news.mlab.sh
Back to the feed
threat-intel

Microsoft calls zero-day releases ‘never justifiable’ as researcher threatens to drop more

High
Summary

Microsoft is responding to a weeks-long campaign by a pseudonymous researcher, ‘Nightmare Eclipse,’ who released uncoordinated zero-day vulnerabilities in Windows. The researcher, motivated by grievances against Microsoft regarding account deletion and bounty payments, threatened further releases and warned of potential harm. Microsoft condemned the disclosures as ‘never justifiable’ and stated its intention to pursue legal action against those enabling cybercrime.

A researcher known as ‘Nightmare Eclipse’ initiated a campaign in April, releasing six zero-day vulnerabilities – BlueHammer, UnDefend, RedSun, YellowKey, GreenPlasma, and MiniPlasma – alongside working proof-of-concept code on GitHub. These vulnerabilities were quickly exploited in live intrusions, confirmed by Microsoft’s patch advisories and appearing on the CISA’s catalog of exploited vulnerabilities. The researcher’s GitHub account and Blogger page have been taken down, and the researcher has publicly voiced grievances against Microsoft, alleging improper handling of their Microsoft Security Response Center account and withheld bounty payments. Microsoft responded by condemning the disclosures and reaffirming its commitment to responsible vulnerability disclosure and security research. They highlighted their ongoing efforts to track threat actors and bring legal action against those enabling cybercrime, while acknowledging the complexities and frustrations within the security community, referencing past criticisms of their handling of vulnerabilities by organizations like Trend Micro and Tenable.

Read the full article at The Record