threat-intel Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot Check Point Research has discovered a method to weaponize Microsoft Defender's own built-in boot-time remediation driver (BTR.sys) to delete security software and manipulate Windows systems. This technique, dubbed ‘BTR Reforged,’ leverages a driver present on all Windows versions since 7, and doesn’t require exploiting… The Hacker News · Aug 21, 2026 High CVE-2021-24092driverbootremediation
supply-chain Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 Researchers have discovered a method to leverage Windows Plug and Play to achieve SYSTEM-level access on Windows 11 machines. By emulating USB devices and exploiting a vulnerability in the driver installation process, an… The Hacker News · Aug 11, 2026 High usbremotedriver
threat-intel 'GodDamn' Ransomware Uses BYOVD to Smite US Companies The ransomware group Hyadina, operating under the name "GodDamn," is leveraging a Microsoft-approved, malicious kernel driver – dubbed "PoisonX" – to infiltrate US organizations and deploy its ransomware. They utilize a… Dark Reading · Jul 9, 2026 High RUransomwaredriverbyovd
threat-intel Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective This article details a technique for evaluating the exploitability of Windows kernel mode drivers, focusing on the potential for BYOVD (Bring Your Own Vulnerability Driver) attacks. It highlights how vulnerabilities in d… The Hacker News · May 22, 2026 Medium USdriverbyovdkernel mode
vulnerability A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here? Project Zero researchers discovered a 0-click exploit chain targeting the Pixel 9 and other Android devices, leveraging a vulnerability in the Dolby UDC audio codec. The exploit chain, requiring only two software defects… Google Project Zero · Jan 14, 2026 High CVE-2025-54957CVE-2025-369340-clickaudiodriver