Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
- ID
- 16504
- Status
- new
- Published
- 21 Aug 2026, 11:52 PM
- Fetched
- 22 Aug 2026, 12:42 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Excerpt
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a
Summary
No summary yet. It will appear after the daemon summarizes this item.