Cyber Intelligence

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Medium Severity Global
Date Occurred Aug 21, 2026 15:52 UTC
Event Type Cyber Intelligence
Source TheHackerNews
Recorded Aug 21, 2026
Full Description

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Win

Event Metadata
  • ID #25557
  • Type Cyber Intelligence
  • Region Global
  • Severity Medium
  • Indexed Aug 21, 2026