Microsoft began rolling out patches Wednesday for two zero-day vulnerabilities in Defender that attackers are actively exploiting to gain SYSTEM privileges or trigger denial-of-service conditions. CISA added the flaws, known as RedSun and UnDefend, to its Known Exploited Vulnerabilities catalog and gave federal agencies until June 3 to apply fixes.

The flaw stems from an improper link resolution before file access weakness, also known as link following, which allows attackers to gain SYSTEM privileges.
CISA warned that this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Expert Take: Enterprise admins should manually confirm the Antimalware ClientVersion matches 1.1.26040.8 or 4.18.26040.7 even with automatic updates enabled, as high-security environments cannot assume defaults alone will meet CISA compliance deadlines.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Apple introduced the M6 as its first 2nm processor inside a new Mac mini and the M5 Ultra as its most powerful chip yet inside a refreshed Mac Studio. The silicon brings higher core counts, substantially improved AI acceleration, increased memory bandwidth, and a next-generation UltraFusion interconnect.
Taiwan indicted nine people including an Nvidia senior manager and two Supermicro employees for allegedly forging documents to illegally export 130 B300 AI servers to China, with 74 delivered via multiple routes. The charges follow a US arrest and underscore enforcement of semiconductor export restrictions that have been in place since 2022.
CISA added CVE-2026-21962, an improper access control flaw in Oracle HTTP Server and the Oracle Weblogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog on 2026-08-24. Federal agencies have until 2026-08-27 to apply mitigations per vendor instructions or discontinue use.