UnDefend is a vulnerability tracked by ThreatCluster, appearing in 10 threat clusters built from 30 intelligence report mentions.
UnDefend is a vulnerability tracked across 10 threat clusters and 30 intelligence report mentions on ThreatCluster. First observed April 17, 2026; most recent activity July 10, 2026.
A recent intrusion campaign utilized the Nightmare-Eclipse privilege escalation tools, specifically BlueHammer, RedSun, and UnDefend, following unauthorized access through compromised FortiGate SSL VPN credentials. This…
A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named 'Copy Fail', allows unprivileged local users to gain root access on virtually all major Linux distributions released since 2017.…
A newly disclosed zero-day vulnerability in Visual Studio Code (VS Code) enables attackers to steal GitHub OAuth tokens by tricking users into clicking a malicious link. The flaw exploits the webview message-passing…
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…
Security researcher Nightmare-Eclipse has disclosed two critical zero-day vulnerabilities affecting Windows 11 and Windows Server 2022/2025. The first, YellowKey, allows attackers to bypass BitLocker encryption,…
A newly discovered Windows zero-day exploit, named MiniPlasma, allows attackers to gain SYSTEM-level privileges on fully patched Windows systems. The exploit targets the cldflt.sys Cloud Filter driver, specifically the…
The anonymous security researcher known as Nightmare-Eclipse has been banned from both GitHub and GitLab due to the release of multiple unpatched Windows vulnerabilities. GitHub terminated the account on May 25, 2026,…
Several zero-day vulnerabilities, including RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma, were disclosed without prior notice to Microsoft, exposing customers to risks. Microsoft emphasizes the…
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
A security researcher, known as Chaotic Eclipse, has publicly released exploit code for a zero-day vulnerability in Windows, dubbed BlueHammer, allowing local privilege escalation to SYSTEM or elevated administrator…
UnDefend is a vulnerability tracked by ThreatCluster, appearing in 10 threat clusters built from 30 intelligence report mentions.
The most recent intelligence report mentioning UnDefend on ThreatCluster is dated July 10, 2026. Activity was first observed April 17, 2026, giving a tracked span from then to July 10, 2026.
Across ThreatCluster reporting, UnDefend most frequently co-occurs with Apt28, Chaotic Eclipse, Fancy Bear, Uac-0001, Data Breach, among 12 tracked related entities.
The most significant recent cluster is “Nightmare-Eclipse Tools Exploit FortiGate VPNs in Live Attacks” (2 articles · Updated April 22, 2026). UnDefend appears across 10 threat clusters in total, listed above with sources.
UnDefend appears in 30 intelligence report mentions across 10 deduplicated threat clusters, aggregated from 17,000+ monitored sources.