Meet the Huntress MCP Server
Access your Huntress data easily with the Huntress MCP Server, connecting your AI assistant directly to your incidents, agents, billing, and more. No portal required.
CPDLC over ATN-B1 Vulnerabilities
CISA has disclosed five vulnerabilities in CPDLC over ATN-B1, a critical aviation data link communications protocol used globally, which rely on unauthenticated cleartext radio frequency links allowing remote message injection, session disruption, and denial-of-service attacks. The vulnerabilities enable adversaries to inject false clearances, disconnect multiple aircraft simultaneously, and inject fraudulent emergency messages, degrading operational safety margins through increased workload and delayed safety-critical communications, though no public exploitation has been reported and attacks require high complexity conditions unlikely outside laboratory settings. No mitigations are currently available for any of the five CVEs, with CVSS scores ranging from 5.3 to 7.1.
Agentic AI for cyber defenders: What security teams built at Black Hat USA 2026
At Black Hat USA 2026, Tenable hosted SWARM, a 48-hour event where nearly 100 security practitioners built open-source agentic AI tools addressing real operational pain points like finding prioritization, cross-scanner reconciliation, and findings triage—all published to the CyberAgents Exchange for community reuse. The winning entries included Chokepoint Finder, which ranks fixes to collapse thousands of findings into concrete remediation actions; ThreatCorraling, which correlates static and dynamic scanning results; and Evidence-Backed Vulnerability Investigator, which matches findings against vendor advisories to prove prior mitigation. By distributing defensive AI tooling openly rather than having teams rebuild solutions in silos, the CyberAgents Exchange aims to give defenders the same compounding advantage threat actors have always enjoyed through shared offensive capabilities.
Healthcare and Victim Support Charities Affected by Beacon Cyber Incident
Beacon notified approximately 1,500 customer charities that its CRM databases were accessed and likely exfiltrated by an unauthorized threat actor. The incident affected healthcare organizations and victim support charities relying on Beacon's services for donor and case management data.
Google Links Redact Extortion Group to BlackFile Rebrand
Google has attributed the Redact extortion group to a rebrand of BlackFile following an alleged affiliate hijack. The threat actor is reportedly conducting vishing and extortion campaigns under its new identity.
Ransomware Surges in July After Q2 Lull
Finance, technology and healthcare sectors were particularly heavily targeted in July, according to Comparitech
GRC vs. Red Teaming: Better Together for Cyber Risk Analysis
What happens when a GRC Assessor and a Red Team Operator evaluate the same organization? 🔗 Register for this FREE Infosec Webcast and other Anti-casts & Summits:
CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX
July 2026 CVE Landscape
In July 2026, Insikt Group identified 85 high-impact vulnerabilities warranting prioritization, with 36 rated as Very Critical by Recorded Future Risk Score. This represents a 44% month-over-month increase in critical vulnerability volume, signaling an elevated threat landscape requiring immediate remediation focus.
The security signal log tailing can't see: tracking npm cooldown removals with Elastic Agent
A 40-line CEL integration snapshots .npmrc files every 6 hours to catch cooldown removals. This post walks through the three ways we broke filestream before landing on snapshot semantics.
CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.6 (Critical). Affects Progress LoadMaster.
OSPF From Zero: Let's Build the Internet (Well...Almost) | Summer of CCNA
Join us for our 90 minute Sumer of CCNA session, today at 5PM ET!
ChainDrop: Inside a Self-Propagating npm Worm
Unit 42 has analyzed ChainDrop, a self-propagating worm distributed through npm that exploits supply chain vulnerabilities to extract secrets from GitHub Actions runners. The malware uses Ethereum smart contracts as an unconventional command-and-control mechanism, demonstrating sophisticated techniques for maintaining persistence across compromised development environments.
When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
Check Point Research discovered five memory-corruption vulnerabilities in workerd, the V8-based runtime underlying both Cloudflare Code Mode and Cloudflare Workers, by exploiting weaknesses in the native C++ code that bridges the sandbox isolation layer. These findings demonstrate that the in-process sandbox design relying solely on V8 for code isolation can be bypassed through memory corruption attacks in the runtime's glue code. The research highlights a critical security gap in how Cloudflare's serverless execution environments handle untrusted code.
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.
Hackers Stalked Me by Hijacking a Smartwatch for Kids
Security researchers demonstrated how vulnerabilities in a GPS-enabled children's smartwatch could be exploited to track and eavesdrop on users, using a WIRED reporter as a test case. The incident highlights broader security weaknesses across the supply chain of GPS-enabled consumer devices marketed for kids.
Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride
In the span of three weeks, OpenAI, Anthropic, and Meta have all disclosed AI agent sandbox escape events affecting real organizations.
Researcher Claims Control of ChatGPT Secure Sandbox
A researcher presented a proof-of-concept attack at Black Hat USA 2026 showing how to achieve command-and-control-style influence over ChatGPT's secure sandbox environment. The demonstration revealed a potential attack chain capable of compromising the isolation mechanisms designed to protect the system during active sessions.
What Is Zero Trust Security? A Guide for Businesses
Zero trust security assumes no user or device is trusted by default. See how Huntress enforces the model with Managed EDR and ITDR for lean IT teams.