logo

Windows Defender Zero-Day Leak Fuels Active Exploitation Campaigns

ID: 8259d34d-78f5-5fab-b23a-65e1ef61d404

STIX ID: report--8259d34d-78f5-5fab-b23a-65e1ef61d404

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-04-17

Date Updated: 2026-04-17

Author: AnuPriya

...
...

A newly leaked zero-day targeting Microsoft Defender—dubbed “Nightmare-Eclipse” and leveraging tools/techniques like BlueHammer and RedSun—is being actively exploited in the wild; Huntress observed malicious binaries executed from user directories (e.g., Pictures, Downloads), reconnaissance commands (whoami/priv, cmdkey/list, net group), and Defender detections/quarantines, indicating real-world weaponization and probing of AV responses. Organizations are advised to monitor endpoint executions from user folders, review logs for suspicious enumeration activity, and ensure Defender signatures and advanced behavioral detections are enabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.