Skip to main content
← All Articles

Tag

#Microsoft Defender

24 articles

Advertisement

LOW
Threat Intel

Microsoft Defender Blocks Legitimate Google Search Links

Microsoft Defender for Office 365's Safe Links feature is incorrectly flagging legitimate Google search results as malicious, blocking user access and generating alerts.

Runtime Rebel Intel
4 min read · Sep 2, 2026
Weaponizing Defender's BTR.sys to Disable Security Software
MEDIUM
Vulnerabilities

Weaponizing Defender's BTR.sys to Disable Security Software

Attackers can weaponize a legitimate Microsoft Defender driver to delete security software at boot, impacting Windows 7-11.

Runtime Rebel Intel
4 min read · Aug 22, 2026
HIGH
Vulnerabilities

ShieldBreak: Windows Zero-Day EoP via Microsoft Defender

Security researcher Nightmare Eclipse released 'ShieldBreak,' a Windows zero-day exploit enabling privilege escalation via Microsoft Defender.

Runtime Rebel Intel
4 min read · Aug 13, 2026
HIGH
Vulnerabilities

CVE-2026-50656: Microsoft Defender Privilege Escalation – Patch Now

Microsoft patches 'RoguePlanet' vulnerability, CVE-2026-50656, in Defender's Malware Protection Engine, enabling privilege escalation. Update immediately.

Runtime Rebel Intel
5 min read · Jul 9, 2026
CRITICAL
Vulnerabilities

Microsoft Defender RoguePlanet Zero-Day Vulnerability Patching Guide

Microsoft addresses the RoguePlanet zero-day in Defender. Learn about the exploitation risks, detection methods, and how to update systems effectively.

Runtime Rebel Intel
4 min read · Jul 9, 2026
CRITICAL
Vulnerabilities

CVE-2026-33825: BlueHammer Zero-Day in Microsoft Defender Exploited by Ransomware

Analysis of the BlueHammer zero-day, CVE-2026-33825, in Microsoft Defender, actively exploited by ransomware groups. Learn detection and mitigation strategies.

Runtime Rebel Intel
4 min read · Jul 1, 2026

Advertisement

HIGH
Threat Intel

Windows BlueHammer Flaw Exploited by Ransomware Gangs — Patch Now

CISA warns that ransomware gangs are now exploiting the BlueHammer privilege escalation vulnerability in Microsoft Defender to bypass security controls.

Runtime Rebel Intel
3 min read · Jun 30, 2026
CRITICAL
Vulnerabilities

Microsoft Defender 'RoguePlanet' Zero-Day Grants SYSTEM Privileges

Analysis of 'RoguePlanet' zero-day in Microsoft Defender allowing local privilege escalation to SYSTEM, its impact, and critical patch guidance.

Runtime Rebel Intel
4 min read · Jun 10, 2026
AI Chatbot Poisoning: Defending Against Malicious Cryptojacking Links
MEDIUM
Threat Intel

AI Chatbot Poisoning: Defending Against Malicious Cryptojacking Links

Microsoft warns of threat actors manipulating AI chatbot recommendations to deliver cryptojacking malware via poisoned web search results.

Runtime Rebel Intel
3 min read · May 27, 2026
INFO
Threat Intel

Automated Endpoint Isolation in Microsoft Defender for Endpoint

Microsoft Defender for Endpoint now features automatic device isolation to block lateral movement and contain high-confidence security breaches effectively.

Runtime Rebel Intel
3 min read · May 26, 2026
Linux Vulnerabilities and Defender Zero-Days: Weekly Threat Recap
HIGH
Threat Intel

Linux Vulnerabilities and Defender Zero-Days: Weekly Threat Recap

Weekly intelligence recap covering Linux flaws, Microsoft Defender zero-days, router botnets, and supply chain compromises targeting developer toolchains.

Runtime Rebel Intel
3 min read · May 25, 2026
Microsoft Defender CVE-2026-41091 Privilege Escalation Exploited
HIGH
Vulnerabilities

Microsoft Defender CVE-2026-41091 Privilege Escalation Exploited

Microsoft warns of active exploitation of CVE-2026-41091 in Defender, a privilege escalation flaw allowing attackers to gain SYSTEM privileges on Windows.

Runtime Rebel Intel
3 min read · May 21, 2026
HIGH
Vulnerabilities

CISA KEV Update: New Microsoft Defender and Legacy Flaws Exploited

CISA adds seven vulnerabilities, including CVE-2026-41091 and CVE-2026-45498, to the Known Exploited Vulnerabilities catalog. Patch now to prevent compromise.

Runtime Rebel Intel
3 min read · May 21, 2026
CRITICAL
Vulnerabilities

CVE-2024-21338: Microsoft Defender Zero-Day Exploited by Lazarus

Microsoft patches two zero-day vulnerabilities in Defender and SmartScreen exploited by Lazarus Group for privilege escalation and malware delivery.

Runtime Rebel Intel
4 min read · May 21, 2026
MEDIUM
Threat Intel

Microsoft Defender DigiCert False Positive: Trojan:Win32/Cerdigent.A!dha

Microsoft Defender is incorrectly identifying DigiCert root certificates as the Cerdigent trojan, causing certificate removal and enterprise disruptions.

Runtime Rebel Intel
3 min read · May 3, 2026
CRITICAL
Vulnerabilities

CVE-2024-38107: Microsoft Defender BlueHammer Flaw Exploited - Patch Now

CISA orders federal agencies to patch the BlueHammer zero-day, a critical Microsoft Defender privilege escalation flaw currently under active exploitation.

Runtime Rebel Intel
4 min read · Apr 23, 2026
CRITICAL
Vulnerabilities

CVE-2024-21412: Microsoft Defender Zero-Day Exploitation and Analysis

Analysis of a Microsoft Defender zero-day vulnerability used to extract NTLM hashes from the SAM database and achieve system-level privileges.

Runtime Rebel Intel
3 min read · Apr 23, 2026
HIGH
Vulnerabilities

CVE-2026-33825: Microsoft Defender Access Control Exploit Analysis

CISA adds CVE-2026-33825 to the KEV catalog following active exploitation of Microsoft Defender's access control mechanisms. Learn how to secure your systems.

Runtime Rebel Intel
4 min read · Apr 23, 2026
Microsoft Defender Binaries Exploited as Attack Tools
MEDIUM
Threat Intel

Microsoft Defender Binaries Exploited as Attack Tools

Security researchers have identified methods to subvert Microsoft Defender binaries for malicious code execution and EDR bypass. Learn how to defend.

Runtime Rebel Intel
3 min read · Apr 22, 2026
Microsoft Defender Zero-Days BlueHammer and RedSun Actively Exploited
CRITICAL
Vulnerabilities

Microsoft Defender Zero-Days BlueHammer and RedSun Actively Exploited

Huntress warns of active exploitation of three Microsoft Defender vulnerabilities, including BlueHammer and RedSun, allowing for privilege escalation.

Runtime Rebel Intel
4 min read · Apr 17, 2026
Microsoft Defender Zero-Day and 17-Year-Old Excel RCE Exploitation
HIGH
Threat Intel

Microsoft Defender Zero-Day and 17-Year-Old Excel RCE Exploitation

Analysis of recent threats including a Microsoft Defender zero-day, SonicWall brute-force campaigns, and critical RCE in legacy Microsoft Excel components.

Runtime Rebel Intel
4 min read · Apr 16, 2026
EngageLab SDK Vulnerability: Protecting Crypto Wallets from Sandbox Bypass
HIGH
Vulnerabilities

EngageLab SDK Vulnerability: Protecting Crypto Wallets from Sandbox Bypass

A flaw in EngageLab SDK exposed 50 million Android users to data theft. Learn how attackers bypass the Android sandbox to access private cryptocurrency keys.

Runtime Rebel Intel
4 min read · Apr 10, 2026
Cookie-Controlled PHP Web Shells Evade Detection on Linux Servers
HIGH
Threat Intel

Cookie-Controlled PHP Web Shells Evade Detection on Linux Servers

Microsoft researchers warn of stealthy PHP web shells on Linux using HTTP cookies for command execution and cron jobs for long-term persistence.

Runtime Rebel Intel
3 min read · Apr 4, 2026
HIGH
Supply Chain

Fake Next.js Job Interview Tests Backdoor Developers

Microsoft Defender discovered a campaign where malicious Next.js job interview tests backdoor developers' devices, posing a supply chain risk.

Runtime Rebel Intel
5 min read · Feb 26, 2026