CuraSec

tag: Edr-Bypass · 2 items

2026-08-24 · The Hacker News · source ↗ #threat-actor#linux-rootkit#edr-bypass
  • Engineer — Learn: Novel Linux rootkit and EDR bypass technique targeting web servers is worth understanding for hardening posture, but no specific CVE, PoC, or KEV signal means no immediate patch action required.
  • SOC/IR — Plan: Build or tune detections for EDR bypass behavior and Linux rootkit indicators on web-facing servers; prioritize collecting relevant Linux endpoint telemetry if not already sourced, ahead of potential targeting expansion beyond current sectors.
  • Leader — Learn: Chinese-speaking cybercrime group targeting education, media, and tech sectors globally; useful for sector risk awareness and future board briefings, but no immediate vendor or regulatory action required based on available signals.
2026-08-22 · The Hacker News · source ↗ #windows-driver#edr-bypass#kernel-level
  • Engineer — Learn: No exploitable flaw and no patch exists — this is abuse of a legitimately signed Defender component, so there’s nothing to patch; understand the technique and evaluate whether existing attack surface reduction or kernel driver allow-listing policies limit BTR.sys invocation outside Defender’s normal use.
  • SOC/IR — Plan: Novel boot-time EDR-disablement technique worth building detections for: plan to hunt for anomalous BTR.sys loading events or unexpected security product file/registry removal at boot, and check whether your EDR vendor provides detection coverage for this abuse pattern.
  • Leader — Learn: Research disclosure with no active exploitation signals; relevant background if stakeholders ask about Defender’s reliability as a security control, but no leadership action is required at this time.