Tag: antivirus
-
New Windows Defender zero-day blocks Microsoft antivirus updates
Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/
-
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.Microsoft’s own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when…
-
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
Tags: antivirus, credentials, crypto, cyber, data, detection, endpoint, exploit, intelligence, microsoft, mitigation, threat, tool, windowsA newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV) and endpoint detection and response (EDR) processes. This allows attackers to steal browser credentials, cryptocurrency wallet data, chat tokens, and Windows credentials. Researchers from the LastPass Threat Intelligence, Mitigation, and Escalation team, in collaboration…
-
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
Tags: antivirus, credentials, crypto, cyber, data, detection, endpoint, exploit, intelligence, microsoft, mitigation, threat, tool, windowsA newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV) and endpoint detection and response (EDR) processes. This allows attackers to steal browser credentials, cryptocurrency wallet data, chat tokens, and Windows credentials. Researchers from the LastPass Threat Intelligence, Mitigation, and Escalation team, in collaboration…
-
Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-fixes-bug-behind-defender-antivirus-is-turned-off-alerts/
-
Scammers leave AI fingerprints all over fake antivirus renewal page
AI appears to be helping scammers with little web development skill build convincing fake antivirus-renewal pages, Malwarebytes found. The researchers came across a scam page … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/ai-antivirus-renewal-scam-fake-pages/
-
Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
Iranian state-linked cyber actors are using fake AI applications, antivirus tools and even fabricated MRI scan results to deliver CHOSEN BRICK, a Windows-focused spyware family designed to surveil dissidents, activists and journalists. A joint advisory from the UK National Cyber Security Centre (NCSC), the FBI and the Netherlands’ AIVD warns that the campaign has targeted…
-
The 12 Best Antivirus (Endpoint Protection) Software for Business, Compared and Priced
Best value overall: Microsoft Defender for Endpoint, if you hold Microsoft 365 E5, you already own competitive enterprise endpoint protection and the marginal cost is zero. Best published pricing: Bitdefender and ESET, both of which let you budget without a sales call. Best detection: CrowdStrike. Best cleanup tool: Malwarebytes. One vendor on the standard […]…
-
Avast Antivirus Zero-Day PoC Lets Attackers Dump SAM Database and Gain SYSTEM Shell
A public proof-of-concept (PoC) repository has revealed a local privilege escalation zero-day vulnerability in GenDigital’s Avast Antivirus. This vulnerability allows an attacker to dump the Windows Security Account Manager (SAM) database and launch a shell running as NT AUTHORITY\SYSTEM. The researcher behind the repository, known as MSNightmare, claims that the issue affects fully patched installations…
-
Credential Security: What Endpoint Protection Really Means for Secrets
TL;DREndpoint protection means AV or EDR: The term “endpoint protection” almost always refers to antivirus or EDR. Antivirus started as signature-based malware detection; EDR added continuous behavioral monitoring and response. Both are designed to detect and stop malicious activity on… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/credential-security-what-endpoint-protection-really-means-for-secrets/
-
Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague
Chaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting GenDigital Avast Antivirus. The researcher named the exploit PrettyPrague, it triggers a privilege escalation flaw. The researcher claims to have found…
-
HardBreacher Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation
A proof of concept called HardBreacher allegedly exploits an unpatched local privilege escalation flaw in Kaspersky Antivirus for Endpoint. This vulnerability allows a local user to control a privileged component. The code was published by a GitHub user named MSNightmare and is being presented as a zero-day vulnerability. However, the vendor has not confirmed it.…
-
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions.Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese…
-
Microsoft Defender Bug Triggers False “Antivirus Turned Off” Alerts on Windows
Microsoft has confirmed an issue with Microsoft Defender Antivirus that generates false notifications on Windows systems, claiming >>Microsoft Defender Antivirus is turned off,<< even though the protection is still operational. These alerts may appear after installing the latest Defender updates, potentially causing unnecessary concern for administrators who observe that Defender settings are healthy and security…
-
Microsoft asks users to ignore ‘Antivirus is turned off’ errors
Microsoft asked customers this week to ignore incorrect alerts that Defender Antivirus has been turned off after installing the latest Defender updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-asks-users-to-ignore-antivirus-is-turned-off-errors/
-
Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud
A cluster of fraudulent websites impersonating Microsoft is using fake “security scans” to pressure victims into uninstalling antivirus products, disclosing personal and banking information, and granting remote access to their computers. The sites, branded as SysScan, claim to assess whether an antivirus product is functioning properly. Their conclusion is predetermined: the victim’s computer is allegedly…
-
HOL Guard: Open-source antivirus for AI agents
HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/25/hol-guard-open-source-antivirus-ai-agents/
-
Fake Microsoft security scans trick victims into uninstalling their antivirus
We found fake Microsoft-branded scanners that invent security problems, tell victims to uninstall AV, and then steer them into a refund scam. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus/
-
Understanding detection coverage and blind spots for UK SMEs
For many UK SMEs, the real question is not whether you have security tools in place, but whether those tools would actually spot a problem in time. A business can spend money on antivirus, logging, and monitoring, yet still miss the events that matter most. That gap is what we mean by detection coverage and……
-
Windows Defender Driver Abuse Enables Kernel-Level EDR and Antivirus Bypass
Security researcher Jiřà Vinopal has published a detailed analysis of BTR.sys, the Microsoft Defender Boot-Time Removal driver. His research reveals how this legitimate, Microsoft-signed component can be exploited to perform file and registry operations under attacker control from kernel mode. This study, titled >>BTR Reforged,<< does not rely on traditional memory-corruption vulnerabilities or the Bring…
-
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-source antivirus engine widely used to scan files and emails for malware. The company…
-
CiscoClamAV Vulnerabilities Let Remote Attackers Crash Antivirus Scanning With Crafted Files
Cisco has disclosed seven high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning by submitting specially crafted files. These vulnerabilities are tracked as CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348, and have been assigned a maximum CVSS score of 7.5. ClamAV Vulnerabilities The issues are detailed in the Cisco…
-
North Korea Rebuilt Its Antivirus Using ClamAV and Gave It Four Different Names
North Korea’s national antivirus appears to have quietly pivoted to ClamAV’s open”‘source engine, recompiled it, and shipped it under four different domestic product names underscoring Pyongyang’s reliance on foreign code to secure tightly controlled networks while obscuring the software’s true origin. ClamAV is a widely used open”‘source antivirus engine maintained by the Cisco Talos team,…
-
New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance teams back to a crypter service called Cruciferra, and the tool turns out to be shared infrastructure used across multiple unrelated criminal…
-
Online Protection Is Simple and Effective with Panda Dome for $29.99
Get antivirus, firewall, and VPN service with a one-year subscription to Panda Dome for just $29.99. The post Online Protection Is Simple and Effective with Panda Dome for $29.99 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/panda-dome-antivirus-security-complete/
-
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public.The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine (“mpengine.dll”), which provides scanning, detection, and cleaning capabilities for its antivirus and First seen on…
-
A single malware file can outweigh an entire AI dataset
Antivirus vendors and security startups keep shipping AI features that promise to read malware the way a seasoned analyst would. The results inside security teams tell a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/research-ai-in-cybersecurity/
-
This Popular Antivirus is on Sale for $19.99
ESET NOD32 Antivirus blocks malware, ransomware, and phishing for $19.99 a year without slowing your PC down. The post This Popular Antivirus is on Sale for $19.99 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/eset-nod32-antivirus-for-windows/
-
1 Year of This Popular Antivirus is on Sale for $20
Tags: antivirusBitdefender Antivirus Plus protects one PC for a full year with no monthly fees, and it even comes with a VPN. The post 1 Year of This Popular Antivirus is on Sale for $20 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/bitdefender-antivirus-plus/

