organization · 7 records
Huntress

Microsoft Takes Down EvilTokens Device-Code Phishing Service
Microsoft and international partners took down the EvilTokens phishing-as-a-service platform that leveraged AI to facilitate large-scale business email compromise.

Critical vulnerability discovered in Cisco Secure Firewall Management Center software
CISA added a newly disclosed zero-day vulnerability in Cisco Secure Firewall Management Center to its Known Exploited Vulnerabilities catalog following reports of active exploitation.

Attackers exploit critical JFrog Artifactory vulnerability to create administrator tokens
Threat actors are exploiting a newly patched critical security flaw in JFrog Artifactory to mint administrator tokens shortly after the vulnerability was disclosed.

Hackers exploit PaperCut software vulnerabilities to steal credentials from educational institutions
Threat actors are exploiting PaperCut software vulnerabilities to conduct credential theft at educational institutions in the U.S. and Europe.

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
North Korean threat actors are expanding their remote employment fraud schemes beyond the IT sector into healthcare, sales, and marketing roles.

Attackers exploit N-central vulnerability after failed security patch
N-able disclosed that attackers exploited an authentication bypass in N-central to gain remote administrative access after an initial patch failed to fully close the vulnerability.

Report details updated DevMan ransomware portal capabilities and insider threat allegations
Swiss cybersecurity firm PRODAFT released a report on the DevMan ransomware-as-a-service operation detailing its updated portal capabilities alongside insider threat allegations involving a former Huntress employee.