CISA has updated its Known Exploited Vulnerabilities catalog to confirm that CVE-2026-33825, a Microsoft Defender privilege escalation flaw dubbed BlueHammer, has been actively exploited in ransomware attacks. The vulnerability was publicly disclosed on April 2 before Microsoft released patches on April 14, and security firm Huntress observed zero-day exploitation in the wild. CISOs are advised to verify patch deployment, monitor KEV catalog updates for ransomware-use designations (not just new entries), and hunt for post-compromise privilege escalation activity in endpoint telemetry.

3m read timeFrom securityboulevard.com
Post cover image
Table of contents
What happenedWho is affectedWhy CISOs should care3 practical actions
139 Impressions