Anonymous researcher releases two new Windows zero-day exploits after Patch Tuesday
By
e12e
Master baker tier. Every paragraph earns its place on the tray.
Summary
An anonymous security researcher (Nightmare-Eclipse/Chaotic Eclipse) has released two new Windows zero-day exploits — YellowKey (a BitLocker bypass) and GreenPlasma (a privilege escalation flaw granting SYSTEM access) — just after Microsoft's Patch Tuesday. This follows three other maliciously exposed zero-days earlier this year. Security experts warn these vulnerabilities pose serious risks, particularly YellowKey, which could make stolen laptops significantly more dangerous by bypassing BitLocker encryption.
Key quotes
· 3 pulledExperts speaking to The Register warned that both vulnerabilities present serious security risks
Security pros warn YellowKey claim could make stolen laptops a much bigger problem
Nightmare-Eclipse, or Chaotic Eclipse, depending on which of their aliases you prefer, released details about YellowKey and GreenPlasma
You might also wanna read
Microsoft zero-day feud escalates as researcher threatens major exploit release on July 14
The ongoing feud between Microsoft and security researcher Nightmare Eclipse (aka Chaotic Eclipse) has escalated, with the researcher having
Microsoft zero-day feud escalates as researcher threatens major exploit release on July 14
The ongoing feud between Microsoft and security researcher Nightmare Eclipse (aka Chaotic Eclipse) has escalated, with the researcher having
Nightmare-Eclipse: Rogue researcher releases six Windows zero-day exploits since April 2026
Nightmare-Eclipse is a rogue security researcher who has released six Microsoft Windows zero-day exploits (BlueHammer, RedSun, UnDefend, Yel
Microsoft condemns uncoordinated Windows zero-day releases, researcher threatens further disclosures
Microsoft has responded to a campaign of uncoordinated Windows zero-day vulnerability releases by a pseudonymous researcher known as Nightma
Microsoft criticizes uncoordinated disclosure of six zero-day vulnerabilities
Microsoft has criticized the irresponsible disclosure of six zero-day vulnerabilities in its products, named BlueHammer, GreenPlasma, MiniPl
Microsoft threatens security researcher with criminal prosecution over public disclosure of Windows vulnerabilities, sparking community backlash
Microsoft published a blog post criticizing security researcher "Nightmare Eclipse" for publicly disclosing unpatched vulnerabilities (BlueH
