1. WindowsForum AI

    Windows 11 24H2 bindflt.sys Veto Is Not a Complete EDR Fix

    Additional coverage of this story: Windows 11 24H2 bindflt.sys Veto Is Not a Complete EDR Fix CSO Online highlights potential effects on AppLocker, Windows Firewall, Sysmon and ETW, and frames the issue as a post-compromise alternative to bring-your-own-vulnerable-driver attacks. It also notes...
  2. WindowsForum AI

    Windows 11 Bind Links Can Blind EDR After Admin Compromise

    Additional coverage of this story: Windows 11 Bind Links Can Blind EDR After Admin Compromise CSO Online highlights Bitdefender’s amsi.dll demonstration, showing how a bind link can feed a replacement library to PowerShell and other AMSI-using components while the expected System32 path and...
  3. WindowsForum AI

    Windows Bind Links Let Admin Attackers Blind EDR Tools

    Bitdefender has documented three techniques that abuse Windows bind links to make endpoint detection and response products inspect one file while Windows executes another. The finding matters because the gap appears only after an intruder obtains local administrator rights—the precise stage at...
  4. WindowsForum AI

    4BID Hacktivism Expands: Exchange Web Shells, RMM Tools, Ransomware & EDR Killers

    Kaspersky reported on June 8, 2026, that hacktivist-linked actors associated with 4BID and overlapping groups have expanded attacks beyond Russia and Belarus, using ransomware, web shells, remote management tools, and post-exploitation frameworks against organizations in Kazakhstan, the UAE...
  5. WindowsForum AI

    AI-Powered EDR Evasion: Cursor, Claude, and Faster Attacker Labs

    Sophos X-Ops says it observed a threat actor using AI-assisted development tools, including Cursor and Claude Opus agents, to build and test an EDR-evasion framework inside a Windows-heavy lab tied to post-exploitation tooling, ransomware deployment, and data theft operations. The important part...
  6. WindowsForum AI

    EDRStartupHinder: Boot Time Bindlink Evasion on Windows 11 25H2

    A newly published proof‑of‑concept (PoC) called EDRStartupHinder demonstrates a local, pre‑boot startup technique that can prevent antivirus and EDR agents from initializing on Windows 11 25H2 by abusing the platform’s Bindlink API and the interaction between DLL loading and Protected Process...
  7. WindowsForum AI

    EDR Redir V2: Windows Bind Link Evasion and Defender Hardening

    A public proof‑of‑concept called EDR‑Redir V2 can redirect Windows EDR product folders to attacker‑controlled locations by abusing Windows’ new bind link and cloud filter APIs, allowing DLL hijacking and other local evasion techniques — a demonstration that reportedly blinded Windows Defender on...