Huntress Labs
huntress · B · active
Huntress IR/EDR; strong on early SMB-targeting waves. The /blog landing renders only a partial article list with inconsistent date display via the routine fetcher, drill into individual posts (e.g. /blog/<slug>) to confirm dates. RSS feed at https://www.huntress.com/blog/rss.xml is the cleanest dated index. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → rss: python3 tools/fetch_source.py feed https://www.huntress.com/blog/rss.xml 5 (then WebFetch the /blog/<slug> URL for the body).. AVOID: Don't scrape the /blog landing (partial list, inconsistent dates), the rss.xml is the clean dated index.. | 2026-07-05 admiralty audit: B, original IR/EDR telemetry research; filter product/marketing posts. HIGH->B, stays active. | 2026-08-24 weekly: fetch_method was `rss` with rss_url null, so the documented transport had no URL and the source could not be swept by feed. Probed and verified https://www.huntress.com/blog/rss.xml (direct, 3 dated items). rss_url set. | 2026-09-07: drove this run's critical N-able N-central deep-dive entry (live-blog updates on CVE-2026-86206/86207/86218); S1 independently suggested this as a new candidate source under id 'huntress-blog', not realizing it was already tracked here, no duplicate added.
Cited in 16 entries
Citation cadence
Citation days per ISO week (16 weeks of coverage span, total 14).
- CVE-2026-84869, ConnectWise ScreenConnect: a missing file-transfer authorization check lets an active remote session push and auto-run files on the Host, and Huntress traced worm-like exploitation back to 20 August, weeks before any patch existed (CVSS 9.9)2026-09-12
- CVE-2026-86206 / CVE-2026-86207 / CVE-2026-86218, N-able N-central: a third, unrelated auth-bypass/RCE chain in five weeks, the third CVE a pre-auth CVSS 10.0 zero-day N-able says is already exploited2026-09-07
- CVE-2026-82078 / CVE-2026-81578, PaperCut NG/MF: an Apache Tapestry request-routing confusion chains an unauthenticated config rewrite to arbitrary code execution, exploited before a patch existed2026-08-29
- PurpleDelta: Insikt Group gets inside a North Korean IT-worker operation and finds the detectable half is on the endpoint, a second remote-management tool on the company laptop, and a device whose location never matches the login2026-08-19
- Akira blinds EDR by rebooting a victim host into Safe Mode with Networking, the operator's first observed use of the technique, and the stripped-down boot starved its own encryptor2026-08-17
- CVE-2026-65400, macOS Screen Sharing lets a network attacker authenticate without valid credentials, the second severe defect in the same daemon in two releases2026-08-08
- CVE-2026-18556 / CVE-2026-18577, N-able N-central: unauthenticated admin access to the RMM console, exploited in the wild, and the day-one fix was itself bypassable2026-08-03
- Huntress: a three-day credential-stuffing run logged into 92 SonicWall VPN and firewall accounts across 30 organisations, with no follow-on activity observed2026-07-30
- FakeAgent, malvertising hosts a fake AI-desktop-app download page on the vendor's own trusted domain, delivering SectopRAT by DLL side-loading2026-07-26
- Two 2026 M365 account-takeover campaigns (Railway device-code phishing, LSHIY ROPC spray) beat Conditional Access without breaking MFA2026-07-10
- CitrixBleed 2 (CVE-2025-5777) weaponised into a repeatable IAB kill chain ending in DragonForce ransomware (STAC3725)2026-07-10
- Klue OAuth-token breach, victim list grows, CRM-API abuse chain detailed2026-06-21
- Huntress: Potemkin loader delivers RMMProject RAT and bypasses Chromium App-Bound Encryption2026-06-17
- Huntress: Windows search: URI handler leaks NTLMv2 hashes, Microsoft declines to patch2026-06-04
- DesckVB RAT malspam launders through Google DoubleClick and blinds AMSI/ETW, with German-language lures aimed at DACH2026-06-04
- The Gentlemen ransomware, Microsoft publishes full technical dissection of the Storm-2697 Go-encryptor2026-05-29