{"podcast":{"title":"CyberWire Daily","slug":"cyberwire-daily-454880","podcast_index_feed_id":454880,"rss_url":"https://feeds.megaphone.fm/cyberwire-daily-podcast","website_url":"https://thecyberwire.com/podcasts/daily-podcast","image_url":"https://megaphone.imgix.net/podcasts/58ab7ae0-def8-11ea-b34c-b35b208b0539/image/8676ed612d7a335a98a9173d70cb11be.png?ixlib=rails-4.3.1&max-w=3000&max-h=3000&fit=crop&auto=format,compress","author":"N2K Networks, Inc.","episode_count":3765,"summary":"The daily cybersecurity news and analysis industry leaders depend on. Published each weekday, the program also includes interviews with a wide spectrum of experts from industry, academia, and research organizations all over the world.","last_synced_at":"2026-09-23T20:18:19.501651+00:00","page_url":"https://stenobird.com/podcast/cyberwire-daily-454880"},"episode":{"title":"The driver's seat to ransomware. [Research Saturday]","slug":"the-driver-s-seat-to-ransomware-research-saturday","published_at":"2026-08-01T07:00:00+00:00","page_url":"https://stenobird.com/podcast/cyberwire-daily-454880/the-driver-s-seat-to-ransomware-research-saturday","show_page_url":"https://stenobird.com/podcast/cyberwire-daily-454880","url":"https://thecyberwire.com/podcasts/research-saturday/435/notes","audio_url":"https://pdst.fm/e/pdrl.fm/85df76/traffic.megaphone.fm/CYBW5586095340.mp3","summary":"This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on \"Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs.\" Researchers examine how the Gentlemen ransomware group used a previously unknown zero-day vulnerability in a legacy Windows driver to disable endpoint detection and response (EDR) tools before deploying ransomware. The report details the group's advanced bring-your-own-vulnerable-driver (BYOVD) techniques, which bypass multiple Windows security protections to gain kernel-level access and terminate protected security software. It also outlines defensive measures organizations can take, including enabling Windows Defender Application Control (WDAC), virtualization-based security (VBS), and vulnerable driver blocklists to reduce the risk of similar attacks. The research and executive brief can be found here: Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs","meta_description":"This week, we are joined by Marcus Hutchins, Principal Threat Researcher at Expel, sharing their work on \"Not very gentlemanly: Analyzing a zero-day explo…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1432,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/the-driver-s-seat-to-ransomware-research-saturday/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cyberwire-daily-454880/the-driver-s-seat-to-ransomware-research-saturday.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}