CISA has updated its Known Exploited Vulnerabilities catalog to confirm that CVE-2026-33825, a Microsoft Defender privilege escalation flaw dubbed BlueHammer, has been actively exploited in ransomware attacks. The vulnerability was publicly disclosed on April 2 before Microsoft released patches on April 14, and security firm Huntress observed zero-day exploitation in the wild. CISOs are advised to verify patch deployment, monitor KEV catalog updates for ransomware-use designations (not just new entries), and hunt for post-compromise privilege escalation activity in endpoint telemetry.
139 Impressions