Huntress Labs
huntress · B · active
Huntress IR/EDR; strong on early SMB-targeting waves. The /blog landing renders only a partial article list with inconsistent date display via the routine fetcher — drill into individual posts (e.g. /blog/<slug>) to confirm dates. RSS feed at https://www.huntress.com/blog/rss.xml is the cleanest dated index. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → rss: python3 tools/fetch_source.py feed https://www.huntress.com/blog/rss.xml 5 (then WebFetch the /blog/<slug> URL for the body).. AVOID: Don't scrape the /blog landing (partial list, inconsistent dates) — the rss.xml is the clean dated index.. | 2026-07-05 admiralty audit: B — original IR/EDR telemetry research; filter product/marketing posts. HIGH->B, stays active.
Cited in 11 entries
Citation cadence
Citation days per ISO week (7 weeks of coverage span, total 7).
- Microsoft 365 account-takeover tradecraft converged this week on auth flows Conditional Access rarely covers — device-code, AiTM, ROPC and manager-impersonation vishing all beat MFA without breaking it2026-07-12
- Confirmed in-the-wild exploitation of internet-facing enterprise software converged this week — ColdFusion, Citrix NetScaler and Gitea all moved from 'at risk' to 'under attack'2026-07-12
- Looking ahead — 2026-W282026-07-12
- Two 2026 M365 account-takeover campaigns (Railway device-code phishing, LSHIY ROPC spray) beat Conditional Access without breaking MFA2026-07-10
- CitrixBleed 2 (CVE-2025-5777) weaponised into a repeatable IAB kill chain ending in DragonForce ransomware (STAC3725)2026-07-10
- Research: ClickFix matured into a productised malware-as-a-service supply chain2026-06-22
- Klue OAuth-token breach — victim list grows, CRM-API abuse chain detailed2026-06-21
- Huntress: Potemkin loader delivers RMMProject RAT and bypasses Chromium App-Bound Encryption2026-06-17
- Huntress: Windows search: URI handler leaks NTLMv2 hashes — Microsoft declines to patch2026-06-04
- DesckVB RAT malspam launders through Google DoubleClick and blinds AMSI/ETW, with German-language lures aimed at DACH2026-06-04
- The Gentlemen ransomware — Microsoft publishes full technical dissection of the Storm-2697 Go-encryptor2026-05-29