<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Microsoft Defender</title><description>Cybersecurity articles tagged #Microsoft Defender on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Microsoft Defender Blocks Legitimate Google Search Links</title><link>https://runtimerebel.com/blog/microsoft-defender-blocks-legitimate-google-search-links</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-defender-blocks-legitimate-google-search-links</guid><description>Microsoft Defender for Office 365&apos;s Safe Links feature is incorrectly flagging legitimate Google search results as malicious, blocking user access and generating alerts.</description><pubDate>Wed, 02 Sep 2026 12:25:15 GMT</pubDate><category>Microsoft Defender</category><category>Office 365</category><category>Safe Links</category><category>False Positive</category><category>Google Search</category></item><item><title>Weaponizing Defender&apos;s BTR.sys to Disable Security Software</title><link>https://runtimerebel.com/blog/weaponizing-defender-s-btr-sys-to-disable-security-software</link><guid isPermaLink="true">https://runtimerebel.com/blog/weaponizing-defender-s-btr-sys-to-disable-security-software</guid><description>Attackers can weaponize a legitimate Microsoft Defender driver to delete security software at boot, impacting Windows 7-11.</description><pubDate>Sat, 22 Aug 2026 08:17:55 GMT</pubDate><category>Microsoft Defender</category><category>Kernel Driver</category><category>Defense Evasion</category><category>Check Point Research</category><category>Windows Security</category></item><item><title>ShieldBreak: Windows Zero-Day EoP via Microsoft Defender</title><link>https://runtimerebel.com/blog/shieldbreak-windows-zero-day-eop-via-microsoft-defender</link><guid isPermaLink="true">https://runtimerebel.com/blog/shieldbreak-windows-zero-day-eop-via-microsoft-defender</guid><description>Security researcher Nightmare Eclipse released &apos;ShieldBreak,&apos; a Windows zero-day exploit enabling privilege escalation via Microsoft Defender.</description><pubDate>Thu, 13 Aug 2026 09:03:52 GMT</pubDate><category>Nightmare Eclipse</category><category>Microsoft Defender</category><category>Windows</category><category>Privilege Escalation</category><category>Zero-Day</category></item><item><title>CVE-2026-50656: Microsoft Defender Privilege Escalation – Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-50656-microsoft-defender-privilege-escalation-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-50656-microsoft-defender-privilege-escalation-patch-now</guid><description>Microsoft patches &apos;RoguePlanet&apos; vulnerability, CVE-2026-50656, in Defender&apos;s Malware Protection Engine, enabling privilege escalation. Update immediately.</description><pubDate>Thu, 09 Jul 2026 11:03:10 GMT</pubDate><category>CVE-2026-50656</category><category>Microsoft Defender</category><category>Privilege Escalation</category><category>RoguePlanet</category><category>Malware Protection Engine</category><category>Endpoint Security</category></item><item><title>Microsoft Defender RoguePlanet Zero-Day Vulnerability Patching Guide</title><link>https://runtimerebel.com/blog/microsoft-defender-rogueplanet-zero-day-vulnerability-patching-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-defender-rogueplanet-zero-day-vulnerability-patching-guide</guid><description>Microsoft addresses the RoguePlanet zero-day in Defender. Learn about the exploitation risks, detection methods, and how to update systems effectively.</description><pubDate>Thu, 09 Jul 2026 07:41:23 GMT</pubDate><category>Microsoft Defender</category><category>RoguePlanet</category><category>Zero-Day</category><category>Windows Security</category><category>Endpoint Protection</category></item><item><title>CVE-2026-33825: BlueHammer Zero-Day in Microsoft Defender Exploited by Ransomware</title><link>https://runtimerebel.com/blog/cve-2026-33825-bluehammer-zero-day-in-microsoft-defender-exploited-by-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-33825-bluehammer-zero-day-in-microsoft-defender-exploited-by-ransomware</guid><description>Analysis of the BlueHammer zero-day, CVE-2026-33825, in Microsoft Defender, actively exploited by ransomware groups. Learn detection and mitigation strategies.</description><pubDate>Wed, 01 Jul 2026 05:40:54 GMT</pubDate><category>CVE-2026-33825</category><category>BlueHammer</category><category>Microsoft Defender</category><category>Ransomware</category><category>Zero-Day</category><category>Vulnerability Exploitation</category></item><item><title>Windows BlueHammer Flaw Exploited by Ransomware Gangs — Patch Now</title><link>https://runtimerebel.com/blog/windows-bluehammer-flaw-exploited-by-ransomware-gangs-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-bluehammer-flaw-exploited-by-ransomware-gangs-patch-now</guid><description>CISA warns that ransomware gangs are now exploiting the BlueHammer privilege escalation vulnerability in Microsoft Defender to bypass security controls.</description><pubDate>Tue, 30 Jun 2026 09:16:59 GMT</pubDate><category>Microsoft Defender</category><category>BlueHammer</category><category>CISA KEV</category><category>Ransomware</category><category>Privilege Escalation</category></item><item><title>Microsoft Defender &apos;RoguePlanet&apos; Zero-Day Grants SYSTEM Privileges</title><link>https://runtimerebel.com/blog/microsoft-defender-rogueplanet-zero-day-grants-system-privileges</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-defender-rogueplanet-zero-day-grants-system-privileges</guid><description>Analysis of &apos;RoguePlanet&apos; zero-day in Microsoft Defender allowing local privilege escalation to SYSTEM, its impact, and critical patch guidance.</description><pubDate>Wed, 10 Jun 2026 01:03:15 GMT</pubDate><category>Microsoft Defender</category><category>RoguePlanet</category><category>Privilege Escalation</category><category>Zero-Day</category><category>Windows Security</category></item><item><title>AI Chatbot Poisoning: Defending Against Malicious Cryptojacking Links</title><link>https://runtimerebel.com/blog/ai-chatbot-poisoning-defending-against-malicious-cryptojacking-links</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-chatbot-poisoning-defending-against-malicious-cryptojacking-links</guid><description>Microsoft warns of threat actors manipulating AI chatbot recommendations to deliver cryptojacking malware via poisoned web search results.</description><pubDate>Wed, 27 May 2026 09:16:19 GMT</pubDate><category>Cryptojacking</category><category>AI Security</category><category>Social Engineering</category><category>Microsoft Defender</category><category>Malware Delivery</category></item><item><title>Automated Endpoint Isolation in Microsoft Defender for Endpoint</title><link>https://runtimerebel.com/blog/automated-endpoint-isolation-in-microsoft-defender-for-endpoint</link><guid isPermaLink="true">https://runtimerebel.com/blog/automated-endpoint-isolation-in-microsoft-defender-for-endpoint</guid><description>Microsoft Defender for Endpoint now features automatic device isolation to block lateral movement and contain high-confidence security breaches effectively.</description><pubDate>Tue, 26 May 2026 13:11:01 GMT</pubDate><category>Microsoft Defender</category><category>Endpoint Security</category><category>Lateral Movement</category><category>Automated Response</category><category>Mde</category></item><item><title>Linux Vulnerabilities and Defender Zero-Days: Weekly Threat Recap</title><link>https://runtimerebel.com/blog/linux-vulnerabilities-and-defender-zero-days-weekly-threat-recap</link><guid isPermaLink="true">https://runtimerebel.com/blog/linux-vulnerabilities-and-defender-zero-days-weekly-threat-recap</guid><description>Weekly intelligence recap covering Linux flaws, Microsoft Defender zero-days, router botnets, and supply chain compromises targeting developer toolchains.</description><pubDate>Mon, 25 May 2026 16:48:57 GMT</pubDate><category>Linux Security</category><category>Microsoft Defender</category><category>Supply Chain Security</category><category>Botnets</category></item><item><title>Microsoft Defender CVE-2026-41091 Privilege Escalation Exploited</title><link>https://runtimerebel.com/blog/microsoft-defender-cve-2026-41091-privilege-escalation-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-defender-cve-2026-41091-privilege-escalation-exploited</guid><description>Microsoft warns of active exploitation of CVE-2026-41091 in Defender, a privilege escalation flaw allowing attackers to gain SYSTEM privileges on Windows.</description><pubDate>Thu, 21 May 2026 13:16:31 GMT</pubDate><category>CVE-2026-41091</category><category>Microsoft Defender</category><category>Privilege Escalation</category><category>Active Exploitation</category></item><item><title>CISA KEV Update: New Microsoft Defender and Legacy Flaws Exploited</title><link>https://runtimerebel.com/blog/cisa-kev-update-new-microsoft-defender-and-legacy-flaws-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-update-new-microsoft-defender-and-legacy-flaws-exploited</guid><description>CISA adds seven vulnerabilities, including CVE-2026-41091 and CVE-2026-45498, to the Known Exploited Vulnerabilities catalog. Patch now to prevent compromise.</description><pubDate>Thu, 21 May 2026 09:16:49 GMT</pubDate><category>CVE-2026-41091</category><category>CVE-2026-45498</category><category>Microsoft Defender</category><category>CISA KEV</category><category>Legacy Systems</category></item><item><title>CVE-2024-21338: Microsoft Defender Zero-Day Exploited by Lazarus</title><link>https://runtimerebel.com/blog/cve-2024-21338-microsoft-defender-zero-day-exploited-by-lazarus</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-21338-microsoft-defender-zero-day-exploited-by-lazarus</guid><description>Microsoft patches two zero-day vulnerabilities in Defender and SmartScreen exploited by Lazarus Group for privilege escalation and malware delivery.</description><pubDate>Thu, 21 May 2026 09:15:26 GMT</pubDate><category>CVE-2024-21338</category><category>CVE-2024-21412</category><category>Lazarus Group</category><category>Microsoft Defender</category><category>Zero-Day</category></item><item><title>Microsoft Defender DigiCert False Positive: Trojan:Win32/Cerdigent.A!dha</title><link>https://runtimerebel.com/blog/microsoft-defender-digicert-false-positive-trojan-win32-cerdigent-a-dha</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-defender-digicert-false-positive-trojan-win32-cerdigent-a-dha</guid><description>Microsoft Defender is incorrectly identifying DigiCert root certificates as the Cerdigent trojan, causing certificate removal and enterprise disruptions.</description><pubDate>Sun, 03 May 2026 20:17:15 GMT</pubDate><category>Microsoft Defender</category><category>Digicert</category><category>False Positive</category><category>Trojan Win32 Cerdigent a Dha</category><category>Certificate Security</category></item><item><title>CVE-2024-38107: Microsoft Defender BlueHammer Flaw Exploited - Patch Now</title><link>https://runtimerebel.com/blog/cve-2024-38107-microsoft-defender-bluehammer-flaw-exploited-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-38107-microsoft-defender-bluehammer-flaw-exploited-patch-now</guid><description>CISA orders federal agencies to patch the BlueHammer zero-day, a critical Microsoft Defender privilege escalation flaw currently under active exploitation.</description><pubDate>Thu, 23 Apr 2026 12:30:07 GMT</pubDate><category>CVE-2024-38107</category><category>BlueHammer</category><category>Microsoft Defender</category><category>CISA KEV</category><category>Zero-Day</category></item><item><title>CVE-2024-21412: Microsoft Defender Zero-Day Exploitation and Analysis</title><link>https://runtimerebel.com/blog/cve-2024-21412-microsoft-defender-zero-day-exploitation-and-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-21412-microsoft-defender-zero-day-exploitation-and-analysis</guid><description>Analysis of a Microsoft Defender zero-day vulnerability used to extract NTLM hashes from the SAM database and achieve system-level privileges.</description><pubDate>Thu, 23 Apr 2026 08:43:18 GMT</pubDate><category>CVE-2024-21412</category><category>Microsoft Defender</category><category>Zero-Day</category><category>Privilege Escalation</category><category>NTLM Stealing</category></item><item><title>CVE-2026-33825: Microsoft Defender Access Control Exploit Analysis</title><link>https://runtimerebel.com/blog/cve-2026-33825-microsoft-defender-access-control-exploit-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-33825-microsoft-defender-access-control-exploit-analysis</guid><description>CISA adds CVE-2026-33825 to the KEV catalog following active exploitation of Microsoft Defender&apos;s access control mechanisms. Learn how to secure your systems.</description><pubDate>Thu, 23 Apr 2026 05:05:39 GMT</pubDate><category>CVE-2026-33825</category><category>Microsoft Defender</category><category>CISA KEV</category><category>Access Control</category><category>Windows Security</category></item><item><title>Microsoft Defender Binaries Exploited as Attack Tools</title><link>https://runtimerebel.com/blog/microsoft-defender-binaries-exploited-as-attack-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-defender-binaries-exploited-as-attack-tools</guid><description>Security researchers have identified methods to subvert Microsoft Defender binaries for malicious code execution and EDR bypass. Learn how to defend.</description><pubDate>Wed, 22 Apr 2026 08:44:37 GMT</pubDate><category>Microsoft Defender</category><category>Living-off-the-Land</category><category>MpCmdRun Exe</category><category>LockBit</category><category>EDR Bypass</category></item><item><title>Microsoft Defender Zero-Days BlueHammer and RedSun Actively Exploited</title><link>https://runtimerebel.com/blog/microsoft-defender-zero-days-bluehammer-and-redsun-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-defender-zero-days-bluehammer-and-redsun-actively-exploited</guid><description>Huntress warns of active exploitation of three Microsoft Defender vulnerabilities, including BlueHammer and RedSun, allowing for privilege escalation.</description><pubDate>Fri, 17 Apr 2026 16:25:02 GMT</pubDate><category>Microsoft Defender</category><category>BlueHammer</category><category>Redsun</category><category>Undefend</category><category>Privilege Escalation</category><category>Zero-Day</category></item><item><title>Microsoft Defender Zero-Day and 17-Year-Old Excel RCE Exploitation</title><link>https://runtimerebel.com/blog/microsoft-defender-zero-day-and-17-year-old-excel-rce-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-defender-zero-day-and-17-year-old-excel-rce-exploitation</guid><description>Analysis of recent threats including a Microsoft Defender zero-day, SonicWall brute-force campaigns, and critical RCE in legacy Microsoft Excel components.</description><pubDate>Thu, 16 Apr 2026 16:38:11 GMT</pubDate><category>Microsoft Defender</category><category>SonicWall</category><category>Excel</category><category>Zero-Day</category><category>RCE</category></item><item><title>EngageLab SDK Vulnerability: Protecting Crypto Wallets from Sandbox Bypass</title><link>https://runtimerebel.com/blog/engagelab-sdk-vulnerability-protecting-crypto-wallets-from-sandbox-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/engagelab-sdk-vulnerability-protecting-crypto-wallets-from-sandbox-bypass</guid><description>A flaw in EngageLab SDK exposed 50 million Android users to data theft. Learn how attackers bypass the Android sandbox to access private cryptocurrency keys.</description><pubDate>Fri, 10 Apr 2026 00:40:05 GMT</pubDate><category>EngageLab SDK</category><category>Android Security</category><category>Crypto Wallet Vulnerability</category><category>Microsoft Defender</category><category>Mobile Security</category></item><item><title>Cookie-Controlled PHP Web Shells Evade Detection on Linux Servers</title><link>https://runtimerebel.com/blog/cookie-controlled-php-web-shells-evade-detection-on-linux-servers</link><guid isPermaLink="true">https://runtimerebel.com/blog/cookie-controlled-php-web-shells-evade-detection-on-linux-servers</guid><description>Microsoft researchers warn of stealthy PHP web shells on Linux using HTTP cookies for command execution and cron jobs for long-term persistence.</description><pubDate>Sat, 04 Apr 2026 00:36:49 GMT</pubDate><category>Php Web Shell</category><category>Linux Security</category><category>Microsoft Defender</category><category>Persistence Mechanisms</category><category>Cron Job Exploitation</category></item><item><title>Fake Next.js Job Interview Tests Backdoor Developers</title><link>https://runtimerebel.com/blog/fake-next-js-job-interview-tests-backdoor-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-next-js-job-interview-tests-backdoor-developers</guid><description>Microsoft Defender discovered a campaign where malicious Next.js job interview tests backdoor developers&apos; devices, posing a supply chain risk.</description><pubDate>Thu, 26 Feb 2026 00:33:15 GMT</pubDate><category>Next Js</category><category>Software Developers</category><category>Supply Chain Attack</category><category>Malware</category><category>Backdoor</category><category>Social Engineering</category><category>Job Scams</category><category>Microsoft Defender</category></item></channel></rss>