DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:12:51ZSOURCES: 14CRITICAL: 31
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Sampled credentials from the FortiBleed dataset and confirmed they are authentic. Many of… /// @MsftSecIntel CRITICAL — Tracking FortiBleed downstream activity. Buyers of the FortiGate credential sets are… /// @TalosSecurity CRITICAL — FortiBleed is just one piece of a broader IAB operation. The same Russian-speaking actor… /// @MalwareHunterTeam CRITICAL — The Gentlemen RaaS internal data leak (May 2026, ~16GB) confirmed operators actively… /// @CrowdStrike CRITICAL — Gentlemen RaaS affiliates are deploying GentleKiller variants that specifically target…
31Critical Threats
18Active CVEs
19IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-45585PUBLISHED: 2026-05-19
MEDIUMCVE-2026-45585★ CISA KEV LISTED

Windows BitLocker WinRE Bypass 'YellowKey' — PoC Public, KEV

VENDOR: Microsoft//PRODUCT: Windows BitLocker / Windows Recovery Environment (WinRE)
6.8
MEDIUM
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PoC AVAILABLE

A security feature bypass in Windows Recovery Environment (WinRE) allows an attacker with physical access to unlock BitLocker-protected drives on TPM-only configurations without credentials by placing specially crafted FsTx files on a USB drive or EFI partition and triggering a command shell via the CTRL key during WinRE boot. Researcher Chaotic Eclipse (Nightmare-Eclipse) published a public PoC on May 13, 2026 and described the flaw as functioning 'like a backdoor'; Trend Micro detected active in-the-wild use shortly after PoC release. CISA added it to KEV on May 20. The June 9 Patch Tuesday update includes the permanent fix; pre-patch mitigation requires switching from TPM-only to TPM+PIN.

Attack Vector
PHYSICAL
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:N
AFFECTED VERSIONSWindows 11 (23H2, 24H2, 25H2) and Windows Server 2022/2025 with TPM-only BitLocker protection; patched in June 2026 Patch Tuesday cumulative update
  • CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • BleepingComputer: https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/
  • Tenable June 2026 Patch Tuesday: https://www.tenable.com/blog/microsofts-june-2026-patch-tuesday-addresses-198-cves-cve-2026-49160-cve-2026-50507
  • The Hacker News: https://thehackernews.com/2026/05/windows-zero-days-expose-bitlocker.html
SHARE BRIEF:✕ Post on Xin Share on LinkedIn