Cyber criminals are targeting Foundation accounting software used by contractors in the construction industry. Discovered by Huntress researchers, the threat actors exploit the software’s mobile-access feature and Microsoft SQL Server’ default admin account to gain brute-force entry and run automated attacks. Experts recommend password rotation and disconnected installs to prevent these attacks.

CMMC’s Reality Check for the Defense Industrial Base: What Contractors Must Do Before Enforcement Hits
The Cybersecurity Maturity Model Certification’s (CMMC) reality check has arrived. After years of delays and speculation, enforcement moves from theory to action in November 2025


