Return to Threats

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

thehackernews.com 2026-08-21 AI supply chain Critical

What Happened

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a

Why It Matters

Report fact: Check Point Research describes a technique that abuses Microsoft Defender’s legitimately signed boot-time remediation driver (BTR.sys) to perform arbitrary kernel-level file and registry operations, including deleting security software at boot, on Windows 7 through Windows 11 25H2, without exploiting a software flaw or importing an external driver. Report fact: Because the capability is built into a trusted, signed component, it can be repurposed by an attacker already on the system to neutralize defensive tools early in the boot process. RealGround analysis: This highlights an AI-adjacent supply chain and platform risk, where trusted security components and remediation tooling can be weaponized and should be inventoried and governed similarly to AI and automation frameworks. RealGround analysis: Organizations should treat such privileged remediation drivers and automated security tooling as part of their broader supply chain and SBOM posture, ensuring configuration hardening, monitoring of driver abuse patterns, and readiness assessments for scenarios where built-in security components are turned against the environment.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html

Talk to AI CISO