Bottom line: Security leaders must ensure their organizations' Windows systems are protected against this technique by disabling the boot-time driver and implementing robust security software updates.
What's happening: Researchers from Check Point Research have discovered a technique that exploits a legitimate Microsoft Defender boot-time driver to perform arbitrary kernel-level file and registry operations, affecting Windows 7 through Windows 11 25H2, and potentially impacting 180 million Windows users worldwide.
What to do: Security leaders should immediately disable the boot-time driver, update their security software to the latest version, and monitor their systems for any signs of malicious activity.