• News/
  • https://www.bleepingcomputer.com/news/security/recently-leaked-windows-zero-days-now-exploited-in-attacks/

Recently leaked Windows zero-days now exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Apr 17, 2026
·
Updated

Threat actors are exploiting three recently disclosed Windows security vulnerabilities in attacks aimed at gaining SYSTEM or elevated administrator permissions. Since the start of the month, a security researcher known as "Chaotic Eclipse" or "Nightmare-Eclipse" has published proof-of-concept exploit code for all three security issues in protest to how Microsoft's Security Response Center (MSRC) handled the disclosure process. Two of the vulnerabilities (dubbed BlueHammer and RedSun) are Microsoft Defender local privilege escalation (LPE) flaws, while the third (known as UnDefend) can be exploited as a standard user to block Microsoft Defender definition updates. At the time of the leak, the security flaws these exploits targeted were considered zero-days by Microsoft's definition, since they had no official patches or updates to address them. On Thursday, Huntress Labs security researchers reported seeing all three zero-day exploits deployed in the wild, with the BlueHammer vulnerability being exploited since April 10. They also spotted UnDefend and RedSun exploits on a Windows device that was breached using a compromised SSLVPN user, in attacks showing evidence of "hands-on-keyboard threat actor activity." "The Huntress SOC is observing the use of Nightmare-Eclipse's BlueHammer, RedSun, and UnDefend exploitation techniques," the researchers said.

While Microsoft is now tracking the BlueHammer vulnerability as CVE-2026-33825 and has patched it in the April 2026 security up...

Read full article

Affected Software

3 affected components
Microsoft Defender
Microsoft Windows=Windows 10, =Windows 11
Microsoft Windows Server
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities are being exploited according to the article?

The article discusses three recently disclosed Windows security vulnerabilities that are being actively exploited.

2

What is the goal of the attacks exploiting these vulnerabilities?

The goal of these attacks is to gain SYSTEM or elevated administrator permissions.

3

Who disclosed the vulnerabilities mentioned in the article?

The vulnerabilities were disclosed by a security researcher known as 'Chaotic Eclipse'.

4

Which versions of Windows are affected by these vulnerabilities?

The affected versions include Windows 10, Windows 11, and Windows Server.

5

What measures are suggested to protect against these vulnerabilities?

The article suggests updating affected software and employing security practices to mitigate risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203