Menu

Post image 1
Post image 2
Post image 3
Post image 4
Post image 5
Post image 6
1 / 6
0

Windows Defender 'BlueHammer' vulnerability now exploited as part of malware campaigns — CISA issues warning despite patch release on April 14

Latest from Tom's Hardware ·Bruno Ferreira·3 months ago
#tuykdS2q
Reading 0:00
15s threshold

(Image credit: Getty Images) Late spring and early summer in the cybersecurity world were marked by multiple Windows exploits, thanks to the efforts of the controversial hacker figure Nightmare Eclipse . One of the better-known exploits is BlueHammer, a race condition in Windows Defender that gets you a shell with access to the SYSTEM user with just a small script — in other words, the keys to the kingdom in exchange for a double-click. Microsoft released a patch on April 14, but as a clear illustration of the lack of cybersecurity awareness, CISA (the U.S. cyber-defense agency) yesterday marked BlueHammer as actively exploited in ransomware campaigns. That marks about a month and a half since the patch, and it illustrates quite clearly that when it comes to computer security , the publication of a patch is almost always the easy part; getting that patch into every device that needs it is the real tricky bit.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More