Advertisement · 728 × 90
#
Hashtag

#microsoftDefender

Advertisement · 728 × 90
Preview
Microsoft Defender suffit-il vraiment en 2026 ? Ce que Microsoft ne vous dit pas (ou presque) Microsoft affirme que Defender suffit pour protéger Windows 11. C'est vrai… en partie. On analyse ce que cache ce discours et quand un antivirus tiers reste utile.

🛡️ Microsoft Defender suffit-il vraiment en 2026 ? Ce que Microsoft ne vous dit pas (ou presque)

👉 www.justgeek.fr/microsoft-de...

#MicrosoftDefender #SécuritéWindows #Antivirus #Windows11 #Microsoft

2 0 0 0
Original post on infosec.exchange

🔐 Just shipped a fix for the April 2026 Windows update (KB5083769) that flags unsigned RDP files as "Unknown Publisher".
If you manage RDP shortcuts via Intune and your users are suddenly seeing red security warnings — here's a complete solution:
✅ Self-signed code signing cert (no PKI required) […]

1 0 0 0
Post image

Zero-day su Microsoft Defender senza patch: exploit pubblici usati in attacchi reali

📌 Link all'articolo : www.redhotcyber.com/post/zero-da...

A cura di Chiara Nardini

#redhotcyber #news #cybersecurity #hacking #malware #zeroDay #microsoftDefender #vulnerabilita

0 0 0 0
Microsoft Defender zero-day vulnerability CVE-2026-33825, RedSun exploit, UnDefend tool, Chaotic Eclipse researcher, Nightmare Eclipse GitHub, SYSTEM privilege escalation, MpSvc.dll, TieringEngineService.exe, cldapi.dll, Windows 10 Windows 11 Windows Server 2019, NTFS junction point attack, CfRegisterSyncRoot SERIOUSLYMSFT, opportunistic lock, EICAR test string, Huntress SSLVPN intrusion, MSRC credit dispute, Patch Tuesday April 2026, out-of-band patch, Tamper Protection, Microsoft Defender ゼロデイ脆弱性, 権限昇格, 定義更新プロセス, ジャンクションポイント攻撃, クラウドファイル同期, MSRCクレジット剥奪, 実攻撃確認, Zen Dodd, Yuanpei Xu, Will Dormann Tharros, Ampcus Cyber, サイバーセキュリティ, 脆弱性開示プロセス, バグバウンティ, ゼロデイエクスプロイト

Microsoft Defender zero-day vulnerability CVE-2026-33825, RedSun exploit, UnDefend tool, Chaotic Eclipse researcher, Nightmare Eclipse GitHub, SYSTEM privilege escalation, MpSvc.dll, TieringEngineService.exe, cldapi.dll, Windows 10 Windows 11 Windows Server 2019, NTFS junction point attack, CfRegisterSyncRoot SERIOUSLYMSFT, opportunistic lock, EICAR test string, Huntress SSLVPN intrusion, MSRC credit dispute, Patch Tuesday April 2026, out-of-band patch, Tamper Protection, Microsoft Defender ゼロデイ脆弱性, 権限昇格, 定義更新プロセス, ジャンクションポイント攻撃, クラウドファイル同期, MSRCクレジット剥奪, 実攻撃確認, Zen Dodd, Yuanpei Xu, Will Dormann Tharros, Ampcus Cyber, サイバーセキュリティ, 脆弱性開示プロセス, バグバウンティ, ゼロデイエクスプロイト

Microsoft Defenderのゼロデイ脆弱性を公開した研究者Chaotic Eclipseが、4月14日のパッチ修正からわずか2日後にPoCを2本追加投下しました。

RedSunは最新パッチ済みのDefenderを攻撃経路に変え、UnDefendはDefender自体を機能停止させます。

Huntressは両方とも既に実攻撃で使用されていることを確認しました。

youtu.be/PRNtG8ZkE3s

#MicrosoftDefender #ゼロデイ #サイバーセキュリティ
Defender weaponized again.

0 0 0 0
Reduce response time and uncertainty. #MicrosoftDefender #DefenderXDR #ThreatHunting #CyberSecurity
Reduce response time and uncertainty. #MicrosoftDefender #DefenderXDR #ThreatHunting #CyberSecurity Stay ahead of real-world threats without overwhelming your team using Microsoft Defender Experts for XDR. Offload high-severity incidents, gain full visibility into every investigation, and follow clear, guided remediation steps so you can contain attacks quickly and confidently, day or night. Extend your security operations with always-on managed detection and response and proactive threat hunting, so you can uncover hidden risks early, stop threats threats they spread, and strengthen your defenses to prevent future attacks. Maynald Savatdy, Microsoft Defender Expert, shows how to detect, contain, and hunt threats across your environment with support from human experts. ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics #MicrosoftDefender #DefenderXDR #ThreatHunting #CyberSecurity

Reduce response time and uncertainty. #MicrosoftDefender #DefenderXDR #ThreatHunting #CyberSecurity: Stay ahead of real-world threats without overwhelming your team using Microsoft Defender Experts for XDR. Offload high-severity… MSFTMechanics #MicrosoftDefender #CyberSecurity #ThreatHunting

0 0 0 0
Preview
New Microsoft Defender “RedSun” zero-day PoC grants SYSTEM privileges A researcher known as "Chaotic Eclipse" has published a proof-of-concept exploit for a second Microsoft Defender zero-day, dubbed "RedSun," in the past two weeks, protesting how the company works with cybersecurity researchers. [...]

New #MicrosoftDefender#RedSun” zero-day PoC grants SYSTEM privileges

www.bleepingcomputer.com/news/microsoft/new-micro...

#Microsoft #Windows #cybersecurity

0 0 0 0
Preview
New Defender XDR permission for viewing and downloading quarantined emails A new Defender XDR RBAC permission gives administrators read and download access to quarantined emails without granting broader access to email content.

Microsoft is rolling out a new Defender XDR RBAC permission for read access to quarantined emails. Without it, IT Security members lose the ability to preview or download quarantined email content. #MicrosoftDefender #ITSecurity

1 0 0 0
Preview
Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild A security researcher using the aliases Chaotic Eclipse and Nightmare Eclipse released two new proof-of-concept privilege-escalation exploits for Microsoft Defender, named RedSun and UnDefend, after earlier publishing BlueHammer. Huntress observed all three techniques used in the wild, with attackers dropping renamed exploit files into users' Pictures and Downloads folders, mapping privileges and harvesting credentials, and Microsoft may need to issue an out-of-band patch. #RedSun #UnDefend

Three Microsoft Defender zero-day exploits—BlueHammer, RedSun, and UnDefend—are actively exploited in the wild, enabling privilege escalation and blocking defenses. Microsoft may need an urgent patch. #RedSun #MicrosoftDefender #USA

0 0 0 0
Preview
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched Huntress is warning that threat actors are exploiting three recently disclosed security flaws in Microsoft Defender to gain elevated privileges in compromised systems. The activity involves the exploitation of three vulnerabilities that are codenamed BlueHammer (requires GitHub sign-in), RedSun, and UnDefend, all of which were released as zero-days by a researcher known as Chaotic Eclipse (

iT4iNT SERVER Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched VDS VPS Cloud #MicrosoftDefender #CyberSecurity #ZeroDay #Vulnerability #Malware

0 0 0 0
Post image

THE PROMPT for Microsoft Security - Issue #67 microsoftdefender.su...

#MicrosoftSentinel #DefenderXDR #MicrosoftDefender #SecurityCopilot #Cybersecurity #MicrosoftSecurity #Security #MicrosoftThreatIntelligence

1 0 0 0
Preview
Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild - Help Net Security The researcher who earlier this month published a PoC exploit for a zero-day LPE vulnerability in Microsoft Defender is back with two more.

Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild

📖 Read more: www.helpnetsecurity.com/2026/04/17/m...

#cybersecurity #cybersecuritynews #exploit #PoC #MicrosoftDefender @huntress.com @wdormann.infosec.exchange.ap.brid.gy

1 0 0 0
Post image

Critical zero-day vulnerability (CVE-2026-33825) in Microsoft Defender allows privilege escalation to SYSTEM level. Patch now to secure your systems! #CyberSecurity #MicrosoftDefender #ZeroDayVulnerability Link: thedailytechfeed.com/zero-day-vul...

0 0 0 0
Microsoft Defender Experts for XDR | Always-on, human-led MXDR
Microsoft Defender Experts for XDR | Always-on, human-led MXDR Stay ahead of real-world threats without overwhelming your team using Microsoft Defender Experts for XDR. Offload high-severity incidents, gain full visibility into every investigation, and follow clear, guided remediation steps so you can contain attacks quickly and confidently, day or night. Extend your security operations with always-on managed detection and response and proactive threat hunting, so you can uncover hidden risks early, stop threats threats they spread, and strengthen your defenses to prevent future attacks. Maynald Savatdy, Microsoft Defender Expert, shows how to detect, contain, and hunt threats across your environment with support from human experts. ► QUICK LINKS: 00:00 - Microsoft Defender Experts 00:54 - 24/7 Security Coverage 01:35 - Visibility & guidance actions 03:34 - Incidents and alerts 04:25 - Social engineering attack 05:36 - Defender Experts for hunting 06:34 - Wrap up ► Link References Get started at https://aka.ms/DefenderExperts ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics #MicrosoftDefender #DefenderXDR #ThreatHunting #CyberSecurity

Microsoft Defender Experts for XDR | Always-on, human-led MXDR: Stay ahead of real-world threats without overwhelming your team using Microsoft Defender Experts for XDR. Offload high-severity incidents, gain full visibility into every… MSFTMechanics #MicrosoftDefender #XDR #CyberSecurity

0 0 0 0
Preview
Microsoft April 2026 Patch Tuesday Fixes 167 Flaws, 2 Zero-Days Microsoft has fixed 167 vulnerabilities in its April 2026 Patch Tuesday update, including an actively exploited SharePoint Server zero-day and a Defender flaw.

winbuzzer.com/2026/04/15/m...

Microsoft April 2026 Patch Tuesday Fixes 167 Flaws, 2 Zero-Days

#PatchTuesday #Microsoft #Security #Cybersecurity #ZeroDayVulnerabilities #MicrosoftSharePoint #MicrosoftDefender #Windows #Windows11 #MicrosoftWindows #WindowsUpdate #RemoteCodeExecution

0 0 0 0
Post image

How to Audit Microsoft Defender Antivirus Exclusions with PowerShell and Identify Their Source | #Guide #Microsoft #Powershell #Security #MicrosoftDefender #PowerShell #WindowsSecurity #CyberSecurity #InfoSec

0 0 0 0
Post image

THE PROMPT for Microsoft Security - Issue #66 microsoftdefender.su...

#MicrosoftSentinel #DefenderXDR #MicrosoftDefender #SecurityCopilot #Cybersecurity #MicrosoftSecurity #Security #MicrosoftThreatIntelligence

1 0 0 0
Preview
Microsoft 365 E3 and E5 customers get Intune Suite and Defender capabilities in July 2026 Microsoft published an FAQ including timelines for when Microsoft 365 E3 and E5 customers can expect the additional Intune Suite capabilities, and when Microsoft 365 E3 customers will receive Defender for Office 365 Plan 1.

Microsoft published an FAQ on timelines for when Microsoft 365 E3 and E5 customers will get additional Intune Suite capabilities and when M365 E3 customers will receive Defender for Office 365 Plan 1. #Microsoft365 #Intune #MicrosoftDefender

0 0 0 0
Post image

THE PROMPT for Microsoft Security - Issue #65 open.substack.com/pu...

#MicrosoftSentinel #DefenderXDR #MicrosoftDefender #SecurityCopilot #Cybersecurity #MicrosoftSecurity #Security #MicrosoftThreatIntelligence

0 0 0 0
Original post on infosec.exchange

Weird Intune/MDE issue 🧵
ASR policy (Block PSExec/WMI) shows 38 Succeeded in Intune, but Get-MpPreference returns empty on endpoints and registry key doesn't exist.
AttackSurfaceReductionRules_ProviderSet = 1 in PolicyManager but no actual rule values written anywhere.
Cloud-only, no SCCM […]

0 0 1 0
Preview
Rubrik Ties Microsoft Defender to Identity Recovery to Cut Response Times to Hours -- Redmondmag.com Rubrik unveiled a new integration with Microsoft Defender at RSAC 2026, linking real-time identity threat detection with automated rollback and recovery capabilities.

Rubrik has introduced a new integration with Microsoft Defender to connect identity threat detection with rollback and recovery across hybrid environments.

See how identity recovery is speeding up: https://ow.ly/E0GN50YzrKg

#Cybersecurity #IdentitySecurity #MicrosoftDefender

0 0 0 0
Preview
Microsoft Defender vs CrowdStrike for small business Microsoft Defender vs CrowdStrike for small business: Learn the key differences, limits of antivirus, and how to choose the right protection for your business.

#Cybersecurity issues, however, rarely begin in an obvious way. They start with uncertainty. This article explains where #MicrosoftDefender works well, where its limits are, and why solutions like CrowdStrike become relevant when security turns into a real business concern. shorturl.at/yPSdT

1 1 0 0
Post image

How to Audit Microsoft Defender Antivirus Exclusions with PowerShell and Identify Their Source | #Guide #Microsoft #Powershell #Security #MicrosoftDefender #PowerShell #WindowsSecurity #CyberSecurity #InfoSec

0 0 0 0
Preview
Falcon Next-Gen SIEM Supports Third-Party EDR Tools, Starting with Microsoft Defender CrowdStrike announced that Falcon Next-Gen SIEM will support third-party EDR solutions beginning with Microsoft Defender, allowing organizations to modernize their SOC without installing a Falcon sensor. The release adds Falcon Onum for real-time data control, federated search across LogScale/ExtraHop/S3, third-party indicator management, and a Query Translation Agent to accelerate migrations and...

Falcon Next-Gen SIEM now supports third-party EDR tools, starting with Microsoft Defender, enabling unified SOC operations without new sensors. Features include Falcon Onum, federated search, and Query Translation Agent. #FalconSIEM #MicrosoftDefender

0 0 0 0
Preview
Defender Unified RBAC will be enabled for new tenants with Defender for Office 365 Plan 2 Microsoft is enabling Unified RBAC for new tenants with Defender for Office 365 Plan 2 starting at the end of May 2026.

Microsoft is enabling Unified RBAC for new tenants with Defender for Office 365 Plan 2 starting at the end of May 2026. #UnifiedRBAC #MicrosoftDefender

0 0 0 0
Post image

THE PROMPT for Microsoft Security - Issue #64 open.substack.com/pu...

#MVPBuzz #MicrosoftSentinel #DefenderXDR #MicrosoftDefender #SecurityCopilot #Cybersecurity #MicrosoftSecurity #Security #MicrosoftThreatIntelligence

0 0 0 0
Canonical colabora con Microsoft para integrar Defender en Ubuntu Pro y reforzar la seguridad en Linux Canonical, la empresa detrás de Ubuntu, ha anunciado una colaboración estratégica con Microsoft para mejorar la seguridad de los sistemas Linux, especialmente en entornos Ubuntu. La iniciativa combina las capacidades de seguridad nativas de Ubuntu Pro con las funciones avanzadas de Microsoft Defender, el conocido antivirus de Windows. El objetivo principal es proporcionar una protección más robusta frente al aumento de amenazas dirigidas a Linux, dado su creciente uso tanto en hogares como en empresas, servidores, nube y gaming. Esta integración permite una gestión unificada de la seguridad, incorporando monitorización continua, detección de amenazas en tiempo real, análisis basado en inteligencia artificial y la vasta red de inteligencia de amenazas de Microsoft. Entre las ventajas destacan la visualización centralizada de incidentes en el portal de Microsoft Defender, lo que facilita la comprensión y respuesta ante alertas, en lugar de manejar notificaciones aisladas. Además, se mantiene el soporte de largo plazo de Ubuntu, con actualizaciones de kernel sin necesidad de reinicios. Aunque la colaboración se orienta inicialmente a entornos empresariales y cargas de trabajo críticas, también beneficiará a usuarios individuales al ofrecer herramientas más potentes sin necesidad de soluciones de terceros independientes. Este acuerdo representa un paso significativo en la evolución de la seguridad en Linux, demostrando una mayor cooperación entre gigantes tecnológicos y el ecosistema open source, en un momento en que los ataques a plataformas Linux están en aumento.

Canonical colabora con Microsoft para integrar Defender en Ubuntu Pro y reforzar la seguridad en Linux

🤖 IA: No es clickbait ✅
👥 Usuarios: No es clickbait ✅

#ubuntu #microsoftdefender #seguridadlinux

Ver resumen IA completo:

0 0 0 0
Preview
Defender for Office 365 now alerts on malicious URL clicks in Microsoft Teams Defender for Office 365 URL click alerts are expanding to Microsoft Teams. When users click malicious links in Teams messages, alerts now appear in the Defender portal for faster detection and investigation.

Defender for Office 365 URL click alerts are expanding to Microsoft Teams. When users click malicious links in Teams messages, alerts now appear in the Defender portal for faster detection and investigation. #MicrosoftDefender #MDO #MicrosoftTeams #phishing

0 0 0 0
Post image

THE PROMPT for Microsoft Security - Issue #63 microsoftdefender.su...

#MicrosoftSentinel #DefenderXDR #MicrosoftDefender #SecurityCopilot #Cybersecurity #MicrosoftSecurity #Security #MicrosoftThreatIntelligence

0 0 0 0
Preview
Microsoft Defender Adds Effective Settings View for Device Security Configurations -- Redmondmag.com New feature helps security teams identify which policies are actively applied across managed devices.

Microsoft Defender has added an Effective Settings view so administrators can see final device security values and where those settings came from across multiple management layers.

Learn more: https://ow.ly/KqyT50Yshiy

#MicrosoftDefender #EndpointSecurity #Cybersecurity

1 0 0 0

Microsoft centralise enfin vos scripts de réponse aux incidents dans Defender. Une avancée majeure pour la productivité du SOC ou un simple "fourre-tout" numérique pour scripts oubliés ?
#PotatoSecurity #MicrosoftDefender #InfoSec #DSI #ClownSecurity

0 0 0 0