home.social

#bluehammer — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bluehammer, aggregated by home.social.

  1. #BlueHammer wurde zum 14. April 2026 als Defender Schwachstelle gepatcht. Hier meine Nachlese samt Link auf eine Fortra-Analyse.

    borncity.com/blog/2026/04/16/b

  2. Pissing off a hacker is never a good idea. The #BlueHammer researcher has dropped another one, abusing Microsoft Defender's dorky behaviour to gain NT Authority privileges.
    github.com/Nightmare-Eclipse/R
    #Security #Microsoft #Windows #RedSun

  3. Fully exploitable Windows Defender vulnerability with full source code public for >8 days no CVE assigned so far (BlueHammer).

    Writeup: hackingpassion.com/bluehammer-

    Full source code: github.com/Nightmare-Eclipse/B

    /cc @bsi Was ist eigentlich der "Prozess" für vollständig öffentliche Lücken zu denen es seit über einer Woche noch nicht einmal eine CVE Nummer gibt?

    Edit: Patch and CVE number CVE-2026-33825 available by now. Took 6 days though.

    #infosec #itsec #Microsoft #WindowsDefender #BlueHammer

  4. Recently this popped up, #Bluehammer a #Windows exploit that exploits Windows Defender for a local privilege elevation

    From user to system level..

    It triggers a Defender scan and locks that after, so it can access a certain database that is been backed up while Defender scans to gain system level access

    GitHub now gives a warning for the repo it seems:
    github.com/Nightmare-Eclipse/B

    Just be careful

  5. @wdormann Of course Microsoft used their GitHub ownership to remove the repo instead of fixing both problems (the exploit and the video requirement).