← Back to feed
Breaches & RansomwareEmerging1 sourceAug 1, 2026 · 07:00via The CyberWire

The driver's seat to ransomware. [Research Saturday]

Brief

This week, we are joined by Marcus Hutchins , Principal Threat Researcher at Expel , sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs."

Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware.

The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software.

It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks.

Read more on The CyberWire