On sourcing. Every figure below is from the Huntress 2026 Cyber Threat
Report and is Huntress’s measurement, not ours. Cyberneza is an authorized Huntress
reseller. We have added the interpretation for defense contractors; the data is theirs.
That is the largest sector movement in the report, and manufacturing is where a great deal of
the defense industrial base actually sits — machine shops, fabricators, engineering firms
and component suppliers holding CUI under a DFARS flow-down.
It is worth being precise about what this does and does not show. It is a rise in observed
attacks against a sector, not a statement that defense suppliers specifically were targeted, and
Huntress’s visibility is into its own customer base rather than the whole economy. What it
does establish is direction: the population of organizations that look like a mid-sized supplier
saw substantially more hostile activity in 2025 than in 2024.
The operational read is that a small manufacturer can no longer treat itself as too small to be
interesting. The attacks in this report are not targeted campaigns against named victims; they
are a standardised playbook run at scale against whoever is reachable.
This is the finding that should worry a small supplier most, because RMM software is how nearly
every organization under a few hundred people receives IT support. Attackers are not exploiting
a vulnerability in it. They are using it the way an administrator would.
Huntress’s own framing is worth quoting: adversaries are “increasingly aligning their
operations with legitimate administrative behavior… blurring the lines between malicious
activity and authorized activity.”
A control that checks whether approved software is installed will not catch this, because the
software is approved. Detecting it means noticing that an approved tool did something unusual
— at an unusual hour, from an unusual place, against an unusual set of hosts. That is a
behavioural judgement made over time, which is a different capability from an inventory.
AiTM phishing does not break multi-factor authentication. It waits for the user to complete it
and steals the resulting session, which means the attacker inherits an authenticated session
without ever holding the second factor.
This matters for anyone whose 800-171 programme treats IA.L2-3.5.3 as
closed because MFA is enforced. MFA remains necessary and it remains the right control. It is
simply not, on its own, sufficient against this technique — and the practice is scored as
implemented either way, which is exactly how a control can be genuinely in place and still leave
the risk open.
Related figures from the same report: over 35% of identity threats came from suspicious logins
— risky locations, malicious networks, anonymising VPNs — and 19% from mailbox
manipulation and persistence, which Huntress describes as a signature of business email
compromise.
RMM abuse, AiTM session theft and mailbox persistence share a property: at the moment they occur
they are indistinguishable from authorized activity. No configuration setting blocks them,
because there is nothing malformed to block. They are identified by someone or something
observing that authorized-looking activity does not fit the pattern.
That is the practical reason several NIST SP 800-171 families — audit and accountability,
system and information integrity, incident response — describe continuous activity rather
than a state. They are written the way they are because the threats they address only become
visible over time.
It is also why a self-assessment can be honestly completed and still overstate. A supplier can
have monitoring tooling deployed, logging enabled and an incident response plan written, and
have none of it reviewed by anyone between one assessment and the next. The controls exist. The
activity the controls describe does not happen.
Find out who can reach your RMM
List every remote access and management tool in the environment, who can authenticate to
each, and whether anyone would notice an out-of-hours session. Include tools belonging to
your IT provider, which are frequently outside your own inventory.
Test whether anyone reads the logs
Pick a security-relevant event from last month and trace who reviewed it and when. If the
answer is nobody, your audit and accountability practices are documented rather than
operating, and that is a finding waiting to happen.
Look past MFA on identity
Check whether you would detect a successful sign-in from an anomalous location on a valid
session, a new mailbox forwarding rule, or a newly consented OAuth application. These are
the AiTM and BEC indicators, and none of them trip an MFA control.
Want to know which of your practices are documented but not running?
We scope the CUI boundary, assess the current state, and are explicit about which requirements
need something operating continuously rather than written down.
Figures throughout are from the Huntress 2026 Cyber Threat Report and are Huntress’s
measurements. Cyberneza is an authorized Huntress reseller.