threat-intel Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot Check Point Research has discovered a method to weaponize Microsoft Defender's own built-in boot-time remediation driver (BTR.sys) to delete security software and manipulate Windows systems. This technique, dubbed ‘BTR Reforged,’ leverages a driver present on all Windows versions since 7, and doesn’t require exploiting… The Hacker News · Aug 21, 2026 High CVE-2021-24092driverbootremediation