A newly disclosed Windows attack technique, dubbed “Download More RAM,” can undermine Virtualization-Based Security (VBS), bypass Hypervisor-Protected Code Integrity (HVCI), and disable endpoint protections including Microsoft Defender and third-party EDR products. The attack was presented at USENIX Security 2026 and is tracked by Microsoft as CVE-2026-23670. Unlike a conventional Windows kernel exploit, Download More RAM […]
Read the original article: