Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures

Cybercriminals have once again demonstrated their evolving sophistication by weaponizing an obscure Toshiba laptop driver to bypass endpoint detection and response systems. The Qilin ransomware operation, active since July 2022, has incorporated a previously unknown vulnerable driver called TPwSav.sys into their attack arsenal, enabling them to stealthily disable EDR protections through a technique known as […]

The post Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: