Tag

Blacklotus

All articles tagged with #blacklotus

NSA's Guide to Combat and Mitigate BlackLotus Malware Threats.
threat-intel-endpoint-security3 years ago

NSA's Guide to Combat and Mitigate BlackLotus Malware Threats.

The NSA has released guidance to help organizations detect and prevent infections of the BlackLotus UEFI bootkit, which can bypass Windows Secure Boot protections. The malware exploits a known Windows flaw called Baton Drop and grants a threat actor complete control over the operating system booting procedure. Organizations are advised to harden user executable policies, monitor the integrity of the boot partition, and customize UEFI Secure Boot to block older, signed Windows boot loaders. Microsoft is expected to completely close the attack vector in the first quarter of 2024.

NSA's Guide to Blocking and Combating BlackLotus Malware Attacks
cybersecurity3 years ago

NSA's Guide to Blocking and Combating BlackLotus Malware Attacks

The NSA has released guidance on how to defend against BlackLotus UEFI bootkit malware attacks, which has been circulating on hacking forums since October 2022. The malware is capable of evading detection, withstanding removal efforts, and neutralizing multiple Windows security features. The NSA recommends applying the latest security updates, hardening defensive policies, and customizing UEFI Secure Boot to block older signed Windows boot loaders. The agency also advises system administrators to implement hardening actions on systems patched against this vulnerability and to use endpoint security products and firmware monitoring tools to monitor device integrity measurements and boot configuration.

Microsoft's Windows 11 Security Woes: Mega Patch in the Works.
technology3 years ago

Microsoft's Windows 11 Security Woes: Mega Patch in the Works.

Microsoft has released a new patch to fix the CVE-2023-24932 vulnerability that BlackLotus was taking advantage of to execute code remotely on the computers of its victims. However, the vulnerability won't be resolved until at least the first quarter of 2024 because the solution needs to be propagated in three different stages, separated by several months. BlackLotus is a sophisticated bootkit that is capable of evading the security mechanisms of SecureBoot, which is a mandatory requirement for installing Windows 11 or upgrading to this version. It is essential that users take steps to protect themselves by keeping their computers and security systems up to date, scanning their computers regularly for malware, and being cautious about the websites they visit and the files they download.

Microsoft's Ongoing Battle with Security Flaws: Latest Updates and Fixes.
technology3 years ago

Microsoft's Ongoing Battle with Security Flaws: Latest Updates and Fixes.

Microsoft has released a patch to fix a Secure Boot bypass bug used by the BlackLotus bootkit, which is the first-known real-world malware that can bypass Secure Boot protections. The new patch for CVE-2023-24932 addresses another actively exploited workaround for systems running Windows 10 and 11 and Windows Server versions going back to Windows Server 2008. However, the update will be disabled by default for at least a few months after it's installed and will eventually render current Windows boot media unbootable. Microsoft will be rolling the update out in phases over the next few months to avoid rendering any users' systems unbootable.

Microsoft Addresses Multiple Security Vulnerabilities with New Patches.
technology3 years ago

Microsoft Addresses Multiple Security Vulnerabilities with New Patches.

Microsoft has released a patch to fix a Secure Boot bypass bug used by the BlackLotus bootkit. The new patch for CVE-2023-24932 addresses another actively exploited workaround for systems running Windows 10 and 11 and Windows Server versions going back to Windows Server 2008. The update will be disabled by default for at least a few months after it's installed and will eventually render current Windows boot media unbootable. Microsoft will be rolling the update out in phases over the next few months to prevent any users' systems from becoming unbootable.

Microsoft's May 2023 Patch Tuesday addresses critical vulnerabilities and zero-day exploits.
cybersecurity3 years ago

Microsoft's May 2023 Patch Tuesday addresses critical vulnerabilities and zero-day exploits.

Microsoft's May Patch Tuesday includes 38 security fixes, with six deemed critical. Two of the vulnerabilities have already been exploited by attackers, including a Win32k elevation of privilege flaw and a Secure Boot security feature bypass vulnerability used by the BlackLotus bootkit. A third vulnerability, a Windows OLE Remote Code Execution flaw, has been publicly disclosed. Adobe released one security bulletin for Adobe Substance 3D Painter, while SAP released 25 new and updated security patches, including two Hot News and nine High Priority notes. Android's latest security bulletin resolved 18 flaws, with the most severe requiring user interaction to exploit.

Microsoft releases optional fix for two zero-day vulnerabilities.
cybersecurity3 years ago

Microsoft releases optional fix for two zero-day vulnerabilities.

Microsoft has released an optional security update to address a Secure Boot zero-day vulnerability exploited by BlackLotus UEFI malware to infect fully patched Windows systems. The security flaw was used to bypass patches released for CVE-2022-21894, another Secure Boot bug abused in BlackLotus attacks last year. The CVE-2023-24932 security patches released today are only available for supported versions of Windows 10, Windows 11, and Windows Server. Customers must undergo a procedure requiring multiple manual steps to update bootable media and apply revocations before enabling this update.