Windows Bug Falsely Claims Microsoft Defender Is Disabled
A new Windows glitch is falsely notifying users that Microsoft Defender Antivirus is disabled, raising fears that organizations will train employees to ignore critical security warnings.

Microsoft has acknowledged a glitch in its latest Microsoft Defender Antivirus updates that triggers false notifications claiming the security software is turned off. Despite the warnings, which appear at startup and intermittently afterward, the antivirus system remains fully functional. The bug affects a vast range of operating systems spanning fourteen years, including Windows 11 version 26H1, Windows Server 2025, Windows 10 Enterprise LTSC 2016, and Windows Server 2012. Microsoft stated it is working on a resolution for a future update.
Cybersecurity experts warn that instructing users to disregard these alerts creates a severe security regression. Disabling endpoint security is a standard tactic in ransomware campaigns, and TrendAI vice president Tom Kellermann noted that about 67 percent of analyzed attacks involve interfering with or shutting down security tools. If users and security operations centers get used to ignoring these warnings, they may miss actual attacks. Experts fear security teams will write suppression rules to quiet the noise, which could filter out genuine alerts long after Microsoft patches the bug.
The false alerts also open the door for social engineering, as hackers can easily convince help desks to ignore real warnings by citing the documented Microsoft glitch. Furthermore, digital consultants advise organizations to preserve their own telemetry data and timestamped sensor records. If a breach occurs, insurance companies might deny claims based on the false notifications, requiring companies to prove that Defender was actually running. Security professionals emphasize that IT departments must verify Defender's actual state rather than teaching users to ignore system warnings.
This is our own summary of reporting by Computerworld AI



