Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit

2026-04-06T19:23:32Zeb226bf86c153a445fa8a8c9380c1547b69e12c77ec168b1afa346c15686aa3c
BlueHammerCVE-2025-55182CVE-2026-35616axiosbrowser-scanning","BrowserGate"cisacredential-theftcrypto-theftdevice-code-phishingdriftexploit-codeforticlient-emsfortinetmaintainer-compromisemedusanpmoauthprivilege-escalationqr-phishingransomwarereact2shellstorm-1175supply-chainwindowszero-day

What happened

Multiple high-risk security incidents reported: a disgruntled researcher published “BlueHammer,” exploit code for an unpatched Windows privilege-escalation zero-day that allows SYSTEM/elevated access; Fortinet FortiClient EMS suffers an actively exploited critical flaw (CVE-2026-35616) prompting emergency patches and a CISA remediation order; Microsoft links a Medusa ransomware affiliate (Storm-1175) to rapid n-day/zero-day attack activity. Other notable events include an automated credential-theft campaign abusing React2Shell (CVE-2025-55182), a $280M Drift protocol crypto theft tied to a six

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
eb226bf86c153a445fa8a8c9380c1547b69e12c77ec168b1afa346c15686aa3c
Enrichment time
2026-04-06T19:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit · Baitaphish