Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New RAM Exploit Bypasses Windows Security Barriers

New RAM Exploit Bypasses Windows Security Barriers

Posted on August 14, 2026 By CWS

A recently uncovered cyberattack, termed ‘Download More RAM,’ effectively circumvents Windows Virtualization-Based Security (VBS), undermines Hypervisor-Enforced Code Integrity (HVCI), and deactivates Microsoft Defender. Microsoft has identified this threat as CVE-2026-23670 and has provided patches in its April 2026 security update.

Vulnerability in RAM Modules

This exploit targets inadequately protected Serial Presence Detect (SPD) data on specific DDR4 and DDR5 memory modules. SPD data contains key configurations like the system’s memory capacity and speed, crucial for RAM module operations.

If the SPD chip is writable, attackers with local admin access can manipulate the reported memory structure, misleading the system into recognizing more RAM capacity than is physically present. This manipulation leads to memory aliasing, where two distinct physical addresses map to the same RAM segment, potentially causing system instability and crashes.

Impact on Windows Security Mechanisms

Researchers discovered that modifying Windows boot settings allows the system to reserve the aliased memory, maintaining stability while granting attackers access to the physical RAM through different addresses. This tactic breaches the security boundaries meant to be upheld by VBS, which uses Hyper-V for isolating sensitive components such as the Secure Kernel.

The ‘Download More RAM’ exploit operates directly on physical memory, bypassing existing protections based on virtual trust levels and process permissions. The approach allows attackers to read and write in memory regions that are supposed to be secure.

Multi-Stage Attack Process

The attack proceeds through a six-stage chain, starting with memory aliasing to create overlapping memory addresses. Subsequent stages involve stabilizing the system to prevent crashes, using signed drivers to access concealed memory, and modifying memory via a RAM-disk utility.

Further, the exploit patches the Secure Kernel Code Integrity library (skci.dll) to disable driver blocklists, enabling the loading of previously blocked drivers. These drivers can then provide extensive physical memory access, enhancing the attacker’s capabilities.

The research indicates that this method allows for the alteration of protected memory areas linked to VBS-protected processes, ultimately deactivating security products like Microsoft Defender.

Mitigation and Future Concerns

The researchers emphasize that this attack requires local administrator rights and writable SPD configurations, found in some consumer memory lines from brands like Corsair and G.Skill. However, not all products are affected, and the protection status varies.

Microsoft’s recent mitigation blocks the specific attack chain but does not address the potential for new stabilization techniques. Organizations are advised to apply the latest Windows updates, maintain Secure Boot and VBS protections, and inspect BIOS settings to prevent SPD writes.

Memory manufacturers are encouraged to implement SPD write protection, especially for critical configuration blocks, to minimize exposure to such exploits in the future.

Cyber Security News Tags:CVE-2026-23670, cybersecurity news, DDR4, DDR5, memory aliasing, Microsoft Defender, RAM exploit, SPD write protection, VBS bypass, Windows security

Post navigation

Previous Post: Trezor Customer Data Exposed in ShipMonk Breach
Next Post: Data Breach Hits Over 1,000 Charities Using Beacon CRM

Related Posts

CISA Releases Operational Technology Guide for Owners and Operators Across all Critical Infrastructure CISA Releases Operational Technology Guide for Owners and Operators Across all Critical Infrastructure Cyber Security News
OverlayPhantom Trojan Exploits Android Devices OverlayPhantom Trojan Exploits Android Devices Cyber Security News
New Android Malware Mimics as SBI Card, Axis Bank Apps to Steal Users Financial Data New Android Malware Mimics as SBI Card, Axis Bank Apps to Steal Users Financial Data Cyber Security News
Everest Ransomware Group Allegedly Exposes 343 GB of Sensitive Data in Major Under Armour Breach Everest Ransomware Group Allegedly Exposes 343 GB of Sensitive Data in Major Under Armour Breach Cyber Security News
Over 6000 Apache ActiveMQ Servers Risk CVE-2026-34197 Exploit Over 6000 Apache ActiveMQ Servers Risk CVE-2026-34197 Exploit Cyber Security News
Cybercriminals Exploit Microsoft Tools in New Phishing Scheme Cybercriminals Exploit Microsoft Tools in New Phishing Scheme Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Data Breach Hits Over 1,000 Charities Using Beacon CRM
  • New RAM Exploit Bypasses Windows Security Barriers
  • Trezor Customer Data Exposed in ShipMonk Breach
  • Aeternum Botnet’s Blockchain Strategy Challenges Security
  • Hackers Target GeoServer’s Unpatched Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Data Breach Hits Over 1,000 Charities Using Beacon CRM
  • New RAM Exploit Bypasses Windows Security Barriers
  • Trezor Customer Data Exposed in ShipMonk Breach
  • Aeternum Botnet’s Blockchain Strategy Challenges Security
  • Hackers Target GeoServer’s Unpatched Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark