GreatXML: Exploiting the WinRE trust boundary behind BitLocker
ID: 930fdecd-e2eb-5552-92fb-a5668b109a0c
STIX ID: report--930fdecd-e2eb-5552-92fb-a5668b109a0c
Feed Name: ThreatLocker Blog
Threat Score
Nightmare Eclipse (aka Chaotic Eclipse) published a zero-day named GreatXML (June 10, 2026) that allows an attacker with local administrator access to bypass BitLocker by abusing the Windows Recovery Environment, Microsoft Defender Offline scan, and Windows Setup unattend files to execute commands as SYSTEM; the report includes technical analysis, replication steps, IOCs for detection, and corresponding ThreatLocker community policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
