NewOperating system security & anti-cheat
Download More RAM: dismantling Windows OS defences
Virtualisation-Based Security is the cornerstone of modern Windows defences: the kernel runs in a lightweight VM watched by an isolated secure kernel, so that even an attacker with administrator privileges is contained. We break that guarantee with a software-only memory aliasing attack that needs no physical access. On the most common consumer DIMMs it yields arbitrary read and write, compromising the secure kernel, Hypervisor Enforced Code Integrity and every defence built on them. Microsoft assigned CVE-2026-23670 and shipped a partial mitigation. The paper won a Distinguished Paper Award at USENIX Security 2026.
This is the serious end of a thread that began with games. Studying anti-cheat systems, which carry some of the most aggressive software protections ever shipped to consumers, and the multi-million-pound market that defeats them, is what taught us where the Windows kernel trust boundaries actually sit. The same techniques now apply to Windows Defender, anti-virus and EDR software.