5 ms·
Mystery Microsoft bug leaker keeps the zero-days coming
- __alexander 5mo agoSo weird that GitHub requires a login to view their BlueHammer repo. https://github.com/Nightmare-Eclipse/BlueHammer https://github.com/Nightmare-Eclipse/BlueHammer
- tsujamin 5mo agoThat warning also doesn’t render right on my iPhone (the buttons are overlapping slightly), and I don’t recall seeing it on other repos. Is it new/bespoke?
- dewey 5mo agoI'm logged in, but I'm seeing this now and can click on "View repository" or "Explore other repositories". Maybe that's why it's behind a login wall. > This repository contains malicious content that may cause technical harms. We have decided to preserve this content for security research purposes. Please exercise CAUTION when clicking links, downloading releases, or otherwise interacting with this repository.
- purpleidea 5mo agoIt's so obvious that many of the bugs being found are/were most likely M$ backdoors. There doesn't seem to be any other plausible explanation. The reckoning needs to come and people need to stop using their products for good. Would love a whistleblower to explain which part of the government or company forced it.
- youre-wrong3 5mo ago[flagged]
- lpcvoid 5mo ago[dead]
- anonymars 5mo agoHaven't there been heaps of vulnerabilities cropping up all over recently, including CopyFail and Dirty Frag?
- zuzululu 5mo agoyeah those have shaken a lot of people's confidence in Linux and I don't really see people ditching Windows either. In some ways the hysteria of sorts is peculiar....its not like we never had secure cybersecurity either its just that we have too much on the cloud and institutions of trust without questioning it because of herd behavior and empty suits. Like the timing of all of these seemingly disparate events from "mystery lonewolf" is too obvious and I'm not the one to entertain conspiracies either.
- Veserv 5mo agoWe had secure cybersecurity? When? I mean, there is some in the high assurance space, but that has never trickled into the broader consumer sphere. Are you referencing those systems? I am unaware of anything else.
- BizarroLand 5mo agoA LOT of people are ditching windows. The only Windows computer I have left out of 5 is a work pc. CachyOS is pretty amazing, too.
- blitzar 5mo agoThey might be incompetent
- hulitu 5mo ago> which part of the government the same one who takes care of Cisco ? and Google ? and ...
- NDlurker 5mo agoOh cool. My brother's old laptop is locked. Maybe this will help
- ndiddy 5mo agoI think the Bitlocker "vuln" is a good reminder not to use vendor provided encryption for any sensitive data. https://github.com/Nightmare-Eclipse/YellowKey/ https://github.com/Nightmare-Eclipse/YellowKey/ You load a specific file onto a flash drive, plug it into a Bitlocker encrypted computer, reboot it while holding a key combination, and it pops up a command prompt with full access to the encrypted volume. There's no way this isn't a backdoor.
- otterley 5mo ago> I think the Bitlocker "vuln" is a good reminder not to use vendor provided encryption for any sensitive data I don't think that's true. Some vendors have a better track record than others. Nobody's popped the storage encryption on iOS or MacOS devices yet AFAIK; and the fact that it's tied to a hardware secure element makes it pretty strong.
- thefz 5mo agoYou mean aside from the NSA? https://en.wikipedia.org/wiki/PRISM https://en.wikipedia.org/wiki/PRISM
- otterley 5mo agoI don't see anything on the linked page that supports a conclusion that NSA has successfully broken the encryption at rest of an Apple device's storage since they introduced the secure element. Care to share a quote?
- ffsm8 5mo agoPrism targeted network communication to my knowledge, hence the data wouldn't be siphoned from at rest encrypted devices. Instead it would've been leaked before it was copied to that local encrypted device, whenever it was transmitted over the wire. Eg when your background task uploaded it to iCloud or similar.
- 5mo ago
- quxuejun 5mo agoi think so~
- NordStreamYacht 5mo agoLaid off Microsoft researcher?
- zuzululu 5mo agoNo way to know but the timing is peculiar....conspiracy?
- pcthrowaway 5mo agoOr laid of NSA, laid off Mossad, or many other possibilities. Or not laid off at all, but otherwise disgruntled security researcher who prompted AI to concoct some personal details that seem to be in line with someone inexplicably dropping Microsoft zero-days.
- pajko 5mo ago... who converted Windows 11 into Emmentaler: https://deadeclipse666.blogspot.com/2026/04/ https://deadeclipse666.blogspot.com/2026/04/
- ChrisArchitect 5mo agoRelated: YellowKey Bitlocker Bypass Vulnerability https://news.ycombinator.com/item?id=48114997 https://news.ycombinator.com/item?id=48114997
- aussieguy1234 5mo agoCould the Bitlocker vulnerability be a backdoor mandated by some government agency?
- aussieguy1234 5mo agoI see upvotes, so at least some people agree with this possibility. One more reason to stick with open source, auditable solutions. Any backdoor in open source software would be quickly noticed by the community (such as recently when NPM packages got compromised).
- getcrunk 5mo agoAnyone remember the Samsung ssd issue with bitlocker from maybe like a decade or so ago where it was an empty encryption key or something
- Havoc 5mo agoSeems odd that someone is both capable of this and homeless. This stuff has decent value on the grey market
- gilrain 5mo agoYou imagine people wind up homeless because they can’t do useful things? What a just world!
- dmantis 5mo agoSome anon hero cleans up backdoored garbage. This year looks very refreshing for software. My guess is because of the AI-assitance in grinding an unlimited amount of code. While I feel sorry for maintainers and developers who have a new CVE everyday, society seems to be sweeping away 20 years of backdoor development by shady companies and spies, making computing actually safe and trusted for the first time in our lifetime.