Check Point Research disclosed a technique that uses Microsoft Defender's boot-time remediation driver, BTR.sys, to perform arbitrary kernel-level file and registry operations on Windows 7 through Windows 11 25H2.
Security researchers Alejandro Hernando and Borja Martínez demonstrated attacks at DEF CON 34 that exploit Windows' automatic hardware identification and driver installation process.
Apple's Private Relay, an opt-in feature designed to hide a user's IP address when browsing the internet with Safari, was found to have flaws that can reveal the supposedly hidden IP address.
In a report by The Hacker News, researchers disclosed a long-standing supply chain attack targeting QuickFox, a VPN and network acceleration tool used by overseas Chinese users.
Fifteen new vulnerabilities were discovered in the zero-touch provisioning (ZTP) systems used by TP-Link’s Omada networking ecosystem, with researchers warning that some flaws can be chained together to compromise entire fleets of managed devices, according to a recent report by Security Week.