Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
🔒 Cybersécurité Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a 📖 Cet article provient d'une source externe. 🔗 Lire l'article complet sur la source → 58 mots extraits · Source originale 🔥 OFFRE PARTENAIRE Ordinateur portable professionnel ULAP A15ZRC 15,6 pouces, 8 Go de RAM + 512 Go de stockage, Windows 11, processeur AMD Ryzen 5 3500U, prise britannique 🔥 Ordinateur portable professionnel ULAP A15ZRC 15,6 pouces, 8 Go de RAM + 512 Go de stocka...