GPS Roundups

Windows bug falsely shows Defender as disabled

By Wulan Hapsari September 1, 2026
Windows bug falsely shows Defender as disabled - windows defender bug
Windows bug falsely shows Defender as disabled

A Windows bug is incorrectly telling users that Microsoft Defender Antivirus is turned off, even when it’s fully functional, according to a report from Microsoft. The company says it’s working to fix the issue.

The bug causes notifications to appear stating that Microsoft Defender Antivirus is turned off, even though the antivirus is functioning correctly and all settings show it as active.

Concerns over user behavior

Consultants say this advisory raises a major concern, as it will train users to ignore critical alerts, making them more susceptible to attacks. Aman Mahapatra, chief strategy officer for technology consulting firm Tribeca Softtech, points out that disabling endpoint protection is standard tradecraft across virtually every ransomware affiliate playbook over the last five years.

Mahapatra expects many security operations centers (SOCs) will create rules to suppress these alerts, which will make the problem even more severe. “When a signal fires constantly and is known to be false, human response degrades in days, not weeks,” he said.

Related: Judge backs Anthropic voids Pentagon supply risk

Potential for social engineering attacks

Mahapatra also predicted that attackers will quickly leverage the bug to help in social engineering attacks. “An attacker calling a help desk with ‘You’ll see Defender alerts on my machine, Microsoft says it’s the known bug, ignore it’ now has a corroborating vendor advisory backing the pretext,” he said.

Lane Thames, team lead for cybersecurity R&D at Fortra, amplified Mahapatra’s concerns. “IT teams need to be very careful about how they communicate this problem to users, and that communication should happen immediately,” he advised.

The better message, according to Thames, is that Microsoft is currently experiencing a known notification issue with Microsoft Defender, but users should continue reporting security warnings through the normal help desk or security channel.

Degradation of trust

Thames stressed that there is a bigger potential issue: degradation of trust. “Security notifications only work when users believe them. If Windows repeatedly tells someone that their antivirus is disabled when IT tells them that it isn’t, eventually one of those sources loses credibility, if not both,” he said.

Tom Kellermann, VP of AI security and threat research at TrendAI, a division of TrendMicro, added that in the attacks his team has analyzed, roughly 67% leverage tampering with and disabling security software, something that is usually a precursor to “a more systemic and intrusive campaign.”

Related: Overlooked Geothermal Plant Gets Second Chance

Noah Kenney, principal consultant at Digital 520, advised CISOs and CIOs to save evidence of this situation to prove insurance claims that will likely initially be denied. “Six months from now, an insurer looking at a breached server won’t accept ‘Microsoft said there was a bug’ as proof that Defender was running,” he said.

The Microsoft advisory’s wording “is a poor example of crisis communications” and is “ridiculous,” according to Kellermann. He advised users to verify if the alert is accurate and involve their threat hunting teams, who can examine XDR telemetry.

In comparison to similar situations, this bug bears some resemblance to past issues with false security alerts, where users were also told to ignore warnings. However, the scale and potential impact of this bug are more significant, given the widespread use of Windows and Microsoft Defender Antivirus.

The bug’s impact on many Windows versions, including Windows 11 26H1 and Windows Server 2025, is also a concern. As Kenney noted, “Companies separate desktops, servers, legacy systems, and critical infrastructure into different patch rings, but Defender runs through all of them.”

Leave a Reply

Your email address will not be published. Required fields are marked *