Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild
ID: 40594062-dc12-5004-bc57-4f6327f3eb04
STIX ID: report--40594062-dc12-5004-bc57-4f6327f3eb04
Feed Name: Help Net Security
A security researcher published PoC exploits (BlueHammer, RedSun, UnDefend) targeting Microsoft Defender to escalate privileges and prevent or disable signature updates; Microsoft patched BlueHammer as CVE-2026-33825 on April 14, while RedSun and UnDefend PoCs were posted later and confirmed effective. Huntress reported active in-the-wild use, where attackers dropped exploit files into Pictures/Downloads, mapped user privileges, retrieved stored credentials, and enumerated Active Directory, prompting calls for an out-of-band Microsoft fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
