Exchange Server

Winsage
May 20, 2026
Microsoft is addressing a zero-day exploit known as YellowKey, identified as CVE-2026-45585, which allows attackers to bypass BitLocker security using a specially crafted USB device. Following the release of exploit code by a hacker named Chaotic Eclipse, Microsoft has issued urgent mitigation advice. Cybersecurity expert Neena Sharma recommends treating this as an active threat and suggests implementing compensating controls, such as restricting USB boot access, until a patch is available. Microsoft has provided guidance for users to protect their systems, including the recommendation to add a PIN to BitLocker protection to reduce the risk of exploitation. Detailed instructions for adding a PIN are included in the advisory. YellowKey has not yet been exploited in the wild but requires physical access to the device.
Winsage
October 17, 2025
Microsoft has released an important update for SQL Server, designated as CVE-2025-59250, which addresses an issue with JDBC integration and requires a server reboot. Additionally, three updates for Microsoft Exchange Server have been issued: CVE-2025-53782, CVE-2025-59249, and CVE-2025-59248. Microsoft has also introduced six important updates for .NET and Visual Studio, including an update for Git (CVE-2025-54132) related to a bug in the Mermaid Diagram tool. Furthermore, Microsoft has released seven updates from various third-party vendors, including CERT/CC, Mitre, and GitHub, with Mitre and AMD advocating for CVE entries on behalf of open-source organizations to expedite patching.
Search