Angry Hacker Drops Exploits on Windows (bitlocker backdoor?)
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Security researcher Nightmare Eclipse publicly dropped multiple zero-day exploits for Microsoft products after disputes with Microsoft's Security Response Center bug bounty program, leading to bans from both GitHub and GitLab. The main focus is 'Yellow Key', an exploit targeting the Windows 11 recovery environment that bypasses BitLocker encryption. It works by placing malicious NTFS transactional file system (FSTX) data on a USB stick, which causes the recovery environment to replay transactions that delete a key INI file, dropping the user into a command shell with access to the decrypted BitLocker partition. The vulnerability exists because Windows 11's recovery environment auto-runs FSTX transactions (unlike Windows 10). Mitigations include removing the BootExecute registry key for FSTX or enabling TPM PIN mode, though the researcher claims a separate vulnerability may bypass even TPM+PIN configurations.
•12m watch time
21 Impressions1 Comment