Marc-Frédéric GOMEZ

Oracle’s September 2026 CSPU: 673 security patches

Oracle released 673 security patches on 15 September 2026, 247 of them for vulnerabilities that are remotely exploitable without authentication. Six carry the maximum score of 10.0, five of those in Fusion Middleware. TLP:CLEAR   PAP:CLEAR   Unlimited disclosure, no restriction on use. Published 16 September 2026 Subject Oracle, September 2026 CSPU Distribution Public Confidence…

GreatXML: Technical and Defensive Analysis of a BitLocker Bypass via WinRE

1. Executive summary GreatXML is a public proof-of-concept, released on 10 June 2026 by the researcher Nightmare Eclipse / Chaotic Eclipse / MSNightmare, claiming a BitLocker bypass. The technique abuses the Windows Recovery Environment (WinRE), the state left behind by Microsoft Defender’s Offline Scan feature, and the legitimate processing of unattended setup answer files (unattend.xml).…

RoguePlanet: a new Microsoft Defender zero-day disclosed in the wake of Patch Tuesday

RoguePlanet: a new Microsoft Defender zero-day disclosed in the wake of Patch Tuesday Threat Intelligence · Vulnerability June 10, 2026 · Marc-Frédéric Gomez · 6 min read Just hours after the June 2026 fixes shipped, the researcher Nightmare Eclipse published a new exploit targeting Microsoft Defender. It works against Windows systems that are already up…

Project Glasswing

Artificial Intelligence — vulnerabilities-anthropic What the First Public Update on Claude Mythos Reveals Anthropic published on May 22, 2026 the results of the first month of its defensive initiative. More than 10,000 vulnerabilities of high or critical severity identified, a bottleneck that has shifted from detection to remediation, and an access strategy that draws a…