惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
Stack Overflow Blog
Stack Overflow Blog
S
SegmentFault 最新的问题
博客园 - 司徒正美
aimingoo的专栏
aimingoo的专栏
U
Unit 42
GbyAI
GbyAI
B
Blog RSS Feed
博客园 - Franky
L
LangChain Blog
Hugging Face - Blog
Hugging Face - Blog
美团技术团队
The GitHub Blog
The GitHub Blog
Y
Y Combinator Blog
云风的 BLOG
云风的 BLOG
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 三生石上(FineUI控件)
Microsoft Azure Blog
Microsoft Azure Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
G
Google Developers Blog
Last Week in AI
Last Week in AI
阮一峰的网络日志
阮一峰的网络日志
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Apple Machine Learning Research
Apple Machine Learning Research

Latest from Windows Central

"An unmatched upgrade opportunity": Intel's new Core Series 3 mobile CPUs target "value buyers"… "There are over 5,700 combinations.": I attended Panasonic's USS Intrepid press conference and saw 10Gbps, Wi‑Fi 7 and on‑device AI in the new Toughbook 56, but should you swap out your Toughbook 55? "We "So Mac folks feel comfortable": Microsoft Microsoft thinks you'll want an Xbox Controller and 1 year of Microsoft 365 and Xbox Game Pass over a MacBook Neo "Thank you to every Greymane": Crimson Desert shows no signs of slowing down, topping over 5 million sales… "Another all-round excellent mini PC:" Beelink's discounted desktop is fantastic for intensive work and… Xbox's Starfield gets Nintendo Switch 2 rating days after its PS5 release, keeping hopes for a port of Bethesda's RPG alive — here's what we know "The stuff that we're seeing is really well put together": Xbox game publishing chief says Forza Horizon 6 takes him back to the golden years of racing games Microsoft's Xbox games lead Matt Booty says its studios are in a "culture of cultures" and work together more than you think — Blizzard is even helping with Fable Rumored feature coming to Steam that will help you track prices, and Microsoft should copy it immediately for Xbox and… Xbox and Best Buy want to help you build your first video game in 2026 Microsoft prepares display upgrades and two stage launch for new Surface Pro and Surface Laptop with Intel and… Someone discovered Seagate's Xbox Storage Expansion cards can be used on PC — which has made their value more… ID@Xbox makes a bold claim — “Games launching day one into Game Pass… do very well on other platforms… Before Forza Horizon 6 takes us to Japan, let's remember where the legend began almost 14 years ago "Users can now simply ask what happened": AppControl's optional AI integration gives you in-depth PC diagnostic history in plain English — It works with popular LLMs, but I'll use offline models for added security Our friends at Tom's Guide are upgrading: Here's what it means, and how our sister site's overhaul… "Quantity over quality is not always the answer": WWE 2K26 comes close to being the best in the world, but yearly releases are holding it back I "This is one headset that absolutely will not disappoint anyone": Our favorite Xbox headset raises the bar for sound quality with a price that's lower than I expected "One of the better laptops I’ve encountered and one I’d happily use daily": This high-end ThinkPad is a solid bet for professionals — especially after this generous discount I've finally found a loophole to block a specific type of YouTube ads, and it won’t cost you a dime: Just a… www.windowscentral.com "The Lotus guys probably figured it didn't matter to be wrong": Excel thinks 1900 was a leap year because of a small shortcut taken in the '80s — I'll think of this next time I want to cut corners Starfield's sales on PlayStation 5 make me wonder why Xbox even bothered... was this worth devaluing exclusivity? Overwatch Season 2 is LIVE! Xbox Your Xbox Storage Expansion Cards can have a life after the console if you get a simple adapter for your PC Microsoft is hiking Surface Prices, but one of its best laptops is dodging it with this BIG discount
"Microsoft fired the skilled people, leaving flowchart fo...
Cale Hunt · 2026-04-16 · via Latest from Windows Central
Windows 11 Blue Hammer
(Image credit: Future | Edited with Gemini)

On April 2, 2026, a security researcher using the name Chaotic Eclipse published a blog post stating that they were "doing it again." Under this warning, a link to a GitHub account page for a user named "Nightmare Eclipse" containing an exploit known as BlueHammer.

BlueHammer, as it turns out, is a zero-day Windows exploit, meaning it was released into the wild ahead of any Microsoft action. BlueHammer has been confirmed to work by Will Dormann, a principal vulnerability analyst at Tharros (via BleepingComputer).

As explained, BlueHammer works by exploiting a local privilege escalation (LPE), time-of-check to time-of-use (TOCTOU), and a path of confusion, breaking down Windows Defender to the point where attackers receive SYSTEM privileges for a complete PC takeover.

It's a nasty little bug, to say the least, and it appears to have been released into the wild due to perceived incompetence on the part of Microsoft's Security Response Center (MSRC).

Microsoft Security Response Center takes the blame; Microsoft responds

BlueHammer GitHub page

The note attached to the GitHub BlueHammer page. (Image credit: GitHub)

The worst part about the BlueHammer incident is that, according to the leaker, it apparently could have been prevented. In the original blog post, the frustrated security researcher stated:

"Unlike previous times, I'm not explaining how this works, y'all geniuses can figure it out. Also, huge thanks to MSRC leadership for making this possible!!! And special thanks to Tom Gallagher!"

The Gallagher mentioned in the jab is assumedly the VP of Engineering for MSRC. The jabs don't stop there, continuing on the BlueHammer GitHub page.

"I'm just really wondering what was the math behind their decision, like you knew this was going to happen and you still did whatever you did? Are they serious?"

Judging by these semi-vague statements, whoever leaked the BlueHammer exploit attempted first to privately work with the MSRC in order to get the issue fixed, but became fed up.

Will Dormann confirming BlueHammer works

Will Dormann confirms the BlueHammer exploit works in a Mastodon post. (Image credit: @wdormann (Mastodon))

Dormann, who confirmed the exploit, shared some interesting words on Mastodon on April 6.

"MSRC used to be quite excellent to work with. But to save money Microsoft fired skilled people, leaving flowchart followers. I wouldn't be surprised if Microsoft closed the case after the reporter refused to submit a video of the exploit, since that's apparently an MSRC requirement now."

The BlueHammer incident isn't a good look for Microsoft's main line of defense against zero-day exploits. Of course, it's nigh impossible to confirm that the leaker actually reached out to Microsoft's Security Response Center team before posting the exploit on GitHub.


In a response to BleepingComputer, added to the original article covering BlueHammer, a Microsoft spokesperson said this:

"Microsoft has a customer commitment to investigate reported security issues and update impacted devices to protect customers as soon as possible. We also support coordinated vulnerability disclosure, a widely adopted industry practice that helps ensure issues are carefully investigated and addressed before public disclosure, supporting both customer protection and the security research community."

It's a rather boilerplate response, and security communities are understandably upset about the leaked exploit and Microsoft's perceived incompetence.

Over on GitHub, the BlueHammer exploit has, at the time of writing, some 1,200 stars and 425 forks. This essentially means that at least 425 people have taken it upon themselves to modify the code for who knows what reasons.

Microsoft promised to make Windows 11 better, so why did MSRC allegedly drop the ball?

Windows 11 Search

The Windows 11 Search bar inside the Start menu. (Image credit: Future)

A zero-day exploit like BlueHammer released into the wild is one thing, but when it's claimed to be in response to MSRC incompetence, it's something else entirely.

Microsoft has been putting a lot of resources lately into improving Windows, mainly in response to sustained negative feedback that's often turned into outrage from the community.

While the EVP of Windows & Devices at Microsoft, Pavan Davuluri, has promised his team is "focusing on making Windows 11 more responsive and consistent" by way of "improving system performance, app responsiveness, File Explorer and the Windows Subsystem for Linux," it won't mean much if Microsoft can't properly stay ahead of serious threats.

A zero-day exploit like BlueHammer released into the wild is one thing, but when it's claimed to be in response to MSRC incompetence, it's something else entirely.

On my mind is news about Claude Mythos, a new AI model that recently proved it could identify cybersecurity vulnerabilities that had gone unnoticed for decades. It was so powerful that it caused cybersecurity stocks to fall off a cliff, and it has since been put back into a cage by its Anthropic overlords while governments figure out what to do about the perceived threat.

If Microsoft has indeed gutted its MSRC team, as posited by Dormann, I don't doubt that Windows could be in serious trouble as security threats evolve.

Microsoft raked in about $281 billion in revenue in 2025. Surely more of that can go towards keeping the MSRC, which has been a key proponent of Windows development and upkeep since 1998, in top form.

BlueHammer was killed in a recent Windows update, but it was live for nearly two weeks

Will Dormann BlueHammer Mastodon

Security researcher Will Dormann comments on the BlueHammer fix and leftover vulnerabilities. (Image credit: @wdormann (Mastodon))

I've been following Will Dormann's updates regarding BlueHammer, and he recently posted proof that the exploit was killed in the latest Windows 11 CVE-2026-33825 update from April 14, 2026.

Dormann notes that the "exploit doesn't get past the point where it makes a symlink within the Windows object manager." However, he also notes that "if you look under the hood, some of the suspicious parts of the exploit still seem to work."

So, yes, the exploit is technically broken after the Windows update, but some of the nasty bits remain.

What do you think about the BlueHammer incident?

All signs point to Microsoft's Security Response Center failing to act when it was presented with BlueHammer exploit details. Do you think the leaker is lying and is instead attempting to libel the company?

Or are you of the mind that security researcher Will Dormann is correct when he says that Microsoft gutted the MSRC program, which led to the leak after official channels failed to act?

Let me know what you think, including any first-hand experience you have with MSRC, in the comments section below.


Click to join us on r/WindowsCentral

Join us on Reddit at r/WindowsCentral to share your insights and discuss our latest news, reviews, and more.


Cale Hunt brings to Windows Central more than nine years of experience writing about PC gaming, Windows laptops, accessories, and beyond. If it runs Windows or in some way complements the hardware, there’s a good chance he knows about it, has written about it, or is already busy testing it.