menu
techminis

A naukri.com initiative

google-web-stories
source image

Securityaffairs

5d

read

393

img
dot

Image Credit: Securityaffairs

Play ransomware affiliate leveraged zero-day to deploy malware

  • The Play ransomware gang exploited a Windows Common Log File System flaw in zero-day attacks to deploy malware, gaining SYSTEM privileges on compromised systems.
  • The vulnerability, CVE-2025-29824, allowed attackers to elevate privileges locally, leading to confirmed exploits in the wild by the Play ransomware gang.
  • Microsoft addressed the flaw in April's Patch Tuesday security updates, after it was added to the Known Exploited Vulnerabilities catalog by CISA.
  • The exploit was used by multiple threat actors before being patched, with connections to malware like PipeMagic and Storm-2460, used by Balloonfly cybercrime group.

Read Full Article

like

23 Likes

For uninterrupted reading, download the app