Windows defenders are facing a new way for attackers to hide activity after gaining administrator access. The technique abuses Windows bind links, a legitimate feature that redirects one file path to another without changing the original file on disk. Rather than dropping a visible replacement file or modifying security software, an attacker can make a trusted path quietly return malicious content. This creates a gap between what a process runs and what endpoint tools believe they are inspecting. Bitdefender said in a report shared with Cyber Security News (CSN) that the issue affects modern Windows systems once an attacker has local administrator privileges. Researchers said the technique can weaken endpoint detection,...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!