Advertisement
Microsoft Defender Blocks Legitimate Google Search Links
Microsoft Defender for Office 365's Safe Links feature is incorrectly flagging legitimate Google search results as malicious, blocking user access and generating alerts.
Weaponizing Defender's BTR.sys to Disable Security Software
Attackers can weaponize a legitimate Microsoft Defender driver to delete security software at boot, impacting Windows 7-11.
ShieldBreak: Windows Zero-Day EoP via Microsoft Defender
Security researcher Nightmare Eclipse released 'ShieldBreak,' a Windows zero-day exploit enabling privilege escalation via Microsoft Defender.
CVE-2026-50656: Microsoft Defender Privilege Escalation – Patch Now
Microsoft patches 'RoguePlanet' vulnerability, CVE-2026-50656, in Defender's Malware Protection Engine, enabling privilege escalation. Update immediately.
Microsoft Defender RoguePlanet Zero-Day Vulnerability Patching Guide
Microsoft addresses the RoguePlanet zero-day in Defender. Learn about the exploitation risks, detection methods, and how to update systems effectively.
CVE-2026-33825: BlueHammer Zero-Day in Microsoft Defender Exploited by Ransomware
Analysis of the BlueHammer zero-day, CVE-2026-33825, in Microsoft Defender, actively exploited by ransomware groups. Learn detection and mitigation strategies.
Advertisement
Windows BlueHammer Flaw Exploited by Ransomware Gangs — Patch Now
CISA warns that ransomware gangs are now exploiting the BlueHammer privilege escalation vulnerability in Microsoft Defender to bypass security controls.
Microsoft Defender 'RoguePlanet' Zero-Day Grants SYSTEM Privileges
Analysis of 'RoguePlanet' zero-day in Microsoft Defender allowing local privilege escalation to SYSTEM, its impact, and critical patch guidance.
AI Chatbot Poisoning: Defending Against Malicious Cryptojacking Links
Microsoft warns of threat actors manipulating AI chatbot recommendations to deliver cryptojacking malware via poisoned web search results.
Automated Endpoint Isolation in Microsoft Defender for Endpoint
Microsoft Defender for Endpoint now features automatic device isolation to block lateral movement and contain high-confidence security breaches effectively.
Linux Vulnerabilities and Defender Zero-Days: Weekly Threat Recap
Weekly intelligence recap covering Linux flaws, Microsoft Defender zero-days, router botnets, and supply chain compromises targeting developer toolchains.
Microsoft Defender CVE-2026-41091 Privilege Escalation Exploited
Microsoft warns of active exploitation of CVE-2026-41091 in Defender, a privilege escalation flaw allowing attackers to gain SYSTEM privileges on Windows.
CISA KEV Update: New Microsoft Defender and Legacy Flaws Exploited
CISA adds seven vulnerabilities, including CVE-2026-41091 and CVE-2026-45498, to the Known Exploited Vulnerabilities catalog. Patch now to prevent compromise.
CVE-2024-21338: Microsoft Defender Zero-Day Exploited by Lazarus
Microsoft patches two zero-day vulnerabilities in Defender and SmartScreen exploited by Lazarus Group for privilege escalation and malware delivery.
Microsoft Defender DigiCert False Positive: Trojan:Win32/Cerdigent.A!dha
Microsoft Defender is incorrectly identifying DigiCert root certificates as the Cerdigent trojan, causing certificate removal and enterprise disruptions.
CVE-2024-38107: Microsoft Defender BlueHammer Flaw Exploited - Patch Now
CISA orders federal agencies to patch the BlueHammer zero-day, a critical Microsoft Defender privilege escalation flaw currently under active exploitation.
CVE-2024-21412: Microsoft Defender Zero-Day Exploitation and Analysis
Analysis of a Microsoft Defender zero-day vulnerability used to extract NTLM hashes from the SAM database and achieve system-level privileges.
CVE-2026-33825: Microsoft Defender Access Control Exploit Analysis
CISA adds CVE-2026-33825 to the KEV catalog following active exploitation of Microsoft Defender's access control mechanisms. Learn how to secure your systems.
Microsoft Defender Binaries Exploited as Attack Tools
Security researchers have identified methods to subvert Microsoft Defender binaries for malicious code execution and EDR bypass. Learn how to defend.
Microsoft Defender Zero-Days BlueHammer and RedSun Actively Exploited
Huntress warns of active exploitation of three Microsoft Defender vulnerabilities, including BlueHammer and RedSun, allowing for privilege escalation.
Microsoft Defender Zero-Day and 17-Year-Old Excel RCE Exploitation
Analysis of recent threats including a Microsoft Defender zero-day, SonicWall brute-force campaigns, and critical RCE in legacy Microsoft Excel components.
EngageLab SDK Vulnerability: Protecting Crypto Wallets from Sandbox Bypass
A flaw in EngageLab SDK exposed 50 million Android users to data theft. Learn how attackers bypass the Android sandbox to access private cryptocurrency keys.
Cookie-Controlled PHP Web Shells Evade Detection on Linux Servers
Microsoft researchers warn of stealthy PHP web shells on Linux using HTTP cookies for command execution and cron jobs for long-term persistence.
Fake Next.js Job Interview Tests Backdoor Developers
Microsoft Defender discovered a campaign where malicious Next.js job interview tests backdoor developers' devices, posing a supply chain risk.