Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

BlueHammer turns into a ransomware step

2 min read
12:09UTC

CISA confirmed ransomware gangs are weaponising BlueHammer, the April Windows Defender flaw, to seize SYSTEM rights before deploying their encryptors.

TechnologyDeveloping
Key takeaway

A patched April flaw in Windows Defender is now a live SYSTEM-access step for ransomware crews.

CISA updated the Known Exploited Vulnerabilities (KEV) entry for CVE-2026-33825, the Windows Defender local-privilege-escalation (LPE) flaw known as BlueHammer, to confirm that ransomware gangs now exploit it for SYSTEM-level access before deploying encryptors. Microsoft patched the flaw on 14 April and CISA listed it on 22 April. It was disclosed by a researcher using the handle Chaotic Eclipse, whose run of Microsoft bugs produced a fifth unpatched zero-day last month . 1

The flaw works as a time-of-check-to-time-of-use race in Defender's remediation engine: the software checks a file's status, then acts on it a moment later, and an attacker swaps the target in between. On its own an LPE does nothing. Chained after an initial break-in, it hands an attacker the SYSTEM rights needed to switch off defences and encrypt at will. That is why the update matters: it turns a three-month-old patch that many programmes deprioritised into a live step in a working ransomware chain.

Deep Analysis

In plain English

Windows Defender is the built-in security software that comes free with Windows and is meant to stop malware. Researchers found a flaw in it that lets someone who has already broken into a computer, through some other route, use Defender itself to take full control of the machine, the highest level of access there is. CISA now says ransomware gangs are using this trick before locking victims' files, which is unsettling because the tool that is supposed to protect the computer has become part of the attack. A researcher who goes by the handle Chaotic Eclipse found the flaw; that same person has found several other serious Windows bugs this year.

Deep Analysis
Root Causes

Windows Defender's kernel-mode components run with system-level trust by design, which is precisely why compromising the security product itself hands a ransomware crew system-level access that a bug in an ordinary, already-restricted application cannot.

Chaotic Eclipse, the same handle already credited with a fifth zero-day disclosure this year, appears to work through private broker or bug-bounty channels rather than Microsoft's own coordinated-disclosure programme. The gap between a privately attributed find and CISA's public 'now confirmed exploited' update suggests BlueHammer circulated in criminal channels before any public patch timeline closed it.

What could happen next?
  • Risk

    Organisations that rely on Windows Defender as their primary endpoint protection now face a scenario where the protection layer itself can be turned against them at the privilege-escalation stage of an intrusion.

  • Meaning

    CISA's decision to update rather than newly list the entry signals the flaw was already tracked before ransomware use was confirmed, suggesting future KEV updates on existing entries deserve the same attention as new listings.

First Reported In

Update #9 · FortiBleed harvest linked to Lynx crew

BleepingComputer· 4 Jul 2026
Read original
Causes and effects
This Event
BlueHammer turns into a ransomware step
A patch many teams deprioritised in April has become a confirmed rung in the ransomware kill chain.
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.