# The driver's seat to ransomware. [Research Saturday] Page: https://stenobird.com/podcast/cyberwire-daily-454880/the-driver-s-seat-to-ransomware-research-saturday Text version: https://stenobird.com/podcast/cyberwire-daily-454880/the-driver-s-seat-to-ransomware-research-saturday.md Podcast: [CyberWire Daily](https://stenobird.com/podcast/cyberwire-daily-454880) Published: 2026-08-01T07:00:00+00:00 Episode link: https://thecyberwire.com/podcasts/research-saturday/435/notes Audio file: https://pdst.fm/e/pdrl.fm/85df76/traffic.megaphone.fm/CYBW5586095340.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/the-driver-s-seat-to-ransomware-research-saturday Duration seconds: 1432 ## Resource This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on "Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs." Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks. The research and executive brief can be found here: Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/the-driver-s-seat-to-ransomware-research-saturday/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cyberwire-daily-454880/the-driver-s-seat-to-ransomware-research-saturday.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.