Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIResearchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Security researchers have demonstrated a critical vulnerability in Windows 11's Plug and Play functionality that allows attackers to achieve SYSTEM-level access by exploiting the automatic installation process for emulated USB devices. The attack leverages signed vendor software fetched through PnP mechanisms and can be executed remotely via Remote Desktop when USB redirection is enabled, affectin
AIChina-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
Cybersecurity researchers at ESET have discovered two previously undocumented Windows variants of the SprySOCKS backdoor, which was originally believed to target only Linux systems. The new variants, designated WIN_DRV and WIN_PLUS, feature hard-coded command-and-control configurations and support multiple communication protocols including TCP and UDP, representing a significant expansion of the C
AINew GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
Security researcher Chaotic Eclipse has disclosed GreatXML, a new exploit that bypasses Windows BitLocker encryption by leveraging vulnerabilities in recovery partition XML files. The exploit was discovered accidentally in just four hours, following the researcher's recent publication of a Microsoft Defender exploit, highlighting potential weaknesses in Windows security mechanisms.
AIMicrosoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
Security researcher Chaotic Eclipse has disclosed a zero-day vulnerability in Microsoft Defender called RoguePlanet that exploits a race condition to grant SYSTEM-level access on fully updated Windows systems. The proof-of-concept exploit has been published on GitHub, with the researcher claiming a 100% success rate under certain conditions. This represents a critical privilege escalation vulnerab
AIUnpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
Security researchers have identified an unpatched vulnerability in Windows Search URI handler that allows attackers to steal users' NTLMv2 password hashes. The flaw is similar to CVE-2026-33829 that affected Windows Snipping Tool, and exploits the search: URI handler to expose authentication credentials. This spoofing vulnerability poses a significant risk to enterprise environments where NTLM aut
