CRITICAL ⚡ MUST-KNOW
CISA Confirms Ransomware Gangs Exploiting Microsoft Defender 'BlueHammer' Flaw (CVE-2026-33825)
CISA confirmed that ransomware gangs are now exploiting CVE-2026-33825, a privilege escalation vulnerability in Microsoft Defender dubbed BlueHammer. The flaw was previously abused as a zero-day before patches were released, and is now being incorporated into ransomware operations. Organizations should apply Microsoft’s patches for CVE-2026-33825 immediately and review Defender logs for signs of privilege escalation activity.