[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fu5oqwMxKYc3yqpFy6BPIihX4j737bOseUgFCvUeZLE8":3},{"article":4,"iocs":32,"watch_terms":36},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":17,"category":18,"article_tags":21},"5b8293cf-6809-47df-83ba-093c016ebdc2","‼️A threat actor using the handle \"secretsdump\" is selling a kernel exploit designed to bypass an...","a-threat-actor-using-the-handle-secretsdump-is-selling-a-kernel-exploit-designed","‼️A threat actor using the handle \"secretsdump\" is selling a kernel exploit designed to bypass and kill AV\u002FEDR protections on a dark web forum. The tool is marketed as a superior alternative to commonly detected pastes and public tools.\n\nAdvertised capabilities include cleaning https:\u002F\u002Ft.co\u002FF0Sa3i3JlF","A threat actor operating under the handle 'secretsdump' is marketing a kernel-level exploit on dark web forums designed to bypass and disable antivirus and endpoint detection and response (EDR) solutions. The tool is positioned as a more reliable alternative to publicly available or frequently detected exploit code, with advertised capabilities including process cleaning and AV\u002FEDR evasion.","Threat actor 'secretsdump' sells kernel exploit to bypass AV\u002FEDR on dark web.",null,"https:\u002F\u002Fx.com\u002FDarkWebInformer\u002Fstatus\u002F2036517456919802258","2026-03-24T18:56:13+00:00","2026-03-24T19:00:16.14416+00:00",7,[],"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":17,"icon":11,"name":19,"slug":20},"Malware","malware",[22,27],{"category":23},{"id":24,"icon":11,"name":25,"slug":26},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":28},{"id":29,"icon":11,"name":30,"slug":31},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[33],{"type":20,"value":34,"context":35},"secretsdump kernel exploit","Dark web-sold kernel exploit tool for AV\u002FEDR bypass",[]]