Cybersecurity News
Filters
Filtered by tag: privilege escalation × Clear
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
Researchers found Microsoft Defender's signed remediation driver can be repurposed as a kernel-level attack primitive without exploits or memory corruption. By instructing the trusted driver to execute arbitrary file and registry operations from Ring 0, attackers gain powerful kernel access. The technique requires no vulnerabilities, leveraging a legitimate Microsoft component against itself.
CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware | Huntress
Huntress identified attacks exploiting CitrixBleed 2 (CVE-2025-5777) that follow a consistent seven-step pattern leading to DragonForce ransomware deployment. The intrusions involve novel local privilege escalation techniques. The similarity across incidents suggests a coordinated threat actor or shared playbook, and organizations using vulnerable Citrix systems are urged to patch immediately.
