Every story tagged Windows Defender, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
2 stories · open in the command center
Hackers are actively exploiting three unpatched Windows Defender vulnerabilities (BlueHammer, UnDefend, and RedSun) that were disclosed by a disgruntled security researcher, with at least one organization already compromised. Only one of the three flaws has been patched by Microsoft, leaving organizations exposed to weaponized exploit code that is publicly available on GitHub and grants attackers administrator-level access. This incident highlights critical risks in the vulnerability disclosure process and creates an urgent race between defenders and cybercriminals, requiring immediate action from IT teams to protect Windows environments.
A privilege escalation vulnerability called BlueHammer exploits Windows Defender's update process to grant attackers SYSTEM-level access on all Windows 10/11 machines, with working exploit code publicly available on GitHub and no patch currently available. The attack chains legitimate Windows components (Defender, Volume Shadow Copy, Cloud Files API) to extract and modify password hashes within minutes from a low-privilege account, leaving no traces. This represents a critical enterprise security risk that affects every Windows endpoint and server, exposing fundamental weaknesses in Microsoft's security response process.