In 2020, a scammer called Andrew Schlemmer's grandfather pretending to be Andrew. His grandfather sent over a significant amount of money before anyone realized what was happening. With a few seconds of audio, attackers can clone a real voice and skip the trust-building work entirely. That call is the reason Andrew works in cybersecurity today. He's trained over 500 people on security basics and AI awareness, and now he's a Channel Account Manager at Huntress, connecting businesses to the kind of protection usually reserved for enterprises with much bigger budgets. We talked to Andrew for our Employee Spotlight series about how that 2020 call still shapes his work, and why the same tactic keeps getting easier to pull off. Check out his story: https://okt.to/FQV0yN
Huntress
Computer and Network Security
Columbia, Maryland 148,450 followers
Enterprise-grade #cybersecurity for ALL businesses. Managed EDR, ITDR, SIEM, SAT, & ISPM built to wreck hackers.
About us
Protect Your Endpoints, Identities, Logs, and Employees. The agentic managed security platform for peace of mind. Designed to deliver the next-level outcomes you need: Endpoint Integrity, Identity Resilience, Operational Readiness. Powered by custom-built enterprise technology for mid-market enterprises, small businesses, and the MSPs that support them. Backed by unrivaled industry analysts in our 24/7 AI-centric Security Operations Center. By delivering a suite of purpose-built solutions that meet budget, security, and peace-of-mind requirements, Huntress is how the globe’s most under-resourced businesses defend against today’s cyber threats. As long as hackers keep hacking, we keep hunting.
- Website
-
https://www.huntress.com/demo?utm_source=linkedin&utm_medium=social&utm_campaign=cy25-10-camp-brand-global-broad-all-organic_social_bio
External link for Huntress
- Industry
- Computer and Network Security
- Company size
- 501-1,000 employees
- Headquarters
- Columbia, Maryland
- Type
- Privately Held
- Founded
- 2015
- Specialties
- Cyber Breach Detection, Incident Response, Endpoint Protection, Malware Analysis, and Managed Services
Locations
-
Primary
Get directions
6996 Columbia Gateway Dr
Columbia, Maryland 21046, US
Employees at Huntress
Updates
-
Normally, threat intel like this stays private. We got the FBI to join us on camera anyway. We flew 800+ teammates to Summer Summit with the goal of figuring out what attackers are actually doing based on what we're seeing across APAC, EMEA, and everywhere in between. Turns out knowing your adversary is the only way to stay ahead of them. And partnerships with law enforcement are what turn that knowledge into action, taking down the ecosystems behind the tradecraft. Episode 3 of _declassified puts all of it on camera. We're going live with Kyle Hanslovan, FBI Cyber Division Assistant Director Brett Leatherman, and John Hammond to share the stuff that usually stays in the room. Save your spot: https://okt.to/nRumWr
-
Has AI already ruined cybersecurity? John Hammond caught up with Chris Bisnett live at Huntress Summer Summit and asked him. Chris's answer: not even close. Yes, attackers are getting faster with AI. But so is Huntress. Investigations that used to take our analysts hours now take minutes. Product Lab is where we show our work, live, in front of the whole company. What's happening LIVE in the lab today: → the web app → the mobile app?!?! → how AI is reshaping endpoint protection against attackers hiding inside legitimate tools. Tune in: https://okt.to/iSYRB7
-
Checking the URL didn't save 29 organizations from an infostealer. The link really did go to claude.ai. What you're looking at is a Claude Artifact. Anyone can make one (a web page, a chart, a document) and publish it publicly on claude.ai. The URL is real and the branding looks right, so it's easy to miss the disclaimer at the top that reads "Content is user-generated and unverified." The attacker built this page inside Claude, hit publish, and registered a lookalike domain. Bing served it as a sponsored ad result when people searched for "Claude Desktop." 29 organizations clicked Download. That button redirected to a domain the attacker registered. From there, it downloaded a file called ClaudeDesktop.exe, which led to SectopRAT (we initially incorrectly attributed this to RedLine Stealer). 7,100 page views before we reported it and Anthropic took it down. Even when a search result looks like it comes from a legitimate company, the "sponsored" or ad links at the top of the page can be fake. Always double-check that you are downloading software from the official, verified website directly, rather than clicking on ads or third-party links. Full breakdown by Michael T. on the Huntress blog: https://lnkd.in/e3-mPPrA
-
-
Initial access brokers are cybercriminals who specialize in one thing: finding a way into a business's network and selling that access to someone else who carries out the actual attack. A basic login goes cheap. Access into a company with more customer data and more money moving through it sells for a lot more. By the time ransomware or a BEC attempt shows up, someone already paid for the door left open. The good news? The basics still work. Turn on multi-factor authentication everywhere you can, and close remote access tools like RDP if you're not using them. Keep software patched, especially anything connected to the internet, and pay attention when a login looks off even if nothing else seems wrong. Check out how these attacks start and how to catch them early: https://okt.to/MbeLXI
-
-
We've been sitting on this story for years. Silk Typhoon, formerly known as HAFNIUM, ran the 2021 Microsoft Exchange campaign that compromised 88,000 organizations. We watched it unfold from inside the attacker's own infrastructure while the public read "limited and targeted" in the news. On July 28, Kyle Hanslovan, John Hammond, and FBI Cyber Division's Assistant Director Brett Leatherman are telling the full story from the cold calls and the war room decisions we couldn't share until now. Join us: https://lnkd.in/eSkfYSYz
[_declassified Episode 3] Know Your Adversary: Counter Operations that Wreck Global Cybercrime
-
Every player has a tell... 🃏 So does every adversary. Black Hat's coming up, and we're headed to Mandalay Bay to compare notes with our favorite community. At Booth #1845, Ben Bernstein's walking through how attackers move from the darknet into your network, and Andrew Brandt's got the receipts on why most malware infections come down to three RMM tools stacked in a trenchcoat. Jamie Levy's sharing the BTS on what an investigation taught us about a threat actor's operations, alongside a full lineup of ethical badasses who've earned the mic this week. Find us August 1-6. We'll trade you a story for a story. #BHUSA
-
New: On July 17, we saw active exploitation against SonicWall SMA 1000 appliances. SonicWall issued hotfixes this week for the vulnerabilities behind that activity, CVE-2026-15409 and CVE-2026-15410. These two vulnerabilities can be combined to create a one-two punch leading to full control of the appliance. With the first (CVE-2026-15409) an attacker can abuse an internet-facing WorkPlace portal to reach (normally unreachable) localhost-only services on the appliance. Once an attacker can talk to these services, they can use the second vulnerability (CVE-2026-15410) to elevate privileges to root. We’ve confirmed active exploitation against seven organizations so far by two disparate sets of attackers, and even found an opendir belonging to one of the actors giving us a glimpse into their tooling used in attacks related to SMA 1000 exploitation. - After exploitation, the threat actors attempted credential theft via Impacket’s SecretsDump and DCSync. - They installed Go-based implants via a C2 at 153.75.81[.]30 on SonicWall appliances (seen in paths: /var/tmp/.sshd and /var/tmp/.rsyncd). - We assess that the implants (.sshd and .rsyncd) are Sliver, an open-source red team framework that’s previously been used in attacks. - The activity was detected by Microsoft Defender and shut down by Huntress. If you use impacted versions of SMA 6210, 7210 or 8200v, apply the latest hotfix, which is available for download here: mysonicwall.com
-
-
We stand by enterprise-grade cybersecurity for ALL businesses 👏 and that includes midmarket organizations. So making the 2026 #MESMidmarket100 List is an honor we don't take lightly. The list recognizes vendors who actually understand what midmarket IT teams are dealing with: too few people, too little time, and security tools that assume you have both. That's the gap we're committed to closing. Thanks to the IT leaders who keep sharing what's working, what's not, and what they wish existed and doesn't yet. Your feedback helps shape the roadmap.
-
-
Huntress has tracked roughly 1.5M login attempts a day against Microsoft's Azure CLI. That's nearly the same volume we saw at the campaign's original June peak, out of LSHIY LLC's IPv6 range. After LSHIY suspended the account behind our findings, the attacker didn't quit. They moved to FranTech, then to 3xK Tech GmbH. FranTech has shown up in password spraying activity before, and Cloudflare named 3xK Tech the largest source of ASN DDoS attacks last summer. Getting a new ASN takes attackers almost no time or money. There's no shortage of infrastructure providers out there, so losing one host barely slows the campaign down; it just buys a few days before the traffic resurfaces somewhere else. The real fix lives in your tenant. Require MFA for all users, all cloud apps, and all client app types, and turn on userStrongAuthClientAuthNRequired to shut down the ROPC flow this attacker relies on. Full update and mitigation guidance here: https://okt.to/BgkCRX
-