Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit
2026-04-06T19:23:32Z•eb226bf86c153a445fa8a8c9380c1547b69e12c77ec168b1afa346c15686aa3c
BlueHammerCVE-2025-55182CVE-2026-35616axiosbrowser-scanning","BrowserGate"cisacredential-theftcrypto-theftdevice-code-phishingdriftexploit-codeforticlient-emsfortinetmaintainer-compromisemedusanpmoauthprivilege-escalationqr-phishingransomwarereact2shellstorm-1175supply-chainwindowszero-day
What happened
Multiple high-risk security incidents reported: a disgruntled researcher published “BlueHammer,” exploit code for an unpatched Windows privilege-escalation zero-day that allows SYSTEM/elevated access; Fortinet FortiClient EMS suffers an actively exploited critical flaw (CVE-2026-35616) prompting emergency patches and a CISA remediation order; Microsoft links a Medusa ransomware affiliate (Storm-1175) to rapid n-day/zero-day attack activity. Other notable events include an automated credential-theft campaign abusing React2Shell (CVE-2025-55182), a $280M Drift protocol crypto theft tied to a six
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- eb226bf86c153a445fa8a8c9380c1547b69e12c77ec168b1afa346c15686aa3c
- Enrichment time
- 2026-04-06T19:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.