Tag

#Huntress

13 stories taggedHuntress.

A split-screen view showing trusted application interfaces on one side morphing into malicious code structures on the other, with download progress indicators v
AI Security

Criminals Are Hiding Malware Inside Trusted AI Tools Like Claude and ChatGPT

Attackers are abusing Claude Artifacts, shared ChatGPT links and sponsored search ads to slip malware past users who trust the branding.

4 min read
An IT service provider's office with technicians at workstations displaying N-able N-central remote management software, critical alert banners visible across m
Vulnerabilities

A Zero-Day With a Perfect Danger Score Is Being Exploited in N-able's Remote Management Software

Three vulnerabilities in four days have left IT service providers scrambling to patch N-central, the tool they use to remotely manage their customers' computers. One flaw is already being used by attackers.

3 min read
A corporate network diagram projected on a screen with IT technician at desk, remote support software interface visible, malware infection paths shown spreading
Threat Intelligence

Hackers Are Hijacking Remote-Support Software to Spread Malware Across Whole Networks

A modified version of the popular IT tool ScreenConnect is being used in a self-spreading attack that starts with a fake tech-support call and ends with criminals inside your entire network.

3 min read
Multiple computer workstations in a network showing real-time system monitoring dashboards, with one screen displaying Adobe file icons being deployed across co
Threat Intelligence

Phishing crews hijacked a legitimate IT tool to take over more than 450 computers

Attackers pushed fake Adobe files that quietly enrolled victim PCs into Faronics Deploy, then used it to install ScreenConnect for hands-on remote control.

3 min read
A corporate hiring office or HR workspace with employment applications and background check documents displayed, with suspicious red flags and warning indicator
Threat Intelligence

North Korean Spies Are Getting Hired as IT Workers. Here Is How to Spot Them.

Security firm Huntress investigated three separate cases in 2026 where North Korean government operatives had successfully applied for, and been hired into, real jobs at Western companies. The red flags they left behind are now a playbook for anyone doing the hiring.

5 min read
A security operations center with massive wall displays showing login attempt metrics, graphs spiking dramatically upward, failed authentication patterns highli
Identity & Access

Password Spraying Attacks Jump 155-Fold as Attackers Hunt for MFA Blind Spots

Huntress logged more than 81 million login attempts in a single two-week campaign, with attackers targeting old sign-in methods that skip multi-factor checks.

3 min read
A network diagram on a screen showing compromised VPN access points and failed encryption processes, ransomware code partially displayed with error messages, re
Ransomware

Akira gang reboots into Safe Mode to blind security tools, then fumbles the ransom

The hackers walked in through a SonicWall VPN with no second login step, but their own ransomware ran out of memory before it could lock a single file.

4 min read
A conference hall stage at a cybersecurity event with a speaker at a podium addressing an audience, with a visual diagram behind them showing the franchise-like
Policy & Regulation

Cybercriminals Now Run Like Franchises. Law Enforcement Still Fights Like It's 2015.

At Black Hat 2026, a former White House cybersecurity adviser laid out why coordinated ransomware gangs and scam networks are winning, and what it would take to actually slow them down.

4 min read
A database administration interface showing SQL queries and command execution windows, with files and sensitive data visible in the background, illustrating how
Threat Intelligence

Hackers hid their attack tools inside an Oracle database itself

A rarely seen technique let intruders run commands, steal password data and browse files from within the database, after breaking in through a sloppy search box.

4 min read
A network diagram showing malware removal on the screen, but in the reflection of the monitor glass, an attacker's entry point remains open in the background sh
Threat Intelligence

What Hackers Actually Do After They're Inside Your Network

A Huntress case study shows why cleaning up the malware is only half the job. If you don't find the front door, they walk back in.

4 min read
A Bing search results page showing a sponsored ad for 'Claude Desktop' at the top, clicking through to a phishing page styled to look identical to Anthropic's o
Threat Intelligence

Fake Claude installer promoted by Bing ads hits 29 organisations with SectopRAT

Attackers hid a phishing page on Anthropic's own domain, then bought Bing ads to send people to a booby-trapped 'Claude Desktop' download.

4 min read
Illustration: a server rack's blinking status lights in a darkened data centre
Identity & Access

81 Million Login Attempts: A Massive Password Spray Attack Hit Microsoft 365 Users

Criminals hammered Microsoft accounts with automated login attempts for two weeks. At least 78 accounts were broken into, and some victims had multi-factor authentication switched on but not configured to cover the login route the attackers actually used.

3 min read
Illustration: a dense server rack aisle in a data center
Cloud Security

Azure CLI Under Sustained IPv6 Password Spray; 78 Tenants Breached

Automated spray campaign from a single ASN burned through 81 million auth attempts in two weeks, hitting az login endpoints from an unusual IPv6 range.

3 min read
© 2026 Threat Vectr