Home/ Blog/ Topics/ Vulnerable drivers (BYOVD)
Topic

Vulnerable drivers (BYOVD)

Bring-your-own-vulnerable-driver attacks that load a signed but flawed driver to disable endpoint defenses from the kernel.

Security news

Mustang Panda's kernel rootkit hides its backdoor from host tools

Mustang Panda's CoolClient backdoor now uses a signed kernel rootkit to hide from host tools. Why it is a hide not a kill, and where to still detect it.

Security news

Silver Fox's new kit hot-swaps vulnerable drivers to kill EDR and plant ValleyRAT

Silver Fox now runs a modular bring-your-own-vulnerable-driver kit with three interchangeable drivers, killing EDR from the kernel to deploy ValleyRAT.

Security news

GodDamn ransomware blinds EDR with a signed kernel driver. Detect the load, not the file.

GodDamn ransomware uses PoisonX, a kernel driver carrying a valid Microsoft signature, to disable EDR.

Security news

EaseUS Partition Master left a Windows driver that lets any user seize the whole PC

A signed driver in EaseUS Partition Master (CVE-2026-12781) lets any standard Windows user read and overwrite the whole disk to reach SYSTEM.

Security news

EDR evasion is now a shipped product. Your agent's silence is the only alarm left.

The Gentlemen ransomware gang ships a standardized EDR killer to affiliates using BYOVD. Here is why driver-name hunting fails and what to detect instead.

Security news

DragonForce hides its C2 inside Microsoft Teams relays. Your network sensors see a clean call.

DragonForce's Backdoor.Turn routes C2 through Microsoft Teams TURN relays, so network sensors see only Microsoft.

Security news

INC ransomware never used a zero-day. It used your patch backlog.

INC reached top-tier RaaS in 2026 with no zero-days. Every edge-device flaw it exploits was patched months earlier. Here is what to actually fix.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.