Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

How To Mitigate The Microsoft Windows BitLocker YellowKey USB 0-Day

Microsoft said the flaw can let attackers reach BitLocker-protected drives and urged admins to apply workarounds before a security update arrives.

  • On Tuesday, Microsoft issued guidance for the 'YellowKey' Windows BitLocker vulnerability , which allows unauthorized access to protected drives using a malicious USB key.
  • Last week, an anonymous researcher known as 'Nightmare Eclipse' disclosed the flaw, publishing a proof-of-concept exploit that describes the issue as a "backdoor".
  • To mitigate YellowKey attacks, Microsoft advised removing the FsTx Auto Recovery Utility entry and configuring 'TPM+PIN' mode. "Specifically, you prevent the FsTx Auto Recovery Utility, autofstx.exe, from automatically starting," Will Dormann, principal vulnerability analyst at Tharros, explained.
  • Organizations should treat this as an active threat, Neena Sharma, a cybersecurity specialist at Filigran, advised, recommending "compensating controls like restricting USB boot access".
  • Alongside YellowKey, Microsoft is tracking other recent zero-day flaws, including BlueHammer and RedSun, both now being exploited in attacks. Users may wait for the security update or apply PIN protections if their risk profile demands immediate action.
Insights by Ground AI
Podcasts & Opinions

13 Articles

New zero-day gap in Windows: The BitLocker vulnerability "YellowKey" allows access to actually protected drives - we already reported. Microsoft now delivers first countermeasures, but a patch is still missing. (Read more)

A new security failure in the BitLocker, Microsoft disk encryption system, has put users and IT administrators on alert this week. Identified as CVE-2026-45585, vulnerability has received the code name YellowKey and is already treated as a serious threat to protected Windows computers only with TPM-based authentication. The problem has gained enormous repercussion after public disclosure of technical details and concept evidence associated with …

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news on Wednesday, May 20, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal