Cyber criminals are targeting Foundation accounting software used by contractors in the construction industry. Discovered by Huntress researchers, the threat actors exploit the software’s mobile-access feature and Microsoft SQL Server’ default admin account to gain brute-force entry and run automated attacks. Experts recommend password rotation and disconnected installs to prevent these attacks.

CISA Warns of Hackers Actively Exploiting Windows Server Update Services RCE Vulnerability in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned organizations worldwide about active exploitation of a critical remote code execution (RCE) vulnerability in Microsoft’s


