Intelligent CISO Issue 89 | Page 11

HID unveils next-generation FIDO hardware and centralised management at scale
Kaspersky uncovers ThrottleStop flaw in Brazil ransomware attack

CISO news

HID unveils next-generation FIDO hardware and centralised management at scale

ID, a leader in trusted identity and access management solutions, has announced a new line of FIDO-certified

H credentials – now powered by the new Enterprise Passkey Management( EPM) solution – designed to help organizations deploy and manage passkeys at the enterprise scale.

New research from FIDO Alliance shows that while 87 % of enterprises are adopting passkeys, nearly half of those that are yet to deploy cite complexity and cost concerns as primary barriers. HID’ s solution streamlines the shift to passwordless authentication.
The next phase of HID’ s passwordless authentication roadmap gives enterprises choice, flexibility, and speed to deploy FIDO without compromising user experience or security posture. The expanded portfolio delivers phishing-resistant authentication with enterprisegrade lifecycle management, making scalable passwordless security accessible to organisations of all sizes. The solution works seamlessly across diverse work environments while reducing IT support requirements through centralised visibility and control.
“ Phishing-resistant authentication isn’ t one-size-fits-all. It’ s a journey, and we’ re here to help enterprises along the way,” said Sean Dyon, Vice President & Head of the Authentication Business Unit at HID.
“ Rolling out passkeys isn’ t just about issuing devices, it is about giving security teams the tools to manage them at the enterprise scale, with the same precision as the rest of the identity stack. Our next-generation portfolio delivers both the hardware diversity and FIDO management capabilities organisations need to deploy and manage passkeys at scale.”

Kaspersky uncovers ThrottleStop flaw in Brazil ransomware attack

reported the vulnerability to the vendor. Kaspersky has also confirmed that its security solutions detect and block the malware.
ThrottleStop is freeware supported by TechPowerUp and is widely used by individual users who want more control over their Central Processing Unit( CPU) behaviour – for example, to reduce heat and power consumption, or to achieve smoother performance on laptops.
Kaspersky’ s Global Emergency Response Team( GERT) experts discovered the vulnerability in ThrottleStop during an attack investigation involving MedusaLocker ransomware. It has been assigned the ID CVE-2025-7771. aspersky has discovered a vulnerability in ThrottleStop, a free tool used to control laptop processor performance,

K that has been exploited by the MedusaLocker ransomware operators during a recent attack on a Brazilian company.

The attackers combined the flaw with a new variant of a known class of malware capable of lowering systems’ defenses. Kaspersky uncovered the findings during an incident investigation and has
“ ThrottleStop is a consumer tool designed for personal laptops – corporations usually do not use it due to strict security policies. In the observed incident, the tool was delivered in a bundle with the EDR-disabling malware. The vulnerable version of the driver exposes two so-called IOCTL interfaces – special communication channels between user and machine – that let regular software read from and write to physical memory. This insecure design can be abused by malicious actors to modify the Windows kernel and execute kernel functions with highest privileges”, said Cristian Souza, Incident Response Specialist at Kaspersky Global Emergency Response Team.
WWW. INTELLIGENTCISO. COM 11