logo

Microsoft Defender under attack as three zero-days, two of them still unpatched, enable elevated access

ID: 3f969d42-dae6-54d5-8818-f20bbe7f0622

STIX ID: report--3f969d42-dae6-54d5-8818-f20bbe7f0622

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-04-18

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Security researchers report that threat actors are exploiting three Microsoft Defender zero-days — BlueHammer, RedSun, and UnDefend — to gain elevated privileges and to disable security updates; BlueHammer (CVE-2026-33825) has been fixed but RedSun and UnDefend remain unpatched, public proof-of-concept code was released, and Huntress observed real-world exploitation beginning in April 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.