Hackers exploit unpatched Windows security flaws to compromise organizations


Hackers have breached at least one organization using Windows vulnerabilities posted online by a disgruntled security researcher over the past two weeks, according to the cybersecurity firm.

Cybersecurity firm Huntress said Friday Series of posts on X Its researchers saw hackers exploiting three security flaws in the Windows operating system, called BlueHammer, UnDefend, and RedSun.

It is not clear who the target of this attack is and who the hackers are.

BlueHammer is the only one of the three exploited vulnerabilities at Microsoft Corrected yet. A fix was rolled out to BlueHammer earlier this week.

The hackers appear to be exploiting the bugs using exploit codes posted online by the security researcher.

Earlier this month, a researcher named it Chaotic Eclipse Posted on their blog What they said was code to exploit an unpatched vulnerability in the Windows operating system. The researcher pointed out that there were some disagreements with Microsoft as a motive for publishing the code.

“I wasn’t fooling Microsoft and I would do it again,” they said books. “Many thanks to MSRC leadership for making this possible,” they added, referring to Microsoft’s Security Response Center, the company’s team that investigates cyberattacks and handles vulnerability reports.

TechCrunch event

San Francisco, California
|
October 13-15, 2026

Days later, Chaotic eclipse Published by UnDefend, then earlier this week published by RedSun. The researcher published code to exploit the three vulnerabilities on his device GitHub page.

All three vulnerabilities affect Microsoft’s Windows Defender antivirus, allowing a hacker to gain high-level or administrator access to a Windows computer.

TechCunch was unable to reach Chaotic Eclipse for comment.

In response to a series of pointed questions, Ben Hope, Microsoft’s director of communications, said in a statement that the company supports “coordinated vulnerability disclosure, a widely adopted industry practice that helps ensure issues are carefully investigated and remedied before public disclosure, supporting the protection of customers and the security research community.”

This is a case of what the cybersecurity industry calls “full disclosure.” When researchers find a bug, they can report it to the affected software maker to help them fix it. At that point, the company usually acknowledges receipt, and if the vulnerability is legitimate, the company works to patch it. Often, the company and researchers agree on a timeline that specifies when the researcher can publicly explain their findings.

Sometimes, for various reasons, this connection is broken and researchers publicly reveal details of the error. In some cases, to partially prove the existence or seriousness of a flaw, researchers go further and publish “proof-of-concept” code capable of abusing the flaw.

When that happens, cybercriminals, government hackers, and others can take the code and use it in their attacks, prompting cybersecurity advocates to rush to deal with the repercussions.

“With these devices now readily available, and already weaponized for ease of use, for better or worse, I think this ultimately puts us in another tug of war between defenders and cybercriminals,” John Hammond, one of the researchers at Huntress who has been tracking the case, told TechCrunch.

“Scenarios like these leave us racing against our adversaries as defenders frantically try to protect against bad-faith actors who quickly exploit these vulnerabilities… especially now that they are just attack tools at the ready,” Hammond said.

Leave a Reply

Your email address will not be published. Required fields are marked *