Blog | G5 Cyber Security

Yomi Hunter Catches the CurveBall

Yomi implements detection for CurveBall exploits and also supports CVE-2020-0601 exploit detection even for signed Powershell modules. CurveBall enables attackers to trick Windows 10, Windows Server 2016 and Windows Server 2019, to impersonate other trusted parties such as Microsoft itself, resulting in being successfully cryptographically verified by the vulnerable hosts. The new detection logic is available into malware reports generated by the Yomi-Hunter community (e.g. LINK), within the new VirusTotal integrated reports, and for every private instances in use by Yorois Cyber Security Defence Center customers.”]

Source: https://securityaffairs.co/wordpress/96691/hacking/yomi-hunter-curveball.html

Exit mobile version