Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
- Posted on August 21, 2026
- By The Hacker News
- 1 Views
- 1 min read
A critical security vulnerability has emerged where Microsoft Defender's legitimate kernel driver can be exploited by attackers with administrative privileges. The BTR Reforged technique leverages Defender's signed BTR.sys driver to perform unauthorized kernel-level operations, enabling threat actors to bypass security measures and potentially disable competing antivirus solutions. This sophisticated attack demonstrates how trusted security components can become vectors for malicious activity when proper access controls are insufficient.
Summary auto-generated by AI from the original publisher's content. Editorial standards.