What does it mean in practice when a zero-day exploit like Redsun strikes?
The so-called Redsun technique is a recent example of how attackers can exploit a zero-day vulnerability in Microsoft Defender to evade detection.
This changes the basis for many companies' security setups.
In a traditional approach, it is assumed that endpoint protection can identify and stop malicious code. But with Redsun, we see a scenario where an attack can operate undetected for a period of time—not because the security is misconfigured, but because the attack exploits something that is not yet known.
This means that even organizations with “mature” technical security measures can still be vulnerable.
And this is exactly where many companies are caught off guard.
What is a zero-day vulnerability, and how is it exploited in practice?
A zero-day vulnerability is an unknown security flaw in software that attackers can exploit before the vendor has a chance to develop a patch.
In the case of Redsun, we see a classic pattern: the attacker exploits a technical vulnerability using a delivery mechanism—often via phishing or social engineering.
It is important to understand that the vulnerability itself rarely stands alone. It is merely one element in a larger chain of attacks.
A typical process might look like this:
- An employee receives a legitimate email
- The attachment or link activates the code
- The code exploits the zero-day vulnerability
- The security system does not detect the attack
It is this combination that makes attacks like Redsun particularly effective.
Why Redsun highlights a well-known but overlooked risk
What’s interesting about Redsun isn’t just the technology itself. It’s what it reveals about modern cybersecurity.
Many companies have invested heavily in technology, but still operate under the implicit assumption that these tools will stop threats.
Redsun proves the opposite.
It shows that:
- Even advanced solutions can have blind spots
- Attacks often succeed by exploiting a combination of technical and human vulnerabilities
- Security is not a product—it is an ongoing process
This is an important realization, especially for management.
How Companies Can Reduce Risk—Even When the Next “Redsun” Strikes
You can’t prevent the next zero-day attack. But you can be significantly better prepared when it strikes.
It starts with accepting that a breach is a realistic scenario, not an exception. That is why companies should take a structured approach to people, technology, and processes.
Awareness plays a key role. Employees should not just be informed once, but should receive ongoing training in how to recognize and respond to attacks. Organizations that prioritize this significantly reduce the likelihood that an attack will gain a foothold in the first place.
Employees are the company’s first line of defense. Boost their vigilance with awareness training.
In addition, it is essential to test the organization’s resilience in practice. Simulating realistic attacks provides insight into how vulnerable the company actually is—and where action needs to be taken.
Finally, security efforts should be grounded in a structured approach. Frameworks such as NIS2 and CIS18 help provide an overview, prioritize efforts, and ensure that security work is not ad hoc but rather an integral part of the business.
Get an overview of the requirements and opportunities with NIS2 Compliance
Listen to our podcast: “Can Defender Be Hacked? The Redsun Vulnerability Explained”
In our podcast, we’ve taken an even closer look at Redsun and its implications for businesses.
Here, we will go over:
- How the attack works in practice
- Why this is relevant for Danish companies
- What specific changes should be made
(You must accept cookies to view the video)





