Security News > 2024 > June > CISA warns of Windows bug exploited in ransomware attacks
![CISA warns of Windows bug exploited in ransomware attacks](/static/build/img/news/cisa-warns-of-windows-bug-exploited-in-ransomware-attacks-medium.jpg)
The U.S. Cybersecurity and Infrastructure Security Agency has added a high-severity Windows vulnerability abused in ransomware attacks as a zero-day to its catalog of actively exploited security bugs.
Successful exploitation lets local attackers gain SYSTEM permissions in low-complexity attacks that don't require user interaction.
The company has yet to update its security advisory to tag the vulnerability as exploited in attacks.
As revealed in a report published earlier this week, Symantec security researchers found evidence that the operators of the Black Basta ransomware gang were likely behind attacks abusing the flaw as a zero-day.
On Thursday, CISA gave FCEB agencies three weeks, until July 4, to patch the CVE-2024-26169 security and thwart ransomware attacks that could target their networks.
Black Basta ransomware gang linked to Windows zero-day attacks.
News URL
Related news
- Windows Quick Assist abused in Black Basta ransomware attacks (source)
- Black Basta ransomware gang linked to Windows zero-day attacks (source)
- CISA says GitLab account takeover bug is actively exploited in attacks (source)
- REvil hacker behind Kaseya ransomware attack gets 13 years in prison (source)
- City of Wichita shuts down IT network after ransomware attack (source)
- CISA's early-warning system helped critical orgs close 852 ransomware holes (source)
- CISA boss: Secure code is the 'only way to make ransomware a shocking anomaly' (source)
- Ransomware attacks impact 20% of sensitive data in healthcare orgs (source)
- Ohio Lottery ransomware attack impacts over 538,000 individuals (source)
- Ascension redirects ambulances after suspected ransomware attack (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-03-12 | CVE-2024-26169 | Unspecified vulnerability in Microsoft products Windows Error Reporting Service Elevation of Privilege Vulnerability | 7.8 |