Microsoft Defender for Endpoint, the company's flagship security product, has been hit by two separate bugs affecting Linux deployments. The first issue causes the security service to stop functioning after a system restart, leaving Linux boxes effectively defenseless until manually reinstated. The second flaw blocks installation entirely on certain hardened Red Hat Enterprise Linux (RHEL) systems, a common choice for UK enterprise servers.
The problems come at a time when Linux adoption in UK businesses is accelerating, particularly in cloud infrastructure, DevOps pipelines, and financial services. According to industry estimates, Linux now powers over 60% of enterprise server workloads in the UK. The bugs could therefore leave a significant number of organisations exposed to malware, ransomware, or unauthorised access during the window between restarts and manual remediation.
Microsoft has not yet released a permanent fix, though temporary workarounds have been shared via support channels. The UK's Information Commissioner's Office (ICO) requires organisations to maintain appropriate technical measures to protect personal data under UK GDPR. A lapse in endpoint protection could, in theory, increase the risk of a data breach, potentially leading to regulatory scrutiny.
From a regulatory perspective, the situation also touches on the broader push for cybersecurity resilience. The EU's AI Act, while primarily focused on artificial intelligence, is part of a wider trend toward tighter security obligations for software vendors. In the UK, the Product Security and Telecommunications Infrastructure (PSTI) Act, which came into force in 2024, already requires manufacturers of internet-connected products to implement minimum security standards. Although Defender for Endpoint is software rather than hardware, the bugs highlight ongoing challenges in ensuring security tools themselves remain reliable.
Dr. Alistair Corbett, a cybersecurity researcher at the University of Cambridge, told UKPulse Media: 'This is a reminder that even mature security products can have blind spots. For UK businesses running Linux in production, the restart bug is particularly concerning because it's silent — you might not know your defences are down until it's too late. The RHEL installation issue also affects some of the most security-conscious organisations, such as those in finance and government.' He recommended that affected IT teams implement manual checks after every restart and consider alternative endpoint detection and response (EDR) tools as a backup.
For UK consumers, the direct impact is limited since Defender for Endpoint is an enterprise product, not the consumer-grade Windows Defender. However, businesses that process consumer data — from retail to banking — could see service disruptions or increased vulnerability. The UK economy, which relies heavily on digital services, faces potential knock-on effects if widespread Linux deployments in cloud providers or financial systems are compromised.