Researchers find way to weaponize Windows Defender's own driver
21-08-2026 22:52 via scworld.com

Researchers find way to weaponize Windows Defender's own driver

Check Point Research disclosed a technique that uses Microsoft Defender's boot-time remediation driver, BTR.sys, to perform arbitrary kernel-level file and registry operations on Windows 7 through Windows 11 25H2.
Read more »

Security news



How to Map Controls Across Frameworks Without Losing Meaning
How to Map Controls Across Frameworks Without Losing Meaning
TrueConf flaws enabling attacks on meeting participants added to KEV catalog
TrueConf flaws enabling attacks on meeting participants added to KEV catalog
Secure AI agent identity in private cloud and hybrid environments
Secure AI agent identity in private cloud and hybrid environments
Navy warns of multi-pronged adversary campaign targeting personnel and installations
Navy warns of multi-pronged adversary campaign targeting personnel and installations
New Agent Tesla malware version uses emoji obfuscation to evade detection
New Agent Tesla malware version uses emoji obfuscation to evade detection
Army seeks AI agents for cyber defense amid evolving threats
Army seeks AI agents for cyber defense amid evolving threats
A ‘kill switch’ law only makes sense for a worst-case scenario
A ‘kill switch’ law only makes sense for a worst-case scenario
The CISO Doesn't Own the Outcome: A Shared-Accountability Model for Security Decisions
The CISO Doesn't Own the Outcome: A Shared-Accountability Model for Security Decisions
Medusa ransomware group attacked more than 500 victims since 2021
Medusa ransomware group attacked more than 500 victims since 2021
Perspective and lessons learned from mergers and acquisitions
Perspective and lessons learned from mergers and acquisitions
Geekom admits malware found in legacy mini PC driver download
Geekom admits malware found in legacy mini PC driver download
Microsoft removes WMIC tool from Windows 11
Microsoft removes WMIC tool from Windows 11
Critical vulnerability in Ray framework allows remote code execution
Critical vulnerability in Ray framework allows remote code execution
CISA explores single contract for cybersecurity software purchases
CISA explores single contract for cybersecurity software purchases
Desktop versie