Back Feeds.4Sysops Microsoft Defender’s signed BTR.sys driver can erase security tools at boot
A Microsoft-signed driver built into Defender can be repurposed to remove antivirus and EDR components before they start, giving attackers with administrator-level privileges a powerful boot-time evasion technique. Check Point Research says the approach works from Windows 7 through Windows 11 25H2, bypasses common driver-blocking controls, and is not currently linked to real-world attacks. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
