Skip to content

company

Huntress

Huntress is a cybersecurity company offering managed detection and response (MDR), threat hunting, and SOC services mainly for small and midsize businesses.

Known aliases

  • huntress.com
  • Huntress Labs
  • Huntress Security Operations Center
  • Huntress SOC

Relationships

No evidence-backed relationships are recorded.

Current stories

security8 publishers

Attackers stage a RAT lure on the real chatgpt.com using a Custom GPT

Huntress traced a RAT campaign that hides its first-stage lure in a ChatGPT Custom GPT on the real chatgpt.com, across at least 40 incidents. Because the page sits on a trusted domain, blocking the ClickFix PowerShell paste is the control that works.

Perspective Coverage

8 publishers
Builder
Builder 30%
Operator
Operator 64%
Investor
Investor 6%

Reality

Evidence70
Adoption20
Hype gap+30
Incentives40
Confidence68
security4 publishers

Four days offline at a small UK plant, and the question stops being whether Iran can get in

An Iran-linked intrusion kept a British generator down for four days while US wastewater plants lost pressure across 12 states. The number that matters now is restoration time.

Perspective Coverage

4 publishers
Builder
Builder 16%
Operator
Operator 68%
Investor
Investor 16%

Reality

Evidence40
Adoption
Insufficient
Hype gap+20
Incentives55
Confidence50
security10 publishers

Chained PaperCut flaws let unauthenticated requests load attacker Java into the server process

Huntress has seen exploitation in two customer environments. One flaw hands over PaperCut's configuration without a login, the second turns that configuration into a class loader, so patching and config review are one job.

Perspective Coverage

10 publishers
Builder
Builder 27%
Operator
Operator 60%
Investor
Investor 13%

Reality

Evidence85
Adoption70
Hype gap−10
Incentives40
Confidence78
security3 publishers

Rogue ScreenConnect clients are pushing VBScripts to every endpoint that connects

ConnectWise's September 3 advisory promises a CVE and a fix within the week, so until one lands the only control is a per-role permission change. Huntress says the spread is already worm-like across newly connected machines.

Perspective Coverage

3 publishers
Builder
Builder 38%
Operator
Operator 57%
Investor
Investor 5%

Reality

Evidence68
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence64
security7 publishers

CVE-2026-86218 gives unauthenticated attackers code execution on N-able N-central consoles

N-able shipped N-central 2026.3 HF4 on Saturday and says nothing confirms production exploitation, while Huntress calls the bug a possible zero-day and has one compromised customer console whose logs had already rotated.

Perspective Coverage

7 publishers
Builder
Builder 17%
Operator
Operator 75%
Investor
Investor 8%

Reality

Evidence72
Adoption40
Hype gap+10
Incentives55
Confidence70
security8 publishers

Revolut handed over passports to a rogue account inside a real government domain

The fraudulent request passed domain authentication because it genuinely came from the agency's mail domain, sent by an account the agency had not authorised. Revolut found out only when it called the agency to check.

Perspective Coverage

8 publishers
Builder
Builder 11%
Operator
Operator 70%
Investor
Investor 19%

Reality

Evidence68
Adoption
Insufficient
Hype gap+5
Incentives55
Confidence66
security13 publishers

CISA sets a September 13 deadline for the MikroTrick RouterOS chain

Federal agencies now have three separate patch deadlines inside twelve days. The lowest-scoring pair of the five flaws added to KEV is the one with a documented 24-day intrusion campaign behind it.

Perspective Coverage

13 publishers
Builder
Builder 21%
Operator
Operator 76%
Investor
Investor 3%

Reality

Evidence68
Adoption
Insufficient
Hype gap+15
Incentives50
Confidence66

Earlier coverage

  1. A signed Windows binary can stand up a real Microsoft login and pocket the tokens

    Security · September 23, 2026 · 1 publisher

  2. One rule in CLAUDE.md lifted Huntress's API recall from 48% to 86% on the same seven tasks

    Security · September 22, 2026 · 1 publisher

  3. Huntress rebuilt a 175-endpoint INC ransomware case from scheduled tasks and a driver fragment

    Security · September 22, 2026 · 1 publisher

  4. Attackers have been pushing VBScript through live ScreenConnect sessions since August 20

    Security · September 14, 2026 · 1 publisher

  5. Three malware campaigns stage their lure pages on Claude and ChatGPT share links

    Build · September 11, 2026 · 1 publisher

  6. One Server Licensor Certificate key decrypts every document an AD RMS deployment ever protected

    Security · September 11, 2026 · 1 publisher

  7. FakeAgent delivered SectopRAT to more than 29 organisations from a page hosted on claude.ai

    Security · September 11, 2026 · 1 publisher

  8. Fake GTA 6 installer destroys files behind a staged "License not found" error

    Security · September 10, 2026 · 1 publisher

  9. Huntress found four paths to an AD RMS root key that cannot be rotated

    Security · September 8, 2026 · 1 publisher

  10. An infected ScreenConnect guest pushes scripts up the support session to the operator's host

    Build · September 8, 2026 · 1 publisher

  11. Closing N-central's CVSS 10.0 pre-auth RCE takes build 2026.3.1.14

    Build · September 8, 2026 · 1 publisher

  12. Microsoft shipped nine cloud fixes that cost its customers nothing to deploy

    Security · September 4, 2026 · 1 publisher

  13. A tampered Exodus installer hides a modular RAT behind a genuine wallet install

    Security · September 1, 2026 · 1 publisher

  14. Two PaperCut flaws chain into pre-auth code execution on every version of NG and MF

    Security · September 1, 2026 · 1 publisher

  15. Huntress confirms five DPRK-aligned workers cleared hiring and onboarding in 2026

    Security · September 1, 2026 · 1 publisher

  16. An unwhitelisted JDBC driver name turns PaperCut's management port into SYSTEM

    Build · August 28, 2026 · 1 publisher

  17. Suspected DPRK workers turn up in healthcare and sales roles, Huntress says

    Security · August 28, 2026 · 1 publisher

  18. GTA VI leak: extortion leverage moves from the regulator to the fanbase

    Security · August 25, 2026 · 1 publisher

  19. Kimsuky keeps picking RDP, which puts detection on configuration instead of files

    Security · August 24, 2026 · 1 publisher

  20. Three lab disclosures, one control failure: the AI hacking stories are eval sandbox stories

    Science · August 23, 2026 · 1 publisher

  21. ClickFix in the sidebar: Def Con follow-up phishing turns a real Google Doc into the payload

    Security · August 20, 2026 · 2 publishers

  22. 81 million attempts, 78 accounts: ROPC is where "we have MFA" stops being true

    Build · August 19, 2026 · 1 publisher

  23. "Work PC" beats DESKTOP-XXXXXXXX: Entra device-join detection needs a new anchor

    Security · August 18, 2026 · 1 publisher

  24. NYDFS says a vendor's flaw reached its banks, and there is no regulator for the vendor

    Invest · August 17, 2026 · 1 publisher

  25. Pre-auth flaw in macOS Screen Sharing turns any exposed Mac into an arbitrary file read

    Security · August 16, 2026 · 1 publisher