<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Undefend on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/undefend/</link><description>Recent content in Undefend on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 19 Apr 2026 10:57:14 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/undefend/index.xml" rel="self" type="application/rss+xml"/><item><title>RedSun and UnDefend: Two Unpatched Windows Defender Zero-Days</title><link>https://hackingpassion.com/redsun-undefend-defender-zero-days/</link><pubDate>Sun, 19 Apr 2026 10:57:14 +0200</pubDate><guid>https://hackingpassion.com/redsun-undefend-defender-zero-days/</guid><description>&lt;p>Two unpatched Windows Defender zero-days have been actively exploited since &lt;strong>April 16th&lt;/strong>, and both of them work on fully patched &lt;strong>Windows 10&lt;/strong>, &lt;strong>Windows 11&lt;/strong>, and &lt;strong>Server 2019&lt;/strong> and later, including machines that installed this month&amp;rsquo;s Patch Tuesday updates. One of them makes Defender write the attacker&amp;rsquo;s payload into &lt;strong>System32&lt;/strong> by itself, then stands back and lets Windows run it as &lt;strong>SYSTEM&lt;/strong>. The other blocks Defender from receiving any new virus definitions and lies to the EDR management console about it, showing green checkmarks on machines that are already fully compromised. 😏&lt;/p></description></item></channel></rss>