惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
大猫的无限游戏
大猫的无限游戏
J
Java Code Geeks
罗磊的独立博客
雷峰网
雷峰网
G
Google Developers Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
爱范儿
爱范儿
B
Blog RSS Feed
腾讯CDC
Apple Machine Learning Research
Apple Machine Learning Research
D
Docker
Recent Announcements
Recent Announcements
T
Tailwind CSS Blog
博客园 - 聂微东
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Vercel News
Vercel News
小众软件
小众软件
人人都是产品经理
人人都是产品经理
云风的 BLOG
云风的 BLOG
IT之家
IT之家
Blog — PlanetScale
Blog — PlanetScale
I
InfoQ
S
SegmentFault 最新的问题

Forbes - Consumer Tech

This Unhackable Quantum Navigation System Is The Size Of A Loaf Of Bread Apple At 50 — A Leadership Shift And An AR Future We Are Under-Investing In Robotics ... 90% Of Humanoid Robots Are Made In China Ditch The Apple White: Beats Expands Colorful Cable Line-Up With New 10-Foot Option Satechi’s New ChargeView 140W Desktop GaN Charger With Real-Time Display The Hasselblad In Your Pocket: Oppo’s Find X9 Ultra Challenges The Galaxy S26 Ultra There's No Such Thing As Brain Honey How AI Agents Could Rebuild Fashion’s Visual Production Layer QClaw Goes Global. The Agent Built Itself In 5 Days Apple’s Tim Cook Exit Hides A $4 Trillion Agentic AI Power Move EZQuest Reveals A New Line Of Pro Series USB-C Hubs For MacBook Neo Samsung Galaxy Z TriFold 2 Already In The Works, Report Claims Apple Revealed New Siri Release Date For iPhone, Latest Report Claims How Arcani’s HARK Is Designed For Modern Battlefield Acoustics The Newest Trend In Tech Embraces Femininity And Fun Samsung’s 75R95H Ushers In A New World Of LCD TVs New Apple iPhone Fold Design Pushes Smartphone Rivals To Go Wider And Taller iPhone 18 Pro Report: Four New Colors Leak As Apple Cancels Popular Shade Nothing’s Design-Led Strategy: Carl Pei Reveals The Tech Brand’s Philosophy iOS 26.5 Release Date: When To Expect Your iPhone Messaging Upgrade Google Pixel And Highsnobiety Build A Talent Pipeline For Fashion Android Circuit: Samsung Raises Galaxy Prices, Oppo Pad Mini Teased, Microsoft Closing Outlook App Apple Loop: iPhone Fold Launch Dates, iPad Air Upgrade, iPhone 18 Pro Specs Comcast $117.5 Million Breach Settlement — Are You Eligible? Amazfit Cheetah 2 Pro Takes Aim At The Garmin Audience Disney’s Launches ‘Infinity Vision’ Certification For Premium Theaters SoundPeats Reveals New Air6 HS Semi-Open Wireless Earbuds Amazon’s $11.57 Billion Leap Into Space: A Challenge To Starlink Meta Quest 3 Hit With $100 Price Increase Backblaze Stops Backing Up Dropbox And Others—Calls It An Improvement
2 New Microsoft Defender Zero-Days Exploited—Patch Now Ro...
Davey Winder · 2026-05-21 · via Forbes - Consumer Tech
Zero-Day in red under a magnifying glass amongst green binary code.

Microsoft and CISA confirm Defender zero-days exploited in the wild.

Getty

Microsoft has started rolling out an emergency security update for Microsoft Defender after the U.S. Cybersecurity and Infrastructure Security Agency confirmed that two new zero-day vulnerabilities are already being exploited in the wild by attackers. One is a privilege escalation problem that affects the Microsoft Malware Protection Engine, while the other has a broader scope, affecting Microsoft Defender Antimalware Platform and Microsoft's System Center Endpoint Protection. Here’s what you need to know about CVE-2026-41091 and CVE-2026-45498, including the mitigation measures confirmed by Microsoft.

ForbesHow To Mitigate The Microsoft Windows BitLocker YellowKey USB 0-Day

Microsoft Defender CVE-2026-41091 And CVE-2026-45498 Zero-Days Explained

Microsoft has now confirmed two new Microsoft Defender zero-days that it said had been exploited. This exploitation was confirmed by CISA, which has added the security flaws to its Known Exploited Vulnerabilities catalog and given federal agencies until June 3 to ensure mitigation measures are in place.

It has not been the greatest few days for Microsoft on the security front, especially regarding zero-day vulnerabilities. Microsoft Exchange users have been warned about an active zero-day exploit demanding emergency mitigation, the now infamous ‘angry hacker’ dropped another two public zero-day exploits, and the Pwn2Own Berlin hacking event uncovered numerous Windows zero-days. All within the space of a week.

The first has a Common Vulnerabilities and Exposures designation of CVE-2026-41091, and Microsoft described it as a Microsoft Defender elevation of privilege vulnerability caused by an improper link resolution before file access. This zero-day affects the Microsoft Malware Protection Engine up to version 1.1.26030.3008 and could give a successful attacker SYSTEM privileges with all that entails.

The second, CVE-2026-45498, is a denial of service vulnerability impacting Microsoft Defender. Microsoft said that this affects the Defender Antimalware Platform up to version 4.18.26030.3011, along with other products that use it, including Microsoft System Center Endpoint Protection, Microsoft System Center 2012 R2 Endpoint Protection, Microsoft System Center 2012 Endpoint Protection and Microsoft Security Essentials.

ForbesMicrosoft Confirms Surprising Edge Password Security U-TurnBy Davey Winder

When adding the zero-days to the KEV Catalog database, CISA warned that “these types of vulnerabilities are frequent attack vectors for malicious cyber actors,” and accordingly gave Federal Civilian Executive Branch agencies just 14 days, starting May 20, to mitigate the threat.

“For enterprise deployments as well as end users,” Microsoft said, “the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Protection Engine are kept up to date automatically,” and as such no action is required as the update that is now rolling out will get applied without user input. However, it is worth checking that the default configuration still applies to your copy of Microsoft Defender and that automatic updating is, indeed, enabled. Microsoft has advised that users should verify installation of the update by opening the Windows Security program, selecting Virus & threat protection and then Protection Updates.