Microsoft Defender Driver Can Be Weaponized to Disable EDR and AV From Windows Kernel
Microsoft Defender’s legitimate Boot-Time Removal (BTR.sys) driver can be repurposed to perform powerful kernel-level file and registry operations, potentially enabling attackers with administrative privileges to neutralize endpoint security protections. The Check Point research does not describe a conventional vulnerability or memory-corruption flaw; instead, it exposes how a trusted, Microsoft-signed remediation component can become a Living-off-the-Land […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
