Technology

Leaked Windows zero-days reportedly being used in attacks

Threat actors are reportedly making use of three recently disclosed Windows security vulnerabilities, aiming to reach SYSTEM—or at least land high-enough privileges to run the next stage. The details are messy in the way real incidents often are: different weaknesses, different goals, and an ugly common thread of proof-of-concept code going public.

Since the start of the month, a security researcher working under the names “Chaotic Eclipse” or “Nightmare-Eclipse” posted proof-of-concept exploit code for all three issues. Misryoum newsroom reported the move was framed as protest over how Microsoft’s Security Response Center handled the disclosure process.

Two of the vulnerabilities—BlueHammer and RedSun—are Microsoft Defender local privilege escalation (LPE) flaws. The third, UnDefend, is different: it can be exploited by a standard user to block Microsoft Defender definition updates. At the time of the leak, Misryoum newsroom noted these were still considered zero-days by Microsoft’s definition, meaning there were no official patches or updates to stop them.

Then it got real. Misryoum newsroom reported that, based on observation of active intrusions, the three exploits are being deployed in the wild. BlueHammer, specifically, has been exploited since April 10, while UnDefend and RedSun were spotted on a Windows device that was breached using a compromised SSLVPN user—there was also evidence described as “hands-on-keyboard threat actor activity.” The phrasing is significant because it suggests the attackers weren’t just tossing in a one-off payload and hoping.

There’s a practical detail that makes this feel close to the day-to-day grind: the kind of security alert that shows up as a popup—or maybe just a dashboard warning—can be easy to ignore when you’re busy. Meanwhile, the exploit chain keeps moving, quietly, in the background.

Microsoft is now tracking BlueHammer as CVE-2026-33825 and has patched it in the April 2026 security updates. Even so, the other two weaknesses remain unaddressed. Misryoum editorial desk noted that the RedSun exploit can be used to gain SYSTEM privileges on Windows 10, Windows 11, and Windows Server 2019 and later systems when Windows Defender is enabled—even after applying the April Patch Tuesday patches.

The explanation from the researcher is blunt. When Windows Defender “realizes” a malicious file has a cloud tag, the antivirus component “decides that it is a good idea to just rewrite the file it found again to it’s original location,” according to the researcher. The proof-of-concept reportedly abuses that behavior to overwrite system files and then gain administrative privileges. Or, more simply: defenders trying to correct something end up giving an attacker a foothold.

In response, a Microsoft spokesperson told Misryoum newsroom that Microsoft has a customer commitment to investigate reported security issues and update impacted devices as soon as possible. The spokesperson also reiterated support for coordinated vulnerability disclosure, describing it as a widely adopted practice meant to ensure issues are investigated and addressed before public disclosure—benefiting both customer protection and the security research community.

For now, the situation is split: BlueHammer appears to be patched, but RedSun and UnDefend are still waiting on remediation. And with exploit code already circulating, defenders will likely be watching not just for signs of privilege escalation, but also for anything that looks like Defender definition updates being stalled. That part can be easy to miss until it’s too late—at least, that’s the fear.

Building a Big Kei RC Mini Truck for an Anime Convention

Architecture as Code and agentic AI: constraints that actually hold

Are we getting what we paid for? Turning AI momentum into value