The Cybersecurity and Infrastructure Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities catalog, one of which is a critical flaw in Sophos Web Appliance that was patched in April 2023. Despite the patch, active exploitation of the vulnerability has been noted, highlighting the common practice among attackers of targeting older vulnerabilities.

Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools
Threat actors associated with Qilin and Warlock ransomware operations have been observed using the bring your own vulnerable driver (BYOVD) technique to silence security tools running on compromised hosts, according


