← BACK TO FEED
TAG

microsoft defender2 articles

Microsoft's Own Defender Driver Can Be Turned Against Itself to Wipe Security Software

Check Point Research has revealed a technique called "BTR Reforged" that weaponizes Microsoft Defender's own legitimately signed boot-time driver, BTR.sys, to perform kernel-level file and registry operations — including deleting entire security software stacks — on all Windows versions from 7 through 11 25H2. Because BTR.sys is a built-in Windows component rather than a third-party driver, it cannot be blocklisted without breaking Defender itself, and a live demonstration at Black Hat USA 2026 showed it successfully removing Defender with Tamper Protection active. Microsoft has declined to issue a patch, stating the technique requires pre-existing administrative privileges and therefore does not meet its criteria for immediate servicing.

23 Aug 2026

One Researcher Is Making Microsoft's Life Very Difficult, Six Weeks Running

A security researcher known as "Nightmare Eclipse" has disclosed six Windows vulnerabilities over six weeks, including three new ones — YellowKey, GreenPlasma, and MiniPlasma — revealed shortly after Microsoft's May 2026 Patch Tuesday. These flaws target core Windows security components, enabling attacks such as BitLocker bypass, privilege escalation to SYSTEM, and exploitation of a vulnerability Microsoft believed it had patched in 2020. Microsoft has only officially patched one of the six flaws so far, and experts warn that the researcher's deliberate timing — releasing disclosures immediately after Patch Tuesday — maximises the window of exposure before the next patch cycle.

20 May 2026