ShieldCrash, a public proof of concept, reaches SYSTEM-level file reads on fully patched Windows hosts, defeating Microsoft's fix for CVE-2026-69414. Only arbitrary read has been shown, not code execution, and there is no confirmed exploitation in the wild.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap0
- Incentives40
- Confidence40
Huntress traced a RAT campaign that hides its first-stage lure in a ChatGPT Custom GPT on the real chatgpt.com, across at least 40 incidents. Because the page sits on a trusted domain, blocking the ClickFix PowerShell paste is the control that works.
Perspective Coverage
8 publishers
- Builder
- Builder 30%
- Operator
- Operator 64%
- Investor
- Investor 6%
Reality
- Evidence70
- Adoption20
- Hype gap+30
- Incentives40
- Confidence68
Roblox Account Manager's developer traced a Defender trojan verdict, from 1 of 75 VirusTotal engines, to the commit that added libsodium. Build-and-scan bisection found the dependency, though the developer can only hypothesise why the model objects to it.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence50
Microsoft says China-aligned NeedyMantis malware, active since at least October 2025, is installed after attackers already have access, to keep it long term. Because entry routes vary, organisations in the five sectors it targets need to look for copies already installed.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives40
- Confidence60
Graz University of Technology researchers used file-change alerts to catch 95.7% of another Windows user's Firefox site visits from an unprivileged account. On shared hosts and on servers that run services under their own accounts, separation between users is weaker than the account model suggests.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
NCSC, FBI and AIVD say two Iranian spyware families report to per-victim Telegram bots and exfiltrate through Vultr, Storj and Backblaze B2. Networks already allow those services, so detection has to rely on host behaviour such as new Defender exclusions.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
Securelist says the newest CoolClient deploys a signed kernel-mode driver as a Windows service to hide its process, files and registry keys. It was seen in Pakistan, Mongolia and Myanmar.
Reality
- Evidence62
- Adoption30
- Hype gap+10
- Incentives35
- Confidence60
An affiliate entered through an MFA-less SonicWall VPN, then used Safe Mode with Networking to kill endpoint controls. The encryptor ran out of virtual memory instead of running.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 65%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption15
- Hype gap+5
- Incentives40
- Confidence70
Microsoft has removed the legacy WMIC binary rather than deprecating it again. WMI itself stays, so admin scripts and detection content keyed to wmic.exe both need rework this cycle.
Publishers:bleepingcomputer.com · scworld.com · windowslatest.com Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 67%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption65
- Hype gap+15
- Incentives
- Insufficient
- Confidence74
Check Point's BTR Reforged turns a required Defender component into Ring 0 file and registry deletion on Windows 7 through 11 25H2. It cannot be blocklisted, so detection is the only lever left.
Reality
- Evidence60
- Adoption8
- Hype gap+10
- Incentives
- Insufficient
- Confidence62
Acronis says the operator borrowed a security vendor's own uninstall driver to shut down Defender on Cambodian machines, and the loader keeps three further ways to blind an agent if the kernel route fails.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
Chaotic Eclipse published working code that abuses Falcon's Office macro removal on fully patched Windows 11 25H2 and Server 2025. It is the fourth endpoint product the researcher has dropped exploit code for, and no CrowdStrike response is on record.
Perspective Coverage
5 publishers
- Builder
- Builder 36%
- Operator
- Operator 51%
- Investor
- Investor 13%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence68
Group-IB says the Iran-linked leak-and-brag front Handala Hack runs HEAVYGRAM, a Python implant that takes orders from a Telegram bot, opens the microphone and lifts saved passwords after a loader writes Defender exclusions for it.
Perspective Coverage
9 publishers
- Builder
- Builder 44%
- Operator
- Operator 52%
- Investor
- Investor 4%
Reality
- Evidence82
- Adoption64
- Hype gap+5
- Incentives45
- Confidence80
Abdelhamid Naceri published the tool over the weekend as the latest move in his dispute with Microsoft over his March 2025 termination, and said it needs only a standard user account on any supported Windows version.
Perspective Coverage
4 publishers
- Builder
- Builder 23%
- Operator
- Operator 56%
- Investor
- Investor 21%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives70
- Confidence60
Microsoft's Purview and Entra Global Secure Access can now block sensitive uploads to unsanctioned AI tools at the network layer, for users and agents. Licensing is not in the announcement, so tenants cannot yet tell whether it is a setting or a purchase.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives85
- Confidence40
Huntress traced a September 2026 intrusion in which the actor compiled a Monero miner on the endpoint, using a MagicINFO flaw Samsung fixed 16 months earlier. The build step is loud in telemetry, but it ran only after Defender had been disabled.
Reality
- Evidence66
- Adoption28
- Hype gap+10
- Incentives62
- Confidence58
The Integrated Security Operations Center preview puts case management and workbooks in the Defender portal with no setup, while behavior analytics and third-party feeds wait on a new Azure-linked workspace. Microsoft has not disclosed pricing.
Reality
- Evidence38
- Adoption9
- Hype gap+34
- Incentives72
- Confidence44
Microsoft is building one foundation inside Defender for security operations and native protection, and the reason it gives is that a single operator with an agent framework now does what once took whole teams.
Reality
- Evidence38
- Adoption15
- Hype gap+45
- Incentives92
- Confidence60
Microsoft's public preview flags jailbreaks, prompt injection and credential leakage from agent telemetry, and agents built outside Copilot Studio, Foundry and Agent Builder need the Agent 365 SDK first.
Publishers:learn.microsoft.com
Reality
- Evidence52
- Adoption12
- Hype gap+15
- Incentives78
- Confidence58
Microsoft says the phishing-as-a-service platform reached more than 12,000 inboxes at over 10,000 organizations in seven months by abusing a legitimate OAuth flow, and its Digital Crimes Unit has now disrupted the infrastructure behind the service.
Reality
- Evidence58
- Adoption62
- Hype gap+20
- Incentives76
- Confidence57
Earlier coverage
- Defender missed 221 high-severity emails per 1,000 users in Microsoft's own benchmark
Security · September 17, 2026 · 1 publisher
- CHOSEN BRICK routes its commands through a Telegram bot issued per victim device
Build · September 17, 2026 · 1 publisher
- A third bypass of the same Defender flaw landed hours after Microsoft's second fix shipped
Build · September 15, 2026 · 2 publishers
- Click-time code generation strips the 15-minute limit out of device code phishing
Leadership · September 13, 2026 · 1 publisher
- REVSTEALER-linked module LockAppHost disables 18 Windows update and malware-removal mechanisms before mining
Security · September 7, 2026 · 1 publisher
- A plugin update adds shell hooks the harness runs before the model sees the tool call
Build · September 10, 2026 · 1 publisher
- A fake ChatGPT Plus billing alert pushed up to 100,000 emails in a single day
Security · September 10, 2026 · 1 publisher
- ReSharper lost Defender's path-based trust the moment it became its own process
Build · September 9, 2026 · 1 publisher
- JetBrains routes WSL projects through an in-WSL agent starting with 2026.2
Build · September 9, 2026 · 1 publisher
- An infected ScreenConnect guest pushes scripts up the support session to the operator's host
Build · September 8, 2026 · 1 publisher
- Synology's APM 2.0 restores cloud backup copies straight into EC2 and Azure VM
Security · September 4, 2026 · 1 publisher
- August's 398-CVE Patch Tuesday moves the bottleneck to the test bench
Security · September 4, 2026 · 1 publisher
- RevStealer spread via fake free Claude Opus 5 desktop build on GitHub
Security · September 1, 2026 · 2 publishers
- Project Griffin puts a token bill at the center of the Army's autonomous cyber defense
Product · August 25, 2026 · 1 publisher
- PyInstaller exits zero, then the real work starts: notarization traps that report success
Build · August 21, 2026 · 1 publisher
- Defender's own signed driver becomes the bypass: BTR.sys and the week's trusted-component defects
Security · August 20, 2026 · 1 publisher
- Microsoft puts AI agents in Entra, which makes agent sprawl an identity team problem
Leadership · August 20, 2026 · 1 publisher
- Portnox adds Defender to its kill switch, conceding agent credentials outlive the login
Product · August 18, 2026 · 1 publisher
- ShieldBreak: a Defender-to-SYSTEM PoC that your last patch cycle did not stop
Build · August 17, 2026 · 1 publisher
- Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held
Security · August 15, 2026 · 6 publishers
- Two years, 117 identified children: the only Com case this week with an outcome attached
Security · August 15, 2026 · 1 publisher