A New Windows Zero-Day Lets Attackers Take Full Control
ID: 3df291f1-cb37-5db2-a6f7-c6a15354a7ed
STIX ID: report--3df291f1-cb37-5db2-a6f7-c6a15354a7ed
Feed Name: WatchGuard Secplicity Blog
Threat Score
**Executive summary:** The report summarizes a newly disclosed Windows zero-day named RedSun that enables local privilege escalation to SYSTEM via Microsoft Defender's handling of cloud-synced files, while also covering a Europol DDoS-for-hire disruption and Microsoft RDP security prompt updates; it stresses that post-compromise escalation is the key threat and recommends detection, least-privilege enforcement, and improved endpoint visibility.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
