#bitlocker — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #bitlocker, aggregated by home.social.
-
Bit Locker mein Tod
Heute kam ein Windows Update soweit so gut, danach lief alles normal. Dann Päuschen gemacht und bein Neubooten schlug Bit Locker zu.
Kannte ich vorher gar nicht.
Ergebnis kein Zugriff mehr, stundenlang mit dem Handy rumgesucht, kenne mein Microsoft Konto natürlich nicht.
Zum Glück hatte ich auf einen USB-Stick noch eine Textdatei mit meinen Sticky Password Accounts.
Ergebnis bin jetzt mit Linux Mint Live DVD hier.
Morgen wird Windows platt gemacht, und dann mache ich auf Linux halt auf die harte Tour.
Bin mächtig gewaltig sauer, zum Glück kein Microsoftmitarbeiter in der Nähe, das gebe ein Blutbad!!!!!!!!!!!!!!!
-
Bit Locker mein Tod
Heute kam ein Windows Update soweit so gut, danach lief alles normal. Dann Päuschen gemacht und bein Neubooten schlug Bit Locker zu.
Kannte ich vorher gar nicht.
Ergebnis kein Zugriff mehr, stundenlang mit dem Handy rumgesucht, kenne mein Microsoft Konto natürlich nicht.
Zum Glück hatte ich auf einen USB-Stick noch eine Textdatei mit meinen Sticky Password Accounts.
Ergebnis bin jetzt mit Linux Mint Live DVD hier.
Morgen wird Windows platt gemacht, und dann mache ich auf Linux halt auf die harte Tour.
Bin mächtig gewaltig sauer, zum Glück kein Microsoftmitarbeiter in der Nähe, das gebe ein Blutbad!!!!!!!!!!!!!!!
-
Security Week 2631: новые приемы корпоративных кибервымогателей
Свежий отчет «Лаборатории Касперского» разбирает два недавних инцидента в Латинской Америке, в ходе которых организации стали жертвой кибервымогателей. Оба инцидента, произошедшие в мае этого года в Мексике и в июне в Колумбии, удалось подробно проанализировать, в результате чего стали понятны методы взлома корпоративной инфраструктуры, а также дальнейшие шаги киберпреступников. Примечательно, что в обоих случаях для шифрования данных с последующим требованием выкупа использовался штатный инструмент Windows, известный как BitLocker. Значок, указывающий на то, что диск зашифрован, стал первым признаком кибератаки, который заметили в организации. Точкой входа в инциденте, произошедшем в Колумбии, стала доступная из Интернета служба удаленного рабочего стола (RDP) на сервере, к которому, в свою очередь, был подключен жесткий диск объемом 8 терабайт с критически важными финансовыми данными. Злоумышленники сначала получили контроль над системой, изменили учетные данные пользователей, а затем применили шифрование. Еще одной любопытной особенностью данной атаки стала печать записки с требованием выкупа прямо на корпоративных принтерах в офисе организации.
-
📰 Latin American Ransomware Uses BitLocker, Prints Physical Ransom Notes
Ransomware attacks in Colombia & Mexico are using Microsoft's BitLocker to encrypt systems and hijacking printers to print physical ransom notes. Kaspersky reports this 'living-off-the-land' tactic makes detection harder. #Ransomware #BitLocker #LATAM
🌐 cyber[.]netsecops[.]io
-
Protecting portable data is crucial. Our latest guide details how to enable BitLocker for removable drives in Windows 11. Encrypt your USB sticks and SD cards to keep your files secure from unauthorized access. Learn the simple steps to add this essential layer of protection. #Windows #BitLocker #Security #Privacy https://geekrewind.com/how-to-encrypt-thumb-drives-with-password-in-windows-11/
-
#Microsoft Issues #Fixes for 622 #Vulnerabilities —A New Record—Including Two Actively Exploited Zero-Days
-
#Microsoft Issues #Fixes for 622 #Vulnerabilities —A New Record—Including Two Actively Exploited Zero-Days
-
Брешь в защите: Война Nightmare Eclipse. Часть 2
Хабр, привет! На связи Александр Бек, аналитик-исследователь угроз кибербезопасности R‑Vision. В первой части мы разобрали три PoC от Nightmare Eclipse — YellowKey, GreenPlasma и MiniPlasma. Это были совершенно разные техники: обход BitLocker через WinRE, низкоуровневый примитив на стыке CTF и Windows Object Managerи цепочка локального повышения привилегий (LPE), основанная на взаимодействии Cloud Files с Windows Error Reporting. Тогда стало понятно, что защищаться от этих техник приходится по-разному. В одних случаях телеметрии практически нет, в других — можно строить вполне рабочие детекты по реестру, процессам и файловой системе. В этой статье мы разберем оставшиеся пять PoC. Среди них — четыре уязвимости в Microsoft Defender (три LPE и одна DoS), а также еще один вариант обхода BitLocker через WinRE. Что особенно важно, три из этих техник уже были замечены в реальных атаках. В отличие от первой части, здесь мы сосредоточимся не только на механике эксплуатации, но и на том, какие артефакты оставляют эксплойты в системе, какие изменения происходят на устройствах Windows и на что стоит обратить внимание SOC- и threat hunting-командам при поиске следов компрометации.
https://habr.com/ru/companies/rvision/articles/1058972/
#информационная_безопасность #кибербезопасность #microsoft_defender #windows #уязвимости #threat_hunting #soc #bitlocker #lpe
-
#ATM #Crypto Software Flaws Uncovered
Vulnerabilities in Microsoft's #BitLocker #encryption layer could leave organizations — and potentially ATMs — exposed to #attack
-
#ATM #Crypto Software Flaws Uncovered
Vulnerabilities in Microsoft's #BitLocker #encryption layer could leave organizations — and potentially ATMs — exposed to #attack
-
Das Open Source Verschlüsselungsprogramm #DiskCryptor für #Windows (Alternative zu #Veracrypt und #Bitlocker) ist in V2.0 als Pre-View verfügbar, wie mir der Entwickler mitteilte.
https://borncity.com/blog/2026/07/09/diskcryptor-2-0-veroeffentlicht/
-
Das Open Source Verschlüsselungsprogramm #DiskCryptor für #Windows (Alternative zu #Veracrypt und #Bitlocker) ist in V2.0 als Pre-View verfügbar, wie mir der Entwickler mitteilte.
https://borncity.com/blog/2026/07/09/diskcryptor-2-0-veroeffentlicht/
-
BitLocker downgrade attacks:
#windows #bitlocker #infosec #informationsecurity #cybersecurity #crypto
-
BitLocker downgrade attacks:
#windows #bitlocker #infosec #informationsecurity #cybersecurity #crypto
-
Listening to Cassius Garat at @passthesaltcon talking about:
Bypassing #BitLocker in under 5 min using boot manager downgrade attacks
https://cfp.pass-the-salt.org/pts2026/talk/RVFD8B/
Not that I need it to access my files, but the #Windows partition of my laptop is also "protected" using BitLocker :-)
-
Listening to Cassius Garat at @passthesaltcon talking about:
Bypassing #BitLocker in under 5 min using boot manager downgrade attacks
https://cfp.pass-the-salt.org/pts2026/talk/RVFD8B/
Not that I need it to access my files, but the #Windows partition of my laptop is also "protected" using BitLocker :-)
-
Взлом BitLocker.
Достаточно просто подложить специальный xml-файл, загрузиться в WinRE и получить шелл с полными правами и доступом к зашифрованному разделу.
-
Взлом BitLocker.
Достаточно просто подложить специальный xml-файл, загрузиться в WinRE и получить шелл с полными правами и доступом к зашифрованному разделу.
-
#Windows #Server2019 #Bitlocker Laufwerke werden seit Mai 2026 #Update nicht mehr erkannt
-
#Windows #Server2019 #Bitlocker Laufwerke werden seit Mai 2026 #Update nicht mehr erkannt
-
Nightmare Eclipse: один против Microsoft
Хабр, привет! На связи Владимир Шнейдмюллер, аналитик-исследователь угроз кибербезопасности R-Vision. Вокруг Nightmare Eclipse за последние недели успело сложиться почти всё, что обычно сопровождает громкие публичные zero-day: резкие заявления автора, споры о такой практике раскрытия, быстрые проверки PoC сообществом, первые форки и закономерный вопрос - что из этого можно увидеть в телеметрии, а что останется почти полностью за пределами SIEM? Мы разобрали несколько опубликованных PoC и в этой статье начнем с первых трёх: YellowKey, GreenPlasma и MiniPlasma. Они существенно различаются как по векторам атак, так и по возможностям обнаружения. YellowKey интересен как обход BitLocker через WinRE, но почти не оставляет удобных событий в ОС. GreenPlasma демонстрирует низкоуровневый примитив на стыке CTF/Winlogon и Windows Object Manager. MiniPlasma, наоборот, уже дает практический сценарий локального повышения привилегий, где можно строить вполне рабочие детекты по реестру, файловой системе и запуску процессов. Ниже не будет пошаговой инструкции по эксплуатации. Нас интересуют механика, артефакты и точки наблюдения, которые полезны SOC и threat hunting-командам.
https://habr.com/ru/companies/rvision/articles/1048510/
#кибербезопасность #управление_уязвимостями #zeroday #windows #bitlocker #poc #winre #MiniPlasma #YellowKey #GreenPlasma
-
#Windows11 #BitLocker
Woao... les machines Windows qui, de manière random, te demandent tout à coup la clé de déchiffrement BitLocker au démarrage au moindre pet de travers, c'est pas cool.
BitLocker - en plus d'être une farce question sécurité - est une gigantesque usine à emmerdes pour les données.(Exemple de l'écran ci-dessous:)
-
#Windows11 #BitLocker
Woao... les machines Windows qui, de manière random, te demandent tout à coup la clé de déchiffrement BitLocker au démarrage au moindre pet de travers, c'est pas cool.
BitLocker - en plus d'être une farce question sécurité - est une gigantesque usine à emmerdes pour les données.(Exemple de l'écran ci-dessous:)
-
#Microsoft hat einen lästigen #BitLocker-Bug in Windows Server 2025 behoben: Nach einem Sicherheitsupdate starteten Systeme unerwartet in den Wiederherstellungsmodus und verlangten den Recovery-Key. https://winfuture.de/news,159313.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
#Microsoft hat einen lästigen #BitLocker-Bug in Windows Server 2025 behoben: Nach einem Sicherheitsupdate starteten Systeme unerwartet in den Wiederherstellungsmodus und verlangten den Recovery-Key. https://winfuture.de/news,159313.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Forscher Nightmare Eclipse will eine weitere BitLocker-Umgehung entdeckt haben. Die Lücke GreatXML soll Systeme betreffen, auf denen ein Defender-Offline-Scan lief. Es gibt aber Zweifel. #Microsoft #BitLocker https://winfuture.de/news,159287.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Forscher Nightmare Eclipse will eine weitere BitLocker-Umgehung entdeckt haben. Die Lücke GreatXML soll Systeme betreffen, auf denen ein Defender-Offline-Scan lief. Es gibt aber Zweifel. #Microsoft #BitLocker https://winfuture.de/news,159287.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
「BitLocker」が回避されてしまう「YellowKey」脆弱性、6月のセキュリティパッチで修正済み/Microsoftがアナウンス
https://forest.watch.impress.co.jp/docs/news/2116567.html#forest_watch_impress #BitLocker #Windows_11 #WinRE #Windows_Server_2025 #YellowKey #セキュリティ #脆弱性 #Windows
-
Microsoft Zero-Day Exploit Bypasses BitLocker Encryption
A security researcher known as Nightmare Eclipse has made a startling discovery, unveiling exploit code called GreatXML that can bypass Microsoft's BitLocker encryption on systems that have run a Microsoft Defender Offline scan. This accidental find took just four hours to uncover, leaving many to wonder about potential vulnerabilities.
-
Microsoft Zero-Day Exploit Bypasses BitLocker Encryption
A security researcher known as Nightmare Eclipse has made a startling discovery, unveiling exploit code called GreatXML that can bypass Microsoft's BitLocker encryption on systems that have run a Microsoft Defender Offline scan. This accidental find took just four hours to uncover, leaving many to wonder about potential vulnerabilities.
-
https://winbuzzer.com/2026/06/11/microsoft-fixes-windows-server-2025-bitlocker-recovery-bug-xcxwbn/
Microsoft has fixed a Windows Server 2025 BitLocker recovery bug, giving IT admins mitigation paths for affected systems at restart.
#WindowsServer2025 #BitLocker #Microsoft #WindowsServer #WindowsUpdate #MicrosoftWindows #SecurityPatches #MicrosoftSecurity #WindowsSecurity #Encryption #Enterprise
-
https://winbuzzer.com/2026/06/11/microsoft-fixes-windows-server-2025-bitlocker-recovery-bug-xcxwbn/
Microsoft has fixed a Windows Server 2025 BitLocker recovery bug, giving IT admins mitigation paths for affected systems at restart.
#WindowsServer2025 #BitLocker #Microsoft #WindowsServer #WindowsUpdate #MicrosoftWindows #SecurityPatches #MicrosoftSecurity #WindowsSecurity #Encryption #Enterprise
-
Microsoft corrige 200 vulnerabilidades en el Patch Tuesday de junio 2026
La actualización mensual de seguridad incluye casi 40 fallas críticas en Windows, Azure, Office, Outlook y Exchange, y suma 360 correcciones adicionales en componentes de terceros. Tres vulnerabilidades ya habían sido divulgadas públicamente antes de ser parcheadas (Fuente Microsoft).
El Patch Tuesday de junio 2026 de Microsoft es uno de los más voluminosos del año. Las actualizaciones de seguridad de junio de 2026 corrigen aproximadamente 200 vulnerabilidades descubiertas en los productos de la compañía. Ninguna parece haber sido explotada en el mundo real, pero tres problemas fueron divulgados públicamente antes de que Microsoft los parcheara.
Las tres vulnerabilidades previamente expuestas concentran la atención de los investigadores. La primera es CVE-2026-49160, un problema de denegación de servicio (DoS) en Windows relacionado con HTTP2/Bomb, una técnica de ataque capaz de dejar fuera de línea servidores web en segundos y que podría afectar a cientos de miles de sitios. La segunda es CVE-2026-50507, un bypass de seguridad en Windows BitLocker que permite a un atacante con acceso físico al sistema acceder a datos cifrados. La falla podría estar relacionada con YellowKey, uno de los exploits filtrados por un investigador conocido como Chaotic Eclipse y Nightmare Eclipse tras una disputa con Microsoft, cuyas filtraciones previas ya fueron aprovechadas en ataques reales. La tercera es CVE-2026-45586, un bug en Windows Collaborative Translation Framework que permite elevar privilegios al nivel System, reportado por un investigador anónimo. Las tres recibieron la calificación de «explotación más probable» por parte de Microsoft.
En el panorama general del parche, casi 40 de las aproximadamente 200 vulnerabilidades tienen calificación crítica. Afectan a Windows, Azure, Office, Outlook, Exchange y herramientas de IA, y su explotación puede derivar en ejecución remota de código, escalada de privilegios y divulgación de información. A ese número se suma un volumen adicional significativo: Microsoft publicó avisos de seguridad para 360 problemas adicionales que afectan a componentes de terceros utilizados por su software.
En paralelo, Adobe también lanzó sus actualizaciones de Patch Tuesday de junio, corrigiendo más de 120 vulnerabilidades. Para los equipos de seguridad IT, la primera semana de junio implica una carga de trabajo considerable. La recomendación es clara: aplicar las actualizaciones cuanto antes, especialmente en entornos con BitLocker activo o servidores web expuestos.
#Actualizacion #adobe #azure #BitLocker #ciberseguridad #CVE #exchange #HTTP2 #microsoft #office #PatchTuesday #PORTADA #SeguridadInformatica #vulnerabilidades #windows -
With YellowKey drawing attention across the forensics community, Passware explains how the WinRE-based BitLocker exploit works, where its limitations lie, and what investigators can do when it fails. https://www.forensicfocus.com/news/bitlocker-decryption-today-yellowkey-explained-and-where-passware-steps-in/ #Passware #BitLocker #DigitalForensics #DFIR
-
#CC2.tv: #Computerclub2
Dateien, #Festplatten und #Cloud richtig verschlüsseln
In diesem Video geht es um die praktische Verschlüsselung persönlicher Daten auf Computer, Smartphone und in der Cloud. Erklärt werden Standardlösungen wie #BitLocker und #Linux-Home-Verschlüsselung sowie ergänzende Werkzeuge wie #ZuluCrypt, #PicoCrypt #NG und #Cryptomator. Dabei wird gezeigt, welche Verfahren sich für lokale Dateien, externe Datenträger, #Backups und #Cloud-Speicher eignen. -
#CC2.tv: #Computerclub2
Dateien, #Festplatten und #Cloud richtig verschlüsseln
In diesem Video geht es um die praktische Verschlüsselung persönlicher Daten auf Computer, Smartphone und in der Cloud. Erklärt werden Standardlösungen wie #BitLocker und #Linux-Home-Verschlüsselung sowie ergänzende Werkzeuge wie #ZuluCrypt, #PicoCrypt #NG und #Cryptomator. Dabei wird gezeigt, welche Verfahren sich für lokale Dateien, externe Datenträger, #Backups und #Cloud-Speicher eignen. -
#Verschlüsselung für #Alltag und #Cloud ( #CC2tv Folge 427 )
In diesem Video geht es um die praktische Verschlüsselung persönlicher Daten auf Computer, #Smartphone und in der #Cloud. Erklärt werden Standardlösungen wie #BitLocker und #Linux-Home-Verschlüsselung sowie ergänzende Werkzeuge wie #ZuluCrypt, #PicoCrypt #NG und #Cryptomator. Dabei wird gezeigt, welche Verfahren sich für lokale Dateien, externe Datenträger, Backups und Cloud-Speicher eignen.
@computerclubzwei
-
#Verschlüsselung für #Alltag und #Cloud ( #CC2tv Folge 427 )
In diesem Video geht es um die praktische Verschlüsselung persönlicher Daten auf Computer, #Smartphone und in der #Cloud. Erklärt werden Standardlösungen wie #BitLocker und #Linux-Home-Verschlüsselung sowie ergänzende Werkzeuge wie #ZuluCrypt, #PicoCrypt #NG und #Cryptomator. Dabei wird gezeigt, welche Verfahren sich für lokale Dateien, externe Datenträger, Backups und Cloud-Speicher eignen.
@computerclubzwei
-
If I understand this correctly every past and present theft of a windows notebook that contains PII encrypted with #bitlocker got a potential „upgrade“ regarding #gdpr.
-
If I understand this correctly every past and present theft of a windows notebook that contains PII encrypted with #bitlocker got a potential „upgrade“ regarding #gdpr.
-
Microsoft Threatens Security Researcher Over Windows Exploits
A mysterious security researcher known as "Nightmare Eclipse" has unleashed a string of powerful Windows exploits, including one that can bypass BitLocker, leaving Microsoft scrambling to respond. The bold move has sparked a tense standoff between the researcher and the tech giant.
#WindowsExploits #Bitlocker #EmergingThreats #VulnerabilityDisclosure #Microsoft
-
https://winbuzzer.com/2026/06/01/github-ban-escalates-microsofts-yellowkey-dispute-xcxwbn/
GitHub appears to have banned the security researcher behind the YellowKey BitLocker exploit reveal, widening Microsoft's fight over public disclosures.
#GitHub #YellowKey #Microsoft #BitLocker #Windows11 #ZeroDay #Exploits #WindowsSecurity #Cybersecurity
-
@bjoern
Es scheint noch viel schlimmer zu sein: Das was über #YellowKey bekannt geworden ist sieht sehr viel mehr wie eine #Backdoor in #Bitlocker aus als eine versehentlich gevibete Schwachstelle... -
Wenn ihr euch bisher darauf verlassen habt dass eure Festplatten dank #Bitlocker verschlüsselt und eure Daten felsenfest geschützt sind... Nope. #YellowKey sieht nicht aus wie ein Bug, sondern wie eine absichtlich eingebaute #Backdoor.
-
Suspeita de #backdoor no #bitlocker #microsoft
-
https://hackingpassion.com/yellowkey-bitlocker-bypass-winre/ - If you can get physical access to a machine, #YellowKey will bypass #BitLocker on a fully patched #Windows machine.
-
Attackierte MS-Defender-Lücken und #BitLocker-Schutzmaßnahmen | Security https://www.heise.de/news/Attackierte-MS-Defender-Luecken-und-BitLocker-Schutzmassnahmen-11301580.html #Patchday
-
#Microsoft #BitLocker-protected drives can now be opened with just some files on a #USB stick — YellowKey #zeroday #exploit demonstrates an apparent backdoor #YellowKey is kind of crazy because now, any device that was stolen but protected by BitLocker is now super-compromised, with no recourse