Microsoft is working on a patch for ‘YellowKey’ attack on BitLocker, offers temporary fix
CSO Online interviewed NetSPI’s VP of Research, Karl Fosaaen, for a May 20, 2026 article about how Microsoft is working on a patch for a zero-day vulnerability dubbed “YellowKey” (CVE-2026-45585). This allows attackers with physical access to a Windows device to bypass BitLocker encryption and read or write files, with a public proof of concept already available. Read the preview below or view it online.
+++
In short, Karl’s message is a two-part warning: lock down physical access before an attack happens, and don’t assume you’ll know if you’ve been hit.
Here’s a further breakdown of the key points:
Karl emphasized that since YellowKey requires physical access to exploit, organizations should focus on strengthening physical security controls around their Windows devices. He recommended strong policies and controls around physical device access as a first step, and suggested that organizations concerned about attackers accessing files on a system should consider limiting the data users are allowed to store locally.
Karl also noted that what makes the vulnerability particularly difficult to deal with is that attacks may not be immediately apparent to users. If an attacker used the exploit simply to read files from the encrypted volume, there likely wouldn’t be any indicators visible to the user. However, if malicious software was implanted, the user might notice increased system utilization or other performance issues.
You can read the full article here
Authors:
Explore More News
Canvas breach puts global education cyber risk in focus
ITBrief interviewed NetSPI's Field CISO, Nabil Hannan, for a May 24, 2026 article about a major data breach in Instructure's Canvas learning management system disrupting final exams at universities.
AI-powered Continuous Pentesting
NetSPI® launches AI-powered Continuous Pentesting to help organizations validate and reduce risk through their Human-led, AI-accelerated platform that supports continuous penetration testing and agentic MCP integrations.
When AI Starts Taking Action, Security Needs to Think Differently
CIO Influence interviewed NetSPI's Field CISO, Nabil Hannan, for an April 6, 2026 article about how AI systems are evolving from generating outputs to taking autonomous actions, amplifying existing vulnerabilities and requiring organizations to adopt proactive security measures and robust governance to mitigate risks.