Summary

A disgruntled security researcher operating under the aliases “Chaotic Eclipse” and “Nightmare Eclipse” has publicly released proof-of-concept exploits for three separate Windows zero-day vulnerabilities in a coordinated campaign timed to coincide with Microsoft’s May 2026 Patch Tuesday. All three have been confirmed exploited in the wild within 24 hours of disclosure.

YellowKey is a BitLocker encryption bypass that undermines one of Windows’ core security features. GreenPlasma targets CTFMON for arbitrary section creation, enabling privilege escalation. Most alarmingly, MiniPlasma exploits the Windows Cloud Files Mini Filter Driver (cldflt.sys) to grant SYSTEM-level privileges on fully patched Windows 11 systems — and security researcher Will Dormann confirmed it works “reliably” on systems running the latest May 2026 updates.

MiniPlasma is particularly embarrassing for Microsoft: the underlying vulnerability was originally reported by Google Project Zero’s James Forshaw in September 2020 and was supposedly fixed in December 2020 under CVE-2020-17103. Chaotic Eclipse discovered the fix was either never properly applied or silently rolled back.

Sources

Commentary

There’s a lot to unpack here, but the core issue is straightforward: a researcher who felt ignored by MSRC decided to go nuclear. Whether you sympathize with Chaotic Eclipse’s frustration or not, the result is three weaponized zero-days being used in active attacks against Windows users worldwide. The researcher has explicitly threatened to continue this cadence monthly, which turns every future Patch Tuesday into a ticking clock.

The MiniPlasma saga is the most damning. A six-year-old bug reported by Google Project Zero, supposedly patched, turns out to still be exploitable on fully updated systems. That’s not just a patch gap — it’s a systemic failure in regression testing. Organizations running Windows should assume they’re vulnerable until Microsoft issues a verified fix, and prioritize endpoint detection for cldflt.sys abuse patterns in the meantime.

By Allan