Cybersecurity News

Filters
Tag
Reset

Filtered by tag: privilege escalation × Clear

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

Researchers found Microsoft Defender's signed remediation driver can be repurposed as a kernel-level attack primitive without exploits or memory corruption. By instructing the trusted driver to execute arbitrary file and registry operations from Ring 0, attackers gain powerful kernel access. The technique requires no vulnerabilities, leveraging a legitimate Microsoft component against itself.

CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware | Huntress

Huntress identified attacks exploiting CitrixBleed 2 (CVE-2025-5777) that follow a consistent seven-step pattern leading to DragonForce ransomware deployment. The intrusions involve novel local privilege escalation techniques. The similarity across incidents suggests a coordinated threat actor or shared playbook, and organizations using vulnerable Citrix systems are urged to patch immediately.