#winre — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #winre, aggregated by home.social.
-
Passend zum Juli-Patchday spendiert #Microsoft #Windows11 auch wieder drei neue dynamische #Updates für #SafeOS bzw. #WinRE. Sie sichern im Ernstfall die Systemwiederherstellung. https://winfuture.de/news,160075.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Passend zum Juli-Patchday spendiert #Microsoft #Windows11 auch wieder drei neue dynamische #Updates für #SafeOS bzw. #WinRE. Sie sichern im Ernstfall die Systemwiederherstellung. https://winfuture.de/news,160075.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Passend zum Juli-Patchday spendiert #Microsoft #Windows11 auch wieder drei neue dynamische #Updates für #SafeOS bzw. #WinRE. Sie sichern im Ernstfall die Systemwiederherstellung. https://winfuture.de/news,160075.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Passend zum Juli-Patchday spendiert #Microsoft #Windows11 auch wieder drei neue dynamische #Updates für #SafeOS bzw. #WinRE. Sie sichern im Ernstfall die Systemwiederherstellung. https://winfuture.de/news,160075.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Passend zum Juli-Patchday spendiert #Microsoft #Windows11 auch wieder drei neue dynamische #Updates für #SafeOS bzw. #WinRE. Sie sichern im Ernstfall die Systemwiederherstellung. https://winfuture.de/news,160075.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Can't trust a scan from within an infected OS. This snippet triggers Windows Defender Offline Scan via WinRE, booting into a minimal PE environment with updated signatures to catch persistent, hidden malware. Windows 10/11, Server 2016+. #windows #snippet #offline-scan #winre #ValtersIT
https://www.valtersit.com/vault/offline-scan-for-persistent-malware-via-winre-integration-274e03/
-
https://winbuzzer.com/2026/07/08/microsoft-tests-cloud-rebuild-for-windows-11-recovery-xcxwbn/
Microsoft has added Windows 11 Cloud Rebuild to preview builds, letting unbootable PCs reinstall from the cloud without USB media while wiping local data.
#CloudRebuild #WinRE #Microsoft #Windows11 #WindowsInsiderProgram #MicrosoftWindows #WindowsPCs
-
https://winbuzzer.com/2026/07/08/microsoft-tests-cloud-rebuild-for-windows-11-recovery-xcxwbn/
Microsoft has added Windows 11 Cloud Rebuild to preview builds, letting unbootable PCs reinstall from the cloud without USB media while wiping local data.
#CloudRebuild #WinRE #Microsoft #Windows11 #WindowsInsiderProgram #MicrosoftWindows #WindowsPCs
-
https://winbuzzer.com/2026/07/08/microsoft-tests-cloud-rebuild-for-windows-11-recovery-xcxwbn/
Microsoft has added Windows 11 Cloud Rebuild to preview builds, letting unbootable PCs reinstall from the cloud without USB media while wiping local data.
#CloudRebuild #WinRE #Microsoft #Windows11 #WindowsInsiderProgram #MicrosoftWindows #WindowsPCs
-
https://winbuzzer.com/2026/07/08/microsoft-tests-cloud-rebuild-for-windows-11-recovery-xcxwbn/
Microsoft has added Windows 11 Cloud Rebuild to preview builds, letting unbootable PCs reinstall from the cloud without USB media while wiping local data.
#CloudRebuild #WinRE #Microsoft #Windows11 #WindowsInsiderProgram #MicrosoftWindows #WindowsPCs
-
https://winbuzzer.com/2026/07/08/microsoft-tests-cloud-rebuild-for-windows-11-recovery-xcxwbn/
Microsoft has added Windows 11 Cloud Rebuild to preview builds, letting unbootable PCs reinstall from the cloud without USB media while wiping local data.
#CloudRebuild #WinRE #Microsoft #Windows11 #WindowsInsiderProgram #MicrosoftWindows #WindowsPCs
-
Microsoft tests Windows 11 cloud rebuild in WinRE, letting users reinstall via the internet without USB drives when the system fails to boot.
#Windows11 #CloudRebuild #WinRE #MicrosoftInsider #WindowsRecovery
https://securityonline.info/windows-11-cloud-rebuild/?utm_source=mastodon&utm_medium=jetpack_social
-
Microsoft tests Windows 11 cloud rebuild in WinRE, letting users reinstall via the internet without USB drives when the system fails to boot.
#Windows11 #CloudRebuild #WinRE #MicrosoftInsider #WindowsRecovery
https://securityonline.info/windows-11-cloud-rebuild/?utm_source=mastodon&utm_medium=jetpack_social
-
🖥️ Windows 11 : comment utiliser la fonction « Restauration à un instant dans le passé »
👉 https://www.justgeek.fr/restauration-instant-passe-windows-11-152537/
#Windows11 #Tutoriel #RestaurationSystème #WinRE #Informatique #PC
-
🖥️ Windows 11 : comment utiliser la fonction « Restauration à un instant dans le passé »
👉 https://www.justgeek.fr/restauration-instant-passe-windows-11-152537/
#Windows11 #Tutoriel #RestaurationSystème #WinRE #Informatique #PC
-
Wieder einmal hat #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE bereitgestellt. Patches sind für drei unterschiedliche Varianten von #Windows11 verfügbar. https://winfuture.de/news,159633.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Wieder einmal hat #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE bereitgestellt. Patches sind für drei unterschiedliche Varianten von #Windows11 verfügbar. https://winfuture.de/news,159633.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Wieder einmal hat #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE bereitgestellt. Patches sind für drei unterschiedliche Varianten von #Windows11 verfügbar. https://winfuture.de/news,159633.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Wieder einmal hat #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE bereitgestellt. Patches sind für drei unterschiedliche Varianten von #Windows11 verfügbar. https://winfuture.de/news,159633.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Wieder einmal hat #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE bereitgestellt. Patches sind für drei unterschiedliche Varianten von #Windows11 verfügbar. https://winfuture.de/news,159633.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Nightmare Eclipse: один против Microsoft
Хабр, привет! На связи Владимир Шнейдмюллер, аналитик-исследователь угроз кибербезопасности R-Vision. Вокруг Nightmare Eclipse за последние недели успело сложиться почти всё, что обычно сопровождает громкие публичные zero-day: резкие заявления автора, споры о такой практике раскрытия, быстрые проверки PoC сообществом, первые форки и закономерный вопрос - что из этого можно увидеть в телеметрии, а что останется почти полностью за пределами SIEM? Мы разобрали несколько опубликованных PoC и в этой статье начнем с первых трёх: YellowKey, GreenPlasma и MiniPlasma. Они существенно различаются как по векторам атак, так и по возможностям обнаружения. YellowKey интересен как обход BitLocker через WinRE, но почти не оставляет удобных событий в ОС. GreenPlasma демонстрирует низкоуровневый примитив на стыке CTF/Winlogon и Windows Object Manager. MiniPlasma, наоборот, уже дает практический сценарий локального повышения привилегий, где можно строить вполне рабочие детекты по реестру, файловой системе и запуску процессов. Ниже не будет пошаговой инструкции по эксплуатации. Нас интересуют механика, артефакты и точки наблюдения, которые полезны SOC и threat hunting-командам.
https://habr.com/ru/companies/rvision/articles/1048510/
#кибербезопасность #управление_уязвимостями #zeroday #windows #bitlocker #poc #winre #MiniPlasma #YellowKey #GreenPlasma
-
Nightmare Eclipse: один против Microsoft
Хабр, привет! На связи Владимир Шнейдмюллер, аналитик-исследователь угроз кибербезопасности R-Vision. Вокруг Nightmare Eclipse за последние недели успело сложиться почти всё, что обычно сопровождает громкие публичные zero-day: резкие заявления автора, споры о такой практике раскрытия, быстрые проверки PoC сообществом, первые форки и закономерный вопрос - что из этого можно увидеть в телеметрии, а что останется почти полностью за пределами SIEM? Мы разобрали несколько опубликованных PoC и в этой статье начнем с первых трёх: YellowKey, GreenPlasma и MiniPlasma. Они существенно различаются как по векторам атак, так и по возможностям обнаружения. YellowKey интересен как обход BitLocker через WinRE, но почти не оставляет удобных событий в ОС. GreenPlasma демонстрирует низкоуровневый примитив на стыке CTF/Winlogon и Windows Object Manager. MiniPlasma, наоборот, уже дает практический сценарий локального повышения привилегий, где можно строить вполне рабочие детекты по реестру, файловой системе и запуску процессов. Ниже не будет пошаговой инструкции по эксплуатации. Нас интересуют механика, артефакты и точки наблюдения, которые полезны SOC и threat hunting-командам.
https://habr.com/ru/companies/rvision/articles/1048510/
#кибербезопасность #управление_уязвимостями #zeroday #windows #bitlocker #poc #winre #MiniPlasma #YellowKey #GreenPlasma
-
Nightmare Eclipse: один против Microsoft
Хабр, привет! На связи Владимир Шнейдмюллер, аналитик-исследователь угроз кибербезопасности R-Vision. Вокруг Nightmare Eclipse за последние недели успело сложиться почти всё, что обычно сопровождает громкие публичные zero-day: резкие заявления автора, споры о такой практике раскрытия, быстрые проверки PoC сообществом, первые форки и закономерный вопрос - что из этого можно увидеть в телеметрии, а что останется почти полностью за пределами SIEM? Мы разобрали несколько опубликованных PoC и в этой статье начнем с первых трёх: YellowKey, GreenPlasma и MiniPlasma. Они существенно различаются как по векторам атак, так и по возможностям обнаружения. YellowKey интересен как обход BitLocker через WinRE, но почти не оставляет удобных событий в ОС. GreenPlasma демонстрирует низкоуровневый примитив на стыке CTF/Winlogon и Windows Object Manager. MiniPlasma, наоборот, уже дает практический сценарий локального повышения привилегий, где можно строить вполне рабочие детекты по реестру, файловой системе и запуску процессов. Ниже не будет пошаговой инструкции по эксплуатации. Нас интересуют механика, артефакты и точки наблюдения, которые полезны SOC и threat hunting-командам.
https://habr.com/ru/companies/rvision/articles/1048510/
#кибербезопасность #управление_уязвимостями #zeroday #windows #bitlocker #poc #winre #MiniPlasma #YellowKey #GreenPlasma
-
Erneut veröffentlicht #Microsoft neue dynamische #Updates für #Windows11, #Windows10 und #WindowsServer. Die Aktualisierungen für #WinRE bzw. #SafeOS stehen ab sofort bereit. https://winfuture.de/news,159330.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Erneut veröffentlicht #Microsoft neue dynamische #Updates für #Windows11, #Windows10 und #WindowsServer. Die Aktualisierungen für #WinRE bzw. #SafeOS stehen ab sofort bereit. https://winfuture.de/news,159330.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Erneut veröffentlicht #Microsoft neue dynamische #Updates für #Windows11, #Windows10 und #WindowsServer. Die Aktualisierungen für #WinRE bzw. #SafeOS stehen ab sofort bereit. https://winfuture.de/news,159330.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Erneut veröffentlicht #Microsoft neue dynamische #Updates für #Windows11, #Windows10 und #WindowsServer. Die Aktualisierungen für #WinRE bzw. #SafeOS stehen ab sofort bereit. https://winfuture.de/news,159330.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Erneut veröffentlicht #Microsoft neue dynamische #Updates für #Windows11, #Windows10 und #WindowsServer. Die Aktualisierungen für #WinRE bzw. #SafeOS stehen ab sofort bereit. https://winfuture.de/news,159330.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
「BitLocker」が回避されてしまう「YellowKey」脆弱性、6月のセキュリティパッチで修正済み/Microsoftがアナウンス
https://forest.watch.impress.co.jp/docs/news/2116567.html#forest_watch_impress #BitLocker #Windows_11 #WinRE #Windows_Server_2025 #YellowKey #セキュリティ #脆弱性 #Windows
-
「BitLocker」が回避されてしまう「YellowKey」脆弱性、6月のセキュリティパッチで修正済み/Microsoftがアナウンス
https://forest.watch.impress.co.jp/docs/news/2116567.html#forest_watch_impress #BitLocker #Windows_11 #WinRE #Windows_Server_2025 #YellowKey #セキュリティ #脆弱性 #Windows
-
「BitLocker」が回避されてしまう「YellowKey」脆弱性、6月のセキュリティパッチで修正済み/Microsoftがアナウンス
https://forest.watch.impress.co.jp/docs/news/2116567.html#forest_watch_impress #BitLocker #Windows_11 #WinRE #Windows_Server_2025 #YellowKey #セキュリティ #脆弱性 #Windows
-
Jetzt liefert #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE aus - diesmal für unterschiedlichen Versionen von #Windows11, #Windows10 und #WindowsServer. https://winfuture.de/news,158736.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Jetzt liefert #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE aus - diesmal für unterschiedlichen Versionen von #Windows11, #Windows10 und #WindowsServer. https://winfuture.de/news,158736.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Jetzt liefert #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE aus - diesmal für unterschiedlichen Versionen von #Windows11, #Windows10 und #WindowsServer. https://winfuture.de/news,158736.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Jetzt liefert #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE aus - diesmal für unterschiedlichen Versionen von #Windows11, #Windows10 und #WindowsServer. https://winfuture.de/news,158736.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Jetzt liefert #Microsoft neue dynamische #Updates für die Windows-Wiederherstellungsumgebung #WinRE aus - diesmal für unterschiedlichen Versionen von #Windows11, #Windows10 und #WindowsServer. https://winfuture.de/news,158736.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
*Kritische Sicherheitslücke in Windows-Systemen: BitLocker-Implementierungen gefährdet*
In kürzester Zeit können Windows-11- und Windows-Server-Systeme mit BitLocker durch den Einsatz eines Proof of Concept (PoC) angreifbar gemacht werden.
{ #Szene #Windows #ITSicherheit #Windows11 #WinRE }
>> https://nydus.org/news/135721-kritische-sicherheitslucke-in-windows-systemen-bitlocker-implementierungen-gefahrdet.html -
----------------
🎯 Threat Intelligence
===================Executive summary. A researcher published a reproduction for a BitLocker bypass originating from a WinRE component. The method requires copying a folder named FsTx to System Volume Information\FsTx on removable media or into the EFI area, then triggering a specific WinRE restart key sequence to obtain a shell with unrestricted access to the BitLocker‑protected volume. The report states the issue affects Windows 11 and Server 2022/2025; Windows 10 is not affected. The disclosure credits MORSE, MSTIC and Microsoft GHOST.
🔹 Technical details
• Affected images: Windows Recovery Environment (WinRE) on Windows 11 builds and Server 2022/2025 according to the author.
• Trigger mechanism: copy FsTx folder to System Volume Information\FsTx on a USB stick or write equivalent files to the EFI partition. Boot the machine, invoke Restart → WinRE via holding SHIFT while clicking Restart, then release SHIFT and hold CTRL during the transition per the reproduction steps. The author reports that if performed correctly, a shell is spawned with access to the BitLocker volume.
• Component presence: the author notes the responsible component appears only inside the WinRE image. The same component name exists in normal Windows installs but allegedly lacks the triggering functionality. The author characterizes this as suspicious but labels it preliminary.
🔹 Analysis
The observable elements are concrete: folder name FsTx, path System Volume Information\FsTx, WinRE entrypoint and the key sequence behavior. No CVE, vendor advisory, or formal patch is cited in the disclosure. The author speculates about intentional inclusion but explicitly calls the claim tentative. The source did not provide binary hashes, signed module names, or precise module APIs invoked.
🔹 Detection
The disclosure does not include vendor detection rules. Observable indicators from the report that defenders can log or hunt for include presence of an FsTx folder on removable media or unexpected files in the EFI partition, and unusual WinRE session activity following the described key sequence. No IoCs or hashes were published in the source.
🔹 Mitigation
The source did not publish mitigations or vendor guidance. Microsoft engagement is mentioned via credited teams, but no advisory is linked in the report. Until vendor guidance appears, administrators should treat the finding as preliminary.
🔹 References
Author disclosure credited MORSE, MSTIC and Microsoft GHOST. The report is labeled preliminary and the source does not verify intent or supply full technical artifacts.
🔹 bitlocker #winre #windows11 #yellowkey #microsoft
-
https://www.europesays.com/pl/430225/ Nowe obejście BitLockera w Windows 11 i Windows Server 2022/2025. Wystarczy fizyczny dostęp oraz nośnik USB #Bezpieczeństwo #BitLocker #cyberbezpieczenstwo #microsoft #Nauka #NaukaITechnika #NaukaTechnika #PL #Poland #Polish #Polska #Polski #Science #ScienceAndTechnology #ScienceTechnology #SzyfrowanieDysków #Technika #Technology #TrustedPlatformModule #Windows11 #WinRE #YellowKey
-
📬 BitUnlocker knackt BitLocker in unter fünf Minuten
#ITSicherheit #Bitlocker #BitUnlocker #CVE202548804 #KB5025885 #SecureBoot #TPM #TPMonlyBitLocker #Windows11 #WinRE #YellowKey https://sc.tarnkappe.info/2ff8e4 -
📬 BitUnlocker knackt BitLocker in unter fünf Minuten
#ITSicherheit #Bitlocker #BitUnlocker #CVE202548804 #KB5025885 #SecureBoot #TPM #TPMonlyBitLocker #Windows11 #WinRE #YellowKey https://sc.tarnkappe.info/2ff8e4 -
📬 BitUnlocker knackt BitLocker in unter fünf Minuten
#ITSicherheit #Bitlocker #BitUnlocker #CVE202548804 #KB5025885 #SecureBoot #TPM #TPMonlyBitLocker #Windows11 #WinRE #YellowKey https://sc.tarnkappe.info/2ff8e4 -
📬 BitUnlocker knackt BitLocker in unter fünf Minuten
#ITSicherheit #Bitlocker #BitUnlocker #CVE202548804 #KB5025885 #SecureBoot #TPM #TPMonlyBitLocker #Windows11 #WinRE #YellowKey https://sc.tarnkappe.info/2ff8e4 -
📬 BitUnlocker knackt BitLocker in unter fünf Minuten
#ITSicherheit #Bitlocker #BitUnlocker #CVE202548804 #KB5025885 #SecureBoot #TPM #TPMonlyBitLocker #Windows11 #WinRE #YellowKey https://sc.tarnkappe.info/2ff8e4 -
Mit fünf neuen #Updates für #Windows 10, 11 und Windows Server liefert #Microsoft Verbesserungen der #Betriebssystem-#Wiederherstellungsumgebung #WinRE. https://winfuture.de/news,158188.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Mit fünf neuen #Updates für #Windows 10, 11 und Windows Server liefert #Microsoft Verbesserungen der #Betriebssystem-#Wiederherstellungsumgebung #WinRE. https://winfuture.de/news,158188.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Mit fünf neuen #Updates für #Windows 10, 11 und Windows Server liefert #Microsoft Verbesserungen der #Betriebssystem-#Wiederherstellungsumgebung #WinRE. https://winfuture.de/news,158188.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Mit fünf neuen #Updates für #Windows 10, 11 und Windows Server liefert #Microsoft Verbesserungen der #Betriebssystem-#Wiederherstellungsumgebung #WinRE. https://winfuture.de/news,158188.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Mit fünf neuen #Updates für #Windows 10, 11 und Windows Server liefert #Microsoft Verbesserungen der #Betriebssystem-#Wiederherstellungsumgebung #WinRE. https://winfuture.de/news,158188.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Wenn das #Betriebssystem nicht mehr startet, ist oft #WinRE die letzte Rettung. #Microsoft hat jetzt vier kritische #Updates für die #Wiederherstellungsumgebung von #Windows11 veröffentlicht. https://winfuture.de/news,157806.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia