Skip to content
The Coolest Info

The Coolest Info

Subscribe
  • News
  • Crypto Predictions
The Coolest Info

The Coolest Info

  • News
  • Crypto Predictions
  • Home
  • 2026
  • June
  • 11
  • New GreatXML Zero-Day Lets Attackers Crack BitLocker via Defender Flaw
  • Security

New GreatXML Zero-Day Lets Attackers Crack BitLocker via Defender Flaw

The TeamJune 11, 2026June 11, 202601 mins

A freshly discovered proof-of-concept exploit dubbed GreatXML can fully bypass BitLocker disk encryption on Windows machines — and the attack vector is surprisingly mundane. Researchers found that by manipulating how Microsoft Defender handles offline scans, an attacker can spawn a SYSTEM-level shell when the machine reboots into Windows Recovery Environment.

What makes this particularly nasty is the attack chain: it doesn’t require physical access in the traditional sense, nor does it need a sophisticated bootkit. Instead, it piggybacks on a legitimate Defender feature designed to catch persistent malware. When Windows RE kicks in for an offline scan, the exploit hijacks the process and drops the attacker into a privileged command prompt — with full access to the supposedly encrypted drive.

BitLocker has long been considered a solid last line of defense for data-at-rest protection. This PoC doesn’t break the encryption mathematically; it sidesteps it entirely by abusing a trusted system component. Microsoft hasn’t issued a patch yet, so organizations relying on BitLocker should monitor for unusual RE boot cycles and consider additional pre-boot authentication layers.

Source: SecurityWeek

Tagged: Account Security bitlocker greatxml Infosecurity Europe Microsoft Defender VPN zero-day

Post navigation

Previous: Iran’s Internet Is Back After 88 Days, but Don’t Celebrate Yet
Next: OceanLotus APT Targets Vietnam Investors With SPECTRALVIPER Backdoor in Dual Campaigns

Related News

NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

June 13, 2026

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

June 13, 2026

Chinese hackers hijack auth flow, spy on isolated network for a decade

June 13, 2026

Microsoft Patches BitLocker Recovery Loop Bug Hitting Windows Server 2025

June 11, 2026June 11, 2026

Recent Posts

  • My first 24 hours with Siri AI on the Mac
  • Bose’s latest QuietComfort Ultra are $70 off, marking a new low price
  • Microsoft hasn’t ruled out spinning off Xbox
  • NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
  • Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Recent Comments

No comments to show.

Archives

  • June 2026

Categories

  • Cryptocurrency
  • Security
  • Security Advisories
  • Technology
  • Crypto Predictions
Online Newspaper - News / Magazine WordPress Theme 2026.
Back To Top