Login
← All news

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

The Hacker News Systems Security

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a…

Read the full story on The Hacker News https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html
Attacks like this land on ordinary sites far more often than on chosen targets. If you would rather your site never became the story, CrockyHost hosting ships with daily backups, automatic updates and a firewall we manage.