Get all your news in one place.
100's of premium titles.
One app.
Start reading
TechRadar
TechRadar
Sead Fadilpašić

CISA puts US government agencies on two-week deadline to patch Microsoft Defender BlueHammer zero-day exploit

A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it.
  • CISA added BlueHammer, a Microsoft Defender privilege escalation flaw, to its Known Exploited Vulnerabilities catalog.
  • Federal agencies have until May 6 to patch or discontinue use, as researchers confirmed active exploitation in the wild.
  • The disclosure came from “Chaotic Eclipse,” who also revealed two other Defender zero‑days, with Huntress Labs linking exploitation attempts to suspicious global infrastructure.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added BlueHammer to its catalog of known exploited vulnerabilities (KEV), giving Federal Civilian Executive Branch (FCEB) agencies a two-week deadline to patch up or stop using the vulnerable software entirely.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.