Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Infosecurity Europe: Reactive Security Is Failing Healthcare, Experts

June 5, 2026

Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

June 5, 2026

Practical Lessons From Lloyds’ Agentic AI Security Playbook

June 5, 2026
Facebook X (Twitter) Instagram
Friday, June 5
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal
News

Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

Team-CWDBy Team-CWDJune 5, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected vendors an opportunity to better understand the impact and address them before they are publicly disclosed.

The development comes after a researcher named Chaotic Eclipse (aka Nightmare-Eclipse) disclosed details of multiple zero-day vulnerabilities affecting various Windows components, including Defender and BitLocker, over the past month, citing a breakdown in Microsoft’s handling of the vulnerability disclosure process.

“In recent weeks, several zero-day vulnerabilities have been publicly disclosed,” the tech giant said. “The details of these vulnerabilities were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk.”

“In response to the unnecessary risk created by these disclosures, our security teams have been working around the clock to understand the impact, protect our customers, and develop security updates.”

The vulnerabilities include BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), UnDefend (CVE-2026-45498), YellowKey (CVE-2026-45585), GreenPlasma, and MiniPlasma. Following disclosure, BlueHammer, RedSun, and UnDefend have all come under active exploitation in the wild.

Microsoft said it “firmly” opposes such uncoordinated disclosures and that putting proof-of-concept code for unpatched vulnerabilities can have “real-world consequences” when they end up in the hands of bad actors.

“We invite diverse perspectives that help the security community work together to protect everyone. We realize that we will not always agree on everything, but we are committed to transparency and continue to create opportunities for dialogue,” the tech giant added.

“These conversations happen at researcher appreciation events, security conferences, and the everyday work we do together to understand and address vulnerabilities.”

The fallout from these disclosures is said to have led GitHub to take down the researcher’s account last week. Although the exploit code for the six vulnerabilities was subsequently uploaded to GitLab, the newly created account has since been blocked.

“So let me get this straight, when I actively asked you to communicate with me, you refused, humiliated me, and made sure to insult me in front of people,” the researcher said in a post published over the weekend.

“You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so and I still happily did like an idiot. Now you take the courtesy to flag my GitHub account and wipe it out of the public, just like that? You are proving to everyone that you [sic] actively escalating this conflict but I’m done begging you.”

The researcher also said they intend to release something on July 14, 2026, that “will make sure your bones are shattered that day.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticlePractical Lessons From Lloyds’ Agentic AI Security Playbook
Next Article Infosecurity Europe: Reactive Security Is Failing Healthcare, Experts
Team-CWD
  • Website

Related Posts

News

Infosecurity Europe: Reactive Security Is Failing Healthcare, Experts

June 5, 2026
News

Practical Lessons From Lloyds’ Agentic AI Security Playbook

June 5, 2026
News

Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

June 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What if your romantic AI chatbot can’t keep a secret?

November 18, 2025

What is it, and how do I get it off my device?

September 11, 2025

Scams target soccer fans with fake World Cup tickets, merchandise

May 22, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.