Device Code Phishing Keeps Evolving. Here’s What to Watch For
Acknowledgments: Special thanks to Rich Mozeleski for his contributions to this investigation and writeup. Huntress has seen a notable influx in device code phishing attacks…
Acknowledgments: Special thanks to Rich Mozeleski for his contributions to this investigation and writeup. Huntress has seen a notable influx in device code phishing attacks…
Acknowledgments: Special thanks to Aaron Deal, Chris Bisnett, Aaron Bennett, Sharon Martin, Dave Kleinatland, James Northey, Josh Kiriakoff, Kamal Bennoune, and Michael Tigges for their…
Suppose an employee gets an email about a “pay increase” meeting. The link looks routine enough, the page feels familiar, and they’re understandably excited. Unfortunately,…
Ask most IT and security leaders how their organization handles compliance, and you’ll get a confident answer. Audits are planned for, documentation is maintained, and…
Acknowledgments: Huntress wishes to acknowledge the contributions of Andrew Schwartz of the DE&TH team for his efforts in tracking remote monitoring and management (RMM) tool…
Acknowledgments: Special thanks to Lindsey O’Donnell-Welch for contributions to this investigation and write-up. Background On July 27, 2026 Huntress was alerted to credential theft activity…
Acknowledgments: Special thanks to Anna Pham, Bryan Masters, and Jai Minton for their contributions to this investigation, improvements to detection signals, and write-up. TL;DR: Huntress…
Security data is only useful if you can get to it when you need it. For most partners and customers, that means logging into the…
Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to…
= trending up from previous month= trending down from previous month = no change in rank from previous month *Denotes a tie Four fresh faces:…
Acknowledgments: Special thanks to Bryan Masters and Stuart Ashenbrenner for their contributions to this investigation and write–up. TL;DR: If you’re running Screen Sharing on macOS…
That’s the story we dug into on Episode 3 of _declassified, where John Hammond, Principal Security Researcher, sat down with Huntress CEO Kyle Hanslovan and…