20th April – Threat Intelligence Report
Multiple zero-days (BlueHammer, RedSun, UnDefend) in Microsoft Defender are being actively exploited, requiring immediate patching.
Vergleich von 20. April 2026 mit dem Vortag 13. April 2026.
Multiple zero-days (BlueHammer, RedSun, UnDefend) in Microsoft Defender are being actively exploited, requiring immediate patching.
The vulnerability can be triggered by an unprivileged user via the keyrings API, enabling local privilege escalation.
Describes active exploitation of multiple unpatched Windows zero-days (RedSun, UnDefend, BlueHammer) in the wild, indicating immediate risk beyond a standard patch advisory.
Describes an active attack campaign exploiting zero-day vulnerabilities in Windows systems, indicating immediate defensive action is required.
Describes an active campaign where attackers are specifically abusing external Teams access for helpdesk impersonation, a novel social engineering vector.
Highlights emergency, out-of-band updates to resolve critical stability or security issues introduced by a recent patch cycle.
Provides insight into the TTPs of a threat actor using SystemBC malware for C2 and lateral movement within a Windows domain environment.
Keine Änderungen in dieser Kategorie.
Keine Änderungen in dieser Kategorie.
The alert highlights the specific risk of SSRF being used to probe internal services and cloud metadata, which is a critical attack path beyond just patching.
This vulnerability allows unauthenticated attackers with adjacent network access to achieve SYSTEM privileges through certificate validation flaws.
Describes a specific attack vector where malware could leverage local admin rights to disable detection, moving beyond a simple patch notification.