Security pros warn YellowKey claim could make stolen laptops a much bigger problem
When Nightmare-Eclipse released BlueHammer (CVE-2026-32201, 6.5) - patched by Microsoft in April - they were described as a disgruntled researcher who has since been rumored to be a former Microsoft employee.
According to their maiden blog post under the Chaotic Eclipse alias, the bug leak began after an alleged violation of trust. “I never wanted to reopen a blog and a new GitHub account to drop code,” they wrote. “But someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.”
[VP of security intelligence at Forescout Rik] Ferguson described the exposure of YellowKey and GreenPlasma as the latest in an escalating, retaliatory campaign against Microsoft, and warned of more coming.
“The same post linking yesterday’s releases warns of another Patch Tuesday surprise and hints at future RCE disclosures. They claim to have a dead man’s switch with more ready to go. This researcher has followed through on every prior threat.”
Well this sounds much more interesting from a human perspective than the other article I read about the exploits!



