Securityaffairs.Co Ransomware Gangs Exploit Microsoft Defender BlueHammer Flaw for Attacks
Article Content
- •CVE-2026-33825, known as BlueHammer, allows privilege escalation in Microsoft Defender.
- •CISA has confirmed active exploitation of BlueHammer in ransomware attacks.
- •Organizations using affected Windows systems are urged to take immediate action.
Ransomware gangs are actively exploiting a high-severity vulnerability in Microsoft Defender, tracked as CVE-2026-33825 and nicknamed BlueHammer. This flaw allows local attackers to bypass access controls and escalate privileges on affected Windows systems. The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, confirming its use in real-world ransomware attacks. The vulnerability was first disclosed as a zero-day exploit by a researcher in April 2026, and has since transitioned from proof-of-concept to active exploitation. Organizations using Microsoft Defender are at risk, and immediate action is recommended to mitigate potential attacks. The situation is evolving, with CISA monitoring the impact and advising on necessary precautions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-33825 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
New BigDiskBuster Zero-Day Blocks Microsoft Defender Updates Security researcher Abdelhamid Naceri, known as NightmareEclipse, released a proof-of-concept tool named BigDiskBuster that prevents Microsoft Defender from installing critical updates. This zero-day vulnerability affects all supported versions of Windows by filling disk space to block update processes. The tool does…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…