windows

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Security researcher Chaotic Eclipse released a new proof-of-concept exploit called LegacyHive, which leverages a Windows User Profile Service vulnerability to achieve arbitrary hive load elevation of privileges. The exploit works on all supported Windows versions, including those patched in the latest July 2026 update, and allows non-admin users to modify registry hives of other accounts, posing a significant privilege escalation risk. Microsoft is investigating the vulnerability and committed to addressing it, while the incident highlights ongoing challenges in coordinated vulnerability disclosure and security patching.

https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html

Microsoft’s Secure Boot Has Been Broken for a Decade and No One Noticed Until Now

Researchers at security firm ESET discovered that Microsoft’s Secure Boot, designed to prevent malicious firmware infections, has been bypassable for 13 years due to old, vulnerable “shim” binaries that were never revoked despite known defects. This flaw affects both Windows and Linux devices by allowing attackers to load malicious firmware at boot time, persisting even after OS reinstallation; Microsoft only revoked the faulty shims after ESET’s report in June 2026. The incident highlights inherent complexity and trust issues in the Secure Boot model, which depends heavily on Microsoft’s oversight and has struggled to handle revocations and scaling effectively.

https://arstechnica.com/security/2026/07/microsoft-secure-boot-has-been-broken-for-most-of-its-existence/

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Microsoft released its largest Patch Tuesday to date, addressing 622 vulnerabilities, including two zero-day elevation-of-privilege flaws actively exploited in SharePoint Server (CVE-2026-56164) and Active Directory Federation Services (CVE-2026-56155). Organizations are urged to prioritize these patches despite their moderate severity ratings, as both affect critical identity and collaboration infrastructure, and attackers are currently exploiting them. The update also ends support for SharePoint Server 2016 and 2019, and continues Kerberos RC4 hardening, which may cause authentication issues if service accounts still rely on RC4.

https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html

Evolving Windows Vulnerability Management to Meet the Speed of AI-powered Discovery

Microsoft is enhancing Windows vulnerability management by leveraging AI-powered tools like the multi-model agentic scanning harness (MDASH) to accelerate discovery, prioritization, and remediation of security issues across its codebase. The company integrates AI into its engineering and validation processes to speed up fixes while maintaining update quality, and provides customers with tools and guidance to deploy timely security updates safely, supporting a shift toward continuous, risk-based patching to reduce exposure amid growing AI-driven vulnerability discovery.

https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/

Patch for Windows Defender 0-Day Could Allow Attackers to Fill Hard Disk

A patch released by Microsoft to fix a zero-day vulnerability (CVE-2026-50656) in the Windows Defender malware protection engine may cause affected Windows machines to write excessively large files that can fill the hard disk. Researcher NightmareEclipse reported that new defense-in-depth mitigations introduced in the patch cause the engine to leak data when handling certain files and their associated Zone.Identifier metadata, potentially allowing attackers to exhaust disk space via specially crafted SMB server responses. Microsoft has not yet confirmed the disk-filling behavior, while the researcher’s ongoing public disclosures highlight a continued dispute with Microsoft over vulnerability handling.

https://arstechnica.com/security/2026/07/patch-for-windows-defender-0-day-could-allow-attackers-to-fill-hard-disk/

Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges

Microsoft has released a security update to patch a privilege escalation vulnerability known as RoguePlanet (CVE-2026-50656) in its Malware Protection Engine, which could allow attackers to gain SYSTEM-level privileges and execute arbitrary code. The flaw, disclosed by researcher Chaotic Eclipse, exploited a race condition and affected fully patched Windows systems, but Microsoft’s update has mitigated the issue along with adding defense-in-depth improvements. Additionally, the researcher identified a potential new data leak caused by the patch that requires further investigation.

https://thehackernews.com/2026/07/microsoft-patches-rogueplanet-defender.html

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch Is in Development

Microsoft has confirmed a privilege escalation zero-day vulnerability in Microsoft Defender, known as RoguePlanet (CVE-2026-50656), and is developing a patch to address it. The flaw, disclosed by researcher Chaotic Eclipse, exploits a race condition that can grant SYSTEM-level access regardless of Defender’s real-time protection setting.

https://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html

Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows

A security researcher known as Chaotic Eclipse has released a proof-of-concept exploit for a Microsoft Defender zero-day vulnerability called RoguePlanet, which enables privilege escalation to SYSTEM access on fully patched Windows 10 and 11 machines. The exploit, a race condition, allows attackers to run arbitrary code and remains effective despite recent updates, although it currently does not work on Windows Server without modification. This disclosure follows a series of public Microsoft Defender vulnerabilities revealed by the researcher amid a dispute with Microsoft over the handling of vulnerability reports and coordinated disclosure.

https://thehackernews.com/2026/06/microsoft-defender-rogueplanet-zero-day.html

June 2026 Patch Tuesday Fixes 200 Microsoft Vulnerabilities

Microsoft's June 2026 Patch Tuesday addressed a record number of 200 vulnerabilities across its products, aiming to enhance security and mitigate risks from potential exploits. This massive update underscores the increasing complexity and volume of vulnerabilities in software ecosystems and highlights the critical need for timely patch management in cybersecurity defense.

https://thecyberexpress.com/june-2026-patch-tuesday-200-microsoft/

Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes

A newly disclosed, unpatched vulnerability in the Windows Search URI handler allows attackers to steal users' NTLMv2 hashes by inducing them to click specially crafted links that connect to malicious SMB servers. This issue, similar to a previously patched flaw in the Windows Snipping Tool, poses risks of relay attacks and deeper network access, but Microsoft has declined to issue a fix, recommending mitigations like blocking outbound SMB traffic and disabling NTLM where possible.

https://thehackernews.com/2026/06/unpatched-windows-search-uri.html

Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit

Microsoft has released a mitigation for the YellowKey vulnerability (CVE-2026-45585), a BitLocker security feature bypass that allows attackers with physical access to circumvent device encryption on affected Windows 11 and Windows Server versions. The exploit uses specially crafted files to spawn an unrestricted shell during recovery mode, granting full access to encrypted data, and Microsoft recommends updating WinRE images and switching from TPM-only to TPM+PIN protection to prevent exploitation.

https://thehackernews.com/2026/05/microsoft-releases-mitigation-for.html

Windows Zero-Day Barrage Continues After Patch Tuesday

Security researcher “Nightmare Eclipse” has disclosed six Windows zero-day vulnerabilities over the past six weeks, including new flaws named YellowKey, GreenPlasma, and MiniPlasma, following Microsoft's May 2026 Patch Tuesday. These vulnerabilities enable severe attacks such as bypassing BitLocker encryption, privilege escalation, and disabling Microsoft Defender, with some already actively exploited, highlighting significant ongoing security challenges for Windows users despite patches.

https://www.darkreading.com/cyberattacks-data-breaches/windows-zero-day-barrage-continues-after-patch-tuesday

Microsoft’s MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday

Microsoft has introduced MDASH, a multi-model AI-driven system designed to autonomously discover, validate, and prove exploitable vulnerabilities in complex codebases like Windows. Tested in a private preview, MDASH identified 16 flaws fixed in the latest Patch Tuesday, including critical remote code execution vulnerabilities in Windows networking and authentication components. This system represents a production-grade advancement in AI vulnerability discovery by orchestrating over 100 specialized AI agents to enhance security at enterprise scale.

https://thehackernews.com/2026/05/microsofts-mdash-ai-system-finds-16.html

Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws

Microsoft released patches addressing 138 security vulnerabilities across its product portfolio, including critical remote code execution flaws in Windows DNS and Netlogon components. These fixes, part of the May 2026 Patch Tuesday, also involve privilege escalation, information disclosure, and spoofing issues, with several vulnerabilities identified through Microsoft's new AI-driven discovery system, highlighting the growing role of AI in vulnerability detection.

https://thehackernews.com/2026/05/microsoft-patches-138-vulnerabilities.html

New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes

A new tool called BitUnlocker exploits a vulnerability in Windows 11's BitLocker encryption, allowing attackers with physical access to decrypt protected volumes in under five minutes by using a downgrade attack on the boot manager. The attack leverages an unrevoked legacy signing certificate, enabling a pre-patch vulnerable boot manager to pass Secure Boot validation, but Microsoft mitigations like enabling TPM+PIN authentication and deploying update KB5025885 can protect systems against this exploit.

https://cybersecuritynews.com/bitunlocker-downgrade-attack-on-windows-11/

Scroll to Top