Tuttiquotidiani is completely free. Every day we aggregate news from 100+ sources and generate original AI summaries for you. Help us keep the service running with a small donation, or become TQ Pro for just €1/month.

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

  • Posted on August 21, 2026
  • By The Hacker News
  • 1 Views
  • 1 min read
In brief

A critical security vulnerability has emerged where Microsoft Defender's legitimate kernel driver can be exploited by attackers with administrative privileges. The BTR Reforged technique leverages Defender's signed BTR.sys driver to perform unauthorized kernel-level operations, enabling threat actors to bypass security measures and potentially disable competing antivirus solutions. This sophisticated attack demonstrates how trusted security components can become vectors for malicious activity when proper access controls are insufficient.

Summary auto-generated by AI from the original publisher's content. Editorial standards.

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

BTR Reforged uses Defender's signed BTR.sys with an administrator account and SeLoadDriverPrivilege for kernel file and registry operations.
continue reading...

Author
The Hacker News

You May Also Like