54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security
2026-03-19T19:24:13Z•ba0eb30b10d080fea86594789970282156fcc4719586a76993d039ffca1b87b1
Android-banking-malwareBYOVDCISAEDR-bypasscredential-theftexploitationiOS-exploit-kitip-kvmopen-source-vulnsransomwaresupply-chain-injectiontelnetdvulnerable-driverswebkitzero-day
What happened
A large set of recent The Hacker News reports highlights active exploitation and high-impact tooling abuse across multiple vectors: 54 EDR-killer programs are abusing ‘bring your own vulnerable driver’ (BYOVD) techniques against 34 signed vulnerable drivers to disable endpoint defenses; Interlock ransomware is exploiting a critical Cisco FMC deserialization zero-day (CVE-2026-20131) for root access; a critical GNU Inetutils telnetd out‑of‑bounds write (CVE-2026-32746) enables unauthenticated root RCE; Ubuntu systemd timing bug (CVE-2026-3888) allows local root escalation; Apple patched a WebK
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- ba0eb30b10d080fea86594789970282156fcc4719586a76993d039ffca1b87b1
- Enrichment time
- 2026-03-19T19:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.