logo

Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild

ID: 40594062-dc12-5004-bc57-4f6327f3eb04

STIX ID: report--40594062-dc12-5004-bc57-4f6327f3eb04

Feed Name: Help Net Security

Threat Score
80/100

Date Published: 2026-04-17

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

A security researcher published PoC exploits (BlueHammer, RedSun, UnDefend) targeting Microsoft Defender to escalate privileges and prevent or disable signature updates; Microsoft patched BlueHammer as CVE-2026-33825 on April 14, while RedSun and UnDefend PoCs were posted later and confirmed effective. Huntress reported active in-the-wild use, where attackers dropped exploit files into Pictures/Downloads, mapped user privileges, retrieved stored credentials, and enumerated Active Directory, prompting calls for an out-of-band Microsoft fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.