{"id":331869,"date":"2025-12-07T02:39:14","date_gmt":"2025-12-07T02:39:14","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/331869\/"},"modified":"2025-12-07T02:39:14","modified_gmt":"2025-12-07T02:39:14","slug":"soc-threat-radar-december-2025","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/331869\/","title":{"rendered":"SOC Threat Radar \u2014 December 2025"},"content":{"rendered":"<p>GUEST RESEARCH:\u00a0 Notable threats targeting organisations seen by Barracuda Managed XDR<\/p>\n<p>\u00a0Takeaways<\/p>\n<p>&#13;<br \/>\nA rise in attackers trying to use ScreenConnect for unauthorised remote access&#13;<br \/>\nA rise in Microsoft 365 login attempts from unfamiliar countries&#13;<br \/>\nAttackers using bought or stolen credentials for ransomware and data theft&#13;<\/p>\n<p>Attackers using ScreenConnect for unauthorised remote access<\/p>\n<p>What\u2019s happening?<\/p>\n<p>The SOC team recently noticed a rise in the suspicious use of ScreenConnect. This includes attackers attempting to connect endpoints to targets\u2019 ScreenConnect deployments, and attackers deploying ScreenConnect themselves to control hosts remotely.<\/p>\n<p>ScreenConnect is a trusted and popular remote device management tool used by many organisations and their managed service providers. As a result, the detection of ScreenConnect does not immediately arouse suspicion.<\/p>\n<p>Earlier in 2025, attackers discovered a serious weakness in older versions of ScreenConnect that could allow them break into systems and run harmful programs without permission. Hackers are using this vulnerability to take control of systems remotely, install ransomware, steal data, and to move through the network to other connected systems.<\/p>\n<p>The successful breach of an existing deployment can give criminals access to many devices and even organisations.<\/p>\n<p>ScreenConnect <a href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\/screenconnect-security-patch-2025.4\" target=\"_blank\" rel=\"noopener nofollow\">released<\/a> a patch for the vulnerability on April 24, 2025.<\/p>\n<p>Your organisation may be at risk if you are:<\/p>\n<p>&#13;<br \/>\nRunning older versions of ScreenConnect that haven\u2019t been updated.&#13;<br \/>\nUsing unmanaged or unauthorised remote access tools.&#13;<br \/>\nLack multifactor authentication (MFA) for admin accounts.&#13;<br \/>\nHave not yet applied the software patch to address the bug.&#13;<\/p>\n<p>To protect your organisation:<\/p>\n<p>&#13;<br \/>\nImplement a strong, multi-layered security solution such as Barracuda XDR Managed Endpoint Security that can spot and contain suspicious ScreenConnect activity.&#13;<br \/>\nEnsure your ScreenConnect software is running the latest version (25.2.4 or newer).&#13;<br \/>\nCheck your logs for suspicious or unusual activity.&#13;<br \/>\nEnable MFA for all accounts, especially administrator accounts.&#13;<br \/>\nBlock unknown remote access tools and closely monitor attempts to look up or connect to ScreenConnect web addresses.&#13;<\/p>\n<p>A rise in Microsoft 365 login attempts from unfamiliar countries<\/p>\n<p>What\u2019s happening?<\/p>\n<p>Barracuda\u2019s SOC team has detected a significant rise in attempts to log into Microsoft 365 accounts from countries where the targets don\u2019t operate \u2013 a clear red flag that attackers are trying to access accounts using stolen usernames and passwords.<\/p>\n<p>If the attackers succeed in breaching the network, they can access emails and files and impersonate the legitimate account holder to launch convincing internal phishing attacks and move deeper into the network.<\/p>\n<p>Your organisation may be at risk if you are:<\/p>\n<p>&#13;<br \/>\nNot implement geo-blocking or location-based login rules.\u00a0&#13;<br \/>\nAllowing employees to use weak or reused passwords.&#13;<br \/>\nLack MFA or don\u2019t enforce it consistently across the organisation.&#13;<br \/>\nNot monitoring logins for unusual locations or times&#13;<br \/>\nLack of monitoring for unusual login patterns.&#13;<\/p>\n<p>To protect your organisation:<\/p>\n<p>&#13;<br \/>\nEnforce the use of complex, unique passwords, and consider password managers.&#13;<br \/>\nEnable MFA everywhere \u2013 this is the single, most effective step you can take.&#13;<br \/>\nMonitor login alerts.&#13;<br \/>\nImplement conditional access policies that block logins originating from a restricted country\/region.&#13;<br \/>\nTrain employees to spot phishing attempts and report them.&#13;<br \/>\nImplement a strong, multi-layered security solution that can spot and block incidents at different stages of the attack chain.&#13;<\/p>\n<p>Attackers using bought or stolen credentials for ransomware and data theft<\/p>\n<p>What\u2019s happening?<\/p>\n<p>Cybercriminals are stealing or buying usernames and passwords (credentials) and using them to break into systems. Once inside, they launch ransomware attacks or steal sensitive data.<\/p>\n<p>These attacks often look like normal activity because the hackers use genuine credentials. Barracuda Managed XDR\u2019s SOC tools spot the clues left by attackers such as the unusual use of legitimate administrative tools (PsExec, PowerShell), multiple repeat or simultaneous login attempts or the unexpected creation of remote services.<\/p>\n<p>Your organisation may be at risk if you are:<\/p>\n<p>&#13;<br \/>\nAllowing employees to use weak or reused passwords.&#13;<br \/>\nLack MFA or don\u2019t enforce it consistently across the organisation.&#13;<br \/>\nNot monitoring unusual logins or the use of admin tools.&#13;<br \/>\nLack alerts for suspicious remote access or script execution.&#13;<\/p>\n<p>To protect your organisation:<\/p>\n<p>&#13;<br \/>\nEnforce the use of complex, unique passwords.&#13;<br \/>\nPassword policies that rotate credentials at regular intervals, for example every three months.&#13;<br \/>\nEnable MFA everywhere, and especially for admin and remote access accounts.&#13;<br \/>\nMonitor activity, looking for odd login times, the unexpected use of admin tools, or new remote services.&#13;<br \/>\nTrain employees to spot phishing attempts and report them.&#13;<br \/>\nImplement a strong, multi-layered security solution that can spot and block incidents at different stages of the attack chain.&#13;<\/p>\n<p>How Barracuda Managed XDR can help your organisation<\/p>\n<p>Barracuda Managed XDR delivers advanced protection against the threats identified in this report by combining cutting-edge technology with expert SOC oversight. With real-time threat intelligence, automated responses, a\u00a024\/7\/365 SOC team and\u00a0<\/p>\n<p>XDR <a href=\"https:\/\/www.barracuda.com\/products\/managed-xdr\/managed-vulnerability-security\" target=\"_blank\" rel=\"noopener nofollow\">Managed Vulnerability Security<\/a> that identifies security gaps and oversights, Barracuda Managed XDR ensures comprehensive, proactive protection across your network, cloud, email, servers and endpoints, giving you the confidence to stay ahead of evolving threats.<\/p>\n<p>For further information on how we can help, please get in touch with <a href=\"https:\/\/www.barracuda.com\/products\/managed-xdr\/consultation?utm_source=10212025a&amp;utm_medium=blog&amp;utm_campaign=blog\" target=\"_blank\" rel=\"noopener nofollow\">Barracuda Managed XDR<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"GUEST RESEARCH:\u00a0 Notable threats targeting organisations seen by Barracuda Managed XDR \u00a0Takeaways &#13; A rise in attackers trying&hellip;\n","protected":false},"author":2,"featured_media":331870,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[64,63,185592,185593,185595,105,12530,185594],"class_list":["post-331869","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-au","tag-australia","tag-barracuda","tag-screenconnect","tag-soc","tag-technology","tag-threat","tag-xdr"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/331869","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=331869"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/331869\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/331870"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=331869"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=331869"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=331869"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}