blackorbird[verified]@blackorbirdActive Exploitation
The ransomware uses the CVE‑2025‑68947 kernel driver flaw to kill protected processes, illustrating active exploitation of a local privilege escalation vulnerability.
BRANDEFENSE | Digital Risk Protection Service[verified]@BrandefenseActive Exploitation
The post reports that the Reynolds ransomware group is actively exploiting CVE-2025-68947 to disable EDR/AV, highlighting a real‑world threat scenario.
Fenikso[verified]@fenikso_ioActive Exploitation
The post reports that the attacker Reynolds is actively exploiting CVE-2025-68947 via BYOVD to disable multiple endpoint defenses before encrypting systems.
transilienceai[verified]@transilienceaiActive Exploitation
CVE-2025-68947 was disclosed in January 2026 and is actively exploited in campaigns, with attackers using side‑loaded loaders and GotoHTTP for persistence.
ThreatSynop[verified]@ThreatSynopActive Exploitation
Black Basta ransomware now embeds a vulnerable kernel driver to exploit CVE-2025-68947, actively disabling EDR/AV before encrypting files, demonstrating in‑the‑wild use of the flaw.
transilienceai[verified]@transilienceaiDisclosure
CVE-2025-68947 is a kernel‑mode driver flaw in NsecSoft NSecKrnl that allows local authenticated attackers to terminate protected processes via crafted IOCTL requests. No PoC, exploit, patch, or active exploitation information is provided.
transilienceai[verified]@transilienceaiDisclosure
This post announces CVE‑2025‑68947, a medium‑severity flaw in a Windows kernel‑mode driver that allows local authenticated attackers to issue crafted IOCTL requests due to missing permission checks. No exploit evidence, patch, or active exploitation is reported.
transilienceai[verified]@transilienceaiDisclosure
CVE-2025-68947 is disclosed as a critical kernel‑mode driver vulnerability that permits local authenticated attackers to terminate protected SYSTEM processes via crafted IOCTL requests.