BlackByte Ransomware Abuses Vulnerable Windows Driver to Disable Security Solutions

Discussion in 'News Aggregator' started by Ravie Lakshmanan, 7 Oct 2022.

  1. In yet another case of bring your own vulnerable driver (BYOVD) attack, the operators of the BlackByte ransomware are leveraging a flaw in a legitimate Windows driver to bypass security solutions. "The evasion technique supports disabling a whopping list of over 1,000 drivers on which security products rely to provide protection," Sophos threat researcher Andreas Klopsch said in a new technical

    Continue reading...
     

Share This Page

Loading...