Back to all news
Security

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

The Hacker News·August 21, 2026·1 min read
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research disclosed a technique abusing Microsoft Defender's signed boot-time remediation driver BTR.sys to perform arbitrary kernel-level file and registry operations on Windows 7 through Windows 11 25H2. No software flaw was exploited, and no external driver was imported. The technique affects systems without requiring user interaction beyond standard access.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store