theSIGNAL TECHNOLOGY
16 July 2026
"Security is mostly a superstition — it does not exist in nature."
Photo: Clint Patterson / Unsplash
A Windows login screen — the precise moment HiveLegacy's hidden code can be triggered by an unsuspecting administrator.
🔓
0 clicks
Victim interaction needed for some attack chains
Discuss
  • What does this vulnerability reveal about the assumptions built into Windows security design?
  • Should security researchers publish exploit details before a patch is available, or wait for coordinated disclosure?
Technology

Windows Flaw Lets Ordinary Users Hijack Admin Sessions

A newly exposed vulnerability called HiveLegacy allows a non-administrator to plant malicious code that runs invisibly when a higher-privileged user logs in.

On most days, the wall between an ordinary Windows user and a system administrator feels solid. It is not. A vulnerability now being called HiveLegacy has exposed a surprisingly old-fashioned crack in that wall — one that does not require any special tools, only patience and a little knowledge of how Windows manages its registry. The flaw was described publicly by Will Dormann, a senior principal vulnerability analyst at Tharros Labs.

When a new user logs on to a Windows machine, the operating system must load that user's "class hive" — a portion of the registry that stores software configuration data. Because the user is not yet active when this loading happens, Windows performs the operation under the authority of NT AUTHORITY\SYSTEM, the most privileged account on the machine. A separate researcher has noted that HiveLegacy exploits precisely this window of elevated trust. A non-administrator who can write to another user's class registry hive can therefore insert code that will be executed automatically — and silently — the moment an administrator next signs in.

What makes the finding especially uncomfortable is its reach. Dormann has warned that the primitive could be chained with a second, separate exploit to gain direct access to an administrative account without any interaction from the victim at all. Microsoft has confirmed it is investigating the report, while also expressing a preference for coordinated disclosure before vulnerabilities are made public. For Windows users waiting for an official patch, independent researcher Kevin Beaumont has published a detection script that can reveal whether a system has already been targeted.

//
I don't need to be an admin myself.
Will Dormann, Senior Principal Vulnerability Analyst, Tharros Labs
Technology

IBM's Worst Day Since Black Monday

On a single Tuesday in June, IBM lost more than a quarter of its market value — a steeper single-day fall than it suffered during the 1987 Black Monday crash — after the company warned that second-quarter revenue had reached only $17.2bn, barely 1% above the previous year. The culprit was a sudden lurch in corporate spending. As AI-driven demand sent prices for servers, memory chips and storage soaring worldwide, IBM's biggest clients rushed to secure that scarce hardware before costs rose further, draining budgets away from IBM's high-margin mainframe software — the very products the company had relied on.…
  • Is AI infrastructure spending permanently reshaping how companies allocate their technology budgets?
Technology

Driver, Not Tesla, Caused Fatal Crash

On a clear June morning in Katy, Texas, a Tesla travelling at more than 70 miles per hour — more than double the 30 mph speed limit — left Rose Hollow Lane and struck the home of Martha Avila, 76, killing her instantly. The US National Transportation Safety Board has now confirmed what Tesla argued from the start: the driver, Michael Butler, had pressed the accelerator to 100%, overriding the Full Self-Driving (Supervised) system entirely. What complicates the picture is Butler's own phone.…
  • If a driver overrides autonomous software, where does legal responsibility truly lie?
AMERICAS · Technology
‘This was a righteous case. A holy war’: the lawyer who took on Meta and Google – and won
AMERICAS · Technology
US military sent explosive drone boats into combat for the first time
EUROPE · Technology
Ukrainian drone strikes forced Russia to stop shipping in vital sea corridor
WORLD · Technology
The fight against AI data centers is just beginning
theSIGNAL IN THE LAB
1VOCABULARY
coordinated disclosurechained
elevated trustlurchhigh-margin
overridingprimitive
2GRAMMAR FOCUS
Causative have/get — have something done
Use 'have/get + object + past participle' to describe arranging for someone else to do something for you, or when something is done to the subject by an outside agent. For example: 'She had her system checked by a specialist.'
audited · executed · patched · investigated · published · leaked · replaced
  1. Microsoft wants researchers to have vulnerabilities through coordinated disclosure rather than making them public immediately.
  2. After the HiveLegacy flaw was revealed, many IT administrators decided to have their registry settings by security specialists.
  3. Kevin Beaumont had a detection script so that Windows users could check whether their machines had already been targeted.
  4. Following the fatal crash in Katy, Texas, investigators had Butler's phone records to understand his intentions before the accident.
  5. IBM's biggest clients had their hardware orders well in advance, draining budgets away from high-margin mainframe software.
  6. After losing more than a quarter of its market value in a single day, IBM's board had its entire financial strategy .
3DEPENDENT PREPOSITIONS
Complete each phrase with the correct preposition. All from today's articles.
  1. The flaw was described publicly ___ Will Dormann, a senior principal vulnerability analyst.
  2. Windows performs the operation ___ the authority of NT AUTHORITY\SYSTEM.
  3. The primitive could be chained ___ a second, separate exploit.
  4. Microsoft has confirmed it is investigating the report, while also expressing a preference ___ coordinated disclosure.
  5. Budgets were drained away ___ IBM's high-margin mainframe software.
4CRITICAL THINKING
IBM's single-day collapse was triggered not by a failed product but by its customers choosing to spend elsewhere — raising the question of whether a company can remain healthy when its clients' priorities shift faster than its own business model can adapt. To what extent should IBM's leadership have anticipated that AI infrastructure spending would compete directly with demand for mainframe software, and what does their apparent failure to do so suggest about how large technology firms read market signals?
5CREATIVE · HEADLINES
Write a headline for the top story in each of the following styles. One line each, no explanation:
  • TABLOID NEWSPAPER
  • LUXURY MAGAZINE
  • ACTIVIST BLOG
6WRITING
The HiveLegacy vulnerability was discovered and disclosed by independent researchers rather than by Microsoft itself — consider what this pattern reveals about the relationship between software companies and the security community, and argue whether corporate self-regulation in cybersecurity is realistic or whether external accountability is structurally necessary.
7DEGREES OF EXTREMITY
Complete each ladder from mild to strong.
  • noticeable→→
  • look into→→
  • careful→→
  • preference→→
  • uncomfortable→→
  • rises→→
8SPEAKING
  1. Could HiveLegacy have been discovered and exploited years earlier?
  2. Does FSD marketing create unrealistic expectations among drivers?
  3. Should mainframe software companies diversify before AI marginalises them?
  4. How should regulators respond when autonomous systems can be overridden?