Attackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them enough room to tamper with memory or disable the security software watching the host. Once an attacker holds that level of access, the tools on the machine stop reliably protecting it. Ransomware crews run the technique as a step before they deploy a payload, a … More →
The post Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support appeared first on Help Net Security.

‘I bought the tool to save time, but I did more manual work than before’: Pentesters are finding more bugs with AI than they can fix
AI-powered penetration testing tools are getting out of hand, according to new research, generating more findings than security teams can validate. Nine-in-ten security practitioners surveyed


