Sign in

Huntress

@huntress.com
413 followers 15 following 71 posts

Managed endpoint protection, detection and response designed to help the 99% fight back against today’s cybercriminals.

PostsRepliesMedia
Huntress @huntress.com · 13/02/2026
We’re running nearly 1 billion Sidekiq background jobs a day to power all of the telemetry processing and detections. Can Redis scale with your workload? Here are the receipts. @mike.contribsys.com where does that rank in your experience?
Screenshot of the Sidekiq dashboard showing nearly 1 billion jobs a day
020
Huntress @huntress.com · 13/05/2025
A construction company recently suffered a VPN brute-force attack, but didn't have SIEM monitoring! The absence of a SIEM led to a 18-minute gap, giving the attacker enough time to attempt to steal credentials - but fortunately the Huntress EDR shut it down.
110
Huntress @huntress.com · 08/05/2025
Our SOC tackled an attempted ransomware intrusion tied to Makop ransomware tactics. Here’s what went down 👇 🎯 Initial Entry Point: Brute-forced an exposed RDP service (don’t skip reviewing your external perimeters!). 🗺️ Enumeration & Credential Targeting: Ran a network scan using netscan.exe.
100
Huntress @huntress.com · 07/05/2025
🚨Samsung MagicINFO 9 Server (v21.1050.0) is still vulnerable to a publicly available PoC. We’ve observed active exploitation in the wild. Ensure your server is not internet-facing until a proper fix is available. Full details + mitigation steps ➡️ bit.ly/44nkzhL
021
Huntress @huntress.com · 06/05/2025
We’ve shared many stories about exposed RDP without MFA. Why? Because it’s a common AF, threat actors waste no time exploiting it. What makes this SOC Story from a dental facility stand out: in under 30 minutes, the attack went from initial access to attempted ransomware deployment.
100
Huntress @huntress.com · 05/05/2025
.@jaiminton.com is a modern-day Doc Holliday. A lawman so feared that threat actors flee at the mere mention of his name… Introducing Celestial Stealer, a notorious infostealer with a surprising connection to Huntress.
100
Huntress @huntress.com · 30/04/2025
🐶 A vulnerability left an animal care facility wide open, and an attacker didn’t hesitate to pounce. Here’s how it unfolded 👇
100
Reposted by Huntress
Lindsey O’Donnell Welch @lindseyodwelch.bsky.social · 23/04/2025
Some good takeaways from @huntress.com’s recent Tradecraft Tuesday ft. Patrick Wardle: -The impact of Apple bringing TCC events to Endpoint Security -#Mac malware persistence techniques vs BTM -Security alert inundation for #macOS users Catch up here⤵️ www.huntress.com/blog/say-hel...
huntress.com
Say Hello to Mac Malware | Huntress
In this month’s Tradecraft Tuesday, we talked about how threat actors are finetuning their macOS malware in order to maintain persistent access and avoid detection by Apple’s security features.
023
Huntress @huntress.com · 22/04/2025
Huntress continues to observe in-the-wild exploitation of CVE-2025-30406, a critical vulnerability in Gladinet CentreStack and Triofox
112
Huntress @huntress.com · 17/04/2025
A threat actor brute forced a manufacturer's VPN appliance 🏭 Here’s what happened👇 📌 Successfully compromised one account for initial access 📌 Enumerated the domain, focusing on trust relationships and domain controllers 📌 Modified the registry and local firewall to enable lateral RDP movement
100
Huntress @huntress.com · 16/04/2025
Exposed RDP can lead to anything—even attempted ransomware attacks. Here’s what went down at this manufacturing business👇
122
Huntress @huntress.com · 14/04/2025
Huntress has observed in-the-wild exploitation of CVE-2025-30406, a critical vulnerability in the Gladinet CentreStack enterprise file-sharing platform.
143
Huntress @huntress.com · 08/04/2025
Threat actors can gain access to your network through an account that’s already on your system. The built-in Windows Guest account is often overlooked because it’s usually disabled by default—but that’s exactly what makes it a stealthy tool for attackers to exploit.
100
Huntress @huntress.com · 07/04/2025
Huntress researchers recently analyzed attacks involving CVE-2025-31161, a critical authentication bypass flaw in CrushFTP. 💡 We observed specific post-exploitation activity used by threat actors leveraging the flaw in the wild
100
Huntress @huntress.com · 04/04/2025
CVE-2025-31161 is the latest example of a critical severity authentication bypass vulnerability in CrushFTP, a growing trend we’re seeing from attackers targeting managed file transfer (MFT) platforms.
110
Huntress @huntress.com · 01/04/2025
Things you might spot in a #smishing text ⬇️ ✅ Sketchy phone number: Pretty sure the USPS isn’t sending out texts from the Philippines ✅ Unclickable links: On the off chance it actually was the USPS, they’d send a link you can click without basically having to solve a riddle
120
Huntress @huntress.com · 24/03/2025
Do you detect phishing from the endpoint or the cloud? 🎣 If you’re part of our Security Operations Center, the answer’s both. Here’s an example 👇 ✅ A proactive, human-led investigation led to our SOC identifying a potentially compromised Microsoft 365 identity
100
Huntress @huntress.com · 12/03/2025
A threat actor slid into a network through exposed virtual network computing (VNC). Here’s what happened 👇 ✅ They deployed C:\\Users\\<redacted>\\Music\\setup.msi to install Atera & Splashtop for persistent remote access
100
Huntress @huntress.com · 10/03/2025
Here’s an example of VPN compromise 👇 ✅ It’s a super common technique we see all the time ✅ Effects businesses of every size ✅ Usually caused by a simple configuration mistake, like an account without MFA enabled Yet it can often lead to network-wide compromise 😟
130
Huntress @huntress.com · 04/03/2025
Our SOC spotted a food wholesale business under duress when a threat actor was attempting to brute force an RDP server from a malicious IP address. Here’s what went down👇
110
Huntress @huntress.com · 25/02/2025
Let’s keep it real: Any service you expose to the internet is fair game for attackers. They’ll target anything to get access into your environment 👇 🎯 Web applications 🎯 #VPN devices 🎯 Remote desktop gateway Here’s how to secure exposed services and wreck a hacker’s day 💪
100
Huntress @huntress.com · 20/02/2025
A ransomware actor compromised a sport club’s network 🏌️ Here’s what went down 👇 ✅ They prepared to launch ransomware by deleting volume shadow copies ✅ Attempted to frustrate defenders by clearing the logs and neutralizing defenses
131
Huntress @huntress.com · 17/02/2025
Threat actors target every level of government 👇 Someone convinced a user via email to run and install tools that gave them malicious remote access to an important workstation at a County Government facility. The threat actor then:
111
Huntress @huntress.com · 13/02/2025
If you administer at least one Microsoft 365 tenant, you might find some surprising results if you audit your #OAuth applications 👀 Statistically speaking, there’s a good chance your tenant is infected with a rogue app that could be malicious 😱
132
Huntress @huntress.com · 12/02/2025
Straight from the 2025 Cyber Threat Report It’s no longer just clicking on sketchy links you need to be aware of. In 2024: 29% of 🐟 attacks involved e-signature impersonation tactics 24% of 🐠 attacks involved malicious image-based content 8% of 🐡 attacks involved embedding malicious QR codes
101