Cybersecurity News

Filters
Tag

Microsoft VSS: Still Essential, But Not the Whole Story

Microsoft's Volume Shadow Copy Service (VSS) has long been central to Windows backup and recovery, enabling consistent snapshots without interrupting operations. However, its limitations — including Windows-only support, scalability constraints, and dependency on VSS-aware applications — mean it shouldn't be the sole data protection strategy. Organizations are advised to pair VSS with additional tools for comprehensive, cross-platform coverage.

Custom HTML for Custom Phishing: Make the Fake Feel Real

Huntress offers a Custom HTML feature for phishing simulations, allowing organizations to build tailored, realistic phishing scenarios. Rather than using generic templates, security teams can design emails that mirror actual vendors and risks specific to their environment, making training more relevant and effective at preparing employees for real-world threats.

Meet Athena: Huntress' Agentic SOC Analyst

Huntress has launched Athena, an AI-powered SOC analyst that autonomously investigates security signals end-to-end. Athena handles triage and analysis tasks typically done by human analysts, aiming to speed up threat detection and response. Human analysts retain final decision-making authority. The tool is designed to reduce analyst workload and improve efficiency in security operations centers.

DigiCert survey finds 81% of Australian organisations hit by AI security incidents or vulnerabilities

Matched: Australia

A DigiCert survey found that 81% of Australian organisations have experienced an AI-related security incident or identified AI-related vulnerabilities. The findings suggest AI security risks are already a widespread concern among Australian enterprises, highlighting the growing challenge businesses face in managing threats introduced or amplified by artificial intelligence adoption.

Partnered Health confirms cyber incident affecting patient information across national clinic network

Matched: health, healthcare

Partnered Health has confirmed a cybersecurity incident involving unauthorised access to patient data across its national clinic network. The breach affected personal and health information held by some clinics. The company is investigating the extent of the incident and has notified relevant authorities. Affected patients are being contacted and advised to monitor for suspicious activity.

Every Ransomware Attack Has a Backstory

Ransomware attacks don't begin with encryption — they start long before, often with access brokers selling stolen credentials or network entry points to attackers. Criminals then use legitimate tools already present in the environment to move quietly through systems, avoiding detection. By the time ransomware deploys, attackers may have been inside for weeks. Stopping them requires catching intrusions early, before the final stage.

ACS welcomes planned Office of AI, calls for focus on skills and recognition

Matched: Australia

The Australian Computer Society has welcomed the federal government's plan to create an Office of AI within the Department of the Prime Minister and Cabinet. The ACS expressed support for the move while calling for the office to prioritise workforce skills development and formal recognition of AI-related competencies as part of Australia's broader artificial intelligence strategy.

Australian critical infrastructure urged to tighten router security after Russian cyber warning

Matched: Australia

Australia's cyber security agency has joined international partners in warning critical infrastructure operators to strengthen the security of routers, firewalls and other network devices following alerts about Russian state-sponsored cyber threats. Operators are being urged to review configurations, apply patches and monitor for suspicious activity to reduce the risk of compromise to essential services.

5 Modern Threats You Need to Watch

Cybersecurity threats increasingly bypass traditional malware, instead starting with legitimate-looking logins. Key patterns to watch include ransomware, business email compromise, and social engineering attacks. IT and security teams are urged to recognize these threats early, focusing on detecting suspicious access attempts rather than relying solely on conventional malware-detection approaches.

Lessons Learned from CISA’s Recent GitHub Leak

CISA released a postmortem after a contractor accidentally exposed dozens of internal credentials, including AWS GovCloud keys, in a public GitHub repository for nearly six months. The leak went undetected until KrebsOnSecurity notified the agency. Security experts say the incident highlights critical gaps in credential monitoring and third-party contractor oversight that all security teams should learn from.

Effective Patch Management Strategies: 7 Best Practices | Huntress

Patch management reduces security risk by keeping software updated. Key practices include maintaining a complete asset inventory, prioritizing patches by severity, testing before deployment, automating where possible, and establishing a regular patching schedule. Organizations should also track patch status, address failures promptly, and document processes. Timely patching closes vulnerabilities before attackers can exploit them.

Threat Actors Achieve Persistence After SQL Injection

Attackers exploited SQL injection vulnerabilities to compromise IIS servers, deploying the BadIIS malware to gain persistence. Once inside, they disabled Windows Defender to avoid detection, then silently installed a cryptominer to hijack system resources. The attack highlights how unpatched web application vulnerabilities can serve as entry points for multi-stage intrusions with lasting impact.

Guide to System Hardening: Checklist & Best Practices [2026] | Huntress

System hardening reduces attack surfaces by securing configurations across hardware, software, and networks. Key practices include disabling unnecessary services and ports, applying patches promptly, enforcing least-privilege access, enabling multi-factor authentication, encrypting sensitive data, and auditing logs regularly. Following established frameworks like CIS Benchmarks helps organizations systematically identify and close security gaps before attackers can exploit them.

Reduce Human Risk | Build a Strong Security Awareness Training Program | Huntress

Huntress offers a managed security awareness training service aimed at reducing human-related cyber risk. The program includes engaging training content, phishing simulations, and behavioral tracking to help organizations build stronger security habits among employees. It is designed to produce measurable results rather than just checkbox compliance.

Conditional Access Misconfigurations Exposed 55 Orgs with MFA On

Huntress researchers found that Conditional Access misconfigurations left 55 organizations vulnerable despite having MFA enabled. Two real attack cases bypassed policies that appeared properly set up, exposing gaps invisible to standard reviews. Huntress's Managed Identity Security Posture Management tool is designed to detect these configuration flaws before attackers can exploit them.

CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware | Huntress

Huntress identified attacks exploiting CitrixBleed 2 (CVE-2025-5777) that follow a consistent seven-step pattern leading to DragonForce ransomware deployment. The intrusions involve novel local privilege escalation techniques. The similarity across incidents suggests a coordinated threat actor or shared playbook, and organizations using vulnerable Citrix systems are urged to patch immediately.

ACSC warns of large-scale campaign exploiting CMS vulnerabilities in Australia

Matched: Australia

Australia's cyber security agency has warned of a large-scale campaign targeting web content management systems, with many Australian businesses already compromised. The ACSC says attackers are exploiting CMS vulnerabilities to gain access to websites and their underlying infrastructure, urging organisations to patch systems, review user accounts, and check for signs of compromise.