SecOpsNews / news

RSS items as GitHub Issues for the discerning engineering leader or security professional
MIT License
43 stars 0 forks source link

[HackerNews] BlackByte Ransomware Abuses Vulnerable Windows Driver to Disable Security Solutions #3863

Closed github-actions[bot] closed 2 years ago

github-actions[bot] commented 2 years ago

In yet another case of bring your own vulnerable driver (BYOVD) attack, the operators of the BlackByte ransomware are leveraging a flaw in a legitimate Windows driver to bypass security solutions. "The evasion technique supports disabling a whopping list of over 1,000 drivers on which security products rely to provide protection," Sophos threat researcher Andreas Klopsch said in a new technical

https://thehackernews.com/2022/10/blackbyte-ransomware-abuses-vulnerable.html

github-actions[bot] commented 2 years ago

This issue is stale because it has been open 1 day with no activity. Remove stale label or comment or this will be closed in 1 day.

github-actions[bot] commented 2 years ago

This issue was closed because it has been stale with no activity.