Microsoft postpones removal of -Credential parameter in Exchange Online PowerShell: Administrators should adapt their scripts ...
Microsoft has published a warning enterprise customers after its Defender Experts observed increased ACR Stealer activity across customer environments from April through June 2026. ACR Stealer ...
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source ...
ACR Stealer campaigns use ClickFix lures, JPEG steganography, and WebDAV to steal browser tokens, passwords, PDFs, and synced ...
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication ...
If you've ever connected a headset, monitor, or Bluetooth speaker to your PC only to have Windows start routing audio to the ...
Microsoft has warned that attackers are varying their post-exploitation techniques while relying on the same ClickFix lure, ...
Huntress 发现一个由 AI 生成的 PowerShell 脚本,用于 AD 侦察,表明攻击者正利用 AI 创建定制化、具备规避能力的工具。 2026 年 6 月 3 日,在一次事件响应调查中,Huntress 分析师 Jevon Ang 从一台被入侵的 Windows Server 中恢复了一个 PowerShell 脚本。攻击者曾使用该脚本绘制受害者 Active Directory 环 ...
One of the Russian government’s most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices ...
Binding, and Silo-Binding techniques abuse Windows filesystem virtualization features to present trusted files to security ...
The South African Human Rights Commission confirmed that its website was breached by a threat actor who injected a trojan in ...
Image courtesy by QUE.com Security researchers at Huntress have identified an intrusion in which a threat actor used what ...