logo

Microsoft Under Pressure to Bolster Defenses for BYOVD Attacks

ID: a2141e77-7d9a-526d-b6fd-1b74bda73d4b

STIX ID: report--a2141e77-7d9a-526d-b6fd-1b74bda73d4b

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-02-13

Date Updated: 2026-04-21

Author: Rob Wright

...
...

This article examines the growing use of bring-your-own-vulnerable-driver (BYOVD) attacks—where threat actors drop and load signed but vulnerable kernel drivers to obtain ring-0 privileges and kill security products—highlighting real-world abuse (e.g., an EnCase driver weaponized, Black Basta/Reynolds campaigns), shortcomings in Windows driver-signing/backward-compatibility and Microsoft's blocklist cadence, and short- and medium-term mitigation strategies for vendors and defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.