YellowKey and GreenPlasma: Two New Windows Zero-Days Unveiled
ID: e458d726-0869-5e76-9b80-f68dca5cba97
STIX ID: report--e458d726-0869-5e76-9b80-f68dca5cba97
Feed Name: LevelBlue SpiderLabs Blog
Nightmare-Eclipse publicly released a suite of Windows exploits including YellowKey (a BitLocker bypass via WinRE and USB) and GreenPlasma (a CTFMON-based local privilege escalation), alongside prior tools (BlueHammer, RedSun, UnDefend) that together enable physical disk access, SYSTEM escalation, and Defender suppression; these tools are reported being exploited in the wild, posing critical risk to enterprises and regulated organizations and prompting urgent patching, USB/boot hardening, ASR deployment, and IOC-based hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
