windows-security

标签

Cards List
#windows-security

@DragonsCyberHQ: Windows PnP is the loader here. Attacker-controlled device identities can make Windows fetch and run vendor code as SYS…

X AI KOLs Timeline ↗ · 2026-08-09 缓存

Security researchers release a DEF CON 34 talk and tooling showing that Windows Plug and Play can silently download and execute vendor code as SYSTEM via attacker-controlled device identities, including through USB emulation and RDP USB redirection.

0 人收藏 0 人点赞
#windows-security

Microsoft BitLocker – YellowKey零日漏洞利用

Hacker News Top ↗ · 2026-05-14 缓存

一名安全研究人员发布了名为YellowKey的零日漏洞利用,可绕过Windows 11和Windows Server 2022/2025上的Microsoft BitLocker加密,通过USB闪存驱动器即可完全访问锁定驱动器;该漏洞似乎以后门的方式运作,使用后相关文件会消失。

0 人收藏 0 人点赞
← 返回首页

提交意见反馈