SUBSCRIBE
Tech Journal Now
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
  • More Articles
Reading: Microsoft is working on a patch for ‘YellowKey’ attack on Bitlocker, offers temporary fix – Computerworld
Share
Tech Journal NowTech Journal Now
Font ResizerAa
  • News
  • Reviews
  • Guides
  • AI
  • Best Buy
  • Games
  • Software
Search
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
  • More Articles
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Tech Journal Now > Software > Microsoft is working on a patch for ‘YellowKey’ attack on Bitlocker, offers temporary fix – Computerworld
Software

Microsoft is working on a patch for ‘YellowKey’ attack on Bitlocker, offers temporary fix – Computerworld

News Room
Last updated: May 21, 2026 2:05 am
News Room
Share
2 Min Read
SHARE

“Organizations should start by auditing their environment for the conditions that exist that leave them vulnerable to YellowKey,” said Eric Grenier, senior director analyst at Gartner. “They should also have a clear understanding of their risk acceptance in the case of a lost/stolen device and, based on that acceptance (or non-acceptance), follow the steps such as customizing Secure Boot and ensuring firmware and Boot integrity.” .

 Karl Fosaaen, VP of research at cybersecurity company NetSPI, agreed. “Since this vulnerability requires physical access to exploit, organizations should be focusing on the physical security controls around their Windows devices,” he said. “Having strong policies and controls around physical access to devices is a good first step in helping protect the potentially vulnerable devices. If there are additional concerns about attackers being able to gain access to files on the system, organizations can look at limiting the data that they allow users to store locally.”

One of the issues facing companies is the proliferation of employees using mobile devices, which makes it harder for organizations to restrict access to them. “You’re increasingly seeing companies with corporate data on their laptops, and YellowKey can leave that data unlocked,” said Nathan Davies-Webb, principal consultant at UK-based security company Acumen. This is where tight device security policies come into play, such as prohibiting users from leaving devices unattended.

However, said Fosaaen, what makes detection of an attack particularly difficult for the individual user is that it is not immediately apparent that a device has been targeted. “If an attacker used the exploit to read files from the encrypted volume, there likely wouldn’t be any indicators to a user. If the attacker implanted malicious software, you might see increased system utilization, or other performance issues,” he noted.

Read the full article here

You Might Also Like

Apple CEO Tim Cook stepping down, to be replaced by John Ternus – Computerworld

Microsoft to cut Windows 365 price for SMBs – Computerworld

The Big Four accounting firms are now hiring more AI specialists than accountants – Computerworld

Terminal paste trap blocked – Computerworld

MacBook Neo forces IT to rethink its budget laptop strategy – Computerworld

Share This Article
Facebook Twitter Email Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Trending Stories

Games

Embark busts 9 myths about Arc Raiders’ aggression-based matchmaking, and says defending yourself is no longer a hostile action

May 21, 2026
Games

How well do you know Baldur’s Gate 3’s third act? See what you remember about the RPG’s big finale with a quiz built for real Elder Brains

May 21, 2026
News

Tributes pour in for S. ‘Soma’ Somasegar, beloved tech mentor and friend – GeekWire

May 21, 2026
Games

It’s my own fault for thinking Warren Spector’s new multiplayer stealth game adding singleplayer would make it the Thief successor I was hoping for

May 21, 2026
News

Seattle considers one-year data center moratorium

May 20, 2026
Games

Splitgate studio reveals its new game, looks a lot like its old game

May 20, 2026

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

Follow US on Social Media

Facebook Youtube Steam Twitch Unity

2024 © Prices.com LLC. All Rights Reserved.

Tech Journal Now

Quick Links

  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?