Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops

Microsoft says uncoordinated disclosures could harm customers as the researcher threatens another release after six Windows zero-days were posted online.

  • On Wednesday, Microsoft threatened legal action against researcher Nightmare Eclipse for publishing six unpatched Windows zero-day vulnerabilities, claiming uncoordinated disclosures harm customers and the digital ecosystem.
  • Nightmare claims Microsoft deleted their reporting account and withheld payments after mistreatment, while Redmond contends the researcher failed to report vulnerabilities through official channels before public disclosure.
  • Attackers began exploiting BlueHammer, RedSun, and UnDefend shortly after Nightmare published proof-of-concept code, while the researcher threatened a "bone shattering" drop for July 14.
  • Security experts criticized Microsoft's response, with Luta Security CEO Katie Moussouris calling it a "dumpster fire" and questioning the outdated term "responsible disclosure."
  • This "David and Goliath dynamic" reflects systemic vendor-researcher tension, as Nightmare noted "Microsoft still has chains in my hands," preventing document releases until July 14.
Insights by Ground AI
Podcasts & Opinions

11 Articles

A conflict between Microsoft and a security researcher is escalating. After the closure of its GitHub account, the discoverer is threatened with further revelations. The US-American technology company Microsoft has issued a clear statement on the uncoordinated publication of security vulnerabilities. The company thus reacted to the recent activities of a security researcher operating under the pseudonyms Chaotic Eclipse and Nightmare Eclipse. In…

The discussion about zero-day vulnerabilities in Windows gained a new chapter after a public conflict between security researchers and the giant Microsoft technology. The case involves the disclosure of critical flaws still uncorrected, the performance of platforms like GitHub and GitLab, and the ban of a researcher known as Chaotic Eclipse. The episode rekindles the debate about how much failure disclosure should be public before an official co…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 50% of the sources lean Left, 50% of the sources are Center
50% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

unsafe.sh broke the news on Thursday, May 28, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal