Episode

Microsoft patches perfect-ten Entra ID flaw, Defender driver deletes Defender at boot, Malware turns cars into proxy botnet

Podcast
Cybersecurity Today
Published
Aug 24, 2026
Duration seconds
530
Processing state
not_requested
Canonical source
https://cybersecuritytoday.libsyn.com/microsoft-patches-perfect-ten-entra-id-flaw-defender-driver-deletes-defender-at-boot-malware-turns-cars-into-proxy-botnet
Audio
https://traffic.libsyn.com/secure/cybersecuritytoday/Microsoft_patches_perfect-ten_Entra_ID_flaw_Defender_driver_deletes_Defender_at_boot_Malware_turns_cars_into_proxy_botnet.mp3?dest-id=679928
JSON
/v1/public/podcasts/cybersecurity-today-65508/episodes/microsoft-patches-perfect-ten-entra-id-flaw-defender-driver-deletes-defender-at-boot-malware-turns-cars-into-proxy-botnet
Markdown
/podcast/cybersecurity-today-65508/microsoft-patches-perfect-ten-entra-id-flaw-defender-driver-deletes-defender-at-boot-malware-turns-cars-into-proxy-botnet.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/microsoft-patches-perfect-ten-entra-id-flaw-defender-driver-deletes-defender-at-boot-malware-turns-cars-into-proxy-botnet/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/cybersecurity-today-65508/microsoft-patches-perfect-ten-entra-id-flaw-defender-driver-deletes-defender-at-boot-malware-turns-cars-into-proxy-botnet.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Entra ID Perfect 10 Patch, Defender Driver Weaponized, SickKids Breach, Live Leaked AWS Keys, and Car Head Unit Malware Microsoft patched a maximum-severity Entra ID deserialization RCE (CVE-2026-69836) after briefly indicating it was exploited in the wild before correcting that claim; the fix is already deployed server-side with no customer action required. Check Point Research detailed how Microsoft Defender's signed BTR.sys remediation driver can be weaponized to remove Defender components during a reboot "golden window," though it requires administrator privileges and no real-world abuse has been seen. Toronto's SickKids reported a cyber incident tied to a third-party application exposing employee-related personal data but not patient systems, offering two years of credit monitoring. Truffle Security found hundreds of thousands of leaked AWS secrets, with 88% of re-verified keys still active, including many root and full-admin keys. Kaspersky described a supply-chain malware chain targeting Android-based car head units, mainly for proxying and ad fraud, reportedly now resolved by DoFun. 00:00 Top Stories Rundown 00:30 Entra ID Perfect 10 Patch 01:55 Defender Driver Weaponized 03:31 SickKids Hit Again 05:10 Leaked AWS Keys Still Live 06:48 Car Head Unit Botnet 08:25 Wrap Up And Sign Off