Ransomware crew may have exploited Windows make-me-admin bug as a zero-day
ID: c6365ee3-6c89-5d24-b8b0-78ecc027c7ba
STIX ID: report--c6365ee3-6c89-5d24-b8b0-78ecc027c7ba
Feed Name: The Register (Security)
Threat Score
Symantec's threat hunters analyzed an exploit used in a failed Black Basta ransomware attempt and found signs the exploit for CVE-2024-26169 (a Windows Error Reporting privilege escalation) may have been compiled before Microsoft patched it, suggesting possible zero-day use; the activity aligns with tactics attributed to Storm-1811/UNC4393 (Quick Assist abuse and scripted deployment) though Symantec calls the evidence suggestive rather than conclusive.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
