Huntress has unveiled their inaugural SMB Threat Report, highlighting key insights on emerging cyber threats and tradecraft targeting small and mid-sized businesses (SMBs). Over half of the third quarter’s cyber attacks on small and medium-sized enterprises (SMEs) were “malware-free.” Adversaries are leveraging scripting frameworks and legitimate tools instead of deploying malware payloads. The report also highlights the increased use of remote monitoring and management (RMM) software tools as a vector for initial access, potentially linked to changes in working practices due to COVID-19. Remote monitoring and management software has been leveraged to facilitate persistence in 65% of incidents in Q3. The report calls for a reassessment of SME defense strategies and a more nuanced approach to threat detection and response.
The U.S. Navy has unveiled its long-awaited cyber strategy, aiming to enhance its cyber enterprise, collaborate with allies, and prioritize defense and operations in cyberspace. The strategy includes seven lines of effort focused on securing critical infrastructure, improving the cyber workforce, conducting cyber operations, defending enterprise IT, partnering to secure the defense industrial base, and fostering cooperation. The Navy acknowledges falling behind other branches in cybersecurity and plans to shift its contributions to digital defense.
Security researchers have discovered vulnerabilities in fingerprint sensors used in laptops from Dell, Lenovo, and Microsoft, allowing bypassing of Windows Hello fingerprint authentication. The researchers reverse-engineered software and hardware, identifying cryptographic flaws in the Synaptics sensor. Microsoft’s Secure Device Connection Protocol (SDCP) was found to be disabled on some devices, highlighting the need for OEMs to enable SDCP and audit fingerprint sensor implementations. This is not the first time Windows Hello biometrics-based authentication has been defeated, and the researchers suggest further exploration of memory corruption attacks on sensor firmware and security on other devices.
Attackers are using your tools against you. Using scripting frameworks and legitimate tools, attackers are evading traditional detection methods. They’re using your own RMM tools.
That said, you can at least take some comfort that the Navy has it hard, too. But know that they are investing, including securing critical infrastructure and improving the cyber workforce, with a comprehensive approach.

