[WHOA] - This 'Unpatch Attack' Is A New One To Me!

Stu Sjouwerman | Aug 9, 2024

blackhat-logoIn a startling revelation at Black Hat 2024, SafeBreach security researcher Alon Leviev demonstrated a critical vulnerability in Windows systems, dubbed the "Windows Downdate" attack.

This exploit allows threat actors to forcibly downgrade fully updated Windows 10, 11, and Windows Server systems to older versions, reintroducing vulnerabilities that had been previously patched.

By exploiting zero-day vulnerabilities (CVE-2024-38202 and CVE-2024-21302), attackers can bypass security features like Credential Guard and Virtualization-Based Security, making a supposedly secure system susceptible to thousands of past exploits.

Despite being reported to Microsoft six months ago, no patch has been released, leaving users vulnerable. Microsoft advises following mitigation strategies until a fix is deployed.

Full article at Bleepingcomputer

Topics: Cybersecurity

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.