Download More RAM Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing

A new attack dubbed “Download More RAM” can bypass Windows Virtualization-Based Security (VBS), weaken Hypervisor-Enforced Code Integrity (HVCI), and disable Microsoft Defender. Microsoft tracked the issue as CVE-2026-23670 and released mitigations in its April 2026 security update. The attack abuses improperly protected Serial Presence Detect (SPD) data on certain consumer DDR4 and DDR5 memory modules. […]

This article has been indexed from Cyber Security News

Read the original article: