DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:03:37ZSOURCES: 14CRITICAL: 15
⚠ ACTIVE ALERTS
SYLVANITE CRITICAL — SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated… /// @MsftSecIntel CRITICAL — We are tracking TeamPCP (UNC6780) activity following the GitHub internal repository… /// @GossiTheDog CRITICAL — The GitHub / TeamPCP breach is now being monetized on BreachForums. Listing is up — $95k… /// @struppigel CRITICAL — SUPPLY CHAIN ALERT: Laravel-Lang PHP packages backdoored May 22-23 via hijacked GitHub… /// @MalwareHunterTeam CRITICAL — Seeing fresh DebugElevator stealer log batches already appearing for sale on Exploit.in —…
15Critical Threats
8Active CVEs
0IOCs Tracked
0New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-41091PUBLISHED: 2026-05-20
HIGHCVE-2026-41091★ CISA KEV LISTED

Microsoft Defender Malware Protection Engine Link-Following LPE (RedSun)

VENDOR: Microsoft//PRODUCT: Microsoft Defender / Malware Protection Engine
7.8
HIGH
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

An improper link resolution before file access (CWE-59) flaw in mpengine.dll allows a low-privileged local attacker to redirect Defender's elevated file writes into protected system directories, escalating to full SYSTEM privileges. Dubbed 'RedSun', the exploit was publicly released on GitHub in April 2026 by a researcher operating as Nightmare Eclipse without coordinated disclosure, and Huntress confirmed real-world exploitation in customer intrusions as early as mid-April 2026. CISA added both CVE-2026-41091 and CVE-2026-45498 to the KEV catalog on May 20, 2026, with a remediation deadline of June 3, 2026.

Attack Vector
LOCAL
Attack Complexity
LOW
Privs Required
LOW
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSMicrosoft Malware Protection Engine v1.1.26030.3008 and earlier
  • https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41091
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://www.techtimes.com/articles/316957/20260521/microsoft-defender-zero-days-patched-redsun-undefend-exploits-already-used-live-intrusions.htm
  • https://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html
SHARE BRIEF:✕ Post on Xin Share on LinkedIn