
Work Here?
Huntress delivers managed security services focused on endpoint detection and response (EDR) and proactive threat hunting. It continuously monitors client systems around the clock to detect cyber threats, particularly ransomware and other advanced attacks, and only raises alerts after analysts verify them. In addition to detection, Huntress provides security awareness training and educational resources to help clients improve cybersecurity practices. The service is designed to complement Microsoft 365 environments and emphasizes personalized reporting and strong customer support. The company’s goal is to help businesses defend against cyber threats with reliable, verified detections and practical guidance, reducing false positives and improving security posture.
Industries
Enterprise Software
Cybersecurity
Company Size
1,001-5,000
Company Stage
Series D
Total Funding
$309.8M
Headquarters
Columbia, Maryland
Founded
2015
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$309.8M
Above
Industry Average
Funded Over
7 Rounds
Industry standards
100% remote work environment
Generous PTO including vacation, sick time, and paid holidays
12 weeks paid parental leave
Highly competitive and comprehensive medical, dental, and vision benefits plans
401(k) with 5% contribution regardless of employee contribution
Life and Disability insurance plans
Stock options for all full-time employees
One-time $500 stipend to build/upgrade home office
Annual allowance for education and professional development assistance
$75 USD/month digital reimbursement
Access to both Udemy and BetterUp platforms for coaching, personal, and professional growth
Arctic Wolf launches new MDR offering for managed service providers. September 18, 2026 Arctic Wolf announced the launch of Aurora MDR Connect, a managed detection and response offering designed for managed service providers (MSPs). This new service aims to provide a streamlined version of Arctic Wolf's cybersecurity platform to partners, enabling them to deliver enterprise-grade security to a wider range of customers more quickly, as reported by Channeldive. Aurora MDR Connect builds upon Arctic Wolf's existing managed detection and response (MDR) services, specifically targeting MSPs that serve midmarket companies and those with fewer than 100 employees. The offering simplifies deployment by eliminating the need for network sensors, relying solely on endpoint agents to collect security data. This allows for faster implementation and reduced operational complexity, catering to businesses embracing remote and hybrid work models. Arctic Wolf's strategy involves treating MSPs as their direct customers, empowering them to integrate Arctic Wolf's technology with their own services. Analysts note that this move positions Arctic Wolf to compete with other MDR providers like Huntress and Blackpoint, though the company must carefully manage its partner tiers to avoid cannibalization. The company emphasizes its channel-first approach, with its MSP program being its fastest-growing business unit.
Huntress expands into Africa with new QBS Software Africa partnership. Cybersecurity firm targets AI-driven threats as it launches distribution deal in South Africa and Sub-Saharan region. Huntress is expanding into Africa through a new distribution partnership with QBS Software Africa, the company announced today. The move marks the latest step in Huntress' international growth as organised, AI-enabled cybercrime continues to rise worldwide. The expansion comes as Africa faces a mounting cybersecurity crisis. According to INTERPOL's 2026 African Cyberthreat Assessment, artificial intelligence is now linked to 55% of reported cybercrime across the continent, with direct economic damages surpassing $5 billion. Attackers are increasingly using AI to scale established tactics against under-resourced organisations, exploiting gaps in security coverage. Under the new agreement, local value-added resellers and managed service providers will gain access to the Huntress Agentic Security Platform and its 24/7 AI-centric Security Operations Center. The platform is powered by Athena, Huntress' agentic investigation system, which the company says combines machine-speed threat investigation with human security expertise to catch novel attacks before they escalate. "Expanding into Africa is an important step in Huntress' mission to protect all businesses from organized cybercrime," said Adam Waggott-Moss, Head of EMEA Distribution at Huntress. "QBS Software Africa brings the local market knowledge, channel relationships, and regional expertise to help extend that protection to more businesses and build a strong foundation for long-term growth across the region." Headquartered in South Africa, QBS Software Africa will act as a launchpad for the rollout, beginning in South Africa before extending into select Sub-Saharan African markets. The partnership pairs Huntress' cybersecurity technology with QBS Software Africa's local channel expertise, technical support, and go-to-market resources, aiming to help regional partners scale stronger security offerings for their customers. "Huntress' combination of innovative technology and elite security expertise gives businesses across Africa the ability to keep pace with the attackers targeting them," said Sanjay Mithal, Head of Strategic Vendor Alliances at QBS Software Africa. "The Huntress Agentic Security Platform brings layered defence together with the security experts who understand adversary behavior best, helping organizations across the region stay ahead of threats and sleep a little easier at night." The Africa launch builds on a period of rapid international growth for Huntress, which now protects 270,000 businesses across more than 100 countries. Over the past year, the company has deepened its presence across Europe and Asia Pacific, with adoption spreading across sectors including manufacturing, construction, retail and utilities, driven by investment in regional teams and channel partnerships. Huntress plans to host a livestream on September 16 covering its Agentic Security Platform, titled "Inside the Agentic Huntress Platform: Beating Adversaries at Machine Speed." You can register for the webinar here.
CVE-2026-86218 pre-auth RCE CVSS 10 exploited in wild. by Nam Phong · Published September 7, 2026 · Updated September 7, 2026 Tl;dr. On September 6, 2026, N-able released an urgent security update fixing an actively exploited zero-day flaw. The critical N-central vulnerability allows remote unauthenticated attackers to execute arbitrary code with root privileges. Consequently, administrators must apply Hotfix 4 immediately to protect on-premises appliances from complete system takeover. Why it matters. Massive attack surface for service providers. Managed service providers run N-central software to control thousands of client computers worldwide. Therefore, compromising a centralized management server exposes every downstream workstation and server on that network. Attackers can execute arbitrary scripts, distribute ransomware payloads, and establish persistent backdoors across entire corporate infrastructures. In fact, a single server intrusion can compromise dozens of connected business networks simultaneously. Active exploitation and maximum severity. Furthermore, threat actors are actively hunting vulnerable appliances across the public internet. The CVSS score for CVE-2026-86218 reaches the maximum possible rating of 10.0. Active N-central vulnerability exploitation makes this security flaw an immediate emergency for IT operations teams. Cybersecurity firm Huntress confirmed real-world intrusions against a production server following separate attacks observed in August. N-able acknowledged the immediate danger in its official advisory. Specifically, the vendor stated, "Unlike the earlier vulnerabilities, this newly identified vulnerability has been observed being exploited in the wild." Compounding risks from earlier exploits. This incident follows earlier security disclosures from August involving remote management consoles. In those previous intrusions, attackers hijacked management tools to control downstream client systems directly. The newly discovered exploit chain bypasses security controls much earlier in the network exchange. As a result, attackers achieve administrative dominance without requiring valid credentials. How the attack works. Reconnaissance and endpoint probing. The attack sequence begins with unauthenticated web requests directed at exposed administration consoles. Specifically, adversaries query the remote control action endpoint with targeted appliance identifiers to map the environment. They send URL-encoded requests to internal API routes to test server permissions. These initial probes help attackers verify the software version before launching their primary exploit. Authentication bypass and account creation. Next, the threat actor exploits an access control flaw within the internal API filter. This flaw pairs with an authentication bypass flaw in internal endpoints. By manipulating request parameters, an attacker triggers unauthorized administrative account creation. Attackers append unexpected strings like invalid domains to known email addresses during user registration. Pre-Authentication remote code execution. Finally, the attacker triggers pre-authentication remote code execution through the CVE-2026-86218 flaw. This action grants the adversary unrestricted control over the underlying operating system. In their technical analysis of the N-able vulnerability exploitation, Huntress confirmed that attackers also established unauthorized Cloudflare tunnels. These hidden tunnels allow threat actors to maintain persistent remote access while bypassing perimeter security tools. Affected versions. Impacted software builds. The security flaw impacts all on-premises N-central builds prior to version 2026.3.1.14. Systems running earlier updates, including Hotfix 3, remain vulnerable to this specific attack chain. Additionally, N-able confirmed that previous hotfixes released in August did not resolve this separate execution vector. Deployment footprint. Fortunately, N-able applied automated updates to all hosted instances across the Americas, Europe, and the Asia-Pacific region. However, thousands of on-premises deployments remain managed directly by independent system administrators. Organizations that maintain their own internal servers must verify their build numbers without delay. Patch and mitigation steps. Immediate firmware updates. Administrators must apply N-central 2026.3 Hotfix 4 immediately across all on-premises installations. N-able stressed urgency in its advisory notes. The company stated, "As this is a critical zero-day vulnerability, we need you to apply this hotfix immediately to protect you and your customers." Upgrading to this release ensures that the underlying API filters block unauthorized command requests. Forensic audits and network lockdown. After applying the patch, security teams should inspect server log files for signs of intrusion. Specifically, examine the proxy logs and system logs for URL-encoded anomalies. Check the user database for unauthorized administrator accounts or anomalous email addresses. Organizations should review the official N-able security advisory for additional update instructions. Finally, restrict console access from the public internet using dedicated virtual private networks. Closing open management ports dramatically reduces the risk of remote intrusion. Support its threat intelligence. If you find its technology report and cybersecurity news helpful, consider supporting its work.
News & articles. At ConnectWeb Connectweb has a team of editors and researchers collating the most relevant information to you and your industry. All Directories' publications and sites provide a wealth of information for research or marketing, and are used by public and corporate libraries, educational institutions, government departments, corporations and SMEs across the country. Access the latest company news and announcements distributed through Medianet. Information Technology 31/08/2026 08:00 blueAPACHE Key Facts: * Huntress is now available two ways through blueAPACHE: as a reseller offering or a fully managed service. * Managed EDR and ITDR extend existing Microsoft Defender, Entra and Business Premium investments. * Follows blueAPACHE's ControlUp, Mimecast and NinjaOne partnerships ahead of its October roadshow. * Huntress Australian headcount up 183 per cent, from 24 to 68 in two years. blueAPACHE expands Huntress partnership to accelerate access to enterprise-grade cybersecurity across Australia. Partnership expands Huntress into blueAPACHE's managed and reseller security models, helping organisations of all sizes access enterprise-grade protection and strengthen security across existing Microsoft environments. SYDNEY, Australia, 31 August, 2026 - blueAPACHE, Australia's most awarded mid-market IT services provider, has expanded its partnership with global cybersecurity company Huntress to include a new reseller offering alongside its existing managed services relationship, giving Australian organisations of all sizes faster, more flexible access to enterprise-grade protection while strengthening the value of their existing Microsoft security investments. Building on more than a year of managed services collaboration, the expanded partnership now gives businesses two ways to access Huntress through blueAPACHE: directly through its reseller model or as part of a fully managed service. Organisations with internal cybersecurity teams can use Huntress for always-on detection and response, freeing their teams to focus on the security priorities most critical to their business, while those that prefer a fully managed approach can continue to rely on blueAPACHE and Huntress to take on the day-to-day security burden and deliver continuous protection. Together, the two models help businesses access enterprise-grade protection faster in a way that is most effective for their business. "Mid-market and SMB businesses need security that fits how they operate without compromising on protection against today's most complex threats," said blueAPACHE CEO Michael Zuppa. "As Microsoft's Partner of Choice for Security Services for SMB and mid-market, we're focused on helping customers get more from their existing Microsoft investments without compromising on the end-to-end security they need. Expanding our partnership with Huntress means strengthening security across customers' environments, freeing their teams to stay focused on the security priorities that matter most to their business." Strengthening blueAPACHE's Microsoft security practice, Huntress helps customers extend the value of their existing Microsoft investments, including Microsoft Defender and Microsoft Entra, through Managed EDR and Managed ITDR. For organisations standardised on Microsoft Business Premium, the partnership extends the value of their existing licenses and adds monitoring, detection and response directly into the environments they already use. The announcement follows a period of rapid regional growth for Huntress, which has expanded its Australian headcount from 24 people in June 2024 to 68 as of July 2026, an increase of 183 per cent in two years, as the company continues to invest in its local channel and reseller ecosystem. "Working with blueAPACHE gives us a partner who already understands what Australian mid-market organisations need from a security platform," said Tuan Nguyen, Vice President of Channels and Alliances at Huntress. "With this expansion in our partnership, blueAPACHE is opening more pathways to enterprise-grade protection with Huntress, giving businesses of all sizes the speed and flexibility to deploy security in the way that works best for them." Huntress continues to expand its security posture management capability across identity and endpoint, giving blueAPACHE customers access to newer parts of the Huntress platform as they roll out. The expanded partnership comes as blueAPACHE prepares to take its Managed Services Re-engineered strategy to market through a national roadshow in October 2026. The program will showcase how organisations can modernise IT operations, strengthen cyber resilience and improve service outcomes through a combination of technology innovation, automation and specialist expertise. Huntress will join blueAPACHE as one of several strategic technology partners supporting the initiative, helping organisations maximise the value of their Microsoft security investments while strengthening detection and response capabilities. About blueAPACHE Founded in 1998, blueAPACHE is an Australian-owned IT services provider specialising in Managed Services, cloud, security and modern workplace solutions for mid-market and enterprise organisations. blueAPACHE delivers outcome-driven services aligned to strong security standards and operational excellence, supporting highly regulated and rapidly scaling businesses across multiple sectors. About Huntress Huntress is a global cybersecurity company on a mission to make enterprise-grade products accessible to all businesses. Fully owned and purpose-built from the ground up, the Huntress Agentic Security Platform is specifically designed to continuously address the unique needs of security and IT teams of all sizes, protecting endpoints, identities, data, and employees, for trusted outcomes and peace of mind. Contact details: Media Contact Fiona Hamann Hamann Communication 0415 191 659 * Images - tuan-nguyen-headshot-portrait.png Tuan Nguyen, Vice President of Channels and Alliances at Huntress Download - Michael Zuppa_Blue-APACHE-Headshots-HIGH-RES-005.jpg blueAPACHE CEO Michael Zuppa Download * attachments - blueAPACHE Huntress media release final.pdf Download. ConnectWeb. ConnectWeb is Australia's leading publisher of biographical data, directories and specialist newsletters. With ConnectWeb you gain access to its comprehensive database of contacts and companies in media, government and associations. Connect with Connectweb.
Huntress vs Arctic Wolf: which MDR model fits a small business. Arctic Wolf integrates the security tools you already own. Huntress brings the detection layer with it. Reviewed August 21, 2026 by Kfir Yair, CISSP · CCFH (CrowdStrike) · ZDTA (Zscaler) Most comparisons between Huntress and Arctic Wolf get stuck on which one detects more. That is the wrong axis for a small business. The more useful question is architectural: does the product bring the detection layer with it, or does it correlate the detection you already have? That single difference explains most of what changes after you sign. Disclosure: Obsidian Ridge is a Huntress MSSP partner and delivers Huntress-powered managed detection and response. Read the recommendation below with that in mind. The framework and the "Arctic Wolf is better for you" cases below are the ones Obsidian Ridge tell prospects to run themselves before deciding. Short answer: the deciding factor is how much telemetry you already generate. Arctic Wolf describes an open XDR architecture with "over 200+ integrations across attack surfaces," designed to pull in telemetry from your existing tools across endpoint, network, cloud, and identity rather than requiring proprietary agents exclusively. Huntress takes the opposite approach. It ships its own detection technology onto the endpoint and is designed to coexist with an antivirus or NGAV layer you already run. So the question answers itself once you look at your own environment: * If you have a managed firewall, a cloud tenant with real logging, an identity provider, and an existing endpoint tool, you have a correlation problem. Arctic Wolf's model is built for that. * If you have laptops, Microsoft 365, and no security tooling worth integrating, you do not have a correlation problem. You have a detection gap, and integrating four sources of nothing produces nothing. Most businesses between five and fifty employees are in the second group and do not realize it. They hear "integrates with everything you own" and read it as a feature, when for them it is closer to a prerequisite. Get monthly field notes. One practical email a month with new articles, security observations, and the patterns worth paying attention to. What Arctic Wolf is actually good at. Arctic Wolf's differentiation is the Concierge Security Team, a group of security experts meant to understand "your organization's environment, priorities, and risks" over time rather than a rotating alert queue. They report completing over 74,000 Security Posture in-Depth Reviews in 2025. That model is genuinely strong, and it solves a real problem: MDR services that only ever tell you what happened, never what to fix. Arctic Wolf structures the relationship around posture improvement, not just alerting. Their published framing runs Detect, Respond, Remediate, Incident Response as four phases, with remediation treated as its own deliverable rather than a footnote. Their headline outcome claim is that MDR can "reduce the frequency of a successful attack by up to 90% and decrease the impact by up to 90%." There is one more area where they are ahead, and it is worth saying plainly rather than skipping past: cyber insurance. Arctic Wolf has invested more visibly in the insurance ecosystem than most MDR vendors, publicly describing work with 150+ organizations across that market. If your buying trigger is an insurance application or a renewal, that alignment is a real advantage and you should weigh it. Where the model strains for a small business. Three places. 1. The integration surface assumes an integration surface. Two hundred integrations is impressive when you can use twenty of them. A dental practice with cloud-managed laptops and a Microsoft 365 tenant will use two or three. You are paying for a correlation engine and feeding it one stream. 2. The buying motion is heavier. Arctic Wolf does not publish pricing. Quotes go through their sales team and generally involve an annual commitment. That is normal for the segment they serve, but it means the evaluation takes weeks, not an afternoon, and you commit for a year before you know how it feels to operate. Treat any per-endpoint number you find on a third-party pricing aggregator as unverified. Several sites publish confident-looking figures with no disclosed source; some of them are run by competitors. Get the quote in writing. 3. Named-team value scales with environment complexity. A Concierge Security Team is worth a great deal when there is enough environment to have opinions about. For a fifteen-person firm running Microsoft 365 and nothing else, the quarterly posture review is going to say roughly the same thing each quarter, and you are funding a relationship model built for a larger buyer. None of that makes Arctic Wolf a bad product. It makes it a product priced and designed for a customer with more surface area than most small practices have. Where Huntress fits instead. Huntress starts from the assumption that you do not already have the detection layer. It brings its own, packages a 24/7 SOC behind it, and is designed to sit alongside whatever antivirus you are already running rather than requiring a rip-and-replace. For a lean team the practical effect is fewer decisions. There is no integration project, no telemetry inventory, no question about whether your firewall logs are rich enough to be worth forwarding. The agent goes on, the SOC watches, and escalations arrive with a remediation instruction attached. The partnership disclosure at the top of this article applies here. I still think the recommendation is defensible, and the reason is operational rather than commercial. The businesses I work with usually need the detection layer itself, not a way to correlate detection layers they never bought. There is a second Huntress advantage worth naming for regulated practices: identity. Business email compromise in a Microsoft 365 tenant is the single most common serious incident I see in dental, legal, and accounting practices, and identity threat detection is packaged rather than being a separate architectural decision. The honest decision framework. Ask these in order. * Count your real telemetry sources. Not tools you own, but sources that produce security-relevant logs someone would actually read. If the answer is under three, the correlation value proposition does not apply to you yet. * Ask who acts on the output. Both services will tell you what to do. Neither will log into your tenant and do it unless you have separately bought that. If nobody on your side owns remediation, you have not solved the problem with either purchase. You have bought a better description of it. * Ask what happens in month thirteen. With an annual commitment, the exit is a year away. Ask what renewal looks like, what happens to pricing at renewal, and whether the contract auto-renews. * If insurance is the trigger, say so out loud. It changes the answer. Arctic Wolf's ecosystem alignment is real. So is the fact that most carrier questionnaires ask about controls (MFA, EDR, backup, awareness training, and increasingly penetration testing) rather than about which vendor supplies them. Getting the evidence pack right often matters more than the logo on it. That is the whole premise of its Cyber Insurance Readiness Sprint. * Price the operating burden, not the license. The cheaper subscription that consumes six hours a month of your office manager's attention is not cheaper. Which one I would pick, by business shape. Under 25 employees, no internal IT, Microsoft 365 and laptops: Huntress. There is nothing for an XDR correlation layer to correlate, and the annual commitment is a poor trade at that size. 25 to 200 employees with a real IT function, a firewall, cloud infrastructure, and existing tooling: genuinely competitive. Arctic Wolf's integration model starts paying off here, and the Concierge Team has enough environment to work with. Run both evaluations. Any size, where the trigger is an insurance renewal in under 60 days: neither purchase alone fixes it. Both take time to deploy and neither retroactively produces the evidence an underwriter asks for. Fix the control gaps and the documentation first, then choose the platform. Regulated practice where BEC is the top risk: weight identity coverage heavily and ask both vendors to walk through exactly what happens when a mailbox rule is created at 2 a.m. The part neither vendor will tell you. The MDR market has converged. Both of these companies run competent SOCs and will catch the things a small business is realistically going to encounter. The difference in raw detection between reputable MDR vendors is much smaller than the difference between having MDR and not having it. What actually varies is the operating model: who watches, what they can touch, how fast they reach you, what they hand you when they do, and what you are still expected to do yourself. That is what you are buying. Evaluate that, and the logo question mostly answers itself. If you want help mapping this against your own environment rather than a vendor matrix, that is what a 30-minute briefing is for. If you would rather see numbers first, its pricing is published, including what is and is not included at each tier. Last updated August 21, 2026. Obsidian Ridge refresh this content as the threat landscape and tools evolve.
Find jobs on Simplify and start your career today
Industries
Enterprise Software
Cybersecurity
Company Size
1,001-5,000
Company Stage
Series D
Total Funding
$309.8M
Headquarters
Columbia, Maryland
Founded
2015
Find jobs on Simplify and start your career today