Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security ToolsThe Hacker News·Feb 17, 05:50 UTC · Feb 17, 2026RansomwareCVE-2025-68947CVE-2025-6115560
Reynolds ransomware uses BYOVD to disable security before encryptionSecurity Affairs·Feb 11, 15:00 UTC · Feb 11, 2026RansomwareCVE-2025-6894760
Wormable XMRig campaign leverages BYOVD and timed kill switch for stealthSecurity Affairs·Feb 23, 18:36 UTC · Feb 23, 2026Threat actor60
BYOVD Attacks Exploit ZeroInfosecurity Magazine·Mar 3, 09:35 UTC · Mar 3, 2025RansomwareCVE-2025-0289CVE-2025-0288CVE-2025-0287+2 CVEs60
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain CredentialsThe Hacker News·Jul 3, 14:36 UTC · Jul 3, 2026RansomwareCVE-2025-577760
Linux variant of Qilin Ransomware targets Windows via remote management tools and BYOVDSecurity Affairs·Oct 27, 10:45 UTC · Oct 27, 2025Ransomware60
New BYOVD loader behind DeadLock ransomware attackCisco Talos·Dec 9, 11:00 UTC · Dec 9, 2025RansomwareCVE-2024-5132460
DeadLock Ransomware Uses BYOVD to Evade Security MeasuresInfosecurity Magazine·Dec 9, 16:00 UTC · Dec 9, 2025RansomwareCVE-2024-5132460
Wormable XMRig Campaign Uses BYOVD Exploit and TimeThe Hacker News·Feb 24, 11:56 UTC · Feb 24, 2026Threat actorCVE-2020-14979CVE-2025-5518260
ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ StoriesThe Hacker News·Feb 5, 17:14 UTC · Feb 5, 2026Vulnerability in the wild160
ThreatsDay Bulletin: CarPlay Exploit, BYOVD Tactics, SQL C2 Attacks, iCloud Backdoor Demand & MoreThe Hacker News·Oct 3, 04:59 UTC · Oct 3, 2025MalwareCVE-2024-3400CVE-2017-792160
⚡ THN Weekly Recap: GitHub Supply Chain Attack, AI Malware, BYOVD Tactics, and MoreThe Hacker News·May 7, 10:33 UTC · May 7, 2025MalwareCVE-2025-29927CVE-2025-23120CVE-2024-56346+13 CVEs60
Analyzing the vulnerability landscape in Q2 2024Kaspersky Securelist·Aug 21, 07:41 UTC · Aug 21, 2024VulnerabilityCVE-2018-0802CVE-2017-11882CVE-2017-0199+6 CVEs60
BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacksCisco Talos·Aug 28, 10:00 UTC · Aug 28, 2024VulnerabilityCVE-2024-3708560
Microsoft Zero-Day CVE-2024-38193 was exploited by North KoreaSecurity Affairs·Aug 19, 08:41 UTC · Aug 19, 2024Exploit / PoC in the wildCVE-2024-38193CVE-2024-2133860
GHOSTENGINE Exploits Vulnerable Drivers to Disable EDRs in Cryptojacking AttackThe Hacker News·May 29, 05:25 UTC · May 29, 2024RansomwareCVE-2021-44228CVE-2023-24860CVE-2023-3601060
Hackers exploited Windows 0-day for 6 months after Microsoft knew of itArs Technica · Security·Mar 4, 22:47 UTC · Mar 4, 2024Exploit / PoC in the wildCVE-2024-2133860
Lazarus APT exploited 0-day in Win driver to gain kernel privilegesSecurity Affairs·Feb 29, 08:11 UTC · Feb 29, 2024Threat actorCVE-2024-2133860
Cybercriminals Exploit CheckPoint Driver Flaws in Malicious CampaignInfosecurity Magazine·Mar 21, 12:45 UTC · Mar 21, 2025Threat actor60
Advanced threat predictions for 2025Kaspersky Securelist·Nov 25, 10:02 UTC · Nov 25, 2024Exploit / PoCCVE-2024-23222CVE-2024-23225CVE-2024-23296+3 CVEs60
Why a decade-old EnCase driver still works as an EDR killerHelp Net Security·Feb 5, 00:00 UTC · Feb 5, 2026Ransomware60
⚡ THN Weekly Recap: Router Hacks, PyPI Attacks, New Ransomware Decryptor, and MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025RansomwareCVE-2025-21590CVE-2025-24983CVE-2025-24984+27 CVEs160
Lazarus Group Exploits Zero-Day Vulnerability to Hack South Korean Financial EntityThe Hacker News·Mar 11, 06:29 UTC · Mar 11, 2023Exploit / PoC60
Delivering vulnerable signed kernel drivers remains popular among attackersHelp Net Security·Jan 13, 00:00 UTC · Jan 13, 2022Ransomware60
Reviewing the trends in ransomware attacks in 2026Kaspersky Securelist·May 12, 07:00 UTC · May 12, 2026Ransomware60
SonicWall Investigating Potential SSL VPN ZeroThe Hacker News·Aug 7, 05:27 UTC · Aug 7, 2025Ransomware in the wild60
RansomHub Went Dark April 1; Affiliates Fled to Qilin, DragonForce Claimed ControlThe Hacker News·May 1, 10:52 UTC · May 1, 2025Ransomware60
RansomHub ransomware gang relies on TDSKiller to disable EDRSecurity Affairs·Sep 11, 13:15 UTC · Sep 11, 2024Ransomware60
BlackByte Ransomware Exploits VMware ESXi Flaw in Latest Attack WaveThe Hacker News·Aug 29, 15:41 UTC · Aug 29, 2024RansomwareCVE-2024-3708560
TeamCity Flaw Leads to Surge in Ransomware, Cryptomining, and RAT AttacksThe Hacker News·Mar 21, 03:22 UTC · Mar 21, 2024RansomwareCVE-2024-2719860
Lazarus Hackers Exploited Windows Kernel Flaw as ZeroThe Hacker News·Feb 29, 14:41 UTC · Feb 29, 2024Threat actor in the wildCVE-2024-2133860
The Gentlemen RaaS: rapid growth and a new ransomware variantKaspersky Securelist·Jun 30, 10:06 UTC · Jun 30, 2026Ransomware160
Beyond the Code: Unearthing the Subtle Business Ramifications of Six Months in VulnerabilitiesRecorded Future·Jun 23, 00:00 UTC · Jun 23, 2026VulnerabilityCVE-2022-41082CVE-2023-0669CVE-2023-286860
ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & MoreThe Hacker News·Mar 19, 14:25 UTC · Mar 19, 2026Ransomware in the wildCVE-2024-55591CVE-2025-71257CVE-2025-71258+4 CVEs60
ThreatsDay Bulletin: OAuth Trap, EDR Killer, Signal Phishing, Zombie ZIP, AI Platform Hack & MoreThe Hacker News·Mar 12, 15:00 UTC · Mar 12, 2026Phishing & fraud in the wild60
⚡ Weekly Recap: Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware & MoreThe Hacker News·Feb 26, 11:25 UTC · Feb 26, 2026MalwareCVE-2026-22769CVE-2026-25926CVE-2026-26119+32 CVEs60