Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Lalit Modi recounts exchange with former RCB legend following 2011 IPL auction rejection

    April 18, 2026

    Cyberpunk platformers, gallivanting geckos and other new indie games worth checking out

    April 18, 2026

    American Eagle is back with Syd and not sorry about it

    April 18, 2026
    Facebook X (Twitter) Instagram
    Select Language
    Facebook X (Twitter) Instagram
    NEWS ON CLICK
    Subscribe
    Saturday, April 18
    • Home
      • United States
      • Canada
      • Spain
      • Mexico
    • Top Countries
      • Canada
      • Mexico
      • Spain
      • United States
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Health
    • Science
    • Sports
    • Travel
    NEWS ON CLICK
    Home»Science & Technology»US Science & Tech»Hackers are abusing unpatched Windows security flaws to hack into organizations
    US Science & Tech

    Hackers are abusing unpatched Windows security flaws to hack into organizations

    News DeskBy News DeskApril 17, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
    Hackers are abusing unpatched Windows security flaws to hack into organizations
    Share
    Facebook Twitter Pinterest Email Copy Link

    Hackers have broken into at least one organization using Windows vulnerabilities published online by a disgruntled security researcher over the last two weeks, according to a cybersecurity firm.

    On Friday, cybersecurity company Huntress said in a series of posts on X that its researchers have seen hackers taking advantage of three Windows security flaws, dubbed BlueHammer, UnDefend, and RedSun. 

    It’s unclear who the target of this attack is, and who the hackers are.

    BlueHammer is the only bug among the three vulnerabilities being exploited that Microsoft has patched so far. A fix for BlueHammer was rolled out earlier this week. 

    It appears that the hackers are exploiting the bugs by using exploit code that the security researcher published online. 

    Earlier this month, a researcher who goes by Chaotic Eclipse published on their blog what they said was code to exploit an unpatched vulnerability in Windows. The researcher alluded to some conflict with Microsoft as the motivation behind publishing the code. 

    “I was not bluffing Microsoft and I’m doing it again,” they wrote. “Huge thanks to MSRC leadership for making this possible,” they added, referring to Microsoft’s Security Response Center, the company’s team that investigates cyberattacks and handles reports of vulnerabilities.

    Techcrunch event

    San Francisco, CA
    |
    October 13-15, 2026

    Days later, Chaotic Eclipse published UnDefend, and then earlier this week published RedSun. The researcher published code to exploit all three vulnerabilities on their GitHub page. 

    All three vulnerabilities affect the Microsoft-made antivirus Windows Defender, allowing a hacker to gain high-level or administrator access to an affected Windows computer.

    TechCunch could not reach Chaotic Eclipse for comment.

    In response to a series of specific questions, Microsoft’s communications director Ben Hope said in a statement that the company supports “coordinated vulnerability disclosure, a widely adopted industry practice that helps ensure issues are carefully investigated and addressed before public disclosure, supporting both customer protection and the security research community.”

    This is a case of what the cybersecurity industry calls “full disclosure.” When researchers find a flaw, they can report it to the affected software maker to help them fix it. At that point, usually the company acknowledges receipt, and if the vulnerability is legitimate, the company works to patch it. Often, the company and researchers agree on a timeline that establishes when the researcher can publicly explain their findings. 

    Sometimes, for a variety of reasons, that communication breaks down and researchers publicly disclose details of the bug. In some cases, in part to prove the existence or severity of a flaw, researchers go a step further and publish “proof-of concept” code capable of abusing that bug.

    When that happens, cybercriminals, government hackers, and others can then take the code and use it for their attacks, which prompts cybersecurity defenders to rush to deal with the fallout. 

    “With these being so easily available now, and already weaponized for easy use, for better or for worse I think that ultimately puts us in another tug-of-war match between defenders and cybercriminals,” John Hammond, one of the researchers at Huntress who has been tracking the case, told TechCrunch. 

    “Scenarios like these cause us to race with our adversaries; defenders frantically try to protect against ill-intended actors who rapidly take advantage of these exploits… especially now as it is just ready-made attacker tooling,” said Hammond.

    bugs Cybersecurity infosec Microsoft Vulnerabilities Windows Zero-days
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
    News Desk
    • Website

    News Desk is the dedicated editorial force behind News On Click. Comprised of experienced journalists, writers, and editors, our team is united by a shared passion for delivering high-quality, credible news to a global audience.

    Related Posts

    US Science & Tech

    Cyberpunk platformers, gallivanting geckos and other new indie games worth checking out

    April 18, 2026
    US Science & Tech

    Once close enough for an acquisition, Stripe and Airwallex are now going after each other

    April 18, 2026
    US Science & Tech

    Sam Altman’s project World looks to scale its human verification empire. First stop: Tinder.

    April 17, 2026
    US Science & Tech

    15 years after ‘Video Games,’ Lana Del Rey has an actual video game song

    April 17, 2026
    CA Science & Tech

    Asus Zenbook A16 Canadian Review: Sometimes bigger is better

    April 17, 2026
    US Science & Tech

    The PBS Artemis II documentary is streaming on YouTube

    April 17, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Don't Miss

    Lalit Modi recounts exchange with former RCB legend following 2011 IPL auction rejection

    News DeskApril 18, 20260

    The landscape of the Indian Premier League (IPL) is defined by sliding-door moments, decisions that…

    Cyberpunk platformers, gallivanting geckos and other new indie games worth checking out

    April 18, 2026

    American Eagle is back with Syd and not sorry about it

    April 18, 2026

    The Curator: 12 best jewellery gifts to buy in 2026 – National

    April 18, 2026
    Tech news by Newsonclick.com
    Top Posts

    Aeromexico connecting Mexico with the world

    March 20, 2026

    ‘We’ll never know why’: Former CEO recalls fatal B.C. ferry sinking 20 years later

    March 22, 2026

    What to Feed Backyard Birds: A Species-by-Species Guide

    March 20, 2026

    Barcelona Events, Festivals, Exhibitions, and Concerts

    December 7, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Editors Picks

    Lalit Modi recounts exchange with former RCB legend following 2011 IPL auction rejection

    April 18, 2026

    Cyberpunk platformers, gallivanting geckos and other new indie games worth checking out

    April 18, 2026

    American Eagle is back with Syd and not sorry about it

    April 18, 2026

    The Curator: 12 best jewellery gifts to buy in 2026 – National

    April 18, 2026
    About Us

    NewsOnClick.com is your reliable source for timely and accurate news. We are committed to delivering unbiased reporting across politics, sports, entertainment, technology, and more. Our mission is to keep you informed with credible, fact-checked content you can trust.

    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube
    Latest Posts

    Lalit Modi recounts exchange with former RCB legend following 2011 IPL auction rejection

    April 18, 2026

    Cyberpunk platformers, gallivanting geckos and other new indie games worth checking out

    April 18, 2026

    American Eagle is back with Syd and not sorry about it

    April 18, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    • Advertise
    • Contact Us
    © 2026 Newsonclick.com || Designed & Powered by ❤️ Trustmomentum.com.

    Type above and press Enter to search. Press Esc to cancel.