Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
2026-08-21T19:24:00Z•8694d4d504b6b9e9e2af67be23ea3375367528bbc13d02673b489f92359560ee
CVE-2026-19478CVE-2026-32475CVE-2026-73570Android malwareGitLabMicrosoft Entra IDNASA AIT-GUI/AMMOS ToolkitNetScalerOAuth abuseSiemens S7 PLCWordPressZimbraaccount hijackingactive exploitationauthentication bypassbanking trojancode injectioncommand injectioncritical infrastructurecyber espionageindustrial control systemskernel-level operationsmalwareprivilege escalationremote code executionsecurity software tamperingsigned driver abusesupply-chain attack
What happened
The feed reports multiple high-impact cybersecurity developments, including active exploitation of vulnerabilities in GitLab and Zimbra, critical flaws enabling authentication bypass or remote code execution in NetScaler, Microsoft Entra ID, Elementor Pro, NASA AIT-GUI, and isolated-vm, plus malware, supply-chain, espionage, infrastructure, and AI-security threats. Several stories involve unauthenticated or kernel-level compromise and attacks against critical infrastructure, cloud platforms, mobile devices, and developer ecosystems.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 8694d4d504b6b9e9e2af67be23ea3375367528bbc13d02673b489f92359560ee
- Enrichment time
- 2026-08-21T19:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.