top of page


Enterprise Security Tech
A cybersecurity resource for CxOs
Search


GreatXML Windows Zero-Day Turns Defender Offline Scan Into a BitLocker Backdoor
The post-compromise technique abuses Windows Recovery Environment to create persistent access to BitLocker-encrypted data, with no patch currently available. According to the Cyderes Howler Cell team, a newly disclosed Windows zero-day called GreatXML can turn Microsoft Defender’s offline scanning process into a pathway for accessing BitLocker-encrypted data without a recovery key or user credentials. The technique targets the interaction between Windows Recovery Environment,
Jun 11


Kali365 Phishing Platform Turns Microsoft Logins Into an AI-Powered Fraud Pipeline
The phishing-as-a-service operation uses Microsoft device codes, stolen authentication tokens and AI-generated business email compromise messages to help attackers bypass traditional account defenses. A newly analyzed phishing platform known as Kali365 is giving cybercriminals an unusually complete toolkit for compromising Microsoft 365 accounts and converting stolen access into financial fraud. Huntress researchers uncovered the operation after detecting a spike in device co
Jun 11


University of Nottingham Cyberattack Exposes Student Financial and Personal Data
Hackers accessed a significant amount of personal data belonging to University of Nottingham students and alumni, potentially including financial records, National Insurance numbers and protected characteristics. The university detected unauthorized activity in its Campus Solutions student records system on Tuesday and took affected systems offline. It has contacted impacted individuals and reported the incident to Action Fraud, the Information Commissioner’s Office and other
Jun 10


Meta AI Support Flaw Led to 20,225 Instagram Account Takeovers
A vulnerability in Meta’s AI-assisted account recovery system allowed attackers to hijack 20,225 Instagram accounts by redirecting password reset links to email addresses they controlled. The flaw affected High Touch Support, or HTS, an AI-powered system designed to help locked-out Instagram users recover their accounts. The recovery process failed to properly confirm that a newly submitted email address was already associated with the account being targeted. Attackers could
Jun 10


White House AI Order Raises the Stakes for Enterprise AI Governance
The White House’s new artificial intelligence executive order is focused heavily on national security, frontier model testing and AI-powered cyber defense. For businesses, however, its broader message is difficult to ignore: AI systems should be tested, monitored and governed before they become deeply embedded in critical operations. The order directs federal agencies to develop classified benchmarks for evaluating the cyber capabilities of advanced AI models. It also propose
Jun 10


RoguePlanet Windows Zero-Day Turns Microsoft Defender Into an Exploitation Tool
A newly disclosed Windows zero-day dubbed RoguePlanet abuses Microsoft Defender’s own quarantine process to give an ordinary user the highest level of control over a Windows 11 machine. Cyderes researchers said they reproduced the local privilege escalation exploit on a fully patched Windows 11 Pro system. The attack requires no administrator rights, kernel vulnerability or memory corruption. Instead, it chains together legitimate Windows features, including Defender scans, N
Jun 10
bottom of page