logo

Recently leaked Windows zero-days now exploited in attacks

ID: 43dfd2b6-775b-559a-ae6c-7b71b8be8251

STIX ID: report--43dfd2b6-775b-559a-ae6c-7b71b8be8251

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-04-17

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Threat actors are actively exploiting three recently disclosed Windows zero-day vulnerabilities—BlueHammer (patched as CVE-2026-33825), RedSun, and UnDefend—after a researcher released proof-of-concept exploit code. Huntress Labs observed RedSun and UnDefend used on compromised systems to gain SYSTEM privileges and block Defender updates, with evidence of hands-on-keyboard activity; BlueHammer has been patched but RedSun and UnDefend remained unaddressed at the time of the report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.