Microsoft has quietly made a welcome change to its AppLocker feature. AppLocker application control policies help organizations manage the applications and files that users can run on their systems.
North Korean threat actors known as the Lazarus Group exploited a flaw in the Windows AppLocker driver (appid.sys) as a zero-day to gain kernel-level access and turn off security tools, allowing them ...