The images in this article were generated with artificial intelligence. How we publish
A new notice from the Huntress cybersecurity firm has turned on the alarms: attackers are taking advantage of three newly reported failures in Microsoft Defender to scale privileges in committed teams. The vulnerabilities, known by the alias BlueHammer, RedSun and UnDefense, were published as zero- days by a researcher who signs as Chaotic Eclipse (also referred to as Nightmare-Eclipse), in protest of how Microsoft, in its view, managed the outreach process.
Of the three failures, BlueHammer and RedSun allow to raise privileges from the system itself, which in practice makes it easier for an intruder with initial access to gain deeper control over the equipment. Instead, UnDefense is designed to cause a service denial condition that can block the definitions updates, a vector that leaves endpoints with no current defenses against malware. Microsoft has addressed BlueHammer in this week's Patch Tuesday updates and vulnerability figures as CVE-2026-33825 but at the time of writing this text RedSun and UnDefend remain without a formal patch.

Huntress published in networks and in his analyses that he has observed active exploitation of the three vulnerabilities. According to the company, BlueHammer has already been used in attacks since April 10, 2026, and on April 16, there was public concept evidence showing the use of RedSun and UnDefense. The operators, the researchers explain, not only executed automated exploits: they carried out typical hands-on-keyboard tasks, that is, manual and directed activity after initial access. Among the commands detected are privilege and credentials consultations such as whoami / priv, cmdkey / list and net group, clear signs that the attacker explores and prepares the ground for subsequent movements.
What makes this episode more worrying is the combination of several factors: public disclosure by the researcher, the existence of exploits and concept tests in circulation, and confirmation of real use by malicious actors. This has forced Huntress to take containment measures in the affected organization to prevent the attackers from deepening their access or moving laterally within the network.
While Microsoft has already corrected BlueHammer in its monthly patch, it is important that security teams do not consider the closed risk until all the failures are mitigated. Microsoft publishes its updates and guides through the Security Response Center ( Microsoft Security Update Guide) and the relevant bulletins should be verified there. The NIST vulnerability database at the entry is available for public reference of the identifier associated with BlueHammer. CVE-2026-33825.

In situations like this, beyond applying patches when available, practical recommendations include strengthening endpoints monitoring and unusual activity detection mechanisms, applying the principle of lower privilege in accounts and services, and reviewing security records to identify commands and indicator patterns of exploration or exfiltration. Microsoft's documentation on protection and management of Microsoft Defender provides additional guidance on configuration and good practices ( official documentation of Defender).
Recent events highlight a problematic trend: the tension between researchers who publish zero-day explosion and the temporary window left by organizations to park and mitigate. Media coverage and response teams often contact suppliers; in this case, The Hacker News He reported on the situation and said he had sought comments from Microsoft. Until the update of this note, official response is expected to clarify the state of mitigation for RedSun and UnDefend.
For managers and security officials the key now is to act quickly and prudently: to install the available corrections, to tighten telemetry to detect suspicious commands and, if they detect compromise, to segment and isolate affected systems to limit impact. The incidents like this remember that the security solutions are as strong as the speed with which the patches are applied and the quality of the human monitoring that accompanies them.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...