home.social

#windowssecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #windowssecurity, aggregated by home.social.

  1. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn

  2. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn

  3. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn

  4. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn

  5. Responder Tool for Network Credential Capture in Active Directory

    In this article, I cover how Responder works, common credential capture techniques, and practical mitigation strategies for defending Active Directory environments.

    denizhalil.com/2026/05/18/resp

    #CyberSecurity #ActiveDirectory #Responder #LLMNR #NTLM #CredentialCapture #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #EthicalHacking #DenizHalil

  6. Responder Tool for Network Credential Capture in Active Directory

    In this article, I cover how Responder works, common credential capture techniques, and practical mitigation strategies for defending Active Directory environments.

    denizhalil.com/2026/05/18/resp

    #CyberSecurity #ActiveDirectory #Responder #LLMNR #NTLM #CredentialCapture #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #EthicalHacking #DenizHalil

  7. Responder Tool for Network Credential Capture in Active Directory

    In this article, I cover how Responder works, common credential capture techniques, and practical mitigation strategies for defending Active Directory environments.

    denizhalil.com/2026/05/18/resp

    #CyberSecurity #ActiveDirectory #Responder #LLMNR #NTLM #CredentialCapture #RedTeam #BlueTeam #Pentesting #WindowsSecurity #InfoSec #EthicalHacking #DenizHalil

  8. Windows SMB Flaw Enables File Lockdowns Without Traditional Ransomware Traces

    New Windows 'GhostLock' flaw lets attackers lock files on SMB shares. It bypasses security and leaves no traditional ransomware traces. Learn how to respond.

    #WindowsSecurity, #CyberAttack, #Ransomware, #SMB, #GhostLock

    newsletter.tf/windows-ghostloc

  9. Attackers can now lock files on Windows SMB shares using a new 'GhostLock' method. This exploit is harder to detect than normal ransomware because it doesn't leave typical signs like file changes.

    #WindowsSecurity, #CyberAttack, #Ransomware, #SMB, #GhostLock
    newsletter.tf/windows-ghostloc

  10. 🔐 Just shipped a fix for the April 2026 Windows update (KB5083769) that flags unsigned RDP files as "Unknown Publisher".
    If you manage RDP shortcuts via Intune and your users are suddenly seeing red security warnings — here's a complete solution:
    ✅ Self-signed code signing cert (no PKI required)
    ✅ rdpsign.exe signing workflow
    ✅ Intune Win32 package (install + uninstall scripts)
    ✅ Trusted Certificate profile + Settings Catalog policies
    ✅ Versioned detection rule for clean updates
    ✅ Supersedence pattern for migrating from unsigned deployments
    Tested in production on a real M365 Business Premium environment.
    🔗 github.com/Bluewal/m365-intune-scripts/tree/main/intune/rdp-signing
    #Intune #Microsoft365 #RDP #BlueTeam #WindowsSecurity #MicrosoftDefender

  11. 🔐 Just shipped a fix for the April 2026 Windows update (KB5083769) that flags unsigned RDP files as "Unknown Publisher".
    If you manage RDP shortcuts via Intune and your users are suddenly seeing red security warnings — here's a complete solution:
    ✅ Self-signed code signing cert (no PKI required)
    ✅ rdpsign.exe signing workflow
    ✅ Intune Win32 package (install + uninstall scripts)
    ✅ Trusted Certificate profile + Settings Catalog policies
    ✅ Versioned detection rule for clean updates
    ✅ Supersedence pattern for migrating from unsigned deployments
    Tested in production on a real M365 Business Premium environment.
    🔗 github.com/Bluewal/m365-intune-scripts/tree/main/intune/rdp-signing
    #Intune #Microsoft365 #RDP #BlueTeam #WindowsSecurity #MicrosoftDefender

  12. 🔐 Just shipped a fix for the April 2026 Windows update (KB5083769) that flags unsigned RDP files as "Unknown Publisher".
    If you manage RDP shortcuts via Intune and your users are suddenly seeing red security warnings — here's a complete solution:
    ✅ Self-signed code signing cert (no PKI required)
    ✅ rdpsign.exe signing workflow
    ✅ Intune Win32 package (install + uninstall scripts)
    ✅ Trusted Certificate profile + Settings Catalog policies
    ✅ Versioned detection rule for clean updates
    ✅ Supersedence pattern for migrating from unsigned deployments
    Tested in production on a real M365 Business Premium environment.
    🔗 github.com/Bluewal/m365-intune-scripts/tree/main/intune/rdp-signing
    #Intune #Microsoft365 #RDP #BlueTeam #WindowsSecurity #MicrosoftDefender

  13. 🔐 Just shipped a fix for the April 2026 Windows update (KB5083769) that flags unsigned RDP files as "Unknown Publisher".
    If you manage RDP shortcuts via Intune and your users are suddenly seeing red security warnings — here's a complete solution:
    ✅ Self-signed code signing cert (no PKI required)
    ✅ rdpsign.exe signing workflow
    ✅ Intune Win32 package (install + uninstall scripts)
    ✅ Trusted Certificate profile + Settings Catalog policies
    ✅ Versioned detection rule for clean updates
    ✅ Supersedence pattern for migrating from unsigned deployments
    Tested in production on a real M365 Business Premium environment.
    🔗 github.com/Bluewal/m365-intune-scripts/tree/main/intune/rdp-signing
    #Intune #Microsoft365 #RDP #BlueTeam #WindowsSecurity #MicrosoftDefender

  14. 🔐 Just shipped a fix for the April 2026 Windows update (KB5083769) that flags unsigned RDP files as "Unknown Publisher".
    If you manage RDP shortcuts via Intune and your users are suddenly seeing red security warnings — here's a complete solution:
    ✅ Self-signed code signing cert (no PKI required)
    ✅ rdpsign.exe signing workflow
    ✅ Intune Win32 package (install + uninstall scripts)
    ✅ Trusted Certificate profile + Settings Catalog policies
    ✅ Versioned detection rule for clean updates
    ✅ Supersedence pattern for migrating from unsigned deployments
    Tested in production on a real M365 Business Premium environment.
    🔗 github.com/Bluewal/m365-intune-scripts/tree/main/intune/rdp-signing
    #Intune #Microsoft365 #RDP #BlueTeam #WindowsSecurity #MicrosoftDefender