Cybersecurity · August 24, 2026
Check Point researchers found that Microsoft Defender's own boot-time cleanup driver, BTR.sys, can be abused to perform kernel-level file and registry changes across every supported Windows version from 7 through 11 25H2. Because the driver is already signed by Microsoft, attackers don't need to exploit a bug or bring in an external driver to gain this level of access. The technique highlights how legitimate, trusted system components can become a stealthy privilege-escalation vector.
// source: thehackernews.com ↗