
- CISA added BlueHammer, a Microsoft Defender privilege escalation flaw, to its Known Exploited Vulnerabilities catalog.
- Federal agencies have until May 6 to patch or discontinue use, as researchers confirmed active exploitation in the wild.
- The disclosure came from “Chaotic Eclipse,” who also revealed two other Defender zero‑days, with Huntress Labs linking exploitation attempts to suspicious global infrastructure.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added BlueHammer to its catalog of known exploited vulnerabilities (KEV), giving Federal Civilian Executive Branch (FCEB) agencies a two-week deadline to patch up or stop using the vulnerable software entirely.