Friday 26 June 2026 09:13:35 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItalianoArabic

#EDR bypass


Ghost Frames Turns the Endpoint’s Own Memory of Itself Into the Weak Link

Published: 22 June 2026 14:45Category: Research, Exploits & Offensive SecurityGeo: Europe / FinlandAuthor: DEBUGSAGE

A reported call-stack manipulation technique puts a rare kind of pressure on EDR: if the stack can be made to look normal, one of its best context signals can become less useful.

A Ransomware Brand With Old Habits and New Evasion Tricks

Published: 04 June 2026 10:26Category: Ransomware & ExtortionAuthor: LOGICFALCON

Payouts King is being described as a post-BlackBasta threat that pairs social engineering overlap with code designed to frustrate some endpoint defenses.

When the Startup Path Becomes the Attack Path

Published: 01 June 2026 14:28Category: Cyber Warfare & Nation-State OperationsGeo: Middle East / IranAuthor: AGONY

A reported .NET abuse chain shows how defenders can lose visibility before an application fully settles, especially when startup manipulation is paired with DLL sideloading and recruitment-themed lures.

When Signed Drivers Become the Weapon: The BYOVD Path into Ransomware

Published: 13 May 2026 09:48Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A Windows trust mechanism meant to protect endpoints can be turned against them, letting attackers use vulnerable drivers to undermine security controls before ransomware takes hold.