Skip to content

other

Microsoft Defender

Microsoft's built-in security suite for Windows and enterprise networks, covering antivirus, endpoint detection and response, and threat hunting.

Known aliases

  • Defender
  • Defender Advanced Hunting
  • Microsoft Defender Antivirus
  • Microsoft Defender for Endpoint
  • Microsoft Defender portal
  • Microsoft Defender XDR
  • Microsoft Malware Protection Engine
  • Windows Defender

Relationships

No evidence-backed relationships are recorded.

Current stories

security8 publishers

Attackers stage a RAT lure on the real chatgpt.com using a Custom GPT

Huntress traced a RAT campaign that hides its first-stage lure in a ChatGPT Custom GPT on the real chatgpt.com, across at least 40 incidents. Because the page sits on a trusted domain, blocking the ClickFix PowerShell paste is the control that works.

Perspective Coverage

8 publishers
Builder
Builder 30%
Operator
Operator 64%
Investor
Investor 6%

Reality

Evidence70
Adoption20
Hype gap+30
Incentives40
Confidence68
security1 publisher

Graz researchers read other users' browsing and keystroke timing through OS file-change alerts

Graz University of Technology researchers used file-change alerts to catch 95.7% of another Windows user's Firefox site visits from an unprivileged account. On shared hosts and on servers that run services under their own accounts, separation between users is weaker than the account model suggests.

Reality

Evidence62
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence60
security3 publishers

WMIC is gone from Windows 11 24H2 and 25H2, and your wmic.exe rules go with it

Microsoft has removed the legacy WMIC binary rather than deprecating it again. WMI itself stays, so admin scripts and detection content keyed to wmic.exe both need rework this cycle.

Publishers:bleepingcomputer.comscworld.comwindowslatest.com

Perspective Coverage

3 publishers
Builder
Builder 28%
Operator
Operator 67%
Investor
Investor 5%

Reality

Evidence72
Adoption65
Hype gap+15
Incentives
Insufficient
Confidence74
security5 publishers

FalconFlank PoC turns CrowdStrike's macro cleanup into a local privilege escalation

Chaotic Eclipse published working code that abuses Falcon's Office macro removal on fully patched Windows 11 25H2 and Server 2025. It is the fourth endpoint product the researcher has dropped exploit code for, and no CrowdStrike response is on record.

Perspective Coverage

5 publishers
Builder
Builder 36%
Operator
Operator 51%
Investor
Investor 13%

Reality

Evidence70
Adoption
Insufficient
Hype gap+10
Incentives55
Confidence68
security9 publishers

Group-IB ties the Handala Hack persona to a Telegram-run backdoor that steals saved passwords

Group-IB says the Iran-linked leak-and-brag front Handala Hack runs HEAVYGRAM, a Python implant that takes orders from a Telegram bot, opens the microphone and lifts saved passwords after a loader writes Defender exclusions for it.

Perspective Coverage

9 publishers
Builder
Builder 44%
Operator
Operator 52%
Investor
Investor 4%

Reality

Evidence82
Adoption64
Hype gap+5
Incentives45
Confidence80
security4 publishers

Naceri's BigDiskBuster stops Defender updating for as long as it runs

Abdelhamid Naceri published the tool over the weekend as the latest move in his dispute with Microsoft over his March 2025 termination, and said it needs only a standard user account on any supported Windows version.

Perspective Coverage

4 publishers
Builder
Builder 23%
Operator
Operator 56%
Investor
Investor 21%

Reality

Evidence55
Adoption
Insufficient
Hype gap+20
Incentives70
Confidence60

Earlier coverage

  1. Defender missed 221 high-severity emails per 1,000 users in Microsoft's own benchmark

    Security · September 17, 2026 · 1 publisher

  2. CHOSEN BRICK routes its commands through a Telegram bot issued per victim device

    Build · September 17, 2026 · 1 publisher

  3. A third bypass of the same Defender flaw landed hours after Microsoft's second fix shipped

    Build · September 15, 2026 · 2 publishers

  4. Click-time code generation strips the 15-minute limit out of device code phishing

    Leadership · September 13, 2026 · 1 publisher

  5. REVSTEALER-linked module LockAppHost disables 18 Windows update and malware-removal mechanisms before mining

    Security · September 7, 2026 · 1 publisher

  6. A plugin update adds shell hooks the harness runs before the model sees the tool call

    Build · September 10, 2026 · 1 publisher

  7. A fake ChatGPT Plus billing alert pushed up to 100,000 emails in a single day

    Security · September 10, 2026 · 1 publisher

  8. ReSharper lost Defender's path-based trust the moment it became its own process

    Build · September 9, 2026 · 1 publisher

  9. JetBrains routes WSL projects through an in-WSL agent starting with 2026.2

    Build · September 9, 2026 · 1 publisher

  10. An infected ScreenConnect guest pushes scripts up the support session to the operator's host

    Build · September 8, 2026 · 1 publisher

  11. Synology's APM 2.0 restores cloud backup copies straight into EC2 and Azure VM

    Security · September 4, 2026 · 1 publisher

  12. August's 398-CVE Patch Tuesday moves the bottleneck to the test bench

    Security · September 4, 2026 · 1 publisher

  13. RevStealer spread via fake free Claude Opus 5 desktop build on GitHub

    Security · September 1, 2026 · 2 publishers

  14. Project Griffin puts a token bill at the center of the Army's autonomous cyber defense

    Product · August 25, 2026 · 1 publisher

  15. PyInstaller exits zero, then the real work starts: notarization traps that report success

    Build · August 21, 2026 · 1 publisher

  16. Defender's own signed driver becomes the bypass: BTR.sys and the week's trusted-component defects

    Security · August 20, 2026 · 1 publisher

  17. Microsoft puts AI agents in Entra, which makes agent sprawl an identity team problem

    Leadership · August 20, 2026 · 1 publisher

  18. Portnox adds Defender to its kill switch, conceding agent credentials outlive the login

    Product · August 18, 2026 · 1 publisher

  19. ShieldBreak: a Defender-to-SYSTEM PoC that your last patch cycle did not stop

    Build · August 17, 2026 · 1 publisher

  20. Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held

    Security · August 15, 2026 · 6 publishers

  21. Two years, 117 identified children: the only Com case this week with an outcome attached

    Security · August 15, 2026 · 1 publisher