Source: BleepingComputer
Author: Lawrence Abrams
URL: https://www.bleepingcomputer.com/news/microsoft/new-microsoft-defender-redsun-zero-day-poc-grants-system-privileges/
ONE SENTENCE SUMMARY:
Researcher Chaotic Eclipse released a RedSun proof‑of‑concept exploiting a second Microsoft Defender zero‑day, protesting Microsoft’s researcher engagement over recent two weeks.
MAIN POINTS:
- Chaotic Eclipse publicly published exploit code as a proof-of-concept.
- RedSun is described as a Microsoft Defender zero-day vulnerability.
- This marks the second Microsoft Defender zero-day PoC released by the researcher.
- The two disclosures occurred within roughly a two-week period.
- Publication was framed as a protest against Microsoft’s handling of researchers.
- The action highlights tension around vulnerability disclosure and vendor communication.
- A working PoC can accelerate real-world exploitation attempts by others.
- Defender’s widespread deployment increases potential exposure if unmitigated.
- Public discussion may pressure faster remediation and clearer disclosure practices.
- Organizations should track vendor updates related to the cited “RedSun” issue.
TAKEAWAYS:
- Proof-of-concept releases can rapidly change the threat landscape, even without full weaponization.
- Repeated zero-day disclosures suggest escalating frustration with the vendor-researcher process.
- Security teams should prioritize monitoring for patches and mitigations tied to RedSun.
- Public protest disclosures underscore the importance of transparent, timely researcher engagement.
- Treat published PoCs for ubiquitous security products as high-signal indicators for defensive action.