daily cyber × ai intelligence

index

tagged

[kontron]

1 edition · 1 item

July 6, 2026

  • The Gentlemen ransomware exploited a zero-day in a signed Kontron driver to disable endpoint defenses via classic BYOVD, gaining kernel-level access to terminate security processes before deploying ransomware, per Expel's analysis. Recommended mitigations include driver blocklisting, VBS, and WDAC. The group has been active this week, adding roughly 20 new victims to its leak site including EMS provider Medic Rescue and German meat giant Tönnies (Expel). · Vulnerabilities & Exploits

in The Gentlemen Weaponize a Signed Kontron Driver Into an EDR Killswitch