ctipilot.ch

Nightmare Eclipse Windows zero-day drops: YellowKey (BitLocker) and GreenPlasma (CTFMON LPE), public PoC

incident · nightmare-eclipse-windows-zerodaydrops-2026-05

Coverage timeline
1
first 2026-05-15 → last 2026-05-15
Briefs
1
1 distinct
Sources cited
3
3 hosts
Sections touched
1
active_threats
Co-occurring entities
0
no co-occurrence

Story timeline

  1. 2026-05-15CTI Daily Brief — 2026-05-15
    active_threatsFirst coverage. YellowKey: TPM-only BitLocker bypass via WinRE NTFS TxF replay. GreenPlasma: CTFMON LPE (partial PoC, UAC prompt). No CVE assigned, no MS patch.

Where this entity is cited

  • active_threats1

Source distribution

  • bleepingcomputer.com1 (33%)
  • security-hub.ncsc.admin.ch1 (33%)
  • theregister.com1 (33%)

Items in briefs about Nightmare Eclipse Windows zero-day drops: YellowKey (BitLocker) and GreenPlasma (CTFMON LPE), public PoC

No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.