Black Basta ransomware gang has embedded a vulnerable driver (NsecSoft NSecKrnl) directly into their ransomware payload, marking a shift from the typical approach of deploying standalone EDR killers. This BYOVD (bring your own vulnerable driver) technique exploits CVE-2025-68947 to terminate security processes with kernel-level

5m read timeFrom darkreading.com
Post cover image
Table of contents
Potential Benefits of Embedded BYOVD AttacksOngoing Challenges With Vulnerable Drivers

Sort: