Tag: RedSun

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: RedSun exploits Microsoft Defender real-time protection

Cybersecurity Threat Advisory: RedSun exploits Microsoft Defender real-time protection

A new proof of concept (PoC), RedSun, exploits Windows devices running Microsoft Defender real‑time protection on Windows 10, Windows 11, and Windows Server 2019+. It abuses Defender’s handling of cloud‑tagged files to achieve local privilege escalation to SYSTEM. Read this...

/ May 15, 2026