The PC Security Channel
Hosted by a malware analyst, this channel reviews antivirus software and malware defense techniques, provides Windows security news, and demonstrates how to analyze and combat threats in a consumer‑friendly style ([www.linkedin.com](https://www.linkedin.com/pulse/top-20-youtube-channels-cybersecurity-pawan-panwar-hhmsc#:~:text=12)).

Windows Defender Vulnerability Lets Malware Install Into System 32
Windows Defender, Microsoft’s built‑in antivirus, was shown to enable a malicious program to write directly to the protected System32 directory. In a live demo, the researcher ran a sample exploit called Redson.exe, which triggered Defender’s “threat found” alert, but the quarantine action opened a command prompt with full system privileges and allowed the file to be rewritten in System32 without administrative rights. The exploit leverages the way Windows treats cloud‑synced files, particularly those flagged as OneDrive items. By masquerading as a cloud file, the malware convinces Defender to rewrite the original location, effectively bypassing the OS’s protection mechanisms. The author released three related projects, each exposing zero‑day flaws that Microsoft has not yet patched. A striking comment from the demo highlights the paradox: “malware is more powerful because of Windows Defender detecting it.” The proof‑of‑concept demonstrates that a simple flag in the code can elevate a regular user process to system level, opening the door for rootkits or ransomware to embed themselves silently. Given that Defender powers many corporate endpoints and the enterprise version serves as a primary EDR, the vulnerability poses a systemic risk. Organizations should monitor Microsoft’s response, apply any forthcoming patches promptly, and consider layered defenses beyond the native antivirus to mitigate similar privilege‑escalation attacks.

CPU-Z and HWMonitor Are Malware!?
The video exposes a supply‑chain breach affecting the official installers of CPU‑Z and HWMonitor. A compromised cryptbase.dll was injected into the legitimate download packages, turning these popular system‑info tools into malware droppers. The malicious DLL contacts a remote command‑and‑control server, retrieves...

NPM Axious Hack: Popular Applications Potentially Infected by a RAT?
The video examines a recent supply‑chain compromise of the widely‑used NPM package Axios, which was hijacked to distribute a remote‑access tool (RAT) that briefly infected an estimated 100 million computers. The malicious payload is delivered in three platform‑specific variants—a Windows PowerShell script,...

Official Game Installs Malware
The video warns that the indie title “Do at Night Abyss” was compromised in a supply-chain attack, delivering the UmbrellaStealer info‑stealer to unsuspecting players. The breach did not require any user click; the malicious payload was bundled with the game’s...

Undetected Discord Malware
The video warns that a new strain of malware is being spread on Discord through seemingly innocuous messages from friends offering a closed‑beta game. The attacker shares a trailer link and a download page that appears legitimate, prompting recipients to...

How Stealthy Was the 7zip Malware and How to Spot It?
The video dives into the Trojan‑laden 7‑Zip installer that was being served from the look‑alike domain 7zip.com, showing how the malicious package mimics the legitimate 7‑Zip setup while silently dropping a back‑door. In the Any.run sandbox the analyst observed that the...