Using a legitmate upgrade to bypass the anti-tamper on endpoint serurity.
- Dec 5, 2025
- 1 min read
Updated: 10 hours ago
Think your endpoint security is safe after implementing anti-tamper (the additional passcode prompt to disable or uninstall your antivirus)? Here's something that might make you think twice.
Recent research from Aon's researched team revealed a legitimate upgrade initiated on the endpoint followed by terminating the upgrade task before it completes could leave the endpoint without protection.
What security leaders need to know:
1. The threat requires local administrative access
2. It leverages signed installers to bypass security
3. This risk could affect multiple endpoint detection products could be vulnerable
Good news:
Sentinel One now offers Local Upgrade Authorization that can block unauthorized agent upgrades and provide time-window controls for legitimate updates.
When a call is made, the caller ID information is set by the originating carrier or VoIP system, not verified by the receiving phone.
Historically, there was no universal verification, meaning the displayed number could be manipulated.

Comments