Huntress found legitimate remote management software abused in 45% of the endpoint incidents it logged in the first quarter of 2026. A rogue copy can behave like IT's approved one, so defenders have to know which tools are sanctioned and how each install arrived.
Reality
- Evidence45
- Adoption55
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Huntress details four ways attackers who already hold administrator rights add Microsoft Defender exclusions to keep malicious files out of every scan. A registry value can also hide those exclusions from any admin who checks for them.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+8
- Incentives62
- Confidence60
Huntress says a threat actor turned member-account file uploads into webshells on three web servers of a shared recreation-management platform. The same upload path served every tenant, and the attacker returned after one server was cleaned but not locked down.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence60
Huntress traced a RAT campaign that hides its first-stage lure in a ChatGPT Custom GPT on the real chatgpt.com, across at least 40 incidents. Because the page sits on a trusted domain, blocking the ClickFix PowerShell paste is the control that works.
Perspective Coverage
8 publishers
- Builder
- Builder 30%
- Operator
- Operator 64%
- Investor
- Investor 6%
Reality
- Evidence70
- Adoption20
- Hype gap+30
- Incentives40
- Confidence68
Huntress traced at least two of more than 40 ClickFix malware incidents to fake custom GPTs on OpenAI's chatgpt.com. On that route every hop before the PowerShell command sat on a Google or OpenAI address, so staff taught to trust familiar domains would click through each one.
Reality
- Evidence45
- Adoption20
- Hype gap+20
- Incentives
- Insufficient
- Confidence50
ShinyHunters says the two to three terabytes it took from the FBI include psychiatric and medical evaluations of bureau staff. Beside a Reuters sample tying named staff to counterintelligence jobs, those files are exposure no password reset can fix.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence40
An affiliate entered through an MFA-less SonicWall VPN, then used Safe Mode with Networking to kill endpoint controls. The encryptor ran out of virtual memory instead of running.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 65%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption15
- Hype gap+5
- Incentives40
- Confidence70
Huntress counted 81 million login attempts against Azure CLI in two weeks of June and 78 compromises. Most of the victims had MFA. It just did not apply to the flow the attacker used.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives65
- Confidence55
An Iran-linked intrusion kept a British generator down for four days while US wastewater plants lost pressure across 12 states. The number that matters now is restoration time.
Perspective Coverage
4 publishers
- Builder
- Builder 16%
- Operator
- Operator 68%
- Investor
- Investor 16%
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence50
Huntress has seen exploitation in two customer environments. One flaw hands over PaperCut's configuration without a login, the second turns that configuration into a class loader, so patching and config review are one job.
Perspective Coverage
10 publishers
- Builder
- Builder 27%
- Operator
- Operator 60%
- Investor
- Investor 13%
Reality
- Evidence85
- Adoption70
- Hype gap−10
- Incentives40
- Confidence78
Huntress found suspected DPRK workers inside an Australian healthcare company and a sales hire wearing a stolen identity, which puts the screening that catches them in the hands of recruiters and background-check vendors.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence50
ConnectWise's September 3 advisory promises a CVE and a fix within the week, so until one lands the only control is a per-role permission change. Huntress says the spread is already worm-like across newly connected machines.
Perspective Coverage
3 publishers
- Builder
- Builder 38%
- Operator
- Operator 57%
- Investor
- Investor 5%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence64
N-able shipped N-central 2026.3 HF4 on Saturday and says nothing confirms production exploitation, while Huntress calls the bug a possible zero-day and has one compromised customer console whose logs had already rotated.
Perspective Coverage
7 publishers
- Builder
- Builder 17%
- Operator
- Operator 75%
- Investor
- Investor 8%
Reality
- Evidence72
- Adoption40
- Hype gap+10
- Incentives55
- Confidence70
The fraudulent request passed domain authentication because it genuinely came from the agency's mail domain, sent by an account the agency had not authorised. Revolut found out only when it called the agency to check.
Perspective Coverage
8 publishers
- Builder
- Builder 11%
- Operator
- Operator 70%
- Investor
- Investor 19%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence66
Federal agencies now have three separate patch deadlines inside twelve days. The lowest-scoring pair of the five flaws added to KEV is the one with a documented 24-day intrusion campaign behind it.
Perspective Coverage
13 publishers
- Builder
- Builder 21%
- Operator
- Operator 76%
- Investor
- Investor 3%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+15
- Incentives50
- Confidence66
Huntress worked two Settra intrusions, in July and September, and found MeshAgent installed for remote control, Windows event logs cleared and recovery partitions removed. SOCRadar counts 93 victims claimed since June.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence70
A single operator is distributing fake "desktop apps" for three US payroll platforms that have no desktop product. Each installer silently sets up ScreenConnect for unattended control of the payroll operator's machine, Allure Security found.
Reality
- Evidence60
- Adoption10
- Hype gap+20
- Incentives40
- Confidence55
Huntress traced a September 2026 intrusion in which the actor compiled a Monero miner on the endpoint, using a MagicINFO flaw Samsung fixed 16 months earlier. The build step is loud in telemetry, but it ran only after Defender had been disabled.
Reality
- Evidence66
- Adoption28
- Hype gap+10
- Incentives62
- Confidence58
Huntress says three of its SOC investigations began with document lures and ended with victims installing rogue ITarian and ScreenConnect clients, and its responders now find RMM abuse in almost 40% of the incidents they work.
Reality
- Evidence45
- Adoption50
- Hype gap+20
- Incentives78
- Confidence48
Huntress found the same one-megabyte PIF in two customer environments, pulled down by a link that promised a PNG. Everything after it is the 2024 DarkMe chain, down to the rundll32 /sta GUID from that campaign.
Reality
- Evidence72
- Adoption22
- Hype gap+14
- Incentives66
- Confidence68
Earlier coverage
- A signed Windows binary can stand up a real Microsoft login and pocket the tokens
Security · September 23, 2026 · 1 publisher
- One rule in CLAUDE.md lifted Huntress's API recall from 48% to 86% on the same seven tasks
Security · September 22, 2026 · 1 publisher
- Huntress rebuilt a 175-endpoint INC ransomware case from scheduled tasks and a driver fragment
Security · September 22, 2026 · 1 publisher
- Attackers have been pushing VBScript through live ScreenConnect sessions since August 20
Security · September 14, 2026 · 1 publisher
- Three malware campaigns stage their lure pages on Claude and ChatGPT share links
Build · September 11, 2026 · 1 publisher
- One Server Licensor Certificate key decrypts every document an AD RMS deployment ever protected
Security · September 11, 2026 · 1 publisher
- FakeAgent delivered SectopRAT to more than 29 organisations from a page hosted on claude.ai
Security · September 11, 2026 · 1 publisher
- Fake GTA 6 installer destroys files behind a staged "License not found" error
Security · September 10, 2026 · 1 publisher
- Huntress found four paths to an AD RMS root key that cannot be rotated
Security · September 8, 2026 · 1 publisher
- An infected ScreenConnect guest pushes scripts up the support session to the operator's host
Build · September 8, 2026 · 1 publisher
- Closing N-central's CVSS 10.0 pre-auth RCE takes build 2026.3.1.14
Build · September 8, 2026 · 1 publisher
- Microsoft shipped nine cloud fixes that cost its customers nothing to deploy
Security · September 4, 2026 · 1 publisher
- A tampered Exodus installer hides a modular RAT behind a genuine wallet install
Security · September 1, 2026 · 1 publisher
- Two PaperCut flaws chain into pre-auth code execution on every version of NG and MF
Security · September 1, 2026 · 1 publisher
- Huntress confirms five DPRK-aligned workers cleared hiring and onboarding in 2026
Security · September 1, 2026 · 1 publisher
- An unwhitelisted JDBC driver name turns PaperCut's management port into SYSTEM
Build · August 28, 2026 · 1 publisher
- Suspected DPRK workers turn up in healthcare and sales roles, Huntress says
Security · August 28, 2026 · 1 publisher
- GTA VI leak: extortion leverage moves from the regulator to the fanbase
Security · August 25, 2026 · 1 publisher
- Kimsuky keeps picking RDP, which puts detection on configuration instead of files
Security · August 24, 2026 · 1 publisher
- Three lab disclosures, one control failure: the AI hacking stories are eval sandbox stories
Science · August 23, 2026 · 1 publisher
- ClickFix in the sidebar: Def Con follow-up phishing turns a real Google Doc into the payload
Security · August 20, 2026 · 2 publishers
- 81 million attempts, 78 accounts: ROPC is where "we have MFA" stops being true
Build · August 19, 2026 · 1 publisher
- "Work PC" beats DESKTOP-XXXXXXXX: Entra device-join detection needs a new anchor
Security · August 18, 2026 · 1 publisher
- NYDFS says a vendor's flaw reached its banks, and there is no regulator for the vendor
Invest · August 17, 2026 · 1 publisher
- Pre-auth flaw in macOS Screen Sharing turns any exposed Mac into an arbitrary file read
Security · August 16, 2026 · 1 publisher