Microsoft published mitigation guidance for a Windows Recovery Environment flaw that can let an attacker bypass BitLocker with a USB stick and a crafted WinRE path. The company says its interim script removes autofstx.exe from the BootExecute registry value to reduce exposure in high-privilege recovery boot paths. The guidance is aimed at users worried about devices and data being stolen, including employees who travel with work machines.
neowin.net
Microsoft apparently blames researcher for publicly exposing a Windows 11 Recovery flaw
Earlier this month we had reported on a recently disclosed Windows security vulnerability that can let attackers bypass BitLocker. Tracked under the ID "CVE-2026-45585," the…
neowin.net
standard-tier
2026-05-22
View full article →
The disclosure also puts Microsoft in a delicate position with the researcher who found the issue: the same week, the company moved to blunt the exploit’s impact after the proof-of-concept for CVE-2026-45585 was publicly released. That makes the password-reset and recovery surface around Windows a near-term concern for Microsoft users and organizations.
neowin.net
Microsoft apparently blames researcher for publicly exposing a Windows 11 Recovery flaw
Earlier this month we had reported on a recently disclosed Windows security vulnerability that can let attackers bypass BitLocker. Tracked under the ID "CVE-2026-45585," the…
neowin.net
standard-tier
2026-05-22
View full article →
On the productivity side, Microsoft says it is finally fixing long-running PowerShell problems on macOS. The next release will be properly notarized by Apple, harden the binaries and libraries, and correct tarball file permissions, while the company says a maintenance release of PowerShell 7.4 or higher will benefit from the changes.
neowin.net
Microsoft finally fixes one of the most annoying things about PowerShell on macOS
Although many of our readers may be familiar with the native version of PowerShell available in Windows, Microsoft offers the task automation solution for macOS…
neowin.net
standard-tier
2026-05-22
View full article →