Episode

The driver's seat to ransomware. [Research Saturday]

Podcast
CyberWire Daily
Published
Aug 1, 2026
Duration seconds
1432
Processing state
not_requested
Canonical source
https://thecyberwire.com/podcasts/research-saturday/435/notes
Audio
https://pdst.fm/e/pdrl.fm/85df76/traffic.megaphone.fm/CYBW5586095340.mp3
JSON
/v1/public/podcasts/cyberwire-daily-454880/episodes/the-driver-s-seat-to-ransomware-research-saturday
Markdown
/podcast/cyberwire-daily-454880/the-driver-s-seat-to-ransomware-research-saturday.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/the-driver-s-seat-to-ransomware-research-saturday/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/cyberwire-daily-454880/the-driver-s-seat-to-ransomware-research-saturday.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks. The research and executive brief can be found here: Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs