[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fG9bZMFvIkXWaxoOSIShsdSAuiq6gsJPDmmTc1GzYfmw":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"ec8b6c3b-5a99-4d80-9785-4160f5263887","Huntress Makes RMM-Blocking Feature Free for All Customers as Attacks Surge 277%","huntress-makes-rmm-blocking-feature-free-for-all-customers-as-attacks-surge-277-abf1dd","Cybersecurity vendor Huntress has opened up a new application control capability to its entire customer base for free, as new data shows attacks abusing remote monitoring and management (RMM) tools rose sharply over the past year. The feature, called RMM Guard, is part of a broader product Huntress is building called Managed Endpoint Security Posture […] The post Huntress Makes RMM-Blocking Feature Free for All Customers as Attacks Surge 277% appeared first on IT Security Guru.","Cybersecurity vendor Huntress has made its RMM Guard feature freely available to all customers due to a significant increase in attacks leveraging remote monitoring and management (RMM) tools. This feature blocks unauthorized remote access software, including attacker-controlled versions of legitimate tools like ScreenConnect. The move comes as Huntress reports a 277% rise in RMM-based attacks over the past year, with a third of incidents potentially preventable by blocking unauthorized RMM software.","Huntress offers RMM-blocking feature for free amid a 277% surge in RMM-based attacks.","Cybersecurity vendor Huntress has opened up a new application control capability to its entire customer base for free, as new data shows attacks abusing remote monitoring and management (RMM) tools rose sharply over the past year. The feature, called RMM Guard, is part of a broader product Huntress is building called Managed Endpoint Security Posture Management (ESPM), currently in early access. RMM Guard inventories every remote access tool running across a customer’s environment and automatically blocks any that haven’t been explicitly authorised, including attacker-controlled copies of legitimate tools such as ScreenConnect. The move comes as Huntress reports that RMM-based attacks increased by 277% over the past year, and that roughly a third of all incidents its analysts observed so far this year could have been prevented by blocking unauthorised RMM software from running in the first place. Attackers have increasingly turned to legitimate remote access software as a way to gain persistent footholds inside victim environments, since such tools are widely trusted by IT teams and rarely raise alarms on their own. Huntress cited a recent case in which a phishing email disguised as a “pay increase” notice led an employee to install LogMeIn Resolve, giving an attacker remote access that was only caught thanks to endpoint monitoring and its 24\u002F7 Security Operations Centre. Application control, sometimes called allow-listing, is a long-established security practice that only permits known, approved software to run rather than trying to catch malicious activity after the fact. Huntress argues, however, that most application control products on the market were designed for large enterprises with dedicated security teams, and are too complex and resource-intensive for smaller IT teams and managed service providers (MSPs) to implement. Industry frameworks typically call for months of planning, policy-building and phased rollout before a full application control programme becomes usable, a timeline the company says is unrealistic for lean teams already stretched across other priorities. Rather than asking customers to build out a full allow-list policy for every application, Huntress says its approach will focus first on categories of software most frequently abused by attackers, starting with RMM tools, before expanding to other categories such as AI and file-sharing applications. RMM Guard was previously restricted to a learning mode and required a Huntress Managed SIEM subscription. Those restrictions have now been lifted, and the capability is available at no additional cost to any Huntress customer or partner with an agent deployed, while Managed ESPM remains in early access ahead of a wider commercial release. Existing Huntress customers can request access to the ESPM early access programme through their account manager.","https:\u002F\u002Fwww.itsecurityguru.org\u002F2026\u002F08\u002F03\u002Fhuntress-makes-rmm-blocking-feature-free-for-all-customers-as-attacks-surge-277\u002F?utm_source=rss&utm_medium=rss&utm_campaign=huntress-makes-rmm-blocking-feature-free-for-all-customers-as-attacks-surge-277","https:\u002F\u002Fwww.itsecurityguru.org\u002Fwp-content\u002Fuploads\u002F2026\u002F08\u002FHuntress-RMM.png","2026-08-03T13:18:28+00:00","2026-08-03T14:00:14.565957+00:00",7,[18,21,24,27,29],{"name":19,"type":20},"Huntress","vendor",{"name":22,"type":23},"RMM Guard","product",{"name":25,"type":26},"Remote Monitoring and Management (RMM) tools","technology",{"name":28,"type":23},"ScreenConnect",{"name":30,"type":23},"LogMeIn Resolve","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":31,"icon":33,"name":34,"slug":35},null,"Threat Intelligence","threat-intelligence",[37,42,47,52],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":43},{"id":44,"icon":33,"name":45,"slug":46},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":48},{"id":49,"icon":33,"name":50,"slug":51},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":53},{"id":31,"icon":33,"name":34,"slug":35},[55,58],{"type":56,"value":28,"context":57},"malware","Attacker-controlled copies of legitimate tools such as ScreenConnect are blocked by RMM Guard.",{"type":56,"value":30,"context":59},"Phishing email led to installation of LogMeIn Resolve, giving attacker remote access."]