Find notable cyber news and cases, enriched with sources, timelines, and signals.

June Huntress post-breach analysis of Windows server persistence, BadIIS, and miner deployment

Technical Analysis
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

A June Huntress investigation reconstructed an attacker’s post-breach hardening on a single Windows server, showing how a compromise can turn into long-lived access and evasion. Initial access came through a SQL injection flaw on a web page tied to Microsoft SQL Server. After entry, the attacker performed service recon, enabled Remote Desktop, created a local Administrator account, and disabled Windows Defender. They then installed BadIIS IIS add-ons and a cryptocurrency miner, layering persistence and monetization on the same host.

Related Happenings

Apache Tomcat Oracle SQL injection flaw under active exploitation

Vulnerability
H score49 First: 05.08.2026 22:55 Last: 05.08.2026 22:55 Sources 1

About this happening: SQL injection in a public-facing Java application running Apache Tomcat let attackers reach an Oracle database and load the khunt toolkit as database-stored Java...

IT services firm in South Asia data exposed after Spirals breach

Data Leak
H score31 First: 16.07.2026 13:00 Last: 16.07.2026 13:00 Sources 1

About this happening: Spirals stole data from an IT services firm in South Asia, creating extortion leverage and a threat of public exposure. The intrusion moved from initial access to...

IT services firm in South Asia hit by ransomware attack

Incident
H score31 First: 16.07.2026 13:00 Last: 16.07.2026 13:00 Sources 1

About this happening: The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...

Major U.S. services company hit by ransomware attack linked to DragonForce

Incident
H score38 First: 16.06.2026 13:18 Last: 16.06.2026 13:18 Sources 1

About this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...

FamousSparrow Azerbaijanian oil-and-gas targeting campaign

Campaign
H score32 First: 13.05.2026 16:00 Last: 13.05.2026 16:00 Sources 1

About this happening: The China-linked FamousSparrow group ran a targeted cyberespionage campaign against an Azerbaijanian oil-and-gas company in the South Caucasus, highlighting a new...

Timeline

  1. 30.07.2026 17:01 2 articles · 8d ago

    June Huntress post-breach analysis of Windows server persistence, BadIIS, and miner deployment

    Initial Disclosure

    Initial access came through an unvalidated web input field that enabled SQL injection and access to the underlying Windows machine. The first observed actions were light reconnaissance and service discovery before persistence and evasion changes began.

    Show sources