Last week, we wrote about YellowKey, the BitLocker bypass that turns a missing Windows 11 laptop into a data exposure event. The proof-of-concept is public, Microsoft has assigned CVE-2026-45585 (CVSS 6.8), and a full security update still has no committed ship date. Mitigation guidance exists, but the choice between Microsoft’s WinRE fix and BitLocker+PIN is… Continue reading Update: YellowKey BitLocker Bypass White Paper Available
Category: Cyber Heads-up
Recent Tenable Agent Update Causes False Positives in EDR Software
Good morning, Yesterday (May 25, 2026), the Assura team began receiving reports that various Endpoint Detection and Response (EDR) platforms began quarantining systems running the Tenable Vulnerability Management agent for Windows. Because this is highly unusual, our Security Operations Center (SOC) team conducted a thorough investigation out of an abundance of caution to rule out… Continue reading Recent Tenable Agent Update Causes False Positives in EDR Software
YellowKey BitLocker Bypass and GreenPlasma SYSTEM Escalation Hit Windows 11 and Server 2022/2025
Overview On May 12, 2026, a security researcher operating under the handles “Chaotic Eclipse” and “Nightmare-Eclipse” dropped two unpatched Windows zero-days on GitHub. The first, YellowKey, bypasses BitLocker drive encryption entirely on Windows 11, Windows Server 2022, and Windows Server 2025 using nothing more than a USB stick and a key press during boot. The… Continue reading YellowKey BitLocker Bypass and GreenPlasma SYSTEM Escalation Hit Windows 11 and Server 2022/2025
Cyber Heads Up: “Copy Fail” (CVE-2026-31431), a High-Severity Linux Kernel Privilege Escalation Vulnerability
Overview: A high-severity privilege escalation vulnerability has been disclosed in the Linux kernel, tracked as CVE-2026-31431 and nicknamed Copy Fail. The flaw was discovered by Taeyang Lee of Theori and carries a CVSS score of 7.8 (High). A working 732-byte Python proof-of-concept exploit is publicly available, and active exploitation in the wild has been reported.… Continue reading Cyber Heads Up: “Copy Fail” (CVE-2026-31431), a High-Severity Linux Kernel Privilege Escalation Vulnerability
Update: Iranian-U.S./Israeli Hostilities Lead to Increased Threat Landscape
Overview: This is an update to the Cyber Heads-up we posted back on March 4, 2026, with detailed information about Iranian threat activity tied to ongoing U.S./Israeli operations. Analysis: At the start of hostilities with Iran, we at Assura took proactive steps to identify and create alerts for known Iranian-sponsored Indicators of Compromise (IOCs). We… Continue reading Update: Iranian-U.S./Israeli Hostilities Lead to Increased Threat Landscape
Iranian-U.S./Israeli Hostilities Lead to Increased Threat Landscape
Overview Iranian‑aligned cyber actors pose an elevated near‑term risk due to their history of espionage, credential theft, disruptive attacks, and high‑visibility “hacktivist” and disinformation operations, often targeting U.S. and allied interests through phishing, exploitation of exposed systems, and social manipulation. Given the current active hostilities between Iran and the U.S./Israeli-led coalition, threat intelligence indicates activity… Continue reading Iranian-U.S./Israeli Hostilities Lead to Increased Threat Landscape
Updated: ACTIVE EXPLOITATION ALERT: Zero-Day Vulnerability Affecting Self-Hosted SharePoint Servers (CVE-2025-53770/53771)
Updated on 24 July 2025 to add links to external references and add guidance around applying security updates published by Microsoft. Overview: On July 18, 2025, Eye Security identified large-scale exploitation of a zero-day SharePoint vulnerability chain that enables unauthenticated remote code execution (RCE). Within hours, attackers were actively compromising self-hosted SharePoint servers worldwide, deploying… Continue reading Updated: ACTIVE EXPLOITATION ALERT: Zero-Day Vulnerability Affecting Self-Hosted SharePoint Servers (CVE-2025-53770/53771)
Cyber Heads Up: “BadSuccessor”—A Critical Active Directory Privilege Escalation Vulnerability in Windows Server 2025
Overview: Akamai researchers have identified a significant privilege escalation vulnerability in Windows Server 2025, termed “BadSuccessor.” This flaw exploits the newly introduced delegated Managed Service Accounts (dMSAs) feature, allowing attackers to impersonate any Active Directory (AD) user, including domain administrators, without altering existing accounts or group memberships. Key Details: Impact: Exploitation of BadSuccessor can lead… Continue reading Cyber Heads Up: “BadSuccessor”—A Critical Active Directory Privilege Escalation Vulnerability in Windows Server 2025
Cyber Heads Up: Tenable Plugin Update Causes Agents to Disconnect from Cloud Console (Read for Fix)
Overview: We hope you had a fantastic holiday! Unfortunately, the Grinch might have left one last surprise for us – Tenable has identified a critical issue affecting Nessus Agent versions 10.8.0 and 10.8.1, causing some headaches for vulnerability management teams. A recent plugin update has rendered these agents offline and unresponsive, halting vulnerability scans on… Continue reading Cyber Heads Up: Tenable Plugin Update Causes Agents to Disconnect from Cloud Console (Read for Fix)
Phishing Campaign Installs Backdoor-Loaded VM to Evade Antivirus and Harvest Credentials
Overview Assura, Inc. has been made aware of this attack pattern, has taken steps to detect it in our managed services, and is following the attack in the blogs of security researchers who found this campaign. A recent phishing attack campaign has attackers installing a virtual machine (VM) on your Windows system, prebuilt with backdoors… Continue reading Phishing Campaign Installs Backdoor-Loaded VM to Evade Antivirus and Harvest Credentials