There’s no sales pitch here. Join _declassifed for raw details on cybercrime counter-ops, & how everyone plays a part in imposing cost and bringing cybercriminals to justice
If you make time for one Huntress live stream this year, make it this one.
https://t.co/uIniLFkOxo
Always double-check that you are downloading software from the official, verified website directly, rather than clicking on ads or third-party links.
Full breakdown by Michael Tigges on the Huntress blog:
https://t.co/Wf6qUXvrJk
Checking the URL didn't save 29 organizations from an infostealer. The link really did go to https://t.co/fnaIm88qdM.
This is a Claude Artifact.
Anyone can make one (a web page, a chart, a document) and publish it publicly on https://t.co/fnaIm88qdM.
7,100 page views before we reported it and Anthropic took it down.
Even when a search result looks like it comes from a legitimate company, the "sponsored" or ad links at the top of the page can be fake.
Normally, threat intel like this stays private. We got the FBI to join us on camera anyway.
On July 28, we're going live with @KyleHanslovan, @FBICyberDiv Assistant Director @Brettleathrman, and @_JohnHammond to share what usually stays in the room: https://t.co/54LxitMj2z
Initial access brokers are cybercriminals who specialize in one thing: finding a way into a business's network and selling that access to whoever's buying next. 💸
Check out how these attacks start and what you can do to catch them early. https://t.co/Bh5HHkFyjs
Every player has a tell... 🃏
So does every adversary.
Black Hat's coming up, and we're headed to Mandalay Bay to compare notes with our favorite community.
Find us at Booth #1845, August 1-6.
#BHUSA
The lifecycle runs discovery to verified remediation, confirming the CVE is actually closed, not just marked deployed.
Every stage has its own risk calculus and judgment call.
Check out our 7 best practices: https://t.co/6kvQhk0TID
Patch management is a proactive security discipline: identifying, evaluating, and applying updates to software, OSes, and firmware across an environment. 🧵
Three categories to know:
1️⃣ OS patches (highest risk)
2️⃣ third-party app patches like browsers and plugins (overlooked, often exploited)
3️⃣ firmware (low-level, still exploitable)
An attacker made 81M login attempts against Microsoft accounts in two weeks.
78 accounts were compromised, all with MFA on...but misconfigured.
We're breaking it all down in this month's Tradecraft Tuesday: https://t.co/1ShHosGDe2
Jul 14, 2026 | 1:00pm ET | 10:00am PT
“Long Live” strong security! 💒 Taylor Swift and Travis Kelce's enchanted wedding had tighter OPSEC than most Fortune 500s.
@Susannigans shares 5 tay-keaways for defenders inspired by the most guarded event of the year. https://t.co/Axe7jDfbjv
We tracked a threat actor abusing Meta’s Business Account Manager workflow to send lure emails from a legit Meta address. By slipping a URL into the partner-name field, they turned a real Meta message into a phishing setup.
Full write-up and IoCs below. https://t.co/STAmrfNs1X
Hope-as-a-service: the security strategy where you buy the tool, skip the setup, and just...hope for the best? 🫣
It's more common than you'd think and attackers know exactly where to look.
@LindseyOD123 on how device code phishing exploits that gap.
https://t.co/LkHLguiMEo
Attackers want your session token.
And they've built entire playbooks around tricking you into handing it over. 🪙
Here are 5 phishing techniques we're seeing in the wild and what your team needs to know to spot them. 👇
https://t.co/Qi0YiPs7px
@kluein If you need to verify whether your data is included, contact an experienced IR team, counsel, or trusted intel partner.
This data could be used to impersonate Klue or Huntress. Stick to channels you know and treat unexpected outreach with skepticism.
https://t.co/BHzqkR2TxW
On June 22, Icarus posted data for Huntress and other companies impacted by the @kluein breach on their leak site.
Here’s what you need to know.
https://t.co/W6UhFAAzNJ