A legitimate and properly endorsed driver exposed vulnerabilities – The Weekly Security Recap with Tony Anscombe

Video
An alleged ad blocker promoted as a security measure utilizes a Microsoft-approved driver that unintentionally subjects individuals to perilous risks

How a legitimate and signed driver left the doors open to threats – Week in Security with Tony Anscombe

Video

An alleged ad blocker promoted as a security measure utilizes a Microsoft-approved driver that unintentionally subjects individuals to perilous risks

Throughout this week, ESET experts have shared their discoveries on HotPage, a browser injection tool that utilizes a driver created by a Chinese company and endorsed by Microsoft.

The malicious software disguises itself as an “Internet café security feature” with ad-blocking functionalities. Nevertheless, it exhibits advertisements related to games and has the ability to alter or supplant the content of a requested page, direct the user to an alternate page, or launch a new page in a fresh tab depending on specific conditions.

Furthermore, it inadvertently creates an avenue for additional threats to execute code at the utmost privilege level within Windows – the SYSTEM account.

Observe as Tony explores the story and elaborates on how the misuse of certificates remains a prevalent concern.

Engage with us on FacebookTwitterLinkedIn and Instagram.

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.