Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Medium Severity
Global
Date OccurredAug 21, 202615:52 UTC
Event TypeCyber Intelligence
SourceTheHackerNews
RecordedAug 21, 2026
Full Description
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Win