#huntress — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #huntress, aggregated by home.social.
-
Samira Aurum:
"O mercado é um labirinto, mas meu faro nunca me engana. Estou sempre um passo à frente."
"The market is a labyrinth, but my scent never deceives me. I am always one step ahead."
lovescape.com/profile/muri...
#SamiraAurum #Pantherian #GeneticExperiment #Huntress #NightMarketVibes -
I joined @huntress because I want to do my part to save the world. That's not bragging or hyperbole. I believe that, every day, in law offices and dental clinics and at construction companies and coffee shops, we're watching your back so you can concentrate on those things that you excel at, and make life better for those around you.
As an industry we're now seeing that cybersecurity has done such a good job at this, as a whole, the attackers are now targeting us - sometimes first - and trying to throw us off our game.
Never gonna happen. The solution to this is for the #infosec space to unify and stay strong. Not unify like "get acquired' but "get aligned" and realize that, even as competitors, we're all pressing toward the same goal: messing up a cybercriminal's day.
I said it last summer, and it was as true this morning as it was then: The Infosec industry is a critical infrastructure, and it both needs and deserves its own #ISAC. I will work with anyone who shares that goal to help me make that a reality.
So with all that, I wanted to share that I worked with some of my colleagues on this rapid response the past day and a half, and I'm pretty proud of the result.
https://www.huntress.com/blog/klue-breach-investigation
#Klue #breach #DataBreach #RapidResponse #IR #DFIR #tokens #compromise #integration #SalesForce #SFDC #Gong #huntress
-
I joined @huntress because I want to do my part to save the world. That's not bragging or hyperbole. I believe that, every day, in law offices and dental clinics and at construction companies and coffee shops, we're watching your back so you can concentrate on those things that you excel at, and make life better for those around you.
As an industry we're now seeing that cybersecurity has done such a good job at this, as a whole, the attackers are now targeting us - sometimes first - and trying to throw us off our game.
Never gonna happen. The solution to this is for the #infosec space to unify and stay strong. Not unify like "get acquired' but "get aligned" and realize that, even as competitors, we're all pressing toward the same goal: messing up a cybercriminal's day.
I said it last summer, and it was as true this morning as it was then: The Infosec industry is a critical infrastructure, and it both needs and deserves its own #ISAC. I will work with anyone who shares that goal to help me make that a reality.
So with all that, I wanted to share that I worked with some of my colleagues on this rapid response the past day and a half, and I'm pretty proud of the result.
https://www.huntress.com/blog/klue-breach-investigation
#Klue #breach #DataBreach #RapidResponse #IR #DFIR #tokens #compromise #integration #SalesForce #SFDC #Gong #huntress
-
I joined @huntress because I want to do my part to save the world. That's not bragging or hyperbole. I believe that, every day, in law offices and dental clinics and at construction companies and coffee shops, we're watching your back so you can concentrate on those things that you excel at, and make life better for those around you.
As an industry we're now seeing that cybersecurity has done such a good job at this, as a whole, the attackers are now targeting us - sometimes first - and trying to throw us off our game.
Never gonna happen. The solution to this is for the #infosec space to unify and stay strong. Not unify like "get acquired' but "get aligned" and realize that, even as competitors, we're all pressing toward the same goal: messing up a cybercriminal's day.
I said it last summer, and it was as true this morning as it was then: The Infosec industry is a critical infrastructure, and it both needs and deserves its own #ISAC. I will work with anyone who shares that goal to help me make that a reality.
So with all that, I wanted to share that I worked with some of my colleagues on this rapid response the past day and a half, and I'm pretty proud of the result.
https://www.huntress.com/blog/klue-breach-investigation
#Klue #breach #DataBreach #RapidResponse #IR #DFIR #tokens #compromise #integration #SalesForce #SFDC #Gong #huntress
-
I joined @huntress because I want to do my part to save the world. That's not bragging or hyperbole. I believe that, every day, in law offices and dental clinics and at construction companies and coffee shops, we're watching your back so you can concentrate on those things that you excel at, and make life better for those around you.
As an industry we're now seeing that cybersecurity has done such a good job at this, as a whole, the attackers are now targeting us - sometimes first - and trying to throw us off our game.
Never gonna happen. The solution to this is for the #infosec space to unify and stay strong. Not unify like "get acquired' but "get aligned" and realize that, even as competitors, we're all pressing toward the same goal: messing up a cybercriminal's day.
I said it last summer, and it was as true this morning as it was then: The Infosec industry is a critical infrastructure, and it both needs and deserves its own #ISAC. I will work with anyone who shares that goal to help me make that a reality.
So with all that, I wanted to share that I worked with some of my colleagues on this rapid response the past day and a half, and I'm pretty proud of the result.
https://www.huntress.com/blog/klue-breach-investigation
#Klue #breach #DataBreach #RapidResponse #IR #DFIR #tokens #compromise #integration #SalesForce #SFDC #Gong #huntress
-
I joined @huntress because I want to do my part to save the world. That's not bragging or hyperbole. I believe that, every day, in law offices and dental clinics and at construction companies and coffee shops, we're watching your back so you can concentrate on those things that you excel at, and make life better for those around you.
As an industry we're now seeing that cybersecurity has done such a good job at this, as a whole, the attackers are now targeting us - sometimes first - and trying to throw us off our game.
Never gonna happen. The solution to this is for the #infosec space to unify and stay strong. Not unify like "get acquired' but "get aligned" and realize that, even as competitors, we're all pressing toward the same goal: messing up a cybercriminal's day.
I said it last summer, and it was as true this morning as it was then: The Infosec industry is a critical infrastructure, and it both needs and deserves its own #ISAC. I will work with anyone who shares that goal to help me make that a reality.
So with all that, I wanted to share that I worked with some of my colleagues on this rapid response the past day and a half, and I'm pretty proud of the result.
https://www.huntress.com/blog/klue-breach-investigation
#Klue #breach #DataBreach #RapidResponse #IR #DFIR #tokens #compromise #integration #SalesForce #SFDC #Gong #huntress
-
Tonight in PoE2, my custom build is leaving the safety of the early zone and venturing into the unforgiving deserts of Deshar in Act 2.
The plan is to see how the spirit-and-undead minion engine holds up against the fast, hard-hitting desert packs, and to start locking down my core mid-game passives. Come hang out for the campaign progression and chat about the build!
Watch the desert push live: https://www.twitch.tv/cheshire_ge
#PoE2 #PathOfExile #Twitch #SmallStreamer #Gaming #Huntress #BuildProgress
-
Tonight in PoE2, my custom build is leaving the safety of the early zone and venturing into the unforgiving deserts of Deshar in Act 2.
The plan is to see how the spirit-and-undead minion engine holds up against the fast, hard-hitting desert packs, and to start locking down my core mid-game passives. Come hang out for the campaign progression and chat about the build!
Watch the desert push live: https://www.twitch.tv/cheshire_ge
#PoE2 #PathOfExile #Twitch #SmallStreamer #Gaming #Huntress #BuildProgress
-
Tonight in PoE2, my custom build is leaving the safety of the early zone and venturing into the unforgiving deserts of Deshar in Act 2.
The plan is to see how the spirit-and-undead minion engine holds up against the fast, hard-hitting desert packs, and to start locking down my core mid-game passives. Come hang out for the campaign progression and chat about the build!
Watch the desert push live: https://www.twitch.tv/cheshire_ge
#PoE2 #PathOfExile #Twitch #SmallStreamer #Gaming #Huntress #BuildProgress
-
Tonight in PoE2, my custom build is leaving the safety of the early zone and venturing into the unforgiving deserts of Deshar in Act 2.
The plan is to see how the spirit-and-undead minion engine holds up against the fast, hard-hitting desert packs, and to start locking down my core mid-game passives. Come hang out for the campaign progression and chat about the build!
Watch the desert push live: https://www.twitch.tv/cheshire_ge
#PoE2 #PathOfExile #Twitch #SmallStreamer #Gaming #Huntress #BuildProgress
-
Tonight in PoE2, my custom build is leaving the safety of the early zone and venturing into the unforgiving deserts of Deshar in Act 2.
The plan is to see how the spirit-and-undead minion engine holds up against the fast, hard-hitting desert packs, and to start locking down my core mid-game passives. Come hang out for the campaign progression and chat about the build!
Watch the desert push live: https://www.twitch.tv/cheshire_ge
#PoE2 #PathOfExile #Twitch #SmallStreamer #Gaming #Huntress #BuildProgress
-
Unpatched Windows Search Flaw Exposes User Hashes
A newly discovered vulnerability in Windows' search feature can be exploited to steal user passwords, allowing hackers to gain access to sensitive information. By simply clicking on a malicious link, a user's login credentials can be exposed to attackers.
#WindowsSearchFlaw #Ntlmv2 #Netntlmv2 #Huntress #WindowsVulnerability
-
#QPosket DC Comics: Birds of Prey #Huntress (Type A) *Sealed* brought to you by the #PlastiqueBoutique https://plastiqueboutique.com/product/qposket-dc-comics-birds-of-prey-huntress-type-a-sealed/?utm_source=mastodon&utm_medium=social&utm_campaign=ReviveOldPost #DCComicsFigure #HuntressCollectors #HuntressCollections #HuntressFigure #HuntressCollection #DCComicsFigures #DCComicsToy #DCComicsStatue #DCComicsCollector #HuntressFigures #DCComicsCollectors #HuntressCollector #DCComicsCollection #DCComicsCollections #DCComicsStatues #DCComicsToys #DCComics
-
#QPosket DC Comics: Birds of Prey #Huntress (Type A) *Sealed* brought to you by the #PlastiqueBoutique https://plastiqueboutique.com/product/qposket-dc-comics-birds-of-prey-huntress-type-a-sealed/?utm_source=mastodon&utm_medium=social&utm_campaign=ReviveOldPost #DCComicsFigure #HuntressCollectors #HuntressCollections #HuntressFigure #HuntressCollection #DCComicsFigures #DCComicsToy #DCComicsStatue #DCComicsCollector #HuntressFigures #DCComicsCollectors #HuntressCollector #DCComicsCollection #DCComicsCollections #DCComicsStatues #DCComicsToys #DCComics
-
shitepop X BUZZCUT: It's An Afterparty @ Stereo - 18 Apr feat. Babyjaii, HUNTRESS
-
🎯 Threat Intelligence
===================Executive summary: Huntress observed a targeted intrusion in December 2025 that culminated in deployment of an ESXi VM-escape exploit toolkit. Initial access is assessed with high confidence to have occurred via a compromised SonicWall VPN. The toolkit contains Simplified Chinese development paths and appears to support a wide range of ESXi builds.
Technical details:
• Toolkit coverage: supports 155 ESXi builds spanning VMware ESXi versions 5.1 through 8.0.
• Evidence of development artifacts: folder named "全版本逃逸--交付" indicating Chinese-language development paths.
• Observed techniques: disabling VMCI devices/drivers via devcon entries, loading unsigned kernel driver via Kernel Driver Utility (KDU), staging data with WinRAR, lateral movement using a compromised Domain Admin account and RDP, reconnaissance with Advanced Port Scanner and SoftPerfect Network Scanner, and share enumeration with ShareFinder.
• Notable artifacts: attempted DA password change via Impacket that was blocked by managed Microsoft Defender for Endpoint.Attack Chain Analysis:
• Initial Access: probable SonicWall VPN compromise (valid account use).
• Lateral Movement: use of compromised Domain Admin credentials and RDP to pivot to backup and primary domain controllers (T1078, T1021.001).
• Execution/Privilege Actions: disabling VMCI devices and loading an unsigned exploit driver using KDU to achieve VM escape.
• Staging/Exfiltration: archiving data with WinRAR for exfiltration (archive via compression observed).Detection guidance:
• Monitor ESXi hosts directly for unexpected processes and open files; Huntress flagged use of lsof -a on hosts as an investigative step.
• Inspect for loading of known vulnerable or unsigned drivers and for devcon-driven device state changes on Windows hosts.
• Note that VSOCK traffic between VMs and hypervisor is typically invisible to network perimeter controls; host-level visibility is required.Impact and limitations:
• Impact: a successful VM escape against ESXi can compromise all workloads on a host and enable large-scale data theft or ransomware.
• Limitations: the toolkit targets specific ESXi builds; end-of-life versions may have no available fixes.References and indicators:
• Observed tooling: Advanced_Port_Scanner_2.5.3869.exe, netscan.exe (SoftPerfect), ShareFinder, devcon, kdu, WinRAR.🔹 vmware #esxi #kdu #vmci #huntress
🔗 Source: https://www.huntress.com/blog/esxi-vm-escape-exploit
-
MAESTRO Toolkit Exploiting VMware VM Escape Vulnerabilities https://hackread.com/maestro-toolkit-vmware-vm-escape-vulnerabilities/ #Cybersecurity #Vulnerability #Security #Huntress #VMEscape #MAESTRO #Toolkit #VMware
-
MAESTRO Toolkit Exploiting VMware VM Escape Vulnerabilities https://hackread.com/maestro-toolkit-vmware-vm-escape-vulnerabilities/ #Cybersecurity #Vulnerability #Security #Huntress #VMEscape #MAESTRO #Toolkit #VMware
-
MAESTRO Toolkit Exploiting VMware VM Escape Vulnerabilities https://hackread.com/maestro-toolkit-vmware-vm-escape-vulnerabilities/ #Cybersecurity #Vulnerability #Security #Huntress #VMEscape #MAESTRO #Toolkit #VMware
-
MAESTRO Toolkit Exploiting VMware VM Escape Vulnerabilities https://hackread.com/maestro-toolkit-vmware-vm-escape-vulnerabilities/ #Cybersecurity #Vulnerability #Security #Huntress #VMEscape #MAESTRO #Toolkit #VMware
-
#QPosket DC Comics: Birds of Prey #Huntress (Type A) *Sealed* brought to you by the #PlastiqueBoutique https://plastiqueboutique.com/product/qposket-dc-comics-birds-of-prey-huntress-type-a-sealed/?utm_source=mastodon&utm_medium=social&utm_campaign=ReviveOldPost #DCComicsCollectors #DCComicsStatues #HuntressCollector #DCComicsFigures #HuntressCollection #DCComicsStatue #DCComicsFigure #DCComicsToys #DCComicsCollection #DCComicsToy #DCComicsCollections #HuntressFigures #HuntressFigure #HuntressCollectors #HuntressCollections #DCComics #DCComicsCollector
-
While the industry focused on securing the endpoint, the ground shifted. New data from Huntress and the Cloud Security Alliance confirms a staggering trend.
In our latest feature, we break down the "Inside-Out" Problem—the technical paradox where virtualization isolation actually shields attackers from guest-level security agents.
👇 READ THE FULL ANALYSIS: https://www.security.land/the-foundation-is-cracking-why-the-hypervisor-is-the-final-frontier-of-stealth-attacks/
#SecurityLand #ExpertDecode #CyberSecurity #Infosec #CloudSecurity #Huntress #Ransomware #Virtualization
-
While the industry focused on securing the endpoint, the ground shifted. New data from Huntress and the Cloud Security Alliance confirms a staggering trend.
In our latest feature, we break down the "Inside-Out" Problem—the technical paradox where virtualization isolation actually shields attackers from guest-level security agents.
👇 READ THE FULL ANALYSIS: https://www.security.land/the-foundation-is-cracking-why-the-hypervisor-is-the-final-frontier-of-stealth-attacks/
#SecurityLand #ExpertDecode #CyberSecurity #Infosec #CloudSecurity #Huntress #Ransomware #Virtualization
-
Fake “Windows Update” screens fuels new wave of ClickFix attacks https://www.helpnetsecurity.com/2025/11/25/fake-windows-update-screen-clickfix/ #socialengineering #Don'tmiss #Hotstuff #Huntress #malware #Windows #News
-
Fake “Windows Update” screens fuels new wave of ClickFix attacks https://www.helpnetsecurity.com/2025/11/25/fake-windows-update-screen-clickfix/ #socialengineering #Don'tmiss #Hotstuff #Huntress #malware #Windows #News
-
Fake “Windows Update” screens fuels new wave of ClickFix attacks https://www.helpnetsecurity.com/2025/11/25/fake-windows-update-screen-clickfix/ #socialengineering #Don'tmiss #Hotstuff #Huntress #malware #Windows #News
-
Fake “Windows Update” screens fuels new wave of ClickFix attacks https://www.helpnetsecurity.com/2025/11/25/fake-windows-update-screen-clickfix/ #socialengineering #Don'tmiss #Hotstuff #Huntress #malware #Windows #News
-
Today's the birthday of Dick Grayson, aka Robin/Nightwing!
(Art by Evan Shaner, Dario Brizuela, Joe Staton, and George Perez.)
#1976DCCalendar #DCComics #comics #Batman #Robin #Nightwing #TeenTitans #Huntress #MagillaGorilla #ScoobyDoo
-
Today's the birthday of Dick Grayson, aka Robin/Nightwing!
(Art by Evan Shaner, Dario Brizuela, Joe Staton, and George Perez.)
#1976DCCalendar #DCComics #comics #Batman #Robin #Nightwing #TeenTitans #Huntress #MagillaGorilla #ScoobyDoo
-
Today's the birthday of Dick Grayson, aka Robin/Nightwing!
(Art by Evan Shaner, Dario Brizuela, Joe Staton, and George Perez.)
#1976DCCalendar #DCComics #comics #Batman #Robin #Nightwing #TeenTitans #Huntress #MagillaGorilla #ScoobyDoo
-
Today's the birthday of Dick Grayson, aka Robin/Nightwing!
(Art by Evan Shaner, Dario Brizuela, Joe Staton, and George Perez.)
#1976DCCalendar #DCComics #comics #Batman #Robin #Nightwing #TeenTitans #Huntress #MagillaGorilla #ScoobyDoo
-
Today's the birthday of Dick Grayson, aka Robin/Nightwing!
(Art by Evan Shaner, Dario Brizuela, Joe Staton, and George Perez.)
#1976DCCalendar #DCComics #comics #Batman #Robin #Nightwing #TeenTitans #Huntress #MagillaGorilla #ScoobyDoo
-
🚨 Incident Response
===================Executive summary: A Huntress Tactical Response investigation encountered substantial telemetry gaps when a suspicious user creation was observed on a Windows host. Event logging for interactive logons (Windows Security 4624) was absent for the incident day (October 1, 2025); the last recorded 4624 on that host dated to September 13, 2025. Credential-validation 4776 events were present and more recent but did not reveal a conclusive origin.
Technical details:
• Observed artifact: user account created with source reported as machine/SYSTEM, consistent with remote execution or lateral access.
• Events inspected: 4624 (successful interactive/logon events) and 4776 (credential validation). 4624 was absent for the incident day.
• Additional artifacts checked: DNS cache entries, active network connections, and other endpoint artifacts; none yielded definitive pivots or source hosts.
• Suspected lateral mechanisms noted in the report: WinRM, WMI, or an RMM product invoked from another host.Analysis:
The absence of 4624 events for the incident window significantly reduces the ability to trace source hosts for interactive/logon activity. The presence of 4776 indicates some credential validation activity but lacks the richer context 4624 would provide (caller host, logon type, etc.). The user creation by machine/SYSTEM aligns with a remote execution pattern where an attacker performs actions via a remote management channel.Detection observations:
• Time-series charts of event counts were used to identify when the last 4624 occurred on the host.
• Correlation attempts included matching 4776 spikes to known timelines and examining DNS cache and active connections for transient indicators.Response actions reported:
• Findings were communicated to the partner, who subsequently performed additional on-site digging.
• The investigation identified that the host’s audit policy had been changed, accounting for missing authentication events; the chain of custody for the user-creation origin remained inconclusive in the available telemetry.Limitations:
• Missing 4624 events removed a critical detection vector for pivoting and source identification.
• 4776 events alone did not supply sufficient context to reconstruct the lateral access origin.References / artifacts (as reported):
Event ID: 4624
Event ID: 4776🔹 incidentresponse #huntress #windows_security #forensics #telemetry_gaps
🔗 Source: https://www.huntress.com/blog/imperfect-telemetry-techniques-effective-incident-response
-
“AI helps, but humans lead.” - Chris Bisnett, CTO & Co-Founder of Huntress
Automation enables efficiency, but real defense depends on judgment, agility & human insight.Full interview ⬇️
https://www.technadu.com/ai-helps-but-humans-lead-by-staying-agile-and-figuring-out-whats-next-as-attackers-innovate/612389/#CyberSecurity #HumanInTheLoop #AI #Huntress #ThreatDetection #TechNadu
-
“AI helps, but humans lead.” - Chris Bisnett, CTO & Co-Founder of Huntress
Automation enables efficiency, but real defense depends on judgment, agility & human insight.Full interview ⬇️
https://www.technadu.com/ai-helps-but-humans-lead-by-staying-agile-and-figuring-out-whats-next-as-attackers-innovate/612389/#CyberSecurity #HumanInTheLoop #AI #Huntress #ThreatDetection #TechNadu
-
“AI helps, but humans lead.” - Chris Bisnett, CTO & Co-Founder of Huntress
Automation enables efficiency, but real defense depends on judgment, agility & human insight.Full interview ⬇️
https://www.technadu.com/ai-helps-but-humans-lead-by-staying-agile-and-figuring-out-whats-next-as-attackers-innovate/612389/#CyberSecurity #HumanInTheLoop #AI #Huntress #ThreatDetection #TechNadu
-
For my first ever #ctf I'm happy. Learned a lot and had some fun. Plenty of room for improvement. #cybersecurity #huntress https://ctf.huntress.com/completion/d959443a735027a8
-
For my first ever #ctf I'm happy. Learned a lot and had some fun. Plenty of room for improvement. #cybersecurity #huntress https://ctf.huntress.com/completion/d959443a735027a8
-
Attackers exploiting WSUS vulnerability drop Skuld infostealer (CVE-2025-59287) https://www.helpnetsecurity.com/2025/10/30/wsus-vulnerability-infostealer-cve-2025-59287/ #PaloAltoNetworks #WindowsServer #EyeSecurity #Don'tmiss #Darktrace #datatheft #Hotstuff #Huntress #malware #Sophos #News
-
Attackers exploiting WSUS vulnerability drop Skuld infostealer (CVE-2025-59287) https://www.helpnetsecurity.com/2025/10/30/wsus-vulnerability-infostealer-cve-2025-59287/ #PaloAltoNetworks #WindowsServer #EyeSecurity #Don'tmiss #Darktrace #datatheft #Hotstuff #Huntress #malware #Sophos #News
-
Attackers exploiting WSUS vulnerability drop Skuld infostealer (CVE-2025-59287) https://www.helpnetsecurity.com/2025/10/30/wsus-vulnerability-infostealer-cve-2025-59287/ #PaloAltoNetworks #WindowsServer #EyeSecurity #Don'tmiss #Darktrace #datatheft #Hotstuff #Huntress #malware #Sophos #News
-
Attackers exploiting WSUS vulnerability drop Skuld infostealer (CVE-2025-59287) https://www.helpnetsecurity.com/2025/10/30/wsus-vulnerability-infostealer-cve-2025-59287/ #PaloAltoNetworks #WindowsServer #EyeSecurity #Don'tmiss #Darktrace #datatheft #Hotstuff #Huntress #malware #Sophos #News
-
Legit tools, illicit uses: Velociraptor, Nezha turned against victims https://www.helpnetsecurity.com/2025/10/09/velociraptor-nezha-attackers-misuse/ #attacktools #opensource #ransomware #Don'tmiss #Hotstuff #Huntress #Sophos #Cisco #News #APT
-
Legit tools, illicit uses: Velociraptor, Nezha turned against victims https://www.helpnetsecurity.com/2025/10/09/velociraptor-nezha-attackers-misuse/ #attacktools #opensource #ransomware #Don'tmiss #Hotstuff #Huntress #Sophos #Cisco #News #APT
-
Legit tools, illicit uses: Velociraptor, Nezha turned against victims https://www.helpnetsecurity.com/2025/10/09/velociraptor-nezha-attackers-misuse/ #attacktools #opensource #ransomware #Don'tmiss #Hotstuff #Huntress #Sophos #Cisco #News #APT
-
Legit tools, illicit uses: Velociraptor, Nezha turned against victims https://www.helpnetsecurity.com/2025/10/09/velociraptor-nezha-attackers-misuse/ #attacktools #opensource #ransomware #Don'tmiss #Hotstuff #Huntress #Sophos #Cisco #News #APT
-
🚨 Incident Response
Executive summary: A post-compromise investigation observed a threat actor gain initial access via a SonicWall device, locate plaintext recovery codes on a user desktop, and then use those codes to access the victim's Huntress portal. The actor performed remediation actions in the portal and uninstalled or removed isolation from hosts; Akira ransomware (process w.exe) executed on at least one workstation while commands to delete shadow copies were observed.
Technical details:
• Initial access: SonicWall VPN compromise (as described in linked advisory context).
• Discovery: Local file containing Huntress recovery codes in plaintext on the user desktop.
• Lateral/privileged actions: Administrative accounts were observed executing commands to delete shadow copies across multiple hosts.
• Malware observed: Akira ransomware running as w.exe on the infected workstation.
• Network indicators: Affected user accounts were accessed from internal IPs in the 192.168.x.x range, per event-log analysis.Analysis & impact:
• The presence of plaintext recovery codes allowed immediate pivot to a remote management/security portal (Huntress), enabling the actor to disable containment controls and remove isolated hosts.
• Not all third-party services enforce secondary protections around recovery codes; compromise of such codes can significantly escalate impact.
• The mass-isolation response limited full environment encryption, indicating containment reduced blast radius despite local encryption.Detection guidance:
• Monitor for unusual administrative actions in security/management portals and correlate with endpoint event logs.
• Alert on processes named w.exe or unusual ransomware-like behavior and on bulk shadow copy deletion commands.
• Search endpoints for plaintext credential artifacts and flagged filenames (e.g., files on desktops with terms like "recovery" or "codes").Mitigation & recommendations:
• Enforce secure storage for recovery codes (password managers,
vaults) and remove plaintext copies from user profiles.
• Require MFA and portal-specific protections for recovery-code usage where service supports it.
• Harden VPN appliances and audit remote access logs for anomalies.References / notes:
• Observations derived from Huntress APAC SOC triage of the incident; details are limited to recorded logs and observed processes.🔗 Source: https://www.huntress.com/blog/dangers-of-storing-unencrypted-passwords
-
Ransomware attackers used incorrectly stored recovery codes to disable EDR agents https://www.helpnetsecurity.com/2025/09/16/akira-ransomware-disable-edr/ #endpointsecurity #credentials #enterprise #ransomware #Don'tmiss #SonicWall #Hotstuff #Huntress #Rapid7 #News #SMBs
-
Ransomware attackers used incorrectly stored recovery codes to disable EDR agents https://www.helpnetsecurity.com/2025/09/16/akira-ransomware-disable-edr/ #endpointsecurity #credentials #enterprise #ransomware #Don'tmiss #SonicWall #Hotstuff #Huntress #Rapid7 #News #SMBs
-
Ransomware attackers used incorrectly stored recovery codes to disable EDR agents https://www.helpnetsecurity.com/2025/09/16/akira-ransomware-disable-edr/ #endpointsecurity #credentials #enterprise #ransomware #Don'tmiss #SonicWall #Hotstuff #Huntress #Rapid7 #News #SMBs
-
Ransomware attackers used incorrectly stored recovery codes to disable EDR agents https://www.helpnetsecurity.com/2025/09/16/akira-ransomware-disable-edr/ #endpointsecurity #credentials #enterprise #ransomware #Don'tmiss #SonicWall #Hotstuff #Huntress #Rapid7 #News #SMBs
-
Huntress Endpoint Detection and Response “does an (alleged) Kaspersky” and chooses to dox a customer having unilaterally decided the customer is evil
…we determined that the host that had installed the Huntress agent was, in fact, malicious. We wanted to serve the broader community by sharing what we learned about the tradecraft that the threat actor was using in this incident. In deciding what information to publish about this investigation, we carefully considered several factors, like strictly upholding our privacy obligations, as well as disseminating EDR telemetry that specifically reflected threats and behavior that could help defenders.
https://www.huntress.com/blog/rare-look-inside-attacker-operation archived at https://archive.ph/viu8w
Re: Kaspersky, allegedly: https://www.kaspersky.co.uk/blog/kaspersky-in-the-shitstorm/11926/
-
Huntress Endpoint Detection and Response “does an (alleged) Kaspersky” and chooses to dox a customer having unilaterally decided the customer is evil
…we determined that the host that had installed the Huntress agent was, in fact, malicious. We wanted to serve the broader community by sharing what we learned about the tradecraft that the threat actor was using in this incident. In deciding what information to publish about this investigation, we carefully considered several factors, like strictly upholding our privacy obligations, as well as disseminating EDR telemetry that specifically reflected threats and behavior that could help defenders.
https://www.huntress.com/blog/rare-look-inside-attacker-operation archived at https://archive.ph/viu8w
Re: Kaspersky, allegedly: https://www.kaspersky.co.uk/blog/kaspersky-in-the-shitstorm/11926/
-
Huntress Endpoint Detection and Response “does an (alleged) Kaspersky” and chooses to dox a customer having unilaterally decided the customer is evil
…we determined that the host that had installed the Huntress agent was, in fact, malicious. We wanted to serve the broader community by sharing what we learned about the tradecraft that the threat actor was using in this incident. In deciding what information to publish about this investigation, we carefully considered several factors, like strictly upholding our privacy obligations, as well as disseminating EDR telemetry that specifically reflected threats and behavior that could help defenders.
https://www.huntress.com/blog/rare-look-inside-attacker-operation archived at https://archive.ph/viu8w
Re: Kaspersky, allegedly: https://www.kaspersky.co.uk/blog/kaspersky-in-the-shitstorm/11926/
-
🚨 Obscura ransomware has rolled out a new dark web leak site, with six new victims already listed on its .onion domain.
Public leak portals are fast becoming ransomware’s go-to weapon of extortion.
💬 What’s your view on how defenders should tackle this trend?Follow @technadu for ongoing cyber threat insights.
#ObscuraRansomware #LeakSite #DarkWeb #CyberThreat #Huntress
-
🚨 Obscura ransomware has rolled out a new dark web leak site, with six new victims already listed on its .onion domain.
Public leak portals are fast becoming ransomware’s go-to weapon of extortion.
💬 What’s your view on how defenders should tackle this trend?Follow @technadu for ongoing cyber threat insights.
#ObscuraRansomware #LeakSite #DarkWeb #CyberThreat #Huntress
-
#QPosket DC Comics: Birds of Prey #Huntress (Type A) *Sealed* brought to you by the #PlastiqueBoutique
Don't forget to give us a follow to keep up on the latest arrivals! https://plastiqueboutique.com/product/qposket-dc-comics-birds-of-prey-huntress-type-a-sealed/?utm_source=mastodon&utm_medium=social&utm_campaign=ReviveOldPost #DCComicsFigure #DCComicsToy #DCComicsCollection #DCComicsCollector #DCComicsFigures #DCComicsStatue #DCComicsToys #HuntressFigure #DCComicsCollections #DCComics #DCComicsStatues #DCComicsCollectors
-
Thanks to Huntress for coming in as a last-minute sponsor for your swag bag at BSides Saskatoon!
Huntress is an enterprise managed security services provider with a multitude of services and offerings. Providing managed #cybersecurity without the complexity. EDR, ITDR, SIEM & SAT crafted for under-resourced IT and Security teams.
Check them out at https://buff.ly/xcsjO2S
-
Thanks to Huntress for coming in as a last-minute sponsor for your swag bag at BSides Saskatoon!
Huntress is an enterprise managed security services provider with a multitude of services and offerings. Providing managed #cybersecurity without the complexity. EDR, ITDR, SIEM & SAT crafted for under-resourced IT and Security teams.
Check them out at https://buff.ly/xcsjO2S
-
Thanks to Huntress for coming in as a last-minute sponsor for your swag bag at BSides Saskatoon!
Huntress is an enterprise managed security services provider with a multitude of services and offerings. Providing managed #cybersecurity without the complexity. EDR, ITDR, SIEM & SAT crafted for under-resourced IT and Security teams.
Check them out at https://buff.ly/xcsjO2S