This worrying Microsoft BitLocker backdoor can grant full access to a locked drive — and all you need is a USB…

https://cdn.mos.cms.futurecdn.net/vLoSnmu8jSgXsvCsvQ36XM-2560-80.jpg
  • Chaotic Eclipse leaks two new Windows flaws: YellowKey (BitLocker bypass) and GreenPlasma (privilege escalation)
  • YellowKey abuses WinRE to bypass BitLocker; verified by Kevin Beaumont, though mitigations are debated
  • GreenPlasma exploits CTFMON services for SYSTEM access; follows earlier leaks RedSun, UnDefend, and BlueHammer (later patched as CVE‑2026‑33825)

Chaotic Eclipse, the security researcher who recently leaked three unpatched Windows vulnerabilities because they weren’t happy with how Microsoft handles bug reports, has now leaked two more flaws, together with proof-of-concepts (PoC) showing how they could be exploited.

In their latest release, Chaotic Eclipse disclosed flaws named YellowKey and GreenPlasma. The former is a BitLocker bypass, while the latter is a privilege escalation vulnerability.

YellowKey targets the Windows Recovery Environment (WinRE) and the BitLocker encryption system. The flaw reportedly lets someone with physical access to a Windows 11device bypass BitLocker protections and access encrypted files without the user’s password, with Chaotic Eclipse stressing...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more

https://www.eu-startups.com/wp-content/uploads/2026/05/Untitled-design-2026-05-19T165310.544.jpg

Berlin-based bunch, an AI-native platform for managers and institutional investors to manage the entire fund lifecycle, raised a €30.1M Series B led by Portage

Sponsor Posts Niantic Spatial: World models need real-world data — Scaniverse is the gateway to spatial services — self-serve and built for AI and robotics. Large-area 3D reconstruction from 360° cameras and precise localization, anywhere machines operate. Protecting your Cloud Applications Data — Backing up Office 365, Google Workspace, Dropbox & Salesforce data