Skip to main content

Microsoft’s latest Windows 10 Insider Preview release all about fighting malware

Windows Timeline
Image used with permission by copyright holder

Microsoft’s latest Windows 10 build 17672 is now available for download, and there’s one big new change in this version. Build 17672 is a Windows Insider preview build available to those who registered for the Fast ring or for Skip Ahead releases, so the software is in testing and isn’t finalized yet for general consumers. There are a number of improvements introduced in this build, but the biggest change is that third-party antivirus software is now handled differently on the platform.

This latest security change stipulates that antivirus software — like those made by Norton Symantec, McAfee, and Kaspersky Lab — must run as a protected process. Microsoft announced system protected processes beginning with the release of Windows 8.1 as a security measure to defend against malicious attacks on system-critical components.

“The protected process infrastructure only allows trusted, signed code to load and has built-in defense against code injection attacks,” Microsoft said at the time. “After the anti-malware services have opted into the protected service mode, only Windows signed code or code signed with the anti-malware vendor’s certificates are allowed to load in that process.”

On build 17672 this means that the default Windows Defender Antivirus that ships with Windows 10 will be enabled and run alongside any antivirus product that has not registered as a protected process. “Products that have not yet implemented this will not appear in the Windows Security UI, and Windows Defender Antivirus will remain enabled side-by-side with these products,” Microsoft detailed in a blog post.

Microsoft is allowing testers to disable this behavior with the creation of a registry key, but this workaround will be removed closer to the consumer release of the next big Windows 10 update.

Other notable fixes include improvements to the Microsoft Edge browser, an update to the recently released Timeline feature that allows users to cycle through tabs, and low battery alerts for compatible Bluetooth-connected devices. Users of Microsoft’s Windows Mixed Reality experience may want to avoid this build for now, as there are a few known issues with this release. Motion controllers may not be recognized in some apps, and your headset may display a black screen.

If you’re looking for malware defense — in addition to or in lieu of Windows Defender — be sure to check out our list of the best free antivirus software. We also have rankings for the best free antivirus tools for MacOS users if you’re in the Apple camp.

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
Windows 11 vs. Windows 10: Is it finally time to upgrade?
Microsoft Surface Laptop 2 sitting on a table.

Windows 11 is the newest version of Windows, and it's one of the best Windows versions ever released. At launch, the operating system was very similar to Windows 10, but it has morphed a lot over the past several years. Now, Windows 11 has several key differences compared to Windows 10.

If you've been holding out on upgrading, we have everything you need to know about Windows 11 and how it's different than Windows 10 in this article. We'll detail the differences, as well as show you the areas where Windows 11 is growing faster than Windows 10.
Windows 11 vs. Windows 10: what's new

Read more
A dangerous new jailbreak for AI chatbots was just discovered
the side of a Microsoft building

Microsoft has released more details about a troubling new generative AI jailbreak technique it has discovered, called "Skeleton Key." Using this prompt injection method, malicious users can effectively bypass a chatbot's safety guardrails, the security features that keeps ChatGPT from going full Taye.

Skeleton Key is an example of a prompt injection or prompt engineering attack. It's a multi-turn strategy designed to essentially convince an AI model to ignore its ingrained safety guardrails, "[causing] the system to violate its operators’ policies, make decisions unduly influenced by a user, or execute malicious instructions," Mark Russinovich, CTO of Microsoft Azure, wrote in the announcement.

Read more