Researchers have uncovered a new Android banking trojan called Herodotus that can mimic human typing to evade detection, conduct device takeover attacks, and target financial institutions and cryptocurrency platforms, highlighting evolving malware techniques and active campaigns in Italy, Brazil, and beyond.
Researchers have discovered 34 vulnerable Windows drivers that could be exploited by non-privileged threat actors to gain full control of devices and execute arbitrary code. These drivers allow attackers to erase/alter firmware, elevate operating system privileges, and defeat security mechanisms. Some drivers can even render systems unbootable. The technique, known as Bring Your Own Vulnerable Driver (BYOVD), has been used by adversaries to gain elevated privileges and disable security software. The research highlights the need for improved security measures to protect against driver vulnerabilities.