Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AINew GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
Security researcher Chaotic Eclipse has disclosed GreatXML, a new exploit that bypasses Windows BitLocker encryption by leveraging vulnerabilities in recovery partition XML files. The exploit was discovered accidentally in just four hours, following the researcher's recent publication of a Microsoft Defender exploit, highlighting potential weaknesses in Windows security mechanisms.
AIMicrosoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
Security researcher Chaotic Eclipse has disclosed a zero-day vulnerability in Microsoft Defender called RoguePlanet that exploits a race condition to grant SYSTEM-level access on fully updated Windows systems. The proof-of-concept exploit has been published on GitHub, with the researcher claiming a 100% success rate under certain conditions. This represents a critical privilege escalation vulnerab
AIUnpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
Security researchers have identified an unpatched vulnerability in Windows Search URI handler that allows attackers to steal users' NTLMv2 password hashes. The flaw is similar to CVE-2026-33829 that affected Windows Snipping Tool, and exploits the search: URI handler to expose authentication credentials. This spoofing vulnerability poses a significant risk to enterprise environments where NTLM aut
