Microsoft Exchange hacked, Defender broken, BitLocker bypassed
Summary
Microsoft faces several active and high-risk security issues across core products: an unpatched Exchange Server spoofing CVE being exploited in the wild, three Microsoft Defender vulnerabilities (including one with public exploit code), and a newly published BitLocker bypass proof-of-concept called YellowKey. Microsoft has released patches for Defender, updated Edge to stop plaintext password handling, and issued Authenticator updates, but the Exchange Server flaw remains without an official patch, requiring emergency mitigation guidance for admins. The BitLocker YellowKey exploit affects TPM-only setups without a PIN and Microsoft has assigned it CVE-2026-45585 with updates for Windows 11 and Server 2025. Administrators should apply available Defender and OS updates, follow Exchange Emergency Mitigation recommendations, and verify engine and app versions to reduce exposure.