Microsoft Defender

Winsage
August 18, 2026
A new exploit named ShieldBreak, developed by Nightmare-Eclipse, targets Microsoft Defender by allowing privilege escalation and bypassing previous security fixes related to the RoguePlanet vulnerability. ShieldBreak operates on Windows 11 25H2, its Canary channel, and Windows Server 2025, achieving a "100% success rate." Windows 10 may also be vulnerable, but the exploit is specifically designed for Windows 11. There is currently no patch for ShieldBreak, and users are advised to disable Microsoft Defender, implement two-factor authentication, and exercise caution with suspicious online activities. Malwarebytes has recommended its Premium Security antivirus as a temporary solution.
Winsage
August 16, 2026
VLC, the open-source media player, is experiencing delays of up to 33 seconds when playing MP3 files on Windows 11, attributed to a recent update to Microsoft Defender that conflicts with VLC’s plugin cache. Developer Jonathan Blow criticized VLC for this issue, prompting the VLC team to clarify that the problem stems from Microsoft Defender quarantining the plugins.cache file. Users can resolve the issue by reinstalling VLC or regenerating the plugin cache, although this will reset personalized settings. Adding an exception for VLC in Microsoft Defender may prevent future issues. Microsoft has not yet commented on the situation.
Tech Optimizer
August 16, 2026
Over the past decade, free antivirus software has significantly improved, now competing with paid security suites in malware protection. Independent testing from 2026 shows that Avast and AVG have achieved top scores in protection, performance, and usability. Microsoft Defender is a reliable option for Windows users who prefer not to install additional software. The leading free antivirus options in 2026 include Avast Free Antivirus, AVG AntiVirus Free, Microsoft Defender Antivirus, Bitdefender Antivirus Free, Avira Free Security, and Malwarebytes Free. Avast Free Antivirus received perfect scores of 6/6 in protection, performance, and usability from AV-TEST in May and June 2026, totaling 18 out of 18. AVG AntiVirus Free matched these scores and also received an Advanced+ rating from AV-Comparatives. Microsoft Defender scored 6/6 in protection, 5.5/6 in performance, and 6/6 in usability, totaling 17.5 out of 18. Bitdefender Antivirus Free is recognized for its lightweight protection, while Avira Free Security offers additional utilities. Malwarebytes Free is noted for its effectiveness in malware removal. Antivirus software is essential in the current cybersecurity landscape, which includes threats like ransomware and phishing attacks. In 2025, the FTC reported approximately .8 billion in fraud losses, a 25% increase from the previous year. While antivirus software cannot eliminate all forms of online fraud, it plays a crucial role in preventing attacks from escalating to data theft or system compromise. Users should be cautious of counterfeit antivirus software and are advised to download programs from official vendor websites. Free antivirus solutions generally focus on malware detection, while paid options offer additional services. For Windows 11 users, Avast Free Antivirus, AVG AntiVirus Free, and Microsoft Defender are recommended options based on 2026 evaluations.
Winsage
August 16, 2026
Microsoft released its August 2026 Patch Tuesday updates, including the latest Defender package for ISO installations. The updates are aimed at combating malware threats and are issued approximately every three months for Windows installation images (WIM and VHD) and ISOs. The latest Windows 11 update is available through the Media Creation Tool (MCT). The security definitions were delivered through security intelligence update version 1.455.50.0, applicable to various platforms including Windows 11, Windows 10 ESU, Windows Server 2022, and others. The update includes enhancements to the anti-malware client, engine, and signature versions, with platform version 4.18.26070.9, engine version 1.1.26070.7, and security intelligence version 1.455.50.0. The previous security intelligence update was version 1.447.236.0, which introduced detections for various malware types. The most recent intelligence update is version 1.457.181.0.
Tech Optimizer
August 15, 2026
Jonathan Blow criticized the VLC media player for significant performance issues, specifically a 33-second delay in loading MP3 files, and announced his intention to switch to Microsoft Media Player. The VideoLAN team responded, attributing the delays to a known issue with Microsoft’s Windows Defender antivirus software, which quarantines the VLC plugin cache. They suggested users could resolve the issue by reinstalling VLC or regenerating the plugin cache. VLC has been downloaded over 6 billion times across various platforms. Microsoft Defender has been known to cause false positives and interfere with third-party applications. Some users have found success using alternative antivirus solutions like Bitdefender Antivirus Free to avoid conflicts with VLC. Additionally, there are suggestions that using VLC for MP3 playback may not be practical, and switching to Microsoft Media Player is viewed unfavorably compared to alternatives like Foobar2000.
Winsage
August 15, 2026
VLC, an open-source media player, is experiencing delays of up to 33 seconds when playing MP3 files on Windows 11, attributed to a bug in Microsoft Defender from a recent update that affects VLC's plugin cache. The VLC development team suggests that reinstalling VLC or regenerating the plugin cache can resolve the issue.
Winsage
August 14, 2026
Jonathan Blow expressed frustration on social media about delays in opening MP3 files in VLC Media Player, which he claimed could take over 30 seconds. A community note suggested that Microsoft Defender might be contributing to the delay. VideoLAN, the organization behind VLC, responded to the discussion, while Blow maintained that VLC should address the issue, despite acknowledging a faulty AMD graphics driver as a factor. Users on Reddit indicated that adding VLC's folder as an exception in Microsoft Defender resolved the delay. Steps to create this exception include navigating to Windows Security, selecting Virus & threat protection, managing settings, and adding an exclusion for the VLC folder. After creating the exclusion, the time to open an MP3 file decreased from approximately five seconds to under one second.
Winsage
August 14, 2026
CoolClient is a sophisticated backdoor family linked to the HoneyMyte APT group, actively used in cyber-espionage campaigns targeting organizations in Asia and Russia since its initial disclosure in 2022. It has capabilities such as keylogging, clipboard theft, credential harvesting, and system reconnaissance. Investigations in 2023 revealed enhancements, including clipboard theft and HTTP traffic interception. By late 2025 and into 2026, a variant was noted that could deploy a signed kernel-mode driver as a Windows service, improving its stealth and operational capabilities. In a recent campaign targeting Myanmar, the HoneyMyte group used PlugX to deploy CoolClient components. They configured Microsoft Defender to exclude a fake Windows Defender installation directory and a renamed executable, defender.exe, to avoid detection. Persistence was achieved through a scheduled task that executed defender.exe with SYSTEM privileges at startup, which sideloaded the malicious libngs.dll to initiate the CoolClient execution chain. The latest CoolClient variant has a multi-stage execution chain, including: - defender.exe / Sang.exe: Exploited legitimate application for DLL sideloading. - libsrapc.dll: Benign dependency for the Sangfor application. - libngs.dll: First-stage loader that decrypts and loads the next stage. - loadcert.ini: Second-stage DLL implementing core functionalities. - cert.ini: Final-stage implant for command and control communication. - time.ini: Configuration file for CoolClient. The execution begins with the legitimate Sangfor application loading libngs.dll, which uses obfuscation to conceal its operations. The second stage, loadcert.ini, is injected into synchost.exe and performs tasks including persistence and process injection. The kernel-mode driver deployment routine involves decrypting time.ini, verifying privileges, and creating a service to execute the driver, enhancing stealth. The deployed kernel-mode driver, msagent.sys, is digitally signed and helps hide processes, files, and registry objects, making detection more difficult. The latest variant continues to target organizations consistent with previous HoneyMyte activities, with confirmed victims in Myanmar, Mongolia, Pakistan, and Russia, including government entities. The deployment of CoolClient as a secondary backdoor after a PlugX infection indicates a strategic approach to maintain access to compromised systems. The malware is confirmed as a new variant of CoolClient associated with the HoneyMyte threat group, with the kernel-mode driver marking a significant advancement in its capabilities.
Winsage
August 13, 2026
Security researcher Nightmare Eclipse has released a zero-day exploit named ShieldBreak that allows privilege escalation on Windows by targeting a vulnerability in Microsoft Defender. This exploit, designated as CVE-2026-50656, is categorized as a race condition vulnerability and affects the latest versions of Windows 11 and Windows Server 2025, with potential impacts on Windows 10. The exploit was disclosed on June 9, 2026, and Microsoft acknowledged the issue on June 16, rolling out fixes by July 9. The mechanics of ShieldBreak involve manipulating Defender’s scan path and executing a scheduled task to gain System-level privileges. Experts have noted differences between ShieldBreak and the previously known RoguePlanet exploit, emphasizing that ShieldBreak requires Defender to be active to function.
Search