TechOptima Ignite
TechOptima Solutions (636) 777-7702

CISA Confirms BlueHammer Exploit Actively Used in Ransomware Attacks

July 7, 2026

CISA confirmed on Monday that ransomware gangs have begun exploiting a high-severity Microsoft Defender privilege escalation vulnerability that has previously been abused in zero-day attacks. BlueHammer was leaked by a security researcher known as "Nightmare Eclipse" in early April, together with proof-of-concept exploit code, in protest at how the Microsoft Security Response Center (MSRC) handles the disclosure process. Microsoft explains in a security advisory: “Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.” Will Dormann, principal vulnerability analyst at Tharros, told BleepingComputer in April that while the issue is not easy to exploit, it gives local attackers access to the Security Account Manager (SAM) database, which contains password hashes for local accounts.

CISA has confirmed active exploitation of the BlueHammer vulnerability in Microsoft Defender by ransomware gangs, adding it to the Known Exploited Vulnerabilities catalog with a patching deadline. The flaw, a local privilege escalation issue, was leaked in early April 2026 by researcher Nightmare Eclipse along with PoC code as a protest against Microsoft's disclosure handling. It allows authorized attackers to elevate privileges by accessing the SAM database for password hashes and potentially gaining SYSTEM control.

Microsoft described it euphemistically as “insufficient granularity of access control,” which the host criticizes as improper design rather than a minor issue, and patched it in the April 2026 Patch Tuesday. Huntress Labs had already observed zero-day hands-on-keyboard exploitation shortly after. Nightmare Eclipse has disclosed multiple related Windows zero-days affecting Defender, BitLocker, and other components, some of which were fixed in June 2026 updates.

CISA initially added BlueHammer (CVE-2026-33825) to KEV on April 22, mandating federal patches by May 7 due to its frequent use as an attack vector. Microsoft has not yet officially tagged it as exploited, but CISA's update now links it to ransomware campaigns, underscoring ongoing risks from Defender vulnerabilities.

Tags: SECURITY | RANSOMWARE | MALWARE | CISA | MICROSOFT

Source: sn-1086-notes.pdf

← Back to Blog