#disable


Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

Oct 3, 2026 // 17:37

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations […]

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Sep 26, 2026 // 21:27

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The […]

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

Sep 9, 2026 // 14:19

A flaw in DeepSeek Harness, DeepSeek’s open-source tool for running AI coding agents on a developer’s machine, let a sandboxed agent turn off its own […]

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Sep 6, 2026 // 12:13

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the […]

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Sep 3, 2026 // 00:22

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. “The campaign has targeted users looking to download […]

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

Aug 27, 2026 // 14:10

Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. […]

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

Aug 14, 2026 // 00:17

An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. […]

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

Aug 14, 2026 // 00:17

An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. […]

GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

Jul 9, 2026 // 14:32

Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense […]

Gentlemen ransomware uses multiple EDR killers to disable defenses

Jun 19, 2026 // 01:36

The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. The […]

1 2 Next