Microsoft resolved a Windows Defender issue that caused quick and full antivirus scans to fail on some Windows 10 and Windows 11 systems, with users reporting msmpeng.exe crashes, WinDefend service timeouts, and 0xc0000005 access violation errors alongside messages stating "Threat service has stopped. Restart it now". Administrators said the failures appeared across multiple devices rather than isolated endpoints, indicating a product-wide fault tied to a recent Defender update or security intelligence release.
Reports from system administrators showed the problem spread widely enough that some customers reinstalled operating systems while troubleshooting. Microsoft confirmed the bug and said it was fixed through Microsoft Defender Antivirus security intelligence update 1.457.236.0 or later, advising affected users to install the latest Defender signature updates through Windows Update; some admins had also circulated a temporary workaround involving removal of dynamic signatures and forcing a signature refresh.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Users and administrators reported starting Tuesday afternoon that Microsoft Defender quick and full scans were failing across multiple Windows 10 and Windows 11 systems, with some environments able to reproduce the issue on multiple devices. Reports included Defender service timeouts, msmpeng.exe crashes, and "Threat service has stopped. Restart it now" messages.
Microsoft confirmed the Defender issue and said it was resolved through Microsoft Defender Antivirus security intelligence update version 1.457.236.0 or later. The company advised affected users to update via Windows Update or enable automatic updates and verify the latest security intelligence was installed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.