A bug in recent Windows security updates has caused some systems to unexpectedly boot into BitLocker recovery mode after installation and reboot. Microsoft confirmed that the issue primarily affects Intel devices with Connected Standby (Modern Standby) support, impacting platforms such as Windows 11 24H2, 25H2, and Windows 10 22H2. Users encountering this problem are required to enter their BitLocker recovery key to regain access, after which the system resumes normal operation without further prompts.
Microsoft has acknowledged the problem and advised IT administrators to use a group policy delivered via Known Issue Rollback (KIR) as a mitigation, with further support available through Microsoft Support for business customers. This incident follows similar BitLocker recovery issues triggered by Windows updates in May 2025, August 2024, and August 2022, highlighting a recurring challenge with update compatibility and BitLocker functionality on certain hardware configurations.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft added a known issue on April 14, 2026 stating that Windows 11 cumulative updates KB5083769 and KB5082052 may cause unexpected BitLocker recovery prompts at boot on systems with certain BitLocker Group Policy settings. The company did not withdraw the updates and advised administrators to review policies, verify recovery key access, and monitor Release Health for further guidance.
Microsoft confirmed that the October 2025 Windows updates could cause affected Windows devices to enter BitLocker recovery after restart. The company said users could recover by entering their BitLocker key and provided mitigation guidance while the issue was investigated.
After installing Microsoft's October 2025 Windows security updates and rebooting, some users were forced into BitLocker recovery mode. Reports indicate the issue primarily affected certain Intel-based systems, especially devices with Modern Standby support.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
ghacks.net
Open sourcecybersecuritynews.com
Open sourcetomshardware.com
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.