The images in this article were generated with artificial intelligence. How we publish
Microsoft corrected three critical vulnerabilities on Windows on Tuesday that, combined with the context of public leaks, have turned on alarms between administrators and incident response teams. Two of these failures, baptized in the community as GreenPlasma and MiniPlasma, are steps of local privilege that allow an attacker to obtain a console with SYSTEM permissions in fully parched equipment; the third, known as YellowKey, opens the door to BitLocker protected disk data recovery from the recovery environment (WinRE) if the system is not updated.
From a technical point of view, GreenPlasma affects the collaborative translation service (CTFMON) and MiniPlasma to the Cloud Files Mini Filter controller, both offering vectors to run code with the highest privileges without the need for high credentials. YellowKey, for its part, exploits the logic of the recovery environment to introduce a "bridge" that allows access to encrypted volumes when a combination of conditions is met (including physical access). Microsoft describes the details and updates needed in its official notices, which should be read before you deploy large-scale changes: CVE-2026-45586 and CVE-2026-45585.

The real impact is not only technical: the disclosure of these failures occurred after the publication by a researcher known as "Nightmare Eclipse," who has been leaking evidence of concept and exploits for several vulnerabilities as a form of protest for the management of disclosure by the Microsoft Response Center. Public tension led Microsoft to issue warnings about responsible disclosure before nuanced its response. The company's official position on coordinated disclosure is available here: a-share-responsibility-protecting-customers-throughout-coordinated -vulnerability-disclosure.
For managers and users, the first and most urgent recommendation is apply the June 2026 patches immediately following internal test processes. In business environments this involves prioritizing servers and machines with access to sensitive data and domain accounts. In addition, to mitigate YellowKey risks while patches are being deployed, Microsoft and experts recommend reviewing the recovery environment configuration and BitLocker protection policies: activate protection devices that require PIN or multifactor authentication in boot and store the recovery keys in a safe and managed place, for example by Active Directory or Azure AD. The official BitLocker documentation provides practical guidelines on protection and recovery: BitLocker - Microsoft Docs.

Not everything can be solved with patches: protection against attacks with physical access requires physical and procedural controls. Ensure the custody of mobile devices and workstations in offices and logistics centres, limit access to the BIOS / UEFI with administrative passwords, enable Secure Boot where possible and audit changes in WinRE configuration. For large organizations, deploy the update through centralized tools such as WSUS, Intune or patch management solutions to control the rollout and reduce exposure windows.
In detection and response, look for commitment indicators associated with local privilege steps and recovery environment manipulation: unusual process creation events with privileges, CTF subsystem modifications, mini-filter installation or modification, and Microsoft Defender handling signals or update policies. It is also prudent to review related vulnerabilities that the researcher has been publishing publicly in recent months, which increases the likelihood of exploitation directed against slow-patching organizations.
Finally, this wave of failures and leaks highlights a strategic lesson: security is not only technical but coordinated. Companies should combine fast patches, hardening critical configurations, policies for the physical protection of assets and agreements with legal and public relations teams that provide for public outreach scenarios. The security community and suppliers also need to improve the channels of interaction to prevent frustration from resulting in disclosures that increase the risk to users.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...