home.social

#yellowkey — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #yellowkey, aggregated by home.social.

fetched live
  1. Nightmare Eclipse: один против Microsoft

    Хабр, привет! На связи Владимир Шнейдмюллер, аналитик-исследователь угроз кибербезопасности R-Vision. Вокруг Nightmare Eclipse за последние недели успело сложиться почти всё, что обычно сопровождает громкие публичные zero-day: резкие заявления автора, споры о такой практике раскрытия, быстрые проверки PoC сообществом, первые форки и закономерный вопрос - что из этого можно увидеть в телеметрии, а что останется почти полностью за пределами SIEM? Мы разобрали несколько опубликованных PoC и в этой статье начнем с первых трёх: YellowKey, GreenPlasma и MiniPlasma. Они существенно различаются как по векторам атак, так и по возможностям обнаружения. YellowKey интересен как обход BitLocker через WinRE, но почти не оставляет удобных событий в ОС. GreenPlasma демонстрирует низкоуровневый примитив на стыке CTF/Winlogon и Windows Object Manager. MiniPlasma, наоборот, уже дает практический сценарий локального повышения привилегий, где можно строить вполне рабочие детекты по реестру, файловой системе и запуску процессов. Ниже не будет пошаговой инструкции по эксплуатации. Нас интересуют механика, артефакты и точки наблюдения, которые полезны SOC и threat hunting-командам.

    habr.com/ru/companies/rvision/

    #кибербезопасность #управление_уязвимостями #zeroday #windows #bitlocker #poc #winre #MiniPlasma #YellowKey #GreenPlasma

  2. Nightmare Eclipse: один против Microsoft

    Хабр, привет! На связи Владимир Шнейдмюллер, аналитик-исследователь угроз кибербезопасности R-Vision. Вокруг Nightmare Eclipse за последние недели успело сложиться почти всё, что обычно сопровождает громкие публичные zero-day: резкие заявления автора, споры о такой практике раскрытия, быстрые проверки PoC сообществом, первые форки и закономерный вопрос - что из этого можно увидеть в телеметрии, а что останется почти полностью за пределами SIEM? Мы разобрали несколько опубликованных PoC и в этой статье начнем с первых трёх: YellowKey, GreenPlasma и MiniPlasma. Они существенно различаются как по векторам атак, так и по возможностям обнаружения. YellowKey интересен как обход BitLocker через WinRE, но почти не оставляет удобных событий в ОС. GreenPlasma демонстрирует низкоуровневый примитив на стыке CTF/Winlogon и Windows Object Manager. MiniPlasma, наоборот, уже дает практический сценарий локального повышения привилегий, где можно строить вполне рабочие детекты по реестру, файловой системе и запуску процессов. Ниже не будет пошаговой инструкции по эксплуатации. Нас интересуют механика, артефакты и точки наблюдения, которые полезны SOC и threat hunting-командам.

    habr.com/ru/companies/rvision/

    #кибербезопасность #управление_уязвимостями #zeroday #windows #bitlocker #poc #winre #MiniPlasma #YellowKey #GreenPlasma

  3. Nightmare Eclipse: один против Microsoft

    Хабр, привет! На связи Владимир Шнейдмюллер, аналитик-исследователь угроз кибербезопасности R-Vision. Вокруг Nightmare Eclipse за последние недели успело сложиться почти всё, что обычно сопровождает громкие публичные zero-day: резкие заявления автора, споры о такой практике раскрытия, быстрые проверки PoC сообществом, первые форки и закономерный вопрос - что из этого можно увидеть в телеметрии, а что останется почти полностью за пределами SIEM? Мы разобрали несколько опубликованных PoC и в этой статье начнем с первых трёх: YellowKey, GreenPlasma и MiniPlasma. Они существенно различаются как по векторам атак, так и по возможностям обнаружения. YellowKey интересен как обход BitLocker через WinRE, но почти не оставляет удобных событий в ОС. GreenPlasma демонстрирует низкоуровневый примитив на стыке CTF/Winlogon и Windows Object Manager. MiniPlasma, наоборот, уже дает практический сценарий локального повышения привилегий, где можно строить вполне рабочие детекты по реестру, файловой системе и запуску процессов. Ниже не будет пошаговой инструкции по эксплуатации. Нас интересуют механика, артефакты и точки наблюдения, которые полезны SOC и threat hunting-командам.

    habr.com/ru/companies/rvision/

    #кибербезопасность #управление_уязвимостями #zeroday #windows #bitlocker #poc #winre #MiniPlasma #YellowKey #GreenPlasma

  4. I am reading the #ThreatIQ report on #YellowKey from Microsoft and..... it is so vague and unhelpful. This is essentially a shrug from #Microsoft saying "well, they found the backdoor, i guess we'll patch that one."

  5. I am reading the #ThreatIQ report on #YellowKey from Microsoft and..... it is so vague and unhelpful. This is essentially a shrug from #Microsoft saying "well, they found the backdoor, i guess we'll patch that one."

  6. I am reading the #ThreatIQ report on #YellowKey from Microsoft and..... it is so vague and unhelpful. This is essentially a shrug from #Microsoft saying "well, they found the backdoor, i guess we'll patch that one."

  7. I am reading the #ThreatIQ report on #YellowKey from Microsoft and..... it is so vague and unhelpful. This is essentially a shrug from #Microsoft saying "well, they found the backdoor, i guess we'll patch that one."

  8. Hey Windows (ab)users! Microsoft patched around 200 vulnerabilities in Windows etc today, a record Patch Tuesday batch. All indications are they fixed two of the zero-days dropped last month by the researcher Nightmare Eclipse, including "Green Plasma" and the "YellowKey" exploit that allowed local access to data encrypted by BitLocker. In response to today's Patch Tuesday, Nightmare Eclipse dropped an exploit for what they claimed was a zero-day bug in Windows Defender.

    Nearly three dozen of the bugs patched this month earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available.

    krebsonsecurity.com/2026/06/a-

    #patchtuesday #windows #nightmareeclipse #greenplasma #yellowkey

  9. Hey Windows (ab)users! Microsoft patched around 200 vulnerabilities in Windows etc today, a record Patch Tuesday batch. All indications are they fixed two of the zero-days dropped last month by the researcher Nightmare Eclipse, including "Green Plasma" and the "YellowKey" exploit that allowed local access to data encrypted by BitLocker. In response to today's Patch Tuesday, Nightmare Eclipse dropped an exploit for what they claimed was a zero-day bug in Windows Defender.

    Nearly three dozen of the bugs patched this month earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available.

    krebsonsecurity.com/2026/06/a-

    #patchtuesday #windows #nightmareeclipse #greenplasma #yellowkey

  10. Hey Windows (ab)users! Microsoft patched around 200 vulnerabilities in Windows etc today, a record Patch Tuesday batch. All indications are they fixed two of the zero-days dropped last month by the researcher Nightmare Eclipse, including "Green Plasma" and the "YellowKey" exploit that allowed local access to data encrypted by BitLocker. In response to today's Patch Tuesday, Nightmare Eclipse dropped an exploit for what they claimed was a zero-day bug in Windows Defender.

    Nearly three dozen of the bugs patched this month earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available.

    krebsonsecurity.com/2026/06/a-

    #patchtuesday #windows #nightmareeclipse #greenplasma #yellowkey

  11. Hey Windows (ab)users! Microsoft patched around 200 vulnerabilities in Windows etc today, a record Patch Tuesday batch. All indications are they fixed two of the zero-days dropped last month by the researcher Nightmare Eclipse, including "Green Plasma" and the "YellowKey" exploit that allowed local access to data encrypted by BitLocker. In response to today's Patch Tuesday, Nightmare Eclipse dropped an exploit for what they claimed was a zero-day bug in Windows Defender.

    Nearly three dozen of the bugs patched this month earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available.

    krebsonsecurity.com/2026/06/a-

    #patchtuesday #windows #nightmareeclipse #greenplasma #yellowkey

  12. Hey Windows (ab)users! Microsoft patched around 200 vulnerabilities in Windows etc today, a record Patch Tuesday batch. All indications are they fixed two of the zero-days dropped last month by the researcher Nightmare Eclipse, including "Green Plasma" and the "YellowKey" exploit that allowed local access to data encrypted by BitLocker. In response to today's Patch Tuesday, Nightmare Eclipse dropped an exploit for what they claimed was a zero-day bug in Windows Defender.

    Nearly three dozen of the bugs patched this month earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available.

    krebsonsecurity.com/2026/06/a-

    #patchtuesday #windows #nightmareeclipse #greenplasma #yellowkey

  13. If I understand this correctly every past and present theft of a windows notebook that contains PII encrypted with #bitlocker got a potential „upgrade“ regarding #gdpr.

    #yellowKey

    cyberplace.social/@GossiTheDog

  14. If I understand this correctly every past and present theft of a windows notebook that contains PII encrypted with #bitlocker got a potential „upgrade“ regarding #gdpr.

    #yellowKey

    cyberplace.social/@GossiTheDog

  15. If I understand this correctly every past and present theft of a windows notebook that contains PII encrypted with #bitlocker got a potential „upgrade“ regarding #gdpr.

    #yellowKey

    cyberplace.social/@GossiTheDog

  16. If I understand this correctly every past and present theft of a windows notebook that contains PII encrypted with #bitlocker got a potential „upgrade“ regarding #gdpr.

    #yellowKey

    cyberplace.social/@GossiTheDog

  17. If I understand this correctly every past and present theft of a windows notebook that contains PII encrypted with #bitlocker got a potential „upgrade“ regarding #gdpr.

    #yellowKey

    cyberplace.social/@GossiTheDog

  18. @bjoern
    Es scheint noch viel schlimmer zu sein: Das was über #YellowKey bekannt geworden ist sieht sehr viel mehr wie eine #Backdoor in #Bitlocker aus als eine versehentlich gevibete Schwachstelle...

    @heiseonline

  19. @bjoern
    Es scheint noch viel schlimmer zu sein: Das was über #YellowKey bekannt geworden ist sieht sehr viel mehr wie eine #Backdoor in #Bitlocker aus als eine versehentlich gevibete Schwachstelle...

    @heiseonline

  20. @bjoern
    Es scheint noch viel schlimmer zu sein: Das was über #YellowKey bekannt geworden ist sieht sehr viel mehr wie eine #Backdoor in #Bitlocker aus als eine versehentlich gevibete Schwachstelle...

    @heiseonline

  21. @bjoern
    Es scheint noch viel schlimmer zu sein: Das was über #YellowKey bekannt geworden ist sieht sehr viel mehr wie eine #Backdoor in #Bitlocker aus als eine versehentlich gevibete Schwachstelle...

    @heiseonline

  22. @bjoern
    Es scheint noch viel schlimmer zu sein: Das was über #YellowKey bekannt geworden ist sieht sehr viel mehr wie eine #Backdoor in #Bitlocker aus als eine versehentlich gevibete Schwachstelle...

    @heiseonline

  23. Wenn ihr euch bisher darauf verlassen habt dass eure Festplatten dank #Bitlocker verschlüsselt und eure Daten felsenfest geschützt sind... Nope. #YellowKey sieht nicht aus wie ein Bug, sondern wie eine absichtlich eingebaute #Backdoor.

  24. Wenn ihr euch bisher darauf verlassen habt dass eure Festplatten dank #Bitlocker verschlüsselt und eure Daten felsenfest geschützt sind... Nope. #YellowKey sieht nicht aus wie ein Bug, sondern wie eine absichtlich eingebaute #Backdoor.

  25. Wenn ihr euch bisher darauf verlassen habt dass eure Festplatten dank #Bitlocker verschlüsselt und eure Daten felsenfest geschützt sind... Nope. #YellowKey sieht nicht aus wie ein Bug, sondern wie eine absichtlich eingebaute #Backdoor.

  26. Wenn ihr euch bisher darauf verlassen habt dass eure Festplatten dank #Bitlocker verschlüsselt und eure Daten felsenfest geschützt sind... Nope. #YellowKey sieht nicht aus wie ein Bug, sondern wie eine absichtlich eingebaute #Backdoor.

  27. Wenn ihr euch bisher darauf verlassen habt dass eure Festplatten dank #Bitlocker verschlüsselt und eure Daten felsenfest geschützt sind... Nope. #YellowKey sieht nicht aus wie ein Bug, sondern wie eine absichtlich eingebaute #Backdoor.

  28. @natesubra
    I just skimmed over that #YellowKey thing. But the way I understand it... well: I don't know whether a responsible way to disclose such a blatantly backdoor-looking vulnerability even exists.
    @GossiTheDog

  29. @natesubra
    I just skimmed over that #YellowKey thing. But the way I understand it... well: I don't know whether a responsible way to disclose such a blatantly backdoor-looking vulnerability even exists.
    @GossiTheDog

  30. @natesubra
    I just skimmed over that #YellowKey thing. But the way I understand it... well: I don't know whether a responsible way to disclose such a blatantly backdoor-looking vulnerability even exists.
    @GossiTheDog

  31. @natesubra
    I just skimmed over that #YellowKey thing. But the way I understand it... well: I don't know whether a responsible way to disclose such a blatantly backdoor-looking vulnerability even exists.
    @GossiTheDog

  32. @natesubra
    I just skimmed over that #YellowKey thing. But the way I understand it... well: I don't know whether a responsible way to disclose such a blatantly backdoor-looking vulnerability even exists.
    @GossiTheDog

  33. hackingpassion.com/yellowkey-b - If you can get physical access to a machine, will bypass on a fully patched machine.

  34. #Microsoft #BitLocker-protected drives can now be opened with just some files on a #USB stick — YellowKey #zeroday #exploit demonstrates an apparent backdoor #YellowKey is kind of crazy because now, any device that was stolen but protected by BitLocker is now super-compromised, with no recourse

    #computersecurity #security #cybersec

  35. #Microsoft #BitLocker-protected drives can now be opened with just some files on a #USB stick — YellowKey #zeroday #exploit demonstrates an apparent backdoor #YellowKey is kind of crazy because now, any device that was stolen but protected by BitLocker is now super-compromised, with no recourse

    #computersecurity #security #cybersec

  36. #Microsoft #BitLocker-protected drives can now be opened with just some files on a #USB stick — YellowKey #zeroday #exploit demonstrates an apparent backdoor #YellowKey is kind of crazy because now, any device that was stolen but protected by BitLocker is now super-compromised, with no recourse

    #computersecurity #security #cybersec

  37. #Microsoft #BitLocker-protected drives can now be opened with just some files on a #USB stick — YellowKey #zeroday #exploit demonstrates an apparent backdoor #YellowKey is kind of crazy because now, any device that was stolen but protected by BitLocker is now super-compromised, with no recourse

    #computersecurity #security #cybersec

  38. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn