Connect with us

News

Hackers are abusing unpatched Windows security flaws to hack into organizations

info

Published

on

Photo mosh getty windows logo.jpg

Hackers have broken into at least one organization using Windows vulnerabilities published online by a disgruntled security researcher over the last two weeks, according to a cybersecurity firm.

On Friday, cybersecurity company Huntress said in a series of posts on X that its researchers have seen hackers taking advantage of three Windows security flaws, dubbed BlueHammer, UnDefend, and RedSun. 

It’s unclear who the target of this attack is, and who the hackers are.

BlueHammer is the only bug among the three vulnerabilities being exploited that Microsoft has patched so far. A fix for BlueHammer was rolled out earlier this week. 

It appears that the hackers are exploiting the bugs by using exploit code that the security researcher published online. 

Earlier this month, a researcher who goes by Chaotic Eclipse published on their blog what they said was code to exploit an unpatched vulnerability in Windows. The researcher alluded to some conflict with Microsoft as the motivation behind publishing the code. 

“I was not bluffing Microsoft and I’m doing it again,” they wrote. “Huge thanks to MSRC leadership for making this possible,” they added, referring to Microsoft’s Security Response Center, the company’s team that investigates cyberattacks and handles reports of vulnerabilities.

Techcrunch event

San Francisco, CA
|
October 13-15, 2026

Days later, Chaotic Eclipse published UnDefend, and then earlier this week published RedSun. The researcher published code to exploit all three vulnerabilities on their GitHub page

All three vulnerabilities affect the Microsoft-made antivirus Windows Defender, allowing a hacker to gain high-level or administrator access to an affected Windows computer.

TechCunch could not reach Chaotic Eclipse for comment.

In response to a series of specific questions, Microsoft’s communications director Ben Hope said in a statement that the company supports “coordinated vulnerability disclosure, a widely adopted industry practice that helps ensure issues are carefully investigated and addressed before public disclosure, supporting both customer protection and the security research community.”

This is a case of what the cybersecurity industry calls “full disclosure.” When researchers find a flaw, they can report it to the affected software maker to help them fix it. At that point, usually the company acknowledges receipt, and if the vulnerability is legitimate, the company works to patch it. Often, the company and researchers agree on a timeline that establishes when the researcher can publicly explain their findings. 

Sometimes, for a variety of reasons, that communication breaks down and researchers publicly disclose details of the bug. In some cases, in part to prove the existence or severity of a flaw, researchers go a step further and publish “proof-of concept” code capable of abusing that bug.

When that happens, cybercriminals, government hackers, and others can then take the code and use it for their attacks, which prompts cybersecurity defenders to rush to deal with the fallout. 

“With these being so easily available now, and already weaponized for easy use, for better or for worse I think that ultimately puts us in another tug-of-war match between defenders and cybercriminals,” John Hammond, one of the researchers at Huntress who has been tracking the case, told TechCrunch. 

“Scenarios like these cause us to race with our adversaries; defenders frantically try to protect against ill-intended actors who rapidly take advantage of these exploits… especially now as it is just ready-made attacker tooling,” said Hammond.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

Ekiti 2026: Re-elect Oyebanji for second term – Tinubu tells residents

info

Published

on

By

Tinubu 2 1.jpg

President Bola Ahmed Tinubu has commended Governor Biodun Oyebanji’s performance in office, telling Ekiti voters that the governor came into leadership fully prepared to serve the people.

Speaking ahead of the June 20 governorship election, Tinubu urged residents to re-elect Oyebanji for a second term.

The endorsement came on Tuesday at the All Progressives Congress mega rally in Ado-Ekiti. The venue was packed with party faithful, allies from other political groups, and supporters across religious and ethnic lines, all showing solidarity with Oyebanji’s re-election bid.

Represented by Vice President Kashim Shettima, President Tinubu praised Ekiti citizens for their loyalty to the APC over the years.

He described the state as fortunate to have Oyebanji at the helm of affairs, noting that the governor’s actions and policies prove that true leadership is about serving people, not oppressing them or undermining their rights.

Tinubu highlighted Oyebanji’s humility, patience, and respect for traditional rulers and past leaders, pointing out the absence of opposition posters across the state as a sign of Oyebanji’s wide acceptance.

“On Saturday, go out and re-elect this humble and peaceful man to further serve you better,” Shettima said on Tinubu’s behalf. The President then symbolically handed Oyebanji over to former governors and first ladies, urging them to secure victory for him.

Chairman of the APC National Campaign Council and Kaduna State Governor, Uba Sani, described Oyebanji’s popularity as electrifying.

Chairman of the APC Governors Forum and Imo State Governor, Hope Uzodinma, said the party’s visibility in Ekiti was unmatched. He noted that only the APC had campaigned market to market and house to house.

APC National Chairman, Prof Nentawe Yilwadta, insisted the party’s confidence was rooted in Oyebanji’s connection to the people, not just in being the ruling party.

A visibly elated Governor Oyebanji, joined by his wife Dr Olayemi Oyebanji and Deputy Monisade Afuye, said he was not relying on federal might but on his record and the promises he kept since 2022.

He appealed for a peaceful election and promised that his second term would surpass the achievements of the last three and a half years.

Continue Reading

News

Nigerian Striker Toyosi Olusanya Completes Permanent Move to Aberdeen on Two-Year Deal

info

Published

on

By

IMG 20260616 WA0268.jpg

Scottish Premiership club Aberdeen have secured the permanent signing of London-born Nigerian striker Toyosi Olusanya, with the forward committing his future to the club on a two-year contract after an impressive loan spell.

READ ALSO: Isaac John Turns Heads at Ex-Internationals Cup in Lagos, Declares Himself Ready for the Big Stage 

Sports247 reports that the 28-year-old joins the Dons as a free agent following the expiration of his contract with Major League Soccer side Houston Dynamo. His arrival marks another key addition to manager Stephen Robinson’s rebuilding project ahead of the new season.

Olusanya spent the second half of the previous campaign on loan at Aberdeen, where he quickly adapted to life in Scottish football.

During his stint, he made 18 appearances across all competitions and contributed three goal involvements, earning the confidence of the coaching staff and convincing the club to pursue a permanent deal.

The striker’s work rate, physical presence, and attacking versatility made him a valuable option during his loan spell, and Aberdeen will be hoping he can build on that foundation as they prepare for the challenges of the upcoming Premiership campaign.

His signing represents the fifth addition to Robinson’s squad during the summer transfer window as the club continues to strengthen its roster with an eye on domestic success and improved performances across all competitions.

Born in London and eligible to represent Nigeria, Olusanya has enjoyed a career spanning English football and Major League Soccer before making the move north of the border.

The permanent transfer offers him the opportunity to continue his development in a familiar environment after settling into the team during his loan period.

For Aberdeen, retaining a player who already understands the club’s style and expectations provides continuity as they reshape the squad for the new season.

Supporters will be eager to see the Nigerian forward translate his promising displays into consistent goals and assists over the course of the campaign.

With his future now secured at Pittodrie, Olusanya begins the next chapter of his career aiming to establish himself as a key figure in Aberdeen’s attack and help the club compete strongly in the Scottish Premiership.

Continue Reading

Trending