April 17, 2026

Zero-day vulnerability in Microsoft Defender

A new zero-day vulnerability—known as Redsun—shows that even advanced security solutions like Microsoft Defender can be bypassed. For businesses, this means that cybersecurity isn’t just about technology,…

What does it mean in practice when a zero-day exploit like Redsun strikes?

The so-called Redsun technique is a recent example of how attackers can exploit a zero-day vulnerability in Microsoft Defender to evade detection.

This changes the basis for many companies' security setups.

In a traditional approach, it is assumed that endpoint protection can identify and stop malicious code. But with Redsun, we see a scenario where an attack can operate undetected for a period of time—not because the security is misconfigured, but because the attack exploits something that is not yet known.

This means that even organizations with “mature” technical security measures can still be vulnerable.

And this is exactly where many companies are caught off guard.

What is a zero-day vulnerability, and how is it exploited in practice?

A zero-day vulnerability is an unknown security flaw in software that attackers can exploit before the vendor has a chance to develop a patch.

In the case of Redsun, we see a classic pattern: the attacker exploits a technical vulnerability using a delivery mechanism—often via phishing or social engineering.

It is important to understand that the vulnerability itself rarely stands alone. It is merely one element in a larger chain of attacks.

A typical process might look like this:

  • An employee receives a legitimate email
  • The attachment or link activates the code
  • The code exploits the zero-day vulnerability
  • The security system does not detect the attack

It is this combination that makes attacks like Redsun particularly effective.

Why Redsun highlights a well-known but overlooked risk

What’s interesting about Redsun isn’t just the technology itself. It’s what it reveals about modern cybersecurity.

Many companies have invested heavily in technology, but still operate under the implicit assumption that these tools will stop threats.

Redsun proves the opposite.

It shows that:

  • Even advanced solutions can have blind spots
  • Attacks often succeed by exploiting a combination of technical and human vulnerabilities
  • Security is not a product—it is an ongoing process

This is an important realization, especially for management.

How Companies Can Reduce Risk—Even When the Next “Redsun” Strikes

You can’t prevent the next zero-day attack. But you can be significantly better prepared when it strikes.

It starts with accepting that a breach is a realistic scenario, not an exception. That is why companies should take a structured approach to people, technology, and processes.

Awareness plays a key role. Employees should not just be informed once, but should receive ongoing training in how to recognize and respond to attacks. Organizations that prioritize this significantly reduce the likelihood that an attack will gain a foothold in the first place.

Employees are the company’s first line of defense. Boost their vigilance with awareness training.

In addition, it is essential to test the organization’s resilience in practice. Simulating realistic attacks provides insight into how vulnerable the company actually is—and where action needs to be taken.

Finally, security efforts should be grounded in a structured approach. Frameworks such as NIS2 and CIS18 help provide an overview, prioritize efforts, and ensure that security work is not ad hoc but rather an integral part of the business.

Get an overview of the requirements and opportunities with NIS2 Compliance

Listen to our podcast: “Can Defender Be Hacked? The Redsun Vulnerability Explained”

In our podcast, we’ve taken an even closer look at Redsun and its implications for businesses.

Here, we will go over:

  • How the attack works in practice
  • Why this is relevant for Danish companies
  • What specific changes should be made

(You must accept cookies to view the video)

Dion Grydell

Introductory Meeting – SecureFirst

Questions?

Should you have any questions, please do not hesitate to contact us by phone or email.  

What is ransomware, and why do companies choose to pay millions to cybercriminals?

What is ransomware, and why do companies choose to pay millions to cybercriminals?

Ransomware has become one of the most serious cyber threats facing modern businesses. These attacks are no longer just about locking files; they increasingly involve extortion, data theft, and threats to a company’s operations and reputation. When the consequences become severe enough, even well-protected organizations may find themselves in a situation where paying a ransom becomes a real consideration.

But why does this happen, and what can companies do to reduce the risk?

How phishing training works

How phishing training works

Phishing remains one of the most common ways for cybercriminals to gain access to businesses. Even though spam filters, firewalls, and security systems are getting better, fake...