HomeSecurityCISA: Ransomware gangs exploit Microsoft Defender's BlueHammer vulnerability

CISA: Ransomware gangs exploit Microsoft Defender's BlueHammer vulnerability

The U.S. Cybersecurity and Infrastructure Security Administration (CISA) is warning that ransomware groups are now actively exploiting the serious BlueHammer in Microsoft Defender, significantly increasing the risk for organizations and businesses that have not installed the latest security updates.

 BlueHammer Microsoft Defender ransomware

The vulnerability, codenamed CVE-2026-33825, allows for elevation of privilege on Windows systems. Although Microsoft has already released a patch, attacks continue against systems that remain unprotected.

From zero-day leak to real attacks

The case began in early April, when cybersecurity researcher with the pseudonym Nightmare Eclipse published both the technical details of the vulnerability and a working PoC exploit.

The leak was, according to him, a protest against the way the Microsoft Security Response Center handles the vulnerability disclosure. However, releasing an exploit before a patch is available significantly increased the risk of exploitation by malicious actors.

See also: SimpleHelp Vulnerability: TaskWeaver and Djinn Stealer Attacks

A few days later, Microsoft released a patch as part of the April 2026 Patch Tuesday. However, researchers at Huntress Labs revealed that the vulnerability had already been used in real-world zero-day attacks before the patch was released.

How the BlueHammer vulnerability works

According to Microsoft, the issue is due to inadequate privilege checking within Microsoft Defender, allowing an attacker who already has limited access to the computer to gain much higher privileges.

Vulnerability analyst Will Dormann explained that while the exploit is not considered particularly simple, the result is quite serious. Attackers can gain access to the Security Account Manager (SAM) database , where hashes of local Windows passwords.

Once this access is gained, cybercriminals can gain SYSTEM privileges, the highest level of privileges in the operating system. Essentially, they gain complete control of the computer, with the ability to install malware, create new administrator accounts, or disable security mechanisms.

CISA: Ransomware gangs exploit Microsoft Defender's BlueHammer vulnerability

CISA confirms ransomware attacks

Initially, CISA had included BlueHammer on the Known Exploited Vulnerabilities (KEV) list, requiring all United States federal agencies to immediately install available security updates.

In its most recent update, however, the US agency took an even more worrying step, confirming that this particular vulnerability is now being actively used by gangs ransomware.

See also: Progress Kemp LoadMaster: Critical root command execution vulnerability

Although Microsoft has not yet officially reported ransomware attacks exploiting this vulnerability, CISA's assessment is based on actual incidents recorded during cybersecurity investigations.

This development significantly increases the severity of the threat, as ransomware attacks typically begin by gaining high privileges within a corporate network before proceeding to encrypt data or steal sensitive information.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Nightmare Eclipse continues to reveal zero-days

This particular vulnerability is not an isolated case. In recent months, researcher Nightmare Eclipse has disclosed several other zero-day vulnerabilities affecting various Windows components.

These include RoguePlanet, RedSun, GreenPlasma, MiniPlasma, YellowKey and UnDefend, which affect both Microsoft Defender and technologies like BitLocker and core Windows subsystems.

Microsoft has already patched several of these vulnerabilities through the June 2026 security updates, but the continued emergence of new zero-days shows that the battle between security researchers, software companies, and cybercriminals remains fierce.

CISA: Ransomware gangs exploit Microsoft Defender's BlueHammer vulnerability

Why organizations need to act immediately

Exploiting privilege escalation vulnerabilities is one of the most common techniques used by modern ransomware groups. Even if an attacker initially gains limited access to a workstation, they can then exploit such vulnerabilities to gain full control of the system and move laterally within the corporate network.

Experts recommend immediately installing all updates Microsoft security monitoring suspicious activity through threat detection tools, and implementing the principle of least privilege on corporate accounts.

See also: Daktronics: Critical vulnerabilities in highway signs

The BlueHammer case is yet another reminder that even built-in security solutions can become entry points for cybercriminals when critical vulnerabilities are discovered. In an era where ransomware attacks are constantly evolving, timely installation of updates and effective cybersecurity management remain the most important lines of defense for any organization.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS