DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:32:56ZSOURCES: 14CRITICAL: 30
⚠ ACTIVE ALERTS
@MandiantThreats CRITICAL — UNC6240 (ShinyHunters) PeopleSoft campaign update: CVE-2026-35273 zero-day exploitation… /// @GossiTheDog CRITICAL — RoguePlanet (CVE-2026-50656) is still unpatched as of today June 29. Microsoft confirmed… /// @vxunderground CRITICAL — Nightmare-Eclipse (aka Chaotic Eclipse, MSNightmare) has now dropped 7 Windows zero-days… /// @MsftSecIntel CRITICAL — We have formally acknowledged CVE-2026-50656 (RoguePlanet) — an EoP in Microsoft Malware… /// @AlvieriD CRITICAL — ShinyHunters DLS still active with new victim adds today. NAIC breach (3.1TB) confirmed…
30Critical Threats
17Active CVEs
18IOCs Tracked
13New Advisories
TLP:WHITE
Disclosure not limited. This advisory may be distributed publicly through any channel.
OFFICIAL ADVISORY // June 2026 Patch Tuesday / MSRC Update Guide 2026-Jun // PUBLISHED 2026-06-28

Microsoft Windows BitLocker Security Feature Bypass Trio — 'YellowKey' & 'Bitskrieg' (CVE-2026-45585, CVE-2026-50507, CVE-2026-45658)

The June 9, 2026 Patch Tuesday addressed three BitLocker security feature bypass vulnerabilities: CVE-2026-45585 ('YellowKey'), CVE-2026-50507 ('Bitskrieg'), and CVE-2026-45658, all enabling attackers to bypass BitLocker encryption and gain access to protected data — critical risk for stolen or unattended devices and physical-access attack scenarios. The same cycle patched 8 Secure Boot bypass vulnerabilities and multiple UEFI-level bypasses, representing a significant boot-chain security cluster. These were among the 39 Critical-rated vulnerabilities in the record-breaking 206-vulnerability Patch Tuesday.

AFFECTED SYSTEM
SEVERITY
EXPLOIT
PATCH
Windows 10 (multiple editions)
MEDIUM
POC
PATCHED
Windows 11 (multiple editions)
MEDIUM
POC
PATCHED
Windows Server 2019, 2022, 2025
MEDIUM
POC
PATCHED

Apply all June 2026 Windows cumulative updates immediately via Windows Update, WSUS, SCCM, or Intune. Enable TPM+PIN authentication (instead of TPM-only) to mitigate YellowKey (CVE-2026-45585) and Bitskrieg (CVE-2026-50507) — PIN authentication adds a knowledge factor that these bypasses cannot trivially defeat. Audit BitLocker deployment configurations across the estate and confirm PIN policies are enforced via Group Policy.

Monitor for unexpected pre-boot environment modifications or Secure Boot policy changes. Alert on BitLocker recovery key requests that do not correlate with known device management actions. Audit TPM event logs for anomalous boot sequence attestation failures. Correlate physical asset access records with BitLocker recovery events.

  • https://msrc.microsoft.com/update-guide/releaseNote/2026-Jun
  • https://arcticwolf.com/resources/blog/microsoft-patch-tuesday-security-recap-june-2026-edition/
  • https://nvd.nist.gov/vuln/detail/CVE-2026-45585
SHARE BRIEF:✕ Post on Xin Share on LinkedIn