惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Security

FBI warns of Kali365 phishing-as-a-service targeting Microsoft 365 access tokens Exclusive: New Zealand’s Alpha Group Holdings allegedly hacked Trump Mobile confirms reports of customer data exposure, unsure whether to notify those impacted Op-Ed: Why CISOs are drowning in alerts but missing the real threat Exclusive: Marketing & merchandise firm Branded Products listed by Qilin ransomware Bank on it: AI-driven cyber crime is reshaping financial sector threats Alert! National Anti-Scam Centre and ASIC warns Aussies of fake crypto trading platforms Report: AI-driven exploitation beats phishing as most popular initial access strategy Exclusive: Victorian regional newspaper alleged hacked ransomware group Exclusive: Victorian regional newspaper allegedly hacked by ransomware group State Library of NSW responding to April cyber intrusion Over 50% of API banking attacks happen in Asia-Pacific, report finds EU wins global cybersecurity competition following digital partnership with Australia Report: Rapid7 warns AI-driven attacks are accelerating vulnerability exploitation Warning! Hackers spotted exploiting poorly patched SonicWall SSL VPN appliances 7-Eleven confirms cyber attack following ShinyHunters claims Busted! Vulnerability remediation is broken, a new report says Exclusive: US fintech firm OpenAI is using for linking bank accounts to ChatGPT discloses years-long cyber incident Thales and Google Cloud launch sovereign cloud operation in Germany Cyber fraud attacks up 17%, new findings reveal Australian Signals Directorate warns of device code phishing activity targeting Microsoft 365 users US banking regulators pause cyber exams for banks to allow Mythos patching Barracuda partners with CyberCert to simplify SMB1001 compliance for Australian SMEs Op-Ed: The reality of data-centric security and Attribute-based Access Control (ABAC) Exclusive: INC Ransom claims cyber attack on Australian engineering service company Op-Ed: To pay, or not to pay… That is the existential ransomware question Cyber Insurance for Small Business: When Getting Hacked Stops Everything Operation Ramz: INTERPOL arrests 201 in MENA region cybercrime operation Exclusive: Australian College of Business Intelligence investigating Qilin ransomware claims Exclusive: Major cleaning and facility services firm confirms third-party cyber incident Sentenced: 35-year-old Melbourne man jailed over phone porting scam Exclusive: Bluize confirms cyber incident, launches investigation US cyber agency warns of active exploitation of Microsoft Exchange Server spoofing vulnerability Three scammers charged following gold bullion purchase using scam profits Exclusive: Qilin ransomware group claims responsibility for Generation Life hack Exclusive: Hospitality IT provider allegedly breached by Qilin Exclusive: Tassie hospitality group confirms CMD Organization ransomware attack 80% of Aussies organisations face identity attacks, survey finds British Airways allegedly breached as hackers claim to have stolen pilot data Q&A with Adam Meyers: “It's going to be an absolute bloodbath.” Act now! Cisco patches ‘perfect 10’ Cisco Catalyst SD-WAN Controller vulnerability AI revolution? CVE disclosures jump by up to 500% for some vendors Report: Business email compromise attacks surged dangerously in April Kick-off! 2026 FIFA World Cup to be a prime target for scammers, cyber criminals Scope Systems confirms cyber incident, says no data loss occurred Instructure breach: ShinyHunters says ‘matter has been resolved’ Rapid7 launches Cyber GRC program to connect compliance with live risk data Australian Federal Budget 2026: The industry perspective Op-Ed: Microsoft May Patch Tuesday reveals 137 vulnerabilities Federal Budget 2026: The state of cyber security spending for the coming year OpenAI offers EU early access to its cyber security model Exclusive: Aussie firm Earth Systems listed by INC Ransom hacking group Op-Ed: Why Middle East tensions demand immediate action on OT security Aussie schools breach: Instructure boss “reaches agreement” with ShinyHunters to not release data Institute of Public Accountants members hit by data breach Union demands answers on Qantas AI plans 1 in 3 small businesses don't think they're a cyber target, new research finds Exclusive: Aussie toy distributor listed by M3rx ransomware Exclusive: Australian Computer Society investigating possible breach after ShinyHunters hack claims The industry speaks – part 2: World Password Day 2026 Aussie schools breach: The Instructure hack “transcends an isolated IT incident” Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems Microsoft the main target of AI phishing attacks, report uncovers Attackers increasingly turning to trusted security tools to compromise Aussie victims Exclusive: Champion Homes confirms customer data compromised in “cyber event” Australia, Japan commit to partnership to meet cyber security challenges & strengthen cyber defences NSW Treasury cyber incident contained, impact no longer ‘significant’ WA rental scam surge: Tenants targeted with fake $500 discount trap Aussie Information Commissioner launches Privacy Awareness Week 2026 Unregistered branded text messages to be labelled ‘Unverified’ from 1 July Exclusive: Major Australian jewellery brand confirms cyber incident Watch this! Komari server monitor tool abused by hackers Act Now! ACSC warns of active exploitation of cPanel & WHM critical vulnerability Exclusive: Kiwi electrical contractor confirms cyber attack Exclusive: Prime Properties listed as breach victim by M3rx ransomware DigiCert launches AI Trust architecture to secure agents, models, and content Winners of the 2026 Australian Cyber Awards unveiled Op-Ed: Redefining performance in the AI-powered SOC NZ council cyber attack leads to ID and financial data being exposed Alert! Wave of fake toll, parking scams impacting countries worldwide, including Australia and New Zealand Vect unveiled: Inside an emerging ransomware group’s affiliate network Exclusive: Gelatissimo confirms unauthorised access, investigates DragonForce hack claims Aussie ice-cream franchise Gelatissimo suffers alleged hack by DragonForce Anthropic Mythos: The model, the myth and the mundane​ Report: Aussie small businesses doing it tough as job scams double, losses rise Cyber attacks on medical devices pose ‘significant’ impact on real-life patient care Twisted Firestarter! Aussie, US, and UK cyber agencies warn of Cisco malware campaign Generation Life informs customers of “cyber incident” as owner shares incident with ASX CBA launches new scam-finding AI agent
Microsoft patches pair of Microsoft Defender zero-days following active exploitation
david.hollin · 2026-05-22 · via Security

The US cyber agency warns of hackers targeting Defender flaws that could disable malware protection and grant SYSTEM privileges.

Microsoft and the United States’ chief cyber agency have warned of active exploitation of a pair of zero-day vulnerabilities in Microsoft Defender, the default security platform on many personal and business computers.

CVE-2026-41091 is an elevation of privilege vulnerability that was first disclosed on 20 May and has a CVSS score of 7.8, making it a high-severity flaw. This vulnerability impacts versions 1.1.26030.3008 and earlier, but has been addressed in later versions.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

According to Microsoft’s Executive Summary, “improper link resolution before file access (‘link following’) in Microsoft Defender” could allow an authorised attacker to elevate privileges locally.

CVE-2026-45498, on the other hand, has a CVSS score of only 4, making it a medium-severity issue. This is a denial-of-service vulnerability that could cause Microsoft Defender’s Antimalware Platform to stop working entirely. This flaw is present in versions 4.18.26030.3011 and earlier.

Microsoft has released a pair of emergency patches that, in theory, should be automatically deployed, but the company has warned customers to verify the updates.

“Best practices recommend that customers regularly verify whether software distribution, such as the automatic deployment of Microsoft Malware Protection Engine updates and malware definitions, is working as expected in their environment,” Microsoft said in its advisory.

The two vulnerabilities relate to a pair of exploits published in April by a GitHub user known as Nightmare Eclipse: RedSun (CVE-2026-41091) and UnDefend (CVE-2026-45498).

Speaking of RedSun, Eclipse said on 16 April that they would normally “just drop the PoC code and let people figure it out. But I can’t for this one, it’s way too funny.”

“When Windows Defender realises that a malicious file has a cloud tag, for whatever stupid and hilarious reason, the antivirus that’s supposed to protect decides that it is a good idea to just rewrite the file it found again to its original location. The PoC abuses this behaviour to overwrite system files and gain administrative privileges,” Eclipse said.

“I think antimalware products are supposed to remove malicious files not be sure they are there but that’s just me.”

As to the UnDefend exploit, Eclipse chose not to publish in its entirety.

“Now funnily enough, I found a way to lie to the EDR web console to show that defender is up and running with the latest update even if it’s not,” Eclipse said.

“I was thinking about publishing the code but after thinking about it, it will cause waaay too much damage so I think I’ll keep that stuff stashed for now.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

Tags:

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.