Tag

#microsoft-defender

17 stories taggedmicrosoft-defender.

Illustration: a generic laptop screen at night showing a plain calendar meeting invitation with a paperclip attachment icon
Threat Intelligence

Fake Meeting Invites Are Now Delivering Real Remote-Control Software

Microsoft says attackers are skipping the malware and installing legitimate MSP360 and ScreenConnect on victim machines, giving themselves a hands-on-keyboard foothold that looks like normal IT admin work.

4 min read
Illustration: a darkened office workstation
Vulnerabilities

A researcher keeps dropping Windows Defender zero-days, and Microsoft is losing patience

Abdelhamid Naceri's latest proof-of-concept, BigDiskBuster, stops Microsoft's built-in antivirus from updating. It is the eleventh unpatched flaw he has posted this year in a public feud with Redmond.

4 min read
Illustration: a modern security operations center at night
AI Security

Microsoft merges Sentinel and Defender into one console for AI-era security teams

The new Integrated Security Operations Center bets that human analysts and AI agents need to share the same tools, signals and controls, not bolt them together after the fact.

4 min read
Illustration: a cluttered corporate mail sorting facility at dusk
Threat Intelligence

Microsoft says Defender missed 221 high-severity emails per thousand users and still won its own benchmark

The vendor's fifth quarterly scorecard shows missed-threat rates climbing across the industry as AI-written phishing gets harder to catch.

4 min read
A security dashboard interface with multiple monitoring windows, one showing a breach notification alert while another display shows patching tools running in t
Vulnerabilities

Researcher Says Microsoft's Fix for Defender Flaw Doesn't Hold

A second proof-of-concept, nicknamed ShieldCrash, claims to walk straight past Microsoft's patch for the ShieldBreak vulnerability in Defender.

4 min read
An office worker's computer screen showing email with Google search links being incorrectly flagged as malicious by security software, with Safe Links warnings
Cloud Security

Microsoft Defender for Office 365 is blocking Google search links by mistake

A faulty security classification inside Safe Links is flagging normal Google URLs as malicious, and copy-pasting them into a browser does not help.

4 min read
A Windows Defender notification panel displayed prominently with false 'Antivirus is Off' warning, background showing actual active protection running, confusio
Vulnerabilities

Microsoft: Ignore the 'Antivirus Is Off' Warnings in Defender, It's a False Alarm

A bad notification, not a broken product. Microsoft says Defender is running normally despite pop-ups claiming otherwise, and a fix is on the way.

3 min read
A computer booting up with system files and registry entries visible in technical monitoring software, with security software components displayed on screen
Vulnerabilities

Microsoft's Own Antivirus Driver Can Be Turned Into a Weapon at Boot

Check Point researchers show how BTR.sys, the trusted cleanup tool inside Microsoft Defender, can be steered to wipe files and registry keys before Windows even finishes starting.

4 min read
A Microsoft security patch notification dashboard showing 22 fixes rolling out across cloud services, with six critical severity indicators glowing red at maxim
Vulnerabilities

Microsoft Pushes 22 Security Fixes, Six Rated Maximum Severity

A batch of patches covers Microsoft's cloud and identity products, with six flaws scoring a perfect 10 out of 10 on the severity scale. Most fixes apply automatically, but one Defender vulnerability is still waiting for a patch.

3 min read
A Windows desktop screen frozen mid-antivirus scan with a crash dialog box visible, surrounded by frustrated user workspaces in the background, with error messa
Vulnerabilities

Windows Defender Crashed Mid-Scan After Buggy Update, Microsoft Ships Fix

A faulty signature update knocked out Microsoft's built-in antivirus on Windows 10 and 11 machines this week, leaving scans failing and some users reinstalling their operating system before a patch arrived.

3 min read
A network analysis dashboard showing multiple domain names rotating and shifting across a visual representation of internet infrastructure, with suspicious beha
Threat Intelligence

Microsoft Ties 30+ Rotating Domains to MacSync, a New Mac Data-Stealing Malware

Defender Experts traced the macOS stealer across shifting web infrastructure by matching endpoint and network behaviour, not just domain names.

4 min read
A network diagram on a screen showing compromised VPN access points and failed encryption processes, ransomware code partially displayed with error messages, re
Ransomware

Akira gang reboots into Safe Mode to blind security tools, then fumbles the ransom

The hackers walked in through a SonicWall VPN with no second login step, but their own ransomware ran out of memory before it could lock a single file.

4 min read
A security researcher's workspace showing code editor with proof-of-concept exploit displayed, Windows Defender interface running in background, security bypass
Vulnerabilities

Researcher publishes 'ShieldBreak' code that claims to defeat a recent Microsoft Defender fix

A proof-of-concept from a researcher known as Chaotic Eclipse says the patch for CVE-2026-50656 can still be bypassed to gain full control of Windows machines.

3 min read
A computer screen showing a fake software update or security warning pop-up window overlaying a browser interface, with cursor hovering near a suspicious downlo
Threat Intelligence

Microsoft Warns of Two ACR Stealer Campaigns Stealing Credentials Through Fake Fixes

Between late April and mid-June 2026, two separate criminal campaigns used a trick called ClickFix to persuade workers to hand over browser passwords, session tokens, and business documents, with no software flaw required.

3 min read
Illustration: a modern laptop screen glowing blue in a dim office
Vulnerabilities

Microsoft patches 'RoguePlanet' Defender flaw after researcher publishes exploit in disclosure spat

The zero-day let attackers hand themselves the keys to a fully patched Windows machine. It was revealed by a researcher publicly feuding with Microsoft.

3 min read
© 2026 Threat Vectr