This is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them.
BTR Reforged uses Defender's signed BTR.sys with an administrator account and SeLoadDriverPrivilege for kernel file and ...
Threat actors are using three publicly available proof-of-concept exploits to attack Microsoft Defender and turn the security platform's primary cleanup and protection functions against organizations ...