An anonymous researcher using the aliases Nightmare-Eclipse and Chaotic Eclipse publicly released details for two alleged Microsoft zero-days, YellowKey and GreenPlasma, adding to a string of earlier disclosures that included BlueHammer, RedSun, and UnDefend. YellowKey is described as a BitLocker bypass that requires physical access and a USB device, allowing an attacker to reboot into the Windows Recovery Environment (WinRE) and gain access to an encrypted drive; reporting said the technique was independently reproduced. Public materials claim the issue affects Windows 11 and Windows Server 2022/2025, while Windows 10 is not affected.
GreenPlasma was disclosed as a local privilege escalation flaw that allegedly abuses CTFMon and Windows Object Manager section handling to obtain SYSTEM privileges, although reports said the released code still triggers a UAC prompt under default settings. Security experts warned that YellowKey could sharply raise the impact of laptop theft because BitLocker is often the final safeguard for stolen Windows devices; suggested mitigations include enabling a BitLocker PIN and locking firmware settings with a BIOS password, while no practical workaround for GreenPlasma was identified beyond a future vendor patch. Microsoft had not publicly responded to the two disclosures at the time of reporting, and prior proof-of-concept releases from the same researcher were reportedly later used in real-world attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Tom’s Hardware reported that Microsoft allegedly deleted Nightmare-Eclipse/Chaotic Eclipse’s Microsoft account used for vulnerability reporting and banned their GitHub account amid an escalating dispute over zero-day disclosures and bug bounty handling. The researcher reportedly moved to GitLab and threatened further disclosures, while Microsoft had not publicly explained the dispute.
Microsoft said it is developing a fix for the YellowKey BitLocker bypass and assigned the flaw CVE-2026-45585. Until a patch is available, the company recommended removing the vulnerable autofstx.exe value from the WinRE image hive and reestablishing BitLocker trust for WinRE, or enabling a BitLocker PIN.
Dark Reading reported that the previously disclosed BlueHammer Windows flaw had been assigned CVE-2026-33825 and added to CISA’s Known Exploited Vulnerabilities catalog. This marked an official escalation in tracking of the issue beyond earlier reports that it had already been patched.
A GitHub repository published by Nightmare-Eclipse claimed that the Windows Cloud Files Mini Filter Driver flaw tracked as CVE-2020-17103 remained exploitable despite an earlier patch. The author said they weaponized the original Project Zero proof of concept into a SYSTEM shell exploit and believed the race-condition issue affected all Windows versions.
After earlier reports said Microsoft had not responded, the company said it is committed to investigating and addressing the publicly disclosed YellowKey and GreenPlasma Windows vulnerabilities. The statement followed publication of proof-of-concept exploit details by the researcher behind the disclosures.
Coverage of the new disclosures noted that earlier zero-days from the same researcher had already prompted fixes: BlueHammer had been patched and RedSun was reportedly silently patched by Microsoft. These prior remediations were cited as part of a broader series of Microsoft zero-day leaks in 2026.
Media reports on the new disclosures said YellowKey had been independently tested successfully and warned it could increase the impact of laptop theft because BitLocker is often the last line of defense. At the time of reporting, Microsoft had not publicly responded to either YellowKey or GreenPlasma.
Shortly after Patch Tuesday, the same researcher publicly disclosed a second alleged Microsoft zero-day called GreenPlasma. It was described as a local privilege-escalation flaw abusing CTFMon and Windows Object Manager section handling to obtain SYSTEM-level access, though reports noted the released code still triggered a UAC prompt in default configurations.
An anonymous researcher using the aliases Nightmare-Eclipse and Chaotic Eclipse published details and code for an alleged Windows zero-day dubbed YellowKey. The disclosure claimed a BitLocker bypass in Windows Recovery Environment affecting Windows 11 and Windows Server 2022/2025, while stating Windows 10 was not affected.
PCWorld reported that Chaotic Eclipse publicly disclosed a Microsoft Defender privilege-escalation vulnerability dubbed RedSun affecting Windows 10, Windows 11, and Windows Server systems using Defender. The researcher published a proof of concept showing Defender could restore a detected file with a cloud tag to its original path, potentially overwriting system files and granting administrative privileges; no patch or in-the-wild exploitation was reported at the time.
BleepingComputer reported that a disgruntled researcher publicly leaked exploit details for a Windows zero-day dubbed BlueHammer. This appears to be the earliest disclosure event for BlueHammer, preceding later reports that Microsoft patched the flaw and that it was assigned CVE-2026-33825.
Huntress reported that attackers had been exploiting earlier Microsoft Defender vulnerabilities disclosed by Chaotic Eclipse since April 2026. The firm assessed that threat actors were likely using the public proof-of-concept code the researcher had released online.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
33 references tracked. Mallory keeps watching after this page renders.
doublepulsar.com
Open sourcetomshardware.com
Open sourcetechrepublic.com
Open sourcelevelblue.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcepcworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.