# Microsoft patches perfect-ten Entra ID flaw, Defender driver deletes Defender at boot, Malware turns cars into proxy botnet Page: https://stenobird.com/podcast/cybersecurity-today-65508/microsoft-patches-perfect-ten-entra-id-flaw-defender-driver-deletes-defender-at-boot-malware-turns-cars-into-proxy-botnet Text version: https://stenobird.com/podcast/cybersecurity-today-65508/microsoft-patches-perfect-ten-entra-id-flaw-defender-driver-deletes-defender-at-boot-malware-turns-cars-into-proxy-botnet.md Podcast: [Cybersecurity Today](https://stenobird.com/podcast/cybersecurity-today-65508) Published: 2026-08-24T01:00:00+00:00 Episode link: https://cybersecuritytoday.libsyn.com/microsoft-patches-perfect-ten-entra-id-flaw-defender-driver-deletes-defender-at-boot-malware-turns-cars-into-proxy-botnet Audio file: https://traffic.libsyn.com/secure/cybersecuritytoday/Microsoft_patches_perfect-ten_Entra_ID_flaw_Defender_driver_deletes_Defender_at_boot_Malware_turns_cars_into_proxy_botnet.mp3?dest-id=679928 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/microsoft-patches-perfect-ten-entra-id-flaw-defender-driver-deletes-defender-at-boot-malware-turns-cars-into-proxy-botnet Duration seconds: 530 ## Resource Entra ID Perfect 10 Patch, Defender Driver Weaponized, SickKids Breach, Live Leaked AWS Keys, and Car Head Unit Malware Microsoft patched a maximum-severity Entra ID deserialization RCE (CVE-2026-69836) after briefly indicating it was exploited in the wild before correcting that claim; the fix is already deployed server-side with no customer action required. Check Point Research detailed how Microsoft Defender's signed BTR.sys remediation driver can be weaponized to remove Defender components during a reboot "golden window," though it requires administrator privileges and no real-world abuse has been seen. Toronto's SickKids reported a cyber incident tied to a third-party application exposing employee-related personal data but not patient systems, offering two years of credit monitoring. Truffle Security found hundreds of thousands of leaked AWS secrets, with 88% of re-verified keys still active, including many root and full-admin keys. Kaspersky described a supply-chain malware chain targeting Android-based car head units, mainly for proxying and ad fraud, reportedly now resolved by DoFun. 00:00 Top Stories Rundown 00:30 Entra ID Perfect 10 Patch 01:55 Defender Driver Weaponized 03:31 SickKids Hit Again 05:10 Leaked AWS Keys Still Live 06:48 Car Head Unit Botnet 08:25 Wrap Up And Sign Off ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/microsoft-patches-perfect-ten-entra-id-flaw-defender-driver-deletes-defender-at-boot-malware-turns-cars-into-proxy-botnet/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cybersecurity-today-65508/microsoft-patches-perfect-ten-entra-id-flaw-defender-driver-deletes-defender-at-boot-malware-turns-cars-into-proxy-botnet.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.