A security researcher with an apparent grudge against Microsoft has in recent days disclosed two more Windows zero-days and released a proof-of-concept exploit against a third vulnerability that Microsoft supposedly patched in 2020. That makes six flaws researcher "Nightmare Eclipse" has disclosed over the past six weeks, some of which attackers are already actively exploiting, and one that the Cybersecurity and Infrastructure Security Agency (CISA) has included in its catalog of known exploited vulnerabilities (KEV). Nightmare Eclipse disclosed the three new vulnerabilities in the days following Microsoft's May 2026 security update a week ago. The vulnerabilities are tracked as YellowKey, GreenPlasma, and MiniPlasma. YellowKey, as researchers at LevelBlue described it, "can enable any attacker with physical access and a USB device to take down BitLocker's encryption and gain unfettered access to encrypted laptops in no time." All the attacker has to do is insert a weaponized USB into BitLocker encryption-enabled target machines and wait for or force a reboot into the Windows Recovery Environment (WinRE) and enter a specific key combination to trigger the exploit. An attacker needs no credentials, PIN, or TPM bypass to completely negate BitLocker encryption protection for physically accessible devices, according to LevelBlue. GreenPlasma meanwhile is a vulnerability that affects Windows 10, Windows 11, and Windows Server. It exploits a Windows component for managing text inpu...
Windows Zero-Day Barrage Continues After Patch Tuesday
Dark Reading
·Jai Vijayan
·Published May 19, 2026
·Updated
Affected Software
4 affected components
Microsoft BitLocker
Microsoft Windows=Windows 10, =Windows 11, =Windows Server
Microsoft Cloud Files Mini Filter Driver
Microsoft Microsoft Defender
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the recent disclosure of multiple Windows zero-day vulnerabilities following Microsoft's Patch Tuesday updates.
2
What security implications are discussed?
The article highlights the risks associated with unpatched zero-day vulnerabilities that could be exploited by attackers.
3
What products or software are affected?
The affected products include Microsoft Windows 10, Windows 11, Windows Server, BitLocker, Microsoft Defender, and Cloud Files Mini Filter Driver.
4
Who is responsible for disclosing these vulnerabilities?
A security researcher with a perceived grudge against Microsoft has released the vulnerabilities and proof-of-concept exploits.
5
What is the significance of the vulnerabilities disclosed?
The vulnerabilities have potentially serious implications for user data security and system integrity, highlighting ongoing concerns about software exploitation.