logo

How a signed driver exposed users to kernel-level threats – Week in Security with Tony Anscombe

ID: 950bebdb-b168-5e93-979f-992bd2061c8d

STIX ID: report--950bebdb-b168-5e93-979f-992bd2061c8d

Feed Name: WeLiveSecurity (ESET Research)

Threat Score

Date Published: 2024-07-21

Date Updated: 2026-05-01

...
...

ESET researchers detailed “HotPage,” a browser-injecting adware masquerading as an Internet café security tool that leverages a Microsoft-signed driver to display game-related ads, modify or redirect web content, and inadvertently expose Windows systems to kernel-level code execution (SYSTEM), underscoring the ongoing risks of certificate and signed-driver abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.