logo

When the Defender Becomes the Door: BlueHammer, RedSun, and UnDefend in the Wild by Justin Howe

ID: 5ed63583-4605-583d-a69a-f44e83953306

STIX ID: report--5ed63583-4605-583d-a69a-f44e83953306

Feed Name: Vectra AI Blog

Threat Score
80/100

Date Published: 2026-04-20

Date Updated: 2026-05-01

...
...

This report details three related attacks against Microsoft Defender: BlueHammer (a TOCTOU race leading to SYSTEM via Defender remediation, patched in April 2026), RedSun (a Defender-abuse exploit that works on fully patched systems and has been observed in the wild), and UnDefend (malware that degrades Defender updates to reduce detection). Huntress observed targeted, hands-on-keyboard intrusions using these techniques; the report emphasizes applying available patches, monitoring behavioral indicators at the network/identity layer, and using independent NDR/EDR integrations (e.g., Vectra) for detection and one-click containment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.