Max Rogers

@maxrogers5.com

Sr. Director of SOC at Huntress. Ex-Mandiant/FireEye. Bringing security to the Fortune 5,000,000.

🚨 @HuntressLabs identified active exploitation of a Local File Inclusion vulnerability affecting Gladinet CentreStack and Triofox systems. A temporary workaround is available while a patch is in development: www.huntress.com/blog/gladine...

Active Exploitation of Gladinet CentreStack and Triofox Local File Inclusion Flaw | Huntress

Huntress has observed in-the-wild exploitation of a Local File Inclusion vulnerability in Gladinet CentreStack and Triofox products.

huntress.com

1⃣ The Huntress team uncovered a campaign by a likely China-nexus threat actor. The most novel finding is use of a publicly available tool called Nezha as a post-exploitation C2 agent. This is the first public reporting of the tool I've seen. www.huntress.com/blog/nezha-c...

The Crown Prince, Nezha: A New Tool Favored by China-Nexus Threat Actors | Huntress

Beginning in mid-2025, Huntress discovered a new tool being used to facilitate webserver intrusions known as Nezha, which up until now hasn’t been publicly reported on. This was used in tandem with ot...

huntress.com

Mac's don't get viruses, right? 🍏 Deepfake Zoom calls. AppleScript lures. Rosetta 2 abuse. Plenty of custom malware: Nim backdoor, Go infostealer, Obj-C keylogger, and more! Amazing write-up by @re.wtf , @stuartjash.bsky.social and Jonathan Semon 🔥 🔗 www.huntress.com/blog/inside-...

Inside the BlueNoroff Web3 macOS Intrusion Analysis | Huntress

Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.

huntress.com

As more companies deploy the Huntress SIEM, we've enjoyed finding the "Door Rattlers"🚪 We see an attacker failing to log in across a number of environments and then eventually succeeding in 1 organization. Stopping attacks at initial access ❤️

Huntress SIEM Door Rattling Door Rattlers Detection Initial Access Brute Force

Huntress has observed in-the-wild exploitation of CVE-2025-30406, a critical vulnerability in the Gladinet CentreStack enterprise file-sharing platform.

It pains me when organizations take their limited security budgets and get tricked into buying products that don't lead to exponential value. Heck these days, lots of VPN and Firewall products are the direct source of business ending intrusions.

Wow, we're finding some scary stuff! All credit to HuskyHacks and the rest of the #ITDR team at Huntress. For the past 6 months, Huntress has been investigating OAuth abuse – and what we found is terrifying. 🧵👇 www.huntress.com/blog/never-j...

6 Months of Researching OAuth Application Attacks | Huntress

There’s never just one termite. Huntress has spent the last 6 months researching and cracking down on malicious OAuth applications. Read about what we’ve found in this blog!

huntress.com