<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[May 11, 2026: The Red Sun still prevails.]]></title><description><![CDATA[<p>May 11, 2026: The Red Sun still prevails. </p><p>However, I noticed something odd. Either this is purely coincidence, or the exploit has less reliability now (?). On a freshly booted system, it works 100%, but after a couple minutes of runtime, it seems that it doesn't always win the race condition (or it takes longer than the usual ~10 seconds).</p>]]></description><link>https://board.circlewithadot.net/topic/ffcccfe7-b2e1-45d9-89a7-0381e27bbd53/may-11-2026-the-red-sun-still-prevails.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 05 Jun 2026 20:39:15 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/ffcccfe7-b2e1-45d9-89a7-0381e27bbd53.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 11 May 2026 06:23:51 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 20:32:27 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@jhr77" rel="nofollow noopener">@<span>jhr77</span></a></span> <span><a href="/user/christopherkunz%40chaos.social" rel="nofollow noopener">@<span>christopherkunz</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> <br />I've not been able to reproduce YellowKey in a VMware Workstation VM.</p><p>So either VMware is interfering with the <code>hold CRTL and do NOT lift your finger off it</code> apparently required part of the exploit, or it simply doesn't work.</p><p>Even if it <strong>did</strong> work, I suspect that it'd perhaps only work on systems that don't both with PIN-on-boot protection.  Which is sort of known to be not terribly secure.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116563505774565548</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116563505774565548</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 20:32:27 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 20:26:23 GMT]]></title><description><![CDATA[<p><span><a href="/user/christopherkunz%40chaos.social">@<span>christopherkunz</span></a></span> <span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> What the h... is that yellowkey? I am a little bit afraid to try it. It sounds that it should be better prepared not on a windows system and tested on a completely separate pc.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116480222953530787/statuses/116563481927169153</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116480222953530787/statuses/116563481927169153</guid><dc:creator><![CDATA[jhr77@mastodon.social]]></dc:creator><pubDate>Tue, 12 May 2026 20:26:23 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 19:52:24 GMT]]></title><description><![CDATA[<p><span><a href="/user/buherator%40infosec.place" rel="nofollow noopener">@<span>buherator</span></a></span> <span><a href="/user/christopherkunz%40chaos.social" rel="nofollow noopener">@<span>christopherkunz</span></a></span> <span><a href="https://mastodon.social/@jhr77" rel="nofollow noopener">@<span>jhr77</span></a></span> <br />Related: In Microsoft's world, CVEs are identifiers for <strong>software updates</strong> released on Patch Tuesday (or OOB through the same channel), not vulnerabilities. They used to have proprietary identifiers for their software updates, like <code>MS08-067</code>, but when they switched to using CVEs, they didn't switch what the identifiers are <strong>for</strong>.</p><p>As such, I could imagine why they didn't think a CVE was necessary for the vulnerability that allowed the RedSun exploit to work.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116563348325602806</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116563348325602806</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 19:52:24 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 19:47:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/buherator%40infosec.place" rel="nofollow noopener">@<span>buherator</span></a></span> <span><a href="/user/christopherkunz%40chaos.social" rel="nofollow noopener">@<span>christopherkunz</span></a></span> <span><a href="https://mastodon.social/@jhr77" rel="nofollow noopener">@<span>jhr77</span></a></span> <br />Right.  There is no official statement that the vulnerability was actually fixed.</p><p>I personally believe that it was fixed, as I can no longer reproduce the exploit with updated definitions.</p><p>I suspect that others in this thread do not agree with me.</p><p>Would be nice to have a definitive answer.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116563327174433757</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116563327174433757</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 19:47:01 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 19:00:50 GMT]]></title><description><![CDATA[<span><a href="/user/wdormann%40infosec.exchange" rel="ugc">@<span>wdormann</span></a></span> <span><a href="/user/christopherkunz%40chaos.social" rel="ugc">@<span>christopherkunz</span></a></span> <span><a href="https://mastodon.social/@jhr77" rel="ugc">@<span>jhr77</span></a></span> Vuln mgmt is hard, e.g. how you track patch coverage vs. signature update status? Not that pushing a sig was a bad idea, I'd just expect a KB for this too.]]></description><link>https://board.circlewithadot.net/post/https://infosec.place/objects/82cf34f4-2795-4e9b-9d56-0767d2484e0d</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.place/objects/82cf34f4-2795-4e9b-9d56-0767d2484e0d</guid><dc:creator><![CDATA[buherator@infosec.place]]></dc:creator><pubDate>Tue, 12 May 2026 19:00:50 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 18:52:17 GMT]]></title><description><![CDATA[<p><span><a href="/user/buherator%40infosec.place" rel="nofollow noopener">@<span>buherator</span></a></span> <span><a href="/user/christopherkunz%40chaos.social" rel="nofollow noopener">@<span>christopherkunz</span></a></span> <span><a href="https://mastodon.social/@jhr77" rel="nofollow noopener">@<span>jhr77</span></a></span> <br />I can't imagine why they'd wait for Patch Tuesday if they already have the path to fix it automatically at any time they want.  <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f937.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--shrug" style="height:23px;width:auto;vertical-align:middle" title="🤷" alt="🤷" />‍<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--male_sign" style="height:23px;width:auto;vertical-align:middle" title="♂" alt="♂" />️</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116563111923156973</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116563111923156973</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 18:52:17 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 18:50:00 GMT]]></title><description><![CDATA[<span><a href="/user/wdormann%40infosec.exchange" rel="ugc">@<span>wdormann</span></a></span> <span><a href="https://mastodon.social/@jhr77" rel="ugc">@<span>jhr77</span></a></span> <span><a href="/user/christopherkunz%40chaos.social" rel="ugc">@<span>christopherkunz</span></a></span> I don't see a Defender entry in today's update that also points to this being a signature based mitigation]]></description><link>https://board.circlewithadot.net/post/https://infosec.place/objects/5400ad45-0d13-4f7f-a2ba-84e396aa5f8d</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.place/objects/5400ad45-0d13-4f7f-a2ba-84e396aa5f8d</guid><dc:creator><![CDATA[buherator@infosec.place]]></dc:creator><pubDate>Tue, 12 May 2026 18:50:00 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 18:18:20 GMT]]></title><description><![CDATA[<p><span><a href="/user/christopherkunz%40chaos.social" rel="nofollow noopener">@<span>christopherkunz</span></a></span> <span><a href="https://mastodon.social/@jhr77" rel="nofollow noopener">@<span>jhr77</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> <br />GreenPlasma prompts for admin creds, so to call it a privilege escalation is a stretch.</p><p>As for YellowKey, the writeup is a bit too hand-wavy for me to follow, so I'll leave the repro to somebody else to try.</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/562/976/889/158/901/original/a893e1cf9e1eebd8.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116562978440825839</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116562978440825839</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 18:18:20 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 18:17:13 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@jhr77">@<span>jhr77</span></a></span> <span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> Well, they're certainly pissed at MS: "Microsoft has chosen to make this worst instead of resolving the situation like adults, they pulled every childish game possible. My patience is running out you're making everyone else paying for it."</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116562974044751009</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116562974044751009</guid><dc:creator><![CDATA[christopherkunz@chaos.social]]></dc:creator><pubDate>Tue, 12 May 2026 18:17:13 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 18:13:40 GMT]]></title><description><![CDATA[<p><span><a href="/user/christopherkunz%40chaos.social">@<span>christopherkunz</span></a></span> <span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> Has this person also other hobbies than exploiting Windows?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116480222953530787/statuses/116562960113246485</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116480222953530787/statuses/116562960113246485</guid><dc:creator><![CDATA[jhr77@mastodon.social]]></dc:creator><pubDate>Tue, 12 May 2026 18:13:40 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 17:58:43 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> <span><a href="https://mastodon.social/@jhr77">@<span>jhr77</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> Meanwhile, slightly elsewhere: <a href="https://github.com/Nightmare-Eclipse/GreenPlasma" rel="nofollow noopener"><span>https://</span><span>github.com/Nightmare-Eclipse/G</span><span>reenPlasma</span></a><br />Looking forward to seeing the writeup to this.<br /><a href="https://github.com/Nightmare-Eclipse/YellowKey" rel="nofollow noopener"><span>https://</span><span>github.com/Nightmare-Eclipse/Y</span><span>ellowKey</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116562901324864457</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116562901324864457</guid><dc:creator><![CDATA[christopherkunz@chaos.social]]></dc:creator><pubDate>Tue, 12 May 2026 17:58:43 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 17:17:26 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> <span><a href="https://mastodon.social/@jhr77">@<span>jhr77</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> OK, I don't get this. I did the following:<br />1. DISM /Online /Cleanup-Image /RestoreHealth<br />2. sfc /scannow<br />3. Checked that the TieringEngineService.exe has two signatures (like in your screenshot) and got replaced properly (as per the log).<br />4. Rebooted and re-checked if the .exe is still properly signed.<br />5. Re-Ran RedSun.exe<br />6. Popped a shell again.<br />I'm going to boot a clean Win11 VM again.</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116562738998159255</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116562738998159255</guid><dc:creator><![CDATA[christopherkunz@chaos.social]]></dc:creator><pubDate>Tue, 12 May 2026 17:17:26 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 17:09:04 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@jhr77" rel="nofollow noopener">@<span>jhr77</span></a></span> <span><a href="/user/christopherkunz%40chaos.social" rel="nofollow noopener">@<span>christopherkunz</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> <br />Always revert your VM to a clean state before (and after) testing an exploit.  <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f602.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--joy" style="height:23px;width:auto;vertical-align:middle" title="😂" alt="😂" /></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116562706046998593</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116562706046998593</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 17:09:04 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 17:03:22 GMT]]></title><description><![CDATA[<p><span><a href="/user/christopherkunz%40chaos.social" rel="nofollow noopener">@<span>christopherkunz</span></a></span> <span><a href="https://mastodon.social/@jhr77" rel="nofollow noopener">@<span>jhr77</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> <br />No, Windows does not do periodic filesystem checks to ensure that files have not been corrupted.</p><p>It's up to you to run <code>sfc /scannow</code> and associated tools if you think your Windows installation is corrupt.</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/562/678/985/489/233/original/a9a21c46233b7ea9.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116562683690652238</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116562683690652238</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 17:03:22 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 16:51:41 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@jhr77" rel="nofollow noopener">@<span>jhr77</span></a></span> <span><a href="/user/christopherkunz%40chaos.social" rel="nofollow noopener">@<span>christopherkunz</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> <br />The exploit made no claims about being temporary.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116562637738196838</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116562637738196838</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 16:51:41 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 16:51:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/christopherkunz%40chaos.social">@<span>christopherkunz</span></a></span> <span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> same same here. It's getting worse when asking more questions. But it was possible to replace with the original version. Hopefully the system is clean now. Maybe making a scan with the defender... <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f605.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--sweat_smile" style="height:23px;width:auto;vertical-align:middle" title="😅" alt="😅" /></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116480222953530787/statuses/116562636283476595</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116480222953530787/statuses/116562636283476595</guid><dc:creator><![CDATA[jhr77@mastodon.social]]></dc:creator><pubDate>Tue, 12 May 2026 16:51:19 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 16:31:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> <span><a href="https://mastodon.social/@jhr77">@<span>jhr77</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> Yeah, mine is unsigned, so I'm doing the whole dism &amp; sfc routine now to presumably fix it.<br />I'm a little surprised though: Is this normal behavior that unsigned corrupted executables remain indefinitely in \system32 and aren't detected or removed? Is this something I would have to trigger manually, like an offline scan of sorts?</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116562559664109980</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116562559664109980</guid><dc:creator><![CDATA[christopherkunz@chaos.social]]></dc:creator><pubDate>Tue, 12 May 2026 16:31:50 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 16:28:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> <span><a href="/user/christopherkunz%40chaos.social">@<span>christopherkunz</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> So this is even worse as this is persistent</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116480222953530787/statuses/116562544890450970</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116480222953530787/statuses/116562544890450970</guid><dc:creator><![CDATA[jhr77@mastodon.social]]></dc:creator><pubDate>Tue, 12 May 2026 16:28:05 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 16:17:16 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@jhr77" rel="nofollow noopener">@<span>jhr77</span></a></span> <span><a href="/user/christopherkunz%40chaos.social" rel="nofollow noopener">@<span>christopherkunz</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> </p><p>Just to be clear, before you attempted the exploit, your <code>C:\Windows\system32\TieringEngineService.exe</code> file had a valid signature?</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/562/500/051/382/994/original/6c858e7cc28607d8.png" alt="Link Preview Image" /><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/562/500/691/472/634/original/257dd96e38cc9d68.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116562502386506447</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116562502386506447</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 16:17:16 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 16:04:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> <span><a href="/user/christopherkunz%40chaos.social">@<span>christopherkunz</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> Hi, today at the first try I had a shell with system rights. So i assume that it worked successfully.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116480222953530787/statuses/116562450368365931</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116480222953530787/statuses/116562450368365931</guid><dc:creator><![CDATA[jhr77@mastodon.social]]></dc:creator><pubDate>Tue, 12 May 2026 16:04:02 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 15:59:14 GMT]]></title><description><![CDATA[<p><span><a href="/user/christopherkunz%40chaos.social" rel="nofollow noopener">@<span>christopherkunz</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> <span><a href="https://mastodon.social/@jhr77" rel="nofollow noopener">@<span>jhr77</span></a></span> </p><p>Though I'll also admit that having <code>Windows Security</code> open seems to indicate that Windows Defender stops when RedSun is attempted.</p><p>From the GUI it's merely <code>Threat service has stopped</code>, but in Event viewer we can get more info in that it's <code>Microsoft Defender Antivirus has encountered a critical error when taking action on malware or other potentially unwanted software.</code></p><p>It restarts automatically.</p><p>If this is an intentional RedSun fix, I'll say that it's less than ideal.  <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f602.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--joy" style="height:23px;width:auto;vertical-align:middle" title="😂" alt="😂" /></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/562/427/543/436/780/original/08ff13aa135022df.png" alt="Link Preview Image" /><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/562/430/656/383/233/original/9f8f8d00f70f9c85.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116562431476040141</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116562431476040141</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 15:59:14 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 15:44:23 GMT]]></title><description><![CDATA[<p><span><a href="/user/christopherkunz%40chaos.social" rel="nofollow noopener">@<span>christopherkunz</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social" rel="nofollow noopener">@<span>GossiTheDog</span></a></span> <span><a href="https://mastodon.social/@jhr77" rel="nofollow noopener">@<span>jhr77</span></a></span> <br />Well yep, if you're testing on an already-popped machine, that's an invalid test.</p><p>That is, if <code>C:\Windows\system32\TieringEngineService.exe</code> has already been replaced, then the exploit might appear to "work" even when it doesn't.</p><p><code>TieringEngineService.exe</code> is a Windows component.  It has nothing to do with Defender, and no Defender update will restore it to its pristine state.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116562373057250174</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/wdormann/statuses/116562373057250174</guid><dc:creator><![CDATA[wdormann@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 15:44:23 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 15:42:40 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> <span><a href="https://mastodon.social/@jhr77">@<span>jhr77</span></a></span> I think my TieringEngineService.exe might be permanently patched/replaced with the RedSun copy and none of the definitions updates have cleaned it up.</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116562366308930037</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116562366308930037</guid><dc:creator><![CDATA[christopherkunz@chaos.social]]></dc:creator><pubDate>Tue, 12 May 2026 15:42:40 GMT</pubDate></item><item><title><![CDATA[Reply to May 11, 2026: The Red Sun still prevails. on Tue, 12 May 2026 15:37:16 GMT]]></title><description><![CDATA[<p><span><a href="/user/wdormann%40infosec.exchange">@<span>wdormann</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> <span><a href="https://mastodon.social/@jhr77">@<span>jhr77</span></a></span> Yeah, the first dialog is the detection of EICAR, the second one is the admission of defeat. I get both, and a NT_AUTHORITY shell, on running RedSun.exe.<br />This is weird, but I suspect we're basically arguing against a ticking clock here. Patch day will land soon and with it, undoubtedly a RedSun mitigation. Actually, let me milk this opportunity for a meme.</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://assets.chaos.social/media_attachments/files/116/562/344/801/191/913/original/247c59440fd3b776.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116562345083458697</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/christopherkunz/statuses/116562345083458697</guid><dc:creator><![CDATA[christopherkunz@chaos.social]]></dc:creator><pubDate>Tue, 12 May 2026 15:37:16 GMT</pubDate></item></channel></rss>