Back to Feed
Zero-dayApr 21, 2026

Exploits Turn Windows Defender into Attacker Tool

Three PoC exploits actively target Windows Defender; two remain unpatched.

Vendor Watch

Run Microsoft?

Get an email when a reviewed story names Microsoft, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

Three proof-of-concept exploits are being actively leveraged in attacks to abuse Microsoft's Windows Defender security platform, turning it into a weapon for attackers. Two of the three exploits remain unpatched, leaving systems vulnerable to this abuse vector. The attacks demonstrate a novel technique of weaponizing built-in security tools against their intended purpose.

Indicators of Compromise

  • malware — Windows Defender exploitation

Entities

Microsoft (vendor)Windows Defender (product)