#yellowkey — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #yellowkey, aggregated by home.social.
-
Nightmare Eclipse: один против Microsoft
Хабр, привет! На связи Владимир Шнейдмюллер, аналитик-исследователь угроз кибербезопасности R-Vision. Вокруг Nightmare Eclipse за последние недели успело сложиться почти всё, что обычно сопровождает громкие публичные zero-day: резкие заявления автора, споры о такой практике раскрытия, быстрые проверки PoC сообществом, первые форки и закономерный вопрос - что из этого можно увидеть в телеметрии, а что останется почти полностью за пределами SIEM? Мы разобрали несколько опубликованных PoC и в этой статье начнем с первых трёх: YellowKey, GreenPlasma и MiniPlasma. Они существенно различаются как по векторам атак, так и по возможностям обнаружения. YellowKey интересен как обход BitLocker через WinRE, но почти не оставляет удобных событий в ОС. GreenPlasma демонстрирует низкоуровневый примитив на стыке CTF/Winlogon и Windows Object Manager. MiniPlasma, наоборот, уже дает практический сценарий локального повышения привилегий, где можно строить вполне рабочие детекты по реестру, файловой системе и запуску процессов. Ниже не будет пошаговой инструкции по эксплуатации. Нас интересуют механика, артефакты и точки наблюдения, которые полезны SOC и threat hunting-командам.
https://habr.com/ru/companies/rvision/articles/1048510/
#кибербезопасность #управление_уязвимостями #zeroday #windows #bitlocker #poc #winre #MiniPlasma #YellowKey #GreenPlasma
-
Nightmare Eclipse: один против Microsoft
Хабр, привет! На связи Владимир Шнейдмюллер, аналитик-исследователь угроз кибербезопасности R-Vision. Вокруг Nightmare Eclipse за последние недели успело сложиться почти всё, что обычно сопровождает громкие публичные zero-day: резкие заявления автора, споры о такой практике раскрытия, быстрые проверки PoC сообществом, первые форки и закономерный вопрос - что из этого можно увидеть в телеметрии, а что останется почти полностью за пределами SIEM? Мы разобрали несколько опубликованных PoC и в этой статье начнем с первых трёх: YellowKey, GreenPlasma и MiniPlasma. Они существенно различаются как по векторам атак, так и по возможностям обнаружения. YellowKey интересен как обход BitLocker через WinRE, но почти не оставляет удобных событий в ОС. GreenPlasma демонстрирует низкоуровневый примитив на стыке CTF/Winlogon и Windows Object Manager. MiniPlasma, наоборот, уже дает практический сценарий локального повышения привилегий, где можно строить вполне рабочие детекты по реестру, файловой системе и запуску процессов. Ниже не будет пошаговой инструкции по эксплуатации. Нас интересуют механика, артефакты и точки наблюдения, которые полезны SOC и threat hunting-командам.
https://habr.com/ru/companies/rvision/articles/1048510/
#кибербезопасность #управление_уязвимостями #zeroday #windows #bitlocker #poc #winre #MiniPlasma #YellowKey #GreenPlasma
-
Nightmare Eclipse: один против Microsoft
Хабр, привет! На связи Владимир Шнейдмюллер, аналитик-исследователь угроз кибербезопасности R-Vision. Вокруг Nightmare Eclipse за последние недели успело сложиться почти всё, что обычно сопровождает громкие публичные zero-day: резкие заявления автора, споры о такой практике раскрытия, быстрые проверки PoC сообществом, первые форки и закономерный вопрос - что из этого можно увидеть в телеметрии, а что останется почти полностью за пределами SIEM? Мы разобрали несколько опубликованных PoC и в этой статье начнем с первых трёх: YellowKey, GreenPlasma и MiniPlasma. Они существенно различаются как по векторам атак, так и по возможностям обнаружения. YellowKey интересен как обход BitLocker через WinRE, но почти не оставляет удобных событий в ОС. GreenPlasma демонстрирует низкоуровневый примитив на стыке CTF/Winlogon и Windows Object Manager. MiniPlasma, наоборот, уже дает практический сценарий локального повышения привилегий, где можно строить вполне рабочие детекты по реестру, файловой системе и запуску процессов. Ниже не будет пошаговой инструкции по эксплуатации. Нас интересуют механика, артефакты и точки наблюдения, которые полезны SOC и threat hunting-командам.
https://habr.com/ru/companies/rvision/articles/1048510/
#кибербезопасность #управление_уязвимостями #zeroday #windows #bitlocker #poc #winre #MiniPlasma #YellowKey #GreenPlasma
-
「BitLocker」が回避されてしまう「YellowKey」脆弱性、6月のセキュリティパッチで修正済み/Microsoftがアナウンス
https://forest.watch.impress.co.jp/docs/news/2116567.html#forest_watch_impress #BitLocker #Windows_11 #WinRE #Windows_Server_2025 #YellowKey #セキュリティ #脆弱性 #Windows
-
「BitLocker」が回避されてしまう「YellowKey」脆弱性、6月のセキュリティパッチで修正済み/Microsoftがアナウンス
https://forest.watch.impress.co.jp/docs/news/2116567.html#forest_watch_impress #BitLocker #Windows_11 #WinRE #Windows_Server_2025 #YellowKey #セキュリティ #脆弱性 #Windows
-
「BitLocker」が回避されてしまう「YellowKey」脆弱性、6月のセキュリティパッチで修正済み/Microsoftがアナウンス
https://forest.watch.impress.co.jp/docs/news/2116567.html#forest_watch_impress #BitLocker #Windows_11 #WinRE #Windows_Server_2025 #YellowKey #セキュリティ #脆弱性 #Windows
-
I am reading the #ThreatIQ report on #YellowKey from Microsoft and..... it is so vague and unhelpful. This is essentially a shrug from #Microsoft saying "well, they found the backdoor, i guess we'll patch that one."
-
I am reading the #ThreatIQ report on #YellowKey from Microsoft and..... it is so vague and unhelpful. This is essentially a shrug from #Microsoft saying "well, they found the backdoor, i guess we'll patch that one."
-
I am reading the #ThreatIQ report on #YellowKey from Microsoft and..... it is so vague and unhelpful. This is essentially a shrug from #Microsoft saying "well, they found the backdoor, i guess we'll patch that one."
-
I am reading the #ThreatIQ report on #YellowKey from Microsoft and..... it is so vague and unhelpful. This is essentially a shrug from #Microsoft saying "well, they found the backdoor, i guess we'll patch that one."
-
Hey Windows (ab)users! Microsoft patched around 200 vulnerabilities in Windows etc today, a record Patch Tuesday batch. All indications are they fixed two of the zero-days dropped last month by the researcher Nightmare Eclipse, including "Green Plasma" and the "YellowKey" exploit that allowed local access to data encrypted by BitLocker. In response to today's Patch Tuesday, Nightmare Eclipse dropped an exploit for what they claimed was a zero-day bug in Windows Defender.
Nearly three dozen of the bugs patched this month earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available.
https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/
#patchtuesday #windows #nightmareeclipse #greenplasma #yellowkey
-
Hey Windows (ab)users! Microsoft patched around 200 vulnerabilities in Windows etc today, a record Patch Tuesday batch. All indications are they fixed two of the zero-days dropped last month by the researcher Nightmare Eclipse, including "Green Plasma" and the "YellowKey" exploit that allowed local access to data encrypted by BitLocker. In response to today's Patch Tuesday, Nightmare Eclipse dropped an exploit for what they claimed was a zero-day bug in Windows Defender.
Nearly three dozen of the bugs patched this month earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available.
https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/
#patchtuesday #windows #nightmareeclipse #greenplasma #yellowkey
-
Hey Windows (ab)users! Microsoft patched around 200 vulnerabilities in Windows etc today, a record Patch Tuesday batch. All indications are they fixed two of the zero-days dropped last month by the researcher Nightmare Eclipse, including "Green Plasma" and the "YellowKey" exploit that allowed local access to data encrypted by BitLocker. In response to today's Patch Tuesday, Nightmare Eclipse dropped an exploit for what they claimed was a zero-day bug in Windows Defender.
Nearly three dozen of the bugs patched this month earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available.
https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/
#patchtuesday #windows #nightmareeclipse #greenplasma #yellowkey
-
Hey Windows (ab)users! Microsoft patched around 200 vulnerabilities in Windows etc today, a record Patch Tuesday batch. All indications are they fixed two of the zero-days dropped last month by the researcher Nightmare Eclipse, including "Green Plasma" and the "YellowKey" exploit that allowed local access to data encrypted by BitLocker. In response to today's Patch Tuesday, Nightmare Eclipse dropped an exploit for what they claimed was a zero-day bug in Windows Defender.
Nearly three dozen of the bugs patched this month earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available.
https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/
#patchtuesday #windows #nightmareeclipse #greenplasma #yellowkey
-
Hey Windows (ab)users! Microsoft patched around 200 vulnerabilities in Windows etc today, a record Patch Tuesday batch. All indications are they fixed two of the zero-days dropped last month by the researcher Nightmare Eclipse, including "Green Plasma" and the "YellowKey" exploit that allowed local access to data encrypted by BitLocker. In response to today's Patch Tuesday, Nightmare Eclipse dropped an exploit for what they claimed was a zero-day bug in Windows Defender.
Nearly three dozen of the bugs patched this month earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available.
https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/
#patchtuesday #windows #nightmareeclipse #greenplasma #yellowkey
-
A Record-Breaking Patch Tuesday for June 2026
https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/
#InternetInformationServices #NightmareEclipse #VisualStudioCode #LatestWarnings #TheComingStorm #CVE-2026-45586 #CVE-2026-49160 #CVE-2026-50507 #SecurityTools #SatnamNarang #TimetoPatch #AdamBarnett #GreenPlasma #YellowKey #Tenable #Rapid7
-
A Record-Breaking Patch Tuesday for June 2026
https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/
#InternetInformationServices #NightmareEclipse #VisualStudioCode #LatestWarnings #TheComingStorm #CVE-2026-45586 #CVE-2026-49160 #CVE-2026-50507 #SecurityTools #SatnamNarang #TimetoPatch #AdamBarnett #GreenPlasma #YellowKey #Tenable #Rapid7
-
A Record-Breaking Patch Tuesday for June 2026
https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/
#InternetInformationServices #NightmareEclipse #VisualStudioCode #LatestWarnings #TheComingStorm #CVE-2026-45586 #CVE-2026-49160 #CVE-2026-50507 #SecurityTools #SatnamNarang #TimetoPatch #AdamBarnett #GreenPlasma #YellowKey #Tenable #Rapid7
-
A Record-Breaking Patch Tuesday for June 2026
https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/
#InternetInformationServices #NightmareEclipse #VisualStudioCode #LatestWarnings #TheComingStorm #CVE-2026-45586 #CVE-2026-49160 #CVE-2026-50507 #SecurityTools #SatnamNarang #TimetoPatch #AdamBarnett #GreenPlasma #YellowKey #Tenable #Rapid7
-
A Record-Breaking Patch Tuesday for June 2026
https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/
#InternetInformationServices #NightmareEclipse #VisualStudioCode #LatestWarnings #TheComingStorm #CVE-2026-45586 #CVE-2026-49160 #CVE-2026-50507 #SecurityTools #SatnamNarang #TimetoPatch #AdamBarnett #GreenPlasma #YellowKey #Tenable #Rapid7
-
If I understand this correctly every past and present theft of a windows notebook that contains PII encrypted with #bitlocker got a potential „upgrade“ regarding #gdpr.
-
If I understand this correctly every past and present theft of a windows notebook that contains PII encrypted with #bitlocker got a potential „upgrade“ regarding #gdpr.
-
If I understand this correctly every past and present theft of a windows notebook that contains PII encrypted with #bitlocker got a potential „upgrade“ regarding #gdpr.
-
If I understand this correctly every past and present theft of a windows notebook that contains PII encrypted with #bitlocker got a potential „upgrade“ regarding #gdpr.
-
If I understand this correctly every past and present theft of a windows notebook that contains PII encrypted with #bitlocker got a potential „upgrade“ regarding #gdpr.
-
https://winbuzzer.com/2026/06/01/github-ban-escalates-microsofts-yellowkey-dispute-xcxwbn/
GitHub appears to have banned the security researcher behind the YellowKey BitLocker exploit reveal, widening Microsoft's fight over public disclosures.
#GitHub #YellowKey #Microsoft #BitLocker #Windows11 #ZeroDay #Exploits #WindowsSecurity #Cybersecurity
-
https://winbuzzer.com/2026/06/01/github-ban-escalates-microsofts-yellowkey-dispute-xcxwbn/
GitHub appears to have banned the security researcher behind the YellowKey BitLocker exploit reveal, widening Microsoft's fight over public disclosures.
#GitHub #YellowKey #Microsoft #BitLocker #Windows11 #ZeroDay #Exploits #WindowsSecurity #Cybersecurity
-
https://winbuzzer.com/2026/06/01/github-ban-escalates-microsofts-yellowkey-dispute-xcxwbn/
GitHub appears to have banned the security researcher behind the YellowKey BitLocker exploit reveal, widening Microsoft's fight over public disclosures.
#GitHub #YellowKey #Microsoft #BitLocker #Windows11 #ZeroDay #Exploits #WindowsSecurity #Cybersecurity
-
https://winbuzzer.com/2026/06/01/github-ban-escalates-microsofts-yellowkey-dispute-xcxwbn/
GitHub appears to have banned the security researcher behind the YellowKey BitLocker exploit reveal, widening Microsoft's fight over public disclosures.
#GitHub #YellowKey #Microsoft #BitLocker #Windows11 #ZeroDay #Exploits #WindowsSecurity #Cybersecurity
-
https://winbuzzer.com/2026/06/01/github-ban-escalates-microsofts-yellowkey-dispute-xcxwbn/
GitHub appears to have banned the security researcher behind the YellowKey BitLocker exploit reveal, widening Microsoft's fight over public disclosures.
#GitHub #YellowKey #Microsoft #BitLocker #Windows11 #ZeroDay #Exploits #WindowsSecurity #Cybersecurity
-
@bjoern
Es scheint noch viel schlimmer zu sein: Das was über #YellowKey bekannt geworden ist sieht sehr viel mehr wie eine #Backdoor in #Bitlocker aus als eine versehentlich gevibete Schwachstelle... -
@bjoern
Es scheint noch viel schlimmer zu sein: Das was über #YellowKey bekannt geworden ist sieht sehr viel mehr wie eine #Backdoor in #Bitlocker aus als eine versehentlich gevibete Schwachstelle... -
@bjoern
Es scheint noch viel schlimmer zu sein: Das was über #YellowKey bekannt geworden ist sieht sehr viel mehr wie eine #Backdoor in #Bitlocker aus als eine versehentlich gevibete Schwachstelle... -
@bjoern
Es scheint noch viel schlimmer zu sein: Das was über #YellowKey bekannt geworden ist sieht sehr viel mehr wie eine #Backdoor in #Bitlocker aus als eine versehentlich gevibete Schwachstelle... -
@bjoern
Es scheint noch viel schlimmer zu sein: Das was über #YellowKey bekannt geworden ist sieht sehr viel mehr wie eine #Backdoor in #Bitlocker aus als eine versehentlich gevibete Schwachstelle... -
Wenn ihr euch bisher darauf verlassen habt dass eure Festplatten dank #Bitlocker verschlüsselt und eure Daten felsenfest geschützt sind... Nope. #YellowKey sieht nicht aus wie ein Bug, sondern wie eine absichtlich eingebaute #Backdoor.
-
Wenn ihr euch bisher darauf verlassen habt dass eure Festplatten dank #Bitlocker verschlüsselt und eure Daten felsenfest geschützt sind... Nope. #YellowKey sieht nicht aus wie ein Bug, sondern wie eine absichtlich eingebaute #Backdoor.
-
Wenn ihr euch bisher darauf verlassen habt dass eure Festplatten dank #Bitlocker verschlüsselt und eure Daten felsenfest geschützt sind... Nope. #YellowKey sieht nicht aus wie ein Bug, sondern wie eine absichtlich eingebaute #Backdoor.
-
Wenn ihr euch bisher darauf verlassen habt dass eure Festplatten dank #Bitlocker verschlüsselt und eure Daten felsenfest geschützt sind... Nope. #YellowKey sieht nicht aus wie ein Bug, sondern wie eine absichtlich eingebaute #Backdoor.
-
Wenn ihr euch bisher darauf verlassen habt dass eure Festplatten dank #Bitlocker verschlüsselt und eure Daten felsenfest geschützt sind... Nope. #YellowKey sieht nicht aus wie ein Bug, sondern wie eine absichtlich eingebaute #Backdoor.
-
@natesubra
I just skimmed over that #YellowKey thing. But the way I understand it... well: I don't know whether a responsible way to disclose such a blatantly backdoor-looking vulnerability even exists.
@GossiTheDog -
@natesubra
I just skimmed over that #YellowKey thing. But the way I understand it... well: I don't know whether a responsible way to disclose such a blatantly backdoor-looking vulnerability even exists.
@GossiTheDog -
@natesubra
I just skimmed over that #YellowKey thing. But the way I understand it... well: I don't know whether a responsible way to disclose such a blatantly backdoor-looking vulnerability even exists.
@GossiTheDog -
@natesubra
I just skimmed over that #YellowKey thing. But the way I understand it... well: I don't know whether a responsible way to disclose such a blatantly backdoor-looking vulnerability even exists.
@GossiTheDog -
@natesubra
I just skimmed over that #YellowKey thing. But the way I understand it... well: I don't know whether a responsible way to disclose such a blatantly backdoor-looking vulnerability even exists.
@GossiTheDog -
https://hackingpassion.com/yellowkey-bitlocker-bypass-winre/ - If you can get physical access to a machine, #YellowKey will bypass #BitLocker on a fully patched #Windows machine.
-
https://hackingpassion.com/yellowkey-bitlocker-bypass-winre/ - If you can get physical access to a machine, #YellowKey will bypass #BitLocker on a fully patched #Windows machine.
-
https://hackingpassion.com/yellowkey-bitlocker-bypass-winre/ - If you can get physical access to a machine, #YellowKey will bypass #BitLocker on a fully patched #Windows machine.
-
https://hackingpassion.com/yellowkey-bitlocker-bypass-winre/ - If you can get physical access to a machine, #YellowKey will bypass #BitLocker on a fully patched #Windows machine.
-
https://hackingpassion.com/yellowkey-bitlocker-bypass-winre/ - If you can get physical access to a machine, #YellowKey will bypass #BitLocker on a fully patched #Windows machine.
-
#Microsoft #BitLocker-protected drives can now be opened with just some files on a #USB stick — YellowKey #zeroday #exploit demonstrates an apparent backdoor #YellowKey is kind of crazy because now, any device that was stolen but protected by BitLocker is now super-compromised, with no recourse
-
#Microsoft #BitLocker-protected drives can now be opened with just some files on a #USB stick — YellowKey #zeroday #exploit demonstrates an apparent backdoor #YellowKey is kind of crazy because now, any device that was stolen but protected by BitLocker is now super-compromised, with no recourse
-
#Microsoft #BitLocker-protected drives can now be opened with just some files on a #USB stick — YellowKey #zeroday #exploit demonstrates an apparent backdoor #YellowKey is kind of crazy because now, any device that was stolen but protected by BitLocker is now super-compromised, with no recourse
-
#Microsoft #BitLocker-protected drives can now be opened with just some files on a #USB stick — YellowKey #zeroday #exploit demonstrates an apparent backdoor #YellowKey is kind of crazy because now, any device that was stolen but protected by BitLocker is now super-compromised, with no recourse
-
YellowKey: BitLocker Bypass or Backdoor
YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.
At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.
Read more: https://forum.hashpwn.net/post/13339
#BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn