The cybersecurity agency CISA has confirmed that the BlueHammer vulnerability in Microsoft Defender is now being actively exploited in ransomware attacks. The flaw, tracked as CVE-2026-33825, was publicly disclosed by a disgruntled researcher in April before Microsoft had released patches, and was initially exploited as a zero-day for privilege escalation. While CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, the specific ransomware group using the exploit remains unknown, and the agency's update has raised questions about how useful these notifications are for security defenders.