2026-05-06 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series Stackable Managed Switches (SG350X) firmware could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when parsing response data for a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an aff…
P5
2026-04-22 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A developer used OpenAI’s Codex to handle suspicious activity, leading to unexpected outcomes found by Huntress SOC analysts during an investigation.
P0
2026-04-17 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A Linux user recently tried to respond to potentially malicious behavior on their machine using OpenAI’s Codex coding agent, before installing the Huntress agent. What ensued shows the unexpected impacts of this AI use case on DFIR investigations.
P0
2026-04-16 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Francis deSouza · indexed 2026-08-15 18:55 UTC
Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulne…
P60
2026-03-23 18:03 UTC
Government
CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC
On 23 March 2026, Citrix published a security advisory addressing multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway. These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations. At the time of writing, there is no public evidence of active exploitation. It is strongly recommended updating affected gateways, prioritising internet-facing assets. It is also recommended to preserve evidence for further investigation.
P0
2026-03-18 07:04 UTC
Other
Red Hunt Labs · Sudhanshu Chauhan · indexed 2026-09-07 17:30 UTC
Prepared by: Sudhanshu Chauhan 🔗 (Director, RedHunt Labs) and Devang Solanki 🔗 (Security Researcher, RedHunt Labs) There is a loop in cybersecurity. A new technology enters the enterprise. Adoption moves faster than governance. Security teams hear about it during incident response instead of during planning. And the exposure window, that gap between deployment and visibility, gets exploited before anyone realizes it even existed. We saw it with open cloud storage buckets. We saw it with expos…
P15
2026-01-15 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
While investigating LDAP filters and attributes, I completely missed "SDFlags" in my Event 1644 logs. When I finally noticed it, the investigation led to nTSecurityDescriptor, attack path discovery, and a high-confidence detection signature.
P0
2026-01-13 06:39 UTC
Other
Red Hunt Labs · Lohit · indexed 2026-09-07 17:30 UTC
Modern payment integrations are fast, flexible, and increasingly complex. APIs talk to gateways, webhooks trigger state changes, third parties handle fraud, retries, refunds, and orchestration layers quietly sit in between. In most teams, the signal that things are “working” is simple: transactions go through. That signal is misleading. At RedHunt Labs, we found that the real-world payment pentests reveal the common mistake of treating PCI DSS as a finish line instead of a baseline. This blog r…
P0
2025-12-22 11:40 UTC
Other
Red Hunt Labs · Lohit · indexed 2026-09-07 17:30 UTC
Payment gateways are built to move money reliably. Attackers view them as systems built on trust, timing, and assumptions. A gateway that works consistently is not a sign of safety. It is a stable environment to study, probe, and eventually abuse. This blog examines payment gateways from an attacker’s perspective, grounded in real exploitation patterns and reinforced with direct insights from industry experts. These patterns are documented extensively in the RedHunt Labs Payment Gateway Integra…
P0
2025-12-09 17:00 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Liz Prucka, Hamzeh Zawawy, Rishika Hooda, Android Security and Privacy Team Last year, Google's Android Red Team partnered with Arm to conduct an in-depth security analysis of the Mali GPU, a component used in billions of Android devices worldwide. This collaboration was a significant step in proactively identifying and fixing vulnerabilities in the GPU software and firmware stack. While finding and fixing individual bugs is crucial, and progress continues on eliminating them entirely…
P0
2025-12-03 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress reports an uptick in threat actors abusing the Velociraptor open-source DFIR tool, linked to incidents involving WSUS exploitation, VS Code tunnels, and more.
P0
2025-11-24 16:27 UTC
Other
Red Hunt Labs · redhuntAdmin · indexed 2026-09-07 17:30 UTC
On 24th Nov 2025, our Internet-scale monitoring systems detected a sharp and anomalous spike in newly indexed Git commits matching highly uniform characteristics. The volume of commits containing the message “Add file” surged from a baseline average of approximately 200/day to more than 13,000 within a single hour. This deviation breached automated anomaly-detection thresholds and initiated an urgent investigation. Subsequent analysis confirmed the emergence of a new variant of the Shai-Hulud N…
P0
2025-11-20 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has seen an uptick in threat actors abusing the Velociraptor open-source DFIR tool in a range of attacks, including a recent incident involving WSUS exploitation.
P0
2025-10-28 09:06 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog details online investment scam campaigns, including fraudulent cryptocurrency, forex, and trading platforms, while offering a technical investigation guide for investigators, based on Group-IB’s technical investigation methodology. It outlines the social engineering tactics and victim manipulation models employed, describes the fraud actor structures behind these schemes, and highlights key infrastructure artifacts identified by Group-IB High-Tech Investigations analysts that can be l…
P0
2025-10-21 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
See how the Huntress Tactical Response team tackles security telemetry gaps. We share real-world techniques for working with missing logs, degraded telemetry, and cloud logging challenges to uncover critical insights and improve investigations.
P0
2025-09-29 05:58 UTC
Other
Red Hunt Labs · Hariharan M · indexed 2026-09-07 17:30 UTC
In the rapidly evolving digital marketplace, e-commerce brands have become prime targets for cybercriminals. Beyond traditional data breaches, these brands now face sophisticated scams that exploit their reputation, deceive consumers, and erode trust. Drawing from investigations conducted by RedHunt Labs’ threat intelligence team, this blog delves into some of the most prevalent scams targeting e-commerce platforms and highlights how a Digital Risk Protection (DRP) solution can help fortify you…
P0
2025-09-22 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn more about what it actually means to go up against hackers–and why creative, human-led investigations are essential for keeping your organization safe from modern threats.
P0
2025-05-06 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Across the larger cybersecurity community, an often-used adage is that “threat actors always change their tactics.” However, when we really start to look at and track incident data, we begin to see that while some changes may be necessitated based on infrastructures and other challenges the threat actor may encounter, there are times when tactics remain consistent across incidents. Recent investigations into exploitation activity for CVE-2025-31151 and CVE-2025-30406 show similar TTPs across di…
P5
2025-03-20 09:09 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Following the arrest of the cybercriminal behind the aliases ALTDOS, DESORDEN, GHOSTR, and 0mid16B, Group-IB provides a deep dive into his activities, uncovering striking similarities and unmasking the cybercriminal that breached more than 90 instances of data leaks worldwide over the span of four years in operation.
P0
2024-11-25 08:05 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
P0
2024-09-18 06:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Investigations into recent campaigns may suggest the reemergence of TeamTNT in 2023 to present day, since evaporating in 2022.
P0
2024-09-16 06:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB dark web investigations: To avoid prying eyes, find out how adversaries increasingly shift from the dark web to social media to execute attacks, leak credentials, share exploitable vulnerabilities, and more.
P0
2024-06-17 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
GCP administrators face challenges in managing HMAC keys within their organizations, lacking visibility into which user accounts have generated these keys and whether they are actively being used to access storage objects. Additionally, there's a lack of functionality to revoke keys associated with other users, restricting their ability to enforce security policies effectively. Similarly, GCP incident response teams rely on Cloud Logging to monitor Cloud Storage object access, but they lack spe…
P0
2024-05-13 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how you can streamline incident response with Huntress Managed EDR's Active Remediation. Sleep soundly while we thwart threats on your behalf.
P0
2024-05-03 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Ransomware is spreading like wildfire. Learn about its growing threat to healthcare, its impact on patient care, and how Huntress managed solutions can better protect your organization from cyberattacks.
P15
2024-02-29 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The publication of the first blog post led a Huntress SOC analyst to identify and escalate a second, similar incident. A deeper investigation into the activity made it clear that the Huntress SOC had obviated several Trigona ransomware attacks, protecting customers from the impact of a ransomware infection.
P15
2023-11-08 07:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Take a deep dive into the operations of one of the most active players in the Ransomware-as-a-Service market.
P15
2023-10-24 08:28 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Get a close look at details of the most notable cases faced by Group-IB’s Digital Forensics and Incident Response (DFIR) team
P0
2023-10-16 10:04 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Twas the night before Christmas, when out came the cry, a cyberattack is happening, so stop them, won’t you try?
P0
2023-09-18 07:28 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Gather valuable insights on how incident response can be a make-or-break factor in securing your business.
P0