CISA Windows BlueHammer Flaw Now Exploited by Ransomware Gangs
Ransomware crews are now abusing a Windows privilege escalation bug in Microsoft Defender that CISA warned about weeks ago.
The flaw lets low-privileged users trigger elevation through Defender's scanning process. CISA added it to the KEV catalog after seeing it in zero-day attacks and now confirms ransomware use.
Affects unpatched Windows systems missing Microsoft’s April 2026 security update. Common risk areas include corporate laptops, developer workstations, and endpoints where local compromise can be chained into ransomware activity.
Ransomware use was confirmed months after the April public leak and patch cycle.
