A critical vulnerability in the BioNTdrv.sys driver of Paragon Partition Manager, identified as CVE-2025-0289, is being exploited by ransomware groups. Attackers with local access can escalate privileges and execute malicious code on Windows systems, leading to significant security risks. The vulnerability has been highlighted in multiple reports, including those from The Hacker News and Infosecurity Magazine. In addition to this, a new phishing campaign is utilizing the ClickFix technique to deploy the Havoc command and control (C2) framework through Microsoft SharePoint sites. This multi-stage attack disguises itself behind trusted services to evade detection. Other recent cybersecurity concerns include AWS misconfigurations being exploited for phishing attacks and a surge in third-party risk claims in cybersecurity incidents.
Hackers Exploit AWS Misconfigurations to Launch Phishing Attacks via SES and WorkMail: https://t.co/HuvzWG8EFT by The Hacker News #infosec #cybersecurity #technology #news
New ClickFix attack deploys Havoc C2 via Microsoft Sharepoint https://t.co/l81Bt4UFVw
Hackers Use ClickFix Trick to Deploy PowerShell-Based Havoc C2 via SharePoint Sites https://t.co/tNZKIKAAbq