Black Basta ransomware gangs exploit patched Windows flaw to launch zero-day attacks



The Cardinal cybercrime group (also known as UNC4393, or Storm-1811), an affiliate of the notorious Black Basta gang, has been found exploiting a recently-patched Windows vulnerability to deploy the encryptor, while the flaw was still a zero-day.

A report from cybersecurity researchers Symantec changes what was so far known about the vulnerability, as Cardinal used an elevation of privilege vulnerability found in Windows Error Reporting Service. 

https://cdn.mos.cms.futurecdn.net/wEXMiPzVwyFScr9dUD6V9B-1200-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img