| |
A security researcher known as "Nightmare-Eclipse" disclosed YellowKey, a vulnerability that allows complete bypass of BitLocker encryption by copying specific files to a USB drive or Windows partition and following a specific boot sequence, with the researcher alleging Microsoft intentionally embedded this backdoor. Microsoft subsequently released an out-of-band patch (CVE-2026-45585) acknowledging the flaw affects Windows 11, Server 2022, and 2025 but stopping short of confirming intentional backdoor claims. The vulnerability requires physical access to the device but grants unrestricted access to encrypted data without requiring passwords.
Read Full Article →
← More Tech news