Windows and LinkedIn flaws used in Conti ransomware attacks, Google warns

An initial access broker, working on behalf of the Conti ransomware group (among others), has been targeting hundreds of organizations every day, leveraging a flaw in MSHTML, a proprietary browser engine for Windows, Google’s researchers are saying.

Google’s Threat Analysis Group found a group dubbed “Exotic Lily” working as an initial access broker – breaching target networks, before selling the acquired access to the highest bidder.
