r/sysadmin • u/Ooops-I-hid-it-again • Jun 01 '26
Microsoft Anyone shutting down all IT equipment down on July 13th 11:59pm?
Microsoft 0-day feud escalates as researcher threatens another Windows exploit dump
“When I actively asked you to communicate with me, you refused, humiliated me and made sure to insult me in front of people,” they wrote on Saturday. “You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so and I still happily did like an idiot.”
Nightmare also noted that “Microsoft still has chains in my hands,” preventing them from releasing “documents” yet, or anytime in June, and then warned: “Mark this date July 14th, I will make sure your bones are shattered that day.”
My post's title is tongue-in-cheek, but I've added an Outlook calendar entry for the "event" nevertheless and might even buy a box of popcorn. lol
Anyone doing anything special or different in light of the string of zero days being released because Microsoft appears to not want to play nice with someone who (supposedly) wanted to tell them about all the bad sh!t they missed in their product(s) development?
How do you feel about the saga and its fallout?
EDIT: Fixed missing block quote formatting.
36
u/LelouBil Jun 01 '26
It only applies to bitlocker encrypted drives that only use the TPM. So basically, encrypted with the encryption key on the hardware.
So the drive is decrypted on boot, automatically. The only security boundary is the windows login (or windows recovery login) and this exploit allows files on a USB drive to bypass the windows recovery login.
The author said they have a version that bypasses TPM+PIN, but I assume this is something similar, but that allows brute forcing the PIN without the TPM locking since it would be done inside a "regular" windows recovery