International Cyber Expo International Cyber Expo
  • About Us
Friday, 18 September, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Huntress Makes RMM-Blocking Feature Free for All Customers as Attacks Surge 277%

Managed ESPM feature RMM Guard now free to all customers as vendor reports sharp rise in RMM-based attacks.

by Guru Writer
August 3, 2026
in News
Huntress Makes RMM-Blocking Feature Free for All Customers as Attacks Surge 277%
Share on FacebookShare on Twitter

Cybersecurity vendor Huntress has opened up a new application control capability to its entire customer base for free, as new data shows attacks abusing remote monitoring and management (RMM) tools rose sharply over the past year.

The feature, called RMM Guard, is part of a broader product Huntress is building called Managed Endpoint Security Posture Management (ESPM), currently in early access. RMM Guard inventories every remote access tool running across a customer’s environment and automatically blocks any that haven’t been explicitly authorised, including attacker-controlled copies of legitimate tools such as ScreenConnect.

The move comes as Huntress reports that RMM-based attacks increased by 277% over the past year, and that roughly a third of all incidents its analysts observed so far this year could have been prevented by blocking unauthorised RMM software from running in the first place.

Attackers have increasingly turned to legitimate remote access software as a way to gain persistent footholds inside victim environments, since such tools are widely trusted by IT teams and rarely raise alarms on their own. Huntress cited a recent case in which a phishing email disguised as a “pay increase” notice led an employee to install LogMeIn Resolve, giving an attacker remote access that was only caught thanks to endpoint monitoring and its 24/7 Security Operations Centre.

Application control, sometimes called allow-listing, is a long-established security practice that only permits known, approved software to run rather than trying to catch malicious activity after the fact. Huntress argues, however, that most application control products on the market were designed for large enterprises with dedicated security teams, and are too complex and resource-intensive for smaller IT teams and managed service providers (MSPs) to implement. Industry frameworks typically call for months of planning, policy-building and phased rollout before a full application control programme becomes usable, a timeline the company says is unrealistic for lean teams already stretched across other priorities.

Rather than asking customers to build out a full allow-list policy for every application, Huntress says its approach will focus first on categories of software most frequently abused by attackers, starting with RMM tools, before expanding to other categories such as AI and file-sharing applications.

RMM Guard was previously restricted to a learning mode and required a Huntress Managed SIEM subscription. Those restrictions have now been lifted, and the capability is available at no additional cost to any Huntress customer or partner with an agent deployed, while Managed ESPM remains in early access ahead of a wider commercial release.

Existing Huntress customers can request access to the ESPM early access programme through their account manager.

ShareTweet
Previous Post

AI pentesting tools are generating more findings than security teams can validate, new survey finds

Next Post

Check Point Named a Visionary Leader in 2026 Frost Radar for Enterprise Risk Mitigation and Management Platforms

Recent News

New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence

New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence

September 17, 2026
When Everyday Habits Become an Invisible Security Risk

When Everyday Habits Become an Invisible Security Risk

September 17, 2026
Could an Email You Never Read Hijack Your AI Assistant?

Could an Email You Never Read Hijack Your AI Assistant?

September 17, 2026
The AI Boom Is an Energy Boom: Kelcy Warren on How Data Centers Are Reshaping Natural Gas Demand

Salt Security expands CrowdStrike integration to tackle AI agent security

September 17, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol