TGViewer
🛡 Cybersecurity & Privacy 🛡 - News 🛡 Cybersecurity & Privacy 🛡 - News @cibsecurity · 28.5K subscribers
Post #90540 286
🖋️ Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot 🖋️

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boottime remediation driver to perform arbitrary kernellevel file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys Boot Time Removal Tool, is a.

📖 Read more.

🔗 Via "The Hacker News"

----------
👁️ Seen on @cibsecurity
More from @cibsecurity
  1. Oct 8, 2026🪖 Securing Water and Wastewater Operational Technology Environments 🪖 Recent cyberattack…
  2. Oct 8, 2026🪖 Introducing the New Small Business Cybersecurity Support Program Finder 🪖 For small bu…
  3. Oct 7, 2026🕵️‍♂️ Anthropic Gives Vetted Defenders Fewer Claude Guardrails 🕵️‍♂️ Anthropic has merge…
  4. Oct 7, 2026🕵️‍♂️ Citizen Lab Slams Trump Administration, 'Techno-Fascist' Executives 🕵️‍♂️ The Citi…
  5. Oct 7, 2026🕵️‍♂️ Australian Gov't Weighs Mandatory AI Incident Reporting 🕵️‍♂️ In the wake of an ag…
  6. Oct 7, 2026🦿 Samsung’s October Update Patches 9 Critical Security Flaws Across Galaxy Devices 🦿 Sam…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →