More

    Hackers exploit zero-day Common Log File System vulnerability to plant ransomware




    • Microsoft said it observed a threat actor known as Storm-2460 abuse a use after free flaw in Windows Common Log File System Driver
    • The flaw is used to deploy PipeMagic, which is then used to deliver ransomware
    • Users are advised to install the released patch immediately

    Cybercriminals are abusing a post-compromise zero-day vulnerability in the Windows Common Log File System (CLFS) to deploy ransomware.

    Earlier this week, Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) published a new in-depth report, describing how a flaw tracked as CVE-2025-29824 is being used in cyberattacks.

    https://cdn.mos.cms.futurecdn.net/ioiGboNmGxjo77hGKRFefJ-1200-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img