Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    eBay Calls GameStop’s $56 Billion Acquisition Offer ‘Not Attractive’

    May 13, 2026

    Microsoft Windows Alert—Angry Hacker Drops 2 New Zero-Day Exploits

    May 13, 2026

    Father-Son Smoothie Brand Takes On Jamba and Smoothie King

    May 13, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Live Wild Feel Well
    Subscribe
    • Home
    • Green Brands
    • Wild Living
    • Green Fitness
    • Brand Spotlights
    • About Us
    Live Wild Feel Well
    Home»Brand Spotlights»Microsoft Windows Alert—Angry Hacker Drops 2 New Zero-Day Exploits
    Brand Spotlights

    Microsoft Windows Alert—Angry Hacker Drops 2 New Zero-Day Exploits

    wildgreenquest@gmail.comBy wildgreenquest@gmail.comMay 13, 2026003 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    Angry hacker drops more Windows 0-Days in ongoing campaign.

    NurPhoto via Getty Images

    The day following the Microsoft Patch Tuesday security updates rollout is known in cybersecurity circles as Exploit Wednesday. This month, there is more reason than ever to take that very seriously indeed. While Microsoft didn’t patch any “in the wild” vulnerabilities this time, an angry hacker known by the monikers Chaotic Eclipse and Nightmare Eclipse decided to synchronize the public disclosure of no less than two zero-day exploits with the official release. Here’s what you need to know, and do, about the YellowKey and GreenPlasma exploits.

    Forbes‘Significant Threat’—Billions Of Gmail Users At Risk From Google Security GaffeBy Davey Winder

    What You Need To Know About The YellowKey And GreenPlasma Microsoft Windows Zero-Day Exploits

    Hell hath no fury like a security researcher scorned. Well, that appears to be so in the case of a bug bounty hacker known as Chaotic Eclipse, who has a history when it comes to posting Windows zero-days after being unhappy over communications with the Microsoft Security Response Center. Having publicly released exploit code for a zero-day in April, that went by the name of BlueHammer and turned Microsoft Defender’s own update workflow into a credential theft mechanism, they are now at it again.

    “Microsoft has chosen to make this worse instead of resolving the situation like adults,” Chaotic Eclipse said, “they pulled every childish game possible. My patience is running out you’re making everyone else paying for it.” The security researcher on a mission went on to address Microsoft security directly, saying, “I’m not sure what type of reaction you expected from me when you threw more gas on the fire after BlueHammer,” warning that the “fire will go as long as you want, unless you extinguish it or until there nothing left to burn.”

    The latest fuel comes in the form of two new zero-day exploits called YellowKey and GreenPlasma. The first is a Windows BitLocker encryption bypass, the second a Windows CTFMON arbitrary section creation elevation of privileges vulnerability. Together, within 24 hours of the public proof of exploit code being published, they have already been used in active attack campaigns.

    ForbesCritical New Linux Zero-Day Leaked—What Admins Need To Do NowBy Davey Winder

    “Both of the released exploit POCs suggest significant, potentially systemic flaws in how modern Windows operating system features handle path trust (GreenPlasma) and recovery (YellowKey),” Gavin Knapp, cyber threat intelligence principal lead at Bridewell, said. Microsoft is not the only vendor suffering from such issues, as is evident in my exclusive report on architectural failings in security mechanisms designed to protect Google Drive and Gmail users. Historical system vulnerabilities are being found rapidly, Knapp wanted, “which is likely due to skilled researchers leveraging AI to expedite and scale vulnerability research and exploit development.”

    Organizations should treat this as an active threat, Neena Sharma, a cybersecurity specialist at Filigree, told me, advising them to “assess their exposure immediately, particularly for devices in high-risk physical access scenarios such as field devices, and shared workstations.” Because immediate patching isn’t possible at the time of writing, Sharma suggested implementing “compensating controls like restricting USB boot access.”

    Meanwhile, Chaotic Eclipse has issued the following warning to the Microsoft Security Response Center: “Your recent actions made me take the difficult decision to drag other companies into this, be prepared to answer questions.
    Next Patch Tuesday will have a big surprise for you, Microsoft. And remember, I never failed to deliver a promise.”



    Source link

    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    wildgreenquest@gmail.com
    • Website

    Related Posts

    Soaring gas prices aren’t the only reason Americans are paying more for groceries

    May 13, 2026

    Why AI Strategy Now Depends More On People Than Models

    May 13, 2026

    The environmental cost of putting data centers in space

    May 13, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Study finds asking AI for advice could be making you a worse person

    March 31, 202612 Views

    Workers are using AI to learn on the job, even though 65% worry about accuracy

    April 21, 20266 Views

    Deadly Ice Prompts a Critical Delay on Mount Everest

    April 21, 20264 Views
    Latest Reviews
    8.5

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    wildgreenquest@gmail.comJanuary 15, 2021
    8.1

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    wildgreenquest@gmail.comJanuary 15, 2021
    8.3

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    wildgreenquest@gmail.comJanuary 15, 2021
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions
    • Disclaimer
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.