Microsoft Defender's Own Driver Can Be Weaponized to Delete Security… | HappeningNow.news

Cybersecurity · 1 views

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to per…

Source The Hacker News Story Brief Updated 1h 16m ago
Story intelligence Beta
Confidence Limited Single-outlet story
Views 1 Community interest
Read time 1 min ~49 words

Story Brief

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine.

Read full article on The Hackernews

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page