// Alert

Microsoft 365 threat report

CVE-2026-33825 (BlueHammer), a privilege-escalation vulnerability in Microsoft Defender (CVSS 7.8), was patched April 14, 2026, following public proof-of-concept disclosure. As of June 30, 2026, CISA confirmed active exploitation by ransomware operators. The flaw allows low-privileged local users to escalate to SYSTEM via a race condition in Defender's file-remediation pipeline. Two related unpatched techniques (RedSun, Undefend) remain unaddressed.

// Get alerts for Microsoft 365