logo

Leaked Windows Defender 0-Day Vulnerability Actively Exploited in Attacks

ID: c2b60561-4b44-58ff-8cf4-842f6ab8ae73

STIX ID: report--c2b60561-4b44-58ff-8cf4-842f6ab8ae73

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-17

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Huntress reports active exploitation of three Windows Defender privilege-escalation techniques (BlueHammer CVE-2026-33825, RedSun, and UnDefend) using public PoC code to gain SYSTEM privileges; BlueHammer was patched in April 2026 while RedSun and UnDefend remain unpatched, with observed staging of binaries in user-writable directories, EICAR baiting, hands-on-keyboard reconnaissance, and recommended immediate patching and hunting for related artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.