Vulnerability Management10 September 2026
Microsoft's Record 973-CVE Patch Tuesday: Two SYSTEM-Level Zero-Days Under Attack
September 2026 is Microsoft's largest Patch Tuesday on record, and two of the fixes — both elevation-of-privilege bugs — are already being exploited to seize SYSTEM control on Windows machines.
patch-tuesdaywindows-securityzero-day
4 min readRead
Endpoint Security22 August 2026
Defender's Own Boot Driver Can Be Turned Into an EDR-Killing Primitive
Check Point Research reverse-engineered BTR.sys, the signed Windows Defender remediation driver, and showed how it can delete or overwrite security software before other endpoint agents even start.
windows-securityedr-bypassliving-off-the-land
4 min readRead
Windows Internals / Offensive Security5 July 2026
GetProcessHandleFromHwnd: How One Windows API Enabled a Persistent UAC Bypass
Google Project Zero traces a public Quick Assist UAC bypass back to a poorly documented Win32 API that Microsoft only half-fixed in 2023 — and shows why fully protected processes stayed exploitable until Windows 11 24H2.
windows-securityuac-bypassprivilege-escalation
5 min readRead