'BlueHammer' Windows Zero-Day Exploit Signals Microsoft Bug Disclosure Issues

2026-04-09T20:51:43Zfdf96c4a2c859c6e9ec7ac3c8171786da2aed0cd2a4f6eb402e55e7f381e0778
AI-assisted-attackAPT28BlueHammerChaotic EclipseDNS-manipulationFortiClientFortinetGitHubIranian-actorsMaaSMedusaOT-securityPLCReact2ShellSOHO-routerStorm-1175Venom-StealerWindowscredential-harvestingemoticon-covert-comms','bug-bounty-disruptionexploitprivilege-escalationransomwaresupply-chainzero-day

What happened

This Dark Reading digest highlights multiple active and high-risk threats: a Windows zero-day PoC released by a researcher using the alias “Chaotic Eclipse” (BlueHammer) enabling local system takeover; an in-the-wild FortiClient authentication-bypass zero-day (CVE-2026-35616) for which Fortinet issued an emergency patch; Storm-1175 rapidly deploying Medusa ransomware by chaining n-day and zero-day flaws; automated credential-harvesting campaigns exploiting React2Shell-exposed Next.js apps; APT28 conducting stealthy espionage via SOHO-router DNS modification; Iranian-linked disruption of OT/PLC

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
fdf96c4a2c859c6e9ec7ac3c8171786da2aed0cd2a4f6eb402e55e7f381e0778
Enrichment time
2026-04-09T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.