Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
    Cybersecurity

    Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

    adminBy adminApril 17, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 17, 2026Vulnerability / Endpoint Security

    Huntress is warning that threat actors are exploiting three recently disclosed security flaws in Microsoft Defender to gain elevated privileges in compromised systems.

    The activity involves the exploitation of three vulnerabilities that are codenamed BlueHammer (requires GitHub sign-in), RedSun, and UnDefend, all of which were released as zero-days by a researcher known as Chaotic Eclipse (aka Nightmare-Eclipse) in response to Microsoft’s handling of the vulnerability disclosure process.

    While both BlueHammer and RedSun are local privilege escalation (LPE) flaws impacting Microsoft Defender, UnDefend can be used to trigger a denial-of-service (DoS) condition and effectively block definition updates.

    Microsoft moved to address BlueHammer as part of its Patch Tuesday updates released earlier this week. The vulnerability is being tracked under the CVE identifier CVE-2026-33825. However, the other flaws do not have a fix as of writing.

    In a series of posts shared on X, Huntress said it observed all three flaws being exploited in the wild, with BlueHammer being weaponized since April 10, 2026, followed by the use of RedSun and UnDefend proof-of-concept (PoC) exploits on April 16.

    “These invocations followed after typical enumeration commands: whoami /priv, cmdkey /list, net group, and others that indicate hands-on-keyboard threat actor activity,” it added.

    The cybersecurity vendor said it has taken steps to isolate the affected organization to prevent further post-exploitation. The Hacker News has reached out to Microsoft for comment, and we will update the story if we hear back.

    Actively Defender Exploited Microsoft Unpatched ZeroDays
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleThe Play Store may soon offer easier access to game categories
    Next Article CarPlay’s ChatGPT integration is way more useful than I expected
    admin
    • Website

    Related Posts

    CoChat Launches AI Collaboration Platform to Combat Shadow AI

    April 17, 2026

    Coast Guard’s New Cybersecurity Rules Offers Lessons for CISOs

    April 17, 2026

    Google wipes out 602 million scam ads with Gemini on duty

    April 17, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google’s Product Feed Strategy Points To The Future Of Retail Discovery

    April 17, 2026

    Solid-state battery tech is finally mainstream, starting with BMX SolidSafe power banks

    April 17, 2026

    CoChat Launches AI Collaboration Platform to Combat Shadow AI

    April 17, 2026

    8 Ways to Elevate Your Brand as a Creator or Entrepreneur (& Close the Pay Gap)

    April 17, 2026
    Categories
    • Blogging (64)
    • Cybersecurity (1,367)
    • Privacy & Online Earning (170)
    • SEO & Digital Marketing (841)
    • Tech Tools & Mobile / Apps (1,635)
    • WiFi / Internet & Networking (227)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google’s Product Feed Strategy Points To The Future Of Retail Discovery

    April 17, 2026

    Solid-state battery tech is finally mainstream, starting with BMX SolidSafe power banks

    April 17, 2026

    CoChat Launches AI Collaboration Platform to Combat Shadow AI

    April 17, 2026
    Most Popular
    • Google’s Product Feed Strategy Points To The Future Of Retail Discovery
    • Solid-state battery tech is finally mainstream, starting with BMX SolidSafe power banks
    • CoChat Launches AI Collaboration Platform to Combat Shadow AI
    • 8 Ways to Elevate Your Brand as a Creator or Entrepreneur (& Close the Pay Gap)
    • Hbada X7 Smart office chair review
    • Coast Guard’s New Cybersecurity Rules Offers Lessons for CISOs
    • OpenAI begins rolling out ads in select markets
    • CarPlay’s ChatGPT integration is way more useful than I expected
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.