SANS Cyber Threat Hunting Survey 2025

The 2025 SANS Threat Hunting Survey reveals a growing trend toward in-house threat hunting capabilities, with organizations prioritizing agility and integration despite challenges like cloud visibility and skilled staffing shortages. Key findings include the prevalence of business email compromise, rising nation-state threats, and the increasing use of living off the land techniques among threat actors. #SANS2025 #ThreatHunting #BusinessEmailCompromise #LivingOffTheLand

Read More
Credential Dumping with NetExec (nxc)

This article discusses the capabilities of NetExec (nxc), a comprehensive post-exploitation framework designed to automate credential dumping in Windows and Active Directory environments. It highlights various methods attackers can use to gather sensitive credentials and offers insights for both red and blue teams to improve detection and mitigation strategies. #NetExec #CredentialDumping

Read More
Cybersecurity Consulting and Ransomware Updates, May

Threat intelligence for May 2025 highlights 77 new vulnerabilities, five active exploits, and increased ransomware activity, with critical issues like CVE-2025-29813 (Azure DevOps Server) and CVE-2025-30386 (Microsoft Office) needing urgent remediation. Ransomware groups such as Safepay and Devman, active exploitation of CISA-listed CVEs, and frequent malware submissions (e.g., Berbew) underscore the need for prioritized patching, asset discovery, and threat-informed defenses. #CVE-2025-29813 #CVE-2025-30386 #Safepay #Devman #Berbew

Read More
SANS Cyber Threat Hunting Survey 2025

The 2025 ransomware landscape is shaped by evolving threat actors adapting to law enforcement actions, increasing data exfiltration, and decreasing ransom payments, alongside emerging legal risks and rising budgets for defense and recovery. Organizations with better outcomes prioritize proactive ransomware playbooks, secure backup recovery, and strong people-centric response strategies to build cyber resilience. #LockBit #BlackCat #BlackBasta

Read More
SANS Cyber Threat Hunting Survey 2025

The ThreatLabz 2025 AI Security Report by Zscaler analyzes over 536 billion AI/ML transactions, revealing explosive growth in AI adoption and highlighting major security concerns such as the weaponization of AI by threat actors. The report emphasizes the necessity of strong security controls, zero trust architecture, and AI-powered defenses to counter evolving AI-driven cyber threats. #ThreatLabz #Zscaler #ChatGPT

Read More
SANS Cyber Threat Hunting Survey 2025

The 2025 Microsoft Vulnerabilities Report reveals a record-breaking 1,360 total vulnerabilities in 2024, highlighting an 11% increase from the previous year, with a notable rise in Security Feature Bypass vulnerabilities. Despite the uptick in some areas, critical vulnerabilities continue to decline overall, though Microsoft Edge showed an unexpected increase. #MicrosoftVulnerabilities #SecurityFeatureBypass #MicrosoftEdge

Read More
SANS Cyber Threat Hunting Survey 2025

The 2025 Global Mobile Threat Report highlights the increasing risks posed by mobile attacks like mishing, sideloaded apps, and outdated OS vulnerabilities, emphasizing the need for continuous app vetting, device attestation, and proactive vulnerability management. Key concerns include rising smishing attacks, spyware and Trojans growth, and insecure data communication within enterprise apps. #Mishing #SideloadedApps #Vultur #DeviceAttestation

Read More