Black Basta Ransomware May Have Exploited MS Windows Zero-Day Flaw
ID: 88e126d1-50c4-5ad9-a293-6a1cd628d82f
STIX ID: report--88e126d1-50c4-5ad9-a293-6a1cd628d82f
Feed Name: The Hacker News
Threat Score
Symantec analysis indicates threat actors linked to the Black Basta/Cardinal cluster exploited CVE-2024-26169 (Windows Error Reporting Service privilege escalation) possibly as a zero-day, with compile timestamps predating Microsoft’s March 2024 patch; the exploit uses a WerFault Debugger registry trick to gain SYSTEM privileges, was observed in an attempted ransomware incident, and prompted CISA to add the CVE to its KEV catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
