#chaoticEclipse
Your BitLocker-protected Windows drive might not be as secure as you think. A new zero-day exploit, YellowKey, allows physical attackers to bypass TPM encryption using a simple USB stick and WinRE. Find out how this critical…

https://www.tpp.blog/5b9srn5

#cybersecurity #chaoticeclipse #microsoft
May 14, 2026 at 2:14 AM
Nightmare Eclipse has released HardBreacher, a PoC exploit for a privilege escalation flaw in Kaspersky Endpoint Security. Kaspersky says the issue was already fixed via database updates. #HardBreacher #Kaspersky #ZeroDay
Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit
Nightmare Eclipse, also known as Chaotic Eclipse, has released a proof-of-concept exploit called HardBreacher that targets a privilege escalation flaw in Kaspersky Endpoint Security. Kaspersky says the underlying issue has already been fixed through an automatic or manual database update. #NightmareEclipse #ChaoticEclipse #HardBreacher #KasperskyEndpointSecurity...
www.hendryadrian.com
August 31, 2026 at 3:15 PM
June 30, 2026 at 7:15 AM
📰 Celah Keamanan Zero-Day "MiniPlasma" pada Windows Berikan Akses SYSTEM, Kode PoC Dirilis Publik

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/05/18/celah-zero-day-miniplasma-windows-beri-akses-system/

#ber
it#beritaTeknologit#chaoticEclipsel#cldfltcyber#cyberSecurityo#exploitPoca href="/hashtag/loc" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#loc
May 18, 2026 at 3:35 AM
📰 Zero-Day Windows yang Baru Bocor Kini Mulai Dieksploitasi dalam Serangan Aktif

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/04/17/zero-day-windows-bocor-kini-dieksploitasi-dalam-serangan-aktif/

#ber
it#beritaTeknologih#bluehammert#chaoticEclipsel#eksploitasia#keamananSibero#microsof
April 17, 2026 at 6:42 AM
📰 PoC Eksploitasi Zero-Day Microsoft Defender "RedSun" Berikan Hak Akses SYSTEM

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/04/17/poc-eksploitasi-zero-day-microsoft-defender-redsun-berikan-hak-akses-system/

#ant
iv#antivirust#beritaTeknologit#chaoticEclipse2#cve33825 #ekspl#eksploita
April 17, 2026 at 5:46 AM
winbuzzer.com/2026/05/18/n...

MiniPlasma is a newly released proof-of-concept exploit that reportedly turns a standard Windows user into SYSTEM on fully patched Windows 11 systems.

#Cybersecurity #MiniPlasma #Microsoft #Windows11 #CVE202017103 #ChaoticEclipse #MicrosoftWindows #Windows11
Old Windows Flaw Returns to Spotlight With MiniPlasma Exploit
MiniPlasma raises fresh doubts about Microsoft's Windows 11 fix for CVE-2020-17103 after a new proof of concept claimed patched systems can reach SYSTEM.
winbuzzer.com
May 18, 2026 at 1:23 PM
RoguePlanet is a Windows LPE PoC from Chaotic Eclipse that races Defender remediation to plant system32wermgr.exe and run as SYSTEM via WER. Detections include %TEMP% staging, named pipes, and wermgr.exe to conhost.exe chains. #RoguePlanet
One More Race to SYSTEM: RoguePlanet Extends the BlueHammer–RedSun–Plasma Lineage
Chaotic Eclipse (also known as Nightmare Eclipse) released RoguePlanet, a Windows local privilege escalation proof of concept that abuses a TOCTOU race in Windows Defender remediation to plant code as System32wermgr.exe and execute it as SYSTEM through Windows Error Reporting. The article also outlines related detections in Sysmon and Guardsix SIEM, including staging in , named pipe activity on RoguePlanet, and suspicious wermgr.exe-to-conhost.exe process chains. #RoguePlanet #ChaoticEclipse #NightmareEclipse #WindowsDefender #wermgr.exe #WindowsErrorReporting
www.hendryadrian.com
June 12, 2026 at 4:03 AM
Chaotic Eclipse disclosed PoCs for three Windows zero-days, YellowKey, GreenPlasma, and MiniPlasma. YellowKey bypasses BitLocker via WinRE; the others escalate to SYSTEM through Cloud Files trust flaws. #YellowKey #GreenPlasma #MiniPlasma
Inside the Latest Chaotic-Eclipse Releases: Mini-Plasma, GreenPlasma, and YellowKey
In May 2026, Chaotic Eclipse disclosed three Windows zero-days—YellowKey, GreenPlasma, and MiniPlasma—with PoCs published days after Microsoft’s Patch Tuesday to delay a fix window. YellowKey bypasses BitLocker through WinRE, while GreenPlasma and MiniPlasma achieve SYSTEM privileges by abusing Windows Cloud Files and related trust relationships. #YellowKey #GreenPlasma #MiniPlasma #ChaoticEclipse
www.hendryadrian.com
June 5, 2026 at 10:00 PM
MiniPlasma zero-day exploit targets Windows cldflt.sys, reportedly gaining SYSTEM access on fully patched Windows 11. Chaotic Eclipse also released a PoC and source code. #MiniPlasma #cldflt #Windows11
New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
A researcher known as Chaotic Eclipse has released the MiniPlasma proof-of-concept exploit, claiming it can still gain SYSTEM privileges on fully patched Windows 11 systems through the cldflt.sys Cloud Filter driver. The disclosure adds to a series of recent Windows zero-days from the same researcher, including BlueHammer, RedSun, YellowKey, and GreenPlasma. #MiniPlasma #ChaoticEclipse #cldfltsys #GoogleProjectZero #Microsoft
www.hendryadrian.com
May 18, 2026 at 12:45 AM
PoC exploits released for two unpatched Windows flaws: YellowKey bypasses BitLocker on Windows 11/Server 2022-2025, and GreenPlasma enables privilege escalation. #YellowKey #BitLocker #Windows11
Windows BitLocker zero-day gives access to protected drives, PoC released
A researcher known as Chaotic Eclipse or Nightmare Eclipse has released proof-of-concept exploits for two unpatched Windows flaws, YellowKey and GreenPlasma, affecting BitLocker and privilege escalation. The leaks follow earlier disclosures of BlueHammer and RedSun, and the researcher says more Windows exploit releases may come before the next Patch Tuesday. #YellowKey #GreenPlasma #BlueHammer #RedSun #ChaoticEclipse #NightmareEclipse
www.hendryadrian.com
May 13, 2026 at 10:15 PM
A leaked Windows zero-day called BlueHammer allows local privilege escalation to SYSTEM level. Exploit published by a researcher known as Chaotic Eclipse after dispute with Microsoft. Full system compromise possible. #BlueHammer #WindowsExploit #USA
Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit
Exploit code was released for an unpatched Windows local privilege escalation flaw dubbed BlueHammer that can grant SYSTEM or elevated administrator permissions. The proof-of-concept was published by a researcher using the aliases Chaotic Eclipse and Nightmare-Eclipse after a disclosure dispute with Microsoft, and researchers confirm it can access the SAM database and enable full system compromise despite bugs and no official patch. #BlueHammer #ChaoticEclipse
www.hendryadrian.com
April 6, 2026 at 10:00 PM
ChaoticEclipse drops new "YellowKey" bypass for Windows "BitLocker" disk encryption drops
Tom's Hardware article on the matter. And here is the hacker's blog. This person has a vendetta against Microsoft? And has been dropping some serious zero days. This post is of interest for the short contents and the top reply two months later, when the YellowKey bypass drop: > > I never wanted to reopen a blog and a new github account to drop code... >> >> But someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine. > You’re a smart guy. Maybe a savant. Just wondering if you’re BiPolar (like me) and see a different reality than what is real. Been there. > > If you take this comment the wrong way, don’t hack me. It would be way too easy for you anyway, not worth your time. > > Just want to let you know that I hope life works out for you. > > The NSA is probably interested and reach out to you. I would recommend that you get treated for BiPolar and be normal again so that you can work for them. > > Such a brilliant mind shouldn’t go to waste. > > I’m a computer guy. Can’t work anymore after my brain got fried from working in a very stressful situation. > > The bitlocker hack had an easier route. The hash key is stored in a disk location. That is how you even boot into a working environment. Very strange comment! * * * Anyways, so far they have dropped: * BlueHammer, a LPE * UnDefend, which disables Microsoft Defender * RedSun, another LPE * GreenPlasma, * YellowKey, the cool new one which allows an attacker with physical access to completely bypass disk encryption. The developer says this looks like a backdoor. Anyways, this is a big one, what the hell
jstpst.net
May 14, 2026 at 10:05 AM