Microsoft has confirmed a Microsoft Defender Antivirus defect that falsely warns Windows users that virus protection is turned off even when Defender and real-time protection remain enabled and functioning. The recurring “Turn on virus protection” notifications can appear at startup or intermittently afterward, including after they are dismissed, and may bypass Windows notification controls and Do Not Disturb settings.
The issue affects supported Windows client and server releases, with reports spanning Windows 10 and Windows 11 versions through 26H1, as well as Windows Server 2025. Microsoft advises users to ignore the erroneous alerts while it develops a correction to be distributed in a future Defender Antivirus update; organizations should nevertheless verify Defender’s actual protection status, as genuine security warnings and social-engineering imitations remain possible.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
False “Turn on virus protection” notifications were reportedly first observed in early August, with reports increasing in the days before the initial coverage.
The erroneous Microsoft Defender Antivirus notifications had affected Windows Insider Release Preview Channel users since June, despite Defender continuing to operate normally.
Microsoft advised affected users to disregard the incorrect notifications and said it is developing a correction for delivery through a future Microsoft Defender Antivirus update; no responsible update version or release date was specified.
Microsoft acknowledged that recent Defender Antivirus updates can incorrectly report that antivirus protection is turned off even while Defender and its protection settings remain active. The issue affects supported Windows client and server systems, and the alerts can recur at startup or during normal use despite notification settings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcewindowslatest.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.