{"id":670697,"date":"2026-05-14T16:03:15","date_gmt":"2026-05-14T16:03:15","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/670697\/"},"modified":"2026-05-14T16:03:15","modified_gmt":"2026-05-14T16:03:15","slug":"microsoft-windows-alert-angry-hacker-drops-2-new-zero-day-exploits-2","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/670697\/","title":{"rendered":"Microsoft Windows Alert\u2014Angry Hacker Drops 2 New Zero-Day Exploits"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/05\/1778688130_177_0x0.jpg\" alt=\"Windows logo appears on the screen of a smartphone.\" data-height=\"1806\" data-width=\"2715\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Angry hacker drops more Windows 0-Days in ongoing campaign.<\/p>\n<p>NurPhoto via Getty Images<\/p>\n<p>Updated May 14: This article, originally published May 13, reveals two new Windows zero-day exploits that have been publicly disclosed by a disgruntled security researcher with a bee in their bonnet regarding the way that the Microsoft Security Response Center deals with vulnerability reports. It has now been updated to include details from the May Patch Tuesday security rollout, which the hacker timed to follow the zero-day drops and has threatened to target next month as well.<\/p>\n<p>The day following the Microsoft Patch Tuesday security updates rollout is known in cybersecurity circles as Exploit Wednesday. This month, there is more reason than ever to take that very seriously indeed. While Microsoft didn\u2019t patch any \u201cin the wild\u201d vulnerabilities this time, an angry hacker known by the monikers Chaotic Eclipse and Nightmare Eclipse decided to synchronize the public disclosure of no less than two zero-day exploits with the official release. Here\u2019s what you need to know, and do, about the YellowKey and GreenPlasma exploits.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-3\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/14\/wont-fix-all-vpn-apps-affected-as-google-android-16-leaks-info\/\" target=\"_blank\" aria-label=\"\u2018Won\u2019t Fix\u2019\u2014All VPN Apps Affected As Google Android 16 Leaks Info\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/14\/wont-fix-all-vpn-apps-affected-as-google-android-16-leaks-info\/\" rel=\"nofollow noopener\">Forbes\u2018Won\u2019t Fix\u2019\u2014All VPN Apps Affected As Google Android 16 Leaks InfoBy Davey Winder<\/a>What You Need To Know About The YellowKey And GreenPlasma Microsoft Windows Zero-Day Exploits<\/p>\n<p>Hell hath no fury like a security researcher scorned. Well, that appears to be so in the case of a bug bounty hacker known as Chaotic Eclipse, who has a history when it comes to posting Windows zero-days after being unhappy over communications with the Microsoft Security Response Center. Having publicly released exploit code for a zero-day in April, that went by the name of <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/04\/08\/1-billion-microsoft-users-warned-as-angry-hacker-drops-0-day-exploit\/?streamIndex=0\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/04\/08\/1-billion-microsoft-users-warned-as-angry-hacker-drops-0-day-exploit\/?streamIndex=0\" target=\"_self\" aria-label=\"BlueHammer\" rel=\"nofollow noopener\">BlueHammer<\/a> and turned Microsoft Defender\u2019s own update workflow into a credential theft mechanism, they are now at it again. <\/p>\n<p>\u201cMicrosoft has chosen to make this worse instead of resolving the situation like adults,\u201d Chaotic Eclipse said, \u201cthey pulled every childish game possible. My patience is running out you&#8217;re making everyone else paying for it.\u201d The security researcher on a mission went on to address Microsoft security directly, saying, \u201cI\u2019m not sure what type of reaction you expected from me when you threw more gas on the fire after BlueHammer,\u201d warning that the \u201cfire will go as long as you want, unless you extinguish it or until there nothing left to burn.\u201d<\/p>\n<p>The latest fuel comes in the form of two new zero-day exploits called <a class=\"color-link\" href=\"https:\/\/github.com\/Nightmare-Eclipse\/YellowKey\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/github.com\/Nightmare-Eclipse\/YellowKey\" aria-label=\"YellowKey\">YellowKey<\/a> and GreenPlasma. The first is a Windows BitLocker encryption bypass, the second a Windows CTFMON arbitrary section creation elevation of privileges vulnerability. Together, within 24 hours of the public proof of exploit code being published, they have already been <a class=\"color-link\" href=\"https:\/\/www.huntress.com\/blog\/nightmare-eclipse-intrusion\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.huntress.com\/blog\/nightmare-eclipse-intrusion\" aria-label=\"used in active attack campaigns\">used in active attack campaigns<\/a>. <\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-4 link-embed--long-title\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/12\/signifcant-threat-billions-of-gmail-users-at-risk-from-google-gaffe\/\" target=\"_blank\" aria-label=\"\u2018Significant Threat\u2019\u2014Billions Of Gmail Users At Risk From Google Security Gaffe\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/12\/signifcant-threat-billions-of-gmail-users-at-risk-from-google-gaffe\/\" rel=\"nofollow noopener\">Forbes\u2018Significant Threat\u2019\u2014Billions Of Gmail Users At Risk From Google Security GaffeBy Davey Winder<\/a><\/p>\n<p>\u201cBoth of the released exploit POCs suggest significant, potentially systemic flaws in how modern Windows operating system features handle path trust (GreenPlasma) and recovery (YellowKey),\u201d Gavin Knapp, cyber threat intelligence principal lead at Bridewell, said. Microsoft is not the only vendor suffering from such issues, as is evident in my <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/12\/signifcant-threat-billions-of-gmail-users-at-risk-from-google-gaffe\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/12\/signifcant-threat-billions-of-gmail-users-at-risk-from-google-gaffe\/\" target=\"_self\" aria-label=\"exclusive report\" rel=\"nofollow noopener\">exclusive report<\/a> on architectural failings in security mechanisms designed to protect Google Drive and Gmail users. Historical system vulnerabilities are being found rapidly, Knapp wanted, \u201cwhich is likely due to <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/13\/from-vibe-coding-to-vibe-hacking---ai-in-a-hoodie\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/13\/from-vibe-coding-to-vibe-hacking---ai-in-a-hoodie\/\" target=\"_self\" aria-label=\"skilled researchers leveraging AI\" rel=\"nofollow noopener\">skilled researchers leveraging AI<\/a> to expedite and scale vulnerability research and exploit development.\u201d <\/p>\n<p>Organizations should treat this as an active threat, Neena Sharma, a cybersecurity specialist at Filigran, told me, advising them to \u201cassess their exposure immediately, particularly for devices in high-risk physical access scenarios such as field devices, and shared workstations.\u201d Because immediate patching isn\u2019t possible at the time of writing, Sharma suggested implementing \u201ccompensating controls like restricting USB boot access.&#8221;<\/p>\n<p>Meanwhile, Chaotic Eclipse has issued the following warning to the Microsoft Security Response Center: \u201cYour recent actions made me take the difficult decision to drag other companies into this, be prepared to answer questions.<br \/>Next <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/14\/41-microsoft-zero-days---now-millions-of-users-face-update-choice\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/14\/41-microsoft-zero-days---now-millions-of-users-face-update-choice\/\" target=\"_self\" aria-label=\"Patch Tuesday\" rel=\"nofollow noopener\">Patch Tuesday<\/a> will have a big surprise for you, Microsoft. And remember, I never failed to deliver a promise.\u201d<\/p>\n<p>The Microsoft May Patch Tuesday Rollout Details<\/p>\n<p>John Carberry, a \u2018solution sleuth\u2019 with  Xcape, Inc., told me that the May Patch Tuesday rollout from Microsoft  is a game changer: \u201cWith 138 vulnerabilities patched this month &#8211; the second-largest volume in history &#8211; and over 500 CVEs addressed since January, Microsoft is on pace to shatter the 2020 record of 1,245 annual patches.\u201d So, what are the main takeaways once you start delving into the long list of vulnerabilities?<\/p>\n<p>Adam Barnett, principal software engineer at Rapid7, confirmed that \u201cMicrosoft is not aware of exploitation in the wild or public disclosure for any of these vulnerabilities,\u201d which is the good news, especially in light of the Chaotic Eclipse zero-day drop. However, Barnett advised that \u201canyone responsible for securing a domain controller should prioritize remediation of CVE-2026-41089, which is a critical stack-based buffer overflow in Windows Netlogon.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-5\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/10\/critical-new-linux-zero-day-confirmed-hackers-get-root-no-patch-yet\/\" target=\"_blank\" aria-label=\"Critical New Linux Zero-Day Leaked\u2014What Admins Need To Do Now\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/10\/critical-new-linux-zero-day-confirmed-hackers-get-root-no-patch-yet\/\" rel=\"nofollow noopener\">ForbesCritical New Linux Zero-Day Leaked\u2014What Admins Need To Do NowBy Davey Winder<\/a><\/p>\n<p>Alex Vovk, CEO at Action1, has warned that another vulnerability, CVE-2026-42831, a critical remote code execution flaw in Microsoft Office caused by a heap-based buffer overflow, could allow an \u201cunauthorized attacker to exploit this issue by sending a malicious Office file, turning one user click into full code execution on a workstation.\u201d Such a compromise could, Vovk said, compromise employee workstations, expose sensitive documents, enable credential theft, and support phishing-based intrusion campaigns. <\/p>\n<p>And finally, Mike Walters, the Action1 co-founder, suggested that two Microsoft Word remote code execution vulnerabilities, CVE-2026-40367 and CVE-2026-40366, are worthy of your attention. CVE-2026-40367 is a critical remote code execution vulnerability in Microsoft Word due to an untrusted pointer dereference flaw. CVE-2026-40366 is a critical remote code execution vulnerability in Microsoft Word due to a use-after-free flaw.  \u201cAn unauthorized attacker could exploit these two flaws to execute code locally, and the Preview Pane is confirmed as an attack vector, increasing the risk of exposure through routine document handling,\u201d Walters explained.<\/p>\n","protected":false},"excerpt":{"rendered":"Angry hacker drops more Windows 0-Days in ongoing campaign. NurPhoto via Getty Images Updated May 14: This article,&hellip;\n","protected":false},"author":2,"featured_media":668503,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[322683,64,63,322688,322684,322687,322685,105,7116,322682,176946,305157,322686],"class_list":["post-670697","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-angry-hacker","tag-au","tag-australia","tag-bluehammer","tag-chaotic-eclipse","tag-greenplasma","tag-nightmare-eclpise","tag-technology","tag-windows","tag-windows-0-day-exploit","tag-windows-security-alert","tag-windows-warning","tag-yellowkey"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/670697","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=670697"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/670697\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/668503"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=670697"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=670697"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=670697"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}