Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

2026-04-18T01:24:21Z630489b1f04b713c2c6951d988b97737ea103e8371c8fd963e46910c43bea9bb
active-exploitationandroid-ratapache-activemqbotnetchrome-extensioncisa-kevciscoddosmalwaremicrosoft-defendern8nnginx-uiobsidianpatch-tuesdayphishingphp-composersapvulnerabilityzero-day

What happened

The feed highlights a surge of actively exploited and high-severity vulnerabilities across widely used products plus multiple large-scale campaigns. Key items include three Microsoft Defender zero-days (BlueHammer, RedSun, UnDefend) under active exploitation, CISA addition of Apache ActiveMQ CVE-2026-34197, critical nginx-ui authentication bypass CVE-2026-33032 in the wild, and large patch rolls (Microsoft Patch Tuesday) and advisories (Cisco, SAP, PHP Composer). The collection also reports significant malware and abuse campaigns (PowMix botnet, Mirax Android RAT, malicious Chrome extensions,n

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
630489b1f04b713c2c6951d988b97737ea103e8371c8fd963e46910c43bea9bb
Enrichment time
2026-04-18T01:24:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.