Ransomware attackers have been exploiting vulnerabilities in the Windows Common Log File System (CLFS) driver to carry out malicious activities, including manipulating the CLFS_CONTROL_RECORD structure and bypassing index verification, ultimately corrupting BLF files.
View full story…