Close Menu
Savannah HeraldSavannah Herald
    • Home
    • News
      • Local
      • State
      • National
      • World
      • HBCUs
    • Events
    • Directories
    • Weather
    • Traffic
    • Sports
    • Politics
    • Lifestyle
      • Faith
      • Senior Living
      • Health
      • Travel
      • Beauty
      • Fashion
      • Food
      • Art & Literature
    • Business
      • Real Estate
      • Entertainment
      • Investing
      • Education
    • Guides
      • Summer Camp Guide
      • Juneteenth Guide
      • Black History Savannah
      • MLK Guide Savannah
    We're Social
    • Twitter
    • Facebook
    • YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Trending
    • The Source |New Music Friday: Fivio Foreign, Loui Paso, and Jon Z Bridge Drill and Latin Trap on “Untouchable”
    • Legendary Rock Tattoo Artist Greg James Dead at 71
    • Minority Prospects HBCU All-Star Game roster released
    • Black midwives challenge regulations in Alabama, Georgia, Mississippi
    • Reid Hoffman is leaving Microsoft’s board to go ‘founder mode’ with startup Manus
    • Roboticist, AI trailblazer named next Spelman president
    • Bush’s Journey: Navy, Politics, and Presidency
    • My Dad Packed for Skydiving. We Ended Up on a Steam Train
    Facebook X (Twitter) Instagram YouTube
    Login
    Savannah HeraldSavannah Herald
    Savannah HeraldSavannah Herald
    Home » Zero-day exploit completely defeats default Windows 11 BitLocker protections
    Tech

    Zero-day exploit completely defeats default Windows 11 BitLocker protections

    Savannah HeraldBy Savannah HeraldMay 17, 20263 Mins Read
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    A computer screen with red and blue warning signs.
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Tech Trends & Innovation: The Latest in Tech News

    Key takeaways
    • Exploit named YellowKey, published by alias Nightmare-Eclipse
    • Uses custom FsTx folder and fstx.dll, leveraging Transactional NTFS to trigger the bypass
    • Attack steps: copy FsTx to USB, boot and hold Ctrl to enter Windows Recovery, get full CMD.EXE access
    • Bypasses BitLocker recovery key; confirmed by researchers Kevin Beaumont and Will Dormann

    A zero-day exploit circulating online allows people with physical access to a Windows 11 system to bypass default BitLocker protections and gain complete access to an encrypted drive within seconds.

    The exploit, named YellowKey, was published earlier this week by a researcher who goes by the alias Nightmare-Eclipse. It reliably bypasses default Windows 11 deployments of BitLocker, the full-volume encryption protection Microsoft provides to make disk contents off-limits to anyone without the decryption key, which is stored in a secured piece of hardware known as a trusted platform module (TPM). BitLocker is a mandatory protection for many organizations, including those that contract with governments.

    When one disk volume manipulates another

    The core of the YellowKey exploit is a custom-made FsTx folder. Online documentation of this folder is hard to find. As explained later, the directory associated with the file fstx.dll appears to involve what Microsoft calls the transactional NTFS, which allows developers to have “transactional atomicity” for file operations in transactions with a single file, multiple files, or ones that span multiple sources.

    The steps for carrying out the bypass are simple:

    1. Copy the custom FsTx folder from the Nightmare-Eclipse exploit page to an NTFS- or FAT-formatted USB drive
    2. Connect the USB drive to the BitLocker-protected device
    3. Boot up the device and immediately press and hold down the [Ctrl] key
    4. Enter Windows recovery

    There are at least two ways to accomplish the third step. One way is to boot into Windows, hold down the [Shift] key, click on the power icon, and click restart. Another is to power on the device and restart it as soon as Windows starts booting.

    In either case, a command (CMD.EXE) prompt appears. The prompt has full access to the entire drive contents, allowing an attacker to copy, modify, or delete them. In a normal Windows Recovery flow, the attacker would need to enter a BitLocker recovery key. Somehow, the YellowKey exploit bypasses this safeguard. Multiple researchers, including Kevin Beaumont and Will Dormann, have confirmed the exploit works as described here.

    It’s unclear what in the custom FsTx folder causes the bypass. Dormann said that it appears to be related to Transactional NTFS, which itself uses command-log file system under the hood. Dormann further noted that by looking at the Windows fstx.dll, one will see code that explicitly looks for \System Volume Information\FsTx in the FsTxFindSessions() function.”

    Read the full article from the original source


    AI and Machine Learning artificial intelligence Consumer Electronics Cybersecurity Updates Data Privacy Digital Trends Enterprise Technology Future of Work Gadget Reviews Green Tech Mobile Tech Robotics News Science and Technology Silicon Valley News Software Development Startups and Tech Tech Industry Insights Tech Innovation Tech Policy Technology News
    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Savannah Herald
    • Website

    Related Posts

    Tech June 5, 2026

    Reid Hoffman is leaving Microsoft’s board to go ‘founder mode’ with startup Manus

    Tech June 5, 2026

    How Paid Influencers Hype Polymarket’s Odds

    Tech June 5, 2026

    These Macs Won’t Support macOS 27 Later This Year

    Tech June 4, 2026

    Denken Sie über einen Wechsel Ihres IT-Servicemanagement-Tool nach?  

    Tech June 3, 2026

    U.K. Prime Minister Condemns Violent Protests as Police Face Criticism Over Handcuffed Student’s Murder

    Tech June 3, 2026

    Apple’s Excellent 11-Inch iPad Is Now Just $299.99 In Your Favorite Colors

    Comments are closed.

    Don't Miss
    Food May 14, 2026By Savannah Herald09 Mins Read

    Immediate Pot Shrimp And Grits The Black Individuals Means

    May 14, 2026

    Fresh from the Kitchen Area Location: Recipes & Food Concepts Food preparation shrimp and grits…

    Tigers Win Four Events At Alice Coachman Invitational

    April 14, 2026

    We Buy Houses Twin Falls, ID: Top 5 Companies

    February 28, 2026

    Black ‘The Price Is Right’ Contestant Abruptly Quits Live Show, Leaving Host Drew Carey and Viewers Stunned

    May 1, 2026

    Black faith leaders march on Wall Street to denounce anti-DEI campaign

    February 28, 2026
    Archives
    • June 2026
    • May 2026
    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • December 2025
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    Categories
    • Art & Literature
    • Beauty
    • Black History
    • Business
    • Climate
    • Culture
    • Education
    • Employment
    • Entertainment
    • Faith
    • Fashion
    • Food
    • Gaming
    • Georgia Politics
    • HBCUs
    • Health
    • Health Inspections
    • Investing
    • Lifestyle
    • Local
    • Lowcountry News
    • National
    • National Opinion
    • News
    • Politics
    • Real Estate
    • Senior Living
    • Sports
    • State
    • Tech
    • Transportation
    • Travel
    • World
    Savannah Herald Newsletter

    Subscribe to Updates

    A round up interesting pic’s, post and articles in the C-Port and around the world.

    About Us
    About Us

    The Savannah Herald is your trusted source for the pulse of Coastal Georgia and the Low County of South Carolina. We're committed to delivering timely news that resonates with the African American community.

    From local politics to business developments, we're here to keep you informed and engaged. Our mission is to amplify the voices and stories that matter, shining a light on our collective experiences and achievements.
    We cover:
    🏛️ Politics
    💼 Business
    🎭 Entertainment
    🏀 Sports
    🩺 Health
    💻 Technology
    Savannah Herald: Savannah's Black Voice 💪🏾

    Our Picks

    FDA reports two new outbreaks

    September 20, 2025

    A sheet pan dinner that actually works

    March 24, 2026

    Caribbean-Inspired Black Beluga Lentils

    May 2, 2026

    WNBA players embrace continuously growing tunnel walk fashion

    May 8, 2026

    How nuclear energy is gaining traction across Africa

    November 1, 2025
    Categories
    • Art & Literature
    • Beauty
    • Black History
    • Business
    • Climate
    • Culture
    • Education
    • Employment
    • Entertainment
    • Faith
    • Fashion
    • Food
    • Gaming
    • Georgia Politics
    • HBCUs
    • Health
    • Health Inspections
    • Investing
    • Lifestyle
    • Local
    • Lowcountry News
    • National
    • National Opinion
    • News
    • Politics
    • Real Estate
    • Senior Living
    • Sports
    • State
    • Tech
    • Transportation
    • Travel
    • World
    Copyright © 2002-2026 Savannahherald.com All Rights Reserved. A Veteran-Owned Business

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}
    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

    Sign In or Register

    Welcome Back!

    Login below or Register Now.

    Lost password?

    Register Now!

    Already registered? Login.

    A password will be e-mailed to you.