<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ransomware on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/ransomware/</link><description>Recent content in Ransomware on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sat, 11 Jul 2026 13:01:35 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/ransomware/index.xml" rel="self" type="application/rss+xml"/><item><title>Signed by Microsoft Does Not Mean Safe</title><link>https://hackingpassion.com/byovd-signed-driver-attacks/</link><pubDate>Sat, 11 Jul 2026 13:01:35 +0200</pubDate><guid>https://hackingpassion.com/byovd-signed-driver-attacks/</guid><description>&lt;p>A digital signature on a Windows driver proves who made it. &lt;strong>It was never proof that the driver is safe.&lt;/strong>
Attackers built a technique on that gap, called Bring Your Own Vulnerable Driver, and it hands them control of Windows at its deepest level. Some of the malware they use was signed through Microsoft&amp;rsquo;s own program.&lt;/p>
&lt;p>A driver is the piece of software that lets Windows and a device work together, your keyboard, your printer, your graphics card. It runs in the kernel, the core of the operating system, at a level called &lt;code>ring 0&lt;/code>, where code has direct access to memory and hardware. Security software mostly watches from a step below. Some of it runs inside the kernel too, but even that cannot protect itself once an attacker controls that level. &lt;strong>Reaching the kernel puts an attacker on top.&lt;/strong>&lt;/p></description></item><item><title>JADEPUFFER Is the First Ransomware Attack Run Entirely by an AI Agent</title><link>https://hackingpassion.com/jadepuffer-ai-ransomware/</link><pubDate>Sun, 05 Jul 2026 13:22:17 +0200</pubDate><guid>https://hackingpassion.com/jadepuffer-ai-ransomware/</guid><description>&lt;p>&lt;strong>JADEPUFFER&lt;/strong> is the first documented ransomware operation run by an AI agent. The agent broke in, stole credentials, jumped to a second target, encrypted a production database, and destroyed data. This is an &lt;strong>agentic threat actor&lt;/strong>: an attacker whose attack power comes from an AI agent rather than from a human toolkit.&lt;/p>
&lt;p>Researchers documented something that changes what a ransomware attack can look like. Ransomware has always needed a person somewhere in the loop. Someone picks the target, tests the stolen logins, and patches up the code when it breaks. This time a large language model did all of it.&lt;/p></description></item><item><title>GhostLock Delivers Ransomware Impact on Windows Without Touching a Single File</title><link>https://hackingpassion.com/ghostlock-smb-file-lock-ransomware/</link><pubDate>Mon, 11 May 2026 14:22:19 +0200</pubDate><guid>https://hackingpassion.com/ghostlock-smb-file-lock-ransomware/</guid><description>&lt;p>&lt;strong>GhostLock locks every shared file on any Windows network in minutes using nothing but a standard login, and every security tool watching stays completely silent. This has been possible for over 30 years. Microsoft is not going to patch this.&lt;/strong>&lt;/p>
&lt;p>Security researcher Kim Dvash published the proof of concept in May 2026, after discovering the technique during a prior authorized red team engagement.&lt;/p>
&lt;p>&lt;strong>SMB&lt;/strong> is the protocol Windows uses to share files across a network. When a program opens a file over SMB, it tells Windows how it wants to share that file with other programs at the same time. Set that sharing mode to zero using a parameter called &lt;code>dwShareMode&lt;/code> in the &lt;code>CreateFileW&lt;/code> API call, and Windows grants an &lt;strong>exclusive deny-share handle&lt;/strong>. While that handle is held open, every other process, user, or system trying to open the same file gets back one thing:&lt;/p></description></item><item><title>GootLoader Tricks Security Tools Into Seeing a Safe File While Windows Runs Malware</title><link>https://hackingpassion.com/gootloader-zip-evasion-2026/</link><pubDate>Sun, 18 Jan 2026 11:28:38 +0100</pubDate><guid>https://hackingpassion.com/gootloader-zip-evasion-2026/</guid><description>&lt;p>GootLoader is back. This week, researchers discovered their newest trick: a way to make security tools completely blind. Your antivirus scans the ZIP file. Nothing found. WinRAR tries to open it. Fails. 7-Zip tries. Also fails. Corrupted file, right? But when you double-click it, Windows opens it just fine. And now you&amp;rsquo;re infected. 🧐&lt;/p>
&lt;p>The trick is simple but brilliant. They take 500 to 1000 ZIP files and glue them together into one massive file. Most analysis tools read ZIP files from the beginning. They hit the first archive, see garbage, and crash. But here is the thing about ZIP files. They are actually read from the END. The &amp;ldquo;End of Central Directory&amp;rdquo; record tells the reader where to find the actual content. Windows knows this. It skips all the junk, finds the last valid archive, and happily extracts the malware.&lt;/p></description></item><item><title>SAP Just Got Breached: Four Critical Vulnerabilities Let Attackers Steal Financial Data (CVE-2026-0501)</title><link>https://hackingpassion.com/sap-patch-tuesday-four-critical-vulnerabilities-cve-2026-0501/</link><pubDate>Tue, 13 Jan 2026 14:03:32 +0100</pubDate><guid>https://hackingpassion.com/sap-patch-tuesday-four-critical-vulnerabilities-cve-2026-0501/</guid><description>&lt;h1 id="sap-just-patched-four-critical-vulnerabilities">SAP just patched four critical vulnerabilities&lt;/h1>
&lt;p>SAP just patched four critical vulnerabilities. CVSS scores up to 9.9. One lets attackers run code with nothing but a malicious link. 425,000 companies run SAP. Over 85% of Fortune 500. The patches dropped today, January 13, 2026. 🧐&lt;/p>
&lt;p>SAP Patch Tuesday just landed with seventeen security notes. Four are HotNews - SAP&amp;rsquo;s term for patch immediately or accept the consequences.&lt;/p>
&lt;p>The most severe vulnerability lets someone with a basic user account run arbitrary SQL queries against the entire financial database.&lt;/p></description></item></channel></rss>