Black Basta Exploits Microsoft Zero-Day After Patch

Robinson+Cole Data Privacy + Security Insider
Contact

It is being reported that Black Basta (aptly named) exploited a Microsoft zero-day prior to Microsoft’s release of a patch for the vulnerability back in March.

The vulnerability, CVE-2024-26169, was on Microsoft’s March update’s Patch Tuesday List. Unpatched, it allows the threat actor to escalate privileges. Symantec’s threat hunter team has discovered that Black Basta was able to gather information on the vulnerability prior to the patch and use it recently in attacks against victims. This means that even if an organization applied the patch, Black Basta may be able to exploit the vulnerability anyway.

It is essential for organizations to apply patches for vulnerabilities in a timely manner. Unfortunately, this research indicates that even if you do so, the threat actors may have already figured out how to exploit the vulnerability to use it against companies after the fact to render the vulnerability a zero-day again. Patch, patch, patch. There’s no way around it, and it is more important than ever. Patch this vulnerability to avoid Black Basta—trust me—they are a bunch of bastas.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide