Ransomware extortionists are exploiting insufficient access controls in Microsoft Defender (CVE-2026-33825) to obtain SYSTEM privileges and fully compromise systems.
Ransomware gangs exploit a vulnerability in Microsoft Defender to gain access to the SAM database through insufficient access controls and obtain SYSTEM privileges.
Ransomware gangs are exploiting the BlueHammer vulnerability in Microsoft Defender for privilege escalation, putting Windows systems at widespread risk.
Microsoft’s benchmarking shows only marginal added value (under 0.05%) for additional email security tools, but experts emphasize that a percentage figure does not reveal the full risk picture and a single missed threat can be critical.