home.social

#huntress — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #huntress, aggregated by home.social.

fetched live
  1. North Korean remote workers are broadening their job hunt beyond IT

    North Korean (DPRK) remote workers are expanding their job searches beyond IT, according to Huntress. Recent investigations have…
    #EuropeSays #Korea #KR #NorthKorea #Cyberespionage #FinancialIndustry #Healthcare #Huntress #remoteworking
    europesays.com/korea/135507/

  2. Samira Aurum:

    "O mercado é um labirinto, mas meu faro nunca me engana. Estou sempre um passo à frente."

    "The market is a labyrinth, but my scent never deceives me. I am always one step ahead."

    lovescape.com/profile/muri...

    #SamiraAurum #Pantherian #GeneticExperiment #Huntress #NightMarketVibes

  3. I joined @huntress because I want to do my part to save the world. That's not bragging or hyperbole. I believe that, every day, in law offices and dental clinics and at construction companies and coffee shops, we're watching your back so you can concentrate on those things that you excel at, and make life better for those around you.

    As an industry we're now seeing that cybersecurity has done such a good job at this, as a whole, the attackers are now targeting us - sometimes first - and trying to throw us off our game.

    Never gonna happen. The solution to this is for the #infosec space to unify and stay strong. Not unify like "get acquired' but "get aligned" and realize that, even as competitors, we're all pressing toward the same goal: messing up a cybercriminal's day.

    I said it last summer, and it was as true this morning as it was then: The Infosec industry is a critical infrastructure, and it both needs and deserves its own #ISAC. I will work with anyone who shares that goal to help me make that a reality.

    So with all that, I wanted to share that I worked with some of my colleagues on this rapid response the past day and a half, and I'm pretty proud of the result.

    huntress.com/blog/klue-breach-

    #Klue #breach #DataBreach #RapidResponse #IR #DFIR #tokens #compromise #integration #SalesForce #SFDC #Gong #huntress

  4. I joined @huntress because I want to do my part to save the world. That's not bragging or hyperbole. I believe that, every day, in law offices and dental clinics and at construction companies and coffee shops, we're watching your back so you can concentrate on those things that you excel at, and make life better for those around you.

    As an industry we're now seeing that cybersecurity has done such a good job at this, as a whole, the attackers are now targeting us - sometimes first - and trying to throw us off our game.

    Never gonna happen. The solution to this is for the #infosec space to unify and stay strong. Not unify like "get acquired' but "get aligned" and realize that, even as competitors, we're all pressing toward the same goal: messing up a cybercriminal's day.

    I said it last summer, and it was as true this morning as it was then: The Infosec industry is a critical infrastructure, and it both needs and deserves its own #ISAC. I will work with anyone who shares that goal to help me make that a reality.

    So with all that, I wanted to share that I worked with some of my colleagues on this rapid response the past day and a half, and I'm pretty proud of the result.

    huntress.com/blog/klue-breach-

    #Klue #breach #DataBreach #RapidResponse #IR #DFIR #tokens #compromise #integration #SalesForce #SFDC #Gong #huntress

  5. I joined @huntress because I want to do my part to save the world. That's not bragging or hyperbole. I believe that, every day, in law offices and dental clinics and at construction companies and coffee shops, we're watching your back so you can concentrate on those things that you excel at, and make life better for those around you.

    As an industry we're now seeing that cybersecurity has done such a good job at this, as a whole, the attackers are now targeting us - sometimes first - and trying to throw us off our game.

    Never gonna happen. The solution to this is for the #infosec space to unify and stay strong. Not unify like "get acquired' but "get aligned" and realize that, even as competitors, we're all pressing toward the same goal: messing up a cybercriminal's day.

    I said it last summer, and it was as true this morning as it was then: The Infosec industry is a critical infrastructure, and it both needs and deserves its own #ISAC. I will work with anyone who shares that goal to help me make that a reality.

    So with all that, I wanted to share that I worked with some of my colleagues on this rapid response the past day and a half, and I'm pretty proud of the result.

    huntress.com/blog/klue-breach-

    #Klue #breach #DataBreach #RapidResponse #IR #DFIR #tokens #compromise #integration #SalesForce #SFDC #Gong #huntress

  6. I joined @huntress because I want to do my part to save the world. That's not bragging or hyperbole. I believe that, every day, in law offices and dental clinics and at construction companies and coffee shops, we're watching your back so you can concentrate on those things that you excel at, and make life better for those around you.

    As an industry we're now seeing that cybersecurity has done such a good job at this, as a whole, the attackers are now targeting us - sometimes first - and trying to throw us off our game.

    Never gonna happen. The solution to this is for the #infosec space to unify and stay strong. Not unify like "get acquired' but "get aligned" and realize that, even as competitors, we're all pressing toward the same goal: messing up a cybercriminal's day.

    I said it last summer, and it was as true this morning as it was then: The Infosec industry is a critical infrastructure, and it both needs and deserves its own #ISAC. I will work with anyone who shares that goal to help me make that a reality.

    So with all that, I wanted to share that I worked with some of my colleagues on this rapid response the past day and a half, and I'm pretty proud of the result.

    huntress.com/blog/klue-breach-

    #Klue #breach #DataBreach #RapidResponse #IR #DFIR #tokens #compromise #integration #SalesForce #SFDC #Gong #huntress

  7. I joined @huntress because I want to do my part to save the world. That's not bragging or hyperbole. I believe that, every day, in law offices and dental clinics and at construction companies and coffee shops, we're watching your back so you can concentrate on those things that you excel at, and make life better for those around you.

    As an industry we're now seeing that cybersecurity has done such a good job at this, as a whole, the attackers are now targeting us - sometimes first - and trying to throw us off our game.

    Never gonna happen. The solution to this is for the #infosec space to unify and stay strong. Not unify like "get acquired' but "get aligned" and realize that, even as competitors, we're all pressing toward the same goal: messing up a cybercriminal's day.

    I said it last summer, and it was as true this morning as it was then: The Infosec industry is a critical infrastructure, and it both needs and deserves its own #ISAC. I will work with anyone who shares that goal to help me make that a reality.

    So with all that, I wanted to share that I worked with some of my colleagues on this rapid response the past day and a half, and I'm pretty proud of the result.

    huntress.com/blog/klue-breach-

    #Klue #breach #DataBreach #RapidResponse #IR #DFIR #tokens #compromise #integration #SalesForce #SFDC #Gong #huntress

  8. Tonight in PoE2, my custom build is leaving the safety of the early zone and venturing into the unforgiving deserts of Deshar in Act 2.

    The plan is to see how the spirit-and-undead minion engine holds up against the fast, hard-hitting desert packs, and to start locking down my core mid-game passives. Come hang out for the campaign progression and chat about the build!

    Watch the desert push live: twitch.tv/cheshire_ge

    #PoE2 #PathOfExile #Twitch #SmallStreamer #Gaming #Huntress #BuildProgress

  9. Tonight in PoE2, my custom build is leaving the safety of the early zone and venturing into the unforgiving deserts of Deshar in Act 2.

    The plan is to see how the spirit-and-undead minion engine holds up against the fast, hard-hitting desert packs, and to start locking down my core mid-game passives. Come hang out for the campaign progression and chat about the build!

    Watch the desert push live: twitch.tv/cheshire_ge

    #PoE2 #PathOfExile #Twitch #SmallStreamer #Gaming #Huntress #BuildProgress

  10. Tonight in PoE2, my custom build is leaving the safety of the early zone and venturing into the unforgiving deserts of Deshar in Act 2.

    The plan is to see how the spirit-and-undead minion engine holds up against the fast, hard-hitting desert packs, and to start locking down my core mid-game passives. Come hang out for the campaign progression and chat about the build!

    Watch the desert push live: twitch.tv/cheshire_ge

    #PoE2 #PathOfExile #Twitch #SmallStreamer #Gaming #Huntress #BuildProgress

  11. Tonight in PoE2, my custom build is leaving the safety of the early zone and venturing into the unforgiving deserts of Deshar in Act 2.

    The plan is to see how the spirit-and-undead minion engine holds up against the fast, hard-hitting desert packs, and to start locking down my core mid-game passives. Come hang out for the campaign progression and chat about the build!

    Watch the desert push live: twitch.tv/cheshire_ge

    #PoE2 #PathOfExile #Twitch #SmallStreamer #Gaming #Huntress #BuildProgress

  12. Tonight in PoE2, my custom build is leaving the safety of the early zone and venturing into the unforgiving deserts of Deshar in Act 2.

    The plan is to see how the spirit-and-undead minion engine holds up against the fast, hard-hitting desert packs, and to start locking down my core mid-game passives. Come hang out for the campaign progression and chat about the build!

    Watch the desert push live: twitch.tv/cheshire_ge

    #PoE2 #PathOfExile #Twitch #SmallStreamer #Gaming #Huntress #BuildProgress

  13. Unpatched Windows Search Flaw Exposes User Hashes

    A newly discovered vulnerability in Windows' search feature can be exploited to steal user passwords, allowing hackers to gain access to sensitive information. By simply clicking on a malicious link, a user's login credentials can be exposed to attackers.

    osintsights.com/unpatched-wind

    #WindowsSearchFlaw #Ntlmv2 #Netntlmv2 #Huntress #WindowsVulnerability

  14. shitepop X BUZZCUT: It's An Afterparty @ Stereo - 18 Apr feat. Babyjaii, HUNTRESS

    #SESH #Babyjaii #HUNTRESS

    sesh.sx/e/1970383

  15. 🎯 Threat Intelligence
    ===================

    Executive summary: Huntress observed a targeted intrusion in December 2025 that culminated in deployment of an ESXi VM-escape exploit toolkit. Initial access is assessed with high confidence to have occurred via a compromised SonicWall VPN. The toolkit contains Simplified Chinese development paths and appears to support a wide range of ESXi builds.

    Technical details:
    • Toolkit coverage: supports 155 ESXi builds spanning VMware ESXi versions 5.1 through 8.0.
    • Evidence of development artifacts: folder named "全版本逃逸--交付" indicating Chinese-language development paths.
    • Observed techniques: disabling VMCI devices/drivers via devcon entries, loading unsigned kernel driver via Kernel Driver Utility (KDU), staging data with WinRAR, lateral movement using a compromised Domain Admin account and RDP, reconnaissance with Advanced Port Scanner and SoftPerfect Network Scanner, and share enumeration with ShareFinder.
    • Notable artifacts: attempted DA password change via Impacket that was blocked by managed Microsoft Defender for Endpoint.

    Attack Chain Analysis:
    • Initial Access: probable SonicWall VPN compromise (valid account use).
    • Lateral Movement: use of compromised Domain Admin credentials and RDP to pivot to backup and primary domain controllers (T1078, T1021.001).
    • Execution/Privilege Actions: disabling VMCI devices and loading an unsigned exploit driver using KDU to achieve VM escape.
    • Staging/Exfiltration: archiving data with WinRAR for exfiltration (archive via compression observed).

    Detection guidance:
    • Monitor ESXi hosts directly for unexpected processes and open files; Huntress flagged use of lsof -a on hosts as an investigative step.
    • Inspect for loading of known vulnerable or unsigned drivers and for devcon-driven device state changes on Windows hosts.
    • Note that VSOCK traffic between VMs and hypervisor is typically invisible to network perimeter controls; host-level visibility is required.

    Impact and limitations:
    • Impact: a successful VM escape against ESXi can compromise all workloads on a host and enable large-scale data theft or ransomware.
    • Limitations: the toolkit targets specific ESXi builds; end-of-life versions may have no available fixes.

    References and indicators:
    • Observed tooling: Advanced_Port_Scanner_2.5.3869.exe, netscan.exe (SoftPerfect), ShareFinder, devcon, kdu, WinRAR.

    🔹 vmware #esxi #kdu #vmci #huntress

    🔗 Source: huntress.com/blog/esxi-vm-esca

  16. While the industry focused on securing the endpoint, the ground shifted. New data from Huntress and the Cloud Security Alliance confirms a staggering trend.

    In our latest feature, we break down the "Inside-Out" Problem—the technical paradox where virtualization isolation actually shields attackers from guest-level security agents.

    👇 READ THE FULL ANALYSIS: security.land/the-foundation-i

    #SecurityLand #ExpertDecode #CyberSecurity #Infosec #CloudSecurity #Huntress #Ransomware #Virtualization

  17. While the industry focused on securing the endpoint, the ground shifted. New data from Huntress and the Cloud Security Alliance confirms a staggering trend.

    In our latest feature, we break down the "Inside-Out" Problem—the technical paradox where virtualization isolation actually shields attackers from guest-level security agents.

    👇 READ THE FULL ANALYSIS: security.land/the-foundation-i

    #SecurityLand #ExpertDecode #CyberSecurity #Infosec #CloudSecurity #Huntress #Ransomware #Virtualization

  18. Today's the birthday of Dick Grayson, aka Robin/Nightwing!

    (Art by Evan Shaner, Dario Brizuela, Joe Staton, and George Perez.)

    #1976DCCalendar #DCComics #comics #Batman #Robin #Nightwing #TeenTitans #Huntress #MagillaGorilla #ScoobyDoo

  19. Today's the birthday of Dick Grayson, aka Robin/Nightwing!

    (Art by Evan Shaner, Dario Brizuela, Joe Staton, and George Perez.)

    #1976DCCalendar #DCComics #comics #Batman #Robin #Nightwing #TeenTitans #Huntress #MagillaGorilla #ScoobyDoo

  20. Today's the birthday of Dick Grayson, aka Robin/Nightwing!

    (Art by Evan Shaner, Dario Brizuela, Joe Staton, and George Perez.)

    #1976DCCalendar #DCComics #comics #Batman #Robin #Nightwing #TeenTitans #Huntress #MagillaGorilla #ScoobyDoo

  21. Today's the birthday of Dick Grayson, aka Robin/Nightwing!

    (Art by Evan Shaner, Dario Brizuela, Joe Staton, and George Perez.)

    #1976DCCalendar #DCComics #comics #Batman #Robin #Nightwing #TeenTitans #Huntress #MagillaGorilla #ScoobyDoo

  22. Today's the birthday of Dick Grayson, aka Robin/Nightwing!

    (Art by Evan Shaner, Dario Brizuela, Joe Staton, and George Perez.)

    #1976DCCalendar #DCComics #comics #Batman #Robin #Nightwing #TeenTitans #Huntress #MagillaGorilla #ScoobyDoo

  23. 🚨 Incident Response
    ===================

    Executive summary: A Huntress Tactical Response investigation encountered substantial telemetry gaps when a suspicious user creation was observed on a Windows host. Event logging for interactive logons (Windows Security 4624) was absent for the incident day (October 1, 2025); the last recorded 4624 on that host dated to September 13, 2025. Credential-validation 4776 events were present and more recent but did not reveal a conclusive origin.

    Technical details:
    • Observed artifact: user account created with source reported as machine/SYSTEM, consistent with remote execution or lateral access.
    • Events inspected: 4624 (successful interactive/logon events) and 4776 (credential validation). 4624 was absent for the incident day.
    • Additional artifacts checked: DNS cache entries, active network connections, and other endpoint artifacts; none yielded definitive pivots or source hosts.
    • Suspected lateral mechanisms noted in the report: WinRM, WMI, or an RMM product invoked from another host.

    Analysis:
    The absence of 4624 events for the incident window significantly reduces the ability to trace source hosts for interactive/logon activity. The presence of 4776 indicates some credential validation activity but lacks the richer context 4624 would provide (caller host, logon type, etc.). The user creation by machine/SYSTEM aligns with a remote execution pattern where an attacker performs actions via a remote management channel.

    Detection observations:
    • Time-series charts of event counts were used to identify when the last 4624 occurred on the host.
    • Correlation attempts included matching 4776 spikes to known timelines and examining DNS cache and active connections for transient indicators.

    Response actions reported:
    • Findings were communicated to the partner, who subsequently performed additional on-site digging.
    • The investigation identified that the host’s audit policy had been changed, accounting for missing authentication events; the chain of custody for the user-creation origin remained inconclusive in the available telemetry.

    Limitations:
    • Missing 4624 events removed a critical detection vector for pivoting and source identification.
    • 4776 events alone did not supply sufficient context to reconstruct the lateral access origin.

    References / artifacts (as reported):
    Event ID: 4624
    Event ID: 4776

    🔹 incidentresponse #huntress #windows_security #forensics #telemetry_gaps

    🔗 Source: huntress.com/blog/imperfect-te