logo

YellowKey and GreenPlasma: Two New Windows Zero-Days Unveiled

ID: e458d726-0869-5e76-9b80-f68dca5cba97

STIX ID: report--e458d726-0869-5e76-9b80-f68dca5cba97

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
88/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: James Ballantyne

...
...

Nightmare-Eclipse publicly released a suite of Windows exploits including YellowKey (a BitLocker bypass via WinRE and USB) and GreenPlasma (a CTFMON-based local privilege escalation), alongside prior tools (BlueHammer, RedSun, UnDefend) that together enable physical disk access, SYSTEM escalation, and Defender suppression; these tools are reported being exploited in the wild, posing critical risk to enterprises and regulated organizations and prompting urgent patching, USB/boot hardening, ASR deployment, and IOC-based hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.