54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security

2026-03-19T19:24:13Zba0eb30b10d080fea86594789970282156fcc4719586a76993d039ffca1b87b1
Android-banking-malwareBYOVDCISAEDR-bypasscredential-theftexploitationiOS-exploit-kitip-kvmopen-source-vulnsransomwaresupply-chain-injectiontelnetdvulnerable-driverswebkitzero-day

What happened

A large set of recent The Hacker News reports highlights active exploitation and high-impact tooling abuse across multiple vectors: 54 EDR-killer programs are abusing ‘bring your own vulnerable driver’ (BYOVD) techniques against 34 signed vulnerable drivers to disable endpoint defenses; Interlock ransomware is exploiting a critical Cisco FMC deserialization zero-day (CVE-2026-20131) for root access; a critical GNU Inetutils telnetd out‑of‑bounds write (CVE-2026-32746) enables unauthenticated root RCE; Ubuntu systemd timing bug (CVE-2026-3888) allows local root escalation; Apple patched a WebK­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ba0eb30b10d080fea86594789970282156fcc4719586a76993d039ffca1b87b1
Enrichment time
2026-03-19T19:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · 54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security · Baitaphish