Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
The Hacker News August 21, 2026

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

BTR Reforged uses Defender's signed BTR.sys with an administrator account and SeLoadDriverPrivilege for kernel file and registry operations.

Advertisement

Advertisement

More like this