logo

Exploits Turn Windows Defender into Attacker Tool

ID: 3f8dded1-7af9-505f-8156-e74264979dee

STIX ID: report--3f8dded1-7af9-505f-8156-e74264979dee

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: Jai Vijayan

...
...

Three publicly released proof-of-concept exploits targeting Microsoft Defender — BlueHammer (CVE-2026-33825), RedSun, and UnDefend — abuse race conditions and unvalidated privileged file operations to escalate to SYSTEM and to impair Defender's update/health reporting; BlueHammer is patched by Microsoft's April 2026 update, while RedSun and UnDefend remain unassigned CVEs and have been observed in targeted, hands-on intrusions often following compromised VPN accounts. The report recommends applying updates, enforcing MFA on remote access, blocking execution from user-writable directories, and validating Defender component versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.