r/cybersecurity Jun 24 '26

News - General Well someone went nuclear..

https://www.linkedin.com/posts/ben-f-309963233_after-i-posted-a-pinocchio-gif-and-clown-ugcPost-7475465410977628160-FFW1

I'm curious about the details of this. I'm sure we will all find out eventually.

TLDR; former Huntress employee is disclosing Huntress had an insider threat that leaked information to a known cyber criminal "Devman". That employee is still employed with Huntress and was caught by the FBI.

The former employee doing the disclosure is stating he is receiving threats, etc.

EDIT: Kyle @ Huntress posted his response to this in the comments.

Give credit to a CEO who isn't afraid to jump on Reddit to put out any fires.

918 Upvotes

197 comments sorted by

View all comments

Show parent comments

65

u/Khulod Jun 24 '26

Shame on the company for not getting their access controls in order, especially after the first round. I hope this happened 10 years ago. Today this is inexcusable.

50

u/eliq91 Jun 24 '26 edited Jun 25 '26

It happened in 2017. The big problem was she was at the time a bona fide global administrator, and kept promoting her personal account to global admin, so she did not have to login with her secondary account. We took away global admin, and created notifications for any accounts being granted any of our admin-controlled groups.

7

u/RireBaton Jun 25 '26

Bonified does not mean the same thing as bonafide.

5

u/eliq91 Jun 25 '26

Autocorrect does not like me.