news.mlab.sh
Back to the feed
threat-intel

Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash

High
Summary

This article reports on a controversy between Microsoft and a security researcher, known as Nightmare Eclipse, regarding the disclosure of several zero-day vulnerabilities affecting Microsoft products. Microsoft initially threatened legal action against the researcher after they publicly released details and proof-of-concept exploits, leading to significant backlash from the cybersecurity community. Microsoft has since clarified its stance, stating it has no intention to pursue legal action against researchers conducting security research, while emphasizing its commitment to constructive relationships with the security community.

The core of the issue stems from a disagreement between Microsoft and Nightmare Eclipse concerning the disclosure of vulnerabilities including RedSun (CVE-2026-41091), UnDefend (CVE-2026-45498), BlueHammer (CVE-2026-33825), YellowKey, GreenPlasma, and MiniPlasma. These vulnerabilities, primarily focused on privilege escalation and denial-of-service attacks, were exploited in the wild shortly after their release. Microsoft responded by releasing patches and mitigations, but the initial reaction – including threats of legal action – sparked considerable criticism from the security community, with figures like Kevin Beaumont and Florian Roth highlighting Microsoft’s perceived overreaction and the potential for chilling effect on responsible disclosure. Microsoft subsequently clarified its position, emphasizing its appreciation for the security research community and its commitment to maintaining respectful relationships, while reserving its legal options for cases involving malicious activity causing harm.

Read the full article at SecurityWeek