CyberWire Daily
CyberWire Daily
N2K Networks
The Black Basta ransomware riddle. [Research Saturday]
19 minutes Posted Jul 27, 2024 at 7:00 am.
0:00
19:04
Download MP3
Show notes

Dick O'Brien from Symantec Threat Hunter team is talking about their work on "Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day." Also going to provide some background/history on Black Basta. CVE-2024-26169 in the Windows Error Reporting Service, patched on March 12, 2024, allowed privilege escalation.

Despite initial claims of no active exploitation, recent analysis indicates it may have been exploited as a zero-day before the patch.

The research can be found here:

Learn more about your ad choices. Visit megaphone.fm/adchoices