Cybersecurity News
Filters
Microsoft Patches a Record 570 Security Flaws
Microsoft released updates fixing 570 security flaws, nearly triple last month's record-breaking total. The company attributed the surge in vulnerability discoveries to artificial intelligence tools. The patches cover Windows operating systems and other Microsoft software.
5 Modern Threats You Need to Watch
Cybersecurity threats increasingly bypass traditional malware, instead starting with legitimate-looking logins. Key patterns to watch include ransomware, business email compromise, and social engineering attacks. IT and security teams are urged to recognize these threats early, focusing on detecting suspicious access attempts rather than relying solely on conventional malware-detection approaches.
Lessons Learned from CISA’s Recent GitHub Leak
CISA released a postmortem after a contractor accidentally exposed dozens of internal credentials, including AWS GovCloud keys, in a public GitHub repository for nearly six months. The leak went undetected until KrebsOnSecurity notified the agency. Security experts say the incident highlights critical gaps in credential monitoring and third-party contractor oversight that all security teams should learn from.
Effective Patch Management Strategies: 7 Best Practices | Huntress
Patch management reduces security risk by keeping software updated. Key practices include maintaining a complete asset inventory, prioritizing patches by severity, testing before deployment, automating where possible, and establishing a regular patching schedule. Organizations should also track patch status, address failures promptly, and document processes. Timely patching closes vulnerabilities before attackers can exploit them.
Threat Actors Achieve Persistence After SQL Injection
Attackers exploited SQL injection vulnerabilities to compromise IIS servers, deploying the BadIIS malware to gain persistence. Once inside, they disabled Windows Defender to avoid detection, then silently installed a cryptominer to hijack system resources. The attack highlights how unpatched web application vulnerabilities can serve as entry points for multi-stage intrusions with lasting impact.
Guide to System Hardening: Checklist & Best Practices [2026] | Huntress
System hardening reduces attack surfaces by securing configurations across hardware, software, and networks. Key practices include disabling unnecessary services and ports, applying patches promptly, enforcing least-privilege access, enabling multi-factor authentication, encrypting sensitive data, and auditing logs regularly. Following established frameworks like CIS Benchmarks helps organizations systematically identify and close security gaps before attackers can exploit them.
Reduce Human Risk | Build a Strong Security Awareness Training Program | Huntress
Huntress offers a managed security awareness training service aimed at reducing human-related cyber risk. The program includes engaging training content, phishing simulations, and behavioral tracking to help organizations build stronger security habits among employees. It is designed to produce measurable results rather than just checkbox compliance.
Conditional Access Misconfigurations Exposed 55 Orgs with MFA On
Huntress researchers found that Conditional Access misconfigurations left 55 organizations vulnerable despite having MFA enabled. Two real attack cases bypassed policies that appeared properly set up, exposing gaps invisible to standard reviews. Huntress's Managed Identity Security Posture Management tool is designed to detect these configuration flaws before attackers can exploit them.
CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware | Huntress
Huntress identified attacks exploiting CitrixBleed 2 (CVE-2025-5777) that follow a consistent seven-step pattern leading to DragonForce ransomware deployment. The intrusions involve novel local privilege escalation techniques. The similarity across incidents suggests a coordinated threat actor or shared playbook, and organizations using vulnerable Citrix systems are urged to patch immediately.
ACSC warns of large-scale campaign exploiting CMS vulnerabilities in Australia
Matched: Australia
Australia's cyber security agency has warned of a large-scale campaign targeting web content management systems, with many Australian businesses already compromised. The ACSC says attackers are exploiting CMS vulnerabilities to gain access to websites and their underlying infrastructure, urging organisations to patch systems, review user accounts, and check for signs of compromise.
AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration | Huntress
Threat actors are using AI tools to generate custom PowerShell malware for Active Directory attacks. Huntress researchers analyzed real "vibe-coded" samples, finding that AI-assisted scripts can enumerate AD environments effectively even without deep attacker expertise. The shift lowers the barrier for creating functional malware, complicating detection since AI-generated code may lack the patterns defenders typically recognize.
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup offering millions for zero-day software vulnerabilities is led by two convicted felons with far-right, conspiracy theorist backgrounds. Their previous ventures included fraudulent intelligence firms and a defunct AI lobbying platform run under false identities, raising serious concerns about the legitimacy of their latest operation.
LoTL Abuse: How to Spot It vs. Normal Admin Activity | Huntress
Attackers increasingly use "Living off the Land" techniques, abusing legitimate tools like PowerShell, WMI, and RMM software to blend in with normal IT activity. Key red flags include scripts running outside business hours, encoded commands, unusual parent-child process relationships, and tools accessing systems they don't normally touch. Context and behavioral baselines are critical for distinguishing malicious use from routine administrator work.
Telstra mobile outage disrupts services across Australia
Matched: Australia
Telstra's mobile network suffered a major outage across Australia, disrupting voice and data services for millions of customers, as well as businesses, transport operators and other organisations. The company acknowledged the issue and said it was working to restore services. It is one of the most significant disruptions to hit Australia's largest telco in recent years.
FBI Seizes NetNut Proxy Platform, Popa Botnet
The FBI seized hundreds of domains tied to NetNut, a residential proxy service run by Israeli company Alarum Technologies. The action followed a KrebsOnSecurity report linking NetNut to the Popa botnet, a network of at least two million devices infected without owner consent. The seizure involved industry partners and came roughly two weeks after the security findings were published.
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Two members of the Scattered Spider cybercrime group pleaded guilty on the first day of their trial in the UK, avoiding what was expected to be a six-week proceeding. The pair were charged in connection with an August 2024 cyberattack on Transport for London, which severely disrupted the city's public transport network.
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
A years-long Android botnet called Popa has hijacked millions of consumer TV boxes to relay traffic tied to ad fraud, account takeovers, and data scraping. Security researchers have linked the operation to NetNut, a residential proxy service run by Alarum Technologies, a publicly traded Israeli company listed on NASDAQ.
Who Runs the Ransomware Group ‘The Gentlemen?’
A ransomware group called The Gentlemen has quickly become the second most active such gang, luring hackers with a 90% affiliate payout. An investigation into the group's administrator reveals clues pointing to a real-world identity behind the operation, though the group's rapid rise and recruitment success make it a significant emerging cybercrime threat.
A Record-Breaking Patch Tuesday for June 2026
Microsoft's June 2026 Patch Tuesday addressed nearly 200 security vulnerabilities across Windows and related software, the largest monthly update in the company's history. Around 30 of the flaws were rated critical, and exploit code for at least three vulnerabilities is already publicly available, raising the urgency for users and administrators to apply the patches promptly.
