Security researcher Chaotic Eclipse has published a proof-of-concept exploit for a Microsoft Defender zero-day vulnerability dubbed "RedSun" over a week after the release of an exploit code for the BlueHammer flaw in Defender, tracked as CVE-2026-33825, GBHackers News reports.
Numerous threat actors have launched intrusions abusing the critical remote code execution flaw in the open-source Python notebook Marimo, tracked as CVE-2026-39987, to deploy illicit payloads and compromise data since the vulnerability was first discovered to be harnessed within hours of its disclosure last week, BleepingComputer reports.
Nearly 180 critical vulnerabilities have been collectively addressed by Microsoft, Adobe, SAP, and Fortinet as part of April's Patch Tuesday, The Hacker News reports.
Under the new model, NIST will only fully enrich CVEs that are listed in the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog, affect federal government software, or impact software classified as critical.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.