Microsoft Defender’s Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research has disclosed a technique that uses Microsoft Defender’s own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine.

The driver, BTR.sys (Boot Time Removal Tool), is a

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while

Attack Update: Top 5 Attack-IPs auf doode.info – 15.09.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 74.7.242.62 — 2648 requests (recent log) 161.118.200.95 — 1191 requests (recent log) 217.142.185.160 — 1183 requests (recent

Attack Update: Top 5 Attack-IPs auf doode.info – 21.09.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 472 requests (recent log) 104.199.223.151 — 425 requests (recent log) 104.238.222.26 — 269 requests (recent