Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

Microsoft Defender bug leaves Linux systems exposed after update

A bug in Microsoft Defender for Endpoint has disabled the security service on some Linux machines after a restart, while another flaw blocks installation on hardened Red Hat Enterprise Linux systems. UK businesses using Linux servers face potential security gaps until fixes are deployed.

  • One bug causes Defender for Endpoint to fail on Linux after a system restart, leaving machines unprotected
  • A separate issue prevents installation on hardened Red Hat Enterprise Linux (RHEL) systems
  • Microsoft has acknowledged the problems but no permanent patch has been confirmed as of 27 July 2026
  • Linux adoption in UK enterprise environments continues to grow, widening the potential impact

Microsoft Defender for Endpoint, the company's flagship security product, has been hit by two separate bugs affecting Linux deployments. The first issue causes the security service to stop functioning after a system restart, leaving Linux boxes effectively defenseless until manually reinstated. The second flaw blocks installation entirely on certain hardened Red Hat Enterprise Linux (RHEL) systems, a common choice for UK enterprise servers.

The problems come at a time when Linux adoption in UK businesses is accelerating, particularly in cloud infrastructure, DevOps pipelines, and financial services. According to industry estimates, Linux now powers over 60% of enterprise server workloads in the UK. The bugs could therefore leave a significant number of organisations exposed to malware, ransomware, or unauthorised access during the window between restarts and manual remediation.

Microsoft has not yet released a permanent fix, though temporary workarounds have been shared via support channels. The UK's Information Commissioner's Office (ICO) requires organisations to maintain appropriate technical measures to protect personal data under UK GDPR. A lapse in endpoint protection could, in theory, increase the risk of a data breach, potentially leading to regulatory scrutiny.

From a regulatory perspective, the situation also touches on the broader push for cybersecurity resilience. The EU's AI Act, while primarily focused on artificial intelligence, is part of a wider trend toward tighter security obligations for software vendors. In the UK, the Product Security and Telecommunications Infrastructure (PSTI) Act, which came into force in 2024, already requires manufacturers of internet-connected products to implement minimum security standards. Although Defender for Endpoint is software rather than hardware, the bugs highlight ongoing challenges in ensuring security tools themselves remain reliable.

Dr. Alistair Corbett, a cybersecurity researcher at the University of Cambridge, told UKPulse Media: 'This is a reminder that even mature security products can have blind spots. For UK businesses running Linux in production, the restart bug is particularly concerning because it's silent — you might not know your defences are down until it's too late. The RHEL installation issue also affects some of the most security-conscious organisations, such as those in finance and government.' He recommended that affected IT teams implement manual checks after every restart and consider alternative endpoint detection and response (EDR) tools as a backup.

For UK consumers, the direct impact is limited since Defender for Endpoint is an enterprise product, not the consumer-grade Windows Defender. However, businesses that process consumer data — from retail to banking — could see service disruptions or increased vulnerability. The UK economy, which relies heavily on digital services, faces potential knock-on effects if widespread Linux deployments in cloud providers or financial systems are compromised.

Why this matters: UK businesses increasingly rely on Linux for critical infrastructure. A security tool that fails on restart or cannot be installed on hardened systems creates exploitable gaps that could lead to data breaches, regulatory fines under UK GDPR, and operational downtime.

What this means for you: If your employer runs Linux servers with Microsoft Defender, your company's security could be compromised after a restart — raising the risk of a data breach affecting your personal information. Check with your IT department whether they have applied the temporary workaround.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.