We’re running nearly 1 billion Sidekiq background jobs a day to power all of the telemetry processing and detections. Can Redis scale with your workload? Here are the receipts. @mike.contribsys.com where does that rank in your experience?
Huntress
@huntress.com
Managed endpoint protection, detection and response designed to help the 99% fight back against today’s cybercriminals.
A construction company recently suffered a VPN brute-force attack, but didn't have SIEM monitoring! The absence of a SIEM led to a 18-minute gap, giving the attacker enough time to attempt to steal credentials - but fortunately the Huntress EDR shut it down.
Our SOC tackled an attempted ransomware intrusion tied to Makop ransomware tactics. Here’s what went down 👇 🎯 Initial Entry Point: Brute-forced an exposed RDP service (don’t skip reviewing your external perimeters!). 🗺️ Enumeration & Credential Targeting: Ran a network scan using netscan.exe.
🚨Samsung MagicINFO 9 Server (v21.1050.0) is still vulnerable to a publicly available PoC. We’ve observed active exploitation in the wild. Ensure your server is not internet-facing until a proper fix is available. Full details + mitigation steps ➡️ bit.ly/44nkzhL
I've confirmed Samsung's MagicINFO 21.1050 is VULNERABLE to the publicly reported POC in the blog below. ssd-disclosure.com/ssd-advisory... The media is reporting this as CVE-2024-7399, but if it is then the patch is incomplete. There is currently NO PATCH AVAILABLE!
We’ve shared many stories about exposed RDP without MFA. Why? Because it’s a common AF, threat actors waste no time exploiting it. What makes this SOC Story from a dental facility stand out: in under 30 minutes, the attack went from initial access to attempted ransomware deployment.
.@jaiminton.com is a modern-day Doc Holliday. A lawman so feared that threat actors flee at the mere mention of his name… Introducing Celestial Stealer, a notorious infostealer with a surprising connection to Huntress.
🐶 A vulnerability left an animal care facility wide open, and an attacker didn’t hesitate to pounce. Here’s how it unfolded 👇
Some good takeaways from @huntress.com’s recent Tradecraft Tuesday ft. Patrick Wardle: -The impact of Apple bringing TCC events to Endpoint Security -#Mac malware persistence techniques vs BTM -Security alert inundation for #macOS users Catch up here⤵️ www.huntress.com/blog/say-hel...
Say Hello to Mac Malware | Huntress
In this month’s Tradecraft Tuesday, we talked about how threat actors are finetuning their macOS malware in order to maintain persistent access and avoid detection by Apple’s security features.
huntress.com
Huntress continues to observe in-the-wild exploitation of CVE-2025-30406, a critical vulnerability in Gladinet CentreStack and Triofox
A threat actor brute forced a manufacturer's VPN appliance 🏭 Here’s what happened👇 📌 Successfully compromised one account for initial access 📌 Enumerated the domain, focusing on trust relationships and domain controllers 📌 Modified the registry and local firewall to enable lateral RDP movement
Exposed RDP can lead to anything—even attempted ransomware attacks. Here’s what went down at this manufacturing business👇
Huntress has observed in-the-wild exploitation of CVE-2025-30406, a critical vulnerability in the Gladinet CentreStack enterprise file-sharing platform.
Threat actors can gain access to your network through an account that’s already on your system. The built-in Windows Guest account is often overlooked because it’s usually disabled by default—but that’s exactly what makes it a stealthy tool for attackers to exploit.
Huntress researchers recently analyzed attacks involving CVE-2025-31161, a critical authentication bypass flaw in CrushFTP. 💡 We observed specific post-exploitation activity used by threat actors leveraging the flaw in the wild
CVE-2025-31161 is the latest example of a critical severity authentication bypass vulnerability in CrushFTP, a growing trend we’re seeing from attackers targeting managed file transfer (MFT) platforms.
Things you might spot in a #smishing text ⬇️ ✅ Sketchy phone number: Pretty sure the USPS isn’t sending out texts from the Philippines ✅ Unclickable links: On the off chance it actually was the USPS, they’d send a link you can click without basically having to solve a riddle
Do you detect phishing from the endpoint or the cloud? 🎣 If you’re part of our Security Operations Center, the answer’s both. Here’s an example 👇 ✅ A proactive, human-led investigation led to our SOC identifying a potentially compromised Microsoft 365 identity
A threat actor slid into a network through exposed virtual network computing (VNC). Here’s what happened 👇 ✅ They deployed C:\\Users\\<redacted>\\Music\\setup.msi to install Atera & Splashtop for persistent remote access
Here’s an example of VPN compromise 👇 ✅ It’s a super common technique we see all the time ✅ Effects businesses of every size ✅ Usually caused by a simple configuration mistake, like an account without MFA enabled Yet it can often lead to network-wide compromise 😟
Our SOC spotted a food wholesale business under duress when a threat actor was attempting to brute force an RDP server from a malicious IP address. Here’s what went down👇
Let’s keep it real: Any service you expose to the internet is fair game for attackers. They’ll target anything to get access into your environment 👇 🎯 Web applications 🎯 #VPN devices 🎯 Remote desktop gateway Here’s how to secure exposed services and wreck a hacker’s day 💪
A ransomware actor compromised a sport club’s network 🏌️ Here’s what went down 👇 ✅ They prepared to launch ransomware by deleting volume shadow copies ✅ Attempted to frustrate defenders by clearing the logs and neutralizing defenses
Threat actors target every level of government 👇 Someone convinced a user via email to run and install tools that gave them malicious remote access to an important workstation at a County Government facility. The threat actor then:
If you administer at least one Microsoft 365 tenant, you might find some surprising results if you audit your #OAuth applications 👀 Statistically speaking, there’s a good chance your tenant is infected with a rogue app that could be malicious 😱
Straight from the 2025 Cyber Threat Report It’s no longer just clicking on sketchy links you need to be aware of. In 2024: 29% of 🐟 attacks involved e-signature impersonation tactics 24% of 🐠 attacks involved malicious image-based content 8% of 🐡 attacks involved embedding malicious QR codes