#Windows #BitLocker #security
https://www.tomshardware.com/tech-industry/cyber-security/microsoft-bitlocker-protected-drives-can-now-be-opened-with-just-some-files-on-a-usb-stick-yellowkey-zero-day-exploit-demonstrates-an-apparent-backdoor
The process is dead simple: grab any USB stick, get write access to the "System Volume Information," and copy into it the "FsTx" folder and its contents. Shift+click Restart to get Windows to the recovery environment, but then switch to holding down the Control key and don't let go. The machine will reboot, and without asking any questions or showing any menus, will drop you in an elevated command line with full access to the formerly Bitlocked drive, without asking for any keys.
https://www.tomshardware.com/tech-industry/cyber-security/microsoft-bitlocker-protected-drives-can-now-be-opened-with-just-some-files-on-a-usb-stick-yellowkey-zero-day-exploit-demonstrates-an-apparent-backdoor
Tom's Hardware
Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates…
Also, it's a twofer with the GreenPlasma zero-day local privilege escalation.
👏2👨💻2🔥1
This media is not supported in your browser
VIEW IN TELEGRAM
#AI #programming
"Is that code AI generated? If it’s AI generated I don’t want it"
https://x.com/richiemcilroy/status/2056681696964022634
"Is that code AI generated? If it’s AI generated I don’t want it"
https://x.com/richiemcilroy/status/2056681696964022634
😁4🔥2👌2
Forwarded from Мам, я DPO
In a post on X, Jeff Cross, co-founder of Narwhal Technologies, the company behind nx.dev, said, "this incident highlights that there need to be deeper, more fundamental changes to how we and other maintainers need to think about securing developer tooling and open source distribution."
"We're also beginning conversations with other high-profile open source maintainers about how we can work together on some of the deeper structural problems around software supply chain security. A lot of the assumptions the ecosystem has operated under for years no longer hold."
In recent months, TeamPCP has rapidly gained notoriety for large-scale software supply chain attacks, specifically going after widely-used open-source projects and security-adjacent tools that developers rely on.
Якби ж тільки була якась спеціальна професія, яка там щороку каже, що не можна ставити шо попало на робочу техніку
https://thehackernews.com/2026/05/github-internal-repositories-breached.html?m=1
🔥2😁2👌2
#Microsoft #GitHub #AWS
Interesting move:
https://www.businessinsider.com/microsoft-github-amazon-ai-cloud-capacity-2026-6
Interesting move:
https://www.businessinsider.com/microsoft-github-amazon-ai-cloud-capacity-2026-6
Business Insider
Microsoft is resorting to its biggest cloud rival to deal with GitHub AI capacity issues
Microsoft is adding AWS capacity to GitHub after AI-driven growth strained infrastructure and triggered a series of reliability issues.
🔥2👏2👀1