Autoium
Back to blog
Threat Intel
The Hacker News
Aug 21, 2026

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems…

How Autoium Vortex helps

Stay ahead of emerging threats with Autoium Vortex — unified cloud, application, and compliance scanning with real-time job tracking and PDF reporting.

  • • Run Web VAPT / Radar to validate application exposure tied to this class of issue.
  • • Use AWS Cloud + Deep Cloud (Prowler / CIS) to catch related cloud misconfigurations.
  • • Export PDF reports from your console for leadership and auditor-ready evidence.

Security briefing

Weekly digest of live threat intel plus Autoium product updates — no spam.