Microsoft issues YellowKey mitigation, no patch yet

2026-05-20T20:51:44Z39f469a922b41590dfd1cf1dc03c1fdc403b90eb447a2d4c7e836f62439187e0
BitLockerCVE-2026-31635CVE-2026-45585DirtyDecryptDrupal emergency updateFox TempestGitHub breachHuawei zero-dayLinux kernelMENA Operation RamzPOCShai-HuludSignalYellowKeycardinglocal privilege escalationmalicious VS Code extensionmalware-signingnpmpayment card leaksupply chaintelecom outageworm

What happened

Multiple high-impact security developments: Microsoft acknowledged a BitLocker bypass dubbed “YellowKey” (tracked as CVE-2026-45585) and published mitigations (disable autofstx.exe, enable TPM+PIN) but no patch yet. A Linux kernel local privilege escalation (DirtyDecrypt, CVE-2026-31635) has a public PoC exploiting a missing COW guard in rxgk_decrypt_skb. Other notable incidents include a trojanized VS Code extension that exfiltrated ~3,800 GitHub internal repos, a free leak of 4.6M stolen payment card records from B1ack’s Stash, Microsoft disruption of the Fox Tempest malware-signing service,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
39f469a922b41590dfd1cf1dc03c1fdc403b90eb447a2d4c7e836f62439187e0
Enrichment time
2026-05-20T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.