Monday , August 24 2026
BitLocker

Multiple 0-days to Bypass BitLocker and Extract Data

Researchers revealed critical zero-day vulnerabilities that bypass Windows BitLocker encryption, enabling attackers with physical access to quickly extract data from encrypted devices.

Research by Alon Leviev and Netanel Ben Simon from Microsoft’s STORM team reveals critical flaws in the Windows Recovery Environment (WinRE) that threaten BitLocker’s security.

Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

A mysterious AI model dubbed "Ox Alpha" has surfaced online and created noise within the developer community after releasing on...
Read More
Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

Four Critical Attack Vectors Discovered:

The researchers found four new vulnerabilities labeled CVE-2025-48800, CVE-2025-48003, CVE-2025-48804, and CVE-2025-48818, each affecting parts of the Windows recovery system.

Boot.sdi Parsing Vulnerability (CVE-2025-48800): This attack alters the WIM offset in the Boot.sdi file to bypass trusted WIM checks. It lets attackers replace legitimate recovery images with malicious ones, enabling untrusted code to run while seeming to preserve system integrity.

ReAgent.xml Exploitation (CVE-2025-48003): The vulnerability exploits WinRE’s offline scanning feature meant for antivirus tasks. Researchers showed that by using tttracer.exe, a valid Time Travel Debugging tool, they could open command prompt sessions with complete access to encrypted volumes.

Trusted App Manipulation (CVE-2025-48804): This exploit targets SetupPlatform.exe, a trusted application that stays registered after Windows updates. It manipulates configuration files to create an infinite time window, allowing attackers to register keyboard shortcuts that open privileged command prompts.

BCD Configuration Attack (CVE-2025-48818): The most advanced vulnerability takes advantage of Push Button Reset (PBR) by altering Boot Configuration Data to misdirect WinRE tasks. Attackers can make the system decrypt BitLocker volumes by crafting harmful ResetSession.xml files on the unprotected recovery partition.

The BlackHat2025 presentation revealed that attacks can be performed by anyone with basic physical access, simply by booting into WinRE with key combinations like Shift+F10. Researchers showed they could fully extract data, including sensitive files, credentials, and system settings from BitLocker-protected drives.

Mitigations:

Microsoft fixed vulnerabilities in July 2025’s Patch Tuesday updates by providing security patches for all affected Windows versions. The company urges organizations to implement the following countermeasures right away:

Enable TPM+PIN authentication for pre-boot security, which stops attacks by requiring user authentication before WinRE accesses encrypted volumes. Use the REVISE method for anti-rollback protection to avoid downgrade attacks. Install all July 2025 security updates via standard Windows Update.

Check Also

Medusa ransomware

500+ critical infrastructure hit by Medusa ransomware

Medusa ransomware hit over 500 critical infrastructure. The Cybersecurity and Infrastructure Security Agency (CISA) said …