• News/
  • darkreading-20260519210654

Windows Zero-Day Barrage Continues After Patch Tuesday

Dark Reading
·
Jai Vijayan
·
Published May 19, 2026
·
Updated

A security researcher with an apparent grudge against Microsoft has in recent days disclosed two more Windows zero-days and released a proof-of-concept exploit against a third vulnerability that Microsoft supposedly patched in 2020. That makes six flaws researcher "Nightmare Eclipse" has disclosed over the past six weeks, some of which attackers are already actively exploiting, and one that the Cybersecurity and Infrastructure Security Agency (CISA) has included in its catalog of known exploited vulnerabilities (KEV). Nightmare Eclipse disclosed the three new vulnerabilities in the days following Microsoft's May 2026 security update a week ago. The vulnerabilities are tracked as YellowKey, GreenPlasma, and MiniPlasma. YellowKey, as researchers at LevelBlue described it, "can enable any attacker with physical access and a USB device to take down BitLocker's encryption and gain unfettered access to encrypted laptops in no time." All the attacker has to do is insert a weaponized USB into BitLocker encryption-enabled target machines and wait for or force a reboot into the Windows Recovery Environment (WinRE) and enter a specific key combination to trigger the exploit. An attacker needs no credentials, PIN, or TPM bypass to completely negate BitLocker encryption protection for physically accessible devices, according to LevelBlue. GreenPlasma meanwhile is a vulnerability that affects Windows 10, Windows 11, and Windows Server. It exploits a Windows component for managing text inpu...

Read full article

Affected Software

4 affected components
Microsoft BitLocker
Microsoft Windows=Windows 10, =Windows 11, =Windows Server
Microsoft Cloud Files Mini Filter Driver
Microsoft Microsoft Defender
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the recent disclosure of multiple Windows zero-day vulnerabilities following Microsoft's Patch Tuesday updates.

2

What security implications are discussed?

The article highlights the risks associated with unpatched zero-day vulnerabilities that could be exploited by attackers.

3

What products or software are affected?

The affected products include Microsoft Windows 10, Windows 11, Windows Server, BitLocker, Microsoft Defender, and Cloud Files Mini Filter Driver.

4

Who is responsible for disclosing these vulnerabilities?

A security researcher with a perceived grudge against Microsoft has released the vulnerabilities and proof-of-concept exploits.

5

What is the significance of the vulnerabilities disclosed?

The vulnerabilities have potentially serious implications for user data security and system integrity, highlighting ongoing concerns about software exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203