Microsoft Defender under attack as three zero-days, two of them still unpatched, enable elevated access
ID: 3f969d42-dae6-54d5-8818-f20bbe7f0622
STIX ID: report--3f969d42-dae6-54d5-8818-f20bbe7f0622
Feed Name: Security Affairs
Threat Score
Security researchers report that threat actors are exploiting three Microsoft Defender zero-days — BlueHammer, RedSun, and UnDefend — to gain elevated privileges and to disable security updates; BlueHammer (CVE-2026-33825) has been fixed but RedSun and UnDefend remain unpatched, public proof-of-concept code was released, and Huntress observed real-world exploitation beginning in April 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
