Wtop
Rise of Fake Windows Defender Alerts and Ransomware Exploits
First seen 2 Dec 2025, 18:33 UTC
•

•10.2
Export
Article Content
Browse articles
A recent report indicates that ransomware groups have developed methods to remotely disable Windows Defender, a built-in security tool from Microsoft, using trusted Windows drivers. This vulnerability allows criminals to turn off security alerts without detection, leading to an increase in fraudulent alerts aimed at gaining remote access to users' computers. Users are advised to be cautious and not rely solely on Windows Defender for protection.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
China-linked Cyber Group Expands Targeting to Southeastern Europe
China-Nexus APT UAT-7290 Targets South Asia Telecoms in Cyber Espionage Campaign
China-linked UAT-7290 Targets Telcos in Cyberespionage Campaign
UAT-7290 Cyber Espionage Targets South Asian Telecoms
APT28 Exploits MSHTML Zero-Day Vulnerability in Windows