BlueHammer: Windows zero-day exploit leaked

2026-04-09T02:51:55Z895ccbe5938ce06b578a625daabb59d449f1c5d31fa3f553ba12de3916b80ec0
access-reviewschaos-malwarecritical-infrastructureexploit-leakflatpakgenerative-ai-data-securityiranian-aptlinux-cloudlocal-privilege-escalationmisconfigured-serversnpmopen-source-supply-chainopensslot-plcpatchesproof-of-conceptrockwell-automationsandbox-escapesocial-engineeringvulnerability-managementwindowszero-day

What happened

This feed highlights multiple high-impact security developments: a public PoC for an unpatched Windows local privilege escalation dubbed “BlueHammer” has been leaked to GitHub (researchers have fixed bugs and expanded its reach to Windows 10/11 and Server); Flatpak 1.16.4 patches a complete sandbox escape allowing host file access and code execution (CVE-2026-34078) plus additional host filesystem issues (CVE-2026-34079 and GHSA-2fxp-43j9-pwvc); OpenSSL 3.6.2 fixes several vulnerabilities (including CVE-2026-31790, CVE-2026-2673, CVE-2026-28386). Other notable items: Chaos botnet malware is扩展从

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
895ccbe5938ce06b578a625daabb59d449f1c5d31fa3f553ba12de3916b80ec0
Enrichment time
2026-04-09T02:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.