{"id":700366,"date":"2026-05-28T23:43:08","date_gmt":"2026-05-28T23:43:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/700366\/"},"modified":"2026-05-28T23:43:08","modified_gmt":"2026-05-28T23:43:08","slug":"microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/700366\/","title":{"rendered":"Microsoft 0-day feud escalates as researcher threatens another Windows exploit dump"},"content":{"rendered":"<p>The ongoing saga of Microsoft versus Nightmare Eclipse (aka Chaotic Eclipse), the disgruntled bug hunter with a deep understanding of Windows and an even deeper grudge against Microsoft, reached a fever pitch, with the researcher, who has thus far released six Windows zero-days, promising a \u201cbone shattering\u201d drop on July 14.\u00a0<\/p>\n<p>Microsoft, for its part, <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/blog\/2026\/05\/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure\" rel=\"nofollow noopener\" target=\"_blank\">finally responded<\/a>\u00a0to the security researcher and their weaponized Windows flaws with a blog post on (un)coordinated vulnerability disclosure about the now-public bugs: <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-41091\" rel=\"nofollow noopener\" target=\"_blank\">RedSun<\/a>, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-45498\" rel=\"nofollow noopener\" target=\"_blank\">UnDefend<\/a>, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-33825\" rel=\"nofollow noopener\" target=\"_blank\">BlueHammer<\/a>, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-45585\" rel=\"nofollow noopener\" target=\"_blank\">YellowKey<\/a>, GreenPlasma, and MiniPlasma. Redmond says that none of these were reported via its official channels prior to being made public.\u00a0<\/p>\n<p>Attackers began hammering three of the six &#8211; <a href=\"https:\/\/www.huntress.com\/blog\/nightmare-eclipse-intrusion\" rel=\"nofollow noopener\" target=\"_blank\">BlueHammer, RedSun, and UnDefend<\/a> &#8211; soon after Nightmare published working <a href=\"https:\/\/www.cyderes.com\/howler-cell\/windows-zero-day-bluehammer\" rel=\"nofollow noopener\" target=\"_blank\">proof-of-concept exploit code<\/a> for each on\u00a0<a href=\"https:\/\/gitlab.com\/nightmare-eclipse\" rel=\"nofollow noopener\" target=\"_blank\">now-banned <\/a>GitHub (owned by Microsoft) and GitLab accounts.\u00a0<\/p>\n<p>YellowKey, GreenPlasma, and MiniPlasma still don\u2019t have fixes, and Microsoft has deemed \u201cexploitation more likely\u201d for YellowKey, aka CVE-2026-45585, citing a working POC.<\/p>\n<p>\u201cWe remain firmly opposed to these actions, and any disclosure outside proper coordination that could harm our customers and the digital ecosystem,\u201d Microsoft <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/blog\/2026\/05\/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure\" rel=\"nofollow noopener\" target=\"_blank\">wrote<\/a> in a Wednesday blog, and then seemingly threatened legal action against Nightmare:<\/p>\n<p class=\"quote\">\u201cUncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences. Our security teams across the company work tirelessly tracking threat actors who look for weaknesses just like these to attack Microsoft and our customers. Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity \u2013 coordinating as needed with law enforcement around the world.\u201d<\/p>\n<p>Microsoft did not respond to The Register\u2019s questions, including\u00a0whether its legal team planned to sue Nightmare,\u00a0whether the zero-day researcher is a current or former employee, and\u00a0whether Microsoft axed Nightmare\u2019s MSRC account, meaning that the bug hunter can\u2019t disclose vulnerabilities to the Windows giant.\u00a0<\/p>\n<p>Nightmare, in their latest anti-Microsoft missive, claims Microsoft did just that.<\/p>\n<p>\u201cWhen I actively asked you to communicate with me, you refused, humiliated me and made sure to insult me in front of people,\u201d they <a href=\"https:\/\/deadeclipse666.blogspot.com\/2026\/05\/\" rel=\"nofollow noopener\" target=\"_blank\">wrote<\/a> on Saturday. \u201cYou defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so and I still happily did like an idiot.\u201d<\/p>\n<p>            Mark this date July 14th, I will make sure your bones are shattered that day<\/p>\n<p>Nightmare also noted that \u201cMicrosoft still has chains in my hands,\u201d preventing them from releasing \u201cdocuments\u201d yet, or anytime in June, and then warned: \u201cMark this date July 14th, I will make sure your bones are shattered that day.\u201d<\/p>\n<p>Regardless of what does or does not happen on July 14, Nightmare has already caused chaos &#8211; and real enterprise-level damage, as systems engineer Muhammad Qasim Shahzad <a href=\"https:\/\/www.linkedin.com\/feed\/update\/urn:li:activity:7464587162366300160\/\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a> on LinkedIn.\u00a0<\/p>\n<p>\u201cOne person caused more enterprise-level damage in six weeks than most APT groups cause in a year,\u201d Shahzad wrote. \u201cThe gap between disclosure and weaponization is now measured in hours, not days. Your patching window is shrinking fast.\u201d<\/p>\n<p>Zero Day Initiative\u2019s bug hunter-in-chief Dustin Childs, who previously spent about seven years working for Microsoft security and has decades of experience on <a href=\"https:\/\/www.theregister.com\/security\/2023\/10\/11\/microsoft-patch-tuesday-turns-20\/686894\" rel=\"nofollow noopener\" target=\"_blank\">both sides<\/a> of the <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2024\/7\/15\/uncoordinated-vulnerability-disclosure-the-continuing-issues-with-cvd\" rel=\"nofollow noopener\" target=\"_blank\">coordinated vulnerability disclosure<\/a> (CVD) process, told The Register that Microsoft could have handled this better. And he wondered what happened between the two parties to get to this point.<\/p>\n<p>\u201cCVD is a two-way street,\u201d he said. \u201cThe vendor has some responsibility as well, so to go out publicly stating this person violated CVD without showing any of the correspondence seems bold.\u201d<\/p>\n<p>Microsoft could also improve its communications to customers on \u201cwhat the real risks from these bugs are and how they can defend themselves,\u201d Childs added. \u201cThat clear direction seems to be missing.\u201d<\/p>\n<p>Microsoft&#8217;s &#8216;dumpster fire&#8217;<\/p>\n<p>Luta Security founder and CEO <a href=\"https:\/\/www.theregister.com\/2022\/08\/10\/us_security_hiring\/\" rel=\"nofollow noopener\" target=\"_blank\">Katie Moussouris<\/a>, who <a href=\"https:\/\/www.theregister.com\/security\/2023\/11\/22\/microsofts-bug-bounty-turns-10-but-are-we-any-more-secure\/290742\" rel=\"nofollow noopener\" target=\"_blank\">pioneered Microsoft\u2019s bug bounty program<\/a> despite execs vowing <a href=\"https:\/\/www.computerworld.com\/article\/2754035\/microsoft--no-money-for-bugs.html\" rel=\"nofollow noopener\" target=\"_blank\">never to pay<\/a> researchers for bugs, said Redmond\u2019s response to Nightmare sends \u201cmixed messages.\u201d<\/p>\n<p>\u201cIt confusingly claims their program \u2018ensures researchers are compensated and publicly acknowledged\u2019 in a statement answering a researcher who says he got neither,\u201d Moussouris told The Register. \u201cThe language choices are also not deescalating. Microsoft invoked the outdated term \u2018responsible disclosure,\u2019 which <a href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/blog\/2010\/07\/coordinated-vulnerability-disclosure-bringing-balance-to-the-force\" rel=\"nofollow noopener\" target=\"_blank\">I retired years ago at Microsoft <\/a>because it was subjective and judgy.\u201d<\/p>\n<p>This phrase, Moussouris added, \u201cgot in the way of coordination\u201d when the two sides disagreed about how to best protect end users.<\/p>\n<p>\u201cThe mention of the Digital Crimes Unit in a post discussing vulnerability disclosure makes the post vaguely threatening, which seems intentional, but then they wrap up the post saying they welcome reports regardless of disclosure history,\u201d she said. \u201cNo one except the parties involved can know for sure what happened between this researcher and Microsoft. Whatever the facts, it&#8217;s hard to imagine why Microsoft would not try to deescalate, if for no other reason than avoiding the chilling effect on other researchers.\u201d <\/p>\n<p>Security sleuth Kevin Beaumont, in his blog on the ongoing Microsoft-Nightmare Eclipse saga, called it a &#8220;<a href=\"https:\/\/medium.com\/doublepulsar\/microsofts-stance-on-zero-day-exploits-is-a-dumpster-fire-of-their-own-making-0946117940a4\" rel=\"nofollow noopener\" target=\"_blank\">dumpster fire<\/a> of [Microsoft\u2019s] own making.\u201d\u00a0<\/p>\n<p>Beaumont also used to work at Microsoft, and he noted that the Windows company previously <a href=\"https:\/\/krebsonsecurity.com\/2020\/04\/microsoft-patch-tuesday-april-2020-edition\/\" rel=\"nofollow noopener\" target=\"_blank\">hired a hacker called SandboxEscaper<\/a> after she published zero-day POC exploits for Microsoft products &#8211; something that Redmond\u2019s blog now describes as criminal.<\/p>\n<p>\u201cIf Microsoft\u2019s tactic is to try to criminalise not following often arbitrary \u2018responsible disclosure\u2019 frameworks, good luck defending that in court &#8211; because there\u2019s a whole clown car of prior decision making within Microsoft and facts which would emerge in that process,\u201d Beaumont said.<\/p>\n<p>To be clear: neither Beaumont nor the researchers that The Reg spoke to support Nightmare\u2019s zero-day antics. Childs called the \u201cJuly 14\u201d post \u201ctroubling\u201d and Moussouris said the date plus \u201cincendiary language \u2026 doesn&#8217;t help organizations trying to make sense of the technical risk.\u201d\u00a0<\/p>\n<p>&#8216;David and Goliath dynamic&#8217;\u00a0<\/p>\n<p>Moussouris did add that this latest missive, taken in context with the earlier blog posts, \u201cpaint[s] a picture of someone who believes they have been pushed to this extreme. It is the sound of someone who believes every legitimate channel was closed to them: GitHub account deleted, payments withheld, credit stripped, then publicly accused of violating CVD after Microsoft cut off their ability to coordinate. The researcher&#8217;s grievances are serious and specific.\u201d\u00a0<\/p>\n<p>Ultimately, \u201cthe bugs are Microsoft&#8217;s,\u201d Moussouris said. \u201cThey wrote the code and they own the risk to customers. Often researchers who previously work with a vendor respond in the extreme only when they feel there is no other choice. The power they hold is not at all proportionate to the vendor. This is a David and Goliath dynamic we don&#8217;t like to see play out, especially since it\u2019s users who lose when coordination negotiations fail.&#8221;<\/p>\n<p>While it\u2019s a very extreme &#8211; perhaps the most extreme &#8211; example of coordinated disclosure gone wrong, it\u2019s not an isolated problem. Researchers have been <a href=\"https:\/\/www.theregister.com\/security\/2023\/08\/07\/microsoft-hits-back-at-tenables-criticism-of-its-infosec\/633426\" rel=\"nofollow noopener\" target=\"_blank\">complaining about CVD<\/a>, and specifically <a href=\"https:\/\/www.theregister.com\/security\/2024\/06\/05\/tenable-finds-an-azure-flaw-microsoft-calls-it-a-feature\/1222119\" rel=\"nofollow noopener\" target=\"_blank\">Redmond\u2019s bug disclosure habits<\/a>, for years.\u00a0<\/p>\n<p>\u201cWhile some companies have improved, Microsoft has not,\u201d Childs said. \u201cIf anything, they are seen as difficult to work with, especially if your bug is Moderate instead of Critical. I\u2019ve had researchers tell me that they stopped looking at Microsoft altogether because they were too difficult to work with.\u201d<\/p>\n<p>Plus, these types of <a href=\"https:\/\/www.theregister.com\/security\/2026\/05\/21\/hackerone-takes-an-axe-to-its-bug-bounty-rewards\/5244458\" rel=\"nofollow noopener\" target=\"_blank\">disagreements between researchers and bug bounty programs<\/a> will likely increase, as <a href=\"https:\/\/www.theregister.com\/patches\/2026\/05\/14\/welcome-to-the-vulnpocalypse-as-vendors-use-ai-to-find-bugs-and-patches-multiply-like-rabbits\/5240027\" rel=\"nofollow noopener\" target=\"_blank\">AI-assisted bug reports<\/a> become <a href=\"https:\/\/www.theregister.com\/security\/2026\/05\/25\/anthropic-to-release-mythos-class-models-to-the-public\/5245596\" rel=\"nofollow noopener\" target=\"_blank\">the norm<\/a> and vulnerabilities skyrocket.<\/p>\n<p>\u201cWe as an industry need to take a breath, remember there are real people involved, and that poor interactions could lead to real customer risk,\u201d Childs said. \u201cReal-world impact is lost far too often when disclosure goes wrong.\u201d\u00a0\u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"The ongoing saga of Microsoft versus Nightmare Eclipse (aka Chaotic Eclipse), the disgruntled bug hunter with a deep&hellip;\n","protected":false},"author":2,"featured_media":700367,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[49,48,61],"class_list":["post-700366","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ca","tag-canada","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/700366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=700366"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/700366\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/700367"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=700366"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=700366"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=700366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}