#Huntress
13 stories taggedHuntress.

Criminals Are Hiding Malware Inside Trusted AI Tools Like Claude and ChatGPT
Attackers are abusing Claude Artifacts, shared ChatGPT links and sponsored search ads to slip malware past users who trust the branding.

A Zero-Day With a Perfect Danger Score Is Being Exploited in N-able's Remote Management Software
Three vulnerabilities in four days have left IT service providers scrambling to patch N-central, the tool they use to remotely manage their customers' computers. One flaw is already being used by attackers.

Hackers Are Hijacking Remote-Support Software to Spread Malware Across Whole Networks
A modified version of the popular IT tool ScreenConnect is being used in a self-spreading attack that starts with a fake tech-support call and ends with criminals inside your entire network.

Phishing crews hijacked a legitimate IT tool to take over more than 450 computers
Attackers pushed fake Adobe files that quietly enrolled victim PCs into Faronics Deploy, then used it to install ScreenConnect for hands-on remote control.

North Korean Spies Are Getting Hired as IT Workers. Here Is How to Spot Them.
Security firm Huntress investigated three separate cases in 2026 where North Korean government operatives had successfully applied for, and been hired into, real jobs at Western companies. The red flags they left behind are now a playbook for anyone doing the hiring.

Password Spraying Attacks Jump 155-Fold as Attackers Hunt for MFA Blind Spots
Huntress logged more than 81 million login attempts in a single two-week campaign, with attackers targeting old sign-in methods that skip multi-factor checks.

Akira gang reboots into Safe Mode to blind security tools, then fumbles the ransom
The hackers walked in through a SonicWall VPN with no second login step, but their own ransomware ran out of memory before it could lock a single file.

Cybercriminals Now Run Like Franchises. Law Enforcement Still Fights Like It's 2015.
At Black Hat 2026, a former White House cybersecurity adviser laid out why coordinated ransomware gangs and scam networks are winning, and what it would take to actually slow them down.

Hackers hid their attack tools inside an Oracle database itself
A rarely seen technique let intruders run commands, steal password data and browse files from within the database, after breaking in through a sloppy search box.

What Hackers Actually Do After They're Inside Your Network
A Huntress case study shows why cleaning up the malware is only half the job. If you don't find the front door, they walk back in.

Fake Claude installer promoted by Bing ads hits 29 organisations with SectopRAT
Attackers hid a phishing page on Anthropic's own domain, then bought Bing ads to send people to a booby-trapped 'Claude Desktop' download.

81 Million Login Attempts: A Massive Password Spray Attack Hit Microsoft 365 Users
Criminals hammered Microsoft accounts with automated login attempts for two weeks. At least 78 accounts were broken into, and some victims had multi-factor authentication switched on but not configured to cover the login route the attackers actually used.

Azure CLI Under Sustained IPv6 Password Spray; 78 Tenants Breached
Automated spray campaign from a single ASN burned through 81 million auth attempts in two weeks, hitting az login endpoints from an unusual IPv6 range.