Skip to main content

Microsoft upgrades Windows Defender to better combat new malware threats

Prevention is better than a cure, that’s how the old saying goes, and it is just as viable in terms of digital security as it is with our own personal health. That’s the mentality Microsoft has entrenched in its development of Windows 10, and it’s continuing to expand on that ethos with its new Advanced Threat Protection system (ATP).

Windows Defender is built into Windows 10 as a core feature, and already offers basic threat detection for all those running the operating system. But on the request of many of its customers, Microsoft is leveraging machine learning to detect threats faster than ever before.

The first step of combating and threat is registering that an attack has taken place. This can take up to 200 days with traditional techniques in some enterprises, according to Microsoft research, so its new system hopes to do it much faster. Looking back at the last six months of system logs and activities, ATP can detect when non-typical activity takes place, allowing for manual follow ups to confirm the breach.

There’s even simplified investigation tools that circumvent the need to look through raw log files, and the ability to send files and URLs to isolated virtual machines for deeper examination. This will help responders to correctly formulate a plan to deal with the breach and figure out a method to close up the flaw in security that allowed it to take place.

The big reason Microsoft is excited for ATP, though, is that it sits alongside Windows Defender and other anti-virus and anti-malware tools without intrusion. Since it operates in a different manner, it can augment existing security, and due to its regular updates through the Windows 10 Insider program, it will be kept at the forefront of detection and malware combat.

This means there’s zero deployment cost or effort on the enterprise end, which many businesses will appreciate.

Already deployed in more than 500,000 test cases, Microsoft hopes that this added feature will encourage other businesses and individuals to switch over to Windows 10 now, with a look to enjoy the benefits of ATP in the near future.

Jon Martindale
Jon Martindale is the Evergreen Coordinator for Computing, overseeing a team of writers addressing all the latest how to…
Microsoft may fix the most frustrating thing about Windows updates
Windows 11 updates are moving to once a year.

Most Windows users will agree that one of the most annoying things about the operating system is the updates. While Windows Updates are necessary, they often tend to come up at the worst possible time, interrupting work and gaming sessions with persistent reminders that the system needs to reboot. Microsoft might be fixing that problem in the upcoming Windows 11 24H2 build, but it's still too early to bid farewell to those ill-timed reboots.

As spotted in the latest Windows 11 Insider Preview Build 26058, Microsoft is testing "hot patching" for some Windows 11 updates. Hot patching refers to a dynamic method of updating that often doesn't change the software version and may not even need a restart. In the context of Windows 11, it's pretty straightforward -- Windows will install the update, and you won't have to reboot your system.

Read more
A dangerous new jailbreak for AI chatbots was just discovered
the side of a Microsoft building

Microsoft has released more details about a troubling new generative AI jailbreak technique it has discovered, called "Skeleton Key." Using this prompt injection method, malicious users can effectively bypass a chatbot's safety guardrails, the security features that keeps ChatGPT from going full Taye.

Skeleton Key is an example of a prompt injection or prompt engineering attack. It's a multi-turn strategy designed to essentially convince an AI model to ignore its ingrained safety guardrails, "[causing] the system to violate its operators’ policies, make decisions unduly influenced by a user, or execute malicious instructions," Mark Russinovich, CTO of Microsoft Azure, wrote in the announcement.

Read more