{
  "id": 889523,
  "title": "'This one just needs a script': Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction",
  "url": "https://urgent.news/2026/08/14/this-one-just-needs-a-script-researchers-find-ultimate-windows-kill",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-14T16:05:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/this-one-just-needs-a-script-researchers-find-ultimate-windows-kill-switch-which-can-disable-antivirus-with-almost-no-user-interaction"
  },
  "original_language": "en",
  "account": "A recently discovered vulnerability, dubbed \"Download more RAM,\" allows threat actors to bypass advanced security measures, disable antivirus software, and gain full control over a target device. This flaw existed in consumer DDR4 and DDR5 memory chips, which could be manipulated to send false configuration reports to the motherboard. As a result, attackers could make the computer believe it has twice the actual RAM capacity, granting them unauthorized access to memory locations that should be protected. Researchers from the University of Birmingham and Durham University uncovered this \"Download more RAM\" flaw during the 2026 USENIX Security Symposium. They demonstrated that the phantom memory could act as an alias for real memory, enabling attackers to read and modify protected memory allocations. This technique bypassed Windows' Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI), which are designed to isolate critical security functions and ensure only trusted code can run in the Windows kernel. Furthermore, the flaw allowed attackers to disable antivirus and endpoint detection and response (EDR) software, introduce older drivers, compromise corporate systems, and circumvent game anti-cheat protections. The researchers noted that this entire process could be chained together into a single-click script, making it possible for almost anyone to exploit the vulnerability. To mitigate the risk, affected users can apply Microsoft's April 2026 Patch Tuesday cumulative update, which addresses the vulnerability (CVE-2026-23670). Additionally, some manufacturers like Corsair and third-party tools such as HWinfo offer solutions to enable write protection on memory modules.",
  "summary": "Microsoft fixed it as part of the April Patch Tuesday cumulative update, but there are other fixes and mitigations available, too.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "TechRadar",
        "title": "The ultimate Mac dock? Ivanky unveils a 26-port Apple Silicon powerhouse that Windows users can't use",
        "url": "https://urgent.news/2026/08/14/the-ultimate-mac-dock-ivanky-unveils-a-26-port-apple-silicon",
        "published": "2026-08-14T18:20:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}