Microsoft patches Defender zero-days exploited in live attacks
… Endpoint security firm Huntress confirmed active exploitation before the patches existed. …
… Endpoint security firm Huntress confirmed active exploitation before the patches existed. …
… GTIG described this as an increasing capability that traditional security tooling is structurally ill-equipped to counter. …
… Microsoft's Autonomous Code Security team built it, with several members coming from Team Atlanta, the group that won the $29.5 million DARPA AI Cyber Challenge. …
… The community pushback The security industry is not siding with Microsoft. …
… All six targeted components are located at or below the endpoint security layer. …
… Security researcher Will Dormann of Tharros independently verified the results. …
… No full security update is available yet. …
… Exchange Server 2016 and 2019 will only get the permanent patch through Microsoft's Period 2 Extended Security Update program. …
… As with most security flaws, the concern isn’t just who found it first, it’s who else might have found it later. …
… Boot-level exploits like BlackLotus have specifically targeted this layer. A device with expired certificates has no patch path against future threats at the firmware level. How to check your device Open Windows Security, select Device Security, and check the Secure Boot section. …