CVE-2025-68947Active Exploitation

HIGHCVSS 5.7 · MEDIUM

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes by issuing crafted IOCTL requests to the driver.

7.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 18 classified signals
  • Public PoC and exploit tooling are both present
  • 27 mentions across 14 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 18 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 17 signals
  • General: 3 classified signals
  • Peaked 6d ago at 9 mentions (2026-02-15); latest day: 1
  • 27 total mentions across 14 days

Deep dive

Activity timeline27 mentions / 14d
02579Mentions · 2026-02-05: 1Mentions · 2026-02-06: 2Mentions · 2026-02-09: 1Mentions · 2026-02-10: 4Mentions · 2026-02-11: 1Mentions · 2026-02-12: 1Mentions · 2026-02-14: 2Mentions · 2026-02-15: 9Mentions · 2026-02-17: 1Mentions · 2026-02-24: 1Mentions · 2026-02-25: 1Mentions · 2026-02-27: 1Mentions · 2026-03-05: 1Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-02-25: 1PoC Mentioned / Linked · 2026-04-11: 1Exploit Tool / Code · 2026-02-05: 1Exploit Tool / Code · 2026-02-12: 1Exploit Tool / Code · 2026-04-11: 1Active Exploitation · 2026-02-06: 2Active Exploitation · 2026-02-09: 1Active Exploitation · 2026-02-10: 3Active Exploitation · 2026-02-11: 1Active Exploitation · 2026-02-12: 1Active Exploitation · 2026-02-14: 1Active Exploitation · 2026-02-15: 6Active Exploitation · 2026-02-24: 1Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-02-27: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-06: 2Technical Details · 2026-02-09: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-15: 7Technical Details · 2026-02-17: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-05: 102-0502-0602-0902-1002-1102-1202-1402-1502-1702-2402-2502-2703-0504-11
Signal classification4 categories
Active Exploitation
1866.7%
Exploit
311.1%
General
311.1%
Disclosure
311.1%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-02-051
Exploit1
2026-02-062
Active Exploitation2
2026-02-091
Active Exploitation1
2026-02-104
Active Exploitation3Exploit1
2026-02-111
Active Exploitation1
2026-02-121
Active Exploitation1
2026-02-142
Active Exploitation1General1
2026-02-159
Active Exploitation6Disclosure3
2026-02-171
General1
2026-02-241
Active Exploitation1
2026-02-251
Active Exploitation1
2026-02-271
Active Exploitation1
2026-03-051
General1
2026-04-111
Exploit1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️🛠️ Reynolds ransomware embeds its own BYOVD evasion, bundling a vulnerable driver to disable EDR before encryption. It drops the NSecKrnl driver (CVE-2025-68947) to kill security tools, reducing detection and affiliate effort. 🔗 Read full attack chain and defense insights → https://thehackernews.com/2026/02/reynolds-ransomware-embeds-byovd-driver.html

    Post summary

    Reynolds ransomware actively exploits the vulnerable NSecKrnl driver (CVE‑2025‑68947) to disable security tools, demonstrating real‑world use of the CVE.

    3231842654.9K
    1.0M followersView on X
  • blackorbird@blackorbird
    Active Exploitation

    The ransomware payload drops a vulnerable NsecSoft NSecKrnl driver and tries to create an NSecKrnl service. This driver is then exploited to kill processes. The NSecKrnl driver is a Windows kernel-mode driver with a known critical security vulnerability (CVE-2025-68947), which means that it fails to verify if a user has sufficient permissions before executing commands. This allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes, by issuing crafted Input/Output Control (IOCTL) requests to the driver.  https://www.security.com/threat-intelligence/black-basta-ransomware-byovd

    Post summary

    The ransomware uses the CVE‑2025‑68947 kernel driver flaw to kill protected processes, illustrating active exploitation of a local privilege escalation vulnerability.

    016263265.4K
    39.9K followersView on X
  • txc@0x747863
    General

    Happy to share my writeup for the challenge 'Kernel Shield' on http://malops.io, created by @MalGamy12. In this challenge we are tasked to analyze a benign kernel driver file, which can be exploited to kill specific processes (CVE-2025-68947). https://txc.gitbook.io/documentation/writeups/malops.io/kernel-shield

    Post summary

    The text shares a writeup about a kernel driver exploit (CVE-2025-68947) that can terminate processes, but it does not provide PoC, exploit code, or patch details.

    011036323.5K
    17 followersView on X
  • Gameel Ali 🤘@MalGamy12
    Active Exploitation

    🚨 New Challenge: Kernel Shield Reverse engineer the NSecKrnl driver (CVE-2025-68947). weaponized in the #Reynolds ransomware BYOVD campaign to kill EDR/AV processes. 🔗 https://malops.io/challenges/kernel-shield 🔗 https://discord.gg/cncpftd3Kt https://t.co/9wxwdIRwJw

    Post summary

    CVE-2025-68947 is being weaponized by the #Reynolds ransomware to terminate EDR/AV processes; no patch or PoC details are provided, but the text confirms active exploitation.

    26039122.4K
    6.4K followersView on X
  • clibm079@clibm079
    General

    BYOVD Example: CVE-2025-68947 Even CVSS Medium vulnerabilities can enable powerful attack chains. Risk assessments must consider operational impact and adversary capabilities, not just scores. https://t.co/ZLJ1CduWBA

    Post summary

    The tweet references CVE-2025-68947 and notes its CVSS Medium score, warning that even medium-rated vulnerabilities can support powerful attack chains, but offers no technical details, PoC, exploit, or patch information.

    03051558
    618 followersView on X
  • BRANDEFENSE | Digital Risk Protection Service@Brandefense
    Active Exploitation

    A new ransomware group called Reynolds is leveraging BYOVD (Bring Your Own Vulnerable Driver) to disable EDR/AV before encryption. They’re abusing the NSecKrnl driver (CVE-2025-68947) to reduce visibility at the kernel level. If you’re not monitoring vulnerable drivers and driver abuse, this threat could slip past you. Read our technical breakdown with IOCs, YARA rules & IR guidance → https://eu1.hubs.ly/H0s5m-F0 #Ransomware #BYOVD #ThreatIntelligence #CyberSecurity #CISO #SOC #Brandefense

    Post summary

    The post reports that the Reynolds ransomware group is actively exploiting CVE-2025-68947 to disable EDR/AV, highlighting a real‑world threat scenario.

    01031130
    1.1K followersView on X
  • AnMioLink@anylink20240604
    General

    https://x.com/anylink20240604/status/1967288987816751520 Update Jan 13. 2026: This vulnerability has been assigned with CVE ID: CVE-2025-68947

    Post summary

    The tweet announces the assignment of CVE-2025-68947 but offers no further details about the vulnerability, exploitation, or remediation.

    0101195
    357 followersView on X
  • Fenikso@fenikso_io
    Active Exploitation

    Evolución táctica: Reynolds usa CVE-2025-68947 y BYOVD para anular Sophos, ESET, Defender y CrowdStrike desde el kernel. El payload deshabilita defensas antes del cifrado. IOCs (SHA-256) detallados en las imágenes. #Infosec #Reynolds #BYOVD #Cybersecurity #Fenikso https://t.co/P0eIZ7xuom

    Post summary

    The post reports that the attacker Reynolds is actively exploiting CVE-2025-68947 via BYOVD to disable multiple endpoint defenses before encrypting systems.

    10020103
    421 followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    @vuln_tracker @fenikso_io CVE-2025-68947 was publicly disclosed around January 2026, with active exploitation observed in campaigns as early as February 2026. Indicators include prior side-loaded loaders and tools like GotoHTTP for persistence. #CyberThreats

    Post summary

    CVE-2025-68947 was disclosed in January 2026 and is actively exploited in campaigns, with attackers using side‑loaded loaders and GotoHTTP for persistence.

    1001039
    313 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 Black Basta Levels Up: BYOVD Driver Embedded Directly Inside Ransomware Payload A new Black Basta campaign embeds a “Bring Your Own Vulnerable Driver” (BYOVD) component directly into the ransomware, dropping the signed NsecSoft NSecKrnl driver and abusing CVE-2025-68947 to kill EDR/AV processes (e.g., Sophos, MsMpEng) before encryption. This matters because bundling kernel-level defense impairment into the payload shortens the attack chain and makes pre-encryption detection/containment significantly harder. 🕷️ Malware: Black Basta (BYOVD using NsecSoft NSecKrnl / CVE-2025-68947) 🎯 Target: Global/Enterprise #️⃣ Category: #CyberCrime #Malware #TargetedAttacks 🔗 URL: https://cybersecuritynews.com/black-basta-ransomware-actors-embeds-byovd/

    Post summary

    Black Basta ransomware now embeds a vulnerable kernel driver to exploit CVE-2025-68947, actively disabling EDR/AV before encrypting files, demonstrating in‑the‑wild use of the flaw.

    10010133
    191 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    Black Basta ransomware uses a vulnerable signed kernel driver (CVE-2025-68947) embedded in its payload to kill security processes and evade defenses, appending “.locked” to encrypted files. Includes GotoHTTP RAT for persistence. #BlackBasta #RansomwareEv… https://ift.tt/fqt7KCW

    Post summary

    Black Basta ransomware actively exploits CVE-2025-68947 by embedding a vulnerable signed kernel driver into its payload to terminate security processes and evade defenses, demonstrating real‑world usage of the vulnerability.

    00110190
    3.6K followersView on X
  • transilienceai@transilienceai
    Disclosure

    🚨 **CVE-2025-68947** is a vulnerability in the NsecSoft **NSecKrnl** Windows kernel-mode driver that fails to verify user permissions before executing commands. This enables local authenticated attackers to terminate protected processes via crafted Input/Output Control (IOCTL) requests. #CyberSecurity #Vulnerability

    Post summary

    CVE-2025-68947 is a kernel‑mode driver flaw in NsecSoft NSecKrnl that allows local authenticated attackers to terminate protected processes via crafted IOCTL requests. No PoC, exploit, patch, or active exploitation information is provided.

    1000054
    313 followersView on X
  • transilienceai@transilienceai
    Disclosure

    🚨 **CVE-2025-68947** is a medium-severity vulnerability (CVSS score: 5.7) in the NsecSoft **NSecKrnl** Windows kernel-mode driver. It fails to properly verify user permissions before executing commands. This flaw allows local, authenticated attackers to send crafted Input/Output Control (IOCTL) requests. 🛡️ #CyberSecurity #Vulnerability

    Post summary

    This post announces CVE‑2025‑68947, a medium‑severity flaw in a Windows kernel‑mode driver that allows local authenticated attackers to issue crafted IOCTL requests due to missing permission checks. No exploit evidence, patch, or active exploitation is reported.

    1000046
    313 followersView on X
  • transilienceai@transilienceai
    Disclosure

    🚨 **CVE-2025-68947** is a critical vulnerability (CVSSv4 score of 5.7) in the NsecSoft NSecKrnl Windows kernel-mode driver. It fails to properly verify user permissions before processing Input/Output Control (IOCTL) requests. This allows local authenticated attackers to terminate protected processes owned by SYSTEM or other users via crafted requests. #CyberSecurity #Vulnerability

    Post summary

    CVE-2025-68947 is disclosed as a critical kernel‑mode driver vulnerability that permits local authenticated attackers to terminate protected SYSTEM processes via crafted IOCTL requests.

    1000051
    313 followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    This newly identified ransomware family bundles the vulnerable, signed NSecKrnl driver directly into its payload, dropping it and creating an "NSecKrnl" service upon execution. #ThreatIntel 🚨 The CVE-2025-68947 vulnerability (CVSS 5.7) fails to properly verify user permissions, enabling local authenticated attackers to send crafted Input/Output Control (IOCTL) requests that kill protected processes, including those owned by SYSTEM.

    Post summary

    A new ransomware family actively exploits CVE-2025-68947 by bundling the vulnerable NSecKrnl driver in its payload, leveraging local privileged IOCTL requests to terminate protected processes.

    1000058
    313 followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    @vuln_tracker @ThreatSynop Reynolds ransomware exploits CVE-2025-68947 in the NsecSoft NSecKrnl kernel driver using a Bring Your Own Vulnerable Driver (BYOVD) technique to terminate security processes before encrypting files with a ".locked" extension. #CyberSecurity #Ransomware 🔒

    Post summary

    Reynolds ransomware is actively exploiting CVE-2025-68947 by using a BYOVD technique to stop security processes before encrypting files.

    1000064
    313 followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    Reynolds ransomware is a new strain that embeds the vulnerable NsecSoft NSecKrnl driver (exploiting CVE-2025-68947) directly in its payload to disable EDR and antivirus tools via the Bring Your Own Vulnerable Driver (BYOVD) technique before encrypting files. #Ransomware #CyberSecurity 🚨

    Post summary

    Reynolds ransomware embeds a vulnerable driver to disable EDR and antivirus tools, demonstrating that CVE‑2025‑68947 is being actively exploited in the wild.

    1000066
    313 followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    @vuln_tracker @ThreatSynop It exploits CVE-2025-68947 to kill EDR/AV processes, evading detection. Then, it encrypts files with a .locked extension (ransomware binary example: wxt4e.exe, SHA256: 6bd8a0291b268d32422139387864f15924e1db05dbef8cc75a6677f8263fa11d). #RansomwareAttack 🔒

    Post summary

    The tweet claims that CVE‑2025‑68947 is being actively exploited by ransomware to terminate EDR/AV processes and encrypt files with a ".locked" extension.

    1000071
    313 followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    @vuln_tracker @IT_news_for_all Reynolds ransomware embeds a vulnerable NsecSoft NSecKrnl driver (exploiting CVE-2025-68947) directly in its payload as a BYOVD technique to disable EDR security tools before encrypting files. 🚨 #CyberSecurity #Ransomware

    Post summary

    Reynolds ransomware embeds the vulnerable NsecSoft NSecKrnl driver (CVE-2025-68947) to disable EDR tools via a BYOVD technique, showing active exploitation of the flaw. No patch or mitigation is referenced.

    1000064
    313 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 Reynolds Ransomware Bundles BYOVD Driver to Kill EDR Before Encrypting Reynolds is a newly identified ransomware that embeds a vulnerable signed NsecSoft kernel driver (NSecKrnl) and exploits CVE-2025-68947 to terminate major security/EDR processes (Defender, CrowdStrike, Sophos, Symantec, etc.) before encrypting files and appending “.locked”. The bundled BYOVD approach reduces attacker steps and shrinks defender response time, making pre-encryption detection and driver-blocking controls even more critical. 🕷️ Malware: Reynolds ransomware 🎯 Target: Global/Enterprise (Windows) #️⃣ Category: #Malware #CyberCrime #TargetedAttacks #Vulnerability 🔗 URL: https://securityaffairs.com/187869/security/reynolds-ransomware-uses-byovd-to-disable-security-before-encryption.html

    Post summary

    Reynolds ransomware actively exploits CVE-2025-68947 by embedding a vulnerable signed kernel driver to terminate security/EDR processes before encrypting files.

    1000072
    191 followersView on X

Explore more