baseVISION TI – Patch, Exploit, Repeat: A Never-Ending Cycle for Windows Common Log File System Driver Vulnerabilities

Since 2024, multiple zero-day vulnerabilities in the Windows Common Log File System (CLFS) driver have been exploited by ransomware groups like RansomEXX and Play (Balloonfly). These Elevation of Privilege (EoP) flaws enabled SYSTEM-level access and were used in real-world attacks before patches were released. Microsoft issued fixes across several Patch Read more…

baseVISION TI – A Looming Menace and Escalating Threat to macOS users

Cybercriminals are increasingly targeting macOS with infostealers, exploiting the growing adoption of Mac devices in corporate environments. Our latest TI-Report uncovers: A 101% increase in macOS infostealer activity in 2024 How Atomic (AMOS) and Poseidon are spreading in Switzerland The tactics behind phishing, malicious downloads, and malvertising Key mitigations to Read more…

baseVISION TI – How threat actors are abusing Microsoft Teams to trick your employees, and what you can do about that

Cybercriminals are increasingly using Microsoft Teams to bypass security controls and target employees. Our first TI-Report uncovers: How groups like Black Basta use Teams as an attack vector The tactics behind phishing, vishing, and email bombing Key mitigations to protect your organization Get the full insights and Indicators of Compromise Read more…