Cybersecurity
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7…
Summary
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedMore from Cybersecurity
Continue reading recent Cybersecurity coverage
- Hackers exploit Citrix NetScaler zero-day to deploy web shellsContinue reading
- Former US Air Force members sent to prison over BEC attacksContinue reading
- French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven WeeksContinue reading
- DARPA Selects Xint to Use AI in Securing Military Messaging AppsContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow