AI-generated content
Transcribed

Record Patch Tuesday: HTTP.sys Zero-Day, BitLocker Bypass & ServiceNow Breach

Jun 11, 2026 · 5m 23s
Record Patch Tuesday: HTTP.sys Zero-Day, BitLocker Bypass & ServiceNow Breach
Chapters

01 · Three Zero-Days — CTFMON, HTTP.sys, BitLocker

32s

02 · AI Exploit Generation Shrinks Patch Window

1m 39s

03 · ServiceNow Breach — Silent Disclosure Problem

2m 24s

04 · Credential Exposure and What to Check Now

3m 19s

05 · What Enterprises Must Do Now

3m 58s

Description

Microsoft has just released the largest Patch Tuesday in its 23-year history, covering up to 208 vulnerabilities — and three of them are confirmed, actively exploited zero-days that demand immediate...

show more
Microsoft has just released the largest Patch Tuesday in its 23-year history, covering up to 208 vulnerabilities — and three of them are confirmed, actively exploited zero-days that demand immediate action across every enterprise environment.

The critical trio: an unauthenticated HTTP.sys remote code execution flaw granting kernel-mode access on internet-facing Windows servers; CVE-2026-45586, a CTFMON privilege escalation that elevates local attackers straight to SYSTEM; and CVE-2026-50507, a BitLocker volume master key bypass that undermines full-disk encryption as an offline defence. All three are in active exploitation. This is emergency patching territory.

Making the response window even tighter: large language models can now reverse-engineer patches and generate functional exploits within hours of public release. The old assumption of weeks between patch and weaponised exploit is gone.

Meanwhile, ServiceNow confirmed a separate breach of its customer data between June 2–3. Attackers exploited an unauthenticated Scripted REST API endpoint — disabled by a single misconfigured parameter — to query IT tickets and harvest embedded credentials across more than 8,000 enterprise instances. The platform was patched June 5; the advisory appeared June 9, behind a customer-only portal. That four-day gap may already have organisations running behind on GDPR, HIPAA, and SEC notification clocks.

In this episode: what to patch first, how to assess your ServiceNow exposure, why the monthly patch cycle no longer fits the threat environment, and the specific actions security teams should take in the next 24 hours.

This episode includes AI-generated content.
show less
Information
Author Yes Oui
Organization YesOui
Website -
Tags

Looks like you don't have any active episode

Browse Spreaker Catalogue to discover great new content

Current

Podcast Cover

Looks like you don't have any episodes in your queue

Browse Spreaker Catalogue to discover great new content

Next Up

Episode Cover Episode Cover

It's so quiet here...

Time to discover new episodes!

Discover
Your Library
Search