Microsoft has announced mitigations for CVE-2026-45585, a BitLocker bypass triggered via FsTx in Windows Recovery.

It’s nasty, but it requires physical access to the computer: The exploit, named YellowKey, was published earlier this week by a researcher who goes by the alias Nightmare-Eclipse.…

The IT researcher behind the "NightmareEclipse" project shows new vulnerabilities: "YellowKey" in BitLocker and privilege escalation with "MiniPlasma".