Zero-day-sårbarhet kringgår standardkryptering med BitLocker i Windows 11

En nyligen publicerad zero-day-sårbarhet gör det möjligt för angripare med fysisk åtkomst att kringgå BitLocker-kryptering på Windows 11-enheter på bara några sekunder. Attacken, som fått namnet YellowKey, riktar sig mot standardkonfigurationen som endast använder TPM och ger full åtkomst till krypterade enheter via en enkel USB-baserad metod.

Sårbarheten publicerades tidigare i veckan av en forskare under aliaset Nightmare-Eclipse. Den fungerar genom att placera en anpassad FsTx-mapp på en USB-enhet formaterad som NTFS eller FAT. Efter att ha anslutit enheten och tvingat fram en start i Windows Recovery, öppnar systemet en kommandotolk med obegränsad åtkomst till enhetens innehåll, vilket kringgår det vanliga kravet på BitLocker-återställningsnyckel.

Relaterade artiklar

Illustration depicting the Linux CopyFail vulnerability enabling root access exploits alongside Ubuntu's DDoS-induced outage.
Bild genererad av AI

Linux CopyFail exploit threatens root access amid Ubuntu outage

Rapporterad av AI Bild genererad av AI

A critical Linux vulnerability known as CopyFail, tracked as CVE-2026-31431, allows attackers to gain root access on systems running kernels since 2017. Publicly released exploit code has heightened risks for data centers and personal devices. Ubuntu's infrastructure has been offline for over a day due to a DDoS attack, hampering security communications.

Daemon Tools, a popular disk image mounting app, was compromised in a supply-chain attack starting April 8, delivering malware through official updates. Security firm Kaspersky reported infections on thousands of machines across over 100 countries. Users are urged to scan their systems immediately.

Rapporterad av AI

New research from ETH Zurich and USI Lugano reveals vulnerabilities in popular password managers, challenging their assurances that servers cannot access user vaults. The study analyzed Bitwarden, Dashlane, and LastPass, identifying ways attackers with server control could steal or modify data, particularly when features like account recovery or sharing are enabled. Companies have begun patching the issues while defending their overall security practices.

The Hacker News has released its latest ThreatsDay Bulletin, focusing on various cybersecurity issues. The bulletin covers topics such as Kali Linux combined with Claude, Chrome crash traps, WinRAR flaws, and activities related to LockBit. It also includes over 15 additional stories on emerging threats.

Rapporterad av AI

Developers of the gacha RPG Duet Night Abyss have apologized for a cybersecurity incident that distributed malware to players' PCs via a launcher update on March 18. The malware, identified as Trojan:MSIL/UmbralStealer.DG!MTB, targets passwords and cryptocurrency. Players receive in-game compensation as the team implements security enhancements.

Denna webbplats använder cookies

Vi använder cookies för analys för att förbättra vår webbplats. Läs vår integritetspolicy för mer information.
Avböj