Huntress hits an inflection point
In my last blog, I wrote about Huntress crossing $250M ARR. That post was about the people who got us here: the teammates, partners, customers,…
In my last blog, I wrote about Huntress crossing $250M ARR. That post was about the people who got us here: the teammates, partners, customers,…
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. MalwareHunterTeam observed this unusual…
Hackers are using Unicode emoji characters to hide an Agent Tesla JScript dropper in a business email compromise campaign aimed at finance teams. The tactic…
A large-scale investigation has uncovered 768 publicly exposed AWS access keys that remain active and grant full administrative privileges to corporate cloud environments, posing a…
Adversa AI has disclosed an attack technique that it says can cause xAI’s Grok chatbot to send a user’s name, approximate location, subscription tier, and…
Microsoft on Thursday announced the rollout of 22 new security updates that resolve severe vulnerabilities across multiple products, including a critical Entra ID zero-day exploited…
U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog Pierluigi Paganini August 22, 2026 U.S. Cybersecurity and Infrastructure Security Agency…
We’re constantly building for the different goals of our customers. Some customers want to optimize for discovery, while others want to protect their content with…
Acknowledgments: Special thanks to Rich Mozeleski for his contributions to this investigation and writeup. Huntress has seen a notable influx in device code phishing attacks…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications…
A Chinese-speaking cybercrime group is using AI-assisted tools to turn vulnerable web servers into entry points. It shows how familiar flaws become more dangerous when…
A newly disclosed prompt-injection technique could turn a routine request to summarize a webpage in xAI’s Grok web chat into a silent data-exfiltration attack, potentially…