# Huntress

Published articles for Huntress.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Ben Bernstein, Manager of Cybersecurity Advisors at Huntress - Interview Series

DevFeed: [Ben Bernstein, Manager of Cybersecurity Advisors at Huntress - Interview Series](<https://devfeed.tech/articles/ben-bernstein-manager-of-cybersecurity-advisors-at-huntress-interview-series-55213.md>)

Original publisher: [Read original article](<https://www.unite.ai/ben-bernstein-manager-of-cybersecurity-advisors-at-huntress-interview-series/>)

Author: Antoine Tardif, CEO & Founder of Unite.AI

Published: 2026-09-18T19:17:48Z

Content type: article

Language: en

Sources: [Unite.AI](<https://devfeed.tech/sources/unite-ai.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>), [software-architecture](<https://devfeed.tech/topics/software-architecture.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [edr](<https://devfeed.tech/tags/edr.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [interview](<https://devfeed.tech/tags/interview.md>), [interviews](<https://devfeed.tech/tags/interviews.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [management](<https://devfeed.tech/tags/management.md>), [siem](<https://devfeed.tech/tags/siem.md>), [soc](<https://devfeed.tech/tags/soc.md>)

### AI overview

An interview with Ben Bernstein, Huntress's Manager of Cybersecurity Advisors, covering his career from helpdesk and systems administration to cybersecurity advisory leadership. Bernstein explains how hands-on IT experience, troubleshooting, and understanding normal system behavior inform security work and threat identification.

### Source excerpt

Ben Bernstein, Manager of Cybersecurity Advisors at Huntress, is a cybersecurity professional with more than a decade of experience spanning technical support, systems administration, client success, technical account management, and security advisory leadership. He began his career in hands-on IT roles, progressing from helpdesk work to systems administration before moving into account management and client success at Integris. Bernstein later spent three years at Red Canary, where he managed...

## Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware

DevFeed: [Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware](<https://devfeed.tech/articles/google-doc-sidebar-sends-mac-and-windows-users-down-different-paths-to-malware-54362.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/google-doc-sidebar-malware-mac-windows>)

Author: Susannah Matt; Ryan Dowd; Jonathan Semon

Published: 2026-09-15T13:00:00Z

Content type: news

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Security](<https://devfeed.tech/topics/security.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>)

Tags: [huntress](<https://devfeed.tech/tags/huntress.md>), [mac](<https://devfeed.tech/tags/mac.md>), [malware](<https://devfeed.tech/tags/malware.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

A Huntress investigation examines how a threat actor used a malicious custom sidebar in a real Google Doc to distribute different malware chains to macOS and Windows users. The reported campaign involved an AMOS infostealer on macOS and a PowerShell-based loader chain on Windows.

### Source excerpt

A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.

## 35 Actionable Password Statistics for Businesses in 2026 | Huntress

DevFeed: [35 Actionable Password Statistics for Businesses in 2026 | Huntress](<https://devfeed.tech/articles/35-actionable-password-statistics-for-businesses-in-2026-huntress-54518.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/password-statistics>)

Author: Brenda Buckman

Published: 2026-09-10T13:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [business](<https://devfeed.tech/tags/business.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [hygiene](<https://devfeed.tech/tags/hygiene.md>), [password](<https://devfeed.tech/tags/password.md>)

### AI overview

This article presents password-security statistics from several reports, covering weak and reused passwords, predictable patterns, stolen credentials, infostealers, and password-hygiene practices for protecting personal and business accounts.

### Source excerpt

The top password statistics might surprise you. Learn how common poor password hygiene is, plus tips to better protect your precious credentials.

## Grand Theft Auto VI hype leads to malware

DevFeed: [Grand Theft Auto VI hype leads to malware](<https://devfeed.tech/articles/grand-theft-auto-vi-hype-leads-to-malware-54344.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/fake-gta6-download-malware-analysis>)

Author: Matt Poto; Ben Nahorney

Published: 2026-09-09T14:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Search engine optimization (SEO)](<https://devfeed.tech/topics/seo.md>), [Disk image](<https://devfeed.tech/topics/disk-image.md>)

Tags: [browser](<https://devfeed.tech/tags/browser.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [iso](<https://devfeed.tech/tags/iso.md>), [malware](<https://devfeed.tech/tags/malware.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [seo](<https://devfeed.tech/tags/seo.md>)

### AI overview

Huntress analyzes malware distributed through fake GTA6 downloads promoted with SEO poisoning, gaming forums, torrent sites, and social media. The ISO sample contained a fake installer, remote access trojans, an infostealer, and wiper ransomware.

### Source excerpt

Threat actors are exploiting GTA6 hype with fake leaked downloads spread via SEO poisoning, packed with RATs, infostealers, and wiper ransomware. Here's what Huntress found.

## Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

DevFeed: [Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence](<https://devfeed.tech/articles/phishing-attacks-serve-browser-in-the-browser-pages-rogue-rmm-persistence-54522.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/phishing-bitb-rmm-attacks>)

Author: Sarah Reddish

Published: 2026-09-09T13:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [browser](<https://devfeed.tech/topics/browser.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [CSS](<https://devfeed.tech/topics/css.md>), [HTML](<https://devfeed.tech/topics/html.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [css](<https://devfeed.tech/tags/css.md>), [html](<https://devfeed.tech/tags/html.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [incident](<https://devfeed.tech/tags/incident.md>), [indicators-of-compromise](<https://devfeed.tech/tags/indicators-of-compromise.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

The article examines two browser-in-the-browser phishing incidents in which attackers used fake browser windows and staged landing pages to persuade targets to download ScreenConnect installers. The resulting rogue remote-management instances and defense-evasion binaries enabled persistence on affected endpoints.

### Source excerpt

See how a browser-in-the-browser phishing attack led to rogue ScreenConnect persistence and evasion tactics Huntress caught in the act.

## Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity

DevFeed: [Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity](<https://devfeed.tech/articles/rogue-screenconnect-installations-across-unrelated-hosts-suggest-worm-like-activity-54555.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/rogue-screenconnect-installations>)

Author: John Hammond; Andrew Brandt; Lindsey O'Donnell-Welch

Published: 2026-09-09T01:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Security](<https://devfeed.tech/topics/security.md>), [remote access](<https://devfeed.tech/topics/remote-access.md>), [execution](<https://devfeed.tech/topics/execution.md>), [file](<https://devfeed.tech/topics/file.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Process](<https://devfeed.tech/topics/process.md>)

Tags: [client](<https://devfeed.tech/tags/client.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cvss](<https://devfeed.tech/tags/cvss.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [incident](<https://devfeed.tech/tags/incident.md>), [monitor](<https://devfeed.tech/tags/monitor.md>), [security](<https://devfeed.tech/tags/security.md>), [unrelated](<https://devfeed.tech/tags/unrelated.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [windows](<https://devfeed.tech/tags/windows.md>), [worm](<https://devfeed.tech/tags/worm.md>)

### AI overview

Huntress reports rogue ScreenConnect installations and unusual process execution across unrelated organizations. ConnectWise identified a file-transfer authorization flaw in affected ScreenConnect sessions and advised organizations to upgrade to version 26.6.5 or disable the relevant file-transfer permission while applying interim guidance.

### Source excerpt

Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.

## Inside Knight Office, a New M365 AiTM Phishing Kit

DevFeed: [Inside Knight Office, a New M365 AiTM Phishing Kit](<https://devfeed.tech/articles/inside-knight-office-a-new-m365-aitm-phishing-kit-54426.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/inside-knight-office-m365-aitm-attack>)

Author: Andrew Brandt; Andrea Hatcher; Lindsey O'Donnell-Welch

Published: 2026-09-02T13:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cloaked Ursa](<https://devfeed.tech/topics/cloaked-ursa.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>), [Python](<https://devfeed.tech/topics/python.md>), [Flask](<https://devfeed.tech/topics/flask.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [dashboard](<https://devfeed.tech/tags/dashboard.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [flask](<https://devfeed.tech/tags/flask.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [python](<https://devfeed.tech/tags/python.md>), [security-operations-center-soc](<https://devfeed.tech/tags/security-operations-center-soc.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

Huntress investigates Knight Office, an AiTM phishing kit used to steal Microsoft 365 session tokens. The report describes its phishing infrastructure, operator console, Entra ID persistence techniques, and Python Flask implementation.

### Source excerpt

An inside look at Knight Office, a newly discovered AiTM phishing kit featuring custom control panels, Cloudflare Turnstile, and M365 Token theft.

## The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT

DevFeed: [The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT](<https://devfeed.tech/articles/the-crypto-wallet-that-never-opened-tampered-exodus-installer-hides-a-modular-rat-54331.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/exodus-crypto-wallet-installer-rat>)

Author: Jonathan Semon; Jose Oregon

Published: 2026-09-01T04:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [browser](<https://devfeed.tech/topics/browser.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [installer](<https://devfeed.tech/tags/installer.md>), [malicious-javascript](<https://devfeed.tech/tags/malicious-javascript.md>), [manage](<https://devfeed.tech/tags/manage.md>), [modular](<https://devfeed.tech/tags/modular.md>), [msi](<https://devfeed.tech/tags/msi.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [rat](<https://devfeed.tech/tags/rat.md>), [scheduled](<https://devfeed.tech/tags/scheduled.md>), [solana](<https://devfeed.tech/tags/solana.md>), [wallet](<https://devfeed.tech/tags/wallet.md>)

### AI overview

Huntress investigates tampered Exodus Wallet installers that conceal a modular remote access trojan. The malware uses decoy documents and a legitimate wallet installation to hide activity while stealing browser credentials across compromised Windows environments.

### Source excerpt

Exodus crypto wallet analysis by Huntress uncovered tampered installers hiding a modular RAT focused on stealing credentials, not coins.

## Modern Phishing Tactics Include ClickFix, Browser Manipulation, and OAuth Consent Phishing

DevFeed: [Modern Phishing Tactics Include ClickFix, Browser Manipulation, and OAuth Consent Phishing](<https://devfeed.tech/articles/next-gen-phishing-tactics-users-aren-t-ready-for-huntress-54184.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/advanced-phishing-tradecraft>)

Author: Shannon Grey; James O'Leary

Published: 2026-08-28T16:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>), [Terminal](<https://devfeed.tech/topics/terminal.md>), [browser](<https://devfeed.tech/topics/browser.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [credential-harvesting](<https://devfeed.tech/tags/credential-harvesting.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [terminal](<https://devfeed.tech/tags/terminal.md>)

### AI overview

This article describes how modern phishing campaigns use browser manipulation, malicious cloud-app consent requests, social engineering, and ClickFix attacks to bypass traditional defenses. It also explains how Huntress SAT scenarios simulate these tactics to train users.

### Source excerpt

Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing--and how to train your users with Huntress SAT.

## New Huntress Managed ITDR Dashboard: Faster Identity Investigations

DevFeed: [New Huntress Managed ITDR Dashboard: Faster Identity Investigations](<https://devfeed.tech/articles/new-huntress-managed-itdr-dashboard-faster-identity-investigations-54476.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/managed-itdr-dashboard-redesigned>)

Author: Erin Meyers

Published: 2026-08-27T14:00:00Z

Content type: release

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [dashboards](<https://devfeed.tech/topics/dashboards.md>), [Security](<https://devfeed.tech/topics/security.md>), [Security Information and Event Management (SIEM)](<https://devfeed.tech/topics/siem-security.md>), [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>), [self-service](<https://devfeed.tech/topics/self-service.md>)

Tags: [dashboard](<https://devfeed.tech/tags/dashboard.md>), [failed](<https://devfeed.tech/tags/failed.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [identity](<https://devfeed.tech/tags/identity.md>), [investigations](<https://devfeed.tech/tags/investigations.md>), [launch](<https://devfeed.tech/tags/launch.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>), [triage](<https://devfeed.tech/tags/triage.md>)

### AI overview

Huntress launched a redesigned Managed ITDR dashboard with Rapid Identity Triage, Failed Login Characterization, and Quick SIEM search to help customers investigate identity activity faster.

### Source excerpt

Huntress' redesigned Managed ITDR dashboard adds Rapid Identity Triage, Failed Login Characterization, and Quick SIEM search for faster investigations.

## Huntress Investigation Examines Suspected DPRK Remote Workers

DevFeed: [Huntress Investigation Examines Suspected DPRK Remote Workers](<https://devfeed.tech/articles/insights-into-suspected-dprk-workers-54398.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/huntress-dprk-remote-worker-investigation>)

Author: Jai Minton; James Maclachlan

Published: 2026-08-26T04:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [account](<https://devfeed.tech/topics/account.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [detection](<https://devfeed.tech/tags/detection.md>), [dprk](<https://devfeed.tech/tags/dprk.md>), [github](<https://devfeed.tech/tags/github.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [identity](<https://devfeed.tech/tags/identity.md>), [investigations](<https://devfeed.tech/tags/investigations.md>), [remote](<https://devfeed.tech/tags/remote.md>), [threats](<https://devfeed.tech/tags/threats.md>)

### AI overview

Huntress analyzes incidents involving suspected North Korean remote workers who used deceptive identities to obtain jobs and funnel wages to the DPRK. The investigation describes indicators that may help organizations detect and prevent related threats.

### Source excerpt

Huntress analyzed several incidents involving DPRK remote workers (Famous Chollima) in partner environments. Learn key indicators to detect and prevent North Korean threats.

## New View for Security Incident Investigations

DevFeed: [New View for Security Incident Investigations](<https://devfeed.tech/articles/new-view-for-security-incident-investigations-54563.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/security-incident-investigations-partner-view>)

Author: Micah Neidhart

Published: 2026-08-24T14:00:00Z

Content type: release

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [dashboard](<https://devfeed.tech/tags/dashboard.md>), [export](<https://devfeed.tech/tags/export.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [incident](<https://devfeed.tech/tags/incident.md>), [investigations](<https://devfeed.tech/tags/investigations.md>), [pdf](<https://devfeed.tech/tags/pdf.md>), [reports](<https://devfeed.tech/tags/reports.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>)

### AI overview

Huntress introduces a redesigned Investigations View and Dashboard that let partners review security investigations from the initial signal through final resolution. The view includes chronological timelines, analyst notes, incident reports, remediation steps, resolution status, search and filters, KPIs, and PDF export, including investigations closed as benign.

### Source excerpt

See how the Huntress SOC runs security incident investigations from first signal to final resolution, including the ones closed as benign.

## RMM Abuse: How Attackers Exploit Remote Access Tools | Huntress

DevFeed: [RMM Abuse: How Attackers Exploit Remote Access Tools | Huntress](<https://devfeed.tech/articles/rmm-abuse-how-attackers-exploit-remote-access-tools-huntress-54552.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/rmm-abuse-trusted-tools-untrusted-hands>)

Author: Beth Robinson

Published: 2026-08-21T17:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [remote access](<https://devfeed.tech/topics/remote-access.md>), [Security](<https://devfeed.tech/topics/security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>)

Tags: [huntress](<https://devfeed.tech/tags/huntress.md>), [malware](<https://devfeed.tech/tags/malware.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

The article explains how attackers abuse legitimate remote monitoring and management tools to gain stealthy access, evade detection, and support social-engineering campaigns. It describes the risks of trusted remote access software and cites reported increases in this attack tactic.

### Source excerpt

RMM abuse jumped 277% & now shows up nearly 40% of Huntress investigations. See how attackers exploit trusted remote access tools, and how to stop it.

## Huntress and the FBI Pursued Silk Typhoon After a Microsoft Exchange Attack Exposed 88,000 Backdoors

DevFeed: [Huntress and the FBI Pursued Silk Typhoon After a Microsoft Exchange Attack Exposed 88,000 Backdoors](<https://devfeed.tech/articles/five-years-88-000-backdoors-and-a-pair-of-handcuffs-inside-the-global-manhunt-that-ended-in-an-arrest-54290.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/declassified-cybercrime-episode-three>)

Author: Beth Robinson

Published: 2026-08-10T13:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Security](<https://devfeed.tech/topics/security.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Server](<https://devfeed.tech/topics/server.md>)

Tags: [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [fbi](<https://devfeed.tech/tags/fbi.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [incident](<https://devfeed.tech/tags/incident.md>), [law-enforcement](<https://devfeed.tech/tags/law-enforcement.md>), [microsoft-exchange](<https://devfeed.tech/tags/microsoft-exchange.md>), [national-security](<https://devfeed.tech/tags/national-security.md>), [security](<https://devfeed.tech/tags/security.md>), [servers](<https://devfeed.tech/tags/servers.md>)

### AI overview

Huntress and the FBI investigated a Microsoft Exchange exploitation campaign attributed to Silk Typhoon after it created 88,000 backdoors. The article describes the public-private response, victim notification efforts, and the FBI's court-authorized removal of malicious web shells from vulnerable servers.

### Source excerpt

Go inside Huntress and the FBI's five-year pursuit of Silk Typhoon, from 88,000 Exchange backdoors to an arrest and a wider fight against cybercrime.

## Huntress Tracks Device Code Phishing Activity Linked to BL Networks

DevFeed: [Huntress Tracks Device Code Phishing Activity Linked to BL Networks](<https://devfeed.tech/articles/device-code-phishing-keeps-evolving-here-s-what-to-watch-for-54302.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/device-code-phishing-evolving-threats>)

Author: Casey Smith

Published: 2026-07-31T13:00:00Z

Content type: news

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Authentication](<https://devfeed.tech/topics/authentication.md>), [microsoft 365](<https://devfeed.tech/topics/microsoft-365.md>), [Network](<https://devfeed.tech/topics/network.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [device-code-phishing](<https://devfeed.tech/tags/device-code-phishing.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-365](<https://devfeed.tech/tags/microsoft-365.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

Huntress reports an evolving wave of device code phishing targeting Microsoft 365 authentication, with activity linked to BL Networks and earlier activity associated with Railway and EvilTokens.

### Source excerpt

Huntress is tracking an evolving wave of device code phishing that abuses trusted Microsoft 365 sign-in flows. Learn the signals defenders should watch for and how to respond.

## Huntress outlines an AI- and partnership-led strategy for expanding cybersecurity protection

DevFeed: [Huntress outlines an AI- and partnership-led strategy for expanding cybersecurity protection](<https://devfeed.tech/articles/huntress-hits-an-inflection-point-54399.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/huntress-inflection-point-future-momentum>)

Author: Kyle Hanslovan

Published: 2026-07-30T15:00:00Z

Content type: opinion

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [API](<https://devfeed.tech/topics/api.md>), [Risk](<https://devfeed.tech/topics/risk.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [api](<https://devfeed.tech/tags/api.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [community](<https://devfeed.tech/tags/community.md>), [cyberattacks](<https://devfeed.tech/tags/cyberattacks.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [partnerships](<https://devfeed.tech/tags/partnerships.md>), [revenue](<https://devfeed.tech/tags/revenue.md>), [security](<https://devfeed.tech/tags/security.md>), [strategy](<https://devfeed.tech/tags/strategy.md>)

### AI overview

Huntress CEO Kyle Hanslovan describes the company's next phase after reaching $250 million in annual recurring revenue. He emphasizes AI with human oversight, API-powered coordination, global telemetry, research, and a broader partner network to respond faster to automated cyberattacks.

### Source excerpt

CEO Kyle Hanslovan outlines how Huntress is evolving its research-led strategy, adopting AI with human oversight, and expanding its partner network to protect businesses against rapid, automated cyberattacks.

## $250M ARR Was Never the Goal. It Came From Staying True to Our Mission.

DevFeed: [$250M ARR Was Never the Goal. It Came From Staying True to Our Mission.](<https://devfeed.tech/articles/250m-arr-was-never-the-goal-it-came-from-staying-true-to-our-mission-54232.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/business-reflection-250m-arr>)

Author: Kyle Hanslovan

Published: 2026-07-30T14:00:00Z

Content type: opinion

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [business](<https://devfeed.tech/tags/business.md>), [ceo](<https://devfeed.tech/tags/ceo.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [growth](<https://devfeed.tech/tags/growth.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [mission](<https://devfeed.tech/tags/mission.md>), [revenue](<https://devfeed.tech/tags/revenue.md>), [scale](<https://devfeed.tech/tags/scale.md>)

### AI overview

Huntress CEO Kyle Hanslovan reflects on the company's growth to $250 million in annual recurring revenue, arguing that the milestone followed its mission to provide cybersecurity protection and expertise to underserved small and mid-sized businesses.

### Source excerpt

Hitting $250M ARR is a milestone, but it wasn't the goal. CEO Kyle Hanslovan reflects on Huntress' mission to protect the 99% and why staying true to it remains his top priority."

## Introducing Huntress Webhooks. Get Real-Time Security Alerts.

DevFeed: [Introducing Huntress Webhooks. Get Real-Time Security Alerts.](<https://devfeed.tech/articles/introducing-huntress-webhooks-get-real-time-security-alerts-54431.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/introducing-huntress-webhooks>)

Author: Micah Neidhart

Published: 2026-07-29T14:00:00Z

Content type: release

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Security Information and Event Management (SIEM)](<https://devfeed.tech/topics/siem-security.md>), [API](<https://devfeed.tech/topics/api.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [notifications](<https://devfeed.tech/topics/notifications.md>), [JSON](<https://devfeed.tech/topics/json.md>), [Slack](<https://devfeed.tech/topics/slack.md>), [n8n](<https://devfeed.tech/topics/n8n.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [automation](<https://devfeed.tech/tags/automation.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [json](<https://devfeed.tech/tags/json.md>), [latency](<https://devfeed.tech/tags/latency.md>), [low-latency](<https://devfeed.tech/tags/low-latency.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>), [slack](<https://devfeed.tech/tags/slack.md>), [webhooks](<https://devfeed.tech/tags/webhooks.md>)

### AI overview

Huntress Webhooks push incidents, escalations, platform actions, and account notices to customer-provided endpoints in real time. The release describes integrations with Slack, PSAs, automation platforms, and SIEM workflows, using structured JSON payloads without polling.

### Source excerpt

Huntress Webhooks push incidents and escalations straight to Slack, your PSA, or SIEM in real time with no polling. See how you can set them up in minutes.

## Credential Stuffing Campaign Hits SonicWall | Huntress SOC Tracking

DevFeed: [Credential Stuffing Campaign Hits SonicWall | Huntress SOC Tracking](<https://devfeed.tech/articles/credential-stuffing-campaign-hits-sonicwall-huntress-soc-tracking-54575.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/sonicwall-credential-stuffing-campaign>)

Author: Jevon Ang; Ethan Williams

Published: 2026-07-28T13:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [Virtual Private Network](<https://devfeed.tech/topics/vpn.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [remote access](<https://devfeed.tech/topics/remote-access.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Security Information and Event Management (SIEM)](<https://devfeed.tech/topics/siem-security.md>), [Network](<https://devfeed.tech/topics/network.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Digital Ocean](<https://devfeed.tech/topics/digital-ocean.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [automated](<https://devfeed.tech/tags/automated.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [devices](<https://devfeed.tech/tags/devices.md>), [digitalocean](<https://devfeed.tech/tags/digitalocean.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [incident](<https://devfeed.tech/tags/incident.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [ip](<https://devfeed.tech/tags/ip.md>), [network](<https://devfeed.tech/tags/network.md>), [organizations](<https://devfeed.tech/tags/organizations.md>), [remote](<https://devfeed.tech/tags/remote.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [soc](<https://devfeed.tech/tags/soc.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [vpn](<https://devfeed.tech/tags/vpn.md>)

### AI overview

Huntress reports an active, opportunistic credential-stuffing campaign targeting SonicWall VPN and firewall login portals. The campaign compromised dozens of organizations beginning July 25, 2026, using infrastructure associated with DigitalOcean.

### Source excerpt

The Huntress SOC is tracking an active credential stuffing campaign targeting SonicWall devices, compromising dozens of organizations since July 25.

## CMMC Updates: DoW Pause and Huntress Hits 50% of Requirements

DevFeed: [CMMC Updates: DoW Pause and Huntress Hits 50% of Requirements](<https://devfeed.tech/articles/cmmc-updates-dow-pause-and-huntress-hits-50-of-requirements-54401.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/huntress-managed-ispm-cmmc-compliance>)

Author: Jeremy Young

Published: 2026-07-24T14:00:00Z

Content type: opinion

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [audit](<https://devfeed.tech/topics/audit.md>), [Protection](<https://devfeed.tech/topics/protection.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [dow](<https://devfeed.tech/tags/dow.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [incident](<https://devfeed.tech/tags/incident.md>), [nist](<https://devfeed.tech/tags/nist.md>), [protection](<https://devfeed.tech/tags/protection.md>)

### AI overview

The U.S. Department of War paused the November 2026 CMMC certification deadline, but existing CUI protection, NIST SP 800-171, DFARS, self-assessment, and prime-contractor obligations remain. The article explains the implications for suppliers and notes Huntress's reported coverage of 55 of 110 requirements.

### Source excerpt

DoW paused the CMMC Phase II deadline in July, but the underlying compliance obligations didn't move. Meanwhile, Huntress Managed ISPM pushes our NIST SP 800-171 coverage to 55 of 110 requirements. Here's what changed, what didn't, and why we're not slowing down.

## Huntress Uses AI Agents to Triage SOC Signals Before Analyst Review

DevFeed: [Huntress Uses AI Agents to Triage SOC Signals Before Analyst Review](<https://devfeed.tech/articles/how-we-cut-noise-before-it-hits-the-analyst-54193.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/ai-signal-triage>)

Author: Spencer Engleson; Aimee Simpson

Published: 2026-07-20T14:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Security](<https://devfeed.tech/topics/security.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [soc](<https://devfeed.tech/tags/soc.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [triage](<https://devfeed.tech/tags/triage.md>)

### AI overview

Huntress describes Athena, an agentic investigation system of more than 40 specialized agents that automates SOC triage work before analysts review cases. The system groups related suspicious signals into investigations using shared characteristics such as processes, source IPs, and attack patterns.

### Source excerpt

Learn how Huntress' AI signal triage and AI-powered SOC triage cut noise before it reaches human analysts. And discover why that matters for response times.

## Microsoft 365 Conditional Access Gaps Enabled Device Code Phishing and ROPC Attacks

DevFeed: [Microsoft 365 Conditional Access Gaps Enabled Device Code Phishing and ROPC Attacks](<https://devfeed.tech/articles/conditional-access-misconfigurations-exposed-55-orgs-with-mfa-on-54254.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/conditional-access-misconfigurations>)

Author: Aimee Simpson; Scott Riley; Rich Mozeleski

Published: 2026-07-09T14:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [microsoft 365](<https://devfeed.tech/topics/microsoft-365.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [device-code-phishing](<https://devfeed.tech/tags/device-code-phishing.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-365](<https://devfeed.tech/tags/microsoft-365.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Huntress describes two Microsoft 365 attack campaigns that bypassed or avoided MFA because Conditional Access policies did not explicitly block vulnerable authentication flows. The campaigns used device code phishing and the deprecated ROPC OAuth flow, with infrastructure including Railway IP addresses and an IPv6 range associated with LSHIY LLC.

### Source excerpt

Two Microsoft 365 attacks got through Conditional Access policies that seemed fully configured. Learn what went wrong and how Huntress Managed ISPM catches these gaps first.

## Meta Phishers Abuse Business Account Manager Service | Huntress

DevFeed: [Meta Phishers Abuse Business Account Manager Service | Huntress](<https://devfeed.tech/articles/meta-phishers-abuse-business-account-manager-service-huntress-54482.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/meta-business-manager-phishing>)

Author: Andrew Brandt

Published: 2026-07-07T12:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Meta](<https://devfeed.tech/topics/meta.md>), [service](<https://devfeed.tech/topics/service.md>), [email](<https://devfeed.tech/topics/email.md>), [Chat Bot](<https://devfeed.tech/topics/chatbot.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [email](<https://devfeed.tech/tags/email.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [messaging](<https://devfeed.tech/tags/messaging.md>), [meta](<https://devfeed.tech/tags/meta.md>), [over](<https://devfeed.tech/tags/over.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [social-media](<https://devfeed.tech/tags/social-media.md>), [telegram](<https://devfeed.tech/tags/telegram.md>)

### AI overview

Huntress investigates a phishing campaign that abused Meta's business partner service to send seemingly legitimate emails and steal Meta account credentials. The attackers used phishing pages, Telegram for credential delivery, and later added a chatbot component.

### Source excerpt

Huntress is tracking a threat actor group as they evolve a phishing attack that uses a Facebook feature to send the initial spam lure.

## Celebrating Canada Day with Localized Managed Phishing

DevFeed: [Celebrating Canada Day with Localized Managed Phishing](<https://devfeed.tech/articles/celebrating-canada-day-with-localized-managed-phishing-54233.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/canada-localized-managed-phishing>)

Author: James O'Leary

Published: 2026-07-02T12:00:00Z

Content type: release

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Risk](<https://devfeed.tech/topics/risk.md>), [Users](<https://devfeed.tech/topics/users.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>)

Tags: [canada](<https://devfeed.tech/tags/canada.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [training](<https://devfeed.tech/tags/training.md>)

### AI overview

Huntress Managed SAT is expanding its Managed Phishing service to Canada with English-language simulations based on familiar Canadian brands and scenarios. The company says localized lures are intended to improve engagement and help learners recognize phishing risk in a controlled environment.

### Source excerpt

Huntress Managed SAT now offers localized phishing simulations for Canada, using familiar, country-specific brands and scenarios to provide more effective security awareness training for your learners.

[Next page](<https://devfeed.tech/tags/huntress.md?cursor=WyIyMDI2LTA3LTAyVDEyOjAwOjAwKzAwOjAwIiwgIjIwMDQ0ZTc2LTUxZDAtNGQ1Mi05NGIyLWY4YzM3NTZhY2E4NiJd>)