Leaked Windows Defender 0-Day Vulnerability Actively Exploited in Attacks
ID: c2b60561-4b44-58ff-8cf4-842f6ab8ae73
STIX ID: report--c2b60561-4b44-58ff-8cf4-842f6ab8ae73
Feed Name: cybersecurityNews.com
Threat Score
Huntress reports active exploitation of three Windows Defender privilege-escalation techniques (BlueHammer CVE-2026-33825, RedSun, and UnDefend) using public PoC code to gain SYSTEM privileges; BlueHammer was patched in April 2026 while RedSun and UnDefend remain unpatched, with observed staging of binaries in user-writable directories, EICAR baiting, hands-on-keyboard reconnaissance, and recommended immediate patching and hunting for related artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
