About 230 results
Open links in new tab
  1. THREAT ADVISORY RedSun Zero-Day (Windows Defender) April 17, …

    Apr 17, 2026 · Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun …

  2. Mitigate RedSun Zero-Day Without A Patch | Qualys

    Apr 22, 2026 · RedSun is a zero-day LPE in Microsoft Defender with no patch available. Learn how to detect and mitigate it instantly using Qualys VMDR and TruRisk™ Eliminate.

  3. Technical steps to mitigate RedSun zero-day in Windows Defender

    RedSun is a newly disclosed local privilege escalation technique that abuses an insecure behaviour in Windows Defender when handling “cloud-tagged” files.

  4. Defender Triple Zero-Day: BlueHammer, RedSun, and UnDefend

  5. 3ch0p01nt/RedSun_Undefend - GitHub

    Apr 20, 2026 · Three related zero-day vulnerabilities targeting Microsoft Defender were publicly disclosed in April 2026 by the researcher "Nightmare-Eclipse" (aka "Chaotic Eclipse"). This repo …

  6. New “RedSunWindows Defender zero-day exploited in the wild

    Apr 17, 2026 · A newly disclosed Windows zero-day vulnerability dubbed “RedSun” is being actively exploited in the wild, allowing attackers to gain SYSTEM privileges by abusing Microsoft Defender.

  7. Microsoft Defender Zero-Day Exploits -BlueHammer & RedSun (April …

    Apr 20, 2026 · Three publicly disclosed and in-the-wild exploited Microsoft Defender zero-day vulnerabilities—BlueHammer, RedSun, and UnDefend—are being used to escalate privileges and/or …

  8. BlueHammer & RedSun: Windows Defender CVE-2026-33825 Zero …

    Apr 17, 2026 · In this blog, we explain how the Windows Defender CVE-2026-33825 vulnerability works, its real-world risk to organizations, and provide practical steps for validation and remediation.

  9. Microsoft Defender 0-Day VulnerabilityRedSun” Enables Full …

    Apr 17, 2026 · A newly disclosed zero-day vulnerability in Microsoft Defender, dubbed "RedSun," allows an unprivileged user to escalate privileges to full SYSTEM-level access on fully patched Windows …

  10. BlueHammer & RedSun: Windows Defender CVE-2026-33825 explained

    Apr 17, 2026 · A straight-faced breakdown of the Windows Defender zero-day CVE-2026-33825 (BlueHammer) and the RedSun variant. What it is, how it works, and what Dutch SOC and endpoint …