The images in this article were generated with artificial intelligence. How we publish
Microsoft corrected three critical vulnerabilities on Windows on Tuesday that, combined with the context of public leaks, have turned on alarms between administrators and incident response teams. Two of these failures, baptized in the community as GreenPlasma and MiniPlasma, are steps of local privilege that allow an attacker to obtain a console with SYSTEM permissions in fully parched equipment; the third, known as YellowKey, opens the door to BitLocker protected disk data recovery from the recovery environment (WinRE) if the system is not updated.
From a technical point of view, GreenPlasma affects the collaborative translation service (CTFMON) and MiniPlasma to the Cloud Files Mini Filter controller, both offering vectors to run code with the highest privileges without the need for high credentials. YellowKey, for its part, exploits the logic of the recovery environment to introduce a "bridge" that allows access to encrypted volumes when a combination of conditions is met (including physical access). Microsoft describes the details and updates needed in its official notices, which should be read before you deploy large-scale changes: CVE-2026-45586 and CVE-2026-45585.

The real impact is not only technical: the disclosure of these failures occurred after the publication by a researcher known as "Nightmare Eclipse," who has been leaking evidence of concept and exploits for several vulnerabilities as a form of protest for the management of disclosure by the Microsoft Response Center. Public tension led Microsoft to issue warnings about responsible disclosure before nuanced its response. The company's official position on coordinated disclosure is available here: a-share-responsibility-protecting-customers-throughout-coordinated -vulnerability-disclosure.
For managers and users, the first and most urgent recommendation is apply the June 2026 patches immediately following internal test processes. In business environments this involves prioritizing servers and machines with access to sensitive data and domain accounts. In addition, to mitigate YellowKey risks while patches are being deployed, Microsoft and experts recommend reviewing the recovery environment configuration and BitLocker protection policies: activate protection devices that require PIN or multifactor authentication in boot and store the recovery keys in a safe and managed place, for example by Active Directory or Azure AD. The official BitLocker documentation provides practical guidelines on protection and recovery: BitLocker - Microsoft Docs.

Not everything can be solved with patches: protection against attacks with physical access requires physical and procedural controls. Ensure the custody of mobile devices and workstations in offices and logistics centres, limit access to the BIOS / UEFI with administrative passwords, enable Secure Boot where possible and audit changes in WinRE configuration. For large organizations, deploy the update through centralized tools such as WSUS, Intune or patch management solutions to control the rollout and reduce exposure windows.
In detection and response, look for commitment indicators associated with local privilege steps and recovery environment manipulation: unusual process creation events with privileges, CTF subsystem modifications, mini-filter installation or modification, and Microsoft Defender handling signals or update policies. It is also prudent to review related vulnerabilities that the researcher has been publishing publicly in recent months, which increases the likelihood of exploitation directed against slow-patching organizations.
Finally, this wave of failures and leaks highlights a strategic lesson: security is not only technical but coordinated. Companies should combine fast patches, hardening critical configurations, policies for the physical protection of assets and agreements with legal and public relations teams that provide for public outreach scenarios. The security community and suppliers also need to improve the channels of interaction to prevent frustration from resulting in disclosures that increase the risk to users.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...