2025-04-17 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In a highly interconnected world, remote monitoring and management (RMM) tools are critical to reducing cost and increasing efficiencies. However, these tools pose challenges and even significant risk if not properly managed.
P0
2025-04-16 07:02 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
P0
2025-04-16 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
App Allowlisting is a good preventative software tool, but it's not enough. Learn why a layered security approach with detection and response is crucial to protect against today's cyber threats.
P0
2025-04-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Varonis Threat Labs discovered a vulnerability in Azure SQL Server allowing privileged users to create malicious firewall rules that can delete Azure resources when triggered by admin actions. The exploit involves manipulating rule names via TSQL to inject destructive commands, potentially leading to large-scale data loss in affected Azure accounts.
P0
2025-04-14 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has observed in the wild exploitation against CVE-2025-30406, a weakness due to hardcoded cryptographic keys.
P25
2025-04-11 08:50 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
For modern CISOs, cyber risk management and reduction are nonstop challenges. But this blog offers exactly what you need to build a strategy that empowers you to manage and mitigate threats—cutting through the noise of an otherwise demanding role.
P0
2025-04-11 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
Fortinet a publié le 10 avril 2025 un billet de blogue [1] indiquant l'utilisation d'une technique de post-exploitation qui permet une atteinte à la confidentialité des données de l'ensemble du système des équipements Fortigate affectés. Cette technique repose sur l'utilisation d'un lien...
P0
2025-04-10 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover how a seemingly simple brute force attack led to the uncovering of a suspected ransomware-as-a-service operation. This ecosystem appears to be leveraged by initial access brokers, driving an illicit and complex network of cybercrime.
P15
2025-04-09 06:04 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
P0
2025-04-09 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors are now exploiting both endpoints and identities in the latest cyberattacks. Learn about the rise of identity-based threats and why a combined EDR and ITDR approach is crucial for your cybersecurity.
P0
2025-04-09 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A path traversal vulnerability in AWS SSM Agent's ValidatePluginId function allows attackers to create directories and execute scripts in unintended locations on the filesystem. This could lead to privilege escalation or other malicious activities, as files may be written to or executed from sensitive areas of the system with root privileges.
P10
2025-04-04 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress observed in-the-wild exploitation of CVE-2025-31161, an authentication bypass vulnerability in versions of CrushFTP and further post-exploitation leveraging MeshCentral and other malware.
P15
2025-04-04 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Poor credential hygiene and misconfigurations give hackers an easy way in. See real-world cyber hygiene failures, how attackers exploit them, and how Managed EDR stops them cold.
P0
2025-04-03 07:16 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Know exactly how cybercriminals are orchestrating attacks on Australia’s citizens and digital assets, and why are they a lucrative target?
P0
2025-04-03 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
**\[Mise à jour du 11 avril 2025\]** Le CERT-FR a connaissance d'une preuve de concept publique permettant de provoquer une exécution de code arbitraire à distance. **[Mise à jour du 04 avril 2025]** Le CERT-FR a connaissance d'une preuve de concept publique permettant de provoquer un arrêt du...
P0
2025-04-02 06:02 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Learn about technical details on the ransomware and Storage Software tool, how the criminals use the affiliate panel as well as information on the Hunters International ransomware group from its emergence to the end of the operation.
P15
2025-04-02 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors are enabling the built-in Windows Guest account to maintain persistence. Learn how they gain access and how to detect this activity.
P0
2025-04-01 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how and why Huntress uses ClickHouse for scalable EDR agent analytics, ensuring availability and stability for millions of endpoints while maintaining cost efficiency.
P0
2025-04-01 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An attacker with `run.services.update` and `iam.serviceAccounts.actAs` permissions but without explicit registry access could deploy new revisions of Cloud Run services that pulled private container images stored in the same GCP project. This was possible because Cloud Run uses a service agent with the necessary registry read permissions to retrieve these images, regardless of the caller’s access level. By updating a service revision and injecting malicious commands into the container's argumen…
P10
2025-03-31 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Doing nothing now can cost your business more than money. Learn why proactive cybersecurity steps keep your business resilient and save costs in the long term.
P0
2025-03-28 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how to lock down common endpoint vulnerabilities like weak passwords and unpatched software to secure your systems against threats like phishing and malware.
P0
2025-03-27 08:09 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Stripping down barriers of distance, language, and the unknown, Group-IB’s mission to fight cybercrime brings us to our latest frontier –Latin America. Join us as we uncover the region’s deceptive criminals and tactics.
P0
2025-03-26 09:03 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Scams like Classiscam automate fake websites to steal financial data, exploiting digitalization’s rise in developing countries, making fraud both effective and hard to detect. In this blog, we dissect the inner working of the scam and its prevalence in Central Asia.
P0
2025-03-26 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A publicly exposed GitHub token in CodeQL workflow artifacts could allow attackers to execute malicious code in repositories using CodeQL, potentially leading to source code exfiltration, secrets compromise, and supply chain attacks. The vulnerability stemmed from a debug artifact containing environment variables, which could be downloaded and exploited within a 1-2 second window.
P0
2025-03-25 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A bug in Entra ID restricted management administrative units allowed creating immutable users that couldn't be modified or disabled, even by Global Administrators. This could enable an attacker to protect a compromised account from containment. The issue was caused by a timing vulnerability when removing users from restricted AUs and required specific steps to remediate affected accounts.
P0
2025-03-24 12:47 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how hypothesis-driven threat hunting uncovered stealthy malware. Learn why having a dedicated in-house team or leveraging expert threat hunting services is crucial for modern cybersecurity.
P0
2025-03-24 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
When Celestial Stealer runs in the wild, it looks for Huntress’ own Jai Minton as a potential threat, and this shuts down the infostealer operation if his name is detected.
P20
2025-03-21 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS identified a security issue in the AWS CDK CLI versions 2.172.0-2.178.1 where temporary credentials from custom credential plugins could be printed to console output. This potentially exposes sensitive information to users with access to the console. The issue affects plugins that include an expiration property when returning temporary credentials.
P0
2025-03-20 09:09 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Following the arrest of the cybercriminal behind the aliases ALTDOS, DESORDEN, GHOSTR, and 0mid16B, Group-IB provides a deep dive into his activities, uncovering striking similarities and unmasking the cybercriminal that breached more than 90 instances of data leaks worldwide over the span of four years in operation.
P0
2025-03-14 16:03 UTC
Other
Black Lantern Security · Mark Gaddy · indexed 2026-09-07 17:30 UTC
The Aperio Eslide Manager application is vulnerable to reflected cross-site scripting (XSS), which primarily affects the Leica Web Viewer within the application.
P5