他们忘了上次的教训:破解 Windows 365 Link [视频]
摘要
一场在 EMF 2026 上的演讲,研究员 Rairii 展示了如何破解微软的 Windows 365 Link 瘦客户端,绕过其锁定型的“安全设计”架构,包括 EFI 安全启动和 BitLocker。
查看缓存全文
缓存时间: 2026/08/04 01:36
相似文章
安全研究人员声称微软为Bitlocker构建了后门,并发布漏洞利用程序
一位安全研究人员声称微软在BitLocker中构建了后门,并发布漏洞利用程序,引发对加密完整性的担忧。
在与研究人员激烈争执后,微软修复了其披露的0-day漏洞
微软修复了研究人员Nightmare Eclipse在激烈争执中披露的一个0-day漏洞,以及MiniPlasma、YellowKey等其他漏洞。该研究人员还发布了针对一个新Windows Defender漏洞的利用代码。
@DragonsCyberHQ: Windows PnP is the loader here. Attacker-controlled device identities can make Windows fetch and run vendor code as SYS…
Security researchers release a DEF CON 34 talk and tooling showing that Windows Plug and Play can silently download and execute vendor code as SYSTEM via attacker-controlled device identities, including through USB emulation and RDP USB redirection.
Microsoft BitLocker – YellowKey零日漏洞利用
一名安全研究人员发布了名为YellowKey的零日漏洞利用,可绕过Windows 11和Windows Server 2022/2025上的Microsoft BitLocker加密,通过USB闪存驱动器即可完全访问锁定驱动器;该漏洞似乎以后门的方式运作,使用后相关文件会消失。
微软的Secure Boot已被攻破十年,至今才被发现
ESET研究人员发现,由于未撤销的已签名shims,微软的Secure Boot在13年间一直存在可被轻易绕过的漏洞,攻击者可借此在Windows和Linux设备上安装持久性固件恶意软件。