International Cyber Expo International Cyber Expo
  • About Us
Sunday, 26 July, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Huntress Unveils Enhanced Identity Threat Detection & Response Solution as New Research Warns of Rising Identity-Based Attacks

First to Deliver Proactive Protection Against OAuth Application Threats in Microsoft 365 Environments

by The Gurus
April 28, 2025
in Featured
Share on FacebookShare on Twitter

Huntress today announced major enhancements to its Managed Identity Threat Detection and Response (ITDR) solution, delivering a purpose-built answer to disrupt hacker identity tradecraft. Alongside the launch, Huntress also revealed new research underscoring the growing threat of identity-based attacks and organisations’ struggles to defend against them.

Based on findings from an independent UserEvidence survey of over 600 IT and security professionals, the Huntress 2025 Managed ITDR Report: Identity Is the New Security Perimeter highlights concerning trends about the surge, impact, and difficulty in detecting identity attacks:

  • Identity-based attacks are increasing: 67% of organisations have seen a rise in identity-related incidents over the past three years, with more than a third (35%) reporting that such attacks made up over 40% of their security incidents in the past year.

  • Rogue applications are a major risk: 45% of respondents experienced rogue or malicious applications within the past year, with 46% citing them as a leading concern.

  • Detection and response remain too slow: 53% of organisations admit it takes hours to detect identity attacks, while 68% said they typically can’t respond until attackers have already established persistence.

  • The financial impact is steep: 32% of businesses that suffered identity-based incidents reported losses exceeding $100,000.

“There’s no denying identity is the new endpoint. With widespread cloud adoption, the shift to hybrid work, and an increased reliance on SaaS applications, the identity attack surface has exploded over the past few years,” said Prakash Ramamurthy, Chief Product Officer at Huntress. “Hackers are no longer wasting time breaking into networks the hard way. They’re logging in using stolen credentials, session cookies, and access tokens to bypass endpoint protection and exploit weak multi-factor authentication. Our Managed ITDR solution gives organisations the proactive detection and response they need to take control of their identity security posture before attackers do.”

Delivering “Always-On” Advanced Detection and Response

Currently safeguarding over 1.8 million identities, Huntress Managed ITDR has stopped 28,000 identity attacks in just the past six months. With an impressive three-minute mean time to respond (MTTR) and a low false positive rate, the solution thwarts phishing, Adversary-in-the-Middle (AitM) attacks, and full-scale account takeovers before they escalate.

Powered by newly introduced capabilities, Rogue Apps, Unwanted Access, and Shadow Workflows, Huntress dismantles the tactics cybercriminals rely on:

  • Rogue Apps: Huntress becomes the first vendor to offer proactive defence against OAuth application threats. Rogue Apps actively detects malicious or risky OAuth apps in Microsoft 365 environments, providing organisations with clear, actionable remediation steps.

  • Unwanted Access: By monitoring for unexpected login behaviours, anomalies related to location or VPN usage, and other suspicious activity, Unwanted Access detects session hijacking and credential theft, isolating compromised identities before damage occurs.

  • Shadow Workflows: Designed to counter business email compromise (BEC) and data theft, Shadow Workflows detects and alerts on malicious inbox rules and mail forwarding settings. Additional enhancements to detect outbound phishing campaigns are planned for Q2.

“Through our research, it became strikingly clear that the threat posed by malicious OAuth applications was far greater than initially anticipated,” said Matt Kiely, Principal Cybersecurity Researcher at Huntress. “That realisation drove us to develop the Rogue Apps capability to empower organisations to proactively detect and eliminate these threats. With this new capability, we’ve already analysed over 20 million OAuth applications across our customer base and have been able to pinpoint those most likely to be malicious with incredible precision. This allows us to shrink the proverbial haystack, quickly find malicious OAuth applications, and swiftly take action.”

Customer feedback has been equally enthusiastic. “Huntress Managed ITDR has been a game-changer for us. Not only is it priced in a way that actually works for our clients, but it’s also made managing their Microsoft 365 identities and email environments so much easier,” said Ryan Rowbottom, Director of IT Services at PCS. “The tool is super effective, and the team at Huntress keeps rolling out new capabilities like Rogue Apps to help us stay ahead of attackers. While I was initially sceptical because the price seemed almost too good to be true, I’ve been completely won over.”

ShareTweet
Previous Post

Organisations Unprepared For Age of Quantum Computing

Next Post

6 Best CMMC Consulting Services for Small Businesses

Recent News

65% of Organisations Still Detect Unauthorised Shadow AI Despite Visibility Optimism

KnowBe4’s Unveils Custom AI Video Builder

July 24, 2026
Examining the Unintended Consequences of the Online Safety Act

Examining the Unintended Consequences of the Online Safety Act

July 24, 2026
Research Shows Quantum Security Deployment Remains Stuck Despite Enterprise Planning

Research Shows Quantum Security Deployment Remains Stuck Despite Enterprise Planning

July 23, 2026
FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations

FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations

July 23, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol