Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
    Cybersecurity

    Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

    adminBy adminApril 17, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 17, 2026Vulnerability / Endpoint Security

    Huntress is warning that threat actors are exploiting three recently disclosed security flaws in Microsoft Defender to gain elevated privileges in compromised systems.

    The activity involves the exploitation of three vulnerabilities that are codenamed BlueHammer (requires GitHub sign-in), RedSun, and UnDefend, all of which were released as zero-days by a researcher known as Chaotic Eclipse (aka Nightmare-Eclipse) in response to Microsoft’s handling of the vulnerability disclosure process.

    While both BlueHammer and RedSun are local privilege escalation (LPE) flaws impacting Microsoft Defender, UnDefend can be used to trigger a denial-of-service (DoS) condition and effectively block definition updates.

    Microsoft moved to address BlueHammer as part of its Patch Tuesday updates released earlier this week. The vulnerability is being tracked under the CVE identifier CVE-2026-33825. However, the other flaws do not have a fix as of writing.

    In a series of posts shared on X, Huntress said it observed all three flaws being exploited in the wild, with BlueHammer being weaponized since April 10, 2026, followed by the use of RedSun and UnDefend proof-of-concept (PoC) exploits on April 16.

    “These invocations followed after typical enumeration commands: whoami /priv, cmdkey /list, net group, and others that indicate hands-on-keyboard threat actor activity,” it added.

    The cybersecurity vendor said it has taken steps to isolate the affected organization to prevent further post-exploitation. The Hacker News has reached out to Microsoft for comment, and we will update the story if we hear back.

    Actively Defender Exploited Microsoft Unpatched ZeroDays
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleThe Play Store may soon offer easier access to game categories
    Next Article CarPlay’s ChatGPT integration is way more useful than I expected
    admin
    • Website

    Related Posts

    Microsoft Web IQ Gives AI Agents Bing Grounding APIs

    June 2, 2026

    FTC broadens Microsoft probe to cloud, AI, and software bundling

    June 2, 2026

    Microsoft Clarity Now Shows Grounding Queries Behind AI Citations

    May 22, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Microsoft Web IQ Gives AI Agents Bing Grounding APIs

    June 2, 2026

    Netskope introduces AI Command Center to monitor and secure enterprise AI sprawl

    June 2, 2026

    How to Do Prompt-Based Keyword Research to Show Up Better in AI Results

    June 2, 2026

    How SEO turns customer success into AI-readable proof

    June 2, 2026
    Categories
    • Blogging (88)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (230)
    • SEO & Digital Marketing (1,343)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (326)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Microsoft Web IQ Gives AI Agents Bing Grounding APIs

    June 2, 2026

    Netskope introduces AI Command Center to monitor and secure enterprise AI sprawl

    June 2, 2026

    How to Do Prompt-Based Keyword Research to Show Up Better in AI Results

    June 2, 2026
    Most Popular
    • Microsoft Web IQ Gives AI Agents Bing Grounding APIs
    • Netskope introduces AI Command Center to monitor and secure enterprise AI sprawl
    • How to Do Prompt-Based Keyword Research to Show Up Better in AI Results
    • How SEO turns customer success into AI-readable proof
    • How to get your website indexed by Google
    • The 50 Most-Cited Websites in Gemini (June 2026)
    • Cisco brings agentic ops platform and security overhaul to Cisco Live
    • Google’s May Core Update Complete After Volatile Rollout
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.