Vendor
high
advisory
Plain Text Passwords: A Direct Path to Organizational Compromise
2 rules 4 TTPs 2 IOCsA threat actor, after gaining initial access via a SonicWall VPN vulnerability, exploited plain text Huntress portal recovery codes found on a security engineer's desktop to infiltrate the security platform, enabling defense evasion and furthering malicious activity.
SonicWall VPNs +1
credential-theft
defense-evasion
ransomware
plain-text-passwords
initial-access
security-platform-compromise
2r
4t
2i
high
advisory
Microsoft Security Updates — July 2026
10 CVEs 227 IOCsRoundup of Microsoft security advisories published in July 2026.
PoC
PowerShell +516
roundup
10c
227i
updated
high
advisory
Threat Actors Disabling AV and EDR Solutions
2 rules 2 TTPsThreat actors are actively disabling antivirus and EDR solutions through abusing Windows Firewall rules, uninstalling agents, and exploiting vulnerable drivers (BYOVD) to establish persistence, move laterally, and deploy ransomware undetected.
Defender Antivirus +2
defense-evasion
privilege-escalation
byovd
2r
2t