CISA: Microsoft Releases Guidance for the BlackLotus Campaign

cisa logo 002

Microsoft Releases Guidance for the BlackLotus Campaign


Microsoft has released Guidance for investigating attacks using CVE-2022-21894: The BlackLotus Campaign(link is external). According to Microsoft, “[t]his guide provides steps that organizations can take to assess whether users have been targeted or compromised by threat actors exploiting CVE-2022-21894(link is external) via a Unified Extensible Firmware Interface (UEFI) bootkit called BlackLotus.” An attacker could exploit this vulnerability to take control of an affected system.

CISA urges users and organizations to review the Microsoft Blog Post(link is external) for more information, and apply necessary detection, recovery, and prevention strategies. 
 

 


A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

Buy Me A Coffee
Patreon

 To keep up to date follow us on the below channels.

join
Telegram
discord
Discord
reddit
Reddit
linkedin
LinkedIn