<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Byovd on CuraSec</title><link>https://curasec.metacog.co.kr/tags/byovd/</link><description>Recent content in Byovd on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 21:01:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/byovd/index.xml" rel="self" type="application/rss+xml"/><item><title>Spark RAT Campaign Abuses Vulnerable OPSWAT Driver via BYOVD in Cambodia</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-spark-rat-targets-cambodia-abuses-vulnerable-opswat-driver-t/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-spark-rat-targets-cambodia-abuses-vulnerable-opswat-driver-t/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The BYOVD technique exploiting a vulnerable OPSWAT driver to kill security tools is a notable evasion class worth understanding, but current targeting is regionally focused on Cambodia with no enrichment signals (no KEV, no PoC, no high EPSS) to justify immediate action in most environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for vulnerable OPSWAT driver loads and anomalous security-tool process terminations consistent with BYOVD; Spark RAT is open-source and signatures should be available to add to EDR and SIEM rule sets this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>ThreatsDay Digest: Gogs RCE, n8n RCE, AI-Assisted Exploits</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-threatsday-gogs-10-0-rce-n8n-workflow-to-rce-10m-reward-glm/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-threatsday-gogs-10-0-rce-n8n-workflow-to-rce-10m-reward-glm/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Gogs 10.0 RCE and n8n workflow-to-RCE are worth tracking if you run either tool, but no enrichment signals (no KEV, PoC, or EPSS) are present and the summary is too thin to drive patching prioritization; read the underlying advisories directly for specifics.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The roundup references signed-driver abuse against defenses (BYOVD pattern) and legitimate-app blending techniques, but supplies no IOCs, ATT&amp;amp;CK mappings, or detection guidance — useful for threat-landscape awareness only.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Cruciferra Crypter Uses BYOVD and Process Ghosting to Evade EDR</title><link>https://curasec.metacog.co.kr/insights/2026-07-27-cruciferra-crypter-uses-byovd-and-process-ghosting-to-hide-w/</link><pubDate>Mon, 27 Jul 2026 13:44:31 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-27-cruciferra-crypter-uses-byovd-and-process-ghosting-to-hide-w/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> BYOVD and Process Ghosting are sophisticated defense-evasion techniques that challenge standard EDR assumptions; no patch action available, but useful for evaluating EDR coverage and hardening kernel driver allow-listing policies.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Multiple unrelated threat clusters adopting Cruciferra makes this detection-relevant — build or tune detections for known vulnerable driver loads (BYOVD) and process ghosting behaviors in your EDR; no IOCs surfaced yet so immediate hunting isn&amp;rsquo;t actionable.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>