CISA, the US cybersecurity agency, has confirmed that ransomware groups are now actively exploiting a Microsoft Defender vulnerability known as BlueHammer. The flaw was patched in April 2026, so systems that are behind on Windows updates are the ones at risk.
- What it is: CVE-2026-33825, a privilege escalation flaw in Microsoft Defender. An attacker who already has a foothold on a machine can use it to gain full system-level control.
- Who is affected: Any Windows computer or server that has not installed the April 2026 (or later) Windows security updates.
- What the risk is: Ransomware operators are using the flaw to escalate their access after an initial break-in, which can lead to data theft and encrypted files across the network.
- What action is needed: Confirm every Windows machine in your business is current with Windows Update. Systems patched from April 2026 onwards are protected against this flaw.
We recommend treating any unpatched machine as a priority this week. If OzComm manages your environment, updates of this kind are applied as part of routine patching, and if you are unsure whether your machines are up to date, contact us and we will confirm. More detail is available from BleepingComputer and SecurityWeek.