daily cyber × ai intelligence

index

tagged

[huntress]

16 editions · 22 items

September 8, 2026

  • N-able N-central shipped Hotfix 4 (build 2026.3.1.14) in the early hours of 6 September UTC for CVE-2026-86218, a static code injection flaw (CWE-96) rated CVSS 4.0 10.0 by N-able as CNA, allowing unauthenticated RCE on the N-central server. Every on-prem build below 2026.3.1.14 is affected, including servers patched to Hotfix 3 roughly eight hours earlier; hosted NCOD instances are already patched. The release notes say a third party disclosed it and that N-able has "no confirmations" of production exploitation, while the incident notice on the status page says the flaw "has been observed being exploited in the wild" (The Hacker News, BleepingComputer). No IoCs, no interim mitigation, no detection guidance beyond auditing N-central user accounts. Huntress, tracking N-central attacks since August, says it reproduced a PoC exploit chain against build 2026.3.1.10 but the appliance logs had rotated, leaving it unable to say which CVE was used; it advises IP allowlisting or VPN-only access to the console (earlier coverage). · Vulnerabilities & Exploits
  • ConnectWise ScreenConnect has an unpatched flaw in file-transfer behaviour affecting both cloud and on-prem, with no CVE assigned and a fix promised later this week. The interim mitigation is to deselect the TransferFiles (or legacy TransferFilesInSession) scoped permission on every role and session group. Shadowserver tracks nearly 6,000 internet-exposed instances (BleepingComputer). Separately, Huntress detailed the worm-like rogue-client activity from three unrelated August incidents: a four-stage VBScript chain (1.vbs4.vbs) where stage one profiles RAM, checks for existing ScreenConnect installs and enumerates Cisco AMP, CrowdStrike, Huntress, Malwarebytes, SentinelOne, Sophos and Symantec into a three-bit state variable in %TEMP%\value.txt (The Hacker News, earlier coverage). · Vulnerabilities & Exploits

in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited

September 6, 2026

  • A new N-able N-central chain can create unauthorized administrator accounts. Huntress built a PoC combining CVE-2026-86206 and CVE-2026-86207, which it says is distinct from the August flaws. Huntress says a hotfix is available; its follow-up recommends hunting for anomalous accounts using .invalid email addresses. · Vulnerabilities & Exploits
  • Huntress reached the Knight Office login console by pivoting from an IP seen in an adversary-in-the-middle incident. Its phishing-kit investigation offers identity defenders a concrete view of the infrastructure behind session and credential theft. Huntress · Threat Activity

in One Loophole, 100 Agents, 27 Minutes

August 10, 2026

  • A pre-auth RCE PoC is circulating for macOS Screen Sharing (CVE-2026-65400). Apple's fix addresses an authentication state-management bug that lets an unauthenticated network attacker reach the service without valid credentials; patched in Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1 (NCSC-NL advisory). Huntress urges immediate patching and has shared detection guidance (Huntress). · Offensive & Exploitation

in ResetNightmare PoC Drops at Black Hat: One Kerberos Flaw, Any Account's Password Reset

August 4, 2026

  • N-able N-central auth bypass (CVE-2026-18577) is under active exploitation, and the first fix didn't hold. Over the weekend N-able discovered a second authentication-bypass vector that grants attackers administrator access to both hosted and on-prem N-central servers, letting them reach the customer systems those servers manage; build 2026.3.1.7 (shipped Aug 2) is the first unaffected version (The Hacker News, BleepingComputer). Huntress has published exploitation details and detection guidance (Huntress). Continues our earlier coverage. · Vulnerabilities & Exploits
  • Unpatched NTLM leak via the Windows search: URI handler — no CVE, no fix. Huntress details a coercion primitive functionally identical to CVE-2026-33829 but closed without a CVE, with arguably higher real-world risk; mitigations include blocking outbound SMB, enforcing SMB signing, disabling NTLM, and monitoring URI-handler activity (Huntress). · Vulnerabilities & Exploits

in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short

July 29, 2026

  • Huntress declassified its role in an FBI manhunt tied to the 2021 Silk Typhoon Exchange campaign — which it puts at 88,000 compromised servers, far beyond the "limited and targeted" framing at the time — ending in the arrest of a state-backed operator (Huntress). · Threat Activity
  • Huntress is also tracking an active SonicWall credential-stuffing campaign that has produced successful unauthorized logins to VPN and firewall accounts across dozens of organizations; the blog carries IOCs (Huntress). · Threat Activity

in Artifactory Zero-Days Confirmed as the Hugging Face AI Agent's Escape Route

July 4, 2026

  • LDAP Ping (cLDAP) is a blind spot for AD detection. Huntress researchers (@HuntressLabs, @4ndr3w6S) showed that using LDAP Ping to enumerate AD usernames leaves no trace in Windows audit logs — requests are handled by netlogon.dll rather than ntdsa.dll, so the usual Event 1644 never fires. The pre-auth, no-credentials technique yields confirmed account names for follow-on password spraying and BloodHound/PowerView recon; traffic is still visible at the network level (UDP/389, WFP traces). Huntress · Offensive & Red Team

in Silent Active Directory Recon and a Near-Perfect Linux Root Exploit Lead the Offensive Beat

July 2, 2026

  • Huntress is tracking an ongoing, automated password-spray campaign against Azure CLI, abusing the OAuth ROPC flow (which bypasses MFA) from an IPv6 range (2a0a:d683::/32) attributed to LSHIY LLC / AS32167 and linked to China. Over 81 million login attempts between June 12–26 compromised at least 78 Microsoft accounts across ~64–78 orgs. Recommended mitigations: enforce comprehensive MFA and block ROPC. Huntress, BleepingComputer. · Cloud & Identity

in Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US

June 23, 2026

  • Klue breach fallout widens to a who's-who of security vendors — after Icarus posted stolen data on June 22, affected Klue customers now include HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium. Huntress says no product data, telemetry, passwords, or card data were touched — exposure is limited to business metadata (names, products trialed, subscription/pricing, sales notes) — and warns the data is ripe for Klue/Huntress impersonation. SecurityWeek · Huntress · Threat Intelligence

in Five Eyes Warns Frontier AI Will Reshape Offensive Cyber Ops as a New Entra ID Conditional Access Bypass Surfaces

June 21, 2026

  • Klue, a competitive-intelligence platform, confirmed attackers stole OAuth tokens used to connect to customers' Salesforce environments, and the new Icarus extortion group has claimed it (BleepingComputer). Salesforce disabled the Klue Battlecards integration on June 11; this is the third Salesforce-connected app abused for CRM data theft, and confirmed victims include security vendors Huntress and Recorded Future (SecurityWeek, The Hacker News). · Cloud & Identity
  • ClickFix campaigns expanded with three new loaders — BabaDeda, Lorem Ipsum, and Potemkin — per Morphisec, BlueVoyant, and Huntress, with the Lorem Ipsum activity possibly tied to Vice Society (The Hacker News). Microsoft also detailed CryptoBandits, a USB-LNK worm spreading a Windows clipper that uses Windows Script Host, ActiveX, and a bundled Tor proxy for C2 (BleepingComputer). · Threat Intelligence
  • Huntress walked through containing a real intrusion at a nursing-facility network: initial access via an exposed RDWeb portal and a compromised test account, followed by RDP lateral movement, enumeration, and persistence attempts — caught and shut down by Managed EDR, Defender telemetry, and SOC response that disabled accounts and blocked the attacker IP before full compromise (Huntress). A useful reminder that internet-exposed RDWeb plus weak test accounts remains a top initial-access path. · Detection & Purple Team

in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog

June 20, 2026

FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token

FortiBleed has compromised ~86,644 internet-facing FortiGate devices in a credential-harvesting campaign, while a leaked GitHub token gave FulcrumSec access to Novo Nordisk, exfiltrating 1.3TB including unreleased drug formulas and internal AI models. Mastra npm packages were trojanized by Sapphire Sleet (North Korea–nexus), and multiple AI infrastructure flaws emerged: SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot, Pickle in the Middle in Google Vertex AI, and vulnerabilities in LiteLLM. Ransomware gangs including Qilin, Gentlemen, and DragonForce continue dominating the threat landscape with EDR-killing tradecraft and cloud-based C2 abuse.