CVE Tools

BlueHammer Vulnerability Exploited in Ransomware Attacks

SecurityWeekBy Eduard Kovacs

Reported exploitedMicrosoft Defender

Our summary

CISA says a vulnerability in Microsoft Defender, tracked as BlueHammer and identified as CVE-2026-33825, is being used as part of ransomware intrusions. The issue affects Microsoft’s Defender component and can enable authenticated attackers to escalate privileges, which is why it matters for incident risk. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog and later updated the entry to indicate ransomware exploitation in the wild, underscoring the need to apply Microsoft’s April patches.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store