HeadFlash

Security

Microsoft's Mega Patch, Nuclear Leak, and Russian Hosts Charged

BitLocker zero-day bypass, record 570 fixes, Kudankulam breach, macOS malware, and bulletproof hosting charges.

Listen

BitLocker Zero-Day CVE-2026-50661 Allows Physical Bypass of Encryption

Microsoft disclosed a publicly known zero-day in BitLocker, tracked as CVE-2026-50661, fixed in the July 2026 Patch Tuesday updates. The vulnerability is a Security Feature Bypass stemming from failures in BitLocker’s protection mechanism rather than the encryption itself. An attacker with physical access can bypass BitLocker Device Encryption on the system storage drive without needing the recovery key or PIN. Microsoft has not observed exploitation in the wild but confirmed the issue was publicly disclosed before patches were available. Affected platforms include Windows 10, Windows 11, and multiple Windows Server editions. The July 14 cumulative updates (KB5099535, KB5099538, KB5099539, KB5099540, KB5101649, KB5101650) address the flaw. Microsoft rates the vulnerability as Exploitation Less Likely due to the requirement for physical access and no observed active exploitation. While remote exploitation is impossible, the risk is significant for lost or stolen devices, especially in remote or shared environments. The company recommends deploying the updates, enabling Secure Boot, using TPM-backed protection, securely storing recovery keys, and enabling pre-boot PINs where appropriate.

Windows BitLocker Zero-Day (CVE-2026-50661) Lets Attackers Bypass Encryption | The CyberSec Guru →

Kudankulam Nuclear Plant Data Leaked by Ransomware Group, Core Systems Unaffected

The ransomware group World Leaks posted a large cache of files related to the Kudankulam nuclear plant on the dark web and claimed a data breach. The Nuclear Power Corporation of India Ltd (NPCIL) and Reliance Group confirmed that core systems were untouched. NPCIL executive director Prateek Agrawal said the files are not related to nuclear safety or security systems, comparing them to tender documents for conventional services typical in thermal power plants. The plant, a 6,000-MW facility in Tamil Nadu jointly developed with Russia’s Rosatom, has units 1 and 2 operational while units 3-6 are under construction. Reliance Infra was involved in infrastructure for units 3 and 4 awarded in 2018. The incident occurred at Yotta Data Services, a third-party data centre provider. Yotta reported that a suspicious process was identified and terminated immediately, with no ransomware execution, data loss, or lateral movement. The incident was reported to CERT-In and disclosed to stock exchanges. NPCIL reiterated that the leaked information pertains only to conventional balance of plant common service facilities and does not involve nuclear safety or security systems.

Kudankulam nuclear plant data breached, NPCIL says core systems untouched →

Microsoft’s July Patch Tuesday Sets Record with 570 Fixes, Two Zero-Days Under Attack

Microsoft patched a record 570 Windows security flaws in July, the most ever in a single month, surpassing the previous record of 206 bugs in June and 164 in April. The increase is attributed to MDASH, an internal AI-powered vulnerability scanning tool that identifies flaws and reduces false positives. Patch management provider Action1 warned that organizations should expect more frequent security updates as Microsoft expands AI use, while human engineers still validate and release patches. Among the fixed vulnerabilities, three were zero-days. Two have already been exploited in attacks: one affecting Microsoft’s Active Directory and one targeting SharePoint. The third zero-day, publicly disclosed but not exploited, affects BitLocker (covered separately in this issue). The update also includes 61 critical vulnerabilities. Non-security enhancements include Widgets behavior changes, faster File Explorer, improved Bluetooth and AirPods pairing, default IPP printing, and the ability to pause updates until a specific date. Updates are mandatory, install automatically, and require a reboot.

Microsoft patches record 570 Windows security bugs with two exploited zero days - update now →

US Charges Three Russian Nationals for Operating Bulletproof Hosting Used in $62M Cybercrime

U.S. prosecutors have charged three Russian nationals — Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova, all residing in St. Petersburg — with hacking, conspiracy, and money laundering. They owned and operated web hosts Media Land and ML.Cloud, which provided bulletproof hosting and infrastructure support for cybercriminals and state-backed hackers. The indictment was first filed in 2024 and unsealed this week. The U.S. Treasury previously sanctioned the companies for allowing ransomware gangs including LockBit, BlackSuit, and Play to use their infrastructure. According to the Justice Department, hackers used the web hosts to launch DDoS attacks, phishing campaigns, and attacks on U.S. critical infrastructure. They targeted dozens of businesses across more than 20 states, netting approximately $62 million in proceeds from cybercrime. The companies allegedly shielded clients from law enforcement demands. The suspects are likely beyond reach in Russia, where extradition is rare, but U.S. Assistant Attorney General A. Tysen Duva stated the government will continue to dismantle these networks and protect critical infrastructure.

US charges Russian ‘bulletproof’ web hosts over cyberattacks that netted $62M from cybercrime victims →

New macOS Malware CrashStealer Impersonates Apple’s Crash Reporter to Steal Credentials

Jamf cybersecurity researchers detailed a new macOS infostealer named CrashStealer that masquerades as Apple’s legitimate crash reporting tool. Written in C++, the malware first appeared via a suspicious VirusTotal upload and was in development around May; it has now been released into the wild. On a victim’s Mac, it uses aliases CrashReporter.dmg and CrashReporter.app with a legitimate-looking icon to trick users. It attempts to unlock the keychain by displaying a fake password prompt mimicking a genuine macOS authorization request. CrashStealer validates stolen credentials locally, then targets installed password managers, browsers, and cryptocurrency wallets. Stolen passwords are exfiltrated in an encrypted package to an attacker-controlled server. The malware arrives as a disk image named Werkbit Setup, which is signed and Apple-notarized, allowing it to bypass Gatekeeper. Jamf recommends three habits to avoid such threats: always check .dmg sources before installing, especially cracked software; verify unexpected password requests, as a system process asking for a password during casual browsing may indicate infection; and keep macOS updated for security fixes.

New Mac malware masquerades as Apple’s crash reporter: 3 ways to dodge the threat →