[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:fake-software-installers-disable-windows-update-and-weaken-microsoft-defender-mtm0lhq6":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":14,"article_ids":15,"ioc_summary":17,"source_urls":18,"status":20,"expires_at":21,"created_at":22,"updated_at":23,"articles":24},"2b1acec2-2245-4db9-863d-ab6b2bbfac9e","Fake Software Installers Disable Windows Update and Weaken Microsoft Defender","fake-software-installers-disable-windows-update-and-weaken-microsoft-defender-mtm0lhq6","Malware disguised as legitimate software installers is actively disabling Windows Update and degrading Microsoft Defender protections. The campaign, potentially linked to Silver Fox, primarily targets China-based operations but affects multiple industries. Compromised systems establish persistence and maintain contact with attacker infrastructure.","high","advisory",[],[13],"Microsoft","Hunt for suspicious installer execution, disabled Windows Update services, and Defender configuration changes. Block known malicious domains and hash indicators of compromise. Scan endpoints for persistence mechanisms and verify Defender and Update services are running and functional.",[16],"4e4390bc-5dc4-4f10-94e6-5fdd258d050f",null,[19],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Ffake-software-installers-disable.html","active","2026-09-05T21:05:47.886+00:00","2026-09-03T21:05:56.541555+00:00","2026-09-03T21:08:11.75727+00:00",[25],{"id":16,"title":6,"url":19}]