The Black Basta ransomware riddle. [Research Saturday]

Published: July 27, 2024, 7 a.m.

Dick O'Brien from Symantec Threat Hunter team is talking about their work on "Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day." Also going to provide some background/history on Black Basta. CVE-2024-26169 in the Windows Error Reporting Service, patched on March 12, 2024, allowed privilege escalation. \nDespite initial claims of no active exploitation, recent analysis indicates it may have been exploited as a zero-day before the patch.\nThe research can be found here:\nRansomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day\n\nLearn more about your ad choices. Visit megaphone.fm/adchoices