WatchGuard has refreshed its Endpoint Security offering for 2026 — EDR Core, EPP, EDR, EPDR, and Advanced EPDR are now Basic, Prime, 360, and Elite.🛡️
Compare the new Endpoint Security licences here: bit.ly/4uOQWA6@WatchGuardUK#EndpointProtection#Cybersecurity
ALT WatchGuard logo next to cybersecurity deployment examples against a dark blue and black background
ALT cyber-retaliator-solutions-crs-retaliatornation-beachheadbeachhead-endpoint-encryption-and-remote-device-management-platform-protecting-corporate-data-across-laptops-and-mobile-devices
🚨 Critical Threat Intelligence Alert 🚨
Research published yesterday by specialist @MatheuzSecurity reveals a local protection bypass technique targeting the Trend Micro Deep Security Agent on Linux.
By generating a controlled “event storm” (high volume of filesystem and process events), it is possible to force the agent to unload the kernel modules bmhook and tmhook, creating a temporary window without behavioral monitoring.
Full article PoC: matheuzsecurity.github.io/ha…
(1/3)
#CyberSecurity#ThreatIntelligence#EDR
Post 2/3
⚠️ Technical Details
•Affected modules: bmhook (Behavior Monitoring) and tmhook (Generic Syscall-Hooking via livepatch).
•Trigger: High-volume benign event storm (writes, renames, symlinks, forks, and exits).
•Mechanism: The ds_am.init process executes rmmod on the modules as part of the agent’s internal recovery mechanism under load.
•Exposure window: Approximately 1.3 seconds without the modules loaded up to ~19.6 seconds for full transition.
During this interval, actions normally blocked by the EDR can be executed successfully.
(2/3)
#LinuxSecurity#EndpointProtection#InfoSec
Post 3/3
📌 Impact and Recommendations for Security Teams
This represents a degradation of the EDR’s own recovery mechanism, exploitable in a repeatable manner by unprivileged local users (or by malware already present on the endpoint). It enables artifact staging and evasion of behavioral detections.
Recommended actions:
•Actively monitor module unload logs (dmesg, /proc/modules)
•Assess exposure in Linux environments running Deep Security Agent
•Implement additional telemetry and compensating controls
•Monitor for official vendor response
Excellent research work by @MatheuzSecurity.
(3/3)
#RedTeam#BlueTeam#VulnResearch#MalwareAnalysis#ThreatHunting
Windows Defender is powerful.
Most people just don’t control it properly. Stealth Managed AntiVirus gives you full command — run scans, configure protection, manage exclusions, and monitor status from one clean interface. No bloat. No third-party engine.
Just control over what already protects you.
#WindowsSecurity#CyberSec#EndpointProtection