Lazarus Hackers Exploited Windows Kernel Flaw as Zero-Day in Recent Attacks
Using a newly patched privilege escalation vulnerability in the Windows kernel, the infamous Lazarus Group attackers took use of a zero-day vulnerability to get kernel-level access and disable security software on compromised machines.
The CVE-2024-21338 vulnerability (CVSS score: 7.8) can allow an attacker to take over a system and obtain SYSTEM privileges. Microsoft fixed it early this month as part of the Patch Tuesday releases.
An attacker would need to sign in to the system to take advantage of this vulnerability, according to Microsoft. "An attacker might then launch a program that has been carefully designed to take advantage of the vulnerability read more Lazarus Hackers Exploited Windows Kernel Flaw as Zero-Day in Recent Attacks.
Get up to date on the latest cybersecurit...

