Entry Thumbnail

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

**Research by: Jiří Vinopal** **(**@vinopaljiri **)** What if a **trusted security component** could be repurposed into an **attacker-controlled** kernel primitive? What if a **signed Microsoft remediation driver** could be instructed to execute arbitrary **file** and **registry** operations from **Ring 0** – **without** exploits, vulnerabilities, or memory corruption? In this publication, […]

Posted by
Entry Thumbnail

[Initial Disclosure] AMD | ZEN 1

### Uh oh! There was an error while loading. Please reload this page. / **security-research** Public # [Initial Disclosure] AMD | ZEN 1 ## Package tbd ## Affected versions tbd ## Patched versions tbd ## Description ### Affected Vendor / Project: AMD ### Affected Product: Zen 1 CPU ### Private […]

Posted by
Entry Thumbnail

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Research by: Jaromír Hořejší (@JaromirHorejsi) We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique, which prompts victims to execute a PowerShell command. This leads to two stages of additional […]

Posted by
Entry Thumbnail

The State of Ransomware Q2 2026

For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The […]

Posted by
Entry Thumbnail

Microsoft Windows TCPIP.SYS IppQualifyAddresses Out-of-Bounds Read Vulnerability

TALOS-2026-2427 CVE-2026-49177 An out-of-bounds read vulnerability exists in the IppQualifyAddresses function of the Microsoft Windows tcpip.sys driver. A specially crafted I/O request packet (IRP) can cause an arbitrary out-of-bounds read, potentially leading to information disclosure or a denial-of-service condition. The versions below were either tested or verified to be vulnerable […]

Posted by