Guide: How to Know if your ScreenConnect Server is Hacked
You’ve probably seen it by now, but there was a major ConnectWise ScreenConnect vulnerability (CVE-2024-1708 and CVE-2024-1709) – which we’re calling “SlashAndGrab” – that’s been…
You’ve probably seen it by now, but there was a major ConnectWise ScreenConnect vulnerability (CVE-2024-1708 and CVE-2024-1709) – which we’re calling “SlashAndGrab” – that’s been…
The Attack On February 8, 2024, Huntress published the first Attacking MSSQL Servers blog post. On February 23, a Huntress SOC analyst observed similar activity…
In an era where cyber threats like SocGholish are becoming increasingly sophisticated, understanding and combating these attacks is crucial for digital safety. This post delves…
Huntress lives in the small- to medium-sized business (SMB) space, partnering with managed service providers (MSPs), and as a result, sees a wide spectrum of…
In this month’s Tradecraft Tuesday, our Developer Tech Lead Jamin Becker and Product Researcher Dave Kleinatland dove deep into the problem of Impossible Travel. Going…
In my last article, I gave an introduction to Apple’s Transparency, Consent, and Control (TCC) framework. The primary goal of TCC is to empower users…
Background As an MDR provider supporting over 2.7 million endpoints across an extremely diverse customer base, Huntress sees a great deal of both legitimate and…
Background Given a diverse customer base, Huntress sees a wide range of activity even when it comes to persistent threat actors. When such a threat…
Security awareness training (SAT) is needed now more than ever. Just look at the barrage of ransomware attacks debilitating healthcare. And it’s no longer just…
Cybercrimes are no longer reserved for the Fortune 500. It’s more than just major banks, national retailers, and hospital networks at risk. Hackers are now…
Background Huntress SOC analysts continue to see alerts indicating malicious activity on endpoints running MSSQL Server or MSSQL Express, either as stand-alone installations, or as…
So you found yourself responding to an alert about one of your employees downloading a malicious version of Advanced IP Scanner? This has become fairly…