Vulnerabilities
YellowKey: A USB Port and a Reboot Bypass BitLocker — and Microsoft's Only Fix Is a Config Change, Not a Patch
Microsoft released mitigations for YellowKey (CVE-2026-45585), a BitLocker bypass disclosed by the researcher behind MiniPlasma. A USB port and a reboot defeat the encryption on any TPM-only device — and the only fix is a TPM+PIN configuration change, not a patch.