Microsoft will automatically enable Memory Integrity—also called Hypervisor-protected Code Integrity (HVCI)—on eligible Windows 11 systems through the October 13, 2026 Patch Tuesday update. The virtualization-based security control isolates code-integrity validation and blocks unsigned, vulnerable, or incompatible kernel-mode drivers from loading into the Windows kernel.
Enablement will follow a device-by-device readiness assessment covering supported processors, enabled virtualization, available memory and storage, and driver compatibility. Systems intentionally opted out through Group Policy, Intune, or registry configuration will remain excluded, but organizations should test legacy drivers because incompatible drivers may fail to load; Windows records affected-driver events as Event ID 3087 in the CodeIntegrity/Operational event log.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft plans to automatically enable Memory Integrity (HVCI) on eligible Windows 11 devices through the October 13, 2026 Patch Tuesday update. The rollout will assess device readiness and will preserve administrator opt-outs configured through Group Policy, Intune, or registry settings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcetomshardware.com
Open sourcewindowslatest.com
Open sourcetechcommunity.microsoft.com
Open sourcelearn.microsoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.