Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Windows 11 Update to Block Untrusted Kernel Drivers

Windows 11 Update to Block Untrusted Kernel Drivers

Posted on March 28, 2026 By CWS

Microsoft is set to enhance the security of its Windows operating systems by blocking untrusted kernel drivers. This initiative, starting with the April 2026 update, will apply to Windows 11 and Windows Server 2025, effectively preventing these drivers from loading unless they are certified through the Windows Hardware Compatibility Program. This move is designed to minimize security risks by reducing the potential attack surface for malicious entities.

Addressing Legacy Security Vulnerabilities

The cross-signed root program, initially introduced in the early 2000s, allowed third-party certificate authorities to issue Windows-trusted code-signing certificates. However, this system lacked the necessary assurances for kernel code security and compatibility. As developers controlled their own private keys, it became a target for credential theft, which enabled attackers to deploy rootkits.

In 2021, Microsoft deprecated this signing program, and its associated certificates have since expired. Despite this, Windows continued to trust these outdated certificates to ensure legacy hardware compatibility, presenting a security risk that the new update aims to eliminate.

Implementation of New Security Measures

Under the new policy, drivers will be blocked on systems by default, with notifications displayed to users. Microsoft aims to sever the remaining trust from the old program by requiring vendors to pass stringent identity verification, submit comprehensive test results, and undergo malware scanning to obtain a Microsoft-owned certificate.

To avoid system disruptions, Microsoft is implementing an explicit allow list for widely used, highly reputable cross-signed drivers. The update will also introduce an evaluation mode, where the Windows kernel will audit driver load signals to prevent interruptions to critical functions. Enforcement will only occur after meeting specific runtime and restart thresholds.

Options for Enterprise Environments

For organizations using internally developed custom kernel drivers, Microsoft offers alternative solutions. Enterprises can bypass the default block by utilizing an Application Control for Business policy. This approach involves signing the policy with an authority rooted in the device’s UEFI Secure Boot variables, allowing administrators to explicitly trust private signers.

This method ensures that threat actors cannot load malicious drivers arbitrarily, while legitimate internal operations remain unaffected. As a result, enterprises can maintain their security posture without compromising operational efficiency.

Stay updated with the latest developments in cybersecurity by following us on Google News, LinkedIn, and X. Contact us to share your stories and insights.

Cyber Security News Tags:application control, cross-signed drivers, Cybersecurity, driver certification, driver security, enterprise solutions, hardware compatibility, kernel drivers, legacy hardware, malware protection, Microsoft update, system security, UEFI Secure Boot, Windows 11, Windows Server 2025

Post navigation

Previous Post: Apple Warns Old iPhone Users of Web Attacks
Next Post: Cyberattack Hits European Commission’s AWS Account

Related Posts

Reddit Faces £14.47 Million Fine for Child Data Breach Reddit Faces £14.47 Million Fine for Child Data Breach Cyber Security News
SoupDealer Malware Bypasses Every Sandbox, AV’s and EDR/XDR in Real-World Incidents SoupDealer Malware Bypasses Every Sandbox, AV’s and EDR/XDR in Real-World Incidents Cyber Security News
Hackers Exploit Government Sites for Malware Distribution Hackers Exploit Government Sites for Malware Distribution Cyber Security News
CISA Urges Action on Windows ActiveX RCE Flaw CISA Urges Action on Windows ActiveX RCE Flaw Cyber Security News
Crypto User Loses ,000 in Seconds After Clicking Instagram Ad Promising Easy Profits Crypto User Loses $9,000 in Seconds After Clicking Instagram Ad Promising Easy Profits Cyber Security News
Critical Citrix 0-Day Vulnerability Exploited Since May, Leaving Global Entities Exposed Critical Citrix 0-Day Vulnerability Exploited Since May, Leaving Global Entities Exposed Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical SharePoint Flaw Allows Remote Code Execution
  • Cisco Addresses Zero-Day Firewall Flaw Amid Active Exploitation
  • New Outlook Flaw Poses Remote Code Execution Risk
  • SAP Security Updates Address Critical Code Injection Risks
  • Remote Threats Target Ivanti Endpoint Manager Services

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical SharePoint Flaw Allows Remote Code Execution
  • Cisco Addresses Zero-Day Firewall Flaw Amid Active Exploitation
  • New Outlook Flaw Poses Remote Code Execution Risk
  • SAP Security Updates Address Critical Code Injection Risks
  • Remote Threats Target Ivanti Endpoint Manager Services

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark