logo

Ransomware crew may have exploited Windows make-me-admin bug as a zero-day

ID: c6365ee3-6c89-5d24-b8b0-78ecc027c7ba

STIX ID: report--c6365ee3-6c89-5d24-b8b0-78ecc027c7ba

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-06-12

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Symantec's threat hunters analyzed an exploit used in a failed Black Basta ransomware attempt and found signs the exploit for CVE-2024-26169 (a Windows Error Reporting privilege escalation) may have been compiled before Microsoft patched it, suggesting possible zero-day use; the activity aligns with tactics attributed to Storm-1811/UNC4393 (Quick Assist abuse and scripted deployment) though Symantec calls the evidence suggestive rather than conclusive.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.