this post was submitted on 29 Feb 2024
20 points (100.0% liked)

Cybersecurity

5983 readers
529 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
 

The Lazarus Group exploited CVE-2024-21338, a zero-day vulnerability in Windows AppLocker's 'appid.sys' driver, to gain kernel privileges and disable security tools, avoiding BYOVD tactics. Avast reported this to Microsoft, leading to a patch. The FudModule rootkit, used by Lazarus, now features enhanced stealth and can disable products like Microsoft Defender and CrowdStrike Falcon.

no comments (yet)
sorted by: hot top controversial new old
there doesn't seem to be anything here