Big Tech
Big Tech analyzes decisions by major platforms and their impact on security, privacy, infrastructure and the market. The cluster connects product announcements, strategic changes and technical consequences for users and businesses.

BitLocker Zero-Day: Encrypted Drives Unlocked via USB and WinRE — No Credentials Needed
A new proof-of-concept named YellowKey enables BitLocker bypasses on Windows 11 and Server editions by exploiting the Windows Recovery…

Microsoft May Patch Tuesday Fixes 120 Flaws, but DNS and Dynamics 365 Bugs Demand Priority
Microsoft’s May 2026 update fixes roughly 120 vulnerabilities, targeting critical gaps in DNS, Dynamics 365, and Office components. Wh…

CVE-2026-3854: Critical GitHub RCE Leaves 88% of On-Premise Servers Exposed
Wiz Research has detailed CVE-2026-3854, a critical RCE vulnerability in GitHub’s internal Git pipeline. While GitHub.com was patched…

Active OAuth Redirection Attacks Targeting Government Entities via Entra ID
Microsoft has identified a phishing campaign exploiting OAuth 2.0 flows to deliver multi-stage malware to public sector organizations,…

Why an Active Directory Password Reset Isn't Enough to Evict an Attacker
A simple Active Directory password reset often fails to eliminate persistence. Valid Kerberos tickets, local hash caching, and ACL-bas…

Weaponized OAuth: Government and Public Sector Targeted in Malicious Redirection Campaign
Microsoft researchers have identified active campaigns abusing OAuth redirection to steer government and public sector entities toward…

Google Raises Android Bug Bounty to $15M — Chrome AI Rewards Cut
Google has overhauled its Vulnerability Reward Programs, offering up to $1.5 million for sophisticated Pixel exploits while reducing p…

RCE Vulnerability in Gemini CLI and Cursor AI: Details and Patches
Details on the critical severity vulnerability in Gemini CLI, the flaw in Cursor AI, and the hijacking of the Gemini panel in Chrome.…

Microsoft Zero-day: The Risk of the Faulty Patch Revealed
Discover the impact of the faulty Microsoft patch that left a new zero-click backdoor in Windows Shell. What to know about CVE-2026-32…