Must Prioritize in 2026
Cybersecurity leaders face evolving threats in 2026, including remote monitoring and management (RMM) tool abuse, artificial intelligence (AI)-powered attacks, ransomware, and identity-based threats. Organizations should reassess their security priorities based on these emerging attack vectors and techniques.
Why it matters: Security leaders and practitioners need to understand which threats pose the greatest near-term risk to their environments and allocate resources accordingly to detect and prevent RMM abuse, AI-enabled attacks, ransomware deployment, and compromised credentials.
- ransomware
I Spent 20 Years at the FBI Chasing These Criminals. Here's What Needs to Change.
Cynthia Kaiser, a former FBI official now at Halcyon, testified to Congress on addressing ransomware threats, advocating for terrorism designations, homicide charges for attackers causing deaths, and enhanced enforcement against those targeting healthcare facilities. Her testimony draws on two decades of FBI experience pursuing cybercriminals and reflects growing concern about escalating ransomware impacts on critical infrastructure.
Why it matters: Healthcare providers and hospital administrators need to monitor regulatory and legal changes; prosecutors and law enforcement should track whether Congress acts on enhanced charging authorities and designations that could reshape ransomware consequences.
- threat intel
Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting
Security researchers discovered an exposed server operating a large-scale exploitation and credential harvesting campaign that utilized AI tools including Claude Code and OpenClaw to orchestrate and refine the attack pipeline. The infrastructure supported the Bissa scanner, a modular platform designed for mass exploitation across multiple victims. The exposure provided detailed visibility into the attacker's AI-assisted workflow and operational techniques.
Why it matters: Organizations and security teams need to understand how adversaries are leveraging AI tools to automate and scale credential harvesting campaigns, and to review their detection and response capabilities for the Bissa scanner and similar modular exploitation platforms.
- ai security
Attackers Didn’t Wait for AI. They Built Workflows Around It.
Threat actors are integrating artificial intelligence into their attack workflows, including fake AI tools, spoofed responses, and automated phishing campaigns. Huntress Labs is monitoring this evolution and its implications for defensive strategies.
Why it matters: Security teams need to understand how AI is being weaponized by attackers to scale phishing, credential harvesting, and social engineering attacks that can bypass traditional detection methods.
- threat intel
Untangling a Linux Incident With an OpenAI Twist (Part 2)
A developer relied on OpenAI's Codex to respond to suspicious Linux activity, resulting in unintended consequences that were later discovered by Huntress SOC analysts. The incident illustrates risks associated with using AI coding assistants to handle security incidents without full understanding of the generated code.
Why it matters: Security teams and developers should understand the limitations and potential risks of AI-generated code in incident response, as blindly executing AI suggestions can introduce new vulnerabilities or worsen an existing incident.
- industry
Wiz at Google Next: Machine-Speed Defense for Any Cloud, Any Platform, Any AI
Wiz announced new security capabilities at Google Cloud Next that extend its AI-APP coverage across AI-generated code, AI and agent studios, and cloud edge environments. The announcement highlights Wiz's expansion of cloud security features designed to protect machine-generated code and AI workloads at scale.
Why it matters: Cloud security practitioners need to evaluate whether Wiz's expanded AI code scanning and agent studio protections address your organization's generative AI and cloud infrastructure risks.
- vulnerabilities
AI Hype vs. Reality: Is AI Really Rewriting the Vulnerability Equation?
Artificial intelligence is improving vulnerability discovery and exploitation speed, but the fundamental challenge for defenders remains unchanged: prioritizing which vulnerabilities to patch first among tens of thousands of disclosures annually. While only a small fraction of disclosed vulnerabilities are actively exploited in the wild, the time window for remediation is narrowing as AI accelerates both attacker and researcher capabilities, creating larger backlogs for organizations relying on manual processes or slow patch cycles.
Why it matters: Vulnerability management teams need to accelerate prioritization and patching workflows immediately, as AI-assisted exploitation is compressing the time-to-weaponization for high-impact flaws and increasing the volume of credible vulnerability reports requiring triage.
- threat intel
Evolution of Chinese-Language Guarantee Telegram Marketplaces
Chinese-language Telegram-based guarantee marketplaces continue to proliferate following Huione Guarantee's 2025 shutdown, with platforms like Dabai Guarantee facilitating coordination among Chinese-speaking criminal syndicates for fraud and cyber campaigns. Dabai Guarantee operates through a large infrastructure of public and private channels, with one notable channel targeting ATM withdrawal and retail fraud schemes in South Korea and Japan. These marketplaces attract criminals by reducing distrust between groups and avoiding the risks associated with traditional dark web marketplaces and their potential exit scams.
Why it matters: Retail businesses, banks, payment providers, insurance companies, and individuals in Asia-Pacific regions are directly exposed to the organized fraud and cyber campaigns coordinated through these guarantee marketplaces; security practitioners should monitor threat actors' use of Telegram as a primary communication platform and track the evolution of these criminal infrastructure models.
- ransomware
Manufacturing Absorbed More Ransomware Claims in March Than the Next Three Verticals Combined
Manufacturing accounted for 208 ransomware claims in March 2026, exceeding the combined total of the next three most-affected sectors. Halcyon's ROC STAR Report analyzed the sector-specific trends in ransomware activity.
Why it matters: Manufacturing leaders and their security teams should prioritize ransomware defenses given the sector's disproportionate targeting, which represents both elevated risk and a concentrated threat landscape requiring immediate response capabilities.
- threat intel
Tradecraft Tuesday Recap: axios npm Supply Chain Compromise
Researchers from Huntress, Wiz, and Aikido Security provided a debrief on the impacts of the axios npm supply chain compromise that occurred weeks prior. The session covered the technical and operational consequences of the attack on the widely-used HTTP client library.
Why it matters: Development teams and security practitioners using axios or npm dependencies need to understand the compromise mechanics and detection methods to assess their exposure and implement mitigations.
- ai security
Closing the Security Gap in the Age of Agentic Coding
Wiz has released Code plugins and the Green Agent tool designed to improve the security of code generated by AI agents operating within integrated development environments. The offerings aim to provide rapid remediation of security issues at the speed of machine-assisted development workflows.
Why it matters: Development teams relying on agentic AI for code generation need visibility and automated remediation controls to prevent insecure code from reaching production, reducing manual security review bottlenecks.
- cloud saas
Mapping Your API Ecosystem: Wiz Expands API Discovery with Apigee
Wiz has expanded its API discovery capabilities to integrate with Apigee, enabling visualization of API architectures including gateways, environments, endpoints, and authorization schemes within the Wiz Security Graph. This integration allows organizations to map their complete API ecosystem across the Apigee platform.
Why it matters: Cloud security teams using Apigee need visibility into their API infrastructure and access controls to identify misconfigurations and unauthorized exposure risks.
- ai security
Emerging Enterprise Security Risks of AI
Agentic AI systems that autonomously execute complex tasks are being rapidly adopted by enterprises, with Gartner predicting 40% of enterprise applications will incorporate task-specific AI agents by end of 2026. These systems amplify existing security weaknesses in software supply chains, identity and access management, and introduce new attack surfaces through prompt manipulation and misconfigurations that can propagate quickly at machine scale. The autonomy and trust requirements of AI agents create inherent tensions with zero-trust security principles, requiring layered controls and human-in-the-loop checkpoints to mitigate risks.
Why it matters: Enterprise security teams must immediately assess and strengthen identity and access controls for AI agents, software supply chain defenses, and prompt injection safeguards, as widespread agent adoption will accelerate both the speed and scope of potential security incidents across interconnected systems.
- cloud saas
Context.ai OAuth Token Compromise
Context.ai OAuth tokens were compromised and used to conduct a supply chain attack through trusted SaaS integrations. The incident exposed a vulnerability in how third-party authentication credentials can be weaponized when breached. Attackers leveraged the legitimate trust relationship to gain unauthorized access across connected systems.
Why it matters: Organizations using Context.ai or its integrated services face potential unauthorized access to their environments; practitioners should immediately audit OAuth token permissions, revoke suspicious tokens, and review SaaS integration activity logs for signs of compromise.
- threat intel
Nightmare-Eclipse Tooling Seen in Real-World Intrusion
Huntress detected active use of Nightmare-Eclipse attack tools (BlueHammer, RedSun, and UnDefend) during a real-world intrusion that began with a compromised FortiGate VPN, followed by reconnaissance and likely data tunneling activity. The incident demonstrates operational deployment of this toolset against production environments.
Why it matters: Security teams managing FortiGate VPN deployments and endpoint defenses need to hunt for signs of Nightmare-Eclipse tooling and the initial FortiGate compromise vectors, as this intrusion shows the toolset is actively weaponized in the wild.
- ransomware
44% and Rising: What the Automotive Industry's Ransomware Problem Tells Us About Where Attacks Are Heading
Ransomware attacks targeting automotive organizations more than doubled in 2025, with such incidents now accounting for 44% of reported ransomware cases. The trend suggests attackers are increasingly focused on the automotive sector as a lucrative and potentially vulnerable target.
Why it matters: Automotive manufacturers, suppliers, and service providers face escalating ransomware risk that could disrupt production, compromise supply chains, and affect operations; practitioners should reassess security posture, backup strategies, and incident response plans specific to this threat landscape.
- cloud saas
Wiz and Databricks: Adding Databricks to the Wiz Security Graph
Wiz, a cloud security platform, has integrated Databricks, a data and AI platform, into its Security Graph to provide extended visibility and security monitoring capabilities. This integration allows organizations using Databricks to gain enhanced threat detection and risk assessment through Wiz's platform.
Why it matters: Organizations running Databricks workloads need to evaluate whether this integration improves their security posture and reduces blind spots in data platform visibility.
- cloud saas
From Code to Pipeline: Wiz Code Now Secures Your Build Environment
Wiz Code has expanded its capabilities to secure build environments, addressing a gap in software supply chain security where threat actors have increasingly targeted build and delivery systems. The tool now protects both the code developers write and the infrastructure that compiles and deploys that code. This addresses a historically overlooked layer of the software development pipeline.
Why it matters: DevSecOps and platform engineering teams need visibility into build pipeline security because attackers are actively exploiting these systems to compromise software at the delivery stage, not just the source code stage.
- vulnerabilities
The Internet Changes Before the Advisory Drops
A GreyNoise study found that malicious targeting activity on the internet typically begins 11 days before vendors publicly disclose vulnerabilities, with the pattern observed across 33 CVEs from 16 vendors. The research showed eight distinct attack surges against a Cisco CVSS 10.0 zero-day compressed from 39 days to just 2 days before disclosure, suggesting attackers gain knowledge of flaws before official advisories.
Why it matters: Security teams need earlier visibility into exploitation activity because attackers are actively probing for vulnerable systems days before patches are available, leaving a critical window where defense is reactive rather than proactive.
- vulnerabilitiesCVE-2026-33634
Lessons from a Supply Chain Security Event: Responding Effectively
Halcyon documented its response to a Trivy supply chain vulnerability (CVE-2026-33634) and extracted seven operational lessons for handling third-party software compromises. The guidance focuses on accelerating detection, containment, and recovery workflows when supply chain incidents occur.
Why it matters: Security teams need practical response playbooks for supply chain incidents affecting their dependencies; this breakdown of real incident handling can reduce mean time to respond (MTTR) when your own tools or libraries are compromised.
- threat intel
Uptick in Bomgar RMM Exploitation
Huntress SOC has observed an increase in incidents where Bomgar remote monitoring and management instances have been compromised. The specific attack vectors and scope of affected organizations are not detailed in the brief report.
Why it matters: Organizations using Bomgar RMM should investigate their instances immediately for signs of compromise, as attackers are actively exploiting this access point to establish persistence and move laterally within networks.
- cloud saas
IaC Inventory: A Unified View Across Code, Deployments, and Cloud
Infrastructure as Code (IaC) inventory tools provide centralized visibility into infrastructure resources created through IaC, their deployment locations, and configuration drift across code, runtime environments, and cloud platforms. As AI workloads proliferate, tracking these resources and detecting drift has become increasingly important for security and operational consistency.
Why it matters: Platform teams and security practitioners need IaC inventory visibility to prevent unauthorized infrastructure changes, detect misconfigurations, and ensure compliance across AI and traditional workloads in hybrid cloud environments.
- cloud saas
Disrupting Attacks on Endpoints | Attack Disruption Engine
Huntress has released an Attack Disruption Engine designed to automatically disrupt threats on endpoints, aiming to close the gap between detection and response in endpoint security. The capability is intended to reduce the impact of endpoint attacks by enabling faster automated action rather than relying solely on detection.
Why it matters: Security teams and managed service providers using endpoint detection and response (EDR) tools should evaluate whether automated disruption capabilities can reduce their mean time to response and limit damage from endpoint compromises.
- cloud saas
Attackers Love Your VPN To-Do List
Huntress SOC data indicates that VPN misconfiguration is a factor in 70% of intrusions they investigate. The article discusses common VPN configuration errors and mitigation steps to reduce this attack surface.
Why it matters: Security teams need to audit and remediate VPN configurations immediately, as misconfigurations account for the majority of successful intrusions and represent a trivial-to-fix entry point for attackers.
- threat intel
4 Essential Integration Workflows for Operationalizing Threat Intelligence Recorded Future
Recorded Future offers threat intelligence integration workflows designed to enhance existing security tools without replacing them. The company recommends assessing organizational maturity across four stages (reactive, proactive, predictive, autonomous) to identify which workflows to prioritize, with core workflows including indicator of compromise enrichment, vulnerability prioritization, and watch list automation. Integration can begin with simple implementations and scale as the organization matures.
Why it matters: Security teams can reduce manual threat intelligence work and accelerate decision-making by integrating threat intelligence into existing tools; practitioners should evaluate their organization's current maturity level to determine which workflows provide the highest ROI for their environment.
- ransomware
Your Cloud Doesn't Protect You from Ransomware
Cloud storage does not inherently protect data from ransomware attacks. Attackers typically compromise endpoints or hijack user sessions, allowing malware to propagate through cloud synchronization services and encrypt files stored there.
Why it matters: Organizations relying on cloud services for ransomware protection may face unexpected data loss if endpoint security or access controls are weak; practitioners should verify that cloud deployments include endpoint hardening, session security, and immutable backups.
- ai security
Securing AI Applications From Inception to Deployment
Wiz has expanded its AI application protection platform to include code-layer analysis for detecting AI-specific security risks from the early development stages through deployment. The solution combines static risk detection with runtime validation and automated remediation through intelligent agents.
Why it matters: Security teams managing AI development pipelines need tools to catch AI-specific vulnerabilities before production; this approach addresses detection and remediation workflow across the development lifecycle.
- breaches incidents
From Bazooka to Fake Nikes
Business impersonation is a unified fraud tactic exploiting trust across payment systems, manifesting in both rising commercial check fraud and AI-powered online shopping scams targeting younger consumers. Fraudsters intercept checks destined for legitimate companies and create shell businesses with similar names to cash them, while simultaneously leveraging social media platforms and brand impersonation to sell counterfeit goods online. Existing controls like Positive Pay and 3D Secure authentication have pushed threat actors to exploit ecosystem gaps in the chain of trust between financial institutions, merchants, card networks, and business registries.
Why it matters: Finance and fraud teams must recognize that business impersonation across payment channels requires cross-functional detection strategies spanning check processing, corporate account onboarding, and merchant verification, as traditional fraud controls now funnel attackers toward identity-based schemes rather than stopping them entirely.
- ransomware
What Mythos Actually Changes About Ransomware (And What It Doesn't)
Mythos represents a genuine advancement in vulnerability discovery through artificial intelligence, but ransomware attackers typically gain access through compromised credentials rather than zero-day exploits. The article examines what aspects of ransomware threats AI tools actually change versus what remains fundamentally unchanged in attacker tactics.
Why it matters: Security teams should understand that investing in vulnerability discovery tools does not address the primary attack vector for ransomware (credential compromise), requiring a balanced approach to both vulnerability management and access control defenses.
- cloud saas
How to Harden GitHub Actions: An Updated Guide
A guide has been updated to provide hardening recommendations for GitHub Actions workflows, drawing lessons from recent attacks such as TeamPCP and Axios. The guidance addresses security practices for protecting build and deployment pipelines from compromise.
Why it matters: Development teams using GitHub Actions need practical hardening steps to prevent supply chain attacks through compromised workflows, reducing risk of malicious code injection into builds and deployments.
- ransomware
Your Supply Chain Breach Is Someone Else's Payday
TeamPCP exploited a single stolen credential to gain write access to software repositories, injecting credential-harvesting malware into LiteLLM and Checkmarx that cascaded across five ecosystems in five days. The compromised code stole API keys, cloud credentials, and access tokens, which were then used to pivot to additional targets. The campaign demonstrates how identity compromise serves as a perimeter breach, enabling attackers to abuse implicit trust in software supply chains without needing to bypass traditional security controls.
Why it matters: Software development and security teams must assume their dependencies and build pipelines are under active compromise; a single unrotated credential can enable attackers to inject malware into widely-distributed packages affecting thousands of downstream organizations, leading to credential theft, operational disruption, and extortion.
- ai security
Securing the AI Edge: Wiz and Cloudflare Integrate for End-to-End AI Protection
Wiz and Cloudflare have integrated their security platforms to provide unified visibility and protection for AI application endpoints and DNS exposure. The integration allows organizations to see which endpoints are protected by Cloudflare and identify gaps that require additional security measures.
Why it matters: Development and security teams need to understand their AI application attack surface and reduce exposure; this integration helps identify unprotected endpoints that could be compromised.
- threat intel
When PUPs Grow Fangs: Dragon Boss Solutions' $10 Supply Chain Risk
Huntress discovered a malware operation leveraging a signed potentially unwanted program (PUP) to deploy antivirus killing tools with SYSTEM level privileges. The attack exploited the supply chain through a compromised update mechanism, allowing threat actors to distribute malware while maintaining legitimate code signatures.
Why it matters: Any organization running this signed PUP faces immediate risk of antivirus bypass and full system compromise; practitioners should audit for this PUP and review signed executable allowlists for similar supply chain weaknesses.
- cloud saas
Introducing Shadow Data Detection: Reduce Cost and Risk Across Your Cloud
A tool or capability for shadow data detection has been introduced to help organizations identify unused, redundant, and inefficient data in cloud environments. The capability aims to reduce storage costs and minimize security exposure by addressing data management inefficiencies.
Why it matters: Cloud security and operations teams need to manage data sprawl and reduce unnecessary storage footprints to lower costs and limit the attack surface from stale or forgotten data repositories.
- research
Primer on GitHub Actions Security - Threat Model, Attacks and Defenses (Part 1/2)
This article provides a first part of a security primer focused on GitHub Actions, covering threat modeling, potential attack vectors, and defensive strategies. The piece aims to help organizations understand the security landscape of GitHub Actions automation and implement appropriate controls.
Why it matters: Development teams using GitHub Actions for CI/CD pipelines need to understand the attack surface and defenses to prevent supply chain compromises and unauthorized code execution in their workflows.
- ransomware
Are Former Black Basta Affiliates Automating Executive Targeting?
Former Black Basta affiliates are conducting an automated social engineering campaign targeting senior executives through email bombing followed by Teams-based help desk impersonation, achieving remote access in under 15 minutes in some cases. The campaign shows a sharp increase in targeting leadership (77% in March 2026 versus 59% earlier) and concentrates on manufacturing and professional services, technical support sectors. This activity represents a significant evolution of Black Basta's original tactics, with 56% of observed Teams phishing activity occurring in 2026 after the group's public decline in early 2025.
Why it matters: Security practitioners must immediately strengthen help desk verification procedures, enforce out-of-band authentication for remote access requests, and run targeted social engineering simulations for senior staff, as former Black Basta operators are rapidly automating attacks that compromise executives within minutes.
- identity access
Your Security Program Was Built for a Threat Landscape That No Longer Exists
Huntress released new data indicating that traditional security programs are inadequate against contemporary identity-based threats. The findings suggest that organizations need to recalibrate their security strategies to address the evolved threat landscape.
Why it matters: Security practitioners managing identity and access controls need to understand where their current programs fall short and adjust defenses against identity threats that now dominate attack chains.
- vulnerabilitiesCVE-2017-7921CVE-2021-22054
March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day
Insikt Group identified 31 high-impact vulnerabilities actively exploited in March 2026, with 29 rated as very critical. The affected products span major vendors including Cisco, Microsoft, Google, ConnectWise, Citrix, and others, with Microsoft and Apple accounting for approximately 32% of the total. Notable findings include the Interlock ransomware group exploiting a Cisco Firewall Management Center zero-day, the continued exploitation of a nine-year-old Hikvision vulnerability, and public proof-of-concept exploits available for 10 of the 31 vulnerabilities.
Why it matters: Security teams must prioritize remediation of these 31 actively exploited vulnerabilities immediately, with special attention to Cisco FMC, Microsoft SQL Server, and products from other affected vendors; legacy systems with known, unpatched vulnerabilities remain high-risk targets and require compensating controls or urgent patching.
- threat intel
Your Staging Site Is More Important than You Think
Staging environments and secondary systems are frequently overlooked in security programs but represent a significant portion of an organization's attack surface. Attackers routinely target these less-monitored systems as entry points to reach production infrastructure and sensitive data.
Why it matters: Security teams and infrastructure owners need to apply equivalent security controls to staging, testing, and development environments as they do to production systems, as compromise of these systems can lead to lateral movement into critical assets.
- ai security
Claude Mythos: Preparing for a World Where AI Finds and Exploits Vulnerabilities Faster Than Ever
Anthropic has developed an AI model capable of autonomously discovering zero-day vulnerabilities and creating working exploits. The capability is currently restricted to authorized users, but security professionals are advised to strengthen incident response procedures and reduce attack surface exposure in preparation for this emerging threat.
Why it matters: Security teams need to begin updating vulnerability management and incident response plans today because AI-driven zero-day discovery and exploit development will outpace traditional patching cycles and require faster detection and remediation protocols.
- identity access
VIP Credential Monitoring Blog
Recorded Future has launched VIP Credential Monitoring to track compromised credentials belonging to high-value targets like executives and system administrators across work and personal accounts. According to the 2025 Data Breach Investigations Report, credential abuse is the leading initial access vector, with attackers able to identify which systems credentials unlock through infostealer malware logs and prioritizing accounts with broad organizational access. The tool continuously scans dark web forums, malware logs, and breach databases to alert security teams within 24 hours when VIP credentials surface, reducing the window between compromise and detection.
Why it matters: Security teams need faster visibility into compromised credentials for high-privileged employees, as a single stolen executive credential can lead to lateral movement and organizational breaches affecting millions of individuals, and most stolen credentials are weaponized within 48 hours of compromise.
- threat intel
Just 21 IP Addresses Are Now Behind Nearly Half of All RDP Scanning on the Internet
GreyNoise researchers identified that approximately 21 IP addresses account for nearly half of all Remote Desktop Protocol (RDP) scanning activity on the internet. The analysis reveals concentrated infrastructure patterns and rapid traffic shifts that create detection challenges for defenders. The findings highlight the concentrated nature of reconnaissance campaigns targeting RDP services globally.
Why it matters: Security teams need to understand that RDP reconnaissance is highly concentrated among a small set of IPs, enabling more efficient firewall rules, threat hunting, and monitoring prioritization to block or flag these known scanning sources.
- ai security
What a Fake Claude Download Says About Security Today
Attackers are distributing fake versions of Claude and other AI tools to compromise organizations adopting these platforms. The article examines how these threats infiltrate environments and what security controls can prevent successful attacks.
Why it matters: All organizations using Claude or similar AI assistants face immediate risk from supply chain impersonation attacks; practitioners should verify software sources and implement controls to block unauthorized tool distributions.
- threat intel
The 60ms Window: How Event 5156 Solves the ADWS Attribution Problem
A technique leverages Windows Event 5156 within a 60 to 80 millisecond timing window to correlate Active Directory Web Service (ADWS) queries logged in Event 1644 with their actual source IP addresses, avoiding the limitation of localhost obfuscation. This method uses data already present in Security Information and Event Management (SIEM) systems to enable proper attribution of ADWS activity.
Why it matters: Security operations and incident response teams need accurate attribution of directory service queries to detect reconnaissance and lateral movement, and this approach provides a practical way to identify true sources of ADWS activity using existing Windows event logs.
- cloud saas
Cloud Threats Retrospective 2026: What AI Changed (and What It Didn’t)
A retrospective analysis examines how cloud security threats evolved during 2025, drawing from public incidents, cloud telemetry data, and investigations to assess the impact of artificial intelligence on cloud risk landscapes. The report provides insights into which cloud threat patterns shifted due to AI capabilities and which remained consistent with prior years.
Why it matters: Cloud practitioners need to understand 2025 threat trends and AI's actual versus overstated impact on their infrastructure, misconfigurations, and incident response priorities.
- cloud saas
Bringing Security Visibility to Vercel with Wiz
Wiz has introduced security visibility capabilities for Vercel, a platform used for deploying and hosting web applications. The integration provides developers and security teams with a unified view of application risks in real time.
Why it matters: Development and security teams using Vercel need visibility into application risks across their deployments, and this integration helps bridge the gap between development velocity and security oversight.
- ransomware
Third-Party Risk Is an Intelligence Operation. It's Time We Treated It Like One.
The cybersecurity industry has traditionally approached third-party risk management as a compliance checklist, but this model is outdated given the scale of modern supply chains and sophistication of threat actors. Organizations now require integrated threat intelligence combined with security ratings to move beyond reactive incident response and enable continuous, proactive monitoring of vendor risk. Effective third-party risk management must function as an intelligence operation that combines hygiene baselines with real-time threat data to identify and prioritize actual exposures.
Why it matters: Enterprise risk and security teams need to transition from quarterly vendor assessments to continuous intelligence-driven monitoring, as threat actors actively exploit supply chain vulnerabilities as entry points to larger targets and often compromise vendors before discovery.
- threat intel
The ADWS Architecture That Hides PowerShell AD Enumeration
A security team discovered that threat actors successfully enumerated an entire Active Directory environment using Get-ADComputer without triggering any detections. The underlying issue stemmed from an architectural gap in how PowerShell communicates with Active Directory rather than sophisticated evasion techniques by the attacker.
Why it matters: Organizations relying on detection rules for PowerShell AD enumeration may have blind spots in their monitoring; practitioners should audit their ADWS (Active Directory Web Services) architecture and PowerShell logging to identify similar gaps in AD reconnaissance detection.
- ransomware
Why the Stryker Attack Still Matters. And Five Steps You Can Take Today
The Stryker incident demonstrated that attackers can weaponize mobile device management (MDM) platforms to remotely wipe devices, creating a more difficult and permanent threat than traditional ransomware. Organizations can reduce this exposure through specific steps to secure management platforms and prevent attackers from turning security infrastructure into an attack vector.
Why it matters: Healthcare organizations and any enterprise relying on MDM for device management face the risk of complete device loss if management platforms are compromised, making this a critical control to harden today.
- government policy
Understanding and Anticipating Venezuelan Government Actions
A geopolitical analysis examines Venezuelan Acting President Delcy Rodríguez's likely policy priorities following a January 2026 US operation that captured former President Nicolás Maduro. Rodríguez is expected to balance cooperation with Washington to secure sanctions relief and economic stabilization against internal threats from rival factions within the ruling party and security apparatus. Her near-term focus will likely be on maintaining party rule and coalition stability rather than ideological maximalism.
Why it matters: Organizations with Venezuelan operations or investments should monitor Rodríguez and rival officials' statements and actions to anticipate regime instability, policy shifts toward US engagement, or internal power struggles that could disrupt business continuity and geopolitical risk assessments.
- ransomware
Decoding NightSpire: Ransomware IOCs Aren't Set in Stone
A recent incident involving NightSpire ransomware demonstrates how its ransomware-as-a-service (RaaS) operational model affects incident scope and recovery complexity. The analysis highlights that the structure and flexibility of RaaS offerings influence how organizations must approach containment and remediation strategies.
Why it matters: Security teams investigating NightSpire incidents need to understand that indicators of compromise (IOCs) may vary based on the RaaS deployment model, which could affect containment scope and recovery timelines.
- threat intel
Introducing C2 Detection: Know When Your Edge Devices Are Calling Home to Attackers
GreyNoise has launched a new C2 Detection intelligence module designed to identify compromised devices in an environment by detecting command and control (C2) communications. The module provides high-confidence signals to alert organizations when edge devices are establishing connections to attacker infrastructure.
Why it matters: Security teams and defenders need early detection capabilities to identify compromised devices and stop attacker command and control communications before data exfiltration or lateral movement occurs.
- threat intel
Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign
A new supply chain campaign exploiting the pull_request_target GitHub workflow has been discovered, attributed to a single actor operating six compromised accounts. The campaign represents a continuation of similar AI-powered attacks, with the attacker active for three weeks before detection. This demonstrates an ongoing threat pattern targeting software development infrastructure.
Why it matters: Software developers and organizations maintaining open source projects or using GitHub workflows are at risk of code injection and supply chain compromise; teams should audit pull request workflows and implement approval controls for pull_request_target triggers.
- industry
Day in the Life: Product Manager at Recorded Future
Recorded Future, a threat intelligence provider, featured a profile of Kyle Kohler, a Senior Product Manager for Integrations. Kohler describes the role as multifaceted, involving strategic initiative planning, translating customer feedback into product improvements, and enabling team collaboration across a global organization covering cyber, geopolitical, and payment fraud intelligence domains.
Why it matters: This is an industry profile with no direct security implications for practitioners; it offers career insight into threat intelligence platform development rather than actionable security guidance.
- vulnerabilitiesCVE-2026-2699CVE-2026-2701
You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)
Researchers discovered and chained two vulnerabilities in Progress ShareFile's Storage Zone Controller (an on-premises gateway managing file transfers) to achieve unauthenticated remote code execution. The flaws, CVE-2026-2699 (authentication bypass) and CVE-2026-2701 (remote code execution), affected version 5.12.3 on the ASP.NET branch and were patched in version 5.12.4 released March 10, 2026. Approximately 30,000 Storage Zone Controller instances are exposed on the internet.
Why it matters: Organizations using ShareFile Storage Zone Controller (on-premises deployments for data sovereignty or regulatory reasons) must upgrade to version 5.12.4 immediately, as the vulnerability allows complete system compromise without authentication and file transfer appliances remain high-value targets for ransomware and APT groups.
- threat intel
Latin America and the Caribbean Cybercrime Landscape
A 2025 report from Insikt Group analyzes cybercrime trends across Latin America and the Caribbean, finding that financially motivated threat actors primarily use Telegram and dark web forums to conduct ransomware attacks, phishing campaigns, and malware distribution. Brazil, Mexico, and Argentina faced the most targeting, with healthcare, finance, and government sectors particularly vulnerable due to legacy systems and operational urgency. The region experienced 452 ransomware incidents in 2025, with banking trojans and infostealers like LummaC2 and Vidar actively exploited against financial institutions.
Why it matters: Security practitioners managing infrastructure, cloud deployments, or financial systems in LAC countries should prioritize implementing strong access controls, multi-factor authentication, and endpoint security given the documented prevalence of ransomware, banking trojans, and social engineering attacks targeting their region's critical sectors.
- threat intel
The Invisible Army: Why IP Reputation Fails Against the Rotation Economy
Attackers increasingly route malicious traffic through residential internet connections that rotate quickly, making IP reputation systems ineffective. GreyNoise analysis of 4 billion sessions found that 39% of IPs targeting edge infrastructure originate from residential address space, with 78% disappearing after just 1-2 sessions before reputation feeds can identify them. Detection strategies must shift from source-based assessment to behavioral analysis of the traffic itself.
Why it matters: Security teams relying on IP reputation for threat detection face a critical gap: attackers are circumventing traditional defenses through fast-rotating residential proxies, requiring immediate adoption of behavior-based detection methods.
- ai security
OpenClaw, Rogue Agents, and Application Hygiene
OpenClaw AI agents can expose identity and data risks when deployed with overly broad cloud permissions, creating a potential attack surface for adversaries. Practitioners should identify and secure these applications to prevent unauthorized access to sensitive resources.
Why it matters: DevOps, cloud, and security teams need to audit AI agent deployments for excessive permissions today, as misconfigurations enable attackers to pivot from compromised agents into cloud environments and exfiltrate data.
- identity access
The Three-Finger Test
The article discusses the limitations of the 'three-finger test,' a security practice for identity verification, and emphasizes the need for more robust security processes to defend against identity-based attacks and social engineering tactics that evolve with advances in artificial intelligence.
Why it matters: Security practitioners should understand that traditional verification methods are becoming insufficient against modern threats, requiring updated identity and access control strategies to reduce organizational risk.
- ransomware
When a Security Gap Costs Lives: How Healthcare CIOs Found Ransomware Protection Worth Sleeping Over
Healthcare organizations experienced over 290 ransomware attacks in 2025, with average recovery costs reaching 3.9 million dollars. Security leaders at healthcare providers attribute improved resilience to purpose-built ransomware protection solutions deployed across their environments.
Why it matters: Healthcare CIOs and security teams must prioritize ransomware defense given the persistent attack volume targeting the sector and the substantial financial impact of breaches on operational budgets and patient care continuity.
- ransomware
Manufacturing Is the Most Targeted Sector in Ransomware. By a Wide Margin.
Manufacturing faced the highest volume of ransomware attacks across all sectors in 2025, representing a 61% increase compared to 2024. Three ransomware groups, Akira, Qilin, and Play, accounted for the majority of incidents targeting the sector.
Why it matters: Manufacturing companies and their suppliers face elevated operational risk from production shutdowns and supply chain disruption; practitioners should review ransomware incident response plans and backup restoration procedures given the targeting intensity.
- breaches incidents
Axios NPM Distribution Compromised in Supply Chain Attack
A maintainer account for the popular axios library was compromised, resulting in malicious packages published to the npm registry. The incident affected multiple environments through the compromised supply chain dependency.
Why it matters: Development teams using axios need to immediately audit their dependency versions and runtime environments to detect and remediate potential compromises, as the malicious packages could have executed arbitrary code during installation or runtime.
- threat intel
Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild
TeamPCP is using credentials and secrets stolen from recent supply chain attacks to gain unauthorized access to cloud environments. The group is exploiting these compromised credentials post-breach to establish persistence and lateral movement within cloud infrastructure.
Why it matters: Cloud infrastructure teams and incident responders need to understand how supply chain compromises create downstream cloud threats: you should audit cloud access logs for suspicious activities from recently affected vendors and review credential rotation policies.
- ransomware
How Halcyon Helps MSSP Partners Deliver Stronger Ransomware Defense
Halcyon offers a ransomware defense platform designed specifically for managed security service providers (MSSPs) to enhance protection and recovery capabilities for their customers.
Why it matters: MSSPs need effective ransomware tools to strengthen their service offerings and reduce client exposure to encryption attacks and data theft.
- ransomware
Beyond Black Friday: Ransomware Defenses for Holiday Retail Operations
The Halcyon Ransomware Research Center has released threat intelligence indicating that retailers face elevated ransomware risks during the holiday season compared to other times of year.
Why it matters: Retail organizations should review their ransomware defenses immediately, as the combination of increased transaction volume, staffing changes, and seasonal pressure creates a higher-risk attack window.
- ransomware
Defensible by Design: Ransomware and Cybersecurity in 2026
The article discusses how 2026 presents both escalating pressure for chief information security officers and an opportunity to fundamentally rebuild organizational resilience against ransomware and cybersecurity threats.
Why it matters: Security leaders need to evaluate their current resilience strategies now, as 2026 will require foundational changes to defense approaches to address evolving ransomware and cyber risks.
- ransomware
Cognitive Dissonance in Cybersecurity
Cognitive dissonance in cybersecurity programs creates misalignment between what organizations believe about their security posture and their actual defenses, potentially creating exploitable gaps. The article discusses how chief information security officers (CISOs) can identify and address this disconnect to strengthen security programs.
Why it matters: CISOs and security leaders should examine whether their organization's stated security priorities align with actual budget allocation, training, and incident response capabilities, as gaps between belief and reality can be exploited by threat actors.
- industry
Leading with Purpose
The article discusses how cybersecurity leaders can develop influence and organizational leadership capabilities beyond technical expertise. The focus is on risk communication and building confidence in leadership roles.
Why it matters: Practitioners seeking advancement should understand that moving into leadership requires both technical credibility and soft skills in risk articulation and organizational influence to drive security decisions effectively.
- ransomware
The Iceberg Effect
A report highlights the significant gap between ransom payments and total incident costs in ransomware attacks. While average ransoms reach $1 million and recoveries average $2.5 million, the full organizational impact ranges from $25 million to $250 million when accounting for hidden expenses.
Why it matters: Organizations underestimating total ransomware costs may underfund incident response, business continuity, and prevention programs, leaving them exposed to greater financial and operational harm.
- industry
The Corporate Brand, Culture, and the CISO: Why Understanding the Business Is Non-Negotiable
A chief information security officer (CISO) perspective on the importance of aligning security programs with corporate brand and culture. The article argues that security leaders who fail to understand and integrate with business objectives struggle to gain organizational trust, funding, and stakeholder engagement. Business alignment is positioned as essential rather than optional for security program success.
Why it matters: CISOs and security leaders need to recognize that internal buy-in and resource allocation depend on demonstrating how security supports business objectives, making cultural and brand alignment a practical prerequisite for effective security governance.
- industry
The Wiz Blue Agent, now Generally Available
The Wiz Blue Agent tool is now generally available for security operations teams to use in threat investigation workflows. This represents a product release from Wiz, expanding their security investigation capabilities to a broader audience.
Why it matters: Security operations teams should evaluate this tool if they are looking to accelerate threat investigation processes and improve SecOps efficiency.
- ransomware
Analyst Report: EDR Alone Won't Stop Ransomware. Halcyon Will.
An analyst report from Omdia concludes that endpoint detection and response (EDR) tools alone are insufficient to prevent ransomware attacks, and presents Halcyon's platform as a solution that detected and reversed attacks missed by traditional tools.
Why it matters: Security teams relying solely on EDR should evaluate whether supplementary ransomware-specific solutions are needed to address detection and isolation gaps in their current defenses.
- cloud saas
Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security
Wiz has achieved Microsoft's Certified Software designation, indicating alignment with Microsoft's security standards for Azure environments. This certification signals that Wiz's cloud security platform meets Microsoft's vetting criteria for customers operating in Azure infrastructure.
Why it matters: Azure customers evaluating cloud security tools can use this certification as a baseline trust signal when assessing Wiz for their cloud workloads, though independent security evaluation remains essential.
- cloud saas
Introducing the Green Agent: AI-Powered Remediation for the Cloud
A new AI-powered tool called Green Agent automates cloud security remediation by investigating vulnerabilities, assigning remediation tasks, and providing guidance to resolve critical issues. The solution aims to help organizations reduce the time and effort required to address cloud security vulnerabilities.
Why it matters: Cloud security teams need to understand whether this tool integrates with their existing workflows and threat models, as adoption of AI-driven remediation can significantly change vulnerability management processes and timelines.
- cloud saas
Introducing Wiz Workflows: Your path to building a self healing cloud
Wiz has introduced Workflows, a feature enabling orchestration of customizable workflows with agents for discovery and response operations in cloud environments. The capability aims to support end-to-end automated processes for cloud security management.
Why it matters: Cloud security practitioners should evaluate whether Wiz Workflows can reduce manual incident response time and improve detection coverage in their existing cloud security tooling.
- threat intel
That “Friendly” Prompt is ClickFix
ClickFix is a social engineering scam that uses deceptive prompts to trick users into executing malicious code on their systems. The threat combines psychological manipulation with technical exploitation to compromise endpoints through user action rather than traditional vulnerabilities.
Why it matters: Practitioners need to understand this social engineering vector to educate users and detect suspicious prompts requesting code execution, as it bypasses traditional perimeter defenses by relying on user compliance.
- threat intel
Ghost Fleet: Half of All New Scanning IPs Last Week Geolocated to Hong Kong — Nearly None Completed a Connection
GreyNoise observed that 242,666 new scanning IP addresses geolocated to Hong Kong emerged in a single week, with 99.7% failing to establish TCP connections. This pattern suggests reconnaissance activity or scanning infrastructure that was not attempting actual exploitation. The finding highlights unusual scanning behavior concentrated in a specific geographic region.
Why it matters: Security teams need to understand whether this Hong Kong-based scanning activity represents a new threat campaign, reconnaissance for future attacks, or scanning infrastructure that may eventually be weaponized; identifying the source and intent helps prioritize defensive responses.
- threat intel
Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign
TeamPCP compromised LiteLLM, a popular open-source library, by releasing trojanized versions 1.82.7 and 1.82.8 that used Python's .pth file mechanism for persistence. The malware exfiltrated cloud credentials, CI/CD secrets, and API keys to attacker-controlled infrastructure. This represents an ongoing pattern of TeamPCP targeting open-source software supply chains.
Why it matters: Developers using LiteLLM in those versions are at risk of credential compromise affecting cloud accounts, deployment pipelines, and API access; immediate upgrade to patched versions and credential rotation are critical.
- identity access
ITDR for Google Workspace | Huntress Managed ITDR
Huntress has extended its Identity Threat Detection and Response (ITDR) capabilities to Google Workspace, offering protection against business email compromise (BEC), inbox rule abuse, and account takeover attacks. The service includes 24/7 security operations center (SOC) monitoring and incident response.
Why it matters: Organizations using Google Workspace need native threat detection for email-based attacks and compromised credentials; Huntress ITDR reduces response time and attack surface for identity-focused threats.
- threat intel
Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure
Threat actors are exploiting Railway, a Platform-as-a-Service (PaaS) offering, as infrastructure to replay stolen Microsoft 365 tokens in attacks targeting hundreds of organizations. The campaign combines adversary-in-the-middle (AiTM) tactics and device code phishing to compromise credentials across a large number of Microsoft 365 tenants and managed service providers (MSPs).
Why it matters: Organizations using Microsoft 365 and MSPs face direct risk from token replay attacks; practitioners should review authentication logs for suspicious token usage and consider disabling legacy authentication and device code flows where possible.
KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack
Checkmarx's KICS GitHub Action was compromised during a supply chain attack by TeamPCP on March 23, with attackers hijacking 35 tags over approximately four hours. The incident appears to involve credential theft and highlights the vulnerability of popular development tools in continuous integration and continuous deployment (CI/CD) pipelines. Organizations using this GitHub Action should audit their workflows for malicious activity and take corrective measures.
Why it matters: Development teams relying on KICS GitHub Action for infrastructure as code scanning may have exposed credentials or injected malicious code into their CI/CD pipelines; immediate audit and remediation of affected workflows is essential.
- industry
Introducing the Wiz Red Agent- AI-Powered Attacker
Wiz has introduced Red Agent, an AI-powered tool designed to identify exploitable security risks across an organization's attack surface through continuous automated assessment. The tool uses context awareness to discover complex vulnerabilities that might span multiple systems or configurations.
Why it matters: Security teams and cloud practitioners should evaluate whether this AI-driven attack simulation capability can enhance their vulnerability management and penetration testing programs to identify gaps before adversaries do.
- threat intel
A _declassified Look Inside the Dark Economy of Cybercrime
A report examines the operational structure and economic models of cybercriminal organizations, including how they organize scam centers and attract customers. The analysis covers the role of generative AI (AI) in automating and expanding the scale of criminal operations.
Why it matters: Security practitioners need to understand cybercrime business models and AI-enabled attack scaling to anticipate threat evolution and inform defensive strategies.
- ransomware
7 Key Manufacturing Cybersecurity Trends for 2026 | Huntress
Huntress outlines seven cybersecurity trends expected in manufacturing for 2026, including ransomware threats, operational technology (OT) takeovers, and production-level risks. The article provides guidance on securing manufacturing facilities against these emerging threats.
Why it matters: Manufacturing and OT environments face escalating cyber risks that can halt production and compromise safety; practitioners need to understand 2026 threat patterns and implement defenses for industrial control systems.
- cloud saas
Introducing Wiz Agents & Workflows: Security at the Speed of AI
Wiz has introduced an AI-driven security operating model built on AI agents and workflows designed to streamline security operations and reduce delays in response processes. The solution aims to help security teams operate more efficiently by automating routine tasks and decision-making within their workflows.
Why it matters: Cloud and SaaS security practitioners should evaluate whether AI-powered automation can improve their mean time to response and reduce manual operational overhead in their current security workflows.
- ai security
Introducing Wiz AI Application Protection Platform (AI-APP)
Wiz announced an AI Application Protection Platform (AI-APP) designed to provide security coverage across multiple layers of AI application environments, including infrastructure, data, access, models, agents, and applications from development through runtime. The platform aims to address security needs across different deployment environments.
Why it matters: Security practitioners managing AI applications need visibility into whether this tool adequately covers their deployment environments and integrates with existing toolchains.
- ai security
AI Runtime Threat Detection: From Input to Real-World Impact
This article discusses approaches for detecting threats and malicious behavior within artificial intelligence systems, spanning from input validation through model execution to cloud deployment. The focus is on comprehensive threat detection that accounts for the full lifecycle of AI workload deployment and operation.
Why it matters: Security practitioners need to understand AI threat detection across the entire stack to protect against evolving attacks on machine learning systems and prevent compromise of AI-driven applications in production environments.
- ransomware
We Asked 100 Security Leaders About Ransomware. Their Answers Surprised Us.
A survey of 100 Chief Information Security Officers found that while many express confidence in their ransomware defenses, actual success rates remain low and endpoint detection and response (EDR) tool effectiveness is declining. The study indicates that artificial intelligence (AI) capabilities are increasingly favoring attackers over defenders.
Why it matters: Security leaders need to reassess ransomware preparedness, EDR deployment effectiveness, and AI-driven attack trends to ensure their organizations' defenses match their confidence levels and address the shifting threat landscape.
- breaches incidents
Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack
Threat actors injected credential-stealing malware into Aqua Security's Trivy vulnerability scanner and related GitHub Actions on March 19, 2026. The attack, attributed to a group called TeamPCP, compromised the supply chain for a widely used open-source security tool. Organizations using Trivy need to audit for indicators of compromise and review credential exposure.
Why it matters: Security teams relying on Trivy for vulnerability scanning face immediate risk of credential theft and potential lateral movement; practitioners should check deployment logs, rotate credentials, and verify scanner integrity.
- vulnerabilitiesCVE-2026-32746
A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE)
A 32-year-old pre-authentication remote code execution vulnerability (CVE-2026-32746) was discovered in GNU inetutils Telnetd by the DREAM Security Research Team. The BSS-based buffer overflow exists in the LINEMODE SLC negotiation handler and affects multiple operating systems and distributions that derive from the same codebase, including Ubuntu, Debian, FreeBSD, NetBSD, and others. Despite the severity and wide impact, the vulnerability had received minimal public analysis at the time of reporting.
Why it matters: Organizations running Telnet on production systems, industrial control devices, or legacy infrastructure are at immediate risk of pre-authentication compromise. Practitioners should audit systems for Telnet services and prioritize patching or disabling the service, as the vulnerability requires no authentication and affects dozens of distributions.
- threat intel
How a Tax Search Leads to Kernel-Mode AV/EDR Kill
Huntress identified a malvertising campaign themed around tax season that uses Google Ads and cloaking techniques to distribute rogue ScreenConnect remote access software. The attackers employ an undocumented Huawei driver to disable antivirus and endpoint detection and response (EDR) security tools at the kernel level.
Why it matters: Organizations and employees using legitimate search tools are at risk of landing on malicious tax-themed ads that install remote access and disable security protections, exposing systems to further compromise. Security teams need to monitor for compromised endpoints running unauthorized ScreenConnect instances and watch for exploitation of kernel-level driver vulnerabilities.
- industry
Meet Cody Browning, a Beekeeper in Cybersecurity
Cody Browning is a Huntress Reseller Sales Manager whose career in cybersecurity was inspired by his grandmother falling victim to a vishing scam. The story highlights how this personal experience drives his work in promoting human-centered cybersecurity practices within the organization.
Why it matters: Security practitioners should understand the motivation behind vendor staff and the importance of human-focused threat awareness, as personal experiences with social engineering often inform product development and customer support priorities.
- ai security
Building an Adversarial Consensus Engine | Multi-Agent LLMs for Automated Malware Analysis
Researchers developed a multi-agent LLM system for malware analysis that uses multiple reverse engineering tools (radare2, Ghidra, Binary Ninja, IDA Pro) in a serial verification pipeline to reduce false positives from individual tool artifacts. Each agent verifies or rejects claims from previous agents before the report is finalized, addressing the problem that single-tool analysis produces unreliable results contaminated by decompiler quirks and hallucinations. The system runs on Anthropic's Claude models and uses an in-memory Shared Context document to pass findings between agents.
Why it matters: Security teams performing malware analysis need to understand that LLM-assisted static analysis without consensus mechanisms produces unreliable reports with false capabilities and misidentified functions, and this multi-agent approach offers a production-tested alternative that reduces analyst time while improving accuracy.
- threat intel
Something Phishy in the /tmp Folder
Huntress detected and contained a MacSync infostealer malware attack on a macOS device that targeted credentials, browser cookies, and cryptocurrency wallets. The threat was stopped before exfiltration occurred. The incident demonstrates the need for vigilant endpoint detection on macOS systems.
Why it matters: macOS users and their security teams need to understand that infostealers like MacSync pose a direct risk to credential and crypto asset theft, requiring rapid detection and containment capabilities.
- vulnerabilitiesCVE-2025-24813CVE-2025-71257
The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)
watchTowr Labs discovered four chained vulnerabilities in BMC FootPrints ITSM solution, including authentication bypass, server-side request forgery, and deserialization flaws that enable pre-authenticated remote code execution. The vulnerabilities affect BMC FootPrints versions 20.20.02 through 20.24.01.001, and disclosure to BMC began in June 2025. ITSM solutions like FootPrints are high-value targets because they manage IT inventory, configuration data, and incident information that organized threat actors leverage for ransomware campaigns.
Why it matters: Organizations running BMC FootPrints should immediately assess their deployment versions and apply patches when available, as ITSM solutions are frequently targeted by ransomware operators for lateral movement and reconnaissance due to their access to sensitive infrastructure data.
- ransomware
Attackers Know When Your Team Goes Home: February 2026 ROC STAR Report
Halcyon's Ransomware Operations Center (ROC) publishes monthly threat intelligence through its ROC STAR Report, which tracks operational patterns and intelligence related to ransomware threats. The February 2026 report provides current threat data and analysis relevant to security practitioners.
Why it matters: Security teams should review current ransomware threat patterns and operational tactics to inform detection and response strategies for their organization.
- industry
Huntress Expands Into Proactive Security Posture Management
Huntress has launched new managed services for endpoint security posture management (ESPM) and identity security posture management (ISPM), designed to proactively address security gaps before attackers can exploit them. The offering represents an expansion of the company's capabilities beyond reactive threat detection into preventive security hardening.
Why it matters: Security teams and MSPs using Huntress should evaluate whether these new proactive services reduce their mean time to remediation and align with their shift-left security strategy.
- ransomware
Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat
LeakNet ransomware operators are expanding their attack capabilities by adopting ClickFix social engineering lures hosted on compromised websites and deploying a Deno-based in-memory loader for command-and-control delivery. The group maintains a consistent post-exploitation sequence across incidents, including jli.dll side-loading into Java, PsExec lateral movement, and S3 bucket payload staging. This shift toward self-directed campaigns reduces LeakNet's reliance on initial access brokers and accelerates their timeline from initial compromise to encryption.
Why it matters: Organizations must implement layered defenses against LeakNet's evolving tactics: block newly registered domains, restrict Win-R access, limit PsExec to authorized administrators, and monitor for suspicious behavior post-compromise, as the group is scaling operations and moving away from detectable initial access broker transactions.
- threat intel
Phishing Techniques Spotted: Email Examples & Red Flags
Security researchers identified five prevalent phishing techniques currently in circulation, including fake UPS shipping notifications and PayPal-themed callback phishing attacks. These methods exploit common user interactions around package tracking and payment services to deceive recipients into revealing credentials or installing malware.
Why it matters: Organizations and employees need to recognize these specific phishing patterns to avoid credential compromise and malware infections that directly impact their systems and data.
- ransomware
Iran’s Next Move: Ransomware, and the Attack You Can't Pay Your Way Out Of
Iranian cyber operations increasingly employ ransomware tactics, with a significant complication: sanctions regulations may prohibit organizations from paying ransoms, eliminating a traditional recovery path. Security teams face distinct preparedness challenges when adversaries operate under U.S. and international sanctions regimes.
Why it matters: Organizations targeted by Iranian threat actors must understand sanctions restrictions on ransom payments and prioritize non-payment recovery strategies (backups, incident response, law enforcement coordination) to avoid legal and operational consequences.
- ransomware
3-2-1 Backup Rule: What It Is + How To Implement | Huntress
The 3-2-1 backup rule is a data protection strategy that involves maintaining three copies of data, stored on two different media types, with one copy kept offsite. This approach is designed to protect against ransomware attacks and data loss by ensuring redundancy and geographic distribution of backups.
Why it matters: Organizations of all sizes need to implement robust backup strategies to recover from ransomware attacks and maintain business continuity; practitioners should assess whether their current backup infrastructure follows the 3-2-1 principle and address any gaps.
- cloud saas
Twenty Years of Cloud Security Research
An analysis examines two decades of cloud security research, dividing the period into distinct eras marked by key milestones that drove transitions between them. The research tracks the evolution of security approaches and challenges as cloud technologies matured.
Why it matters: Security practitioners benefit from understanding historical trends and pivotal moments in cloud security to inform current architectural decisions and anticipate emerging challenges.
- ransomware
How the Huntress SOC Stopped a VPN-Based Ransomware Attack
Huntress Security Operations Center (SOC) detected and prevented a ransomware attack that exploited an unsecured VPN connection. The incident highlights the importance of comprehensive security practices beyond software solutions alone.
Why it matters: Organizations relying on VPN access are at risk from ransomware operators targeting weak remote access controls; practitioners should review VPN hardening, access controls, and detection capabilities today.
- threat intel
Data Exfiltration and Threat Actor Infrastructure Exposed
Threat actors occasionally make operational mistakes that inadvertently reveal information about their identities, tactics, or infrastructure. These errors can provide security researchers and defenders with actionable intelligence for tracking and disrupting malicious operations.
Why it matters: Security teams should monitor for and document threat actor mistakes and exposed infrastructure, as these findings can inform incident response, attribution efforts, and protective measures against known adversaries.
- threat intel
How Threat Actors Abuse Remote Management Tools | Huntress
Threat actors are increasingly abusing remote monitoring and management (RMM) tools to gain initial access, maintain persistence, and evade detection by daisy chaining multiple RMM software instances. This technique represents a significant tactical shift in how attackers leverage legitimate administrative tools for malicious purposes.
Why it matters: Organizations using RMM tools for legitimate management need to understand how attackers exploit these same tools to move laterally and hide in plain sight, requiring immediate attention to RMM access controls, logging, and monitoring.
- industry
C'est officiel : Wiz rejoint Google
Google has completed its acquisition of Wiz, the cloud security company. The deal marks Google's significant expansion into cloud and AI security capabilities.
Why it matters: Cloud infrastructure teams and security buyers should monitor how Google integrates Wiz's technology into its security portfolio and what changes this brings to existing Wiz customer agreements and roadmaps.
- ai security
Understanding and Reducing AI Risk in Modern Applications
The article discusses approaches to identifying and mitigating artificial intelligence risks in modern software applications by analyzing signals across different layers of AI systems. It emphasizes the importance of understanding context when evaluating threats to AI deployments.
Why it matters: Security practitioners need practical methods to assess AI risks in their applications, as poorly understood AI threats can leave systems vulnerable to misuse, data poisoning, or model manipulation.
- threat intel
GreyNoise Integrates with Google Security Operations to Enhance Detection and Response Capabilities
GreyNoise has integrated with Google Security Operations to provide standardized indicator ingestion, pre-built dashboards, YARA-L detection rules, saved searches, response actions, webhook support, and ready-to-deploy playbooks. The integration enables security teams to streamline detection and response workflows using GreyNoise's threat intelligence within Google's platform.
Why it matters: Security operations teams using Google Security Operations can now more efficiently ingest and act on GreyNoise intelligence for faster threat detection and response.
- identity access
36 Must-Know Password Statistics for 2026 | Huntress
Huntress compiled password statistics for 2026 highlighting prevalence of poor password hygiene practices. The report provides insights into common credential management weaknesses and recommends protective measures for organizations and users.
Why it matters: Security practitioners need current data on password weaknesses to prioritize identity and access management controls and education efforts that address the most common attack vectors.
- identity access
Top 10 Worst Places to Store a Password | Huntress
Huntress compiled a list of the top ten worst practices for password storage based on feedback from IT and information security professionals. The article identifies common insecure methods that organizations and individuals should avoid.
Why it matters: Security practitioners should review this guidance to understand prevalent password storage risks and educate their teams and users on secure credential management practices.
- threat intel
A Threat Actor Abuses Another Free Trial
A threat actor exploited SolarWinds Web Help Desk and abused an Elastic Cloud SIEM free trial to exfiltrate data and conduct reconnaissance on targeted infrastructure. The incident demonstrates how attackers leverage legitimate, freely available services to conduct operations while avoiding detection.
Why it matters: Security teams managing SolarWinds Web Help Desk deployments and those relying on cloud SIEM services need to monitor for unauthorized access and understand how free trials can be weaponized for post-compromise activity.
- threat intel
Unmasking an Attack Chain of MuddyWater
Huntress has documented a complete attack timeline in a customer environment that matches tactics attributed to MuddyWater, an Iranian-linked advanced persistent threat (APT) group. The analysis provides visibility into the threat actor's operational methods and progression through the compromised infrastructure.
Why it matters: Security teams tracking Iranian APT activity should review this timeline to understand MuddyWater's current attack chain and identify indicators of compromise in their own environments.
- cloud saas
Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations
Wiz has released Tenant Manager, a feature that enables federated organizations to manage multiple Wiz tenants from a centralized console. This simplifies security operations for enterprises with complex multi-tenant deployments by reducing operational friction.
Why it matters: Security teams managing federated organizations can now streamline multi-tenant governance and visibility, reducing operational overhead and potential security blind spots across subsidiary or business unit instances.
- regulatory
The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response
This article discusses how Wiz for U.S. Government addresses FedRAMP Revision 5 incident response controls and detection benchmarks through cloud detection and response capabilities. The piece concludes a series on Agile FedRAMP compliance by focusing on reactive risk management within cloud environments.
Why it matters: Federal agencies and contractors subject to FedRAMP requirements need to understand tools and approaches that satisfy IR-4 and other incident response controls, plus the 20x detection benchmarks that demonstrate security posture during FedRAMP authorization and continuous monitoring.
- breaches incidents
How a Pharmacy Cyberattack is a Warning Sign for | Huntress
A cyberattack on a pharmacy technology provider resulted in access disruptions affecting millions of patients, highlighting systemic vulnerabilities in healthcare infrastructure. The incident demonstrates how a single point of failure in a widely used technology platform can cascade across the entire healthcare ecosystem. This event signals the need for healthcare organizations to reassess their dependency on third-party vendors and implement more resilient incident response practices.
Why it matters: Healthcare providers, pharmacies, and patients face operational disruptions and service delays when critical pharmacy infrastructure is compromised; practitioners should review their vendor risk management and incident response plans for healthcare supply chain dependencies.
- identity access
SSO vs. MFA: Key Differences, Compared + Explained | Huntress
Single sign-on (SSO) and multi-factor authentication (MFA) serve different security purposes and are often complementary rather than interchangeable. SSO streamlines access by allowing users to authenticate once across multiple applications, while MFA adds security layers by requiring multiple verification methods. Organizations can benefit from implementing both technologies together to balance user convenience with stronger authentication controls.
Why it matters: Security practitioners need to understand that SSO and MFA address distinct threats: SSO reduces friction for users but requires MFA integration to prevent account compromise if credentials are stolen, helping teams design authentication strategies that don't sacrifice security for usability.
- threat intel
RMM Abuse: When IT Convenience Bites Back
Remote monitoring and management (RMM) abuse has surged 277 percent as attackers exploit these widely trusted IT tools to establish covert access to networks. The trend reflects a shift in adversary tactics away from isolated attacks toward leveraging legitimate software for prolonged, stealthy persistence. Organizations need to move beyond trusting RMM vendors and implement behavioral verification controls.
Why it matters: IT teams and security operations rely on RMM tools daily; defenders must audit which RMM instances exist in their environment, verify their legitimacy, and establish baseline behavior to detect compromise before attackers gain deep network access.
- identity access
Why BEC Is Now an Identity Problem
Business email compromise (BEC) attacks increasingly exploit Google Workspace and other cloud identity systems rather than relying solely on external email spoofing. Modern attackers focus on compromising or impersonating user identities within cloud platforms to gain credibility and access to organizational resources.
Why it matters: Security teams must treat BEC as an identity and access problem, not just an email security problem; cloud identity compromise is now a primary attack vector requiring updated detection and response strategies.
- research
On the Effectiveness of Mutational Grammar Fuzzing
Researchers examined the effectiveness of mutational grammar fuzzing, a technique that maintains structural validity while mutating test inputs through predefined grammars. The analysis identifies a critical flaw: achieving greater code coverage does not necessarily lead to finding more bugs, particularly in structure-aware fuzzing of languages where bugs require specific function call sequences and data dependencies. The author proposes techniques to address this limitation in fuzzing workflows.
Why it matters: Developers and security researchers using fuzzing for vulnerability discovery need to understand that coverage metrics alone are insufficient for bug detection; grammar fuzzing improvements could enhance the discovery of complex issues in language implementations, compilers, and parsers.
- threat intel
How Fake OpenClaw Installers Spread GhostSocks Malware
Security researchers at Huntress identified malicious GitHub repositories distributing fake OpenClaw installers that deploy GhostSocks malware. The attack exploits developers searching for legitimate software by hosting counterfeit packages that execute malware upon installation.
Why it matters: Developers and organizations using open source tools face supply chain risk when downloading installers from GitHub; verify package authenticity and monitor for unexpected network connections after installation.
- industry
GreyNoise Intelligence Is Available Across the CrowdStrike Falcon Platform
GreyNoise Intelligence has been integrated into the CrowdStrike Falcon platform, enabling security teams to access internet-wide scanning context within SIEM queries, SOAR workflows, and AI-driven triage systems. This integration combines GreyNoise's threat intelligence capabilities with CrowdStrike's endpoint detection and response infrastructure.
Why it matters: Security teams using CrowdStrike Falcon can now enrich alert investigations with GreyNoise's internet scanning data, reducing triage time and false positives when evaluating potentially malicious internet activity.
- regulatory
Wiz Achieves CPSTIC Certification in Spain
Wiz has achieved CPSTIC certification in Spain, a credential that signals compliance with cloud security standards for the country's public sector. This certification positions the company to support government and public administration organizations in their cloud modernization efforts.
Why it matters: Spanish public sector organizations and government cloud procurement decisions should note this certification as a vendor qualification milestone when evaluating cloud security tools.
- research
Cyber Resilience as a Corporate Mindset
This news piece discusses the importance of embedding cyber resilience as a core element of organizational culture and strategy. The article suggests that companies that prioritize this mindset are better positioned to succeed in managing cyber risks.
Why it matters: Security leaders need to advocate for cyber resilience as a strategic priority, not just a technical function, to gain executive buy-in and ensure sustained investment in security programs.
- regulatory
CIRCIA’s Next Chapter: Five Things I’ll Be Listening for in CISA’s Town Halls
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) is emerging as a potentially significant regulatory framework for the cybersecurity sector. The article discusses what to expect from upcoming CISA (Cybersecurity and Infrastructure Security Agency) town halls regarding CIRCIA's implementation.
Why it matters: Critical infrastructure operators and organizations subject to CIRCIA need to understand reporting requirements and compliance expectations as CISA provides guidance, making these town halls essential for practitioners to learn implementation details.
- ransomware
The Evolving Linux Threat Landscape
Linux systems face an evolving threat landscape with narrowing security gaps compared to traditional targets, including cross-platform attacks that exploit Windows Subsystem for Linux (WSL) and threats from both ransomware operators and nation-state actors. Security practitioners should monitor emerging attack vectors that leverage Linux's growing adoption in enterprise environments. The threat profile for Linux endpoints has shifted from niche concern to mainstream targeting by organized threat actors.
Why it matters: Linux administrators and enterprise security teams need to reassess defensive postures as Linux endpoints become priority targets for ransomware gangs and state-sponsored groups, requiring platform-specific detection and response capabilities.
- vulnerabilitiesCVE-2026-21902
Sometimes, You Can Just Feel The Security In The Design (Juniper Junos Evolved CVE-2026-21902 Pre-Auth RCE)
CVE-2026-21902 is an unauthenticated remote code execution vulnerability in Juniper's Junos OS Evolved on PTX Series routers, caused by incorrect permission assignment in the On-Box Anomaly Detection Framework. The vulnerable service listens on port 8160 and is accessible over the network despite being intended for internal-only access, allowing attackers to execute code as root without authentication. The vulnerability affects Junos OS Evolved 25.4 versions before 25.4R1-S1-EVO and 25.4R2-EVO, with the service enabled by default.
Why it matters: Organizations operating Juniper PTX Series routers with Junos OS Evolved versions 25.4 (excluding 25.4R1-EVO and earlier) should immediately patch to 25.4R1-S1-EVO or later to prevent unauthenticated remote takeover of core network infrastructure.
- ai security
Seeing AI Clearly: Building Visibility Across Modern AI Applications
Organizations deploying AI applications face visibility gaps because traditional security tools lack the capability to monitor modern AI architectures spanning models, agents, and cloud environments. A new implementation-agnostic approach is emerging to help security teams address these blind spots and support safer AI adoption.
Why it matters: Security practitioners need visibility strategies to prevent misconfigurations and exposures in AI systems before they become exploitable vulnerabilities in production environments.
- threat intel
Fake Tech Support Delivers Havoc Command & Control
Threat actors are using fake technical support schemes to distribute a customized version of the Havoc command and control (C2) framework. The attacks employ advanced evasion techniques including DLL sideloading, syscall evasion methods like HellsGate, and legitimate remote monitoring and management (RMM) tools to establish persistent access to victim systems.
Why it matters: Organizations receiving unsolicited tech support contacts face risk of malware deployment and persistent compromise; security teams should educate users on social engineering tactics and monitor for suspicious RMM tool activity.
- threat intel
Active Reconnaissance Campaign Targets SonicWall Firewalls Through Commercial Proxy Infrastructure
GreyNoise detected over 84,000 scanning sessions targeting SonicWall SonicOS firewalls within four days, using coordinated rotating proxy infrastructure to conduct active reconnaissance. The campaign indicates organized threat actor activity probing SonicWall deployments at scale.
Why it matters: Organizations running SonicWall firewalls face immediate exposure from active reconnaissance that precedes exploitation or breach attempts; practitioners should review firewall logs, restrict SonicOS admin interfaces, and monitor for follow-on attack activity.
- threat intel
A Survivor’s Journey Through the Cybercrime Underground
Mohammad's account reveals how individuals are trafficked and coerced into conducting cybercrime operations, specifically crypto scams, exposing the human trafficking networks that facilitate large-scale fraud. The story highlights recruitment methods and warning signs that organizations and individuals should recognize to protect themselves from targeted exploitation.
Why it matters: Security practitioners need to understand that cybercriminals leverage human trafficking to scale operations, meaning victims may appear as legitimate threats; awareness of these recruitment tactics helps teams identify compromised insiders and understand adversary operational structure.
- research
A Deep Dive into the GetProcessHandleFromHwnd API
A researcher examines the GetProcessHandleFromHwnd API, tracing its evolution from Windows Vista through Windows 11, and finds significant discrepancies between its documented behavior and actual implementation. The API's documentation incorrectly describes its mechanisms, and its security properties have changed substantially over time, particularly with regard to integrity level requirements and user context restrictions.
Why it matters: Security practitioners building or maintaining Windows applications need accurate understanding of this API's actual behavior, especially since documented misinformation could lead to incorrect threat modeling or missed security controls around UAC and process handle access.
- vulnerabilitiesCVE-2024-28986CVE-2024-28988
Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s))
SolarWinds Web Help Desk has been found to contain multiple pre-authentication remote code execution vulnerabilities via Java deserialization, including CVE-2025-40552, CVE-2025-40553, and CVE-2025-40554. Researchers achieved RCE on a fully patched instance by chaining an authentication bypass with a deserialization flaw, demonstrating that previous patches for similar 2024 vulnerabilities did not fully address the underlying issues. This continues a pattern of recurring deserialization problems in the product.
Why it matters: Help desk administrators running SolarWinds Web Help Desk need to immediately assess if they are exposed to pre-auth RCE and apply patches, as these vulnerabilities bypass authentication and allow unauthenticated remote code execution on internet-facing systems handling sensitive internal data.
- ransomware
Unraveling DXP and DLP: Halcyon’s Data Extortion Defense
Halcyon has released DXP (Data Extortion Protection), a security solution designed to address gaps in traditional Data Loss Prevention (DLP) tools, specifically targeting ransomware double extortion attacks where threat actors encrypt data and threaten to publish it unless paid. The solution aims to provide additional protections beyond what conventional DLP systems offer.
Why it matters: Security teams managing ransomware risk need to evaluate whether DXP fills detection and response gaps in their existing DLP deployments to reduce exposure to data theft and extortion threats.
- cloud saas
Security Insights Where Work Happens: Notion Custom Agents + Wiz MCP
Wiz and Notion have integrated cloud security insights into Notion's Custom Agents feature, allowing security teams to automate reporting, investigation, and workflows within Notion. This integration brings Wiz security data directly into the collaboration platform where teams already operate.
Why it matters: Security and DevOps teams using Notion can now streamline cloud security workflows and reduce context-switching by accessing Wiz findings without leaving their collaboration tool.
- threat intel
2026 GreyNoise State of the Edge Report: Where Attacks Concentrate and Defenses Fall Short
GreyNoise released a 2026 report analyzing nearly 3 billion malicious sessions over 162 days, identifying patterns in edge attacks and defense gaps. The research examines VPN targeting, infrastructure concentration, and IP rotation tactics by attackers, providing quantified data on where edge defenses fall short.
Why it matters: Security teams managing edge infrastructure need to understand actual attack patterns and concentration points to prioritize defensive investments and identify gaps in their current edge security posture.
- industry
Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories
Wiz received four awards in the 2026 Latio Application Security Report, recognizing the company's capabilities in application security across code and runtime protection.
Why it matters: Security practitioners evaluating application security tools should consider Wiz's performance recognition when assessing vendors for their application protection strategy.
- ransomwareCVE-2023-46604
Apache ActiveMQ Exploit Leads to LockBit Ransomware
A threat actor exploited CVE-2023-46604 on an exposed Apache ActiveMQ server in mid-February 2024 to achieve remote code execution using a Java Spring class, leading to LockBit ransomware deployment. The intrusion demonstrates how unpatched critical vulnerabilities in internet-facing services remain an effective attack vector for ransomware operators.
Why it matters: Organizations running Apache ActiveMQ need to verify patches for CVE-2023-46604 are deployed; exposed instances face immediate ransomware risk from active threat actors.
- cloud saas
Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next
Wiz and Infosys Cyber Next have developed a reference architecture for cloud security that leverages multiple coordinated agents to automate investigation and remediation of security issues in cloud environments.
Why it matters: Cloud security teams can adopt this architecture to reduce manual response times and improve the consistency of threat investigation and remediation across their infrastructure.
- ai security
The Growing Reality of AI-Enhanced Candidate Fraud
Artificial intelligence (AI) is increasingly used to facilitate fraud during hiring processes, including deepfakes and resume falsification. Organizations need data-informed strategies to detect and prevent AI-enhanced candidate deception at scale.
Why it matters: Hiring teams and HR practitioners face immediate risk of onboarding fraudulent or unqualified candidates; understanding AI-enabled fraud tactics and detection methods is essential to protect organizational security posture and trust.
- regulatory
The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring
This article discusses how Wiz for U.S. Government helps organizations automate visibility and prioritize risk remediation to meet FedRAMP continuous monitoring requirements while maintaining development velocity. It is part of a series on adopting agile practices within the FedRAMP authorization framework.
Why it matters: Government contractors and federal agencies using FedRAMP authorizations need to balance continuous monitoring compliance with agile development; this content addresses how to streamline that process without creating bottlenecks.
- threat intel
Hiding in Plain Sight with App Domain Manager Injection
Attackers exploit App Domain Manager injection to execute arbitrary code within trusted .NET applications by modifying configuration files, allowing them to circumvent application controls. This technique enables malicious code execution while appearing to originate from legitimate processes. Organizations can implement detection and mitigation strategies to identify and prevent such attacks.
Why it matters: Development and security teams managing .NET applications need to understand this injection vector to protect against code execution that bypasses traditional application whitelisting and control mechanisms.
- cloud saas
Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs
Wiz Research has developed a method to automatically detect malicious Azure OAuth applications and consent phishing campaigns using large language models. The approach aims to identify emerging threats in the Azure ecosystem that attempt to trick users into granting unauthorized access.
Why it matters: Organizations using Azure and Microsoft 365 should understand that LLM-based detection tools can help identify consent phishing attacks before users grant permissions to malicious applications, reducing exposure to account compromise and data exfiltration.
- industry
Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026
Wiz received recognition from Forrester Research as a leader in Cloud Native Application Protection Platform (CNAPP) solutions in Q1 2026, earning the highest score in the Current Offering category. The evaluation reflects the vendor's focus on cloud security capabilities.
Why it matters: Security practitioners evaluating CNAPP solutions should review Forrester's assessment to inform procurement decisions and validate that Wiz meets their organization's cloud native protection requirements.
- cloud saas
From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes
Wiz is promoting an approach to application security that prioritizes exploitability and root cause fixes by connecting runtime vulnerability detections back to source code through its Security Graph. The method aims to reduce noise by focusing remediation efforts on vulnerabilities that pose actual risk rather than generic alerts.
Why it matters: Development and security teams should evaluate whether exploitability-focused triage and direct code-level remediation capabilities can reduce the time and resources spent on patch management and vulnerability prioritization.
- ransomware
The Silent Credential Heist
The article discusses the challenge of defending against ransomware by emphasizing that detection must extend beyond identifying active malicious processes to include inactive threats already present in the environment. Organizations need to focus on discovering compromised credentials and dormant malware that attackers can activate later in their campaigns.
Why it matters: Security teams must prioritize credential hunting and lateral movement detection alongside traditional endpoint monitoring, as compromised accounts pose an immediate risk for ransomware deployment and data exfiltration regardless of current activity levels.
- threat intel
A New RAT and a Hands-on-Keyboard Intrusion
Security researchers identified a new remote access trojan (RAT) called AstarionRAT deployed via ClickFix infection chains that use the Matanbuchus 3.0 loader. The analysis reveals a multi-stage attack followed by hands-on intrusion activity.
Why it matters: Organizations need to monitor for ClickFix social engineering campaigns and understand the infection chain leading to AstarionRAT, as successful compromises enable interactive attacker access to systems.
- ransomware
Ransomware Attacks Reach Peak Levels During December 2025 Holiday Period
December 2025 recorded 727 ransomware attacks, the highest monthly total to date. LockBit was responsible for 96 of those attacks, with healthcare organizations accounting for 45 incidents. Attackers took advantage of reduced staffing levels during the holiday period to conduct their campaigns.
Why it matters: Security teams at healthcare providers and all critical sectors need to strengthen holiday-period defenses and incident response readiness, as attackers are actively targeting predictable staffing gaps.
- regulatory
The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point
Wiz outlines a risk-first approach to achieving FedRAMP High authorization that balances compliance requirements with continued product innovation. The company is publishing a four-part series covering how its platform addresses FedRAMP requirements through proactive, preventative, and reactive risk management strategies.
Why it matters: Security teams building or maintaining Federal Risk and Authorization Management Program (FedRAMP) compliant solutions need practical frameworks for rapid authorization without sacrificing development velocity and security posture.
- ransomware
Statement Regarding Misattributed Ransomware Leak-Site Listing
A statement addresses a ransomware leak-site listing that was incorrectly attributed to an organization or entity. The clarification appears intended to correct the record regarding which party was actually responsible for the listing or the associated incident.
Why it matters: Security teams tracking ransomware threats and leak sites need accurate attribution to understand true threat actors, assess actual risk exposure, and avoid misdirected incident response or threat intelligence efforts.
- cloud saas
Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Wiz Research has created AI Cyber Model Arena, a benchmark that evaluates offensive AI security capabilities across 257 real-world scenarios including zero-day vulnerabilities, CVEs, API and web attacks, and cloud misconfigurations on AWS, Azure, Google Cloud, and Kubernetes. The benchmark measures what AI models and agents can accomplish in practical cybersecurity contexts.
Why it matters: Security teams need to understand AI capabilities in both attack and defense to assess autonomous agent risks and inform offensive security tooling decisions.
- cloud saas
The Identity Breach You Didn’t Know You Had: Google Workspace
Google Workspace environments frequently experience breaches that remain undetected for extended periods. Attackers exploit misconfigured permissions to gain unauthorized access, and organizations should understand the warning signs to identify compromises earlier.
Why it matters: Google Workspace administrators need to audit permission configurations immediately and implement detection mechanisms, as delayed breach discovery significantly increases exposure to data theft and lateral movement.
- vulnerabilitiesCVE-2026-1731
Reconnaissance Has Begun for the New BeyondTrust RCE (CVE-2026-1731): Here's What We See So Far
A proof of concept for CVE-2026-1731, a remote code execution vulnerability in BeyondTrust, was published on GitHub on February 10. Within 24 hours, reconnaissance activity was detected scanning for vulnerable instances.
Why it matters: Organizations running BeyondTrust should immediately check for exposure to CVE-2026-1731 and apply patches, as active reconnaissance indicates imminent exploitation attempts.
- vulnerabilities
Bypassing Administrator Protection by Abusing UI Access
A researcher discovered and disclosed nine bypasses of Windows Administrator Protection, five of which exploited vulnerabilities in the UI Access implementation. UI Access was designed to allow accessibility applications to interact with higher-privilege processes while maintaining User Interface Privacy Isolation (UIPI) protections, but the feature's implementation contained exploitable weaknesses that have since been patched.
Why it matters: Windows administrators and security teams need to ensure affected systems are fully patched, as these bypasses could allow attackers to escalate privileges by abusing accessibility features; organizations relying on accessibility software should verify their implementations meet current security requirements.
- ransomware
Employee Monitoring and SimpleHelp Software Abused in | Huntress
Huntress researchers identified ransomware operations leveraging employee monitoring software and SimpleHelp remote management tools to establish persistence and deploy ransomware payloads. Attackers are exploiting legitimate administrative tools to evade detection and maintain access to victim systems.
Why it matters: Organizations using employee monitoring or SimpleHelp RMM are at immediate risk if these tools fall under attacker control; security teams should audit access controls and monitor for suspicious activity within these platforms.
- ransomware
A Ransomware Reversal: Sicarii Can't Decrypt (But Halcyon Can)
Sicarii ransomware contains a critical encryption flaw that prevents even its operators from decrypting files, creating an unintended barrier to victim recovery. Security firm Halcyon has developed technology to capture Sicarii's encryption keys, potentially enabling recovery for affected organizations.
Why it matters: Organizations hit by Sicarii should contact Halcyon immediately, as the ransomware's broken implementation may allow decryption without paying the ransom, reducing operational recovery time and financial impact.
- threat intel
Active Ivanti Exploitation Traced to Single Bulletproof IP—Published IOC Lists Point Elsewhere
GreyNoise detected active exploitation of two critical Ivanti Endpoint Manager Mobile vulnerabilities, with 83% of observed attacks originating from a single IP address hosted on bulletproof infrastructure. This IP does not appear on most public indicator of compromise (IOC) lists, suggesting gaps in threat intelligence sharing.
Why it matters: Organizations running Ivanti Endpoint Manager Mobile need to monitor for exploitation attempts from this IP and update detection rules, as widely shared IOC lists may miss this primary attack vector.
- research
10 Endpoint Security Trends and Tips for 2026 | Huntress
Huntress outlines ten endpoint security trends anticipated for 2026, including AI-powered defenses, zero trust architecture, and human-led threat hunting approaches designed to support security teams with limited resources. The piece emphasizes practical strategies for detecting and stopping threats more efficiently in evolving threat landscapes.
Why it matters: Security practitioners managing understaffed teams need to understand emerging defensive strategies and tooling categories to prioritize their 2026 security investments and operational improvements.
- vulnerabilitiesCVE-2025-26399
Active Exploitation of SolarWinds Web Help Desk (CVE-2025-26399)
Huntress has identified active exploitation of CVE-2025-26399, a deserialization and remote code execution vulnerability affecting SolarWinds Web Help Desk. Attackers are currently leveraging this flaw in production environments.
Why it matters: Organizations running SolarWinds Web Help Desk need to patch immediately, as public exploitation is underway and remote code execution allows full system compromise.
- ransomware
Malware vs Ransomware: A Primer
This article provides an overview of ransomware as distinct from broader malware categories, tracing its evolution into a significant enterprise threat. It covers the technical and operational differences between ransomware and other malware types, alongside organizational resilience approaches.
Why it matters: Security practitioners need to understand ransomware's distinct threat model and business mechanics to design appropriate detection, response, and recovery strategies for their organizations.
- cloud saas
Wiz + Spotify Backstage: Security at the Developer’s Desk
Wiz has integrated its security scanning capabilities into Spotify's Backstage, a developer platform for managing infrastructure and services. The integration allows developers to view and address security issues directly within their existing workflow tools rather than accessing separate security platforms.
Why it matters: Development teams adopting Backstage can now reduce friction in remediation by surfacing Wiz security findings where developers already work, improving the likelihood of faster issue resolution.
- research
Windows ProjFS Internals: A Technical Deep Dive | Huntress
Huntress published a technical analysis of Windows Projected File System (ProjFS), covering the ProjFS driver architecture, virtualization roots, and relevant PowerShell commands. The article provides a deep examination of how ProjFS functions at the operating system level.
Why it matters: Security practitioners should understand ProjFS internals to identify suspicious file system virtualization behavior, detect potential evasion techniques, and secure systems against attacks exploiting this Windows subsystem.
- threat intel
They Got In Through SonicWall. Then They Tried to Kill | Huntress
Huntress responded to an intrusion where attackers used compromised SonicWall VPN credentials and a revoked EnCase forensic driver to disable endpoint detection and response (EDR) processes through a bring-your-own-vulnerable-driver (BYOVD) attack. The incident demonstrates the attack chain from initial access through VPN compromise to EDR evasion. The attacker's ability to leverage legitimate-looking drivers highlights the sophistication of post-compromise techniques.
Why it matters: Security practitioners managing VPN access and EDR deployments need to monitor for compromised credentials on external-facing services and defend against unsigned or revoked drivers that can terminate security tooling.
- threat intel
New in Event Feeds: Vendor CVE Spike & Tag Spike
GreyNoise has introduced new features called Vendor CVE Spike and Tag Spike to detect patterns of coordinated vendor targeting and botnet activity increases. These detection capabilities aim to identify threats before a Common Vulnerabilities and Exposures (CVE) identifier is officially assigned.
Why it matters: Security operations teams using GreyNoise can now identify emerging threats and attack coordination earlier in the lifecycle, enabling faster incident response and proactive vulnerability management before formal CVE disclosures.
- ai security
Building AI Security Together: New Ways to Partner with Wiz for AI Security in 2026
Wiz is expanding its integration network with new tools and programs designed to enhance AI security capabilities for partners and developers. The enhancements include a model context protocol (MCP) integration, developer AI agents, a dedicated AI security category, and a partner hackathon focused on AI security.
Why it matters: Security practitioners and partners using Wiz should evaluate these new integration options to strengthen their AI security posture and determine whether participating in the hackathon or leveraging the new developer tools can improve their threat detection and response capabilities.
- breaches incidents
Hacking Moltbook: The AI Social Network Any Human Can Control
A misconfigured database exposed sensitive credentials and personal information from Moltbook, an AI social network. The breach revealed approximately 35,000 emails, 1.5 million API keys, and details on 17,000 users with access to the platform's systems.
Why it matters: Security practitioners managing or assessing AI platforms need to verify proper access controls and credential management, as exposed API keys and user data can enable unauthorized access to services and user accounts.
- research
Reduce Alert Fatigue Like a Huntress Cybersecurity Pro
Huntress offers practical guidance on managing alert fatigue in security operations centers (SOCs) by sharing techniques to reduce alert volume, prevent analyst burnout, and prioritize genuine threats. The advisory addresses the challenge of distinguishing actionable security incidents from noise in modern security environments.
Why it matters: SOC teams and security practitioners drowning in alerts need concrete strategies to improve detection quality and analyst retention; poor alert tuning directly impacts incident response speed and the ability to catch real threats.
- ransomware
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
GreyNoise identified 59 vulnerabilities in the CISA Known Exploited Vulnerabilities (KEV) catalog that were updated to reflect known ransomware use during 2025, but these changes were not prominently announced. The research highlights a gap in vulnerability tracking visibility and introduces a new feed to monitor these updates.
Why it matters: Security teams relying on CISA's KEV catalog need to actively track ransomware designations on known exploited vulnerabilities to prioritize patching of actively weaponized threats; the new feed closes a visibility gap that could delay remediation of high-risk assets.
- vulnerabilitiesCVE-2025-55182
React Server Components Exploitation Consolidates as Two IPs Generate Majority of Attack Traffic
Two months after the December 3, 2024 disclosure of CVE-2025-55182, exploitation targeting React Server Components has consolidated, with the majority of attack traffic originating from just two IP addresses.
Why it matters: React developers and organizations running affected applications need to assess their exposure and apply available patches, as concentrated attack patterns suggest active, targeted exploitation campaigns.
- vulnerabilitiesCVE-2026-1281CVE-2026-1340
Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)
Ivanti released patches for two pre-authentication remote code execution vulnerabilities (CVE-2026-1281 and CVE-2026-1340) in Endpoint Manager Mobile (EPMM), an enterprise mobility management platform used to control corporate mobile devices. The vulnerabilities are actively exploited in the wild and have been added to CISA's Known Exploited Vulnerabilities list. Permanent patches are not available until Q1 2026; customers are currently receiving temporary RPM patches that must be reapplied after system updates to remain effective.
Why it matters: Organizations running Ivanti EPMM are at immediate risk of unauthenticated remote code execution and must apply temporary patches now and monitor for active exploitation; failure to act leaves corporate mobile fleets and enterprise resources vulnerable to compromise.
- research
The Year in Wiz Research: 2025 Most Read Blogs
Wiz published a retrospective of its most-read security research and investigations from 2025, covering cloud security issues, vulnerabilities, and developments related to AI and supply chain threats. The summary highlights key trends that shaped the security landscape during the year.
Why it matters: Security practitioners should review the year's high-impact research to understand emerging attack patterns and vulnerabilities affecting cloud environments and supply chains, informing their 2026 defense priorities.
- vulnerabilitiesCVE-2024-54529CVE-2025-31235
Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529
A security researcher details the exploitation of CVE-2024-54529, a type confusion vulnerability in macOS coreaudiod system daemon discovered through knowledge-driven fuzzing. The vulnerability in the CoreAudio framework's Mach message handlers allows attackers to hijack control flow by crafting a pointer chain through heap memory to dereference a controlled fake vtable.
Why it matters: macOS users running vulnerable versions of CoreAudio are at risk of local privilege escalation or code execution if an attacker can craft and deliver a malicious Mach message; security teams should monitor for patched versions and assess exposure in their macOS deployments.
- ai security
AI Agents vs Humans: Who Wins at Web Hacking in 2026?
Wiz Research and Irregular, an AI security lab, conducted a comparative study to evaluate the capabilities of AI agents versus human hackers in web-based security scenarios. The research appears to examine relative performance and effectiveness across hacking techniques and exploitation methods.
Why it matters: Security practitioners need to understand emerging AI capabilities in offensive security to assess their own defenses, workforce planning, and whether AI-augmented threats represent a material change in attack surface risk.
- ransomware
From Cybercrime to Conflict: Why Infrastructure Defenders Must Rethink Risk
Nation-states are increasingly deploying ransomware techniques against critical infrastructure, leveraging criminal methods to achieve rapid disruption while maintaining operational deniability. This convergence of state-sponsored activity and cybercriminal tactics represents a shift in attack methodology that infrastructure operators must understand and prepare for.
Why it matters: Critical infrastructure defenders, energy operators, and government agencies face a blurred threat landscape where nation-state adversaries use ransomware techniques; understanding this hybrid approach is essential for detection, response, and attribution today.
- threat intel
The (!FALSE) Pattern | Huntress
SOAPHound uses an LDAP query pattern that undergoes transformation during LDAP optimization, resulting in a distinctive (!FALSE) signature in Event 1644 logs. This transformation provides a detection method for identifying SOAPHound activity that security teams may not be familiar with. The finding highlights the importance of understanding how LDAP query optimization affects logging and detection signatures.
Why it matters: Defenders monitoring for SOAPHound reconnaissance need to recognize this transformed pattern in Event 1644 logs to detect LDAP attacks that would otherwise appear as normal directory queries.
- cloud saas
Introducing the WIN Partner Index: The Integrations That Powered Modern Cloud Security in 2025
A new industry benchmark called the WIN Partner Index tracks how cloud security integrations are adopted and deliver value across organizations in 2025. The index provides data-driven insights into integration adoption patterns and their effectiveness in modern cloud security programs.
Why it matters: Security leaders evaluating cloud security tools should understand integration trends and adoption patterns to make informed vendor and platform decisions aligned with industry best practices.
- ransomware
What CISOs Need to Know About Ransomware: The AI Revolution Behind the Threat
Artificial intelligence is enabling ransomware actors to develop more sophisticated attacks, prompting chief information security officers to reassess their defensive posture, supply chain security, and overall resilience strategies. The evolution reflects a shift in how ransomware threats operate and necessitates updated security approaches across organizations.
Why it matters: CISOs and security teams need to understand how AI-augmented ransomware techniques are evolving to ensure their detection, response, and recovery capabilities remain effective against these emerging threats.
- industry
GreyNoise Introduces Recall: Time-Series Intelligence for GreyNoise Query Language (GNQL)
GreyNoise has launched Recall, a time-series feature for its query language (GNQL) that allows customers to analyze historical scanner activity data across specific time periods rather than viewing only current snapshots. The capability enables security teams to examine how IP behavior evolved over time at granular hourly intervals.
Why it matters: Security practitioners using GreyNoise can now perform historical threat investigations and trend analysis to better understand attacker behavior patterns and scanner campaigns affecting their infrastructure.
- cloud saas
AI-Powered Forensics, at Cloud Speed
Wiz has announced a public preview of AI-powered forensics capabilities designed for cloud environments, offering context-aware analysis to expedite investigation and response workflows. The announcement highlights the company's approach to integrating artificial intelligence into forensic analysis at cloud scale.
Why it matters: Security teams managing cloud infrastructure need faster forensic investigation tools to reduce incident response time; practitioners should evaluate whether AI-assisted context awareness improves their investigation efficiency and threat detection capabilities.
- research
Introducing SITF: The First Threat Framework Dedicated to SDLC Infrastructure
A new threat framework called SITF (Secure Infrastructure Threat Framework) has been introduced to address attacks targeting software development lifecycle infrastructure, moving beyond basic checklist approaches to provide visualization, mapping, and blocking capabilities for production SDLC environments.
Why it matters: Development teams and security practitioners need to understand and defend SDLC infrastructure, as compromises at this layer can affect the integrity of all downstream software products and deployments.
- ransomware
The AI Arms Race
Ransomware operators are increasingly leveraging artificial intelligence to enhance their attack capabilities and operational efficiency. The article argues that organizations should pivot their security strategy from prevention-focused approaches toward building operational resilience and preparedness measures instead.
Why it matters: Security leaders and executives need to reassess ransomware defenses today, as AI-enhanced attacks are becoming more sophisticated and prevention alone is insufficient; readiness and recovery capabilities are now critical.
- vulnerabilities
Huntress Catches SmarterMail Account Takeover Leading to RCE
Huntress has identified a vulnerability in SmarterMail versions before Build 9511 that allows attackers to take over privileged accounts and achieve remote code execution. The vulnerability enables unauthorized access to administrative functions and system compromise.
Why it matters: Organizations running SmarterMail versions prior to Build 9511 face immediate risk of account compromise and server takeover; administrators should prioritize updating to the patched version.
- ransomware
One Vendor, 1,000 Victims
Recent ransomware attacks against major vendors such as PowerSchool, Change Healthcare, and CDK Global revealed widespread supply chain vulnerabilities affecting thousands of downstream customers. These incidents highlighted how compromising a single vendor can create cascading exposure across multiple organizations and sectors. The attacks demonstrated the need for stronger vendor security practices and customer oversight of third-party risk.
Why it matters: Organizations using these vendors faced direct operational disruption and data exposure, making vendor security assessment and incident response planning critical priorities for practitioners managing supply chain dependencies.
- cloud saas
WizExtend is Here: AI and Cloud Security Insights in Your Daily Workflow
WizExtend, a new capability from Wiz, integrates security insights and remediation actions directly into cloud security posture (CSP) portals, version control system (VCS) consoles, and threat research platforms. The feature aims to streamline security workflows by embedding risk assessment and response options into developers' existing tools.
Why it matters: Security teams and developers can now identify and address cloud misconfigurations and risks without leaving their primary workflow, potentially reducing mean time to remediation for cloud security issues.
- cloud saas
How Hacked Construction Apps Are Bringing Down Jobsite Security
Construction industry applications face security vulnerabilities that can be exploited through flaws in the software itself or its underlying components, creating risks across jobsites. These compromised apps expand the overall attack surface for construction organizations and their operations.
Why it matters: Construction companies and their IT teams need to assess their app inventory and vendor security practices, as compromised construction applications can disrupt jobsite operations and expose sensitive project data.
- cloud saas
From Detection to Remediation: Wiz in Your JetBrains IDE
Wiz has released a generally available JetBrains IDE plugin that allows developers to identify and remediate security risks directly within their local development environment before code is committed or deployed. The plugin integrates security scanning into the developer workflow, shifting security checks earlier in the software development lifecycle.
Why it matters: Development teams using JetBrains IDEs can now detect and fix vulnerabilities and misconfigurations at the source, reducing the burden on security teams to catch issues in later stages and accelerating time to remediation.
- ai security
Agentic Browser Security: 2025 Year-End Review
A review examines security challenges and attack vectors emerging around agentic browsers in 2025, along with how vendors are implementing security layers to protect against AI-driven browser risks. The analysis provides guidance for organizations evaluating these technologies.
Why it matters: Security teams need to understand agentic browser vulnerabilities and vendor security capabilities as these AI-driven tools become more prevalent in enterprise environments.
- threat intel
Dissecting CrashFix: KongTuke's New Toy
KongTuke operates a deceptive campaign called CrashFix that delivers a fake ad blocker extension designed to deliberately crash user browsers, then prompts victims to install a fix that deploys ModeloRAT malware. The campaign appears to target higher-value victims for remote access and control.
Why it matters: Security teams and end users should watch for fake ad blocker installations and fraudulent browser repair tools, as this social engineering tactic chains commodity frustration with credential theft and malware deployment.
- cloud saas
CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild
Wiz Research identified a critical supply chain vulnerability that exploited a CodeBuild misconfiguration to gain unauthorized access to AWS GitHub repositories, including the one hosting the JavaScript SDK for the AWS Console. The attack demonstrates how misconfigurations in build infrastructure can be leveraged to compromise widely-used software dependencies that impact many downstream users.
Why it matters: Organizations using AWS services and the AWS JavaScript SDK are potentially exposed to compromised code; security teams should audit their CodeBuild configurations, GitHub repository access controls, and SDK dependencies immediately.
- threat intel
SDFlags | Huntress
A security investigator discovered that SDFlags, an overlooked field in Event 1644 logs, can reveal attack paths through analysis of nTSecurityDescriptor attributes in Active Directory. This finding enables creation of high-confidence detection signatures for identifying suspicious security descriptor modifications. The discovery highlights how neglected log fields can provide valuable forensic indicators.
Why it matters: Blue teams and Active Directory defenders need to monitor SDFlags changes to detect lateral movement and privilege escalation attempts that exploit security descriptor modifications.
- cloud saas
A 90-Day Action Plan to Turn Resolutions into Results with Wiz
Wiz is promoting a 90-day action plan designed to help organizations implement cloud security improvements, targeting both new users and those beginning their cloud security initiatives. The plan aims to convert security commitments into measurable outcomes within the first quarter.
Why it matters: Cloud security practitioners evaluating implementation timelines should assess whether structured onboarding frameworks align with their organizational readiness and threat posture.
- industry
Introducing the Wiz Partner Alliance: A New Chapter for Partner Success
Wiz has announced the Wiz Partner Alliance, a new initiative for partner engagement in cloud security. The program appears designed to strengthen collaboration between Wiz and its partners in the cloud security space.
Why it matters: Cloud security partners and resellers should evaluate whether this alliance affects their go-to-market strategy, pricing, or support relationships with Wiz.
- vulnerabilities
A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave
A security researcher discovered three bugs in the BigWave driver on Google Pixel 9, including a use-after-free vulnerability accessible from the mediacodec sandbox context. The most severe bug allows an attacker to achieve kernel-level arbitrary read and write capabilities by exploiting a race condition where the driver accesses job objects on a worker thread after the file descriptor has been closed and memory freed. Google released fixes for all three vulnerabilities on January 5, 2026.
Why it matters: Pixel 9 users and device administrators should apply the January 2026 security updates, as this 0-click exploit chain can be triggered through decoding operations without user interaction, leading to complete device compromise.
- industry
Cross-Platform Unity in EDR
Huntress researchers examine the technical challenges of maintaining equivalent endpoint detection and response (EDR) capabilities across Windows, macOS, and Linux platforms. The analysis highlights how differences in security architectures and platform maturity influence product development decisions across operating systems.
Why it matters: Security teams and vendors building or evaluating EDR solutions should understand platform-specific limitations and capabilities that affect visibility and protection consistency across their infrastructure.
- threat intel
Reflecting on AI in 2025: Faster Attacks, Same Old Tradecraft
Huntress reports that AI is enabling faster attack execution through automated scripting in 2025, but threat actors continue to rely on established tradecraft and techniques. Detection capabilities and basic security hygiene remain the most effective defenses against these accelerated attacks.
Why it matters: Security practitioners should prioritize detection improvements and foundational hygiene practices, as they remain more effective than assuming novel AI-driven attack techniques require entirely new defenses.
- threat intel
Filtering Noise in (Cyber)Space
GreyNoise employs scientific methods to distinguish between benign internet noise and genuine threats, helping security defenders gain more accurate visibility into malicious activity. The approach filters out routine scanning and other non-threatening network behavior to focus attention on actual security risks.
Why it matters: Security teams need reliable threat intelligence filtering to prioritize incident response and reduce alert fatigue, making GreyNoise's noise-filtering methodology relevant to defenders managing high-volume network data.
- government policy
Preparing for Post-Quantum Cryptography
Organizations should begin assessing their cryptographic infrastructure and inventory to identify systems that will require quantum-resistant algorithm replacements. Migration to post-quantum cryptography (PQC) requires planning across applications, hardware, and supply chains, with standards like NIST's recently finalized PQC algorithms providing a foundation for implementation roadmaps.
Why it matters: Security practitioners need to start planning now because transitioning to PQC is a multi-year effort affecting all cryptographically dependent systems, and delay increases risk from adversaries collecting encrypted data today for decryption once quantum computers emerge.
- ransomware
The Ransomware Ground Game: How A Christmas Scanning Campaign Will Fuel 2026 Attacks
A ransomware operator conducted an intensive four-day scanning campaign in December, testing over 240 exploits across the internet and documenting confirmed vulnerabilities for use in future targeted attacks.
Why it matters: Organizations need to patch systems proactively and monitor for indicators of compromise, as documented vulnerabilities from this campaign will likely be weaponized in 2026 attacks against their environments.
- ai security
Threat Actors Actively Targeting LLMs
Security researchers operating Ollama honeypots detected 91,403 attack sessions over a four-month period and identified two distinct threat campaigns systematically targeting large language model (LLM) deployments. The attacks demonstrate that threat actors are actively mapping and probing the growing attack surface created by widespread AI infrastructure.
Why it matters: Organizations deploying LLMs and other AI models need to implement monitoring and access controls immediately, as adversaries are actively scanning for exposed instances to compromise data, compute resources, or inject malicious responses.
- vulnerabilities
ESXi Exploitation in the Wild
Huntress has documented an active multi-stage attack that exploits vulnerabilities to escape guest virtual machines and compromise VMware ESXi hypervisors, leveraging VSOCK communication channels to conceal the exploitation chain. The attack involves potential zero-day exploits that allow attackers to move from guest systems to the underlying hypervisor infrastructure.
Why it matters: Infrastructure teams and virtualization administrators need to assess their ESXi deployments against this attack chain immediately, as compromise of the hypervisor layer enables lateral movement and persistence across all hosted VMs and workloads.
- industry
Wiz Recognized as a 2025 Customers’ Choice in the Gartner® Peer Insights™ Voice of the Customer for CNAPP
Wiz has been recognized as a Customers' Choice in the Gartner Peer Insights Voice of the Customer for Cloud Native Application Protection Platform (CNAPP) for the second consecutive year, making it the only vendor to achieve this distinction twice in a row.
Why it matters: Cloud security practitioners evaluating CNAPP solutions should note Wiz's consistent customer satisfaction ratings, which may inform vendor selection and contract renewal decisions.
- identity access
Expanding the Zero Critical Club to set a new standard for AppSec and SecOps teams
A new initiative introduces the Zero Code Criticals and Zero Time to Respond clubs, creating benchmarks for development teams to achieve secure coding practices and faster incident response capabilities. These standards aim to provide teams with clear metrics and goals for application security and security operations.
Why it matters: Development and security teams should understand these benchmarks to evaluate their current posture and roadmap improvements in secure development practices and incident response times.
- threat intel
Rogue RMMs: Common Social Engineering Tactics We Saw in 2025
Researchers documented social engineering tactics used in attacks involving ScreenConnect remote monitoring and management (RMM) software throughout 2025, including lures referencing Social Security statements. The report details attack patterns using top-affected domains and associated malware hashes that attackers leveraged in campaigns.
Why it matters: Security teams and managed service providers using ScreenConnect should understand current attack vectors and social engineering themes to improve endpoint defenses, employee awareness training, and detection capabilities against RMM-based threats.
- threat intel
Snipping the Long Tail of Shai-Hulud 2.0
Wiz Research published findings on Shai-Hulud 2.0, a campaign exploiting gaps in cloud credential rotation practices. The research documents the extent of infections over a month-long period and identifies a potential connection to the Trust Wallet incident. The researchers detail how they disrupted the ongoing attack chain.
Why it matters: Cloud infrastructure operators and incident responders need to understand credential rotation weaknesses and how this campaign persisted across multiple targets, informing both detection and remediation priorities.
- vulnerabilities
Protecting Against Zero-Day Vulnerabilities with SOC-Level ASM Alert
Wiz's Attack Surface Management (ASM) platform enables security operations centers (SOCs) to identify exploitable vulnerabilities before attackers discover them, helping organizations eliminate zero-day exposure risk. The approach uses pre-breach alerts to surface risky assets and configurations across the attack surface. This proactive methodology aims to reduce the window of vulnerability exploitation.
Why it matters: SOC teams and security leaders need to prioritize continuous attack surface monitoring to catch misconfigurations and unpatched systems before adversaries weaponize them, reducing breach likelihood.
- threat intel
The LDAP Whitespace Problem | Huntress
A technical issue with LDAP detection rules causes them to fail in production environments due to whitespace variations in Event 1644 logging. The article explains why these variations break Sigma detection rules and provides guidance on remediation.
Why it matters: Security teams relying on LDAP monitoring and Sigma rules need to understand whitespace handling to ensure their detection rules function reliably in production and catch actual threats.
- vulnerabilitiesCVE-2025-14847
MongoBleed (CVE-2025-14847) exploited in the wild: everything you need to know
CVE-2025-14847, an unauthenticated information leak vulnerability in MongoDB, is being actively exploited in the wild. Organizations running affected MongoDB instances face immediate risk of data exposure and should apply patches urgently.
Why it matters: Any organization running MongoDB without the latest patches is exposed to data exfiltration via unauthenticated access; apply updates immediately to prevent unauthorized information disclosure.
- vulnerabilitiesCVE-2025-14847
Merry Christmas Day! Have a MongoDB security incident.
A public exploit for CVE-2025-14847 was released on Christmas Day, enabling unauthenticated memory reads from MongoDB instances. The vulnerability affects all MongoDB versions over the past decade and allows attackers to extract sensitive data such as database passwords and AWS secret keys. With over 200,000 MongoDB instances exposed to the internet and the exploit now publicly available, mass exploitation is expected.
Why it matters: Organizations running internet-facing MongoDB instances need to prioritize patching immediately, as attackers can now easily extract credentials and cloud secrets without authentication and there are no known log-based detection methods yet.
- industry
The Kenna Transition: Your Strategic Shift to Exposure Management
Kenna, a vulnerability management platform, is being sunset, prompting security organizations to evaluate alternative approaches to managing vulnerabilities and exposures. This transition offers an opportunity for teams to adopt integrated exposure management strategies rather than maintaining isolated vulnerability tools.
Why it matters: Security practitioners using Kenna must plan migration to alternative platforms and evaluate whether a broader exposure management approach better aligns with their risk management capabilities and organizational needs.
- threat intel
Tradecraft Tuesday Recap | Huntress
Huntress provides a summary of current threat tradecraft, including exploitation techniques like React2Shell and phishing campaigns that abuse legitimate websites. The recap covers tactics affecting both enterprise and consumer targets.
Why it matters: Security teams need awareness of active exploitation methods and phishing vectors to strengthen defenses and user awareness programs against these demonstrated tactics.
- threat intel
Rising Supply Chain Attacks on Cybersecurity Ecosystems | Huntress
Supply chain attacks continue to target software and cybersecurity ecosystems, shifting the landscape of trust relationships and dependencies. Organizations need to implement stronger defenses and monitoring practices to address vulnerabilities throughout their software supply chains. The article discusses how enterprises can build greater resilience against these evolving threats.
Why it matters: Enterprise security teams must reassess their software vendor and dependency management practices, as compromised supply chain components directly expose production environments to attackers and require immediate inventory and risk assessment.
- cloud saas
Bringing Oracle Cloud Identity to Wiz
Wiz has integrated Oracle Cloud Infrastructure (OCI) identity management capabilities into its Security Graph platform, providing unified visibility across OCI identities, permissions, and policies. This integration enables security teams to map and visualize identity configurations within Wiz's broader cloud security posture framework.
Why it matters: OCI users need visibility into identity and access controls to detect misconfigurations and over-privileged accounts; Wiz's integration streamlines this monitoring for organizations running workloads in Oracle's cloud.
- ai security
From MCP to Vibe Coding: Full Endpoint Visibility in Wiz AI Security
Wiz announced AI-SPM (Software Posture Management), a tool that provides visibility across AI application endpoints including Vibe Coding and Model Context Protocol (MCP) implementations. The solution aims to help organizations identify and manage exposed AI infrastructure and related security risks.
Why it matters: Security teams managing AI deployments need visibility into all endpoint types to identify misconfigurations and exposures in their AI stacks before attackers can exploit them.
- threat intel
Trial, Error & Typos: Malware Isn't Always 'Sophisticated' | Huntress
Huntress research highlights that threat actors frequently make mistakes and deploy relatively basic malware, contrary to the assumption that all attackers are highly sophisticated. These errors and unsophisticated techniques often provide defenders with opportunities to detect and stop attacks before significant damage occurs.
Why it matters: Security teams should recognize that effective defense doesn't always require countering advanced techniques; many attacks fail due to attacker mistakes and poor malware quality, making robust detection of common patterns and monitoring for obvious errors an efficient defense strategy.
- regulatory
Securing Your Business: The Vital Role of Cyber Insurance | Huntress
This article discusses cyber insurance as a component of business security strategy and its role in protecting organizational assets from cyber threats. It explains how insurance coverage serves as a financial safeguard alongside other security measures.
Why it matters: Security and risk leaders should evaluate cyber insurance policies to understand coverage gaps, limits, and exclusions that affect incident response costs and recovery timelines.
- vulnerabilities
Gladinet CentreStack/Triofox: Cryptography Vulnerability | Huntress
Gladinet's CentreStack and Triofox products contain hardcoded cryptographic keys in their AES implementation, creating a vulnerability that threat actors are actively exploiting. The flaw allows attackers to potentially decrypt sensitive data protected by the affected encryption mechanism. This issue affects organizations relying on these file sharing and synchronization solutions for data protection.
Why it matters: Organizations using CentreStack or Triofox face immediate risk of data compromise if the hardcoded keys are leveraged to decrypt stored or transmitted data; patching or migrating away from vulnerable versions should be prioritized.
- threat intel
A Series of Unfortunate (RMM) Events
Threat actors are increasingly leveraging legitimate remote monitoring and management (RMM) tools, specifically PDQ and GoTo Resolve, to deploy additional RMM tools during attacks. This represents a method for attackers to establish persistence and expand their foothold within compromised environments.
Why it matters: Organizations using PDQ and GoTo Resolve should enhance monitoring for suspicious tool deployments and lateral movement, as these legitimate platforms are being weaponized as entry points for further compromise.
- ransomware
Cat’s Got Your Files: Lynx Ransomware
A ransomware intrusion labeled Lynx began in March 2025 when an attacker gained Remote Desktop Protocol access to an internet-exposed system. The successful logon showed no signs of brute force or credential stuffing, suggesting the attacker may have possessed valid credentials beforehand.
Why it matters: Organizations running internet-exposed RDP services face direct risk from Lynx operators, who gained initial access without obvious credential compromise techniques, implying need for review of RDP exposure and access controls.
- threat intel
There's Payloads, And Then There's pAIloads: A Look At Selected Opportunistic (And Possibly AI-"Enhanced") React2Shell Probes and Attacks
The React2Shell campaign has conducted widespread exploitation attempts against vulnerable React Server Components over approximately 1.5 weeks. Analysis of payload sizes in these attacks shows patterns consistent with automated scanners, alongside a smaller number of more sophisticated probes.
Why it matters: Development teams using React Server Components face active exploitation risk from both automated tooling and targeted attacks; practitioners should assess exposure and apply patches or mitigations promptly.
- threat intel
Coordinated Credential-Based Campaign Targets Cisco and Palo Alto Networks VPN Gateways
GreyNoise has identified a coordinated, automated campaign attempting to compromise enterprise VPN gateways through credential-based attacks targeting Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign appears to be systematically probing authentication infrastructure across multiple organizations.
Why it matters: Organizations using Cisco SSL VPN or Palo Alto Networks GlobalProtect should review access logs for brute force activity and enforce strong authentication controls, as successful compromise could grant attackers remote access to internal networks.
- vulnerabilities
Zero‑Days in the Age of AI: Behind the Scenes of ZeroDay.cloud 2025, with a Record High of CVEs in Critical Cloud Infra
ZeroDay.cloud (ZDC) 2025 awarded $320,000 in bug bounties and identified a record number of critical CVEs affecting core cloud infrastructure components. The findings highlight the security challenges in open-source software that powers modern cloud environments.
Why it matters: Cloud infrastructure operators and open-source maintainers need to prioritize patching critical CVEs in their dependencies, as these vulnerabilities affect the foundational layers used across the industry.
- research
Welcome to the new Project Zero Blog
Google Project Zero launched a redesigned blog featuring previously unpublished security research posts. The new platform will continue to publish vulnerability research and exploitation techniques to highlight attacker capabilities and defensive opportunities against zero-day exploits.
Why it matters: Security practitioners should monitor Project Zero's research output as it documents real exploitation techniques and attack surfaces that may affect the systems they defend.
- research
The OID Problem: Writing LDAP Detections That Actually Work
This article explains challenges with LDAP detection rules and their failure to trigger properly, attributing the issue to how object identifiers (OIDs) are transformed into bitwise operations. The piece provides guidance on fixing these detection mechanisms to improve security monitoring effectiveness.
Why it matters: Security teams responsible for LDAP monitoring and threat detection need to understand OID transformation issues to ensure their detection rules function correctly and catch actual threats.
- vulnerabilitiesCVE-2025-8110
Gogs 0-Day Exploited in the Wild
Wiz Threat Research detected active exploitation of CVE-2025-8110 affecting Gogs, a self-hosted Git service. The vulnerability is being actively targeted by threat actors in production environments.
Why it matters: Organizations running Gogs instances need to assess exposure immediately, as this zero-day is under active attack and patches or workarounds should be deployed without delay.
- regulatory
CMMC: The Opportunity ($$) and Challenge for MSPs
The Cybersecurity Maturity Model Certification (CMMC) framework creates both operational challenges and potential business opportunities for managed service providers (MSPs). MSPs can position themselves to help defense contractors and their suppliers meet CMMC requirements while generating new revenue streams.
Why it matters: MSPs serving the defense industrial base need to understand CMMC compliance obligations and market positioning, as CMMC will become a mandatory requirement for Department of Defense (DoD) contractors and subcontractors.
- vulnerabilitiesCVE-2025-55182
PeerBlight Linux Backdoor Exploits React2Shell CVE-2025-55182
Huntress researchers have identified threat actors actively exploiting a React2Shell vulnerability (CVE-2025-55182) to install a Linux backdoor, reverse proxy tunnel, and Go-based post-exploitation implant on victim systems.
Why it matters: Linux administrators and organizations running React2Shell should prioritize patching CVE-2025-55182 immediately, as active exploitation is already occurring in the wild with full post-exploitation capabilities being deployed.
- cloud saas
Code to Cloud Attacks: From Github PAT to Cloud Control Plane
Attackers are exploiting compromised GitHub Personal Access Tokens (PATs) from employees to gain unauthorized access to cloud environments and control planes. This attack chain bridges code repositories to cloud infrastructure by leveraging the permissions granted to developer credentials. The technique demonstrates how initial access through development tools can escalate to cloud resource compromise.
Why it matters: Development teams and cloud infrastructure owners need to monitor for unauthorized token usage and implement least-privilege access controls on PATs, as compromised developer credentials create a direct path to cloud control plane access.
- industry
Announcing the Latest Report on Huntress Managed SAT | Huntress
Huntress released an independent report examining how its Managed Security Awareness Training (SAT) approach drives actual behavioral change in security culture. The report provides insights into effective methods for building stronger security awareness within organizations.
Why it matters: Security practitioners evaluating awareness training programs should review this report to understand evidence-based approaches that demonstrably improve employee security behavior and reduce human-driven risk.
- threat intel
AI-Poisoning & AMOS Stealer: The Biggest Mac Threat | Huntress
Attackers are using artificial intelligence and search engine optimization techniques to distribute an updated version of Atomic macOS Stealer, a malware designed to steal information from Apple devices. The campaign leverages social engineering to bypass traditional security controls, representing an evolving threat to macOS users.
Why it matters: macOS users and IT teams need to recognize that legitimate-looking AI-related downloads from search results can deliver infostealer malware that circumvents network defenses, requiring heightened scrutiny of application sources and user security awareness.
- cloud saas
Top AWS re:Invent Announcements for Security Teams in 2025
AWS re:Invent 2025 included several announcements relevant to security teams, though the specific technical details were not provided in the source material. Security practitioners should review the full announcements to determine which services and capabilities align with their organization's security posture and operational needs.
Why it matters: Security teams relying on AWS need to evaluate new security features and services announced at re:Invent to plan updates to their infrastructure and policies in the coming year.
- ransomware
Hardening the Hypervisor | Huntress
Hypervisors are frequently targeted in ransomware attacks, making their security critical for protecting virtualized infrastructure. Huntress provides guidance on securing hypervisor environments through access controls, runtime protections, patching strategies, and recovery planning.
Why it matters: Infrastructure teams and security practitioners responsible for virtual environments need to prioritize hypervisor hardening to prevent ransomware actors from compromising the foundation of their IT systems and all hosted workloads.
- vulnerabilities
Cybersecurity industry overreacts to React vulnerability, starts panic, burns own house down again
CVE-2025-55182 affects React v19 with React Server Components enabled, a relatively new and niche configuration used by a minority of organizations. The security industry has generated widespread panic and false proofs of concept, with some vendors like Cloudflare implementing hasty patches that caused significant outages, despite the vulnerability having a narrow attack surface and straightforward mitigation path.
Why it matters: Most organizations running older React versions or without Server Components are not vulnerable; practitioners should verify their actual exposure with developers before taking reactive measures, as premature patching based on industry hype can introduce greater operational risk than the vulnerability itself.
- vulnerabilitiesCVE-2025-55182
CVE-2025-55182 (React2Shell) Opportunistic Exploitation In The Wild: What The GreyNoise Observation Grid Is Seeing So Far
GreyNoise has detected opportunistic exploitation attempts targeting CVE-2025-55182, a remote code execution vulnerability in React Server Components Flight protocol, with attacks appearing largely automated and widespread in early stages of disclosure.
Why it matters: Development teams using React Server Components Flight are immediately at risk from automated attack campaigns; organizations should prioritize patching and monitoring for exploitation attempts.
- threat intel
Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks
Russian threat actor UTA0355 is conducting sophisticated phishing campaigns that impersonate legitimate European security conferences, including the Belgrade Security Conference and Brussels Indo-Pacific Dialogue, to compromise Microsoft 365 and Google accounts. The attacks combine rapport-building via email and messaging apps, fake professional websites, and abuse of Microsoft OAuth and Device Code authentication workflows to steal credentials. Victims are socially engineered to grant unauthorized account access after being primed through fake event registrations and multi-channel communication.
Why it matters: Security teams managing Microsoft 365 and Google environments need to implement OAuth phishing defenses and authentication hardening immediately, as employees attending legitimate international events are being actively targeted with credential harvesting campaigns using legitimate conference details.
- threat intel
A Hidden Pattern Within Months of Credential-Based Attacks Against Palo Alto GlobalProtect
GreyNoise observed over 7,000 IP addresses attempting to log into Palo Alto GlobalProtect, with attack signatures matching earlier SonicWall API scanning and previous Palo Alto campaigns. The incidents indicate a sustained pattern of credential-based attacks spanning several months against these security vendors' products.
Why it matters: Security teams running GlobalProtect or other Palo Alto products need to monitor for unauthorized login attempts and review access logs immediately, as this represents an active, widespread credential attack campaign.
- vulnerabilitiesCVE-2025-55182
React2Shell (CVE-2025-55182): Everything You Need to Know About the Critical React Vulnerability
CVE-2025-55182, known as React2Shell, is a critical remote code execution vulnerability affecting React and Next.js applications that has been observed in active exploitation. Organizations using these frameworks should prioritize patching to prevent compromise.
Why it matters: Development teams and application owners running React or Next.js in production face immediate risk of remote code execution; patching should be treated as urgent.
- threat intel
What Does the Dark Web Look Like? Pulling Back the Curtain | Huntress
This article provides an overview of the dark web's structure, characteristics, and content, along with information on how to access it. The piece frames the exploration as educational and conducted from a safe distance.
Why it matters: Security practitioners need foundational knowledge of dark web architecture and common services to understand threat actor communication channels, data leak sites, and malware distribution networks relevant to incident response and threat hunting.
- cloud saas
Wiz Product Announcements at re:Invent 2025: Expanding Visibility from Code to Cloud
Wiz announced new product capabilities at AWS re:Invent 2025 designed to enhance visibility and collaboration between security and engineering teams across cloud environments. The announcements focus on expanding monitoring and management from code to cloud infrastructure.
Why it matters: Cloud security practitioners should evaluate whether these tools improve their ability to detect and remediate risks across development and production environments in AWS and multi-cloud setups.
- threat intel
Velociraptor Misuse, Pt. II: The Eye of the Storm
Huntress has identified an increase in threat actors misusing Velociraptor, an open-source digital forensics and incident response tool, in attacks that exploit WSUS (Windows Server Update Services) and VS Code tunnels. The trend suggests adversaries are leveraging legitimate security tools to evade detection during post-compromise activities.
Why it matters: Security teams and defenders need to monitor for Velociraptor abuse in their environments, especially in conjunction with WSUS and development tool exploitation, as this represents a shift in attacker tradecraft toward living-off-the-land techniques.
- vulnerabilities
Small numbers of Notepad++ users reporting security woes
A small number of organizations, primarily with East Asia interests, have experienced security incidents where Notepad++ processes appear to have provided initial access to threat actors. The issue stems from potential interception of the Notepad++ updater (GUP) traffic at the ISP level, allowing attackers to redirect downloads to malicious payloads, though the exact attack chain remains unclear. Notepad++ version 8.8.8 addresses this by forcing downloads through GitHub, which is more difficult to intercept covertly.
Why it matters: Security teams managing Notepad++ deployments should monitor for suspicious GUP process behavior and ensure systems are running version 8.8.8 or later, especially if operating in or connecting to East Asia where this targeted activity has been observed.
- cloud saas
Introducing Wiz SAST: Where Code Risk Meets Cloud Context
Wiz announced a static application security testing (SAST) tool that integrates code vulnerability detection with cloud infrastructure context. The solution correlates code flaws with deployment environment details including workload location, access permissions, and exposure risk.
Why it matters: Development and security teams need to evaluate whether this SAST offering improves their ability to prioritize code risks based on actual cloud blast radius and access scope.
- cloud saas
Wiz Becomes Fastest Security ISV to Reach $1 Billion in AWS Marketplace Lifetime Sales
Wiz, a cloud security software vendor, has become the fastest independent software vendor to reach $1 billion in lifetime sales through the AWS Marketplace. The achievement reflects customer adoption of the platform and the strength of Wiz's partnership with AWS.
Why it matters: Cloud security buyers should understand that Wiz's marketplace dominance indicates broad market validation of its cloud posture management approach, which may influence vendor selection for organizations building AWS security strategies.
- industry
It's Here! Wiz Exposure Management is Now GA
Wiz announced the general availability of its exposure management platform, which includes updated vulnerability management and attack surface management capabilities. The platform moves beyond traditional CVE counting toward comprehensive exposure assessment across environments.
Why it matters: Security teams evaluating vulnerability and exposure management tools should review Wiz's GA feature set to determine fit for their asset discovery, prioritization, and remediation workflows.
- identity access
Datacenter Infrastructure & Identity Attacks
A new detection system using Autonomous System (AS) based analysis has been developed to identify a previously overlooked dimension of identity attacks beyond location and VPN-based indicators. The system addresses a visibility gap in understanding the full origin and path of identity-based threats targeting datacenter infrastructure.
Why it matters: Security teams responsible for identity and access controls need this detection approach to close gaps in their threat visibility and better defend against attacks that bypass traditional location and VPN monitoring.
- research
What Is Cyber Threat Hunting? Types, Tricks, and Tips | Huntress
Cyber threat hunting is a proactive security practice where analysts search for indicators of compromise and malicious activity within networks rather than waiting for alerts. The practice involves specific strategies, methodologies, and skill sets that differentiate it from routine monitoring and incident response.
Why it matters: Security teams should understand threat hunting fundamentals to strengthen detection capabilities, reduce dwell time for attackers, and move from reactive to proactive security postures.
- identity access
What Is Account Takeover Fraud? A Comprehensive Guide | Huntress
Account takeover fraud occurs when attackers steal login credentials to gain unauthorized access to accounts. The article provides guidance on detection and prevention techniques for this threat vector. Organizations need to understand the attack mechanisms and implement protective measures to mitigate risk.
Why it matters: Security practitioners must understand account takeover fraud to protect user accounts and organizational assets, as compromised credentials enable attackers to access sensitive data, conduct lateral movement, or establish persistence in systems.
- ransomware
Building Cyber Resiliency in Today’s Chaotic Business Environment
The article discusses cyber resiliency in the context of modern threats including AI-driven attacks, supply chain vulnerabilities, and ransomware that can disrupt operations at scale. It emphasizes the importance of building organizational resilience to withstand and recover from cyber incidents in an increasingly complex threat environment.
Why it matters: All organizations face evolving attack vectors and should evaluate their ability to detect, respond to, and recover from cyber incidents before the next major incident occurs.
- breaches incidents
Shai-Hulud 2.0 Aftermath: Trends, Victimology and Impact
Shai-Hulud 2.0 was a supply chain attack that compromised multiple victims. The analysis examines how the infection spread, identifies affected organizations, tracks how leaked information was distributed, and documents community reactions to the incident.
Why it matters: Organizations using affected supply chain components face potential compromise and data exposure; practitioners need to assess whether their software dependencies were impacted and review incident response logs for indicators of the malware.
- cloud saas
Service Catalog is Here: Expand Risk Visibility for Your Service and Its Dependencies, Simplify Issue Ownership
A service catalog tool has been released to provide security and development teams with a unified view of cloud risks organized by application and its dependencies. The offering aims to clarify risk ownership and improve visibility into how services and their related components are exposed.
Why it matters: Security teams and developers need clear assignment of risk ownership to prioritize remediation; this tool addresses fragmented visibility that typically delays incident response and patch management across interconnected cloud services.
- ai security
WizOS: Powering Secured Image Adoption with AI
WizOS has reached general availability as a tool designed to help organizations reduce Common Vulnerabilities and Exposures (CVEs) and establish a secure foundation using artificial intelligence. The product focuses on secured image adoption to support organizations in building trusted infrastructure.
Why it matters: Security teams responsible for container and image management should evaluate WizOS to understand how it addresses CVE reduction in their build pipelines and whether it fits their vulnerability management workflow.
- cloud saas
3 OAuth TTPs Seen This Month — and How to Detect Them with Entra ID Logs
Recent threat activity has demonstrated three OAuth tactics, techniques, and procedures (TTPs) that attackers use to compromise accounts and access systems. The article explains how to identify these behaviors through Azure Entra ID sign-in logs, JWT fields, and OAuth token artifacts, and provides guidance on converting these signals into detection rules.
Why it matters: Security teams managing Azure Entra ID environments need these detection methods to identify OAuth-based attacks before attackers establish persistence or lateral movement in their networks.
- threat intel
#ShadyHacks with Kyle Hanslovan
Huntress CEO Kyle Hanslovan conducted a live hacking demonstration showcasing modern attack techniques including credential theft, multifactor authentication (MFA) bypass, and Microsoft 365 token hijacking. The session covered both the tactics used by attackers and defensive countermeasures for organizations.
Why it matters: Security teams need to understand these attack chains (credential compromise, MFA bypass, and cloud token theft) to properly prioritize detection and response capabilities in their M365 environments and identity infrastructure.
- ransomware
Why Financial Services Can No Longer Rely on Ransomware Defense Alone: 10 Key Takeaways for CISOs
A Halcyon webinar brought together three cybersecurity experts to discuss how financial services organizations need to shift their approach to ransomware defense in 2025 and beyond, moving beyond traditional ransomware-focused strategies. The discussion covered both tactical and philosophical changes required to address evolving threats in the financial sector.
Why it matters: Financial services CISOs should evaluate whether their current ransomware defenses are sufficient against emerging attack patterns, as the consensus among security leaders indicates a fundamental change in strategy is necessary.
- regulatory
The Boardroom Blind Spot: How CISOs Can Bridge the Cyber Resilience Knowledge Gap
This article addresses the challenge of communicating cybersecurity and resilience concepts to board-level executives who may lack technical expertise. CISOs need strategies to translate complex security issues into business language that resonates with decision-makers and influences budget allocation.
Why it matters: CISOs and security leaders must effectively communicate cyber risks to non-technical boards to secure funding and executive buy-in for resilience programs.
- ransomware
Halcyon Advocates for State and Local Cybersecurity Funding as PILLAR Act Passes House
The Halcyon ransomware recovery company joined industry advocates supporting the PILLAR Act, which passed the House and extends federal funding for state and local cybersecurity initiatives through 2033. The legislation aims to strengthen ransomware protection and resilience for public sector organizations.
Why it matters: State and local government IT staff and security leaders need to track this funding authorization, as expanded federal cybersecurity resources could affect grant availability, compliance requirements, and security investment timelines for their agencies.
- cloud saas
Mastering Software Governance with Hosted Technologies Inventory
Organizations are increasingly adopting inventory management solutions to track and govern software technologies across their environments. These hosted platforms provide centralized visibility to identify governance gaps and improve security posture.
Why it matters: Development and security teams need accurate technology inventories to enforce policies, manage risk, and maintain compliance; adopting these tools reduces the attack surface from unknown or unmanaged assets.
- threat intel
Your IP Address Might Be Someone Else's Problem (And Here's How to Find Out)
GreyNoise has released an IP Check tool that allows users to determine whether their IP address has been flagged for internet scanning activity. The free, privacy-focused service helps home network owners identify if their IP has been involved in reconnaissance or scanning behavior.
Why it matters: Home network operators need to know if their IP is tagged for malicious scanning, as this affects their network's reputation and may indicate compromise, botnet involvement, or upstream network misconfiguration requiring immediate investigation.
- industry
7 Benefits of Outsourcing Cybersecurity Services | Huntress
This article discusses advantages of outsourcing cybersecurity operations, including resource optimization and improved security posture. The piece appears to be vendor content exploring business benefits such as cost efficiency, team focus, and strengthened defenses.
Why it matters: Security leaders evaluating service delivery models should understand outsourcing tradeoffs, though this content is promotional and should be weighed against organizational risk, compliance requirements, and internal capability gaps.
- threat intel
Shai-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposing Secrets
A supply chain attack leveraging malicious npm packages has affected more than 25,000 repositories across approximately 350 users, following the pattern of the original Shai-Hulud campaign. The attack exposes secrets and credentials stored in targeted repositories. Security researchers have identified detection and mitigation strategies for the compromised packages.
Why it matters: Development teams and open-source maintainers must audit their npm dependencies immediately to identify and remove malicious packages before exposed credentials are weaponized against their infrastructure and applications.
- threat intel
ClickFix Gets Creative: Malware Buried in Images
Huntress identified a campaign using ClickFix lures to deliver malware through steganography, with threat actors embedding infostealers such as LummaC2 and Rhadamanthys inside PNG images. The multi-stage attack chain demonstrates evolving evasion techniques to bypass traditional detection methods by hiding malicious payloads in image files.
Why it matters: Security teams and end users need to recognize that ClickFix social engineering remains active and increasingly sophisticated; practitioners should reinforce awareness training and monitor for steganographic indicators of compromise, as image-based malware delivery complicates standard file filtering.
- industry
Get Certified on Wiz Defend for Threat Detection and Response
Wiz, a cloud security platform, is offering a certification program for Wiz Defend that covers cloud threat detection and response capabilities. The certification is targeted at security operations center (SOC) professionals, IT staff, and security practitioners.
Why it matters: SOC and security teams considering Wiz Defend should evaluate this certification to assess whether the training aligns with their detection and response workflows and skill development needs.
- regulatory
What organisations can learn from the record breaking fine over Capita’s ransomware incident
The UK Information Commissioner's Office issued a record £14 million fine to Capita for negligent cybersecurity practices surrounding a Black Basta ransomware incident, citing failures in their Security Operations Center (SOC) operations including unresponded alerts, inadequate staffing, and missed service level agreements. The incident involved initial compromise via Qakbot malware, with critical alerts left unaddressed for over 58 hours, and Capita initially misrepresented the attack to customers as a technical issue rather than a security breach. The decision establishes significant regulatory precedent regarding organizational accountability for preventable cybersecurity failures, even when companies contest the regulator's jurisdiction over internal operational standards.
Why it matters: Security leaders and managed service providers should understand that regulators now hold organizations accountable for internal SOC SLAs and alert response times, regardless of claimed affordability constraints, making documented incident response procedures and staffing adequacy critical to avoid substantial regulatory penalties.
- threat intel
Velociraptor WSUS Exploitation, Pt. I: WSUS-Up?
Huntress has observed an increase in threat actors leveraging Velociraptor, an open-source digital forensics and incident response (DFIR) tool, for various attacks including exploitation of Windows Server Update Services (WSUS). The activity suggests adversaries are repurposing legitimate security tools to conduct offensive operations.
Why it matters: Security teams should monitor for suspicious Velociraptor activity and WSUS exploitation attempts in their environments, as these techniques could indicate post-compromise activity or lateral movement by attackers using legitimate tools to evade detection.
- ransomware
The Quick Guide to Ransomware Resilience
The article provides guidance on building ransomware resilience strategies and defensive measures. It covers practical approaches for organizations to reduce exposure to ransomware threats and improve recovery capabilities.
Why it matters: Security practitioners need actionable ransomware defense strategies to protect their organizations from attacks that disrupt operations and threaten data availability.
- regulatory
Blueprint for Security: A Guide to Code, Governance, and Response Frameworks
This article discusses foundational approaches to security and compliance, covering code practices, governance structures, and incident response frameworks. It provides guidance for organizations seeking to establish or strengthen their security posture across multiple dimensions.
Why it matters: Security practitioners need structured frameworks to prioritize controls, ensure compliance with regulatory requirements, and respond effectively to incidents; this resource helps teams design integrated security programs.
- threat intel
Introducing Query-Based Blocklists: Fully Configurable, Real-Time Threat Blocking in the GreyNoise Platform
GreyNoise announced a feature enabling customers to convert custom queries into real-time blocklists that can be deployed across firewalls, security orchestration and response (SOAR) platforms, and other enforcement mechanisms. The capability allows organizations to dynamically block traffic based on GreyNoise threat intelligence data without manual list management.
Why it matters: Security teams using GreyNoise can now operationalize custom threat intelligence queries directly into blocking infrastructure, reducing latency between threat identification and enforcement.
- vulnerabilities
FortiWeb CVE‑2025‑64446: What We’re Seeing in the Wild
GreyNoise has detected active exploitation of CVE-2025-64446, a critical path-traversal vulnerability in Fortinet FortiWeb that allows unauthenticated attackers to execute administrative commands on affected appliances. The flaw is being actively exploited in the wild against internet-facing FortiWeb instances.
Why it matters: Organizations running FortiWeb appliances face immediate risk from unauthenticated remote code execution attacks; patching or applying mitigations should be prioritized today.
- vulnerabilities
Palo Alto Scanning Surges 40X in 24 Hours, Marking 90-Day High
GreyNoise detected a 40-fold surge in scanning activity targeting Palo Alto Networks GlobalProtect portals starting on November 14, 2025, within a 24-hour period, reaching the highest level observed in the previous 90 days. This escalation indicates increased malicious reconnaissance efforts against the internet-facing authentication gateway. The activity suggests either exploitation attempts following a newly disclosed vulnerability or an organized campaign targeting known Palo Alto deployments.
Why it matters: Organizations running Palo Alto Networks GlobalProtect should immediately review access logs, verify gateway security configurations, and confirm patch status, as the surge indicates active reconnaissance that could precede intrusion attempts.
- industry
Huntress Acquires Inside Agent
Huntress has acquired Inside Agent to expand its security offerings with an identity and access provisioning management (ISPM) solution. The acquisition aims to strengthen Huntress's capabilities in proactive defense against cyberattacks through identity security enhancements.
Why it matters: Security teams using Huntress or evaluating identity security tools should understand that the platform's capabilities and roadmap have shifted with this ISPM addition, affecting deployment planning and vendor consolidation decisions.
- industry
Huntress Lands on the Microsoft Marketplace
Huntress security software is now available on the Microsoft Marketplace, enabling integration with Microsoft 365 and Defender. The offering combines endpoint protection with continuous monitoring at an enterprise-grade level, positioning itself as a cost-effective alternative to traditional security solutions.
Why it matters: Organizations using Microsoft 365 can now more easily evaluate and deploy Huntress for managed threat detection and response without separate procurement processes.
- research
What Should A Modern Cybersecurity Stack Look Like? | Huntress
Huntress discusses the essential components and architecture of a modern cybersecurity stack. The article provides guidance on structuring security defenses and obtaining support from organizational leadership for implementation.
Why it matters: Security practitioners need to understand how to architect comprehensive defense strategies and communicate their value to executives who control budget and resource allocation.
- threat intel
When Bulletproof Hosting Proves Bulletproof: The Stark Industries Shell Game
Stark Industries, an entity subject to EU sanctions in May 2025, rebranded to THE.Hosting and continued operating malicious infrastructure according to GreyNoise data. The rebranding allowed the group to evade enforcement actions and maintain its operations under a new identity.
Why it matters: Organizations and law enforcement tracking sanctions evasion should monitor infrastructure rebranding patterns, as threat actors are demonstrating they can quickly circumvent legal pressures and continue operations.
- industry
Google Unified Security Recommended Program Names Wiz Among First 3 Strategic Partners
Google announced its Unified Security Recommended Program, naming Wiz as one of the first three strategic partners. The program aims to create an open, unified security ecosystem through strategic partnerships.
Why it matters: Organizations evaluating security tools and partnerships should monitor Google's recommended vendor list, as it signals trusted integrations and interoperability with Google Cloud and other Google security products.
- ransomware
Threats Plague Educational Organizations
Threat actors are conducting multiple attack campaigns against educational institutions, including data breaches, phishing, ransomware deployments, and brute force attacks on remote access systems. The education sector faces persistent multi-vector threats that span credential compromise to full system encryption.
Why it matters: School administrators, IT staff, and security teams at educational organizations must prioritize RDP hardening, email filtering, backup strategies, and staff security awareness training to defend against active threats targeting their networks and sensitive student and staff data.
- vulnerabilities
Introducing Posture Issues: Transform Security Findings into Actionable Outcomes
A tool or service announced that organizes vulnerability findings, exposed secrets, and data-related security issues into a unified framework called Posture Issues to help teams prioritize and address security backlogs more efficiently.
Why it matters: Security teams managing large backlogs of disparate findings need consolidated visibility and prioritization mechanisms to focus remediation efforts on the most critical issues first.
- industry
Empower and Accelerate Your SOC with the Blue Agent
Wiz has released the Blue Agent, an AI-powered tool designed to accelerate threat triage and investigation within security operations centers. The platform aims to help analysts process security threats more quickly while maintaining visibility into the triage process.
Why it matters: SOC teams and security operations practitioners should evaluate whether AI-assisted threat triage can reduce investigation time and improve alert handling efficiency in their environments.
- ai security
Exposure Report: 65% of Leading AI Companies Found with Verified Secret Leaks
A security analysis scanned leading private artificial intelligence (AI) companies and identified verified secret leaks in 65 percent of them. The report presents findings from the researchers' disclosure efforts to affected organizations.
Why it matters: Security practitioners and AI company stakeholders need to understand the prevalence of credential exposure in AI vendors, as compromised secrets could enable unauthorized access to critical AI infrastructure and datasets.
- identity access
MFA for Business: Benefits, Methods & Why It Still Matters
This article discusses multi-factor authentication (MFA) for business environments, covering its benefits, implementation methods, and practical deployment considerations. It positions MFA as a highly effective security control while acknowledging it has limitations.
Why it matters: Security practitioners should understand MFA deployment options and benefits to drive adoption across their organizations, as MFA remains one of the most effective defenses against account compromise and unauthorized access.
- ransomware
Ransomware Resilience: Lessons Learned for Protection Today
The article appears to be empty or contains no substantive content to summarize.
Why it matters: Without article content, practitioners cannot assess what ransomware resilience lessons or protection strategies are relevant to their organization's incident response and recovery planning.
- research
Deobfuscating Files for Flags: Huntress CTF 2025 Retro
Huntress held its 2025 Capture the Flag (CTF) competition, attracting over 11,000 participants. The article covers competition winners and key insights from the event.
Why it matters: Security practitioners should review CTF competition results and technical insights to assess emerging skill levels, common vulnerabilities exploited, and gaps in defensive knowledge within the broader security community.
- ransomware
Gootloader | Threat Detection Overview
Gootloader malware has resumed activity with enhanced obfuscation methods, including custom WOFF2 fonts and modified persistence techniques, while maintaining its collaboration with the Vanilla Tempest group for ransomware distribution. The campaign demonstrates evolving evasion capabilities as the threat adapts to detection measures.
Why it matters: Organizations running Windows endpoints are at direct risk from Gootloader's improved evasion techniques, which could allow initial compromise followed by ransomware deployment; practitioners should review detection rules and employee security awareness around malware delivery vectors.
- regulatory
Huntress and DEFCERT Are Streamlining CMMC Assessment Prep
Huntress and DEFCERT have partnered to assist organizations with Cybersecurity Maturity Model Certification (CMMC) compliance. They offer a Shared Responsibility Matrix and operational plans designed to streamline the preparation process for Level 2 assessments.
Why it matters: Defense contractors and vendors subject to CMMC requirements need to demonstrate compliance; this partnership provides tools and guidance to reduce assessment complexity and cost.
- research
What GreyNoise Learned from Deploying MCP Honeypots
GreyNoise deployed honeypots mimicking Model Context Protocol (MCP) middleware to observe attacker behavior against this emerging AI infrastructure layer. The research provides insights into how adversaries interact with and potentially exploit AI middleware when exposed to the internet.
Why it matters: Security practitioners deploying MCP or similar AI middleware need to understand real-world attack patterns and misconfigurations that expose these systems, since GreyNoise's findings highlight actual threat behaviors against production-relevant infrastructure.
- cloud saas
Wizdom 2025 Product Announcements: Extending the Cloud Operating Model
Wizdom announced new AI agents and product innovations at its 2025 conference designed to expand visibility and security across cloud environments, SaaS applications, workloads, AI infrastructure, and external exposures. The updates aim to help teams secure their cloud deployments and on-premises systems through extended monitoring and intelligence capabilities.
Why it matters: Cloud and infrastructure teams need to evaluate whether these new agents improve their visibility into SaaS, workload, and AI infrastructure security gaps to prioritize remediation efforts.
- ai security
When AI Becomes the Heart of Security: Powering a Future You Can Trust
This article discusses the role of artificial intelligence in enhancing security operations and decision-making processes. It emphasizes how AI capabilities can improve visibility, judgment, and safe operational outcomes for security teams.
Why it matters: Security practitioners should understand how AI integration into their tools and workflows can improve detection accuracy, reduce response times, and strengthen overall security posture.
- ai security
AI-Powered Wiz: From Agents to Everyday Intelligence
Wiz has introduced AI-powered agents and integrations designed to enhance security workflows by embedding intelligence directly into existing tools and processes. The announcement focuses on making AI capabilities more accessible within the environments where security teams already operate.
Why it matters: Security practitioners should evaluate whether Wiz's AI agents reduce operational friction and improve detection or response times in their cloud security posture management workflows.
- cloud saas
Defend Agentless Workload Detection: Bringing Visibility to Blind Spots in Threat Detection
An article discusses agentless workload detection as a method for improving visibility into environments and addressing gaps in threat detection capabilities.
Why it matters: Security teams managing cloud and on-premise workloads need better visibility into unmonitored assets to reduce the risk of missed threats and compromised systems going undetected.
- ai security
Securing AI Agents with Wiz AI-SPM
Wiz has announced AI-SPM (AI Security Posture Management), a platform designed to provide visibility and continuous monitoring for AI agents deployed in enterprise environments. The offering addresses security gaps in intelligent automation systems by combining contextual threat detection with ongoing defense mechanisms.
Why it matters: Security teams evaluating AI agent deployments need tools to identify and remediate misconfigurations and exposures before attackers exploit them in production environments.
- identity access
Live Hacking Into Microsoft 365 with Kyle Hanslovan
A live demonstration showcases techniques used by cybercriminals to bypass multi-factor authentication (MFA) in Microsoft 365 and steal credentials. The session covers attack methods and corresponding defense strategies to protect organizational systems.
Why it matters: Security practitioners need to understand MFA bypass techniques targeting Microsoft 365 to properly configure defenses and detect credential theft attempts in their environments.
- threat intel
PHP Cryptomining Campaign: October/November 2025
Between August and October 2025, GreyNoise detected increased exploitation attempts targeting PHP and PHP-based frameworks, with attackers deploying cryptominers to take advantage of rising Bitcoin prices and improved mining economics.
Why it matters: Organizations running PHP applications face active cryptomining threats that consume resources and degrade performance; practitioners should audit PHP deployments for unauthorized process execution and implement runtime monitoring.
- ransomware
CyberSlop — meet the new threat actor, MIT and Safe Security
MIT and Safe Security released a research paper claiming 80% of ransomware attacks use generative AI, which security researchers have criticized as methodologically unsound and lacking credible evidence. The paper was widely circulated before being removed from MIT's website without notice, though copies persist on Internet Archive and were cited by major publications like the Financial Times. The incident highlights how trusted institutions can spread unsubstantiated claims about AI threats, termed 'cyberslop' by critics, potentially misleading security practitioners and organizations.
Why it matters: Security practitioners should be skeptical of widely-cited research on generative AI threats in ransomware operations, as this case demonstrates that even institutional sources can propagate claims without rigorous evidence, potentially misdirecting defensive priorities and resources.
- industry
Introducing Wiz ASM: Context-Driven Attack Surface Management
Wiz has released a new Attack Surface Scanner product designed to identify and contextualize exposures across infrastructure while providing ownership details and prioritization guidance. The tool aims to help organizations understand and manage their external attack surface more effectively.
Why it matters: Security teams using Wiz or evaluating attack surface management tools should understand this new capability for inventory and prioritization of external exposures across cloud and on-premises environments.
- ransomware
Halcyon: Ransomware and Data Extortion Business Risk Report
Halcyon released a 2024 report on ransomware and data extortion risks aimed at security leaders. The report assesses the business impact and threat landscape of these attacks on organizations.
Why it matters: CISOs and CSOs need current risk assessments to prioritize defenses against ransomware and extortion campaigns that threaten operational continuity and financial exposure.
- ransomware
Halcyon Threat Insights 006: June 2024 Ransomware Report
Halcyon released a June 2024 ransomware report analyzing threat activity and trends during that period. The report provides insights into ransomware campaigns, affected sectors, and attacker behavior documented in the first half of 2024.
Why it matters: Security practitioners need current ransomware threat intelligence to assess their organization's exposure, prioritize defenses against active threat groups, and understand which industries are being targeted.
- ransomware
Whitepaper: What CFOs Should Know about Ransomware
A whitepaper addresses ransomware considerations specifically for chief financial officers, covering financial and operational impacts of such attacks. The document aims to help CFOs understand ransomware risks and their role in organizational response and recovery.
Why it matters: CFOs and finance teams need to understand ransomware's direct impact on budgets, insurance, and recovery costs to support informed business continuity and incident response decisions.
- ransomware
Report: Ransomware Command-and-Control Providers Unmasked by Halcyon Researchers
Halcyon researchers have identified and analyzed ransomware command-and-control (C2) infrastructure providers that support threat actors. The research uncovers how these specialized services enable ransomware operations by providing the technical backbone for attackers to manage campaigns and communicate with compromised systems.
Why it matters: Security teams and incident responders need to understand the C2 provider ecosystem to better identify, block, and disrupt ransomware infrastructure during investigations and threat hunts.
- ransomware
Ransomware Roundup: 08.28.23
The article appears to be a ransomware roundup dated August 28, 2023, but contains no content to summarize.
Why it matters: Without article content, practitioners cannot determine which ransomware groups, incidents, or threat trends are relevant to their environment or require immediate response.
- ransomware
Power Rankings: Halcyon Ransomware Malicious Quartile Q2-2024
Halcyon released its quarterly ransomware ranking report covering the second quarter of 2024, analyzing ransomware groups and their activities during that period. The report tracks malicious actors and their relative threat levels during the quarter.
Why it matters: Security teams monitoring ransomware threats should review this quarterly threat ranking to understand which groups are most active and pose the greatest risk to their organization.
- ransomware
Last Week in Ransomware: 09.09.2024
RansomHub claimed responsibility for exfiltrating sensitive data from Planned Parenthood. A new Linux variant of Cicada3301 ransomware emerged, and reporting indicated that some organizations who paid ransoms experienced multiple subsequent attacks.
Why it matters: Healthcare and social services organizations face active ransomware threats with both data theft and operational risks; practitioners should review backup strategies and ransomware incident response plans.
- ot ics
Securing Critical Infrastructure in the Cloud Era: A Policy and Technology Blueprint
This article discusses strategies for securing critical infrastructure in cloud environments, addressing the intersection of policy frameworks and technological implementations needed in modern deployments. The piece presents a blueprint for organizations managing critical systems as they transition toward cloud-based architectures.
Why it matters: Infrastructure operators and security leaders responsible for critical systems need to understand how policy and technology converge to protect essential services from evolving cloud-based threats.
- industry
How CISOs Should Plan Security Budgets for 2026
A new CISO survey and guidance article outlines budget planning strategies for 2026 security investments. The piece emphasizes using data-driven approaches and return on investment (ROI) metrics rather than intuition when allocating security resources.
Why it matters: CISOs and security leaders need actionable budget frameworks to justify spending and align security initiatives with business priorities in the coming year.
- ransomware
Turning the Tide Against Ransomware: How Halcyon Detects, Disrupts, and Defeats Modern Attacks
Halcyon provides a ransomware resilience platform that focuses on detecting, disrupting, and defeating modern ransomware attacks to enable rapid recovery. The company emphasizes a multi-stage approach to ransomware defense rather than prevention alone.
Why it matters: Organizations managing ransomware risk should evaluate whether Halcyon's detection and disruption capabilities address their recovery time objectives and incident response gaps.
- identity access
What Is the Zero Trust Security Model? | Huntress
Zero Trust Security is a framework that requires continuous verification of users and systems rather than trusting based on network location or initial authentication. The model operates on the principle that no user, device, or connection should be automatically trusted and implements verification at every access point to reduce attack surface and lateral movement risks.
Why it matters: Security practitioners should understand Zero Trust principles to evaluate and redesign access controls, as this approach significantly limits the impact of breaches by eliminating the assumption of trust that attackers exploit once inside a network.
- regulatory
Beyond the Checkbox: How Wiz Transforms SOC 2 into a Security Powerhouse
Wiz presents an approach to SOC 2 compliance that moves beyond static audit checkpoints toward continuous security validation and monitoring. The strategy emphasizes treating compliance as an ongoing security practice rather than a periodic checkbox exercise.
Why it matters: Security teams and compliance managers need to understand how continuous compliance monitoring reduces audit friction and maintains control effectiveness between formal assessments.
- cloud saas
Bringing Visibility to Kubernetes: Unified Inventory and Network Insight
The article discusses improved visibility solutions for Kubernetes environments that consolidate inventory data and network information across multiple clusters, enabling better collaboration between platform operations and security teams.
Why it matters: Security practitioners managing Kubernetes deployments need unified visibility to identify misconfigurations, lateral movement risks, and unauthorized network activity across clustered environments.
- vulnerabilitiesCVE-2025-59287
Exploitation of Windows Server Update Services Remote Code | Huntress
Threat actors are actively exploiting CVE-2025-59287, a remote code execution vulnerability in Microsoft Windows Server Update Services (WSUS), according to Huntress observations. WSUS is a critical Windows infrastructure component used by organizations to manage and deploy security updates across their systems.
Why it matters: Organizations running WSUS are at immediate risk of remote code execution and should prioritize patching this vulnerability and monitoring their WSUS deployments for signs of exploitation, as attackers are actively weaponizing this flaw.
- threat intel
We Got Yelled At by Amazon So You Didn’t Have To
GreyNoise operates sensors that absorb attacker traffic to gather threat intelligence and share findings with the security community. The company positions its approach as a way to help other organizations avoid direct exposure to reconnaissance and attack attempts.
Why it matters: Security teams benefit from threat intelligence derived from honeypot and sensor data, which can improve detection and response capabilities without the organization bearing the cost of absorbing malicious traffic directly.
- cloud saas
Microsoft builds on Recall with Gaming Copilot — fails basic privacy tests
Microsoft is rolling out Gaming Copilot on Windows 11, a feature that uses AI vision technology similar to Recall to capture screenshots of gameplay and send them to Microsoft servers for analysis and model training. The feature installs silently without onboarding, privacy configuration options, or clear documentation, and continues to send network traffic even when the UI is disabled.
Why it matters: Windows 11 users face undisclosed data collection and cloud transmission of gameplay content without explicit consent, creating potential privacy compliance issues and a new attack surface that security practitioners need to understand and address in their environments.
- industry
GreyNoise Welcomes New Director of Intelligence, Nishawn Smagh
GreyNoise has appointed Nishawn Smagh as Director of Intelligence to serve as a principal liaison between the company and government and enterprise partners. In this role, Smagh will help organizations detect, understand, and respond to cyber threats using GreyNoise's threat intelligence capabilities.
Why it matters: Security teams and government agencies using GreyNoise should be aware of leadership changes that may affect service delivery, support quality, and the company's strategic direction on threat intelligence offerings.
- ransomware
Looking Through a Pinhole at a Qilin Ransomware Attack
This article provides guidance on analyzing Qilin ransomware attacks, focusing on techniques for confirming commands, validating findings, and assessing actual impact during an incident. It is framed as an educational resource for security professionals new to incident analysis and response.
Why it matters: Security teams responding to Qilin ransomware attacks need practical methods to validate their findings and understand true business impact during active incidents to prioritize containment and recovery efforts.
- threat intel
Dealing with Imperfect Telemetry
Huntress Tactical Response team discusses practical approaches to conducting security investigations when telemetry is incomplete or degraded. The article covers real-world techniques for handling missing logs, degraded telemetry, and cloud logging challenges to extract useful intelligence from imperfect data.
Why it matters: Security practitioners dealing with incomplete or unreliable log data need effective investigative techniques to maintain visibility and respond to incidents despite telemetry gaps.
- threat intel
Threat Actors Deploying New IPs Daily to Attack Microsoft RDP
Threat actors are rotating through new IP addresses daily to attack Microsoft Remote Desktop Protocol (RDP) services, focusing on timing vulnerabilities in Remote Desktop (RD) Web Access and RDP login enumeration techniques. The rotating IP strategy allows attackers to evade detection systems that rely on blocking known malicious addresses.
Why it matters: Organizations running exposed RDP services face active enumeration and compromise attempts from adversaries using evasion tactics; practitioners should review RDP exposure, enforce multi-factor authentication, and monitor for brute force patterns across changing source IPs.
- cloud saas
The Foundation Modern AppSec Is Still Missing: Code to Cloud, Rebuilt the Right Way
An article discusses the need for comprehensive visibility and traceability in application security, spanning from code development through production deployment. The piece emphasizes automatic tracking mechanisms that eliminate manual workarounds and resource tagging limitations, enabling both developers and security teams to identify and respond to risks.
Why it matters: Development and security teams need reliable, automated traceability from code to production to reduce blind spots and operational overhead in identifying and remediating risks across the application lifecycle.
- ransomware
Dispelling Ransomware Deployment Myths
Huntress released an analysis of ransomware activity patterns and detection opportunities, examining common misconceptions about how ransomware attacks are deployed and executed.
Why it matters: Security teams benefit from accurate ransomware threat intelligence to improve detection capabilities and prioritize defensive investments based on real attack patterns rather than incorrect assumptions.
- vulnerabilities
Dismantling a Critical Supply Chain Risk in VSCode Extension Marketplaces
Wiz Research identified over 550 secrets exposed in Visual Studio Code (VSCode) extension marketplaces and coordinated with Microsoft to remediate the issue. The exposure represented a significant supply chain vulnerability where sensitive credentials could be discovered and exploited by threat actors.
Why it matters: Developers relying on VSCode extensions face supply chain compromise risk if exposed secrets in the marketplace enable attackers to access infrastructure or inject malicious code into the extension ecosystem.
- threat intel
The Crown Prince, Nezha | Huntress
Huntress has identified a previously unreported tool called Nezha being deployed since mid-2025 to compromise web servers, often used alongside Ghost RAT and AntSword for malware and web shell management.
Why it matters: Organizations running web servers need to monitor for Nezha indicators of compromise and review access logs for signs of web shell deployment, as this tool facilitates persistent server access.
- vulnerabilities
Active Exploitation of Gladinet CentreStack and Triofox | Huntress
Huntress has discovered active in-the-wild exploitation of a Local File Inclusion vulnerability affecting Gladinet CentreStack and Triofox products. The vulnerability allows attackers to access files on affected systems without authorization. Organizations running these products face immediate risk from active threat actors.
Why it matters: Operators of CentreStack and Triofox deployments need to patch or mitigate this vulnerability immediately, as exploit code is actively being used in attacks.
- threat intel
GreyNoise’s Recent Observations Around F5
GreyNoise has released threat intelligence observations about activity targeting F5 BIG-IP systems following a security incident announced on October 15, 2025. The intelligence sharing aims to help organizations strengthen their defensive measures against attacks exploiting the BIG-IP vulnerability.
Why it matters: Organizations running F5 BIG-IP load balancers need to review GreyNoise's findings immediately to understand the threat landscape and prioritize patching and defensive actions.
- ransomware
Code Blue: Ransomware Lessons from the Healthcare Front Line
Ransomware attacks on healthcare providers are characterized as a public health crisis rather than merely a technology problem, highlighting the systemic impact on patient care and safety.
Why it matters: Healthcare administrators and security leaders need to prioritize ransomware defenses because attacks directly disrupt clinical operations, patient access to records, and care delivery—creating life-safety implications beyond typical data breaches.
- research
How to Offend Your IT Team: Cybersecurity Tips
This article provides guidance on common cybersecurity mistakes and practical recommendations for improving security behaviors. It appears aimed at helping individuals avoid actions that create problems for IT teams and security staff.
Why it matters: All practitioners need reminders on hygiene and user behavior, as human error remains a leading cause of security incidents and IT operational friction.
- industry
Introducing GreyNoise Block: Fully configurable, real-time blocklists
GreyNoise Block is a new offering that provides real-time, configurable IP blocklists based on primary-sourced intelligence designed to reduce false positives compared to traditional blocklist approaches. The service allows organizations to customize blocking rules rather than apply generic, one-size-fits-all lists.
Why it matters: Security teams deploying IP-based defenses can now evaluate a customizable blocklist solution that may reduce operational friction from overly broad blocking rules that impact legitimate traffic.
- breaches incidents
Huntress Threat Advisory: Widespread SonicWall SSLVPN Compromise
Huntress has identified an increase in compromises affecting SonicWall SSLVPN (Secure Sockets Layer Virtual Private Network) devices across multiple customer environments. The advisory indicates a widespread pattern of attacks targeting this remote access solution. The company has documented these incidents to alert organizations using this technology.
Why it matters: Organizations running SonicWall SSLVPN need to assess their deployments immediately for signs of compromise, as threat actors are actively exploiting this access point at scale.
- threat intel
100,000+ IP Botnet Launches Coordinated RDP Attack Wave Against US Infrastructure
GreyNoise has tracked a coordinated botnet operation since October 8, 2025 involving over 100,000 unique IP addresses from more than 100 countries targeting Remote Desktop Protocol (RDP) services in the United States. The campaign represents a large-scale, geographically distributed attack infrastructure.
Why it matters: US organizations exposing RDP services need to immediately audit access controls, require multi-factor authentication, and monitor for unauthorized connection attempts, as this active campaign directly targets their infrastructure.
- threat intel
APT Meets GPT: Targeted Operations with Untamed LLMs
Volexity detected a China-aligned threat actor tracked as UTA0388 conducting sophisticated spear phishing campaigns from June 2025 across North America, Asia, and Europe using fabricated identities and multiple languages. The campaigns employed a malware family called GOVERSHELL delivered through archive files with legitimate executables that load malicious payloads via DLL search order hijacking. Evidence suggests UTA0388 leveraged Large Language Models, including OpenAI's ChatGPT, to assist with campaign development and social engineering, with some campaigns involving extended rapport-building email exchanges before malicious links were sent.
Why it matters: Organizations in North America, Asia, and Europe face targeted spear phishing risk from a China-aligned actor using LLM-assisted social engineering and custom malware; practitioners should enhance email security, implement defenses against DLL hijacking, and monitor for GOVERSHELL variants.
- threat intel
Introducing GreyNoise Feeds: Real-Time Intel for Real-Time Response
GreyNoise has launched a new feeds product that delivers threat intelligence through real-time, event-driven updates rather than polling-based methods. The service aims to reduce detection and response latency for new exploits, IP-based threats, and zero-day vulnerabilities.
Why it matters: Security operations teams using GreyNoise intelligence can now respond faster to emerging threats without polling delays, improving their incident response times.
- research
Introducing HoneyBee: How We Automate Honeypot Deployment for Threat Research
A security organization has developed HoneyBee, an automation tool for deploying honeypots to support threat research and cloud security analysis. The tool enables faster, more scalable honeypot deployments to gather attacker intelligence and inform defensive improvements.
Why it matters: Security teams evaluating threat detection and response strategies should consider how automated honeypot infrastructure can reveal attack patterns and validate cloud security controls in their environments.
- research
Ditch Lame Cybersecurity Tips | Huntress
This article discusses updated cybersecurity strategies and practices for protecting organizations against modern threats, moving beyond conventional advice. It emphasizes actionable approaches relevant to current threat landscapes.
Why it matters: Security practitioners need practical, current guidance to strengthen defenses against evolving threat actors rather than relying on outdated recommendations.
- vulnerabilitiesCVE-2025-49844
RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score
Wiz Research has identified a critical remote code execution vulnerability in Redis (CVE-2025-49844) that stems from a bug present for 13 years across all versions of the software. Redis is used in approximately 75% of cloud environments, making this flaw potentially widespread.
Why it matters: Organizations running Redis in production should treat this as urgent: a CVSS 10 remote code execution vulnerability affects a foundational technology in most cloud deployments and requires immediate patching or mitigation.
- industry
Build a Stronger Security Awareness Program with Huntress
Huntress has launched Managed Security Awareness Training, a service intended to help organizations improve their security culture and reduce incidents through employee training. The offering focuses on strengthening an organization's human defenses against security threats.
Why it matters: Security leaders overseeing awareness programs should evaluate whether managed training services can reduce phishing clicks and incident response costs in their environment.
- ransomware
Defending against database ransomware attacks
Attackers target exposed databases to conduct extortion campaigns, leveraging unsecured or misconfigured systems as entry points. Organizations can implement technical and operational controls to detect unauthorized access, monitor database activities, and segment networks to limit lateral movement and data exposure.
Why it matters: Database administrators and security teams need to identify and remediate exposed databases in their environments, as attackers actively exploit them for ransomware and extortion.
- ai security
AI Security 101: Mapping the AI Attack Surface
This article provides a guide to understanding artificial intelligence (AI) security risks, blind spots, and necessary protections for security teams. It addresses the AI attack surface and how organizations can identify and mitigate vulnerabilities in AI systems.
Why it matters: Security practitioners need to understand AI-specific attack surfaces and gaps in their existing defenses to protect AI-enabled systems and data in their environments.
- threat intel
Top Cyber Threat Trends of 2025: Deepfakes, ClickFix & More | Huntress
Huntress security researchers highlight emerging cyber tradecraft trends in 2025, including ClickFix attacks and deepfake-based social engineering. The analysis covers novel attack techniques observed in the threat landscape during the year's early months.
Why it matters: Security practitioners need awareness of ClickFix and deepfake tactics to recognize and block these techniques before they compromise their organizations.
- vulnerabilitiesCVE-2021-43798
Coordinated Grafana Exploitation Attempts on 28 September
GreyNoise detected a coordinated spike in exploitation attempts against CVE-2021-43798, a Grafana path traversal vulnerability that allows arbitrary file reads, on September 28. All attacking IP addresses were classified as malicious.
Why it matters: Organizations running Grafana instances should verify patching status for this vulnerability immediately, as the coordinated attack pattern indicates active exploitation campaigns targeting this known weakness.
- industry
Be Offensive: A bold take on Cybersecurity Awareness Month.
Huntress is launching a new campaign for Cybersecurity Awareness Month that shifts from traditional defensive messaging to an offensive-minded security approach. The initiative represents a departure from the typical awareness messaging deployed over the past two decades.
Why it matters: Security teams and awareness practitioners should evaluate whether this approach changes how they message security culture and engagement to their organizations this year.
- cloud saas
Introducing zeroday.cloud: First-of-its-kind cloud and AI hacking competition
Wiz and major cloud service providers are launching a large-scale hacking competition focused on securing open-source software used in cloud infrastructure. The competition aims to identify and address vulnerabilities in critical components of the cloud ecosystem.
Why it matters: Cloud practitioners and security teams should monitor this competition as it may uncover vulnerabilities in widely deployed open-source software they depend on, potentially leading to patches or workarounds needed in production environments.
- threat intel
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion
A case study documents an intrusion where the Lunar Spider threat actor gained initial access through a single click and maintained presence for approximately two months. The report traces the attacker's progression through execution, persistence, privilege escalation, and lateral movement phases, providing detailed technical analysis and indicators of compromise.
Why it matters: Organizations need to understand how minimal user interaction (a single click) can lead to prolonged dwell time; security teams should review detection capabilities for Lunar Spider tactics and implement controls around initial access vectors and persistence mechanisms.
- cloud saas
Unifying Cloud Risk and Network Defense: Wiz and Check Point
Wiz and Check Point are integrating their security platforms to combine cloud risk management with network defense capabilities. The partnership aims to provide security teams with enriched visibility by correlating cloud security data with network context.
Why it matters: Security teams managing both cloud and network environments benefit from unified threat context and improved posture visibility, reducing manual correlation between separate tools.
- threat intel
ClickFix Attack: Variants, Detection & How It Works | Huntress
ClickFix is a social engineering attack that uses variants such as FileFix, TerminalFix, and DownloadFix to manipulate users into compromising their systems. The article covers how these techniques operate and provides detection strategies using behavioral analytics and chokepoint identification.
Why it matters: Security teams need to understand ClickFix variants to detect and block these attacks before users execute malicious commands or download payloads, reducing compromise risk across the organization.
- ai security
The emerging use of malware invoking AI
Security researchers have identified emerging malware that leverages artificial intelligence capabilities, including LameHug, a compromise affecting the Amazon Q Developer Extension, s1ngularity, and PromptLock. These threats represent a new attack surface where AI tools and models are being weaponized or targeted by adversaries. The findings highlight how development environments and AI-powered applications are becoming vectors for sophisticated malware deployment.
Why it matters: Development teams and organizations using AI-assisted coding tools like Amazon Q Developer face new compromise risks that could lead to supply chain attacks and code injection; practitioners need to evaluate the security posture of AI extensions and implement additional controls in development workflows.
- regulatory
Wiz achieves FedRAMP High authorization
Wiz, a cloud security platform, achieved FedRAMP High authorization, enabling it to serve U.S. federal government agencies and sensitive systems with its commercial security features. FedRAMP High is a rigorous certification that demonstrates the platform meets federal security and compliance requirements. This authorization allows government customers to adopt Wiz for cloud security operations while maintaining compliance with federal standards.
Why it matters: Federal agencies and contractors can now use Wiz for cloud security workloads in high-impact systems, reducing compliance friction and expanding the vendor options available to government IT teams.
- threat intel
A Vietnamese threat actor's shift from PXA Stealer to PureRAT
A Vietnamese threat actor has transitioned from using the PXA Stealer malware to deploying PureRAT, a more sophisticated remote access trojan. This evolution reflects a shift from custom Python-based tools to a .NET-based commodity malware with expanded capabilities.
Why it matters: Organizations tracking Vietnamese threat actors need to update detection signatures and behavioral baselines, as the switch to PureRAT indicates more advanced operational capabilities and persistence techniques that may evade existing defenses.
- cloud saas
Wiz + HCP Terraform: Close the IaC-to-Cloud Infrastructure Security Gap
Wiz has released a generally available connector for HCP Terraform that automatically maps cloud infrastructure risks back to their source code without requiring manual configuration. The tool bridges the gap between infrastructure as code (IaC) and actual cloud deployments by providing visibility into how code changes translate to cloud security exposures.
Why it matters: Cloud and DevOps teams need to understand how IaC misconfigurations propagate to production environments; this connector helps practitioners quickly identify and remediate infrastructure risks at the source.
- research
SAT effectiveness | Huntress
Huntress released a report examining the effectiveness of security awareness training (SAT) and questions whether increased training spending actually reduces human risk. The report suggests there are gaps between training investment and measurable risk reduction, and proposes approaches to improve outcomes.
Why it matters: Security leaders allocating budgets to training programs need to understand whether current SAT spending delivers security outcomes; this report examines that ROI question.
- cloud saas
IMDS Abused: Hunting Rare Behaviors to Uncover Exploits
Security researchers are analyzing abnormal behavior patterns in Instance Metadata Service (IMDS) requests to detect exploitation attempts. By identifying rare query behaviors that deviate from normal application operations, defenders can surface active IMDS-based attacks that would otherwise blend into routine traffic.
Why it matters: Cloud practitioners and blue teams need detection methods for IMDS exploitation because attackers commonly abuse this service to steal credentials in compromised cloud environments, and behavioral hunting can catch attacks that signature-based defenses miss.
- threat intel
How EDR Telemetry Powers Managed Investigations
This article discusses the role of Endpoint Detection and Response (EDR) telemetry in supporting managed investigations and the importance of human-led investigative work in combating modern cyber threats. The piece emphasizes that effective security requires combining automated telemetry collection with creative analytical approaches by security professionals.
Why it matters: Security operations teams need to understand how EDR telemetry enables investigation capabilities and why human expertise remains critical for threat hunting and incident response today.
- cloud saas
Beyond CVEs: The Exploitation of Everyday Misconfigurations
The article examines how configuration errors in everyday systems create exploitable weaknesses for attackers and outlines mitigation strategies teams can implement. Simple setup flaws are a common attack vector that organizations often overlook in favor of patching known vulnerabilities.
Why it matters: Security teams need to prioritize misconfiguration hunting and remediation as part of their vulnerability management program, since these flaws are often easier to exploit than disclosed CVEs and can go undetected across enterprise environments.
- research
Wiz Research Discovers One in Five Organizations Exposed to Systemic Risks in Vibe-Coded Applications - Here's How to Secure Them
Wiz research identified four common security risks affecting vibe-coded applications and released remediation strategies developed with Lovable. The findings indicate that approximately 20 percent of organizations use these applications and face systematic vulnerabilities.
Why it matters: Organizations deploying vibe-coded applications need awareness of these systemic risks and the remediation guidance to reduce their attack surface.
- threat intel
How Malicious Hackers Try to Infiltrate Your IT Team
Threat actors are impersonating IT and cybersecurity professionals to gain system access and exfiltrate sensitive data. Organizations need methods to identify and mitigate these social engineering attacks that exploit trust in internal technical roles.
Why it matters: Security teams must implement verification procedures for IT personnel access requests and educate staff on vetting legitimacy, as attackers using this technique can bypass traditional perimeter defenses.
- threat intel
GreyNoise Intel Now Available Through MCP
GreyNoise has released an MCP (Model Context Protocol) server that allows AI agents to directly access GreyNoise threat intelligence. This integration enables automated security workflows to leverage GreyNoise data for real-time threat analysis and decision-making.
Why it matters: Security practitioners using AI-driven tools can now automate threat intelligence consumption from GreyNoise, reducing manual data lookups and accelerating incident investigation and threat hunting workflows.
- cloud saas
Introducing Wiz Incident Response: Your Expert Partner for Cloud Security Incidents
Wiz has announced a public preview of its new Incident Response service designed to help customers investigate, contain, and resolve cloud security incidents. The offering leverages Wiz's internal incident response expertise to provide guidance and support throughout the incident lifecycle.
Why it matters: Cloud security teams managing active incidents now have access to expert-led incident response capabilities, reducing time-to-resolution and minimizing exposure during breach investigations.
- threat intel
Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware
A supply chain attack dubbed Shai-Hulud compromises over 100 packages by distributing data-stealing malware through package repositories. The threat affects downstream users and organizations consuming these compromised dependencies. Immediate detection and mitigation measures are recommended.
Why it matters: Development teams and organizations using affected packages face data exfiltration risks; prioritize scanning dependencies, identifying compromised versions, and upgrading to patched releases.
- ransomware
The Dangers of Storing Unencrypted Passwords
Threat actors exploited a SonicWall VPN vulnerability to gain initial access, deployed Akira ransomware, and uninstalled Huntress Managed Endpoint Detection and Response (EDR) agents after discovering plaintext recovery codes stored on the compromised systems. The incident demonstrates the risk posed by inadequate credential protection and the importance of secure credential management practices.
Why it matters: Organizations using SonicWall VPN and relying on EDR protection need to audit for unencrypted passwords and recovery codes, patch the VPN vulnerability, and implement defense-in-depth measures to prevent Akira ransomware deployment and agent evasion.
- regulatory
DORA Compliance in the Cloud Era: Insights from Deloitte and Wiz
Deloitte and Wiz provide guidance on managing Digital Operational Resilience Act (DORA) compliance within cloud environments. The resources address practical challenges organizations face when implementing DORA requirements across their cloud infrastructure and services.
Why it matters: EU-regulated financial institutions and their service providers must understand DORA implementation gaps in cloud deployments to avoid regulatory penalties and operational disruption.
- ransomware
Firewall Lockouts: Play Ransomware and SonicWall Exploits
Ransomware groups including Play, Akira, and Qilin are exploiting SonicWall firewalls to gain such complete control that victims are forced to perform hard resets and physically disconnect network equipment. These attacks leverage compromised firewall access to establish persistent footholds and lock defenders out of their own infrastructure.
Why it matters: Organizations using SonicWall firewalls face the risk of complete network compromise and operational disruption; practitioners should review firewall access logs, apply available patches, and verify remote management security settings immediately.
- ai security
How Wiz Customers like Brex and FICO See AI Changing Security
Executives from payment processing company Brex and credit scoring firm FICO discuss how artificial intelligence is transforming their security strategies and operations. The article presents perspectives from industry leaders on the integration of AI technologies into contemporary security practices.
Why it matters: Security leaders evaluating AI tools and vendors should understand how peer organizations in fintech and financial services are deploying AI to inform technology selection and internal strategy.
- ransomware
Emerging Threat Actor: Interlock Ransomware
Interlock is an emerging ransomware group whose operational tactics, tools, and focus on disrupting victim recovery processes closely resemble established threat actors like BlackCat/ALPHV and LockBit. The group appears to be following established ransomware patterns from more established operations.
Why it matters: Organizations need to understand Interlock's operational tactics now because the group's similarity to known ransomware operations suggests it may adopt proven attack chains and extortion methods, requiring updated detection and response playbooks.
- industry
Wiz Recognized as a Leader in the 2025 IDC MarketScape for ASPM
Wiz has been recognized as a leader in the 2025 IDC MarketScape for Application Security Posture Management (ASPM), reflecting its focus on securing modern cloud and AI-native applications.
Why it matters: Security teams evaluating ASPM tools should note Wiz's positioning as a market leader for protecting cloud and AI-native environments.
Widespread npm Supply Chain Attack: Breaking Down Impact & Scope Across Debug, Chalk, and Beyond
A supply chain attack affected widely-used npm packages including debug and chalk, introducing a wallet-hijacking browser interceptor that remained undetected for approximately two hours. The incident achieved near-universal package prevalence with malware present in roughly ten percent of affected installations, and analysis reveals the attack's rapid propagation across the ecosystem.
Why it matters: JavaScript developers and organizations using npm dependencies face immediate exposure to wallet theft and browser interception if they installed affected versions of debug, chalk, or dependent packages during the attack window; urgent dependency audits and updates are required.
- cloud saas
WizOS Is Here: Transforming Container Security from the Image Up
Wiz announced WizOS, a new offering now in public preview that allows customers to deploy and manage secured container images at scale. WizOS addresses container security by focusing on the image layer of containerized applications.
Why it matters: DevOps and security teams using Wiz can now implement hardened container images across their infrastructure, reducing the attack surface in containerized environments that are critical to modern deployments.
- threat intel
An Attacker’s Blunder Gave Us a Look Into Their Operations
A threat actor accidentally installed Huntress endpoint detection software on their own machine, exposing their operational methods including use of AI for workflow automation, searches for phishing tools like Evilginx, and reconnaissance targeting software development companies. This unintended exposure provided security researchers with rare visibility into the attacker's techniques and tooling choices.
Why it matters: Practitioners should understand emerging adversary tactics, particularly AI-driven workflows and phishing infrastructure targeting development firms, to refine detection and threat modeling for their organization.
- ransomware
Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
A digital forensics and incident response analysis documents an intrusion with technical indicators and tactics linking it to three major ransomware gangs. The report traces the attack across initial access, privilege escalation, lateral movement, and exfiltration stages using the MITRE ATT&CK framework and Diamond Model methodology.
Why it matters: Security teams should review the indicators of compromise and detection signatures to identify similar activity in their environments, as the campaign involves established ransomware operators with demonstrated extortion and encryption capabilities.
- cloud saas
From Compromised Keys to Phishing Campaigns: Inside a Cloud Email Service Takeover
Attackers gained access to a cloud email service through compromised credentials and used the compromised infrastructure to launch widespread phishing campaigns. The incident demonstrates how cloud email services are attractive targets for attackers seeking to amplify the reach and credibility of social engineering attacks.
Why it matters: Organizations using cloud email services face risk of account takeover and reputation damage if their credentials are exposed; security teams should audit credential exposure, enforce strong authentication, and monitor email services for unauthorized access and message sending.
- vulnerabilities
25,000 IPs Scanned Cisco ASA Devices — New Vulnerability Potentially Incoming
GreyNoise detected two spikes in scanning activity targeting Cisco Adaptive Security Appliance (ASA) devices in late August, with one surge involving over 25,000 unique IP addresses. This represents a dramatic increase from the typical baseline of fewer than 500 daily scans, suggesting potential reconnaissance before a vulnerability disclosure.
Why it matters: Security teams managing Cisco ASA devices should monitor for imminent vulnerability announcements and prepare patching procedures, as the scanning surge indicates attackers are actively probing these devices and may have exploitation capability ready.
- threat intel
s1ngularity's Aftermath: AI, TTPs, and Impact in the Nx Supply Chain Attack
A technical analysis of the Nx supply chain attack examines how AI-powered malware performed during the incident, quantifies its impact, and documents new tactics, techniques, and procedures (TTPs) discovered. The assessment provides security teams with actionable intelligence for detecting and investigating similar supply chain compromises.
Why it matters: Practitioners using Nx or dependent on Nx-supplied software need to understand the attack mechanics and indicators of compromise to validate their own environments, while defenders studying this incident gain new detection signatures and behavioral patterns for future supply chain threats.
- ransomware
Obscura, an Obscure New Ransomware Variant
Huntress researchers discovered a previously unknown ransomware variant named Obscura deployed on a victim organization's domain controller. The findings suggest an emerging threat in the ransomware landscape that security teams have not yet widely documented or characterized.
Why it matters: Organizations need awareness of new ransomware variants to update detection signatures and incident response procedures, particularly when found on critical assets like domain controllers that can facilitate lateral movement and full environment compromise.
- identity access
Debunking Microsoft 365 & Identity Myths
Huntress publishes guidance debunking common misconceptions about Microsoft 365 identity security, addressing myths around logins, multi-factor authentication (MFA), Conditional Access, Impossible Travel detection, and security tuning. The article aims to clarify correct practices for organizations relying on Microsoft 365 for authentication and access control.
Why it matters: Security practitioners managing Microsoft 365 environments should review this guidance to correct potential misconfigurations or false assumptions that could leave accounts vulnerable to compromise.
- threat intel
From a Fake AnyDesk Installer to MetaStealer
A fake AnyDesk installer was used to distribute MetaStealer, demonstrating an evolution of ClickFix tactics by threat actors. The attack leverages legitimate software spoofing to deliver malware capable of stealing credentials and files from compromised systems.
Why it matters: Organizations and users targeted by ClickFix campaigns face credential and data theft; practitioners should educate users on verifying software downloads and monitor for MetaStealer indicators.
- breaches incidents
s1ngularity: supply chain attack leaks secrets on GitHub: everything you need to know
A supply chain attack involving the Nx NPM package exposed secrets on GitHub. Organizations using Nx need to assess their exposure and take immediate remediation steps.
Why it matters: Development teams and organizations relying on the Nx build tool are at risk of compromised dependencies and leaked credentials, requiring urgent verification of their supply chains and secrets rotation.
- threat intel
Join Huntress' John Hammond & Dave Kleinatland on a | Huntress
Huntress researchers are conducting a tour of dark web activity, examining how threat actors use marketing strategies and discussing cybercrime discussions on BreachForums. The presentation appears to focus on emerging tactics and trends in underground forums.
Why it matters: Security practitioners should understand threat actor operational security practices and communication channels to better anticipate attack methods and identify emerging threats earlier.
- threat intel
Should MSPs Turn Off Google Gemini? | Huntress
Google Gemini's email summary feature is being exploited by attackers to deliver phishing messages that bypass traditional security controls by avoiding links and attachments. Managed service providers (MSPs) should evaluate whether the feature's risks outweigh its benefits in their environments.
Why it matters: MSPs and their clients face increased phishing risk if Gemini summaries are processing malicious emails, making it critical to assess whether to disable the feature or implement additional email filtering rules to protect against this attack vector.
- cloud saas
Secrets Found. Owners Identified. Issues Fixed.
Wiz has released functionality that identifies exposed secrets, provides context about their potential impact, determines ownership, and offers AI-powered remediation recommendations. The tool integrates secret detection with risk quantification and automated fixes to streamline response workflows.
Why it matters: Security teams managing cloud environments need to prioritize secret remediation by blast radius and ownership; this capability helps reduce the time from discovery to fix and clarifies responsibility for action.
- cloud saas
Unpacking the 2025 Gartner Market Guide for CNAPP
Gartner released a 2025 market guide for Cloud Native Application Protection Platforms (CNAPP), examining the evolving landscape of security solutions that consolidate multiple cloud security tools into unified platforms. The report highlights the shift away from fragmented, point-solution approaches toward integrated protection frameworks for cloud native environments.
Why it matters: Security teams evaluating cloud native protection strategies need to understand Gartner's current vendor positioning and capabilities assessment to inform platform consolidation decisions and budget allocation.
- industry
Ten Years of Resilience, Innovation & Community-Driven Defense
Huntress marked a decade of operations with a retrospective highlighting key milestones and lessons learned in defending against evolving threats. The company emphasized its role in community-driven cybersecurity and innovation throughout its ten-year history.
Why it matters: Security practitioners should understand vendor evolution and market positioning when evaluating managed detection and response (MDR) tools and security partners for their environments.
- threat intel
Nearly 2,000 Malicious IPs Probe Microsoft Remote Desktop After Single-Day Surge
GreyNoise detected a sudden surge in scanning activity targeting Microsoft Remote Desktop (RDP) services on August 21, with attackers probing for timing vulnerabilities that could expose valid usernames. The reconnaissance activity from approximately 2,000 malicious IP addresses appears designed to enable credential-based attacks. This pattern suggests coordinated preparation for intrusion attempts rather than isolated scanning noise.
Why it matters: Organizations exposing RDP to the internet face immediate reconnaissance risk from attackers mapping valid accounts; security teams should review RDP access controls, network segmentation, and authentication protections today.
- ransomware
Cephalus Ransomware: Don’t Lose Your Head
Huntress identified two incidents in mid-August connected to Cephalus ransomware, which exploited DLL sideloading through a legitimate SentinelOne executable to gain execution.
Why it matters: Organizations using SentinelOne or other security tools need to understand that Cephalus operators are weaponizing trusted executables for initial access, requiring immediate review of DLL sideloading attack vectors.
- cloud saas
A new type of long-lived key on AWS: Bedrock API keys
AWS has introduced a new type of long-lived API key for Bedrock that simplifies authentication processes. These keys persist over time rather than requiring periodic rotation, which presents both convenience and security tradeoffs for practitioners managing foundation model access.
Why it matters: Development teams using AWS Bedrock should understand the security posture of long-lived keys versus temporary credentials, assess where they fit in your authentication strategy, and implement appropriate controls like IP restrictions and key rotation policies.
- ransomware
Halcyon Announces General Availability Release of Anti-Ransomware Platform
Halcyon has announced the general availability release of its anti-ransomware platform, which the company positions as the first dedicated solution of its kind in the nation.
Why it matters: Security teams evaluating ransomware defense tools should assess whether this platform's capabilities and integration approach align with their incident response and backup protection strategies.
- ransomware
Ransomware TMZ: More Than a Year of Leaks, Lies and Betrayals
The ransomware ecosystem has experienced significant internal conflicts over the past year, including site hijackings, public exposure of individuals, and disputes among criminal actors. These incidents reveal instability and mistrust within ransomware operations and leak site management.
Why it matters: Security teams should monitor ransomware group dynamics and leak site reliability, as internal fractures may affect threat actor capabilities, victim notification patterns, and the timing of data releases.
- cloud saas
Build to Runtime, Covered: A New Standard for Container Image Visibility
Wiz has launched an enhanced container image page that provides visibility across the software development lifecycle, from code through runtime execution. The tool aims to help teams prioritize and remediate issues more efficiently by consolidating information across build and runtime stages.
Why it matters: DevOps and security teams using container-based deployments need better visibility into image vulnerabilities and configurations to reduce exposure window and remediation time.
- ransomware
Exposing Data Exfiltration | Huntress
Ransomware threat actors frequently exfiltrate data before deploying encryption as part of double extortion schemes, making detection challenging since the activity resembles legitimate administrator actions. Data theft during attacks is a common tactic across various threat groups. Identifying these activities requires distinguishing malicious data movement from normal system administration patterns.
Why it matters: Security teams need detection capabilities to identify data exfiltration attempts, as ransomware operators increasingly combine encryption with data theft to increase extortion pressure on victims.
- cloud saas
Wiz Completes IRAP Assessment to Support Australian Government Cloud Security
Wiz, a cloud security firm, has completed an Information Security Registered Assessors Program (IRAP) assessment. This certification enables Wiz to support Australian government agencies deploying workloads on approved cloud platforms. The completion demonstrates compliance with Australia's security assessment framework for government technology vendors.
Why it matters: Australian government agencies and their cloud service integrators need to verify vendor compliance before procurement and deployment; this certification clears Wiz as an eligible provider for sensitive government workloads.
- breaches incidents
90 Data Breach Trends & Statistics for 2026
This article presents data breach statistics and trends spanning recent years, including analysis of common causes and variations across industry sectors. The report examines historical breach patterns to identify emerging trends for the year ahead.
Why it matters: Security leaders should understand breach patterns, root causes, and industry-specific vulnerabilities to benchmark their organization's defenses and prioritize controls against the most common attack vectors.
- ai security
Inside Grammarly’s AI-driven automation with the MCP Server for Wiz
Grammarly has implemented an MCP (Model Context Protocol) Server integration with Wiz that uses AI-driven automation to streamline manual triage processes. The system reportedly reduces manual triage time by 90%, allowing engineering teams to concentrate on higher-level strategic work rather than repetitive tasks.
Why it matters: Security teams using Grammarly or Wiz should evaluate whether this automation improves their own triage efficiency and frees up analysts for more complex threat assessment work.
- ransomware
Kawabunga, Dude, You’ve Been Ransomed!
Huntress, a security firm, observes a wide range of threat activity through its customer base, including undocumented ransomware variants and detailed telemetry on threat actor behavior and timing. The company gains visibility into both known and previously unreported ransomware families through these incidents.
Why it matters: Security teams and incident responders benefit from Huntress's visibility into emerging and undocumented ransomware variants, which can help identify new threats in their own environments before public disclosure.
- ransomware
Active Exploitation of SonicWall VPNs
A zero-day vulnerability in SonicWall VPNs is being actively exploited by threat actors to bypass multi-factor authentication (MFA) and deploy ransomware. Attackers are rapidly moving to domain controllers after initial compromise. Huntress recommends immediately disabling the VPN service or restricting access through IP allow-listing.
Why it matters: Organizations running SonicWall VPNs face immediate risk of unauthorized access, lateral movement, and ransomware deployment; urgent mitigation or service restriction is required today.
- regulatory
Huntress for CMMC Compliance
Huntress has released capabilities aligned with the 2024 Cybersecurity Maturity Model Certification (CMMC) framework, including a Sensitive Data Mode feature designed to protect Controlled Unclassified Information (CUI) and assist organizations with compliance requirements. The update addresses the evolving security standards for defense contractors and subcontractors.
Why it matters: Defense contractors and their supply chain partners required to meet CMMC 2.0 standards need to evaluate how Huntress tooling supports their compliance posture and CUI protection obligations.
- industry
What Security Should Look Like When Built for Developers
A discussion on how security tooling should align with developer workflows and practices. The article advocates for security solutions designed with developer experience and operational realities in mind.
Why it matters: Development teams and security leaders need to understand how security integration impacts adoption and effectiveness; tools that match developer behavior reduce friction and improve actual security outcomes.
- threat intel
A Coordinated Brute Force Campaign Targets Fortinet SSL VPN
GreyNoise detected a coordinated brute force campaign against Fortinet SSL VPN on August 3rd, 2025, with over 780 unique IPs engaging in attack traffic. This represents the highest single-day volume of such activity observed in recent months.
Why it matters: Organizations running Fortinet SSL VPN should immediately verify account security, review login logs for unauthorized access attempts, and implement rate limiting or IP blocking to defend against this active threat campaign.
- threat intel
Go Get ‘Em: Updates to Volexity Golang Tooling
Volexity released updates to its Golang analysis tooling to address challenges in reverse engineering obfuscated and non-obfuscated Go binaries. The new GoStringExtractor utility for IDA Pro and Ghidra extracts and organizes string data from Go binaries, while GoResolver was enhanced with runtime type information (RTTI) parsing capabilities to improve binary structure analysis.
Why it matters: Security practitioners analyzing Go-based malware or conducting detection engineering need better tools to extract actionable intelligence from increasingly obfuscated Go samples, making these open-source utilities valuable for malware analysis workflows.
- research
What Hollywood Movies Get Right (and Wrong) About Hacking
This article examines hacking portrayals in popular films and television, evaluating which depictions align with technical reality and which take creative liberties. It covers scenes from movies like The Social Network and The Matrix Reloaded to highlight both accurate and inaccurate representations of hacking.
Why it matters: Security practitioners may find this relevant for understanding how hacking is commonly misrepresented in media, which can inform public perception and organizational security awareness training.
- cloud saas
From Cloud to Hybrid: 360° Runtime Protection, Anywhere You Run
Wiz announced a Sensor Workload Scanner that provides runtime visibility and contextual analysis across hybrid infrastructure environments including cloud, on-premises, and edge systems within a single platform.
Why it matters: Security teams managing hybrid or multi-cloud deployments need unified visibility into workload behavior and runtime threats across all infrastructure layers to detect and respond to threats effectively.
- cloud saas
Introducing Wiz for Exposure Management: Unify, Prioritize, and Remediate Exposures Everywhere
Wiz has introduced new capabilities for exposure management, including a Unified Vulnerability Management (UVM) system and Sensor Workload Scanner, designed to help organizations identify and prioritize exposures across cloud, code, and on-premises environments. The offering aims to consolidate fragmented vulnerability tracking into a single platform to streamline remediation efforts.
Why it matters: Security teams using multiple tools to track vulnerabilities across disparate environments need a consolidated approach to reduce alert fatigue and ensure critical exposures are addressed first.
- threat intel
How to Identify Recruiting Scams and How Huntress Fights Back
Recruitment scams are increasing, targeting job seekers with fraudulent offers and identity theft risks. The article discusses how to identify common scam tactics and describes Huntress's efforts to combat these threats.
Why it matters: Job seekers and organizations managing hiring processes face credential compromise and identity theft from recruitment scams; security teams should understand these attack vectors to protect employees and warn job applicants.
- vulnerabilitiesCVE-2025-23319
Breaking NVIDIA Triton: CVE-2025-23319 - A Vulnerability Chain Leading to AI Server Takeover
Wiz Research has identified a critical vulnerability chain in NVIDIA's Triton Inference Server that permits unauthenticated attackers to achieve complete server compromise. The flaw, identified as CVE-2025-23319, exposes a significant attack surface for organizations deploying NVIDIA's widely used AI inference platform without proper security controls.
Why it matters: Organizations running NVIDIA Triton Inference Servers need to assess exposure immediately, as unauthenticated remote attackers can gain full control of AI inference infrastructure and underlying data.
- research
The insider’s guide to Black Hat 2025
Black Hat 2025 will feature over 100 talks covering emerging security topics including artificial intelligence vulnerabilities, cloud-based attacks, and networking opportunities. The conference provides a curated overview of current threat landscapes and industry trends.
Why it matters: Security practitioners attending or evaluating conference content should prioritize sessions on AI threats and cloud security to stay current on attack vectors relevant to their infrastructure.
- ransomware
The Commented Kill Chain: Why Old Ransomware Playbooks Never Die
Huntress discovered that attackers are reusing old, commented ransomware scripts that inadvertently reveal their tactics and methods. The security team used this visibility to prevent encryption attacks and documented how multiple threat actors are recycling established playbooks rather than developing novel techniques.
Why it matters: Defenders and incident responders should monitor for reused code patterns and commented scripts in attack campaigns, since visibility into attacker methodology can enable faster detection and prevention of active encryption threats.
- threat intel
GreyNoise Uncovers Early Warning Signals for Emerging Vulnerabilities
GreyNoise research shows that increases in attacker activity often appear up to six weeks before a new CVE (Common Vulnerabilities and Exposures) is publicly disclosed. This early warning signal provides security teams with a narrow window to strengthen defenses and monitor for exploitation before official vulnerability announcements.
Why it matters: Security defenders can use attacker activity patterns to anticipate emerging vulnerabilities and proactively harden systems before exploits become widely available.
- threat intel
Faster Threats, Faster Defense: GreyNoise Launches Real-Time Threat Defense Capabilities at Black Hat 2025
GreyNoise announced new real-time threat defense capabilities including dynamic blocklists, push-based threat intelligence feeds, and SOAR (Security Orchestration, Automation and Response) integrations designed to accelerate detection and response to automated attacks. The announcement was made at Black Hat 2025 and focuses on reducing the time gap between threat emergence and defensive action.
Why it matters: Security teams using GreyNoise or SOAR platforms should evaluate these new capabilities to improve response times against automated threats, as faster blocklist updates and threat feeds can reduce dwell time.
- cloud saas
Celebrating 200 WINtegrations—and the Partners Who Make It Possible
A cloud security platform has reached 200 integrations within its ecosystem, highlighting the breadth of partner integrations available to customers. The milestone demonstrates the platform's commitment to interoperability and collaborative security tools.
Why it matters: Security teams evaluating cloud security platforms should assess integration breadth as a factor in tool selection, since native connections to existing infrastructure and threat intelligence sources reduce deployment friction.
- threat intel
Information to Insights: Intrusion Analysis Methodology
An article discusses methodology for analyzing Windows event data to detect intrusions, focusing on authentication events, credential dumping, and remote desktop protocol (RDP) activity. The guidance aims to help practitioners convert raw log data into actionable threat intelligence for defensive purposes.
Why it matters: Security teams and incident responders need structured approaches to forensic analysis of Windows logs to identify compromised credentials, lateral movement, and attacker persistence before damage escalates.
- vulnerabilities
Wiz Research Uncovers Critical Vulnerability in AI Vibe Coding platform Base44 Allowing Unauthorized Access to Private Applications
Wiz Research identified a critical vulnerability in the Base44 AI-powered Vibe Coding platform that could enable unauthorized access to private applications. The finding highlights security risks inherent in AI-assisted development environments and similar code generation platforms.
Why it matters: Development teams using Base44 or similar AI coding platforms need to assess their exposure to unauthorized application access and review platform security controls immediately.
- threat intel
TraderTraitor: Deep Dive
The article examines a subgroup operating under the Lazarus umbrella that has been targeting cloud platforms, compromising supply chains, and conducting large-scale theft of digital assets. The reporting provides technical and operational analysis of this threat actor's infrastructure and methods.
Why it matters: Organizations using cloud platforms and managing software supply chains face direct risk from this nation-state backed group; security teams should review logs for indicators of compromise and strengthen access controls on cloud environments and build systems.
- government policy
What the U.S. AI Action Plan Means For Cyber Defenders
The U.S. is advancing an AI Action Plan that balances rapid innovation with national security priorities. The plan shapes how organizations integrate artificial intelligence into their operations and defensive strategies.
Why it matters: Cyber defenders need to understand the U.S. AI Action Plan's requirements and guidance to align their AI-driven security tools and strategies with government policy expectations.
- regulatory
The Cyber Insurance Paradox: Rising Risk, Falling Premiums
Cyber insurance carriers face challenges applying traditional actuarial models to a rapidly evolving threat landscape where individual configuration errors or unpatched systems can cause significant losses. The disconnect between rising cyber risks and carrier pricing models creates market instability as insurers struggle to accurately assess and price their exposure.
Why it matters: Risk managers and security leaders need to understand that cyber insurance carriers may be underpricing coverage, which affects both premium affordability today and claims payment reliability during incidents; actuarial pressure also incentivizes carriers to demand stronger security controls as a condition of coverage.
- cloud saas
Operationalizing Cloud Security: How PwC and Wiz Help Turn Risk into Resilience
PwC has integrated Wiz's cloud security platform to help clients strengthen their cloud transformation efforts by combining strategic guidance with enhanced visibility and execution capabilities.
Why it matters: Security practitioners evaluating cloud transformation partners should assess whether PwC's offering provides the technical depth and real-time visibility needed to identify and remediate misconfigurations and cloud-native risks during migration phases.
- threat intel
A Spike in the Desert: How GreyNoise Uncovered a Global Pattern of VOIP-Based Telnet Attacks
GreyNoise detected a surge in botnet traffic from a rural New Mexico utility that led to discovery of a globally distributed botnet launching Voice over Internet Protocol (VoIP) based Telnet attacks. The analysis combined human expertise with AI-powered techniques to identify compromised devices and reveal attack patterns across infrastructure. The findings highlight the importance of monitoring anomalous network activity from critical infrastructure locations.
Why it matters: Utility operators and network defenders need to understand that VoIP devices can serve as botnet nodes for attacks on critical infrastructure, requiring immediate inventory and access control review of all VoIP systems and Telnet-exposed assets.
- threat intel
Soco404: Multiplatform Cryptomining Campaign Uses Fake Error Pages to Hide Payload
Wiz Research has identified a new cryptomining campaign called Soco404 that operates across multiple platforms and uses fake error pages to conceal its malicious payload. The campaign represents an ongoing evolution in tactics used by threat actors to distribute mining malware while avoiding detection.
Why it matters: Organizations running web-facing infrastructure need to monitor for anomalous error pages and unexpected resource consumption, as this campaign's obfuscation techniques could allow cryptominers to establish persistence and degrade system performance without immediate detection.
- identity access
Stop Blaming the User: One Weak Password Shouldn’t Kill a Company
The article argues that organizations should move beyond blaming users for security failures and instead build systems designed to withstand human error. It contends that a single weak password or user mistake should not be catastrophic for a company, and that security responsibility lies with system design rather than user behavior alone.
Why it matters: Security practitioners need to shift from a user-blame culture to designing defense-in-depth controls that mitigate the impact of credential compromise, reducing organizational risk and breach likelihood.
- ransomware
Ransomware Shuts Down 158-Year-Old UK Logistics Firm
A ransomware attack has forced the closure of a UK logistics firm that had operated for 158 years. The incident demonstrates how ransomware can overwhelm an organization's recovery capabilities and lead to permanent business shutdown.
Why it matters: Logistics and supply chain operators face direct operational risk from ransomware attacks, and this case shows the critical need for robust backup, incident response, and continuity plans to survive extortion attempts.
- vulnerabilitiesCVE-2025-53770CVE-2025-53771
SharePoint Vulnerabilities (CVE-2025-53770 & CVE-2025-53771): Everything You Need to Know
Microsoft has disclosed two critical vulnerabilities in SharePoint Server, CVE-2025-53770 and CVE-2025-53771, that are currently being actively exploited in the wild. These flaws require immediate detection and mitigation efforts from affected organizations.
Why it matters: Organizations running SharePoint Server face active exploitation risk and should prioritize patching or implementing mitigations to prevent unauthorized access or data compromise.
- vulnerabilities
Zero-Day Vulnerability Exploited to Deploy Stealthy Overstep Backdoor
A zero-day vulnerability is being actively exploited in targeted attacks to deploy Overstep, a sophisticated backdoor with rootkit-level capabilities. This indicates adversaries are using unpatched critical flaws to establish persistent, privileged access on victim systems.
Why it matters: Organizations face immediate risk from zero-day exploits they cannot patch; security teams must assume advanced adversaries have rootkit-level persistence in their environments and should prioritize detection and containment of abnormal system-level activity.
- ransomware
Getting to the Crux (Ransomware) of the Matter
Huntress has identified a new ransomware variant called Crux that has been deployed in multiple incidents. The variant appears to be actively used in threat campaigns targeting organizations.
Why it matters: Security teams should monitor for Crux indicators of compromise and ensure detection rules are updated, as the variant is demonstrably active and targeting multiple victims.
- ransomware
Dark 101 Ransomware Leverages .NET Binary to Disable Recovery Features
Dark 101 ransomware uses a .NET binary to disable system recovery features, preventing victims from restoring files through built-in Windows recovery mechanisms. This represents a broader trend where ransomware operators are systematically targeting backup and recovery capabilities as part of their attack strategy.
Why it matters: Organizations relying solely on backup restoration as their ransomware defense are exposed to critical risk; practitioners must implement detection and prevention controls earlier in the attack chain to block these threats before recovery mechanisms are compromised.
- vulnerabilitiesCVE-2025-23266
NVIDIAScape - Critical NVIDIA AI Vulnerability: A Three-Line Container Escape in NVIDIA Container Toolkit (CVE-2025-23266)
A critical vulnerability (CVE-2025-23266) in NVIDIA Container Toolkit has been identified with a CVSS score of 9.0, enabling container escape in NVIDIA AI environments. The flaw affects the container toolkit used widely in AI infrastructure deployments. Organizations using NVIDIA's containerized AI solutions face systemic risk from this high-severity issue.
Why it matters: AI infrastructure operators and container security teams must urgently assess their NVIDIA Container Toolkit deployments for container escape exposure, as this critical vulnerability could allow attackers to break out of containerized environments and compromise host systems.
- research
The 2025 Cybercrime Report: 9 Emerging Trends + Statistics | Huntress
Huntress released a 2025 cybercrime report based on a survey of over 500 American IT professionals, identifying nine emerging trends and providing statistics on the current threat landscape. The report includes recommendations for improving cybersecurity practices.
Why it matters: IT professionals and security teams need visibility into emerging cybercrime trends and peer benchmarking data to prioritize defenses and validate their security strategies against documented industry patterns.
- cloud saas
Wiz MCP Server Now Available in the new AWS Marketplace AI Agents and Tools category
Wiz announced availability of its Model Context Protocol (MCP) server in AWS Marketplace's new AI Agents and Tools category. The MCP server enables users to leverage natural language workflows for security posture improvement and risk remediation.
Why it matters: Security teams using AWS can now integrate Wiz's AI-driven capabilities directly into their workflows, potentially accelerating vulnerability discovery and remediation cycles.
- threat intel
Remote Monitoring and Management Tools | Huntress
Huntress investigated two separate incidents where threat actors exploited remote monitoring and management (RMM) tools used by managed service providers (MSPs) to target multiple businesses. The incidents showed similar attack patterns but with tactical variations, indicating evolving methods in how adversaries abuse RMM infrastructure for lateral movement and network access.
Why it matters: MSPs and their downstream customers face direct risk from RMM compromise, as these tools provide legitimate administrative access across multiple client networks, making them high-value targets for attackers seeking broad network access.
- vulnerabilitiesCVE-2025-48927
Flaw in Signal App Clone Could Leak Passwords — GreyNoise Identifies Active Reconnaissance and Exploit Attempts
A vulnerability in TeleMessage SGNL, identified as CVE-2025-48927, allows heap memory exposure that may contain plaintext usernames, passwords, and sensitive data. GreyNoise has observed active reconnaissance and exploit attempts targeting this flaw in affected deployments.
Why it matters: Organizations using TeleMessage SGNL deployments face immediate credential exposure risk; practitioners should check for this CVE and apply available patches or mitigations to prevent password theft.
- ransomware
Ransomware Gangs Are Bleeding the Healthcare Supply Chain
Ransomware groups are increasingly targeting healthcare supply chain entities such as laboratory facilities, blood centers, and pharmacy networks to amplify operational disruption and pressure victims into faster payment. These attacks exploit the time-sensitive nature of healthcare services where delays in processing or distribution directly harm patients and create acute business pressure on victims.
Why it matters: Hospital administrators, lab directors, and pharmacy network operators need to assess supply chain exposure immediately, as ransomware targeting upstream vendors can disrupt patient care and create cascading incidents beyond their direct control.
- vulnerabilitiesCVE-2025-5777
Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public
GreyNoise detected active exploitation of CVE-2025-5777, a memory overread vulnerability in Citrix NetScaler, starting June 23, approximately two weeks before a public proof-of-concept was publicly released on July 4. This indicates attackers had access to exploitation knowledge or techniques ahead of public disclosure.
Why it matters: Citrix NetScaler administrators need to prioritize patching this vulnerability immediately, as evidence of pre-public exploitation suggests threat actors are actively leveraging it in the wild.
- ransomware
How Interlock Ransomware Gang’s New RAT Slips Through the Cracks
Ransomware operators are exploiting gaps in traditional security detection by leveraging legitimate tools and social engineering tactics. These methods allow threat actors to evade conventional endpoint and network defenses. The Interlock ransomware gang has developed new remote access trojan (RAT) capabilities as part of this evasion strategy.
Why it matters: Security teams need to update detection logic and incident response procedures to catch living-off-the-land attacks and legitimate-tool abuse, as traditional signatures and behavioral rules may miss Interlock's new RAT variants.
- industry
Huntress Collabs with Microsoft to Boost Business Security
Huntress has entered into a collaboration with Microsoft to enhance security offerings for business customers leveraging Microsoft's security products and services. The partnership aims to help organizations maximize the value of their existing Microsoft security investments.
Why it matters: Security teams using Microsoft products should evaluate whether this Huntress partnership improves their security posture or creates vendor dependencies that affect their architecture decisions.
- ransomware
KongTuke FileFix Leads to New Interlock RAT Variant
Researchers from The DFIR Report and Proofpoint have identified a new PHP-based variant of the Interlock ransomware group's remote access trojan (RAT), marking a shift from the group's previous JavaScript-based implementation known as NodeSnake. The new variant has been observed in active campaigns since May 2025 and represents an evolution in the group's malware toolkit.
Why it matters: Organizations should monitor for Interlock RAT activity and implement detection rules for the new PHP variant, as the group continues to refine its tools and deploy them in widespread campaigns targeting potential victims.
- cloud saas
Why AppSec and CloudSec Belong Together in the Age of AI
Industry commentary argues that application security and cloud security teams should operate with integrated workflows and shared context to keep pace with AI-driven development velocity. Combining these disciplines is positioned as necessary to avoid security becoming a bottleneck to innovation.
Why it matters: AppSec and CloudSec practitioners need to evaluate whether their current tooling and team structures enable the cross-functional visibility required to secure AI-accelerated development pipelines without slowing deployment cycles.
- vulnerabilitiesCVE-2025-47812
Wing FTP Server RCE (CVE-2025-47812) Exploited in the Wild | Huntress
Huntress identified active exploitation of a remote code execution vulnerability (CVE-2025-47812) in Wing FTP Server in the wild. The vulnerability involves an injection flaw that attackers are currently leveraging to compromise systems. Organizations running Wing FTP Server should assess their exposure and implement available mitigations immediately.
Why it matters: Organizations deploying Wing FTP Server face active exploitation of this RCE vulnerability and must patch or restrict access to prevent unauthorized code execution on affected systems.
- ransomware
Iranian Ransomware Crew Blurs the Line Between Profit and Proxy Attacks
An Iranian ransomware group is employing data wiping as an escalation tactic when extortion and data theft fail to coerce victims into paying ransom demands. Security researchers warn this represents an increasingly destructive approach that blurs the distinction between financially motivated cybercrime and state-sponsored destructive operations.
Why it matters: Organizations operating in critical sectors or with geopolitical exposure face elevated risk of destructive attacks beyond encryption and extortion, requiring incident response plans that account for data destruction scenarios.
- threat intel
GreyNoise Identifies New Scraper Botnet Concentrated in Taiwan
GreyNoise researchers discovered a previously untracked scraper botnet variant with a concentration of activity in Taiwan, using JA4+ network fingerprinting techniques to identify its distinctive traffic signature. The botnet was detected through a globally unique network fingerprint that sets it apart from known variants.
Why it matters: Security teams should monitor for this botnet signature if they suspect scraper activity in their environment, particularly those with Taiwan-based infrastructure or user bases, as identifying new botnet variants helps enable earlier detection and response.
- ransomware
BERT Ransomware's First Moves: Kill the VMs, Kill the Backups
BERT ransomware's initial attacks focus on compromising ESXi hosts to simultaneously disable multiple virtual machines and backup systems, amplifying the impact across an organization's infrastructure. This attack pattern exploits the centralized nature of virtualization environments to maximize damage and operational disruption from a single point of compromise.
Why it matters: Organizations running ESXi environments face rapid, widespread outages if a single host is compromised, as BERT can disable dozens of VMs and backups at once; security teams should prioritize ESXi hardening, segmentation, and immutable backups to prevent total operational failure.
- threat intel
Scattered Spider and Other Criminal Compromise of Outsourcing Providers Increases Victim Attacks
Attackers including the Scattered Spider group are targeting business process outsourcing (BPO) providers to gain access to multiple client organizations simultaneously. Compromising outsourcing providers creates a multiplier effect, allowing attackers to move laterally across numerous client environments from a single intrusion point.
Why it matters: Organizations using BPO providers face indirect exposure to attacks on their vendors; security teams should review access controls and monitoring for third-party connections to detect lateral movement from compromised outsourcers.
- vulnerabilitiesCVE-2025-5349CVE-2025-5777
Critical vulnerabilities in NetScaler ADC exploited in-the-wild: everything you need to know
Three critical vulnerabilities affecting Citrix NetScaler ADC and Gateway devices are being actively exploited in the wild. Organizations should apply patches immediately to mitigate the identified CVEs (2025-5349, 2025-5777, and 2025-6543).
Why it matters: NetScaler ADC operators face immediate risk from active exploitation and must prioritize patching these critical vulnerabilities to prevent unauthorized access and data exfiltration.
- vulnerabilities
Exposed JDWP Exploited in the Wild: What Happens When Debug Ports Are Left Open
Java Debug Wire Protocol (JDWP) ports left exposed in production environments are being actively exploited by attackers to gain unauthorized access and control of systems. The vulnerability arises when developers inadvertently deploy applications with debug mode enabled, creating an unauthenticated entry point for remote code execution. Organizations should identify and restrict access to debug ports as part of routine security hygiene.
Why it matters: Development teams and infrastructure operators need to audit production deployments for exposed JDWP ports immediately, as attackers can achieve code execution without credentials if debug functionality remains enabled.
- vulnerabilities
RMM Tools: A Gateway for Bulk Attacks | Huntress
A recent incident demonstrates that threat actors continue to exploit Remote Management and Monitoring (RMM) tools as a vector to compromise the downstream customers of managed service providers (MSPs), mirroring attack patterns from the 2021 Kaseya supply chain breach. RMM software remains a high-value target because compromising a single MSP platform can enable simultaneous access to numerous organizational endpoints.
Why it matters: MSPs and their customers need to prioritize RMM platform hardening and segmentation, as a single vulnerability or compromise can cascade to many organizations; practitioners should audit RMM access controls, multi-factor authentication (MFA), and backup procedures today.
- ai security
What the OpenAI Court Order Means for Cybersecurity and Privacy
OpenAI faces a court order related to data privacy and cybersecurity concerns. The legal action raises questions about how artificial intelligence systems handle sensitive information and comply with privacy obligations. This development may influence how AI vendors approach data protection and security standards going forward.
Why it matters: Security practitioners need to monitor how this court order affects vendor obligations for data handling, encryption, and privacy controls in AI deployments that process sensitive organizational data.
- threat intel
FBI Warns of Increased Scattered Spider Attacks in US
The FBI has issued a warning about increased attacks from Scattered Spider, a threat actor known for social engineering and bypassing multi-factor authentication (MFA) through manipulation of help desk staff rather than exploiting technical vulnerabilities.
Why it matters: US organizations face immediate risk from Scattered Spider's human-focused attack methods; security teams should prioritize help desk security awareness training and implement strict MFA reset procedures to prevent unauthorized access.
- threat intel
Scattered Spider Tactics Observed Amid Shift to US Targets
Scattered Spider, a threat actor, is leveraging tactics designed for hybrid environments and using rapid encryption methods that can encrypt systems in hours rather than the days traditionally required. This represents an evolution in their operational speed and capability against organizations with mixed on-premises and cloud infrastructure.
Why it matters: Security teams managing hybrid environments need to accelerate incident response and detection capabilities, as the compressed attack timeline significantly reduces the window available to identify and stop encryption attacks before widespread damage occurs.
- vulnerabilities
CISA Flags Actively Exploited Flaws in AMI, D-Link, and Fortinet Devices
CISA has identified actively exploited vulnerabilities affecting AMI, D-Link, and Fortinet devices. These flaws are being leveraged in real-world attacks and require immediate patching.
Why it matters: Organizations using AMI, D-Link, or Fortinet equipment face direct exploitation risk; patch these devices immediately to prevent compromise.
- ransomware
Hide Your RDP: Password Spray Leads to RansomHub Deployment
A password spray attack against an exposed RDP server in November 2024 led to RansomHub ransomware deployment. Threat actors used known malicious IP addresses to conduct multiple login attempts, eventually gaining access and deploying the ransomware payload.
Why it matters: Organizations running internet-facing RDP services are directly exposed to this attack vector; practitioners should immediately audit RDP accessibility, enforce strong credentials or multi-factor authentication, and monitor for brute force login attempts from known malicious sources.
- cloud saas
The Ultimate Cloud Security Championship | 12 Months × 12 Challenges
An organization has announced a new cloud security challenge series spanning twelve months with twelve individual challenges. The series appears designed to promote engagement and learning around cloud security topics.
Why it matters: Security practitioners can use structured challenge programs to build or validate cloud security skills, assess knowledge gaps, and stay current with evolving cloud threats and defenses.
- threat intel
Understanding Business Email Compromise (BEC): How It Works | Huntress
Business Email Compromise (BEC) attacks involve threat actors impersonating trusted sources to extract sensitive information from targeted individuals. BEC scams rely on social engineering and credential compromise to infiltrate organizational email systems and facilitate fraudulent transactions or data theft.
Why it matters: Organizations and their employees face financial loss and data exfiltration when BEC attacks succeed; practitioners should ensure email authentication controls (SPF, DKIM, DMARC) are deployed and staff training on email verification protocols is current.
- ransomware
UK’s NHS Says Ransomware Contributed to Patient Death
The UK's National Health Service (NHS) has attributed a patient death in part to a ransomware attack. The incident highlights the direct health and safety consequences that can result from ransomware targeting critical healthcare infrastructure.
Why it matters: Healthcare providers and their security teams face potential legal liability and regulatory scrutiny when ransomware impacts patient care; demonstrating robust incident response and system resilience is now a clinical safety imperative.
- ransomware
Unpatched SimpleHelp Vulnerabilities Continue to be Exploited by DragonForce
Unpatched vulnerabilities in SimpleHelp remote access software continue to be exploited by the DragonForce group. Remote management tools with known flaws remain attractive targets for ransomware operators seeking initial access.
Why it matters: Organizations using SimpleHelp should prioritize patching to prevent ransomware operators from gaining remote access; administrators managing remote access tools need to verify their systems are current.
- threat intel
Iranian Use of Cybercriminal Tactics in Destructive Cyber Attacks
Iranian state actors may employ destructive cyber attacks as part of retaliatory operations if they assess such actions would achieve strategic impact. The assessment reflects concerns about escalating cyber threats from nation-state adversaries leveraging destructive capabilities.
Why it matters: Organizations and critical infrastructure operators need to understand Iranian cyber threat patterns and prepare defenses against destructive attacks, which may target industrial systems, networks, or data in response to geopolitical events.
- threat intel
Recutting the Kerberos Diamond Ticket
A technical approach refines the Kerberos Diamond Ticket technique to improve operational security and create more convincing ticket forgeries. The method addresses misconceptions about the original technique and extends it to both Ticket Granting Tickets and Service Tickets, resulting in forgeries that blend better with legitimate Kerberos traffic. This represents an advancement over traditional Silver Ticket methods for Kerberos-based attacks.
Why it matters: Security practitioners defending Windows and Kerberos-based environments need to understand evolving ticket forgery techniques that evade detection more effectively than previous methods, as attackers refine these tradecraft to bypass authentication controls.
- vulnerabilities
Surge in MOVEit Transfer Scanning Could Signal Emerging Threat Activity
GreyNoise detected a sharp increase in scanning activity targeting MOVEit Transfer systems starting May 27, 2025, with daily scanning IPs jumping from fewer than 10 to over 100, and reaching 319 unique IPs by May 29. This surge suggests potential emerging threat activity or reconnaissance efforts against the file transfer platform.
Why it matters: Organizations running MOVEit Transfer should monitor for exploitation attempts and verify their systems are fully patched, as the spike in reconnaissance activity often precedes active attacks.
- identity access
Huntress Managed ITDR Supports AD-Synced Identity Disablement
Huntress has updated its Managed ITDR (Identity Threat Detection and Response) platform to support Active Directory synchronized identity disablement, enabling organizations to disable compromised identities across both on-premises and cloud environments from a single control point.
Why it matters: Security teams managing hybrid identity environments need coordinated response capabilities to revoke access quickly when compromise is detected, reducing the window for lateral movement and cloud privilege abuse.
- ransomware
Qilin Ransomware Group Adds Legal Support to Lure Affiliates
The Qilin ransomware group is offering legal support services to its affiliates as part of a recruitment and retention strategy. This move signals operational maturity and commitment to partner success, positioning the group as a professional enterprise within the ransomware ecosystem.
Why it matters: Security teams and law enforcement tracking ransomware-as-a-service operations need to understand how criminal groups professionalize their offerings; Qilin's expansion into legal services indicates the group is scaling operations and may pose increased threat sophistication.
- ransomware
New Ransomware Threat Adds File-Wiping Destruction to Encryption Attacks
A new ransomware variant incorporates a file-wiping capability alongside encryption, enabling attackers to permanently destroy data if ransom demands are not met. This dual-payload approach represents an escalation in destructive potential beyond traditional encryption-based extortion. Victims now face the prospect of both data inaccessibility and irreversible data loss.
Why it matters: Organizations using backup and recovery systems must validate that wipers cannot reach backup infrastructure; incident responders need to assess whether paying ransom prevents file destruction or merely stops ongoing encryption.
- industry
Cybersecurity Leadership: Build Unstoppable Security Teams | Huntress
Huntress has published guidance on cybersecurity leadership focused on building and managing effective security teams. The article covers hiring, retention, and addressing burnout among security professionals.
Why it matters: Security leaders and managers need practical frameworks for recruiting and retaining talent while maintaining team morale and performance in a competitive market.
- cloud saas
Operationalize Cloud Security in Zendesk: Wiz Now Available on the Zendesk Marketplace
Wiz, a cloud security platform, is now available on the Zendesk Marketplace, enabling organizations to integrate cloud security findings directly into their Zendesk ticketing system for streamlined remediation workflows.
Why it matters: DevOps and security teams using Zendesk can now prioritize and track cloud security issues without context switching, reducing time to remediation for cloud infrastructure vulnerabilities.
- cloud saas
Cloud Attacks Retrospective: Evolving Tactics, Familiar Entry Points
A retrospective analysis examines eight cloud attack patterns that security teams should monitor throughout 2025, highlighting evolving adversary tactics and persistent entry point vulnerabilities. The report synthesizes trends to help practitioners anticipate and defend against cloud-targeted threats.
Why it matters: Cloud infrastructure operators and security teams need to understand current attack vectors to prioritize defensive measures and reduce exposure to the most common compromise paths.
- threat intel
Inside the BlueNoroff Web3 macOS Intrusion Analysis
North Korea's BlueNoroff group conducted a targeted intrusion campaign against macOS systems focused on Web3 and cryptocurrency targets. The attack involved a multi-stage malware chain leveraging social engineering and custom tools designed to establish persistent access to compromised systems.
Why it matters: Cryptocurrency and Web3 practitioners on macOS need to understand BlueNoroff's evolving tactics to identify and prevent similar attacks targeting their organizations and assets.
- ai security
Leaking Secrets in the Age of AI
AI-assisted development tools are introducing new patterns and trends in how secrets, such as credentials and API keys, are leaked into codebases and public repositories. The article examines how developers using AI coding assistants may inadvertently expose sensitive information through automated code generation and completion features.
Why it matters: Developers and security teams need to understand AI-assisted tooling risks to prevent credential exposure in their codebase, as widespread secret leakage creates attack surface for threat actors.
- cloud saas
Proactive Account Review Uncovers Unauthorized | Huntress
A medical clinic discovered unauthorized use of productivity monitoring tools during a routine account review, revealing that employee monitoring software had been deployed without proper oversight. The incident highlights how such tools can persist undetected in healthcare environments and emphasizes the value of regular audits in identifying shadow IT and security gaps.
Why it matters: Healthcare practitioners need to audit for unapproved monitoring tools that could expose patient data, violate HIPAA, create compliance violations, or serve as entry points for attackers in regulated environments.
- identity access
Introducing Behavior-Based Assignments
A security vendor has introduced Behavior-Based Assignments, a feature that integrates with managed endpoint detection and response (EDR) and managed identity threat detection and response (ITDR) services to deliver targeted security awareness training based on detected incidents. The feature aims to convert real-world security events into training opportunities to reduce human risk.
Why it matters: Security teams using managed EDR or managed ITDR can now automatically trigger relevant training when employees trigger security alerts, directly addressing gaps in user behavior that lead to incidents.
- vulnerabilitiesCVE-2023-28771
GreyNoise Observes Exploit Attempts Targeting Zyxel CVE-2023-28771
GreyNoise detected exploit attempts targeting CVE-2023-28771, a remote code execution vulnerability in Zyxel IKE (Internet Key Exchange) packet decoders accessible over UDP port 500. The vulnerability allows unauthenticated attackers to execute arbitrary code on affected Zyxel devices. Active exploitation of this flaw is now occurring in the wild.
Why it matters: Organizations running vulnerable Zyxel VPN and network appliances need to patch immediately, as the vulnerability is under active attack and affects devices typically exposed to the internet.
- research
141 Key Cybersecurity Statistics for 2026 and Beyond
A compilation of cybersecurity statistics for 2026 and beyond covering cybercrime trends, data breaches, and workforce insights. The article aggregates key metrics to help organizations understand the current threat landscape and security challenges.
Why it matters: Security leaders and practitioners need current statistics on breach prevalence, cybercrime tactics, and staffing gaps to justify budget decisions and prioritize defensive measures.
- ai security
Wiz Integrates with NVIDIA Enterprise AI Factory Validated Design
Wiz has been integrated into NVIDIA's Enterprise AI Factory validated design to help developers securely build and deploy enterprise AI agents at scale. The partnership combines Wiz's security capabilities with NVIDIA's AI infrastructure to address security needs in enterprise AI deployments.
Why it matters: Organizations building AI agents on NVIDIA infrastructure should evaluate whether this integration meets their cloud security and AI governance requirements for production use.
- industry
How Huntress Addresses Lateral Movement
Huntress Managed EDR incorporates layered telemetry collection and detection mechanisms to address lateral movement, a common post-compromise attack technique. The approach aims to identify malicious activity while reducing false positive alerts.
Why it matters: Security teams evaluating endpoint detection and response (EDR) tools should understand how vendors handle lateral movement detection, as effective identification of this tactic directly impacts breach containment and dwell time.
- ai security
AI Is Everywhere—But Security Teams Are Still Catching Up
A report surveying 96 organizations examines how security teams are adopting and managing artificial intelligence deployments in cloud environments. The findings highlight gaps between widespread AI adoption and the maturity of security practices protecting these systems.
Why it matters: Security practitioners need to understand current AI security maturity levels and identify where their organization stands relative to peers in implementing controls, detection, and governance for AI systems in production.
- cloud saas
Building a Security Operations Center for the Cloud: Key Considerations for People, Processes, and Technology
Cloud adoption requires security operations teams to reevaluate their personnel, procedures, and technical infrastructure to support Cloud Detection and Response and defend against emerging cloud-based threats. Organizations must align their security operations centers with the realities of distributed cloud environments.
Why it matters: Security teams managing cloud infrastructure need to assess and potentially restructure their SOC capabilities to detect and respond to cloud-specific attacks, or risk missing threats in their cloud environments.
- cloud saas
Extending Threat Coverage on Macs with XProtect and | Huntress
Huntress announced expanded endpoint detection and response (EDR) capabilities for macOS that now integrate with Apple XProtect and Microsoft Defender for Endpoint. The service aims to improve threat detection and response coverage for organizations managing Mac devices.
Why it matters: Organizations relying on macOS should evaluate whether Huntress EDR integration with XProtect and Defender improves their current detection coverage and reduces blind spots in their Mac security stack.
- ai security
Lean and Mean: How We Fine-Tuned a Small Language Model for Secret Detection in Code
This article discusses the development and optimization of a small language model designed to detect secrets and sensitive data within source code. The piece covers the full lifecycle from data preparation through to deployment of the specialized model.
Why it matters: Security teams and developers need efficient secret detection tools to prevent credential leaks in code repositories; understanding how to fine-tune compact models enables practical deployment across more resource-constrained environments.
- cloud saas
Cut the Noise, Find the Threats: Wiz Defend Launches for Government
Wiz has launched Wiz Defend as part of its Wiz for Gov offering, providing cloud runtime threat detection capabilities designed for government organizations. The product aims to help public sector teams detect, investigate, and remediate threats more rapidly by providing contextual information.
Why it matters: Government security teams managing cloud infrastructure should evaluate whether Wiz Defend's runtime detection capabilities address their detection and response workflows for cloud-native threats.
- industry
Introducing Threat Simulator for Better Employee Security | Huntress
Huntress has introduced Threat Simulator, a security awareness training tool within its Managed Security Awareness Training (SAT) platform that uses gamified, interactive sessions to educate employees. The solution aims to improve organizational security posture by providing hands-on training experiences to staff.
Why it matters: Security teams responsible for employee training and awareness programs can evaluate whether this tool reduces phishing susceptibility and improves organizational security culture.
- threat intel
Coordinated Brute Force Activity Targeting Apache Tomcat Manager Indicates Possible Upcoming Threats
GreyNoise detected a coordinated spike in brute force attacks against Apache Tomcat Manager interfaces on June 5, 2025, with attack volumes significantly exceeding normal baselines. The activity suggests attackers are systematically probing for exposed Tomcat services to gain unauthorized access at scale.
Why it matters: Organizations running exposed Apache Tomcat Manager interfaces face immediate risk of unauthorized access and potential compromise; security teams should audit Tomcat deployments, restrict manager access, and monitor for brute force attempts.
- ai security
Rules Files for Safer Vibe Coding
Open-sourced rules files have been released to help large language models (LLMs) generate code that is more secure and safer. These rules enable LLMs to better understand and apply security best practices during code generation.
Why it matters: Development teams using LLMs for code generation should adopt these rules to reduce the risk of deploying vulnerable code and enforce secure coding standards in their CI/CD pipelines.
- threat intel
Boring Isn't Harmless: Common Cyberattack Tradecraft Risks | Huntress
Huntress SOC has published analysis demonstrating that attackers succeed using common, straightforward tradecraft techniques rather than sophisticated exploits. The report provides practical defensive measures that security teams can deploy to counter these fundamental attack methods.
Why it matters: All organizations running endpoint detection and response (EDR) or managed detection and response (MDR) should review these tactics to improve their detection and response capabilities against the most frequently observed attacker behaviors.
- cloud saas
Zero Critical Issues, Infinite Security Potential
Wiz, a cloud security vendor, reports that more than half of its customer base has achieved a state of zero critical vulnerabilities in their cloud environments. The metric reflects progress in cloud risk remediation among the company's user base.
Why it matters: Cloud security practitioners should understand remediation benchmarks from vendor-reported metrics; achieving zero critical issues is one milestone in a broader risk management program, though context on issue definitions and timeframes matters for comparison.
- threat intel
Infostealers Crash Course: A Tradecraft Tuesday Recap
Infostealers have become a major threat as cybercriminals accumulate large volumes of stolen credentials, financial information, and sensitive data. The article discusses the prevalence of infostealer malware and provides guidance on how organizations can defend against these threats.
Why it matters: Organizations of all sizes are targets for infostealer campaigns; defenders need to understand infostealer tactics and implement protections to prevent credential and financial data theft.
- threat intel
DevOps Tools Targeted for Cryptojacking
Wiz Threat Research has identified a cryptojacking campaign targeting popular DevOps tools such as Nomad and Consul. The campaign exploits these widely deployed applications to compromise infrastructure for cryptocurrency mining operations.
Why it matters: DevOps teams and infrastructure operators need to audit Nomad and Consul deployments immediately for signs of compromise, as these tools have broad access to orchestration and service discovery infrastructure.
- cloud saas
Introducing Wiz Service Catalog: Democratize Cloud Security with Application Service Visibility
Wiz has introduced a Service Catalog product designed to give platform teams and developers better visibility into application services running in cloud environments. The tool aims to reduce alert fatigue, enable distributed ownership of security tasks, and speed up the remediation of cloud-native application vulnerabilities.
Why it matters: Platform teams and DevOps practitioners need to evaluate whether this tooling improves their ability to correlate security alerts with specific services and assign remediation work to application owners without overwhelming them.
- vulnerabilitiesCVE-2023-39780
GreyNoise Discovers Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers
GreyNoise identified a stealthy campaign exploiting ASUS routers through CVE-2023-39780 and unpatched methods to establish persistent backdoor access affecting thousands of devices. The attackers employ evasion techniques designed to avoid detection. Defenders need awareness of these tactics to identify and remediate compromised routers.
Why it matters: Organizations and individuals running ASUS routers face persistent backdoor compromise; security teams should immediately identify exposed devices, verify patching status for CVE-2023-39780, and investigate any suspicious network behavior on affected routers.
- breaches incidents
'Advanced' Intrusion Targeting a Marketing Research Company | Huntress
Huntress identified and responded to an intrusion at a market research company that employed living-off-the-land techniques, including service creation and registry manipulation. The incident demonstrates the use of native operating system tools to avoid detection and establish persistence. Huntress has released detection guidance and mitigation strategies for similar attacks.
Why it matters: Security teams managing market research firms and other organizations should implement the detection methods and mitigation strategies provided to identify and respond to living-off-the-land attacks that use legitimate system tools.
- threat intel
Coordinated Cloud-Based Scanning Operation Targets 75 Known Exposure Points in One Day
GreyNoise detected a coordinated reconnaissance campaign on May 8 involving 251 malicious IP addresses hosted on Amazon AWS and geolocated to Japan, targeting 75 known exposure points in a single day. The synchronized nature and infrastructure patterns indicate centralized planning and direction of the scanning activity.
Why it matters: Organizations exposing known vulnerabilities or misconfigurations are at immediate risk from this active scanning campaign; practitioners should verify whether their assets match the targeted exposure points and patch or remediate visible weaknesses.
- cloud saas
The ROI of DSPM: Why Data Security Posture Management Is a Business Imperative
An article discusses how Data Security Posture Management (DSPM) provides measurable business benefits including risk reduction, compliance improvements, and operational efficiency gains. The piece examines the return on investment associated with implementing DSPM solutions.
Why it matters: Security practitioners evaluating data protection tools should understand DSPM's cost-benefit profile to justify budget allocation and prioritize data security investments.
- cloud saas
Data Foundations: From Insight to Action
This article discusses Wiz's approach to data management, classification, and remediation, offering structured frameworks and compliance tools for organizations to act on their data insights. The piece emphasizes moving from data discovery and classification to practical response and remediation workflows.
Why it matters: Security teams managing data risks and compliance requirements need practical remediation frameworks; Wiz's tools may help streamline response workflows for classified data vulnerabilities.
- threat intel
Detecting Malicious Security Product Bypass Techniques
A technique called defendnot uses undocumented Windows Application Programming Interfaces (APIs) to bypass Windows Defender's protections. The article discusses detection strategies and defensive measures to counter this evasion method.
Why it matters: Organizations relying on Windows Defender need to understand and implement detection capabilities for API-based evasion techniques to maintain effective endpoint protection.
- cloud saas
Deloitte’s Secure by Design (SbD) Approach – Enhanced with Wiz
Deloitte has integrated Wiz, a cloud security platform, into its Secure by Design (SbD) approach to help organizations maintain security controls throughout the development lifecycle. The partnership aims to balance security requirements with development velocity by embedding security checks earlier in the process rather than as a gate at the end.
Why it matters: Development teams and security leaders need to evaluate whether this integration reduces friction between velocity and compliance, particularly for organizations already using Deloitte's SbD methodology or considering Wiz for cloud workload scanning.
- cloud saas
Wiz Data Foundations: Data Classification
Wiz has released an update to its data classification engine, introducing new Novel Classifiers to enhance data identification and categorization capabilities. The enhancement aims to improve organizations' ability to discover and classify sensitive data across their environments.
Why it matters: Security teams using Wiz or evaluating data discovery tools need to understand how classification improvements affect their data protection and compliance posture.
- breaches incidents
Building an Incident Response Plan That Works
Effective incident response plans must be customized to the specific context and requirements of individual organizations rather than using a one-size-fits-all approach. A tailored plan helps organizations respond more effectively to security incidents and reduce overall risk exposure.
Why it matters: Security practitioners need incident response plans that match their actual environment and threat model to ensure rapid, effective containment and recovery when breaches occur.
- threat intel
2025 Managed ITDR Report: The Rise of Identity Threats | Huntress
Huntress released a 2025 Managed Identity Threat Detection and Response (ITDR) report highlighting the growing prevalence of identity-based threats in enterprise environments. The report provides insights into attack trends and the increasing need for identity-focused security measures.
Why it matters: Security teams need to understand evolving identity threat landscapes to prioritize detection and response capabilities that address credential attacks and unauthorized access vectors.
- vulnerabilitiesCVE-2025-4427CVE-2025-4428
Ivanti EPMM Zero-Days: Reconnaissance to Exploitation
Two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (CVE-2025-4427 and CVE-2025-4428) are under active exploitation following increased reconnaissance scanning activity. When chained together, these flaws allow unauthenticated remote code execution on affected systems.
Why it matters: Organizations running Ivanti EPMM need immediate action to patch or isolate these systems, as threat actors are actively exploiting these vulnerabilities to gain unauthorized access without credentials.
- ransomware
Breaking Down Ransomware Attacks | Learn How To Stay Protected
This article discusses the mechanics of ransomware attacks and outlines protective strategies. It mentions Huntress as a solution for ransomware defense.
Why it matters: Security practitioners need to understand ransomware attack methods and deployment options to effectively defend their organizations and select appropriate protective tools.
- industry
Introducing WizOS: Securing Wiz from the ground up with hardened, near-zero-CVE container base images.
Wiz announced WizOS, a hardened container base image product designed to reduce vulnerabilities in containerized environments. The offering is now available in private preview for Wiz customers as part of the company's security toolkit.
Why it matters: DevOps and security teams building container applications need minimal attack surfaces; WizOS addresses the growing pressure to ship secure container images from the start rather than patch vulnerabilities later.
- industry
Simplify Agent Management with Automated Health Checks
Huntress has released a client-side API for its endpoint detection and response (EDR) product that provides real-time agent health checks and status monitoring. The API enables security teams to quickly identify and manage endpoint agent health across their infrastructure.
Why it matters: Security operations teams using Huntress EDR can now monitor agent deployment status in real-time, reducing blind spots where endpoints may lack active protection.
- ransomware
Time to Ransom is Money
A recent analysis found that ransomware attackers typically demand payment within approximately 17 hours of initiating an attack. This metric reveals the speed at which threat actors move from initial compromise to extortion demands in their campaigns.
Why it matters: Security and incident response teams need to understand that the window for detection and containment of ransomware is measured in hours, not days, making rapid threat hunting and backup verification critical during the earliest stages of compromise.
- vulnerabilities
Post-Exploitation Activities Observed from the Samsung | Huntress
Huntress confirmed that attackers are actively exploiting vulnerabilities in Samsung MagicINFO 9 Server version 21.1050.0. The security firm recommends keeping the affected software off internet-facing networks until a patch is released and deployed.
Why it matters: Organizations running MagicINFO 9 Server face immediate post-exploitation risk if the software is internet-exposed; practitioners should isolate affected systems now and monitor for compromise indicators while waiting for patches.
- threat intel
Utilizing ASNs for Hunting & Response
Autonomous system numbers (ASNs) function as identifiers for internet routing blocks and can be used to distinguish between trusted and untrusted IP addresses. The Huntress Hunt and Response teams leverage ASN data as part of their threat hunting and incident response workflows.
Why it matters: Security practitioners can use ASN-based filtering to identify and prioritize suspicious traffic sources during hunting and response operations, improving efficiency when investigating potential threats.
- cloud saas
What Analyzing Hundreds of Thousands of Cloud Environments Taught Us About Data Exposure
Wiz Research analyzed hundreds of thousands of cloud environments to identify data security trends and exposures. The study reveals patterns of misconfiguration and data exposure practices across real-world cloud deployments.
Why it matters: Cloud practitioners and security teams need to understand common misconfigurations in their environments to prioritize remediation and reduce data exposure risk.
- vulnerabilities
Rapid Response: Samsung MagicINFO 9 Server Flaw
Huntress has confirmed that Samsung's MagicINFO 9 Server version 21.1050.0 is vulnerable to a publicly available proof-of-concept exploit. The vulnerability poses a significant risk if the server is exposed to the internet without a patch applied.
Why it matters: Organizations running MagicINFO 9 Server 21.1050.0 should immediately assess internet exposure and restrict access until Samsung releases a patch, as public exploit code is available.
- cloud saas
Deployed on AWS: Wiz and AWS Marketplace
Wiz has announced its 'Deployed on AWS' status through AWS Marketplace, reflecting an expanded partnership between the two companies. This designation is intended to help customers make informed purchasing decisions about Wiz's cloud security offerings.
Why it matters: Security practitioners evaluating cloud security solutions should note that Wiz's AWS Marketplace presence may simplify procurement and billing integration for AWS-based deployments.
- cloud saas
Introducing The Cloud Hunting Games CTF: Test Your Cloud Incident Response Skills
Wiz has launched The Cloud Hunting Games, a Capture the Flag (CTF) competition designed to test participants' skills in cloud incident response scenarios. The event provides a hands-on platform for security practitioners to practice detecting and responding to cloud-based security incidents.
Why it matters: Cloud security teams should consider participating to validate and improve their incident response capabilities in cloud environments, which are increasingly targeted by attackers.
- vulnerabilitiesCVE-2025-30406CVE-2025-31151
Do Tigers Really Change Their Stripes?
Security researchers analyzed exploitation patterns for two recent vulnerabilities and found that threat actors often maintain consistent tactics and procedures across multiple incidents, contrary to the common belief that adversaries continuously change their methods.
Why it matters: Security teams should recognize that threat actors may repeat proven techniques, enabling defenders to build more effective detections and incident response plans based on observed patterns rather than assuming constant tactical evolution.
- vulnerabilities
Verizon DBIR 2025: Edge KEVs Are Increasingly Left Unpatched — and More Often Exploited in Breaches
Verizon's 2025 Data Breach Investigations Report (DBIR) documents an eightfold increase in exploitation of edge vulnerabilities, which are security gaps in devices and systems at network boundaries. Despite these vulnerabilities appearing in the Known Exploited Vulnerabilities (KEV) catalog and carrying immediate exploitation risk, many organizations leave them unpatched.
Why it matters: Security teams must prioritize patching edge vulnerabilities given the sharp rise in real-world exploits; delay increases breach likelihood across all organizations relying on edge infrastructure.
- cloud saas
Federal Data, Meet your New Bodyguard: DSPM joins Wiz for Government
Wiz has integrated Data Security Posture Management (DSPM) capabilities into its FedRAMP-authorized cloud security offering. The addition enables automated data classification, policy enforcement, and continuous monitoring for sensitive data in cloud environments serving federal agencies.
Why it matters: Federal agencies and contractors must comply with FedRAMP requirements; this integration simplifies sensitive data visibility and policy compliance in cloud deployments.
- threat intel
Applying Criminal Justice Principles to Detection Engineering
A piece examines how criminal justice concepts such as burden of proof and intent can be applied to detection engineering to improve threat identification and reduce false positives in cybersecurity. The approach frames detection engineering challenges through a legal lens to strengthen defensive strategies.
Why it matters: Security teams managing alert fatigue and tuning detection systems should consider these analytical frameworks to improve signal-to-noise ratios and prioritize genuine threats.
- industry
Minutes Matter | Huntress
Huntress announced updates to its Managed SIEM platform focused on improving threat detection and response speed and accessibility. The announcement highlights new features and real-world case studies demonstrating how the platform supports cybersecurity operations and compliance requirements.
Why it matters: Security teams evaluating SIEM solutions should assess whether Huntress's speed and ease of use address their detection and response timelines and compliance obligations.
- identity access
Identity Threats Got a Whole Lot Nastier, But So Did We
Identity-based attacks are increasing in frequency and sophistication, with malicious OAuth applications emerging as a notable threat vector. Organizations are responding with enhanced detection and response capabilities designed to identify and block unauthorized access attempts before they compromise systems.
Why it matters: Security teams need to monitor OAuth application permissions and implement identity threat detection and response (ITDR) solutions to prevent credential compromise and unauthorized access, which represent the primary entry point for most attacks today.
- threat intel
Spike in Git Config Crawling Highlights Risk of Codebase Exposure
GreyNoise identified a surge in reconnaissance activity targeting Git configuration files exposed on the internet. Successful discovery of these files can reveal internal codebases, developer workflows, and sensitive credentials to attackers.
Why it matters: Development teams and organizations hosting code repositories are at risk of codebase exposure and credential compromise if Git configuration files are discoverable; practitioners should audit internet-facing repositories and ensure Git directories are not publicly accessible.
- regulatory
Conquer HIPAA Controls With Wiz
Wiz has published content positioning its cloud security platform as a tool to help organizations understand and implement HIPAA controls. The offering appears designed to simplify HIPAA compliance for healthcare and life sciences customers managing regulated workloads in the cloud.
Why it matters: Healthcare organizations and life sciences companies need to demonstrate HIPAA compliance; Wiz's tooling may reduce the operational burden of mapping cloud infrastructure to specific control requirements.
- identity access
Credential Theft: Expanding Your Reach, Pt. II
This article discusses credential theft techniques within the MITRE ATT&CK framework and their manifestation on endpoints. It aims to help security professionals recognize, detect, and respond to credential theft activities.
Why it matters: Security practitioners need to understand credential theft indicators on endpoints to identify compromised credentials before attackers use them for lateral movement and persistence.
- threat intel
How to Stop Malware Attacks with a Security-First Culture
The article discusses building organizational resilience against malware through cultural and awareness initiatives. It emphasizes employee training and security practices as foundational defenses against cyber threats.
Why it matters: Security leaders need practical approaches to reduce human error and insider risk, which account for a majority of successful malware incidents in most organizations.
- vulnerabilities
GreyNoise Uncovers Unique Risks From Resurgent Cybersecurity Vulnerabilities
GreyNoise released research identifying resurgent vulnerabilities as a particularly dangerous threat class being actively exploited by attackers. The research examines the characteristics, risks, and implications of these vulnerabilities for both defenders and policymakers.
Why it matters: Security teams need to understand resurgent vulnerability risks and exploitation patterns to prioritize remediation and detection strategies effectively.
- threat intel
9X Surge in Ivanti Connect Secure Scanning Activity
GreyNoise detected a nine-fold increase in suspicious scanning activity targeting Ivanti Connect Secure and Ivanti Pulse Secure VPN systems, with more than 230 unique IP addresses conducting probes against these endpoints. The surge in reconnaissance activity suggests possible coordinated preparation for future exploitation attacks.
Why it matters: Organizations running Ivanti VPN solutions should investigate logs for scanning activity and verify systems are patched, as this reconnaissance surge indicates attackers are actively preparing for exploits.
- cloud saas
Wiz Data Foundations: Where’s My Sensitive Data—And Who Can Access It?
Wiz released a hands-on guide demonstrating how to use its platform to discover sensitive data and identify which users or systems can access it. The walkthrough covers practical workflows for data discovery and access control visibility within Wiz Data Foundations.
Why it matters: Security teams need to understand how to locate and audit access to sensitive data in their environments. Practitioners should review this guide to improve data discovery and access management capabilities.
- threat intel
Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflows
Since early March 2025, Russian threat actors tracked as UTA0352 and UTA0355 have conducted targeted social engineering campaigns against Microsoft 365 users, particularly those working on Ukraine-related issues at NGOs and human rights organizations. The attackers impersonate European political officials via Signal and WhatsApp, then send OAuth phishing links claiming to be for video conference access, requesting victims return Microsoft-generated authentication codes. This represents a shift from earlier Device Code Authentication phishing attacks, with the threat actors now abusing other legitimate M365 OAuth workflows to compromise accounts.
Why it matters: Organizations and individuals engaged in Ukraine advocacy, human rights work, and diplomatic activities face heightened risk of account compromise and data theft; security teams should review OAuth authentication logs, disable suspicious sessions, and train staff on this multi-step phishing technique that requires both code generation and user cooperation.
- threat intel
Say Hello to Mac Malware
Threat actors are developing increasingly sophisticated macOS malware designed to maintain persistent access while evading Apple's security defenses. The focus includes techniques to avoid detection and achieve long-term foothold capabilities on compromised Mac systems.
Why it matters: Mac users and IT teams managing Apple infrastructure should evaluate their detection and response capabilities, as adversaries are actively refining attacks against this historically lower-targeted platform.
- cloud saas
Introducing the MCP Server for Wiz: Smarter AI Context, Stronger Cloud Security
Wiz has introduced a Model Context Protocol (MCP) server that integrates with AI assistants to provide real-time cloud security context and recommendations. The tool enables security teams to query vulnerability and misconfiguration data directly within AI interfaces, streamlining the remediation workflow.
Why it matters: Cloud security teams using AI assistants can now access Wiz findings and remediation guidance without switching tools, reducing investigation time and accelerating incident response.
- ai security
Research Briefing: MCP Security
The article examines security considerations for the Model Context Protocol (MCP), addressing both current safeguards and emerging challenges as the protocol continues to develop and see wider adoption.
Why it matters: Organizations integrating MCP with AI systems need to understand security implications to prevent unauthorized data access, capability misuse, and supply chain risks in their AI deployments.
- cloud saas
Tales of Too Many RMMs
Remote monitoring and management (RMM) tools are widely used to reduce operational costs and improve efficiency, but they create security risks when not properly managed. Organizations face challenges in securing these tools across interconnected environments.
Why it matters: Security practitioners need to assess their RMM tool deployments for misconfigurations and access control gaps, as these are common attack vectors for lateral movement and persistence.
- cloud saas
CIEM and Secure Cloud Access: Best Practices from Wiz and CyberArk
Wiz and CyberArk have integrated their platforms to help organizations secure cloud identities and implement Zero Standing Privileges (ZSP), a principle that limits unnecessary persistent access rights. The integration combines Cloud Infrastructure Entitlement Management (CIEM) with secure cloud access controls to reduce the attack surface from overprivileged identities.
Why it matters: Cloud infrastructure practitioners need to evaluate how CIEM and Zero Standing Privileges practices can reduce their organization's risk from compromised or malicious cloud identities, especially in multi-cloud environments where identity sprawl is common.
- threat intel
Why App Allowlisting & Zero Trust Alone Won't Save You | Huntress
Application allowlisting is presented as an effective preventative control, but security experts argue it requires complementary detection and response capabilities to address modern threats. A layered security approach beyond allowlisting alone is necessary for comprehensive protection.
Why it matters: Security teams relying solely on allowlisting or zero trust frameworks need to understand that additional detection and response mechanisms are essential to defend against evolving attack techniques that may bypass preventative controls.
- cloud saas
Insights from the field: Key Findings from the ICIT report on Government Cloud Security
Wiz partnered with the Institute for Critical Infrastructure Technology to publish a report based on survey findings from federal and state agencies. The research highlights the increasing adoption of cloud and artificial intelligence (AI) technologies across government, alongside concerns about resource constraints and data protection measures.
Why it matters: Government security practitioners need to understand the current state of cloud and AI security posture across agencies to identify gaps, prioritize resource allocation, and benchmark their data protection practices against peers.
- research
Top security talks from KubeCon Europe 2025
KubeCon Europe 2025 featured multiple security-focused presentations. The conference highlighted key discussions relevant to container and cloud-native security practices within the open source community.
Why it matters: Practitioners should review KubeCon Europe security talks to stay current on emerging threats, defensive strategies, and best practices specific to Kubernetes and cloud-native environments.
- ransomware
Ransomware Initial Access Brokers Exposed
A brute force attack exposed a suspected ransomware-as-a-service operation being used by initial access brokers. The discovery revealed a complex network facilitating illicit cybercrime activities.
Why it matters: Organizations should review access controls and monitoring for brute force attempts, as these tactics continue to serve as entry points for ransomware operators and downstream attacks.
- cloud saas
Crying out Cloud: Our Favorite Stories of 2024
This article highlights selected podcast episodes from 2024, focusing on topics relevant to cloud security and related areas. The piece serves as a curated retrospective of the year's discussions.
Why it matters: Security practitioners can use curated podcast recommendations to stay informed on key developments and emerging threats discussed throughout the year.
- identity access
How EDR and ITDR Elevate Your Security
Threat actors are increasingly targeting both endpoints and user identities in attacks, requiring organizations to defend across these vectors. A combined endpoint detection and response (EDR) and identity threat detection and response (ITDR) approach provides more comprehensive coverage. The article discusses why integrating these two security disciplines has become critical for modern defense strategies.
Why it matters: Security teams responsible for endpoint and identity security need to evaluate whether their current tools can detect threats across both domains, as attackers now routinely exploit identity infrastructure alongside endpoint compromise.
- threat intel
Credential Theft Prevention: Techniques & Defenses
The article discusses credential theft methods used by threat actors, including phishing, brute force attacks, and tools such as Mimikatz or Registry hive dumps that enable initial access and lateral movement within networks.
Why it matters: Security practitioners need to understand credential theft vectors and implement defenses because stolen credentials are the primary entry point for breaches, ransomware, and persistent lateral movement across enterprise environments.
- vulnerabilities
GreyNoise Observes 3X Surge in Exploitation Attempts Against TVT DVRs — Likely Mirai
GreyNoise detected a threefold increase in exploitation attempts targeting TVT NVMS9000 DVRs, a network video management system vulnerability that could allow attackers to obtain administrative access. The surge suggests activity potentially linked to the Mirai botnet or similar automated exploitation campaigns.
Why it matters: Organizations operating TVT DVRs face immediate risk of compromise and botnet infection; patch or isolate affected NVMS9000 systems urgently to prevent loss of administrative control.
- threat intel
Cyber Hygiene Threats: RDP, VPNs & Remote Tool Risks | Huntress
Huntress discusses how weak credential practices and misconfigurations in remote access tools like RDP and VPNs create entry points for attackers. The article examines real-world hygiene failures and how endpoint detection and response solutions can mitigate these risks.
Why it matters: Security teams should review remote access configurations and credential policies today, as these are frequent attack vectors that directly enable compromise of internal systems.
- vulnerabilitiesCVE-2025-31161
CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation
Huntress detected active exploitation of CVE-2025-31161, an authentication bypass flaw in CrushFTP, followed by post-exploitation activity involving MeshCentral and additional malware. The vulnerability allows attackers to bypass authentication controls and establish persistence through secondary tools.
Why it matters: Organizations running vulnerable CrushFTP versions face immediate risk of unauthorized access and lateral movement; patching and monitoring for MeshCentral installation are critical next steps.
- cloud saas
Introducing Wiz Defend: Redefining a new standard for cloud detection and response
Wiz has introduced Wiz Defend, a new cloud detection and response offering aimed at enhancing cloud security operations. The product appears positioned to advance detection and response capabilities within cloud environments.
Why it matters: Cloud security teams should evaluate whether this tool addresses their detection and response gaps, as cloud misconfigurations and threats remain a top exposure for most organizations.
- threat intel
The Unwanted Guest
Threat actors have been exploiting the built-in Windows Guest account to establish persistence on compromised systems. The article examines the techniques used to gain access and provides guidance on detecting this activity.
Why it matters: Security teams managing Windows environments need to monitor and restrict Guest account activity, as adversaries leveraging this built-in feature can evade standard detection and maintain unauthorized access.
- research
GoResolver: Using Control-flow Graph Similarity to Deobfuscate Golang Binaries, Automatically
Volexity released GoResolver, an open-source tool that automatically recovers obfuscated function names in Golang binaries by analyzing control-flow graph similarities. The tool addresses the challenge of analyzing Golang malware that has been obfuscated with tools like Garble, which randomizes function and package names to hinder reverse engineering. GoResolver works by comparing control-flow graphs from obfuscated samples against clean template binaries to identify the original function and package names.
Why it matters: Threat analysts and incident responders investigating Golang-based malware will benefit from faster deobfuscation and symbol recovery, reducing time spent on manual reverse engineering and enabling quicker malware identification and attribution.
- industry
Scalable EDR Advanced Agent Analytics with ClickHouse
Huntress, an endpoint detection and response (EDR) provider, uses ClickHouse, an open-source columnar database, to process analytics from its EDR agents across millions of endpoints. The approach enables the company to scale its detection capabilities while managing infrastructure costs and maintaining system stability.
Why it matters: Security practitioners using Huntress should understand how the platform handles large-scale endpoint telemetry, relevant to evaluating EDR tool performance and reliability for enterprise deployments.
- threat intel
Heightened In-The-Wild Activity On Key Technologies Observed On March 28
On March 28, GreyNoise detected a sharp increase in wild exploitation activity targeting multiple vendors including SonicWall, Zoho, Zyxel, F5, Linksys, and Ivanti. The affected technologies span both edge systems and internal management tools, suggesting a broad attack campaign.
Why it matters: Organizations running these widely deployed management and edge technologies face immediate active exploitation risk and should prioritize patching and monitoring for compromise indicators.
- threat intel
CPU_HU: Fileless cryptominer targeting exposed PostgreSQL with over 1.5K victims
Attackers are exploiting exposed PostgreSQL databases in cloud environments to deploy fileless cryptominers, affecting over 1,500 victims. The campaign, named CPU_HU, leverages weak credentials or misconfigurations to gain database access and execute malicious payloads without writing files to disk. This method allows attackers to evade traditional endpoint detection while consuming compute resources for cryptocurrency mining.
Why it matters: Database administrators and cloud security teams need to audit PostgreSQL instances for weak credentials, network exposure, and unauthorized command execution privileges, as attackers are actively targeting these weaknesses at scale.
- research
Why cybersecurity matters for your business.
This article discusses the business value of proactive cybersecurity investments and how they reduce long-term costs compared to reactive incident response. It emphasizes that cybersecurity measures contribute to organizational resilience and financial protection.
Why it matters: Business leaders and security practitioners need to understand the cost-benefit case for cybersecurity investment to justify budgets and prioritize risk mitigation over reactive spending.
- threat intel
Surge in Palo Alto Networks Scanner Activity Indicates Possible Upcoming Threats
Over the past 30 days, approximately 24,000 unique IP addresses have attempted to access Palo Alto Networks portals in a coordinated pattern. The probing activity suggests reconnaissance for exposed or vulnerable systems that could lead to targeted attacks.
Why it matters: Organizations running Palo Alto Networks infrastructure should investigate inbound scanner traffic and verify portal access controls, as this reconnaissance activity may precede exploitation attempts against their specific environments.
- threat intel
Securing Endpoints from Common Vulnerabilities
The article discusses best practices for securing endpoints by addressing common vulnerabilities such as weak passwords and unpatched software to mitigate risks from phishing and malware attacks.
Why it matters: Security practitioners need to prioritize endpoint hardening through password policies and patch management to reduce attack surface for all organizations using networked systems.
- vulnerabilitiesCVE-2020-8515CVE-2021-20123
Amid Reports of Worldwide Reboots, GreyNoise Observes In-the-Wild Activity Against DrayTek Routers
GreyNoise has detected active exploitation attempts in the wild targeting multiple known vulnerabilities in DrayTek routers, including CVE-2020-8515, CVE-2021-20123, and CVE-2021-20124. The observation coincides with reports of widespread reboots affecting DrayTek devices globally. Organizations using these routers face immediate risk from adversaries actively weaponizing these flaws.
Why it matters: DrayTek router administrators and network teams need to verify patches are applied immediately, as these vulnerabilities are being actively exploited and could lead to unauthorized access or network compromise.
- vulnerabilitiesCVE-2025-1974
IngressNightmare: CVE-2025-1974 - 9.8 Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX
A critical remote code execution vulnerability (CVE-2025-1974) with a 9.8 CVSS score exists in Ingress NGINX, affecting over 40% of cloud environments and potentially enabling complete cluster takeover. The vulnerability is unauthenticated, allowing attackers to execute code without credentials. Patch deployment is required to remediate the exposure.
Why it matters: Organizations running Ingress NGINX controllers are at immediate risk of total cluster compromise; this requires urgent patching and assessment of current deployments.
- threat intel
The Ultimate Validation: Making a Hacker’s “Do Not Engage” List
A malware researcher's name was embedded in the Celestial Stealer infostealer code as a kill-switch, causing the malware to shut down operations if the researcher's system is detected. This defensive measure reflects the researcher's visibility and threat to the malware operator's activities.
Why it matters: Security teams and threat researchers should understand that active researcher engagement can become a recognized threat vector to attackers, potentially triggering evasion or shutdown in malware operations targeting their organizations.
- cloud saas
How to use the new CloudTrail network activity events for AWS VPC Endpoints
AWS has introduced new CloudTrail network activity events that provide visibility into Virtual Private Cloud (VPC) Endpoint traffic. These logs enable security teams to audit endpoint policies, detect anomalous data flows, and investigate potential data exfiltration attempts.
Why it matters: AWS customers managing VPC Endpoints need this logging capability to detect unauthorized data access and verify that endpoint policies are correctly restricting traffic as intended.
- vulnerabilitiesCVE-2025-24813
GreyNoise Observes Active Exploitation of Critical Apache Tomcat RCE Vulnerability (CVE-2025-24813)
GreyNoise has detected active exploitation of CVE-2025-24813, a critical remote code execution vulnerability in Apache Tomcat, with multiple IP addresses conducting attacks across several regions. The vulnerability allows attackers to execute arbitrary code on affected Tomcat servers.
Why it matters: Organizations running vulnerable Tomcat instances face immediate risk of compromise and must prioritize patching or applying mitigations to prevent active exploitation.
- cloud saas
Wiz to Join Google Cloud: Making Magic Together
Wiz, a cloud security company, is joining Google Cloud in a strategic acquisition. The transaction aims to combine Wiz's security capabilities with Google Cloud's infrastructure and AI platform to strengthen cloud and AI security offerings.
Why it matters: Organizations using Wiz or evaluating Google Cloud's security posture should monitor how this acquisition affects product roadmaps, pricing, support timelines, and integration with Google Cloud's native security tools.
- cloud saas
Securing Cloud Databases: Best Practices with ClickHouse and Wiz
A guide addresses security approaches for cloud-hosted databases, focusing on built-in controls, operational best practices, and continuous monitoring. The article appears to cover preventive strategies for organizations managing sensitive data in cloud environments.
Why it matters: Database administrators and cloud security teams should evaluate whether their ClickHouse deployments and broader cloud database configurations align with current best practices to reduce misconfigurations and unauthorized access exposure.
- vulnerabilities
Resurgence of In-The-Wild Activity Targeting Critical ServiceNow Vulnerabilities
GreyNoise observed renewed exploitation attempts targeting three critical ServiceNow vulnerabilities in the wild, with the majority of observed traffic directed at targets in Israel. The activity suggests active and ongoing attacks against unpatched ServiceNow instances.
Why it matters: Organizations running vulnerable ServiceNow deployments need immediate visibility into exposure and should prioritize patching, especially those in Israel which appear to be the primary target.
- threat intel
New GitHub Action supply chain attack: reviewdog/action-setup
Wiz Research identified a supply chain attack on the reviewdog/action-setup GitHub Action that may have facilitated a separate compromise of the tj-actions/changed-files repository, which leaked secrets from affected repositories over the weekend. The attack demonstrates the risk of compromised GitHub Actions as a vector for broader supply chain compromise.
Why it matters: Development teams using these GitHub Actions are at risk of credential theft and lateral movement; practitioners should audit repositories using reviewdog/action-setup@v1 and tj-actions/changed-files for unauthorized access and rotate exposed secrets immediately.
- breaches incidents
GitHub Action tj-actions/changed-files supply chain attack: everything you need to know
A supply chain attack targeted the GitHub Action tj-actions/changed-files, resulting in exposed secrets across many dependent repositories. The attack exploited the widespread use of this action in continuous integration pipelines to access sensitive credentials. Organizations using this action need to audit for potential unauthorized access and rotate affected secrets.
Why it matters: Developers and DevOps teams using tj-actions/changed-files are at immediate risk of credential compromise; review workflow logs, identify exposed secrets, and rotate credentials in affected repositories today.
- vulnerabilities
New SSRF Exploitation Surge Serves as a Reminder of 2019 Capital One Breach
GreyNoise detected over 400 IP addresses exploiting Server-Side Request Forgery (SSRF) vulnerabilities across multiple platforms, with recent activity concentrated in Israel and the Netherlands. The surge recalls the 2019 Capital One breach, which leveraged SSRF weaknesses to compromise sensitive data. SSRF remains a practical attack vector for accessing internal resources and cloud metadata services.
Why it matters: Cloud and application operators must patch SSRF flaws and restrict outbound connections from application servers, as active exploitation campaigns show attackers are actively scanning for and exploiting these weaknesses in production environments today.
- threat intel
Untold Tales from Tactical Response | Huntress
Huntress discusses its threat analysis processes and investigative techniques used to uncover and address real-world cyberattacks. The article explores the challenges faced by security analysts working on tactical incident response.
Why it matters: Security practitioners should understand emerging investigative approaches and operational challenges that inform their own detection and response strategies.
- research
90% of IT Pros are Confident in Remote Cybersecurity | Huntress
A Huntress survey found that 90 percent of IT professionals express confidence in their remote cybersecurity practices. The survey examined attitudes toward security in remote and hybrid work environments.
Why it matters: IT leadership responsible for remote work security should evaluate whether confidence reflects actual risk posture, as overconfidence can mask vulnerabilities in distributed workforce protections.
- vulnerabilitiesCVE-2024-4577
GreyNoise Detects Mass Exploitation of Critical PHP-CGI Vulnerability (CVE-2024-4577), Signaling Broad Campaign
GreyNoise has detected widespread exploitation of CVE-2024-4577, a critical PHP-CGI vulnerability, across multiple geographic regions including the United States, Singapore, and Japan. Attack activity has continued to spike throughout January 2025, indicating a broad exploitation campaign rather than isolated incidents.
Why it matters: Organizations running vulnerable PHP-CGI implementations face immediate risk from active, geographically distributed attacks and should prioritize patching this critical vulnerability without delay.
- threat intel
Detect and Eliminate Persistent Malware Before It Wreaks Havoc | Huntress
Huntress has published guidance on detecting and eliminating persistent malware that remains active in systems after initial compromise. The approach emphasizes identifying and removing the mechanisms that allow malware to maintain a foothold rather than addressing isolated alerts.
Why it matters: Security teams need effective strategies for hunting and removing persistent malware threats before they establish long-term presence in networks.
- cloud saas
Introducing new Slack AI App for Wiz and Bi-Directional Slack Integration
Wiz announced new artificial intelligence (AI) capabilities for Slack alongside a bi-directional integration that allows security teams to investigate and respond to risks directly within the Slack platform. The enhancement brings risk assessment and remediation workflows into the collaboration tool where teams already communicate.
Why it matters: Security teams using Slack and Wiz can reduce investigation time and coordinate response actions without switching contexts; practitioners should evaluate whether this integration improves their incident response workflows.
- vulnerabilities
GreyNoise Detects Active Exploitation of Silk Typhoon-Linked CVEs
GreyNoise has identified more than 90 threat actor IP addresses actively exploiting vulnerabilities associated with Silk Typhoon, a China-linked advanced persistent threat group, within the past 24 hours. This activity follows Microsoft's recent disclosure of the group's updated tactics and techniques. The exploitation indicates rapid weaponization of these vulnerabilities in the wild.
Why it matters: Organizations using affected Microsoft products need to prioritize patching Silk Typhoon-linked CVEs immediately, as active exploitation by multiple threat actors demonstrates imminent risk to unpatched systems.
- industry
How Huntress Achieved a Blazing Fast MTTR
Huntress reports that its Security Operations Center (SOC) has achieved an average mean time to respond (MTTR) of 8 minutes for threat investigation and incident resolution. The fast response capability is designed to detect and contain threats before attackers can escalate their activities.
Why it matters: Security practitioners using Huntress need to understand this response time baseline when evaluating SOC services; faster MTTR directly reduces attacker dwell time and potential damage.
- vulnerabilities
GreyNoise Observes Exploitation of Three Newly Added KEV Vulnerabilities
On March 3, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. GreyNoise observed active exploitation of three of these newly cataloged vulnerabilities. CISA's KEV catalog tracks vulnerabilities confirmed to be exploited in real-world attacks.
Why it matters: Security practitioners should prioritize patching these three vulnerabilities as CISA confirmation of active exploitation indicates immediate threat to their environments and potential for rapid attacker adoption.
- research
Cybersecurity Threats in Healthcare [2025 Report] | Huntress
Huntress released a 2025 report surveying IT professionals about the most significant cybersecurity threats facing the healthcare industry. The report identifies key threat patterns and provides guidance for healthcare organizations to mitigate risks.
Why it matters: Healthcare practitioners and IT teams need to understand the current threat landscape specific to their sector to prioritize defensive investments and incident response planning.
- ransomware
Uncover Tomorrow’s Cyber Threats Today | Huntress
Huntress published a 2025 Cyber Threat Report covering ransomware trends, advanced phishing tactics, and targeted industries from 2024. The report is available for download and offers insights into emerging cyber threats.
Why it matters: Security practitioners should review threat trend reports to understand attacker tactics and prioritize defenses for industries and attack vectors most relevant to their organizations.
- threat intel
Hunt for RedCurl | Huntress
Huntress identified RedCurl, an advanced persistent threat (APT) group, conducting operations across multiple Canadian organizations since at least 2023. The group employs techniques designed to evade detection while stealing sensitive data. RedCurl's targeting of Canadian entities suggests a focused campaign against specific regional interests.
Why it matters: Organizations in Canada and those with Canadian operations face active data exfiltration risk from a capable, stealthy adversary; security teams should review detection gaps and implement APT-focused monitoring to identify RedCurl's evasion tactics before data loss occurs.
- industry
Emily Heath’s 5 Key Questions CISOs Should Ask Before Board Meetings
Industry leaders provide guidance on how CISOs should prepare for board meetings through structured questioning and communication strategies. The framework helps executives align security priorities with organizational oversight responsibilities.
Why it matters: CISOs need to clarify their messaging to boards to secure support for security initiatives and demonstrate the business impact of their programs.
- threat intel
New DDoS Botnet Discovered: Over 30,000 Hacked Devices, Majority of Observed Activity Traced to Iran
Security researchers at Nokia Deepfield have identified a botnet called Eleven11bot that has compromised over 30,000 devices, primarily security cameras and network video recorders, with the majority of observed activity traced to Iran. The botnet is being used to launch distributed denial-of-service attacks at scale. The threat continues to expand globally across internet-connected devices.
Why it matters: Organizations operating security cameras, NVRs, and other IoT devices face immediate risk of compromise and should audit their device inventory, apply firmware patches, and isolate these systems on network segments to prevent botnet recruitment and DDoS participation.
- ransomware
GreyNoise 2025 Mass Internet Exploitation Report: Attackers Are Moving Faster Than Ever — Are You Ready?
GreyNoise released its 2025 Mass Internet Exploitation Report, showing that attackers are automating large-scale exploitation of both new and established vulnerabilities, including some before they appear in the Known Exploited Vulnerabilities (KEV) catalog. The report analyzes the most-exploited CVEs in 2024, ransomware groups' use of mass exploitation techniques, and emphasizes the importance of real-time threat intelligence.
Why it matters: Security practitioners need to monitor exploitation activity beyond official KEV listings and understand how rapidly ransomware groups are automating attacks, as the threat landscape is moving faster than traditional vulnerability management processes.
- threat intel
How Effective Is Your SAT Program? | Huntress
Huntress discusses approaches to evaluating the effectiveness of security awareness training (SAT) programs and how organizations can modernize their training to build a stronger security culture. The article presents strategies for transforming workforce behavior and attitudes toward cybersecurity.
Why it matters: Security practitioners should assess whether their current SAT programs are meaningfully reducing user-driven security incidents and changing employee behavior, as ineffective training wastes resources while effective programs reduce breach risk from human error.
- industry
Wiz Named #1 CDR Solution by G2
Wiz has been ranked as the top Cloud Detection and Response (CDR) solution by G2 in the Winter 2025 Grid Report, based on independent customer reviews. The ranking reflects user satisfaction and performance in the CDR market. This achievement recognizes Wiz's position among competing cloud security vendors.
Why it matters: Security teams evaluating CDR tools should consider Wiz's top rating when assessing vendor options for cloud workload protection and threat detection capabilities.
- vulnerabilitiesCVE-2018-0171CVE-2023-20198
GreyNoise Observes Active Exploitation of Cisco Vulnerabilities Tied to Salt Typhoon Attacks
GreyNoise detected active exploitation attempts against two Cisco vulnerabilities, CVE-2023-20198 and CVE-2018-0171, with over 110 malicious IP addresses targeting the former vulnerability from multiple countries. The vulnerabilities were mentioned in recent Salt Typhoon reporting but GreyNoise has not attributed the observed exploitation to the Chinese state-sponsored group.
Why it matters: Organizations running affected Cisco infrastructure should immediately verify if these vulnerabilities are patched, as multiple threat actors are actively exploiting them in the wild.
- research
2025 State of Code Security: Key Trends and Risks
A report examines key trends and security risks affecting code and cloud environments in 2025. The analysis identifies emerging vulnerabilities and risk factors that organizations should monitor as security threats evolve.
Why it matters: Development and security teams need to understand current code and cloud security trends to prioritize remediation efforts and protect applications from emerging threats.
- cloud saas
Introducing Wiz Lens: Role-based views for every security team
Wiz announced Wiz Lens, a feature providing role-based views tailored to different security team members while maintaining unified visibility across cloud environments. The tool is designed to improve team efficiency and reduce context-switching by presenting relevant information based on user role.
Why it matters: Security teams managing multi-cloud environments can streamline workflows and reduce response time by filtering data to their specific responsibilities without losing broader context of cloud security posture.
- cloud saas
The Role of Runtime Security in Cloud Environments
Wiz has developed a hybrid approach to runtime security designed for cloud environments. The approach aims to address security monitoring and threat detection in modern cloud infrastructure. Runtime security in cloud contexts focuses on detecting and responding to threats during application execution rather than at deployment time.
Why it matters: Cloud practitioners need to evaluate runtime security tools and strategies to detect active threats and respond to attacks in their production environments, particularly as containerized and serverless workloads become standard.
- industry
The Overlooked Attack Surface: Securing Code Repositories, Pipelines, and Developer Infrastructure
Wiz released an Application Security Posture Management (ASPM) product feature that extends security monitoring to developer infrastructure, code repositories, and CI/CD pipelines to enforce secure defaults and detect threats across the software supply chain.
Why it matters: Development and security teams need to reduce risk in code repositories and build pipelines, which are frequent targets for supply chain attacks and credential theft.
- threat intel
Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication
Russian threat actors conducted targeted social-engineering and spear-phishing campaigns against Microsoft 365 accounts starting in mid-January 2025, using device code authentication as a lesser-known compromise method. Volexity identified multiple campaigns impersonating officials from the US State Department, Ukrainian Ministry of Defence, and other organizations to trick users into granting authentication access. The attacks proved more effective than typical targeted phishing and have been attributed to Russian actors including those tracked as CozyLarch, UTA0304, and UTA0307.
Why it matters: Organizations and government agencies using Microsoft 365 face elevated risk from persistent Russian nation-state phishing and device code attacks; security teams should review authentication logs for suspicious device code flows and reinforce user awareness on impersonation tactics targeting senior staff and officials.
- research
Dev and Sec: The Perfect Pair <3
The article discusses the relationship between development and security teams and how their collaboration creates secure and agile environments. It offers guidance on fostering better integration between these functions within organizations.
Why it matters: Security practitioners need to understand how to build effective dev-sec partnerships to embed security earlier in the software development lifecycle and reduce friction between teams.
- cloud saas
Cisco and Wiz Help Customers Modernize Cybersecurity
Cisco and Wiz have announced an enhanced collaboration to strengthen cloud security capabilities for their joint customers. The partnership aims to make security solutions more accessible across cloud-based businesses and improve overall cybersecurity posture.
Why it matters: Cloud-reliant organizations should evaluate whether this expanded integration simplifies their security stack and reduces deployment complexity in cloud environments.
- vulnerabilities
New Exploitation Surge: Attackers Target ThinkPHP and ownCloud Flaws at Scale
GreyNoise has identified a significant increase in exploitation attempts targeting vulnerabilities in ThinkPHP and ownCloud, including one vulnerability previously flagged as a priority target by government agencies. The surge demonstrates widespread, real-world attacks against these platforms, underscoring the importance of tracking active exploitation trends.
Why it matters: Organizations running ThinkPHP or ownCloud instances need immediate visibility into which vulnerabilities are actively exploited in the wild to prioritize patching and remediation efforts today.
- ransomware
2025 Cybersecurity Threat Report | Huntress
Huntress released its 2025 Cyber Threat Report covering major threats including remote access trojans (RATs), phishing campaigns, and ransomware attacks. The report emphasizes that defenders must adapt to evolving threat tactics to maintain effective security postures.
Why it matters: Security practitioners should review threat trend data to prioritize defenses and update detection rules against the most active attack vectors this year.
- cloud saas
Our Container Security AMA: You asked, Wiz answered
Wiz hosted a question and answer session focused on container security, with this article highlighting the most notable questions and responses from the community discussion.
Why it matters: Container security practitioners should review the AMA responses to understand current best practices and expert guidance on securing containerized environments.
- threat intel
6 Months of Researching OAuth Application Attacks | Huntress
Huntress released findings from a six month investigation into malicious OAuth applications, examining patterns and techniques used in OAuth-based attacks. The research highlights the prevalence of compromised or weaponized OAuth apps as an attack vector across organizations.
Why it matters: Security teams need to understand OAuth application risks to detect and prevent unauthorized access to sensitive data and organizational systems through compromised third-party integrations.
- threat intel
Device Code Phishing: OAuth 2.0 Attacks in Google & Azure
Researchers analyzed device code phishing attacks targeting OAuth 2.0 implementations, comparing security approaches between Google and Azure. The study examines how differences in OAuth implementation design affect attacker success rates and the practical effectiveness of phishing techniques against these platforms.
Why it matters: Cloud and identity practitioners should understand OAuth implementation variations because device code phishing can bypass standard authentication controls, and platform-specific weaknesses may create asymmetric risk across your enterprise cloud footprint.
- regulatory
The Huntress Cyber Insurance Trends Report (2025) | Huntress
The Huntress Cyber Insurance Trends Report analyzes current trends in cyber insurance coverage for 2025 and provides guidance on selecting appropriate policies for organizations. The report aims to help security practitioners understand the evolving insurance landscape and make informed decisions about coverage options.
Why it matters: Risk managers and security leaders need to understand how cyber insurance requirements and coverage are shifting in 2025 to ensure adequate protection and compliance with insurer expectations.
- industry
Introducing the Wiz Certified Program: Validate Your Expertise and Showcase Your Mastery!
Wiz has launched a certification program designed to validate cloud security expertise and help professionals demonstrate their skills to employers and peers.
Why it matters: Security practitioners pursuing career advancement in cloud security should consider whether this certification aligns with their professional development goals and employer requirements.
- cloud saas
The Basics of AWS Infrastructure Security
This article outlines foundational strategies for securing AWS infrastructure, emphasizing layered protection approaches and the shared responsibility model between AWS and customers. It serves as a guide for organizations to improve their overall security posture within Amazon Web Services deployments.
Why it matters: AWS customers need to understand their security obligations and implement multi-layered defenses to prevent unauthorized access, data exposure, and misconfigurations across their cloud infrastructure.
- cloud saas
Why Every Business Needs Endpoint Protection | Huntress
Endpoints represent a significant attack surface that adversaries actively target. Endpoint protection is presented as a foundational control to reduce the risk of compromise across deployed systems.
Why it matters: All organizations depend on endpoints; security practitioners need effective endpoint protection strategies to prevent devices from becoming initial compromise points for broader network attacks.
- cloud saas
Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History
Wiz Research identified a publicly accessible database belonging to DeepSeek that lacked proper access controls, exposing over a million lines of log data. The misconfiguration allowed unauthorized database operations and access to sensitive internal information. The exposure highlights risks from inadequate cloud security practices.
Why it matters: Organizations using DeepSeek services should assess whether their data was included in the exposure and verify the security posture of third-party AI platforms they depend on.
- cloud saas
Key Performance Indicators for Effective DSPM Implementation
This article discusses key performance indicators (KPIs) for data security posture management (DSPM) implementations, focusing on which metrics organizations should track and how to use them to strengthen their security practices.
Why it matters: Security practitioners implementing DSPM programs need to understand which metrics drive success and demonstrate value to stakeholders, ensuring resource allocation and compliance with data protection requirements.
- vulnerabilitiesCVE-2022-40684
Hackers Actively Exploiting Fortinet Firewalls: Real-Time Insights from GreyNoise
Attackers are actively exploiting Fortinet FortiGate firewalls vulnerable to CVE-2022-40684, with real-time threat intelligence available from GreyNoise. The article provides insights to help defenders understand and respond to ongoing exploitation attempts.
Why it matters: Organizations running FortiGate firewalls need to verify patching status for CVE-2022-40684 immediately, as active exploitation means unpatched instances face direct compromise risk to their network perimeter.
- vulnerabilitiesCVE-2024-40891
Active Exploitation of Zero-day Zyxel CPE Vulnerability (CVE-2024-40891)
A telnet-based command injection vulnerability (CVE-2024-40891) in Zyxel Customer Premises Equipment (CPE) devices is being actively exploited in the wild. Over 1,500 exposed systems are currently at risk, and the vendor has not yet released a patch.
Why it matters: Organizations running Zyxel CPE devices need to immediately inventory and isolate affected systems, as attackers are actively exploiting this vulnerability and a vendor patch is unavailable.
- cloud saas
Cloud Detection Without Drowning: The Zero-Noise Approach
A 'Zero Noise' approach to cloud security detection prioritizes attacker-focused analytics, continuous feedback mechanisms, and comprehensive alert handling to reduce false positives while maintaining threat visibility. The method aims to help security teams respond faster to genuine threats by filtering out noise inherent in cloud environments.
Why it matters: Security operations teams managing cloud infrastructure need efficient detection strategies to avoid alert fatigue; this approach offers a framework to improve signal quality and response velocity.
- cloud saas
The anatomy of a Toxic Combination of Risk
The article discusses identifying and mitigating potential threats and critical risks within cloud environments. It appears to focus on risk assessment and threat discovery methodologies for cloud infrastructure.
Why it matters: Cloud practitioners need to understand threat identification and risk elimination techniques to protect their environments from exposure and prevent security incidents.
- cloud saas
Securing the Container Frontier: Kubernetes Trends Report 2025
A new Kubernetes Security Report for 2025 examines the evolving threat landscape and defensive measures in container environments, highlighting both attack trends and security strategies. The report provides insights into the current state of Kubernetes security practices and challenges.
Why it matters: Platform engineers and security teams running Kubernetes clusters need to understand emerging attack patterns and defense strategies to prioritize their security investments and hardening efforts.
- threat intel
PerfMon! What Is It Good For? | Huntress
Performance Monitor (PerfMon) counters offer an alternative detection method for Kerberos roasting attacks that complements traditional Windows event monitoring. The approach provides security teams with additional visibility into attack patterns beyond standard event logs 4768 and 4769. This diversified detection strategy strengthens defenders' ability to identify and respond to Kerberos-based credential attacks.
Why it matters: Security operations teams need multiple detection vectors for Kerberos roasting to catch sophisticated attackers who may evade traditional event-based monitoring, making PerfMon counters a valuable supplementary detection layer.
- threat intel
Evaluating Threat Intelligence Providers: What Security Teams Need to Know
A white paper provides guidance for security teams evaluating threat intelligence providers, helping them assess their specific needs and identify gaps in their current capabilities. The resource aims to support informed decision-making when selecting threat intelligence solutions.
Why it matters: Security teams deciding whether to adopt or upgrade threat intelligence capabilities need practical evaluation criteria to ensure their investment matches their organization's risk profile and operational maturity.
- cloud saas
Tracking cloud-fluent threat actors - Part two: Behavioral cloud IOCs
This article discusses behavioral indicators of compromise (IOCs) specific to cloud environments and how security teams can use them to detect malicious activity. The piece provides real-world examples and practical detection techniques for identifying threat actors operating within cloud infrastructure.
Why it matters: Security teams managing cloud workloads need to understand behavioral patterns that distinguish legitimate from malicious cloud activity to improve detection coverage and reduce time to identify compromised accounts or infrastructure.
- threat intel
LOLBins: What are they & How to Detect Them
Living-off-the-Land Binaries (LOLBins) are legitimate system tools that threat actors exploit to carry out malicious activities while evading detection. The article discusses how these binaries pose security risks, outlines detection methods, and covers prevention strategies to mitigate attacks that abuse native operating system utilities.
Why it matters: Security teams need to understand LOLBin abuse techniques to detect anomalous behavior from legitimate processes and implement controls that prevent threat actors from using built-in tools to move laterally or execute payloads.
- industry
Welcoming Our New CFO & President
Fazal Merchant has joined the organization in a new leadership role as CFO and President.
Why it matters: Security practitioners monitoring vendor leadership changes should track organizational transitions that may affect product roadmaps, support continuity, or strategic priorities.
- vulnerabilitiesCVE-2025-0282CVE-2025-0283
CVE-2025-0282 and CVE-2025-0283: Critical Ivanti 0days Exploited in the Wild
Ivanti has disclosed two critical remote code execution (RCE) vulnerabilities in Connect Secure, identified as CVE-2025-0282 and CVE-2025-0283, that are being actively exploited in the wild. Organizations using these products require immediate patching to prevent compromise.
Why it matters: Organizations running Ivanti Connect Secure are exposed to active exploitation; patching should be prioritized immediately to prevent unauthorized remote access.
- vulnerabilitiesCVE-2024-55956
Cleo Software Actively Being Exploited in the Wild | Huntress
Huntress has detected active exploitation of three Cleo file transfer management products (LexiCom, VLTransfer, and Harmony) in the wild, tracked as CVE-2024-55956. The vulnerability is being actively exploited against organizations using these widely deployed solutions.
Why it matters: Organizations running Cleo's file transfer software need to assess exposure immediately, apply available patches, and monitor for signs of compromise, as threat actors are actively weaponizing this vulnerability.
- cloud saas
2025 Cloud Security Predictions: Trends to Look Out for
Wizards has published predictions about cloud security trends expected to emerge in 2025. The article identifies key areas of focus for organizations operating in cloud environments throughout the coming year.
Why it matters: Cloud security practitioners should review these predictions to prioritize their security roadmaps and resource allocation for 2025.
- vulnerabilitiesCVE-2024-43405
Breaking the Chain: Wiz Uncovers a Signature Verification Bypass in Nuclei, the Popular Vulnerability Scanner (CVE-2024-43405)
Wiz researchers discovered a high-severity vulnerability in Nuclei, a widely-used open-source vulnerability scanner, that allows bypassing signature verification and could enable arbitrary code execution. The flaw, tracked as CVE-2024-43405, affects a tool commonly relied upon by security teams for scanning and testing.
Why it matters: Security practitioners using Nuclei for vulnerability scanning face potential code execution risk if they run untrusted or modified scanner templates; immediate patching is critical to maintain the integrity of your scanning infrastructure.
- threat intel
Exploring Package Tracking Smishing Scams | Huntress
Smishing, or SMS-based phishing attacks, occurs more frequently during the holiday season. The article provides guidance on recognizing and avoiding these scams that impersonate package tracking notifications.
Why it matters: All employees and users are vulnerable to holiday-season smishing attacks that can compromise credentials or install malware; security teams should educate staff to verify shipping notifications through official carrier channels rather than clicking links in unsolicited texts.
- cloud saas
Avoiding mistakes with AWS OIDC integration conditions
The article discusses common security mistakes made when integrating OpenID Connect (OIDC) with AWS and how to avoid them. Practitioners working with AWS identity federation should review their OIDC configurations to ensure they are properly secured.
Why it matters: AWS users relying on OIDC for identity federation need to validate their condition configurations to prevent unauthorized access and privilege escalation.
- threat intel
2024: Revisiting a Year in Threats | Huntress
Huntress provides a retrospective analysis of notable cybersecurity threats identified and examined throughout 2024. The article reviews significant threat trends and incidents from the year without detailed specifics provided in the excerpt.
Why it matters: Security practitioners should understand 2024's threat landscape and key incidents to inform risk assessments and defensive posture for the coming year.
- regulatory
How Managed SIEM Helps Decode Compliance | Huntress
This article discusses how managed Security Information and Event Management (SIEM) platforms assist organizations in meeting compliance requirements across different jurisdictions. The piece explains the relationship between security monitoring capabilities and regulatory obligations.
Why it matters: Compliance practitioners and security teams need to understand how SIEM solutions can streamline evidence collection and audit readiness for regulatory frameworks in their operating regions.
- research
Checking It Twice: Profiling Benign Internet Scanners — 2024 Edition
A 2024 analysis profiled benign internet scanning services such as Shodan and Censys by deploying 24 sensors across multiple geographies and autonomous systems to measure discovery speeds and thoroughness. Most scanners identified new internet-facing assets within 5 minutes, with ONYPHE achieving the fastest first contact. The research provides a baseline understanding of how legitimate reconnaissance activity operates at scale.
Why it matters: Security practitioners need to understand scanning behavior to distinguish benign reconnaissance from malicious probing, tune monitoring rules to avoid alert fatigue, and establish baseline expectations for network exposure discovery timelines.
- cloud saas
The many ways to obtain credentials in AWS
A resource explores various methods through which credentials can be obtained in AWS environments, focusing on understanding AWS Identity and Access Management (IAM) credential mechanisms and SDK behaviors. The article emphasizes how defenders can improve their security posture by developing deeper knowledge of these credential procurement vectors and service-specific implementations.
Why it matters: Cloud security practitioners need to understand credential attack surfaces in AWS to properly detect, prevent, and respond to unauthorized credential access that could lead to account compromise and data exfiltration.
- threat intel
Analyzing Initial Access Across Today's Business Environment | Huntress
Huntress has published analysis of initial access techniques observed by its security operations center and tactical response teams. The report provides insights into how threat actors commonly gain entry into business environments.
Why it matters: Security practitioners need to understand prevalent initial access vectors to prioritize detection and prevention controls that address the most common attack paths in their environments.
- ot ics
When and Where SIEM Fits in Healthcare IT Settings | Huntress
This article discusses the role of Security Information and Event Management (SIEM) systems within healthcare IT environments, examining when SIEM tools are valuable, where they have limitations, and how they fit into a broader security infrastructure. The piece provides guidance on integrating SIEM into healthcare security architectures to optimize detection and response capabilities.
Why it matters: Healthcare IT practitioners need to understand SIEM deployment trade-offs and optimal use cases to build effective detection stacks that meet regulatory requirements and protect patient data while managing implementation complexity and costs.
- threat intel
Unpacking Diicot - Evolving Campaign Targeting Linux Environments
Wiz Threat Research identified a new malware campaign targeting Linux environments and attributed it to the Diicot threat group. The campaign represents an evolution in the group's capabilities and tactics. Details about the specific malware functionality and affected systems were documented in the research.
Why it matters: Linux infrastructure operators and defenders need to understand Diicot's evolving attack patterns to detect and defend against this threat in their environments today.
- vulnerabilities
Under the Radar: Exploring Spring Boot Actuator Misconfigurations
Wiz Threat Research identified misconfigurations in Spring Boot Actuator endpoints that expose sensitive data including environment variables, passwords, and API keys, with potential for remote code execution. Spring Boot Actuator is a commonly used monitoring and management tool in Java applications. These exposures occur when endpoints are improperly secured or left accessible without authentication.
Why it matters: Development teams and Java application owners need to audit Spring Boot Actuator endpoint configurations immediately to prevent credential exposure and unauthorized remote code execution in their infrastructure.
- threat intel
Does Santa Like NordVPN? | Huntress
Huntress published research examining security risks associated with popular virtual private network (VPN) and proxy services, including NordVPN and Mullvad, as part of their managed IT detection and response (ITDR) offerings. The analysis appears aimed at helping organizations understand potential threats posed by these tools during the holiday season.
Why it matters: Security teams evaluating third-party VPN and proxy solutions need to understand the threat landscape and misuse risks these tools introduce, as employees increasingly use them for remote work and personal purposes.
- threat intel
New Developments in LLM Hijacking Activity
A campaign named JINX-2401 is targeting AWS environments using identity and access management (IAM) privilege escalation tactics. The activity involves hijacking large language model (LLM) environments to gain elevated permissions within cloud infrastructure.
Why it matters: Cloud practitioners and AWS administrators need to review IAM policies and detect unauthorized privilege escalation attempts, as this campaign directly targets their environments for lateral movement and persistence.
- vulnerabilitiesCVE-2024-55956
Cleo Malichus Malware Analysis CVE-2024-55956| Huntress
Huntress security researchers have analyzed CVE-2024-55956, a vulnerability in Cleo software, and documented a new malware family they named Malichus. The analysis provides technical details on how the vulnerability is being exploited in the wild.
Why it matters: Organizations running Cleo software need to assess whether they are vulnerable to Malichus exploitation via CVE-2024-55956 and prioritize patching to prevent compromise.
- vulnerabilities
A Cloud-First Approach to Vulnerability Remediation: A Holistic Approach
Wiz offers a cloud-first approach to vulnerability remediation that provides visibility across the code-to-cloud environment to help organizations operationalize their remediation processes. The approach aims to streamline how organizations identify, prioritize, and address vulnerabilities throughout their cloud infrastructure and applications.
Why it matters: Cloud security practitioners need efficient vulnerability management workflows that span development through production to reduce exposure windows and prioritize remediation efforts effectively.
- industry
Wiz supports creation of new Japan tenants
Wiz, a cloud security vendor, is expanding its operations in Japan by supporting the creation of new tenants and expanding its leadership team in the region.
Why it matters: Organizations in Japan using or evaluating Wiz for cloud security should monitor the vendor's regional expansion and leadership changes to understand service availability and support quality.
- vulnerabilities
From PoC to Attacker Interest in Hours: Real-Time Insights into Mitel MiCollab Vulnerabilities
Attackers are exploiting Mitel MiCollab vulnerabilities within hours of proof-of-concept code releases, creating a narrow window for defenders to respond. GreyNoise provides real-time intelligence data to help organizations detect and disrupt these threats faster. The research highlights how quickly threat actors move from public exploits to active attacks in the wild.
Why it matters: Mitel MiCollab users and their defenders must prioritize patching and monitoring because exploitation begins immediately after PoC release; real-time threat intelligence is now essential for early detection and faster incident response.
- threat intel
Ultralytics AI Library Hacked via GitHub for Cryptomining
Ultralytics, a popular AI library, was compromised through a supply chain attack that leveraged GitHub Actions to inject malicious packages into PyPI. The attacker used the compromised repository to distribute code for cryptomining purposes. Users who installed affected versions received malware designed to commandeer system resources.
Why it matters: Developers and organizations using Ultralytics for AI/ML workloads should audit installed versions immediately and check for unusual system activity or resource consumption indicating cryptomining activity.
- cloud saas
Wiz at Re:Invent 2024
Wiz presented updates at Amazon's Re:Invent 2024 conference, highlighting its continued partnership with AWS to help secure customer environments. The announcement emphasizes Wiz's role in the AWS security ecosystem and ongoing collaboration between the two companies.
Why it matters: AWS customers using Wiz for cloud security should review the new capabilities announced to assess whether they strengthen their current security posture and warrant adoption or expansion.
- government policy
Authorized Agility: Wiz adds Code Security in the FedRAMP offering (Wiz for Gov)
Wiz has integrated its code security capabilities into its government-focused offering, Wiz for Gov, allowing organizations to map attack paths from cloud infrastructure to code and enforce security controls throughout the software development process. This expansion extends Wiz's FedRAMP-authorized platform to include source code analysis and threat visualization for federal and authorized government customers.
Why it matters: Federal agencies and government contractors using FedRAMP-authorized solutions need visibility into code-level security risks within their compliance-approved platforms; practitioners should evaluate whether this integrated approach reduces tool fragmentation and improves their ability to enforce secure development practices.
- industry
2024 Wrapped: Huntress Managed SAT Edition | Huntress
Huntress published a year-end review highlighting developments and features added to their Managed Security Awareness Training (SAT) product throughout 2024. The article serves as a retrospective on product improvements and capabilities released during the year.
Why it matters: Security teams evaluating or using Huntress Managed SAT should review the new capabilities to determine if recent updates address their awareness training and phishing simulation needs.
- cloud saas
Wiz Defend: Delivering the Promise of Cloud-Native Security Operations
Wiz announced Wiz Defend, a new product designed to detect and respond to threats targeting cloud-native environments. The offering aims to address security operations challenges specific to cloud infrastructure and applications.
Why it matters: Cloud infrastructure teams need integrated detection and response capabilities to identify threats across their cloud-native deployments, making this relevant for practitioners managing cloud security operations.
- industry
Managed SIEM and the Art of Perfecting Cyber Defense | Huntress
Huntress has published content about its Managed SIEM (Security Information and Event Management) service and its approach to signal recognition in cyber defense. The article emphasizes the platform's capabilities for threat detection and response.
Why it matters: Security teams evaluating SIEM solutions need to understand vendor capabilities for log analysis, alerting, and incident response to make informed tooling decisions.
- cloud saas
Introducing Wizdom Community: A New Era of Cloud Security Collaboration
Wizdom Community is a new platform designed for cloud security professionals to connect and collaborate. The initiative aims to foster community engagement around cloud security practices and knowledge sharing.
Why it matters: Cloud security practitioners benefit from peer networks and collaborative forums to stay current on emerging threats and share defensive strategies.
- industry
Huntress Managed Security Awareness Training: Relevance | Huntress
Huntress has announced a blog series exploring managed episodes from its Managed Security Awareness Training (SAT) platform, providing context on training topics and their current relevance to practitioners.
Why it matters: Security awareness training practitioners should monitor this series to understand evolving training priorities and how managed SAT aligns with emerging threat vectors and organizational needs.
- cloud saas
How to use AWS Resource Control Policies
This article discusses AWS Resource Control Policies as a security and governance tool for organizations using AWS. The piece covers how to implement and leverage these policies to enforce consistent security standards across infrastructure.
Why it matters: AWS users and cloud security teams need to understand policy controls available to them to prevent misconfigurations and enforce least privilege access across their environments.
- research
From Help Desk to CISO: How Communication Shapes Security Success
A survey of over 220 cybersecurity professionals identified effective communication as the most undervalued skill in the industry. The findings highlight how soft skills such as emotional intelligence and adaptability enable security teams to translate technical complexity for executives and diverse stakeholders, ultimately improving collaboration and incident response outcomes.
Why it matters: Security leaders and practitioners should prioritize communication and stakeholder management as core competencies, since these skills directly impact how incidents are communicated, risk is conveyed to business leaders, and teams coordinate during crises.
- ai security
Wiz collaborates with NVIDIA to advance ML research for data classification
Wiz Research is collaborating with NVIDIA to advance machine learning capabilities for sensitive data classification, leveraging NVIDIA's Llama 3 model and NIM (NVIDIA Inference Microservices) technology. This partnership aims to enhance data classification research and security practices. The work demonstrates growing integration of large language models into data protection workflows.
Why it matters: Security practitioners building or evaluating data classification solutions should track this development as it signals emerging best practices for using ML models to identify and classify sensitive information at scale.
- cloud saas
Deloitte’s Cyber Cloud Managed Services (CCMS) - Enhance cyber posture with AWS and Wiz
Deloitte has launched Cyber Cloud Managed Services (CCMS), a service powered by Wiz that provides automated security workflows and risk management capabilities for AWS cloud environments. The offering aims to streamline vulnerability identification and remediation across cloud infrastructure.
Why it matters: Organizations using AWS should evaluate whether this managed service aligns with their cloud security needs and can accelerate their remediation timelines compared to in-house alternatives.
- threat intel
Know Thy Enemy: A Novel November Case | Huntress
Huntress SOC researchers documented a threat actor's lateral movement and persistence techniques using novel infrastructure. The analysis provides insights into attack methods and adversary operational patterns based on incident investigation findings.
Why it matters: Security teams need to understand emerging threat actor tactics and infrastructure patterns to detect similar lateral movement and persistence attempts in their own environments.
- threat intel
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early 2022, Volexity discovered that Russian APT28 (also known as GruesomeLarch) breached an organization by exploiting a novel attack method later dubbed the Nearest Neighbor Attack. The threat actor compromised nearby organizations to locate systems with both wired and wireless network connections, then used those dual-homed systems to authenticate to the target organization's enterprise Wi-Fi network using credentials obtained through password-spray attacks, ultimately gaining network access from thousands of miles away.
Why it matters: Security teams managing enterprise Wi-Fi should review whether their wireless networks enforce the same multi-factor authentication controls as other services, and consider network segmentation to prevent compromised nearby organizations from becoming pivot points into corporate systems.
- industry
Wiz to acquire Dazz, transforming risk remediation from cloud to code
Cloud security firm Wiz announced an acquisition of Dazz, a company focused on application security posture management (ASPM). The combined entity aims to integrate remediation capabilities across the software development lifecycle, from code to cloud deployment.
Why it matters: Security teams responsible for application and cloud posture management should monitor this integration to understand how the merged ASPM offerings may affect their current tooling strategy and remediation workflows.
- cloud saas
Wiz Remediation and Response - Now available for Azure and GCP environments
Wiz has expanded its remediation and response capabilities to support Azure and Google Cloud Platform (GCP) environments, enabling real-time enforcement of security policies. The tool aims to streamline incident management across multi-cloud deployments.
Why it matters: Cloud security teams managing Azure or GCP workloads can now automate policy enforcement and incident response, reducing manual remediation effort and response time.
- ot ics
New Report Reveals Hidden Risks: How Internet-Exposed Systems Threaten Critical Infrastructure
A Censys report identified approximately 145,000 internet-exposed industrial control systems (ICS) and thousands of insecure human-machine interfaces (HMI), creating readily exploitable entry points for attackers. Real-world incidents demonstrate active threats, including state-backed actors from Iran and Russia targeting HMI systems to compromise water infrastructure in Pennsylvania and Texas. GreyNoise research confirms attackers are actively scanning for HMI vulnerabilities and prioritizing remote access services as lower-friction attack vectors compared to direct ICS protocol exploitation.
Why it matters: Critical infrastructure operators managing water systems, utilities, and industrial facilities need immediate visibility into externally exposed HMI and RAS endpoints, as documented state-sponsored activity shows these systems are being actively targeted and weaponized.
- threat intel
You Can Run, but You Can’t Hide: Defender Exclusions | Huntress
Windows Defender AntiVirus includes exclusion functionality that allows certain files, folders, and processes to skip malware scans. Adversaries can exploit these exclusions to hide malicious code from detection. Understanding these mechanisms is important for defenders to prevent their own security tools from being weaponized against their infrastructure.
Why it matters: Security teams using Windows Defender need to audit and restrict AntiVirus exclusions to prevent attackers from leveraging them as a persistence or evasion mechanism on defended systems.
- cloud saas
Introducing The Champion Center: Operationalize and Measure Cloud Security Maturity Across Your Organization
Wiz has introduced the Champion Center, a tool designed to help organizations centralize security insights, streamline cloud security adoption, and track measurable progress across their infrastructure. The platform aims to operationalize cloud security maturity by providing a unified view and scaling security practices throughout an organization.
Why it matters: Cloud security teams need visibility into adoption rates and maturity metrics to justify tooling investments and demonstrate progress to leadership; this addresses the gap between point solutions and organization-wide security governance.
- industry
Make Your Microsoft Security Tools Come to Life With Huntress | Huntress
Huntress has joined the Microsoft Intelligent Security Association (MISA) to enhance security capabilities for small and medium-sized businesses (SMBs) using Microsoft tools. This partnership aims to strengthen defenses against advanced cyber threats through integrated security solutions.
Why it matters: SMBs using Microsoft security tools can benefit from enhanced threat detection and response capabilities, particularly those seeking to improve their security posture against sophisticated attacks with limited security budgets.
- threat intel
Silencing the EDR Silencers | Huntress
Adversaries are employing tools such as EDRSilencer to interfere with Endpoint Detection and Response (EDR) communications, disrupting security monitoring capabilities. The article discusses techniques used to tamper with EDR systems and presents defensive countermeasures organizations can implement.
Why it matters: Security teams running EDR solutions need to understand these tampering techniques to detect and prevent attackers from disabling their monitoring, preserving visibility into endpoint compromise.
- identity access
To MFA or Not To MFA | Huntress
Multifactor authentication (MFA) is presented as a critical security control that can prevent unauthorized financial transactions, yet it remains underutilized and often viewed as an inconvenience by organizations. The article questions why such an effective protective measure is not treated as a mandatory security requirement.
Why it matters: Finance and operations teams are at risk of wire fraud and unauthorized money transfers; practitioners should prioritize MFA implementation for payment systems and financial access as a business-critical control.
- vulnerabilities
BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA
Volexity discovered a zero-day credential disclosure vulnerability in Fortinet's FortiClient Windows VPN client in July 2024, exploited by the Chinese state-affiliated threat actor BrazenBamboo through its modular malware DEEPDATA. The vulnerability allows extraction of VPN credentials from the VPN client's process memory, and Fortinet published a public acknowledgement with patching guidance in December 2024. BrazenBamboo also operates related malware families including LIGHTSPY and DEEPPOST for information gathering and file exfiltration.
Why it matters: Organizations running FortiClient VPN on Windows are at immediate risk of credential theft if using unpatched versions; security teams must apply Fortinet's December 2024 patches and review logs for signs of DEEPDATA exploitation or credential extraction.
- cloud saas
Kubernetes Audit Log “Gotchas”
Kubernetes audit logs present challenges and security gaps for forensics and attack detection. Organizations using Kubernetes must understand these limitations to effectively investigate incidents and identify threats. Proper configuration and analysis of audit logs are essential for comprehensive security visibility in containerized environments.
Why it matters: DevOps and security teams relying on Kubernetes audit logs for forensics need to understand their limitations to avoid gaps in threat detection and incident response capabilities.
- cloud saas
Introducing new Amazon Q Developer plugin for Wiz
Wiz has released a new Amazon Q Developer plugin that integrates with Amazon Web Services (AWS) to help customers improve their cloud security posture using generative AI capabilities. The plugin enables AWS and Wiz customers to leverage AI-powered insights within their existing development and security workflows.
Why it matters: AWS and Wiz customers can now use AI-assisted analysis to identify and remediate cloud security issues more efficiently, reducing manual security review overhead and improving threat detection speed.
- ransomware
It’s Not Safe To Pay SafePa
Huntress has identified multiple ransomware variants, including Akira, ReadText34, and INC, being actively deployed by threat actors in observed intrusions.
Why it matters: Organizations face active threats from multiple ransomware families; security teams should monitor for these indicators of compromise and strengthen defenses against affiliates conducting reconnaissance and deployment operations.
- cloud saas
Making Sense of Kubernetes Initial Access Vectors Part 2 - Data Plane
This article discusses Kubernetes data plane access vectors, focusing on the applications, container images, and execution-as-a-service workloads that operate within clusters. It is the second part of a series examining initial access methods in Kubernetes environments.
Why it matters: Platform engineers and security teams managing Kubernetes clusters should understand data plane attack surfaces to identify and defend against unauthorized access to containerized applications and their underlying resources.
- cloud saas
Accelerating our commitment to Europe with even more investments
Wiz announced expanded investments in Europe, including support for Amazon Web Services European Sovereign Cloud and establishment of new regional headquarters to serve European customers.
Why it matters: European organizations using AWS ESC or evaluating cloud security vendors need to assess Wiz's compliance posture and regional service capabilities for their deployments.
- research
A Parent's Guide to Securing Children's Tech Gifts | Huntress
Huntress published guidance for parents on securing technology devices given to children during the holiday season. The resource addresses device security, privacy protection, and establishing digital safety practices for young users.
Why it matters: Parents and guardians need practical steps to protect children's devices from compromise and data exposure before gifts are used.
- identity access
WTF is ITDR? | Huntress
ITDR (Identity Threat Detection and Response) is a security practice focused on detecting and responding to threats targeting identity systems and access controls. The article explains why ITDR has become an important component of modern security defense strategies.
Why it matters: Security practitioners need to understand ITDR capabilities to strengthen defenses against identity-based attacks, which are a primary attack vector for threat actors.
- threat intel
Turning TTPs into CTF Challenges: Huntress CTF 2024 Retro | Huntress
Huntress Capture the Flag (CTF) 2024 was a month-long competition where teams solved cyber challenges focused on reverse engineering and malware analysis. The event featured complex technical problems designed around real-world tactics, techniques, and procedures.
Why it matters: Security practitioners should review CTF challenges and solutions to sharpen defensive skills, understand common malware behavior patterns, and identify gaps in their own incident response capabilities.
- threat intel
Unmasking Phishing: Strategies for identifying 0ktapus domains and beyond
Wiz Research examines phishing tactics and methods for tracing and investigating phishing campaigns, including techniques related to 0ktapus domains.
Why it matters: Security teams need practical investigation strategies to identify and track phishing campaigns targeting their organizations and users.
- industry
Lead the Pack with SAT Leaderboards | Huntress
Huntress has added leaderboard and manager notification features to its Managed Security Awareness Training (SAT) platform to help organizations track learner progress and encourage engagement with training content.
Why it matters: Security teams need visibility into employee training completion and engagement to reduce human risk; these features support tracking and motivation across the workforce.
- cloud saas
Data access governance: Who's got the keys to your data kingdom?
Wiz released content discussing data access governance and how its platform can help organizations control and protect data access within cloud environments. The piece focuses on managing permissions and protecting sensitive data through governance controls.
Why it matters: Security practitioners need robust data access controls to prevent unauthorized exposure; understanding governance frameworks helps enforce least-privilege access and reduce breach risk.
- regulatory
HISAA: Raised Cybersecurity Standards for Healthcare | Huntress
The Health Infrastructure Security and Accountability Act (HISAA) aims to establish stricter cybersecurity standards across the healthcare sector. The legislation is designed to improve security posture and accountability measures within healthcare organizations. This represents a regulatory effort to address cybersecurity threats in a critical industry.
Why it matters: Healthcare providers and security teams need to monitor this legislation as compliance requirements may impose new security controls, audit obligations, and operational changes that affect their infrastructure and budgets.
- industry
The Evolution of the Huntress Neighborhood Watch Program | Huntress
Huntress has expanded its Neighborhood Watch Program, which provides managed detection and response (MDR) and endpoint detection and response (EDR) capabilities to managed service providers (MSPs). The program aims to enhance the security capabilities available to MSPs and their clients.
Why it matters: MSPs and their customers should understand what expanded MDR and EDR services Huntress now offers to determine if the program meets their detection and response requirements.
- cloud saas
Introducing the next generation of AI-powered remediation: Choose your own remediation strategy
Wiz has announced an updated version of its AI-powered remediation tool that leverages generative AI (GenAI) and research expertise to identify and address cloud-native attack paths. The tool aims to automate and guide cloud security remediation decisions.
Why it matters: Cloud security teams need to evaluate whether this remediation capability reduces their mean-time-to-remediation for identified cloud-native vulnerabilities and misconfigurations in their environments.
- ai security
Tricks and Treats: Top 3 GenAI Security Best Practices for a Safer Halloween
An article discusses three generative AI security best practices framed around Halloween themes. The piece emphasizes strategies for organizations to mitigate risks associated with generative AI deployments.
Why it matters: Security practitioners need to understand AI security best practices to reduce exposure from generative AI misconfigurations, data leaks, and prompt injection attacks in their organizations.
- breaches incidents
Supply chain attack on lottie-player: everything you need to know
A supply chain attack compromised the lottie-player library, a popular tool used in web development. The compromised versions inject malicious Web3 wallet prompts into affected websites. Users should update to a patched version or revert to an earlier uncompromised release.
Why it matters: Developers and web administrators using lottie-player need to audit and patch immediately to prevent their sites from displaying credential-harvesting prompts to users.
- vulnerabilities
GreyNoise Intelligence Discovers Zero-Day Vulnerabilities in Live Streaming Cameras with the Help of AI
GreyNoise Intelligence identified previously unknown zero-day vulnerabilities in internet-connected live streaming cameras using artificial intelligence (AI) techniques. The discovery represents an early example of AI-augmented threat detection identifying zero-day flaws before active exploitation occurred.
Why it matters: Organizations deploying IoT-connected cameras need to monitor for patches and updates from manufacturers, as zero-day vulnerabilities in streaming devices could enable unauthorized access or surveillance.
- threat intel
The Persistent Perimeter Threat: Strategic Insights from a Multi-Year APT Campaign Targeting Edge Devices
GreyNoise released strategic intelligence on a multi-year advanced persistent threat (APT) campaign that exploited network perimeter vulnerabilities to target high-value entities through edge devices. The research identifies critical security gaps in edge device deployments and provides actionable defensive recommendations for security teams.
Why it matters: Practitioners managing network perimeters and edge infrastructure need to assess whether their organizations are exposed to the same attack patterns, and prioritize patching and monitoring of perimeter devices that may be targeted by sophisticated threat actors.
- vulnerabilities
The essential steps for cloud vulnerability management
Cloud vulnerability management requires a structured workflow approach to prioritize findings effectively and balance speed with accuracy. Organizations need processes that help teams navigate the complexity of vulnerability assessment in cloud environments without overwhelming resources.
Why it matters: Cloud security practitioners need a repeatable prioritization framework today to allocate remediation efforts efficiently and reduce exposure windows in cloud infrastructure.
- cloud saas
Wiz Expands Runtime Protection to Serverless Containers
Wiz has expanded its runtime protection capabilities to cover serverless container environments, adding support for AWS Fargate and Azure Container Apps. The extension provides visibility, blocking, and threat hunting features for these managed container platforms.
Why it matters: Organizations running serverless containers on AWS and Azure need runtime visibility to detect and block threats in production; this expansion addresses a gap for teams managing these workloads.
- threat intel
Protect Yourself from Political Donation Scams | Huntress
Political donation scams are proliferating through robocalls, fraudulent websites, and synthetic media to deceive voters into fraudulent contributions. These schemes exploit civic participation and can result in financial loss and identity compromise for victims.
Why it matters: Employees and voters are at risk of financial fraud and potential credential harvesting through phishing-style donation scams, affecting organizational security awareness and personal cybersecurity hygiene during election cycles.
- identity access
Ask the Mac Guy: What's the Deal with Full Disk Access for Mac? | Huntress
Full Disk Access is a macOS security feature that controls which applications can read and write to sensitive files and directories on a Mac. Understanding this feature is essential for proper system security and ensuring that applications function correctly when they require elevated file permissions.
Why it matters: Mac administrators and security teams need to understand Full Disk Access requirements to properly grant permissions to legitimate tools while preventing malware from gaining unauthorized access to sensitive user data and system files.
- research
AskAI – Text to Security Graph Query
AskAI is a tool that converts natural language text into security graph queries, enabling practitioners to translate written requests into structured database searches. This simplifies the process of extracting security insights from graph-based data repositories without requiring users to learn specialized query languages.
Why it matters: Security teams seeking to streamline threat hunting and incident investigation workflows can adopt this approach to faster, more accessible querying of security telemetry and asset relationships.
- identity access
Protect your Okta identities with Wiz
Wiz announced an extension of its security capabilities to include Okta identity management, offering visibility and risk assessment through its Security Graph platform. The integration provides real-time threat detection specifically for Okta environments.
Why it matters: Identity and access management (IAM) practitioners should evaluate whether this Wiz integration reduces blind spots in Okta monitoring, as improved visibility into identity risks can help prevent unauthorized access and lateral movement.
- industry
Thank You for Helping Us Earn Another Inc. Power Partner | Huntress
Huntress has received an Inc. Power Partner Award for 2024, marking the second consecutive year the cybersecurity company has received this recognition. The award acknowledges contributions from the company's partners.
Why it matters: Partners and resellers working with Huntress may value the vendor's recognition as an indicator of market credibility and partnership stability, though this does not directly impact security operations or threat mitigation today.
- threat intel
U.S. and UK Warn of Russian Cyber Threats: 9 of 12 GreyNoise-Tracked Vulnerabilities in the Advisory Are Being Probed Right Now
The U.S. and UK governments issued a joint advisory identifying 24 vulnerabilities exploited by Russian state-sponsored APT 29. GreyNoise Intelligence confirmed that nine of these vulnerabilities are currently being actively probed in the wild, indicating imminent exploitation risk.
Why it matters: Organizations running affected systems face immediate risk of compromise by a nation-state adversary; prioritize patching the nine actively probed CVEs to prevent intrusion.
- threat intel
Detecting Malicious Use of LOLBins, Pt. II | Huntress
Huntress SOC analysts challenge the common assumption that attackers use LOLBins (living-off-the-land binaries) primarily to evade detection by blending in with normal administrative activity. The article suggests that threat actors' actual use of these legitimate system tools often leaves detectable patterns that differ from typical operational behavior.
Why it matters: Security teams relying on the assumption that LOLBin activity is inherently difficult to detect may miss opportunities to identify attackers; understanding realistic detection methods helps practitioners improve their threat hunting and monitoring strategies.
- threat intel
Inside Adversary-in-the-Middle Attacks | Huntress
Adversary-in-the-Middle (AiTM) attacks intercept and hijack user sessions by positioning malicious actors between clients and servers. The article provides guidance on identifying and preventing these attacks. Understanding AiTM tactics and defenses is essential for protecting authentication mechanisms and user sessions.
Why it matters: Security practitioners need to understand AiTM attack vectors because these threats can bypass standard multi-factor authentication and compromise user accounts across all organizations, requiring detection and prevention strategies in your environment.
- cloud saas
Ta Da! The Wiz Runtime Sensor is now available in Wiz for Gov (FedRAMP)
Wiz has added its Runtime Sensor to Wiz for Gov's Authority to Operate (ATO), expanding the FedRAMP-authorized offering with eBPF (extended Berkeley Packet Filter) based monitoring. The sensor enhances risk prioritization, threat detection, and runtime protection for container hosts and virtual machines in government environments.
Why it matters: Federal agencies and contractors using Wiz for Gov can now deploy deeper runtime visibility and threat detection in containerized and virtualized workloads, improving their ability to detect and respond to attacks in production environments.
- vulnerabilitiesCVE-2024-9463CVE-2024-9464
Critical vulnerabilities in Palo Alto Expedition: everything you need to know
Palo Alto Networks' Expedition tool contains five critical vulnerabilities (CVE-2024-9463, CVE-2024-9464, CVE-2024-9465, CVE-2024-9466, CVE-2024-9467) that require urgent patching. These flaws expose organizations using the migration and assessment platform to significant risk.
Why it matters: Organizations running Palo Alto Expedition must prioritize patching to prevent exploitation of these critical vulnerabilities affecting a widely deployed migration tool.
- cloud saas
AWS Account Vending
AWS account vending and landing zones are two distinct strategies for provisioning and managing cloud environments. Account vending focuses on automated deployment of pre-configured accounts to users or teams, while a landing zone provides a foundational architectural framework for multi-account governance. Understanding the differences helps organizations choose the right approach for their account management and operational needs.
Why it matters: Cloud architects and AWS practitioners need to evaluate which strategy aligns with their organization's scale, governance requirements, and automation maturity to reduce manual overhead and maintain consistent security posture across accounts.
- threat intel
What is Behavioral Analysis in Cybersecurity? | Huntress
Behavioral analysis is an approach in cybersecurity that leverages human judgment to identify attackers and patterns that automated systems may miss. The article discusses how behavioral analysis functions as a complementary method alongside AI and technical controls in threat hunting operations.
Why it matters: Security practitioners should understand behavioral analysis techniques because they fill gaps in automated detection and improve the effectiveness of threat hunting programs.
- ai security
Protecting Democracy From The Growing Threat of Deepfakes and Disinformation
Deepfakes and disinformation campaigns powered by AI are increasingly threatening election integrity and democratic processes. The article discusses how false narratives spread through these tools, erode public trust, and deepen polarization, while calling for public awareness, media literacy, and coordinated defensive approaches.
Why it matters: Election officials, communications teams, and security practitioners need to understand AI-driven disinformation tactics to protect voting systems and public confidence in democratic institutions from manipulation campaigns.
- cloud saas
Cloud Logging Tip & Tricks: Getting the most value out of your cloud logs
Cloud logging provides essential real-time visibility into cloud environment activity and is a fundamental component of detection and response programs. Proper logging practices enable security teams to monitor and investigate events across cloud infrastructure.
Why it matters: Security practitioners need effective logging strategies to detect threats and respond to incidents in cloud environments, which often lack traditional perimeter visibility.
- cloud saas
How Wiz Meets CISA “Secure by Design” Objectives
Wiz has announced its alignment with the Cybersecurity and Infrastructure Security Agency's (CISA) Secure by Design objectives. The company is committing to security practices that integrate protection into product development from the earliest stages rather than adding it afterward.
Why it matters: Organizations evaluating cloud security tools should understand vendors' commitment to secure development practices, which directly impacts the integrity and trustworthiness of the products protecting their environments.
- threat intel
How to Prevent Business Email Compromise: A Guide for 2026
This article provides guidance on preventing business email compromise (BEC) attacks and communicating the threat to employees. BEC remains a significant attack vector targeting organizations of all sizes, requiring both technical controls and employee awareness.
Why it matters: Security practitioners need to understand BEC prevention strategies and how to educate staff, as these attacks directly target financial transactions and sensitive data across most organizations.
- threat intel
Top 3 Cybersecurity Threats of 2024 (So Far) | Huntress
A security report identifies three prominent cybersecurity threats in 2024: remote monitoring and management (RMM) tool abuse, bring-your-own-vulnerable-driver (BYOVD) attacks, and WebDAV protocol abuse. The report outlines defensive strategies for organizations facing these emerging attack vectors.
Why it matters: Security teams need to understand these three attack methods—RMM abuse, BYOVD attacks, and WebDAV abuse—to prioritize detection and prevention controls before these techniques become widespread in their environment.
- regulatory
NERC CIP Training Requirements | Huntress
The Huntress Blog provides guidance on the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) training requirements under CIP-004 R2. The article explains compliance obligations and the specific elements that auditors will evaluate during assessments.
Why it matters: Energy sector security teams responsible for NERC compliance need to understand CIP-004 R2 training mandates to avoid audit findings and maintain regulatory standing.
- ot ics
NERC CIP-014 Standard Explained | Huntress
Huntress provides an explanation of NERC CIP-014, a North American Electric Reliability Corporation (NERC) standard designed to enhance physical security at electric utility facilities. The standard was established to address vulnerabilities in the power grid infrastructure and outlines specific security requirements for utility operators.
Why it matters: Electric utility operators and security teams responsible for critical infrastructure protection need to understand CIP-014 compliance requirements to prevent physical attacks that could disrupt power systems across North America.
- research
What Triggers the Need for Security Awareness Training? | Huntress
The article discusses key triggers and considerations for implementing security awareness training programs in organizations. It emphasizes how training can improve employee vigilance, mitigate security risks, and build a stronger cybersecurity culture.
Why it matters: Security teams and organizational leaders need to understand what drives effective awareness training adoption so they can better prioritize budget and resources to reduce human-factor vulnerabilities.
- threat intel
Password Spraying Tools: How Attackers Spray M365
Huntress Threat Hunters released analysis on password spraying tactics used by threat actors against Microsoft 365 (M365) and other targets, ranging from small businesses to large enterprises. The report documents how attackers employ these techniques to gain unauthorized access by testing common passwords across multiple accounts. Password spraying remains a persistent attack vector due to its simplicity and effectiveness against organizations with weak password policies.
Why it matters: Security practitioners managing M365 environments or identity infrastructure must understand password spraying attack methods to implement appropriate detection rules, rate limiting, and multi-factor authentication controls that prevent or mitigate these attacks.
- research
One Order of Tips, Tricks & Hot Takes for Cybersecurity | Huntress
Huntress has published a collection of security tips, tricks, and commentary to mark Cybersecurity Awareness Month. The piece offers practical guidance and perspectives from the vendor on current security practices and approaches.
Why it matters: Security practitioners evaluating best practices and industry perspectives can review this collection to identify actionable recommendations relevant to their environments and current threat landscape.
- vulnerabilitiesCVE-2024-28995
What Are Hackers Searching for in SolarWinds Serv-U (CVE-2024-28995)?
GreyNoise is tracking exploit attempts targeting CVE-2024-28995 in SolarWinds Serv-U through honeypot monitoring. The research identifies specific files that attackers are targeting and provides real-time visibility into exploitation patterns to help security teams distinguish active threats from background noise.
Why it matters: SolarWinds Serv-U users need to understand active exploitation patterns for CVE-2024-28995 to prioritize patching and threat detection based on observed attacker behavior in the wild.
- vulnerabilitiesCVE-2024-47076CVE-2024-47175
CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, CVE-2024-47177: Everything you need to know
Four vulnerabilities (CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, and CVE-2024-47177) have been identified affecting CUPS (Common Unix Printing System) and Internet Printing Protocol (IPP) packages. These flaws require detection and mitigation efforts from affected organizations.
Why it matters: System administrators managing CUPS and IPP implementations need to assess whether these vulnerabilities affect their infrastructure and plan patching or mitigation strategies.
- vulnerabilitiesCVE-2024-0132
Wiz Research Finds Critical NVIDIA AI Vulnerability Affecting Containers Using NVIDIA GPUs, Including Over 35% of Cloud Environments
Wiz Research disclosed CVE-2024-0132, a critical vulnerability in NVIDIA Container Toolkit and GPU Operator that affects AI workloads running in containerized environments. The vulnerability impacts over 35% of cloud deployments using NVIDIA GPUs, creating significant exposure for organizations leveraging GPU-accelerated containers.
Why it matters: Cloud operators and security teams managing GPU-accelerated container workloads need to assess exposure immediately, as the vulnerability affects a substantial portion of cloud environments and poses direct risk to AI infrastructure.
- threat intel
Friendly Reminder: SAT Can Be Enjoyable | Huntress
Huntress announced a managed security awareness training offering that uses animated, story-based episodes to make security training more engaging for employees. The service aims to improve organizational security posture through more relatable and enjoyable training formats compared to traditional long-form sessions.
Why it matters: Security teams responsible for employee training can reduce phishing susceptibility and security incident risk by adopting more engaging training formats that employees will actually complete and retain.
- cloud saas
Introducing Hybrid File Integrity Monitoring
Wiz has released a hybrid File Integrity Monitoring solution that combines agentless and runtime monitoring approaches for tracking file changes. The product integrates both detection methods to provide broader coverage across infrastructure environments.
Why it matters: Security teams evaluating file integrity monitoring tools should assess whether hybrid agentless and runtime approaches fit their deployment needs and compliance requirements.
- cloud saas
Secure your Data Cloud with Wiz CNAPP for Snowflake
Wiz has announced a Cloud Native Application Protection Platform (CNAPP) offering for Snowflake that provides unified visibility into security posture and threats. The tool integrates with existing cloud security workflows to streamline Snowflake monitoring.
Why it matters: DevOps and security teams using Snowflake should evaluate whether this CNAPP extends their current cloud security visibility to data warehouses and reduces monitoring tool sprawl.
- threat intel
Phishing and Social Engineering: The Human Factor in Election Security
Phishing and social engineering attacks pose significant threats to the 2024 U.S. elections by exploiting human vulnerabilities to compromise systems. The article examines how these tactics work and discusses defensive measures to counter evolving attack methods targeting election infrastructure and personnel.
Why it matters: Election officials, IT security staff, and poll workers need to recognize phishing and social engineering risks today because successful attacks could compromise voter data, election systems, or operational continuity during voting.
- industry
Unlocking SIEM: The Role of Smart Filtering | Huntress
Huntress has announced a Smart Filtering Engine designed to improve log data ingestion and management within Security Information and Event Management (SIEM) systems. The tool aims to help organizations more effectively manage and analyze their security logs.
Why it matters: Security teams managing large volumes of log data need efficient filtering to reduce noise and focus on genuine threats; this capability may reduce alert fatigue and improve investigation speed.
- ransomware
ReadText34 Ransomware Incident | Huntress
Huntress analysts regularly observe ransomware attacks and occasionally identify incidents with novel characteristics that warrant special attention.
Why it matters: Security teams should monitor Huntress threat reports for emerging ransomware tactics and variants that may affect their environments.
- ot ics
Challenging Assumptions: Enhancing the Understanding of Securing Internet-Exposed Industrial Control Systems
Censys and GreyNoise released research at LABSCon 2024 examining real-world threats to internet-exposed Industrial Control Systems (ICS). The findings show that attackers prioritize common Remote Access Service (RAS) protocols over ICS-specific communications when targeting internet-connected human-machine interfaces (HMIs), challenging previous assumptions about how critical infrastructure is compromised.
Why it matters: Industrial control system operators and critical infrastructure defenders need to reconsider their threat model priorities, as the research indicates that generic RAS protocols rather than specialized ICS exploits represent the primary attack vector for internet-connected systems.
- ransomware
Akira Ransomware Indicators | Huntress
Huntress analysts have identified multiple indicators associated with Akira ransomware attacks, including threat actor workstation names, passwords used during account creation or modification, and CloudFlare tunnel tokens. Early detection of these artifacts in the attack chain enables organizations to prevent or block file encryption deployment.
Why it matters: Security teams using Huntress or similar detection tools can now identify Akira compromise activity before encryption occurs, reducing ransomware damage and recovery costs.
- research
Making Sense of Alphabet Soup: 16 Security Terms and Acronyms You Should Know | Huntress
Huntress has published a guide covering 16 essential cybersecurity terms and acronyms that security professionals should understand. The article provides reference material to help practitioners build foundational knowledge in key security concepts.
Why it matters: Security practitioners benefit from standardized terminology and acronym definitions to communicate clearly with teams, leadership, and vendors, and to avoid operational misunderstandings.
- threat intel
The State of the Dark Web | Huntress
Huntress is publishing content about the state of the dark web. The article preview does not provide substantive details about the specific findings or topics covered.
Why it matters: Threat researchers and security practitioners monitoring cybercriminal activity should review this report to understand current dark web trends, actor behavior, and emerging threats relevant to their organization's risk profile.
- cloud saas
Cloud Logging Tips and Tricks
An article providing guidance on cloud logging practices and optimization techniques. The piece offers recommendations for practitioners seeking to improve their logging configurations and data collection strategies in cloud environments.
Why it matters: Security teams managing cloud infrastructure need effective logging to detect threats, investigate incidents, and meet compliance requirements; poor logging practices can result in missed security events or audit failures.
- threat intel
Cracks in the Foundation: FOUNDATION Accounting Intrusions | Huntress
Threat actors are exploiting accounting software commonly used by construction companies to gain unauthorized access to networks. The intrusions, tracked as FOUNDATION, suggest a focused campaign targeting this industry vertical through application vulnerabilities or supply chain weaknesses.
Why it matters: Construction companies and their accountants face direct compromise risk; practitioners should audit access to accounting software, review user activity logs, and patch or isolate affected systems immediately.
- research
The Top 3 Cyber Challenges for Mid-Market Businesses | Huntress
Mid-market businesses face three primary cybersecurity challenges: insufficient time and skilled personnel, human vulnerabilities, and limited budgets. These constraints limit their ability to implement and maintain effective security programs. Organizations in this segment struggle to balance security investments with operational demands.
Why it matters: Mid-market business leaders and security teams need to prioritize resource allocation and adopt scalable solutions that address skill gaps and automate security operations to reduce reliance on specialized staff.
- industry
Wiz joins the Microsoft Intelligent Security Association
Wiz has joined the Microsoft Intelligent Security Association (MISA), a collaborative initiative focused on improving cloud security. The partnership aims to enhance security outcomes through integrated solutions and shared expertise between the two organizations.
Why it matters: Cloud security practitioners should monitor this partnership for new integrated capabilities, API improvements, and coordinated threat intelligence that may affect their Microsoft and Wiz deployments.
- identity access
Are Biometrics the Hero or Villain in Cybersecurity? | Huntress
Biometric authentication systems offer enhanced security capabilities but introduce distinct risks and vulnerabilities that practitioners must understand. The article examines both the benefits and potential downsides of deploying biometric technologies in security architectures.
Why it matters: Security teams evaluating biometric implementations need to weigh improved access controls against emerging attack surfaces, credential compromise risks, and the irreversible nature of biometric data breaches.
- cloud saas
Wiz Code: Experience True ASPM With Code-to-Cloud Context
Wiz has released Wiz Code, a product that integrates third-party static application security testing (SAST) scanners with cloud context to help organizations prioritize and remediate application security risks more efficiently.
Why it matters: Development and security teams using Wiz can accelerate vulnerability remediation workflows by correlating code findings with their cloud deployment context, reducing time spent on triage and prioritization.
- threat intel
The Role of State-Sponsored Actors in Election Interference
State-sponsored actors conduct election interference through cyberespionage and disinformation campaigns designed to undermine democratic processes. These activities target election infrastructure and public trust through coordinated tactics. Effective countermeasures are available to protect electoral systems and maintain the integrity of democratic institutions.
Why it matters: Election officials, government cybersecurity teams, and critical infrastructure defenders need to understand state-sponsored tactics and implement countermeasures to secure voting systems and prevent erosion of public confidence in elections.
- industry
Developers Deserve Better: Why Wiz Code Is Built for You.
Wiz announced Wiz Code, a developer-focused security tool that integrates into development workflows to provide real-time guidance across code and cloud infrastructure. The product aims to reduce remediation delays by catching security issues earlier in the development lifecycle.
Why it matters: Development teams should evaluate whether integrated security tooling reduces the friction of security reviews and accelerates secure code delivery in their CI/CD pipelines.
- industry
Introducing Wiz Code: transform your AppSec with Wiz
Wiz has introduced Wiz Code, a new offering focused on application security within cloud-native environments. The product aims to address security concerns at the code level for organizations building cloud applications.
Why it matters: Development and security teams adopting cloud-native architectures should evaluate whether Wiz Code addresses their application security testing and remediation gaps in the development pipeline.
- industry
MSPCFO: Identifying Operational Improvements from Huntress | Huntress
Huntress has released research examining how managed service providers (MSPs) using its platform experience improvements in ticket management efficiency, operational costs, and overall productivity. The study aims to demonstrate tangible operational benefits that MSPs can achieve through the Huntress security solution.
Why it matters: MSP decision-makers evaluating security platforms should understand the claimed efficiency gains and cost impacts that Huntress delivers to similar organizations.
- industry
You’re the “Why” Behind the Huntress Hub | Huntress
Huntress has launched Huntress Hub, a centralized platform providing resources, training, and marketing tools for security professionals and businesses. The platform aims to streamline workflows and support business growth through integrated cybersecurity resources.
Why it matters: Security practitioners and managed service providers should evaluate whether this hub can reduce tool fragmentation and improve operational efficiency in their security operations.
- ai security
Will Patients’ Data Ever Be Safe if We Let GPTs Into Healthcare? | Huntress
This article examines concerns about integrating large language models into healthcare settings, focusing on the tension between operational benefits and risks to patient data security. The piece features expert perspectives on whether AI systems can be safely deployed in medical environments while maintaining data integrity.
Why it matters: Healthcare practitioners and IT leaders need to understand the security implications of adopting generative AI tools, as patient data sensitivity and regulatory obligations (HIPAA, GDPR) create heightened compliance and breach risk.
- cloud saas
Chaos to Clarity: How Our Community Helped Transform SIEM | Huntress
Huntress developed a Managed SIEM (Security Information and Event Management) product informed by community feedback to address complexity and alert fatigue in security event management. The solution emphasizes simplified operations, reduced noise, and transparent pricing models.
Why it matters: Security practitioners evaluating SIEM platforms should assess whether Huntress Managed SIEM addresses your organization's detection engineering costs and false positive burden compared to alternatives.
- cloud saas
Uncovering Hybrid Cloud Attacks Part 1 – Addressing the Speed of Cloud Attacks
This article introduces a series examining hybrid cloud attack challenges and the difficulty of responding effectively to threats in cloud environments. The piece sets up the problem space around cloud attack speed and response limitations without detailed technical specifics in this first installment.
Why it matters: Security teams defending hybrid cloud infrastructures need to understand attack vectors and response gaps to prioritize detection and incident response capabilities that can keep pace with cloud-native threats.
- cloud saas
Avoiding security incidents due to request collapsing
Request collapsing is a caching optimization feature that can inadvertently expose sensitive data when multiple concurrent requests are merged into a single backend call. Understanding and properly configuring this behavior is necessary to prevent accidental information disclosure in cached systems.
Why it matters: Development and operations teams using caching services need to identify and mitigate request collapsing risks to prevent sensitive data exposure in production environments.
- threat intel
Phishing in the Fast Lane | Huntress
Huntress researchers present an overview of phishing techniques from an attacker's perspective, detailing malicious methods used in contemporary phishing campaigns. The presentation focuses on understanding the tactics and strategies employed by threat actors to compromise targets.
Why it matters: Security practitioners need to understand adversary phishing tactics and techniques to better detect, respond to, and train users against common attack vectors in their organizations.
- cloud saas
Frost & Sullivan recognizes Wiz as Cloud Security Posture Management leader
Frost & Sullivan published a research report evaluating cloud security posture management (CSPM) vendors, recognizing Wiz as a leader based on innovation and growth metrics. The benchmarking exercise assessed vendor performance across these dimensions in the competitive CSPM market.
Why it matters: Security leaders evaluating CSPM tools should review third-party benchmarks like this to inform vendor selection and understand competitive positioning in cloud security solutions.
- threat intel
APT Targeting Vietnamese Human Rights Defenders | Huntress
Huntress discovered a multi-year intrusion targeting a non-profit organization that supports Vietnamese human rights. The attack appears to be conducted by an advanced persistent threat (APT) actor with sustained access to the organization's systems over an extended period.
Why it matters: Human rights organizations and civil society groups should immediately audit their systems for similar indicators of compromise, as this pattern suggests targeted surveillance campaigns against advocacy organizations in the region.
- threat intel
Which States Are Most at Risk for Government Cyberattacks? | Huntress
A report highlights which U.S. states experienced the highest volume of cyberattacks against government and critical infrastructure in 2023, when global attack volume exceeded 420 million. The analysis examines geographic risk patterns across state-level targets.
Why it matters: State and local government officials, critical infrastructure operators, and security teams in high-risk states need to assess their exposure and prioritize incident response readiness based on demonstrated attack patterns in their regions.
- cloud saas
AWS Console Session Traceability: How Attackers Obfuscate Identity Through the AWS Console
AWS Console sessions can be difficult to trace to specific identities when SourceIdentity is not configured in default setups. Attackers may exploit this configuration gap to obscure their actions and complicate attribution efforts. Security teams relying on standard AWS logging may struggle to identify which user performed specific console actions.
Why it matters: AWS account owners and security teams need to verify SourceIdentity configuration to ensure console activity is properly attributed; without it, insider threats and compromised credentials become harder to investigate and track.
- research
Remote Work Security | Huntress
Huntress has released a new SAT (Security Awareness Training) episode featuring a character named Imani learning about security best practices in remote work environments. The episode appears to be part of Huntress's educational content series for security awareness.
Why it matters: Remote workers and their security teams need practical guidance on securing distributed work environments, as remote configurations present unique attack surfaces and endpoint management challenges.
- cloud saas
Defeating Kubernetes Privilege Escalation: A Cloud Detection & Response Case Study
A case study examines how to detect and respond to privilege escalation attacks targeting Kubernetes environments in cloud deployments. The analysis emphasizes the need for rapid, heuristic-based, and contextual detection methods tailored to cloud infrastructure.
Why it matters: Kubernetes operators and cloud security teams need effective detection strategies to identify and respond to privilege escalation attempts before attackers gain elevated access to containerized workloads and cluster resources.
- research
BLUUID: Firewallas, Diabetics, And… Bluetooth
GreyNoise Labs published research on Bluetooth Low Energy (BLE) security, examining remote device identification techniques, vulnerabilities, and implications for IoT and healthcare systems. The work highlights security gaps in BLE implementations across various device categories including firewalls and medical devices.
Why it matters: Security practitioners managing connected devices and healthcare environments should understand BLE attack surface and device fingerprinting risks, as many organizations lack visibility into these wireless communications.
- identity access
Protecting Against Session Hijacking & Credential Theft | Huntress
Huntress has announced a new Unwanted Access capability designed to defend against session hijacking and credential theft attacks. The tool aims to help organizations minimize risks to business-critical assets by detecting and preventing unauthorized access through compromised sessions and stolen credentials.
Why it matters: Security teams managing identity and access controls need to evaluate whether this capability addresses gaps in their current session and credential monitoring to reduce the risk of account compromise.
- vulnerabilities
Unveiling Vulnerability Insights from the CISA KEV Catalog at BSidesLV
A blog post discusses three key insights from an analysis of the CISA Known Exploited Vulnerabilities (KEV) Catalog, presented at BSidesLV. The post aims to help organizations understand and prioritize vulnerabilities that are actively exploited in the wild.
Why it matters: Security teams need to align their patching and remediation workflows with active exploitation data to reduce exposure to threats that adversaries are already weaponizing.
- research
Strategies for performing security migrations
The article discusses strategies and best practices for executing security migrations, covering key approaches such as establishing metrics, configuring alerts, and implementing prevention strategies to ensure successful project completion.
Why it matters: Security teams executing migration projects need practical frameworks for planning and monitoring these complex initiatives to minimize risk and maintain compliance during transitions.
- cloud saas
Increasing transparency in cloud security: Wiz is now a CVE Numbering Authority (CNA)
Wiz has been designated as a CVE Numbering Authority (CNA), enabling the company to assign CVE identifiers for vulnerabilities it discovers or coordinates disclosure for. This designation aims to improve transparency and streamline the vulnerability disclosure process in cloud security.
Why it matters: Cloud security practitioners should track this development as it may accelerate CVE assignment timelines for cloud-specific vulnerabilities and affect how organizations monitor and patch cloud infrastructure exposures.
- threat intel
Emerging phishing campaign targeting AWS accounts
Wiz Threat Research has identified a new phishing campaign specifically targeting Amazon Web Services (AWS) accounts. The campaign appears to be designed to steal credentials and gain unauthorized access to cloud infrastructure. Details about the attack methodology and scope are limited at this time.
Why it matters: AWS users and cloud security teams need to be alert to this campaign and review email security controls, user awareness training, and account access logs for signs of compromise.
- cloud saas
Introducing Wizlympics: The First Cloud Security Olympic Games
A cloud security competition called Wizlympics has launched, framed as an Olympic-style event for participants to demonstrate cloud services expertise. The event appears designed to engage practitioners in competitive cloud security challenges.
Why it matters: Cloud security practitioners interested in skill development and competitive benchmarking should evaluate whether this event aligns with their professional development goals and provides relevant hands-on experience.
- industry
Celebrating a Milestone: 100 WIN Integrations and Counting!
The Wiz Integration (WIN) Platform has reached a milestone of 100 integrations one year after its launch. This represents growth in the platform's ecosystem and connectivity options for users.
Why it matters: Security teams using Wiz should review the new integrations to identify tools that could enhance their cloud security workflows and data sharing capabilities.
- cloud saas
Don't Get Security from Your RMM Provider: Know the Risks | Huntress
An article discusses the risks of purchasing cybersecurity products and services through remote monitoring and management (RMM) providers rather than independent vendors. It examines common pitfalls and recommends evaluating endpoint detection and response (EDR) and managed detection and response (MDR) solutions independently.
Why it matters: MSPs and IT teams need to understand vendor bundling limitations: RMM-integrated security may lack specialization, feature parity, or competitive pricing compared to dedicated EDR/MDR providers, affecting detection and response capabilities.
- vulnerabilities
SlashAndGrab ConnectWise ScreenConnect Vulnerability
Huntress researchers identified a vulnerability in ConnectWise ScreenConnect and provided analysis and community support regarding the discovery. The article outlines how the vulnerability was found and Huntress's role in coordinating the response.
Why it matters: Practitioners using ConnectWise ScreenConnect need to assess exposure and apply patches immediately, as this remote access tool is widely deployed in managed service provider and enterprise environments.
- threat intel
StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms
StormBamboo, a Chinese-linked threat actor, compromised an internet service provider's DNS infrastructure to redirect software update requests to malware-hosting servers. The attacks targeted applications with insecure update mechanisms that use HTTP and lack signature validation, allowing attackers to distribute malware families including MACMA and POCOSTICK to Windows and macOS systems across victim organizations.
Why it matters: Organizations relying on software with HTTP-based update mechanisms and weak signature validation face direct infection risk from DNS-level attacks; practitioners should audit third-party applications for secure update practices and network monitoring for unexpected update traffic.
- vulnerabilities
The Tortilla Test: Ensuring Your Vulnerability Intelligence is Always Fresh
GreyNoise has introduced a real-time vulnerability prioritization tool designed to help security teams focus on current, actively exploited threats. The tool provides actionable intelligence to help organizations address the most pressing vulnerabilities rather than spending resources on theoretical or outdated risks.
Why it matters: Security teams need to prioritize remediation efforts effectively; access to real-time threat data helps practitioners focus on vulnerabilities that pose immediate risk and are likely to be exploited rather than the entire vulnerability backlog.
- vulnerabilities
Huntress CVE Numbering Authority (CNA): Common Vulnerabilities and Exposures Explained
Huntress has become a CVE Numbering Authority (CNA), allowing it to assign CVE IDs to vulnerabilities. The article explains what CNAs do, their role in vulnerability management, and how the CNA program functions. This represents a milestone for Huntress in the vulnerability disclosure ecosystem.
Why it matters: Security practitioners should understand that CNAs like Huntress help expedite CVE assignment for vulnerabilities, which affects how quickly organizations can track and remediate emerging issues.
- cloud saas
Introducing pattern-based agentless malware detection using YARA rules
Wiz has enhanced its detection platform to incorporate pattern-based malware identification through YARA rules developed by its research team, expanding the company's existing security capabilities. This advancement enables automated scanning and identification of malicious code patterns without requiring agent deployment on systems.
Why it matters: Security teams evaluating Wiz's cloud security platform should understand this agentless detection approach reduces deployment complexity and provides additional malware identification options alongside existing tools.
- research
Physical Security 101
This appears to be a general overview of physical security fundamentals and how they relate to enterprise resilience. The piece discusses basic principles for protecting organizational assets through physical security measures.
Why it matters: Security practitioners need to understand physical security basics as part of a comprehensive defense strategy that complements cybersecurity controls and reduces overall organizational risk.
- cloud saas
Understanding the Gartner® Market Guide for Cloud-Native Application Protection Platforms
Gartner has published a market guide examining cloud-native application protection platforms (CNAPPs) and their role in securing modern cloud applications. The guide reflects growing market evolution and the increasing necessity for organizations to adopt these solutions.
Why it matters: Security practitioners evaluating cloud security tools need to understand CNAPP capabilities and positioning to align investments with their application protection strategy.
- industry
Huntress Recognized with 44 New G2 Leader Badges for Summer 2024 | Huntress
Huntress Managed Endpoint Detection and Response (EDR) earned 44 Leader badges across 50 G2 reports in summer 2024 and maintained its number one ranking for the ninth consecutive quarter. The company's product performance reflects continued market recognition in the endpoint security space.
Why it matters: Security teams evaluating EDR solutions should note that Huntress has demonstrated sustained competitive strength, but vendor rankings alone should be one input among hands-on testing, your threat model, and integration needs.
- cloud saas
Mastering cloud security with custom roles: one more step towards democratization
Wiz has introduced a Custom Roles feature to its role-based access control (RBAC) system, allowing organizations to define granular user permissions aligned with their specific security and business requirements. This enhancement provides more flexible permission management while maintaining security controls across cloud environments.
Why it matters: Cloud security teams and administrators need to implement least-privilege access models: Custom Roles in Wiz enable you to reduce over-provisioned permissions and improve access governance without extensive workarounds.
- vulnerabilities
SeleniumGreed: Threat actors exploit exposed Selenium Grid services for Cryptomining
Threat actors are exploiting exposed Selenium Grid services, a popular open-source testing framework, for cryptomining operations. Wiz researchers have documented ongoing campaigns targeting improperly secured instances of the framework that are accessible on the internet.
Why it matters: Security teams running Selenium Grid in development, testing, or CI/CD environments need to verify network access controls immediately, as exposed instances can be hijacked for unauthorized resource consumption and potential lateral movement into internal systems.
- ai security
Introducing the Prompt Airlines CTF: Test Your AI Security Skills
Wiz has announced Prompt Airlines, a new Capture the Flag (CTF) competition designed to test security practitioners' skills in identifying and exploiting AI vulnerabilities within cloud environments.
Why it matters: Security professionals should engage with hands-on AI security exercises to develop practical skills in identifying AI-specific vulnerabilities before encountering them in production systems.
- threat intel
When Trust Becomes a Trap: Foiling a Medical Software Hack | Huntress
Huntress identified a malware distribution campaign where attackers created a fraudulent clone of a legitimate medical image viewer website to deceive users. The threat was detected and disclosed before widespread compromise occurred, preventing potential harm to healthcare organizations. This incident highlights the risks of domain spoofing and the importance of rapid threat detection in the healthcare sector.
Why it matters: Healthcare IT teams and security operations centers need to monitor for malicious clones of trusted medical software vendors and implement controls to verify software authenticity, as users may unknowingly download malware when seeking legitimate tools.
- threat intel
Understanding the Election Cybersecurity Landscape
GreyNoise is launching a multipart series examining election cybersecurity threats and protective measures. The series will cover state-sponsored actors, phishing, social engineering, deepfakes, and disinformation as key risks to election integrity.
Why it matters: Election officials, poll workers, and IT staff need to understand current threats and mitigation strategies to defend critical election infrastructure and processes.
- cloud saas
Your control tower to secure code across GitHub, GitLab, and Azure Repos
Wiz has released a security solution that provides visibility and control across code repositories on GitHub, GitLab, and Azure Repos. The offering integrates configuration checks and code scanning capabilities to secure development pipelines.
Why it matters: Development teams using multiple repository platforms need to assess whether this centralized visibility tool reduces gaps in code security and reduces manual scanning overhead.
- vulnerabilities
SAPwned: SAP AI vulnerabilities expose customers’ cloud environments and private AI artifacts
Wiz Research identified vulnerabilities in SAP AI Core that could allow attackers to take control of the service and access customer data and private AI artifacts stored within cloud environments.
Why it matters: SAP AI Core customers need to assess their exposure immediately, as attackers could potentially compromise accounts, steal intellectual property, and access sensitive business data stored in the platform.
- threat intel
Fake Browser Updates Lead to BOINC Volunteer Computing Software | Huntress
Security researchers at Huntress have identified a new malware delivery technique involving fake browser updates that distribute BOINC volunteer computing software. The malicious variant appears to be related to SocGholish malware and represents an evolving method to compromise systems through socially engineered software updates.
Why it matters: Organizations and individuals using volunteer computing platforms are at risk of credential theft and system compromise through convincing fake update prompts; security teams should educate users on verifying legitimate update sources and consider blocking or monitoring BOINC execution in enterprise environments.
- threat intel
Cybersecurity Threats to Dental Practices: What's Happening | Huntress
The FBI recently issued a warning to dental practices regarding potential cyberattacks. Dental organizations face elevated security risks and require proactive defense measures to protect patient data and operational continuity.
Why it matters: Dental practice administrators and IT teams need to understand the specific threat landscape targeting their sector and implement appropriate security controls to prevent data breaches and ransomware attacks.
- cloud saas
Enhance existing security workflows with high-fidelity cloud security data from Wiz in ServiceNow
Wiz has integrated its cloud and container security capabilities with ServiceNow, enabling organizations to incorporate Wiz's security data into their existing CMDB, vulnerability response, and IT service management workflows.
Why it matters: Security and operations teams using ServiceNow can now enrich their incident management and vulnerability tracking with cloud-native security context, reducing tool sprawl and streamlining response workflows.
- industry
9 Pro Tips for Better Endpoint Security | Huntress
This article provides guidance on endpoint security best practices for IT and security professionals. The piece covers recommended approaches to securing endpoints as part of a comprehensive cyber defense strategy.
Why it matters: Security practitioners need current best practices to evaluate and improve their endpoint protection posture, which is foundational to reducing attack surface.
- cloud saas
Guardians of Compliance: Unleashing the Magic of Wiz4Wiz
Wiz, a cloud security platform, provides governance, risk, and compliance (GRC) capabilities that help teams improve operational efficiency. The article highlights how organizations can leverage Wiz's features to streamline compliance workflows and maximize their GRC program effectiveness.
Why it matters: GRC teams should evaluate whether Wiz's capabilities address their compliance management gaps and reduce manual overhead in governance and risk activities.
- government policy
Defending Critical Infrastructure Against Cyber Threats | Huntress
Huntress discusses the current landscape of cyber threats targeting critical infrastructure and offers guidance for state and local government entities on defensive strategies. The article addresses how these organizations can strengthen their security posture to mitigate breach risks.
Why it matters: State and local government officials and their security teams need to understand emerging threats to critical infrastructure and implement effective defenses to prevent operational disruption and data compromise.
- industry
Wiz Ranked #1 CNAPP and CSPM by G2
Wiz received top rankings in G2's Summer 2024 Grid Reports for cloud-native application protection platform (CNAPP) and cloud security posture management (CSPM) categories, based on independent customer reviews.
Why it matters: Cloud security practitioners evaluating CNAPP and CSPM solutions should note Wiz's market positioning when assessing tools for cloud workload and configuration management.
- cloud saas
How Wiz customers are flippin' vulnerabilities this July 4th weekend
Wiz reports that 40% of its customers have achieved zero critical vulnerabilities in their cloud environments. The article highlights three companies that successfully eliminated critical security issues in their infrastructure.
Why it matters: Cloud security practitioners should understand best practices for identifying and remediating critical vulnerabilities, as this trend reflects achievable security posture improvements in production environments.
- threat intel
Hackers Are Hiding in Plain Sight | Huntress
Huntress released its 2024 Cyber Threat Report highlighting trends in cyberattacks, including criminals leveraging legitimate remote monitoring tools and cloud storage services to blend into normal system operations.
Why it matters: Security teams need to understand how attackers abuse legitimate tools to avoid detection, requiring enhanced monitoring and visibility into remote access and cloud service usage patterns.
- vulnerabilitiesCVE-2024-6387
RCE vulnerability in OpenSSH: everything you need to know
CVE-2024-6387 is a remote code execution vulnerability in OpenSSH that allows attackers to execute arbitrary code on affected systems. Organizations should apply patches immediately to mitigate the risk.
Why it matters: Any organization running vulnerable OpenSSH versions faces potential unauthorized access and full system compromise; patching is a critical priority to prevent active exploitation.
- industry
It’s Magic! Wiz named Microsoft Commercial Marketplace Partner of the Year
Wiz has been named Microsoft's Commercial Marketplace 2024 Partner of the Year in recognition of its go-to-market and joint-selling efforts. The award acknowledges Wiz's collaboration with Microsoft and performance within the Microsoft partner ecosystem.
Why it matters: Security practitioners should note this partnership recognition as it may signal expanded integration between Wiz's cloud security offerings and Microsoft's platform, potentially affecting deployment options and feature availability.
- vulnerabilitiesCVE-2024-0769
Perma-Vuln: D-Link DIR-859, CVE-2024-0769
A path traversal vulnerability (CVE-2024-0769) in the D-Link DIR-859 router enables extraction of account details through information disclosure. The device is end-of-life and will not receive patches, creating a permanent exposure for users who continue operating it.
Why it matters: Organizations and users running DIR-859 routers face persistent risk of credential theft with no vendor remediation available, requiring immediate device replacement or network isolation.
- breaches incidents
Accidental vs. Intentional Data Loss in Healthcare | Huntress
Healthcare organizations face data loss risks from both accidental equipment misplacement and intentional theft or insider threats. The article discusses practical security measures to protect sensitive patient data and maintain trust. Effective data protection requires strategies addressing multiple threat vectors in healthcare environments.
Why it matters: Healthcare practitioners need to implement controls against accidental device loss and insider threats to avoid patient data exposure, regulatory violations, and reputational damage.
- industry
Huntress and Our Culture of BElonging | Huntress
Huntress Chief People Officer Todd Riesterer discusses the company's approach to workplace culture, emphasizing humaneness, equity, and diversity as core pillars of organizational values.
Why it matters: Practitioners should recognize that security vendors' internal culture and hiring practices can influence their approach to customer support, product development, and threat research quality.
- industry
Auto-Remediations: Save Precious Time on Low-Level Incidents | Huntress
Huntress has introduced an Auto-Remediations feature designed to automatically address low-severity security incidents. The feature aims to reduce manual response time by instantly remediating low-level threats, allowing security teams to focus on higher-priority issues.
Why it matters: Security operations teams managing multiple endpoints can reduce incident response overhead by automating remediation of low-severity threats, freeing resources for critical risks.
- vulnerabilitiesCVE-2024-37032
Probllama: Ollama Remote Code Execution Vulnerability (CVE-2024-37032) – Overview and Mitigations
Wiz Research identified CVE-2024-37032, a remote code execution vulnerability in Ollama, an open-source AI infrastructure project. The vulnerability is described as easy to exploit, presenting a significant risk to deployments running affected versions.
Why it matters: Organizations running Ollama in production environments need to assess their exposure and apply patches immediately, as the low barrier to exploitation increases the likelihood of compromise.
- industry
Tailored Cybersecurity vs. Bundles like K365 | Huntress
Bundled cybersecurity solutions like Kaseya K365 may not deliver optimal value for all organizations compared to tailored alternatives. The article discusses how to evaluate and select more effective endpoint detection and response (EDR) and managed detection and response (MDR) solutions for specific organizational needs.
Why it matters: Security teams making vendor decisions need to assess whether bundled packages align with their risk profile and budget, as generic bundles can leave gaps or waste resources on unnecessary services.
- ai security
GenAI risks to be aware of — and prepare for — according to Gartner®
Gartner identifies emerging security risks associated with deploying generative artificial intelligence systems, large language models (LLMs), and conversational chat interfaces that expand potential attack surfaces. Organizations need to understand and prepare for these expanded threats as GenAI adoption accelerates across enterprises.
Why it matters: Security practitioners must assess how GenAI deployments in their organizations create new attack vectors and data exposure risks, requiring updated threat modeling and security controls.
- industry
Here’s to the Future | Huntress
Huntress announced a Series D funding round led by CEO Kyle Hanslovan. The investment will support the company's continued growth and partner enablement in the cybersecurity market.
Why it matters: MSP and security partners relying on Huntress for threat detection and response tools should monitor how this funding shapes product roadmap priorities and partner programs.
- cloud saas
Wiz at Re:Inforce 2024
Wiz shared updates and announcements at the Re:Inforce 2024 conference. The article provides a recap of the company's presentations and initiatives showcased at the event.
Why it matters: Cloud security practitioners should review Wiz's latest capabilities and product updates to evaluate potential enhancements to their current security posture and tool portfolio.
- ai security
Debunking 5 Major macOS Myths | Huntress
Huntress addresses misconceptions about macOS security, noting that the operating system has become an increasingly common target for attackers. The article provides factual information about macOS vulnerabilities and recommends practical security measures to strengthen protection.
Why it matters: Security practitioners managing macOS environments need accurate threat intelligence to prioritize defenses effectively, as outdated assumptions about macOS security may leave systems underprotected against active exploitation.
- cloud saas
Custom runtime rules and runtime response policies: new layers of defense
Wiz has introduced custom runtime rules and runtime response policies as additional security controls for defense-in-depth strategies. These new features enable organizations to define and enforce runtime behavior policies tailored to their environment.
Why it matters: Security teams implementing container and cloud workload protection should evaluate whether Wiz's runtime enforcement capabilities align with their incident response and policy requirements.
- cloud saas
Wiz remediation and response: enforcing security best practices and responding to incidents made easy
Wiz has announced remediation and response capabilities designed to enforce security policies in real-time and streamline incident management workflows. The features aim to help organizations implement automated response actions and policy enforcement across their environments.
Why it matters: Security practitioners managing cloud and SaaS environments need remediation automation to reduce mean time to response and enforce consistent security policies at scale.
- cloud saas
Mistakes to Mastery | Huntress
Huntress has introduced Phishing Defense Coaching, a new feature within its Security Awareness Training (SAT) platform that provides personalized feedback to users after phishing simulations to help them identify threats more effectively.
Why it matters: Security teams responsible for user training and phishing readiness need awareness of new coaching tools available to improve training effectiveness and reduce click-through rates in their user base.
- ransomware
Examining the Impact of Ransomware on the Healthcare | Huntress
Ransomware attacks on healthcare organizations have increased, prompting new guidance from the Department of Health and Human Services (HHS) to address the trend. The article examines factors contributing to the surge and the regulatory response to mitigate risk in the sector.
Why it matters: Healthcare IT leaders and security practitioners need to understand current attack vectors and compliance expectations as HHS guidance may shape incident response requirements and security investments.
- threat intel
Pause off my cluster: DERO cryptojacking takes a new shape
Threat actors behind the DERO cryptojacking campaign have evolved their attack methods to avoid detection systems. Security researchers have documented these new techniques and provided mitigation guidance for organizations to protect against this evolving threat.
Why it matters: DevOps and cloud infrastructure teams should review DERO's updated tactics to identify potential indicators of compromise in their environments and implement the recommended defenses before attackers exploit their clusters.
- ransomware
Healthcare in the Crosshairs | Huntress
Huntress released a cyber threat report discussing ransomware and business email compromise (BEC) threats currently targeting the healthcare sector. The report provides guidance on identifying and addressing these emerging threats.
Why it matters: Healthcare administrators and security teams need awareness of active ransomware and BEC tactics to protect patient data and operational continuity, which directly impact clinical services and regulatory compliance.
- cloud saas
Sail Further with Wiz Cost Optimization for Amazon EKS
Wiz has released a cost optimization feature for Amazon Elastic Kubernetes Service (EKS) that identifies outdated clusters to help organizations reduce cloud infrastructure spending. The tool enables teams to rationalize their EKS deployments and redeploy savings toward business priorities.
Why it matters: DevOps and cloud security teams managing Kubernetes on AWS should evaluate whether this feature applies to their environment, as outdated clusters represent both cost waste and potential security exposure.
- regulatory
Wiz achieves StateRAMP authorization
Wiz, a cloud security platform provider, has obtained StateRAMP authorization for its government-focused offering. StateRAMP is a federal authorization process that validates security controls and compliance for systems used by state and local government agencies.
Why it matters: State and local government IT teams can now procure Wiz with pre-validated compliance credentials, reducing their authorization timelines and enabling faster deployment of cloud security tools across public sector environments.
- industry
Macs Need Security Too: Announcing Huntress Managed EDR for macOS | Huntress
Huntress announced a managed endpoint detection and response (EDR) solution designed specifically for macOS systems. The announcement addresses growing security threats targeting Apple's operating system as its adoption increases in enterprise environments.
Why it matters: macOS administrators and security teams need EDR solutions that understand platform-specific attack vectors to protect increasingly prevalent Mac deployments from targeted threats.
- ai security
Wiz AI-SPM model scanning: Securely innovate with AI community models
Wiz has introduced an AI-SPM (AI Security Posture Management) model scanning capability designed to detect malicious hosted AI models. The tool helps organizations identify security risks in the AI models that data science teams rely on. This addresses the growing need for security controls as enterprises increasingly integrate third-party and community AI models into their workflows.
Why it matters: Data scientists and security teams adopting third-party AI models need to screen for compromised or malicious models before deploying them, making this detection capability relevant for organizations using untrusted model sources.
- threat intel
Attack Behaviors | Huntress
Huntress examines whether threat actors genuinely change their tactics frequently or if this is an overstated assumption in the security industry. The analysis questions common claims among analysts about tactical evolution and examines actual incident data to determine patterns in adversary behavior.
Why it matters: Security practitioners should understand actual threat actor behavior patterns to allocate detection and response resources effectively, rather than relying on industry assumptions.
- cloud saas
Wiz launches new data center in UAE, supercharging global operations in the region
Wiz, a cloud security platform provider, has opened a new data center in the United Arab Emirates to expand its regional operations. The facility enables organizations in the region to access Wiz's security services with improved local infrastructure.
Why it matters: Organizations using or evaluating Wiz in the Middle East region now have local data residency options, which may improve compliance posture and reduce latency for cloud security operations.
- cloud saas
Empowering SecOps in the cloud: enhancing threat detection with Wiz and Google Security Operations
Wiz has integrated its platform with Google Security Operations to improve cloud threat detection capabilities for security operations teams. The integration aims to help organizations identify and address critical security issues more effectively in cloud environments.
Why it matters: SecOps teams using both Wiz and Google Cloud need to evaluate whether this integration improves their detection workflows and reduces time to identify critical cloud misconfigurations and threats.
- threat intel
The Rise of Social Engineering Across Healthcare | Huntress
Healthcare organizations face an escalating threat from social engineering attacks that exploit human error and organizational vulnerabilities. Social engineering tactics target staff to gain unauthorized access and compromise sensitive patient data and systems. Understanding these attack vectors is essential for healthcare security teams to implement effective defenses.
Why it matters: Healthcare practitioners and security teams need to recognize and defend against social engineering tactics that compromise staff and systems, exposing patient data and operational continuity.
- vulnerabilities
The risk in malicious AI models: Wiz Research discovers critical vulnerability in AI-as-a-Service provider, Replicate
Wiz Research identified a critical vulnerability affecting Replicate, an AI-as-a-service platform. The discovery highlights security risks within AI service providers that could impact downstream users and deployed models.
Why it matters: Organizations using Replicate or similar AI-as-a-service providers need to assess exposure and apply patches or mitigations to prevent exploitation of AI infrastructure and model integrity.
- threat intel
Smuggler’s Gambit | Huntress
Huntress has published analysis of adversary-in-the-middle tradecraft techniques observed targeting their partner network. The post documents specific attack methods used against managed service provider (MSP) customers and infrastructure.
Why it matters: MSP partners and their clients need to understand these active attack patterns to detect and defend against credential interception and identity compromise in their environments.
- cloud saas
Shifting from CWPP to CNAPP: new standards for cloud security
Cloud Native Application Protection Platform (CNAPP) and Cloud Workload Protection Platform (CWPP) are complementary cloud security approaches that differ in scope and integration. CNAPP represents a broader, more unified framework compared to CWPP, and the market is increasingly adopting CNAPP to address modern cloud security requirements. This shift reflects demand for more comprehensive and integrated solutions in cloud environments.
Why it matters: Security teams selecting cloud protection tools need to understand CNAPP vs. CWPP distinctions to ensure their solution covers application protection, workload security, and compliance at the integrated level required by modern cloud-native deployments.
- vulnerabilities
Wiz achieves Red Hat Vulnerability Scanner Certification
Wiz has obtained Red Hat Vulnerability Scanner Certification, which allows its vulnerability scanning capabilities to be recognized as certified for assessing vulnerabilities in Red Hat products. This certification indicates that Wiz's scanning tool meets Red Hat's standards for vulnerability detection in their environment.
Why it matters: Red Hat customers using Wiz can now rely on certified vulnerability assessment for their Red Hat infrastructure, reducing risk of missed or misclassified vulnerabilities in production systems.
- cloud saas
The magic of inclusion: Wiz’s journey to democratize cloud security
Wiz has launched initiatives focused on making cloud security tools and knowledge more accessible to a broader range of stakeholders. The effort aims to remove barriers that have traditionally limited who can participate in and benefit from cloud security practices.
Why it matters: Cloud security teams and practitioners benefit from expanded access to tools and resources, lowering costs and improving organizational security posture across companies of all sizes.
- cloud saas
The wait is over: Wiz releases real-time CSPM
Wiz has released a real-time cloud security posture management (CSPM) capability designed to detect and prevent misconfigurations in cloud environments before they can be exploited.
Why it matters: Cloud infrastructure teams need to evaluate whether real-time CSPM will reduce the time window for misconfiguration-based attacks compared to their current posture management tools.
- cloud saas
Unveiling the power of Wiz's Security Graph with automated blast radius and root cause analysis for cloud incident response
Wiz has released a Security Graph feature that helps incident response and security operations teams automatically assess security incidents by identifying root causes and calculating the potential blast radius of compromised cloud resources. The tool is designed to assist with faster containment and response in cloud environments.
Why it matters: IR and SOC teams need to understand incident scope and impact quickly; this feature speeds up blast radius analysis and root cause identification to reduce mean time to response.
- industry
Time to Act | Huntress
Huntress MDR (Managed Detection and Response) offers organizations capabilities for rapid incident response to cyber threats. The service emphasizes providing defenders with time advantages in responding to security incidents.
Why it matters: Security teams evaluating detection and response services should assess whether faster incident response aligns with their risk tolerance and operational capabilities.
- industry
Active Remediation: Proactive Response with Huntress Managed EDR | Huntress
Huntress Managed Endpoint Detection and Response (EDR) offers an Active Remediation feature that enables automated threat response capabilities. The service aims to provide organizations with proactive threat mitigation without requiring manual intervention.
Why it matters: Security teams managing multiple endpoints need to evaluate whether automated remediation aligns with their incident response workflow and risk tolerance, as it shifts response timing from human-reviewed to system-initiated actions.
- industry
From South Park to Curriculaville | Huntress
Huntress has brought on Jeff Gill, an Emmy award-winning animator and storyteller, to create content for its Security Awareness Training program. Gill's background in animation and narrative design will contribute to Huntress's security education offerings.
Why it matters: Security teams using Huntress awareness training should understand that the quality and engagement level of training content directly affects employee security behavior and incident prevention.
- industry
Celebrating Our $1 Billion Funding Round and $12 Billion Valuation
A company announced a $1 billion funding round that valued the organization at $12 billion. The announcement included acknowledgment of stakeholders including customers, investors, and employees.
Why it matters: Security practitioners should monitor vendor financial health and leadership changes, as funding rounds and valuations can signal shifts in product roadmap, pricing, or service availability that affect your security stack.
- cloud saas
What does "Platform" mean in cloud security?
The article discusses the term 'platform' in the context of cloud security, exploring its definition and role in security frameworks. It emphasizes the importance of platform security across the full lifecycle, from development through cloud deployment to security operations.
Why it matters: Cloud security teams and developers need a shared understanding of 'platform' to effectively implement integrated security controls across their entire infrastructure.
- ransomware
Healthcare Held Hostage: Fighting the Plague of Ransomware | Huntress
Ransomware attacks continue to pose a significant threat to the healthcare sector, affecting patient care and operational continuity. Organizations are increasingly turning to managed security solutions to defend against these evolving threats. The article discusses the ransomware landscape in healthcare and mitigation strategies.
Why it matters: Healthcare providers and IT teams need to prioritize ransomware defenses because attacks directly disrupt patient care, delay treatments, and expose sensitive health data; managed detection and response services offer a practical path to faster threat detection and containment.
- ransomware
LOLBin to INC Ransomware
Huntress has detected ongoing INC ransomware deployment activity with indications that the threat actors may be refining or shifting their operational tactics.
Why it matters: Organizations targeted by INC ransomware need to understand the group's evolving methods to strengthen defenses and incident response procedures.
- ot ics
The Undeniable Benefits of Healthcare Security Awareness | Huntress
Huntress discusses the benefits of implementing security awareness training programs within healthcare organizations. The article emphasizes how security awareness can help build a culture of security and protect against threats in the healthcare sector.
Why it matters: Healthcare security leaders and IT teams need awareness training programs to reduce human error and improve their organization's defense posture against cyber threats targeting patient data and critical systems.
- threat intel
LightSpy Malware Variant Targeting macOS | Huntress
A new variant of LightSpy malware has been discovered targeting macOS systems, expanding the scope of this threat beyond its previously documented iOS focus. Huntress researchers analyzed the macOS variant and found it represents a previously unreported capability of the LightSpy malware family.
Why it matters: macOS users and organizations running Apple systems need to assess their exposure to LightSpy and implement detection measures, as this represents an expansion of an active threat family into a new platform.
- cloud saas
Stay safe with Wiz's winning hand for securing Kubernetes
Wiz has released guidance for securing Kubernetes environments aligned with OWASP's Kubernetes Top 10 framework, including reporting and remediation capabilities. The offering aims to help organizations identify and address security issues in container orchestration platforms.
Why it matters: Platform teams and security practitioners managing Kubernetes clusters need to understand current attack patterns and remediation approaches to reduce exposure from misconfigurations and known weaknesses in their container infrastructure.
- cloud saas
It Costs How Much? | Huntress
Managed endpoint detection and response (EDR) solutions can help small and medium-sized businesses address cybersecurity resource constraints by providing threat prevention capabilities while reducing long-term costs. The article discusses how outsourced EDR services enable SMBs to achieve security outcomes despite budget limitations.
Why it matters: SMBs with constrained security budgets need to understand whether managed EDR delivers cost-effective threat detection and response to justify vendor investment and reduce breach risk.
- cloud saas
Expanding coverage with Linux runtime
Wiz has released a Runtime Sensor for Linux, extending its threat detection and response capabilities to cloud workloads running on Linux systems.
Why it matters: Cloud security teams using Linux in their environments can now monitor and respond to runtime threats more comprehensively, reducing gaps in workload visibility.
- cloud saas
Boosting efficiency with Wiz's AI-driven remediation steps powered by Amazon Bedrock
Wiz has introduced AI-driven remediation steps powered by Amazon Bedrock to help customers address risks more efficiently. The feature leverages generative AI to automate and accelerate the remediation process. This capability aims to reduce the time and effort required for security teams to resolve identified vulnerabilities and misconfigurations.
Why it matters: Security teams using Wiz can now streamline incident response and reduce mean time to remediation, improving their operational efficiency and reducing exposure windows.
- cloud saas
What does "democratizing cloud security" mean?
Cloud security democratization refers to making security a shared responsibility across all organizational levels as cloud adoption expands. Organizations are exploring how to engage broader teams in security practices beyond traditional IT security departments.
Why it matters: Security practitioners need to understand how to implement shared security responsibility models across their organizations to reduce exposure as cloud use grows.
- industry
Wiz Acquires Gem Security to Reinvent Threat Detection in the Cloud
Wiz has acquired Gem Security to strengthen its cloud detection and response capabilities. The acquisition is part of Wiz's strategy to consolidate technology and enhance threat detection offerings for cloud environments.
Why it matters: Cloud security teams should monitor how this acquisition affects Wiz's product roadmap and pricing, as consolidation can impact existing deployments and feature availability.
- industry
Huntress Snags Over 40 Leader Badges in G2 Spring 2024 Reports | Huntress
Huntress earned 42 leader badges in G2's Spring 2024 Reports. The recognition reflects the company's standing across multiple software categories and user satisfaction metrics. G2 leader badges typically indicate top performance in functionality, customer satisfaction, or both.
Why it matters: Security practitioners evaluating endpoint detection and response (EDR) or managed detection and response (MDR) vendors should note Huntress' strong market positioning and customer satisfaction ratings when comparing solutions for their environment.
- cloud saas
Operationalizing cloud security with Wiz and Tines
Wiz, a cloud security platform, has partnered with Tines, an automation platform, to integrate visibility and automated response capabilities for cloud security operations. The partnership aims to help organizations streamline their cloud security workflows by combining asset discovery and threat detection with automated remediation.
Why it matters: Cloud security practitioners should evaluate whether integrated visibility and automation reduce mean time to response for cloud misconfigurations and threats in their environment.
- ot ics
Interconnected Devices Inject Risk into Patient Safety | Huntress
Healthcare providers face security risks from interconnected medical devices that could compromise patient safety and data protection. The article discusses how managed Endpoint Detection and Response (EDR) solutions and expert partnerships can help healthcare organizations address these device security challenges and maintain continuity of care.
Why it matters: Healthcare IT teams need to secure medical devices and clinical infrastructure to prevent patient harm and regulatory violations, making managed EDR and vendor partnerships a practical approach to reduce device-related risks.
- cloud saas
Finding the needle in the haystack: effortless SBOM search in your cloud with Wiz
Wiz announced a feature for searching Software Bill of Materials (SBOM) data across cloud environments to help identify where operating system and open-source packages are deployed. The capability allows security teams to locate vulnerable components before they become active threats in production infrastructure.
Why it matters: Cloud platform operators and security engineers need to quickly discover which systems contain specific packages to prioritize remediation when new vulnerabilities are disclosed.
- ai security
Wiz Research finds architecture risks that may compromise AI-as-a-Service providers and consequently risk customer data; works with Hugging Face on mitigations
Wiz researchers identified architectural vulnerabilities in AI-as-a-Service platforms that could expose customer data. The researchers collaborated with Hugging Face to develop and implement mitigations for the discovered risks.
Why it matters: AI platform operators and customers need to review their infrastructure for similar architectural weaknesses that could lead to unauthorized data access or service compromise.
- vulnerabilities
Defense in depth: XZ Utils
This article discusses defense strategies for the XZ Utils vulnerability, covering assessment, prevention, and detection approaches to protect organizations from exploitation. It focuses on practical defensive measures rather than detailing the vulnerability itself.
Why it matters: Security practitioners need actionable guidance on XZ Utils risk assessment, prevention controls, and detection methods to secure their systems and respond to this critical vulnerability.
- industry
Wizards of security, casting spells on themselves for ultimate digital security
Wiz, a cloud security vendor, uses its own platform to monitor its cloud infrastructure and services, demonstrating internal adoption of its security tooling. The article describes Wiz's security practices and how the company applies its own solutions to its operations.
Why it matters: Organizations evaluating Wiz's cloud security platform benefit from knowing that the vendor practices internal adoption; practitioners should assess whether Wiz's approach aligns with their own cloud monitoring and infrastructure security needs.
- threat intel
Analyzing a Malicious Advanced IP Scanner Google Ad Redirection | Huntress
Threat actors are distributing malicious versions of Advanced IP Scanner through malvertising campaigns to compromise targets. The malware masquerades as the legitimate network scanning tool, redirecting users via Google ads to malicious sites.
Why it matters: Organizations and individuals relying on legitimate system administration tools are at risk of compromise through trusted search results. Practitioners should verify software sources and block known malicious ad campaigns redirecting to fake scanner downloads.
- vulnerabilitiesCVE-2024-3094
Backdoor in XZ Utils allows RCE: everything you need to know
CVE-2024-3094 is a critical backdoor discovered in XZ Utils, a widely used data compression library, that enables remote code execution. This represents a significant supply chain compromise affecting systems that depend on the affected software. Organizations need to urgently apply patches to mitigate the risk.
Why it matters: Any organization using XZ Utils or systems that depend on it faces immediate RCE risk and should patch immediately; this supply chain vulnerability could affect countless downstream applications and infrastructure.
- cloud saas
Security Posture Management for GitHub: spotting and fixing risks in your GitHub organization just got a lot easier
Wiz has released a security posture management (SPM) tool for version control systems that helps identify and remediate risks within GitHub organizations. The tool simplifies the process of spotting and addressing security issues in GitHub instances.
Why it matters: Development teams and security practitioners managing GitHub organizations need visibility into misconfigurations and access risks that could expose code or credentials; this tool provides automated detection and remediation guidance.
- threat intel
MSSQL to ScreenConnect | Huntress
Huntress has observed ongoing attacks against MSSQL server systems, identifying patterns across incidents including reuse of living-off-the-land binaries (LOLBins) and consistent IP addresses attributed to threat actors.
Why it matters: Security teams managing MSSQL deployments should review network logs and process monitoring for indicators of compromise from known threat actor IPs and LOLBin usage patterns to detect potential intrusions early.
- industry
How Huntress Managed EDR Stands Against the Competition | Huntress
Huntress has published a comparison of its Managed Endpoint Detection and Response (EDR) offering against competing solutions, highlighting features and benefits that differentiate its platform. The article examines key capabilities and outcomes across EDR vendors to help organizations understand their options.
Why it matters: Security teams evaluating EDR platforms need to understand feature differentiation and competitive positioning when selecting tools for endpoint protection and threat detection.
- cloud saas
Announcing the release of “Google Cloud Security Foundations for Dummies”
Google has released a new guide titled 'Google Cloud Security Foundations for Dummies' designed to help users understand security practices on the Google Cloud platform.
Why it matters: Google Cloud customers and security teams should review this resource to align their cloud security practices with Google's recommended foundations and reduce misconfigurations.
- cloud saas
Uncle Sam wants you… to secure your cloud: takeaways from the NSA’s top ten cloud security mitigation strategies
The NSA has published a list of top ten cloud security mitigation strategies. The guidance addresses key cloud security risks and provides recommendations for securing cloud infrastructure.
Why it matters: Organizations using cloud services should review NSA guidance to align security practices with government best practices and reduce exposure to common cloud attacks.
- cloud saas
Announcing the release of the Financial Services Cloud Security Playbook
Wiz has released a cloud security playbook designed for financial services organizations. The playbook provides guidance on implementing and managing cloud security practices within the financial services sector.
Why it matters: Financial services practitioners need practical cloud security frameworks to address sector-specific regulatory requirements and protect sensitive customer data in cloud environments.
- regulatory
7 Don’ts of Security Awareness Training
This article discusses common pitfalls in security awareness training (SAT) programs that hinder effectiveness and knowledge retention. It examines features and approaches that typically reduce the impact of SAT solutions on organizational security posture.
Why it matters: Security leaders and training program managers need to understand counterproductive SAT design patterns to avoid wasting budget and ensure employees actually retain security behaviors.
- cloud saas
Securing the Cloud Together: Wiz and Splunk team up to secure your cloud resources
Wiz and Splunk have integrated their platforms, allowing customers to use a Wiz app within Splunk to consume and analyze cloud security data through a dedicated dashboard. This integration aims to streamline cloud resource security monitoring and visibility for organizations using both tools.
Why it matters: Security teams using Splunk for SIEM and Wiz for cloud security can now centralize cloud risk analysis without switching platforms, reducing alert fatigue and improving response times to cloud misconfigurations and vulnerabilities.
- threat intel
Managing Attack Surface | Huntress
Huntress identified a threat actor attempting to establish persistence on an endpoint by using SQL Server (MSSQL) commands to upload a reverse shell to a web-accessible location. The attack was prevented by the organization's antivirus (MAV) and process-based detection mechanisms. This incident illustrates how attackers chain legitimate database tools with web infrastructure to gain initial access.
Why it matters: Operations and security teams should monitor for suspicious MSSQL activity and enforce strict controls on what database services can execute and where files can be written, as attackers commonly abuse trusted database tools as a stepping stone to compromise web servers.
- cloud saas
Improve MTTR with Wiz’s AI-powered remediation guidance using Microsoft Azure OpenAI service
Wiz has integrated Microsoft Azure OpenAI service to provide AI-powered remediation guidance, helping organizations generate automated remediation steps to reduce mean time to remediation (MTTR).
Why it matters: Security teams using Wiz can accelerate vulnerability remediation workflows, shortening response times and reducing exposure windows for cloud and infrastructure vulnerabilities.
- cloud saas
Sailing Securely Across the SDLC: Introducing Wiz's Image Trust and Kubernetes Audit Log Collector
Wiz has introduced Image Trust and Kubernetes Audit Log Collector, new capabilities designed to help organizations verify container image integrity and monitor Kubernetes control plane activity in near-real time. These tools aim to strengthen security throughout the software development lifecycle by preventing untrusted images from being deployed and detecting anomalous behavior.
Why it matters: Kubernetes operators and container platform teams need these tools to reduce the risk of deploying compromised images and to detect unauthorized access or control plane modifications that could compromise cluster security.
- cloud saas
Wiz becomes the first CNAPP to provide DSPM capabilities for Oracle Cloud Infrastructure
Wiz has added Data Security Posture Management (DSPM) capabilities to its Cloud Native Application Protection Platform (CNAPP) offering, enabling Oracle Cloud Infrastructure customers to better identify and protect sensitive data in their environments. This integration provides CNAPP users with built-in data security visibility without requiring separate tools.
Why it matters: Oracle Cloud Infrastructure customers using Wiz now have consolidated visibility into data security risks, reducing tool sprawl and helping security teams identify sensitive data exposure more efficiently.
- cloud saas
NamespaceHound: protecting multi-tenant K8s clusters
NamespaceHound is an open-source security tool designed to identify namespace isolation violations and unauthorized access risks in multi-tenant Kubernetes clusters. The tool helps detect configuration issues that could allow workloads to cross namespace boundaries or access resources without proper authentication.
Why it matters: Platform engineers and Kubernetes administrators managing multi-tenant clusters need to assess this tool to prevent namespace-level isolation failures that could expose one tenant's workloads or data to another.
- ransomware
Using Backup Utilities for Data Exfiltration | Huntress
Huntress researchers have identified ransomware affiliates using legitimate backup utilities to exfiltrate data during double extortion attacks, prior to encrypting files. The use of benign tools to stage data theft is a technique previously associated with Noberus/ALPHV ransomware operators.
Why it matters: Organizations using backup utilities may not flag their routine use as suspicious, making this approach effective for threat actors conducting data theft; practitioners should monitor backup tool usage for unauthorized data staging and transfers.
- cloud saas
Monitor sensitive data [3**-** ***7] that resides in code
Practitioners should implement monitoring systems to detect sensitive data embedded in code repositories, which helps prevent unintended exposure or regulatory violations. Code-based secret detection and data loss prevention reduce the risk of credentials, API keys, and other protected information being committed to version control systems.
Why it matters: Development teams and security practitioners need to prevent credential leaks and compliance violations by scanning code for embedded secrets before deployment or public exposure.
- research
Announcing the K8s LAN Party Challenge
A new Capture The Flag (CTF) event called the K8s LAN Party Challenge has been announced to test participant investigation skills and Kubernetes network knowledge. The competition appears designed to assess hands-on capabilities in container orchestration environments.
Why it matters: Security practitioners should monitor CTF events and competitions as they provide valuable skill-building opportunities and exposure to real-world Kubernetes security scenarios that are increasingly relevant to production environments.
- research
Full Transparency: Controlling Apple's TCC (Part 2) | Huntress
Huntress publishes an in-depth technical analysis of Apple's Transparency, Consent, and Control (TCC) framework, exploring the mechanics and background processes that enforce application access controls to user data. The article continues a multi-part series examining how TCC governs data privacy and permissions on Apple systems.
Why it matters: Security practitioners and macOS defenders need to understand TCC internals to identify misconfigurations, bypass techniques, or malware that circumvent privacy controls affecting endpoint protection strategies.
- research
CISOs share their top 7 strategies for gaining C-Suite buy-in
Three CISOs discussed strategies for securing executive buy-in during a Wiz-hosted webinar focused on advancing comprehensive security programs. The discussion centered on approaches to align security initiatives with C-suite priorities and organizational goals.
Why it matters: Security practitioners need effective strategies to communicate business value of security investments to executives who control budgets and strategic direction.
- vulnerabilitiesCVE-2024-27198CVE-2024-27199
Authentication bypass vulnerabilities in TeamCity: everything you need to know
JetBrains TeamCity contains two authentication bypass vulnerabilities with CVSS scores of 9.8 and 7.3. Organizations running affected TeamCity instances should immediately apply available patches to prevent unauthorized access.
Why it matters: TeamCity administrators must patch CVE-2024-27198 and CVE-2024-27199 now to prevent unauthenticated attackers from gaining administrative access to their CI/CD pipeline and build infrastructure.
- cloud saas
Wiz becomes the first CNAPP to provide native security to Akamai Linode Cloud
Wiz, a cloud native application protection platform (CNAPP), announced native security support for Akamai Linode Cloud, expanding its coverage to help organizations protect workloads across additional cloud infrastructure. The integration enables Wiz customers to secure applications and resources deployed on Linode Cloud alongside their existing cloud environments.
Why it matters: Organizations using Akamai Linode Cloud need visibility and protection for workloads in that environment, and Wiz's native support eliminates the need for workaround security tools or manual controls.
- industry
Please Allow Me to (Re)introduce Myself | Huntress
Huntress introduced a new security awareness training platform designed specifically for small and medium-sized businesses with limited resources. The solution uses story-driven episodes to improve knowledge retention and is fully managed by Huntress to minimize administrative overhead.
Why it matters: SMB practitioners need effective, low-friction security awareness training to reduce phishing and social engineering risks without straining IT staff or budgets.
- threat intel
Insights: RMM Tools | Huntress
Huntress has published multiple blog posts over the past year documenting instances where remote monitoring and management (RMM) tools have been installed or abused by threat actors. RMM tools, which are legitimate software for IT support and monitoring, have become targets for exploitation due to their privileged access to systems.
Why it matters: Security practitioners need to understand RMM tool attack vectors and misuse patterns to detect unauthorized installations, restrict tool access, and defend against threat actors leveraging legitimate administrative tools for lateral movement and persistence.
- threat intel
Navigate SocGholish with Huntress | Huntress
Huntress provides guidance on detecting and responding to SocGholish, a browser-based malware delivery threat. The post outlines an approach for IT professionals to use Huntress tools to identify and mitigate SocGholish infections.
Why it matters: IT teams need practical detection methods for SocGholish, which compromises browsers to deliver secondary malware payloads affecting Windows endpoints.
- vulnerabilities
Wiz extends vulnerability scanning support to MacOS instances
Wiz has expanded its vulnerability scanning platform to include agentless detection of vulnerabilities and misconfigurations in macOS workloads, with built-in CIS Benchmarks for Apple macOS. This extends the company's existing multi-cloud and infrastructure scanning capabilities to Apple's operating system.
Why it matters: Organizations running macOS in their environments can now identify vulnerabilities and configuration gaps without deploying agents, reducing deployment overhead and expanding security visibility across previously under-scanned infrastructure.
- ransomware
Attacking MSSQL Servers, Pt. II | Huntress
Huntress detected and stopped multiple Trigona ransomware attacks against MSSQL servers following publication of their initial analysis. The SOC team's investigation identified a second incident that revealed a pattern of attacks, preventing customer impact through timely escalation and response.
Why it matters: Organizations running MSSQL servers need to understand the attack vectors Trigona uses and review their MSSQL security posture, access controls, and monitoring to detect similar compromise attempts before ransomware deploys.
- ransomware
BlackCat Ransomware Affiliate TTPs | Huntress
Huntress SOC analysts documented tactics, techniques, and procedures (TTPs) used by a BlackCat ransomware affiliate operator who moved their target endpoint to different infrastructure before deployment. The analysis was shared with the affected organization, and no Huntress customers experienced impact from the ransomware attack.
Why it matters: Security teams should understand BlackCat affiliate TTPs to detect similar attack patterns and lateral movement tactics in their environments before ransomware deployment occurs.
- regulatory
DORA: Safeguarding Europe's financial sector
The Digital Operational Resilience Act (DORA) is a European regulation designed to strengthen the operational resilience of financial institutions. Wiz offers solutions to help financial organizations comply with DORA's requirements.
Why it matters: Financial services firms operating in Europe must understand and implement DORA controls to meet regulatory obligations and avoid enforcement actions.
- cloud saas
Welcome to the Zero Critical Club: celebrating flawless cloud security with Wiz
Wiz has announced a new marketing initiative called the Zero Critical Club, which recognizes customers who have eliminated all critical security issues in their cloud environments. The program highlights organizations that have achieved a specific security posture milestone using Wiz's platform.
Why it matters: Cloud security teams should understand that this represents a marketing announcement rather than a security advisory, but it may reflect industry benchmarks for critical vulnerability remediation timelines.
- vulnerabilitiesCVE-2024-1708CVE-2024-1709
SlashAndGrab | Huntress
Security researchers at Huntress have documented post-exploitation activity following the ScreenConnect vulnerabilities (CVE-2024-1709 and CVE-2024-1708). The report details observed adversary tactics, tradecraft, and techniques deployed after initial compromise through these flaws.
Why it matters: Organizations running vulnerable ScreenConnect instances need immediate visibility into how attackers operationalize these CVEs post-breach to inform incident response and containment strategies.
- threat intel
Proof of storage crypto miners
The article discusses proof-of-storage cryptocurrencies such as Chia and examines how attackers could exploit these systems through cryptojacking. It also outlines detection strategies for security defenders to identify such attacks.
Why it matters: Organizations need to understand proof-of-storage cryptojacking risks to their infrastructure and implement detection measures to prevent unauthorized use of computational resources.
- vulnerabilities
Detection Guidance for ConnectWise CWE-288 | Huntress
Huntress has published detection guidance for a critical authentication bypass vulnerability (CWE-288) affecting ConnectWise. The vulnerability requires patching to version 23.9.8 or later to remediate the exposure.
Why it matters: Organizations using ConnectWise management software need immediate detection and patching guidance to prevent attackers from bypassing authentication controls, which could lead to unauthorized access to remote management capabilities.
- cloud saas
Solving Endpoint Security Challenges with a Managed EDR | Huntress
Endpoint detection and response (EDR) tools are critical for endpoint security, but organizations often struggle to remediate detected threats due to resource constraints and expertise gaps. Without adequate response capabilities, EDR systems may generate alerts faster than teams can act on them.
Why it matters: Security teams evaluating or deploying EDR solutions need to ensure they have sufficient resources and expertise to respond to alerts, or consider managed EDR services to avoid alert fatigue and missed threats.
- cloud saas
Cupid in the cloud: celebrating developer and security team partnerships
An article celebrates the relationship between developers and security teams in cloud security contexts, framing their collaboration as a 'love story' on Valentine's Day. The piece highlights the importance of partnerships between these two groups in securing cloud environments.
Why it matters: Development and security teams that work together effectively reduce friction in deployment cycles and improve security outcomes; practitioners should evaluate whether their teams have adequate communication channels and shared tooling to support this partnership.
- ot ics
The Health Sector is Under Attack. But You Can Fight Back. | Huntress
Healthcare organizations face escalating cyber threats, and the U.S. Department of Health and Human Services is introducing new cybersecurity measures while small and mid-sized healthcare providers are encouraged to strengthen their defenses. The article emphasizes proactive security postures as a critical response to the current threat landscape.
Why it matters: Healthcare providers, especially smaller organizations, must understand evolving HHS requirements and take immediate defensive action to protect patient data and operational continuity against increasing attacks.
- threat intel
Threat Intel Accelerates Detection and Response | Huntress
Huntress deployed an agent on an endpoint and quickly identified evidence of a pre-existing exploit within minutes using threat intelligence data. The analysts provided remediation recommendations to address the root cause. This case demonstrates the value of rapid detection and response capabilities when threat intelligence is integrated into security tooling.
Why it matters: Security teams and managed service providers should evaluate how quickly their tools detect compromises and whether integrated threat intelligence can accelerate incident response and reduce dwell time.
- vulnerabilitiesCVE-2024-21762CVE-2024-23113
February Fortinet Advisory: everything you need to know
Fortinet released advisory guidance for two critical remote code execution (RCE) vulnerabilities affecting FortiOS and FortiProxy, identified as CVE-2024-21762 and CVE-2024-23113. The advisory includes detection and mitigation steps, with Fortinet recommending urgent patching to address these issues.
Why it matters: Organizations running FortiOS or FortiProxy are exposed to critical RCE attacks and should prioritize patching immediately to prevent exploitation.
- cloud saas
New attack vectors in EKS
Amazon EKS (Elastic Kubernetes Service) Access Entries and Pod Identity features have introduced new security attack vectors. The article examines how adversaries could potentially exploit these relatively recent capabilities.
Why it matters: Platform engineers and security teams managing EKS clusters need to understand these new attack vectors to properly configure access controls and pod identity policies, preventing lateral movement and privilege escalation in their Kubernetes environments.
- threat intel
Midnight Blizzard attack on Microsoft corporate environment: a detailed analysis, detections and recommendations
Microsoft disclosed a breach of its corporate environment by Midnight Blizzard (APT29), a state-sponsored Russian threat actor. The incident involved unauthorized access to internal systems and data. Security researchers have published detailed analysis of the attack chain along with detection and mitigation guidance.
Why it matters: Security practitioners defending enterprise environments need to understand this nation-state attack technique to identify similar intrusions in their own infrastructure and apply recommended mitigations immediately.
- cloud saas
Wiz AI-SPM extends support to Microsoft Azure OpenAI Service models
Wiz has expanded its AI Security Posture Management (AI-SPM) platform to support Microsoft Azure OpenAI Service models, offering visibility into AI pipelines and associated risks through the Wiz Security Graph. The extension enables organizations to monitor and assess security posture across their Azure-based AI deployments.
Why it matters: Teams using Azure OpenAI need visibility into AI pipeline risks and misconfigurations; this capability helps security practitioners assess and remediate exposure in cloud-hosted generative AI workloads.
- cloud saas
New EKS Access Management and Pod Identity features: a security analysis
Wiz released a security analysis of Amazon EKS's newly introduced access management and pod identity features. The research examines the security implications of these capabilities and provides guidance on implementing them securely.
Why it matters: Organizations deploying AWS EKS should review these findings to understand the security posture and best practices for the new identity features that affect their Kubernetes infrastructure.
- threat intel
RATs! Remote Management Software from the Hacker’s Perspective | Huntress
Huntress published a Tradecraft Tuesday recap focused on remote management software (RMM) abuse, including hunting techniques, persistence methods, and the relationship between RMM functionality and command and control capabilities. The post explores how attackers leverage legitimate remote access tools for malicious purposes.
Why it matters: Security teams need to understand RMM abuse tactics and detection methods because attackers routinely abuse legitimate remote management software for persistence and lateral movement in compromised environments.
- vulnerabilities
Leaky Vessels: runC and BuildKit container escape vulnerabilities - everything you need to know
Two container escape vulnerabilities, tracked as 'Leaky Vessels', affect runC and BuildKit. Organizations using these container technologies need to apply patches to prevent attackers from escaping container boundaries and accessing host systems. The vulnerabilities enable privileged execution outside of container isolation.
Why it matters: Development and operations teams running runC or BuildKit containers face immediate risk of container escape attacks that could compromise host infrastructure; patching and detection of exploitation attempts should be prioritized immediately.
- ai security
Wiz Enhances AI-SPM Support for Amazon Bedrock
Wiz has expanded its AI Security Posture Management (AI-SPM) capabilities to support Amazon Bedrock, enabling organizations to gain visibility into generative AI pipelines and identify risks. The enhancement allows practitioners to monitor and remediate security issues specific to Bedrock deployments within their AI infrastructure.
Why it matters: Teams using Amazon Bedrock need visibility and risk management for their generative AI workloads; this expansion gives them tooling to detect and address vulnerabilities before exploitation.
- cloud saas
Secure non-human identities with Wiz’s newest CIEM dashboard
Wiz has released a new dashboard for Cloud Identity and Entitlement Management (CIEM) focused on visibility and protection of non-human identities, including service accounts, within cloud environments.
Why it matters: Organizations managing cloud infrastructure need to monitor and control service accounts and other non-human identities to reduce lateral movement risk and unauthorized access exposure.
- industry
Wiz recognized with top score for the current offering category in The Forrester Wave™: Cloud Workload Security, Q1, 2024
Wiz received a top ranking from Forrester in its Q1 2024 Cloud Workload Security Wave evaluation, scoring highest in the current offering category among 13 evaluated providers. The recognition reflects Wiz's position in the competitive cloud security market.
Why it matters: Security teams evaluating cloud workload protection solutions should review Forrester's detailed scoring criteria to determine if Wiz's strengths align with their organization's specific requirements and deployment environment.
- cloud saas
5 Surprising facts from the Cloud Security Salary Guide
Wiz released a Cloud Security Salary Guide report highlighting compensation trends across cloud security roles. The report identifies five key findings about job positions and their associated pay packages in the field.
Why it matters: Security leaders and practitioners evaluating compensation, career progression, and talent retention strategies should review current market rates to benchmark roles and salaries in their organizations.
- government policy
Everything you need to know about NASCIO’s top 10 priorities for 2024
NASCIO released its top ten policy and technology priorities for 2024, outlining focus areas for state information security officers. The priorities guide strategic planning and resource allocation for state government cybersecurity programs.
Why it matters: State CISOs and security leaders need to align their programs with NASCIO priorities to ensure compliance with emerging state-level security requirements and access funding or resources tied to these initiatives.
- cloud saas
Announcing the Release of "Kubernetes Security for Dummies"
Wiz has released a new guide titled "Kubernetes Security for Dummies" in collaboration with Wiley publications. The book provides comprehensive coverage of security practices and considerations for Kubernetes environments.
Why it matters: DevOps and platform teams managing Kubernetes deployments should review this resource to strengthen their understanding of container orchestration security controls and identify potential gaps in their current configurations.
- threat intel
Introducing the Cloud Threat Landscape, a new TI resource for cloud defenders
A new threat intelligence resource called the Cloud Threat Landscape has been introduced, providing a database of cloud incidents with analysis of targeting patterns and initial access methods for cloud security defenders.
Why it matters: Cloud security teams need accessible threat intelligence on common attack patterns and entry points to prioritize their defensive strategies and incident response planning.
- cloud saas
Wiz ❤️ HashiCorp: Wiz’s new integration with Terraform Run Tasks helps customers slash risks and boost developer productivity
Wiz announced an integration with HashiCorp's Terraform Run Tasks that allows customers to scan infrastructure as code (IaC) configurations and enforce security best practices during Terraform execution. The integration is designed to help joint Wiz and HashiCorp customers identify and reduce security risks in their infrastructure code.
Why it matters: DevOps and infrastructure teams using Terraform can now detect IaC security misconfigurations earlier in the deployment pipeline, reducing the window for misconfigured resources to reach production environments.
- ai security
Wiz Research presents its latest report: “State of AI in the Cloud 2024”
Wiz released a research report examining artificial intelligence (AI) usage patterns and trends within cloud environments during 2024. The report provides observations about how organizations are deploying and managing AI workloads in cloud infrastructure.
Why it matters: Cloud security practitioners should review this report to understand emerging AI deployment patterns and identify potential security gaps in their own AI and cloud infrastructure strategies.
- ransomware
Ransomware Deployment Attempts Via TeamViewer | Huntress
Huntress has observed ongoing attempts to access endpoints through legacy TeamViewer installations and compromised TeamViewer credentials. These unauthorized access attempts represent a continuing threat vector for attackers seeking to establish persistence on victim systems.
Why it matters: Organizations using TeamViewer should audit for outdated versions and enforce credential security, as attackers are actively exploiting this access method to potentially deploy ransomware and other malware.
- ot ics
Securing Healthcare: Handling Cyber Threats with Care | Huntress
This article discusses the cybersecurity threat landscape in healthcare and outlines defensive strategies to protect patient data and systems. The piece emphasizes the importance of addressing cyber threats within the healthcare sector's operational context.
Why it matters: Healthcare organizations face increasing cyber threats that directly impact patient safety and data privacy, making threat awareness and defensive readiness essential for security teams.
- ai security
Wiz extends its AI-SPM offering to OpenAI platform
Wiz has launched an AI security capability for OpenAI's platform, becoming the first cloud native application protection platform (CNAPP) to offer this integration. The new OpenAI connector enables developers and data scientists to identify and address security risks within their OpenAI organizations.
Why it matters: Teams using OpenAI need visibility into AI-related security posture; this connector allows practitioners to detect and mitigate risks in their OpenAI environments directly through Wiz.
- cloud saas
Wiz recognized as a leader in Snowflake's inaugural cybersecurity report
Wiz has been recognized as a leader in Snowflake's first cybersecurity report. The recognition highlights Wiz's Cloud Native Application Protection Platform (CNAPP) offering to their shared customers.
Why it matters: Practitioners evaluating CNAPP vendors should note Wiz's standing in Snowflake's inaugural report if they use Snowflake for data workloads.
- ai security
The top 10 AI security articles you must read in 2024
A curated collection of 10 articles highlighting AI security threats and defensive strategies for developers has been published. The selection covers emerging risks to AI models and practical approaches for protecting them.
Why it matters: AI practitioners and developers need to stay informed on current threats and mitigation techniques to secure their models and deployments against evolving attack vectors.
- industry
Empowering the Hunt: All Your Security in One Place | Huntress
Huntress released an updated platform user interface for 2024 that consolidates security operations center insights and triage feeds into a single unified interface.
Why it matters: Security teams using Huntress benefit from improved operational efficiency and faster incident response through centralized visibility of security data.
- ai security
Choosing an AI-SPM tool: The four questions every security organization needs to ask
The article outlines four key questions that security organizations should evaluate when selecting an AI software package management (SPM) tool to ensure secure AI adoption within their operations. These questions serve as a framework for vetting AI-SPM solutions against organizational security requirements and risk tolerance.
Why it matters: Security teams implementing AI-SPM tools need evaluation criteria to select solutions that adequately protect against supply chain risks and AI-specific vulnerabilities in their development environments.
Navigating Cybersecurity Challenges in Healthcare | Huntress
This article discusses cybersecurity strategies and best practices for healthcare organizations, focusing on addressing common challenges, managing limited resources, and protecting patient information. The piece appears to be educational content aimed at helping healthcare practitioners strengthen their security posture.
Why it matters: Healthcare organizations face ongoing threats to patient data and operational continuity, making practical guidance on resource optimization and defensive strategies relevant to IT and security teams evaluating their current programs.
- cloud saas
Combating Emerging Microsoft 365 Tradecraft: Initial Access | Huntress
Huntress is discussing evolving threat tactics targeting Microsoft 365 and how defensive strategies need to adapt accordingly. The article appears to focus on initial access vectors as part of broader efforts to counter emerging attack methods against Microsoft 365 environments.
Why it matters: Microsoft 365 administrators and security teams need to understand new attack tradecraft to detect and prevent initial compromise attempts in their environments.
- threat intel
Effortless Phishing Simulations Now Part of Huntress | Huntress
Huntress has added Managed Phishing to its Managed Security Awareness Training (SAT) offering, providing automated simulated phishing campaigns for security teams. The feature is designed to reduce operational overhead for organizations running phishing awareness programs.
Why it matters: Security teams and managed service providers can now deploy phishing simulations without internal resource constraints, helping measure and improve user susceptibility to social engineering attacks.
- cloud saas
Setting secure defaults on AWS and avoiding misconfigurations
A Wiz researcher outlines best practices for establishing secure default configurations on Amazon Web Services (AWS) and reducing misconfiguration risks. The guidance aims to help organizations strengthen their cloud security posture through preventive measures rather than remediation.
Why it matters: Organizations using AWS need actionable guidance on secure defaults to prevent misconfigurations that commonly lead to data exposure, compliance violations, and lateral movement opportunities for attackers.
- ai security
How to leverage AI-powered security in your organization
The article discusses how organizations can use AI-powered security tools to enhance operational efficiency and expand the capacity of their security teams. It presents a framework for implementing AI security solutions within an organization.
Why it matters: Security leaders evaluating AI tools need practical guidance on adoption strategies to maximize team productivity and address staffing constraints in their operations.
- industry
Behind the scenes at the Wiz Booth: how to create a memorable expo experience
Wiz describes its approach to designing booth experiences and themes at cybersecurity conferences and trade shows. The company focuses on creating memorable, engaging interactions for attendees at industry events.
Why it matters: Security practitioners evaluating vendors at conferences should note that booth experience design does not reflect product capability, maturity, or security effectiveness; focus vendor evaluation on technical demos, roadmap, and reference customers instead.
- threat intel
Teach Yourself to Phish | Huntress
Huntress provides guidance on phishing simulations as a security training strategy. The article discusses how organizations can use simulated phishing campaigns to build awareness and resilience against actual phishing threats.
Why it matters: Security teams and awareness program managers need to understand phishing simulation methodologies to effectively reduce employee susceptibility to real attacks that target their organizations.
- cloud saas
Celebrating cloud defenders at the world's fastest-growing organizations
An article celebrates security teams at rapidly growing organizations for managing cloud security effectively with constrained budgets and resources. The piece highlights their efforts to secure cloud environments despite operational challenges.
Why it matters: Cloud security practitioners at scaling organizations benefit from recognition of peers solving resource constraints, and may find tactical insights in how others navigate similar budget limitations.
- threat intel
Curling for Data: A Dive into a Threat Actor's Malicious TTPs | Huntress
Huntress analysts documented a new set of tactics, techniques, and procedures employed by a threat actor for collecting and exfiltrating data. The research provides insights into the attacker's operational methods and data theft capabilities.
Why it matters: Security teams should review the documented tactics to identify if these techniques appear in their own environments and strengthen detection rules accordingly.
Orienting Intelligence Requirements to the Small Business Space
This article discusses approaches to gathering and organizing intelligence information relevant to small business operations, focusing on practical applications for decision-making and cost management. It addresses how small businesses can balance the benefits of intelligence gathering with budget constraints through outsourcing options.
Why it matters: Small business decision-makers should understand how to implement effective intelligence practices within resource constraints to make informed strategic decisions.
- threat intel
Exploring the Value of Indicators In Small Business Defense
This article discusses how small businesses can use technical indicators to strengthen their cybersecurity defenses and improve overall security effectiveness. It provides practical guidance on implementing these indicators as part of a defense strategy.
Why it matters: Small business owners and security practitioners need practical, cost-effective approaches to threat detection and response, making understanding how to leverage technical indicators relevant for organizations with limited resources.
- industry
Huntress MDR for Microsoft 365 Update | Huntress
Huntress announced updates to its Managed Detection and Response (MDR) service for Microsoft 365, including recent improvements and upcoming features and fixes.
Why it matters: Practitioners using Huntress MDR for Microsoft 365 should review the updates to understand new detection capabilities, behavioral changes, and roadmap items that may affect their threat monitoring strategy.
- industry
Wiz recognized by Frost and Sullivan as a leading Cloud Native Application Protection Platform for 2023
Frost and Sullivan recognized Wiz as a leading Cloud Native Application Protection Platform vendor in 2023, citing its cloud infrastructure security capabilities. The analyst firm highlighted Wiz's platform strength in their Frost Radar Report.
Why it matters: Cloud security practitioners evaluating CNAPP solutions should note this third-party validation when assessing platform capabilities and market positioning.
- industry
Raftt is Now Part of Wiz! Together We Are Empowering Developers.
Wiz has acquired Raftt, a developer-focused security tool. This acquisition is intended to help Wiz accelerate its efforts to build products that appeal to both security and development teams.
Why it matters: Development teams and Wiz customers should understand how this acquisition may change Raftt's product roadmap, pricing, or integration with Wiz's broader cloud security platform over the coming months.
- regulatory
CIS Controls Security Awareness Training | Huntress
Huntress offers a managed security awareness training program designed to help organizations meet CIS (Center for Internet Security) control requirements. The program targets employee security behavior and compliance with established control frameworks.
Why it matters: Security practitioners responsible for compliance and employee training need awareness solutions that map to CIS controls; Huntress positions its offering as a way to close the awareness gap and demonstrate control adherence.
- threat intel
macOS Terms and Trends You Should Know About | Huntress
This article examines the current state of macOS malware threats and provides terminology relevant to the macOS threat landscape. It offers practitioners a foundational reference for understanding emerging macOS security concerns.
Why it matters: macOS administrators and security teams need current threat awareness and shared terminology to detect, communicate about, and respond to macOS-specific malware effectively.
- vulnerabilitiesCVE-2023-43117
MFT Exploitation and Adversary Operations | Huntress
Huntress analyzed CVE-2023-43117, a vulnerability in CrushFTP, as part of a broader trend of adversaries exploiting managed file transfer (MFT) applications to gain unauthorized access and control. The vulnerability and similar MFT exploitation tactics represent an expanding attack surface that organizations commonly overlook. Security teams should prioritize patching and monitoring these file transfer systems due to their privileged access and operational criticality.
Why it matters: Organizations using MFT applications like CrushFTP face immediate risk from active exploitation of CVE-2023-43117 and similar vulnerabilities, requiring urgent patching and detection of suspicious file transfer activities.
- cloud saas
Wiz named a 2023 AWS EMEA Marketplace Partner of the Year
AWS has recognized Wiz as a 2023 Marketplace Partner of the Year in the EMEA region for its work helping customers balance innovation with security practices.
Why it matters: Wiz customers and prospects in Europe, Middle East, and Africa should note this recognition as validation of the vendor's capabilities; organizations evaluating cloud security solutions may consider this in their vendor selection process.
- threat intel
Can’t Touch This: Data Exfiltration via Finger
A blog post examines an uncommon method of data exfiltration using native system utilities, specifically highlighting a technique that threat actors have employed during incidents but remains infrequently observed in practice.
Why it matters: Security teams need awareness of unconventional exfiltration paths to improve detection and response capabilities, as attackers continue to leverage built-in tools to evade traditional monitoring.
- cloud saas
Introducing the Wiz extension: cloud security delivered to your AWS console
Wiz has released a Chrome browser extension that integrates cloud security capabilities directly into the AWS console, enabling users to access Wiz security features without leaving their cloud management interface.
Why it matters: AWS administrators and security teams can reduce context switching and improve security workflows by accessing cloud security tools directly from their primary workspace.
- cloud saas
Extend Wiz to your Developers: Enable secure cloud development with agility
Wiz announced new capabilities for its Cloud Native Application Protection Platform (CNAPP) designed to extend security coverage across the entire software development pipeline. The enhancement enables organizations to maintain security oversight while developing cloud-native applications.
Why it matters: Development teams and cloud security leaders should evaluate whether this expanded CNAPP functionality reduces friction between development velocity and security governance in their CI/CD pipelines.
- government policy
Biden's AI Executive Order: What it says, and what it means for security teams
Biden's 2023 Executive Order on artificial intelligence (AI) establishes requirements affecting companies that develop and deploy AI systems. The order addresses AI safety, privacy protections, and has direct implications for how security teams manage AI-related risks and compliance obligations.
Why it matters: Security teams need to understand the Executive Order's requirements to ensure their organizations meet mandated AI safety standards and avoid regulatory exposure.
- research
Key Insights from Huntress’ SMB Threat Report
Huntress released a threat report focused on small and medium-sized businesses (SMBs) that examines the evolving cyber threats affecting this market segment. The report provides insights into the threat landscape and risks that SMBs face.
Why it matters: SMB security practitioners need to understand current threat trends to prioritize defenses and resource allocation against attacks targeting their organization size and industry.
- cloud saas
Wiz launches support for Google Cloud excessive access findings based on audit logs
Wiz has added functionality to detect excessive access within Google Cloud Platform (GCP) environments by analyzing Google audit logs, enabling customers to optimize their permission configurations. This new capability helps organizations identify and remediate overly broad access rights in their cloud infrastructure.
Why it matters: GCP customers using Wiz can now identify and reduce excessive permissions, lowering the attack surface and blast radius of compromised accounts or credentials.
- cloud saas
Unveiling eBPF: Harnessing Its Power to Solve Real-World Issues
This article examines how extended Berkeley Packet Filter (eBPF) technology can be applied to defend against Kubernetes attacks and discusses related security best practices. The piece explores practical applications of eBPF in detecting and preventing threats within container orchestration environments.
Why it matters: Kubernetes security teams need to understand eBPF's detection and prevention capabilities to protect containerized workloads from runtime attacks and reduce their attack surface.
- ai security
Wiz becomes the first CNAPP to provide AI Security Posture Management
Wiz has expanded its Cloud Native Application Protection Platform (CNAPP) offering to include AI Security Posture Management (AI-SPM) capabilities. The addition aims to help organizations secure their AI workloads while maintaining rapid cloud deployment velocities.
Why it matters: Cloud and AI security teams need to evaluate whether AI-SPM tooling addresses their specific model deployment and data governance risks in production environments.
- cloud saas
Unleashing the power of cloud security: drive business impact with Wiz
Wiz, a cloud security vendor, reports that it serves hundreds of organizations including 40% of the Fortune 100 companies seeking to improve their security posture and operational efficiency.
Why it matters: Cloud security practitioners evaluating vendor solutions should note Wiz's market penetration among enterprise customers as one data point when assessing tool options for their environment.
- cloud saas
5 Steps to Establishing a Zero Trust Foundation in the Cloud with Wiz
Wiz outlines a five-step approach for organizations implementing zero trust principles in cloud environments, emphasizing the importance of visibility into infrastructure and risk assessment as foundational elements.
Why it matters: Cloud security teams need practical frameworks to transition from perimeter-based to zero trust models; this guidance addresses the visibility and assessment requirements that precede effective implementation.
- vulnerabilitiesCVE-2023-47246
Critical Vulnerability: SysAid CVE-2023-47246 | Huntress
Huntress has analyzed CVE-2023-47246, a critical vulnerability affecting SysAid, and developed a proof-of-concept exploit demonstrating the attack chain.
Why it matters: SysAid users and their managed service provider (MSP) partners need to assess their exposure to this critical vulnerability and apply available patches or mitigations immediately, as proof-of-concept exploits increase risk of active attacks.
- breaches incidents
Bitter Pill | Huntress
Huntress discovered unauthorized access incidents at multiple healthcare organizations where a threat actor exploited ScreenConnect, a remote access tool, to gain entry to systems. The investigation revealed the compromise affected several healthcare facilities, highlighting the use of legitimate remote access software as an attack vector.
Why it matters: Healthcare providers must audit ScreenConnect instances and review access logs immediately, as attackers are actively targeting healthcare organizations through this vector and may have established persistent access.
- cloud saas
Key takeaways from the Wiz 2023 Kubernetes Security Report
Wiz released its 2023 Kubernetes Security Report, which provides findings and recommendations on the security state of Kubernetes deployments. The report analyzes trends, vulnerabilities, and misconfigurations across containerized environments.
Why it matters: Platform and DevOps teams should review the report's findings to identify common security gaps in their Kubernetes infrastructure and prioritize remediation efforts.
- industry
PwC and Wiz form strategic alliance in the United Kingdom
PwC UK and Wiz announced a strategic partnership to provide enhanced cloud security solutions to customers. The alliance combines PwC's consulting expertise with Wiz's cloud security platform capabilities.
Why it matters: Organizations evaluating cloud security vendors should note this partnership may affect service delivery models, pricing, and integration options for Wiz solutions in the UK market.
- ransomwareCVE-2023-22518
Confluence to Cerber: Exploitation of CVE-2023-22518
CVE-2023-22518 in Atlassian Confluence is being actively exploited to deploy Cerber ransomware. Huntress has documented the attack chain and provided mitigation guidance for organizations running vulnerable Confluence instances.
Why it matters: Organizations using Confluence face direct ransomware risk if CVE-2023-22518 remains unpatched; apply available patches and monitor for exploitation attempts immediately.
- cloud saas
Ensuring Supply Chain Security: Verify container image integrity with the Wiz Admission Controller
Wiz has released an admission controller designed to enforce container image verification in Kubernetes environments, allowing organizations to restrict deployments to trusted images only. This tool addresses supply chain security concerns by preventing unauthorized or compromised container images from being deployed to production systems.
Why it matters: DevOps and Kubernetes administrators need to evaluate this solution to reduce the risk of deploying malicious or compromised container images, protecting against supply chain attacks targeting containerized infrastructure.
- vulnerabilities
Eight questions to measure vulnerability remediation "pain"
An article examines what characteristics make some vulnerabilities particularly difficult for security teams to remediate and explores how vendors can improve the remediation experience. The piece frames the challenge as vulnerability remediation 'pain' and uses eight key questions as a framework for understanding the problem.
Why it matters: Security practitioners managing vulnerability response programs should understand these friction points to prioritize remediation efforts more effectively and provide vendors with feedback on tooling and patch delivery that reduces operational burden.
- industry
Wiz inducted into the JPMorgan Chase Hall of Innovation
JPMorgan Chase has inducted cloud security vendor Wiz into its Hall of Innovation program, recognizing the company among selected partners. This acknowledgment reflects Wiz's standing in enterprise security solutions.
Why it matters: Security practitioners evaluating cloud security vendors should note Wiz's recognition by a major financial institution, though this announcement itself does not signal new vulnerabilities, threats, or compliance requirements requiring immediate action.
- vulnerabilitiesCVE-2023-46604
Critical Vuln: Apache ActiveMQ CVE-2023-46604 Exploited | Huntress
CVE-2023-46604 is a critical remote code execution vulnerability affecting Apache ActiveMQ that is being actively exploited in the wild. Organizations running affected versions should apply patches immediately to prevent unauthorized code execution.
Why it matters: Any organization deploying Apache ActiveMQ is at direct risk of compromise through remote code execution without authentication; immediate patching is required to block active exploitation.
- research
Announcing the EKS Cluster Games
Wiz is sponsoring a capture-the-flag competition called the EKS Cluster Games designed to test participants' investigation skills and Kubernetes knowledge.
Why it matters: Security practitioners can use this event to benchmark their Kubernetes and Amazon EKS (Elastic Kubernetes Service) investigation capabilities in a hands-on, competitive environment.
- cloud saas
Securing clouds, securely
Wiz has designed an agentless workload scanner with modular and scalable architecture, incorporating security measures to protect customer data during cloud scanning operations.
Why it matters: Cloud security practitioners need to understand how scanning tools protect sensitive data while assessing workload security, particularly when evaluating agentless solutions for their environments.
- research
The Hackers in the Arena: The Huntress CTF Retrospective | Huntress
Huntress conducted a month-long Capture the Flag (CTF) event showcasing diverse cybersecurity challenges and fostering community engagement among participants. The retrospective reflects on the event's challenges, participant experiences, and the collaborative spirit within the hacker community.
Why it matters: Security practitioners can benefit from CTF participation to sharpen offensive and defensive skills, stay current with attack techniques, and network with peers in the cybersecurity field.
- research
Exposed Passwords on Endpoints Are More Common Than You Think
A report from Huntress highlights that exposed passwords stored on endpoints are more widespread than previously understood, presenting a significant security risk. The research provides findings and recommendations for protecting credentials from exposure on devices within organizational networks.
Why it matters: Security practitioners need to assess their endpoints for stored credentials, as widespread password exposure increases the risk of lateral movement and account compromise across networks.
- threat intel
Linux rootkits explained – Part 2: Loadable kernel modules
This article examines loadable kernel modules (LKMs) and kernel-space rootkits, covering what LKMs are, how attackers abuse them to establish persistence, and detection methods.
Why it matters: Security practitioners need to understand LKM-based rootkits because they operate at kernel privilege level, making them difficult to detect and remove, and are commonly deployed in advanced persistent threats targeting Linux systems.
- industry
Wiz recognized as a 2023 Frost & Sullivan Radar Leader in Cloud Workload Protection Platform
Wiz has been recognized as a Radar Leader in the Global Cloud Workload Protection Platform market according to Frost and Sullivan's 2023 analysis. The recognition identifies Wiz among top companies in the CWPP sector.
Why it matters: Organizations evaluating cloud workload protection tools should note Wiz's positioning in analyst rankings when assessing vendor options for their cloud security infrastructure.
- ai security
Clint Gibler on AI and cybersecurity: the current state of the art and where we’re headed
Wiz conducted an interview with security expert Clint Gibler discussing applications of artificial intelligence in cybersecurity and emerging trends in the field. The conversation covers current AI capabilities and future directions for AI-driven security solutions.
Why it matters: Security practitioners should understand current and emerging AI capabilities to evaluate whether AI tools can enhance their organization's detection, response, and risk management workflows.
- cloud saas
Wiz launches data center in Mumbai, supporting the growing operations of global organizations in India
Wiz, a cloud security company, has opened a new data center in Mumbai to support its operations in India. This expansion allows the company to serve global organizations operating in the region with localized infrastructure.
Why it matters: Organizations using Wiz for cloud security in India now have regional data residency options, which may help meet data localization compliance requirements and reduce latency.
- threat intel
Phishing Email Examples: 5 Scams You Should Know | Huntress
Huntress provides an overview of phishing tactics, common scam types, and methods to identify suspicious emails. The article emphasizes security awareness training as a defense against these attacks.
Why it matters: Security practitioners and end-users need to recognize phishing red flags to prevent credential theft and malware infections that remain the leading attack vector in breaches.
- cloud saas
Wiz launches support for Google Workspace, helping organizations secure Google Cloud identities
Wiz has extended its cloud security platform to include support for Google Workspace, enabling organizations to model and protect identities within Google Cloud environments and detect suspicious activity through new threat detection rules.
Why it matters: Security teams managing Google Cloud and Workspace deployments now have dedicated tooling to monitor identity risks and detect threats in their Google authentication infrastructure, reducing blind spots in their cloud identity posture.
- cloud saas
Huntress Managed ITDR (formerly MDR for Microsoft 365) | Huntress
Huntress has rebranded its MDR (Managed Detection and Response) for Microsoft 365 service to Managed ITDR (Identity Threat Detection and Response), positioning it as a solution to address business email compromise attacks. The shift reflects an expansion in focus toward identity-based threats beyond email alone.
Why it matters: Security practitioners managing Microsoft 365 environments should evaluate whether this refreshed offering addresses BEC and identity compromise risks in their organizations.
- industry
Why Are You Still Paying for Antivirus? | Huntress
A Huntress blog post examines the value proposition of legacy antivirus solutions and discusses what characteristics matter most when evaluating antivirus and endpoint protection tools. The piece implicitly questions whether organizations should continue investing in traditional antivirus products.
Why it matters: Security leaders evaluating endpoint protection budgets should understand current antivirus capabilities and limitations to make informed decisions about technology investments and coverage.
- cloud saas
The good, the bad, and the vulnerable
Wiz released a new report outlining its methodology for prioritizing and triaging vulnerabilities in cloud environments. The report presents a framework for distinguishing critical risks from less severe findings in cloud infrastructure.
Why it matters: Cloud practitioners and security teams need defensible vulnerability triage approaches to allocate remediation resources effectively and reduce exposure in complex cloud environments.
- threat intel
Pairing SOCs with Automation | Huntress
Huntress discusses using automation, detection and response capabilities, and open-source tools to address common security operations center challenges. The piece outlines practical approaches for implementing SOC automation to improve operational efficiency.
Why it matters: SOC teams and security leaders should evaluate automation strategies to reduce manual workload and improve incident response speed, particularly in resource-constrained environments.
- vulnerabilitiesCVE-2023-42115
Critical and high severity Exim vulnerabilities: everything you need to know
Exim has released patches for six vulnerabilities, including critical and high severity issues tracked as CVE-2023-42115 and others. Organizations running affected versions should apply patches urgently to mitigate potential exploitation.
Why it matters: Teams managing Exim mail servers must identify affected configurations and patch immediately, as critical severity vulnerabilities expose systems to remote compromise and potential data theft.
- vulnerabilities
Critical Vulnerabilities: WS_FTP Exploitation | Huntress
Huntress is investigating multiple vulnerabilities in WS_FTP Server's Ad Hoc Transfer Module that are being actively exploited in the wild. The vulnerabilities pose an immediate threat to organizations running affected WS_FTP instances.
Why it matters: Organizations running WS_FTP Server with Ad Hoc Transfer Module need to assess exposure and prioritize patches immediately, as these vulnerabilities are under active exploitation.
- vulnerabilitiesCVE-2023-4863CVE-2023-5217
Critical vulnerabilities in media libraries exploited in the wild: everything you need to know
Two critical vulnerabilities were identified in widely used media libraries: CVE-2023-4863 in libwebp and CVE-2023-5217 in libvpx. Both flaws are being actively exploited in the wild, affecting systems that process web images and video codecs.
Why it matters: Organizations using libwebp or libvpx in web browsers, applications, or media processing pipelines face immediate risk from active exploitation and must prioritize patching to prevent code execution.
- ai security
Humans vs. AI: The Critical Role of Human Expertise | Huntress
An article examines whether artificial intelligence can completely replace human expertise in cybersecurity and argues that human-powered security remains essential for staying ahead of evolving threats. The piece emphasizes the continued importance of human judgment and experience in the security field despite advances in AI capabilities.
Why it matters: Security teams should understand the complementary roles of AI and human expertise when evaluating tools and staffing strategies for their organizations.
- vulnerabilitiesCVE-2023-4863
Critical Vuln: WebP Heap Buffer Overflow CVE-2023-4863 | Huntress
A critical vulnerability in the libwebp WebP image library (CVE-2023-4863) is being tracked by Huntress and observed in active exploitation. The flaw involves a heap buffer overflow that affects any software leveraging this widely used image processing library.
Why it matters: Organizations using WebP image processing across web browsers, applications, and services need to patch immediately, as the vulnerability is actively exploited in the wild.
- research
Unveiling eBPF: Revolutionizing Security and Observability
Extended Berkeley Packet Filter (eBPF) is a technology that enables in-kernel execution of programs to monitor and inspect system behavior without modifying kernel code. This capability is being applied to enhance security monitoring, network observability, and application performance analysis across production environments.
Why it matters: Security practitioners should evaluate eBPF-based tools for real-time threat detection, runtime security, and network visibility in their infrastructure, as adoption of eBPF is growing across cloud platforms and observability vendors.
- vulnerabilities
Netscaler Exploitation to Social Engineering | Huntress
Huntress team analyzed recent intrusions linked to Netscaler exploitation, examining the attack chain and techniques used by threat actors. The analysis documents how attackers leveraged the vulnerability to establish initial access and conduct follow-on operations.
Why it matters: Security teams managing Citrix Netscaler instances need to understand the post-exploitation tactics and social engineering techniques used in these intrusions to improve detection and response capabilities.
- industry
Introducing Incident Notification | Huntress
Huntress has released Incident Notification, a feature that enables managed service providers and partners to receive immediate alerts about critical incidents via SMS or phone call. The capability integrates into Huntress's threat detection platform to improve incident response speed.
Why it matters: MSPs and security teams using Huntress need to understand this notification option to ensure they receive timely alerts during active incidents and can configure their preferred alert channels.
- cloud saas
Wiz launches support for Amazon SageMaker, helping organizations innovate faster and more securely with AI
Wiz has expanded its cloud security platform to support Amazon SageMaker, the machine learning service from AWS, enabling organizations to secure their generative AI applications more effectively. The expansion allows enterprises to protect their ML workflows and models within the SageMaker environment while maintaining development velocity.
Why it matters: ML and AI practitioners using SageMaker need visibility and security controls for their generative AI workloads; Wiz's support reduces the risk of unprotected model deployments and data exposure in production ML pipelines.
- threat intel
Understanding Evil: How to Reverse Engineer Malware | Huntress
This is an educational resource covering the basics of reverse engineering malware to understand how malicious software operates. The article explains fundamental techniques and approaches used to analyze and deconstruct malware behavior.
Why it matters: Security practitioners need malware analysis skills to investigate incidents, understand attack mechanics, and develop effective detection and remediation strategies.
- cloud saas
Inside the vault: how financial institutions protect their cloud environments
Wiz hosted a webinar featuring security experts discussing how financial institutions prioritize cloud security and scale security practices across their organizations. The discussion covered strategies for protecting sensitive assets in cloud environments specific to the financial sector.
Why it matters: Financial institution security teams should understand peer approaches to cloud security prioritization and organizational security scaling to improve their own posture against cloud-based threats.
- industry
Enhancing Cybersecurity for MSPs in Australia and New Zealand | Huntress
Huntress publishes guidance for managed service providers (MSPs) in Australia and New Zealand on improving their cybersecurity capabilities and sales approaches with customers. The article offers practical recommendations for MSPs to strengthen their security posture and market their services more effectively.
Why it matters: MSPs supporting customers in Australia and New Zealand need current best practices to maintain competitive security offerings and demonstrate value in customer conversations.
- regulatory
GAO Study Reveals: Government Faces Challenges with Continuous Monitoring
The Government Accountability Office (GAO) has identified challenges that government agencies face in implementing continuous monitoring for cloud security compliance. The study highlights gaps between current practices and GAO-recommended best practices for managing risk and compliance in cloud environments. Agencies need to strengthen their monitoring capabilities to meet these standards.
Why it matters: Federal agencies responsible for cybersecurity compliance must understand these GAO findings to prioritize continuous monitoring investments and demonstrate compliance with recommended cloud security practices.
- cloud saas
38TB of data accidentally exposed by Microsoft AI researchers
Wiz Research discovered a misconfigured shared access signature (SAS) token in Microsoft's AI GitHub repository that exposed approximately 38 terabytes of data, including over 30,000 internal Microsoft Teams messages. The exposure occurred through improper configuration rather than an active security breach. Microsoft secured the repository following the disclosure.
Why it matters: Organizations using GitHub and cloud storage must audit service account tokens and access credentials in code repositories, as misconfigured SAS tokens and similar authentication mechanisms commonly leak sensitive internal communications and proprietary data.
- cloud saas
Fortify your cloud security with Wiz as it integrates with Microsoft Sentinel
Wiz has integrated with Microsoft Sentinel to help organizations monitor and respond to cloud security threats. The integration provides context for investigations and enables automated response workflows within the Sentinel platform.
Why it matters: Cloud security teams using Microsoft Sentinel can now leverage Wiz's vulnerability and misconfiguration detection to streamline threat investigation and response automation.
- threat intel
Spidering Through Identity for Profit and Disruption | Huntress
Scattered Spider, a threat group, conducted cyberattacks against Las Vegas casinos that exploited identity-based attack vectors. The article discusses the incidents and defensive measures organizations can implement against similar identity-focused threats.
Why it matters: Organizations managing high-value assets and those with exposed credentials or weak identity controls are vulnerable to identity-based initial access attacks; practitioners should review credential hygiene, multi-factor authentication enforcement, and lateral movement detection.
- cloud saas
Wiz enhances real-time threat detection and response capabilities to stop threats from becoming incidents
Wiz announced general availability of its Runtime Sensor for Kubernetes, a tool designed to detect cloud attacks in real-time and provide response capabilities tailored to cloud-native environments. The sensor offers customizable detection options and response automation to help organizations prevent security incidents in containerized infrastructure.
Why it matters: Security teams managing Kubernetes deployments need effective runtime monitoring to catch attacks before they cause breaches; this GA release provides another option for detecting and responding to threats in cloud-native workloads.
- cloud saas
Wiz and Fortinet announce partnership to deliver cloud-native security protection
Wiz and Fortinet have partnered to integrate cloud security capabilities with network firewall functionality, allowing customers to detect, prioritize, and remediate public cloud exposures using both platforms together.
Why it matters: Organizations using both Wiz and Fortinet can now automate the detection and remediation of cloud security misconfigurations, reducing the time between discovery and fixing exposed resources.
- cloud saas
A security community success story of mitigating a misconfiguration
A security team identified and remediated a misconfiguration in the integration between GitHub Actions and AWS IAM (Identity and Access Management) roles. The incident led to improvements that reduce the likelihood of similar misconfigurations occurring in the future. The case demonstrates how security issues can be prevented through collaborative problem-solving and external environmental changes.
Why it matters: Development and security teams using GitHub Actions with AWS IAM should understand this misconfiguration pattern to audit their current integrations and apply the lessons learned to prevent credential exposure or unauthorized access.
- threat intel
Storm-0558 Update: Takeaways from Microsoft's recent report
Microsoft released updated findings on the Storm-0558 attack campaign, and security researchers at Wiz have analyzed the report to extract key lessons for cloud customers regarding the incident and its implications.
Why it matters: Cloud infrastructure operators need to understand the attack techniques and defensive measures highlighted in Microsoft's Storm-0558 report to assess their own exposure and implement appropriate protections.
- threat intel
Evolution of USB-Borne Malware, Raspberry Robin | Huntress
Huntress published a technical analysis of Raspberry Robin, a USB-borne malware that spreads through removable storage devices. The report details the malware's evolution and demonstrates how Huntress endpoint detection and response and managed antivirus solutions can identify and contain the threat.
Why it matters: Organizations relying on USB-connected devices face infection risk from Raspberry Robin; security teams should review detection coverage for USB-based malware propagation in their environment.
- threat intel
I know what you mined last summer: summarizing Summer '23 cryptomining activity
Wiz Research identified multiple cryptomining campaigns targeting cloud workloads during summer 2023 and documented the associated indicators of compromise. The report provides detection and prevention guidance for similar threats.
Why it matters: Cloud operators and security teams need visibility into cryptomining threats affecting their infrastructure, with concrete detection methods and indicators to identify these attacks in their environments.
- research
Ask the Mac Guy: Best Practices for Securing Macs | Huntress
Huntress provides security guidance for macOS devices, covering best practices for both individual users and IT administrators managing Mac fleets. The article offers practical recommendations for securing Mac environments against threats.
Why it matters: Mac administrators and security teams responsible for macOS deployments need current guidance on hardening strategies to reduce risk across their Mac estate.
- cloud saas
Recap: Wiz innovations at Google Cloud NEXT ‘23
Wiz presented innovations integrating its Cloud Native Application Protection Platform (CNAPP) with Google Cloud at the NEXT '23 conference. The integration is designed to help organizations improve security posture while accelerating development velocity.
Why it matters: Cloud security practitioners using Google Cloud should evaluate whether Wiz's CNAPP integration improves their visibility into application security and reduces remediation time for their deployments.
- industry
How Huntress Transformed Its Detection Engine
Huntress redesigned its data analysis infrastructure to address scaling challenges, moving toward a custom detection engine to better handle its growing workload. The post details how the company adapted its systems to maintain detection performance as operational demands increased.
Why it matters: Huntress customers and prospects evaluating endpoint detection and response solutions should understand how the vendor's architecture changes affect detection speed, accuracy, and coverage of their environments.
- threat intel
Qakbot Malware Takedown and Defending Forward | Huntress
The FBI dismantled the Qakbot malware infrastructure, and Huntress developed a vaccine to protect systems from the threat. The security firm details its defensive approach in response to the takedown.
Why it matters: Organizations using Huntress or evaluating Qakbot remediation should understand the available protective measures now that the botnet is disrupted.
- threat intel
Threat Hunting and Tactical Malware Analysis | Huntress
This article provides an overview of threat hunting and tactical malware analysis as complementary cybersecurity practices. It explains how these two disciplines work together to identify and respond to threats in an organization's environment.
Why it matters: Security practitioners need to understand threat hunting and malware analysis techniques to detect and investigate advanced threats that automated tools may miss.
- research
Best Practices to Reduce Your Attack Surface
The article provides guidance on reducing organizational attack surface through asset inventory management and related cybersecurity practices. It offers expert recommendations for strengthening overall security strategies.
Why it matters: Security teams need practical approaches to identify and minimize exposure points; attack surface reduction is a foundational control that lowers risk across all threat vectors.
- cloud saas
Docker and Kubernetes, we have got you covered: Wiz simplifies compliance and security posture management for Docker and Kubernetes environments.
Wiz announced new capabilities to help organizations manage security posture and compliance for Docker and Kubernetes environments against CIS benchmarks. The offering provides reporting and remediation guidance for identified issues.
Why it matters: Security teams managing containerized infrastructure need efficient tools to validate compliance and fix misconfigurations before they become exploitable vulnerabilities.
- threat intel
Gone Phishing: An Analysis of a Targeted User Attack | Huntress
Huntress published an analysis examining how threat actors use phishing and social engineering tactics to target users and compromise organizations. The report provides insights into attack methodologies and infiltration techniques employed against corporate environments.
Why it matters: Security practitioners should understand current phishing and social engineering attack vectors to better defend users and detect compromise attempts before attackers gain organizational access.
- industry
Traditional Antivirus vs. Managed Antivirus | Huntress
Huntress compares traditional antivirus solutions with managed antivirus services, arguing that standalone traditional antivirus is insufficient against modern cyber threats. The article promotes Huntress's managed antivirus as a more proactive and effective alternative.
Why it matters: Security teams evaluating endpoint protection strategies should understand the limitations of legacy antivirus tools and consider whether managed antivirus services better address current threat landscapes.
- ransomware
Investigating New INC Ransom Group Activity | Huntress
Huntress investigated a ransomware attack attributed to the INC Ransom threat actor group, documenting the observed attack activity and methods used during the incident.
Why it matters: Security teams should monitor INC Ransom activity to understand attack patterns and protect systems against this emerging threat group.
- identity access
Identity: The Third Phase of Security Operations | Huntress
Huntress discusses the emergence of identity security as a critical focus area in security operations, emphasizing the need for organizations to adapt to evolving threats targeting identities. The article positions identity protection as a key priority alongside traditional security practices.
Why it matters: Security practitioners need to assess whether their current identity protection strategies are sufficient against modern threats, and should evaluate tools and processes to strengthen identity security posture.
- threat intel
How Security-Centric Procedures and Training Helped | Huntress
Huntress detected and stopped an attempted business email compromise (BEC) attack that would have resulted in over $100,000 in losses if successful. The case demonstrates the value of security procedures and employee training in identifying and preventing financial fraud schemes. Huntress published a writeup highlighting how the combination of technical controls and human awareness prevented the attack from succeeding.
Why it matters: Finance teams, HR staff, and executives who handle wire transfers and payments need to implement BEC detection controls and training, as attackers actively target payment processes and can inflict rapid, direct financial damage.
- cloud saas
Wiz is the #1 Cloud Security Company on the 2023 Forbes Cloud 100
Wiz ranked as the top cloud security company on Forbes' 2023 Cloud 100 list and was noted as one of the year's biggest movers on the ranking, similar to OpenAI's positioning.
Why it matters: Security buyers and practitioners evaluating cloud security platforms should consider that Wiz's market recognition and growth trajectory reflect strong momentum in the sector, potentially indicating competitive advantages worth assessing in vendor evaluations.
- research
How Businesses Should Be Scaling Their Security
This article discusses how organizations can address modern security challenges by scaling their security practices and moving beyond traditional antivirus solutions. It emphasizes the need for evolved defense strategies to strengthen organizational security posture.
Why it matters: Security leaders need to understand current best practices for modernizing and scaling security operations to protect against evolving threats beyond legacy tools.
- vulnerabilitiesCVE-2023-39143
Another PaperCut: CVE-2023-39143 Remote Code Execution | Huntress
Huntress has identified CVE-2023-39143, a remote code execution vulnerability affecting PaperCut that allows attackers to achieve full code execution on unpatched systems. The vulnerability poses an immediate threat to organizations running vulnerable versions of the software.
Why it matters: Organizations running unpatched PaperCut systems face complete server compromise and should prioritize patching immediately to prevent remote exploitation.
- threat intel
Legitimate Apps as Traitorware for Persistent Microsoft | Huntress
Huntress researchers discovered threat actors using legitimate email applications to maintain persistent access to compromised Microsoft 365 environments. The attackers leveraged these benign tools to evade detection while preserving their foothold in victim networks.
Why it matters: Microsoft 365 users and administrators need to monitor for suspicious email app additions and implement stricter controls over third-party application access, as attackers are exploiting legitimate tools to hide persistence.
- cloud saas
Wiz helps organizations innovate with AI securely and responsibly, launching support for Google Cloud Vertex AI
Wiz has announced support for Google Cloud Vertex AI to help organizations secure their AI infrastructure deployments on Google Cloud. The capability allows data scientists and engineers to develop and deploy AI applications while maintaining security posture against cloud-based attacks.
Why it matters: DevOps and security teams using Google Cloud for AI workloads need visibility into Vertex AI environments to prevent misconfigurations and unauthorized access that could expose trained models or sensitive training data.
- threat intel
Breaking Down the Threat Hunting Process | Huntress
This article outlines the structured phases and methodology that threat hunters use to proactively identify threats within an organization. The piece explains how hunters organize their activities across distinct stages to systematically search for compromised systems and attack indicators before they escalate.
Why it matters: Security practitioners should understand threat hunting processes to improve their detection capabilities and shift from reactive to proactive threat identification in their environments.
- industry
The Magic of Branding: Creating an Optimistic Identity for a Security Product
Wiz, a security product company, is adopting an optimistic and positive branding approach rather than relying on fear-based messaging that is typical in the security industry. The company views this philosophy as a differentiator in how it communicates its value to customers and the market.
Why it matters: Security practitioners evaluating vendor messaging and product positioning should understand how different branding philosophies may influence purchasing decisions and vendor relationships.
- industry
Why Huntress Trusts Microsoft Defender Antivirus | Huntress
Huntress published an article recommending Microsoft Defender Antivirus as a solid antivirus solution. The piece discusses reasons why organizations might consider switching to or adopting Defender as part of their security stack.
Why it matters: Security teams evaluating antivirus solutions should understand vendor perspectives on Defender's capabilities and positioning relative to competing products for informed procurement decisions.
- vulnerabilities
Wiz's agentless approach to cloud-native vulnerability management
Wiz has released an agentless vulnerability management solution designed for cloud-native environments. The tool prioritizes critical vulnerabilities according to business impact, avoiding the need for agent deployment.
Why it matters: Cloud security teams can evaluate whether agentless scanning meets their vulnerability prioritization and remediation workflows compared to agent-based alternatives.
- vulnerabilitiesCVE-2023-2640CVE-2023-32629
GameOver(lay): Easy-to-exploit local privilege escalation vulnerabilities in Ubuntu Linux affect 40% of Ubuntu cloud workloads
Wiz Research identified two privilege escalation vulnerabilities, CVE-2023-2640 and CVE-2023-32629, in Ubuntu Linux' OverlayFS module that are straightforward to exploit. These flaws impact approximately 40 percent of Ubuntu cloud workloads, creating a significant exposure across deployed instances.
Why it matters: Ubuntu cloud users and administrators need to assess whether their workloads run vulnerable versions and apply patches immediately, as local attackers can escalate privileges with minimal complexity.
- breaches incidents
Business Email Compromise via Azure Administrative Privileges | Huntress
Huntress detected and prevented a business email compromise attack that exploited Azure administrative privileges to target multiple user accounts in an organization. The incident demonstrates how attackers can leverage cloud identity systems to gain unauthorized email access at scale. Huntress' detection capabilities were key to stopping the compromise before significant damage occurred.
Why it matters: Organizations using Azure are at risk of BEC attacks through compromised admin accounts; security teams should audit privileged account access and implement conditional access policies to prevent unauthorized email access.
- cloud saas
Top 16 cloud security experts you should follow in 2023
A curated list of 16 cloud security thought leaders has been selected by a research team for practitioners to follow. The list aims to highlight experts whose insights and perspectives are relevant to the cloud security field.
Why it matters: Security practitioners should follow industry experts to stay informed about emerging cloud security trends, best practices, and threat landscape developments that affect their infrastructure and security posture.
- regulatory
The Power of Cyber Insurance: What Every MSP Should Know | Huntress
This article discusses cyber insurance fundamentals, its benefits, and practical considerations relevant to managed service providers (MSPs). It covers key aspects MSPs should understand when evaluating cyber insurance options for their organizations and clients.
Why it matters: MSPs need to understand cyber insurance coverage, limits, and exclusions to properly protect their firms against breach liabilities and to advise clients on appropriate coverage today.
- cloud saas
Streamline Software Bill of Materials (SBOM) Generation with Wiz's Agentless SBOM
Wiz has released an agentless scanning capability for Software Bill of Materials (SBOM) generation that aims to simplify software security and supply chain risk management. The tool enables organizations to create SBOMs without requiring agent deployment across their infrastructure.
Why it matters: Security teams and procurement professionals need effective SBOM visibility to manage supply chain risk and comply with emerging regulations; agentless scanning reduces operational friction in adopting this critical practice.
- breaches incidents
Compromised Microsoft Key: More Impactful Than We Thought
Researchers have determined that the Storm-0558 security incident involving a compromised Microsoft key has a wider scope than initially disclosed by Microsoft and CISA (Cybersecurity and Infrastructure Security Agency). Organizations using Microsoft and Azure services are advised to assess their potential exposure from this incident.
Why it matters: Organizations using Microsoft and Azure services need to immediately review their access logs and authentication events to determine if they were targeted or compromised by this Chinese threat actor, as the true scope of the breach may affect far more customers than originally acknowledged.
- cloud saas
Kubernetes API limitations in finding non-standard pods and containers
Kubernetes environments contain several types of non-standard pods and containers, such as static pods, mirror pods, init containers, pause containers, and ephemeral containers, that may not be easily discoverable through standard API queries. Monitoring these non-standard workloads is important because they can exist outside typical visibility frameworks and may represent security blind spots in cluster observability.
Why it matters: Security practitioners managing Kubernetes clusters need to ensure comprehensive visibility across all container types to detect unauthorized or malicious workloads, as standard API monitoring may miss critical components.
- industry
Celebrating One Year of Security Awareness Training
Huntress has released an update on its Security Awareness Training platform one year after acquiring Curricula, highlighting improvements and progress made during that period. The announcement reflects the company's continued development of its awareness training offerings for organizations.
Why it matters: Security practitioners evaluating awareness training platforms should understand Huntress's platform evolution and capabilities following the acquisition, which may impact training effectiveness and feature availability for their organizations.
- cloud saas
How to get rid of AWS access keys – Part 3: Replacing the authentication
The third article in a series on AWS access key management discusses alternative authentication methods to replace traditional access keys. The piece concludes a multi-part discussion on removing unused keys and implementing least-privilege access strategies.
Why it matters: AWS practitioners managing credentials should understand the replacement options to adopt more secure authentication mechanisms and reduce exposure from long-lived access keys.
- threat intel
Thwarting Financial Fraud | Huntress
Huntress detected and prevented a business email compromise (BEC) attack targeting Microsoft 365 that aimed to commit financial fraud. The blog describes the threat detection methods and incident response procedures used to identify and stop the fraudulent activity.
Why it matters: Organizations using Microsoft 365 need visibility into BEC attacks that target financial transactions; practitioners should understand detection techniques to identify similar compromise attempts before funds are transferred.
- threat intel
PyLoose: Python-based fileless malware targets cloud workloads to deliver cryptominer
PyLoose is a Python-based fileless malware that targets cloud workloads and delivers cryptocurrency mining payloads. The malware operates without writing files to disk, making detection more difficult. Security researchers have documented the attack chain and provided mitigation guidance.
Why it matters: Cloud infrastructure operators and DevOps teams should assess their workloads for PyLoose indicators and implement the recommended mitigations to prevent unauthorized cryptomining that degrades performance and increases costs.
- vulnerabilities
Move It on Over: Reflecting on the MOVEit Exploitation | Huntress
A security blog reflects on the long-term consequences and lessons from the MOVEit exploitation campaign. The post provides guidance for defenders on maintaining vigilance and applying historical insights to improve defenses.
Why it matters: Security practitioners should understand the persistent impact of MOVEit to inform their patch management and file transfer security strategies, especially if they use or support Progress MOVEit Transfer.
- threat intel
BEC Threat Hunting: How to Detect Microsoft 365 Compromises
Security researchers explored threat hunting techniques to detect business email compromise (BEC) in Microsoft 365 environments by analyzing anomalous user agent patterns. The research identifies indicators that may reveal compromised accounts within cloud email systems.
Why it matters: Security operations and incident response teams managing Microsoft 365 need improved detection methods for compromised accounts, since BEC attacks directly target email infrastructure and can lead to unauthorized access, data theft, and financial fraud.
- threat intel
Linux rootkits explained – Part 1: Dynamic linker hijacking
Dynamic linker hijacking using LD_PRELOAD is a Linux rootkit technique that various threat actors have deployed in real-world attacks. The article explains this attack method and describes detection approaches.
Why it matters: Linux administrators and security teams need to understand this rootkit persistence mechanism to identify and respond to compromised systems before attackers establish long-term control.
- cloud saas
How to get rid of AWS access keys – Part 2: Reducing Privileges
This article is the second part of a series on managing AWS access keys, focusing on techniques to reduce the privileges associated with existing keys to lower their potential impact if compromised. The post builds on earlier guidance about access key cleanup and provides specific mitigation strategies.
Why it matters: AWS users and practitioners need to apply least privilege principles to access keys to limit blast radius if credentials are exposed or misused.
- ai security
How to leverage generative AI in cloud apps without putting user data at risk
Organizations can implement generative AI capabilities within cloud applications while maintaining data security through established best practices. The guidance addresses concerns specific to multi-tenant environments where customer data isolation is critical.
Why it matters: Cloud application developers and security teams need practical guidance on safely integrating AI features without exposing customer data or violating data residency requirements.
- threat intel
dmXProtect: Stop, Drop, Shut Malware Down
The article examines whether Apple's built-in macOS malware prevention tools, XProtect and XProtect Remediator, provide sufficient security protection or if third-party solutions are necessary for users.
Why it matters: macOS users and IT administrators need to understand the effectiveness of native Apple security controls to make informed decisions about whether additional endpoint protection is required for their environments.
- threat intel
One MSP, Three Microsoft 365 Compromises, 72 Hours | Huntress
Huntress identified three separate business email compromise attacks targeting a managed service provider within a 72-hour window using its Managed Identity Threat Detection and Response platform. The incidents demonstrate rapid attack patterns against MSPs and their customers through email-based compromise techniques.
Why it matters: MSPs and their customers face concentrated business email compromise risk; practitioners should review email authentication controls, identity monitoring alerts, and incident response procedures for detecting multiple simultaneous attacks.
- cloud saas
Wiz becomes the first CNAPP to provide end-to-end cloud forensics experience
Wiz announced a cloud-native application protection platform (CNAPP) capability that delivers end-to-end cloud forensics for incident response. The feature is designed to streamline security incident investigation in cloud environments.
Why it matters: Security teams investigating cloud incidents need faster forensic visibility and incident response capabilities to reduce investigation time and potential damage.
- industry
How To Speak To SMBs About Cybersecurity | Huntress
This article provides guidance on how to conduct effective cybersecurity sales conversations with small and medium-sized businesses (SMBs). It offers practical tips and talking points for security professionals engaging with SMB clients during sales meetings.
Why it matters: Sales teams and security vendors need effective messaging strategies to communicate value propositions to SMB buyers who may lack in-house security expertise and have limited budgets.
- cloud saas
Winning together with Wiz: Introducing the Wiz Integration (WIN) platform for greater agility and flexibility to build best-of-breed cloud security programs
Wiz announced a new integration platform called WIN that enables connections with industry partners to enhance its cloud security capabilities. The platform is designed to provide greater flexibility and composability for building cloud security programs.
Why it matters: Cloud security teams can now extend Wiz functionality through third-party integrations, reducing the need for separate tools and improving operational efficiency in their security stack.
- identity access
Understanding GDAP and Its Operational Impact | Huntress
Microsoft's Granular Delegated Admin Privileges (GDAP) is an authentication control that manages administrative access permissions. The article provides guidance on understanding GDAP and its operational implications for organizations using Microsoft services.
Why it matters: IT administrators and managed service providers (MSPs) need to understand GDAP configuration and deployment to properly secure delegated administrative access and comply with Microsoft security requirements.
- cloud saas
Kubernetes Grey Zone: Risks in Managed Cluster Middleware
The article examines security risks associated with middleware components in managed Kubernetes clusters. It discusses how organizations can identify and mitigate these risks to improve cluster security posture.
Why it matters: Teams running managed Kubernetes deployments need to understand middleware vulnerability exposure and implement controls to prevent unauthorized access or data compromise through the cluster stack.
- cloud saas
Crying Out Cloud: a magical podcast for cloud security enthusiasts
Wiz is launching a podcast focused on cloud security topics, featuring industry expertise and insights. The show aims to provide guidance and news relevant to cloud security practitioners.
Why it matters: Cloud security professionals seeking current information and expert perspectives on cloud threats and defense strategies should evaluate whether this resource fits their professional development needs.
- industry
Three tips for building your CISO career in today’s evolving security industry
Article discusses career guidance for aspiring and current chief information security officers (CISOs) on building effective teams and advancing to new positions in the security industry.
Why it matters: Security leaders evaluating their career trajectory and team-building strategies can reference practitioner advice on professional development and organizational effectiveness.
- threat intel
Calm In The Storm: Reviewing Volt Typhoon
Volt Typhoon is a threat actor that has been disclosed as exploiting external-facing services and network appliances in widespread campaigns. Recent reporting has provided details on the group's targeting patterns and methods across compromised infrastructure.
Why it matters: Organizations managing OT, ICS, and critical infrastructure are at risk, as Volt Typhoon targets internet-exposed devices to establish persistent access; practitioners should audit external-facing appliances and services for unauthorized access or misconfigurations.
- cloud saas
Wiz for CSPM: A modern approach to cloud security
Wiz has announced a cloud security posture management (CSPM) tool that uses context-based risk assessment to help organizations prioritize misconfigurations by severity and business impact rather than volume. The approach aims to reduce alert fatigue common in traditional CSPM solutions.
Why it matters: Cloud security teams need to evaluate whether this tooling addresses their current noise and triage challenges in managing cloud misconfigurations at scale.
- cloud saas
The Big IAM Challenge: Test Your Cloud Security Skills
A capture the flag (CTF) challenge focused on AWS Identity and Access Management (IAM) has been announced to test and improve cloud security skills. The challenge appears designed to help practitioners validate and enhance their understanding of IAM configurations and security practices.
Why it matters: Cloud security practitioners should evaluate their IAM knowledge gaps through hands-on challenges, as IAM misconfigurations remain a primary cause of cloud breaches and unauthorized access.
- threat intel
Beware of Traitorware: Using Splunk for Persistence
Splunk Universal Forwarder (UF) can be leveraged by attackers as a persistence mechanism and for remote code execution after initial compromise. This technique, termed traitorware, exploits legitimate software to maintain access to affected systems.
Why it matters: Security teams managing Splunk deployments need to monitor Universal Forwarder configurations and communications for signs of abuse, as attackers can weaponize this trusted infrastructure component for post-exploitation activities.
- cloud saas
Ta-da! Wiz launches Runtime Sensor to provide real-time detection and response
Wiz has released a Runtime Sensor product that combines agentless visibility and risk assessment with real-time detection and response capabilities. The offering aims to provide comprehensive visibility across cloud environments while enabling immediate threat detection and response actions.
Why it matters: Cloud security practitioners need to evaluate whether this runtime detection capability improves their ability to detect and respond to threats faster than existing agentless approaches, particularly for workload and container security.
- cloud saas
CTO Point of View: Why Wiz is launching a Runtime Sensor
Wiz announced a new Runtime Sensor that collects real-time signals from workload runtimes to enhance threat detection and response capabilities within its Cloud Detection and Response platform. The sensor is designed to simplify security operations by providing visibility into runtime behavior across cloud environments.
Why it matters: Cloud security teams need to evaluate whether runtime monitoring complements their existing detection and response tools, particularly if they currently lack visibility into workload behavior during execution.
- vulnerabilitiesCVE-2023-34362
MOVEit Transfer Critical Vulnerability CVE-2023-34362 | Huntress
Huntress is tracking active exploitation of a zero-day vulnerability in Progress MOVEit Transfer that enables privilege escalation and unauthorized access. The flaw affects the web-based file transfer application and is being leveraged by attackers in real-world attacks.
Why it matters: Organizations running MOVEit Transfer need to assess their exposure immediately, as attackers are actively exploiting this vulnerability to gain elevated access to file transfer systems.
- cloud saas
How to get rid of AWS access keys- Part 1: The easy wins
An article provides guidance on identifying and removing unused or unnecessary long-lived AWS Identity and Access Management (IAM) User access keys as part of a multi-part series on AWS access key management. The piece focuses on straightforward approaches to eliminate unnecessary credentials that pose security risks.
Why it matters: AWS practitioners managing cloud environments need to reduce their attack surface by eliminating dormant credentials; unused access keys represent a persistent exposure if compromised.
- threat intel
Threat Advisory: XMRig Cryptomining By Way Of TeamViewer
Threat actors are increasingly compromising TeamViewer accounts to distribute and install XMRig, a cryptomining malware. Security researchers at Huntress have observed a spike in this activity and published technical analysis on the campaign.
Why it matters: Organizations using TeamViewer for remote access are at immediate risk if account credentials are weak or compromised; administrators should audit TeamViewer access logs and strengthen credential hygiene to prevent unauthorized installation of resource-draining cryptominers.
- cloud saas
Bridging the Security Gap: Mitigating Lateral Movement Risks from On-Premises to Cloud Environments
A blog post outlines tactics, techniques, and procedures (TTPs) used by attackers to move laterally from on-premises systems into cloud environments, along with defensive best practices for securing hybrid infrastructure. The post targets cloud builders and security defenders seeking to reduce lateral movement risks across on-premises and cloud boundaries.
Why it matters: Security teams managing hybrid on-premises and cloud deployments need to understand and defend against lateral movement paths that span both environments, as misconfigured trust relationships and identity federation create exploitation vectors.
- vulnerabilitiesCVE-2023-32784
Exploitable and unpatched KeePass vulnerability: everything you need to know
CVE-2023-32784 is a vulnerability in KeePass that allows attackers to extract the master password in cleartext from application memory. The flaw remains unpatched in affected versions, requiring users to implement detection and mitigation measures to protect their password vaults.
Why it matters: Organizations and individuals using KeePass need to assess their exposure immediately, as compromise of the master password grants full access to all stored credentials and requires urgent mitigation or version upgrades.
- identity access
MM vs MDM for macOS: What's the Difference? | Huntress
This article compares remote monitoring and management (RMM) with mobile device management (MDM) for macOS systems, explaining their distinct functions and how Huntress integrates with both approaches. RMM and MDM serve different purposes in endpoint security, with implications for how organizations manage and protect their macOS fleet.
Why it matters: MSP and IT practitioners need to understand the functional differences between RMM and MDM to properly architect macOS security and management strategies for their environment.
- cloud saas
Wiz Receives 2023 Global Cloud Security Entrepreneurial Company of the Year Award
Wiz received the 2023 Global Cloud Security Entrepreneurial Company of the Year Award from Frost & Sullivan in recognition of its innovation and impact in cloud security. The award recognizes the company's contributions to the cloud security market.
Why it matters: Cloud security practitioners should monitor award-winning vendors like Wiz to understand which companies are driving innovation, but awards alone should not drive purchasing decisions without independent evaluation of specific security capabilities and organizational needs.
- industry
New Investment Fuels Our Mission To Enable SMBs to Better Protect Their Business Assets | Huntress
Huntress, a cybersecurity company focused on small and medium-sized businesses, has secured $60 million in Series C funding led by Sapphire Ventures, with participation from existing investors Forgepoint Capital and JMI Equity. The funding will support Huntress's mission to help SMBs enhance their business asset protection capabilities. This round indicates continued investor confidence in the SMB security market.
Why it matters: SMB security practitioners should monitor Huntress's expanded capabilities and product roadmap post-funding, as increased investment typically accelerates feature development, customer support, and market reach that could affect your tooling and vendor strategy.
- cloud saas
How to monitor, detect, and respond to cloud data risks faster with built-in security controls for cloud events
Wiz has enhanced its Data Security Posture Management (DSPM) platform with new capabilities to correlate and detect suspicious events affecting unprotected data with near real-time visibility. The built-in security controls aim to help organizations monitor, identify, and respond to cloud data risks more rapidly.
Why it matters: Cloud security teams need faster detection and response to data exposure events; this tooling enhancement enables practitioners to identify threats to sensitive data in cloud environments before they escalate.
- threat intel
Advanced CyberChef Tips: AsyncRAT Loader | Huntress
Huntress published a blog post offering advanced tips for using CyberChef, with a focus on AsyncRAT loader analysis. The post provides guidance for security practitioners using the open-source analysis tool in malware investigation workflows.
Why it matters: Security analysts and incident responders benefit from practical CyberChef techniques when investigating AsyncRAT malware loaders and obfuscated payloads.
- government policy
Here's what security teams need to know about the new Biden-Harris National Cybersecurity Strategy
The Biden-Harris Administration released an updated National Cybersecurity Strategy that outlines federal priorities and guidance for cybersecurity across the United States. Security teams should review the strategy to understand new government expectations, requirements, and frameworks that may affect their organizations and compliance obligations.
Why it matters: Security practitioners need to understand the new strategic priorities and any mandatory requirements the administration may impose on critical infrastructure, federal contractors, and private sector organizations.
- industry
The Power of People: Inside Huntress EDR and 24/7 Operations | Huntress
Huntress has released a webinar recording showcasing its endpoint detection and response (EDR) platform and the role of human analysts in its 24/7 security operations. The presentation is intended for the security community to understand how the platform functions and its operational capabilities.
Why it matters: Security practitioners evaluating EDR solutions should review how Huntress differentiates itself through human-driven threat analysis, which may inform procurement and deployment decisions.
- cloud saas
How secure is your public cloud? Quick wins & best practices
The article discusses cross-tenant risk in public cloud environments and introduces the PEACH framework as a tool for identifying vulnerabilities and implementing security best practices. It addresses how organizations can assess and improve their cloud security posture.
Why it matters: Cloud platform users need to understand cross-tenant isolation risks and apply structured approaches like PEACH to prevent exposure of sensitive data and workloads shared on public cloud infrastructure.
- cloud saas
How to put your organization’s cloud security strategy into action
Security leaders from Paramount, Aon, and Wiz discuss practical approaches to implementing and sustaining cloud security strategies within their organizations. The article highlights insights and lessons learned from these executives about building resilient cloud security frameworks.
Why it matters: CISOs responsible for cloud infrastructure need concrete implementation methods and best practices from peers to evaluate and enhance their own cloud security posture and strategy.
- threat intel
Endpoint Security In a macOS World | Huntress
This article provides an overview of endpoint security for macOS environments, covering foundational concepts, detailed technical analysis, and practical guidance for detection engineers implementing these protections.
Why it matters: Security teams managing macOS infrastructure need to understand endpoint security capabilities to protect against attacks targeting Apple systems, which have become increasingly targeted by threat actors.
- cloud saas
Deloitte and Wiz Announce a Strategic Alliance to Help their Mutual Clients Accelerate Digital Transformation with a Modern Cloud Security Strategy
Deloitte and Wiz have formed a strategic alliance to help clients improve their cloud security posture through better identification, prioritization, and remediation of risks. The partnership combines Deloitte's consulting expertise with Wiz's cloud security platform capabilities to support digital transformation initiatives.
Why it matters: Organizations managing cloud environments should understand this alliance may provide new service offerings and integrated approaches to cloud risk management, potentially affecting vendor selection and security tool evaluation.
- vulnerabilities
Critical Vulnerabilities in PaperCut Print Management Software | Huntress
Huntress is tracking zero-day vulnerabilities in PaperCut MF/NG print management software that enable unauthenticated remote code execution through an authentication bypass mechanism. Active exploitation of these flaws has been observed in the wild.
Why it matters: Organizations using PaperCut MF/NG face immediate risk of compromise without authentication requirements; security teams should prioritize investigation and patching of affected infrastructure.
- vulnerabilities
#BrokenSesame: Accidental ‘write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services
Wiz Research discovered a container escape vulnerability paired with overly permissive write access to Alibaba Cloud's private registry, creating a potential supply-chain attack vector that could have led to remote code execution and database compromise. The misconfiguration was identified during security research and highlights risks in container orchestration and registry access controls. Alibaba Cloud addressed the issues after responsible disclosure.
Why it matters: Cloud infrastructure operators and DevOps teams need to audit container escape mitigations and private registry permissions immediately, as this pattern affects production databases and enables supply-chain compromise across dependent services.
- cloud saas
Wiz: First agentless cloud security vendor to attain CIS SecureSuite Vendor Certification for cloud-managed Kubernetes
Wiz has achieved CIS SecureSuite Vendor Certification for cloud-managed Kubernetes compliance, becoming the first agentless vendor to do so. The certification enables organizations to generate compliance reports and remediate issues against CIS Benchmarks for Kubernetes environments.
Why it matters: Security teams managing Kubernetes in cloud environments can now use a certified agentless solution to demonstrate CIS Benchmark compliance and reduce the operational burden of manual remediation.
- cloud saas
Wiz is on the FedRAMP Marketplace
Wiz, a cloud security vendor, has achieved an 'in process' milestone on the FedRAMP marketplace, indicating progress toward federal authorization. This status allows the company to work with U.S. government agencies while completing the full FedRAMP certification process.
Why it matters: Government security practitioners and procurement teams can now evaluate Wiz for federal contracts and deployments, accelerating adoption of the platform within public sector organizations.
- vulnerabilitiesCVE-2023-21554CVE-2023-28252
Microsoft April 2023 Patch Tuesday Highlights: everything you need to know
Microsoft released patches in April 2023 addressing multiple critical vulnerabilities, including CVE-2023-28252, an elevation of privilege (EoP) vulnerability being exploited in active attacks, and CVE-2023-21554, a critical remote code execution (RCE) flaw. Organizations are advised to prioritize patching these issues immediately.
Why it matters: All Windows environments running unpatched systems are at immediate risk of compromise from active exploitation of CVE-2023-28252 and potential RCE attacks via CVE-2023-21554, requiring urgent patching.
- cloud saas
Five ways to bolster security as cloud environments and budgets come under attack
Security experts provide recommendations for strengthening cloud security as threats to cloud environments increase in frequency and scale. The article discusses practical approaches for organizations managing security in cloud infrastructures amid growing attack pressures.
Why it matters: Cloud practitioners need actionable security improvements as cloud-targeted attacks accelerate, making it critical to prioritize defense strategies within budget constraints.
- cloud saas
Why data security capabilities should be integrated with CNAPP
Cloud native application protection platforms (CNAPPs) are expanding to address data security risks across cloud environments at scale. Integrating data protection capabilities into CNAPPs enables organizations to identify and mitigate data exposure threats more effectively during runtime and deployment.
Why it matters: Cloud security practitioners need to evaluate whether their CNAPP solutions include data discovery and classification features to prevent unauthorized data access in cloud-native applications before incidents occur.
- cloud saas
How CNAPPs identify and prioritize excessive risk in a single platform, according to Gartner®
This article discusses how Cloud-Native Application Protection Platforms (CNAPPs) function to identify and prioritize risk across cloud environments using a unified platform, based on Gartner's March 2023 market analysis. CNAPPs consolidate multiple security functions into a single interface to help organizations manage cloud security more effectively.
Why it matters: Security teams evaluating cloud protection tools should understand how CNAPPs reduce tool sprawl and improve risk visibility, enabling faster prioritization of security issues in cloud-native environments.
- threat intel
Traitorware and Living Off the Land | Huntress
The article discusses traitorware, a technique where legitimate security tools are weaponized or abused by attackers to conduct malicious activities while evading detection. This approach leverages trusted software already present in an environment, enabling adversaries to blend in with normal operations.
Why it matters: Security teams need to understand that their own defensive tools can become attack vectors; practitioners should review access controls and monitoring for legitimate tools being misused by insiders or compromised accounts.
- cloud saas
Intro to forensics in the cloud: A container was compromised. What’s next?
This article provides guidance on conducting forensic investigations in cloud environments, focusing on tools, data sources, and practical application when a container has been compromised. It serves as an introductory resource for security teams handling cloud-based incidents.
Why it matters: Cloud and container security teams need practical forensics procedures and tooling knowledge to investigate and respond to compromises in their environments.
- regulatory
Huntress Is SOC2, GDPR and CCPA Compliant! | Huntress
Huntress has achieved SOC2 Type II certification and compliance with GDPR (General Data Protection Regulation) and CCPA (California Consumer Privacy Act), demonstrating adherence to security, availability, and data privacy standards. The compliance certifications apply to Huntress operations and its partner ecosystem.
Why it matters: MSPs and enterprises using Huntress can reference these certifications in customer compliance programs and RFP responses, reducing friction in security tool procurement.
- industry
Huntress Heads Into Q2 Serving More SMBs and 2 Million Endpoints | Huntress
Huntress announced it has surpassed two million endpoints under management, reflecting growth in its customer base of small and medium-sized businesses. The milestone marks the company's expansion in the SMB security market.
Why it matters: MSPs and SMB security teams should track Huntress's growing platform footprint as it may affect competitive positioning, integration opportunities, or threat intelligence data quality across their client base.
- breaches incidents
Contextualizing Events & Enabling Defense: What 3CX Means | Huntress
Huntress published analysis contextualizing the 3CX supply chain compromise and discussing defensive strategies in response to the incident. The post examines the attack's implications and provides guidance for organizations affected by or concerned about the compromise.
Why it matters: Security teams using 3CX or managing affected endpoints need to understand the compromise scope and implement recommended defenses to detect and respond to related threats.
- breaches incidents
3CX VoIP Software Compromise & Supply Chain Threats | Huntress
The 3CX VoIP Desktop Application was compromised to distribute malware through official software updates. Huntress is investigating the incident and assessing the broader supply chain threat to organizations.
Why it matters: Any organization using 3CX VoIP software may have received malicious updates; practitioners should immediately audit 3CX installations and check for signs of compromise from this supply chain attack.
- cloud saas
BingBang: How a simple developer mistake could have led to Bing.com takeover
Wiz Research discovered a misconfiguration in a Microsoft Bing application that could have allowed attackers to modify Bing search results and access private data of millions of users. The vulnerability stemmed from a developer mistake in how the application was set up. Microsoft addressed the issue following responsible disclosure.
Why it matters: All organizations using Microsoft cloud services should review their own application configurations for similar misconfigurations, as this type of error can expose search engines and user data at scale.
- cloud saas
BingBang: AAD misconfiguration led to Bing.com results manipulation and account takeover
Wiz Research discovered a misconfiguration in Azure Active Directory (AAD) that exposed multiple Microsoft applications, including a Bing management portal, to manipulation and account takeover attacks. The vulnerability stemmed from improper configuration settings within AAD rather than a flaw in the platform itself. This finding highlights how enterprise identity systems can be compromised through common setup oversights.
Why it matters: Security teams managing Azure environments must audit AAD configurations to identify and remediate similar misconfigurations that could lead to unauthorized access to critical applications and sensitive portals.
- industry
Partnering and prioritization: Lessons learned when building security operations at hyperspeed
CISOs discuss strategies and lessons learned for establishing security operations in rapidly growing organizations. The article covers approaches to prioritizing security initiatives and building effective partnerships when resources and time are constrained.
Why it matters: Security leaders in hypergrowth companies need practical frameworks for balancing security investments with business velocity, making this directly relevant to practitioners scaling security programs.
- research
Mid-Sized Businesses vs. The Threat Landscape in 2023 | Huntress
A survey examining mid-sized businesses identified common cybersecurity vulnerabilities present in this market segment. The findings highlight specific security gaps and provide recommendations for improving defensive measures in 2023.
Why it matters: Mid-sized business security leaders should review these findings to benchmark their current posture against peers and prioritize remediation of widely exploited weaknesses.
- cloud saas
Everything you ❤ about Wiz, now deployed in a new Canadian data center
Wiz has launched a new Canadian data center and added support for the CSE Information Technology Security Guidance (ITSG) 33 framework. This expansion enables Canadian organizations to maintain data residency while meeting local compliance requirements for cloud security.
Why it matters: Canadian cloud security practitioners need to assess whether local data residency and ITSG-33 compliance support align with their regulatory obligations and security posture evaluation timelines.
- cloud saas
Detect critical application misconfiguration risks
Wiz has released agentless capabilities designed to identify application misconfigurations that pose security risks equivalent to code execution or information disclosure vulnerabilities. The tool correlates detected misconfigurations with attack surface analysis and business impact to prioritize the most critical findings.
Why it matters: Security teams need to detect and remediate application misconfigurations that expose systems to exploitation, as these gaps often remain hidden without dedicated detection tools.
- research
macOS (Not)ifications | Huntress
Huntress published a blog post examining macOS notifications and the design choices that influence their behavior and functionality. The article explores how notifications work on Apple's macOS platform and the reasoning behind their implementation.
Why it matters: Security practitioners should understand macOS notification mechanisms to identify potential attack vectors or misconfigurations that could be exploited for persistence, privilege escalation, or social engineering attacks on managed endpoints.
- cloud saas
Using Service Control Policies to protect security baselines
Service Control Policies (SCPs) in AWS can be used to enforce and protect security baseline configurations across accounts by preventing unauthorized actions. This approach helps maintain landing zone standards by restricting what can be done within AWS accounts. The technique is applicable to organizations managing multiple AWS accounts with defined security requirements.
Why it matters: Security practitioners managing AWS multi-account environments should evaluate SCPs to prevent configuration drift and enforce baseline security controls across their organization.
- vulnerabilitiesCVE-2023-23397
Everything We Know About CVE-2023-23397 | Huntress
CVE-2023-23397 is a zero-day vulnerability affecting Microsoft Outlook that allows attackers to capture user credential hashes without requiring any user interaction. Huntress is monitoring this vulnerability as it poses a significant threat to email users.
Why it matters: Organizations using Microsoft Outlook face immediate risk of credential compromise and lateral movement attacks; patch or deploy compensating controls without delay.
- threat intel
Addressing Initial Access | Huntress
Huntress published a series of blog posts sharing guidance on reducing attack surface and preventing cyber attacks based on their operational experience. The content focuses on initial access vectors and how organizations can better defend against them.
Why it matters: Security practitioners should review the guidance to understand common initial access techniques and implement controls that reduce their organization's exposure to attack entry points.
- cloud saas
Shift left with Wiz Guardrails: New Wiz Admission Controller capabilities enable security policy checks at deployment time
Wiz has introduced new Admission Controller capabilities that allow developers to enforce security policies earlier in the deployment pipeline through its CLI and Admission Controller tools. These features enable consistent policy application across cloud-native environments during the deployment phase rather than after resources are already provisioned.
Why it matters: Development and security teams can reduce cloud misconfigurations and policy violations by catching issues at deployment time, shortening remediation cycles and preventing non-compliant resources from reaching production.
- regulatory
Compliance made easy with Wiz
Wiz offers compliance management capabilities covering over 100 frameworks, enabling organizations to generate reports and remediate issues with guided and automated remediation features. The platform aims to streamline compliance operations and reduce the time required to address identified gaps.
Why it matters: Security teams and compliance officers need efficient tools to demonstrate adherence to multiple regulatory frameworks and address findings quickly; Wiz's approach reduces manual effort in compliance reporting and remediation workflows.
- vulnerabilitiesCVE-2023-27532
Veeam Backup & Replication CVE-2023-27532 Response | Huntress
CVE-2023-27532 is a vulnerability in Veeam Backup & Replication that allows unauthenticated users to retrieve host credentials. This vulnerability could enable attackers to gain unauthorized access to backup infrastructure and related systems.
Why it matters: Organizations using Veeam Backup & Replication need to assess exposure and apply fixes immediately, as credential disclosure could lead to lateral movement and compromise of protected infrastructure.
- cloud saas
From Pod Security Policies to Pod Security Standards – a Migration Guide
Kubernetes removed Pod Security Policies (PSPs) in version 1.25, and organizations using the deprecated feature need to transition to Pod Security Standards (PSSs). This guide provides the steps and considerations for migrating from the legacy security mechanism to its modern replacement.
Why it matters: Kubernetes operators and platform teams must migrate off deprecated PSPs to maintain security posture and compliance with current Kubernetes best practices, as the old feature is no longer available in supported versions.
- cloud saas
Wiz enhances its industry leading data security solution with broader cloud data coverage and customizable platform capabilities
Wiz announced general availability of its Data Security Posture Management (DSPM) solution, which expands cloud data coverage and allows customization across its platform. The offering aims to help organizations identify and remediate cloud data exposure risks more quickly.
Why it matters: Cloud security practitioners need to evaluate whether broader data discovery and remediation capabilities reduce their mean time to response for data exposure incidents in their environment.
- cloud saas
Wiz and SentinelOne announce exclusive partnership to deliver end to end cloud security
Wiz and SentinelOne announced an exclusive partnership to deliver integrated cloud security solutions. The collaboration aims to enhance customer value and reshape the enterprise security market through combined capabilities.
Why it matters: Customers using either platform should evaluate how this partnership affects their existing contracts, integrations, and security posture, as exclusive arrangements may limit choice or create new licensing considerations.
- industry
How To Get Buy-In for an EDR Purchase
This article provides guidance on how to obtain organizational approval and budget for endpoint detection and response (EDR) tools, including key questions to address and talking points for stakeholders. It positions EDR as a fundamental security control that organizations should prioritize in their security infrastructure.
Why it matters: Security practitioners and leaders need strategies to justify EDR investment to decision makers, making this relevant for those planning procurement or upgrades to their endpoint protection capabilities.
- cloud saas
The benefits of a customer-centric cloud security mindset
This article discusses how adopting a customer-centric approach to cloud security can drive innovation and improve security team outcomes. The piece emphasizes the business value of aligning security practices with customer needs and expectations in cloud environments.
Why it matters: Security leaders and cloud architects need to understand how customer-focused strategies can enhance both security posture and team productivity in their organizations.
- industry
Securing a successful merger: Insights from MGM Studios
MGM Studios' Chief Information Security Officer discusses how the organization uses Wiz to enable collaboration and transparency across business units during a merger. The article highlights approaches to security governance and organizational integration during a significant corporate transaction.
Why it matters: Security teams managing merger integrations need to understand how to maintain visibility and coordinate security practices across consolidated entities to avoid gaps and compliance issues.
- threat intel
What are the biggest cyberthreats heading our way in 2023?
Experts from Wiz and Procter & Gamble discuss anticipated cybersecurity threats for 2023 and provide recommendations for addressing them. The article presents security insights and guidance from industry practitioners based on threat landscape analysis.
Why it matters: Security practitioners need to understand emerging threat trends to inform their defense priorities and strategic planning for the year ahead.
- breaches incidents
Redirection Roulette: Thousands of hijacked websites in East Asia redirecting visitors to other sites
Starting in early September 2022, tens of thousands of websites targeting East Asian audiences were compromised and redirected users to adult-themed content. The attack affected hundreds of thousands of visitors whose sessions were hijacked to other sites. The campaign demonstrates widespread website security compromise across the region.
Why it matters: Website administrators and organizations hosting content for East Asian audiences need to audit their systems for unauthorized redirects, verify integrity of their web configurations, and patch vulnerabilities that enabled the initial compromise.
- cloud saas
Enhanced policy management with GitOps and Terraform
Wiz has released new GitOps workflows and a Terraform provider that allow customers to manage policies through code-based infrastructure-as-code practices. This extends Wiz's cloud security platform to support programmatic policy configuration and version control integration.
Why it matters: Cloud security teams using Terraform for infrastructure automation can now manage Wiz policies consistently with their existing IaC workflows, reducing manual configuration overhead and improving policy auditability.
- industry
Wiz becomes the world’s largest cybersecurity unicorn
Wiz reached a $10 billion valuation in just three years from its founding, becoming the world's largest cybersecurity unicorn and the fastest SaaS company to achieve this milestone.
Why it matters: Security practitioners should monitor Wiz's growth and product direction as a leading cloud security vendor, given its rapid expansion and market influence in the sector.
- cloud saas
Lateral movement risks in the cloud and how to prevent them – Part 3: from compromised cloud resource to Kubernetes cluster takeover
This blog post discusses lateral movement risks that enable attackers to move from compromised cloud resources into Kubernetes clusters, covering attacker tactics and defensive best practices for securing cloud environments.
Why it matters: Cloud and Kubernetes practitioners need to understand cross-platform lateral movement techniques to prevent attackers from escalating from cloud resource compromise to cluster takeover.
- cloud saas
What Endpoint Detection and Response (EDR) Looks Like | Huntress
An article examining the landscape of Endpoint Detection and Response (EDR) solutions, exploring how different EDR tools vary in their capabilities and effectiveness in the market. The piece aims to clarify what EDR actually entails and help readers understand the differences among available solutions.
Why it matters: Security practitioners evaluating EDR tools need to understand the actual capabilities and limitations of different solutions to select the right one for their organization's threat detection and response requirements.
A Brief History of Wiz Socks
An article explores the historical context and development of Wiz Socks, tracing their role in cloud protection across various time periods. The piece uses metaphorical references to major historical events and figures to frame the narrative.
Why it matters: This appears to be promotional or non-technical content with no direct security implications or actionable guidance for practitioners.
- research
Built-in macOS Security Tools | Huntress
Huntress highlights several built-in security capabilities available natively within macOS. The article reviews tools and features that are part of the standard macOS installation for defensive purposes.
Why it matters: macOS administrators and security practitioners should understand available native security tools to maximize built-in protections without requiring additional software licensing.
- industry
Not All Managed Is Created Equally | Huntress
The article discusses how companies use the term 'managed' in different ways, and that solutions marketed as managed services may not be equivalent despite surface similarities. It highlights the importance of distinguishing between different managed service implementations.
Why it matters: MSP and security practitioners need to evaluate whether managed solutions truly meet their operational and security requirements, as terminology alone does not ensure consistent capability or protection levels.
- industry
Adapt to endure: navigating the current economic environment
CISOs are adapting their strategies to navigate economic challenges by consolidating security tools and maintaining investment in security capabilities. The article discusses how security leaders are responding to current business conditions through operational adjustments and continued prioritization of security spending.
Why it matters: Security leaders need to understand consolidation trends and budget strategies to align their own tool selection and spending with peer practices in a challenging economic environment.
- cloud saas
Choosing the Right EDR: Managed vs. Unmanaged
This article discusses the decision between managed and unmanaged endpoint detection and response (EDR) solutions, comparing their respective advantages and helping organizations determine which approach aligns with their needs and capabilities.
Why it matters: Security teams evaluating EDR deployments should understand managed versus unmanaged models to match their staffing, budget, and response capabilities with the right solution for their environment.
- threat intel
Investigating Intrusions From Intriguing Exploits
Huntress observed a security alert triggered in a protected environment on February 2, 2023, and investigated the underlying threat. The blog post documents the triage process and findings from this incident response case.
Why it matters: Security practitioners should review the investigation methodology and indicators of compromise to enhance their own threat detection and response capabilities.
- cloud saas
Let it snow! Wiz and Snowflake join forces to power insights with actionable intelligence
Wiz and Snowflake have announced an integration that enables organizations to automatically export cloud security findings from Wiz into Snowflake for analysis and reporting on security metrics. The partnership allows security teams to consolidate cloud posture data with their data platform for deeper insights and more comprehensive security reporting.
Why it matters: Security teams using both platforms can now streamline workflows by centralizing cloud security data in Snowflake, reducing manual data export work and enabling faster decision-making on remediation priorities.
- ransomwareCVE-2021-21974
Ransomware attacks targeting VMware ESXi servers: everything you need to know
Recent attacks are exploiting CVE-2021-21974, a known vulnerability in VMware ESXi servers, to deploy ransomware. Security teams are being urged to apply patches and monitor for signs of compromise on affected systems.
Why it matters: Infrastructure teams running VMware ESXi must patch immediately to prevent ransomware installation that could take down virtual environments and halt business operations.
- cloud saas
Getting started with Open Policy Agent (OPA) to improve your cloud security
Open Policy Agent (OPA) is a tool for implementing policy-as-code in cloud environments, with Rego as the policy language. The resource provides foundational guidance on using OPA and Rego to express and enforce security policies across cloud infrastructure.
Why it matters: Cloud security practitioners need to evaluate and adopt policy-as-code tools to automate compliance checks and reduce manual security configuration errors across their environments.
- threat intel
Ave Maria and the Chambers of Warzone RAT | Huntress
An article discusses Elasticsearch syntax in the context of malware analysis, specifically related to Warzone RAT (Remote Access Trojan) investigation techniques. The piece appears to focus on improving analyst capabilities for threat detection and investigation.
Why it matters: Security analysts and threat hunters need to understand advanced search and filtering techniques to effectively identify and investigate Warzone RAT infections in their environments.
- cloud saas
Streamlining OS and Application Hardening: Revealing Misconfigurations with Wiz’s Agentless Custom Host Configuration Rules
Wiz has released agentless custom host configuration rules that allow security teams to automate shell commands for scanning workload misconfigurations on a daily basis, eliminating manual execution processes. This capability enables operating system and application hardening by programmatically detecting configuration drift and security gaps across infrastructure without requiring agent installation.
Why it matters: Cloud security teams can now identify and remediate OS and application misconfigurations at scale without agent overhead, reducing the window for attackers to exploit hardening gaps.
- cloud saas
Enhancing Kubernetes security with user namespaces
Kubernetes v1.25 introduced user namespaces as a security feature to strengthen cluster isolation and protection. User namespaces enable better separation of user identities and processes within containers, reducing the blast radius of potential compromises. This feature helps organizations implement defense-in-depth strategies for Kubernetes deployments.
Why it matters: Platform engineers and cluster operators managing Kubernetes environments should evaluate user namespaces to limit the impact of container escapes and privilege escalation attacks on their infrastructure.
- vulnerabilitiesCVE-2022-44877
CVE-2022-44877, critical RCE in CentOS Control Web Panel exploited in the wild: everything you need to know
CVE-2022-44877 is a critical remote code execution vulnerability in CentOS Control Web Panel that allows unauthenticated attackers to execute arbitrary code. The vulnerability is actively being exploited in the wild, prompting urgent calls for patching.
Why it matters: Organizations running CentOS Control Web Panel are at immediate risk of compromise; security teams should prioritize patching this actively exploited vulnerability to prevent unauthorized access and data theft.
- breaches incidents
Why Having Backups Isn't Enough | Huntress
Backups alone are insufficient for comprehensive business continuity and disaster recovery planning. Organizations need additional controls and processes beyond data backup to ensure operational resilience during outages or incidents.
Why it matters: Security practitioners must implement layered recovery strategies including backup testing, failover procedures, and incident response protocols to minimize downtime and protect critical business functions when backups alone cannot restore operations quickly enough.
- cloud saas
Hunting for signs of persistence in the cloud: an IR guide following the CircleCI incident
This article provides incident response guidance for detecting malicious persistence mechanisms in major cloud platforms, AWS, Google Cloud Platform (GCP), and Microsoft Azure. The guidance is framed in the context of lessons from the CircleCI security incident and aims to help practitioners identify attacker artifacts left behind after initial compromise.
Why it matters: Cloud engineers and security teams need practical detection methods to identify persistence foothold techniques in their cloud environments before attackers can maintain long-term access or move laterally.
- cloud saas
Wiz launches Australia cloud data center further demonstrating commitment to ANZ and multinational organizations
Wiz announced a new cloud data center in Australia and added support for Essential Eight controls, a cybersecurity framework widely adopted in the Asia-Pacific region. The expansion reinforces Wiz's commitment to serving Australian and multinational organizations operating in the ANZ region.
Why it matters: Organizations using Wiz for cloud security in Australia and the Asia-Pacific now have regional data residency options and compliance support for Australian security standards, reducing latency and addressing local regulatory requirements.
- industry
Insistence on Persistence | Huntress
Huntress has developed a new macOS agent and is sharing details about its capabilities, detection focus, and product roadmap. The brief announcement indicates the company is expanding its endpoint detection and response (EDR) platform to better serve Mac-based environments.
Why it matters: Organizations using macOS in their security operations need to evaluate whether Huntress's expanded agent meets their endpoint visibility and threat detection requirements.
- industry
New Year’s Resolutions: Where CISOs plan to invest and scale back in 2023
Security leaders are sharing their investment priorities and strategic shifts for 2023, including areas where they plan to increase spending and where they may reduce focus. The article captures perspectives from chief information security officers (CISOs) on how they are allocating resources and reshaping their security programs for the coming year.
Why it matters: Security practitioners should understand emerging priorities among peer organizations to benchmark their own roadmaps, identify emerging investment trends, and make informed decisions about where to allocate their budgets and personnel in 2023.
- cloud saas
Managed Endpoint Detection and Response (EDR) in Action | Huntress
This is promotional content describing how managed endpoint detection and response (EDR) services detect and prevent attacks on endpoints by targeting vulnerabilities in endpoint security. The article outlines the role of managed EDR in stopping attacks before they can cause damage.
Why it matters: Security teams evaluating detection and response capabilities should understand how managed EDR addresses endpoint attack patterns and can support their incident response strategy.
- threat intel
Malicious PyTorch dependency 'torchtriton' on PyPI: everything you need to know
PyTorch developers discovered a malicious dependency confusion attack targeting the project through a fake 'torchtriton' package on PyPI. The attack aimed to compromise PyTorch users by distributing malware through a package name similar to a legitimate dependency. Security teams should verify systems for the malicious package and rotate any exposed credentials.
Why it matters: PyTorch users and organizations relying on machine learning workflows are at risk of supply chain compromise; practitioners should immediately check for the malicious package and audit access keys.
- research
Going the Distance: Cyber Predictions for 2023 | Huntress
Huntress security researchers John Hammond and Dray Agha have published their cybersecurity predictions for 2023. The piece presents their forecasts on emerging threats and trends expected in the year ahead.
Why it matters: Security practitioners should review expert predictions to anticipate threat landscape shifts and adjust defensive priorities and staffing accordingly.
- vulnerabilitiesCVE-2022-41080CVE-2022-41082
OWASSRF, a new exploit for Exchange vulnerabilities, exploited in the wild: everything you need to know
A new exploitation technique called OWASSRF has been discovered targeting two known Exchange server vulnerabilities (CVE-2022-41080 and CVE-2022-41082) and is being actively exploited. This method bypasses previously deployed workarounds, requiring organizations to apply patches rather than rely on earlier mitigation strategies.
Why it matters: Organizations running vulnerable Exchange servers need to patch immediately, as existing workarounds no longer protect against active exploitation.
- cloud saas
Automatically discover and secure your APIs with Wiz Dynamic Scanner
Wiz has enhanced its Dynamic Scanner tool to automatically identify publicly exposed and unauthenticated application programming interfaces (APIs) in cloud environments. The update aims to help organizations discover API-related security gaps that could be exploited by attackers.
Why it matters: Cloud security teams need to inventory and remediate exposed APIs to prevent unauthorized access to backend services and data; this tool helps reduce the window of exposure for unauthenticated endpoints.
- cloud saas
Wiz introduces Dangling Domain Detection to help you prevent subdomain takeovers
Wiz has released a Dangling Domain Detection feature designed to identify and mitigate the risk of subdomain takeovers. The tool helps organizations prevent attackers from hijacking abandoned or misconfigured subdomains that can be leveraged for phishing attacks and credential theft.
Why it matters: Security teams managing cloud infrastructure need this capability because dangling domains are a common attack vector that can directly compromise customer data and brand trust.
- ransomware
Using Shodan Images to Hunt Down Ransomware Groups | Huntress
Shodan, a search engine for internet-connected devices, can be used to identify and map infrastructure operated by ransomware groups by searching for distinctive artifacts and configurations associated with their command and control servers and other operational systems.
Why it matters: Security teams and threat hunters can use Shodan to proactively locate ransomware group infrastructure, enabling faster takedowns, disruption of attacks, and intelligence gathering on threat actors targeting their organizations.
- cloud saas
Wiz enhances dynamic scanner to analyze and validate external exposure
Wiz has enhanced its dynamic scanner with external exposure analysis capabilities, allowing customers to identify and validate resources that are accessible from outside their cloud environments. The tool provides a perspective similar to an attacker's reconnaissance phase, helping organizations prioritize external-facing assets with less noise from false positives.
Why it matters: Cloud security teams using Wiz need to understand this new external scanning capability to improve their posture assessment and reduce alert fatigue when identifying internet-facing cloud resources.
- cloud saas
Use cases for Delegated Administrator for AWS Organizations
AWS has released a Delegated Administrator feature for AWS Organizations that allows organizations to delegate administrative tasks across their AWS infrastructure. The feature addresses common operational challenges in multi-account environments by enabling selective delegation of administrative permissions.
Why it matters: AWS customers managing multiple accounts need to understand delegated administrator capabilities to reduce security exposure from over-privileged central admin accounts and streamline governance across their organization.
- cloud saas
Introducing PEACH, a tenant isolation framework for cloud applications
A framework called PEACH has been introduced to help model and improve tenant isolation in cloud applications by reducing attack surface. The framework provides a structured approach for SaaS (Software as a Service) and PaaS (Platform as a Service) providers to strengthen isolation between customers' data and workloads.
Why it matters: Cloud platform operators and security teams should evaluate this framework to better isolate tenants and prevent cross-tenant data breaches or resource access, reducing a critical class of multi-tenant vulnerabilities.
- vulnerabilities
Overblown Claims of Vulnerabilities, Exploits, & Severity | Huntress
Huntress has raised concerns about the severity claims and exploitation allegations regarding ConnectWise Control vulnerabilities, stating that the threat level presented by a security researcher appears overstated. The company's analysis suggests a more measured risk assessment is warranted for these vulnerabilities.
Why it matters: ConnectWise Control users need accurate threat assessment to prioritize patching and remediation efforts, as exaggerated severity claims can misdirect security resources away from more critical risks.
- vulnerabilitiesCVE-2022-27518
CVE-2022-27518 exploited in the wild by APT5: everything you need to know
CVE-2022-27518 is an unauthenticated remote code execution vulnerability affecting Citrix ADC and Gateway that has been exploited in active attacks by the nation state actor APT5. Organizations running affected Citrix products face immediate risk and should prioritize patching.
Why it matters: Practitioners managing Citrix ADC or Gateway deployments must patch immediately, as this vulnerability is being actively exploited by a sophisticated adversary with capability to gain system-level access without authentication.
- cloud saas
Secret-based cloud supply-chain attacks: Case study and lessons for security teams
Researchers examined CI/CD pipeline misconfigurations in cloud environments that could enable supply-chain attacks. The study identifies common security gaps and provides remediation guidance for development teams to prevent compromise of software delivery pipelines.
Why it matters: DevOps and security teams need to audit CI/CD pipeline configurations immediately, as misconfigurations create direct paths for attackers to inject malicious code into deployed software affecting downstream users and customers.
- ransomware
The Value of Managed EDR for the Modern MSP | Huntress
Huntress highlights a case study where its managed endpoint detection and response (EDR) capability helped a partner organization, Clear Guidance Partners, respond to an active ransomware attack in real-time.
Why it matters: Managed service providers (MSPs) need to evaluate whether their EDR tooling provides sufficient visibility and response speed when ransomware incidents occur on customer endpoints.
- cloud saas
Introducing Azure Least Privilege: Enforce least privilege access for Azure environments
Wiz has announced an expansion of its Cloud Identity and Entitlement Management (CIEM) platform to support least privilege access enforcement in Azure environments. The enhancement enables organizations to better manage and restrict identity permissions across their Azure deployments.
Why it matters: Azure administrators and security teams need tools to identify and remediate excessive permissions that increase breach risk and lateral movement potential.
- cloud saas
Top Security Talks from AWS re:Invent 2022
AWS re:Invent 2022 featured hundreds of talks, with a selection of cloud security presentations now available online. The conference is AWS's largest annual event for customers and partners seeking to learn about cloud technologies and best practices.
Why it matters: Cloud security practitioners should review these talks to understand AWS security capabilities, emerging threats, and architectural guidance relevant to their infrastructure deployments.
- cloud saas
Uncover what is really deployed in your environment with the enhanced Wiz inventory
Wiz has enhanced its inventory capabilities to provide comprehensive detection of cloud services deployed across environments. The update aims to improve visibility and control over shadow IT, enabling organizations to identify unauthorized or unmanaged cloud usage.
Why it matters: Cloud infrastructure and security teams need accurate visibility into all deployed services to reduce attack surface and enforce compliance, making this relevant for organizations struggling with shadow IT discovery and management.
- regulatory
Navigating the road ahead for CISOs following the Uber verdict
Following a recent legal verdict involving Uber, industry experts discuss the implications and challenges for Chief Information Security Officers (CISOs) moving forward. The article outlines best practices that CISOs can implement to mitigate similar risks and legal exposures in their organizations.
Why it matters: CISOs need to understand the legal and governance lessons from high-profile cases to strengthen their security programs and reduce organizational liability.
- cloud saas
Wiz introduces agentless solution for detecting host and application misconfigurations
Wiz has announced an agentless solution that detects misconfigurations at the host and application layers, expanding its risk assessment capabilities. The tool helps organizations identify and remediate configuration issues to maintain their security and compliance posture.
Why it matters: Application and infrastructure teams need to quickly identify misconfigurations across their environments, as these are common attack vectors and compliance violations that require remediation.
- industry
Giving thanks for a more secure cloud
A company expresses gratitude to its customers during the holiday season, highlighting them as a key asset. The brief statement provides no substantive information about cloud security developments, vulnerabilities, or incidents.
Why it matters: Practitioners should skip this story; it contains no actionable security information or threat intelligence relevant to cloud infrastructure defense.
- threat intel
Defense Evasion: Defenders Strike Back! | Huntress
Huntress published guidance on monitoring and detecting defense evasion techniques as the final installment in a series focused on this adversarial tactic. The post offers detailed recommendations for defenders to identify when attackers attempt to circumvent security controls.
Why it matters: Security teams need practical detection strategies to identify defense evasion in their environments, as attackers routinely disable or bypass endpoint protections, logging, and monitoring tools to maintain persistence.
- cloud saas
Wiz at re:Invent 2022 (event recap)
Wiz and AWS discussed their ongoing partnership at the re:Invent 2022 conference in Las Vegas, focusing on securing AWS environments. The companies emphasized their collaborative approach to cloud security for customers.
Why it matters: Cloud security practitioners using AWS should understand how Wiz and AWS are working together to address security posture in their environments.
- vulnerabilities
Hell’s Keychain: Supply-chain vulnerability in IBM Cloud Databases for PostgreSQL allows potential unauthorized database access
A supply-chain vulnerability was discovered in IBM Cloud Databases for PostgreSQL involving hardcoded secrets in build artifacts. The flaw could potentially allow unauthorized access to database infrastructure, and IBM's security team detected the reconnaissance activity during the investigation.
Why it matters: Organizations using IBM Cloud Databases for PostgreSQL should review their deployments for exposure to hardcoded credentials and assess whether their database access controls have been compromised.
- cloud saas
Wiz integrates with AWS Security Hub to help you better manage your AWS security posture
Wiz has announced a new integration with AWS Security Hub that allows AWS customers to send security findings detected in their AWS resources directly to Security Hub. This integration streamlines the consolidation of security alerts from Wiz into AWS's native security management platform.
Why it matters: AWS customers using Wiz need to understand this integration option to reduce alert fragmentation and improve visibility into their security posture across cloud environments.
- cloud saas
Wiz integrates with Amazon Security Lake to improve cloud security through cloud security data sharing
Wiz has integrated with Amazon Security Lake to allow customers to consolidate security logs, conduct investigations, and analyze security metrics within a customer-owned data lake. This integration aims to improve visibility and analysis of cloud security data in a centralized location.
Why it matters: Cloud security teams using Wiz and Amazon Web Services (AWS) can now streamline log management and threat investigation workflows, reducing time to detect and respond to security issues in their cloud environments.
- cloud saas
Wiz and BigID expand partnership to extend visibility and control for enterprise data to prevent breaches
Wiz and BigID have expanded their partnership to provide enhanced visibility and control over enterprise data in cloud environments, aiming to strengthen data protection from discovery through enforcement. The integration combines Wiz's cloud security capabilities with BigID's data intelligence platform to help organizations identify and manage sensitive data across their cloud infrastructure.
Why it matters: Enterprise security teams need coordinated tools to discover and protect sensitive data in cloud environments; this partnership integration may reduce blind spots that lead to breaches.
- breaches incidents
Incident Response: A Choose Your Own Adventure Exercise
A news piece discusses incident response using a choose-your-own-adventure framework and describes ground rules and case studies from assisted incidents. The article presents incident response as a dynamic process with multiple decision points.
Why it matters: Practitioners should review this for tactical guidance on incident response decision-making and real-world case study examples that could inform their own IR procedures and choices.
- threat intel
Threat Advisory: Qakbot Activity Is Rising | Huntress
Qakbot malware activity is increasing, presenting a heightened threat to organizations. Security teams should review detection and response capabilities to mitigate potential infections.
Why it matters: Organizations using Qakbot-affected systems face elevated risk of malware infections and data theft; security practitioners should prioritize monitoring and updating defenses against this threat.
- research
Tradecraft, Shenanigans and Spice: hack_it 2022 Recap | Huntress
Huntress held hack_it 2022, an event featuring presentations on hacker tradecraft, cybersecurity techniques, and related topics. The article summarizes highlights and memorable moments from the conference.
Why it matters: Security practitioners should review conference takeaways to learn about current attack methods and defensive strategies discussed by the broader security community.
- regulatory
Do You Have a Security Hygiene Checklist in Place?
This article discusses the importance of establishing a security hygiene checklist as a foundational element for managed service providers (MSPs). It appears to provide guidance for cybersecurity practitioners, particularly those new to the field, on building a robust security program.
Why it matters: MSPs and security teams need practical hygiene processes to reduce exposure and prevent incidents; this resource offers baseline steps for organizations establishing or improving their security practices.
- cloud saas
Wiz and Google Cloud’s Security Command Center: Modern threat detection and response rooted in risk prioritization
Wiz has integrated its Security Graph with Google Cloud's Security Command Center to combine cloud risk context with advanced threat detection capabilities. The integration aims to improve threat prioritization and response efficiency by providing unified visibility across cloud environments.
Why it matters: Cloud security teams using Google Cloud and multi-cloud environments can reduce mean time to respond by correlating risk context with detected threats, enabling faster triage of high-impact incidents.
- ransomware
Creating macOS Ransomware | Huntress
Huntress has released a beta version of its macOS agent and is sharing details about the development work behind it. The agent represents the company's effort to extend its security platform to Apple's operating system.
Why it matters: macOS users and organizations running Apple infrastructure should evaluate whether this agent expands their endpoint visibility and threat detection capabilities.
- cloud saas
Wiz introduces VMware vSphere support to provide a unified hybrid cloud security platform
Wiz has added VMware vSphere integration to its cloud security platform, enabling coverage of both on-premises and cloud environments. The integration is agent-less, allowing unified security monitoring across hybrid infrastructure without requiring additional software deployment.
Why it matters: DevOps and security teams managing hybrid VMware and cloud environments can now consolidate visibility and threat detection across both domains without agent overhead, reducing operational complexity.
- industry
macOS Support Is Here! | Huntress
Huntress has announced general availability of its macOS agent for endpoint security monitoring. The announcement suggests the capability will help detect persistent threats on Apple devices.
Why it matters: Security teams managing heterogeneous environments now have a Huntress agent option for macOS endpoints, expanding their visibility and threat detection across platforms.
- vulnerabilities
ConnectWise/R1Soft RCE & Supply Chain Risks | Huntress
Huntress confirmed an authentication bypass and sensitive file disclosure vulnerability in the ZK Java framework used by ConnectWise R1Soft Server Backup Manager SE. The flaw allows unauthorized access and exposure of sensitive data in the backup management software. This represents a supply chain security risk affecting organizations relying on this widely used backup solution.
Why it matters: Organizations running R1Soft Server Backup Manager SE face potential compromise of their backup infrastructure and exposure of sensitive data; practitioners should immediately verify if they are affected and apply available mitigations or patches.
- industry
Huntress Myths and Misconceptions | Huntress
Huntress, a security vendor, published a post addressing misconceptions about its technology capabilities and offerings. The company aims to clarify inaccurate claims circulating about its current stack.
Why it matters: Security practitioners evaluating or using Huntress tools should review the clarifications to ensure their understanding of the vendor's actual capabilities and limitations aligns with reality.
- research
Cybersecurity Basics: A Chat With Syncro | Huntress
Huntress and Syncro conducted a webinar discussing cybersecurity fundamentals and best practices for managed service providers (MSPs) to help protect small and medium-sized businesses (SMBs) from threats. The session covered baseline security measures and defensive strategies relevant to MSP customers.
Why it matters: MSPs and SMBs should review foundational security practices to ensure their threat prevention posture aligns with current attack vectors and business risk.
- cloud saas
Wiz rapidly finds and removes risks across the container development lifecycle and entire cloud environment
Wiz announced new capabilities designed to identify and prioritize security risks across containers, Kubernetes, and cloud environments using deep context and visibility without requiring agents. The solution integrates container development lifecycle protection with broader cloud environment security scanning.
Why it matters: Cloud and container platform operators need visibility into risks across their infrastructure; this tool offers agent-free scanning to reduce operational overhead while securing containerized workloads.
- cloud saas
KubeCon + CloudNativeCon North America 2022: Our top 10 sessions to attend
KubeCon + CloudNativeCon North America 2022 featured multiple technical sessions. The article highlights recommended conference presentations for both in-person and virtual attendees.
Why it matters: Kubernetes practitioners benefit from curated session guidance to prioritize learning opportunities aligned with cloud native security and operations priorities at the conference.
- industry
Meet Wiz at KubeCon North America
Wiz, a cloud security vendor, is attending and sponsoring KubeCon North America for the first time and plans to share guidance on securing container and Kubernetes environments.
Why it matters: Platform and infrastructure teams evaluating container security solutions should note Wiz's presence and messaging at the event.
- industry
Making Cybersecurity Accessible for Women | Huntress
An article discussing barriers to women's participation and accessibility within the cybersecurity industry. The piece highlights a systemic issue that requires attention and action from the sector.
Why it matters: Organizations and recruitment teams should recognize that underrepresentation of women in cybersecurity limits talent pipelines, diversity of perspectives, and workforce capacity for critical security roles.
- cloud saas
Lateral movement risks in the cloud and how to prevent them – Part 1: the network layer (VPC)
This article introduces lateral movement risks within virtual private clouds (VPCs) and explores attacker tactics, techniques, and procedures. It provides best practices for security practitioners to secure cloud environments and mitigate lateral movement threats at the network layer.
Why it matters: Cloud practitioners need to understand VPC-level lateral movement risks to prevent attackers from moving between resources after initial compromise, which directly impacts your ability to contain and limit breach scope.
- industry
A Sneak Peek at hack_it 2022 | Huntress
Huntress is hosting hack_it 2022, a workshop focused on hacker tradecraft, scheduled for November 14-16. The event invites participants to register and attend.
Why it matters: Security practitioners should consider attending to deepen knowledge of adversary techniques and tactics that may inform defensive strategies and threat modeling.
- vulnerabilities
New 0-Day Vulnerabilities Found in Microsoft Exchange | Huntress
Huntress researchers have identified new zero-day vulnerabilities in Microsoft Exchange servers that leverage techniques similar to the earlier ProxyShell and ProxyLogon exploits. The vulnerabilities appear to target the same attack surface previously exploited in those campaigns.
Why it matters: Organizations running Microsoft Exchange are at immediate risk of compromise through these unpatched zero-day vulnerabilities, requiring urgent security review and monitoring of Exchange servers.
- vulnerabilities
Bug Bounties for the 99%
Bug bounty programs have become standard for large enterprises, but small and mid-sized businesses often lack the resources to establish similar vulnerability disclosure programs. This gap in access to coordinated security testing creates unequal security postures across organizations of different sizes.
Why it matters: SMBs and under-resourced organizations need practical alternatives to traditional bug bounties, as they remain vulnerable to uncoordinated disclosure and lack structured channels for security researchers to report findings responsibly.
- industry
Wiz Receives Morgan Stanley Innovation Award at 20th Innovation Summit
Wiz received recognition from Morgan Stanley at the firm's 20th Innovation Summit in the Cyber category, acknowledging its technology partnership with the financial institution. The award highlights Wiz's work in cybersecurity solutions for enterprise clients.
Why it matters: Security teams evaluating cloud security platforms should note that Wiz has demonstrated integration and trust with major financial institutions, though this award does not indicate new capabilities or threat-specific relevance.
- vulnerabilities
AttachMe: critical OCI vulnerability allows unauthorized access to customer cloud storage volumes
AttachMe was a critical vulnerability in Oracle Cloud Infrastructure (OCI) that allowed unauthorized access to and modification of other users' storage volumes, violating cloud isolation. Oracle patched the vulnerability within hours of disclosure, and no customer action was required.
Why it matters: OCI customers needed to verify their storage volumes were not accessed during the vulnerability window; the rapid patch and no-action requirement reduced immediate remediation burden, but the exposure duration and scope merit audit review.
- identity access
Back to Basics: Protecting Your Endpoints With Managed EDR and ITDR
Organizations need to prioritize endpoint protection beyond servers, with managed endpoint detection and response (EDR) and identity threat detection and response (ITDR) solutions playing a key role in securing workstations. Workstations are frequently overlooked but represent a significant attack surface that adversaries exploit to gain initial access to networks.
Why it matters: Security practitioners must ensure comprehensive endpoint coverage across workstations and servers to prevent attackers from establishing footholds, as neglecting workstation security creates an exploitable gap in defense.
- cloud saas
How Wiz and Torq Combine to Mitigate Existential Cloud Security Threats
Wiz and Torq have partnered to combine cloud detection and response (CDR) capabilities with security orchestration and automation. The integration enables organizations to analyze cloud security events and threats together within an automated incident response workflow.
Why it matters: Cloud security teams can reduce mean time to response for cloud incidents by connecting threat detection with automated remediation, lowering the window for attackers to exploit cloud misconfigurations and compromises.
- threat intel
Unraveling a Reverse Shell with Managed EDR | Huntress
Huntress documented a case study in which their Managed Endpoint Detection and Response (EDR) service identified and traced a PowerShell reverse shell attack. The investigation demonstrates how behavioral monitoring and alerting capabilities helped detect anomalous activity and enable incident response.
Why it matters: Security teams using or evaluating EDR solutions should understand how managed detection services identify reverse shell threats, a common post-compromise activity that requires rapid response to prevent lateral movement.
- industry
Evolving Endpoint Protection and the Next Iteration of Huntress
Huntress has introduced Process Insights, a new managed endpoint detection and response (EDR) capability added to its Managed Security Platform. The feature is designed to enhance detection of cyberattacks in real-time by providing deeper visibility into endpoint processes.
Why it matters: Security teams and managed service providers using Huntress can improve their ability to identify and respond to active threats on endpoints, reducing dwell time and potential breach impact.
- breaches incidents
How Progressive Computing Combated a Large-Scale Cyberattack | Huntress
Progressive Computing responded to and recovered from a large-scale cyberattack, documenting lessons learned from the incident. The company emerged with insights into their defensive capabilities and organizational resilience.
Why it matters: Managed service providers and their customers need to understand attack patterns and response strategies to strengthen their own incident handling procedures.
- threat intel
Gifting User Passwords to Adversaries With NPPSPY | Huntress
Security researchers at Huntress identified a method by which threat actors can harvest cleartext passwords using NPPSPY, a Notepad++ plugin framework. The investigation documents how this attack vector enables adversaries to capture user credentials in unencrypted form during normal system activity.
Why it matters: Development and security teams using Notepad++ should audit plugin installations and usage immediately, as this technique allows threat actors to steal passwords at scale from compromised systems.
- cloud saas
The cloud has an isolation problem: PostgreSQL vulnerabilities affect multiple cloud vendors
Wiz Research identified multiple related vulnerabilities in PostgreSQL managed database services offered by Google Cloud Platform, Microsoft Azure, and other cloud providers. These vulnerabilities affect the isolation between customer databases on shared infrastructure. The findings highlight a systematic issue in how cloud vendors implement database isolation in their Platform-as-a-Service offerings.
Why it matters: Organizations using managed PostgreSQL databases on GCP, Azure, or similar platforms face potential data exposure if isolation boundaries are weak; practitioners should contact their cloud provider to verify which vulnerabilities affect their deployments and request patches or mitigations.
- industry
$100M ARR in 18 months: Wiz becomes the fastest-growing software company ever
Wiz, a cloud security company, has achieved 100 million dollars in annual recurring revenue within 18 months of launch, making it reportedly the fastest-growing software company to reach that milestone. The company serves hundreds of major organizations and focuses on enabling secure cloud development.
Why it matters: Security practitioners should monitor Wiz's growth and product capabilities as a emerging leader in cloud security solutions that may impact tool selection and competitive positioning in their organization's security stack.
- industry
Wiz expands board and executive team with top security leaders from DocuSign, Aon, Meta and Okta
Wiz, a cloud security company, has added Emily Heath to its board of directors and expanded its executive team with experienced security leaders from major technology and professional services firms. The company is continuing to scale its leadership structure to support ongoing growth.
Why it matters: Practitioners evaluating Wiz or considering partnerships should note leadership changes that may affect product direction, support quality, and strategic priorities.
- industry
Meet new Wiz board member Emily Heath
Wiz, a cloud security vendor, has appointed Emily Heath, formerly Chief Trust and Security Officer at DocuSign, to its board of directors. The article highlights Heath's background and her decision to join the company as a board member.
Why it matters: Cloud security practitioners should note leadership changes at major vendors, as board appointments often signal strategic direction and can influence product roadmap priorities for organizations relying on these platforms.
- cloud saas
New customers, new clouds, new challenges
Wiz continues to attract new customers seeking cloud environment visibility and security management. The article highlights growing demand for cloud security solutions as organizations expand their cloud infrastructure deployments.
Why it matters: Security practitioners evaluating cloud security platforms should monitor Wiz's market positioning and capabilities, as customer adoption trends can inform tooling decisions for multi-cloud visibility and risk management.
- industry
Breaking new ground in the cloud
Wiz, a cloud security vendor, has achieved rapid growth, reaching $100 million annual recurring revenue within 18 months of reaching $1 million ARR. The company now serves hundreds of customers focused on cloud infrastructure protection and innovation acceleration.
Why it matters: Cloud infrastructure teams and security buyers should understand the market momentum around cloud-native security solutions and evaluate whether Wiz's approach aligns with their organization's cloud protection strategy.
- threat intel
Don’t Get Schooled: How to Catch a Phish | Huntress
The article discusses techniques for identifying phishing and smishing attacks by analyzing text messages to determine their authenticity and legitimacy.
Why it matters: Security practitioners and end users need to recognize phishing and smishing tactics to avoid credential theft and system compromise, which remain common attack vectors across organizations.
- industry
Join Wiz at Black Hat 2022
Wiz is sponsoring Black Hat 2022 in Las Vegas and will have a booth with research experts, product demonstrations, and networking opportunities available to attendees.
Why it matters: Security practitioners attending Black Hat can connect with Wiz staff to learn about cloud security research and product capabilities relevant to their organizations.
- cloud saas
Securing Azure middleware agents with new auto-patching capabilities
Wiz identified Azure customers with unpatched cloud middleware vulnerabilities and collaborated with Microsoft to develop an auto-patching capability for cloud middleware security issues. The new feature aims to reduce the window of exposure by automating patch deployment on the Azure platform.
Why it matters: Azure administrators need to understand this auto-patching capability to assess their middleware vulnerability posture and ensure timely remediation of critical exposures.
- vulnerabilitiesCVE-2022-29149
Revisiting OMI: Analysis of CVE-2022-29149, a privilege escalation vulnerability in Azure OMI
A privilege escalation vulnerability (CVE-2022-29149) affects Azure OMI (Open Management Infrastructure) cloud middleware software. Organizations using agents based on OMI must apply updates to remediate the issue.
Why it matters: Azure customers running OMI-based agents face privilege escalation risk and need to inventory and update affected deployments immediately.
- industry
Huntress’ Commitment to the Cybersecurity Community | Huntress
Huntress has published commentary outlining its commitment to supporting and advancing the cybersecurity community through various initiatives. The piece describes the company's approach to contributing to the field's development.
Why it matters: Organizations evaluating security vendors should review vendor statements about community engagement and support as part of vendor selection and partnership criteria.
- breaches incidents
Threat Advisory: Hackers Are Selling Access to MSPs | Huntress
A hacker is selling access to a managed service provider (MSP) that manages over 50 customer organizations across more than 1,000 servers. This represents a potential supply chain compromise affecting multiple downstream organizations simultaneously.
Why it matters: MSP customers and managed service providers need to immediately investigate whether they are affected, as compromised MSP access could enable attackers to breach dozens of organizations at scale.
- cloud saas
Wiz CDR and Amazon GuardDuty: Contextualize and prioritize threat detection
Wiz has announced integration capabilities with Amazon GuardDuty that use its Cloud Security Graph to help security teams contextualize and prioritize threat detections. The integration aims to simplify the investigation process by providing visibility into what occurred, where it occurred, and recommended response steps.
Why it matters: Cloud defenders using GuardDuty need faster context on alerts to reduce investigation time and prioritize high-risk threats in their AWS environments.
- industry
Meet the Wiz Research team at fwd:cloudsec
Wiz Research will host four technical sessions and a social event at the fwd:cloudsec conference in Boston. The announcement is a brief promotional notice for the company's participation in the event.
Why it matters: Practitioners interested in cloud security research and networking should note Wiz Research's sessions for current threat intelligence and industry insights.
- research
Practical Tips for Conducting Digital Forensics Investigations | Huntress
This article discusses practical approaches and strategies for conducting digital forensics investigations. It emphasizes that while such investigations can be time-consuming, there are efficient methods available to help investigators achieve their objectives.
Why it matters: Security practitioners and incident responders need effective forensics techniques to investigate breaches, preserve evidence, and support legal proceedings in a timely manner.
- industry
Behind the Scenes: Crushing Cybercriminals with MAV | Huntress
Huntress published a blog post providing additional technical analysis and threat insights related to their managed antivirus (MAV) capabilities, expanding on content from a prior webinar. The piece examines cybercriminal tactics and defenses from a threat analysis perspective.
Why it matters: Security practitioners implementing or evaluating managed antivirus solutions should review this analysis to understand current threat patterns and MAV effectiveness against active cybercriminal techniques.
- industry
Putting the Dee(Dee) in Defense: Huntress Acquires Curricula | Huntress
Huntress has acquired Curricula, a story-based security awareness training platform. The acquisition is part of Huntress's strategy to expand its security offerings to small and medium-sized businesses and enterprises.
Why it matters: Security teams expanding their training programs should evaluate how integrated awareness platforms affect their overall security posture and operational workflows.
- threat intel
Four Sneaky Attacker Evasion Techniques You Should Know About | Huntress
Huntress outlines four prominent evasion techniques used by attackers to avoid detection in compromised environments. The article provides guidance on defending against these methods to strengthen detection capabilities.
Why it matters: Security teams need awareness of current evasion tactics to tune detection rules and incident response procedures, reducing dwell time and preventing attackers from maintaining persistence.
- cloud saas
Wiz extends CNAPP leadership with protection for Alibaba Cloud
Wiz announced support for Alibaba Cloud in its cloud native application protection platform (CNAPP), extending its coverage across multiple cloud providers. This follows the recent launch of Oracle Cloud Infrastructure (OCI) integration, broadening the platform's multi-cloud capabilities.
Why it matters: Organizations using Alibaba Cloud now have additional CNAPP protection options from Wiz, relevant for security teams evaluating cloud workload coverage across their multi-cloud environments.
- vulnerabilities
Fighting Log4Shell with Huntress Managed EDR | Huntress
Huntress ThreatOps team deployed Managed EDR (Endpoint Detection and Response) and Managed Antivirus to detect and stop threat actors exploiting Log4Shell vulnerabilities. The case study demonstrates how these security tools identified and halted active exploitation attempts targeting the critical logging framework flaw.
Why it matters: Security practitioners managing endpoints need to understand EDR and antivirus effectiveness against Log4Shell exploitation, as this vulnerability remains actively exploited and requires robust detection and response capabilities.
Diversity in Security Awareness Training Content
A provider offers security awareness training content that incorporates diversity and inclusivity principles alongside threat identification and mitigation skills. The training is designed to help organizations improve their overall security posture through engaging, inclusive modules.
Why it matters: Security teams and training officers responsible for building effective awareness programs should evaluate whether inclusive training design correlates with better engagement and retention in their organization.
- industry
Scaling To Protect the 99% | Huntress
Huntress has announced platform changes and updates as part of its efforts to scale its security offerings. The article discusses the company's strategy to expand protection capabilities across its customer base.
Why it matters: Security practitioners evaluating endpoint detection and response (EDR) or managed security service provider (MSSP) solutions should review Huntress's platform updates to assess whether new features address their organization's detection and response needs.
- research
Triangulation | Huntress
Huntress published a blog post discussing triangulation as a methodological approach for security investigations and incident reporting. The piece explores how practitioners can use triangulation principles to strengthen their investigative work.
Why it matters: Security teams benefit from structured investigation methodologies that improve evidence quality and reporting accuracy during incident response.
- cloud saas
The cloud gray zone—secret agents installed by cloud service providers
Wiz Research presented findings at RSA Conference 2022 examining how cloud middleware deployed by cloud service providers can create security vulnerabilities in customer virtual machines. The research builds on previous OMIGOD findings, highlighting new attack vectors that emerge from the use of middleware across cloud infrastructures.
Why it matters: Cloud customers and practitioners need to understand how provider-installed middleware can become an attack surface; this affects workload security posture and requires review of installed agents and their permissions.
- cloud saas
A new vision for cloud security unites builders and defenders
A security vendor has introduced attack path analysis and cloud detection and response capabilities integrated with its security graph platform to enhance cloud security visibility and threat detection.
Why it matters: Cloud security teams evaluating detection and response tools should assess whether integrated attack path analysis improves their ability to prioritize and remediate cloud threats in production environments.
- cloud saas
Wiz launches cloud detection and response to help organizations quickly identify threats and limit breach exposure
Wiz announced new capabilities for its cloud security platform focused on detection and response features. The additions are designed to help organizations identify threats more quickly and reduce the scope of potential breaches.
Why it matters: Cloud security practitioners need to evaluate whether new detection and response capabilities can improve their incident response times and breach containment in cloud environments.
- regulatory
Recap: Navigating the NIST Cybersecurity Framework | Huntress
The article provides guidance on the NIST Cybersecurity Framework and its application to prioritizing security investments. It suggests that organizations using the framework can allocate resources more effectively to build strong defensive strategies.
Why it matters: Security practitioners benefit from understanding the NIST framework to justify budget decisions and align security spending with industry-standard best practices.
- cloud saas
Wiz now integrates with Oracle Cloud Infrastructure, bringing a graph-based cloud security approach to all major providers
Wiz, a cloud security company, has announced integration with Oracle Cloud Infrastructure (OCI), extending its graph-based security approach across all major cloud providers. The integration enables enterprises like Avery Dennison to maintain security visibility and governance across their OCI deployments alongside other cloud environments.
Why it matters: Cloud security practitioners using OCI now have access to Wiz's unified security posture management across multiple cloud providers, reducing fragmentation and improving their ability to identify cross-cloud risks.
- research
Out of Sight, Top of Mind | Huntress
A Huntress article discusses how security professionals can communicate the value and impact of cybersecurity investments when preventive measures are working effectively and threats are being blocked before they materialize.
Why it matters: Security leaders and practitioners need strategies to demonstrate ROI and justify budget allocations to stakeholders who may not see visible incidents when defenses are functioning properly.
- vulnerabilities
Rapid Response: Microsoft Office RCE - “Follina” MSDT Attack | Huntress
A new attack vector allows adversaries to compromise users through malicious Microsoft Office documents, leveraging MSDT (Microsoft Support Diagnostic Tool) in an attack called Follina. The vulnerability enables remote code execution when users open specially crafted Office files, potentially affecting widespread Office users globally.
Why it matters: Organizations using Microsoft Office are exposed to remote code execution through document-based attacks; security teams should prioritize patching and monitoring for this attack pattern immediately.
- industry
Connect with Wiz at our first-ever RSA Conference
Wiz is sponsoring RSA Conference 2022 in San Francisco and inviting attendees to visit their booth, attend speaking sessions, and participate in an evening event at SFMOMA.
Why it matters: Security practitioners attending RSA Conference can connect with Wiz's team for product demonstrations and networking opportunities.
- threat intel
The Mechanics of Defense Evasion | Huntress
Huntress published a blog post continuing their series on defense evasion tactics, providing practical, real-world examples of how attackers evade defensive measures in the field.
Why it matters: Security teams need to understand common evasion techniques deployed by adversaries to improve detection, hunting capabilities, and defensive strategies.
- cloud saas
How Huntress Protects SMBs | Huntress
Huntress describes its managed security platform as designed to enable small and medium-sized businesses (SMBs) to quickly and effectively respond to security threats. The platform aims to provide threat mitigation capabilities tailored to organizations with limited security resources.
Why it matters: SMB security practitioners should evaluate whether this platform addresses their detection and response gaps given constrained budgets and staffing.
- industry
Huntress API Is Now in Public Beta!
Huntress has released its API into public beta, allowing managed service providers (MSPs) and IT administrators to integrate monitoring, management, and maintenance capabilities into their cybersecurity workflows. The API enables customization of how security tools are deployed and operated across customer environments.
Why it matters: MSPs and IT administrators can now build custom integrations with Huntress tooling to streamline security operations and improve visibility across their managed infrastructure.
- cloud saas
Securing AWS Lambda function URLs
AWS Lambda function URLs can be exposed to security risks if misconfigured, allowing unauthorized access to serverless functions. Proper configuration and access controls are essential to prevent unintended exposure of Lambda endpoints.
Why it matters: Practitioners managing AWS Lambda deployments need to review function URL settings to ensure they enforce appropriate authentication and authorization, as misconfiguration could allow attackers to invoke functions or access sensitive data.
- threat intel
Evicting the Adversary | Huntress
Huntress published guidance on detecting and stopping adversary lateral movement across machines within a network, along with steps to remove the threat. The blog provides practical techniques for threat hunting and incident response.
Why it matters: Security practitioners need actionable methods to detect, contain, and remediate active lateral movement before adversaries establish persistence or reach critical assets.
- ransomware
One Year Later | Huntress
Huntress reflects on lessons learned from the Colonial Pipeline ransomware attack one year after the incident occurred. The piece recaps key takeaways from how the breach unfolded and its aftermath.
Why it matters: Operators managing critical infrastructure and incident responders should understand the vulnerabilities and response gaps exposed by Colonial Pipeline to better defend their own environments and prepare for similar attacks.
- threat intel
What Is Defense Evasion? | Huntress
Huntress published an overview of defense evasion as an attack technique, explaining what it encompasses and its role in security threats. The article explores why practitioners should understand how attackers use evasion tactics to bypass security controls.
Why it matters: Security teams need to understand defense evasion techniques to detect and respond to attacks that bypass their existing monitoring and prevention tools.
- vulnerabilities
Wiz Research discovers "ExtraReplica"— a cross-account database vulnerability in Azure PostgreSQL
Wiz Research identified a chain of critical vulnerabilities in Azure Database for PostgreSQL Flexible Server that could allow cross-account database access. The vulnerability, termed ExtraReplica, demonstrates a significant security gap in how Azure manages database replicas across customer accounts. Organizations using this managed database service are potentially exposed to unauthorized data access from other Azure accounts.
Why it matters: Teams managing Azure PostgreSQL deployments need to assess their exposure immediately and check for vendor patches or workarounds, as this vulnerability enables attackers to access databases across different Azure accounts.
- threat intel
Bring Your Own Command & Control (BYOC2)
A malware sample has been discovered with no obfuscation, making its command and control infrastructure and functionality directly visible to security researchers. The sample demonstrates a "bring your own command and control" approach where attackers rely on infrastructure without protecting their malware code.
Why it matters: Security teams analyzing this sample can extract intelligence on command and control mechanisms and tactics without reverse engineering complexity, aiding threat detection and attribution.
- industry
How Huntress Can Complement—Not Complicate—Your Security Stack | Huntress
Huntress positions itself as a complementary security tool designed to work alongside existing security infrastructure rather than add complexity. The company emphasizes its approach to supporting managed service providers and small to mid-sized organizations in their security operations.
Why it matters: MSPs and organizations managing security stacks need to evaluate whether new tools integrate smoothly with existing workflows; Huntress's positioning suggests integration-first design that practitioners should assess against their current tooling.
- industry
Product Support the Huntress Way | Huntress
Huntress published an overview of how its Support team operates as part of its ThreatOps organization. The article explores the team structure and operational practices within this support function.
Why it matters: Organizations evaluating Huntress for threat detection and response should understand the vendor's support model and response capabilities.
- vulnerabilitiesCVE-2022-22963
Addressing the Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments
This article addresses two remote code execution (RCE) vulnerabilities affecting Spring Framework: Spring4Shell and CVE-2022-22963. The piece provides guidance on addressing these vulnerabilities specifically within cloud deployment environments.
Why it matters: Organizations running Spring applications in cloud environments must patch these RCE vulnerabilities immediately, as they allow unauthenticated attackers to execute arbitrary code and compromise entire systems.
- breaches incidents
What’s Your Backup Plan? | Huntress
Huntress partnered with Servosity, a backup and disaster recovery specialist, to share recommendations for World Backup Day. The article provides best practices and tips for implementing effective backup strategies.
Why it matters: Security practitioners need robust backup and disaster recovery plans to mitigate ransomware impact and ensure business continuity, making expert guidance on backup implementation a practical priority for operational resilience.
- research
A Day in the Life of a Security Researcher | Huntress
Huntress published a Q&A session offering insight into the daily work and responsibilities of security researchers. The article provides a behind-the-scenes perspective on research activities and professional practices within a threat research organization.
Why it matters: Security practitioners benefit from understanding researcher workflows and methodologies to better contextualize threat intelligence and vulnerability disclosures in their own operations.
- cloud saas
Hardening your cloud environment against LAPSUS$-like threat actors
This article provides guidance on securing cloud environments against threat actors similar to LAPSUS$, a group known for targeting cloud infrastructure and using social engineering to gain access. The recommendations focus on defensive measures and configuration best practices to reduce exposure to these attack methods.
Why it matters: Cloud infrastructure operators and security teams need to implement LAPSUS$-style attack defenses today, as this threat group targets cloud credentials, multi-factor authentication (MFA) weaknesses, and supply chain access to compromise high-value assets.
- research
A Day in the Life of a Threat Analyst | Huntress
This article follows a day in the work life of a ThreatOps analyst at Huntress, offering a behind-the-scenes look at the daily responsibilities and activities of a threat analyst role. The piece provides insight into the practical work of monitoring and responding to security threats in a real-world setting.
Why it matters: Security leaders and practitioners can learn about the actual workflow and priorities of threat analysis teams, which may inform hiring, team structure, and professional development decisions.
- research
What Is Endpoint Detection and Response? | Huntress
This is an educational article explaining endpoint detection and response (EDR) technology, its background, and key criteria for evaluating EDR solutions. The piece serves as a primer on EDR capabilities and their role in modern cybersecurity defenses.
Why it matters: Security practitioners evaluating detection and response tools should understand EDR fundamentals and selection criteria to choose solutions that align with their detection and incident response requirements.
- research
Ending the Culture of Silence in Cybersecurity | Huntress
The article discusses breaking organizational silence around cybersecurity issues and promoting open communication to improve security outcomes. It emphasizes cultural approaches to enhancing an organization's overall security posture through transparent dialogue.
Why it matters: Security practitioners should understand that fostering internal communication channels for threat reporting and vulnerability disclosure directly impacts incident detection speed and organizational resilience.
- industry
An Inside Look at Huntress’ Platform Vision and Mission | Huntress
Huntress published a blog post outlining its platform vision and mission, discussing its approach to building security products and its perspective on the current security market.
Why it matters: Security practitioners evaluating vendor platforms should review Huntress's strategic direction and product philosophy to assess alignment with their organization's security needs and tooling strategy.
- cloud saas
Wiz and ServiceNow VR: Prioritize and respond to cloud vulnerabilities faster
Wiz has integrated with ServiceNow Vulnerability Response to streamline cloud vulnerability management and improve risk prioritization in a unified workflow. The integration aims to reduce visibility gaps and accelerate response across cloud environments.
Why it matters: Cloud security teams using both platforms can consolidate vulnerability data and prioritization, reducing time spent on manual handoffs and lowering the risk of missed high-impact cloud vulnerabilities.
- threat intel
Targeted APT Activity: BABYSHARK Is Out for Blood | Huntress
Huntress researchers discovered targeted APT activity involving the BABYSHARK malware strain on a partner's system. The article discusses the malware's characteristics and attack methodology.
Why it matters: Organizations running Huntress monitoring need to understand BABYSHARK's tactics to identify and respond to targeted intrusions in their environments.
- regulatory
NERC CIP Cyber Security Awareness Program | Huntress
NERC CIP-004 R1 mandates a Cyber Security Awareness Program for NERC entities, with specific requirements that apply to Low Impact entities as well. The regulation establishes baseline expectations for security training and awareness across the bulk electric system industry.
Why it matters: Operators of bulk electric systems and NERC-registered entities must design and implement compliant awareness programs or face regulatory penalties, and must demonstrate program effectiveness during compliance audits.
- research
Hackers No Hashing | Huntress
Huntress research reveals that attackers are circumventing security tools by making minor modifications to default configurations. The findings suggest that preventive security measures may be less effective than assumed when attackers apply basic customization techniques.
Why it matters: Security practitioners need to understand that default tool settings may not stop determined attackers, requiring active tuning and monitoring to close gaps in their defensive posture.
- vulnerabilities
Detect and prioritize CISA Known Exploited Vulnerabilities in the cloud with Wiz
Wiz announced support for CISA's Known Exploited Vulnerabilities (KEV) catalog, enabling organizations to detect and prioritize actively exploited vulnerabilities in cloud environments. The Wiz Research team aggregates threat intelligence from multiple sources and independent research to map KEV findings.
Why it matters: Cloud practitioners need to identify and remediate CISA KEV entries in their environments as these represent vulnerabilities with confirmed active exploitation and should be prioritized over other patches.
- regulatory
Balancing the Scales of Cybersecurity and Insurance
The article examines the relationship between cybersecurity insurance and organizational security practices, exploring how insurance requirements and policies shape the tools and strategies companies deploy, and conversely, how security implementations influence insurance coverage terms and pricing.
Why it matters: Security practitioners need to understand insurance requirements and incentives that may mandate or encourage specific controls, as these affect budget allocation, tool selection, and risk management priorities.
- cloud saas
Wiz and RegScale: Cloud security compliance management at scale
Wiz and RegScale have partnered to integrate cloud security with compliance management capabilities, allowing organizations to address multiple compliance framework controls across their infrastructure. The integration aims to streamline compliance operations for enterprises managing security at scale.
Why it matters: Security teams managing compliance requirements across multiple frameworks need integrated tools to reduce manual overhead and risk of control gaps; this integration may reduce the time required to map security controls to compliance obligations.
- cloud saas
5 reasons endpoint security agents are not enough
This article examines limitations of endpoint security agents and advocates for supplementing them with agentless solutions to strengthen cloud environment security. The piece outlines five specific gaps in agent-based endpoint protection and explains how agentless approaches can address those deficiencies.
Why it matters: Security teams evaluating endpoint protection strategies need to understand both the constraints of agent-based tools and the complementary role that agentless solutions can play in reducing cloud security blind spots.
- government policy
Leaving the Silo: MSP Vendors Give Back | Huntress
Huntress has launched an initiative in partnership with the Dutch Institute for Vulnerability Disclosure (DIVD) to improve vulnerability disclosure practices. The program appears focused on breaking down information silos and encouraging collaboration among managed service providers (MSPs) and security vendors.
Why it matters: MSPs and their clients benefit from coordinated vulnerability disclosure standards that reduce response time and improve patching outcomes; practitioners should understand how this initiative affects their disclosure workflows and vendor relationships.
- threat intel
Threat Recap: Huntress Managed EDR Trial by Fire | Huntress
Huntress Managed EDR detected and helped respond to follow-on attacks targeting VMware Horizon servers in real time. The case study demonstrates how the platform identified and mitigated post-compromise activity on affected systems.
Why it matters: Security teams managing VMware Horizon environments should understand how EDR can detect lateral movement and secondary payloads after initial compromise, which is critical for limiting attacker dwell time.
- industry
A Journey Back to the World of MSP Security | Huntress
Dima Kumets has rejoined the managed service provider (MSP) security sector, taking on a Principal Product Manager role at Huntress. The article discusses his career trajectory and motivations for returning to MSP-focused security work.
Why it matters: MSP practitioners and Huntress customers should understand how product leadership changes may influence platform direction and feature priorities for their security tooling.
- threat intel
A Beginner’s Guide to Phishing Simulation Training for Employees | Huntress
Huntress has published a beginner's guide to phishing simulation training, covering how organizations can implement simulated phishing attacks to test employee awareness. The guide provides foundational knowledge for security practitioners looking to establish or improve phishing awareness programs within their organizations.
Why it matters: Security teams responsible for employee training and incident prevention should review this guidance to evaluate whether their phishing simulation program is effective and identifies high-risk users before real attacks occur.
- cloud saas
The top cloud security threats to be aware of in 2022
Wiz Research has identified the most pressing cloud security threats for 2022 as organizations continue migrating to cloud environments. The report provides guidance on protective measures for cloud infrastructure as attackers increasingly target cloud deployments.
Why it matters: Cloud practitioners need to understand evolving threats to their deployments in order to prioritize security controls and reduce exposure in cloud environments.
- threat intel
VMware Horizon Servers Actively Being Hit With Cobalt Strike | Huntress
Huntress has identified active attacks targeting VMware Horizon servers with Cobalt Strike malware. The attackers are leveraging the remote access capabilities of Horizon to deliver post-exploitation tools and maintain persistence.
Why it matters: Organizations running VMware Horizon should immediately review logs for Cobalt Strike activity and assess whether their Horizon infrastructure has been compromised, as successful exploitation enables attackers to move laterally and establish long-term access.
- ransomware
Ransomware Canaries: A 2022 Update | Huntress
Huntress has released an updated version of its Ransomware Canaries service. The update includes new features and improvements to the security tool for detecting ransomware threats.
Why it matters: Security teams using Huntress Ransomware Canaries need to understand the 2022 updates to ensure their detection capabilities remain current and effective against evolving ransomware tactics.
- industry
Huntress Donates $100,000 to DIVD Bug Bounty Program | Huntress
Huntress has donated $100,000 to the Dutch Institute for Vulnerability Disclosure (DIVD) bug bounty program. The contribution reflects Huntress's commitment to supporting the managed service provider (MSP) community's cybersecurity efforts through vulnerability research and disclosure initiatives.
Why it matters: MSPs and their clients benefit from accelerated vulnerability disclosure and research funded by vendor support, reducing exposure windows for known flaws.
- vulnerabilities
Towards a better cloud vulnerability response model
Cloud vulnerability responsibility is often unclear when new vulnerabilities are disclosed, with ambiguity around who should take action and in what sequence. This uncertainty can delay patching and increase exposure across shared cloud infrastructure models.
Why it matters: Cloud practitioners and infrastructure teams need clarity on responsibility boundaries to respond efficiently when vulnerabilities emerge, avoiding coordination failures that leave systems exposed.
- research
2021 in Review (And Other Horror Stories) | Huntress
This article provides a retrospective review of cybersecurity trends and significant events that occurred during 2021. It aims to help security professionals prepare for the challenges expected in the coming year based on lessons from the past year's incidents and patterns.
Why it matters: Security practitioners should review past-year trends and incidents to refine their threat models, prioritize defenses, and anticipate which attack vectors may persist or evolve in the new year.
- vulnerabilities
Log4Shell: Wrap all your Log4j fixes before the holidays
A security resource discusses the ongoing challenges of identifying and fixing Log4j vulnerabilities across infrastructure, recommending that organizations complete their remediation efforts before the holiday period. The article emphasizes the difficulty of discovering all affected Log4j libraries within complex environments.
Why it matters: Security teams responsible for patching and vulnerability management must locate and remediate Log4j instances across their infrastructure to reduce exposure to active exploitation risks.
- cloud saas
NotLegit: Azure App Service vulnerability exposed hundreds of source code repositories
Wiz Research Team identified a vulnerability in Azure App Service that exposed hundreds of source code repositories. The flaw, named NotLegit, allowed unauthorized access to sensitive code assets stored in the affected service. This exposure represents a significant risk to organizations relying on Azure App Service for application hosting and development.
Why it matters: Organizations using Azure App Service need to assess whether their source code repositories were exposed and should immediately validate access controls and audit recent activity; developers and security teams should review this vulnerability and apply available mitigations.
- vulnerabilities
Log4Shell 10 days later: Enterprises halfway through patching
Wiz and EY analyzed over 200 enterprise cloud environments and found that 93 percent are at risk from Log4Shell, with organizations having patched approximately 45 percent of vulnerable cloud resources by day 10 after the vulnerability became public. The data reveals a significant gap between vulnerability exposure and remediation pace in cloud environments.
Why it matters: Cloud infrastructure owners and security teams need to assess their own patching velocity against this benchmark and prioritize remaining Log4Shell instances, as the majority of enterprises are still exposed to active exploitation of this critical vulnerability.
- industry
Making the Switch to Huntress Managed Microsoft Defender| Huntress
Huntress has published case studies featuring partners United Systems and F1 Solutions discussing their experiences with Huntress Managed Microsoft Defender. The article highlights partner adoption and integration of the managed security offering.
Why it matters: Managed service providers and IT partners evaluating endpoint detection and response (EDR) solutions should review real-world deployment experiences from similar organizations to inform procurement and implementation decisions.
- vulnerabilities
Log4Shell Meltdown: How to protect your cloud from this critical RCE threat
A news article provides an overview of Log4Shell, a critical remote code execution (RCE) vulnerability, and offers guidance for security teams on protection and mitigation strategies for cloud environments.
Why it matters: Security teams managing cloud infrastructure should review their Log4j configurations and patch status, as Log4Shell remains exploitable in unpatched systems and poses immediate RCE risk.
- vulnerabilitiesCVE-2021-44228
Critical RCE Vulnerability Updates (log4j - CVE-2021-44228) | Huntress
Huntress released analysis of CVE-2021-44228, a critical remote code execution vulnerability in the Java logging library Log4j that enables unauthenticated attackers to execute arbitrary code on affected systems.
Why it matters: Organizations running Log4j-dependent applications face immediate compromise risk; practitioners should prioritize patching or implementing mitigations across their infrastructure today.
- cloud saas
Wiz magic shifts left
Wiz has introduced capabilities that enable customers to identify and remediate vulnerabilities and misconfigurations earlier in the software development pipeline, before code reaches production. This shift-left approach reduces security exposure and streamlines remediation workflows by catching issues at development time rather than post-deployment.
Why it matters: Development and security teams using Wiz can now integrate vulnerability detection into their CI/CD pipeline, reducing the window of exposure and enabling faster remediation before deployment.
- industry
The True Value of the Huntress SOC Team | Huntress
Huntress argues that while automation plays a role in security operations, human expertise remains essential for effective threat detection and analysis. The piece emphasizes that skilled security analysts provide value that automated systems alone cannot deliver.
Why it matters: SOC teams and security leaders need to understand the balance between automation and staffing when designing detection strategies, as purely automated approaches may miss threats requiring contextual judgment and investigation.
- cloud saas
Assess your cloud compliance posture in minutes
Wiz offers a cloud compliance assessment tool that enables organizations to evaluate their compliance status across different industry standards and business units quickly. The platform is designed to identify compliance gaps and weaknesses in cloud environments.
Why it matters: Cloud security teams need to regularly audit compliance posture against multiple standards; this tool accelerates that process to reduce exposure windows.
- cloud saas
Wiz integrates with the new Amazon Inspector for enhanced security insights, context, and accuracy
Wiz has joined Amazon as a launch partner for an updated version of Amazon Inspector, integrating the service's findings with Wiz insights to provide customers with contextually rich security intelligence. The partnership aims to deliver prioritized, actionable recommendations by combining both platforms' capabilities.
Why it matters: Cloud security practitioners using Wiz should evaluate this integration to understand how it improves vulnerability discovery, prioritization, and remediation workflow in their Amazon Web Services (AWS) environments.
- identity access
Is There a Right Way to Set Up Two-Factor Authentication? | Huntress
Huntress examines methods that attackers use to circumvent two-factor authentication (2FA) and provides guidance on proper implementation. The article explores common weaknesses in 2FA setups and recommendations for secure configuration.
Why it matters: Security practitioners need to understand 2FA bypass techniques and implementation pitfalls to protect their organizations against account compromise and credential-based attacks.
- breaches incidents
Investigating Unauthorized Access | Huntress
Huntress reported unauthorized access to its QA and product testing environment. The company conducted an investigation into the incident. No details were provided about the scope, duration, or impact of the unauthorized access.
Why it matters: Huntress customers and prospects need clarity on whether production systems, customer data, or credentials were exposed, as this affects trust in the security vendor's infrastructure.
- vulnerabilities
Security industry call to action: we need a cloud vulnerability database
The security industry is calling for the creation of a centralized database to track cloud-specific vulnerabilities, as existing vulnerability databases were designed for traditional on-premises infrastructure and do not adequately cover the unique risks introduced by cloud environments.
Why it matters: Cloud practitioners and security teams need clarity on which cloud configuration and architecture issues pose material risk; a standardized database would enable consistent vulnerability reporting and remediation across cloud deployments.
- vulnerabilities
ChaosDB explained: Azure's Cosmos DB vulnerability walkthrough
The Wiz Research Team discovered a vulnerability in Azure Cosmos DB, termed ChaosDB, that allowed unauthorized access to databases belonging to thousands of Microsoft Azure customers. The flaw provided complete, unrestricted access to affected database instances. The vulnerability was identified and disclosed by the research team.
Why it matters: Azure Cosmos DB users need to assess whether their instances were exposed during the vulnerability window and implement recommended mitigations, as the flaw affected thousands of customers.
- cloud saas
How we broke the cloud with two lines of code: the full story of ChaosDB
Wiz researchers presented findings about ChaosDB at BlackHat Europe 2021, a vulnerability in a managed cloud service that could be exploited with minimal code. The presentation covered the vulnerability's scope, its potential impact, and broader security implications for cloud services.
Why it matters: Organizations using affected managed cloud services need to understand the attack surface of their cloud deployments and verify patches are applied, as this vulnerability could enable unauthorized access.
- ransomware
How Ransomware Works and Why It's a Hacker Favorite | Huntress
Ransomware remains a profitable attack method in the current threat landscape. The article examines how ransomware operates and its appeal to threat actors as a revenue-generating criminal enterprise.
Why it matters: Organizations of all sizes are targets for ransomware attacks, making it critical for practitioners to understand attack mechanics, detection strategies, and response procedures to protect operations and data.
- research
Top Tips and Takeaways from hack_it 2021.2 | Huntress
Huntress hosted a security training event called hack_it 2021.2 that provided insights based on thinking like an attacker. The event shared tactics and lessons for security practitioners to improve their defensive posture.
Why it matters: Security teams benefit from understanding attacker perspectives and methodologies to strengthen their detection and response capabilities.
- vulnerabilities
Vulnerabilities & Info Disclosure in MSP Survey Software | Huntress
A security researcher identified an information disclosure vulnerability in survey software used by managed service providers (MSPs). The vulnerability was responsibly disclosed to the software vendor and has been remediated.
Why it matters: MSP practitioners and their clients should verify they are running the patched version to prevent exposure of survey data and customer information.
- industry
Evolving the Hunt: Host Isolation for Smarter Defense
Huntress has added a Host Isolation feature to its security platform. This capability allows defenders to quickly isolate compromised or suspect hosts from network connectivity as part of their incident response workflow.
Why it matters: Security teams using Huntress now have an additional containment tool to prevent lateral movement and limit attacker access during active incidents.
- vulnerabilities
Hackers Are Exploiting a Vulnerability in Billing Software | Huntress
Huntress researchers identified threat actors exploiting a blind SQL injection vulnerability in BillQuick Web Suite billing software. The vulnerability allows attackers to inject malicious SQL commands without immediate feedback, enabling unauthorized data access and system compromise. This represents an active threat against organizations using the affected software.
Why it matters: Organizations running BillQuick Web Suite face immediate risk of data theft and system compromise if the vulnerability remains unpatched, requiring urgent assessment and mitigation.
- industry
Celebrating Our Series C: Zero to $6 Billion in 18 Months
Wiz announced completion of its Series C funding round, achieving a $6 billion valuation within 18 months of operation. The company positions itself as a solution for organizations struggling to manage increasingly complex cloud environments.
Why it matters: Cloud security practitioners should monitor Wiz's growth and product developments as a well-funded player in cloud security tooling and threat detection.
- industry
New Faces and Features to Help You Evolve the Hunt | Huntress
Huntress announced platform updates including Managed Antivirus, Host Isolation capabilities, and 24/7 ThreatOps coverage. These additions expand the company's managed detection and response offerings for security teams.
Why it matters: Managed service providers and IT teams should evaluate whether these new capabilities improve their threat detection, response, and containment workflows, particularly if they rely on Huntress for endpoint protection.
- vulnerabilities
Protecting cloud environments from the new critical Apache HTTP Server vulnerability
A critical vulnerability affecting Apache HTTP Server has emerged, requiring protection measures for cloud environments. Organizations running this widely-deployed web server should evaluate their exposure and apply available mitigations or patches. The article discusses defensive strategies for cloud-hosted instances of Apache HTTP Server.
Why it matters: Cloud infrastructure operators and security teams need to identify Apache HTTP Server deployments in their environments and prioritize patching to prevent exploitation of this critical flaw.
- cloud saas
How to Protect Your Cloud Environment from Supply Chain Attacks
This article provides guidance on securing cloud environments against supply chain attacks. It addresses defensive strategies and best practices for organizations relying on cloud infrastructure and third-party dependencies.
Why it matters: Cloud practitioners and security teams need practical mitigation strategies to reduce the risk of downstream compromise through compromised suppliers, vendors, and software dependencies that could expose production environments and customer data.
- research
Top 4 Tips for Cybersecurity Awareness Month | Huntress
Huntress has published four recommended tips for Cybersecurity Awareness Month to improve personal cybersecurity hygiene and knowledge. The article appears to be general guidance for practitioners looking to enhance their security posture.
Why it matters: Security practitioners should review these tips to reinforce awareness training and identify relevant takeaways for their organizations during Cybersecurity Awareness Month.
- research
Free Training Tool for Unlocked Computers
Huntress has released a free training tool designed to educate employees about the risks of leaving computers unlocked. The tool gamifies security awareness to make the training more engaging for users.
Why it matters: Security practitioners should consider this resource for phishing and social engineering awareness programs, as it addresses a common physical security gap that can expose organizations to unauthorized access and data theft.
- research
Learn to Think Like a Hacker at hack_it 2021.2 | Huntress
Huntress is promoting an upcoming hack_it event designed to teach participants how attackers think and operate. The event aims to help security professionals better understand hacker techniques and methodologies.
Why it matters: Security practitioners should consider attending to build offensive security knowledge that improves their defensive capabilities and threat assessment skills.
- cloud saas
Agents are not enough: Why cloud security needs agentless deep scanning
The article discusses limitations of security agents for cloud protection and proposes agentless deep scanning as an alternative approach to cloud infrastructure security. It examines the trade-offs between agent-based and agentless methods for defending cloud environments.
Why it matters: Cloud security practitioners need to understand when agent-based solutions fall short and evaluate agentless scanning options to improve infrastructure visibility and threat detection coverage.
- vulnerabilities
The Top Four CVEs Attackers Exploit | Huntress
This article discusses the four most frequently exploited Common Vulnerabilities and Exposures (CVEs) and provides guidance on defensive strategies. The piece aims to help organizations understand which vulnerabilities pose the greatest risk from active attackers.
Why it matters: Security practitioners need to prioritize patching and monitoring the most actively exploited vulnerabilities to reduce their organization's exposure to current attack campaigns.
- cloud saas
OMIGOD: Critical Vulnerabilities in OMI Affecting Countless Azure Customers
Wiz Research discovered four critical vulnerabilities in OMI (Operations Management Infrastructure), a widely deployed but lesser-known agent used across a significant portion of Linux virtual machines in Azure. The vulnerabilities affect a large number of Azure customers relying on this software component. Remediation and patching efforts are needed to address the exposure.
Why it matters: Azure customers running Linux VMs with OMI need to assess their exposure and apply patches immediately, as the critical vulnerabilities could allow attackers to compromise affected infrastructure.
- cloud saas
“Secret” Agent Exposes Azure Customers To Unauthorized Code Execution
Wiz Research identified vulnerabilities in open source code that expose Azure customers to unauthorized code execution risks. The findings underscore supply chain security concerns for cloud computing users relying on third party dependencies.
Why it matters: Azure customers and their applications face potential compromise through open source supply chain attacks, requiring immediate review of dependencies and implementation of supply chain controls.
- industry
Wiz goes (even more) global
Wiz, a cloud security company, raised an additional $250 million in funding during the first half of 2021, bringing its total funding to $350 million. The capital injection from investors including Sequoia and Salesforce enabled the company to expand its headcount from 25 to 120 employees during that period.
Why it matters: Security practitioners should track Wiz's expansion as the company's increased resources and market presence may influence cloud security tool adoption, competitive positioning, and available solutions for cloud workload protection.
- research
Should We Be Playing Offense or Defense in Cybersecurity? | Huntress
This article explores the strategic debate between offensive and defensive approaches to cybersecurity, examining which methodology is most effective for IT professionals in combating threats. The piece presents arguments for both proactive offense and reactive defense as means to protect against attackers.
Why it matters: IT leaders and security teams must understand the relative merits and limitations of offensive versus defensive strategies to allocate resources and personnel effectively for their organization's threat posture.
- threat intel
Malware Deep Dive | Huntress
Huntress published a technical analysis of malware, providing step-by-step investigation and decoding of a malicious payload used to establish initial system access.
Why it matters: Security teams and incident responders should review this analysis to understand current attack techniques and improve detection and remediation strategies for similar intrusions.
- cloud saas
ChaosDB: How to discover your vulnerable Azure Cosmos DBs and protect them
Wiz Research discovered a critical vulnerability in Azure Cosmos DB that allows any Azure user to gain full administrative access to other customers' Cosmos DB instances without authorization. The flaw enables attackers to read, write, and delete data across affected databases. The vulnerability represents a severe tenant isolation failure affecting the multi-tenant service.
Why it matters: Organizations using Azure Cosmos DB face immediate data exposure and loss risks; practitioners should urgently audit their Cosmos DB configurations and contact Microsoft for remediation guidance.
- cloud saas
ChaosDB: How we hacked thousands of Azure customers’ databases
Wiz Research discovered a vulnerability in Azure Cosmos DB that could affect thousands of customers. The flaw was identified while the security firm was researching cloud attack surfaces for its cloud-native application protection platform. Details of the breach, termed ChaosDB, indicate a significant exposure in Microsoft's flagship database service.
Why it matters: Organizations using Azure Cosmos DB need immediate visibility into whether they were affected and should review Microsoft's remediation guidance and their own database access logs.
- vulnerabilities
ProxyShell vs. ProxyLogon: What's the Difference? | Huntress
ProxyShell and ProxyLogon are two separate vulnerabilities affecting Microsoft Exchange on-premises servers, occurring in August 2021 and March 2021 respectively. The article compares and contrasts these two exploit families to help security teams understand their distinct characteristics and impacts.
Why it matters: Exchange administrators and security teams need to distinguish between these vulnerabilities to ensure they have applied the correct patches and mitigations for their on-premises infrastructure.
- threat intel
Bullseye: A Story of a Targeted Cyberattack | Huntress
Huntress published a cyber threat analysis examining how attackers achieve persistence in targeted cyberattacks. The article focuses on the technical mechanisms and strategies adversaries use to maintain long-term access to compromised systems.
Why it matters: Security practitioners need to understand persistence techniques to detect and evict established attackers, as these methods directly impact dwell time and the scope of potential damage to their environments.
- vulnerabilities
Microsoft Exchange Servers Still Vulnerable to ProxyShell | Huntress
Attackers continue to scan for and exploit Microsoft Exchange servers affected by ProxyShell vulnerabilities, which were patched in early 2021 but remain present on unpatched systems. The ongoing attacks indicate that a significant number of organizations have not applied these critical patches despite the nearly three-year window since the fixes were released.
Why it matters: Organizations running unpatched Exchange servers face immediate risk of compromise and data theft; administrators should verify their Exchange versions are fully patched and monitor for scanning activity targeting these known vulnerabilities.
- threat intel
Snakes on a Domain: An Analysis of a Python Malware Loader | Huntress
Huntress researchers analyzed a Python-based malware loader and its associated remote access trojan (RAT) payload, documenting the threat chain and technical characteristics. The analysis provides insights into the delivery mechanism and capabilities of this Python-based attack toolkit.
Why it matters: Security teams monitoring for malware activity should understand Python-based loaders and RATs as they represent an evolving delivery method; threat hunters can use the technical details to detect similar implants in their environments.
- threat intel
A Brief Evolution of Hacker Tradecraft | Huntress
The article examines the historical evolution of hacker tradecraft and how cybercriminals have adapted their attack tactics over time. It provides insights into the changing methods and strategies employed by threat actors in the cybersecurity landscape.
Why it matters: Security practitioners should understand how attacker tradecraft evolves to anticipate emerging threats and refine defensive strategies accordingly.
- vulnerabilities
Is your organization leaking sensitive Dynamic DNS data? Here’s how to find out
Wiz researchers presented findings at Black Hat regarding a vulnerability in DNS hosting services that impacts millions of corporate endpoints. The vulnerability could lead to exposure of sensitive Dynamic DNS data across affected organizations.
Why it matters: Organizations using Dynamic DNS services need to assess whether they are affected by this vulnerability and take steps to identify and remediate any data leakage of sensitive DNS information.
- cloud saas
Black Hat 2021: How isolated is your AWS cloud environment?
Wiz Research identified three vulnerabilities in AWS services that permitted cross-account access, potentially allowing unauthorized reading or writing to other customers' accounts. The researchers discovered these issues while analyzing AWS services that support multi-account access to determine isolation gaps.
Why it matters: AWS customers face potential data exposure and unauthorized modification risks if these vulnerabilities are exploited; practitioners should verify patching status and review cross-account access policies.
- vulnerabilities
Black Hat 2021: DNS loophole makes nation-state level spying as easy as registering a domain
Wiz Research discovered a new class of vulnerabilities in dynamic DNS services that exposed sensitive data from millions of endpoints globally. The vulnerability allows attackers to access dynamic DNS records with relatively minimal effort, creating a widespread exposure across internet-connected systems.
Why it matters: Organizations using dynamic DNS services face immediate risk of reconnaissance and targeting by threat actors; practitioners should audit their DNS configurations and restrict access to dynamic DNS update mechanisms.
- breaches incidents
Lessons Learned During the Kaseya VSA Supply Chain Attack | Huntress
Huntress provides a retrospective analysis of the Kaseya VSA supply chain attack, examining key events and outcomes from the incident. The recap offers lessons learned for organizations seeking to understand and prevent similar supply chain compromises in the future.
Why it matters: MSP customers and IT teams using VSA or similar remote management tools need to understand supply chain attack mechanics and detection strategies to reduce exposure in their own environments.
- industry
The Age of Rapid-Response Managed Detection and Response | Huntress
Huntress partnered with Magna5 to discuss real-time prevention, detection, and response capabilities for managed detection and response (MDR) services. The partnership focuses on rapid-response approaches to threat management.
Why it matters: Security teams evaluating MDR providers should understand how real-time detection and response capabilities can reduce dwell time and minimize breach impact in their environment.
- threat intel
Why Persistence Is a Staple for Today’s Hackers | Huntress
This article discusses how hackers use persistence techniques to maintain access to compromised systems and environments over time. Persistence is a critical stage in the attacker lifecycle, allowing threat actors to retain control even after initial breach vectors are closed. Understanding these methods helps organizations defend against long-term unauthorized access.
Why it matters: Security practitioners need to understand persistence mechanisms to detect and remove established footholds, preventing attackers from maintaining long-term access to their infrastructure and networks.
- ransomware
The Hunt to Find Origins of Kaseya's VSA Mass Ransomware | Huntress
Security researchers from Huntress analyzed the Kaseya VSA supply chain attack, examining how attackers executed the compromise and discussing factors that constrained the overall impact of the incident. The analysis provides insights into the attack methodology and threat vectors leveraged in this widely-publicized ransomware campaign.
Why it matters: IT service providers and their customers using Kaseya VSA software need to understand the attack mechanics and containment factors to assess their own exposure and improve detection and response capabilities.
- ransomware
Experts Weigh in on the State of Email-Based Threats | Huntress
Cybersecurity experts John Hammond and Sébastien Goutal discuss the current landscape of email-based threats, including phishing, ransomware, and related attack vectors. The article presents their insights on the evolving threat environment delivered through email.
Why it matters: Security practitioners need to understand current phishing and ransomware tactics delivered via email, as these remain primary attack vectors affecting most organizations and require active defense prioritization.
- vulnerabilities
Critical Vuln.: PrintNightmare Exposes Windows Servers to RCE | Huntress
PrintNightmare is a critical remote code execution and local privilege escalation vulnerability affecting Windows servers. The vulnerability allows attackers to execute arbitrary code and escalate privileges on compromised systems.
Why it matters: Windows server administrators and security teams must patch immediately, as this critical RCE vulnerability can be exploited remotely to compromise systems and gain elevated access.
- industry
The 10 must-attend sessions at Black Hat 2021
Black Hat 2021 is featuring ten notable sessions across cybersecurity topics. The article identifies key talks that practitioners should prioritize attending at the conference.
Why it matters: Security professionals selecting which sessions to attend should review this list to identify talks most relevant to their current defensive priorities and technical interests.
- cloud saas
Reducing Cyber Risk and Liability with Managed Threat Detection | Huntress
This article discusses how managed detection and response (MDR) services can help organizations reduce cybersecurity risk and associated liability. The piece examines the role of MDR in lowering overall cyber exposure for enterprises.
Why it matters: Security practitioners should understand how MDR services address liability and risk reduction, particularly when evaluating whether to implement or recommend such solutions for their organizations.
- research
Creating a Better Why for Cyber Security Awareness Training | Huntress
This article discusses the value of cybersecurity awareness training as a risk reduction strategy for organizations. It emphasizes the importance of establishing clear motivations and rationales for implementing such training programs.
Why it matters: Security practitioners need effective awareness training to reduce human-caused incidents and credential compromise; understanding the business case helps secure stakeholder buy-in and budget for ongoing programs.
- threat intel
ThreatOps Analysis: Keyed Malware | Huntress
Huntress published a threat analysis examining a PowerShell command that delivers environmentally keyed malware. The analysis likely explores how the malware's execution is conditional on specific environmental factors present on target systems.
Why it matters: Security teams and incident responders should understand how environmental keying works to improve detection strategies and recognize when malware may bypass standard sandboxing or testing environments.
- industry
Salesforce Ventures, Blackstone, and Aglaé Join Team Wiz!
Wiz completed its Series B funding round with an additional $120 million investment from Salesforce Ventures and Blackstone, along with participation from Aglaé Ventures. The round was previously announced in March and has now closed with these additional backers joining the effort.
Why it matters: Security practitioners should monitor Wiz's product roadmap and capabilities as it continues to scale with significant institutional backing, particularly given its focus on cloud security solutions that may affect their infrastructure assessments.
- threat intel
How Are Hackers Sneaking Past Your Automated Systems? | Huntress
The article discusses how attackers evade automated security systems and highlights managed threat detection and response (MTDR) as a defensive approach. It addresses the ongoing challenge of adversaries developing techniques to bypass detection automation.
Why it matters: Security teams relying solely on automated tools face an increasing risk of missing sophisticated attacks; practitioners should evaluate whether their detection and response capabilities include human expertise to identify novel evasion techniques.
- ransomware
Discovering a Ransomware Remedy in the Wild | Huntress
Huntress ThreatOps discovered Raccine, a ransomware mitigation tool that operates by hooking into Image File Execution Options (IFEO) debuggers to interrupt ransomware processes. The finding represents an observation of this defense mechanism being deployed in real-world environments.
Why it matters: Security teams should understand Raccine as a potential defensive control in their environment and evaluate its effectiveness and compatibility with their incident response and malware defense strategies.
- threat intel
How a College Student Lost $10,000 to "The IRS" | Huntress
A college student fell victim to a phishing scam impersonating the Internal Revenue Service (IRS) and lost $10,000. The incident is documented as a case study from a security awareness consultant highlighting how the social engineering attack was executed.
Why it matters: Students and individuals are targeted by IRS impersonation phishing scams; practitioners should use this case to strengthen user awareness training and email security controls against identity-based threats.
- research
Endpoint Protection: Promises vs. Reality | Huntress
This article examines the capabilities and limitations of endpoint protection technologies, comparing antivirus (AV), next-generation antivirus (NGAV), and endpoint detection and response (EDR) solutions against their marketing claims. The analysis explores how well these tools actually deliver on their promised security outcomes.
Why it matters: Security teams evaluating endpoint protection solutions need to understand the real-world capabilities and gaps of available tools to make informed procurement and deployment decisions that align with actual threat coverage.
- industry
Understanding Your SMB Clients' Cybersecurity Needs
Small and medium-sized businesses require more sophisticated cybersecurity capabilities to protect themselves against evolving threats. Security practitioners can use advanced threat detection and response tools to help their SMB clients improve their security posture.
Why it matters: MSP and managed security service provider staff supporting SMB clients need to understand modern threat detection capabilities to properly advise customers on defense investments and incident response preparedness.
- ransomware
Cyber Security Insurance Perspective on Ransomware | Huntress
Cybersecurity insurance providers are adjusting their coverage and practices in response to evolving ransomware threats and claims. Organizations need to understand how these changes affect their insurance options and what steps they should take to maintain adequate coverage.
Why it matters: Insurance buyers and security teams need to understand how ransomware risk is being priced and excluded so they can both reduce exposure through controls and negotiate appropriate coverage limits.
- cloud saas
New 451 Research report analyzes Wiz and the cloud security market
A 451 Research report examines the cloud security market and analyzes Wiz's product strategy, technology, and competitive positioning. The report provides third-party perspective on the company and the broader cloud security sector.
Why it matters: Cloud security practitioners evaluating Wiz or competitive solutions should review the market analysis to inform technology selection and procurement decisions.
- government policy
7 Takeaways from the Executive Order on Improving Cybersecurity | Huntress
President Biden signed a 34-page Executive Order focused on strengthening national cybersecurity standards. The order establishes new requirements and directives for federal agencies and contractors. Key provisions address incident response, security standards, and technology modernization across government systems.
Why it matters: Federal contractors, agencies, and vendors must understand new cybersecurity mandates that may affect compliance requirements, procurement standards, and operational practices starting immediately.
- research
What’s the Real Cost of Cybersecurity for Your SMB Clients? | Huntress
This article discusses cybersecurity costs and protection strategies for small and medium-sized business clients, emphasizing the need for threat detection and response capabilities. It highlights the importance of evolving security approaches as threats become more sophisticated.
Why it matters: SMB-focused practitioners need to understand cost-benefit tradeoffs for threat detection tools and intelligence capabilities when budgeting security investments for their clients.
- industry
Huntress Series B: Our Next Chapter of Growth
Huntress announced a Series B funding round as part of its growth strategy. The company aims to expand its platform capabilities to enhance security protection for its customers.
Why it matters: MSPs and security teams relying on or evaluating Huntress should track the company's product roadmap and service expansions that may result from this funding.
- industry
Scale Your Security Operations with Confidence | Huntress
Huntress promotes security capabilities for managed service providers and small-to-medium businesses seeking to expand their operations. The vendor emphasizes threat detection and response functionality as a means to support business growth.
Why it matters: MSP and SMB operators evaluating security tools should assess whether enhanced threat detection and response capabilities align with their operational scaling goals and resource constraints.
- threat intel
Emerging Cybersecurity Trends That May Impact Your SMB Clients | Huntress
This article discusses emerging cybersecurity trends relevant to managed service providers (MSPs) and their small to medium-sized business (SMB) clients. The piece aims to prepare MSPs for evolving attack vectors, hacking techniques, and data breach threats.
Why it matters: MSPs and their SMB clients need visibility into emerging threats to prioritize defense strategies and allocate resources effectively against current attack patterns.
- threat intel
What Is a Persistent Foothold? | Huntress
This article defines persistent footholds in cybersecurity and explains why attackers prioritize establishing them. A persistent foothold is a technique allowing attackers to maintain long-term access to a compromised system, often enabling lateral movement and data exfiltration.
Why it matters: Security teams need to understand foothold establishment and detection to prevent attackers from maintaining access to networks and systems for extended periods.
- threat intel
How Hackers Exploit Windows Administrative Shares
Windows administrative shares are a built-in feature that attackers exploit to move laterally across networks and propagate malware after gaining initial access. Organizations often overlook these shares in their security hardening practices, creating a pathway for compromise spread.
Why it matters: System administrators and security teams need to understand and restrict administrative share access to prevent lateral movement and limit the blast radius of compromises.
- industry
Wiz becomes fastest growing security startup ever with new $1.7B valuation
Wiz, a cloud security company, has reached a $1.7 billion valuation and is recognized as the fastest growing security startup to reach this milestone. The company continues to expand its market presence in the cloud infrastructure protection space.
Why it matters: Security practitioners evaluating cloud security vendors should track Wiz's growth and product roadmap as a well-funded competitor in the cloud protection market.
- threat intel
Abusing Ngrok: Hackers at the End of the Tunnel | Huntress
Threat actors are leveraging ngrok, a tunneling service, to establish remote access to compromised networks. The abuse of legitimate tunneling tools by attackers highlights a common tactic that can evade traditional network monitoring.
Why it matters: Security teams and endpoint defenders need to monitor for ngrok traffic patterns and unauthorized tunneling services, as attackers use these legitimate tools to bypass firewall controls and establish persistent remote access.
- threat intel
Peeling Back the Layers of .NET Malware
A security analysis examines a .NET malware sample and reverses its obfuscation layers to determine its actual purpose and capabilities. The research traces through the malware's defensive techniques used by attackers to conceal their code.
Why it matters: Practitioners tracking .NET threats need to understand common obfuscation patterns and analysis techniques to identify malware intent during incident response and threat hunting.
- vulnerabilities
Rapid Response: Mass Exploitation of On-Prem Exchange Servers | Huntress
Microsoft Exchange Server on-premises vulnerabilities are being actively exploited in attacks. Organizations running Exchange Server are encountering real-world exploitation efforts targeting their infrastructure.
Why it matters: Practitioners managing on-premises Exchange deployments need to assess their exposure and apply available patches or mitigations immediately to prevent compromise.
- research
What Is Human-Powered Threat Hunting? | Huntress
Huntress published a blog post explaining threat hunting, contrasting manual human analysis with automated approaches, and providing an example of human-powered threat hunting methodology.
Why it matters: Security teams evaluating threat hunting capabilities should understand when manual investigation uncovers threats that automated tools miss, informing operational procedures and resource allocation.
- vulnerabilities
Zero-Day Vulnerabilities in Platforms Could Leave MSPs Exposed | Huntress
Huntress disclosed zero-day vulnerabilities in virtual event platforms commonly used by managed service providers (MSPs) and Fortune 500 companies. The disclosure includes analysis of potential supply chain attack vectors through these platforms. Organizations relying on these event platforms for business operations face direct exposure to exploitation.
Why it matters: MSPs and their enterprise customers need to assess their reliance on these virtual event platforms and coordinate patching or mitigation with their platform vendors to prevent supply chain compromise.
- research
Cybersecurity Education Is the Key to Outsmarting Hackers | Huntress
Cybersecurity education and training are presented as essential components for improving security outcomes against attackers. Continuous learning and skill development are highlighted as key strategies in the cybersecurity field.
Why it matters: Security teams and practitioners need to evaluate whether expanding internal training programs and upskilling initiatives align with their organization's risk posture and available resources.
- cloud saas
82% of companies unknowingly give 3rd parties access to all their cloud data
A majority of companies inadvertently grant third-party vendors overly broad permissions in cloud environments due to the complexity of identity access controls, creating risk of unintended data exposure. The issue stems from innocent-looking permission configurations that can provide access far beyond intended scope.
Why it matters: Security practitioners need to audit third-party cloud access permissions immediately, as most companies face undetected over-provisioning that could expose all organizational data to vendors.
- vulnerabilities
Recent Linux sudo vulnerability affects a major percent of cloud workloads
A Linux sudo vulnerability affects versions dating back to 2011 and potentially impacts approximately 90% of cloud workloads running Linux-based operating systems. The widespread use of sudo across Linux distributions means a large number of cloud infrastructure assets may be vulnerable to exploitation.
Why it matters: Cloud infrastructure teams need to identify and patch affected sudo versions across their Linux estate immediately, as the vulnerability affects a substantial portion of deployed cloud workloads and has a long historical footprint.
- breaches incidents
The SolarWinds Attack
The SolarWinds supply chain compromise, discovered in December 2020, involved attackers injecting malicious code into legitimate software updates from the IT management vendor SolarWinds, affecting thousands of organizations including U.S. government agencies. The attack demonstrated how trusted software distribution channels can be weaponized to achieve widespread access and persistence. This incident became a watershed moment for understanding supply chain risk and the need for enhanced software integrity controls.
Why it matters: Organizations using SolarWinds Orion and other products need to understand how supply chain compromises bypass traditional perimeter defenses; this attack affected critical infrastructure operators, federal agencies, and enterprises, making it relevant to any practitioner managing software inventory and vendor risk today.
- threat intel
Malware Under The Microscope: Manual Analysis
This article provides an overview of manual malware analysis techniques employed by threat researchers, covering static and dynamic analysis approaches, reverse engineering tools, and practical investigation methodologies used in real-world scenarios.
Why it matters: Security practitioners and analysts should understand these core techniques to independently investigate suspicious code, reduce reliance on automated tools, and effectively respond to targeted threats in their environments.
- industry
Redefining Beta | Huntress
Huntress describes its approach to beta releases as part of its strategy to rapidly develop and deploy security defense capabilities. The company emphasizes frequent releases to accelerate product development and improve security outcomes.
Why it matters: Security practitioners should monitor Huntress product announcements to evaluate whether early-stage features and releases meet their organization's stability and support requirements before adopting them in production environments.
- threat intel
Top Hacker Tradecraft That Caught Our Eye in 2020 | Huntress
A security firm reviews notable hacker tradecraft and techniques observed throughout 2020, highlighting innovative approaches used by attackers during the year. The article examines trends in attacker behavior and methodology that stood out to security researchers.
Why it matters: Security practitioners need to understand evolving attacker techniques and tradecraft to improve detection, response capabilities, and defensive strategies against sophisticated threat actors.
- regulatory
Annual Security Awareness Training is a Waste of Time | Huntress
Annual security awareness training delivered once per year is ineffective for building employee security practices. Continuous, ongoing security awareness programs are needed to maintain vigilance and adapt to evolving cyber threats.
Why it matters: Security leaders and training administrators need to assess whether annual training programs meet modern threat landscapes; practitioners should consider shifting to continuous awareness initiatives to reduce human-centered risk.
- breaches incidents
Supply Chain Exploitation of SolarWinds Orion Software | Huntress
SolarWinds' Orion platform was exploited as part of a coordinated attack to distribute malware through the software supply chain. The attack leveraged the trusted nature of the platform to reach multiple downstream victims. This represents a significant supply chain compromise affecting organizations that rely on the management software.
Why it matters: Organizations running SolarWinds Orion need to assess whether they were affected by this supply chain attack and take immediate steps to detect and remediate any compromised instances, as the attack reached customers through legitimate software updates.
- industry
Wiz comes out of stealth with $100M Series A funding to reinvent cloud security
Wiz, a cloud security company, has raised $100 million in Series A funding led by Index Ventures, Sequoia Capital, Insight Partners, and Cyberstarts. The funding marks the company's emergence from stealth mode as it pursues its mission in cloud security.
Why it matters: Practitioners should monitor Wiz as a new cloud security vendor entering the market, particularly if evaluating solutions for cloud infrastructure protection and visibility.
- industry
I Have a Lot to be Thankful for in 2020
Huntress CEO Kyle Hanslovan reflects on positive developments in 2020, expressing gratitude toward the managed service provider (MSP) community. The brief excerpt does not provide specific security-related incidents, vulnerabilities, or policy developments for detailed analysis.
Why it matters: MSP practitioners may find value in industry commentary on business trends affecting the channel, though this excerpt lacks concrete security findings or actionable guidance for immediate implementation.
- threat intel
Tried and True Hacker Technique: DOS Obfuscation | Huntress
Huntress researchers analyzed a malware sample that employed batch scripting obfuscation techniques and discovered it functioned as a launcher for TrickBot, a well-known banking trojan. The obfuscation method represents a established evasion tactic used by threat actors to conceal malicious payloads.
Why it matters: Organizations need to understand common obfuscation patterns used to deliver banking trojans like TrickBot; detection teams should review their scripts and batch file monitoring to catch similar launchers before payload execution.
- industry
Huntress Service: Partner Enablement | Huntress
Huntress has announced a new Partner Enablement service designed to help partners configure and sell Huntress cybersecurity tools. The service aims to support partners in implementing and marketing Huntress solutions to their customers.
Why it matters: Huntress partners and resellers need to understand this new enablement offering to effectively support their customer deployments and sales efforts.
- research
Cybersecurity Lessons We Learned from hack_it 2020 | Huntress
hack_it 2020 was a virtual security training event featuring interactive exercises, malware research, and analysis sessions. The event provided hands-on learning opportunities for cybersecurity practitioners covering technical and analytical topics.
Why it matters: Security teams benefit from understanding practical malware analysis techniques and defensive exercises that improve incident response readiness.
- threat intel
Phishing, Office 365 and the Commercialization of Cybercrime | Huntress
Cybercriminals are improving their technical capabilities and increasingly sharing their skills and tools through dark web marketplaces, making advanced attack techniques more accessible to lower-skilled actors.
Why it matters: Security teams must anticipate a broader base of threat actors capable of conducting sophisticated attacks, requiring expanded detection and response capabilities across phishing, credential theft, and post-compromise activities.
- threat intel
Hiding in Plain Sight: Part 2
A security research organization identified malware that operates through multiple abstraction layers, building on previous findings. The threat uses layered techniques to obscure its functionality and detection.
Why it matters: Security teams should understand obfuscation techniques and layered malware behavior to improve detection and incident response capabilities.
- industry
Evolving the Hunt: Removing Obstacles to Innovation
Huntress has announced a focus on advancing security innovation by removing operational obstacles that impede new approaches to threat detection and response. The company aims to balance threat management with creating space for security teams to develop and deploy novel solutions.
Why it matters: Security practitioners should assess whether Huntress tools and services can reduce friction in their incident response workflows and enable faster adoption of emerging detection methodologies.
- breaches incidents
The Impact of Data Breaches on Our Society | Huntress
Huntress examines how to quantify the overall societal impact of data breaches and discusses the role of cybersecurity awareness training in reducing breach-related risk.
Why it matters: Security practitioners need to understand breach impact assessment methodologies and recognize awareness training as a key mitigation control for their organizations.
- vulnerabilities
Validating the SolarWinds N-central 'Dumpster Diver' Vuln | Huntress
Huntress has validated a vulnerability in SolarWinds N-central that has been labeled the 'Dumpster Diver' vulnerability. The validation work involved testing and confirming the technical details of this flaw in the platform. SolarWinds N-central is a remote monitoring and management tool used by managed service providers and enterprises.
Why it matters: MSPs and enterprises running SolarWinds N-central should assess their exposure to this validated vulnerability and prepare patching strategies, as remote management tools are high-value targets for attackers.
- vulnerabilities
Validating the Bishop Fox Findings in ConnectWise Control | Huntress
Huntress has validated eight vulnerabilities in ConnectWise Control ranging from low to high severity, based on findings initially disclosed by Bishop Fox. The validation confirms the scope and nature of the security issues in the remote access tool.
Why it matters: ConnectWise Control users and managed service providers (MSPs) relying on this platform need to assess which vulnerabilities affect their deployments and prioritize patching based on severity ratings.
- threat intel
Assisted Remediation in Action | Huntress
Huntress provided assisted remediation services to help an MSP (managed service provider) partner contain and remediate an Emotet and TrickBot malware infection. The article describes a case study of how the platform's remediation capabilities were deployed in response to these threats.
Why it matters: MSPs and their clients need to understand how to efficiently respond to and remove banking trojan malware; this case demonstrates practical containment and remediation workflows that practitioners should evaluate for their own incident response processes.
- industry
Huntress Development Notes: Updating the Updater
Huntress has published development notes regarding updates to its agent updater component, specifically wyUpdate.exe. The brief article appears to be introductory content for a technical discussion about the Huntress Agent's update mechanism.
Why it matters: Security practitioners using Huntress Agent should monitor these development notes to understand changes to critical agent infrastructure and ensure their deployments remain current.
- vulnerabilities
Keeping up with BlueKeep
Remote Desktop Services (RDS) provides value to organizations by enabling remote work flexibility for employees and simplifying system management and updates for IT administrators. The technology reduces the need for employees to carry equipment and streamlines administrative overhead across large networks.
Why it matters: Organizations using RDS should understand both its operational benefits and security implications, particularly given historical vulnerabilities like BlueKeep that have exposed RDS implementations to remote exploitation.
- threat intel
Deep Dive: A LNK in the Chain
Huntress team released a deep dive analysis about a discovery related to LNK files, which are Windows shortcut files commonly used in attack chains. The blog post explores technical details and implications of this finding for security defenders.
Why it matters: Security practitioners should review this analysis to understand how LNK files may be exploited in attacks targeting their environments and what detection or mitigation strategies apply.
- industry
Incident Education: Sales Ammo for the IT Arsenal
A technical founder argues that cybersecurity education, rather than fear-based messaging, provides genuine value for security professionals and organizations building their defenses.
Why it matters: Security practitioners should understand how education-driven approaches differ from fear tactics when evaluating vendor claims and building internal security awareness programs.
- breaches incidents
Rapid Response: ASUS Live Update Attack (Operation ShadowHammer)
ASUS Live Update was compromised in a supply chain attack known as Operation ShadowHammer, affecting IT departments globally. The incident prompted coordinated response efforts from security organizations due to its scale and scope. This type of attack leverages trusted software update mechanisms to distribute malicious code to a broad user base.
Why it matters: IT departments and organizations using ASUS Live Update are directly exposed to compromise through a trusted update channel; practitioners should immediately verify their systems and implement detection and response measures for this supply chain attack.
- vulnerabilitiesCVE-2017-18362
CVE-2017-18362: SQL Injection in ManagedITSync Integration | Huntress
A SQL injection vulnerability, CVE-2017-18362, was identified in the ConnectWise ManagedITSync integration, which synchronizes data between ConnectWise Manage PSA and Kaseya VSA RMM platforms. The flaw was disclosed in late 2017 and could allow attackers to execute arbitrary SQL commands against affected systems.
Why it matters: MSPs and IT service providers using both ConnectWise and Kaseya with the ManagedITSync integration need to verify if they are running patched versions, as SQL injection could expose customer data or enable lateral movement within managed environments.
- threat intel
Failing to Revive AUTOEXEC.BAT on Windows 7 & 10
This article examines whether AUTOEXEC.BAT, a legacy MS-DOS startup file, executes on modern Windows operating systems including Windows 7 and 10. The piece appears to test the file's functionality and discuss registry-based persistence mechanisms as alternative methods for maintaining system access. The content relates to how attackers might establish and maintain persistence on contemporary systems.
Why it matters: Defenders and system administrators should understand legacy execution vectors and persistence mechanisms to detect abnormal execution patterns and registry modifications used by attackers to maintain access to endpoints.
- identity access
Distrusting Symantec Issued Certificates
Symantec issued certificates have become a subject of distrust in the security community due to historical issues with certificate issuance practices. Security platforms are updating their handling and validation of these certificates. This reflects ongoing efforts to improve certificate trust and validation mechanisms.
Why it matters: Organizations relying on Symantec certificates or using platforms that validate them need to understand updated trust policies and potential impacts on certificate chains and authentication workflows.
- threat intel
Attackers Abuse Trust with Indirection
Security researchers discuss how attackers use indirection and obfuscation techniques to evade heuristic-based detection systems, even as antivirus products have advanced beyond simple signature matching. The article highlights an ongoing arms race between malware developers and defensive security vendors seeking to identify malicious behaviors.
Why it matters: Security teams relying on behavioral detection and heuristics must understand that attackers continuously develop new evasion techniques, requiring ongoing tuning and updates to detection rules and threat intelligence.
- threat intel
Ask Huntress: Fake .XPS Invoice Leading to Credential Phishing
A phishing campaign is distributing fake invoices with .XPS file attachments to trick recipients into opening files that lead to credential theft. The attackers use standard payment request social engineering tactics to increase the likelihood of engagement.
Why it matters: Organizations using file-based email workflows are at risk from this low-tech but effective attack vector; practitioners should educate users to verify invoice authenticity through out-of-band channels and block or scrutinize .XPS attachments.
- threat intel
Potentially Unwanted Programs: It's Not Always Malware | Huntress
Potentially Unwanted Programs (PUPs) are applications that users often install inadvertently while downloading free software, manifesting as intrusive ads, pop-ups, and generically named applications. Unlike malware, PUPs operate in a gray area between legitimate and malicious software, typically bundled with other downloads rather than explicitly designed to cause harm. Security teams need to distinguish PUPs from true malware to properly allocate resources and set appropriate remediation priorities.
Why it matters: Security practitioners should understand PUP behavior and prevalence because they consume incident response capacity, generate user complaints, and can obscure detection of genuine threats, requiring clear classification policies to manage effectively.
- vulnerabilities
Deep Dive: Kaseya VSA Mining Payload
Huntress ThreatOps conducted a technical analysis of a vulnerability affecting Kaseya VSA, a product widely used by managed services providers. The team documented findings on the exploitation payload and attack mechanics observed during the incident.
Why it matters: Managed services providers using Kaseya VSA need to understand the technical details of this vulnerability and payload to assess their exposure, verify remediation, and prevent further compromise.
- research
Huntress Labs to Host Hands-On “Hacking Windows” Training | Huntress
Huntress Labs announced it will host hands-on training on Windows hacking at an upcoming IT Nation event, following recognition as Best Newcomer at the previous year's conference. The training session aims to provide practical skill-building for IT professionals and security practitioners.
Why it matters: IT security professionals and managed service providers should attend to build practical defensive skills and stay current with common Windows attack techniques used in real-world threats.
- threat intel
Abusing Trusted Applications with Nested Execution
A talk at DerbyCon 7.0 discussed techniques for evading persistence enumeration tools by abusing trusted applications through nested execution. The presentation covered evasion methods that leverage legitimate system applications, a topic gaining attention in the infosec community but lacking detailed analysis on the mechanics and discovery process for identifying suitable host applications.
Why it matters: Defenders and security teams need to understand how attackers abuse trusted applications to maintain persistence and evade detection tools, informing defensive strategies and monitoring capabilities.
- threat intel
MSP Moment | Huntress
Emotet malware has resurfaced with new self-propagation capabilities, adopting techniques similar to those used by WannaCry and Petya. The malware family is being leveraged as crimeware in recent campaigns.
Why it matters: Managed service providers and their customers face direct risk from Emotet's worm-like spread, which can rapidly move laterally across networks without user interaction, making detection and containment significantly more difficult.
- threat intel
Deep Dive: Squashing an MSSQL Attack
A case study examines tactics used by attackers to compromise a Microsoft SQL Server (MSSQL) database, disable antivirus protections, download malware, and establish persistence within a network. The incident was detected by security partner NTConnections using Huntress tools. The analysis provides details on the attackers' methodology for lateral movement and persistence.
Why it matters: Security teams managing MSSQL environments and using endpoint detection tools should understand these attack patterns to recognize and block similar database-targeting campaigns that lead to antivirus evasion and network persistence.
- threat intel
Redosdru — Encrypting DLL Payloads to Avoid On-Disk Signatures
Redosdru is a malware variant that encrypts its DLL payloads to evade on-disk signature detection. Huntress researchers analyzed its keylogging capabilities and detection methods. The analysis provides defenders with technical indicators and response strategies.
Why it matters: Security teams need to understand Redosdru's encryption techniques and behavioral patterns to improve detection and response for keylogger threats in their environments.
- ransomware
Security Awareness Training Will Prevent Ransomware | Huntress
Security awareness training is presented as an effective approach to preventing ransomware attacks within organizations. The article discusses how employee training can reduce an organization's exposure to ransomware threats.
Why it matters: Security leaders and IT practitioners should evaluate whether current awareness programs adequately address ransomware risks, as employee behavior remains a critical control in incident prevention.
- industry
Troubleshooting Procmon & Sysmon v3.32
Sysinternals utilities, including Procmon and Sysmon, are widely used by IT and security professionals for troubleshooting Windows systems, analyzing malware samples, and identifying security misconfigurations. The tools are described as foundational resources comparable to a comprehensive utility kit for diagnostic and security work.
Why it matters: Windows administrators and security teams rely on these tools for daily incident response and system analysis; understanding their capabilities and updates ensures effective malware analysis and misconfiguration detection.
- industry
Huntress Wins ConnectWise IT Nation Partner’s Choice Award!
Huntress received the ConnectWise IT Nation Partner's Choice Award, recognizing its Managed Detection and Response (MDR) service at the industry conference. The award reflects recognition from managed service providers (MSPs) attending the event.
Why it matters: MSPs and organizations evaluating MDR vendors should note this market validation, though practitioners should assess Huntress capabilities against their specific detection and response requirements independent of awards.
- threat intel
How do you protect computers from attackers if you’re not | Huntress
Traditional antivirus and firewall defenses have proven insufficient against modern attack techniques, allowing attackers to cause significant damage even when these preventative technologies are in place. The article suggests that organizations unfamiliar with hacking methods face particular challenges in protecting their computer systems.
Why it matters: Security practitioners need to understand the limitations of legacy defenses and implement layered, threat-informed security strategies beyond antivirus and firewalls to protect their organizations.
- vulnerabilities
How My StubHub Account Got Hacked | Huntress
Huntress has identified a significant vulnerability affecting StubHub accounts that could expose users to unauthorized access. The security firm highlights the risk to StubHub users and promotes its security awareness training as a mitigation approach.
Why it matters: StubHub users and anyone managing ticketing accounts need to understand the specific vulnerability details to assess their exposure and take protective action.